ABSTRACT
Abstract
Techniques and tools for implementing protocols for secure multi-party communication after quantum key distribution (âQKDâ) are described herein. In example implementations, a trusted authority facilitates secure communication between multiple user devices. The trusted authority distributes different quantum keys by QKD under trust relationships with different users. The trusted authority determines combination keys using the quantum keys and makes the combination keys available for distribution (e.g., for non-secret distribution over a public channel). The combination keys facilitate secure communication between two user devices even in the absence of QKD between the two user devices. With the protocols, benefits of QKD are extended to multi-party communication scenarios. In addition, the protocols can retain benefit of QKD even when a trusted authority is offline or a large group seeks to establish secure communication within the group.
Description
CROSS REFERENCE TO RELATED APPLICATION
This is a Continuation of U.S. patent application Ser. No. 12/895,367, filed Sep. 30, 2010, the disclosure of which is hereby incorporated by reference.
ACKNOWLEDGEMENT OF GOVERNMENT SUPPORT
The United States government has rights in this invention pursuant to Contract No. DE-AC52-06NA25396 between the United States Department of Energy and Los Alamos National Security, LLC for the operation of Los Alamos National Laboratory.
FIELD
A trusted authority distributes quantum keys to different user devices, which use the quantum keys for secure multi-party communication.
BACKGROUND
In quantum communication, two parties exchange information encoded in quantum states. Typically, the quantum states are specially defined properties of photons such as pairs of polarization states (e.g., 0° and 90°, or 45° and 135°) or circular basis states (e.g., left-handedness and right-handedness). Through the quantum communication (âQCâ), the two parties produce a shared random series of bits known only to them, which can then be used as secret keys in subsequent encryption and decryption of messages. The process of producing such keys through QC is also called quantum key distribution (âQKDâ).
A third party can, in theory, eavesdrop on the QC between the two parties. Such eavesdropping perturbs the QC, however, introducing anomalies that the two intended parties can detect. Using conventional communication, the two parties post-process the results of the QC to remove any partial information acquired by an eavesdropper, and form shared secret keys from the remaining information resulting from the QC.
For example, according to one general approach to QKD, a transmitter sets the quantum state of binary information, makes a record of how it set the quantum state, and transmits the information. Table 1 shows an example of quantum states and bases for different polarizations of photons. For the bases and states shown in Table 1, the transmitter selects a basis (rectilinear or diagonal), sets the polarization state for a photon in the selected basis, and records the bit value (0 or 1), the selected sending basis and the time of transmission.
TABLE 1
Example bases and quantum states.
Basis
0
1
Rectilinear (+)
90°
â0°
Diagonal (Ã)
45°
135° (or â45°)
A receiver receives the binary information, measures the quantum state of the information and makes a record of how it measured the quantum state. The measured state depends on how the receiver performs the measurement (e.g., with measuring basis of rectilinear or diagonal). The transmitter and receiver are expected to record different bit values in some instances because the transmitter and receiver at times set/measure the quantum-state-encoded information in different ways. Thus, after exchanging information in quantum states, the transmitter and receiver compare their records of how the quantum states were set and measured. For this comparison, the transmitter and receiver exchange information over a public channel. Then, the transmitter and receiver produce a shared series of bits (keys) from the encoded information for which quantum states were set and measured in the same way by the transmitter and receiver.
For the bases and states shown in Table 1, for example, the receiver selects a basis (rectilinear or diagonal), measures the polarization state in the selected basis, and records the measured bit value and measuring basis. No possible measuring basis can distinguish all four states, so the receiver essentially guesses either rectilinear or diagonal. If the measuring basis happens to match the sending basis, the receiver should measure the correct bit value. If the measuring basis does not match the sending basis, however, the measured bit value is as likely to be correct as incorrect. For example, if the sending basis is diagonal for the bit value 0 (polarization state of 45°) but the measuring basis is rectilinear, the measured bit values of 0) (90° and 1 (0°) are equally likely. The transmitter and receiver compare the sending basis and measuring basis for a given photon, and keep the bit value for a photon if the sending basis and measuring basis match.
If an eavesdropper intercepts and measures a photon, the measurement perturbs the quantum state of the photon. The eavesdropper can only guess the original sending basis when it re-encodes and re-transmits the photon to the intended destination. At the time of measurement by the receiver, the eavesdropping is not detected. Instead, for subsets of the bit values for which sending basis and measuring basis are found to match, the transmitter and receiver compare parity values. The parity values should match exactly, if the system is appropriately tuned and free from imperfections in transmission and reception. Eavesdropping introduces noticeable discrepancies in the bit values, which allows the transmitter and receiver to detect the eavesdropping, correct the keys, and establish an upper limit on the eavesdropper's partial information.
An error-free bit string shared by the transmitter and receiver can then be privacy-amplified (e.g., by hashing with a hashing function) to reduce its length. (Or, bits can simply be dropped, but this lacks advantages of privacy amplification.) The final length of the shared bit string can depend on the number of errors detected. Shortening the shared bit string with privacy amplification reduces knowledge an eavesdropper might have to an arbitrarily low levelâtypically, much less than a single bit.
Other approaches to QC exploit other quantum properties (e.g., quantum entanglement) to exchange information encoded in quantum states. In addition, techniques such as privacy amplification can be used to eliminate the partial information that an eavesdropper can acquire. Techniques such as information reconciliation can be used to resolve small discrepancies in the shared bit values of the transmitter and receiver.
The theoretical framework for QC has been established for over 25 years, and its advantages in terms of security of keys are well accepted. Over the past two decades, implementations of QKD systems have become cheaper, more reliable, easier to maintain (e.g., self-tuning, self-checking), and easier to use. Even so, compared to other security solutions that use public key cryptography, QKD system have tended to be expensive and difficult to deploy. A typical QKD system is large and operates only in point-to-point mode over a fiber connection between transmitter and receiver. Several commercially available QKD systems perform QKD only over point-to-point links, are not portable, and require a dedicated fiber connection. Moreover, their QC cannot co-exist with network traffic. As a result, despite the general knowledge that threats to public key cryptography exist from ever more powerful computers, QKD has not gained a commercial foothold.
SUMMARY
Innovations described herein facilitate the use of quantum key distribution (âQKDâ). These innovations help make QKD more practical and useful for secure multi-party communication, authentication, access control and other applications.
According to one aspect of the innovations described herein, a computing system that implements a trusted authority facilitates secure communication between multiple user devices. The computing system distributes one or more first quantum keys by first QKD under a first trust relationship between the trusted authority and a first user, and distributes one or more second quantum keys by second QKD under a second trust relationship between the trusted authority and a second user. The QKD can be between the trusted authority and a user device, or between the trusted authority and a fillgun device (which conveys the keys to a user device). The computing system determines one or more combination keys based at least in part upon at least one of the first quantum key(s) and at least one of the second quantum key(s). The computing system makes the combination key(s) available for distribution (e.g., for non-secret distribution over a public channel). The combination key(s) facilitate secure communication between a first user device and second user device even in the absence of QKD between the first and second user devices.
