High-entropy random numbers are an essential part of cryptography, and Quantum Random Number Generators (QRNG) are an emergent technology that can provide high-quality keys for cryptographic algorithms but unfortunately are currently difficult to access. Existing Entropy-as-a-Service solutions require users to trust the central authority distributing the key material, which is not desirable in a high-privacy environment. In this paper, we present a novel key transmission protocol that allows users to obtain cryptographic material generated by a QRNG in such a way that the server is unable to identify which user is receiving each key. This is achieved with the inclusion of Zero Knowledge Succinct Non-interactive Arguments of Knowledge (zk-SNARK), a cryptographic primitive that allow users to prove knowledge of some value without needing to reveal it. The security analysis of the protocol proves that it satisfies the properties of Anonymity, Unforgeability and Confidentiality, as defined in this document. We also provide an implementation of the protocol demonstrating its functionality and performance, using NFC as the transmission channel for the QRNG key.
翻译:高熵随机数是密码学的重要组成部分,量子随机数生成器(QRNG)作为一种新兴技术,能够为密码算法提供高质量密钥,但遗憾的是目前难以普及。现有的“熵即服务”解决方案要求用户信任分发密钥材料的中央机构,这在高度隐私环境中并不可取。本文提出了一种新颖的密钥传输协议,允许用户获取由QRNG生成的密码学材料,且服务器无法识别每个密钥由哪个用户接收。该协议通过引入零知识简洁非交互式知识论证(zk-SNARK)实现——这是一种密码学原语,允许用户在无需透露某个值的情况下证明对该值的知识。协议的安全性分析表明,它满足本文定义的匿名性、不可伪造性和机密性。我们还提供了该协议的实现,以NFC作为QRNG密钥的传输通道,验证了其功能与性能。