Since the first quantum key distribution (QKD) protocol BB84  was proposed, quantum communication has attracted much attention in the filed of infor- mation security. In order to meet the demand of adaptive quantum communi- cation, quantum communication in the area of wireless network has been exploited. Cheng et al.  made the first attempt in wireless quantum networks (WQN) and proposed a quantum routing mechanism, which allows teleporting a quantum state from a node to another node. Li et al.  designed a framework for distributed wireless quantum networks. In 2013, Cao et al.  applied a cluster mesh structure and addressed the problems of EPR resources and quantum channel establishment. The above researches gradually enhance the feasibility of wireless quantum networks. However, there are still a problem in WQN, that is inefficient, i.e., a source node will consume relay nodes’ resources , and it can only send a message to one destination node once instead of several nodes.
Quantum secret sharing (QSS) is an important branch of quantum crypto- graphy, which is a generalization of the classical secret sharing into the quantum domain. Since the first QSS protocol was presented by Hillery et al. , various QSS schemes have been proposed    . In a typical three-party QSS scheme , a sender, Alice, splits a secret message into two shares and dis- tributes the shares to two receivers, Bob and Charlie, so that none of them can recover the secret from their own shares. Only if Bob and Charlie publish their own measurement results honestly, can they read out the secret message cor- rectly.
Inspired by the feature of QSS that more than one party can receive secret message each time, we introduce the idea of QSS into a wireless quantum network, and propose a quantum secret broadcast scheme to solve the troubling efficiency problem. In a cluster network cored on three parties of QSS, three cluster heads, Alice, Bob, and Charlie will collaborate honestly to broadcast messages to cluster members by using pre-shared GHZ states. The communi- cation mode can be whole-network broadcast or intra-cluster broadcast. Furthermore, to prevent illegal eavesdropping, three cluster heads will perio- dically update a encoding key Y. Consequently, illegal nodes cannot read out the message correctly for lack of suitable decoding key.
2. Related Works
2.1. Wireless Quantum Networks
Wireless quantum networks (WQN) has been studied by many groups     to exploit quantum communication into the area of wireless network. The basic method of communication between nodes in WQN is quantum tele- portation. Figure 1 shows an example of wireless quantum network, where dotted line represents quantum channel based on EPR pairs. We assume node A is a source node and node E is a destination node. A possible routing path is, which means the relay node C and D will also consume their EPR pairs and classical bits to assist this communication.
Although WQN has been explored further in the aspects of EPR-pair allo- cation , routing optimization, network architecture construction  , and so on, the basic issues of the WQN are still EPR-pair distribution and quantum
Figure 1. Wireless quantum network.
relay path establishment.
2.2. Three-Party QSS
In 2009, Liu et al.  proposed a three-party QSS scheme with pre-shared GHZ states, which uses an auxiliary EPR pair to encode two secret message bits.
By convention, the sender is denoted as Alice (A), and the receivers is denoted as Bob (B) and Charlie (C). First, they share three-particle GHZ states, each of which is:
After eavesdropping check to ensure the security of quantum channel (GHZ states), Alice prepares an EPR pair in the state:
Four unitary operators are defined as:, , ,.
The system state after encoding can be expressed as:
where is one of four operations, , , , which encodes a two-bit message “00”, “01”, “10”, and “11”, respectively.
Next, Alice applies a controlled-NOT (CNOT) gate on both particle and particle, here is the controller and is the target. Then she sends the particle and through the Hadamard (H) gate, respectively.
Then Alice applies a Bell-state measurement on both particles and, Bob and Charlie measure the particle and with diagonal basis , respectively. After that, they all publish measurement results.
Their measurement results will be correlated in certain forms according to different encoding operation Alice performs. Thus Bob and Charlie can consider three parties’ measurement results and further recover secret messages.
3. The Proposed Scheme
In Liu’s QSS scheme , the correlation between the measurement results and secret message play a important role in decoding. Assume that other nodes are also aware of the correlation, they can also recover the secret messages.
