ConceptioArchiveGoogle Patents
Google Patentsopen access

Authentication using key distribution through segmented quantum computing … — Accenture Global Solutions Limited (US11736298B2)

Accenture Global Solutions Limited · Google Patents
Google Patents · Patents · License: Open Access
Open Source ↗
accentureglobalsolutionslimited
patent, google patents, intellectual property, US11736298B2, Accenture Global Solutions Limited, Benjamin Glen McCarty, en, 2023

ABSTRACT

Abstract

Methods, systems, and apparatus for authenticating and authorizing users using quantum key distribution through segmented quantum computing environments. In one aspect, a method includes receiving a first and second plaintext data input from a first party and from a second party, respectively; applying a quantum computation translation operation to the first and second plaintext data inputs to generate a corresponding first sequence of quantum computations and a second sequence of quantum computations; implementing the first and second sequence of quantum computations in a first and second segmented quantum computing environment, respectively, to obtain a first and second sequence of measurement results; generating a first and second encryption key using the first and second sequence of measurement results, respectively, and an encrypted authorization token using the second encryption key; and sending the first encryption key to the first party, and the encrypted authorization token to the second party.

Description

CROSS REFERENCE TO RELATED APPLICATION

This application is a continuation of U.S. patent application Ser. No. 16/599,586, filed Oct. 11, 2019, now allowed, which is incorporated by reference in its entirety.

BACKGROUND

Authentication techniques are used for many purposes, including granting access to client devices, confidential data, computer networks, and other secure systems. There are various authentication techniques that can be used to verify the identity of a person attempting to gain access to a system. One common authentication technique is the use of passwords. However, passwords are easily stolen. Another authentication technique is multi-factor authentication in which two or more authentication factors—knowledge factors such as a password, possession factors such as a hardware or software token, or inherence factors such as a biometric identifier or signature—are verified prior to granting access. This technique can be more secure than using a password alone. However, even multi-factor authentication techniques that use strong encryption may not be secure against quantum computing attacks.

SUMMARY

This specification describes systems, methods, devices and other techniques for authenticating and authorizing users using quantum key distribution through segmented quantum computing environments.

In general, one innovative aspect of the subject matter described in this specification can be implemented in a method that includes receiving i) a first plaintext data input from a first party, and ii) a second plaintext data input from a second party; applying a quantum computation translation operation to i) the first plaintext data input to generate a corresponding first sequence of quantum computations, and ii) the second plaintext data input to generate a corresponding second sequence of quantum computations; implementing i) the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results, and ii) the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results; generating i) a first encryption key using the first sequence of measurement results, ii) a second encryption key using the second sequence of measurement results, and iii) an encrypted authorization token using the second encryption key; and sending i) the first encryption key to the first party, and ii) the encrypted authorization token to the second party.

Other implementations of this aspect include corresponding classical, quantum or classical-quantum computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods. A system of one or more classical and quantum computers can be configured to perform particular operations or actions by virtue of having software, firmware, hardware, or a combination thereof installed on the system that in operation causes or cause the system to perform the actions. One or more computer programs can be configured to perform particular operations or actions by virtue of including instructions that, when executed by data processing apparatus, cause the apparatus to perform the actions.

The foregoing and other implementations can each optionally include one or more of the following features, alone or in combination. In some implementations applying a quantum computation translation operation to i) the first plaintext data input to generate a corresponding first sequence of quantum computations, and ii) the second plaintext data input to generate a corresponding second sequence of quantum computations comprises independently: applying the quantum computation translation operation to the first plaintext data input using a first classical processor in the first segmented quantum computing environment; and applying the quantum computation translation operation to the second plaintext data input using a second classical processor in the second segmented quantum computing environment.

In some implementations implementing i) the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results comprises, for each quantum computation in the first sequence of quantum computations: implementing the quantum computation on a first qubit included in the first segmented quantum computing environment; measuring the first qubit in the first segmented quantum computing environment; and providing a measurement result to classical hardware included in the first segmented quantum computing environment.

In some implementations the classical hardware is subjected to one or more of Network-Function-Virtualization or Software-Defined-Networking.

In some implementations implementing i) the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results comprises, for each quantum computation in the second sequence of quantum computations: implementing the quantum computation on a second qubit included in the second segmented quantum computing environment; measuring the second qubit in the second segmented quantum computing environment; and providing a measurement result to classical hardware included in the second segmented quantum computing environment.

In some implementations the classical hardware is subjected to one or more of Network-Function-Virtualization or Software-Defined-Networking.

In some implementations the first segmented quantum computing environment comprises a first ephemeral segmented quantum computing environment and the second segmented quantum computing environment comprises a second ephemeral segmented quantum computing environment.

In some implementations the method further comprises: receiving, from a second party, an indication that a first party has requested access to data stored by the second party; and creating the first ephemeral segmented quantum computing environment and the second ephemeral segmented quantum computing environment.

In some implementations the first plaintext data input comprises a first response to an authentication challenge and the second plaintext data input comprises a second response to the authentication challenge.

In some implementations the authentication challenge comprises an authentication challenge sent to the first party from the second party in response to the second party receiving a request from the first party to access to data stored by the second party, the authentication challenge comprising an authentication challenge previously established between the first party and the second party during an enrollment process.

In some implementations the second response to the authentication challenge comprises an expected response to the authentication challenge.

In some implementations the first plaintext data input is received via an Out-of-Band authenticator device.

In some implementations the method further comprises sending, to the second party, an indication that the first plaintext data input has been received from the first party.

In some implementations the method further comprises destroying the first encryption key after sending the first encryption key to the first party; and destroying the first segmented quantum computing environment after destroying the first encryption key.

In some implementations the method further comprises destroying the second encryption key after generating the encrypted authorization token; and destroying the second segmented quantum computing environment after sending the encrypted authorization token to the second party.

In some implementations in response to receiving the first encryption key, the first party provides the first encryption key to the second party; and the second party authorizes access to data requested by the first party when the first encryption key decrypts the encrypted authorization token.

In some implementations the first segmented quantum computing environment comprises a first qubit and the second segmented quantum computing environment comprises a second qubit.

In some implementations implementing i) the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results, and ii) the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results comprises, for an n-th quantum computation in the first sequence of quantum computations and in the second sequence of quantum computations: initializing the first qubit and the second qubit in a zero state; initializing a third qubit and a fourth qubit in a zero state; entangling the third qubit and the fourth qubit; applying a first swap quantum gate to the first qubit and the third qubit; applying a second swap quantum gate to the second qubit and the fourth qubit; applying the n-th quantum computation in the first sequence of quantum computations on the first qubit and measuring the first qubit to obtain a respective n-th measurement result in the first sequence of measurement results; and applying the n-th quantum computation in the second sequence of quantum computations on the second qubit and measuring the second qubit to obtain a respective n-th measurement result in the second sequence of measurement results.

In some implementations entangling the third qubit and the fourth qubit comprises applying a Hadamard gate to the third qubit and a CNOT operation to the third qubit and the fourth qubit, wherein the third qubit acts as a control for the CNOT operation.

In some implementations the quantum computation translation operation comprises an operation that maps each character in a plaintext data input to a respective quantum computation.

In some implementations the first plaintext data input and the second plaintext data input comprise hexadecimal data inputs.

In some implementations the quantum computation translation operation maps each hexadecimal character in a data input to a respective quantum computation in a set of multiple quantum computations.

In some implementations the set of multiple quantum computations comprises quantum computations comprising at most three single-qubit quantum gates.

In some implementations the set of multiple quantum computations comprises five quantum computations comprising one respective single-qubit quantum gate.

In some implementations the set of multiple quantum computations comprises seven quantum computations comprising two respective single-qubit quantum gates.

In some implementations the set of multiple quantum computations comprises four quantum computations comprising three respective single-qubit quantum gates.