In some implementations, the computing system that implements the trusted authority authenticates the first user and the second user before the first QKD and the second QKD, respectively, to establish the respective trust relationships. For example, the authentication uses pre-placed keys for the respective users, which can then be replaced with quantum keys resulting from the QKD. The system that implements the trusted authority can also use password-based authentication with a quantum identification protocol (âQIPâ). For example, before the first QKD and the second QKD, respectively, the system uses a first (or second) password within a QIP for authentication between the first (or second) user and the trusted authority. The password can include a set of multiple alphanumeric characters input by the user, a high entropy key stored at the user device and/or a digest based on biometric indicia for the user.
In some use scenarios, the first quantum key(s) include a key derivation key, the second quantum key(s) include an encryption key for the second user device, and one of the combination keys is determined from the key derivation key and the encryption key for the second user device. The first quantum key(s) can also include a key authentication key, and the computing system that implements the trusted authority can create a key authentication value from the encryption key for the second user device and the key authentication key. In other use scenarios, the first and second quantum keys are used in other ways.
In some configurations, the computing system that implements the trusted authority has a single physical node. In other configurations, the system that implements the trusted authority is distributed among multiple physical nodes, and quantum secret sharing is used to facilitate QKD for a given user and the multiple physical nodes of the trusted authority. A trusted authority can be part of a hierarchy of trusted authorities or be the only trusted authority.
According to another aspect of the innovations described herein, a first user device retrieves one or more first quantum keys that result from QKD with a trusted authority under a trust relationship between the trusted authority and a first user. The first user device also retrieves a combination key that is based at least in part upon one of the first quantum key(s) and a key for a second user device. The first user device communicates with the second user device based at least in part on one of the first quantum key(s) and the combination key. The combination key facilitates secure communication between the first and second user devices even in the absence of QKD between the first and second user devices.
In some implementations, before the QKD, the first user device receives biometric indicia for the first user, encrypts the biometric indicia using a pre-placed secret key, and transmits the encrypted biometric indicia to the trusted authority for authentication of the first user to establish the trust relationship. The first quantum key(s) can include a new key for use in subsequent authentication of the first user. Moreover, before the QKD, the first user device can use a password within a QIP for authentication of the first user to the trusted authority and for authentication of the trusted authority to the first user.
In some use scenarios, the first quantum key(s) include a key derivation key, and the first user device determines the key for the second user device from the key derivation key and the combination key. The first quantum key(s) can further include an encryption key for the first user device, where the encryption key for the first user device is used to encrypt messages to the second user device, and the key for the second user device is used to decrypt messages from the second user device. Or, the first user device can decrypt a message from the second user device using the key for the second user device, where the message includes a session key, then use the session key to encrypt/decrypt messages to/from the second user device. Or, the first quantum key(s) can include other keys used for secure communication.
In group keying scenarios, the first quantum key(s) include a different key for each of multiple user devices other than the first user device. The first user device, as a group leader, determines a group session key. For each of the multiple user devices other than the first user device, the first user device encrypts the group session key using an encryption key specific to pair-wise communication between the first user device and the other user device, and communicates the encrypted group session key to the other user device. The first user device can also assign sub-group keys to sub-groups of the multiple user devices and assign individual group member keys to individual ones of the multiple user devices.
According to another aspect of the innovations described herein, a user device includes a processor, memory and storage storing computer-executable instructions for causing the user device to perform a method of secure communication with a target device. For the secure communication, the user device retrieves a key derivation key that results from QKD with a trusted authority, and retrieves a pair key that is based at least in part on the key derivation key and a key for the target device. The user device derives the key for the target device from the key derivation key and the pair key. The user device then uses the key for the target device in communication with the target device. In some implementations, the user device also retrieves a key authentication key that results from the QKD with the trusted authority, and retrieves a reference key authentication value made available by the trusted authority. The user device determines a check key authentication value from the key for the target device and the key authentication key, then compares the check key authentication value to the reference key authentication value.
According to another aspect of the innovations described herein, a computing system that implements a trusted authority distributes one or more first quantum keys by QKD, where the first quantum key(s) include an encryption key for a first user device. The computing system also distributes one or more second quantum keys by QKD, where the second quantum key(s) include a key derivation key for a second user device. The computing syst
CROSS REFERENCE TO RELATED APPLICATION
This is a Continuation of U.S. patent application Ser. No. 12/895,367, filed Sep. 30, 2010, the disclosure of which is hereby incorporated by reference.
ACKNOWLEDGEMENT OF GOVERNMENT SUPPORT
The United States government has rights in this invention pursuant to Contract No. DE-AC52-06NA25396 between the United States Department of Energy and Los Alamos National Security, LLC for the operation of Los Alamos National Laboratory.
FIELD
A trusted authority distributes quantum keys to different user devices, which use the quantum keys for secure multi-party communication.
BACKGROUND
In quantum communication, two parties exchange information encoded in quantum states. Typically, the quantum states are specially defined properties of photons such as pairs of polarization states (e.g., 0° and 90°, or 45° and 135°) or circular basis states (e.g., left-handedness and right-handedness). Through the quantum communication (âQCâ), the two parties produce a shared random series of bits known only to them, which can then be used as secret keys in subsequent encryption and decryption of messages. The process of producing such keys through QC is also called quantum key distribution (âQKDâ).
A third party can, in theory, eavesdrop on the QC between the two parties. Such eavesdropping perturbs the QC, however, introducing anomalies that the two intended parties can detect. Using conventional communication, the two parties post-process the results of the QC to remove any partial information acquired by an eavesdropper, and form shared secret keys from the remaining information resulting from the QC.
For example, according to one general approach to QKD, a transmitter sets the quantum state of binary information, makes a record of how it set the quantum state, and transmits the information. Table 1 shows an example of quantum states and bases for different polarizations of photons. For the bases and states shown in Table 1, the transmitter selects a basis (rectilinear or diagonal), sets the polarization state for a photon in the selected basis, and records the bit value (0 or 1), the selected sending basis and the time of transmission.
TABLE 1
Example bases and quantum states.
Basis
0
1
Rectilinear (+)
90°
â0°
Diagonal (Ã)
45°
135° (or â45°)
A receiver receives the binary information, measures the quantum state of the information and makes a record of how it measured the quantum state. The measured state depends on how the receiver performs the measurement (e.g., with measuring basis of rectilinear or diagonal). The transmitter and receiver are expected to record different bit values in some instances because the transmitter and receiver at times set/measure the quantum-state-encoded information in different ways. Thus, after exchanging information in quantum states, the transmitter and receiver compare their records of how the quantum states were set and measured. For this comparison, the transmitter and receiver exchange information over a public channel. Then, the transmitter and receiver produce a shared series of bits (keys) from the encoded information for which quantum states were set and measured in the same way by the transmitter and receiver.
For the bases and states shown in Table 1, for example, the receiver selects a basis (rectilinear or diagonal), measures the polarization state in the selected basis, and records the measured bit value and measuring basis. No possible measuring basis can distinguish all four states, so the receiver essentially guesses either rectilinear or diagonal. If the measuring basis happens to match the sending basis, the receiver should measure the correct bit value. If the measuring basis does not match the sending basis, however, the measured bit value is as likely to be correct as incorrect. For example, if the sending basis is diagonal for the bit value 0 (polarization state of 45°) but the measuring basis is rectilinear, the measured bit values of 0) (90° and 1 (0°) are equally likely. The transmitter and receiver compare the sending basis and measuring basis for a given photon, and keep the bit value for a photon if the sending basis and measuring basis match.