The main idea of our scheme is that in a cluster network cored on three parties of QSS, Alice (A), Bob (B), and Charlie (C) are cluster heads. In each communication period, one cluster head plays the role of a message sender, other two cluster heads are assistants to help sender broadcast messages. Moreover, we design two types of communication modes, namely whole- network broadcast and intra-cluster broadcast, to meet different requirement of a sender.
The quantum secret broadcast scheme is described as follows:
Step 0: Initializing
Figure 2 shows initializing phase of the scheme. We apply a cluster structure for network, three cluster heads A, B, and C, own three-party GHZ states, each GHZ state is:
where, and indicate the particle held by A, B, C respectively. Each cluster head has its own cluster members, we denote A’s members as, B’s and C’s members as and, respectively. Moreover, each cluster head shares EPR pairs with its own cluster members, respectively.
Before communication, quantum channel of GHZ states should be checked for potential attacks, the GHZ among A, B and C can be rewritten as:
Figure 2. Initializing phase.
where,. According to Equation (7), if A
performs measurement under basis on her particle and the result is or, the measurement results of B and C should be, or,. For a secure channel without disturbing, three parties’ measurement results must be correlated as Equation (7). By using this method, A can choose a subset of particles to detect if there exists a attack. If the error rate of measurement results is under the threshold, the channel is secure and the scheme continues, otherwise, if the channel is insecure, the scheme is ter- minated.
Step 1: Encoding key updating. When each communication period begins, three cluster heads generate a two-bit “encoding key” by turns, and then transmit it to other two cluster heads by quantum teleportation.
Assume that it is A’s turn to produce the “encoding key”, which is one of the four possible encoding key “00”, “01”, “10”, and “11”. Then she prepares two
qubits for B and C, respectively, in which the state means “1”, and the state means “0”. After that, A sends two qubits
represented to B and C by controlled quantum teleportation , res- pectively.
When B, C both receive the encoding key, three cluster heads transmit the key to their own cluster members by quantum teleportation based on shared EPR pairs.
After that, the whole network knows the latest encoding key. So the encoding key updating phase is completed.
Step 2: Communication mode selecting. To meet different requirement of cluster heads, the communication mode can be selected to whole-network broadcast or intra-cluster broadcast.
If a cluster head needs to broadcast messages to the whole network, it will announce an application in this step. Then three cluster heads discuss to select one appropriate cluster heads to be the sender of whole-network broadcast. Otherwise, the communication switches into the mode of intra-cluster broadcast if no cluster heads announce an application.
1) Whole-network broadcast
Step 3: Message encoding. Assume that cluster head A is chosen to be the sender. For each shared GHZ state, she prepares an auxiliary EPR state as follows:
Figure 3(a) shows the system states before encoding, where, , form a three-particle entangled state, and form a two-particle entangled
Figure 3. System state of whole-network broadcast.
We define four unitary operators:
Step (3.1) A encodes message on EPR state with two operators and, the system state becomes:
where is the two bits message and is the encoding key.
For convenience, we assume the encoding key is “00”. After encoding with two operators, we obtain:
Step (3.2) A applies a CNOT gate on both particles and, here is the controller and is the target.
Step (3.3) A performs a Hadamard gate on and, respectively. After that, the system state can be written as:
System state after encoding is as shown in Figure 3(b), where the original entangled GHZ state is destroyed, while particles, , form a new three-party entangled state, and form a two-party entangled state.
Step4: Measurement result broadcasting. Sender A performs Bell-state mea- surement on both particles and, B and C measures their own particle and with basis, respectively. Then, they broadcast own mea- surement results.
Step 5: Message decoding.
Step (5.1) All the cluster members consider three cluster heads’ measurement results and can read out A’s messages by referring to the correlation of measurement results and messages, which can be inferred from Equations (13)-(16) and listed in Table 1.
Step (5.2) As is a message encoded with the encoding key, so re- ceivers need to decode the message with encoding key to obtain the original message:
Let us take an example to illustrate how the mode of whole-network broadcast works. At first, we assume that the encoding key is “10”, and it is informed to all nodes in Step 1 of Encoding key updating, and A is chosen to be the sender in the mode of whole-network broadcast. After encoding, A’s measurement results are, B’s results are, and C’s results are, all nodes consider three cluster heads’ results and refer to Table 1
Table 1. Correlation of measurement results and messages in whole-network mode.
to read out massages as “11”, “10”, “01”, …, then receivers XOR (exclusive OR) the encoding key and to recover original messages as “01”, “00”, “11”, ….
