EP4706203A1 - System and method for randomness extraction and method of performing quantum cryptography - Google Patents

System and method for randomness extraction and method of performing quantum cryptography

Info

Publication number
EP4706203A1
EP4706203A1 EP24797570.9A EP24797570A EP4706203A1 EP 4706203 A1 EP4706203 A1 EP 4706203A1 EP 24797570 A EP24797570 A EP 24797570A EP 4706203 A1 EP4706203 A1 EP 4706203A1
Authority
EP
European Patent Office
Prior art keywords
sub
block
blocks
key
entropy
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP24797570.9A
Other languages
German (de)
French (fr)
Other versions
EP4706203A4 (en
Inventor
Hong Jie NG
Wen Yu KON
Ignatius William PRIMAATMAJA
Chao Wang
Ci Wen LIM
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
National University of Singapore
Original Assignee
National University of Singapore
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by National University of Singapore filed Critical National University of Singapore
Publication of EP4706203A1 publication Critical patent/EP4706203A1/en
Publication of EP4706203A4 publication Critical patent/EP4706203A4/en
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F7/00Methods or arrangements for processing data by operating upon the order or content of the data handled
    • G06F7/58Random or pseudo-random number generators
    • G06F7/588Random number generators, i.e. based on natural stochastic processes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/0643Hash functions, e.g. MD5, SHA, HMAC or f9 MAC
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0852Quantum cryptography
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0869Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds

Landscapes

  • Engineering & Computer Science (AREA)
  • Signal Processing (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computational Mathematics (AREA)
  • Electromagnetism (AREA)
  • Power Engineering (AREA)
  • Mathematical Analysis (AREA)
  • Mathematical Optimization (AREA)
  • Pure & Applied Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

A system and a method for randomness extraction for quantum cryptography and a method of performing quantum cryptography between two or more parties. The system for randomness extraction for quantum cryptography comprises a sampling module configured to sample a cryptographic key to generate one or more sub-blocks; an entropy module configured to determine a lower bound of the entropy in each sub-block, wherein the determining of the lower bound comprises consideration of correlations between each sub-block and unsampled bits of the cryptographic key and/or other sub-blocks; and a hashing module configured to hash each sub-block for randomness extraction on each sub-block.

