Key distribution method, device, storage medium, and program product
Patent Information
- Application Number
- PCT/CN2026/084037
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-17
- Filing Date
- 2026-03-17
- Publication Date
- 2026-09-24
Smart Images

Figure CN2026084037_24092026_PF_FP_ABST
Abstract
Description
Key distribution methods, devices, storage media and program products
[0001] Cross-references to related applications
[0002] This application claims priority to Chinese patent application No. 202510315432.X, filed on March 17, 2025, entitled “Key Distribution Method, Apparatus, Storage Medium and Program Product”, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application relates to the field of communication technology, and in particular to a key distribution method, device, storage medium, and program product. Background Technology
[0004] Quantum communication is essentially a point-to-point connection. Currently, relay nodes can be used to interconnect the transmitting end (also called the sending node) and the receiving end (also called the receiving node) to extend the transmission distance or extend it to multiple users to realize a quantum communication network. Summary of the Invention
[0005] The technical solution adopted in this application is as follows:
[0006] Firstly, a key distribution method is provided, applied to a sending node. The method includes: obtaining a first original key of the sending node and a first original key of a relay node; generating the first original key of the relay node based on a first subkey and a second subkey of the first original key of the relay node; the first subkey and the second subkey of the first original key of the relay node are keys obtained by performing a first phase slice filtering on a random phase of the relay node based on the first phase slice index and the second phase slice index of the relay node; the first phase slice index and the second phase slice index of the relay node satisfy the following formula: |j B1 |mod M = 0 or M / 2,|j B2 |mod M = 0 or M / 2; where j B1 j represents the index of the first phase slice of the relay node. B2 The second phase slice index of the relay node is represented, and M represents the number of random phase slices; the first intermediate key of the sending node is determined based on the first original key of the sending node and the first original key of the relay node; the first intermediate key of the receiving node is obtained; the first target key is determined based on the first intermediate key of the sending node and the first intermediate key of the receiving node, and the first target key is used by the sending node to communicate with the receiving node through the relay node.
[0007] In one possible implementation, determining the first intermediate key of the sending node based on the first original key of the sending node and the first original key of the relay node includes: acquiring the phase information of the first sending node, the phase information of the first relay node, the first measurement result between the sending node and the relay node, and the first measurement result between the relay node and the receiving node; the phase information of the first sending node is the phase information obtained by performing a first phase slice filtering on the random phase of the sending node; the phase information of the first relay node is the phase information obtained by performing a first phase slice filtering on the random phase of the relay node; the first measurement result between the sending node and the relay node is the measurement result obtained by performing interferometric measurement and the first phase slice filtering on the sending node and the relay node; the first measurement result between the relay node and the receiving node is the measurement result obtained by performing interferometric measurement and the first phase slice filtering on the relay node and the receiving node; and determining the first intermediate key of the sending node based on the first original key of the sending node, the first original key of the relay node, the phase information of the first sending node, the phase information of the first relay node, the first measurement result between the sending node and the relay node, and the first measurement result between the relay node and the receiving node.
[0008] In one possible implementation, the phase information of the first relay node is obtained based on the first sub-phase information and the second sub-phase information of the first relay node; the values of the first sub-phase information and the second sub-phase information of the first relay node satisfy the following condition: in |j Bi When |mod M=0, Φ1 Bi =0; or, in |j Bi When |mod M=M / 2, Φ1 Bi =1; where i∈{1,2}, j B1 j represents the index of the first phase slice of the relay node. B2 Indicates the second phase slice index of the relay node, Φ1 B1 This represents the first sub-phase information of the first relay node, Φ1 B2 This indicates the second sub-phase information of the first relay node.
[0009] In one possible implementation, obtaining the first original key of the sending node includes: performing a first phase slice filtering on the random phase of the sending node based on the phase slice index of the sending node and the phase slice index of the receiving node to obtain the first original key of the sending node; the phase slice index of the sending node and the phase slice index of the receiving node satisfy the following formula: |j A |mod M = 0 or M / 2,|j C |mod M = 0 or M / 2; where j A j represents the phase slice index of the sending node.C This represents the phase slice index of the receiving node, and M represents the number of random phase slices.
[0010] In one possible implementation, the method further includes: obtaining a second original key of the sending node; determining a second intermediate key of the sending node based on the second original key of the sending node; obtaining a first subkey of the second intermediate key of the relay node; and determining a first subkey of a second target key based on the second intermediate key of the sending node and the first subkey of the second intermediate key of the relay node, wherein the first subkey of the second target key is used for communication between the sending node and the relay node.
[0011] In one possible implementation, determining the second intermediate key of the transmitting node based on the second original key of the transmitting node includes: acquiring phase information between the transmitting node and the relay node and a second measurement result between the transmitting node and the relay node; the second measurement result between the transmitting node and the relay node is the measurement result obtained by interferometric measurement and second phase slice filtering of the transmitting node and the relay node; and determining the second intermediate key of the transmitting node based on the second original key of the transmitting node, the phase information between the transmitting node and the relay node, and the second measurement result between the transmitting node and the relay node.
[0012] In one possible implementation, the phase information between the transmitting node and the relay node satisfies the following condition: in |j A -j B1 +j d When |mod M=0, Φ AB =0; or, in |j A -j B1 +j d When |mod M=M / 2, Φ AB =1; where Φ AB j represents the phase information between the sending node and the relay node. A j represents the phase slice index of the sending node. B1 j represents the index of the first phase slice of the relay node. d To optimize phase compensation in response to environmental noise, M represents the number of random phase slices; the first phase slice index of the relay node is obtained based on the first sub-phase information of the second relay node.
[0013] In one possible implementation, obtaining the second original key of the sending node includes: performing a second phase slice filtering on the random phase of the sending node based on the phase slice index of the sending node and the first phase slice index of the relay node to obtain the second original key of the sending node; the phase slice index of the sending node and the first phase slice index of the relay node satisfy the following formula |j A -jB1 +j d |mod M = 0 or M / 2; where j A j represents the phase slice index of the sending node. B1 j represents the index of the first phase slice of the relay node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices.
[0014] Secondly, a key distribution method is provided, applied to a receiving node, the method comprising: obtaining a first original key of the receiving node; determining a first intermediate key of the receiving node based on the first original key of the receiving node; obtaining a first intermediate key of the sending node; and determining a first target key based on the first intermediate key of the receiving node and the first intermediate key of the sending node, the first target key being used by the sending node to communicate with the receiving node through a relay node.
[0015] In one possible implementation, determining the first intermediate key of the receiving node based on the first original key of the receiving node includes: determining the first intermediate key of the receiving node based on the first original key of the receiving node and the first phase information of the receiving node; the first phase information of the receiving node is the phase information obtained by performing a first phase slice filtering on the random phase of the receiving node.
[0016] In one possible implementation, obtaining the first original key of the receiving node includes: performing a first phase slice filtering on the random phase of the sending node based on the phase slice index of the sending node and the phase slice index of the receiving node to obtain the first original key of the receiving node; the phase slice index of the sending node and the phase slice index of the receiving node satisfy the following formula: |j A |mod M = 0 or M / 2,|j C |mod M = 0 or M / 2; where j A j represents the phase slice index of the sending node. C This represents the phase slice index of the receiving node, and M represents the number of random phase slices.
[0017] In one possible implementation, the method further includes: obtaining a second original key of the receiving node; determining a second intermediate key of the receiving node based on the second original key of the receiving node; obtaining a second subkey of the second intermediate key of the relay node; and determining a second subkey of a second target key based on the second intermediate key of the receiving node and the second subkey of the second intermediate key of the relay node, wherein the second subkey of the second target key is used for communication between the relay node and the receiving node.
[0018] In one possible implementation, determining the second intermediate key of the receiving node based on the second original key of the receiving node includes: acquiring phase information between the relay node and the receiving node and a second measurement result between the relay node and the receiving node; the second measurement result between the relay node and the receiving node is the measurement result obtained by interferometric measurement and second phase slice filtering of the relay node and the receiving node; and determining the second intermediate key of the receiving node based on the second original key of the receiving node, the phase information between the relay node and the receiving node, and the second measurement result between the relay node and the receiving node.
[0019] In one possible implementation, the phase information between the relay node and the receiving node satisfies the following condition: in |j B2 -j C +j d When |mod M=0, Φ BC =0; or, in |j B2 -j C +j d When |mod M=M / 2, Φ BC =1; where Φ BC j represents the phase information between the relay node and the receiving node. B2 j represents the second phase slice index of the relay node. C j represents the phase slice index of the receiving node. d To optimize the phase compensation for environmental noise, M represents the number of random phase slices; the second phase slice index of the relay node is obtained based on the second sub-phase information of the second relay node.
[0020] In one possible implementation, obtaining the second original key of the receiving node includes: performing a second phase slice filtering on the random phase of the receiving node based on the second phase slice index of the relay node and the phase slice index of the receiving node to obtain the second original key of the receiving node; the second phase slice index of the relay node and the phase slice index of the receiving node satisfy the following formula: |j B2 -j C +j d |mod M = 0 or M / 2; where j B2 j represents the second phase slice index of the relay node. C j represents the phase slice index of the receiving node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices.
[0021] Thirdly, a key distribution method is provided, applied to relay nodes. The method includes: performing a first phase slice filtering on the random phases of the relay node based on either the first phase slice index or the second phase slice index of the relay node, to obtain the first subkey of the first original key and the second subkey of the first original key of the relay node; the first phase slice index and the second phase slice index of the relay node satisfy the following formula: |j B1 |mod M = 0 or M / 2,|j B2 |mod M = 0 or M / 2; where j B1 j represents the index of the first phase slice of the relay node. B2 The second phase slice index of the relay node is represented, and M represents the number of random phase slices. Based on the first subkey of the first original key of the relay node and the second subkey of the first original key of the relay node, the first original key of the relay node is generated. The first original key of the relay node is published, and the location information of the first subkey of the first original key of the relay node is sent to the sending node, and the location information of the second subkey of the first original key of the relay node is sent to the receiving node. The first original key of the relay node is used by the sending node to determine the first intermediate key of the sending node, and then to determine the first target key based on the first intermediate key of the sending node. The first target key is used by the sending node to communicate with the receiving node through the relay node.
[0022] In one possible implementation, the method further includes: performing a first phase slice screening on the random phase of the relay node to obtain the phase information of the first relay node; publishing the phase information of the first relay node, which is used by the sending node to determine the first intermediate key of the sending node.
[0023] In one possible implementation, a first phase slice filtering is performed on the random phase of the relay node to obtain the phase information of the first relay node. This includes: performing a first phase slice filtering on the random phase of the relay node to obtain the first sub-phase information and the second sub-phase information of the first relay node; the values of the first sub-phase information and the second sub-phase information of the first relay node satisfy the following condition: in |j Bi When |mod M=0, Φ1 Bi =0; or, in |j Bi When |mod M=M / 2, Φ1 Bi =1; where i∈{1,2}, j B1 j represents the index of the first phase slice of the relay node. B2 Indicates the second phase slice index of the relay node, Φ1 B1 This represents the first sub-phase information of the first relay node, Φ1 B2This represents the second sub-phase information of the first relay node; based on the first sub-phase information and the second sub-phase information of the first relay node, the phase information of the first relay node is determined.
[0024] In one possible implementation, the method further includes: obtaining a first subkey of the second intermediate key of the relay node and a second subkey of the second intermediate key of the relay node; determining the first subkey of the second intermediate key of the relay node as the first subkey of the second target key, wherein the first subkey of the second target key is used for communication between the sending node and the relay node; and determining the second subkey of the second intermediate key of the relay node as the second subkey of the second target key, wherein the second subkey of the second target key is used for communication between the relay node and the receiving node.
[0025] In one possible implementation, obtaining the first subkey of the second intermediate key of the relay node and the second subkey of the second intermediate key of the relay node includes: obtaining the first subkey of the second original key of the relay node and the second subkey of the second original key of the relay node; determining the first subkey of the second original key of the relay node as the first subkey of the second intermediate key of the relay node; and determining the second subkey of the second original key of the relay node as the second subkey of the second intermediate key of the relay node.
[0026] In one possible implementation, obtaining the first subkey of the second original key of the relay node and the second subkey of the second original key of the relay node includes: performing a second phase slice filtering on the random phase of the relay node based on the phase slice index of the sending node and the first phase slice index of the relay node to obtain the first subkey of the second original key of the relay node; the phase slice index of the sending node and the first phase slice index of the relay node satisfy the following formula: |j A -j B1 +j d |mod M = 0 or M / 2; where j A j represents the phase slice index of the sending node. B1 j represents the index of the first phase slice of the relay node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices. Based on the second phase slice index of the relay node and the phase slice index of the receiving node, a second phase slice filtering is performed on the random phase of the relay node to obtain the second subkey of the second original key of the relay node. The second phase slice index of the relay node and the phase slice index of the receiving node satisfy the following formula: |j B2 -j C +j d |mod M = 0 or M / 2; where j B2 j represents the second phase slice index of the relay node.C This represents the phase slice index of the receiving node.
[0027] In one possible implementation, the method further includes: performing a second phase slice filtering on the random phase of the relay node to obtain the first sub-phase information of the second relay node and the second sub-phase information of the second relay node; publishing the first sub-phase information of the second relay node and the second sub-phase information of the second relay node; using the first sub-phase information of the second relay node to determine the second intermediate key of the sending node; and using the second sub-phase information of the second relay node to determine the second intermediate key of the receiving node.
[0028] Fourthly, a key distribution device is provided, applied to a sending node. The device includes a transmission unit and a processing unit. The transmission unit is used to acquire a first original key of the sending node and a first original key of a relay node. The first original key of the relay node is generated based on a first subkey and a second subkey of the first original key of the relay node. The first subkey and the second subkey of the first original key of the relay node are keys obtained by performing a first phase slice filtering on the random phase of the relay node based on the first phase slice index and the second phase slice index of the relay node. The first phase slice index and the second phase slice index of the relay node satisfy the following formula: |jB1|mod M=0 or M / 2, |jB2|mod M = 0 or M / 2; where jB1 represents the first phase slice index of the relay node, jB2 represents the second phase slice index of the relay node, and M represents the number of random phase slices; the processing unit is used to determine the first intermediate key of the sending node based on the first original key of the sending node and the first original key of the relay node; the transmission unit is also used to obtain the first intermediate key of the receiving node; the processing unit is also used to determine the first target key based on the first intermediate key of the sending node and the first intermediate key of the receiving node, the first target key being used by the sending node to communicate with the receiving node through the relay node.