If an eavesdropper intercepts and measures a photon, the measurement perturbs the quantum state of the photon. The eavesdropper can only guess the original sending basis when it re-encodes and re-transmits the photon to the intended destination. At the time of measurement by the receiver, the eavesdropping is not detected. Instead, for subsets of the bit values for which sending basis and measuring basis are found to match, the transmitter and receiver compare parity values. The parity values should match exactly, if the system is appropriately tuned and free from imperfections in transmission and reception. Eavesdropping introduces noticeable discrepancies in the bit values, which allows the transmitter and receiver to detect the eavesdropping, correct the keys, and establish an upper limit on the eavesdropper's partial information.
An error-free bit string shared by the transmitter and receiver can then be privacy-amplified (e.g., by hashing with a hashing function) to reduce its length. (Or, bits can simply be dropped, but this lacks advantages of privacy amplification.) The final length of the shared bit string can depend on the number of errors detected. Shortening the shared bit string with privacy amplification reduces knowledge an eavesdropper might have to an arbitrarily low levelâtypically, much less than a single bit.
Other approaches to QC exploit other quantum properties (e.g., quantum entanglement) to exchange information encoded in quantum states. In addition, techniques such as privacy amplification can be used to eliminate the partial information that an eavesdropper can acquire. Techniques such as information reconciliation can be used to resolve small discrepancies in the shared bit values of the transmitter and receiver.
The theoretical framework for QC has been established for over 25 years, and its advantages in terms of security of keys are well accepted. Over the past two decades, implementations of QKD systems have become cheaper, more reliable, easier to maintain (e.g., self-tuning, self-checking), and easier to use. Even so, compared to other security solutions that use public key cryptography, QKD system have tended to be expensive and difficult to deploy. A typical QKD system is large and operates only in point-to-point mode over a fiber connection between transmitter and receiver. Several commercially available QKD systems perform QKD only over point-to-point links, are not portable, and require a dedicated fiber connection. Moreover, their QC cannot co-exist with network traffic. As a result, despite the general knowledge that threats to public key cryptography exist from ever more powerful computers, QKD has not gained a commercial foothold.
SUMMARY
Innovations described herein facilitate the use of quantum key distribution (âQKDâ). These innovations help make QKD more practical and useful for secure multi-party communication, authentication, access control and other applications.
According to one aspect of the innovations described herein, a computing system that implements a trusted authority facilitates secure communication between multiple user devices. The computing system distributes one or more first quantum keys by first QKD under a first trust relationship between the trusted authority and a first user, and distributes one or more second quantum keys by second QKD under a second trust relationship between the trusted authority and a second user. The QKD can be between the trusted authority and a user device, or between the trusted authority and a fillgun device (which conveys the keys to a user device). The computing system determines one or more combination keys based at least in part upon at least one of the first quantum key(s) and at least one of the second quantum key(s). The computing system makes the combination key(s) available for distribution (e.g., for non-secret distribution over a public channel). The combination key(s) facilitate secure communication between a first user device and second user device even in the absence of QKD between the first and second user devices.
In some implementations, the computing system that implements the trusted authority authenticates the first user and the second user before the first QKD and the second QKD, respectively, to establish the respective trust relationships. For example, the authentication uses pre-placed keys for the respective users, which can then be replaced with quantum keys resulting from the QKD. The system that implements the trusted authority can also use password-based authentication with a quantum identification protocol (âQIPâ). For example, before the first QKD and the second QKD, respectively, the system uses a first (or second) password within a QIP for authentication between the first (or second) user and the trusted authority. The password can include a set of multiple alphanumeric characters input by the user, a high entropy key stored at the user device and/or a digest based on biometric indicia for the user.
In some use scenarios, the first quantum key(s) include a key derivation key, the second quantum key(s) include an encryption key for the second user device, and one of the combination keys is determined from the key derivation key and the encryption key for the second user device. The first quantum key(s) can also include a key authentication key, and the computing system that implements the trusted authority can create a key authentication value from the encryption key for the second user device and the key authentication key. In other use scenarios, the first and second quantum keys are used in other ways.
In some configurations, the computing system that implements the trusted authority has a single physical node. In other configurations, the system that implements the trusted authority is distributed among multiple physical nodes, and quantum secret sharing is used to facilitate QKD for a given user and the multiple physical nodes of the trusted authority. A trusted authority can be part of a hierarchy of trusted authorities or be the only trusted authority.
According to another aspect of the innovations described herein, a first user device retrieves one or more first quantum keys that result from QKD with a trusted authority under a trust relationship between the trusted authority and a first user. The first user device also retrieves a combination key that is based at least in part upon one of the first quantum key(s) and a key for a second user device. The first user device communicates with the second user device based at least in part on one of the first quantum key(s) and the combination key. The combination key facilitates secure communication between the first and second user devices even in the absence of QKD between the first and second user devices.
In some implementations, before the QKD, the first user device receives biometric indicia for the first user, encrypts the biometric indicia using a pre-placed secret key, and transmits the encrypted biometric indicia to the trusted authority for authentication of the first user to establish the trust relationship. The first quantum key(s) can include a new key for use in subsequent authentication of the first user. Moreover, before the QKD, the first user device can use a password within a QIP for authentication of the first user to the trusted authority and for authentication of the trusted authority to the first user.
In some use scenarios, the first quantum key(s) include a key derivation key, and the first user device determines the key for the second user device from the key derivation key and the combination key. The first quantum key(s) can further include an encryption key for the first user device, where the encryption key for the first user device is used to encrypt messages to the second user device, and the key for the second user device is used to decrypt messages from the second user device. Or, the first user device can decrypt a message from the second user device using the key for the second user device, where the message includes a session key, then use the session key to encrypt/decrypt messages to/from the second user device. Or, the first quantum key(s) can include other keys used for secure communication.
In group keying scenarios, the first quantum key(s) include a different key for each of multiple user devices other than the first user device. The first user device, as a group leader, determines a group session key. For each of the multiple user devices other than the first user device, the first user device encrypts the group session key using an encryption key specific to pair-wise communication between the first user device and the other user device, and communicates the encrypted group session key to the other user device. The first user device can also assign sub-group keys to sub-groups of the multiple user devices and assign individual group member keys to individual ones of the multiple user devices.
According to another aspect of the innovations described herein, a user device includes a processor, memory and storage storing computer-executable instructions for causing the user device to perform a method of secure communication with a target device. For the secure communication, the user device retrieves a key derivation key that results from QKD with a trusted authority, and retrieves a pair key that is based at least in part on the key derivation key and a key for the target device. The user device derives the key for the target device from the key derivation key and the pair key. The user device then uses the key for the target device in communication with the target device. In some implementations, the user device also retrieves a key authentication key that results from the QKD with the trusted authority, and retrieves a reference key authentication value made available by the trusted authority. The user device determines a check key authentication value from the key for the target device and the key authentication key, then compares the check key authentication value to the reference key authentication value.
