ABSTRACT
Abstract
A method of exchanging a combined cryptographic key between a first node and a second node,the first node and the second node being connected through a first communication and a second communication network, wherein the first communication network is a quantum communication network wherein information is encoded on weak light pulses; andthe first node and the second node being configured to:exchange one or more first cryptographic keys on the first communication network;exchange one or more second cryptographic keys using the second communication network; andform the combined cryptographic key by combining the one or more first cryptographic keys and the one or more second cryptographic keys, such that the first node and the second node share knowledge of the combined cryptographic key.
Description
CROSS-REFERENCE TO RELATED APPLICATIONS
This application is a continuation of and claims the benefit of priority under 35 U.S.C. § 120 from U.S. application Ser. No. 16/797,575 filed Feb. 21, 2020, and claims the benefit of priority from United Kingdom Application No. 1902472.8 filed 22 Feb. 2019, the entire contents of each of which are incorporated herein by reference.
FIELD
Embodiments described herein relate to apparatus and methods for key exchange in secure communication networks.
BACKGROUND
The exchange of cryptographic keys between two parties underpins the security of modern communication infrastructure. To guarantee the security of the communication infrastructure, the secrecy of the cryptographic keys must be maintained. The secrecy of the cryptographic keys is threatened by attacks by adversaries having access to advanced computing systems, including quantum computers, which may solve particular mathematical problems efficiently.
A quantum communication network may be used to share secret cryptographic keys between two nodes, a source node and a destination node, often referred to as âAliceâ and âBobâ, and this technique is known as quantum key distribution (QKD). In a quantum communication network, information is sent between a transmitter and a receiver by encoded single quanta, such as single photons. Each photon carries one bit of information encoded upon a property of the photon, such as its polarization, phase or energy/time. The photon may even carry more than one bit of information, for example, by using properties such as angular momentum.
The attraction of QKD is that it provides a test of whether any part of the key can be known to an unauthorized eavesdropper âEveâ. In many forms of QKD, Alice and Bob use two or more non-orthogonal bases in which to encode the bit values. The laws of quantum mechanics dictate that measurement of the photons by Eve without prior knowledge of the encoding basis of each causes an unavoidable change to the state of some of the photons. These changes to the states of the photons will cause errors in the bit values sent between Alice and Bob. By comparing a part of their common bit string, Alice and Bob can thus determine if Eve has gained information.
Independently of QKD, a classical communication network may also be used to share cryptographic keys between two nodes using public key cryptography. The security of public key cryptography relies on the computational hardness of inverting one-way mathematical problems. For example, the RSA algorithm relies on the difficulty in factorizing a product of two large prime numbers. Other algorithms based on similar principles but using different mathematical problems, such as quantum-resistant algorithms (QRA) may also be used. The attraction of QRA is that it uses mathematical problems where the computation of the inversion is not sped up by quantum computers. Thus, exchanging cryptographic keys between two nodes using QRA is believed to be resilient to attacks by quantum computers.
BRIEF DESCRIPTION OF THE FIGURES
Devices and methods in accordance with non-limiting embodiments will now be described with reference to the accompanying figures in which:
FIG. 1 shows a schematic illustration of a quantum communication network, wherein a source node A and a destination node F are linked to each other through repeater nodes B, E, C, and D.
FIG. 1 ( b ) shows a schematic illustration of a node used in the quantum communication network shown in FIG. 1 .
FIG. 2 shows a schematic illustration of quantum communication system that could be used to implement a quantum channel in the network shown in FIG. 1 ,
FIG. 3 shows a schematic illustration of a first node and a second node, connected via an intermediate node, using the quantum communication network of FIG. 1 .
FIG. 4 shows a schematic illustration of the quantum communication network of FIG. 1 , wherein end nodes A and F are further linked to each other through a second communication network.
FIG. 5 shows a schematic of an initiator node (Node A) linked to a responder node (Node F) through the second communication network.
FIG. 6 ( a ) illustrates the process of classical key exchange between a source node (Alice) and a destination node (Bob), according to an algorithm, used in a method for exchanging a second cryptographic key in accordance with an embodiment.
FIG. 6 ( b ) illustrates the process of classical key exchange between a source node (Alice) and a destination node (Bob), using a quantum resistant algorithm used in a method for exchanging a second cryptographic key in accordance with an embodiment.
FIG. 6 ( c ) illustrates the process of classical key exchange between a source node (Alice) and a destination node (Bob), using another quantum resistant algorithm, used in a method for exchanging a second cryptographic key in accordance with an embodiment.
FIG. 7 is a schematic illustration of a method of exchanging a combined cryptographic key between a first node and a second node according to an embodiment, where one or more first keys are exchanged using a quantum communication network and one or more second keys are exchanged using a classical communication network, and the one or more first keys are combined with the one or more second keys to form a combined cryptographic key, such that the first node and the second node share knowledge of the combined cryptographic key.
FIG. 7 b is a schematic illustration of a method combining a cryptographic key between a first node and a second node according to according to an embodiment showing the key combination process in the first or second node of FIG. 7 .
DETAILED DESCRIPTION OF FIGURES
According to a first aspect of the invention, there is provided a method of exchanging a combined cryptographic key between a first node and a second node,
the first node and the second node being connected through a first communication and a second communication network, wherein the first communication network is a quantum communication network wherein information is encoded on weak light pulses; and
the first node and the second node being configured to:
exchange one or more first cryptographic keys on the first communication network;
exchange one or more second cryptographic keys using the second communication network; and
form the combined cryptographic key by combining the one or more first cryptographic keys and the one or more second cryptographic keys, such that the first node and the second node share knowledge of the combined cryptographic key.
According to a second aspect of the invention, there is provided a communication network for exchanging a combined cryptographic key between a first node and a second node, wherein
the first node and the second node are connected through a first communication and a second communication network, the first communication network being a quantum communication network wherein information is encoded on weak light pulses; and
the first node and the second node are configured to:
exchange one or more first cryptographic keys on the first communication network; exchange one or more second cryptographic keys using the second communication network; and form the combined cryptographic key by combining the one or more first cryptographic keys and the one or more second cryptographic keys, such that the first node and the second node share knowledge of the combined cryptographic key.
According to a third aspect of the invention, there is provided a first node configured to exchange a combined cryptographic key with a second node on a communication network,
the first node being connected to at least one intermediate node through a first communication network, the first communication network being a quantum communication network wherein information is encoded on weak light pulses;
the first node being directly connected to the second node using a second communication network;
the first node and the second node being further configured to:
exchange one or more first cryptographic keys on the first communication network;
exchange one or more second cryptographic keys using the second communication network; and
form the combined cryptographic key using the one or more first cryptographic keys and the one or more second cryptographic keys, such that the first node and the second node share knowledge of the combined cryptographic key.
A quantum communication network between one node Alice and another node Bob may be called a QKD link. QKD links suffer from limited distance reach and to connect nodes that are far from each other, intermediate nodes are required. To guarantee the secrecy, the intermediate nodes have to be trusted nodes, and with an increasing number of intermediate nodes, the risk of a node being compromised also increases. In the field of QKD, the solution has been to route quantum keys through at least two independent paths within a quantum network and then combine the quantum keys obtained from the independent paths, such that compromise of an intermediate node in one path does not affect the secrecy of the combined quantum key.
Separately, public key cryptography, with increasingly robust algorithms such as QRA, has been used as an alternative to QKD key exchange. Classical key exchanges such as QRA may be viewed as preferable solutions because the key exchange does not require on intermediate nodes and is therefore technically more efficient to implement than using intermediate nodes in a QKD, where each pair of nodes requires significant infrastructure. Thus, classical key exchange such as QRA is viewed as an alternative to QKD.