2) Intra-cluster broadcast
Assume that no cluster heads announce an application, the communication will switch into the mode of intra-cluster broadcast, in which three cluster heads can send messages to their own cluster members. We take A as an example to illustrate this mode.
Step 3: Message encoding. Similarly, based on the idea of QSS, A randomly selects two cluster members (denote as and) to be assistant. The system state of three parties is:
As is shown in Figure 4(a), A holds particle 1 and 3, while and hold the particle 2 and 4, respectively. Particle 1 and 2 form an entangled state, 3 and 4 form an entangled state.
We define two unitary operators for encoding:
A encodes one bit message on particle 1 with two operators and, system state will be :
where is the one bit message, is a number by XORing the first digit and the second digit of the encoding key. For example, assume the encoding key is “11”, should be.
For convenience, we assume “” as 0. After encoding, we obtain:
Figure 4. System state of intra-cluster broadcast.
From Equations (21)-(22), system state is changed as shown in Figure 4(b), where the two original entangled pairs are all destroyed, and particle 1 and 3 form a new entangled state, 2 and 4 form a new entangled state.
Step 4: Measurement result Broadcasting. A performs a Bell-state mea- surement on both particles 1 and 3, and measures the particle 2 and 4 with basis. Then, they all broadcast the measurement results.
Step 5: Message decoding.
Step (5.1) A’s cluster members consider three parties’ results and read out message by referring to the correlation of measurement results and messages, which is inferred from Equations (21)-(22) and listed in Table 2.
Step (5.2) is a message encoded with, so receivers need to decode the message with to obtain the original message:
We take an example of A cluster to illustrate how intra-cluster mode works. Assume that the encoding key is still “10”, so. A’s results are, ‘s and ‘s results are and, respectively. A’s cluster members consider three parties’ results and refer to Table 2 to read out messages “0”, “0”, “0”, …, then they XOR the and to recover original messages as “1”, “1”, “1”, ….
4. Scheme Analysis
Our scheme aims to achieve message broadcast in WQN, which attempts to extend communication mode and improve network performance. Different from conventional schemes based on quantum teleportation    , we apply the method of QSS instead of teleportation.
For the reason of applying QSS, our scheme has differences with conventional schemes which are based on quantum teleportation in many aspects. Our scheme transmits classical messages by broadcast, while previous ones transmit quantum state by teleportation. Our scheme makes a attempt to achieve message broadcast, the number of receivers can be or under different com- munication mode, where is the number of cluster members. Each sender needs two assistants in our scheme, while conventional schemes also needs
Table 2. Correlation of measurement results and messages in intra-cluster mode.
nodes as assistants to build a routing path from source to destination, the farther distance between source and destination is, the more assistant nodes are needed. we denote as the number of assistant nodes.
Table 3 gives a summary of comparison between our scheme and con- ventional schemes.
The efficiency in our quantum communication protocol can be defined as:
where is the number of transmitted qubits, is the number of consumed qubits, is the number of message receivers.
We make a comparison between our scheme and Cao’s scheme , for the latter is a typical research of previous schemes and it also uses a cluster structure for WQN.
Consider a situation that a cluster head sends messages to his and other cluster heads’ members. In our scheme, for 2 classical bits are eq- uivalent to 1 qubit, , (in the mode of whole-network broadcast), is the number of one cluster members. In Cao’s scheme, , , , for the distance between sender and receiver is at least 1.
Table 4 makes a comparison between our scheme and Yang’s scheme.
We can see from Table 4 that the performance of our scheme is better than Yang’s scheme, especially when the number of receivers is larger and distance is farther.
Table 3. Comprehensive comparison.
Table 4. Efficiency comparison.
In the proposed scheme, no qubits carrying messages are transmitted directly, so quantum channel only exists in the GHZ states. If an eavesdropper Eve cannot escape from the security check at the phase of Step 0: Initializing, our scheme is secure. The security check method of our scheme is the same as QSS schemes in  , which assumes Eve’s attack performs on Hilbert space, then the whole quantum system can be written as:
The error rate involved in Eve is, so Eve can be easily detected during the process of security check.
