WO2011059306A2 - A secure key distribution protocol based on hash functions utilizing quantum authentication channel (kdp-6dp) - Google Patents

A secure key distribution protocol based on hash functions utilizing quantum authentication channel (kdp-6dp) Download PDF

Info

Publication number
WO2011059306A2
WO2011059306A2 PCT/MY2010/000190 MY2010000190W WO2011059306A2 WO 2011059306 A2 WO2011059306 A2 WO 2011059306A2 MY 2010000190 W MY2010000190 W MY 2010000190W WO 2011059306 A2 WO2011059306 A2 WO 2011059306A2
Authority
WO
WIPO (PCT)
Prior art keywords
receiver
sender
quantum
key distribution
hash functions
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/MY2010/000190
Other languages
French (fr)
Other versions
WO2011059306A3 (en
Inventor
Mohammed Munther A. Majeed
Khalid A. S. Al-Khateeb
Magdy M. Saeb
Mohamed Ridza Wahiddin
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Mimos Bhd
Original Assignee
Mimos Bhd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Mimos Bhd filed Critical Mimos Bhd
Publication of WO2011059306A2 publication Critical patent/WO2011059306A2/en
Publication of WO2011059306A3 publication Critical patent/WO2011059306A3/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0852Quantum cryptography
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3236Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions

Definitions

  • the present invention relates generally to a method for a secure key distribution protocol based on hash functions utilizing quantum authentication channel.
  • Key distribution is a fundamental process in cryptography applications either in symmetric or asymmetric ciphers.
  • symmetric ciphers one usually resorts to a courier-based key exchange or in some cases quantum key distribution is used.
  • a schema for using hash functions as a medium for key exchange in both symmetric and asymmetric cipher allows the data to be encrypted and decrypted in a secure form.
  • Patent No US 5729608 discloses a method and system for providing secure authenticated cryptographic key distribution in a communication system wherein having properties similar to a Two-Party Authentication Protocol.
  • the prior article is distinguished from the present invention in that it only teaches a protocol of key distribution and authentication that is similar to the Two-Party Authentication Protocol.
  • the protocol does not teach any method of key distribution using hash functions and a random string. It has a disadvantage in that it may not protect against any eavesdroppers and other data attacks.
  • the present invention allows the sender and/or receiver to detect any data transmission attack if there are any occurrences of such trespassing.
  • the message passes through several encryption and character authentication processes that are not available in the prior art above. Therefore, the present invention has disclosed a novel protocol of key distribution based on hash functions and utilizing an authentication channel for the enhancement of security in key distribution.
  • the present invention seeks to address the above-mentioned disadvantages over the prior arts by promoting novel and inventive protocol generate a secure key distribution based on hash functions and utilizing quantum authentication channel.
  • the present invention introduces high security and reliability in preserving the transmission of secure message and data as compared to prior arts.
  • One object of the invention is to provide a method for a secure key distribution protocol based on hash functions utilizing a quantum authentication, channel.
  • the method comprises authenticating a receiver using quantum authentication channel and distributing secure key from the sender to the receiver by encrypting message using hash functions.
  • Authenticating the receiver using quantum authentication channel further comprises preparing six quantum states at a sender, sending two quantum states to the receiver, flipping the quantum states at the receiveri sending the flipped quantum states to the sender and validating the quantum states at the sender.
  • the quantum authentication channel is an out-of-band channel and comprises a free space or optical fiber.
  • the two quantum states comprise sending two qubits.
  • Another object of the invention is where flipping the quantum states comprises using one of four operators of /, X, iY or Z and, validating the quantum states that includes testing forward and backward paths of the quantum channel.
  • a further object of the present invention is where the hash functions includes selected hash or a cascade of hash functions and shared secret keys and preferably, the secure key comprises either first mode of key distribution using random string between the sender and the receiver; or second mode of key distribution using one string at sender station, and third mode of key distribution using one string generated, message encryption and concatenation at sender station, and send to receiver station to get the value of j for driving the hash cascade selection and get the key and massage.
  • FIG. 1 is data flow of a secure key distribution protocol based on hash functions utilizing quantum authentication channel using deterministic six state protocol (KDP-6DP).
  • FIG. 2 is a flow chart of quantum authentication process using quantum authentication channel and key distribution based on hash functions.
  • FIG. 3 Is a flow chart of a first mode of key distribution using random string between a sender and a receiver.
  • FIG. 4 is a flow chart of a second mode of key distribution using one string generated at a sender.
  • FIG. 5 is a flow chart of a third mode of key distribution using one string generated, message encryption and concatenation at a sender, and send to receiver station to get the value of j for driving the hash cascade selection and get the key and massage.
  • the present invention relates to a method for a secure key distribution protocol based on hash functions and utilizing quantum authentication channel.
  • this specification will describe the present invention according to the preferred embodiments of the present invention. However, it is to be understood that limiting the description to the preferred embodiments of the invention is merely to facilitate discussion of the present invention and it is envisioned that those skilled in the art may devise various modifications and equivalents without departing from the scope of the appended claims.
  • the method for a secure key distribution protocol comprises authenticating (210) a receiver using quantum authentication channel and distributing (220) secure key from sender to the receiver by encrypting message using hash functions (222).
  • Authenticating the receiver using quantum authentication channel further comprises preparing six quantum states at a sender (212), sending two quantum states to the receiver (214), flipping the quantum states at the receiver (216), sending the flipped quantum states to the sender (216), and validating the quantum states at the sender (218).
  • FIG. 1 depicts a flow data diagram of a secure key distribution protocol based on hash functions utilizing six-state quantum authentication channel (100).
  • the sender prepares two qubits (144) rather than one of the six states given by equations (1), (2), and (3) wherein the equations as shown below:
  • the sender delivers the two qubits to the receiver station (120) through quantum authentication channel (130), wherein the quantum channel consists of free space or optical fiber.
  • the quantum channel is an out-of-band channel wherein eavesdropper or any other data attacks may not intercept. This channel provides security and confidentiality of the characters transmitted from the sender (140) to the receiver (120).