Description

SYSTEM AND METHOD FOR RANDOMNESS EXTRACTION AND METHOD OF PERFORMING QUANTUM CRYPTOGRAPHY
FIELD OF INVENTION
The present invention relates broadly to a system and a method for randomness extraction for quantum cryptography and to a method of performing quantum cryptography between two or more parties.
BACKGROUND
Any mention and/or discussion of prior art throughout the specification should not be considered, in any way, as an admission that this prior art is well known or forms part of common general knowledge in the field.
All practical implementations of quantum cryptographic protocols have finite resources, and thus, suffer from statistical fluctuations in finite-size data. Such statistical fluctuations must be taken into account to ensure that the protocol is information-theoretically secure. This introduces the requirement that the size of the data collected has to be large. However, a large data size is detrimental for hashing, which is one of the necessary steps in both quantum key distribution (QKD) and quantum random number generation (QRNG). This is because a large data size severely slows down the execution of the hashing function, which has an execution time that increases superlinearly with respect to the data size. For the above reasons, hashing is widely known to be the bottleneck of QKD and QRNG implementations.
In more detail, implemented quantum cryptographic protocols are run for a finite duration, and therefore have finite resources. Because of the statistical fluctuations in finite-size data, randomness extraction has to be performed on large input sizes for practical implementations of quantum cryptographic protocols. For example, in QKD, finite-size analysis requires a block size of at least 106 bits. When one is considering protocols with weaker assumptions, such as in the measurement-device-independent setting and the device-independent setting, the block size required is even larger, around 1011 bits.
If one takes device-independent QKD as an example, despite improvements from both theoretical and experimental aspects, the required block size is still larger than the input sizes of state-of-the-art implementations of Toeplitz hashing on FPGAs. This is because the hashing process becomes increasingly impractical as the input size increases. This can be attributed to two scenarios, which are a decrease in throughput or an increase in resources required. As the input size of hashing increases, the output speed naturally decreases, as a larger number of bits have to be processed to produce even a single secure bit. Alternatively, to prevent the throughput of hashing from decreasing, the FPGA can create duplicates of certain hardware and execute them in parallel. However, this leads to a large increase in resource utilization, which restricts the quantum cryptographic system to the use of high-end FPGAs.
Embodiments of the present invention seek to address at least one of the above problems.
SUMMARY
In accordance with a first aspect of the present invention, there is provided a system for randomness extraction for quantum cryptography, comprising a sampling module configured to sample a cryptographic key to generate one or more sub-blocks; an entropy module configured to determine a lower bound of the entropy in each subblock, wherein the determining of the lower bound comprises consideration of correlations between each sub-block and unsampled bits of the cryptographic key and/or other sub-blocks; and a hashing module configured to hash each sub-block for randomness extraction on each sub-block.
In accordance with a second aspect of the present invention, there is provided a method of randomness extraction for quantum cryptography, comprising the steps of: sampling a cryptographic key to generate one or more sub-blocks; determining a lower bound of the entropy in each sub-block, wherein the determining of the lower bound comprises consideration of correlations between each sub-block and unsampled bits of the cryptographic key and/or other sub-blocks; and hashing each sub-block for randomness extraction on each sub-block.
In accordance with a third aspect of the present invention, there is provided method of performing quantum cryptography between two or more parties, the method comprising announcing a uniform random variable Vt e [1, Ws| identifying which bit of the cryptographic key is sampled into which sub-block.
BRIEF DESCRIPTION OF THE DRAWINGS
Embodiments of the invention will be better understood and readily apparent to one of ordinary skill in the art from the following written description, by way of example only, and in conjunction with the drawings, in which: FIG. 1 shows a schematic drawing illustrating the sequential model for the the generalized entropy-accumulation theorem (GEAT), where an initial state PR0E0 undergoes a series of GEAT channels, AQ, to generate the final state PXNCNRNEN-
FIG. 2 shows a plot of the key rate per signal sent against the number of sampled sub-blocks (i.e., 1/Ps), with and without the sampled sub-block hashing method according to an example embodiment applied
FIG. 3 shows a plot of the expected key rate per unit time of randomness extraction with and without the sampled sub-block hashing method according to an example embodiment applied.
FIG. 4A shows a comparison of key rate per signal sent versus the number of sampled subblocks. The dashed line represents a target key rate per signal of 0.5. "Full” refers to hashing the sifted key directly, "splitting” refers to use of the sampled subblock hashing method according to an example embodiment, and "small block" refers to our running the QKD protocol for (N/Ns) rounds Ns times and performing parameter estimation and hashing for each of the Ns blocks separately.
FIG. 4B shows a comparison of key rate per unit time versus the number of sampled subblocks. The dashed lines represent the optimal Ns value, and its corresponding throughput, that achieves the target key rate per signal for the splitting (Ns = 17) method and the small-block (Ns = 4) method. "Full" refers to hashing the sifted key directly, "splitting" refers to use of our sampled subblock hashing method, and "small block" refers to our running the QKD protocol for (N/Ns) rounds Ns times and performing parameter estimation and hashing for each of the Ns blocks separately.
FIG. 5 shows results obtained from the NIST 800-22 statistical test suite for an example embodiment.
FIG. 6A shows Minimum P Value results obtained from the National Institute of Standards and Technology 800-22 statistical test suite for the concatenated output of 152.56 Mbits according to an example embodiment.
FIG. 6B shows Min Proportion results obtained from the National Institute of Standards and Technology 800-22 statistical test suite for the concatenated output of 152.56 Mbits according to an example embodiment.
FIG. 7 shows a schematic drawing illustrating a system 700 for randomness extraction for quantum cryptography according to an example embodiment.
FIG. 8 shows a flowchart 800 illustrating a method of randomness extraction for quantum cryptography, according to an example embodiment. DETAILED DESCRIPTION