According to another aspect of the innovations described herein, a computing system that implements a trusted authority distributes one or more first quantum keys by QKD, where the first quantum key(s) include an encryption key for a first user device. The computing system also distributes one or more second quantum keys by QKD, where the second quantum key(s) include a key derivation key for a second user device. The computing system determines a pair key based at least in part on the encryption key for the first user device and the key derivation key for the second user device, and makes the pair key available for distribution. The pair key is usable by the second user device in combination with the key derivation key for the second user device to determine the encryption key for the first user device. In some implementations, the second quantum key(s) further include a key authentication key for the second user device. The computing system that implements the trusted authority determines a key authentication value from the encryption key for the first user device and the key authentication key for the second user device. The computing system makes the key authentication value available for distribution. The key authentication value is usable by the second user device in combination with the key authentication key for the second user device to authenticate the encryption key for the first user device.
According to another aspect of the innovations described herein, a computing system that implements a child trusted authority in a hierarchy facilitates secure communication between multiple user devices. For example, a first child trusted authority is part of a hierarchy that includes a second child trusted authority and a parent trusted authority. The first child trusted authority distributes first quantum keys by first QKD under a trust relationship between the first child trusted authority and a first user. Separately, the second child trusted authority distributes second quantum keys by second QKD under a trust relationship between the second child trusted authority and a second user. The first child trust authority retrieves third quantum keys that result from third QKD with the parent trusted authority. The first child trust authority then uses one of the third quantum keys and one of the first quantum keys to facilitate communication between two user devices. For example, the first child trust authority receives an encrypted session key from the parent trusted authority and decrypts the encrypted session key using one of the third quantum keys. Then, the first child trust authority re-encrypts the session key using one of the first quantum keys, and distributes the re-encrypted session key to a first user device.
The foregoing and other objects, features, and advantages of the invention will become more apparent from the following detailed description, which proceeds with reference to the accompanying figures.
BRIEF DESCRIPTION OF THE DRAWINGS
FIGS. 1 , 2 and 3 are diagrams of example operating environments in which keys are acquired through QKD, disseminated, and used for encryption, authentication and access control.
FIGS. 4 a and 4 b are flowcharts illustrating different aspects of a generalized protocol for QKD in a framework with a QC card, base station and trusted authority.
FIG. 5 is a block diagram of a generalized QC card.
FIGS. 6 a - 6 c are block diagrams of example implementations of integrated optics modules for a QC card.
FIG. 7 is a block diagram of a mobile device that incorporates a QC card in some embodiments.
FIG. 8 is a block diagram of a generalized base station for a QC card, and FIG. 9 is a block diagram of a generalized trusted authority adapted to QKD with a QC card.
FIG. 10 is a flowchart illustrating use of the same optical fiber as a quantum channel and public channel.
FIG. 11 is a diagram illustrating an example protocol that includes QKD between a trusted authority and one or more user devices for secure multi-party communication.
FIGS. 12 a and 12 b are diagrams illustrating protocols for modes of operation in secure multi-party communication between user devices.
FIG. 13 is a flowchart illustrating a generalized technique for key distribution including QKD between a trusted authority and one or more user devices for secure multi-party communication.
FIG. 14 is a flowchart illustrating a generalized technique for secure multi-party communication between user devices.
DETAILED DESCRIPTION
Techniques and tools for quantum key distribution (âQKDâ) between a quantum communication (âQCâ) card, base station and trusted authority are described herein. In example implementations, the QC card is a relatively inexpensive, portable device that couples with a base station and acquires keys through QKD with a trusted authority. The keys can be used to set up secure communication, for authentication, for access control, or for other purposes.
Techniques and tools for implementing protocols for secure multi-party communication after QKD are also described herein. With the protocols, benefits of QKD such as forward security and resistance to archival attacks are extended to multi-party communication scenarios. In addition, the protocols retain benefits of QKD even when user devices lack a quantum link with each other, a trusted authority is offline or a large group seeks to establish secure communication within the group.
The protocols for secure multi-party communication can be used with the QC cards, with devices that acquire keys from QC cards and/or with devices that acquire keys through conventional QKD with a trusted authority. Conversely, the QC card/trusted authority framework can be used with the secure multi-party communication protocols described herein or with other protocols.
For the sake of presentation, in some places, the term âtrusted authorityâ is used as shorthand for a computing system that implements the role of trusted authority, and the term âuserâ is used to indicate a computing system associated with a user. Unless the context clearly indicates otherwise, operations described herein are implemented with and performed by computing systems. For example, description of transmission of information to a trusted authority or user, determination of a value, and receipt of information from a trusted authority or user generally indicate operations with a computing system associated with the trusted authority or user. On the other hand, description of user input or biometric input to a user device implies a human user providing such input.
In addition, the terms âsystemâ and âdeviceâ are used interchangeably herein. Unless the context clearly indicates otherwise, neither term implies any limitation on a type of computing system or computing device. In general, a computing system or computing device can be local or distributed, and can include any combination of special-purpose hardware and/or general-purpose computer hardware with software implementing the functionality described herein. The term âuser deviceâ generally indicates a computing system associated with a user.
Various alternatives to the implementations described herein are possible. Certain techniques described with reference to flowchart diagrams can be altered by changing the ordering of stages shown in the flowcharts, by splitting, repeating or omitting certain stages, etc. Different aspects of the QKD framework and secure multi-party communication protocols described herein can be used in combination or separately. Different embodiments implement one or more of the described techniques and tools. Some of the techniques and tools described herein address one or more of the problems noted in the background. Typically, a given technique/tool does not solve all such problems.
I. Example Operating Environments
FIG. 1 shows an example operating environment ( 100 ) in which various user devices acquire keys through QKD with a trusted authority ( 101 ). The user devices include a QC card ( 102 ) that couples with a base station ( 103 ), a mobile phone ( 107 ) that has a QC card, a satellite ( 108 ), and several computers ( 106 ) connected to a conventional QC transmitter ( 105 ). A user device can be for an individual user or for a business, financial institution or government institution as user.
A computing system implements the trusted authority ( 101 ). The trusted authority ( 101 ) authenticates a user, produces quantum keys in communication with a user device (or conventional QC transmitter ( 105 )), and stores the quantum keys. At some point, the trusted authority ( 101 ) performs QKD with different devices, and the trusted authority ( 101 ) stores quantum keys produced in the different QKD sessions. Using quantum keys and other information provided by the trusted authority ( 101 ), a given user device can securely communicate with other user devices that have quantum keys from QKD with the trusted authority ( 101 ).
The QC card ( 102 ) contains a miniaturized QC transmitter. The QC card ( 102 ) couples with a base station ( 103 ), which provides a network connection with the trusted authority ( 101 ) and can provide electric power to the QC card ( 102 ). Example implementations for a base station ( 103 ), QC card ( 102 ), and trusted authority adapted for QKD with a QC card ( 102 ) are detailed in Section II. Whereas conventional QKD solutions have tended to be expensive and difficult to deploy, example implementations of the QC card ( 102 ) and base station ( 103 ) are relatively inexpensive. A QC card ( 102 ) is easily carried, and quantum keys generated with QKD facilitate security that is stronger than that provided with conventional non-quantum key distribution.