  • the receiver (120) Upon receiving the two qubits, the receiver (120) then performs qubits flipping process (124) by operating the qubits with one of the four operators /, X, FY or Z. This would result in zero, one or two qubits being flipped, as shown in Table 1 below.
  • Table 1 shows that the possible combinations of the qubits send back by the receiver (120), the operations on the qubits and the qubits flipping process (124) as result of the measurement by the receiver (120).
  • the flipped qubits are resent to the sender (140) to be measured in the same basis where they were prepared in, thus letting the sender (140) decide deterministically how many qubits had been flipped by the receiver (120).
  • the receiver (120) resends both the flipped qubits to the sender (140) to re- measure the flipped qubits.
  • the operators chosen by the receiver (120) or sender (140) are the same as they expect the outcomes of their measurement to be correlated on both the forward and backward paths. Every deviation from this anticipated scenario is considered an error. If the detected errors are below a certain security threshold, established in advance by the sender (140) and receiver (120), the communication goes on with the usual error correction and privacy amplification stages. However, if the security threshold is transcended, the whole communication aborts.
  • sender (140) and receiver (120) forfeit the run to perform quantum channel control.
  • the sender (140) and receiver (120) test the forward and backward paths of the channel with a procedure equivalent to the one adopted in BB84 protocol.
  • the receiver (120) Upon receiving the two qubits from sender (140), the receiver (120) makes a projective measurement of the two qubits along a basis randomly chosen among x, y ox z .
  • the sender (140) authenticates the receiving part is the designated receiver (120).
  • sender (140) when sender (140) sends qubits in thex, y combination by choosing the states +) and
  • sender (140) authenticates that the designated receiver, also if it results in the only state ⁇ x +) +)) flipped, the operator used is iY (X).
  • the sender (140) proceeds with message encryption (142) at his/her particular station (140).
  • the hash functions (142,122) wherein consists of at least selected hash cascade of two hash functions is used to cipher and decipher the message.
  • the ciphered message is transmitted through classical channel or the Internet (110).
  • the sender (140) and receiver (120) authentication which has previously performed in the quantum channel, the message may be straightforwardly delivered to the legitimate receiver.
  • the encrypted message is then transmitted to the receiver station (140) for the receiver to decrypt (122) and retrieve the message.
  • the key distribution protocol is performed by atomic actions as in Table 2 by the sender and the receiver
  • the figure explains the basis of the present invention pursuant to FIG. 2 of a protocol to generate a secure key distribution based on has functions utilizing quantum authentication channel (200).
  • the sender prepares six quantum states (212) and sends two quantum states (214) to the receiver.
  • the receiver then flips the states and sends (216) to the sender to check and compare (218) whether all states corresponds with what the receiver has flipped. This process continues with its forward and backward paths until the measurement by the receiver and the sender corresponds. If the flipped state does not correspond, the process restarts from the first stage of preparation of the six quantum states (212). This is to ensure that the receiver is a legitimate receiver.
  • FIG. 3 depict the first mode of key distribution by using random string (300) between a sender, Alice and a receiver Bob.
  • Ks S A or S B (340, 318) where Ks is the sub-key used only for verification.
  • L the required key length pointer field given by ⁇ . That is L S A. B ⁇ n K .
  • First n bit is used as the sub-key Ks and the bits of the secret field, in this sub-key, as a pointer to the hash function is utilized. The size of Ks is taken the same as the length of the smaller string.
  • both Alice (348) and Bob (310) exchange the sub-key of KSA to Bob (338) and KSB to Alice (320) to verify its correctness and that no transmission errors occurred while exchanging S A and S B .
  • Ks an initial value (h 0 ) to a pseudo random number generator (PNRG)
  • PNRG pseudo random number generator
  • the initial vector (IV) of the hash h is also part of this shared secret.
  • This set of constants and the vector IV can be generated from a physical device acting as a true random number generator and stored for further use. This addition of random variables to the computation of the pad using hash function tends to approximate the behavior of a true random number generator. The values of the constants and the vector IV should be changed regularly, however not for every session.
  • the size of the required key (K) is determined by n,
  • Alice (348) or Bob (310) can select a different hash every time a new session is started.
  • the hash is selected from a value in a secret field of the sub-key Ks.
  • FIG. 4 shows a flow chart of a second mode of key distribution using one string generated at a sender, Alice station (400).
  • Alice generates string S A (430) and sends S A to Bob (428).
  • Bob waits (412) without generating his own string.
  • Both Alice (432) and Bob (410) read the value of j (426, 416) that is the pointer to the type of hash to be employed.
  • the obtained key is encrypted (422, 420) in Alice (432) and Bob (410) stations by using hash functions and transmitted to each other for message retrieval.
  • the value of j may be used to choose random combinations of two cascades hash function stored.
  • FIG. 5 shows a flow chart of third mode of key distribution (one shot) using one string generated, message encryption and concatenation at sender's station and sent to the receiver, Bob station for message retrieval (500).
  • Bob receives S A C M (522) to get j (Vj) from S A (524) and performs ( , ⁇ , ⁇ , S A ) (526) to generate a new key.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Physics & Mathematics (AREA)
  • Electromagnetism (AREA)
  • Theoretical Computer Science (AREA)
  • Optical Communication System (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