The disclosed method, network and or nodes provide an improvement to the security of communication networks by realising the shortcomings of QKD and exploiting the benefits of classical key exchange techniques to implement a hybrid network combining both QKD and classical key exchange. The effect of this combination is a more efficient yet secure communication network.
In an embodiment, the first communication network comprises at least one intermediate node, other than the first node and the second node, said intermediate node configured to receive and transmit a signal encoded on weak light pulses.
In another embodiment, the first node is configured to send information through the first communication network to:
exchange a quantum cryptographic key with the at least one intermediate node;
generate a local secret key, the local secret key being used to form the one or more first cryptographic keys;
form a further key using the local secret key and the quantum cryptographic key; and
transmit the further key to the at least one intermediate node.
In another embodiment, the at least one intermediate node is configured to:
receive the further key;
extract the local secret key using the further key and the exchanged quantum cryptographic key;
form a second further key using the local secret key and the second quantum cryptographic key; and
transmit the second further key to another of the at least one intermediate node or to the second node.
In another embodiment, the second node is configured to:
receive the second further key; and
extract the local secret key using the second further key and the second quantum cryptographic key, such that the second node has knowledge of the local secret key generated by the first node.
In another embodiment, the second communication network is a classical network directly connecting the first node and the second node, the second communication network comprising a communication channel between the first node and the second node.
In another embodiment, the second cryptographic key is exchanged between the source node and the destination node using a classical key exchange protocol.
In another embodiment, the classical key exchange protocol uses a quantum-resistant algorithm.
In another embodiment, the quantum-resistant algorithm comprises lattice, multivariate, hash, code, and supersingular elliptic curve cryptography.
In another embodiment, the one or more first cryptographic keys and the one or more second cryptographic keys are combined using operations comprising exclusive-or, and/or universal hashing, and/or pseudorandom functions.
In another embodiment, the one or more first cryptographic keys have equal lengths with the one or more second cryptographic keys.
In another embodiment, the one or more first cryptographic keys have different lengths from the one or more second cryptographic keys.
In another embodiment, the first node and the second node are configured to store the one or more first cryptographic keys in an indexed key store, wherein each entry in the indexed key store corresponds to a particular pair of the first node and the second node.
In another embodiment, the first node and/or the second node comprises a counter, the value of the counter being used to select the one or more first cryptographic key corresponding to the particular pair of the first node and the second node.
In another embodiment, the counter is incremented after the one or more first cryptographic keys is provided.
In another embodiment, the first communication network comprises at least one intermediate node, other than the first node and the second node, said intermediate node configured to receive and transmit a signal e
CROSS-REFERENCE TO RELATED APPLICATIONS
This application is a continuation of and claims the benefit of priority under 35 U.S.C. § 120 from U.S. application Ser. No. 16/797,575 filed Feb. 21, 2020, and claims the benefit of priority from United Kingdom Application No. 1902472.8 filed 22 Feb. 2019, the entire contents of each of which are incorporated herein by reference.
FIELD
Embodiments described herein relate to apparatus and methods for key exchange in secure communication networks.
BACKGROUND
The exchange of cryptographic keys between two parties underpins the security of modern communication infrastructure. To guarantee the security of the communication infrastructure, the secrecy of the cryptographic keys must be maintained. The secrecy of the cryptographic keys is threatened by attacks by adversaries having access to advanced computing systems, including quantum computers, which may solve particular mathematical problems efficiently.
A quantum communication network may be used to share secret cryptographic keys between two nodes, a source node and a destination node, often referred to as âAliceâ and âBobâ, and this technique is known as quantum key distribution (QKD). In a quantum communication network, information is sent between a transmitter and a receiver by encoded single quanta, such as single photons. Each photon carries one bit of information encoded upon a property of the photon, such as its polarization, phase or energy/time. The photon may even carry more than one bit of information, for example, by using properties such as angular momentum.
The attraction of QKD is that it provides a test of whether any part of the key can be known to an unauthorized eavesdropper âEveâ. In many forms of QKD, Alice and Bob use two or more non-orthogonal bases in which to encode the bit values. The laws of quantum mechanics dictate that measurement of the photons by Eve without prior knowledge of the encoding basis of each causes an unavoidable change to the state of some of the photons. These changes to the states of the photons will cause errors in the bit values sent between Alice and Bob. By comparing a part of their common bit string, Alice and Bob can thus determine if Eve has gained information.
Independently of QKD, a classical communication network may also be used to share cryptographic keys between two nodes using public key cryptography. The security of public key cryptography relies on the computational hardness of inverting one-way mathematical problems. For example, the RSA algorithm relies on the difficulty in factorizing a product of two large prime numbers. Other algorithms based on similar principles but using different mathematical problems, such as quantum-resistant algorithms (QRA) may also be used. The attraction of QRA is that it uses mathematical problems where the computation of the inversion is not sped up by quantum computers. Thus, exchanging cryptographic keys between two nodes using QRA is believed to be resilient to attacks by quantum computers.
BRIEF DESCRIPTION OF THE FIGURES
Devices and methods in accordance with non-limiting embodiments will now be described with reference to the accompanying figures in which:
FIG. 1 shows a schematic illustration of a quantum communication network, wherein a source node A and a destination node F are linked to each other through repeater nodes B, E, C, and D.
FIG. 1 ( b ) shows a schematic illustration of a node used in the quantum communication network shown in FIG. 1 .
FIG. 2 shows a schematic illustration of quantum communication system that could be used to implement a quantum channel in the network shown in FIG. 1 ,
FIG. 3 shows a schematic illustration of a first node and a second node, connected via an intermediate node, using the quantum communication network of FIG. 1 .
FIG. 4 shows a schematic illustration of the quantum communication network of FIG. 1 , wherein end nodes A and F are further linked to each other through a second communication network.
FIG. 5 shows a schematic of an initiator node (Node A) linked to a responder node (Node F) through the second communication network.
FIG. 6 ( a ) illustrates the process of classical key exchange between a source node (Alice) and a destination node (Bob), according to an algorithm, used in a method for exchanging a second cryptographic key in accordance with an embodiment.
FIG. 6 ( b ) illustrates the process of classical key exchange between a source node (Alice) and a destination node (Bob), using a quantum resistant algorithm used in a method for exchanging a second cryptographic key in accordance with an embodiment.
FIG. 6 ( c ) illustrates the process of classical key exchange between a source node (Alice) and a destination node (Bob), using another quantum resistant algorithm, used in a method for exchanging a second cryptographic key in accordance with an embodiment.
FIG. 7 is a schematic illustration of a method of exchanging a combined cryptographic key between a first node and a second node according to an embodiment, where one or more first keys are exchanged using a quantum communication network and one or more second keys are exchanged using a classical communication network, and the one or more first keys are combined with the one or more second keys to form a combined cryptographic key, such that the first node and the second node share knowledge of the combined cryptographic key.
FIG. 7 b is a schematic illustration of a method combining a cryptographic key between a first node and a second node according to according to an embodiment showing the key combination process in the first or second node of FIG. 7 .
DETAILED DESCRIPTION OF FIGURES
According to a first aspect of the invention, there is provided a method of exchanging a combined cryptographic key between a first node and a second node,
the first node and the second node being connected through a first communication and a second communication network, wherein the first communication network is a quantum communication network wherein information is encoded on weak light pulses; and
the first node and the second node being configured to:
exchange one or more first cryptographic keys on the first communication network;
exchange one or more second cryptographic keys using the second communication network; and
form the combined cryptographic key by combining the one or more first cryptographic keys and the one or more second cryptographic keys, such that the first node and the second node share knowledge of the combined cryptographic key.