In some implementations each quantum computation in the set of multiple quantum computations comprises one or more single-qubit quantum gates from the Clifford group.

In some implementations each quantum computation in the set of multiple quantum computations comprises one or more single-qubit quantum gates from a set of single-qubit quantum gates, the set of single qubit gates comprising identity operations, Pauli-X gates, Pauli-Y gates, Pauli-Z gates, Hadamard gates, S gates and complex conjugates of the S gate.

In some implementations the quantum computation translation operation maps: a first hexadecimal character to a single qubit identity operation; a second hexadecimal character to a Pauli-X gate, wherein the second hexadecimal character is different to the first hexadecimal character; a third hexadecimal character to a Hadamard gate, wherein the third hexadecimal character is different to the first and second hexadecimal character; a fourth hexadecimal character to a Hadamard gate and a Pauli-X gate, wherein the fourth hexadecimal character is different to the first to third hexadecimal character; a fifth hexadecimal character to a Hadamard gate and a S gate, wherein the fifth hexadecimal character is different to the first to fourth hexadecimal character; a sixth hexadecimal character to a Hadamard gate and a complex conjugate of an S gate, wherein the sixth hexadecimal character is different to the first to fifth hexadecimal character; a seventh hexadecimal character to a Pauli-Y gate and a Hadamard gate, wherein the seventh hexadecimal character is different to the first to sixth hexadecimal character; a eighth hexadecimal character to a Pauli-X gate and a Hadamard gate, wherein the eighth hexadecimal character is different to the first to seventh hexadecimal character; a ninth hexadecimal character to a Pauli-Z gate and a Hadamard gate, wherein the ninth hexadecimal character is different to the first to eighth hexadecimal character; a tenth hexadecimal character to a S gate and a Hadamard gate, wherein the tenth hexadecimal character is different to the first to ninth hexadecimal character; a eleventh hexadecimal character to a S gate, wherein the eleventh hexadecimal character is different to the first to tenth hexadecimal character; a twelfth hexadecimal character to a complex conjugate of an S gate, wherein the twelfth hexadecimal character is different to the first to eleventh hexadecimal character; a thirteenth hexadecimal character to a Pauli-X gate, an S gate, and a Hadamard gate, wherein the thirteenth hexadecimal character is different to the first to twelfth hexadecimal character; a fourteenth hexadecimal character to a Pauli-Y gate, an S gate, and a Hadamard gate, wherein the fourteenth hexadecimal character is different to the first to thirteenth hexadecimal character; a fifteenth hexadecimal character to a Pauli-Z gate, an S gate, and a Hadamard gate, wherein the fifteenth hexadecimal character is different to the first to fourteenth hexadecimal character; and a sixteenth hexadecimal character to a S gate, a Hadamard gate, and a Pauli-X gate wherein the sixteenth hexadecimal character is different to the first to fifteenth hexadecimal character.

In general, another innovative aspect of the subject matter described in this specification can be implemented in a method that includes sending, from a first party accessor and to a second party access target, a request to access the second party access target; receiving, from the second party access target and at the first party accessor, an authentication challenge, wherein the authentication challenge comprises an authentication challenge previously established between the first party accessor and the second party access target during an enrollment process; generating, by the first party accessor, a response to the received authentication challenge, wherein the response comprises a first plaintext data input; sending, from the first party accessor, the first plaintext data input to a third party quantum computing environment, wherein the third party quantum computing environment: applies a quantum computation translation operation to i) the first plaintext data input to generate a corresponding first sequence of quantum computations, and ii) a second plaintext data input received from the second party access target to generate a corresponding second sequence of quantum computations; implements i) the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results, and ii) the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results; and generates i) a first encryption key using the first sequence of measurement results, ii) a second encryption key using the second sequence of measurement results, and iii) an encrypted authorization token using the second encryption key; receiving, by the first party accessor and from the third party quantum computing environment, the first encryption key; providing the first encryption key to the second party access target; and in response to the second party access target authorizing the reque

CROSS REFERENCE TO RELATED APPLICATION

This application is a continuation of U.S. patent application Ser. No. 16/599,586, filed Oct. 11, 2019, now allowed, which is incorporated by reference in its entirety.

BACKGROUND

Authentication techniques are used for many purposes, including granting access to client devices, confidential data, computer networks, and other secure systems. There are various authentication techniques that can be used to verify the identity of a person attempting to gain access to a system. One common authentication technique is the use of passwords. However, passwords are easily stolen. Another authentication technique is multi-factor authentication in which two or more authentication factors—knowledge factors such as a password, possession factors such as a hardware or software token, or inherence factors such as a biometric identifier or signature—are verified prior to granting access. This technique can be more secure than using a password alone. However, even multi-factor authentication techniques that use strong encryption may not be secure against quantum computing attacks.

SUMMARY

This specification describes systems, methods, devices and other techniques for authenticating and authorizing users using quantum key distribution through segmented quantum computing environments.

In general, one innovative aspect of the subject matter described in this specification can be implemented in a method that includes receiving i) a first plaintext data input from a first party, and ii) a second plaintext data input from a second party; applying a quantum computation translation operation to i) the first plaintext data input to generate a corresponding first sequence of quantum computations, and ii) the second plaintext data input to generate a corresponding second sequence of quantum computations; implementing i) the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results, and ii) the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results; generating i) a first encryption key using the first sequence of measurement results, ii) a second encryption key using the second sequence of measurement results, and iii) an encrypted authorization token using the second encryption key; and sending i) the first encryption key to the first party, and ii) the encrypted authorization token to the second party.

Other implementations of this aspect include corresponding classical, quantum or classical-quantum computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods. A system of one or more classical and quantum computers can be configured to perform particular operations or actions by virtue of having software, firmware, hardware, or a combination thereof installed on the system that in operation causes or cause the system to perform the actions. One or more computer programs can be configured to perform particular operations or actions by virtue of including instructions that, when executed by data processing apparatus, cause the apparatus to perform the actions.

The foregoing and other implementations can each optionally include one or more of the following features, alone or in combination. In some implementations applying a quantum computation translation operation to i) the first plaintext data input to generate a corresponding first sequence of quantum computations, and ii) the second plaintext data input to generate a corresponding second sequence of quantum computations comprises independently: applying the quantum computation translation operation to the first plaintext data input using a first classical processor in the first segmented quantum computing environment; and applying the quantum computation translation operation to the second plaintext data input using a second classical processor in the second segmented quantum computing environment.

In some implementations implementing i) the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results comprises, for each quantum computation in the first sequence of quantum computations: implementing the quantum computation on a first qubit included in the first segmented quantum computing environment; measuring the first qubit in the first segmented quantum computing environment; and providing a measurement result to classical hardware included in the first segmented quantum computing environment.

In some implementations the classical hardware is subjected to one or more of Network-Function-Virtualization or Software-Defined-Networking.

In some implementations implementing i) the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results comprises, for each quantum computation in the second sequence of quantum computations: implementing the quantum computation on a second qubit included in the second segmented quantum computing environment; measuring the second qubit in the second segmented quantum computing environment; and providing a measurement result to classical hardware included in the second segmented quantum computing environment.

In some implementations the classical hardware is subjected to one or more of Network-Function-Virtualization or Software-Defined-Networking.

In some implementations the first segmented quantum computing environment comprises a first ephemeral segmented quantum computing environment and the second segmented quantum computing environment comprises a second ephemeral segmented quantum computing environment.

In some implementations the method further comprises: receiving, from a second party, an indication that a first party has requested access to data stored by the second party; and creating the first ephemeral segmented quantum computing environment and the second ephemeral segmented quantum computing environment.

In some implementations the first plaintext data input comprises a first response to an authentication challenge and the second plaintext data input comprises a second response to the authentication challenge.