A method for a secure key distribution protocol based on hash functions utilizing quantum authentication channel (KDP-6DP) (200), comprising authenticating (210) a receiver using quantum authentication channel and distributing (220) secure key from sender to the receiver by encrypting message using hash functions (222). Authenticating the receiver using quantum authentication channel further comprises preparing six quantum states at a sender (212), sending two quantum states to the receiver (214), flipping the quantum states at the receiver (216), sending back the flipped quantum states to the sender (216), and validating the quantum states at the sender (218).

Description

A SECURE KEY DISTRIBUTION PROTOCOL BASED ON HASH FUNCTIONS UTILIZING QUANTUM AUTHENTICATION CHANNEL (KDP-6DP)
FIELD OF INVENTION
The present invention relates generally to a method for a secure key distribution protocol based on hash functions utilizing quantum authentication channel.
BACKGROUND ART
Key distribution is a fundamental process in cryptography applications either in symmetric or asymmetric ciphers. In symmetric ciphers, one usually resorts to a courier-based key exchange or in some cases quantum key distribution is used. On the other hand, a schema for using hash functions as a medium for key exchange in both symmetric and asymmetric cipher allows the data to be encrypted and decrypted in a secure form.
Patent No US 5729608 (Janson et al.) discloses a method and system for providing secure authenticated cryptographic key distribution in a communication system wherein having properties similar to a Two-Party Authentication Protocol. However, the prior article is distinguished from the present invention in that it only teaches a protocol of key distribution and authentication that is similar to the Two-Party Authentication Protocol. The protocol does not teach any method of key distribution using hash functions and a random string. It has a disadvantage in that it may not protect against any eavesdroppers and other data attacks. The present invention allows the sender and/or receiver to detect any data transmission attack if there are any occurrences of such trespassing. Moreover, the message passes through several encryption and character authentication processes that are not available in the prior art above. Therefore, the present invention has disclosed a novel protocol of key distribution based on hash functions and utilizing an authentication channel for the enhancement of security in key distribution.
In another patent which is patent No US 5515438 (Bennet et al.), that discloses a quantum key distribution. It uses non-orthogonal quantum states to distribute random information. However, the prior art has a disadvantage wherein the key is merely transmitted by applying quantum cryptography which is said to be insecure. With current advancement of technology, eavesdropping and other advance data attackers may easily intercept the transmission of data in the quantum channel. Therefore, by applying additional hash function ciphering and deciphering in quantum channel, the present invention introduces a new protocol in key distribution and message encryption towards this process.
The present invention seeks to address the above-mentioned disadvantages over the prior arts by promoting novel and inventive protocol generate a secure key distribution based on hash functions and utilizing quantum authentication channel. The present invention introduces high security and reliability in preserving the transmission of secure message and data as compared to prior arts.
SUMMARY OF INVENTION
One object of the invention is to provide a method for a secure key distribution protocol based on hash functions utilizing a quantum authentication, channel. The method comprises authenticating a receiver using quantum authentication channel and distributing secure key from the sender to the receiver by encrypting message using hash functions. Authenticating the receiver using quantum authentication channel further comprises preparing six quantum states at a sender, sending two quantum states to the receiver, flipping the quantum states at the receiveri sending the flipped quantum states to the sender and validating the quantum states at the sender.
Preferably, the quantum authentication channel is an out-of-band channel and comprises a free space or optical fiber. Preferably, the two quantum states comprise sending two qubits.
Another object of the invention is where flipping the quantum states comprises using one of four operators of /, X, iY or Z and, validating the quantum states that includes testing forward and backward paths of the quantum channel.
A further object of the present invention is where the hash functions includes selected hash or a cascade of hash functions and shared secret keys and preferably, the secure key comprises either first mode of key distribution using random string between the sender and the receiver; or second mode of key distribution using one string at sender station, and third mode of key distribution using one string generated, message encryption and concatenation at sender station, and send to receiver station to get the value of j for driving the hash cascade selection and get the key and massage.
The present invention consists of features and a combination of parts hereinafter fully described and illustrated in the accompanying drawings, it is being understood that various changes in the details may be made without departing from the scope of the invention or sacrificing any of the advantages of the present invention.
BRIEF DESCRIPTION OF THE ACCOMPANYING DRAWINGS
To further clarify various aspects of some embodiments of the present invention, a more particular description of the invention will be rendered by references to specific embodiments thereof, which are illustrated, in the appended drawings. It is appreciated that these drawings depict only typical embodiments of the invention and are therefore not to be considered limiting of its scope. The invention will be described and explained with additional specificity and detail through the accompanying drawings in which: FIG; 1 is data flow of a secure key distribution protocol based on hash functions utilizing quantum authentication channel using deterministic six state protocol (KDP-6DP).
FIG. 2 is a flow chart of quantum authentication process using quantum authentication channel and key distribution based on hash functions.
FIG. 3 Is a flow chart of a first mode of key distribution using random string between a sender and a receiver.
