[论文解读] Authentication of quantum key distribution with post-quantum cryptography and replay attacks
本文提出两种基于后量子密码学(PQC)的量子密钥分发(QKD)数据后处理认证协议,实现无需预共享密钥的长期量子抗性安全。通过使用PQC签名对纠错、随机数传输和最终密钥验证进行认证,协议可防止重放攻击,原因在于测量基和信号状态的固有随机性。
With the development of quantum computers, traditional cryptographic systems are facing more and more serious security threats. Fortunately, quantum key distribution (QKD) and post-quantum cryptography (PQC) are two cryptographic mechanisms with quantum-resistant security, and both will become important solutions for future information security. However, neither of them is perfect, and they are complementary. Quantum key distribution has unconditional security that post-quantum cryptography does not have, and PQC can provide secure and convenient authentication for QKD networks. In this paper, we propose two protocols based on PQC to realize the full authentication of the QKD data post-processing, and we only need to assume the short-term security of PQC algorithm to ensure the long-term quantum resistant security of distributed keys. We found that for the above two authentication protocols, attackers cannot successfully implement replay attacks. These authentication protocols can solve the problems of the current pre-shared key authentication in the application of large-scale quantum key distribution networks, and are expected to realize a key distribution mechanism with practical operability and quantum resistant security, which will be beneficial to promote the deployment and application of quantum key distribution networks.
研究动机与目标
- 解决大规模QKD网络中预共享密钥认证的可扩展性和实用性问题。
- 通过集成后量子密码学(PQC)用于认证,实现在QKD中实现抗量子安全。
- 通过基于PQC的相互认证,消除城域QKD网络中对可信中继的依赖。
- 通过仅假设PQC算法具有短期安全性,确保分发密钥的长期安全性。
提出的方法
- 使用PQC数字签名(例如基于格或哈希的签名)对QKD后处理中的纠错验证和最终密钥验证进行认证。
- 通过PQC签名的摘要对随机数传输进行认证,以防止伪装攻击。
- 应用隐私放大以消除从已认证摘要中泄露的任何密钥信息,确保无侧信道泄露。
- 设计两种协议:一种对基矢选择、纠错和随机数传输进行PQC认证;另一种使用隐私放大后密钥的一小部分对最终密钥验证进行PQC认证。
- 利用测量基和信号调制的随机性防止重放攻击,因为若无先前合法的QKD会话,无法重现相同的纠错后密钥。
- 即使PQC算法在认证后被攻破,最终QKD密钥仍保持安全,原因在于已认证数据仅一次性使用。
实验结果
研究问题
- RQ1基于PQC的认证能否在大规模QKD网络中替代预共享密钥,同时保持长期量子抗性?
- RQ2当PQC用于认证后处理步骤时,能否成功对QKD协议实施重放攻击?
- RQ3测量基和信号状态的随机性对QKD中重放攻击可行性有何影响?
- RQ4如何在不损害最终密钥无条件安全性的情况下,将PQC认证集成到QKD协议中?
- RQ5仅假设PQC算法具有短期安全性,是否足以保证QKD密钥的长期安全性?
主要发现
- 所提出的基于PQC的认证协议可防止重放攻击,因为纠错后密钥无法被重现,原因在于对方测量基和信号状态的随机性。
- 攻击者成功重放签名摘要的概率约为 $2^{-k}$,其中 $k$ 为纠错后密钥的长度,因此在实践中不可行。
- 即使后续PQC算法被攻破,最终QKD密钥仍保持安全,因为认证过程在密钥生成前已完成,且密钥不依赖于PQC的长期安全性。
- 这些协议与多种QKD协议兼容,包括测量设备无关QKD、双场QKD和连续变量QKD。
- 使用PQC认证可减少或消除城域QKD网络中对可信中继的需求,从而提升网络互连性和安全性。
- 这些协议在无需预共享对称密钥的情况下实现抗量子安全,显著提升了大规模QKD部署的可扩展性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。