In some implementations the authentication challenge comprises an authentication challenge sent to the first party from the second party in response to the second party receiving a request from the first party to access to data stored by the second party, the authentication challenge comprising an authentication challenge previously established between the first party and the second party during an enrollment process.

In some implementations the second response to the authentication challenge comprises an expected response to the authentication challenge.

In some implementations the first plaintext data input is received via an Out-of-Band authenticator device.

In some implementations the method further comprises sending, to the second party, an indication that the first plaintext data input has been received from the first party.

In some implementations the method further comprises destroying the first encryption key after sending the first encryption key to the first party; and destroying the first segmented quantum computing environment after destroying the first encryption key.

In some implementations the method further comprises destroying the second encryption key after generating the encrypted authorization token; and destroying the second segmented quantum computing environment after sending the encrypted authorization token to the second party.

In some implementations in response to receiving the first encryption key, the first party provides the first encryption key to the second party; and the second party authorizes access to data requested by the first party when the first encryption key decrypts the encrypted authorization token.

In some implementations the first segmented quantum computing environment comprises a first qubit and the second segmented quantum computing environment comprises a second qubit.

In some implementations implementing i) the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results, and ii) the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results comprises, for an n-th quantum computation in the first sequence of quantum computations and in the second sequence of quantum computations: initializing the first qubit and the second qubit in a zero state; initializing a third qubit and a fourth qubit in a zero state; entangling the third qubit and the fourth qubit; applying a first swap quantum gate to the first qubit and the third qubit; applying a second swap quantum gate to the second qubit and the fourth qubit; applying the n-th quantum computation in the first sequence of quantum computations on the first qubit and measuring the first qubit to obtain a respective n-th measurement result in the first sequence of measurement results; and applying the n-th quantum computation in the second sequence of quantum computations on the second qubit and measuring the second qubit to obtain a respective n-th measurement result in the second sequence of measurement results.

In some implementations entangling the third qubit and the fourth qubit comprises applying a Hadamard gate to the third qubit and a CNOT operation to the third qubit and the fourth qubit, wherein the third qubit acts as a control for the CNOT operation.

In some implementations the quantum computation translation operation comprises an operation that maps each character in a plaintext data input to a respective quantum computation.

In some implementations the first plaintext data input and the second plaintext data input comprise hexadecimal data inputs.

In some implementations the quantum computation translation operation maps each hexadecimal character in a data input to a respective quantum computation in a set of multiple quantum computations.

In some implementations the set of multiple quantum computations comprises quantum computations comprising at most three single-qubit quantum gates.

In some implementations the set of multiple quantum computations comprises five quantum computations comprising one respective single-qubit quantum gate.

In some implementations the set of multiple quantum computations comprises seven quantum computations comprising two respective single-qubit quantum gates.

In some implementations the set of multiple quantum computations comprises four quantum computations comprising three respective single-qubit quantum gates.

In some implementations each quantum computation in the set of multiple quantum computations comprises one or more single-qubit quantum gates from the Clifford group.

In some implementations each quantum computation in the set of multiple quantum computations comprises one or more single-qubit quantum gates from a set of single-qubit quantum gates, the set of single qubit gates comprising identity operations, Pauli-X gates, Pauli-Y gates, Pauli-Z gates, Hadamard gates, S gates and complex conjugates of the S gate.

In some implementations the quantum computation translation operation maps: a first hexadecimal character to a single qubit identity operation; a second hexadecimal character to a Pauli-X gate, wherein the second hexadecimal character is different to the first hexadecimal character; a third hexadecimal character to a Hadamard gate, wherein the third hexadecimal character is different to the first and second hexadecimal character; a fourth hexadecimal character to a Hadamard gate and a Pauli-X gate, wherein the fourth hexadecimal character is different to the first to third hexadecimal character; a fifth hexadecimal character to a Hadamard gate and a S gate, wherein the fifth hexadecimal character is different to the first to fourth hexadecimal character; a sixth hexadecimal character to a Hadamard gate and a complex conjugate of an S gate, wherein the sixth hexadecimal character is different to the first to fifth hexadecimal character; a seventh hexadecimal character to a Pauli-Y gate and a Hadamard gate, wherein the seventh hexadecimal character is different to the first to sixth hexadecimal character; a eighth hexadecimal character to a Pauli-X gate and a Hadamard gate, wherein the eighth hexadecimal character is different to the first to seventh hexadecimal character; a ninth hexadecimal character to a Pauli-Z gate and a Hadamard gate, wherein the ninth hexadecimal character is different to the first to eighth hexadecimal character; a tenth hexadecimal character to a S gate and a Hadamard gate, wherein the tenth hexadecimal character is different to the first to ninth hexadecimal character; a eleventh hexadecimal character to a S gate, wherein the eleventh hexadecimal character is different to the first to tenth hexadecimal character; a twelfth hexadecimal character to a complex conjugate of an S gate, wherein the twelfth hexadecimal character is different to the first to eleventh hexadecimal character; a thirteenth hexadecimal character to a Pauli-X gate, an S gate, and a Hadamard gate, wherein the thirteenth hexadecimal character is different to the first to twelfth hexadecimal character; a fourteenth hexadecimal character to a Pauli-Y gate, an S gate, and a Hadamard gate, wherein the fourteenth hexadecimal character is different to the first to thirteenth hexadecimal character; a fifteenth hexadecimal character to a Pauli-Z gate, an S gate, and a Hadamard gate, wherein the fifteenth hexadecimal character is different to the first to fourteenth hexadecimal character; and a sixteenth hexadecimal character to a S gate, a Hadamard gate, and a Pauli-X gate wherein the sixteenth hexadecimal character is different to the first to fifteenth hexadecimal character.

In general, another innovative aspect of the subject matter described in this specification can be implemented in a method that includes sending, from a first party accessor and to a second party access target, a request to access the second party access target; receiving, from the second party access target and at the first party accessor, an authentication challenge, wherein the authentication challenge comprises an authentication challenge previously established between the first party accessor and the second party access target during an enrollment process; generating, by the first party accessor, a response to the received authentication challenge, wherein the response comprises a first plaintext data input; sending, from the first party accessor, the first plaintext data input to a third party quantum computing environment, wherein the third party quantum computing environment: applies a quantum computation translation operation to i) the first plaintext data input to generate a corresponding first sequence of quantum computations, and ii) a second plaintext data input received from the second party access target to generate a corresponding second sequence of quantum computations; implements i) the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results, and ii) the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results; and generates i) a first encryption key using the first sequence of measurement results, ii) a second encryption key using the second sequence of measurement results, and iii) an encrypted authorization token using the second encryption key; receiving, by the first party accessor and from the third party quantum computing environment, the first encryption key; providing the first encryption key to the second party access target; and in response to the second party access target authorizing the request using the encrypted authorization token and the first encryption key, obtaining access to the second party access target; or in response to the second party denying the request using the encrypted authorization token and the first encryption key, receiving data indicating denial of access to the second party access target.

Other implementations of this aspect include corresponding classical, quantum or classical-quantum computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods. A system of one or more classical and quantum computers can be configured to perform particular operations or actions by virtue of having software, firmware, hardware, or a combination thereof installed on the system that in operation causes or cause the system to perform the actions. One or more computer programs can be configured to perform particular operations or actions by virtue of including instructions that, when executed by data processing apparatus, cause the apparatus to perform the actions.