A generic N -round protocol, with honest parties [or a single honest party] and an adversary typically has the following steps:
• [1] Data generation. The honest parties exchange classical and quantum information for N rounds, which could be attacked by the adversary. At the end of each round of exchange, the honest parties receive a raw bit string At, with the honest parties publicly exchanging information f, and with the adversary holding side information Et. It is assumed that At is generated independently from any memory [from previous rounds) that the honest parties possesses.
• [2] Statistical check. Honest parties assign each round of the data generation as either a test round [ 7] = 1) or a data-generation round (Ti = 0], with testing probability y. For test rounds, the honest parties announce information iff which includes Ai and compute statistisc Ci.. On the basis of the observed statistics CN, the protocol aborts if they do not fall into the set of events fl.
• [3] Additional information exchange. Additional public information can be exchanged by the honest parties, labelled Y , which is not generated in a round- by-round manner [for instance, error correction).
• [4) Sifting. Honest users discard rounds that are inconclusive [for instance, due to loss or no detection) and part of the test rounds, arriving at a shorter sifted bit string A'.
• [5) Randomness extraction. Randomness extraction is performed on the sifted bit string A' to obtain outputs = FRE(A'), where fRE is a hash function randomly chosen from a family of two-universal hash functions.
At the end of the protocol, the adversary will have information EN' = TN IN Itest)N EN, along with Y and the hash function FRE.
After randomness extraction, one ideally wants the hashed output K to be secret from the adversary. Accordingly, bounds on the penalty due to the announcements can be provided, for instance, with use of tighter min- entropy chain rules.
To ensure that (1) the quantum cryptographic protocol satisfies the finite-size effect; and (2) the hashing step remains practical, embodiments of the present invention implement a sampled sub-block hashing method to improve current hashing implementations.
In more detail, in example embodiments of the present invention, the large-input data on which randomness extraction is to be performed is randomly split (via sampling) into subblocks, and a lower bound is provided on the conditional smooth min-entropy of each subblock, noting that the correlation between different sub-blocks is considered in the entropy determination step.
In one example embodiment, for single round sampling, where the input data is reduced to one sampled sub-block, and randomness extraction is performed on that sub-block accounting for the correlation between different sampled sub-blocks, i.e. in this example embodiment between the bits randomly sampled into the one sub-block and the unsampled bits. This contrasts with discarding the unsampled bits, which would effectively introduce a large loss of entropy, as has been recognised by the present inventors.
In another example embodiment, the input data is sampled into multiple sampled sub-blocks, and randomness extraction is performed on each sub-block independently, before all the outputs are concatenated together. In this example embodiment, the method can account for the correlation between different sampled sub-blocks. Thus, the present method is operable to perform hashing on all the sub-blocks and concatenate the outputs while still preserving the overall security.
In order to demonstrate the performance of example embodiments of the present invention, a theoretical assessment is made when the hashing method according to an example embodiment is performed on a protocol satisfying certain properties and whose security can be analysed with the recent generalized entropy-accumulation theorem (GEAT), which demonstrates that the hashing method according to an example embodiment introduces only a small (linear) loss in security while providing a linear improvement in the speed of randomness extraction and maintaining the same number of secure bits obtained. It is noted that to obtain this lower bound, i.e. the entropy determination, GEAT can be replaced using other methods that are, or may become to be available for determining the entropy while accounting for the correlation between one sampled sub-block and the unsampled bits and/or between different sampled subblocks.
An example embodiment of the present invention makes use of the generalised entropy accumulation theorem (GEAT) [T. Metger, O. Fawzi, D. Sutter, and R. Renner, in 2022 IEEE 63rd Annual Symposium on Foundations of Computer Science (FOCS) (IEEE Computer Society, Denver, CO, USA, 2022), p. 844], which will be first briefly described below, using QKD as an example. Suppose that a QKD protocol can be analysed with the GEAT, with the raw string having some min-entropy (1) and where n is the total number of rounds (or signals exchanged) during the protocol, f is the min-tradeoff function present in GEAT, Ci is the test statistic, OR; is the state before the GEAT channel, is the GEAT channel, Xi is the sifted bit string, and A is the set of accepted statistics that would not trigger an abort of the protocol.
More specifically, the GEAT is used to prove the utility of example embodiments, and a brief description of GEAT is provided here. Suppose at the end of some protocol, one has the output quantum state PX NCNRNEN' which can be described as being generated by applying a sequence of channels ,MN (termed "GEAT channels"], My Rl-1El-1 -» XiRiCiEi, on some initial state PROEO (see FIG. 1 XN = Xlt ,XN typically refers to the output (e.g., raw keys in QKD], CN - C^-- , CN refers to the statistics used to select an event (e.g., whether the protocol should be aborted], Rt is the side information carried by Alice and Bob, and Et is Eve’s side information. The GEAT provides a fairly tight bound on the conditional smooth min-entropy of the output XN conditioned on the side information EN, i.e., Hmin(XN The entropy is evaluated on the state where fl c CN is a set of events. This bound is extremely useful as it is directly related to the final key length and the security parameter in quantum cryptographic protocols.
The GEAT states, that if the two conditions described below are satisfied, then
(2J with variables f , y, and p, which are independent of f , and Var(f)', Max(f) and Minjfj as the variance, maximum value, and minimum value of some affine min-trade-off function f( (q).The two conditions are:
• (1] Nonsignaling. One requires that any side information that Eve can have aboutX1;--- ,Xi-1 should already be contained in El-1, and not stored in Ri-1 and revealed in later rounds (for instance, to E]). More formally, for each GEAT channel there exists a channel Ry Ei-1 -> Et such that T where o represents the composition of the channels.
• (2] Projective reconstructability. One should be able to reconstruct statistics CN by performing a projective measurement onX* and EN, and applying a function on the outcomes. More formally, there exists a channel 7 such that
