Source-linked AI summary

Experimental quantum secure network with digital signatures and encryption

Hua-Lei Yin, Yao Fu, Chen-Long Li, Chen-Xun Weng, Bing-Hong Li, Jie Gu, Yu-Shuo Lu, Shan Huang, Zeng-Bing Chen

arXiv:2107.14089v4quant-ph

TL;DR

Efficient information-theoretically secure digital signatures remain difficult, especially for long documents. This paper proposes an OTUH-QDS protocol combining secret sharing, one-time universal2 hashing, and the one-time pad, and demonstrates a quantum secure network integrating several cryptographic primitives. The protocol uses a 384-bit key for long documents and achieves major signature-efficiency improvements experimentally.

  • Problem

    Efficient digital signatures providing information-theoretically secure integrity, authenticity, and non-repudiation remain an urgent open problem, while prior quantum digital signatures require approximately 10^5 bits to sign one bit.

  • Method

    The protocol combines secret sharing, one-time universal2 hashing, and the one-time pad, and integrates digital signatures with secure communication, secret sharing, and conference key agreement in a quantum secure network.

  • Results

    1.22 tps is achieved for signing 10^6-bit documents, versus 3.23 × 10^-9 tps using Ref., while the experimental security bound reaches 10^-32.

  • Takeaways & Limitations

    The demonstrated framework provides information-theoretically secure digital signatures and a full-function quantum secure network meeting confidentiality, integrity, authenticity, and non-repudiation objectives.

Abstract

from arXiv · show

Cryptography promises four information security objectives, namely, confidentiality, integrity, authenticity, and non-repudiation, to support trillions of transactions annually in the digital economy. Efficient digital signatures, ensuring the integrity, authenticity, and non-repudiation of data with information-theoretical security are highly urgent and intractable open problems in cryptography. Here, we propose a protocol of high-efficiency quantum digital signatures using secret sharing, one-time universal$_2$ hashing, and the one-time pad. We just need to use a 384-bit key to sign documents of up to $2^{64}$ lengths with a security bound of $10^{-19}$. If one-megabit document is signed, the signature efficiency is improved by more than $10^8$ times compared with previous quantum digital signature protocols. Furthermore, we build the first all-in-one quantum secure network integrating information-theoretically secure communication, digital signatures, secret sharing, and conference key agreement and experimentally demonstrate this signature efficiency advantage. Our work completes the cryptography toolbox of the four information security objectives.

I. INTRODUCTION

The paper motivates quantum-secure digital signatures because existing classical cryptographic primitives can be broken, while quantum key distribution addresses confidentiality but not integrity, authenticity, or non-repudiation. It proposes an information-theoretically secure QDS protocol designed to improve the severe efficiency limits of earlier schemes.

  • Current quantum key distribution and quantum secure direct communication ensure confidentiality but not integrity, authenticity, or non-repudiation.
  • Classical digital signatures support software distribution, e-mail, web browsing, and financial transactions, but their hash functions and public-key algorithms are vulnerable to classical or quantum computers.
  • Earlier QDS schemes required approximately 10^5 bits to sign one bit, and their best reported gigahertz signature rate was below 1 tps for one-bit signatures at 100 km.
  • The proposed OTUH-QDS protocol uses one-time universal2 hashing, one-time-pad encryption, and secret sharing to sign arbitrarily long documents with information-theoretical security.
  • A 384-bit key can sign documents up to 2^64 lengths with a security bound of 10^-19.
  • The work experimentally demonstrates a quantum secure network integrating private communication, digital signatures, secret sharing, and conference key agreement.

Efficient QDS protocol

The protocol uses secret-shared correlated keys among Alice, Bob, and Charlie, with Alice signing and Bob and Charlie independently verifying through OTP decryption and OTUH hashing. Its design replaces fixed classical hashing and public-key relationships with refreshed, asymmetric quantum keys.

