Quanta identity authentication system based on Polarization Modulation
Technical field
The present invention relates to a kind of quanta identity authentication system based on Polarization Modulation, solving the authenticating user identification problem in the information security field, is the advanced subject of a plurality of subjects such as combining cipher, optical fiber communication, quantum optices, nonlinear optics and network service.
Background technology
Quantum cryptography is the novel cipher system based on classical cryptoraphy and quantum physics, and the fail safe of this cryptographic system is subjected to grasping in the quantum bit assurance of attribute (Heisenberg's indeterminacy).Quantum can not cloning theorem and Heisenberg uncertainty principle guaranteed that quantum cryptography has unconditional security and to the detectability of eavesdropping, makes quantum cryptography have good performance and prospect.
1969, S.Wiesner at first proposed quantum cryptography thought.1984, the scientist C.H.Bennett of American I BM company and Canadian cryptologist G.Brassard proposed first quantum key distribution agreement---BB84 agreement in the world.After several years, Bennett and Brassard and they leader's group utilizes the BB84 agreement, adopts the weak laser pulse to realize the quantum key distribution in the free space first in the laboratory as the quantum signal generator.From then on, the quantum cryptography that is based upon on the quantum optical communication basis becomes one of problem of common concern in the world, the various countries scholar carries out quantum cryptography research from different angles in theory with scientist, content relates to quantum key distribution, quantum key checking, quantal data encryption, quantum secret sharing, quanta identity authentication, quantum signature, quantum bit promise, quantum Oblivious Transfer, quantum calculates in many ways and the information theory of quantum cryptography, in addition, Quantum Error Correcting Codes also more and more is subject to people's attention.
Quanta identity authentication as one of quantum cryptography important branch causes the increasing interest of various countries scholar.Miloslav Dusek has reported a kind of identity authorization system (Miloslav Dusek based on quantum key distribution and classical authentication, Ondrej Haderka, Martin Hendrych and Robert Myska, Phys.Rev.A 60,149 (1999)), in this system, Alice and Bob adopt BB84 agreement exchange capacity sub-key, utilize this key to adopt classical mode to realize authentication then.Miloslav Dusek does not fundamentally solve the theory and technology problem of quanta identity authentication, he is the unconditional security and the detectivity certified transmission password to eavesdropping of utilization quantum key distribution only, utilizes classical certificate scheme validation of a user's identity then.Classical authentication needs finally validation of a user's identity of three-way handshake, and it is very low to cause authenticating efficient.In the world, generally use the weak laser pulse, adopt the mode dispensed amount sub-key of phase modulation, and the Polarization Modulation mode rarely has report as quantum signal.
Summary of the invention
The objective of the invention is at the deficiencies in the prior art, provide a kind of new full dose sub-identity verification scheme, remedy the deficiency of classical part in the Miloslav Dusek identity verification scheme, improve authentication efficient, promote China's information security capital construction.
For realizing such purpose, the present invention proposes a kind of quanta identity authentication system based on Polarization Modulation, adopt the weak laser pulse as quantum signal, adopt the dynamic polarization controller as the quantum signal modulator, work in avalanche silicon diode under the Geiger pattern as single-photon detector, dynamically set up the customer data base data according to user cipher and ID card, utilize the safety that can not cloning theorem guarantees system of unknown quantum state.