Considering that receivers read out messages according to the three cluster head’s measurement results, another secure problem is that if an eavesdropper also knows the correlation between messages and measurement results, it can obtain messages. To solve this problem, our scheme generates an encoding key periodically to add an extra encoding operation. Just like one-time pad, the encoding key plays a role of periodically updating a key to encode and decode messages, and it will be informed to all network before communication. If an eavesdropper is not in the cluster of three heads, it will not obtain the latest key, so it can only randomly select one of “00”, “01”, “10”, “11” as the key to recover messages.
In the whole-network mode, by randomly selecting a key, an eavesdropper will recover a message with the error rate 75%, while in the intra-cluster mode, the error rate is 50%. So our scheme uses security check for quantum channel and key updating for secret messages to ensure security.
In this paper, a quantum secret broadcast scheme was proposed to solve efficiency problem in WQN, where each two bits are encoded in an auxiliary EPR states. The proposed scheme constructs a cluster network cored on three- party QSS, three cluster heads share three-party GHZ states, and each cluster head shares EPR pairs with its own cluster members. For different requirement of cluster heads, the scheme can be selected into whole-network broadcast, in which one cluster head is message sender and other two cluster heads are assistants to help broadcast messages to whole network, or intra-cluster broad- cast, in which each cluster head chooses two cluster members as assistants to help broadcast messages to its intra-cluster members. Furthermore, a wireless quantum network with more than three cluster heads needs to be investigated for extensive application.
This project was supported by the National Natural Science Foundation of China (No. 61571024) and the National Key Research and Development Program of China (No. 2016YFC1000307) for valuable helps.
 Bennett, C.H. and Brassard, G. (1984) Quantum Cryptography: Public-Key Distribution and Tossing. Proceedings of IEEE International Conference on Computers, Systems and Signal Processing, Bangalore, India, IEEE Press, 175-179.
 Cheng, S.T., Wang, C.Y. and Tao, M.H. (2005) Quantum Communication for Wireless Wide-Area Networks. IEEE Journal on Selected Areas in Communications, 23, 1424-1432. https://doi.org/10.1109/JSAC.2005.851157
 Li, J.S. and Yang, C.F. (2009) Quantum Communication in Distributed Wireless Sensor Networks. IEEE 6th International Con-ference, Macau, 12-15 Oct. 2009, 1024-1029. https://doi.org/10.1109/MOBHOC.2009.5337016
 Cao, Y., Yu, X.Y. and Cai, Y.X. (2013) Wireless Quantum Communication Networks with Mesh Structure. IEEE 3rd International Conference on Information Science and Technology, Yangzhou, 23-25 March 2013, 1485-1489. https://doi.org/10.1109/ICIST.2013.6747818
 Deng, F.G., Zhou, H.Y. and Long, G.L. (2005) Bidirectional Quantum Secret Sharing and Secret Splitting with Polarized Single Photons. Physics Letters A, 337, 329-334. https://doi.org/10.1016/j.physleta.2005.02.001
 Wang, J., Zhang, Q. and Tang, C.J. (2007) Multiparty Quantum Se-cret Sharing of Secure Direct Communication Using Teleportation. Communications in Theoretical Physics, 47, 454-458. https://doi.org/10.1088/0253-6102/47/3/015
 Nguyen, T.M.T., Sfaxi, M.A. and Ghernaouti-Helie, S. (2006) Integration of Quantum Cryptography in 802.11 Networks. Proc. 1st Int. Conf. on Availability, Reliability and Security, Vi-enna, 20-22 April 2006, 116-123. https://doi.org/10.1109/ARES.2006.75
 Zhou, J.D., How, G. and Wu, S.J. (2007) Controlled Teleportation of an Arbi-trary Multi-Qudit State in a General Form with d-Dimensional Greenberger-Horne-Zei- linger States. Chinese Physics Letters, 24, 1151-1153. https://doi.org/10.1088/0256-307X/24/5/007