In general, another innovative aspect of the subject matter described in this specification can be implemented in a method that includes receiving, by a second party access target and from a first party accessor, a request for access to the second party access target; sending, from the second party access target and to the first party accessor, an authentication challenge, wherein the authentication challenge comprises an authentication challenge previously established between the first party accessor and the second party access target during an enrollment process; sending, from the second party access target and to a third party quantum computing system, a response to the authentication challenge, wherein the response comprises a second plaintext data input and wherein the third party quantum computing environment: applies a quantum computation translation operation to i) a first plaintext data input received from the first party accessor to generate a corresponding first sequence of quantum computations, and ii) the second plaintext data input to generate a corresponding second sequence of quantum computations; implements i) the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results, and ii) the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results; and generates i) a first encryption key using the first sequence of measurement results, ii) a second encryption key using the second sequence of measurement results, and iii) an encrypted authorization token using the second encryption key; receiving, by the second party access target and from the third party, the encrypted authorization token; receiving, from the first party accessor, the first encryption key; decrypting the first encryption key using the encrypted authorization token; determining whether decryption of the first encryption key is successful or unsuccessful; in response to determining that the decryption is successful, allowing the first party accessor access; and in response to determining that the decryption is unsuccessful, denying the first party access.

Other implementations of this aspect include corresponding classical, quantum or classical-quantum computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform the actions of the methods. A system of one or more classical and quantum computers can be configured to perform particular operations or actions by virtue of having software, firmware, hardware, or a combination thereof installed on the system that in operation causes or cause the system to perform the actions. One or more computer programs can be configured to perform particular operations or actions by virtue of including instructions that, when executed by data processing apparatus, cause the apparatus to perform the actions.

The subject matter described in this specification can be implemented in particular ways so as to realize one or more of the following advantages.

The presently described authentication and authorization techniques provide secure authentication and authorization in post-quantum era where other conventional techniques, e.g., password-less multifactor authentication techniques that use strong encryption, may no longer be secure. In particular, the presently described techniques can be more effective at preventing quantum or classical attacks, e.g., attacks against asymmetric cryptography, from malicious parties since a same key is generated in independent computing environments without communicating or sharing the key between the independent computing environments. Furthermore, the advantages of quantum security can be achieved without requiring qubit transmission or a functional, scalable quantum internet.

Performing the classical and quantum computations required to generate authentication keys and tokens within segmented computing environments provides additional layers of security that can increase protection against threat actors seeking to manipulate or eavesdrop on the authentication process. For example, smaller and independent computing environments may be easier to isolate, e.g., against threat actors and to prevent unwanted information exchanges between the computing environments. In addition, smaller and independent computing environments may be easier to monitor and protect. As another example, segmenting the computing environment can require that hackers compromise multiple computing environments instead of one. As another example, segmented (or virtualized) computing environments can be generated in randomized (logically and physically) locations which mitigates eavesdroppers. As another example, virtualized computing environments can be designed to have reduced attack surfaces and attack vectors by only enabling functionality/components needed for the specialized task(s) expected of the virtual computing environment to generate a quantum key and nothing more.

In addition, the presently described techniques are consistent with current cloud architecture, since current software-as-a-service architectures run within shared hardware a lot of the time. The techniques allow for hardware to be shared. Therefore quantum operations can leverage qubits within close proximity (as is typical for quantum computing hardware setups) but the software environments can be segmented. Additionally, when they are separate, the segments of memory cannot be accessed by the other party. Further, they can be ephemeral so no collateral key material will be stored longer than the system needs the collateral key material.

The details of one or more implementations of the subject matter of this specification are set forth in the accompanying drawings and the description below. Other features, aspects, and advantages of the subject matter will become apparent from the description, the drawings, and the claims.

BRIEF DESCRIPTION OF THE DRAWINGS

FIG. 1 shows a conceptual block diagram of an example system performing an authentication and authorization process using quantum key distribution through segmented quantum computing environments.

FIG. 2 shows an example an example third party quantum computing system.

FIG. 3 shows an example quantum circuit for implementing a first quantum computation in a first segmented quantum computing environment and a second quantum computation in a second segmented quantum computing environment.

FIG. 4 illustrates an example quantum computation translation operation that maps hexadecimal characters to respective quantum computations.

FIG. 5 shows an example truth table of measurement results for implementations of an example quantum computation translation.

FIG. 6 is a flow diagram of an example process for generating a secure authentication token and secure authentication key.

FIG. 7 is a flow diagram of an example process for secure data access.

FIG. 8 is a flow diagram of an example process for providing secure access to a second party access target.

FIG. 9 depicts an example classical processor that may be used to carry out the classical computing methods described herein.

Like reference numbers and designations in the various drawings indicate like elements.

DETAILED DESCRIPTION

This specification describes methods and systems for authenticating a first party accessor and authorizing the first party accessor access to a second party access target using quantum key distribution through segmented quantum computing environments, e.g., ephemeral segmented quantum clouds.

FIG. 1 shows a conceptual block diagram of an example system 100 performing an authentication and authorization process using quantum key distribution through segmented quantum computing environments. Briefly, the system 100 includes a first party accessor 102 , a second party access target 104 , and a third party quantum computing system 106 . The components of the system 100 can exchange electronic communications over one or more networks, or can exchange communications in another way, such as over one or more wired or wireless connections. Generally, quantum computing components of the system 100 can be implemented as quantum computers having physical hardware like that described with respect to FIG. 2 and classical computing components of the system 100 can be implemented as one or more classical computers having physical hardware like that described with respect to FIG. 10 .

During stage (A) of the quantum key distribution process, the first party accessor 102 and second party access target 104 register, record and provision one or more authentication protocols in an enrollment stage.

For example, the first party accessor 102 and second party access target 104 can register, record and provision a challenge-response based authentication protocol. In these examples, during enrollment the first party accessor 102 and second party access target 104 can establish multiple challenge questions and corresponding responses. Then, after enrollment, when the first party accessor 102 requests access to the second party access target 104 , the second party access target 104 can send the first party accessor 102 a randomly selected challenge from the pre-established multiple challenge questions. The first party accessor 102 can generate a response to the received challenge, e.g., by applying a cryptographic hash function to the received challenge combined with a user password. The second party access target 104 can also apply the same hash function to the known response that corresponds to the randomly selected challenge, combined with its own copy of the user password. In a standard challenge-response approach, if the hash function outputs match, there is a high probability that the first party accessor 102 has submitted the correct password and the second party access target 104 can determine to allow the first party accessor 102 access.

For convenience, the authentication and authorization techniques described in this specification implement challenge-response authentication protocols, however other authentication protocols may also be used, e.g., password based authentication protocols.

During stage (B) of the quantum key distribution process, the first party accessor 102 transmits a request to the second party access target 104 for access to the second party access target 104 .

During stage (C) of the quantum key distribution process, the second party access target 104 selects an authentication challenge for the first party accessor 102 using information generated during stage (A), and transmits data representing the authentication challenge to the first party accessor 102 . The second party access target 104 can further transmit data indicating that the first party accessor 102 has requested authentication and access to the second party access target 104 to the third party quantum computing system 106 .

In some implementations, during stage (D) of the quantum key distribution process, the third party quantum computing system 106 creates a first and second ephemeral segmented quantum computing environment for ingestion and manipulation of data (e.g., responses to the authentication challenge) received from the first party accessor 102 and the second party access target 104 , respectively. In other implementations the third party quantum computing system 106 may already include the first and second segmented quantum computing environment.

During stage (E) of the quantum key distribution process, the first party accessor 102 generates a response to the authentication challenge received during stage (C), and transmits the generated response to the third party quantum computing system 106 . In some implementations the first party accessor 102 can use an Out-of-Band authenticator device, e.g., any device that utilizes a communications channel separate from the primary communication channels, to securely transmit the generated response to the third party quantum computing system 106 .

During stage (F) of the quantum key distribution process, the second party access target 104 selects or identifies an expected response to the authentication challenge using information generating during stage (A), and transmits the response to the third party quantum computing system 106 .