[0029] In one possible implementation, the transmission unit is configured to acquire phase information of a first transmitting node, phase information of a first relay node, a first measurement result between the transmitting node and the relay node, and a first measurement result between the relay node and the receiving node; the phase information of the first transmitting node is phase information obtained by performing a first phase slice filtering on the random phase of the transmitting node; the phase information of the first relay node is phase information obtained by performing a first phase slice filtering on the random phase of the relay node; the first measurement result between the transmitting node and the relay node is the measurement result obtained by performing interferometric measurement and the first phase slice filtering on the transmitting node and the relay node; the first measurement result between the relay node and the receiving node is the measurement result obtained by performing interferometric measurement and the first phase slice filtering on the relay node and the receiving node; the processing unit is further configured to determine a first intermediate key of the transmitting node based on the first original key of the transmitting node, the first original key of the relay node, the phase information of the first transmitting node, the phase information of the first relay node, the first measurement result between the transmitting node and the relay node, and the first measurement result between the relay node and the receiving node.
[0030] In one possible implementation, the processing unit is further configured to perform a first phase slice filtering on the random phase of the sending node based on the phase slice index of the sending node and the phase slice index of the receiving node, to obtain the first original key of the sending node; the phase slice index of the sending node and the phase slice index of the receiving node satisfy the following formula: |j A |mod M = 0 or M / 2,|j C |mod M = 0 or M / 2; where j A j represents the phase slice index of the sending node. C This represents the phase slice index of the receiving node, and M represents the number of random phase slices.
[0031] In one possible implementation, the first original key of the relay node is generated based on a first subkey and a second subkey of the first original key of the relay node; the first and second subkeys of the first original key of the relay node are keys obtained by performing a first phase slice filtering on the random phase of the sending node based on the first and second phase slice indices of the relay node; the first and second phase slice indices of the relay node satisfy the following formula: |j B1 |mod M = 0 or M / 2,|j B2 |mod M = 0 or M / 2; where j B1 j represents the index of the first phase slice of the relay node. B2 This represents the index of the second phase slice of the relay node, and M represents the number of random phase slices.
[0032] In one possible implementation, the transmission unit is further configured to acquire the second original key of the sending node; the processing unit is further configured to determine the second intermediate key of the sending node based on the second original key of the sending node; the transmission unit is further configured to acquire the first sub-key of the second intermediate key of the relay node; the processing unit is further configured to determine the first sub-key of the second target key based on the second intermediate key of the sending node and the first sub-key of the second intermediate key of the relay node, wherein the first sub-key of the second target key is used for communication between the sending node and the relay node.
[0033] In one possible implementation, the transmission unit is further configured to acquire phase information between the transmitting node and the relay node, as well as a second measurement result between the transmitting node and the relay node; the second measurement result between the transmitting node and the relay node is a measurement result obtained by interferometric measurement and second phase slice filtering of the transmitting node and the relay node; the processing unit is further configured to determine a second intermediate key of the transmitting node based on the second original key of the transmitting node, the phase information between the transmitting node and the relay node, and the second measurement result between the transmitting node and the relay node.
[0034] In one possible implementation, the phase information between the transmitting node and the relay node satisfies the following condition: in |j A -j B1 +j d When |mod M=0, Φ AB =0; or, in |j A -j B1 +j d When |mod M=M / 2, Φ AB =1; where Φ AB j represents the phase information between the sending node and the relay node. A j represents the phase slice index of the sending node. B1 j represents the index of the first phase slice of the relay node. d To optimize phase compensation in response to environmental noise, M represents the number of random phase slices; the first phase slice index of the relay node is obtained based on the first sub-phase information of the second relay node.
[0035] In one possible implementation, the processing unit is further configured to perform a second phase slice filtering on the random phase of the sending node based on the phase slice index of the sending node and the first phase slice index of the relay node, to obtain the second original key of the sending node; the phase slice index of the sending node and the first phase slice index of the relay node satisfy the following formula |j A -j B1 +j d|mod M = 0 or M / 2; where j A j represents the phase slice index of the sending node. B1 j represents the index of the first phase slice of the relay node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices.
[0036] Fifthly, a key distribution apparatus is provided for use at a receiving node. The apparatus includes a transmission unit and a processing unit. The transmission unit is configured to acquire a first original key of the receiving node. The processing unit is configured to determine a first intermediate key of the receiving node based on the first original key of the receiving node. The transmission unit is further configured to acquire a first intermediate key of a sending node. The processing unit is further configured to determine a first target key based on the first intermediate key of the receiving node and the first intermediate key of the sending node. The first target key is used by the sending node to communicate with the receiving node through a relay node.
[0037] In one possible implementation, the processing unit is further configured to receive the first original key of the receiving node and the first receiving node phase information, and determine the first intermediate key of the receiving node; the first receiving node phase information is the phase information obtained by performing a first phase slice filtering on the random phase of the receiving node.
[0038] In one possible implementation, the processing unit is further configured to perform a first phase slice filtering on the random phase of the sending node based on the phase slice index of the sending node and the phase slice index of the receiving node, to obtain the first original key of the receiving node; the phase slice index of the sending node and the phase slice index of the receiving node satisfy the following formula: |j A |mod M = 0 or M / 2,|j C |mod M = 0 or M / 2; where j A j represents the phase slice index of the sending node. C This represents the phase slice index of the receiving node, and M represents the number of random phase slices.
[0039] In one possible implementation, the transmission unit is further configured to acquire the second original key of the receiving node; the processing unit is further configured to determine the second intermediate key of the receiving node based on the second original key of the receiving node; the transmission unit is further configured to acquire the second sub-key of the second intermediate key of the relay node; the processing unit is further configured to determine the second sub-key of the second target key based on the second intermediate key of the receiving node and the second sub-key of the second intermediate key of the relay node, wherein the second sub-key of the second target key is used for communication between the relay node and the receiving node.
[0040] In one possible implementation, the transmission unit is further configured to acquire phase information between the relay node and the receiving node, as well as a second measurement result between the relay node and the receiving node; the second measurement result between the relay node and the receiving node is a measurement result obtained by interferometric measurement and second phase slice filtering of the relay node and the receiving node; the processing unit is further configured to determine a second intermediate key of the receiving node based on the second original key of the receiving node, the phase information between the relay node and the receiving node, and the second measurement result between the relay node and the receiving node.
[0041] In one possible implementation, the phase information between the relay node and the receiving node satisfies the following condition: in |j B2 -j C +j d When |mod M=0, Φ BC =0; or, in |j B2 -j C +j d When |mod M=M / 2, Φ BC =1; where Φ BC j represents the phase information between the relay node and the receiving node. B2 j represents the second phase slice index of the relay node. C j represents the phase slice index of the receiving node. d To optimize the phase compensation for environmental noise, M represents the number of random phase slices; the second phase slice index of the relay node is obtained based on the second sub-phase information of the second relay node.
[0042] In one possible implementation, the processing unit is further configured to perform a second phase slice filtering on the random phase of the receiving node based on the second phase slice index of the relay node and the phase slice index of the receiving node, to obtain the second original key of the receiving node; the second phase slice index of the relay node and the phase slice index of the receiving node satisfy the following formula: |j B2 -j C +j d |mod M = 0 or M / 2; where j B2 j represents the second phase slice index of the relay node. C j represents the phase slice index of the receiving node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices.
[0043] Sixthly, a key distribution apparatus is provided, applied to a relay node. The apparatus includes: a transmission unit and a processing unit; the processing unit is used to perform a first phase slice filtering on the random phase of the relay node based on a first phase slice index or a second phase slice index of the relay node, to obtain a first subkey of the first original key of the relay node and a second subkey of the first original key of the relay node; the first phase slice index and the second phase slice index of the relay node satisfy the following formula: |j B1 |mod M = 0 or M / 2,|j B2 |mod M = 0 or M / 2; where j B1 j represents the index of the first phase slice of the relay node. B2 The second phase slice index of the relay node is represented by M, and the number of random phase slices is represented by M. The processing unit is used to generate the first original key of the relay node based on the first subkey of the first original key of the relay node and the second subkey of the first original key of the relay node. The processing unit is used to publish the first original key of the relay node, send the location information of the first subkey of the first original key of the relay node to the sending node, and send the location information of the second subkey of the first original key of the relay node to the receiving node. The first original key of the relay node is used by the sending node to determine the first intermediate key of the sending node, and then determine the first target key based on the first intermediate key of the sending node. The first target key is used by the sending node to communicate with the receiving node through the relay node.
[0044] In one possible implementation, the processing unit is further configured to perform a first phase slice filtering on the random phase of the relay node to obtain the phase information of the first relay node; the processing unit is further configured to publish the phase information of the first relay node, which is used by the sending node to determine the first intermediate key of the sending node.
[0045] In one possible implementation, the processing unit is further configured to perform a first phase slice filtering on the random phase of the relay node to obtain the first sub-phase information and the second sub-phase information of the first relay node; the values of the first sub-phase information and the second sub-phase information of the first relay node satisfy the following condition: in |j Bi When |mod M=0, Φ1 Bi =0; or, in |j Bi When |mod M=M / 2, Φ1 Bi =1; where i∈{1,2}, j B1 j represents the index of the first phase slice of the relay node. B2 Indicates the second phase slice index of the relay node, Φ1 B1 This represents the first sub-phase information of the first relay node, Φ1B2 The processing unit is further configured to determine the phase information of the first relay node based on the first sub-phase information and the second sub-phase information of the first relay node.
[0046] In one possible implementation, the transmission unit is further configured to acquire the first subkey of the second intermediate key of the relay node and the second subkey of the second intermediate key of the relay node; the processing unit is further configured to determine the first subkey of the second intermediate key of the relay node as the first subkey of the second target key, and the first subkey of the second target key is used for communication between the sending node and the relay node; the processing unit is further configured to determine the second subkey of the second intermediate key of the relay node as the second subkey of the second target key, and the second subkey of the second target key is used for communication between the relay node and the receiving node.
[0047] In one possible implementation, the transmission unit is further configured to acquire the first subkey of the second original key of the relay node and the second subkey of the second original key of the relay node; the processing unit is further configured to determine the first subkey of the second original key of the relay node as the first subkey of the second intermediate key of the relay node; the processing unit is further configured to determine the second subkey of the second original key of the relay node as the second subkey of the second intermediate key of the relay node.
[0048] In one possible implementation, the processing unit is further configured to perform a second phase slice filtering on the random phase of the relay node based on the phase slice index of the transmitting node and the first phase slice index of the relay node, to obtain the first subkey of the second original key of the relay node; the phase slice index of the transmitting node and the first phase slice index of the relay node satisfy the following formula: |j A -j B1 +j d |mod M = 0 or M / 2; where j A j represents the phase slice index of the sending node. B1 j represents the index of the first phase slice of the relay node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices. The processing unit is also used to perform a second phase slice filtering on the random phase of the relay node based on the second phase slice index of the relay node and the phase slice index of the receiving node, obtaining the second subkey of the second original key of the relay node. The second phase slice index of the relay node and the phase slice index of the receiving node satisfy the following formula: |j B2 -j C +j d |mod M = 0 or M / 2; where j B2 j represents the second phase slice index of the relay node. CThis represents the phase slice index of the receiving node.
[0049] In one possible implementation, the processing unit is further configured to perform a second phase slice filtering on the random phase of the relay node to obtain the first sub-phase information of the second relay node and the second sub-phase information of the second relay node; the processing unit is further configured to publish the first sub-phase information of the second relay node and the second sub-phase information of the second relay node; the first sub-phase information of the second relay node is used by the sending node to determine the second intermediate key of the sending node; the second sub-phase information of the second relay node is used by the receiving node to determine the second intermediate key of the receiving node.
[0050] A seventh aspect is an electronic device, comprising: a processor and a memory; wherein the memory is used to store one or more programs, the one or more programs including computer-executable instructions, and when the electronic device is running, the processor executes the computer-executable instructions stored in the memory to cause the electronic device to perform a key distribution method as described in the first aspect.
[0051] Eighthly, a computer-readable storage medium is provided for storing one or more programs, the one or more programs including instructions that, when executed by a computer, cause the computer to perform a key distribution method as described in the first aspect.
[0052] In a ninth aspect, a computer program product is provided, wherein when computer instructions are executed on an electronic device, the electronic device performs a key distribution method as described in the first aspect. Attached Figure Description
[0053] Figure 1 is a schematic diagram of a trusted relay process based on a QKD network provided in an embodiment of this application;
[0054] Figure 2 is a schematic diagram of a trusted relay process in a quantum communication network based on the QKD protocol provided in an embodiment of this application;
[0055] Figure 3 is a schematic diagram of a quantum communication network based on TF-QKD provided in an embodiment of this application;
[0056] Figure 4 is a schematic diagram of a trusted relay + untrusted relay process in a quantum communication network based on the TF-QKD protocol provided in an embodiment of this application;
[0057] Figure 5 is a schematic diagram of the structure of a key distribution system provided in an embodiment of this application;
[0058] Figure 6 is a schematic flowchart of a key distribution method provided in an embodiment of this application;
[0059] Figure 7 is a schematic flowchart of a key distribution method provided in an embodiment of this application;
[0060] Figure 8 is a schematic flowchart of a key distribution method provided in an embodiment of this application;
[0061] Figure 9 is a schematic flowchart of a key distribution method provided in an embodiment of this application;
[0062] Figure 10 is a schematic flowchart of a key distribution method provided in an embodiment of this application;
[0063] Figure 11 is a schematic flowchart of a key distribution method provided in an embodiment of this application;
[0064] Figure 12 is a schematic flowchart of a key distribution method provided in an embodiment of this application;
[0065] Figure 13 is a flowchart illustrating a key distribution method provided in an embodiment of this application.
[0066] Figure 14 is a schematic flowchart of a key distribution method provided in an embodiment of this application;
[0067] Figure 15 is a schematic flowchart of a key distribution method provided in an embodiment of this application;
[0068] Figure 16 is a schematic flowchart of a key distribution method provided in an embodiment of this application;
[0069] Figure 17 is a schematic flowchart of a key distribution method provided in an embodiment of this application.
[0070] Figure 18 is a flowchart illustrating a key distribution method provided in an embodiment of this application.