To generate quantum keys, a user inserts the QC card ( 102 ) into the base station ( 103 ). Typically, as a pre-condition for QKD, the trusted authority ( 101 ) authenticates the user. For example, the QC card ( 102 ) accepts a fingerprint scan and personal identification number (âPINâ) from the user, encrypts the PIN and fingerprint scan data, and transmits the encrypted material to the trusted authority ( 101 ) for comparison against information previously provided to the trusted authority ( 101 ). Alternatively, the QC card ( 102 ) accepts other biometric information and/or other information that identifies the user.
The QC card ( 102 ) then performs QKD with the trusted authority ( 101 ) and stores the resulting quantum keys in secure memory on the QC card ( 102 ). In FIG. 1 , the base station ( 103 ) is connected to the trusted authority ( 101 ) over installed fiber ( 104 ). The installed fiber ( 104 ) is used as a quantum channel for point-to-point QKD between the QC card ( 102 ) and trusted authority ( 101 ), for example, for transmission of photons encoded with quantum state information. The point-to-point QKD can happen over a single optical span or multiple spans in a fiber network whose topology supports QKD. For example, the topology includes intermediate routers between the QC card and trusted authority, but the routers preserve quantum state information. In FIG. 1 , the installed fiber ( 104 ) is also used as a public channel to exchange non-quantum information between the QC card ( 102 ) and trusted authority ( 101 ), for example, authentication information, non-quantum information about measuring bases, recording basis in the QKD, and/or non-secret key information from the trusted authority ( 101 ). Alternatively, the QC card ( 102 ) and trusted authority ( 101 ) communicate non-quantum information over another type of network media (e.g., copper, RF) or free space (optical), or over a fiber network having another network topology.
In one use scenario, a business purchases QC cards ( 102 ) for its employees and purchases one or more base stations ( 103 ) located at its facilities. An employee periodically plugs his or her QC card ( 102 ) into a base station to load up on quantum keys. The employee can then use the quantum keys for activities such as purchasing over the Internet, authentication or access control at a remote site.
The mobile phone ( 107 ) includes a QC card ( 102 ) as well as conventional mobile phone components. The mobile phone ( 107 ) couples with a base station ( 103 ) that is adapted to connect to the mobile phone ( 107 ) and provides a network connection to the trusted authority ( 101 ). The mobile phone's base station ( 103 ) can also provide electric power and a data connection for synchronization of information on the mobile phone ( 107 ). The mobile phone ( 107 ) stores quantum keys produced by the QC card ( 102 ) and trusted authority ( 101 ). Example implementations for a mobile phone ( 107 ) that includes a QC card are described below in Section II.
As shown in FIG. 1 , the trusted authority ( 101 ) can also produce quantum keys for devices other than a QC card ( 102 ). For example, the trusted authority ( 101 ) performs QKD to distribute quantum keys to a low-orbit satellite ( 108 ) using equipment for QC transmission and reception through free space. Or, the trusted authority ( 101 ) performs QKD with a conventional QC transmitter ( 105 ), which directly conveys the quantum keys produced by QKD to a locally connected computer ( 106 ) at a secure facility. The conventional QC transmitter ( 105 ) can connect to the trusted authority ( 101 ) over installed fiber ( 104 ) (e.g., standard fiber for telecommunications in a building, FTTx link, metro area, etc.) or free space (e.g., rooftop to rooftop, airplane to ground, ship to ship, satellite to ground).
In any case, the QKD produces cryptographic-quality secret random numbers, which can be used as quantum keys for encryption, secure multi-party audio or video communication, authentication, bank transactions, facility access control, access control for a computing system or database, access control for an online control system, vehicle access, digital signatures, e-voting, tele-presence or another application. As random numbers, the quantum keys have forward secrecy. The quantum keys do not depend on any pre-placed secret key, and they are not subject to conventional attacks, nor are they vulnerable to future advances that exploit increased computing power or flaws discovered in key generation algorithms. Some of the quantum keys produced by QKD can be used for authentication and other set-up operations before subsequent QKD sessions, so that such set-up operations are automatic and seamless to the user.
In the examples shown in FIG. 1 , the computing system that implements the trusted authority ( 101 ) has a QC receiver. Alternatively, computing system that implements the trusted authority ( 101 ) has a QC transmitter, and the other party to QKD includes a QC receiver.
FIG. 2 shows an example operating environment ( 200 ) in which a QC card ( 102 ) further distributes quantum keys obtained through QKD with the trusted authority ( 101 ). A QC card ( 102 ) can distribute stored quantum keys to a mobile phone ( 117 ) or a user's computer ( 116 ). For example, the QC card ( 102 ) transmits the quantum keys over a point-to-point fiber connection or wireless connection. Or, a QC card ( 102 ) provides quantum keys to a satellite control center ( 113 ), which uploads the quantum keys to a satellite ( 118 ).
In this way, the QC card ( 102 ) can be used as a âfillgunâ to load quantum keys from its secure memory into a remote encryptor on a spacecraft, naval vessel or other vehicle. For example, the QC card ( 102 ) loads up with quantum keys while coupled with a base station at a terminal, is carried to a spacecraft before launch, and then loads the quantum keys onto a computing device aboard the spacecraft. The computing device aboard the spacecraft can then use the quantum keys for secure communication with the terminal or another device.
FIG. 3 shows an example operating environment ( 300 ) in which quantum keys distributed through QKD are used to establish secure communication, used for authentication or used for access control. With one or more quantum keys and information provided by the trusted authority ( 101 ), a user device can securely communicate with another user device directly or over a public network ( 130 ) such as the Internet. Or, the user device can use a quantum key to authenticate itself to another user device or gain access to a facility through an access control device ( 120 ). Within the network of user devices that have each received quantum keys from QKD with the trusted authority, one user device can establish a secure connection with any other user device without QKD between the two user devices.
A user device shown in FIG. 3 can acquire its quantum keys through any form of QKD with the trusted authority ( 101 ). Some of the user devices shown in FIG. 3 acquired quantum keys directly through QKD with the trusted authority ( 101 ), as illustrated in FIG. 1 . For example, the mobile phone ( 107 ) and QC card ( 102 ) acquired quantum keys from QKD with the trusted authority. The user computers ( 106 ) acquired quantum keys directly from a local connection to a conventional QC transmitter in QKD with the trusted authority. Other user devices shown in FIG. 3 acquired quantum keys from a QC card, as shown in FIG. 2 . For example, the satellite ( 118 ), mobile phone ( 117 ) and user computers ( 116 ) acquired quantum keys from a QC card ( 102 ). In any case, a user device can use its quantum keys at a location different than the location at which the quantum keys were distributed to the user device.
