论文标题
用量子后加密和重播攻击的量子密钥分布的身份验证
Authentication of quantum key distribution with post-quantum cryptography and replay attacks
论文作者
论文摘要
随着量子计算机的开发,传统的加密系统正面临越来越严重的安全威胁。幸运的是,量子密钥分布(QKD)和量词后加密术(PQC)是两个具有抗量子安全性的加密机制,两者都将成为未来信息安全的重要解决方案。但是,他们俩都不是完美的,而且是互补的。量子密钥分布具有无条件的安全性,后量词加密术没有,PQC可以为QKD网络提供安全且方便的身份验证。在本文中,我们提出了两个基于PQC的协议,以实现QKD数据后处理的全部身份验证,我们只需要假设PQC算法的短期安全性即可确保分布式密钥的长期量子阻力。我们发现,对于上述两个身份验证协议,攻击者无法成功实施重播攻击。这些身份验证协议可以解决当前预共享的密钥身份验证在应用大规模量子密钥分布网络中的问题,并有望实现具有实用可操作性和抗量子性安全性的关键分配机制,这将有助于促进量子密钥分配网络的部署和应用。
With the development of quantum computers, traditional cryptographic systems are facing more and more serious security threats. Fortunately, quantum key distribution (QKD) and post-quantum cryptography (PQC) are two cryptographic mechanisms with quantum-resistant security, and both will become important solutions for future information security. However, neither of them is perfect, and they are complementary. Quantum key distribution has unconditional security that post-quantum cryptography does not have, and PQC can provide secure and convenient authentication for QKD networks. In this paper, we propose two protocols based on PQC to realize the full authentication of the QKD data post-processing, and we only need to assume the short-term security of PQC algorithm to ensure the long-term quantum resistant security of distributed keys. We found that for the above two authentication protocols, attackers cannot successfully implement replay attacks. These authentication protocols can solve the problems of the current pre-shared key authentication in the application of large-scale quantum key distribution networks, and are expected to realize a key distribution mechanism with practical operability and quantum resistant security, which will be beneficial to promote the deployment and application of quantum key distribution networks.