The min-trade-off function is an affine function f(q], where for all i = 1, , N , It is noted that any protocol that cannot be analyzed with the GEAT framework may still have utility if an alternative proof theory can be applied and satisfied. This includes quantum cryptography protocols that in general cannot be reduced to a sequential process that obeys the nonsignaling condition according to the GEAT.
According to example embodiments, a sampling method is considered where each round is sampled randomly, with some probability ps. In this scenario, it is possible to define an appropriate GEAT channel to compute the min-entropy Hε nin(Xs\EnS') of sub-block Xs by announcing St during the protocol and including only Xt- that are in the sampled sub-block Xs
In more detail, a sampled subblock hashing protocol is used in an example embodiment. One begins with the raw bit string AN = QQ, ..., Aw) from a cryptographic key generation module, which is understood in the art and will not be described herein. By way of example, not limitation, reference is made to description of QKD key generation modules in a recent review of protocols and implementation in [Feihu Xu, Xiongfeng Ma, Qiang Zhang, Hoi-Kwong Lo, and Jian-Wei Pan, Rev. Mod. Phys. 92, 025002 [2020]], and to description of QRNG key generation modules to a review of protocols and implementation in [Ma, X., Yuan, X., Cao, Z. et al. Quantum random number generation, npj Quantum Inf 2, 16021 (2016)]. The raw bit string AN = (A1; ..., is supposed to undergo sifting and randomness extraction, ps be the sampling probability and Ns=l/psl°& is chosen such that there areNs e MLQBJL The sampled sub-block hashing method according to an example embodiment comprises:
• (1) Sampling. For each round i e [1, TV], the honest parties generate a uniform random variable Vb which can take values vt e [1,TV$] (i.e., Vt can take values from 1 to Ns, each with probability ps). In an example embodiment, if Vt = j, it means that bitAj is "sampled" into the j th subblock, which is denoted as As., where the indices for a set Sy = {i: V,- = j} . The value of Vt is then announced to the rest of the honest parties (if necessary).
• (2) Sifting. For each subblock Sy, sifting can be performed to discard rounds that are inconclusive or part of the test rounds, leaving sifted subblocks A$.. In general, the length of these bitstrings is notfixed. Therefore, to preventan excessively long bit string from slowing the Toeplitz hashing, in a preferred example embodiment one can choose to abort if the size of any sifted subblocks As' exceeds a predetermined threshold ls vB. In practice, this aborting probability would be very small.
• (3) Randomness extraction. If the protocol according to an example embodiment does not abort, randomness extraction is performed on all the subblocks independently to yield output Kj = fRE y where fRE y are random hash functions chosen independently from a family of two-universal hash functions. For simplicity, the length of output Kj is taken to be ~l for every j . • [4] Concatenation. The final output, denoted by K = (K±, ■■■ ,KNs), is obtained by concatenation of all the individual outputs of randomness extraction on each subblock.
It is noted that when the sampled subblock hashing according to an example embodiment is applied, is additionally announced, along with the use of multiple hash functions, fRE 1 ••• fRE: Ns, and would be accessible to the adversary, which is considered in the security assessment of the example embodiment.
In the example embodiment, when multiple hashed strings are concatenated, the min-entropy of each sub-block to be computed is o account for correlations between sub-blocks. With appropriate GEAT channels announcing Xi for nonsampled rounds, the min-entropy value for each sub-block can be computed. Again, it is noted that to obtain this lower bound, i.e. the entropy determination, GEAT can be replaced using other methods that are, or may become to be available for determining the entropy while accounting for the correlation between one sampled sub-block and the unsampled bits and/or between different sampled sub-blocks.
Generally, for the security analysis demonstrating the utility of an example embodiment it is assumed that for each subprotocol, i.e. for each sub-block, the associated smooth min-entropy is of the form which accounts for correlations between the sampled raw bit strings. Since the original protocol to which the sampled sub-block hashing method according to an example embodiment is applied is GEAT-analyzable, one is able to write down GEAT channels Mi and apply the EAT by defining some min-trade-off function ffq). To construct the min-trade-off function for the sampled sub-block hashing method according to an example embodiment applied to the original protocol, one can adapt the EAT channel to output As' ( (note As' ( =± is inserted if the / th round is discarded or not included in As' ) while forwarding the information 1 and Vi j to Eve. Since only a fraction ps of the bits 4- is output as As' h the entropy and thus the min-trade-off function gain a factor of ps = 1/NS, giving the modification in the claim.
The security condition of concern is where one can guarantee the bit string K is secret from the adversary, who has access to ^ RE By introducing an intermediate state of the form rK1...Kj ® PK.+I...KNSVNE^SY^> one can apply the triangle inequality to arrive at
Since subblock hashing according to an example embodiment computes each output string Kj = fRE j , one can apply the quantum leftover-hash lemma [M. Tomamichel, C. Schaffner, A. Smith, and R. Renner, Leftover hashing against quantum side information, IEEE Trans. Inf. Theory 57, 5524 [2011]] [ M. Tomamichel and A. Leverrier, A largely self- contained and complete security proof for quantum key distribution, Quantum 1, 14 [2017]] on each subblock. Therefore, one could set to achieve the required security level, where the min-entropy is evaluated on p , and refers to the set of hash functions used except for fRE , .. J To determine the error, the important quantity to compute is the min-entropy. One can begin by lower-bounding the min-entropy using the data-processing inequality, since Kt = fRE,t(_As' '), and /l^can be computed from As ,
where the second inequality stems from the fact thatF^A is independent of all other terms in the min-entropy.
To analyze the min-entropy with the GEAT, one has to remove the conditioning on Y , which, by definition, cannot be expressed as being generated round by round. Depending on the nature of Y, there are many ways to remove the conditioning with the min-entropy chain rule. Here, one possible efficient method is described by way of example, if Y is generated by blocks according to an example embodiment. Suppose Yj is generated from the information in rounds Sj only, i.e., Yj = g (AS' .,IS^. Then one could remove the conditioning with where = Uj: S^. The second inequality makes use of the property that conditioning does not increase min-entropy, the third inequality uses the data-processing inequality on Yt for i #= j , since LQ?JJ and Is. (in EN' ) are present, and the final inequality uses the chain rule. For consistency, however, the min-entropy expansion in the main text is used in the following analysis (incurs a penalty log2|Y|) but it will be appreciated that it is straightforward to generalize the result to the more-efficient case highlighted here.