  • Pre-distribution stage: Alice, Bob, and Charlie pre-distribute correlated n-bit and 2n-bit keys satisfying Xa = Xb ⊕ Xc and Ya = Yb ⊕ Yc.The pre-distribution stage can use quantum key distribution or quantum secret sharing.
  • Signing of Alice: Alice generates an LFSR-based Toeplitz matrix, hashes the m-bit document into n bits, and combines the hash with OTP-protected data to form the signature.
  • Verification of Bob: Bob forwards the received document and signature with his keys to Charlie, who returns key material enabling Bob to reconstruct matching verification keys by XOR.
  • Figure 2 illustrates the asymmetric QDS arrangement and gives a hexadecimal signing example for “The 120th anniversary of Nanjing University.”
  • Verification of Bob: Bob decrypts an expected digest and polynomial, hashes the document with the reconstructed LFSR-based Toeplitz matrix, and accepts only when the digests match.
  • Verification of Charlie: Charlie performs analogous OTP decryption and hashing with reconstructed keys, accepting the signature only when his actual and expected digests are identical.

Security proof

The security analysis models forgery, repudiation, and honest rejection under distrust between Alice and Bob and a trusted Charlie. It derives information-theoretic bounds from secret sharing, OTP encryption, refreshed OTUH functions, and authenticated key exchange.

  • The QDS threat model treats Alice and Bob as mutually distrustful attackers, while Charlie is trusted and verifies signatures.Bob and Charlie counter repudiation; Alice and Charlie counter forgery; robustness is also considered.
  • Security against forgery: Bob’s forgery probability is bounded by guessing key material or the signer’s LFSR polynomial, with universal2 collision probability m/2^(n−1).
  • Security against forgery: Refreshing keys and the universal2 hash function after every signing round prevents Bob from using information from previous rounds.
  • Security against forgery: The forgery proof remains information-theoretically secure even when Bob has unlimited computing power.
  • Security against repudiation: Bob and Charlie recover identical XOR-combined keys and polynomials, so the repudiation probability is zero apart from insignificant secure-message-authentication failure.
  • Robustness: When all parties are truthful, shared keys and polynomials produce the same hash function and digest, yielding zero honest aborting probability.
  • With 128-bit OTUH and 256-bit OTP keys, the security bound is below 2^64/(2^128−1) ≈ 1.1 × 10^-19 for documents up to 2^64 lengths.

Simulation results of the QDS

The OTUH-QDS protocol is simulated with quantum key distribution and quantum secret sharing, supporting high-rate signing in metropolitan-area networks with a fixed 384-bit key.

  • The framework can use known and future quantum secret sharing or quantum key distribution protocols to establish the parties’ perfect bit correlation.
  • For fiber distances below 50 km, a gigahertz system can implement digital signatures at up to 10^4 tps, including 2^64-bit documents.
  • 384-bit keys support signatures for documents up to 2^64 length with a security bound of approximately 1.1 × 10^-19.
  • The protocol’s key consumption remains almost constant as document length increases to 10^19 bits, using a 384-bit key.

Experimental results of the QDS

The experiment implements OTUH-QDS over long-distance quantum links and demonstrates successful signing of a one-megabit document with substantially higher efficiency than an earlier single-bit-type QDS protocol.

  • 6,021 and 470 bits per second were measured for the Bob–Alice and Charlie–Alice quantum key distribution links, respectively, over 101-km and 126-km fibers.
  • A 130,250-byte document was successfully signed over 101-km fiber using a 128-bit OTUH hash, a 128-bit irreducible polynomial, and OTP encryption.
  • 1.22 tps was achieved for signing a 10^6-bit document, compared with 3.23 × 10^-9 tps for Ref..
  • The OTUH-QDS experiment required less than one second, whereas Ref. would require approximately four years to accumulate data for the same document size.
  • Uniform hashing maps long documents to short hash values, while the encrypted hash and hash function force an attacker to guess them randomly.
  • The experiment produced at least six orders of magnitude improvement in signature efficiency for a 1.042 × 10^6-bit document.

Demonstration of other cryptographic tasks

The quantum secure network demonstrates encryption, secret sharing, and conference key agreement with information-theoretical security alongside digital signatures.

  • Encryption: OTP encryption enables private communication between Bob and Charlie using identical keys relayed through Alice’s XOR operation.
  • Secret sharing: In secret sharing, Bob and Charlie must cooperate to recover the mountain image, while either individual obtains only a complete noise map.
  • Conference key agreement: Conference key agreement gives all three participants the same key, allowing each to recover the lake image independently during group encryption.
  • The private communication task requires trusted relay node Alice, whereas digital signatures, secret sharing, and conference key agreement do not.