The quanta identity authentication system that the present invention is based on Polarization Modulation is made up of authentication center and user's two parts.Authentication center comprises light path part and control section, light path part is made up of semiconductor laser, attenuator, the polarizer, center dynamic polarization controller, analyzer, photodetector, and the control section of authentication center is made up of center master controller, user profile database, randomizer.User side also comprises control light path part and control section, and light path part comprises two speculums, user's ID card, user side dynamic polarization controller, and the user side control section comprises user side master controller, synchronous clock generator.Semiconductor laser and attenuator are as the quantum signal generator, the accurate single photon that produces as information carrier, be initialized as the vertical polarization attitude through the polarizer, be transferred to user side by free space, through two speculum change transmission directions of 90 degree angles layouts each other, behind user's ID card, be transferred to user side dynamic polarization controller, be transferred to the dynamic polarization controller of authentication center again through free space, polarization state by the accurate single photon after the analyzer detection conversion, survey single photon by detector, the light transmission shaft of analyzer is parallel with the light transmission shaft of the polarizer; The user side master controller is according to user cipher control user side dynamic polarization controller, the center master controller of control centre's dynamic polarization controller and the master controller of user side are by classical channel communication, synchronous clock generator links to each other with two master controllers respectively, randomizer links to each other with the center master controller, the random number that needs when producing registration for the center master controller, user profile database is a center master controller stored user identity information.
The course of work of system of the present invention comprises registration phase and authentication phase.Registration phase: the user proposes register requirement to authentication center, authentication center prepares the single photon sequence of perpendicular linear polarization, user's ID card and the perpendicular linear polarization attitude of single photon is modulated by password Driven Dynamic Polarization Controller, authentication center operates the single photon sequence (variation has taken place the perpendicular linear polarization of the single photon sequence after ovennodulation) that is written into subscriber identity information once more according to random number, and concrete operations and random number are dynamically set up the customer data base data as subscriber identity information.Authentication phase: after user's authentication request is received by authentication center, the single photon sequence of preparation perpendicular linear polarization, and from database, access the data of relative users, system client is modulated the perpendicular linear polarization attitude of single photon according to ID card and user cipher, authentication center's server end is carried out corresponding conversion according to the data in the database once more to the polarization state of the single photon sequence after modulating, and measure, by comparing and measuring the whether consistent legitimacy of coming identifying user identity of random number in result and the subscriber data.
The quanta identity authentication system that the present invention is based on Polarization Modulation adopts the weak laser pulse as quantum signal, and this technology is quite ripe, can satisfy the requirement of system to single-photon source preferably.Avalanche silicon diode is as single-photon detector under the Geiger pattern to adopt commonly used in the world working in, and test of many times both domestic and external proves that this detection method is practicable.The dynamic polarization controller is by the linear polarization of rotation half-wave plate modulating the incident light, and precision can reach 0.03 °.Native system need not utilize BB84 protocol transmission authenticate key, and the transmission course of quantum signal and verification process are carried out simultaneously, directly verifies the user profile in the user profile database, does not need to carry out three-way handshake, has improved authentication efficient.
Description of drawings
Fig. 1 is a quanta identity authentication system schematic diagram of the present invention.
As shown in Figure 1, the quanta identity authentication system that the present invention is based on Polarization Modulation is made up of authentication center and user's two parts.The light path part of authentication center is made up of laser, attenuator, the polarizer, dynamic polarization controller 2, analyzer, photodetector, and the control section of authentication center is made up of master controller 2, user profile database, randomizer.The light path part of user side comprises speculum 1, speculum 2, user's ID card, dynamic polarization controller 1, and the control section of user side comprises master controller 1, synchronous clock generator.
Embodiment
Below in conjunction with drawings and Examples technical scheme of the present invention is further described.
Quanta identity authentication system of the present invention is made up of authentication center and user's two parts as shown in Figure 1.Authentication center comprises light path part and control section, the light path part of authentication center is made up of DL-100 semiconductor laser, attenuator, the polarizer, dynamic polarization controller 2, analyzer, photodetector, and the control section of authentication center is made up of master controller 2, user profile database, randomizer.DL-100 semiconductor laser and attenuator are as the accurate single photon of quantum signal generator generation as information carrier.The polarizer is initialized as the vertical polarization attitude to accurate single photon.The laser that sends from semiconductor laser is initialized as the vertical polarization attitude by the polarizer after being attenuated the device decay, is transferred to user side by free space.The accurate single photon that dynamic polarization controller 2 conversion of being controlled by master controller 2 come from client transmissions, analyzer detects the polarization state of single photon, and avalanche silicon diode is surveyed single photon as photodetector.Randomizer is that master controller 2 produces the random number that needs when registering.The master controller 1 of master controller 2 and user side is controlled dynamic polarization controller 2 by classical channel communication.