FIG. 4 is a flow chart of a second mode of key distribution using one string generated at a sender.
FIG. 5 is a flow chart of a third mode of key distribution using one string generated, message encryption and concatenation at a sender, and send to receiver station to get the value of j for driving the hash cascade selection and get the key and massage. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
The present invention relates to a method for a secure key distribution protocol based on hash functions and utilizing quantum authentication channel. Hereinafter, this specification will describe the present invention according to the preferred embodiments of the present invention. However, it is to be understood that limiting the description to the preferred embodiments of the invention is merely to facilitate discussion of the present invention and it is envisioned that those skilled in the art may devise various modifications and equivalents without departing from the scope of the appended claims.
The method for a secure key distribution protocol according to the present invention comprises authenticating (210) a receiver using quantum authentication channel and distributing (220) secure key from sender to the receiver by encrypting message using hash functions (222). Authenticating the receiver using quantum authentication channel further comprises preparing six quantum states at a sender (212), sending two quantum states to the receiver (214), flipping the quantum states at the receiver (216), sending the flipped quantum states to the sender (216), and validating the quantum states at the sender (218).
FIG. 1 depicts a flow data diagram of a secure key distribution protocol based on hash functions utilizing six-state quantum authentication channel (100). In the first stage, the sender prepares two qubits (144) rather than one of the six states given by equations (1), (2), and (3) wherein the equations as shown below:
Figure imgf000007_0001
:
Figure imgf000008_0001
At the sender station (140), the sender delivers the two qubits to the receiver station (120) through quantum authentication channel (130), wherein the quantum channel consists of free space or optical fiber. The quantum channel is an out-of-band channel wherein eavesdropper or any other data attacks may not intercept. This channel provides security and confidentiality of the characters transmitted from the sender (140) to the receiver (120).
Upon receiving the two qubits, the receiver (120) then performs qubits flipping process (124) by operating the qubits with one of the four operators /, X, FY or Z. This would result in zero, one or two qubits being flipped, as shown in Table 1 below.
Table 1
Sender's
iY /
Basis' Choice
2 0
x y y x 1 1
1 2 1 0
X Z Z X
2 1 1 0
y z t z y
10 01 11 00
Boolean value
Table 1 shows that the possible combinations of the qubits send back by the receiver (120), the operations on the qubits and the qubits flipping process (124) as result of the measurement by the receiver (120).
Subsequently, after performing qubits flipping process (124) by using one of the /, X, iY or Z operators, the flipped qubits are resent to the sender (140) to be measured in the same basis where they were prepared in, thus letting the sender (140) decide deterministically how many qubits had been flipped by the receiver (120).
Thereafter, the receiver (120) resends both the flipped qubits to the sender (140) to re- measure the flipped qubits. In authentication, the operators chosen by the receiver (120) or sender (140) are the same as they expect the outcomes of their measurement to be correlated on both the forward and backward paths. Every deviation from this anticipated scenario is considered an error. If the detected errors are below a certain security threshold, established in advance by the sender (140) and receiver (120), the communication goes on with the usual error correction and privacy amplification stages. However, if the security threshold is transcended, the whole communication aborts.
In ensuring secure data transmission against eavesdropper attacker (Eve), sender (140) and receiver (120) forfeit the run to perform quantum channel control. The sender (140) and receiver (120) test the forward and backward paths of the channel with a procedure equivalent to the one adopted in BB84 protocol. Upon receiving the two qubits from sender (140), the receiver (120) makes a projective measurement of the two qubits along a basis randomly chosen among x, y ox z . The sender (140) authenticates the receiving part is the designated receiver (120).
For the first example, when sender (140) sends qubits in thex, y combination by choosing the states +) and|j> +) and if the sender's (140) final measurements results in none or both of the qubits flipped in the qubits flipping process (124), sender (140) would assume that the operation handled by the receiver (120) was using the /(Z) operator. For a second example, sender (140) authenticates that the designated receiver, also if it results in the only state \x +)
Figure imgf000010_0001
+)) flipped, the operator used is iY (X).
Once the sender (140) has authenticated that the receiver (120) is the designated receiver (120) to receive the data, the sender proceeds with message encryption (142) at his/her particular station (140). In this stage, the hash functions (142,122) wherein consists of at least selected hash cascade of two hash functions is used to cipher and decipher the message. After encryption (142) is performed at the sender's station, the ciphered message is transmitted through classical channel or the Internet (110). During this particular process, eavesdropper and other malicious attacks may not be able to intercept the transmission as the message has been encrypted by the hash functions and the receiver has primarily been authenticated. In result of the sender (140) and receiver (120) authentication, which has previously performed in the quantum channel, the message may be straightforwardly delivered to the legitimate receiver. The encrypted message is then transmitted to the receiver station (140) for the receiver to decrypt (122) and retrieve the message.
The key distribution protocol is performed by atomic actions as in Table 2 by the sender and the receiver
Table 2
Action Form Informal Implication
Send <m : A→ B> Send message m from
A to B
Receive (m : A→ B) Receive message m
from A at B
New (v i) Obtain new value of j
Concurrently ® Cluster can be executed
execute concurrently
Sequentially execute Sequential or ordered
actions
Concatenate Strings Sx and Sy are
concatenated into one
string SxSv