[0071] Figure 19 is a schematic flowchart of a key distribution method provided in an embodiment of this application.
[0072] Figure 20 is a schematic flowchart of a key distribution method provided in an embodiment of this application.
[0073] Figure 21 is a schematic flowchart of a key distribution method provided in an embodiment of this application.
[0074] Figure 22 is a schematic flowchart of a key distribution method provided in an embodiment of this application.
[0075] Figure 23 is a schematic flowchart of a key distribution method provided in an embodiment of this application.
[0076] Figure 24 is a flowchart illustrating a key distribution method provided in an embodiment of this application.
[0077] Figure 25 is a schematic diagram of an untrusted relay process in a quantum communication network based on the TF-QKD protocol provided in an embodiment of this application;
[0078] Figure 26 is a schematic diagram of the structure of a key distribution device provided in an embodiment of this application;
[0079] Figure 27 is a schematic diagram of the structure of a key distribution device provided in an embodiment of this application;
[0080] Figure 28 is a schematic diagram of the structure of a key distribution device provided in an embodiment of this application;
[0081] Figure 29 is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0082] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0083] In the description of this application, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. "And / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Furthermore, "at least one" and "multiple" refer to two or more. The terms "first," "second," etc., do not limit the quantity or order of execution, and "first," "second," etc., do not necessarily imply differences.
[0084] 5G (Fifth Generation Mobile Communication Technology) quantum communication is a communication method based on the principles of quantum mechanics, guaranteeing unconditional security during communication. As quantum information technology gradually rises to the macro-strategic level, China has established quantum communication networks, including important trunk lines and macro-wide-area quantum secure communication backbone networks. However, quantum communication is essentially a point-to-point connection, and quantum signals cannot be amplified; therefore, transmission loss between points is often limited to below 20dB. To extend the transmission distance or expand to multi-user quantum communication networks, relay nodes are needed to connect the sending and receiving nodes.
[0085] For example, a chain relay scheme can be used for key distribution, which connects several short-distance point-to-point quantum key distribution links into a long-distance quantum secure communication link using relay nodes. Keys are generated and shared between different intervals using quantum key distribution devices, and secure key transfer between relay nodes is achieved using segment-by-segment encryption (e.g., one-time pad), ultimately completing the secure distribution of quantum keys.
[0086] However, the aforementioned trusted relay process is highly dependent on the security and reliability of the relay nodes. The leakage of the key in any relay node will lead to the leakage of the final session key, and the security of quantum communication cannot be guaranteed.
[0087] Furthermore, while trusted relays enable interconnection between multiple points, their use requires the relay nodes to be trusted by default. As the number of trusted relay nodes increases, the overall security of the network decreases. Quantum relays, as untrusted relays, utilize quantum entanglement and storage technology to make the relay process unconditionally secure; however, research on quantum repeaters has not yet reached practical application and remains far from being implemented.
[0088] Quantum key distribution protocols based on third-party measurements, due to their measurement device independence, ensure that the third-party measurement end (also called the probe or measurement end) cannot obtain the key generated by the protocol when connecting two communicating users. Therefore, using the third-party measurement end as an effective relay node in untrusted relay schemes in related technologies can reduce the proportion of trusted relay nodes in the quantum key distribution network; that is, the third-party measurement end can act as an untrusted relay. However, quantum key distribution networks based on third-party measurement protocols still require both trusted and untrusted relays to be built, and the security vulnerabilities introduced by trusted relays cannot be ruled out. A trusted relay node, or reliable relay node, refers to a relay node with high security and reliability.
[0089] The following section, with reference to Figure 1, introduces several traditional trusted relay processes in a trusted relay-based quantum key distribution (QKD) network:
[0090] (1) Chain Relay Scheme: The earliest key relay algorithm adopted a very intuitive approach, which utilizes trusted relay nodes to connect several short-distance point-to-point quantum key distribution links into a long-distance quantum secure communication link. Keys are generated and shared between different intervals using quantum key distribution devices, and segment-by-segment encryption is used to achieve secure key transfer between relay points, ultimately completing the secure distribution of quantum keys. The specific process is as follows:
[0091] 1. The sender A first uses the key shared with relay node B.AB Alternatively, sender A first uses a quantum random number generator to generate the key Key. RN As K1. Then use the key shared with relay node B. A B Perform an XOR operation on K1, i.e., Key AB ⊕K1 and XOR the result with the key, then send it to relay node B. Relay node B uses the key... AB Performing an XOR operation on the result yields K1, which is the Key. AB ⊕Key AB ⊕K1=K1.
[0092] 2. Relay node B uses the same key as relay node C. BC Perform an XOR operation on K1, i.e., Key BC ⊕K1 and XOR the result with the key, then send it to relay node C. Relay node C uses the key... BC Performing an XOR operation on the result yields K1, which is the Key. BC ⊕Key BC ⊕K1=K1.
[0093] 3. Relay node C uses the same key as receiver D. CD Perform an XOR operation on K1, i.e., Key CD ⊕K1 and XOR the result with the key, then send it to receiver D. Receiver D uses the key... CD Performing an XOR operation on the result yields K1, which is the Key. CD ⊕Key CD ⊕K1=K1.
[0094] 4. At this point, the sending end A has transmitted the key K1 to the receiving end D through relay nodes B and C.
[0095] (2) XOR Storage Relay Scheme: In this scheme, the trusted relay node XORs the shared key between its two adjacent upstream and downstream relay nodes in the key relay route, deletes the shared key, and only saves the XOR result. The specific process is as follows:
[0096] 1. Relay node B shares its key with sender A. AB Key shared with relay node C BC Perform an XOR operation, i.e., Key AB ⊕Key BC and Key AB With Key BC Delete. Upon receiving a key relay processing request, XOR the result Key. AB ⊕Key BCSend to receiver D.
[0097] 2. Relay node C shares its key with relay node B. BC Key shared with receiver D CD Perform an XOR operation, i.e., Key BC ⊕Key CD and Key BC With Key CD Delete. Upon receiving a key relay processing request, XOR the result Key. BC ⊕Key CD Send to receiver D.
[0098] 3. Receiver D uses the same key as relay node C. CD XOR the received XOR result, i.e., calculate the Key. AB ⊕Key BC ⊕Key BC ⊕Key CD ⊕Key CD Get the session key AB .
[0099] 4. Finally, sender A transmits the key to receiver D through relay nodes B and C. AB (i.e., K1 in the chain relay scheme).
[0100] (3) Centralized Relay Scheduling Scheme: This scheme employs a centralized key relay. The shared keys between adjacent relay nodes of a trusted relay node are XORed and uploaded to the centralized key relay. The previously shared keys are then deleted. The centralized key relay centrally schedules the XORed keys, completing the key relay process. The specific process is as follows:
[0101] 1. Relay node B shares its key with sender A. AB Key shared with relay node C BC Perform XOR operation on Key AB ⊕Key BC and Key AB With Key BC Delete. Upon receiving a key relay processing request, the XORed result is sent to the centralized key relay.
[0102] 2. Relay node C shares its key with relay node B. BC Key shared with receiver D CD Perform XOR operation on Key BC ⊕Key CD and Key BCWith Key CD Delete. Upon receiving a key relay processing request, the XORed result is sent to the centralized key relay.
[0103] 3. The centralized key relay performs an XOR operation on the data reported by each relay node, i.e., calculates the Key. AB ⊕Key CD =Key AB ⊕Key BC ⊕Key BC ⊕Key CD The result of the XOR operation is then sent to the receiving end D.
[0104] 4. Receiver D uses the same key as relay node C. CD XOR the received XOR result, i.e., calculate the Key. AB =Key AB ⊕Key CD ⊕Key CD Get the session key AB .
[0105] 5. Finally, sender A transmits the key Key to receiver D via relay node B, relay node C, and the centralized key relay. AB .
[0106] The trusted relay process of the quantum communication network based on the QKD protocol will be described in more detail below with reference to Figure 2. The specific steps are as follows:
[0107] 1. Preparation: Sender A generates key bits k A Relay node B generates key bits k B1 and k B2 Relay node C generates key bits k C .
[0108] 2. Measurement: Transmitter A exchanges quantum state optical signals with relay node B. Relay node B measures and publishes the results R. AB Receiver C exchanges quantum state optical signals with relay node B, and receiver C measures and publishes the result R. BC .
[0109] 3. Post-processing: Sender A and relay node B perform key filtering, error correction, and privacy amplification. Receiver C and relay node B perform key filtering, error correction, and privacy amplification.
[0110] 4. Obtaining the Key: Sender A and relay node B perform key filtering, error correction, and privacy amplification to obtain the shared key, Key. AB The receiving end C and the relay node B perform key filtering, error correction, and privacy amplification to obtain the shared key Key.BC .
[0111] 5. Relay: Sender A randomly generates K1 and uses the key Key shared with relay node B. AB Perform an XOR operation on K1 to obtain Key. AB ⊕K1. And Key AB K1 is sent to relay node B. Relay node B uses Key... AB For Key AB XORing ⊕K1 yields Key AB ⊕Key AB ⊕K1=K1. Further relay node B uses the key shared with receiver C. BC Perform an XOR operation on K1 to obtain Key. BC ⊕K1. And Key BC K1 is sent to receiver C. Receiver C uses Key... BC For Key BC XORing ⊕K1 yields Key BC ⊕Key BC ⊕K1=K1.
[0112] The aforementioned trusted relay process is highly dependent on the security and reliability of the relay nodes. The leakage of a key in any relay node will lead to the final session key K1 (Key). AB The leakage of ) is a concern. Furthermore, Scheme (III) must also ensure the security and reliability of the centralized key relay.
[0113] In related technologies, a third-party measurement terminal can be used as an effective relay node in an untrusted relay scheme to reduce the proportion of trusted relay nodes in the quantum key distribution network. This is based on a quantum communication network using the Twin-field quantum key distribution (TF-QKD) protocol. Referring to Figure 3, the specific steps of this Twin-field quantum key distribution process and method are as follows:
[0114] 1. Preparation: A first optical signal generated by a first transmitter A is transmitted to the detector via a first channel, and a second optical signal generated by a second transmitter B is transmitted to the detector via a second channel. The first transmitter A and the second transmitter B have optical fields with random phases. The optical fields are determined based on random numbers held by each transmitter. The first and second optical signals include a quantum frame portion used for coding and a reference frame portion not used for coding. The quantum frame portion includes an X basis vector and a Z basis vector representing the original key.
[0115] 2. Measurement: The first and second optical signals are processed by the detection end to obtain the single-photon detection information of the optical signals and the global phase difference of the quantum frame. The global phase difference is then sent to the first transmitter A and the second transmitter B through the certified classical channel.
[0116] 3. Post-processing: Based on the global phase difference and single-photon detection information of the optical signal, the first transmitter A and the second transmitter B respectively perform key filtering, key error correction, and key privacy amplification on their respective random numbers to obtain a secure shared key (i.e., Key). AB ).
[0117] The specific process of the post-processing stage is as follows:
[0118] 1. The first transmitter A and the second transmitter B select successful detection events based on the single-photon detection information from the detector and the global phase difference of the quantum frame, that is, only one of the two detectors (R and L) emits a response.
[0119] 2. If detector R responds, then the second transmitter B (or the first transmitter A) reverses the key bits.
[0120] 3. If the global phase difference of the quantum frame is π, then the second transmitter B (or the first transmitter A) reverses the key bits.
[0121] 4. The first sending end A and the second sending end B perform key error correction and key privacy amplification on the selected keys to obtain a secure shared key (i.e., Key). AB ).
[0122] The following section, with reference to Figure 4, provides a more detailed description of the trusted relay + untrusted relay process in the quantum communication network based on the TF-QKD protocol in Figure 3. The specific steps are as follows:
[0123] 1. Preparation: Network user node A and network user node B act as the sending ends, and randomly generate key bits k. A and k B1 Weakly coherent quantum signal optical pulses (i.e., quantum state optical signals) are randomly generated for each network user node. Network user node B and network user node C act as transmitters, randomly generating key bits k. B2 and k C Quantum state optical signals were randomly prepared for each.
[0124] 2. Measurement: The first untrusted relay acts as a probe to perform interferometric measurements on the quantum state optical signals sent by network user nodes A and B, and publishes the measurement results R. AB Simultaneously, the second untrusted relay, acting as a probe, performs interferometric measurements on the quantum state optical signals sent by network user nodes B and C and publishes the measurement results R. BC .
[0125] 3. Post-processing: Network user nodes A and B perform key filtering, error correction, and privacy amplification. Network user node C and B perform key filtering, error correction, and privacy amplification.
[0126] 4. Obtaining the Key: Network user nodes A and B perform key filtering, error correction, and privacy amplification to obtain the shared key, Key. AB Network user nodes C and B perform key filtering, error correction, and privacy amplification to obtain the shared key Key. BC .
[0127] 5. Relay: Network user node A randomly generates K1, using the key Key shared with network user node B. AB Perform an XOR operation on K1 to obtain Key. AB ⊕K1. And Key AB K1 is sent to network user node B. Network user node B uses Key... AB For Key AB XORing ⊕K1 yields Key AB ⊕Key AB ⊕K1=K1. Further, network user node B uses the key shared with network user node C. BC Perform an XOR operation on K1 to obtain Key. BC ⊕K1. And Key BC K1 is sent to network user node C. Network user node C uses Key... BC For Key BC XORing ⊕K1 yields Key BC ⊕Key BC ⊕K1=K1.
[0128] However, the aforementioned TF-QKD-based quantum communication network still requires the joint construction of trusted and untrusted relays. Although the third-party measurement terminal is considered an untrusted relay, it still cannot solve the security shortcomings brought about by trusted relays in the quantum communication network. That is, B is needed as a trusted relay to realize the key transfer between A and C.
[0129] To address the issue that the security of quantum communication networks inevitably decreases with the increase of relay nodes due to the use of trusted relays in quantum key distribution networks, this application provides a key distribution method. Specifically, it proposes an untrusted relay method for relay node B, which, combined with a third-party measurement protocol, ensures that relay node B does not need to assume the relay nodes are trusted when facilitating key transmission between A and C. That is, relay node B cannot obtain the key transmitted between A and C based on negotiated information or its own information. This solves the security assumption problem of trusted relays in quantum communication networks and avoids the security vulnerabilities caused by the default trustworthiness of relay nodes during the relay process.