User side also comprises light path part and control section, and light path part comprises speculum 1, speculum 2, dynamic polarization controller 1.Control section comprises master controller 1, synchronous clock generator.The transmission direction that speculum 1 and speculum 2 changes light constitutes optical circuit, by the dynamic polarization controller 1 of the master controller 1 control polarization state according to the accurate single photon of user cipher conversion.Master controller 1 and master controller 2 are by classical channel communication.Synchronous clock generator provides synchronizing clock signals for master controller 1 and master controller 2.Laser, attenuator, the polarizer, speculum 1, speculum 2, dynamic polarization controller 1, dynamic polarization controller 2, analyzer, photodetector are linked in sequence and constitute the opticator of quanta identity authentication system.Master controller 1, master controller 2, user profile database, randomizer constitute the control section of quanta identity authentication system.
Hold in authentication center, system of the present invention will decay the accurate single photon that produces as information carrier significantly from the laser pulse that semiconductor laser sends---the dried light source of LASER Light Source symbolic animal of the birth year, its number of photons distributes and satisfies Poisson distribution, when pulse laser is decayed to average 0.1 photon of each pulse, the probability that each pulse contains 1 above photon only is 0.5%, the light pulse of this moment shows the quantum attribute such as can not clone, the present invention this accurate single-photon source that constitutes by laser and attenuator as the quantum signal generator.Accurate single photon is through behind the polarizer, and its polarization state is initialized to the vertical polarization attitude, and accurate single photon is transferred to the Verification System user side through free space.At user side, the transmission direction that speculum 1, speculum 2 change light constitutes optical circuit.User's ID card and by 1 pair of accurate single photon conversion of user cipher Driven Dynamic Polarization Controller from the vertical polarization attitude of server end.The light transmission shaft of analyzer is parallel with the light transmission shaft of the polarizer, work in avalanche diode under the Geiger pattern as single-photon detector, if user's ID card, dynamic polarization controller 1, dynamic polarization controller 2 are transformed to the horizontal polarization attitude to the vertical polarization attitude, then to detect the probability of photon be 0 to detector; If still be the vertical polarization attitude after the conversion, the probability that detector detects photon is 1.After registration request from user is received by authentication center, produce the random number R=(r of n bit
1, r
2..., r
n), the user inserts ID card, makes the linear polarization face rotation Φ of accurate single photon
1, input n position password, i position password makes the linear polarization face of accurate single photon rotate Φ once more by user side master controller 1 control dynamic polarization controller 1
2i, authentication center is the angle Φ that 0 or 1 definite 2 pairs of linearly polarized lights of dynamic polarization controller rotate once more according to the i bit of random number
3i,
Work as r
i=0 o'clock, Φ
1+ Φ
2i+ Φ
3i=0 ° or 180 °
Work as r
i=1 o'clock, Φ
1+ Φ
2i+ Φ
3i=90 ° or 270 °
After registration finished, authentication center set up the subscriber data with user's filename by name in database, and file content is
R=(r
1, r
2..., r
n) and Φ
3=(Φ
31, Φ
32..., Φ
3n)
In authentication phase, the user inserts ID card, the input password, and the user of authentication center accesses corresponding user file from user profile database, use Φ
3=(Φ
31, Φ
32..., Φ
3n) driving dynamic polarization controller 2, the monitoring photodetector is according to rule: detect photon correspondence 0; Detection is less than photon correspondence 1, the random number the Bit String that collects during with registration relatively, if consistent, authentication success then, otherwise, authentification failure.