Encrypt Ek( m ) = Cm Encrypt message m
using key k to get cipher
Cm
Figure imgf000011_0001
Referring to FIG. 1 , the figure explains the basis of the present invention pursuant to FIG. 2 of a protocol to generate a secure key distribution based on has functions utilizing quantum authentication channel (200). In the first stage of authenticating (210) the receiver, the sender prepares six quantum states (212) and sends two quantum states (214) to the receiver. The receiver then flips the states and sends (216) to the sender to check and compare (218) whether all states corresponds with what the receiver has flipped. This process continues with its forward and backward paths until the measurement by the receiver and the sender corresponds. If the flipped state does not correspond, the process restarts from the first stage of preparation of the six quantum states (212). This is to ensure that the receiver is a legitimate receiver. Then, in key distribution (220) process, once after the receiver is authenticated in the quantum channel, the sender sends the encrypted message using hash functions (222) through classical channel to the receiver for decryption. This secure distribution allowed the message to be securely transmitted from one sender to designated receiver.
Referring to Table 3 and FIG. 3 depict the first mode of key distribution by using random string (300) between a sender, Alice and a receiver Bob. Table 3
Figure imgf000012_0001
In the Alice station (348), Alice generates SA (346) to generate a string. SB string is also generated in Bob station (310) on the concurrent time. These generated strings will be cross-distributed in a random mode to Alice station (348) and Bob station (310) respectively. Alice (348) and Bob (310) perform the following operation of Ks = SA or SB (340, 318) where Ks is the sub-key used only for verification. However, the only restriction on these two random strings (SA and SB) is that their length (L), in number of bits, should be greater than or equal to the required key length pointer field given by ηκ. That is LSA. B≥ nK. In general LSA and Uedo not have to be equal in length. First n« bit is used as the sub-key Ks and the bits of the secret field, in this sub-key, as a pointer to the hash function is utilized. The size of Ks is taken the same as the length of the smaller string.
Next, both Alice (348) and Bob (310) exchange the sub-key of KSA to Bob (338) and KSB to Alice (320) to verify its correctness and that no transmission errors occurred while exchanging SA and SB. Considering the value of Ks as an initial value (h0) to a pseudo random number generator (PNRG), now Alice (348) and Bob (310) independently can perform, on site, the following operation:
Figure imgf000012_0002
where ai and bj are both elements of a set of large random integers that is a part of the shared secret between Alice (348) and Bob (310) and i = 0,1 ,2 n. The initial vector (IV) of the hash h is also part of this shared secret. This set of constants and the vector IV can be generated from a physical device acting as a true random number generator and stored for further use. This addition of random variables to the computation of the pad using hash function tends to approximate the behavior of a true random number generator. The values of the constants and the vector IV should be changed regularly, however not for every session.
The size of the required key (K) is determined by n,
requiredkeysize
where n = bits
hashwordsize
Alice (348) or Bob (310) can select a different hash every time a new session is started. The hash is selected from a value in a secret field of the sub-key Ks.
After both of the receiver and sender, Alice (348) and Bob (310) received KSA and KSB respectively (322, 336), they will compare KSA=KSB and
Figure imgf000013_0001
(334, 324) to check whether both the keys corresponds with each other in order to verify whether the sender and the receiver are legitimate parties. Once verified, the process proceeds to encryption and decryption of message (330, 328) wherein the message will be transmitted either to Alice station (348) or Bob station (310) through classical channel or internet.
Referring to Table 4 and FIG. 4 shows a flow chart of a second mode of key distribution using one string generated at a sender, Alice station (400).
Table 4
Figure imgf000013_0002
This is a different mode that may be applied in order to distribute key from Alice station (432) to Bob station (410). In this mode, Alice generates string SA(430) and sends SAto Bob (428). Concurrently, Bob waits (412) without generating his own string. Both Alice (432) and Bob (410) read the value of j (426, 416) that is the pointer to the type of hash to be employed. Further, both of the sender and receiver perform (K) =hj {α,β,ς,ν\, KAS or KBS) (424, 418). Next, the obtained key is encrypted (422, 420) in Alice (432) and Bob (410) stations by using hash functions and transmitted to each other for message retrieval. The value of j may be used to choose random combinations of two cascades hash function stored.
The example of the select d hash is shown below:
Figure imgf000014_0002
Referring to Table 5 and FIG. 5 shows a flow chart of third mode of key distribution (one shot) using one string generated, message encryption and concatenation at sender's station and sent to the receiver, Bob station for message retrieval (500).
Table 5
Figure imgf000014_0001
Alice (542) generates SA (540) and get value of j (Vj), A from SA (538). Then Alice (542) performs (A,KAS =hj (a,fi, ,SA)) (536) to generate a key. The key generated is encrypted in a character of CM =EK (M) (534). Once encrypted, the characters are concatenated (532) by performing SACM = (SACM) (532). Alice then sends SACM (530) to Bob for authentication. Bob then receives SACM (522) to get j (Vj) from SA (524) and performs
Figure imgf000015_0001
( ,β, ς, SA) (526) to generate a new key. Finally, message is retrieved at Bob's station as M=DK (CM) (528). During generation of key (540) at Alice station (542), Bob has to wait (512, 514, 516, 518, 520) until a specified generated key has been established. Since other modifications and changes varied to fit particular operating requirements and environments will be apparent to those skilled in the art, the invention is not considered to be limited to the example chosen for purposes of disclosure, and covers all changes and modifications which do not constitute departures from the true scope of this invention. Having thus described the invention, what is desired to be protected by this patent is presented in the subsequently appended claims.

