QKD Identity Authentication Using Indexed Qubit Subsequences
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing QKD protocols lack an effective identity authentication mechanism that is not compromised by a compromised classical channel and does not require trust in a third-party quantum channel.
Innovation Solution
A method and apparatus for identity authentication using quantum and classical channels, where qubits are shared between entities to generate sequences of binary axis identifiers and bit values, with subsequences encrypted and decrypted using shared cryptographic keys, allowing authentication based on error analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If classical identity authentication mechanisms are used on the classical channel, then identity authentication can be performed, but the authentication is compromised if the classical channel is compromised
Solution Approach 1:
The patent introduces quantum-generated sequences as an intermediary authentication mechanism. Instead of relying solely on classical channel authentication, the system uses quantum-generated bit sequences and axis identifiers that are exchanged through the classical channel but authenticated through quantum mechanical properties. This intermediary quantum-based verification layer protects against classical channel compromise.
Solution Approach 2:
The patent replaces classical cryptographic authentication mechanisms with quantum mechanical-based authentication. By using quantum-generated sequences and measuring quantum correlations through the classical channel, the system substitutes traditional mechanical/cryptographic authentication with quantum-based verification that remains secure even when the classical channel is compromised.
2Reliability
If other quantum channels different from the quantum communication channel are used for authentication, then identity authentication can be achieved, but trust in a third party is required
Solution Approach 1:
The patent makes the primary quantum communication channel serve multiple functions: both quantum key distribution and identity authentication. The same quantum channel that establishes the cryptographic key also provides the quantum sequences用于authentication, eliminating the need for separate authentication quantum channels and third-party infrastructure.
Solution Approach 2:
The patent merges the authentication function with the existing quantum communication channel. By combining key generation and authentication into a single integrated process using the same quantum channel, the system eliminates the need for separate authentication infrastructure and third-party quantum channels.
3Reliability
If quantum-generated sequences are exchanged through the classical channel without encryption, then authentication can be performed, but the communication is vulnerable to eavesdropping
Solution Approach 1:
The patent applies partial encryption by encrypting only the critical authentication elements (axis identifiers or bit values) rather than the entire communication sequence. This selective encryption approach provides sufficient protection against eavesdropping while maintaining authentication functionality and minimizing the impact of potential classical channel compromise.
Data Source
AI summary
For Bob's authentication to Alice, Alice sends to Bob randomly selected indexes via the classical channel between Alice and Bob. In response, Bob extracts, from the sequences of qubit-related data generated by Bob and based on the randomly selected indexes received from Alice, subsequences of qubit-related data (e.g. including binary axis identifiers and bit values) and Bob sends the extracted subsequences via the classical channel. At least one of sent subsequences may be encrypted with a shared secret cryptographic key. Then Alice can authenticate Bob on the basis of a number of errors computed based on the decrypted subsequences received from Bob.


