论文标题

量子密钥分销网络中的信息理论有保护的拜占庭式易值公差共识

An Information-theoretical Secured Byzantine-fault Tolerance Consensus in Quantum Key Distribution Network

论文作者

Luo, Yi, Mao, Hao-Kun, Li, Qiong

论文摘要

量子密钥分布(QKD)网络有望在长距离内提供信息理论安全性(ITS)通信。基于QKD网络的基于可信赖的继电器体系结构现在是实践中最广泛使用的方案。但是,这是一个不切实际的假设,即所有继电器在复杂的网络中都是完全可信的。过去,只有少数研究理论上分析了不诚实接力线和相应的防御方法被动窃听攻击的情况。但是,我们发现,不诚实接力线的主动攻击可能更具威胁性。考虑到被动和主动攻击,我们将不诚实的继电器视为拜占庭节点,并分析QKD网络可以容纳的拜占庭节点的上限。在本文中,我们建议基于点对点QKD链接实现端到端密钥分布,以实现拜占庭错误公差(BFT)QKD网络方案。为了确保一致性并在QKD网络中提供BFT能力,我们为该网络方案设计了ITSBFT-CONSESUS协议。为了确保共识的信息理论安全性,我们设计了一个基于点对点QKD链接密钥的临时签名方案。为了防止拜占庭节点破坏钥匙分布的执行过程,我们设计了一种端到端键分配方案与共识结合在一起。从理论上讲,我们从四个方面分析了ITSBFT-QKD网络方案:QKD密钥分配安全性,临时签名安全性,共识安全性和领导者选举公平性。模拟结果证明了可行性并证明了性能。

Quantum key distribution (QKD) networks is expected to provide information-theoretical secured (ITS) communication over long distances. QKD networks based trusted relay architecture are now the most widely used scheme in practice. However, it is an unrealistic assumption that all relays are fully trustable in complex networks. In the past, only a few studies have theoretically analyzed the case of passive eavesdropping attack by dishonest relays and corresponding defense method. However, we have found that active attacks by dishonest relays can be more threatening. With the consideration of passive and active attacks, we treat dishonest relays as Byzantine nodes and analyzes the upper limit of Byzantine nodes that the QKD network can accommodate. In this paper, we propose an ITS Byzantine-fault tolerance (BFT) QKD network scheme to achieve end-to-end key distribution based on point-to-point QKD links. To ensure consistency and provide BFT ability in the QKD network, we design an ITSBFT-consensus protocol for this network scheme. To ensure the information-theoretic security of consensus, we design a temporary signature scheme based on point-to-point QKD link keys. To prevent Byzantine nodes from disrupting the execution process of key distribution, we design an end-to-end key distribution scheme combined with consensus. We theoretically analyze proposed ITSBFT-QKD network scheme from four aspects: QKD key distribution security, temporary signature security, consensus security, and leader election fairness. The simulation result proved the feasibility and demonstrate the performance.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源