Claims

1. A method for a secure key distribution protocol based on hash functions utilizing quantum authentication channel (200) comprising:
authenticating (210) a receiver using quantum authentication channel; and distributing (220) secure key from sender to the receiver by encrypting message using hash functions (222);
characterized in authenticating (210) the receiver using quantum authentication channel further comprises:
preparing six quantum states at a sender (212);
sending two quantum states to the receiver (214);
flipping the quantum states at the receiver (216);
sending the flipped quantum states to the sender (2 6); and
validating the quantum states at the sender (2 8).
2. The method according to claim 1 wherein the quantum authentication channel is an out-of-band channel.
3. The method according to claim 1 wherein the quantum authentication channel comprises a free space or optical fiber.
4. The method according to claim 1 wherein sending the two quantum states (214) comprises sending two qubits.
5. The method according to claim 1 wherein flipping the quantum states (216) comprises using one of four operators of I, X, iY or Z to flip the quantum states.
6. The method according to claim 1 wherein validating the quantum states (218) includes testing forward and backward paths of the quantum channel.
7. The method according to claim 1 wherein hash functions (222) includes selected hash or a cascade of hash functions and shared secret keys.
8. The method according to claim 1 wherein distributing (220) the secure key comprises:
either first mode of key distribution using random string between the sender and the receiver;
or second mode of key distribution using one string at sender station;
or third mode of key distribution using one string generated, message encryption and concatenation at sender station.
PCT/MY2010/000190 2009-11-13 2010-09-30 A secure key distribution protocol based on hash functions utilizing quantum authentication channel (kdp-6dp) Ceased WO2011059306A2 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
MYPI20094827 MY145389A (en) 2009-11-13 2009-11-13 A secure key distribution protocol based on hash functions utilizing quantum authentications channel (kdp-6dp)
MYPI20094827 2009-11-13

Publications (2)

Publication Number Publication Date
WO2011059306A2 true WO2011059306A2 (en) 2011-05-19
WO2011059306A3 WO2011059306A3 (en) 2011-08-11