[0130] This application provides a key distribution method applicable to key distribution systems. Figure 5 shows a schematic diagram of a key distribution system. As shown in Figure 5, the key distribution system includes a sending node 11, a relay node 12, and a receiving node 13. The sending node 11, relay node 12, and receiving node 13 can be connected via wired or wireless means; this application does not limit the connection in this way.
[0131] The sending node 11 is used to obtain the first original key of the sending node 11 and the first original key of the relay node 12, determine the first intermediate key of the sending node 11 based on the first original key of the sending node 11 and the first original key of the relay node 12, obtain the first intermediate key of the receiving node 13, and determine the first target key based on the first intermediate key of the sending node 11 and the first intermediate key of the receiving node 13, so as to realize secure communication between the sending node 11 and the receiving node 13 through the relay node 12 based on the first target key.
[0132] The receiving node 13 is used to obtain the first original key of the receiving node 13, determine the first intermediate key of the receiving node 13 based on the first original key of the receiving node 13, obtain the first intermediate key of the sending node 11, and determine the first target key based on the first intermediate key of the receiving node 13 and the first intermediate key of the sending node 11, so as to realize secure communication between the sending node 11 and the receiving node 13 through the relay node 12 based on the first target key.
[0133] Relay node 12 is used to obtain and publish the first original key of relay node 12. The first original key of relay node 12 is used by sending node 11 to determine the first intermediate key of sending node 11, and then to determine the first target key based on the first intermediate key of sending node 11, so as to realize secure communication between sending node 11 and receiving node 13 through relay node 12 based on the first target key.
[0134] Sending node 11, relay node 12, and receiving node 13 can be network devices with transceiver capabilities. Examples include: base station equipment, desktop computers (also known as desktop PCs), servers, or server clusters composed of multiple servers. They can also be terminal devices such as mobile phones, tablets, laptops, ultra-mobile personal computers (UMPCs), netbooks, and personal digital assistants (PDAs).
[0135] The key distribution method provided by an embodiment of this application is described below with reference to the accompanying drawings. As shown in Figure 6, the key distribution method provided by this application embodiment is applied to a sending node, and the method includes S201-S205:
[0136] S201. Obtain the first raw key of the sending node.
[0137] The first original key of the relay node is generated based on the first subkey of the first original key of the relay node and the second subkey of the first original key of the relay node. The first subkey of the first original key of the relay node and the second subkey of the first original key of the relay node are keys obtained by performing the first phase slice filtering on the random phase of the relay node based on the first phase slice index and the second phase slice index of the relay node.
[0138] The first phase slice index and the second phase slice index of the relay node satisfy the following formula:
[0139] |j B1 |mod M = 0 or M / 2,|j B2 |mod M = 0 or M / 2.
[0140] Where, j B1 j represents the index of the first phase slice of the relay node. B2 This represents the index of the second phase slice of the relay node, and M represents the number of random phase slices.
[0141] Optionally, the sending node can exchange information with the relay node and perform phase filtering to obtain the sending node's first original key (K1). A ).
[0142] Optionally, the relay node can determine the random phase (φ) of the relay node based on the relay node's first phase slice index and second phase slice index. B1 φ B2 The first phase slice filtering is performed to obtain the first subkey (K1) of the first original key of the relay node. B1 ) and the second subkey (K1) of the first original key of the relay node B2 Furthermore, the relay node can XOR the first subkey of the first original key and the second subkey of the relay node's first original key to generate the relay node's first original key, i.e., K1. B1 ⊕K1 B2 .
[0143] How the sending node and relay node exchange information and perform phase filtering to obtain K1. AThe details can be found in the following embodiment S401, which will not be repeated here.
[0144] S202, Obtain the first raw key of the relay node.
[0145] Optionally, the relay node can publish its first original key, thereby allowing the sending node to obtain the relay node's first original key (K1) from the relay node. B1 ⊕K1 B2 ).
[0146] It should be noted that when a node publishes certain information, it means that all nodes on the transmission link can obtain that information.
[0147] S203. Based on the first original key of the sending node and the first original key of the relay node, determine the first intermediate key of the sending node.
[0148] Optionally, the first intermediate key of the sending node can be the Key calculated by the sending node when the relay node acts as an untrusted relay. AC .
[0149] Regarding how the sending node determines its first intermediate key based on its first original key and the relay node's first original key, please refer to the following embodiment S301, which will not be elaborated here.
[0150] S204. Obtain the first intermediate key of the receiving node.
[0151] Optionally, the receiving node can exchange its first intermediate key with the sending node, thereby allowing the sending node to obtain the receiving node's first intermediate key from the receiving node. The receiving node's first intermediate key can be a Key calculated by the receiving node when the relay node acts as an untrusted relay. AC .
[0152] It should be noted that when a relay node acts as an untrusted relay, it indicates that the relay node is not secure or reliable. In this case, a key shared by the sending and receiving nodes is directly generated. AC Relay nodes cannot perform operations based on key. AC The encrypted data is then decrypted, ensuring it remains secure as it passes through relay nodes. This prevents data leakage that can occur when a relay node acts as an untrusted relay.
[0153] S205. Determine the first target key based on the first intermediate key of the sending node and the first intermediate key of the receiving node.
[0154] The first target key is used by the sending node to communicate with the receiving node through the relay node.
[0155] Optionally, the sending node can determine the first target key based on the first intermediate key of the sending node and the first intermediate key of the receiving node. That is, the sending node and the receiving node can exchange their respective first intermediate keys and perform parameter estimation, error correction and privacy amplification on their own first intermediate keys and the other party's first intermediate keys to generate the final key (i.e., the first target key).
[0156] Furthermore, the sending node can encrypt the original data to be transmitted using the first target key and send the encrypted data to the relay node. The relay node then forwards the encrypted data to the receiving node. The receiving node decrypts the encrypted data using the first target key to obtain the original data.
[0157] In other words, the target key is determined based on the intermediate keys of the sending and receiving nodes. This means that the sending and receiving nodes jointly generate a shared target key, but neither the sending nor the relay nodes share the target key. Therefore, after the sending node encrypts the data transmitted to the receiving node using the target key, the relay node cannot decrypt the data using its own key. Thus, regardless of whether the relay node is secure or reliable, communication security can be ensured.
[0158] The following describes the specific steps for generating the first intermediate key for the sending node.
[0159] In one design, as shown in Figure 7, the key distribution method provided in this embodiment of the application includes steps S203 above, specifically steps S301-S304:
[0160] S301. Obtain the phase information of the first transmitting node.
[0161] The phase information of the first transmitting node is obtained by performing a first phase slice filtering on the random phase of the transmitting node.
[0162] Optionally, the transmitting node can specify the random phase (φ) of the transmitting node. A The first phase slice filtering is performed to obtain the phase information of the first transmitting node (Φ1). A ), where φ A ∈[0, 2π).
[0163] The description of the random phase of the transmitting node can be found in the following embodiment, and will not be repeated here.
[0164] S302. Obtain the phase information of the first relay node from the relay node.
[0165] The phase information of the first relay node is obtained by performing a first phase slice selection on the random phase of the relay node.
[0166] Optionally, the relay node can specify the random phase (φ) of the relay node. B1 and φ B2 The first phase slice screening is performed to obtain the phase information of the first relay node (Φ1). B1 ⊕Φ1 B2 Furthermore, the relay node can publish the phase information of the first relay node (Φ1). B1 ⊕Φ1 B2 Thus, the sending node can obtain the phase information of the first relay node from the relay node.
[0167] S303, Obtain the first measurement result between the sending node and the relay node, and the first measurement result between the relay node and the receiving node.
[0168] The first measurement result between the transmitting node and the relay node is the measurement result obtained by interferometric measurement and the first phase slice screening of the transmitting node and the relay node; the first measurement result between the relay node and the receiving node is the measurement result obtained by interferometric measurement and the first phase slice screening of the relay node and the receiving node.
[0169] Optionally, the first untrusted relay, acting as the detection end, between the transmitting node and the relay node can perform interferometric measurements and a first phase slice screening on the weakly coherent quantum signal light pulses transmitted by the transmitting node and the relay node, to obtain the first measurement result (R1) between the transmitting node and the relay node. AB The sending node then publishes the first measurement result between the sending node and the relay node. The sending node can then obtain the first measurement result between the sending node and the relay node from the first untrusted relay.
[0170] Similarly, the second untrusted relay, acting as the probe end, between the relay node and the receiving node can perform interferometric measurements and the first phase slice screening on the weakly coherent quantum signal light pulses transmitted by the relay node and the receiving node. The first measurement result between the relay node and the receiving node (R1) BC The transmitting node then publishes the first measurement result between the relay node and the receiving node. The transmitting node can then obtain the first measurement result between the relay node and the receiving node from the second untrusted relay.
[0171] S304. Based on the first original key of the sending node, the first original key of the relay node, the phase information of the first sending node, the phase information of the first relay node, the first measurement result between the sending node and the relay node, and the first measurement result between the relay node and the receiving node, determine the first intermediate key of the sending node.
[0172] Optionally, the sending node can perform an XOR operation on the first original key of the sending node, the first original key of the relay node, the first measurement result between the sending node and the relay node, and the first measurement result between the relay node and the receiving node to obtain K1. A ', i.e. K1 A =K1 A ⊕K1 B1 ⊕K1 B2 ⊕R1 AB ⊕R1 BC .
[0173] Furthermore, the sending node can target K1. A The phase information of the first transmitting node and the phase information of the first relay node are XORed to obtain the first intermediate key of the transmitting node, i.e., Key. AC =K1 A '⊕Φ1 A ⊕Φ1 B1 ⊕Φ1 B2 .
[0174] In one possible implementation, the phase information of the first relay node is based on the first sub-phase information (Φ1) of the first relay node. B1 ) and the second sub-phase information of the first relay node (Φ1) B2 The values of the first sub-phase information and the second sub-phase information of the first relay node satisfy the following condition: in |j Bi When |mod M=0, Φ1 Bi =0. Or, in |j Bi When |mod M=M / 2, Φ1 Bi =1.
[0175] Where, i∈{1,2}, j B1 j represents the index of the first phase slice of the relay node. B2 Indicates the second phase slice index of the relay node, Φ1 B1 This represents the first sub-phase information of the first relay node, Φ1 B2 This indicates the second sub-phase information of the first relay node.
[0176] Optionally, the relay node can perform an XOR operation on the first sub-phase information and the second sub-phase information of the first relay node to obtain the phase information of the first relay node, i.e., Φ1. B1 ⊕Φ1 B2 .
[0177] The specific steps for generating the first raw key for the sending node are described below.
[0178] In one design, as shown in Figure 8, the key distribution method provided in this application embodiment includes step S201, specifically step S401:
[0179] S401. Based on the phase slice index of the sending node and the phase slice index of the receiving node, perform the first phase slice filtering on the random phase of the sending node to obtain the first original key of the sending node.
[0180] The phase slice index of the transmitting node and the phase slice index of the receiving node satisfy the following formula: |j A |mod M = 0 or M / 2,|j C |mod M = 0 or M / 2. j A j represents the phase slice index of the sending node. C This represents the phase slice index of the receiving node, and M represents the number of random phase slices.
[0181] Optionally, the sending node and the receiving node can exchange their phase slice indices. Furthermore, the sending node can perform a first phase slice filtering on its random phase based on its own phase slice indices and the receiving node's phase slice indices to obtain its first original key.
[0182] It should be noted that when distributing keys, in addition to distributing the key shared between the sending node and the receiving node, it is also possible to simultaneously distribute the key shared between the sending node and the relay node, as well as the key shared between the relay node and the receiving node. If only the key shared between the sending node and the receiving node is distributed, then data cannot be transmitted between the sending node and the relay node, and data cannot be transmitted between the relay node and the receiving node, resulting in limited data transmission. The specific steps for distributing the key shared between the sending node and the relay node separately are described below.
[0183] In one design, as shown in Figure 9, an embodiment of this application provides a key distribution method, which further includes steps S501-S504:
[0184] S501, Obtain the second original key of the sending node.
[0185] Optionally, the sending node can obtain the sending node's second original key (K2). A ).
[0186] The description of how the sending node obtains the second original key can be found in the following embodiment S701, and will not be repeated here.
[0187] S502. Determine the second intermediate key of the sending node based on the second original key of the sending node.
[0188] Optionally, the sending node can determine its second intermediate key based on its second original key. The second intermediate key can be a key calculated by the sending node when the relay node acts only as a user node. AB .
[0189] S503, Obtain the first subkey of the second intermediate key of the relay node.
[0190] Optionally, the relay node can send the first subkey of the relay node's second intermediate key to the sending node. The sending node can then obtain the first subkey of the relay node's second intermediate key from the relay node. The first subkey of the relay node's second intermediate key can be the Key calculated by the relay node when the relay node acts only as a user node. AB .
[0191] It should be noted that when a relay node acts only as a user node, it means that data needs to be transmitted between the relay node and the sending node. Therefore, a key shared between the sending node and the relay node needs to be distributed to enable data transmission between them.
[0192] S504. Based on the second intermediate key of the sending node and the first subkey of the second intermediate key of the relay node, determine the first subkey of the second target key.
[0193] The first subkey of the second target key is used for communication between the sending node and the relay node.
[0194] Optionally, both the sending node and the relay node can determine the first subkey of the second target key based on the second intermediate key of the sending node and the first subkey of the second intermediate key of the relay node. That is, the sending node and the relay node can exchange their respective second intermediate keys and perform parameter estimation, error correction and privacy amplification on their own second intermediate keys and the other party's second intermediate keys to generate the final key (i.e., the first subkey of the second target key).
[0195] Furthermore, the sending node can encrypt the original data to be transmitted based on the first subkey of the second target key, and then send the encrypted data to the relay node. The relay node decrypts the encrypted data based on the first subkey of the second target key to obtain the original data, thereby enabling data transmission between the relay node and the sending node.
[0196] In one design, as shown in Figure 10, the key distribution method provided in this application embodiment includes steps S502 above, specifically steps S601-S603:
[0197] S601. Obtain the phase information between the sending node and the relay node.
[0198] How does the sending node obtain the phase information (Φ) between the sending node and the relay node? AB The description of the following embodiments can be referred to, and will not be repeated here.
[0199] S602, Obtain the second measurement result between the sending node and the relay node.