Optionally, in response to receiving the response to the authentication challenge from the first party accessor 102 and prior to step (F). the third party quantum computing system 106 can transmit data to the second party access target 104 confirming that the first party accessor 102 generated and provided a response to the authentication challenge. In this way, the second party access target's providing of an expected response occurs after the first party accessor has provided its response and thus the second party access target's provision of an expected response cannot be hacked and used by the first party accessor in providing its response that occurred earlier in time.

During stage (G) of the quantum key distribution process, the third party quantum computing system 106 uses two segmented quantum computing environments (e.g., ephemeral segmented quantum computing environments) to apply a quantum computation translation operation independently to a) the authentication challenge response received from the first party accessor 102 and b) the authentication challenge response received from the second party access target 104 . For example, the third party quantum computing system 106 can use a classical processor included in the first segmented quantum computing environment to apply the quantum computation translation operation to the authentication challenge response received from the first party accessor 102 and a classical processor included in the second segmented quantum computing environment to apply the quantum computation translation operation to the authentication challenge response received from the second party access target 104 .

The quantum computation translation operation maps the authentication challenge responses to respective sequences of quantum computations. For example, each character in an authentication challenge response can be mapped in sequence to a corresponding quantum computation, e.g., one or more quantum gates. Example quantum computation translation operations are described in more detail below with reference to FIGS. 4 - 6 .

During stage (H) of the quantum key distribution process, the third party quantum computing system 106 performs a first sequence of quantum computations corresponding to the authentication challenge responses received from the first party accessor 102 within one of the two segmented quantum computing environments, and performs a second sequence of quantum computations corresponding to the authentication challenge received from the second party access target 104 within the other segmented quantum computing environment. Performing sequences of quantum computations corresponding to authentication challenge responses within isolated quantum computing environments is described in more detail below with reference to FIGS. 3 - 6 .

The third party quantum computing system 106 uses measured results from the first sequence of quantum computations and second sequence of quantum computations to independently generate a first authentication key and a second authentication key, respectively, in each of the two segmented quantum computing environments. The third party quantum computing system 106 further generates an authorization token encrypted by the second symmetric authentication key.

During stage (I) and (J) of the quantum key distribution process, the third party quantum computing system 106 transmits the generated authentication token to the second party access target 104 and the generated first authentication key to the first party accessor 102 .

During stage (K) of the quantum key distribution process, the first party accessor 102 authenticates to the second party access target 104 . The first party accessor 102 transmits the first authentication key received from the third party quantum computing system 106 during stage (J) to the second party access target 104 . The second party access target 104 uses the first authentication key to decrypt the authorization token received from the third party quantum computing system 106 during stage (I). If the authorization key successfully decrypts the authorization token, the second party access target 104 grants the first party accessor 102 access to a second party access target resource. If the authorization key does not successfully decrypt the authorization token, the first party accessor 102 is denied access to the second party access target 104 .

FIG. 2 is a block diagram of an example third party quantum computing system 106 . The system 106 is an example of a system implemented as computer programs on one or more classical and quantum computing devices in one or more locations, in which the systems, components, and techniques described below can be implemented. In some implementations the third party quantum computing system 106 may be a cloud-based quantum computing service.

The example system 106 includes multiple classical processors 116 for performing classical computations and quantum computing hardware 110 for performing quantum computations. For convenience, the classical processors 116 and quantum computing hardware 110 are illustrated as separate entities. However, in some implementations one or more classical processors can be included in quantum computing hardware 110 , e.g., the quantum computing hardware 110 can include one or more components for performing classical computing operations.

The quantum computing hardware 110 includes components for performing quantum computations using quantum circuits. For example, the quantum computing hardware 110 includes multiple qubits 114 that are used to perform algorithmic operations or quantum computations and control devices 112 that operate the multiple qubits 114 .

The specific physical realization of the qubits 114 and how they interact with one another is dependent on a variety of factors including the type of quantum computations that the quantum computing hardware 110 is performing. For example, the qubits may be realized via atomic, molecular or solid-state quantum systems. In other examples the qubits may include, but are not limited to, superconducting qubits or semi-conducting qubits.

The qubits 114 can be frequency tunable. For example, each qubit may have associated operating frequencies that can be adjusted, e.g., using one or more of the control devices 112 , through application of voltage pulses via one or more drivelines coupled to the qubit. Example operating frequencies include qubit idling frequencies, qubit interaction frequencies, and qubit readout frequencies. Different frequencies correspond to different operations that the qubit can perform. For example, setting the operating frequency to a corresponding idling frequency may put the qubit into a state where it does not strongly interact with other qubits, and where it may be used to perform single-qubit gates, e.g., Pauli-X, Pauli-Y, Pauli-Z, Hadamard and S gates. As another example, in cases where qubits interact via couplers with fixed coupling, qubits can be configured to interact with one another by setting their respective operating frequencies at some gate-dependent frequency detuning from their common interaction frequency. In other cases, e.g., when the qubits interact via tunable couplers, qubits can be configured to interact with one another by setting the parameters of their respective couplers to enable interactions between the qubits and then by setting the qubit's respective operating frequencies at some gate-dependent frequency detuning from their common interaction frequency. Such interactions may be performed in order to perform multi-qubit gates, e.g., CNOT gates or swap gates.

The control devices 112 can further include measurement devices, e.g., readout resonators. Measurement results obtained via measurement devices may be provided to one or more of the classical processors 116 for processing and analyzing.

The classical processors 116 include components for performing classical computations. For example, the classical processors 116 can be configured to apply quantum computation translation operations to authentication challenge responses received at the third party <figure-callout id="106" label="quantum computing system" filenames="US11736298-20230822-D00000.png,US11736298-20230822-D00001.png" state="

CLAIMS

Claims ( 20 )

What is claimed is:

1. A computer-implemented method comprising:

sending, from a first party accessor and to a second party access target, a request for access to data stored by the second party access target;

receiving, by the first party accessor and from the second party access target, data specifying an authentication challenge;

generating, by the first party accessor, a response to the authentication challenge;

sending, from the first party accessor, the response to a third party quantum computing environment;

receiving, by the first party accessor and from the third party quantum computing environment, a first encryption key;

sending, by the first party accessor, the first encryption key to the second party access target, for the second party access target to determine whether the first encryption key decrypts an encrypted authorization token that was received by the second party access target from the third party quantum computing environment; and

based on the determination by the second party access target, either i) obtaining access to the data stored by the second party access target or ii) receiving data indicating denial of access to the data stored by the second party access target.

2. The method of claim 1 , wherein the authentication challenge comprises an authentication challenge established between the first party accessor and the second party access target during an enrollment process.

3. The method of claim 1 , wherein the response to the authentication challenge comprises a first plaintext data input and wherein in response to receiving the response to the authentication challenge, the quantum computing environment:

applies a quantum computation translation operation to i) the first plaintext data input to generate a corresponding first sequence of quantum computations, and ii) a second plaintext data input received from the second party access target to generate a corresponding second sequence of quantum computations;

implements i) the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results, and ii) the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results; and

generates i) the first encryption key using the first sequence of measurement results, ii) a second encryption key using the second sequence of measurement results, and iii) an encrypted authorization token using the second encryption key.

4. The method of claim 3 , wherein to apply a quantum computation translation operation to i) the first plaintext data input to generate a corresponding first sequence of quantum computations, and ii) the second plaintext data input to generate a corresponding second sequence of quantum computations, the quantum computing environment independently:

applies the quantum computation translation operation to the first plaintext data input using a first classical processor in the first segmented quantum computing environment; and

applies the quantum computation translation operation to the second plaintext data input using a second classical processor in the second segmented quantum computing environment.

5. The method of claim 3 , wherein

to implement the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results, the quantum computing environment, for each quantum computation in the first sequence of quantum computations:

implements the quantum computation on a first qubit included in the first segmented quantum computing environment;

measures the first qubit in the first segmented quantum computing environment; and

provides a measurement result to classical hardware included in the first segmented quantum computing environment; and

to implement the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results, the quantum computing environment, for each quantum computation in the second sequence of quantum computations:

implements the quantum computation on a second qubit included in the second segmented quantum computing environment;

measures the second qubit in the second segmented quantum computing environment; and

provides a measurement result to classical hardware included in the second segmented quantum computing environment.