Family

ID=43992271

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/MY2010/000190 Ceased WO2011059306A2 (en) 2009-11-13 2010-09-30 A secure key distribution protocol based on hash functions utilizing quantum authentication channel (kdp-6dp)

Country Status (2)

Country Link
MY (1) MY145389A (en)
WO (1) WO2011059306A2 (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108768646A (en) * 2018-08-03 2018-11-06 浙江九州量子信息技术股份有限公司 A kind of QKD authentication methods based on quantum security key
US10313114B2 (en) 2015-07-31 2019-06-04 Alibaba Group Holding Limited Authentication method, device and system for quantum key distribution process

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105471584B (en) * 2015-12-04 2019-02-22 长春大学 An Identity Authentication Method Based on Quantum Key Encryption

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7298847B2 (en) * 2002-02-07 2007-11-20 Nokia Inc. Secure key distribution protocol in AAA for mobile IP
US8761401B2 (en) * 2006-08-28 2014-06-24 Motorola Mobility Llc System and method for secure key distribution to manufactured products

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10313114B2 (en) 2015-07-31 2019-06-04 Alibaba Group Holding Limited Authentication method, device and system for quantum key distribution process
US10999068B2 (en) 2015-07-31 2021-05-04 Alibaba Group Holding Limited Authentication method, device and system for quantum key distribution process
CN108768646A (en) * 2018-08-03 2018-11-06 浙江九州量子信息技术股份有限公司 A kind of QKD authentication methods based on quantum security key
CN108768646B (en) * 2018-08-03 2022-05-27 浙江九州量子信息技术股份有限公司 QKD authentication method based on quantum security key

Also Published As

Publication number Publication date
WO2011059306A3 (en) 2011-08-11
MY145389A (en) 2012-01-26

Similar Documents

Publication Publication Date Title
US10397195B2 (en) Method and system for shared key and message authentication over an insecure shared communication medium
US8670563B2 (en) System and method for designing secure client-server communication protocols based on certificateless public key infrastructure
CA2747891C (en) Method for generating an encryption/decryption key
US8744078B2 (en) System and method for securing multiple data segments having different lengths using pattern keys having multiple different strengths
US20190268145A1 (en) Systems and Methods for Authenticating Communications Using a Single Message Exchange and Symmetric Key
Mattsson et al. Quantum-resistant cryptography
CN109150923A (en) Transmitted data on network security processing based on Hybrid Encryption
CA2639649A1 (en) Cryptography method and system
US11838424B2 (en) Authenticated encryption apparatus with initialization-vector misuse resistance and method therefor
Jakobsen et al. A practical cryptanalysis of the Telegram messaging protocol
CN114499857A (en) Method for realizing data correctness and consistency in big data quantum encryption and decryption
US12174971B1 (en) System and method for secure electronic transmission
JPH09312643A (en) Key sharing method and encryption communication method
CN120710665A (en) A secure inter-core communication method based on derived key negotiation
CN103117850B (en) A kind of method for building up of the cryptographic system based on random sequence database
Luring et al. Analysis of security features in DLMS/COSEM: Vulnerabilities and countermeasures
CN120223293B (en) Authentication encryption method, verification and decryption method, system and device based on block cipher
Nissar et al. Implementation of security enhancement in AES by inducting dynamicity in AES s-box
Alhazmi et al. Mitigating man-in-the-middle attack using quantum key distribution
WO2011059306A2 (en) A secure key distribution protocol based on hash functions utilizing quantum authentication channel (kdp-6dp)
AbdulWahab et al. Proposed new quantum cryptography system using quantum description techniques for generated curves
Amro et al. Known-plaintext attack and improvement of PRNG-based text encryption
Mantoro et al. Preventing Cyber Crime in Electronic Medical Records Using Encryption Data
Angga et al. Implementation of AES-128 and TOTP to Enhance Single Sign-On Authentication (Case Study: SSO of the St. Pius X Parish Application, Bengkayang)
WO2025012609A1 (en) System and method for key amplification

Legal Events

Date Code Title Description
NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 10830237

Country of ref document: EP

Kind code of ref document: A2