According to a second aspect of the invention, there is provided a communication network for exchanging a combined cryptographic key between a first node and a second node, wherein
the first node and the second node are connected through a first communication and a second communication network, the first communication network being a quantum communication network wherein information is encoded on weak light pulses; and
the first node and the second node are configured to:
exchange one or more first cryptographic keys on the first communication network; exchange one or more second cryptographic keys using the second communication network; and form the combined cryptographic key by combining the one or more first cryptographic keys and the one or more second cryptographic keys, such that the first node and the second node share knowledge of the combined cryptographic key.
According to a third aspect of the invention, there is provided a first node configured to exchange a combined cryptographic key with a second node on a communication network,
the first node being connected to at least one intermediate node through a first communication network, the first communication network being a quantum communication network wherein information is encoded on weak light pulses;
the first node being directly connected to the second node using a second communication network;
the first node and the second node being further configured to:
exchange one or more first cryptographic keys on the first communication network;
exchange one or more second cryptographic keys using the second communication network; and
form the combined cryptographic key using the one or more first cryptographic keys and the one or more second cryptographic keys, such that the first node and the second node share knowledge of the combined cryptographic key.
A quantum communication network between one node Alice and another node Bob may be called a QKD link. QKD links suffer from limited distance reach and to connect nodes that are far from each other, intermediate nodes are required. To guarantee the secrecy, the intermediate nodes have to be trusted nodes, and with an increasing number of intermediate nodes, the risk of a node being compromised also increases. In the field of QKD, the solution has been to route quantum keys through at least two independent paths within a quantum network and then combine the quantum keys obtained from the independent paths, such that compromise of an intermediate node in one path does not affect the secrecy of the combined quantum key.
Separately, public key cryptography, with increasingly robust algorithms such as QRA, has been used as an alternative to QKD key exchange. Classical key exchanges such as QRA may be viewed as preferable solutions because the key exchange does not require on intermediate nodes and is therefore technically more efficient to implement than using intermediate nodes in a QKD, where each pair of nodes requires significant infrastructure. Thus, classical key exchange such as QRA is viewed as an alternative to QKD.
The disclosed method, network and or nodes provide an improvement to the security of communication networks by realising the shortcomings of QKD and exploiting the benefits of classical key exchange techniques to implement a hybrid network combining both QKD and classical key exchange. The effect of this combination is a more efficient yet secure communication network.
In an embodiment, the first communication network comprises at least one intermediate node, other than the first node and the second node, said intermediate node configured to receive and transmit a signal encoded on weak light pulses.
In another embodiment, the first node is configured to send information through the first communication network to:
exchange a quantum cryptographic key with the at least one intermediate node;
generate a local secret key, the local secret key being used to form the one or more first cryptographic keys;
form a further key using the local secret key and the quantum cryptographic key; and
transmit the further key to the at least one intermediate node.
In another embodiment, the at least one intermediate node is configured to:
receive the further key;
extract the local secret key using the further key and the exchanged quantum cryptographic key;
form a second further key using the local secret key and the second quantum cryptographic key; and
transmit the second further key to another of the at least one intermediate node or to the second node.
In another embodiment, the second node is configured to:
receive the second further key; and
extract the local secret key using the second further key and the second quantum cryptographic key, such that the second node has knowledge of the local secret key generated by the first node.
In another embodiment, the second communication network is a classical network directly connecting the first node and the second node, the second communication network comprising a communication channel between the first node and the second node.
In another embodiment, the second cryptographic key is exchanged between the source node and the destination node using a classical key exchange protocol.
In another embodiment, the classical key exchange protocol uses a quantum-resistant algorithm.
In another embodiment, the quantum-resistant algorithm comprises lattice, multivariate, hash, code, and supersingular elliptic curve cryptography.
In another embodiment, the one or more first cryptographic keys and the one or more second cryptographic keys are combined using operations comprising exclusive-or, and/or universal hashing, and/or pseudorandom functions.
In another embodiment, the one or more first cryptographic keys have equal lengths with the one or more second cryptographic keys.
In another embodiment, the one or more first cryptographic keys have different lengths from the one or more second cryptographic keys.
In another embodiment, the first node and the second node are configured to store the one or more first cryptographic keys in an indexed key store, wherein each entry in the indexed key store corresponds to a particular pair of the first node and the second node.
In another embodiment, the first node and/or the second node comprises a counter, the value of the counter being used to select the one or more first cryptographic key corresponding to the particular pair of the first node and the second node.
In another embodiment, the counter is incremented after the one or more first cryptographic keys is provided.
In another embodiment, the first communication network comprises at least one intermediate node, other than the first node and the second node, said intermediate node configured to receive and transmit a signal encoded on weak light pulses.
FIG. 1 is a schematic of a quantum communication network 1 comprising nodes A to F. Each node is connected to at least one other node. In the configuration of FIG. 1 , communication takes place between two nodes when there is a quantum transmitter in one node and a quantum receiver in the other node.
In a quantum communication network, information sent between a quantum transmitter and a quantum receiver is encoded as single quanta, such as single photons. Each photon carries one bit of information encoded upon a property of the photon, such as its polarization, phase, or energy/time. The photon may carry more than one bit of information, for example, by using properties such as angular momentum.
In a quantum communication network in general, a quantum transmitter will be capable of encoding information on weak light pulses. A quantum receiver will be capable of decoding this information. Either discrete variable (DV) or continuous variable (CV) quantum information can be encoded. In DV QKD, weak coherent light pulses (WCP) can be generally thought of as light pulses that have a probability of containing less than one photon per pulse on average during quantum encoding, the information is encoded on weak light pulses using polarisation, phase, and time-bin information etc. In CV QKD, each WCP pulse can contain up to 100 photons per pulse on average.
A DV QKD system consists of a QKD transmitter and a QKD receiver. The quantum transmitter transmits an encoded quantum signal pulses, each of which contains on average less than one photon per pulse. These optical signals are transmitted through a quantum channel before reaching the quantum receiver, which decodes the incoming signals and detects them using single photon detectors.
For ease of language, the term quantum communication unit 101 will be used to refer to either a quantum transmitter and/or a quantum receiver. In an embodiment, if a node is connected to two other nodes, it has a dedicated quantum communication unit at each end of the connection. Thus, in an embodiment, every node has a number of quantum communication units that equals the number of connections to that node. Alternatively, each node may have a single quantum communication in combination with a switching device which sequentially connects the end of each connection to the quantum communication unit.
In a quantum communication network 1 , such as the one illustrated in FIG. 1 , communication between two nodes takes place through a quantum channel. The quantum channel may be implemented in an optical fibre connection. The quantum channel can be chosen to operate at any wavelength that is suitable for transmission over optical fibre channel which typically supports only one optical mode and is usually referred to as single mode fibre. For example, the quantum wavelength can be chosen at 1310 nm or at 1550 nm. When a quantum communication network is used to perform QKD, the quantum channel is also called a QKD link. Quantum channels are shown as solid lines between nodes in FIG. 1 .
The embodiment described herein is not limited to information being encoded on weak light pulses using a particular degree of freedom such as polarization, phase and time-bin etc. In fact, encoding can be applied upon one of, or a mixture of, many different degrees of freedoms, such as phase, polarisation and time-bin etc.
Further, the embodiments described herein are not limited to a certain QKD protocol. It is applicable to different QKD protocols, such as BB84, B92, differential-phase-shift (DPS), coherent-one-way protocol and round-robin DPS protocols.