[0200] The second measurement result between the transmitting node and the relay node is the measurement result obtained by interferometric measurement of the transmitting node and the relay node and the second phase slice screening.
[0201] Optionally, the first untrusted relay, acting as the detection end, between the transmitting node and the relay node can perform interferometric measurements and a second phase slice screening on the weakly coherent quantum signal light pulses transmitted by the transmitting node and the relay node to obtain a second measurement result (R2) between the transmitting node and the relay node. AB The sending node then publishes the second measurement result between the sending node and the relay node. This allows the sending node to obtain the second measurement result between the sending node and the relay node from the first untrusted relay.
[0202] S603. Based on the second original key of the sending node, the phase information between the sending node and the relay node, and the second measurement result between the sending node and the relay node, determine the second intermediate key of the sending node.
[0203] Optionally, the sending node can perform an XOR operation on its second original key, the phase information between the sending node and the relay node, and the second measurement result between the sending node and the relay node to obtain the sending node's second intermediate key, i.e., Key. AB =K2 A ⊕R2 AB ⊕Φ AB .
[0204] In one possible implementation, the phase information between the transmitting node and the relay node satisfies the following condition: in |j A -j B1 +j d When |mod M=0, Φ AB =0. Or, in |j A -j B1 +j d When |mod M=M / 2, Φ AB =1.
[0205] Where, Φ AB j represents the phase information between the sending node and the relay node.A j represents the phase slice index of the sending node. B1 j represents the index of the first phase slice of the relay node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices.
[0206] The first phase slice index of the relay node is obtained based on the first sub-phase information of the second relay node.
[0207] Optionally, the relay node can publish the first sub-phase information (Φ) of the second relay node. AB Furthermore, the relay node can obtain the first phase slice index of the relay node based on the first sub-phase information of the second relay node.
[0208] It should be noted that j is the index of the random phase φ, and its value can be an integer. Since the phase may differ due to offset or different reference frames, the index numbers may not be identical when the phases corresponding to the phase slices are the same (or when the coverage areas are closest). However, the index numbers are ordered, and there is always a fixed difference j between the two index numbers. d j d It can be determined through random sampling.
[0209] The following describes the specific steps for the sending node to generate its second original key.
[0210] In one design, as shown in Figure 11, the key distribution method provided in this embodiment of the application includes step S501, specifically step S701:
[0211] S701. Based on the phase slice index of the sending node and the first phase slice index of the relay node, a second phase slice filtering is performed on the random phase of the sending node to obtain the second original key of the sending node.
[0212] The phase slice index of the transmitting node and the first phase slice index of the relay node satisfy the following formula: |j A -j B1 +j d |mod M = 0 or M / 2. j A j represents the phase slice index of the sending node. B1 j represents the index of the first phase slice of the relay node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices.
[0213] Optionally, the sending node can perform a second phase slice filtering on the random phase of the sending node based on the phase slice index of the sending node and the first phase slice index of the relay node to obtain the second original key of the sending node.
[0214] In one design, as shown in Figure 12, an embodiment of this application provides a key distribution method applied to a receiving node, the method including S801-S804:
[0215] S801, Obtain the first raw key of the receiving node.
[0216] Optionally, the receiving node can exchange information with the relay node and perform phase filtering to obtain the first original key (K1) of the sending node. C ).
[0217] How the receiving node and relay node exchange information and perform phase filtering to obtain K1. C The details can be found in the following embodiment S1001, which will not be repeated here.
[0218] S802. Determine the first intermediate key of the receiving node based on the first original key of the receiving node.
[0219] Optionally, the first intermediate key of the receiving node can be the Key calculated by the receiving node when the relay node acts as an untrusted relay. AC .
[0220] Regarding how the receiving node determines the first intermediate key based on the receiving node's first original key, please refer to the following embodiment S901, which will not be elaborated here.
[0221] S803, Obtain the first intermediate key of the sending node.
[0222] Optionally, the receiving node can exchange its first intermediate key with the sending node, thereby allowing the receiving node to obtain the sending node's first intermediate key. The sending node's first intermediate key can be the Key calculated by the sending node when the relay node acts as an untrusted relay. AC .
[0223] It should be noted that when a relay node acts as an untrusted relay, it indicates that the relay node is not secure or reliable. In this case, a key shared by the sending and receiving nodes is directly generated. AC Relay nodes cannot perform operations based on key. AC The encrypted data is then decrypted, ensuring it remains secure as it passes through relay nodes. This prevents data leakage that can occur when a relay node acts as an untrusted relay.
[0224] S804. Determine the first target key based on the first intermediate key of the receiving node and the first intermediate key of the sending node.
[0225] The first target key is used by the sending node to communicate with the receiving node through the relay node.
[0226] Optionally, the receiving node can determine the first target key based on the receiving node's first intermediate key and the sending node's first intermediate key. That is, the sending node and the receiving node can exchange their respective first intermediate keys and perform parameter estimation, error correction, and privacy amplification on their own first intermediate keys and the other party's first intermediate keys to generate the final key (i.e., the first target key).
[0227] Furthermore, the sending node can encrypt the original data to be transmitted using the first target key and send the encrypted data to the relay node. The relay node then forwards the encrypted data to the receiving node. The receiving node decrypts the encrypted data using the first target key to obtain the original data.
[0228] In other words, the target key is determined based on the intermediate keys of the sending and receiving nodes. This means that the sending and receiving nodes jointly generate a shared target key, but neither the sending nor the relay nodes share the target key. Therefore, after the sending node encrypts the data transmitted to the receiving node using the target key, the relay node cannot decrypt the data using its own key. Thus, regardless of whether the relay node is secure or reliable, communication security can be ensured.
[0229] The specific steps for generating the first intermediate key for the receiving node are described below.
[0230] In one design, as shown in Figure 13, the key distribution method provided in this embodiment of the application, the method in step S802 above specifically includes S901:
[0231] S901. Based on the first original key of the receiving node and the phase information of the first receiving node, determine the first intermediate key of the receiving node.
[0232] The phase information of the first receiving node is obtained by performing a first phase slice selection on the random phase of the receiving node.
[0233] Optionally, the receiving node can specify the random phase (φ) of the receiving node. C The first phase slice screening is performed to obtain the phase information of the first receiving node (Φ1). C ).
[0234] The receiving node can XOR the first original key and the first phase information of the receiving node to obtain the first intermediate key of the receiving node, i.e., Key. AC =K1 C ⊕Φ1C .
[0235] The following describes the specific steps for generating the first raw key for the receiving node.
[0236] In one design, as shown in Figure 14, the key distribution method provided in this application embodiment includes step S801, specifically step S1001:
[0237] S1001. Based on the phase slice index of the sending node and the phase slice index of the receiving node, perform the first phase slice filtering on the random phase of the sending node to obtain the first original key of the receiving node.
[0238] The phase slice index of the transmitting node and the phase slice index of the receiving node satisfy the following formula: |j A |mod M = 0 or M / 2,|j C |mod M = 0 or M / 2. j A j represents the phase slice index of the sending node. C This represents the phase slice index of the receiving node, and M represents the number of random phase slices.
[0239] Optionally, the sending node and the receiving node can exchange their phase slice indices. Furthermore, the receiving node can perform a first phase slice filtering on its random phase based on the sending node's and receiving node's phase slice indices to obtain the receiving node's first raw key.
[0240] It should be noted that when distributing keys, in addition to distributing the key shared between the sending node and the receiving node, it is also possible to simultaneously distribute the key shared between the sending node and the relay node, as well as the key shared between the relay node and the receiving node. If only the key shared between the sending node and the receiving node is distributed, then data cannot be transmitted between the sending node and the relay node, and data cannot be transmitted between the relay node and the receiving node, resulting in limited data transmission. The specific steps for distributing the key shared between the relay node and the receiving node are described below.
[0241] In one design, as shown in Figure 15, an embodiment of this application provides a key distribution method, which further includes steps S1101-S1104:
[0242] S1101, Obtain the second original key of the receiving node.
[0243] Optionally, the receiving node can obtain the receiving node's second original key (K2). C ).
[0244] The description of how the receiving node obtains the second original key can be found in the following embodiment S1301, and will not be repeated here.
[0245] S1102. Determine the second intermediate key of the receiving node based on the second original key of the receiving node.
[0246] Optionally, the receiving node can determine its second intermediate key based on its second original key. The second intermediate key can be the Key calculated by the receiving node when the relay node acts only as a user node. BC .
[0247] S1103, Obtain the second subkey of the second intermediate key of the relay node.
[0248] Optionally, the relay node can send a second subkey of the relay node's second intermediate key to the receiving node. The receiving node can then obtain the second subkey of the relay node's second intermediate key from the relay node. The second subkey of the relay node's second intermediate key can be a Key calculated by the relay node when the relay node is only acting as a user node. BC .
[0249] It should be noted that when a relay node acts only as a user node, it means that data needs to be transmitted between the relay node and the receiving node. Therefore, a shared key between the relay node and the receiving node needs to be distributed to enable data transmission between them.
[0250] S1104. Based on the second intermediate key of the receiving node and the second sub-key of the second intermediate key of the relay node, determine the second sub-key of the second target key.
[0251] The second subkey of the second target key is used for communication between the relay node and the receiving node.
[0252] Optionally, the receiving node can determine the second subkey of the second target key based on the second intermediate key of the receiving node and the second subkey of the second intermediate key of the relay node. That is, the relay node and the receiving node can exchange their respective second intermediate keys and perform parameter estimation, error correction and privacy amplification on their own second intermediate keys and the other party's second intermediate keys to generate the final key (i.e., the second subkey of the second target key).
[0253] Furthermore, the relay node can encrypt the original data to be transmitted using the second subkey of the second target key, and send the encrypted data to the receiving node. The receiving node decrypts the encrypted data using the second subkey of the second target key to obtain the original data, thus enabling data transmission between the relay node and the receiving node.
[0254] In one design, as shown in Figure 16, the key distribution method provided in this application embodiment includes steps S1102 above, specifically steps S1201-S1203:
[0255] S1201. Obtain the phase information between the relay node and the receiving node.
[0256] How the receiving node obtains the phase information (Φ) between the relay node and the receiving node. BC The description of the following embodiments can be referred to, and will not be repeated here.
[0257] S1202, Obtain the second measurement result between the relay node and the receiving node.
[0258] The second measurement result between the relay node and the receiving node is the measurement result obtained by interferometric measurement of the relay node and the receiving node and the second phase slice screening.
[0259] Optionally, a second untrusted relay, acting as a probe between the relay node and the receiving node, can perform interferometric measurements and a second phase slice screening on the weakly coherent quantum signal light pulses transmitted by the transmitting node and the relay node, obtaining a second measurement result (R2) between the relay node and the receiving node. BC The relay node will then publish the second measurement result between itself and the receiving node. The receiving node can then obtain the second measurement result between itself and the relay node from the second untrusted relay.
[0260] S1203. Based on the second original key of the receiving node, the phase information between the relay node and the receiving node, and the second measurement result between the relay node and the receiving node, determine the second intermediate key of the receiving node.
[0261] Optionally, the receiving node can perform an XOR operation on its second original key, the phase information between the relay node and the receiving node, and the second measurement result between the relay node and the receiving node to obtain the receiving node's second intermediate key, i.e., Key. BC =K2 C ⊕R2 BC ⊕Φ BC .
[0262] In one possible implementation, the phase information between the relay node and the receiving node satisfies the following condition: in |j B2 -j C +j d When |mod M=0, Φ BC =0. Or, in |j B2 -j C +j dWhen |mod M=M / 2, Φ BC =1.
[0263] Where, Φ BC j represents the phase information between the relay node and the receiving node. B2 j represents the second phase slice index of the relay node. C j represents the phase slice index of the receiving node. d To optimize phase compensation in response to environmental noise, M represents the number of random phase slices;
[0264] The second phase slice index of the relay node is obtained based on the second sub-phase information of the second relay node.
[0265] Optionally, the relay node can publish the second sub-phase information (Φ) of the second relay node. BC Then, the receiving node can obtain the second phase slice index of the relay node based on the second sub-phase information of the second relay node.
[0266] The following describes the specific steps for the receiving node to generate its second original key.
[0267] In one design, as shown in Figure 17, the key distribution method provided in this application embodiment includes step S1101, specifically step S1301:
[0268] S1301. Based on the second phase slice index of the relay node and the phase slice index of the receiving node, perform a second phase slice filtering on the random phase of the receiving node to obtain the second original key of the receiving node.
[0269] The second phase slice index of the relay node and the phase slice index of the receiving node satisfy the following formula: |j B2 -j C +j d |mod M = 0 or M / 2. j B2 j represents the second phase slice index of the relay node. C j represents the phase slice index of the receiving node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices.
[0270] Optionally, the receiving node can perform a second phase slice filtering on the random phase of the receiving node based on the second phase slice index of the relay node and the phase slice index of the receiving node to obtain the second original key of the receiving node.
[0271] In one design, as shown in Figure 18, an embodiment of this application provides a key distribution method applied to a relay node, the method including S1401-S1403:
[0272] S1401. Based on the first phase slice index or the second phase slice index of the relay node, perform the first phase slice filtering on the random phase of the relay node to obtain the first subkey of the first original key of the relay node and the second subkey of the first original key of the relay node.
[0273] The first phase slice index and the second phase slice index of the relay node satisfy the following formula: |j B1 |mod M = 0 or M / 2,|j B2 |mod M = 0 or M / 2.
[0274] Where, j B1 j represents the index of the first phase slice of the relay node. B2 This represents the index of the second phase slice of the relay node, and M represents the number of random phase slices.
[0275] S1402. Generate the first original key of the relay node based on the first subkey of the first original key of the relay node and the second subkey of the first original key of the relay node.
[0276] S1403. Publish the first original key of the relay node, and send the location information of the first subkey of the first original key of the relay node to the sending node, and send the location information of the second subkey of the first original key of the relay node to the receiving node.
[0277] The relay node's first original key is used by the sending node to determine the sending node's first intermediate key, and then to determine the first target key based on the sending node's first intermediate key. The first target key is used by the sending node to communicate with the receiving node through the relay node.
[0278] It should be noted that K1 B1 and K1 B2 The location information is consistent. If the relay node sends incorrect location information to either the sending node or the receiving node, the sending node and the receiving node will not be aligned, but the relay node will also be unable to know the final key.
[0279] The description of the first original key for the relay node can be found in the above embodiment, and will not be repeated here.