The trusted authority ( 101 ) is both a QC node (as in FIG. 1 ) and a conventional network contact point. Aside from QKD, acting in the role of a network server, the trusted authority ( 101 ) can exchange information using conventional network communication with a user device that acts in the role of a network client. In this way, the user device can receive information that is usable in combination with one of its stored quantum keys to establish a secure connection with another user device. Or, the user device can receive material from the trusted authority ( 101 ) that has been encrypted with one of its stored quantum keys.
Quantum keys can facilitate secure communication even when the quantum keys are not used for algorithmic encryption. If two user devices have the same quantum keys, a first user device can use stored quantum keys to determine patterns to spread information content between wavelengths and/or time slots of a signal, then spread the information according to the patterns in transmission. The second user device determines the patterns from the stored quantum keys and de-spreads the information content from the signal it receives. The patterns depend on the stored quantum keys, but security is provided at the physical layer in transmission, not through use of the stored quantum keys in encryption.
When the quantum keys are used, the trusted authority ( 101 ) can be online or offline. For example, suppose two devices have each acquired quantum keys from QKD with the trusted authority ( 101 ). To establish a secure connection with a second user device, a first user device contacts the trusted authority ( 101 ) over a public network ( 130 ) such as the Internet. The first user device receives information from the trusted authority ( 101 ) that can be used, with a quantum key at the first user device, to establish a secure connection with the second user device. The first and second user devices can then use a joint session key for secure communication over the public network ( 130 ) or otherwise. Or, the trusted authority ( 101 ) can provide such information to the first user device and/or second user device, then go offline. Even though the trusted authority is offline, the first and second user devices can subsequently establish a secure connection over the public network ( 130 ) or directly with each other. The information that the trusted authority ( 101 ) provides for use with the quantum keys can be provided in a non-secret way over the public network ( 130 ), since the information is only useful to the possessor of a quantum key. Section III describes example protocols for secure multi-party communication. The example protocols can be used for secure communication, authentication, access control, and other applications in operating environments such as the example environment ( 300 ) of FIG. 3 .
II. QKD Using QC Card, Base Station and Trusted Authority
A typical smartcard is a small plastic device, the size of credit card, with an embedded microprocessor. Some smartcards use a hashing function and pre-placed secret keys to generate encryption keys. The encryption keys are then used according to conventional encryption techniques for communication, authentication, access control, etc. Although smartcards are relatively inexpensive and easy to carry, they do not provide security strong enough for many scenarios.
The mechanism of generating encryption keys using a hashing function is susceptible to attack with conventional computers. In the past, hashing functions have been undermined by improvements in algorithmic attacks, and there are no guarantees that current smartcard technology has not been successfully undermined already. At base, smartcards that use known algorithms to generate keys produce random numbers that do not have complete forward secrecy, which means a current key can potentially be predicted from the last key. An adversary can record numbers entered by a legitimate user from his smartcard and crack the algorithm or determine the pre-placed secret key, allowing the adversary to make usable keys to impersonate the legitimate user.
On the other hand, quantum keys produced by QKD have strong forward secrecy. To date, however, QC security solutions have tended to be expensive and difficult to deploy.
A QC card combines advantages of smartcard technology with advantages of QKD. In example implementations, a QC card is relatively inexpensive, lightweight and portable. A QC card stores quantum keys produced by QKD with a trusted authority, and the quantum keys have strong forward security.
In general, a QC card couples with a base station and produces quantum keys by QKD with a trusted authority. For example, a user inserts the QC card into the base station, and the QC card transmits authentication information to the trusted authority. If the user is authenticated, the QC card and trusted authority produce cryptographic-quality secret random numbers for quantum keys. The QC card stores the quantum keys in secure memory. The QC card can later use the quantum keys or distribute the quantum keys to another device for use. Either way, the quantum keys can be used for encryption, authentication, access control or digital signatures by a user. Because the quantum keys produced in QKD are randomly generated and do not depend on any pre-placed secret keys, the quantum keys provide strong security for access to facilities, access to computing systems, bank transactions, secure multi-party communication and other applications.
In some embodiments, a QC card includes a miniaturized QC transmitter, and the computing system for the trusted authority includes a QC receiver. For example, the QC card includes integrated electro-optical modules capable of selectively producing individual photons having any of four non-orthogonal polarization states for QKD (e.g., 0°, 45°, 90° or 135°). The QC card can be fabricated as a single integrated unit with a small footprint. Compared to conventional QC transmitters, the QC transmitter in the QC card is a low-power transmitter. Nonetheless, to the extent energy consumption might be a concern, the QC card can draw electric power from the base station at which the QC card is coupled for QKD. The QC card is lightweight and robust, and it can be packaged in a mobile phone or other device for which limited size, weight and power consumption are desirable attributes.
The QC card/trusted authority framework can produce quantum keys that are used for secure multi-party communication and authentication according to protocols described in section III. In example protocols, a trusted authority distributes quantum keys to different user devices. When the trusted authority is online, a user device can query the trusted authority for information used to set up communication with another device, authenticate the other device, or grant access to the other device. Even if the trusted authority is offline, the different user devices can use information previously provided by the trusted authority to securely communicate with each other or authenticate each other. In the example protocols, secure multi-party communication and authentication efficiently work with a relatively small number of quantum keys, and quantum keys can be periodically renewed with the trusted authority. In these respects and other respects, example protocols of section III are well-suited for use with quantum keys generated by a QC card and trusted authority. Alternatively, however, the QC card/trusted authority framework can produce quantum keys that are used for secure multi-party communication or authentication according to another protocol for key management and/or authentication. For example, the key management protocol can be a variation of Leighton-Micali protocol, and the authentication protocol can be a variation of Wegman-Carter authentication.
A. Generalized Techniques for QKD Between QC Card and Trusted Authority.
FIG. 4 a illustrates a generalized technique ( 400 ) for a QC card to acquire quantum keys through QKD with a trusted authority. Although some acts of FIG. 4 a (e.g., docking QC card with a base station, undocking QC card from the base station) are physically performed by a user, the QC card performs corresponding acts (e.g., coupling, decoupling). FIG. 4 b illustrates a corresponding technique ( 450 ) for the trusted authority to acquire quantum keys through QKD with the QC card.
With reference to FIG. 4 a , a user docks ( 405 ) the QC card with a base station. At this point, the QC card couples to the base station for QC between the QC card and the trusted authority. The base station provides a network connection to the computing system that implements the trusted authority. Upon coupling with the base station, the QC card optically couples to the network connection of the base station. In some implementations, the optical coupling between the QC card and base station uses a fiber connection. Alternatively, the optical coupling uses a wireless connection (e.g., transmission over free space).