In some embodiments, for QKD operation, supporting classical optical channels are provided for realising functions of clock synchronisation and for exchanging messages for sifting between the QKD transmitter and receiver. Supporting optical classical channels are shown as dashed lines between nodes in FIG. 1 . While these classical channels can be placed into a separate fibre, wavelength division multiplexing is often used to combine both these classical channels and quantum channel so that they can all be transmitted through the same fibre.
In some cases, QKD need to share the same fibre with additional data traffic in the same fibre. In this case, a wavelength filter may be used to combine/separate QKD signals (quantum, synchronisation and classical) and additional data signal. It is preferable to assign a wavelength group to accommodate QKD optical signals, for example, a coarse-wavelength-division-multiplexing (CWDM) band within Telecom C-band. Further details of a QKD system will be provided below.
Returning to the quantum communication network 1 of FIG. 1 , nodes are connected to each other using point-to-point QKD links. Point-to-point QKD links suffer from a limited distance reach over optical fibre connections due to losses that increase exponentially with distance. Therefore, to exchange a first cryptographic key, which is referred to as a quantum key, between source node A and destination node F, it is necessary to route the quantum key through intermediate nodes that act as repeater nodes.
In an embodiment, shown in FIG. 1 ( b ) a node 5 in the quantum communication network 1 will contain at least a first key generator ( 102 ), together with at least one quantum communication unit ( 101 ). The first key generator ( 102 ), together with the quantum communication unit ( 101 ), is configured to implement an agreed QKD protocol using the quantum communication network 1 . The node 5 may further comprise a key store 103 for storing indexed shared keys, a local key generator 104 for generating and transmitting a local key. The local key generator 104 may comprise a local secret generator 105 and a key combiner 106 . The local secret generator 105 generates a local secret key. The key combiner 106 may be configured to form a further key by combining a key from the key store 103 with a local secret key from the local secret generator 105 . The local key generator 104 may be further configured to transmit the further keyâthe transmission may be through a classical communication link or through a quantum communication link. The node may contain a processor configured to implement the QKD protocol. The processor may be a central processing unit (CPU), graphical processing unit (GPU), or a field programmable gate array (FPGA). Details of a QKD protocol demonstrating how a first cryptographic key is shared or exchanged will be described below.
Repeater nodes are nodes on the quantum communication network 1 that are connected to at least two other nodes. Repeater nodes comprise at least a quantum communication unit ( 101 ) and a first key generator ( 102 ) to serve each connection.
In FIG. 1 , source node A and destination node F comprise at least a quantum communication unit and at least a first key generator 102 configured to implement an agreed QKD protocol at the end of each connection. Node A has a quantum communication unit 101 and a first key generator 102 configured to transmit information to Node B over the quantum channel. Node F has a quantum communication unit and a first key generator configured to transmit information to Node D over a QKD link, and a quantum communication unit and a first key generator configured to transmit information to Node E over another QKD link.
Thus, every node has a number of first key generators 102 and a number of quantum communication units 101 that equal the number of connections to that node. Alternatively, each node may have a single first key generator 102 and a single quantum communication unit 101 as well as a switching device which sequentially connects the end of each connection to the quantum communication unit.
The quantum communication network may comprise a network controller, the network controller being adapted to direct a signal relating to a first cryptographic key from a source node to a destination node via at least one repeater node.
In the quantum communication network illustrated in FIG. 1 , the quantum key may be routed from A to F through the following nodes: AâBâEâF; AâBâCâDâF; AâBâEâDâF, and so on.
Generation and exchange of a quantum key between nodes A and F, denoted K QKD , may be performed as follows. As an example, the communication chain AâBâEâF is considered. A and B first execute a QKD protocol to generate a key K AB ; B executes a QKD protocol with E to generate K BE ; A encrypts secret information K S with K AB , and transmit to B, over a supporting classical channel. B obtains K S by decrypting with K AB , and B re-encrypts K S with K BE and transmits it to node E over a supporting classical channel. Similarly node E executes a QKD protocol with node F to generate a key K EF , E decrypts the message from B to obtain K S , re-encrypts K S with K EF , and transmits the encrypted information to F over a supporting classical channel. End node F deciphers the message from E using K EF to obtain K S . End nodes A and F now have knowledge of the secret information K S . A shared secret key between nodes A and F, K QKD , can be derived from secret information K S according to an appropriate protocol. Details of a QKD protocol that could be implemented to exchange keys between each pair of nodes will be described below.
QKD Key exchange according to one example is described in FIG. 3 .
Nodes
1 , 2 and 3 are three QKD nodes in a quantum communication network 1 . Node 1 is termed the first node, node 3 is termed the second node, and node 2 is an intermediate node. The first node and the second nodes are end-nodes. Each node consists at least a quantum communication unit 101 . Each quantum communication unit 101 comprises a QKD transmitter and/or a QKD receiver. In this example, Nodes
1 and 3 do not have a direct QKD link and their shared quantum keys have to be formed via Node 2 , which has a QKD link with each of node 1 and node 3 . For each pair of nodes, there is a pair of quantum cryptographic keys (K 12 , K 21 , K 23 , K 32 ) that is stored between them. For each pair of nodes, each quantum cryptographic key of the pair of quantum cryptographic keys is identical to each other. In each node of the pair of nodes, the quantum cryptographic key corresponding to that pair is indexed and stored. For example, node 1 and node 2 share QKD keys K 12 and K 21 , where K 12 =K 21 , and node 1 contains a key store âstore 1-2â containing K 12 , while and node 2 contains a key store âstore 2-1â containing K 21 . Node 2 and node 3 share QKD keys K 23 and K 32 , where K 23 =K 32 , node 2 contains a key store âstore 2-3â containing K 23 , while node 3 contains a key store âstore 3-2â containing K 32 . More generally, in QKD nodes having a direct QKD link, the key stores between them will be filled with quantum keys generated between them.
Node 1 also contains a local key generator 104 . The local key generator 104 comprises a local secret generator 105 and a key combiner 106 . The local secret generator 104 may be a random number generator (RNG). A RNG is configured to generate a sequence of numbers that cannot be reasonably predicted better than by a random chance. In a further embodiment, the local secret generator may be a quantum random number generator (QRNG). A QRNG is a RNG that relies on quantum mechanical physical property, e.g., shot noise, or random phases in vacuum field, to generate the sequence of random numbers. The (Q)RNG is used to generate a local random secret, K R . The key combiner 106 is used to combine the local random secret K R with a key from the key store 103 to form a further key. In this example, the further key is K R1 âK 12 and this is transmitted to node 2 ; however, it will be understood that a different operation and/or a different key from a different key store could be used to form a further key that is sent to a different node.
Between nodes without a direct QKD link, e.g., node 1 and node 3 , their mutual key stores âstore 1-3â and âstore 3-1â are populated in such a way described below. First, node 1 uses its RNG or QRNG device to generate local secret K R1 . K R1 is stored in the key store 1-3, and K R1 combined with K 12 to form a further key K R1 âDK 12 . The further key K R1 âK 12 is then transmitted to node 2 . At node 2 , K R1 is obtained from K R1 âK 12 âK 21 =K R1 . K R1 is combined with a second quantum cryptographic key K 23 from the âstore 2-3â key store to form a second further key K R1 âK 23 , and the second further key K R1 âK 23 transmitted to node 3 . At node 3 , K R1 is obtained from K R1 âK 23 âK 32 =K R1 , and the retrieved K R1 is stored in key store âstore 3-1â. Therefore, the local secret K R1 , generated by node 1 , has become known to node 3 , and is stored in the mutual key stores âstore 1-3â and âstore 3-1â in nodes
1 and 3 respectively. More generally, between a node N without a direct link node 1 , the local secret K R1 is stored in the mutual key stores âstore 1-Nâ and âstore N-1â in nodes 1 and N respectively.