[0280] In one design, as shown in Figure 19, the key distribution method provided in this embodiment of the application further includes steps S1501-S1502 after step S1403:
[0281] S1501. Perform the first phase slice screening on the random phase of the relay node to obtain the phase information of the first relay node.
[0282] S1502. Announce the phase information of the first relay node.
[0283] The phase information of the first relay node is used by the sending node to determine the first intermediate key of the sending node.
[0284] The description of the phase information of the first relay node can be found in the above embodiment, and will not be repeated here.
[0285] In one design, as shown in Figure 20, the key distribution method provided in this embodiment of the application, the method of step S1501 above specifically includes S1601-S1602:
[0286] S1601. Perform the first phase slice filtering on the random phase of the relay node to obtain the first sub-phase information and the second sub-phase information of the first relay node.
[0287] The values of the first sub-phase information and the second sub-phase information of the first relay node satisfy the following condition: in |j Bi When |mod M=0, Φ1 Bi =0. Or, in |j Bi When |mod M=M / 2, Φ1 Bi =1. i∈{1,2},j B1 j represents the index of the first phase slice of the relay node. B2 Indicates the second phase slice index of the relay node, Φ1 B1 This represents the first sub-phase information of the first relay node, Φ1 B2 This indicates the second sub-phase information of the first relay node.
[0288] S1602. Based on the first sub-phase information and the second sub-phase information of the first relay node, determine the phase information of the first relay node.
[0289] The descriptions of the first sub-phase information and the second sub-phase information of the first relay node can be found in the above embodiments and will not be repeated here.
[0290] In one design, as shown in Figure 21, an embodiment of this application provides a key distribution method, which further includes steps S1801-S1803:
[0291] S1801. Obtain the first subkey of the second intermediate key of the relay node and the second subkey of the second intermediate key of the relay node.
[0292] S1802. Determine the first subkey of the second intermediate key of the relay node as the first subkey of the second target key.
[0293] The first subkey of the second target key is used for communication between the sending node and the relay node.
[0294] S1803. Determine the second subkey of the second intermediate key of the relay node as the second subkey of the second target key.
[0295] The second subkey of the second target key is used for communication between the relay node and the receiving node.
[0296] The explanation of how relay nodes obtain the first subkey of the second target key and the second subkey of the second target key can be found in the above embodiments, and will not be repeated here.
[0297] In one design, as shown in Figure 22, the key distribution method provided in this application embodiment includes steps S1801 above, specifically steps S1901-S1903:
[0298] S1901. Obtain the first subkey of the second original key of the relay node and the second subkey of the second original key of the relay node.
[0299] S1902, Determine the first subkey of the second original key of the relay node as the first subkey of the second intermediate key of the relay node. That is, Key AB =K2 B1 .
[0300] S1903, determine the second subkey of the second original key of the relay node as the second subkey of the second intermediate key of the relay node. That is, Key BC =K2 B2 .
[0301] In one design, as shown in Figure 23, the key distribution method provided in this embodiment of the application, the method in step S1901 above specifically includes S2001-S2002:
[0302] S2001. Based on the phase slice index of the transmitting node and the first phase slice index of the relay node, a second phase slice filtering is performed on the random phase of the relay node to obtain the first subkey of the second original key of the relay node.
[0303] The phase slice index of the transmitting node and the first phase slice index of the relay node satisfy the following formula: |j A -j B1 +j d |mod M = 0 or M / 2. j A j represents the phase slice index of the sending node. B1 j represents the index of the first phase slice of the relay node. dTo optimize phase compensation for environmental noise, M represents the number of random phase slices.
[0304] S2002. Based on the second phase slice index of the relay node and the phase slice index of the receiving node, perform a second phase slice filtering on the random phase of the relay node to obtain the second subkey of the second original key of the relay node.
[0305] The second phase slice index of the relay node and the phase slice index of the receiving node satisfy the following formula: |j B2 -j C +j d |mod M = 0 or M / 2. j B2 j represents the second phase slice index of the relay node. C This represents the phase slice index of the receiving node.
[0306] In one design, as shown in Figure 24, the key distribution method provided in this embodiment of the application further includes steps S2101-S2102 after step S1403:
[0307] S2101. Perform a second phase slice filtering on the random phase of the relay node to obtain the first sub-phase information of the second relay node and the second sub-phase information of the second relay node.
[0308] S2102. Publish the first sub-phase information of the second relay node and the second sub-phase information of the second relay node.
[0309] The first sub-phase information of the second relay node is used by the sending node to determine the second intermediate key of the sending node; the second sub-phase information of the second relay node is used by the receiving node to determine the second intermediate key of the receiving node.
[0310] In some embodiments, as shown in Figure 25, a schematic diagram of an untrusted relay process in a quantum communication network based on the TF-QKD protocol provided in this application is presented (i.e., a complete flowchart of a key distribution method provided in an embodiment of this application). The specific steps are as follows:
[0311] 1. Preparation: Network user node A (i.e., the sending node in this disclosure) and network user node B (i.e., the relay node in this disclosure) act as the sending ends and randomly generate key bits k. A ∈{0,1} and k B1 ∈{0,1}, and different light intensities μ were randomly prepared. A μ B1 And the phase is random φ A ∈[0, 2π), φ B1 Weakly coherent quantum signal light pulse |μ ∈ [0, 2π) A1 / 2 e i(φA+πkA) >、|μ B1 1 / 2 ei(φB1+πkB1)>. Sent via a quantum channel to the first untrusted relay.
[0312] Meanwhile, network user node B and network user node C (i.e., the receiving node in this disclosure) act as the sending end and randomly generate key bits k. B2 ∈{0,1} and k C ∈{0,1}, and different light intensities μ were randomly prepared. B2 μ C And the phase is random φ B2 ∈[0, 2π), φ C Quantum state optical signal |μ ∈ [0, 2π) B2 1 / 2 ei(φB2+πkB2)>、|μ C 1 / 2 e i(φC+πkC) >, transmitted via a quantum channel to a second untrusted relay. Where, μ A μ B1 μ B2 μ C Randomly select from {μ / 2, ν1 / 2, ν2 / 2} with probability P. μ P ν1 P ν2 , (P μ +P ν1 +P ν2 =1). μ / 2 represents the signal state strength, and ν1 / 2 and ν2 / 2 are the decoy state strengths, satisfying μ≥ν1≥ν2.
[0313] 2. Measurement: The first untrusted relay acts as the detector to perform interferometric measurements on the quantum state optical signals sent by A and B, and publishes the measurement results R. AB Simultaneously, the second untrusted relay, acting as a detector, performs interferometric measurements on the quantum state optical signals sent by B and C and publishes the measurement results R. BC The detection is declared successful and recorded when exactly one of the two detectors, L or R, responds. When L responds, R... AB R BC The value of R is 0, and R detector responds when R... AB R BC The value is 1.
[0314] 3. Post-processing: Based on the global phase difference and single-photon detection information of the optical signal, the first transmitter A and the second transmitter B respectively perform key filtering, key error correction, and key privacy amplification on their respective random numbers to obtain a secure shared key (i.e., Key). AB).
[0315] (a) Based on the successful measurement results published by the first untrusted relay, A exchanges optical intensity μ with user node B via the classical authentication channel. A μ B1 Perform key filtering; after key filtering, A and B retain k. A and k B1 As their original key bits. From the successful measurement results published by the second untrusted relay, B exchanges optical intensity μ with C via a classical authentication channel. B2 μ C Perform key filtering; after key filtering, B and C retain k. B2 and k C As their original key bits.
[0316] (b)B with random phase φ B1 φ B2 Phase slice selection is performed. Here, M is the number of random phase slices, and j... B1 For phase slice φ B1 ∈[2πj B1 / M,2π(j B1 The index of +1) / M), j B2 For phase slice φ B2 ∈[2πj B2 / M,2π(j B2 The index of +1) / M). When the index of the phase slice containing the random phase of the weakly coherent quantum signal optical pulse satisfies |j B1 |mod M = 0 or M / 2 and |j B2 | When mod M=0 or M / 2, the key bit k corresponding to the weakly coherent quantum signal B1 k B2 Further filtering to K1 B1 K1 B2 This process is the first phase slice screening; k B1 k B2 The remaining key bits are filtered to K2. B1 K2 B2 This process is the second phase slice screening.
[0317] (c) The first phase slice screening process also includes: after the first phase slice screening in step (b), B publishes K1. B1 ⊕K1 B2 At the same time, send K1 B1 The corresponding location information is sent to A, and K1 is sent. B2 The corresponding location information is given to C. A and C are based on K1. B1 K1 B2The corresponding location information is obtained from the measurement results R of the untrusted relay. AB R BC Further screening revealed R1 AB R1 BC When the phase index j of A A Satisfy condition |j A When |mod M=0 or M / 2, A is derived from key bits k A K1 was further selected from the middle A and send K1 A The corresponding position information is given to C; when the phase index j of C... C Satisfy condition |j C When |mod M=0 or M / 2, C is derived from key bits k C K1 was further selected from the middle C and send K1 C The corresponding location information is given to A.
[0318] (d) The second phase slice filtering process also includes: after the second phase slice filtering in step (b), B sends K2. B1 The corresponding location information is sent to A and K2. B2 The corresponding location information is given to C. A and C are based on K2. B1 K2 B2 The corresponding location information is obtained from the measurement results R of the untrusted relay. AB R BC Further screening revealed R2 AB R2 BC When the phase index j of A and B A j B1 Satisfy condition |j A -j B1 +j d1 When |mod M=0 or M / 2, A is derived from key bits k A K2 was further selected from the middle A j d1 ∈{0, 1, ..., M / 2-1}, used to compensate for the phase deviation between A and B due to different phase reference frames; when the phase index j of B and C is... B2 j C Satisfy condition |j B2 -j C +j d2 When |mod M=0 or M / 2, C is derived from key bits k C The corresponding key bits K2 were further filtered out. C j d2 ∈{0, 1, ..., M / 2-1}, used to compensate for the phase deviation between B and C caused by the different phase reference frames.
[0319] (e) From the results of the first phase slice screening, A uses the information K1 published by B. B1 ⊕K1 B2 Measurement results R1 published by untrusted relay nodes AB R1 BC K1 was calculated A =K1 A ⊕K1 B1 ⊕K1 B2 ⊕R1 AB ⊕R1 BC .
[0320] (f) The first phase slice filtering process is applied when B is an untrusted relay. Here, it is defined that when |j Bi When |mod M=0, the phase slice information Φ1 Bi =0, when |j Bi When |mod M=M / 2, the phase slice information Φ1 Bi =1, i∈{1,2}. Subsequently, B, as an untrusted relay, publishes the first phase slice information Φ1. B1 ⊕Φ1 B2 .
[0321] (g) When B acts as an untrusted relay, it is also defined that when |j A When |mod M=0, the phase slice information Φ1 A =0, when |j C When |mod M=M / 2, the phase slice information Φ1 C =1. A calculates the Key. AC =K1 A '⊕Φ1 A ⊕Φ1 B1 ⊕Φ1 B2 C calculates the Key AC =K1 C ⊕Φ1 C A and C perform parameter estimation, error correction, and privacy amplification on the key bits to generate the final key.
[0322] (h) The second phase slice filtering process is applied when B is only a user node. Here, it is defined that when |j A -j B1 +j d When |mod M=0, the phase slice information Φ AB =0, when |j A -j B1 +j d When |mod M=M / 2, the phase slice information Φ AB =1. When |jB2 -j C +j d When |mod M=0, the phase slice information Φ BC =0, when |j B2 -j C +j d When |mod M=M / 2, the phase slice information Φ BC =1; Subsequently, B released the second phase slice information Φ AB Φ BC Among them, j d Phase optimization compensation to address environmental noise.
[0323] (i) A calculates the Key AB =K2 A ⊕R2 AB ⊕Φ AB B calculates the Key AB =K2 B1 A and B perform parameter estimation, error correction, and privacy amplification on the key bits to generate the final key. B calculates the Key... BC =K2 B2 C calculates the Key BC =K2 C ⊕R2 BC ⊕Φ BC B and C perform parameter estimation, error correction, and privacy amplification on the key bits to generate the final key.
[0324] The foregoing mainly describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, it includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, in conjunction with the units and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0325] This application embodiment can divide a key distribution method into functional modules based on the above method example. For example, each function can be divided into its own functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. Optionally, the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0326] Figure 26 is a schematic diagram of a key distribution device provided in an embodiment of this application. As shown in Figure 26, a key distribution device 270 is used to solve the problem that the trusted relay process is highly dependent on the security and reliability of the relay node, and cannot ensure the security of quantum communication. For example, it is used to execute a key distribution method shown in Figure 6. The key distribution device 270 includes: a transmission unit 2701 and a processing unit 2702; the transmission unit 2701 is used to obtain the first original key of the sending node and the first original key of the relay node; the first original key of the relay node is generated based on the first subkey and the second subkey of the first original key of the relay node; the first subkey and the second subkey of the first original key of the relay node are keys obtained by performing a first phase slice screening on the random phase of the relay node based on the first phase slice index and the second phase slice index of the relay node; the first phase slice index and the second phase slice index of the relay node satisfy the following formula: |j B1 |mod M = 0 or M / 2,|j B2 |mod M = 0 or M / 2; where j B1 j represents the index of the first phase slice of the relay node. B2 The second phase slice index of the relay node is represented by M, and M represents the number of random phase slices. The processing unit 2702 is used to determine the first intermediate key of the sending node based on the first original key of the sending node and the first original key of the relay node. The transmission unit 2701 is also used to obtain the first intermediate key of the receiving node. The processing unit 2702 is also used to determine the first target key based on the first intermediate key of the sending node and the first intermediate key of the receiving node. The first target key is used by the sending node to communicate with the receiving node through the relay node.
[0327] In one possible implementation, the transmission unit 2701 is used to acquire the phase information of the first transmitting node, the phase information of the first relay node, the first measurement result between the transmitting node and the relay node, and the first measurement result between the relay node and the receiving node; the phase information of the first transmitting node is the phase information obtained by performing a first phase slice screening on the random phase of the transmitting node; the phase information of the first relay node is the phase information obtained by performing a first phase slice screening on the random phase of the relay node; the first measurement result between the transmitting node and the relay node is the measurement result obtained by performing interferometric measurement and the first phase slice screening on the transmitting node and the relay node; the first measurement result between the relay node and the receiving node is the measurement result obtained by performing interferometric measurement and the first phase slice screening on the relay node and the receiving node; the processing unit 2702 is further used to determine the first intermediate key of the transmitting node based on the first original key of the transmitting node, the first original key of the relay node, the phase information of the first transmitting node, the phase information of the first relay node, the first measurement result between the transmitting node and the relay node, and the first measurement result between the relay node and the receiving node.
