[论文解读] Experimental Authentication of Quantum Key Distribution with Post-quantum Cryptography
该论文提出并实验验证了一种基于后量子密码学(PQC)的量子密钥分发(QKD)认证协议,采用基于格的Aigis-Sig数字签名方案,并与公钥基础设施(PKI)集成。该方法在无需预共享对称密钥的情况下,实现了高效、可扩展且安全的QKD认证,展示了亚毫秒级的签名生成与验证性能,30小时稳定运行,并可无缝集成于城域QKD网络中。
Quantum key distribution (QKD) can provide information theoretically secure key exchange even in the era of quantum computer. However, QKD requires the classical channel to be authenticated, and the current method is pre-sharing symmetric keys. For a QKD network of $n$ users, this method requires $C_n^2 = n(n-1)/2$ pairs of symmetric keys to realize pairwise interconnection. In contrast, with the help of mature public key infrastructure (PKI) and post-quantum cryptography (PQC) with quantum resistant security, each user only needs to apply for a digital certificate from certificate authority (CA) to achieve efficient and secure authentication for QKD. We only need to assume the short-term security of the PQC algorithm to achieve the long-term security of the distributed keys. Here, we experimentally verified the feasibility, efficiency and stability of the PQC algorithm in QKD authentication, and demonstrated the advantages when new users join the QKD network. Using PQC authentication we only need to believe the CA is safe, rather than all trusted relays. QKD combined with PQC authentication will greatly promote and extend the application prospects of quantum safe communication.
研究动机与目标
- 解决因经典信道认证需预共享对称密钥而导致的QKD网络可扩展性与密钥管理瓶颈问题。
- 评估后量子密码学(PQC)在真实条件下用于QKD系统认证的可行性与性能表现。
- 证明PQC认证可替代可信中继,降低QKD基础设施中的全网信任依赖。
- 验证PQC在QKD数据处理流水线中长期运行的稳定性与低延迟性能。
- 通过数字证书而非成对密钥分发,实现QKD网络中新用户的高效接入。
提出的方法
- 作者实现了基于格的Aigis-Sig数字签名方案,该方案源自学习误差(LWE)与小整数解(SIS)问题,用于实现抗量子攻击的认证。
- 设计了增强型PKI协议,每个用户从证书颁发机构(CA)获取证书,通过公钥验证实现相互认证。
- 认证协议包含两个阶段:(1) 使用CA公钥交换并验证数字证书;(2) 使用带nonce保护的Aigis-Sig对消息摘要进行签名与验证,以防范重放攻击。
- 在签名前使用SM3哈希函数生成256位消息摘要,数据处理中考虑了有限密钥效应。
- PQC实现运行于Windows 10 64位系统,配备Intel i7-9750H CPU,签名生成耗时459,903个CPU周期,验证耗时104,337个CPU周期。
- 系统采用BB84协议结合诱骗态,通过40 km光纤传输,利用波分复用技术同步脉冲光信号。
实验结果
研究问题
- RQ1后量子数字签名能否在真实QKD系统中实现高效且安全的经典信道认证?
- RQ2PQC认证是否在不降低QKD密钥生成速率的前提下,保持低延迟与高性能?
- RQ3在多用户QKD网络中,PQC认证与预共享密钥方法相比,在可扩展性与运行开销方面有何差异?
- RQ4PQC认证能否替代QKD网络中的可信中继,从而减少信任假设并提升安全性?
- RQ5PQC认证在真实QKD条件下连续运行时,其长期稳定性如何?
主要发现
- Aigis-Sig算法平均签名生成耗时459,903个CPU周期,验证耗时104,337个CPU周期,签名大小为2,445字节。
- 签名与验证的实际执行时间均低于1毫秒,表明对QKD系统性能影响可忽略不计。
- 系统在40 km光纤链路上连续稳定运行30小时,密钥持续生成且PQC认证无中断。
- 通过实验测试验证,该协议成功防范了中间人攻击,且通过nonce机制有效缓解了重放攻击。
- 该方法实现了用户间直接QKD连接,无需可信中继,降低了网络信任依赖并简化了密钥管理。
- 结果证实,PQC认证在城域QKD中继与全通网络中具备部署可行性,相较于预共享密钥方法,在可扩展性与运行效率方面具有显著优势。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。