The security of the exchanged key requires that each repeater node is a trusted node as each repeater node has knowledge of secret information K S or K R1 ; compromise to a single node may compromise the security of the entire network. In the network shown in FIG. 1 , a breach of secrecy in node B, for example, compromises the security of the key exchange from node A to node F. In the example shown in FIG. 3 , a breach of secrecy in node 2 compromises the security of the key exchange because node 2 has knowledge of K R1 .
Transmitting and detecting quantum signals through the quantum channel generates raw quantum keys between two end nodes. These raw QKD keys that are produced by end nodes may be further processed to correct errors and improve secrecy. Improving secrecy includes the method of privacy amplification where the keys produced by the end nodes are shortened, for example, by using universal hash functions, such that any eavesdropper would have negligible information about the new amplified key. In the description above in relation to FIG. 3 , K 12 , K 21 , K 23 , K 32 represent the keys that have been processed and are the keys that are stored in the key stores.
For completeness, a description of a QKD system that can be applied to any of the embodiments follows below. In the description below, the first key generator 102 and the first communication unit 101 at the source node act as âAliceâ, while the first key generator 202 and the first communication unit 201 at the destination node act as âBobâ.
FIG. 2 is a schematic illustration of a quantum communication system suitable for implementing a QKD link. In this embodiment the quantum transmitter 101 and the quantum receiver 201 are based on asymmetrical Mach-Zehnder interferometers (MZI). Transmitter unit 801 comprises quantum transmitter 901 and classical communication device 830 . Receiver unit 805 comprises quantum receiver 201 and classical communication device 806 . Quantum transmitter 901 and quantum receiver 902 are connected through fibre 802 b , wavelength division multiplexer 832 , and fibre channel 804 . Classical communication device 830 and classical communication device 806 are connected through fibre 802 a , wavelength division multiplexer 832 and fibre 804 . This is referred to as the classical channel Photon source 810 inside quantum transmitter 901 generates a quantum signal, comprising pulses of light. The pulses are then encoded using the asymmetrical MZI 811 . The pulses are directed into a beam splitter 812 . One output of the beam splitter 812 is connected to a phase modulator 816 . The output of the phase modulator 816 is connected to polarising beam splitter 817 . This forms the short arm 813 of the interferometer. The other output of the beam splitter 812 is connected to a fibre loop 815 , which is in turn connected to polarising beam splitter 817 . This forms the long arm 814 of the interferometer. Light pulses travelling the long arm 814 are delayed with respect to light pulses travelling the short arm 813 .
Quantum transmitter 901 may also comprise an intensity modulator configured to vary the intensity of light pulses. The intensity modulator may be configured to realise a decoy-state QKD protocol, in which pulses of different intensities are sent which allows the sender and receiver to determine the presence of an eavesdropper by measuring the number of pulses which have been safely received with the different intensities. The transmitter may comprise more than one intensity modulator.
Phase modulator 816 is configured to apply a modulation to the phase of a light pulse travelling the short arm 813 . A phase modulator can comprise a crystal waveguide, such as a LiNbO 3 crystal waveguide, in which the refractive index is a function of electric field strength. Alternatively the phase modulation can be provided by passive means, for example, a plurality of fixed phase elements which are each configured to apply a different fixed phase difference and a switch configured to select each of the said components.
The polarisation of a light pulse travelling from the short arm 813 of the interferometer is flipped by the polarizing beam splitter 817 , from a first polarisation to a second polarisation, which is orthogonal to the first polarisation.
The quantum transmitter 901 therefore generates coherent double pulses with a chosen phase difference and orthogonal polarization travelling down the fibre link 804 . A polarisation controller 818 corrects any deviation of the polarisation of the pulses. Each quantum transmitter at each ONU may use a separate polarisation controller to align the polarisation of the pulses arriving at the receiver individually. The quantum transmitters may be pre-compensated. Alternatively, a single polarisation controller could be installed at the receiver side.
Quantum light pulses exit the quantum transmitter 901 and are sent via fibre 802 - 1 b to wavelength division multiplexer 832 . The quantum signals are transmitted with a first wavelength. Wavelength division multiplexer 832 sends signals inputted from fibre 802 - 1 b into fibre 804 . The quantum signals are sent via fibre 804 to the quantum receiver 902 .
In the quantum receiver 902 the pulses are decoded using the asymmetrical MZI 821 . The short arm 824 of the interferometer 821 comprises a phase modulator 826 , such as has been described previously. The long arm 823 of the interferometer comprises a fibre loop 825 , which exactly matches the fibre loop 815 in the transmitter. The long arm 823 and the short arm 824 are each connected to one of the outputs of the polarizing beam splitter 822 and to one of the inputs of beam splitter 827 .
The polarizing beam splitter 822 sends a light pulse that ent
CLAIMS
Claims ( 14 )
The invention claimed is:
1. A method of exchanging a combined cryptographic key between a first node and a second node,
the first node and the second node being connected through a first communication and a second communication network, wherein the first communication network comprises a quantum communication network wherein information is encoded on weak light pulses, and wherein the first communication network comprises at least one intermediate node, other than the first node and the second node, said intermediate node configured to receive and transmit a signal encoded on weak light pulses; and
the first node and the second node being configured to:
exchange one or more first cryptographic keys on the first communication network;
exchange one or more second cryptographic keys on the second communication network, wherein the second cryptographic key is exchanged between the first and second node with a quantum-resistant algorithm; and
form the combined cryptographic key by combining the one or more first cryptographic keys and the one or more second cryptographic keys, such that the first node and the second node share knowledge of the combined cryptographic key,
wherein the first node is configured to send information through the first communication network to:
exchange a quantum cryptographic key with the at least one intermediate node;
generate a local secret key, the local secret key being used to form the one or more first cryptographic keys;
form a further key using the local secret key and the quantum cryptographic key; and
transmit the further key to the at least one intermediate node.
2. A method according to claim 1 , wherein the at least one intermediate node is configured to:
receive the further key;
extract the local secret key using the further key and the exchanged quantum cryptographic key;
form a second further key using the local secret key and the second quantum cryptographic key; and
transmit the second further key to another of the at least one intermediate node or to the second node.
3. A method according to claim 2 , wherein the second node is configured to:
receive the second further key, and
extract the local secret key using the second further key and the second quantum cryptographic key, such that the second node has knowledge of the local secret key generated by the first node.
4. A method according to claim 1 wherein the second communication network is a classical network directly connecting the first node and the second node, the second communication network comprising a communication channel between the first node and the second node.
5. A method according to claim 4 wherein the second cryptographic key is exchanged between the first node and the second node using a classical key exchange protocol.
6. A method according to claim 1 wherein the quantum-resistant algorithm comprises lattice, multivariate, hash, code, and supersingular elliptic curve cryptography.
7. A method according to claim 1 wherein the one or more first cryptographic keys and the one or more second cryptographic keys are combined using operations comprising exclusive-or, and/or universal hashing, and/or pseudorandom functions.
8. A method according to claim 7 wherein the one or more first cryptographic keys have equal lengths with the one or more second cryptographic keys.
9. A method according to claim 7 wherein the one or more first cryptographic keys have different lengths from the one or more second cryptographic keys.
10. A method according to claim 1 wherein the first node and the second node are configured to store the one or more first cryptographic keys in an indexed key store, wherein each entry in the indexed key store corresponds to a particular pair of the first node and the second node.