In some implementations, the network connection provided by the base station is a fiber connection to the computing system that implements the trusted authority. The network connection can be a dedicated point-to-point fiber connection for direct communication between the QC card and the trusted authority, a dedicated fiber connection over multiple spans connected with one or more optical routers enabling QC transmission and reception through the optical router(s), or a commercial (non-dedicated) fiber connection over a single span or multiple spans of a network of devices with QC transmission and reception equipment. QC typically uses weak photon pulses to mitigate problems that could arise from interception of extra photons. Dedicated fiber (sometimes called âdarkâ fiber) conveys weak photon pulses encoding quantum state information and may also convey bright synchronization pulses. The weak photon pulses are relatively easy to detect, however, due to the absence of other traffic. On the other hand, for QC over non-dedicated fiber, weak photon pulses that encode quantum state information are more difficult to detect. Non-dedicated fiber (sometimes called âlightâ fiber) conveys quantum-state-encoded information in weak photon pulses but also conveys conventional network traffic in bright pulses. Even when synchronization, temporal multiplexing and wavelength multiplexing are used to separate the weak photon pulses of a quantum signal from the bright pulses of other traffic, scattering and other impairments can complicate the task of detecting the weak photon pulses. Various steps can be taken to improve QC performance over non-dedicated fiber. For details, see (1) Peters et al., âDense Wavelength Multiplexing of 1550 nm QKD with Strong Classical Channels in Reconfigurable Networking Environments,â New Journal of Physics 11, 17 pp. (April 2009) and (2) Chapuran et al., âOptical Networking for Quantum Key Distribution and Quantum Communications,â New Journal of Physics 11, 19 pp. (October 2009).
The network between the QC card and trusted authority can include a single span or multiple spans. If there are two spans, for example, and routing between them disrupts quantum state of the quantum-state-encoded information, the QC card can perform QKD with an intermediate trusted node, which also performs QKD with the trusted authority. The intermediate trusted node subsequently distributes quantum keys to the QC card and trusted authority, respectively, that have been encrypted using the quantum keys resulting from the respective QKD sessions. Or, if the quantum state is not disrupted, the QC card can perform QKD directly with the trusted authority across multiple spans.
Aside from providing a network connection, the base station can also provide power to the QC card. For example, when the user docks ( 405 ) the QC card, the QC card electrically couples with the base station. The QC card draws electric power from the base station. The QC card can use the electric power to power one or more integrated optics modules and/or cool one or more integrated optics modules to an operating temperature for QC. The electrical coupling between the QC card and base station can be implemented with a conventional wired technique, or the electrical coupling can be implemented with a wireless technique (e.g., to transfer power by electro-magnetic induction over a short range between the QC card and a charging pad of the base station). In some implementations, the QC card and trusted authority perform QC over free space, with the base station providing electric power to the QC card and/or aligning the QC card when the QC card is coupled to the base station.
Generally, in the techniques ( 400 , 450 ) shown in FIGS. 4 a and 4 b , the base station is a âdumbâ terminal that provides a network connection and, in some cases, electric power. The base station need not be trusted, since the QC card performs the actual QKD with the trusted authority. In alternative embodiments, such as those described at the end of section II.C, the base station is partially trusted or trusted and provides additional functionality for aspects of QKD.
When authentication of a user is a condition of QKD, the QC card prepares and transmits ( 410 ) a message with information for authentication. For example, the QC card receives identifying information for a user, such as a fingerprint scan, other biometric indicia, numeric input for a PIN, or other user input for personal information. The QC card encrypts the identifying information using an authentication key and transmits the encrypted information as the message to the trusted authority for authentication of the user.
To establish QC with the QC card coupled with the base station, the trusted authority authenticates the user. The trusted authority receives ( 455 ) the message with the information for authentication. The trusted authority checks ( 460 ) the message and, if appropriate, authenticates the user. For example, the trusted authority receives encrypted information as the message, where the information is identifying information for the user that has been encrypted using an authentication key. The trusted authority decrypts the identifying information using the authentication key and determines whether to authenticate the user based on the identifying information.
In general, for an initial QKD session between the QC card and trusted authority, the authentication key used to encrypt/decrypt the identifying information is a pre-placed key in the QC card that is known to the trusted authority. The initial key can be replaced with a quantum key subsequently generated in the QKD between the QC card and trusted authority. The new quantum key is stored in a special location in the QC card and trusted authority for use in authentication before the next QKD session. In this way, reuse of the initial authentication key is avoided and security is improved.
The trusted authority can send a message to the QC card indicating the user has been authenticated. The QC card checks ( 415 ) whether authentication of the user has succeeded.
If authentication has succeeded, the QC card and trusted authority create ( 420 , 470 ) one or more quantum keys in QKD with each other. The quantum key(s) are produced based upon QC (information encoded in quantum states) and non-quantum communication (e.g., information exchanged over a public channel to settle upon the quantum keys) between the QC card and trusted authority.
The mechanics of the QC depend on implementation. For example, the QC card includes a connector that is optically coupled to one or more integrated optics modules for a QC transmitter, which is adapted to transmit information encoded in quantum states to a QC receiver of the trusted authority. The quantum-state-encoded information is transmitted in a quantum channel as part of the QC between the QC card and trusted authority through the base station. FIGS. 5 and 6 a - 6 c show details for example QC cards with QC transmitters, and operations of the example QC cards are explained below with reference to those figures. Alternatively, the QC card includes one or more integrated optics modules for a QC receiver that receives information encoded in quantum states from a QC transmitter of the trusted authority. The QC card and trusted authority can use the same network connection for QC and non-quantum communication. For example, QC between the QC card and trusted authority uses a quantum channel over optical fiber, and non-quantum communication between the QC card and trusted authority uses a public channel over the optical fiber. Alternatively, the QC and non-quantum communication use different network connections. For example, the QC uses an optical connection but the non-quantum communication uses a non-optical connection.
The QC card stores ( 430 ) the quantum key(s). The trusted authority also stores ( 480 ) the quantum key(s). For example, the QC card stores the quantum key(s) in secure memory of the QC card, and the trusted authority stores the quantum key(s) in secure memory of the trusted authority.
The user then undocks ( 440 ) the QC card from the base station. At this point, the QC card decouples from the base station. In some scenarios, the QC card is used as a fillgun and transmits stored quantum keys to another user device for storage in memory of the other user device. In other scenarios, the QC card itself uses stored quantum keys for secure communication, authentication, access control, etc. with one or more other devices that have received quantum key information from the trusted authority.
For example, in some use scenarios, the QC card (or device including the QC card) contacts the trusted authority over a public channel (e.g., wireless Internet connection, cell phone connection), encrypts identifying information using a stored quantum key, and transmits the encrypted identifying information to the trusted authority over the public channel. The trusted authority responds with encrypted key material, which is decrypted using the same quantum key or the next stored quantum key. The key material can then be used for secure communication with the other device(s), authentication to the other device(s), access control past the other device(s), etc. The other device(s) similarly communicate with the trusted authority over the public channel and similarly
CLAIMS
Claims ( 26 )
The invention claimed is:
1. A method of facilitating secure communication between plural user devices, the plural user devices including a first user device and a second user device, the method comprising, with a system that implements a trusted authority:
distributing one or more first quantum keys by first quantum key distribution under a first trust relationship between the trusted authority and a first user, wherein the one or more first quantum keys include a key authentication key;
distributing one or more second quantum keys by second quantum key distribution under a second trust relationship between the trusted authority and a second user, wherein the one or more first quantum keys are different than the one or more second quantum keys, and wherein the one or more second quantum keys include an encryption key for the second user device;
determining one or more combination keys based at least in part upon at least one of the one or more first quantum keys and at least one of the one or more second quantum keys;
creating a key authentication value using the encryption key for the second user device and the key authentication key; and
making the one or more combination keys and the key authentication value available for distribution, wherein the one or more combination keys facilitate secure communication between the first user device and the second user device even in the absence of quantum key distribution between the first user device and the second user device.