Focusing now on the min-entropy term ( ;| J ) which is now amenable to GEAT analysis, one can define the channel M with E
• (1] Implement EAT channel which maps from R^ E- Ao RjEi'A'iCi [2] Generate a uniformly random variable Vt (step 1 of sample and hash],
[3] Define
• (4) Announce the values of A$ p for k = j + 1, , Ns and Vb i.e., they will be known to the adversary.
• (5) Trace out A'i.
Applying this channel yields the state S t the end of the protocol according to an example embodiment, with E,,- = kwAt, +i ... As' E^ being known to the adversary. To show that this is a valid EAT channel, one must check for the two conditions of projective reconstructability and nonsignaling discussed above.
The statistics generated in | , is no different from that in Moreover, since Ci is generated from (/test)w ; which includes A, by assumption, the same generation method can be used in analyzing t . Therefore, using 7 from the projective reconstructability of the M, EAT channel, one can create 7', which acts on the expanded It is clear that ?' □ satisfies projective reconstructability.
The proof of nonsignaling for an example embodiment relies on the assumption that the original EAT channel Mi is nonsignaling and that A' is generated independently of any memory, i.e., Rl t of the EAT channel. Because of this independence, one could, in general, split the EAT channel Mt into two parts. The first part E-^ -> A'iQlEl is responsible for the generation of A', taking only inputs E/_1 since it is independent of A', with modifications to form Et and possible intermediate systems Q, generated. The second part E2: Ai-tEjA'Qi -> RLE'A'LCL includes the use of R^ to arrive at the final output systems of the M; channel. Since the first part does not depend on R^, the nonsignaling condition will depend only on the second part, i.e., that there exists R': A'iQiEl -> E/ such that TrA>R. □
Consider the channel M/ described above, which can be written as a series of channels, M where describes the generation of Vi and the sampling step. The order of the maps and £2 is interchangeable, as neither acts to alter the systems that are inputs to the other channel. Therefore, one has where the second equality traces out the output As' t, the fourth equality applies the nonsignaling property, and the final equality swaps the order of the trace over since neither c,1 nor /t . * v r\ c ' " n ., c acts on /?,- ,. Noting that/R, 1 = /? *,' ° g ri; , * v ; Ac , □
1 d7+l,t 1 d7+l,t ' ’ 'n ^ cNS’1
E^ maps Ei^ to Ei = ViE-As'l~^ — As'l~^As' .+i. -- AS'N , one can see that the channel ,M/ is nonsignaling.
With M/ as a valid EAT channel, one can now consider the min-trade-off function to use before the GEAT is applied. In this case, the min-trade-off function has to satisfy with where
The von Neumann entropy can be simplified by expansion in terms of different vL values. When v; * j, As' t =±, which has entropy 0 since it is a fixed value. When v, = ;, AS'j l = A'i and AS'k ; =± for k>j. Since vt is fixed as j, with As' t for k>j containing no information on A'i, the conditional entropy can be reduced to H^A'i\E'''E^). Since ••• are not used in channel M( 7, they do not give any information on A't and one can obtain H Moreover, since the generation of A' and the generation of Ei' in M/ are fully determined by the channel .M,, the states to be optimized over reduce to 2i(q), thus yielding the requirement on the min-trade-off function where the factor ps is due to the probability of vi=j. From the GEAT-analyzable original protocol, there exists a min-trade-off function f(q) that lower-bounds the right-hand side without the factor ps. Therefore, f'(q)=psf(q) is a valid min-trade-off function.
Applying the GEAT using this min — trade — off function, along with EAT channels one arrives at the result in the main text. Since this result applies to all min- entropy terms in Eq. (3) one has (13).
If the smoothing parameters aressm ; = £“ sm set to be equal for all rounds, £sm j = sm , the error reduces to
(14).
The present invention is demonstrated by employing it on the standard BB84 QKD protocol according to an example embodiment, with n = 4 X 109 number of rounds, assuming a phase and bit error rate of 1%. Optimising the key and test basis probabilities over a range of values of ps using the GEAT, FIG. 2 shows a plot of the key rate per signal sent against the number of sampled sub-blocks (i.e., 1/ps), with and without the sampled sub-block hashing method according to an example embodiment applied. Additionally, FIG. 3 shows a plot of the expected key rate per unit time of randomness extraction with and without the sampled subblock hashing method according to an example embodiment applied. From FIGS. 2 and 3, it is clear that using the sampled sub-block hashing method according to an example embodiment, there is a small loss in key rate per signal sent, but the speed up that is obtained is large.
To illustrate the effects of the sampled subblock hashing method according to another example embodiment, a BBM92 protocol is considered with N=109 rounds and secrecy parameter E,C=1X10A The optimized testing probability px value for direct hashing is 0.0176, which is rounded to 0.02. This method of choosing px corresponds to the scenario where an optimized setup has already been achieved and one would like to modify the postprocessing step to increase the throughput. From FIG. 4, it is clear that with use of the sampled sub-block hashing method according to an example embodiment, there is also a small loss in key rate per signal sent, but a linear speedup is obtained. The loss in key rate from sampling, as shown in FIG. 4A, is expected, and is a result of the penalty from sampling. Interestingly, despite the loss, there is an advantage over starting with a smaller block. This may be because the analysis of the sampled sub-block hashing method according to an example embodiment uses the overall statistics of N rounds to estimate the min-entropy of each subprotocol, whereas the small block scenario only uses each protocol’s statistics of N/Ns rounds. In addition, as the time required scales more favorably for lower input size (based on the clock cycle equation obtained), a shorter subblock would increase the generation rate despite a loss in key length, as seen in FIG. 4B.
A hardware implementation of a method according to an example embodiment is performed with simulated datasets. ps = 0.05 was chosen, because at that point, the loss in extractable key length is small, but the increase in execution speed is large. In this example embodiment, the method is implemented on a Xilinx ZCU 111 evaluation board and the results are tabulated below. First, Table 1 presents the results of Toeplitz hashing on large block sizes for the example BB84 protocol, without sampling. As expected, when the input size of randomness extraction increases, the speed of the randomness extraction decreases rapidly. This is because to generate even a single bit of output, a larger number of bits needs to be processed first.