11. A method according to claim 10 wherein the first node and/or the second node comprises a counter, the value of the counter being used to select the one or more first cryptographic key corresponding to the particular pair of the first node and the second node.
12. A method according to claim 11 wherein the counter is incremented after the one or more first cryptographic key is provided.
13. A communication network for exchanging a combined cryptographic key between a first node and a second node,
wherein the first node and the second node are connected through a first communication and a second communication network, the first communication network comprising a quantum communication network wherein information is encoded on weak light pulses, and comprising at least one intermediate node, other than the first node and the second node, said intermediate node configured to receive and transmit a signal encoded on weak light pulses, and
the first node and the second node are configured to:
exchange one or more first cryptographic keys on the first communication network;
exchange one or more second cryptographic keys on the second communication network, wherein the second cryptographic key is exchanged between the first and second node with a quantum-resistant algorithm; and
form the combined cryptographic key by combining the one or more first cryptographic keys and the one or more second cryptographic keys, such that the first node and the second node share knowledge of the combined cryptographic key,
wherein the first node is configured to send information through the first communication network to:
exchange a quantum cryptographic key with the at least one intermediate node;
generate a local secret key, the local secret key being used to form the one or more first cryptographic keys;
form a further key using the local secret key and the quantum cryptographic key; and
transmit the further key to the at least one intermediate node.
14. A first node configured to exchange a combined cryptographic key with a second node on a communication network,
the first node being connected to at least one intermediate node through a first communication network, the first communication network comprising a quantum communication network wherein information is encoded on weak light pulses, wherein the first communication network comprises at least one intermediate node, other than the first node and the second node, said intermediate node configured to receive and transmit a signal encoded on weak light pulses, wherein the first node is configured to exchange a quantum cryptographic key with the at least one intermediate node; the first node being directly connected to the second node using a second communication network;
the first node and the second node being further configured to:
exchange one or more first cryptographic keys on the first communication network;
exchange one or more second cryptographic keys on the second communication network, wherein the second cryptographic key is exchanged between the first and second node with a quantum-resistant algorithm; and
form the combined cryptographic key using the one or more first cryptographic keys and the one or more second cryptographic keys, such that the first node and the second node share knowledge of the combined cryptographic key
wherein the first node is configured to send information through the first communication network to:
exchange a quantum cryptographic key with the at least one intermediate node;
generate a local secret key, the local secret key being used to form the one or more first cryptographic keys;
form a further key using the local secret key and the quantum cryptographic key; and
transmit the further key to the at least one intermediate node.
US17/505,720
2019-02-22
2021-10-20
Secure communication network
Active
2040-04-26
US11695550B2
( en )
Priority Applications (1)
Application Number
Priority Date
Filing Date
Title
US17/505,720
US11695550B2
( en )
2019-02-22
2021-10-20
Secure communication network
Applications Claiming Priority (5)
Application Number
Priority Date
Filing Date
Title
GB1902472.8A
GB2581528B
( en )
2019-02-22
2019-02-22
A method, a communication network and a node for exchanging a cryptographic key
GB1902472
2019-02-22
GB1902472.8
2019-02-22
US16/797,575
US11196550B2
( en )
2019-02-22
2020-02-21
Secure communication network
US17/505,720
US11695550B2
( en )
2019-02-22
2021-10-20
Secure communication network
Related Parent Applications (1)
Application Number
Title
Priority Date
Filing Date
US16/797,575
Continuation
US11196550B2
( en )
2019-02-22
2020-02-21
Secure communication network
Publications (2)
Publication Number
Publication Date
US20220045855A1
US20220045855A1 ( en )
2022-02-10
US11695550B2
true
US11695550B2 ( en )
2023-07-04
Family
ID=65998968
Family Applications (2)
Application Number
Title
Priority Date
Filing Date
US16/797,575
Active
2040-04-01
US11196550B2
( en )
2019-02-22
2020-02-21
Secure communication network
US17/505,720
Active
2040-04-26
US11695550B2
( en )
2019-02-22
2021-10-20
Secure communication network
Family Applications Before (1)
Application Number
Title
Priority Date
Filing Date
US16/797,575
Active
2040-04-01
US11196550B2
( en )
2019-02-22
2020-02-21
Secure communication network
Country Status (3)
Country
Link
US
( 2 )
US11196550B2
( en )
JP
( 1 )
JP7021272B2
( en )
GB
( 1 )
GB2581528B
( en )
Cited By (1)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20250240155A1
( en )
*
2024-01-18
2025-07-24
Qunu Labs Private Limited
System and method for point-to-point decoy differential phase shift (dps) quantum key distribution (qkd)
Families Citing this family (56)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
CN110380844B
( en )
*
2018-04-13
2021-01-29
åä¸ºææ¯æéå ¬å¸
A quantum key distribution method, device and storage medium
US11251947B1
( en )
*
2019-05-08
2022-02-15
Cable Television Laboratories, Inc.
Encrypted data transmission in optical- and radio-access networks based on quantum key distribution
US20220294618A1
( en )
*
2019-08-12
2022-09-15
British Telecommunications Public Limited Company
Improvements to qkd methods
US11552793B1
( en )
2019-09-10
2023-01-10
Wells Fargo Bank, N.A.
Systems and methods for post-quantum cryptography communications channels
US11218301B1
( en )
2019-09-10
2022-01-04
Wells Fargo Bank, N.A.
Systems and methods for post-quantum cryptography communications channels
US11218300B1
( en )
2019-09-10
2022-01-04
Wells Fargo Bank, N.A.
Systems and methods for post-quantum cryptography communications channels
US11985235B2
( en )
*
2019-09-16
2024-05-14
Quantum Technologies Laboratories, Inc.
Quantum communication system
US11329730B2
( en )
2019-09-26
2022-05-10
Eagle Technology, Llc
Quantum communication system having time to frequency conversion and associated methods
US11418330B2
( en )
2019-10-21
2022-08-16
Eagle Technology, Llc
Quantum communication system that switches between quantum key distribution (QKD) protocols and associated methods
US11082216B2
( en )
2019-10-30
2021-08-03
Eagle Technology, Llc
Quantum communication system having quantum key distribution and using a midpoint of the talbot effect image position and associated methods
US11240018B2
( en )
*
2019-10-30
2022-02-01
Eagle Technology, Llc
Quantum communications system having quantum key distribution and using a talbot effect image position and associated methods
US11050559B2
( en )
2019-11-19
2021-06-29
Eagle Technology, Llc
Quantum communications system using Talbot effect image position and associated methods
CN114584288B
( en )
*
2020-11-30
2023-09-26
å¦è¬éåç§ææéå ¬å¸
Key distribution method based on linear quantum key distribution network
CN112787807B
( en )
*
2020-12-31
2022-03-18
æ¸ å大å¦
Quantum communication method and communication network based on secure relay
CN112822010B
( en )
*
2021-01-28
2022-08-26
æé½ä¿¡æ¯å·¥ç¨å¤§å¦
Removable storage medium management method based on quantum key and block chain
GB2604326B
( en )
*
2021-01-29
2023-07-12
Arqit Ltd
QKD switching system
CA3206803A1
( en )
2021-01-29
2022-08-04
Arqit Limited
Key exchange protocol for satellite based quantum network
US12212669B2
( en )
2021-02-19
2025-01-28
Eagle Technology, Llc
Quantum communications system using pulse divider and associated methods
US11502758B2
( en )
*
2021-02-19
2022-11-15
Eagle Technology, Llc
Communications system using pulse divider and associated methods
US11558123B2
( en )
2021-02-19
2023-01-17
Eagle Technology, Llc
Quantum communications system having stabilized quantum communications channel and associated methods
US12192318B2
( en )
*
2021-03-10
2025-01-07
Quantropi Inc.