6. The method of claim 5 , wherein the first segmented quantum computing environment comprises a first ephemeral segmented quantum computing environment and the second segmented quantum computing environment comprises a second ephemeral segmented quantum computing environment.

7. The method of claim 3 , wherein the quantum computation translation operation comprises an operation that maps each character in a plaintext data input to a respective quantum computation.

8. The method of claim 1 , wherein sending the response to the third party quantum computing environment comprises sending the response via an Out-of-Band authenticator device.

9. A computer-implemented method comprising:

receiving, by a second party access target and from a first party accessor, a request for access to data stored by the second party access target;

sending, by the second party access target and to the first party accessor, data specifying an authentication challenge;

sending, by the second party access target and to a third party quantum computing system, an expected response to the authentication challenge;

receiving, by the second party access target, i) an encrypted authorization token from the third party quantum computing system and ii) a first encryption key from the first party accessor that the first party accessor previously received from the third party quantum computing system;

decrypting, by the second party access target and using the first encryption key, the encrypted authorization token;

determining, by the second party access target, whether decryption is successful or unsuccessful; and

in response to determining that the decryption is successful, allowing, by the second party access target, the first party accessor access to the data; or

in response to determining that the decryption is unsuccessful, denying, by the second party access target, the first party accessor access to the data.

10. The method of claim 9 , wherein the authentication challenge comprises an authentication challenge established between the first party accessor and the second party access target during an enrollment process.

11. The method of claim 9 , wherein the expected response to the authentication challenge comprises a second plaintext data input and in response to receiving the second plaintext data input, the third party quantum computing environment:

applies a quantum computation translation operation to i) a first plaintext data input received from the first party accessor to generate a corresponding first sequence of quantum computations, and ii) the second plaintext data input to generate a corresponding second sequence of quantum computations;

implements i) the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results, and ii) the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results; and

generates i) the first encryption key using the first sequence of measurement results, ii) a second encryption key using the second sequence of measurement results, and iii) the encrypted authorization token using the second encryption key.

12. The method of claim 11 , wherein to apply a quantum computation translation operation to i) the first plaintext data input to generate a corresponding first sequence of quantum computations, and ii) the second plaintext data input to generate a corresponding second sequence of quantum computations, the quantum computing environment independently:

applies the quantum computation translation operation to the first plaintext data input using a first classical processor in the first segmented quantum computing environment; and

applies the quantum computation translation operation to the second plaintext data input using a second classical processor in the second segmented quantum computing environment.

13. The method of claim 11 , wherein

to implement the first sequence of quantum computations in a first segmented quantum computing environment to obtain a first sequence of measurement results, the quantum computing environment, for each quantum computation in the first sequence of quantum computations:

implements the quantum computation on a first qubit included in the first segmented quantum computing environment;

measures the first qubit in the first segmented quantum computing environment; and

provides a measurement result to classical hardware included in the first segmented quantum computing environment; and

to implement the second sequence of quantum computations in a second segmented quantum computing environment to obtain a second sequence of measurement results, the quantum computing environment, for each quantum computation in the second sequence of quantum computations:

implements the quantum computation on a second qubit included in the second segmented quantum computing environment;

measures the second qubit in the second segmented quantum computing environment; and

provides a measurement result to classical hardware included in the second segmented quantum computing environment.

14. The method of claim 13 , wherein the first segmented quantum computing environment comprises a first ephemeral segmented quantum computing environment and the second segmented quantum computing environment comprises a second ephemeral segmented quantum computing environment.

15. The method of claim 11 , wherein the quantum computation translation operation comprises an operation that maps each character in a plaintext data input to a respective quantum computation.

16. The method of claim 9 , wherein denying the first party accessor access to the data comprises sending, to the first party accessor, data indicating denial of access to the data stored by the second party access target.

17. The method of claim 9 , further comprising sending, from the second party access target and to the third party quantum computing environment, an indication that the first party accessor has requested access to data stored by the second part and a request for creation of a first ephemeral segmented quantum computing environment and a second ephemeral segmented quantum computing environment.

18. The method of claim 9 , further comprising receiving, by the second party access target and from the third party quantum computing environment, an indication that the third party quantum computing environment has received a response to the authentication challenge from the first party accessor.

19. A system comprising:

a first party accessor comprising one or more classical processors; and

a third party quantum computing environment comprising quantum computing hardware;

wherein the system is configured to perform operations comprising:

sending, from the first party accessor and to a second party access target, a request for access to data stored by the second party access target;

receiving, by the first party accessor and from the second party access target, data specifying an authentication challenge;

generating, by the first party accessor, a response to the authentication challenge;

sending, from the first party accessor, the response to the third party quantum computing environment;

receiving, by the first party accessor and from the third party quantum computing environment, a first encryption key;

sending, by the first party accessor and to the second party access target, the first encryption key, for the second party access target to determine whether the first encryption key decrypts an encrypted authorization token that was received by the second party access target from the third party quantum computing environment; and

based on the determination by the second party access target, obtaining access to the data stored by the second party access target or receiving data indicating denial of access to the data stored by the second party access target.

20. A system comprising:

a second party access target comprising one or more classical processors; and

a third party quantum computing environment comprising quantum computing hardware;

wherein the system is configured to perform operations comprising:

receiving, by the second party access target and from a first party accessor, a request for access to data stored by the second party access target;

sending, by the second party access target and to the first party accessor, data specifying an authentication challenge;

sending, by the second party access target and to the third party quantum computing system, an expected response to the authentication challenge;

receiving, by the second party access target, i) an encrypted authorization token from the third party quantum computing system and ii) a first encryption key from the first party accessor that the first party accessor previously received from the third party quantum computing system;

decrypting, by the second party access target and using the first encryption key, the encrypted authorization token;

determining, by the second party access target, whether decryption is successful or unsuccessful; and

in response to determining that the decryption is successful, allowing, by the second party access target, the first party accessor access to the data; or

in response to determining that the decryption is unsuccessful, denying, by the second party access target, the first party accessor access to the data.

US17/403,008

2019-10-11

2021-08-16

Authentication using key distribution through segmented quantum computing environments

Active

2040-01-22

US11736298B2

( en )

Priority Applications (1)

Application Number

Priority Date

Filing Date

Title

US17/403,008

US11736298B2

( en )

2019-10-11

2021-08-16

Authentication using key distribution through segmented quantum computing environments

Applications Claiming Priority (2)

Application Number

Priority Date

Filing Date

Title

US16/599,586

US11121878B2

( en )

2019-10-11

2019-10-11

Authentication using key distribution through segmented quantum computing environments

US17/403,008

US11736298B2

( en )

2019-10-11

2021-08-16

Authentication using key distribution through segmented quantum computing environments

Related Parent Applications (1)

Application Number

Title

Priority Date

Filing Date

US16/599,586

Continuation

US11121878B2

( en )

2019-10-11

2019-10-11

Authentication using key distribution through segmented quantum computing environments

Publications (2)

Publication Number

Publication Date

US20210377034A1

US20210377034A1 ( en )

2021-12-02

US11736298B2

true

US11736298B2 ( en )

2023-08-22

Family

ID=75383358

Family Applications (2)

Application Number

Title

Priority Date

Filing Date

US16/599,586

Active

2040-06-08

US11121878B2

( en )

2019-10-11

2019-10-11

Authentication using key distribution through segmented quantum computing environments

US17/403,008

Active

2040-01-22

US11736298B2

( en )

2019-10-11

2021-08-16

Authentication using key distribution through segmented quantum computing environments

Family Applications Before (1)

Application Number

Title

Priority Date

Filing Date

US16/599,586

Active

2040-06-08

US11121878B2

( en )

2019-10-11

2019-10-11

Authentication using key distribution through segmented quantum computing environments

Country Status (1)

Country

Link

US

( 2 )

US11121878B2

( en )

Cited By (1)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US12585785B2

( en )

2024-02-20

2026-03-24

Bank Of America Corporation

Code vulnerability evaluator

Families Citing this family (46)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US11030618B1

( en )

2016-09-30

2021-06-08

Winkk, Inc.