Table 2 presents the results of Toeplitz hashing on large block sizes for the example BB84 protocol, utilizing the method according to an example embodiment. Comparing Tables 1 and 2, it is clear that despite having a larger input size, randomness extraction with the method according to an example embodiment has an execution speed that is faster by almost an order of magnitude. This shows that the method according to an example embodiment allows one to satisfy the finite-size effect without too heavy a penalty on the speed of execution.
The results in Table 2 are for single round sampling, where the input data is reduced to 1 sampled sub-block, and randomness extraction is performed on that sub-block. In the next setting according to another example embodiment, a concatenation approach is considered, where the input data from the BB84 example protocol is sampled into three different subblocks, by way of example, not limitation, and randomness extraction is performed on each sub-block independently, before all the outputs are concatenated together. The results are presented in Table 3.
Comparing the results from Tables 2 and 3, there is a further improvement in terms of speed when the method is performed with multiple sub-blocks. This is because the time taken for sampling, which only needs to be executed once, is averaged over a greater output size For a further assessment of an implementation of an example embodiment, the concatenated output of approximately 55.728 Mbit is fed into the NIST 800-22 statistical test suite [A. Rukhin, J. Soto, J. Nechvatal, E. Barker, S. Leigh, M Levenson, D. Banks, A. Heckert, and J. Dray, NIST 800-22 A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications (2010).39] to test for uniformity The results are shown in FIG. 5.
A P-value greater than 0.0001 indicates that the sequence under test passes that particular test for uniformity. From FIG. 5, the concatenated output passes all the tests in the test suite. Tn addition, as the security is maintained by the above-described theoretical model, it can be confidently certified that the output is uniform and secret, even from the adversary
In another implementation, again ps = 0.05 is chosen, because at that point the loss in extractable key length is small but the increase in execution speed is large. A Xilinx ZCU111 evaluation board is used as implementation platform and the results of the BBM92 example protocol are presented in Table 4. As expected, when the input size of randomness extraction increases, the speed of the randomness extraction decreases linearly. This is because to generate even a single bit of output, a larger number of bits needs to be processed first. From comparison between direct hashing (data labelled “traditional method" in table 4) and the example embodiment, the method according to the example embodiment has an execution speed that is faster by almost 20 times. This shows that the example embodiment allows one to satisfy the finite-size effect without too great a penalty on speed. In particular, for the cases where the input size is 960.40 and 1920 Mbits, traditional Toeplitz hashing would have taken approximately 413 and 1695 h, respectively, but our method reduced the timing to 20.73 and 84.99 h, respectively, therefore greatly improving the practicality of large-input hashing.
For further assessment of an implementation according to an example embodiment, , the concatenated output of 152.56 Mbits is fed into the National Institute of Standards and Technology 800-22 statistical test suite [A. Rukhin, I. Soto. l. Nechvatal. E. Barker. S. Leigh, M, Levenson. D. Banks. A. Heckert, and I. Dray, NIST 800-22 A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications C20101.1 to test for uniformity. In FIG. 6A, the P values of each individual test in the test suite are shown. A P value greater than 10‘4 indicates that the sequence under test passes that particular test for uniformity. Additionally, in FIG. 6B, the proportion result of each individual test are shown. The proportion result shows the proportion of samples from the sequence under test that passes that particular test. A proportion greater than 0.9657, illustrated by the horizontal line 500 in FIG. 5B, indicates that the sequence under test passes that particular test for uniformity. The combined results show that the concatenated output passes all the tests in the test suite. In addition, as the security is guaranteed by the theoretical model described above, it can again be confidently certified that the output is uniform and secret, even from the adversary.
Table 5 presents the resource utilisation results from the implementation of the method according to an example embodiment on the ZCU111 evaluation kit. The utilisation of lookup table (LUT), LUTRAM, flip-flop (FF), block RAM (BRAM), and digital signal-processing (DSP) blocks are low. The low utilisation percentage also indicates that the entire project can fit on platforms which are smaller and have lower cost.
As described above, the method according to an example embodiment improves the speed of hashing while accounting for finite-size effects that impose the requirement of large block sizes. The operations required are advantageously straightforward to implement, and the overall security of the entire process is information-theoretic and preserved. Additionally, the method according to an example embodiment can also be implemented on resource-constrained platforms due to its low resource utilization.
FIG. 7 shows a schematic drawing illustrating a system 700 for randomness extraction for quantum cryptography according to an example embodiment, comprising a sampling module 702 configured to sample a cryptographic key to generate one or more sub-blocks; an entropy module 704 configured to determine a lower bound of the entropy in each sub-block, wherein the determining of the lower bound comprises consideration of correlations between each subblock and unsampled bits of the cryptographic key and/or other sub-blocks, and a hashing module 706 configured to hash each sub-block for randomness extraction on each sub-block.
The cryptographic key may comprise either a raw key or a sifted key.
The sampling module 702 may be configured to sample the cryptographic key into the one or more sampled sub-blocks in a random manner based on a pre-determined probability.
The system 700 may comprise a sifting module 708 configured to sift the cryptographic key or to sift the one or more sampled sub-blocks.
The sampling module 702 may be configured to apply a thresholding on the length of bit strings representing the respective sub-blocks and to abort the method if the length of the bit string for any sub-block exceeds a predetermined threshold.
The system 700 may comprise a concatenation module configured to concatenate the hashed sub-blocks to generate a secret key.