Quantum-safe cryptographic method and system
CN115085908B
( en )
*
2021-03-16
2025-03-21
å京å¦è¬éåç§ææéå ¬å¸
Key distribution method and system based on quantum communication satellite and DH algorithm
US11290181B1
( en )
*
2021-03-18
2022-03-29
The United States Of America As Represented By The Secretary Of The Army
System and method for measurement of entangled photons wavefunctions
CN117043808A
( en )
2021-03-19
2023-11-10
æ ªå¼ä¼ç¤¾ä¸è
Information management system and method for autonomous control of manufacturing processes and services
WO2022211731A1
( en )
*
2021-03-30
2022-10-06
Speqtral Pte. Ltd.
Secure symmetric key distribution
GB2605392B
( en )
*
2021-03-30
2023-12-06
Toshiba Kk
Optical system and method
US11496447B1
( en )
*
2021-04-16
2022-11-08
Umm AI-Qura University
Cryptosystem and method with efficient elliptic curve operators for an extraction of EiSi coordinate system
US11711689B2
( en )
*
2021-05-26
2023-07-25
Google Llc
Secure localized connectionless handoffs of data
US12052350B2
( en )
*
2021-07-08
2024-07-30
Cisco Technology, Inc.
Quantum resistant secure key distribution in various protocols and technologies
WO2023000075A1
( en )
*
2021-07-23
2023-01-26
Huawei Technologies Canada Co., Ltd.
Methods and systems of multi-user quantum key distribution and management
US11743037B2
( en )
*
2021-07-29
2023-08-29
QuNu Labs Private Ltd
Quantum key distribution system and method for performing differential phase shift in a quantum network
EP4125238B1
( en )
*
2021-07-29
2026-01-28
Id Quantique Sa
System and method using minimally trusted nodes over a qkd network
JP7837537B2
( en )
2021-12-23
2026-03-31
å½ç«ç ç©¶éçºæ³äººæ å ±éä¿¡ç ç©¶æ©æ§
Cryptographic key sharing system
US12413391B2
( en )
*
2022-02-23
2025-09-09
Mellanox Technologies, Ltd.
Devices, systems, and methods for integrating encryption service channels with a data path
GB2616049A
( en )
2022-02-25
2023-08-30
Toshiba Kk
Authentication method and system, a quantum communication network, and a node for quantum communication
US12212668B2
( en )
*
2022-03-29
2025-01-28
Verizon Patent And Licensing Inc.
Mobile edge network cryptographic key delivery using quantum cryptography
US12192328B1
( en )
2022-05-10
2025-01-07
Wells Fargo Bank, N.A.
Systems and methods for secure communication based on random key derivation
CN119072897A
( en )
2022-05-25
2024-12-03
ä½åçµæ°å·¥ä¸æ ªå¼ä¼ç¤¾
Encryption system and encryption method
US12034836B1
( en )
*
2022-06-30
2024-07-09
Wells Fargo Bank, N.A.
Systems and methods for hardware security module communication management
EP4311160A1
( en )
2022-07-22
2024-01-24
Terra Quantum AG
A quantum key distribution device and method suitable for establishing a global quantum key distribution network
WO2024136930A2
( en )
*
2022-09-14
2024-06-27
Nec Laboratories America, Inc.
Hybrid quantum cryptography protocol for optical communications
JP2024048894A
( en )
2022-09-28
2024-04-09
æ¥æ¬é»æ°æ ªå¼ä¼ç¤¾
Relay device, transmission control method, and network management device in quantum cryptography communication network
US12231416B1
( en )
2022-12-06
2025-02-18
Wells Fargo Bank, N.A.
Systems and methods for multi-factor device authentication using quantum entangled particles
JPWO2024127597A1
( en )
*
2022-12-15
2024-06-20
WO2024127593A1
( en )
*
2022-12-15
2024-06-20
æ¥æ¬é»ä¿¡é»è©±æ ªå¼ä¼ç¤¾
Encryption device, key generation method, and encryption program
GB2625539A
( en )
*
2022-12-19
2024-06-26
Arqit Ltd
Multi-algorithm bootstrapping
EP4606056A1
( en )
*
2023-02-15
2025-08-27
evolutionQ Inc.
Multimodal cryptographic system, computer executable instructions and method
CN116318689B
( en )
*
2023-05-25
2023-07-28
天津å¸åå¸è§å设计ç ç©¶æ»é¢æéå ¬å¸
Method and system for improving information transmission safety of Internet of things equipment by utilizing quantum key
CN116743445B
( en )
*
2023-06-01
2024-04-09
æµåå®è¿ ç§ææéå ¬å¸
Secret communication system
GB2634920A
( en )
*
2023-10-25
2025-04-30
Toshiba Kk
A node for a quantum communication network, a quantum communication network and a method of producing a signed message
US20250175329A1
( en )
*
2023-11-27
2025-05-29
T-Mobile Innovations Llc
Data communication with network slices that deliver quantum capabilities
US12452049B2
( en )
2024-01-05
2025-10-21
Bank Of America Corporation
System and method for AI-based adaptive security parameter calculation in license key generation with quantum-resistant protections
WO2025156042A1
( en )
*
2024-01-23
2025-07-31
Evolutionq Inc.
System and method for performing secure multi-hop quantum key distribution
CN118694528B
( en )
*
2024-08-28
2024-12-20
ä¸çµä¿¡éåä¿¡æ¯ç§æé墿éå ¬å¸
Anti-quantum security enhancement method for on-line certificate issuing and key pair distribution
US20260113183A1
( en )
*
2024-10-23
2026-04-23
Bank Of America Corporation
System and method for encoding and encrypting sensitive data based on quantum entanglement
CN119788193A
( en )
*
2025-03-05
2025-04-08
æ·±å³å¸é«æ¯ééä¿¡è¡ä»½æéå ¬å¸
End-side deployment and ICT fusion method and system based on quantum communication technology
Citations (12)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20040184603A1
( en )
*
2003-03-21
2004-09-23
Pearson David Spencer
Systems and methods for quantum cryptographic key transport
US20050063547A1
( en )
*
2003-09-19
2005-03-24
Audrius Berzanskis
Standards-compliant encryption with QKD
US20050286723A1
( en )
*
2004-06-28
2005-12-29
Magiq Technologies, Inc.
QKD system network
US20060212936A1
( en )
*
2005-03-16
2006-09-21
Audrius Berzanskis
Method of integrating QKD with IPSec
JP2011082832A
( en )
2009-10-07
2011-04-21
Nec Corp
Encryption communication system and encryption communication method
US20110188659A1
( en )
*
2008-09-10
2011-08-04
Mimos Berhad
Method of integrating quantum key distribution with internet key exchange protocol
US20130051559A1
( en )
*
2011-08-26
2013-02-28
Shinichi Baba
Key sharing device, key sharing method, and computer program product
US20130251145A1
( en )
*
2010-12-02
2013-09-26
Qinetiq Limited
Quantum key distribution
US20150215122A1
( en )
*
2014-01-30
2015-07-30
Kabushiki Kaisha Toshiba
Quantum key distribution device, quantum key distribution system, and quantum key distribution method
US20160248581A1
( en )
*
2015-01-08
2016-08-25
Alibaba Group Holding Limited
Quantum key distribution system, method and apparatus based on trusted relay
US20170338952A1
( en )
*
2016-05-20
2017-11-23
Electronics And Telecommunications Research Institute
Apparatus for quantum key distribution on a quantum network and method using the same
US20180351734A1
( en )
*
2015-05-05
2018-12-06
Quantumctek Co., Ltd
Cloud storage method and system
Family Cites Families (5)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US8082443B2
( en )
*
2006-01-09
2011-12-20
Bbnt Solutions Llc.
