发表机构
AIT Austrian Institute of Technology; Digital Factory Vorarlberg GmbH(奥地利技术研究所; 福拉尔贝格数字工厂有限公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出一种零知识拓扑验证机制,可在不披露QKD网络内部拓扑的情况下,证明端点间存在符合策略的路由,其证明成本与网络规模无关,且基于BBS的构造性能符合预期。
AI 中文摘要
大规模量子密钥分发(QKD)网络依赖可信中继,使得所选通信路径的安全属性成为端到端保证的关键部分。与此同时,网络运营商可能不愿披露其内部拓扑。我们提出一种拓扑验证机制,允许服务提供者以零知识证明两个端点之间存在符合策略的路由,且在单次展示中不披露路由信息。我们的核心思路是使用多消息签名独立验证节点和边,而非将完整图作为一个对象签名。对于预先选定的路由,证明大小以及密码学生成和验证工作取决于其位置和属性,与整体网络规模无关,而路由发现和验证则具有与图相关的单独成本。该构造将实际路由长度隐藏至一个公开界限,并概述了针对图周期内节点不相交路由和单调添加的扩展方案。我们为通用构造提供了形式化安全模型以及不可伪造性和图隐藏性的条件证明。对于基于BBS的构造,当ℓ=m=n=50时,展示大小估计保持在300KiB以下;当ℓ=64且m=n=8时,测得的生成和验证时间保持在400ms以下。
英文摘要
Large-scale Quantum Key Distribution (QKD) networks rely on trusted repeaters, making the security properties of the selected communication path an essential part of end-to-end assurance. At the same time, network operators may be unwilling to disclose their internal topology. We present a topology-certification mechanism that lets a provider prove in zero knowledge that policy-compliant routes between two endpoints exist, without disclosing the routes in an individual presentation. Our main idea is to certify nodes and edges independently using multi-message signatures, rather than signing the complete graph as one object. For a route chosen in advance, proof size and cryptographic proving and verification work depend on its positions and attributes, independently of the overall network size, whereas route discovery and certification have separate graph-dependent costs. The construction hides the actual route length up to a public bound and sketches extensions to node-disjoint routes and monotonic additions within a graph epoch. We give a formal security model and conditional proofs of unforgeability and graph hiding for a generic construction. For a BBS-based construction, presentation-size estimates remain below $300$\,KiB at $\ell=m=n=50$, and measured generation and verification times remain below $400$\,ms at $\ell=64$ and $m=n=8$.