III. CONCLUSIONS

The paper demonstrates a full-function quantum secure network covering confidentiality, integrity, authenticity, and non-repudiation, with OTUH-QDS providing a 100-million-fold signature-efficiency improvement.

  • The demonstrated network meets all four information security objectives: confidentiality, integrity, authenticity, and non-repudiation.
  • The OTUH-QDS protocol uses few resources to sign almost arbitrarily long documents while improving signature efficiency by 100 million fold.
  • The network was implemented with current technology and could be extended through more advanced technology such as a future quantum internet.

Pre-distribution stage

The pre-distribution stage establishes correlated key strings among Alice, Bob, and Charlie, using quantum communication protocols such as quantum key distribution and quantum secret sharing. The protocol’s one-time universal2 hashing uses compact, freshly randomized LFSR-based Toeplitz matrices to map long documents to short hash values with low collision probability.

  • Alice, Bob, and Charlie hold key strings satisfying Xa = Xb ⊕Xc and Ya = Yb ⊕Yc, forming the required secret-sharing correlations.
  • Quantum key distribution links can generate symmetric quantum keys for the participating parties, with dishonest parties lacking knowledge of the corresponding key.
  • Alice’s XOR operation produces a signer–receiver asymmetry because she possesses the relevant knowledge of Bob’s and Charlie’s keys.
  • Measurement-device-independent quantum secret sharing allows all three participants to remain ignorant of others’ quantum keys, so any participant can be a receiver or signer.
  • Universal2 hashing maps long documents to short hash values with small collision probability, while LFSR-based Toeplitz matrices reduce random-bit requirements.
  • The LFSR-based Toeplitz matrix is freshly randomized for each signature through a new initial vector and irreducible polynomial, a novel OTUH-QDS requirement.

1. Cryptography toolbox

The cryptography toolbox links major information-processing threats to the security objectives they threaten and to classical cryptographic techniques addressing them. Eavesdropping threatens confidentiality, while tampering, disguise, and repudiation concern integrity, authenticity, and non-repudiation.

  • Eavesdropping threatens confidentiality and can be prevented using symmetric or asymmetric cryptography.
  • Tampering threatens data integrity and can be addressed with one-way hash functions, message authentication codes, or digital signatures.
  • Disguise threatens sender authenticity because an attacker pretends to be the real information sender; message authentication codes and digital signatures address it.
  • Digital signatures provide non-repudiation by addressing attempts to repudiate a person’s behavior.

2. One-time pad

The protocol combines one-time-pad encryption with LFSR-based Toeplitz hashing and refreshed randomness to provide information-theoretically secure authentication and quantum digital signatures. Its security analysis bounds forgery through the hash-function structure and requires a new universal2 hash function in every signature round.

  • One-time pad: The one-time pad encrypts the hash value, concealing information about the almost universal2 hash function used in the signature.The scheme uses the hash value and irreducible polynomial to acquire the signature while concealing the hash-function information.
  • Security analysis: The hash collision probability for LFSR-based Toeplitz hashing is bounded by ϵ = m/2^(n−1).The bound depends on message length m and polynomial degree n.
  • LFSR-based Toeplitz hashing: LFSR-based Toeplitz hashing uses a random irreducible polynomial and initial vector to construct an n-by-m matrix, whose product with the message yields the hash.The polynomial determines the feedback-shift process that generates the matrix columns.
  • Security analysis: The authentication proof analyzes zero and nonzero forged tags, with the zero-tag case occurring with probability at most m/2^(n−1).The zero-tag bound follows from the probability that the message polynomial has an irreducible factor matching the randomly chosen polynomial.
  • OTUH-QDS security: OTUH-QDS forgery is related to message-authentication attacks because Bob lacks the initial vector and irreducible polynomial before forwarding a signed document.The second OTUH-QDS forgery type has the same failure probability as the corresponding message-authentication attack: m/2^(n−1).
  • OTUH-QDS security: Unlike later-round message authentication, OTUH-QDS must randomly update the initial vector and irreducible polynomial after every round.Bob receives information about the prior round after verification, so reusing the hash function would expose the protocol to attacks based on previous-round information.
Loading 2107.14089v4…