Authentication and personal data sharing for partner services using out-of-band optical mark recognition

US11637694B2

( en )

2018-07-16

2023-04-25

Winkk, Inc.

Secret material exchange and authentication cryptography operations

US11487504B2

( en )

2019-10-11

2022-11-01

Accenture Global Solutions Limited

Generating quantum representations of hexadecimal data

US11121878B2

( en )

2019-10-11

2021-09-14

Accenture Global Solutions Limited

Authentication using key distribution through segmented quantum computing environments

US12273456B2

( en )

*

2019-10-21

2025-04-08

Omnissa, Llc

Two-way authentication for voice-activated devices

US11936787B2

( en )

2019-12-10

2024-03-19

Winkk, Inc.

User identification proofing using a combination of user responses to system turing tests using biometric methods

US11588794B2

( en )

2019-12-10

2023-02-21

Winkk, Inc.

Method and apparatus for secure application framework and platform

US11652815B2

( en )

*

2019-12-10

2023-05-16

Winkk, Inc.

Security platform architecture

US12335399B2

( en )

2019-12-10

2025-06-17

Winkk, Inc.

User as a password

US11657140B2

( en )

2019-12-10

2023-05-23

Winkk, Inc.

Device handoff identification proofing using behavioral analytics

US11563582B2

( en )

2019-12-10

2023-01-24

Winkk, Inc.

Method and apparatus for optical encryption communication using a multitude of hardware configurations

US11553337B2

( en )

2019-12-10

2023-01-10

Winkk, Inc.

Method and apparatus for encryption key exchange with enhanced security through opti-encryption channel

US11574045B2

( en )

2019-12-10

2023-02-07

Winkk, Inc.

Automated ID proofing using a random multitude of real-time behavioral biometric samplings

US12153678B2

( en )

2019-12-10

2024-11-26

Winkk, Inc.

Analytics with shared traits

US12132763B2

( en )

2019-12-10

2024-10-29

Winkk, Inc.

Bus for aggregated trust framework

US11328042B2

( en )

2019-12-10

2022-05-10

Winkk, Inc.

Automated transparent login without saved credentials or passwords

US12341790B2

( en )

2019-12-10

2025-06-24

Winkk, Inc.

Device behavior analytics

US12073378B2

( en )

2019-12-10

2024-08-27

Winkk, Inc.

Method and apparatus for electronic transactions using personal computing devices and proxy services

US12143419B2

( en )

2019-12-10

2024-11-12

Winkk, Inc.

Aggregated trust framework

US11928193B2

( en )

2019-12-10

2024-03-12

Winkk, Inc.

Multi-factor authentication using behavior and machine learning

US11366897B1

( en )

*

2020-01-17

2022-06-21

Wells Fargo Bank, N.A.

Systems and methods for layered quantum computing detection

US12126713B1

( en )

2020-01-17

2024-10-22

Wells Fargo Bank, N.A.

Systems and methods for quantum computing threat detection

US11334667B1

( en )

2020-01-17

2022-05-17

Wells Fargo Bank, N.A.

Systems and methods for disparate quantum computing threat detection

US11240223B1

( en )

*

2020-02-11

2022-02-01

Wells Fargo Bank, N.A.

Systems and methods for quantum consensus

US11574307B2

( en )

*

2020-08-06

2023-02-07

Bank Of America Corporation

Three party authentication using quantum key distribution

US12164898B2

( en )

*

2021-02-11

2024-12-10

Capital One Services, Llc

Automated deployment of changes to applications on a cloud computing platform

US11570007B2

( en )

*

2021-02-16

2023-01-31

Bank Of America Corporation

Quantum-level cryptography for delegated digital signatures

US11843943B2

( en )

2021-06-04

2023-12-12

Winkk, Inc.

Dynamic key exchange for moving target

US12095751B2

( en )

2021-06-04

2024-09-17

Winkk, Inc.

Encryption for one-way data stream

US11824999B2

( en )

2021-08-13

2023-11-21

Winkk, Inc.

Chosen-plaintext secure cryptosystem and authentication

US12267421B2

( en )

*

2021-10-18

2025-04-01

International Business Machines Corporation

Post quantum secure ingress/egress network communication

US12452305B2

( en )

*

2022-02-15

2025-10-21

Hewlett Packard Enterprise Development Lp

Adaptive enforcement of security within a network

US12406047B2

( en )

*

2022-02-21

2025-09-02

Red Hat, Inc.

Quantum authentication of protected resources

US11818257B1

( en )

*

2022-04-27

2023-11-14

Cisco Technology, Inc.

Systems and methods for providing user authentication for quantum-entangled communications in a cloud environment

CN115174051B

( en )

*

2022-06-22

2025-07-18

厦门工学院

Quantum key distribution method and system based on password block chaining mode

US12438731B2

( en )

2022-09-21

2025-10-07

Winkk, Inc.

Diophantine system for digital signatures

US12500749B2

( en )

*

2023-03-30

2025-12-16

Bank Of America Corporation

Quantum-based encryption

US20240340169A1

( en )

*

2023-04-10

2024-10-10

Cambridge Weaponry

Method and system for a quantum-enhanced decryption process for rsa and aes encryptions

US12335396B2

( en )

2023-05-18

2025-06-17

Red Hat, Inc.

Superpositioned qubits as finite token generators for authentication

CN116527256A

( en )

*

2023-06-08

2023-08-01

中国联合网络通信集团有限公司

Encryption method, device, equipment and storage medium based on quantum entanglement

CN116527259B

( en )

*

2023-07-03

2023-09-19

中电信量子科技有限公司

Cross-domain identity authentication method and system based on quantum key distribution network

US12526130B2

( en )

*

2023-08-03

2026-01-13

Accenture Global Solutions Limited

Cryptographic hash digests from quantum information

US12476984B2

( en )

*

2023-08-15

2025-11-18

Wells Fargo Bank, N.A.

Quantum-based information protection

US20250131422A1

( en )

*

2023-10-18

2025-04-24

Sean Harrison Worthington

Key Exchange Through a Plurality of Non-Trusted Third Parties

CN118487748B

( en )

*

2024-04-19

2025-03-04

安徽成方量子科技有限公司

Deployment method and device of quantum key management system based on confidential calculation

CN118473648B

( en )

*

2024-07-12

2024-10-01

国网安徽省电力有限公司信息通信分公司

Quantum encryption method and device suitable for AES encryption algorithm

Citations (12)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US7028275B1

( en )

2001-10-15

2006-04-11

The Texas A&amp;M University System

Quantum circuit design for grover&#39;s algorithm

US7035411B2

( en )

2000-06-12

2006-04-25

Canon Kabushiki Kaisha

Encryption method and apparatus encrypting and adding signature information to qubits

US8631367B2

( en )

2010-12-16

2014-01-14

Northrop Grumman Systems Corporation

Methods of increasing fidelity of quantum operations

US8744075B2

( en )

*

2009-12-16

2014-06-03

Sony Corporation

Quantum public key encryption system

US20170222803A1

( en )

*

2016-02-02

2017-08-03

Kabushiki Kaisha Toshiba

Communication device, cryptographic communication system, cryptographic communication method, and computer program product

US10574446B2

( en )

*

2016-10-14

2020-02-25

Alibaba Group Holding Limited

Method and system for secure data storage and retrieval

US20200272928A1

( en )

2019-02-21

2020-08-27

International Business Machines Corporation

Method for estimating a quantum phase

US20210058244A1

( en )

2017-12-30

2021-02-25

Compsecur Sp. Z.O.O.

