sdn控制的量子集成光网络中广义量子辅助数字签名业务

IF 4 2区 计算机科学 Q1 COMPUTER SCIENCE, HARDWARE & ARCHITECTURE Journal of Optical Communications and Networking Pub Date : 2025-01-08 DOI:10.1364/JOCN.534089
Alessio Giorgetti;Nicola Andriolli;Marco Ferrari;Elisabetta Storelli;Gennaro Davide Paduanelli;Antonino Cacicia;Rudi Paolo Paganelli;Alberto Tarable;Emilio Paolini;Giada Sajeva;Marco Brunero;Alessandro Gagliano;Paolo Martelli;Pietro Noviello;Giovanni Schmid;Alberto Gatto
{"title":"sdn控制的量子集成光网络中广义量子辅助数字签名业务","authors":"Alessio Giorgetti;Nicola Andriolli;Marco Ferrari;Elisabetta Storelli;Gennaro Davide Paduanelli;Antonino Cacicia;Rudi Paolo Paganelli;Alberto Tarable;Emilio Paolini;Giada Sajeva;Marco Brunero;Alessandro Gagliano;Paolo Martelli;Pietro Noviello;Giovanni Schmid;Alberto Gatto","doi":"10.1364/JOCN.534089","DOIUrl":null,"url":null,"abstract":"Digital signature (DS) is an essential application of cryptography, used to certify the provenance of a message and its authenticity, guaranteeing the non-repudiation, unforgeability, and transferability of messages. However, the forthcoming advent of quantum computation poses a significant threat to classical signature schemes. A possible solution could be the introduction of novel DS schemes based on the fundamental laws of quantum physics. Recently, several quantum DS (QDS) protocols have been proposed, even relying on the exploitation of off-the-shelf quantum key distribution (QKD) solutions. However, their efficiency and large signature size, uncorrelated to the size of the message to sign, represent the main limitation in their employment in a practical scenario. A trade-off solution could be a quantum-assisted DS (QADS), where the QKD technology is exploited together with classical cryptographic functions to achieve a stronger DS scheme, more resistant even to quantum attacks. We propose a generalized quantum-assisted digital signature (G-QADS) protocol based on a hybrid system, composed by the standard Wegman-Carter Message Authentication Code (WG-MAC) together with symmetric QKD keys, to enhance the security of the DS, allowing messages with arbitrary lengths to be signed while maintaining a suitable DS length. In this work, the G-QADS process is proposed for a three-party configuration (one signer and two verifiers), where the third participant is involved in the procedure just in the case of contention between the other two parties. The G-QADS protocol is then experimentally tested to prove its resilience to forging and non-repudiation attacks, demonstrating its capability in securing the message signature (with a success probability of the attacks \n<tex>${ \\lt }10^{- 18}$</tex>\n). The performance is experimentally tested exploiting QKD prototypes based on standard BB84 protocol with decoy states and polarization encoding, in a software-defined network (SDN) infrastructure supervised by a single SDN controller, which provides the management of both classical and quantum communication channels. The proposed solution could push the practical exploitation of QKD into a new application domain, leading to a more pervasive integration of quantum technology in realistic scenarios.","PeriodicalId":50103,"journal":{"name":"Journal of Optical Communications and Networking","volume":"17 2","pages":"A155-A164"},"PeriodicalIF":4.0000,"publicationDate":"2025-01-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Generalized quantum-assisted digital signature service in an SDN-controlled quantum-integrated optical network\",\"authors\":\"Alessio Giorgetti;Nicola Andriolli;Marco Ferrari;Elisabetta Storelli;Gennaro Davide Paduanelli;Antonino Cacicia;Rudi Paolo Paganelli;Alberto Tarable;Emilio Paolini;Giada Sajeva;Marco Brunero;Alessandro Gagliano;Paolo Martelli;Pietro Noviello;Giovanni Schmid;Alberto Gatto\",\"doi\":\"10.1364/JOCN.534089\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Digital signature (DS) is an essential application of cryptography, used to certify the provenance of a message and its authenticity, guaranteeing the non-repudiation, unforgeability, and transferability of messages. However, the forthcoming advent of quantum computation poses a significant threat to classical signature schemes. A possible solution could be the introduction of novel DS schemes based on the fundamental laws of quantum physics. Recently, several quantum DS (QDS) protocols have been proposed, even relying on the exploitation of off-the-shelf quantum key distribution (QKD) solutions. However, their efficiency and large signature size, uncorrelated to the size of the message to sign, represent the main limitation in their employment in a practical scenario. A trade-off solution could be a quantum-assisted DS (QADS), where the QKD technology is exploited together with classical cryptographic functions to achieve a stronger DS scheme, more resistant even to quantum attacks. We propose a generalized quantum-assisted digital signature (G-QADS) protocol based on a hybrid system, composed by the standard Wegman-Carter Message Authentication Code (WG-MAC) together with symmetric QKD keys, to enhance the security of the DS, allowing messages with arbitrary lengths to be signed while maintaining a suitable DS length. In this work, the G-QADS process is proposed for a three-party configuration (one signer and two verifiers), where the third participant is involved in the procedure just in the case of contention between the other two parties. The G-QADS protocol is then experimentally tested to prove its resilience to forging and non-repudiation attacks, demonstrating its capability in securing the message signature (with a success probability of the attacks \\n<tex>${ \\\\lt }10^{- 18}$</tex>\\n). The performance is experimentally tested exploiting QKD prototypes based on standard BB84 protocol with decoy states and polarization encoding, in a software-defined network (SDN) infrastructure supervised by a single SDN controller, which provides the management of both classical and quantum communication channels. The proposed solution could push the practical exploitation of QKD into a new application domain, leading to a more pervasive integration of quantum technology in realistic scenarios.\",\"PeriodicalId\":50103,\"journal\":{\"name\":\"Journal of Optical Communications and Networking\",\"volume\":\"17 2\",\"pages\":\"A155-A164\"},\"PeriodicalIF\":4.0000,\"publicationDate\":\"2025-01-08\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Optical Communications and Networking\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://ieeexplore.ieee.org/document/10834438/\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"COMPUTER SCIENCE, HARDWARE & ARCHITECTURE\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Optical Communications and Networking","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/10834438/","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, HARDWARE & ARCHITECTURE","Score":null,"Total":0}
引用次数: 0