Pedigrees for quantum cryptography
GB0801395D0
( en )
*
2008-01-25
2008-03-05
Qinetiq Ltd
Network having quantum key distribution
EP2245789B1
( en )
*
2008-01-25
2014-08-20
QinetiQ Limited
Quantum cryptography apparatus
EP3432509B1
( en )
*
2017-07-21
2021-06-09
ID Quantique S.A.
Quantum enhanced application security
CN107453869B
( en )
*
2017-09-01
2019-10-22
ä¸å½çµåç§æéå¢å ¬å¸ç¬¬ä¸åç ç©¶æ
A Method of Realizing Quantum Safe IPSecVPN
2019
2019-02-22
GB
GB1902472.8A
patent/GB2581528B/en
active
Active
2020
2020-02-18
JP
JP2020025093A
patent/JP7021272B2/en
active
Active
2020-02-21
US
US16/797,575
patent/US11196550B2/en
active
Active
2021
2021-10-20
US
US17/505,720
patent/US11695550B2/en
active
Active
Patent Citations (13)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20040184603A1
( en )
*
2003-03-21
2004-09-23
Pearson David Spencer
Systems and methods for quantum cryptographic key transport
US20050063547A1
( en )
*
2003-09-19
2005-03-24
Audrius Berzanskis
Standards-compliant encryption with QKD
US20050286723A1
( en )
*
2004-06-28
2005-12-29
Magiq Technologies, Inc.
QKD system network
JP2008504791A
( en )
2004-06-28
2008-02-14
ãã¸ã㯠ãã¯ããã¸ã¼ãºï¼ã¤ã³ã³ã¼ãã¬ã¼ããã
QKD system network
US20060212936A1
( en )
*
2005-03-16
2006-09-21
Audrius Berzanskis
Method of integrating QKD with IPSec
US20110188659A1
( en )
*
2008-09-10
2011-08-04
Mimos Berhad
Method of integrating quantum key distribution with internet key exchange protocol
JP2011082832A
( en )
2009-10-07
2011-04-21
Nec Corp
Encryption communication system and encryption communication method
US20130251145A1
( en )
*
2010-12-02
2013-09-26
Qinetiq Limited
Quantum key distribution
US20130051559A1
( en )
*
2011-08-26
2013-02-28
Shinichi Baba
Key sharing device, key sharing method, and computer program product
US20150215122A1
( en )
*
2014-01-30
2015-07-30
Kabushiki Kaisha Toshiba
Quantum key distribution device, quantum key distribution system, and quantum key distribution method
US20160248581A1
( en )
*
2015-01-08
2016-08-25
Alibaba Group Holding Limited
Quantum key distribution system, method and apparatus based on trusted relay
US20180351734A1
( en )
*
2015-05-05
2018-12-06
Quantumctek Co., Ltd
Cloud storage method and system
US20170338952A1
( en )
*
2016-05-20
2017-11-23
Electronics And Telecommunications Research Institute
Apparatus for quantum key distribution on a quantum network and method using the same
Non-Patent Citations (14)
* Cited by examiner, â Cited by third party
Title
Aldhaheri et al., " A novel secure quantum key distribution algorithm, " IEEE Long Island Systems, Applications and Technology (LISAT) Conference 2014, 2014, pp. 1-4, doi: 10.1109/LISAT.2014.6845185. (Year: 2014).
*
Alléaume et al.-" Topological optimization of quantum key distribution networks ", New Journal of Physics, vol. 11, Jul. 2009, (25 pages).
Douglas Stebila, et al., " Post-quantum Key Exchange for the Internet and the Open Quantum Safe Project ", International Conference on Selected Areas in Cryptography, 2016, pp. 14-37.
Examination Report dated Jul. 6, 2021 issued in corresponding patent application GB1902472.8 (3 pages).
Gong et al., " Applied Research on Quantum Key Distribution Technology in Distributed Space TT&C Network ", IEEE, doi: 10.1109/WICOM.2009.5302783, 2009, pp. 1-4. (Year: 2009).
Hegde et al., " A Comparative study on state of art Cryptographic key distribution with quantum networks, " 2022 IEEE 3rd Global Conference for Advancement in Technology (GCAT), 2022, pp. 1-7, doi: 10.1109/GCAT55367.2022.9971870. (Year: 2022).
*
Japanese Office Action dated Mar. 30, 2021 in Japanese Patent Application No. 2020-025093 (with English translation), 6 pages.
Joppe W. Bos, et al., " Post-quantum key exchange for the TLS protocol from the ring learning with errors problem ", 2015 IEEE Symposium on Security and Privacy, May 2015, pp. 553-570.
Logan O. Mailloux, et al., " Post-Quantum Cryptography: What Advancements in Quantum Computing Mean for IT Professionals ", IT Professional, vol. 18, No. 5, 2016, pp. 42-47.
Makanda et al., " Key Distribution Protocol on Quantum Cryptography, " 2013 International Conference on IT Convergence and Security (ICITCS), 2013, pp. 1-2, doi: 10.1109/ICITCS.2013.6717850. (Year: 2013).
*
Pattaranantakul et al., " Secure and efficient key management technique in quantum cryptography network ", IEEE, doi: 10.1109/ ICUFN.2012.6261711, 2012, pp. 280-285. (Year: 2012).
Techateerawat, " Network Management System for Quantum Key Distribution ", IEEE, doi: 10.1109/ITNG.2012.58, 2012, pp. 807-808. (Year: 2012)
William Buchanan, et al., " Will quantum computers be the end of public key encryption? ", Journal of Cyber Security Technology, vol. 1, No. 1, 2017, pp. 1-22 & cover page.
Zhou et al., " Quantum Network: Security Assessment and Key Management, " in IEEE/ACM Transactions on Networking, vol. 30, No. 3, pp. 1328-1339, Jun. 2022, doi: 10.1109/TNET.2021.3136943. (Year: 2022).
*
Cited By (1)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20250240155A1
( en )
*
2024-01-18
2025-07-24
Qunu Labs Private Limited
System and method for point-to-point decoy differential phase shift (dps) quantum key distribution (qkd)
Also Published As
Publication number
Publication date
GB2581528A
( en )
2020-08-26
US20200274701A1
( en )
2020-08-27
US20220045855A1
( en )
2022-02-10
JP7021272B2
( en )
2022-02-16
JP2020145672A
( en )
2020-09-10
US11196550B2
( en )
2021-12-07
GB2581528B
( en )
2022-05-18
GB201902472D0
( en )
2019-04-10
Similar Documents
Publication
Publication Date
Title
US11196550B2
( en )
2021-12-07
Secure communication network
EP3243294B1
( en )
2019-12-25
Communication with everlasting security from short-term-secure encrypted quantum communication
US9160529B2
( en )
2015-10-13
Secret communication system and method for generating shared secret information
US12250300B2
( en )
2025-03-11
Authentication method and system, a quantum communication network, and a node for quantum communication
US20240313949A1
( en )
2024-09-19
Key exchange protocol for quantum network
EP4107902A1
( en )
2022-12-28
A method for quantum key distribution, a method for transmitting an optical signal, a method for receiving an optical signal, and a receiver of an optical signal for quantum key distribution
KR20040058326A
( en )
2004-07-03
Cryptographic communication apparatus
<tr item