The One-Qubit Pad (OQP) for entanglement encryption of quantum information

US20210111898A1

( en )

2019-10-11

2021-04-15

Accenture Global Solutions Limited

Authentication using key distribution through segmented quantum computing environments

US20210109707A1

( en )

2019-10-11

2021-04-15

Accenture Global Solutions Limited

Generating quantum representations of hexadecimal data

US11206131B1

( en )

*

2019-05-17

2021-12-21

Wells Fargo Bank, N.A.

Post quantum unique key per token system

US11245519B1

( en )

*

2019-10-04

2022-02-08

Wells Fargo Bank, N.A.

Systems and methods for quantum entanglement random number generation

2019

2019-10-11

US

US16/599,586

patent/US11121878B2/en

active

Active

2021

2021-08-16

US

US17/403,008

patent/US11736298B2/en

active

Active

Patent Citations (13)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US7035411B2

( en )

2000-06-12

2006-04-25

Canon Kabushiki Kaisha

Encryption method and apparatus encrypting and adding signature information to qubits

US7028275B1

( en )

2001-10-15

2006-04-11

The Texas A&amp;M University System

Quantum circuit design for grover&#39;s algorithm

US8744075B2

( en )

*

2009-12-16

2014-06-03

Sony Corporation

Quantum public key encryption system

US8631367B2

( en )

2010-12-16

2014-01-14

Northrop Grumman Systems Corporation

Methods of increasing fidelity of quantum operations

US20170222803A1

( en )

*

2016-02-02

2017-08-03

Kabushiki Kaisha Toshiba

Communication device, cryptographic communication system, cryptographic communication method, and computer program product

US10574446B2

( en )

*

2016-10-14

2020-02-25

Alibaba Group Holding Limited

Method and system for secure data storage and retrieval

US20210058244A1

( en )

2017-12-30

2021-02-25

Compsecur Sp. Z.O.O.

The One-Qubit Pad (OQP) for entanglement encryption of quantum information

US20200272928A1

( en )

2019-02-21

2020-08-27

International Business Machines Corporation

Method for estimating a quantum phase

US11206131B1

( en )

*

2019-05-17

2021-12-21

Wells Fargo Bank, N.A.

Post quantum unique key per token system

US11245519B1

( en )

*

2019-10-04

2022-02-08

Wells Fargo Bank, N.A.

Systems and methods for quantum entanglement random number generation

US20210111898A1

( en )

2019-10-11

2021-04-15

Accenture Global Solutions Limited

Authentication using key distribution through segmented quantum computing environments

US20210109707A1

( en )

2019-10-11

2021-04-15

Accenture Global Solutions Limited

Generating quantum representations of hexadecimal data

US11121878B2

( en )

2019-10-11

2021-09-14

Accenture Global Solutions Limited

Authentication using key distribution through segmented quantum computing environments

Non-Patent Citations (8)

* Cited by examiner, † Cited by third party

Title

[No Author Listed], " Activity Guide—Encoding Hexadecimal Numbers ", retrieved from URL: https://www.mrshasseld.com/uploads/2/6/1/1/26119949/u214activityguide_key-hexadecimalnumbers.pdf, retrieved on Dec. 11, 2019, 4 pages.

A quantum encryption design featuring confusion, diffusion, and mode of operation, Hu et al., Oct. 2020 (Year: 2020).

Barnum et al., " Authentication of Quantum Message " arXiv:quant-ph/0205128, dated May 20, 2002, 23 pages.

Crockett et al., " Prototyping post-quantum and hybrid key exchange and authentication in TLS and SSH ", retrieved from URL: https://csrc.nist.gov/CSRC/media/Events/Second-PQC-Standardization-Conference/documents/accepted-papers/stebila-prototyping-post-quantum.pdf, dated Jul. 19, 2019, 24 pages.

Kiktenko et al., " Lightweight authentication for quantum key distribution ", arXiv:1903.10237v1, dated Mar. 25, 2019, 10 pages.

Ozols, " Clifford Group ", retrieved from URL: http://home.lu.lv/˜sd20008/papers/essays/Clifford%20group%20%5bpaper%5d.pdf, dated Jul. 31, 2008, 4 pages.

Secured cloud authentication using quantum cryptography, Murali et al, Aug. 2017 (Year: 2017).

*

Soni et al., " Multi-factor Authentication Security Framework in Cloud Computing ", International Journal of Advanced Research in Computer Science and Software Engineering, 5(1):1065-1071, dated Jan. 1, 2015.

Cited By (1)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US12585785B2

( en )

2024-02-20

2026-03-24

Bank Of America Corporation

Code vulnerability evaluator

Also Published As

Publication number

Publication date

US20210377034A1

( en )

2021-12-02

US11121878B2

( en )

2021-09-14

US20210111898A1

( en )

2021-04-15

Similar Documents

Publication

Publication Date

Title

US11121878B2

( en )

2021-09-14

Authentication using key distribution through segmented quantum computing environments

US20220255732A1

( en )

2022-08-11

Systems And Methods For Encrypted Content Management

US12362921B2

( en )

2025-07-15

Systems and methods for providing user authentication for quantum-entangled communications in a cloud environment

CN108292402B

( en )

2022-10-04

Determination of a common secret and hierarchical deterministic keys for the secure exchange of information

US11614918B1

( en )

2023-03-28

Generating quantum representations of hexadecimal data

US20240073010A1

( en )

2024-02-29

Systems and methods for providing dynamic quantum cloud security through entangled particle distribution

Dutta et al.

2022

Controlled secure direct quantum communication inspired scheme for quantum identity authentication: A. Dutta, A. Pathak

CN105474575A

( en )

2016-04-06

Multi-party secure authentication system, authentication server, intermediate server, multi-party secure authentication method, and program

US20240283664A1

( en )

2024-08-22

Authentication with Cloud-Based Secure Enclave

Sharma et al.

2020

Dual factor third‐party biometric‐based authentication scheme using quantum one time passwords

Shi et al.

2015

A novel quantum deniable authentication protocol without entanglement

Das et al.

2022

A decentralized open web cryptographic standard

CN114765551A

( en )

2022-07-19

SDP access control method and device based on block chain

CN108737383B

( en )

2021-05-11

Anonymous authentication method capable of confusing

Ahammad et al.

2024

Key based secured cryptosystems used for online data sharing on the cloud

Liu et al.

2018

Authenticated semiquantum dialogue with secure delegated quantum computation over a collective noise channel: L. Liu et al.

Zhang et al.

2022

Instantiation of quantum point obfuscation

Su et al.

2013

Improved quantum signature scheme with weak arbitrator

CN113079177B

( en )

2022-05-31

A Remote Sensing Data Sharing Method Based on Time and Decryption Times Limitation

Bagchi et al.

2025

Big Data Analytics-Envisioned Quantum-Safe Lattice-Based Three-Party Authenticated Key Agreement Protocol for Cloud IoT-Enabled Healthcare Applications

Gunasinghe et al.

2024

PEBASI: a privacy preserving, efficient biometric authentication scheme based on irises

Lu et al.

2023

Efficient secure computation from SM series cryptography

Chang et al.

2015

Novel and practical scheme based on secret sharing for laptop data protection

KR102173282B1

( en )

2020-11-06

Method for quantum entity authentication

Wu et al.

2016

A lightweight authentication and key agreement scheme for mobile satellite communication systems

Legal Events

Date

Code

Title

Description

<tr itemprop="legalEvents" it

Related documents

Record · ID 607102
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.