摘要

数字签名(DS)是密码学的一个基本应用,用于证明消息的来源及其真实性,保证消息的不可否认性、不可伪造性和可转移性。然而,即将到来的量子计算对经典签名方案构成了重大威胁。一种可能的解决方案是引入基于量子物理基本定律的新型DS方案。最近,已经提出了几种量子密钥分发(QKD)协议,甚至依赖于利用现成的量子密钥分发(QKD)解决方案。然而,它们的效率和庞大的签名大小(与要签名的消息大小无关)是在实际场景中使用它们的主要限制。一个折衷的解决方案可能是量子辅助DS (QADS),其中QKD技术与经典密码功能一起被利用来实现更强大的DS方案,甚至更能抵抗量子攻击。本文提出了一种基于混合系统的广义量子辅助数字签名(G-QADS)协议,该协议由标准的Wegman-Carter消息认证码(WG-MAC)和对称的QKD密钥组成,以提高DS的安全性,允许任意长度的消息签名,同时保持合适的DS长度。在这项工作中,G-QADS流程被提议用于三方配置(一个签名者和两个验证者),其中第三个参与者仅在其他两方之间存在争议的情况下参与该过程。然后对G-QADS协议进行实验测试,以证明其对伪造和不可否认攻击的弹性,证明其保护消息签名的能力(攻击的成功概率为${\lt}10^{- 18}$)。在一个由单个SDN控制器监督的软件定义网络(SDN)基础设施中,利用基于带有诱饵状态和极化编码的标准BB84协议的QKD原型,对性能进行了实验测试,该基础设施提供了经典和量子通信信道的管理。提出的解决方案可以将量子密钥分配的实际利用推向一个新的应用领域,从而在现实场景中更普遍地集成量子技术。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Generalized quantum-assisted digital signature service in an SDN-controlled quantum-integrated optical network
Digital signature (DS) is an essential application of cryptography, used to certify the provenance of a message and its authenticity, guaranteeing the non-repudiation, unforgeability, and transferability of messages. However, the forthcoming advent of quantum computation poses a significant threat to classical signature schemes. A possible solution could be the introduction of novel DS schemes based on the fundamental laws of quantum physics. Recently, several quantum DS (QDS) protocols have been proposed, even relying on the exploitation of off-the-shelf quantum key distribution (QKD) solutions. However, their efficiency and large signature size, uncorrelated to the size of the message to sign, represent the main limitation in their employment in a practical scenario. A trade-off solution could be a quantum-assisted DS (QADS), where the QKD technology is exploited together with classical cryptographic functions to achieve a stronger DS scheme, more resistant even to quantum attacks. We propose a generalized quantum-assisted digital signature (G-QADS) protocol based on a hybrid system, composed by the standard Wegman-Carter Message Authentication Code (WG-MAC) together with symmetric QKD keys, to enhance the security of the DS, allowing messages with arbitrary lengths to be signed while maintaining a suitable DS length. In this work, the G-QADS process is proposed for a three-party configuration (one signer and two verifiers), where the third participant is involved in the procedure just in the case of contention between the other two parties. The G-QADS protocol is then experimentally tested to prove its resilience to forging and non-repudiation attacks, demonstrating its capability in securing the message signature (with a success probability of the attacks ${ \lt }10^{- 18}$ ). The performance is experimentally tested exploiting QKD prototypes based on standard BB84 protocol with decoy states and polarization encoding, in a software-defined network (SDN) infrastructure supervised by a single SDN controller, which provides the management of both classical and quantum communication channels. The proposed solution could push the practical exploitation of QKD into a new application domain, leading to a more pervasive integration of quantum technology in realistic scenarios.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
9.40
自引率
16.00%
发文量
104
审稿时长
4 months
期刊介绍: The scope of the Journal includes advances in the state-of-the-art of optical networking science, technology, and engineering. Both theoretical contributions (including new techniques, concepts, analyses, and economic studies) and practical contributions (including optical networking experiments, prototypes, and new applications) are encouraged. Subareas of interest include the architecture and design of optical networks, optical network survivability and security, software-defined optical networking, elastic optical networks, data and control plane advances, network management related innovation, and optical access networks. Enabling technologies and their applications are suitable topics only if the results are shown to directly impact optical networking beyond simple point-to-point networks.
期刊最新文献
On the cross-layer restoration to address packet layer failures in P2MP-TRX-based WSONs SHAP-assisted EE-LightGBM model for explainable fault diagnosis in practical optical networks Demonstration of a three-node wavelength division multiplexed hybrid quantum-classical network through multicore fiber Programmable packet-optical network security and monitoring using DPUs with embedded GPUs [Invited] Overview of SDN control of multiband over SDM optical networks with physical layer impairments [Invited Tutorial]
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1