[0328] In one possible implementation, the phase information of the first relay node is obtained based on the first sub-phase information and the second sub-phase information of the first relay node; the values of the first sub-phase information and the second sub-phase information of the first relay node satisfy the following condition: in |j Bi When |mod M=0, Φ1 Bi =0; or, in |j Bi When |mod M=M / 2, Φ1 Bi =1; where i∈{1,2}, j B1 j represents the index of the first phase slice of the relay node. B2 Indicates the second phase slice index of the relay node, Φ1 B1 This represents the first sub-phase information of the first relay node, Φ1 B2 This indicates the second sub-phase information of the first relay node.
[0329] In one possible implementation, processing unit 2702 is further configured to perform a first phase slice filtering on the random phase of the sending node based on the phase slice index of the sending node and the phase slice index of the receiving node, to obtain the first original key of the sending node; the phase slice index of the sending node and the phase slice index of the receiving node satisfy the following formula: |j A |mod M = 0 or M / 2,|j C |mod M = 0 or M / 2; where j A j represents the phase slice index of the sending node. CThis represents the phase slice index of the receiving node, and M represents the number of random phase slices.
[0330] In one possible implementation, the transmission unit 2701 is further configured to obtain the second original key of the sending node; the processing unit 2702 is further configured to determine the second intermediate key of the sending node based on the second original key of the sending node; the transmission unit 2701 is further configured to obtain the first sub-key of the second intermediate key of the relay node; the processing unit 2702 is further configured to determine the first sub-key of the second target key based on the second intermediate key of the sending node and the first sub-key of the second intermediate key of the relay node, wherein the first sub-key of the second target key is used for communication between the sending node and the relay node.
[0331] In one possible implementation, the transmission unit 2701 is further configured to acquire phase information between the transmitting node and the relay node, as well as a second measurement result between the transmitting node and the relay node; the second measurement result between the transmitting node and the relay node is the measurement result obtained by interferometric measurement and second phase slice filtering of the transmitting node and the relay node; the processing unit 2702 is further configured to determine a second intermediate key of the transmitting node based on the second original key of the transmitting node, the phase information between the transmitting node and the relay node, and the second measurement result between the transmitting node and the relay node.
[0332] In one possible implementation, the phase information between the transmitting node and the relay node satisfies the following condition: in |j A -j B1 +j d When |mod M=0, Φ AB =0; or, in |j A -j B1 +j d When |mod M=M / 2, Φ AB =1; where Φ AB j represents the phase information between the sending node and the relay node. A j represents the phase slice index of the sending node. B1 j represents the index of the first phase slice of the relay node. d To optimize phase compensation in response to environmental noise, M represents the number of random phase slices; the first phase slice index of the relay node is obtained based on the first sub-phase information of the second relay node.
[0333] In one possible implementation, processing unit 2702 is further configured to perform a second phase slice filtering on the random phase of the sending node based on the phase slice index of the sending node and the first phase slice index of the relay node, to obtain the second original key of the sending node; the phase slice index of the sending node and the first phase slice index of the relay node satisfy the following formula |j A -j B1 +j d |mod M = 0 or M / 2; where j A j represents the phase slice index of the sending node. B1 j represents the index of the first phase slice of the relay node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices.
[0334] Figure 27 is a schematic diagram of a key distribution device provided in an embodiment of this application. As shown in Figure 27, a key distribution device 280 is used to solve the problem that the trusted relay process is highly dependent on the security and reliability of relay nodes, and cannot ensure the security of quantum communication. For example, it is used to execute a key distribution method shown in Figure 12. The key distribution device 280 includes: a transmission unit 2801 and a processing unit 2802; the transmission unit 2801 is used to obtain a first original key of the receiving node; the processing unit 2802 is used to determine a first intermediate key of the receiving node based on the first original key of the receiving node; the transmission unit 2801 is also used to obtain a first intermediate key of the sending node; the processing unit 2802 is also used to determine a first target key based on the first intermediate key of the receiving node and the first intermediate key of the sending node, the first target key being used by the sending node to communicate with the receiving node through the relay node.
[0335] In one possible implementation, the processing unit 2802 is further configured to receive the first original key of the receiving node and the first receiving node phase information, and determine the first intermediate key of the receiving node; the first receiving node phase information is the phase information obtained by performing a first phase slice filtering on the random phase of the receiving node.
[0336] In one possible implementation, the processing unit 2802 is further configured to perform a first phase slice filtering on the random phase of the sending node based on the phase slice index of the sending node and the phase slice index of the receiving node, to obtain the first original key of the receiving node; the phase slice index of the sending node and the phase slice index of the receiving node satisfy the following formula: |j A |mod M = 0 or M / 2,|j C |mod M = 0 or M / 2; where j A j represents the phase slice index of the sending node. CThis represents the phase slice index of the receiving node, and M represents the number of random phase slices.
[0337] In one possible implementation, the transmission unit 2801 is further configured to acquire the second original key of the receiving node; the processing unit 2802 is further configured to determine the second intermediate key of the receiving node based on the second original key of the receiving node; the transmission unit 2801 is further configured to acquire the second sub-key of the second intermediate key of the relay node; the processing unit 2802 is further configured to determine the second sub-key of the second target key based on the second intermediate key of the receiving node and the second sub-key of the second intermediate key of the relay node, wherein the second sub-key of the second target key is used for communication between the relay node and the receiving node.
[0338] In one possible implementation, the transmission unit 2801 is further configured to acquire phase information between the relay node and the receiving node, as well as a second measurement result between the relay node and the receiving node; the second measurement result between the relay node and the receiving node is the measurement result obtained by interferometric measurement and second phase slice screening of the relay node and the receiving node; the processing unit 2802 is further configured to determine a second intermediate key of the receiving node based on the second original key of the receiving node, the phase information between the relay node and the receiving node, and the second measurement result between the relay node and the receiving node.
[0339] In one possible implementation, the phase information between the relay node and the receiving node satisfies the following condition: in |j B2 -j C +j d When |mod M=0, Φ BC =0; or, in |j B2 -j C +j d When |mod M=M / 2, Φ BC =1; where Φ BC j represents the phase information between the relay node and the receiving node. B2 j represents the second phase slice index of the relay node. C j represents the phase slice index of the receiving node. d To optimize the phase compensation for environmental noise, M represents the number of random phase slices; the second phase slice index of the relay node is obtained based on the second sub-phase information of the second relay node.
[0340] In one possible implementation, the processing unit 2802 is further configured to perform a second phase slice filtering on the random phase of the receiving node based on the second phase slice index of the relay node and the phase slice index of the receiving node, to obtain the second original key of the receiving node; the second phase slice index of the relay node and the phase slice index of the receiving node satisfy the following formula: |j B2 -j C +j d |mod M = 0 or M / 2; where j B2 j represents the second phase slice index of the relay node. C j represents the phase slice index of the receiving node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices.
[0341] Figure 28 is a schematic diagram of a key distribution device provided in an embodiment of this application. As shown in Figure 28, a key distribution device 290 is used to solve the problem that the trusted relay process is highly dependent on the security and reliability of the relay node, and cannot ensure the security of quantum communication. For example, it is used to execute a key distribution method shown in Figure 18. The key distribution device 290 includes: a transmission unit 2901 and a processing unit 2902; the processing unit 2902 is used to perform a first phase slice screening on the random phase of the relay node based on the first phase slice index or the second phase slice index of the relay node, to obtain the first subkey of the first original key of the relay node and the second subkey of the first original key of the relay node; the first phase slice index and the second phase slice index of the relay node satisfy the following formula: |j B1 |mod M = 0 or M / 2,|j B2 |mod M = 0 or M / 2; where j B1 j represents the index of the first phase slice of the relay node. B2 The second phase slice index of the relay node is represented by M, and M represents the number of random phase slices. The processing unit 2902 is used to generate the first original key of the relay node based on the first subkey of the first original key of the relay node and the second subkey of the first original key of the relay node. The processing unit 2902 is used to publish the first original key of the relay node, send the location information of the first subkey of the first original key of the relay node to the sending node, and send the location information of the second subkey of the first original key of the relay node to the receiving node. The first original key of the relay node is used by the sending node to determine the first intermediate key of the sending node, and then determine the first target key based on the first intermediate key of the sending node. The first target key is used by the sending node to communicate with the receiving node through the relay node.
[0342] In one possible implementation, the processing unit 2902 is further configured to perform a first phase slice screening on the random phase of the relay node to obtain the phase information of the first relay node; the processing unit 2902 is further configured to publish the phase information of the first relay node, which is used by the sending node to determine the first intermediate key of the sending node.
[0343] In one possible implementation, the processing unit 2902 is further configured to perform a first phase slice filtering on the random phase of the relay node to obtain the first sub-phase information and the second sub-phase information of the first relay node; the values of the first sub-phase information and the second sub-phase information of the first relay node satisfy the following condition: in |j Bi When |mod M=0, Φ1 Bi =0; or, in |j Bi When |mod M=M / 2, Φ1 Bi =1; where i∈{1,2}, j B1 j represents the index of the first phase slice of the relay node. B2 Indicates the second phase slice index of the relay node, Φ1 B1 This represents the first sub-phase information of the first relay node, Φ1 B2 The processing unit 2902 is further configured to determine the phase information of the first relay node based on the first sub-phase information and the second sub-phase information of the first relay node.
[0344] In one possible implementation, the transmission unit 2901 is further configured to acquire the first subkey of the second intermediate key of the relay node and the second subkey of the second intermediate key of the relay node; the processing unit 2902 is further configured to determine the first subkey of the second intermediate key of the relay node as the first subkey of the second target key, and the first subkey of the second target key is used for communication between the sending node and the relay node; the processing unit 2902 is further configured to determine the second subkey of the second intermediate key of the relay node as the second subkey of the second target key, and the second subkey of the second target key is used for communication between the relay node and the receiving node.
[0345] In one possible implementation, the transmission unit 2901 is further configured to acquire the first subkey of the second original key of the relay node and the second subkey of the second original key of the relay node; the processing unit 2902 is further configured to determine the first subkey of the second original key of the relay node as the first subkey of the second intermediate key of the relay node; the processing unit 2902 is further configured to determine the second subkey of the second original key of the relay node as the second subkey of the second intermediate key of the relay node.
[0346] In one possible implementation, processing unit 2902 is further configured to perform a second phase slice filtering on the random phase of the relay node based on the phase slice index of the transmitting node and the first phase slice index of the relay node, to obtain the first subkey of the second original key of the relay node; the phase slice index of the transmitting node and the first phase slice index of the relay node satisfy the following formula: |j A -j B1 +j d |mod M = 0 or M / 2; where j A j represents the phase slice index of the sending node. B1 j represents the index of the first phase slice of the relay node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices; processing unit 2902 is also used to perform a second phase slice filtering on the random phase of the relay node based on the second phase slice index of the relay node and the phase slice index of the receiving node, to obtain the second subkey of the second original key of the relay node; the second phase slice index of the relay node and the phase slice index of the receiving node satisfy the following formula: |j B2 -j C +j d |mod M = 0 or M / 2; where j B2 j represents the second phase slice index of the relay node. C This represents the phase slice index of the receiving node.
[0347] In one possible implementation, the processing unit 2902 is further configured to perform a second phase slice filtering on the random phase of the relay node to obtain the first sub-phase information of the second relay node and the second sub-phase information of the second relay node; the processing unit 2902 is further configured to publish the first sub-phase information of the second relay node and the second sub-phase information of the second relay node; the first sub-phase information of the second relay node is used by the sending node to determine the second intermediate key of the sending node; the second sub-phase information of the second relay node is used by the receiving node to determine the second intermediate key of the receiving node.
[0348] In the case of implementing the functions of the integrated modules described above in hardware, this application provides a possible structural schematic diagram of the electronic device involved in the above embodiments. As shown in FIG29, an electronic device 300 is used to solve the problem that the trusted relay process is highly dependent on the security and reliability of relay nodes, and cannot ensure the security of quantum communication, for example, for executing a key distribution method shown in FIG6. The electronic device 300 includes a processor 3001, a memory 3002, and a bus 3003. The processor 3001 and the memory 3002 can be connected via the bus 3003.
[0349] Processor 3001 is the control center of the communication device. It can be a single processor or a collective term for multiple processing elements. For example, processor 3001 can be a general-purpose central processing unit (CPU) or other general-purpose processors. Among them, the general-purpose processor can be a microprocessor or any conventional processor.
[0350] As one embodiment, processor 3001 may include one or more CPUs, such as CPU 0 and CPU 1 shown in FIG29.
[0351] The memory 3002 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.
[0352] As one possible implementation, the memory 3002 can exist independently of the processor 3001. The memory 3002 can be connected to the processor 3001 via a bus 3003 and is used to store instructions or program code. When the processor 3001 calls and executes the instructions or program code stored in the memory 3002, it can implement a key distribution method provided in the embodiments of this application.
[0353] In another possible implementation, the memory 3002 can also be integrated with the processor 3001.
[0354] Bus 3003 can be an industry standard architecture (ISA) bus, a peripheral component interconnect (PCI) bus, or an extended industry standard architecture (EISA) bus. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in Figure 29, but this does not indicate that there is only one bus or one type of bus.
[0355] It should be noted that the structure shown in Figure 29 does not constitute a limitation on the electronic device 300. In addition to the components shown in Figure 29, the electronic device 300 may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0356] As an example, referring to Figure 26, the transmission unit 2701 and processing unit 2702 in the key distribution device 270 perform the same functions as the processor 3001 in Figure 29.
[0357] Optionally, as shown in FIG29, the electronic device 300 provided in this application embodiment may further include a communication interface 3004.
[0358] Communication interface 3004 is used to connect with other devices via a communication network. This communication network can be Ethernet, a wireless access network, a wireless local area network (WLAN), etc. Communication interface 3004 may include a receiving unit for receiving data and a transmitting unit for transmitting data.