The entropy module 704 may be configured to determine the lower bound based on the generalized entropy -accumulation theorem. FIG. 8 shows a flowchart 800 illustrating a method of randomness extraction for quantum cryptography, according to an example embodiment. At step 802, a cryptographic key is sampled to generate one or more sub-blocks. At step 804, a lower bound of the entropy in each sub-block is determined, wherein the determining of the lower bound comprises consideration of correlations between each sub-block and unsampled bits of the cryptographic key and/or other sub-blocks. At step 806, each sub-block is hashed for randomness extraction on each subblock.
The cryptographic key may comprise either a raw key or a sifted key.
The step of sampling the raw key into the one or more sub-blocks may be performed in a random manner based on a pre-determined probability.
The method may comprise sifting the cryptographic key or sifting the one or more sampled sub-blocks.
The method may comprise applying a thresholding on the length of bit strings representing the respective sub-blocks and aborting the method if the length of the bit string for any sub-block exceeds a predetermined threshold.
The method may comprise concatenating the hashed sub-blocks to generate a secret key.
The step of determining the lower bound may be based on the generalized entropyaccumulation theorem.
In one embodiment, a method of performing quantum cryptography between two or more parties is provided, the method comprising announcing a uniform random variable Vt e [1, Als] identifying which bit of the cryptographic key is sampled into which sub-block.
The method may use the system for randomness extraction for quantum cryptography of any example embodiment described herein.
The method may comprise using the method for randomness extraction for quantum cryptography of any example embodiment described herein.
Industrial applications of example embodiments
The method according to example embodiments can be useful in all quantum cryptographic protocols. The speed up obtained, together with accounting for finite-size security, are useful features to have in, for example, both QKD and QRNG implementations. As such, the method according to example embodiments can be utilised as a general approach for randomness extraction in both QKD and QRNG systems.
The method according to example embodiments are believed to be especially useful in the measurement-device-independent scheme, as well as the device-independent protocols. This is because such protocols require a large block size to account for finite-size effects, as described herein.
In addition, chip-based implementations of QKD and QRNG systems, which are of keen interest to the industry, can also greatly benefit from the method according to example embodiments. This is because on-chip systems have tight resource-constrains, which would lead to a decrease in throughput due to the finite-size effect. The method according to example embodiments can resolve this issue, allowing finite-size effects to be addressed for on-chip systems without heavy penalties to the speed, with the addition of non-complex operations.
Aspects of the systems and methods described herein, such as the sampling module, the entropy module, the hashing module, and the concatenation module described herein, including in the claims, may be implemented on computing device(s), including cloud-based computing device(s) and/or Internet-of-Things computing device(s), for example as functionality programmed into any of a variety of circuitry, including programmable logic devices (PLDs), such as field programmable gate arrays (FPGAs), programmable array logic (PAL) devices, electrically programmable logic and memory devices and standard cell-based devices, as well as application specific integrated circuits (ASICs). Some other possibilities for implementing aspects of the system include: microcontrollers with memory (such as electronically erasable programmable read only memory (EEPROM)), embedded microprocessors, firmware, software, etc. Furthermore, aspects of the system may be embodied in microprocessors having software-based circuit emulation, discrete logic (sequential and combinatorial), custom devices, fuzzy (neural) logic, quantum devices, and hybrids of any of the above device types. Of course, the underlying device technologies may be provided in a variety of component types, e.g., metal-oxide semiconductor field-effect transistor (MOSFET) technologies like complementary metal-oxide semiconductor (CMOS), bipolar technologies like emitter- coupled logic (ECL), polymer technologies (e.g., silicon-conjugated polymer and metal- conjugated polymer-metal structures), mixed analog and digital, etc.
The various functions or processes disclosed herein may be described as data and/or instructions embodied in various computer-readable media, in terms of their behavioral, register transfer, logic component, transistor, layout geometries, and/or other characteristics. Computer-readable media in which such formatted data and/or instructions may be embodied include, but are not limited to, non-volatile storage media in various forms (e.g., optical, magnetic or semiconductor storage media) and carrier waves that may be used to transfer such formatted data and/or instructions through wireless, optical, or wired signaling media or any combination thereof. When received into any of a variety of circuitry (e.g. a computer), such data and/or instruction may be processed by a processing entity (e.g., one or more processors).
It will be appreciated by a person skilled in the art that numerous variations and/or modifications may be made to the present invention as shown in the specific embodiments without departing from the spirit or scope of the invention as broadly described. The present embodiments are, therefore, to be considered in all respects to be illustrative and not restrictive. Also, the invention includes any combination of features described for different embodiments, including in the summary section, even if the feature or combination of features is not explicitly specified in the claims or the detailed description of the present embodiments.
In general, in the following claims, the terms used should not be construed to limit the systems and methods to the specific embodiments disclosed in the specification and the claims but should be construed to include all processing systems that operate under the claims.
Accordingly, the systems and methods are not limited by the disclosure, but instead the scope of the systems and methods is to be determined entirely by the claims.
Unless the context clearly requires otherwise, throughout the description and the claims, the words "comprise," "comprising," and the like are to be construed in an inclusive sense as opposed to an exclusive or exhaustive sense; that is to say, in a sense of "including, but not limited to." Words using the singular or plural number also include the plural or singular number respectively. Additionally, the words "herein," "hereunder," "above," "below," and words of similar import refer to this application as a whole and not to any particular portions of this application. When the word "or" is used in reference to a list of two or more items, that word covers all of the following interpretations of the word: any of the items in the list, all of the items in the list and any combination of the items in the list.

Claims

1. A system for randomness extraction for quantum cryptography, comprising a sampling module configured to sample a cryptographic key to generate one or more sub-blocks; an entropy module configured to determine a lower bound of the entropy in each subblock, wherein the determining of the lower bound comprises consideration of correlations between each sub-block and unsampled bits of the cryptographic key and/or other sub-blocks; and a hashing module configured to hash each sub-block for randomness extraction on each sub-block.
2. The system of claim 1, wherein the cryptographic key comprises either a raw key or a sifted key.
3. The system of claims 1 or 2, wherein the sampling module is configured to sample the cryptographic key into the one or more sampled sub-blocks in a random manner based on a pre-determined probability.
4. The system of any one of the preceding claims, comprising a sifting module configured to sift the cryptographic key or to sift the one or more sampled sub-blocks.
5. The system of any one of the preceding claims, wherein the sampling module is configured to apply a thresholding on the length of bit strings representing the respective subblocks and to abort the method if the length of the bit string for any sub-block exceeds a predetermined threshold.
6. The system of any one of the preceding claims, comprising a concatenation module configured to concatenate the hashed sub-blocks to generate a secret key
7. The system of any one of the preceding claims, wherein the entropy module is configured to determine the lower bound based on the generalized entropy-accumulation theorem.
8. A method of randomness extraction for quantum cryptography, comprising the steps of: sampling a cryptographic key to generate one or more sub-blocks; determining a lower bound of the entropy in each sub-block, wherein the determining of the lower bound comprises consideration of correlations between each sub-block and unsampled bits of the cryptographic key and/or other sub-blocks; and hashing each sub-block for randomness extraction on each sub-block.
9. The method according to claim 8, wherein the cryptographic key comprises either a raw key or a sifted key.
10. The method according to claims 8 or 9, wherein the step of sampling the raw key into the one or more sub-blocks is performed in a random manner based on a pre-determined probability.
11. The method of any one of claims 8 to 10, comprising sifting the cryptographic key or sifting the one or more sampled sub-blocks.
12. The method of any one of claims 8 to 11, comprising applying a thresholding on the length of bit strings representing the respective sub-blocks and aborting the method if the length of the bit string for any sub-block exceeds a predetermined threshold.
13. The method of any one of claims 8 to 12, comprising concatenating the hashed subblocks to generate a secret key.
14. The method of any one of claims 8 to 13, wherein the step of determining the lower bound is based on the generalized entropy-accumulation theorem.
15. A method of performing quantum cryptography between two or more parties, the method comprising announcing a uniform random variable Vt e [1, Ms] identifying which bit of the cryptographic key is sampled into which sub-block.
16. The method of claim 15, using the system for randomness extraction for quantum cryptography of any one of claims 1 to 7.
17. The method of claims 15 or 16, comprising using the method for randomness extraction for quantum cryptography of any one of claims 8 to 14.
EP24797570.9A 2023-04-24 2024-04-24 SYSTEM AND METHOD FOR RANDOM DISTRIBUTION EXTRACTION AND METHOD FOR PERFORMING QUANTUM CRYPTOGRAM Pending EP4706203A4 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
SG10202301126V 2023-04-24
PCT/SG2024/050267 WO2024225978A1 (en) 2023-04-24 2024-04-24 System and method for randomness extraction and method of performing quantum cryptography

Publications (2)

Publication Number Publication Date
EP4706203A1 true EP4706203A1 (en) 2026-03-11
EP4706203A4 EP4706203A4 (en) 2026-03-25

Family

ID=93257353

Family Applications (1)

Application Number Title Priority Date Filing Date
EP24797570.9A Pending EP4706203A4 (en) 2023-04-24 2024-04-24 SYSTEM AND METHOD FOR RANDOM DISTRIBUTION EXTRACTION AND METHOD FOR PERFORMING QUANTUM CRYPTOGRAM

Country Status (3)

Country Link
EP (1) EP4706203A4 (en)
CN (1) CN120958772A (en)
WO (1) WO2024225978A1 (en)

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115361127B (en) * 2022-08-23 2024-10-18 中国科学院计算技术研究所 A quantum random number post-processing method and device

Also Published As

Publication number Publication date
EP4706203A4 (en) 2026-03-25
WO2024225978A1 (en) 2024-10-31
CN120958772A (en) 2025-11-14

Similar Documents

Publication Publication Date Title
Pinkas et al. Phasing: Private set intersection using permutation-based hashing
Daemen et al. Full-state keyed duplex with built-in multi-user support
Thakur et al. DES, AES and Blowfish: Symmetric key cryptography algorithms simulation based performance analysis
Prasetyo et al. An implementation of data encryption for Internet of Things using blowfish algorithm on FPGA
US8625642B2 (en) Method and apparatus of network artifact indentification and extraction
Gaži et al. The exact PRF-security of NMAC and HMAC
CN110299988B (en) Method and device for detecting anti-attack capability of lightweight block cipher algorithm
Alawida et al. A new hash function based on chaotic maps and deterministic finite state automata
Yang et al. One-way hash function construction based on chaotic map network
Madani et al. Digital Implementation of an Improved LTE Stream Cipher Snow‐3G Based on Hyperchaotic PRNG
Shi et al. A light-weight white-box encryption scheme for securing distributed embedded devices
Partheeban et al. Dynamic key dependent AES S-box generation with optimized quality analysis
CN111191253B (en) A data encryption combination method
Hammood et al. RC4 stream cipher with a random initial state
Zaki et al. 4G Network Security Algorithms: Overview.
Rao et al. FPGA implementation of combined S-Box and InvS-Box of AES
EP4706203A1 (en) System and method for randomness extraction and method of performing quantum cryptography
Zhang et al. A parallel hash function with variable initial values
Krause et al. Reducing the space complexity of BDD-based attacks on keystream generators
Anbumani et al. Area-efficient vlsi architecture for advanced encryption standard
Dimitrova et al. Security analysis of lightweight cryptographic algorithms
Taher et al. Hardware implementation of the serpent block cipher using FPGA technology
Morawiecki et al. Parallel authenticated encryption with the duplex construction
Rajashekarappa et al. Study on cryptanalysis of the tiny encryption algorithm
Lakshmanan et al. Security and robustness enhancement of existing Hash algorithm

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20250919

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR

A4 Supplementary search report drawn up and despatched

Effective date: 20260220

RIC1 Information provided on ipc code assigned before grant

Ipc: H04L 9/08 20060101AFI20260216BHEP

Ipc: G06F 7/58 20060101ALI20260216BHEP

Ipc: H04L 45/7453 20220101ALI20260216BHEP