[0359] In one design, the communication interface in the electronic device provided in this application embodiment can also be integrated into the processor.
[0360] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional units is used as an example. In practical applications, the above functions can be assigned to different functional units as needed, that is, the internal structure of the device can be divided into different functional units to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0361] This application also provides a computer-readable storage medium storing instructions. When a computer executes these instructions, the computer performs each step of the method flow shown in the above-described method embodiments.
[0362] The embodiments of this application provide a computer program product in which, when computer instructions are run on an electronic device, the electronic device executes a key distribution method according to the above method embodiments.
[0363] The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), registers, hard disks, optical fibers, compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing, or any other form of computer-readable storage medium in the art.
[0364] An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside within an application-specific integrated circuit (ASIC).
[0365] In the embodiments of this application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0366] Since the electronic devices, computer-readable storage media, and computer program products in the embodiments of this application can be applied to the above methods, the technical effects they can achieve can also be referred to the above method embodiments. The embodiments of this application will not be repeated here.
[0367] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be covered within the scope of protection of this application.
Claims
1. A key distribution method applied to a sending node, the method comprising: Obtain the first original key of the sending node and the first original key of the relay node; The first original key of the relay node is generated based on the first subkey of the first original key of the relay node and the second subkey of the first original key of the relay node; the first subkey of the first original key of the relay node and the second subkey of the first original key of the relay node are keys obtained by performing a first phase slice filtering on the random phase of the relay node based on the first phase slice index and the second phase slice index of the relay node; The first phase slice index and the second phase slice index of the relay node satisfy the following formula: |j B1 |mod M = 0 or M / 2,|j B2 |mod M = 0 or M / 2; Where, j B1 j represents the first phase slice index of the relay node. B2 The second phase slice index of the relay node is represented, and M represents the number of random phase slices; Based on the first original key of the sending node and the first original key of the relay node, the first intermediate key of the sending node is determined; Obtain the first intermediate key from the receiving node; Based on the first intermediate key of the sending node and the first intermediate key of the receiving node, a first target key is determined. The first target key is used by the sending node to communicate with the receiving node through the relay node.
2. The method according to claim 1, wherein, The step of determining the first intermediate key of the sending node based on the first original key of the sending node and the first original key of the relay node includes: The process involves acquiring phase information of a first transmitting node, phase information of a first relay node, a first measurement result between the transmitting node and the relay node, and a first measurement result between the relay node and the receiving node. The first transmitting node phase information is obtained by performing a first phase slice filtering on a random phase of the transmitting node. The first relay node phase information is obtained by performing a first phase slice filtering on a random phase of the relay node. The first measurement result between the transmitting node and the relay node is obtained by performing interferometric measurements and the first phase slice filtering on the transmitting node and the relay node. The first measurement result between the relay node and the receiving node is obtained by performing interferometric measurements and the first phase slice filtering on the relay node and the receiving node. Based on the first original key of the sending node, the first original key of the relay node, the phase information of the first sending node, the phase information of the first relay node, the first measurement result between the sending node and the relay node, and the first measurement result between the relay node and the receiving node, the first intermediate key of the sending node is determined.
3. The method according to claim 2, wherein, The phase information of the first relay node is obtained based on the first sub-phase information and the second sub-phase information of the first relay node; the values of the first sub-phase information and the second sub-phase information of the first relay node satisfy the following conditions: In |j Bi When |mod M=0, Φ1 Bi =0; Or, in |j Bi When |mod M=M / 2, Φ1 Bi =1; Where, i∈{1,2}, j B1 j represents the first phase slice index of the relay node. B2 Φ1 represents the second phase slice index of the relay node. B1 This represents the first sub-phase information of the first relay node, Φ1 B2 This represents the second sub-phase information of the first relay node.
4. The method according to claim 1, wherein, Obtaining the first raw key of the sending node includes: Based on the phase slice index of the sending node and the phase slice index of the receiving node, the random phase of the sending node is subjected to the first phase slice filtering to obtain the first original key of the sending node; The phase slice index of the transmitting node and the phase slice index of the receiving node satisfy the following formula: |j A |mod M = 0 or M / 2,|j C |mod M = 0 or M / 2; Where, j A j represents the phase slice index of the transmitting node. C The phase slice index represents the receiving node, and M represents the number of random phase slices.
5. The method according to claim 1, further comprising: Obtain the second original key of the sending node; Based on the second original key of the sending node, determine the second intermediate key of the sending node; Obtain the first subkey of the second intermediate key of the relay node; Based on the second intermediate key of the sending node and the first subkey of the second intermediate key of the relay node, the first subkey of the second target key is determined, and the first subkey of the second target key is used for communication between the sending node and the relay node.
6. The method according to claim 5, wherein, Determining the second intermediate key of the sending node based on the second original key of the sending node includes: The phase information between the transmitting node and the relay node, as well as the second measurement result between the transmitting node and the relay node, are obtained; the second measurement result between the transmitting node and the relay node is the measurement result obtained by performing interferometric measurement and a second phase slice filtering on the transmitting node and the relay node; The second intermediate key of the sending node is determined based on the second original key of the sending node, the phase information between the sending node and the relay node, and the second measurement result between the sending node and the relay node.
7. The method according to claim 6, wherein, The phase information between the transmitting node and the relay node satisfies the following condition: In |j A -j B1 +j d When |mod M=0, Φ AB =0; Or, in |j A -j B1 +j d When |mod M=M / 2, Φ AB =1; Where, Φ AB j represents the phase information between the transmitting node and the relay node. A j represents the phase slice index of the transmitting node. B1 j represents the first phase slice index of the relay node. d To optimize phase compensation in response to environmental noise, M represents the number of random phase slices; The first phase slice index of the relay node is obtained based on the first sub-phase information of the second relay node.
8. The method according to claim 5, wherein, Obtaining the second original key of the sending node includes: Based on the phase slice index of the sending node and the first phase slice index of the relay node, a second phase slice filtering is performed on the random phase of the sending node to obtain the second original key of the sending node; The phase slice index of the transmitting node and the first phase slice index of the relay node satisfy the following formula: |j A -j B1 +j d |mod M = 0 or M / 2; Where, j A j represents the phase slice index of the transmitting node. B1 j represents the first phase slice index of the relay node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices.
9. A key distribution method applied to a receiving node, the method comprising: Obtain the first raw key of the receiving node; Based on the first original key of the receiving node, determine the first intermediate key of the receiving node; Obtain the first intermediate key from the sending node; Based on the first intermediate key of the receiving node and the first intermediate key of the sending node, a first target key is determined. The first target key is used by the sending node to communicate with the receiving node through a relay node.
10. The method according to claim 9, wherein, Determining the first intermediate key of the receiving node based on the first original key of the receiving node includes: Based on the first original key and the first phase information of the receiving node, the first intermediate key of the receiving node is determined; the first phase information of the receiving node is the phase information obtained by performing a first phase slice filtering on the random phase of the receiving node.
11. The method according to claim 9, wherein, The step of obtaining the first original key of the receiving node includes: Based on the phase slice index of the sending node and the phase slice index of the receiving node, the random phase of the sending node is subjected to the first phase slice filtering to obtain the first original key of the receiving node; The phase slice index of the transmitting node and the phase slice index of the receiving node satisfy the following formula: |j A |mod M = 0 or M / 2,|j C |mod M = 0 or M / 2; Where, j A j represents the phase slice index of the transmitting node. C The phase slice index represents the receiving node, and M represents the number of random phase slices.
12. The method according to claim 9, further comprising: Obtain the second original key of the receiving node; Based on the second original key of the receiving node, determine the second intermediate key of the receiving node; Obtain the second subkey of the second intermediate key of the relay node; Based on the second intermediate key of the receiving node and the second sub-key of the second intermediate key of the relay node, a second sub-key of the second target key is determined. The second sub-key of the second target key is used for communication between the relay node and the receiving node.
13. The method according to claim 12, wherein, Determining the second intermediate key of the receiving node based on the second original key of the receiving node includes: The phase information between the relay node and the receiving node, as well as the second measurement result between the relay node and the receiving node, are obtained; the second measurement result between the relay node and the receiving node is the measurement result obtained by performing interferometric measurement and a second phase slice screening on the relay node and the receiving node; The second intermediate key of the receiving node is determined based on the second original key of the receiving node, the phase information between the relay node and the receiving node, and the second measurement result between the relay node and the receiving node.
14. The method according to claim 13, wherein, The phase information between the relay node and the receiving node satisfies the following condition: In |j B2 -j C +j d When |mod M=0, Φ BC =0; Or, in |j B2 -j C +j d When |mod M=M / 2, Φ BC =1; Where, Φ BC This represents the phase information between the relay node and the receiving node, j B2 j represents the second phase slice index of the relay node. C j represents the phase slice index of the receiving node. d To optimize phase compensation in response to environmental noise, M represents the number of random phase slices; The second phase slice index of the relay node is obtained based on the second sub-phase information of the second relay node.
15. The method according to claim 12, wherein, The step of obtaining the second original key of the receiving node includes: Based on the second phase slice index of the relay node and the phase slice index of the receiving node, a second phase slice filtering is performed on the random phase of the receiving node to obtain the second original key of the receiving node; The second phase slice index of the relay node and the phase slice index of the receiving node satisfy the following formula: |j B2 -j C +j d |mod M = 0 or M / 2; Where, j B2 j represents the second phase slice index of the relay node. C j represents the phase slice index of the receiving node. d To optimize phase compensation for environmental noise, M represents the number of random phase slices.
16. A key distribution method applied to a relay node, the method comprising: Based on the first phase slice index or the second phase slice index of the relay node, the random phase of the relay node is subjected to the first phase slice filtering to obtain the first subkey of the first original key of the relay node and the second subkey of the first original key of the relay node. The first phase slice index and the second phase slice index of the relay node satisfy the following formula: |j B1 |mod M = 0 or M / 2,|j B2 |mod M = 0 or M / 2; Where, j B1 j represents the first phase slice index of the relay node. B2 The second phase slice index of the relay node is represented, and M represents the number of random phase slices; The first original key of the relay node is generated based on the first subkey of the first original key of the relay node and the second subkey of the first original key of the relay node; The relay node publishes its first original key and sends the location information of the first subkey of the first original key to the sending node, and sends the location information of the second subkey of the first original key to the receiving node. The first original key of the relay node is used by the sending node to determine the first intermediate key of the sending node, and then determines the first target key based on the first intermediate key of the sending node. The first target key is used by the sending node to communicate with the receiving node through the relay node.
17. The method according to claim 16, further comprising: The random phase of the relay node is first sliced and filtered to obtain the phase information of the first relay node; The phase information of the first relay node is published, and the phase information of the first relay node is used by the sending node to determine the first intermediate key of the sending node.
18. The method according to claim 17, wherein, The first phase slice filtering of the random phase of the relay node to obtain the phase information of the first relay node includes: The random phase of the relay node is subjected to a first phase slice screening to obtain the first sub-phase information and the second sub-phase information of the first relay node. The values of the first sub-phase information and the second sub-phase information of the first relay node satisfy the following conditions: In |j Bi When |mod M=0, Φ1 Bi =0; Or, in |j Bi When |mod M=M / 2, Φ1 Bi =1; Where, i∈{1,2}, j B1 j represents the first phase slice index of the relay node. B2 Φ1 represents the second phase slice index of the relay node. B1 This represents the first sub-phase information of the first relay node, Φ1 B2 This indicates the second sub-phase information of the first relay node; The phase information of the first relay node is determined based on the first sub-phase information and the second sub-phase information of the first relay node.
19. The method according to claim 16, further comprising: Obtain the first subkey of the second intermediate key of the relay node and the second subkey of the second intermediate key of the relay node; The first subkey of the second intermediate key of the relay node is determined as the first subkey of the second target key, and the first subkey of the second target key is used for communication between the sending node and the relay node; The second subkey of the second intermediate key of the relay node is determined as the second subkey of the second target key, and the second subkey of the second target key is used for communication between the relay node and the receiving node.
20. The method according to claim 19, wherein, The step of obtaining the first subkey of the second intermediate key of the relay node and the second subkey of the second intermediate key of the relay node includes: Obtain the first subkey of the second original key of the relay node and the second subkey of the second original key of the relay node; The first subkey of the second original key of the relay node is determined as the first subkey of the second intermediate key of the relay node; The second subkey of the second original key of the relay node is determined as the second subkey of the second intermediate key of the relay node.
21. The method according to claim 20, wherein, The process of obtaining the first subkey of the second original key of the relay node and the second subkey of the second original key of the relay node includes: Based on the phase slice index of the transmitting node and the first phase slice index of the relay node, a second phase slice filtering is performed on the random phase of the relay node to obtain the first subkey of the second original key of the relay node; The phase slice index of the transmitting node and the first phase slice index of the relay node satisfy the following formula: |j A -j B1 +j d |mod M = 0 or M / 2; Where, j A j represents the phase slice index of the transmitting node. B1 j represents the first phase slice index of the relay node. d To optimize phase compensation in response to environmental noise, M represents the number of random phase slices; Based on the second phase slice index of the relay node and the phase slice index of the receiving node, a second phase slice filtering is performed on the random phase of the relay node to obtain the second subkey of the second original key of the relay node; The second phase slice index of the relay node and the phase slice index of the receiving node satisfy the following formula: |j B2 -j C +j d |mod M = 0 or M / 2; Where, j B2 j represents the second phase slice index of the relay node. C This represents the phase slice index of the receiving node.
22. The method according to claim 16, further comprising: A second phase slice filtering is performed on the random phase of the relay node to obtain the first sub-phase information of the second relay node and the second sub-phase information of the second relay node; The first sub-phase information and the second sub-phase information of the second relay node are published; the first sub-phase information of the second relay node is used by the sending node to determine the second intermediate key of the sending node; the second sub-phase information of the second relay node is used by the receiving node to determine the second intermediate key of the receiving node.
23. An electronic device, comprising: Processor and memory; The memory is used to store one or more programs, the one or more programs including computer execution instructions. When the electronic device is running, the processor executes the computer execution instructions stored in the memory to cause the electronic device to perform the method of any one of claims 1-22.
24. A computer-readable storage medium storing one or more programs, said one or more programs including instructions that, when executed by a computer, cause the computer to perform the method as claimed in any one of claims 1-22.
25. A computer program product comprising computer instructions that, when executed on an electronic device, perform the method as described in any one of claims 1-22.