2. The method of claim 1 further comprising, with the system that implements the trusted authority:
before the first quantum key distribution, authenticating the first user, based at least in part upon biometric indicia for the first user, to establish the first trust relationship; and
before the second quantum key distribution, authenticating the second user, based at least in part upon biometric indicia for the second user, to establish the second trust relationship.
3. The method of claim 2 wherein:
the authenticating the first user uses a first pre-placed secret key;
the one or more first quantum keys distributed by the first quantum key distribution include a first new key for use in subsequent authentication of the first user;
the authenticating the second user uses a second pre-placed secret key; and
the one or more second quantum keys distributed by the second quantum key distribution include a second new key for use in subsequent authentication of the second user.
4. The method of claim 1 wherein the one or more first quantum keys further include a key derivation key.
5. The method of claim 1 wherein the creating the key authentication value comprises using a cryptographic hash function.
6. The method of claim 1 wherein the key authentication key is a first key authentication key, wherein the one or more first quantum keys include an encryption key for the first user device, a first key derivation key and the first key authentication key, and wherein the one or more second quantum keys include the encryption key for the second user device, a second key derivation key and a second key authentication key.
7. The method of claim 6 wherein:
the determining the one or more combination keys includes:
determining a first combination key of the one or more combination keys from the first key derivation key and the encryption key for the second user device; and
determining a second combination key of the one or more combination keys from the second key derivation key and the encryption key for the first device;
the method further comprises, with the system that implements the trusted authority, creating one or more other key authentication values and making the one or more other key authentication values available for distribution, wherein:
a value of the one or more other key authentication values is determined from the encryption key for the first device and the second key authentication key.
8. The method of claim 1 wherein the system that implements the trusted authority is distributed among plural physical nodes, and wherein the method further comprises:
using first quantum secret sharing to facilitate the first quantum key distribution for the first user and the plural physical nodes of the trusted authority; and
using second quantum secret sharing to facilitate the second quantum key distribution for the second user and the plural physical nodes of the trusted authority.
9. A method of secure communication between plural user devices, the plural user devices including a first user device and a second user device, the method comprising, with the first user device:
retrieving one or more first quantum keys that result from quantum key distribution with a trusted authority under a trust relationship between the trusted authority and a first user, wherein the one or more first quantum keys include a key authentication key;
retrieving a combination key that is based at least in part upon one of the one or more first quantum keys and a key for the second user device;
authenticating the key for the second user device using the key authentication key and a reference key authentication value made available by the trusted authority; and
communicating with the second user device based at least in part on the key for the second user device, wherein the combination key facilitates secure communication between the first user device and the second user device even in the absence of quantum key distribution between the first user device and the second user device.
10. The method of claim 9 further comprising, before the quantum key distribution, with the first user device:
receiving biometric indicia for the first user;
encrypting the biometric indicia using a pre-placed secret key; and
transmitting the encrypted biometric indicia to the trusted authority for authentication of the first user to establish the trust relationship between the trusted authority and the first user;
wherein the one or more first quantum keys distributed by the quantum key distribution include a new key for use in subsequent authentication of the first user.
11. The method of claim 9 wherein the one or more first quantum keys further include a key derivation key, and wherein the combination key is based at least in part on the key derivation key, the method further comprising, with the first user device:
determining the key for the second user device using the key derivation key and the combination key.
12. The method of claim 11 further comprising, with the first user device:
retrieving the reference key authentication value made available by the trusted authority;
as part of the authenticating:
determining a check key authentication value using the key for the second user device and the key authentication key; and
comparing the check key authentication value to the reference key authentication value.
13. The method of claim 9 wherein the one or more first quantum keys include a different key for each of plural user devices other than the first user device, the method further comprising, with the first user device:
determining a group session key; and
for each of the plural user devices other than the first user device:
encrypting the group session key using an encryption key specific to pair-wise communication between the first user device and the other user device; and
communicating the encrypted group session key to the other user device.
14. The method of claim 13 wherein, for each of the plural user devices other than the first user device, the different key is:
the encryption key specific to pair-wise communication between the first user device and the other user device, or
a key derivation key usable by the first user device to determine the encryption key specific to pair-wise communication between the first user device and the other user device.
15. The method of claim 13 further comprising, with the first user device:
assigning plural subgroup keys for plural subgroups, respectively, each of the plural user devices other than the first user device belonging to one of the plural sub-groups; and
for each of the plural user devices other than the first user device:
assigning an individual group member key;
identifying which of the plural subgroup keys applies for the other user device;
encrypting the individual group member key and the identified subgroup key using the encryption key specific to pair-wise communication between the first user device and the other user device; and
communicating the encrypted individual group member key and the encrypted subgroup key to the other user device.
16. A system that implements a trusted authority, the system comprising a processor, memory and storage storing computer-executable instructions for causing the system to perform a method of facilitating secure communication between plural user devices, the plural user devices including a first user device and a second user device, the method comprising, with the system that implements a trusted authority:
distributing one or more first quantum keys by quantum key distribution, wherein the one or more first quantum keys include an encryption key for the first user device;
distributing one or more second quantum keys by quantum key distribution, wherein the one or more second quantum keys include a key derivation key for the second user device and a key authentication key for the second user device;
determining a pair key based at least in part on the encryption key for the first user device and the key derivation key for the second user device;
determining a key authentication value using the encryption key for the first user device and the key authentication key for the second user device; and
making the pair key and the key authentication value available for distribution, wherein the pair key is usable by the second user device in combination with the key derivation key for the second user device to determine the encryption key for the first user device, and wherein the key authentication value and the key authentication key for the second user device are usable by the second user device to authenticate the encryption key for the first user device.
17. The system of claim 16 wherein the pair key is determined as bitwise XOR of the encryption key for the first user device and the key derivation key for the second user device.
18. The system of claim 16 wherein:
for each given user device i of the plural user devices, plural quantum keys for the given user device i include:
a different encryption key K(i,j) for pair-wise communication between the given user device i and each other user device j of the plural user devices; and
a different key derivation key L(i,j) for the pair-wise communication between the given user device i and each other user device j of the plural user devices; and
for each given user device i of the plural user devices, a different pair key P(i,j) for each other user device j of the plural user devices is determined, the different pair key P(i,j) being based at least in part upon:
the different key derivation key L(i,j) for the given user device i with respect to the other user device j; and
the different encryption key K(j,i) for the other user device j with respect to the given user device i.
19. One or more non-transitory computer-readable storage media storing computer-executable instructions for causing a first user device programmed thereby to perform a method comprising:
retrieving one or more first quantum keys that result from quantum key distribution with a trusted authority under a trust relationship between the trusted authority and a first user, wherein the one or more first quantum keys include a key authentication key;
retrieving a combination key that is based at least in part upon one of the one or more first quantum keys and a key for a second user device;
authenticating the key for the second user device using the key authentication key and a reference key authentication value made available by the trusted authority; and communicating with the second user device based at least in part on the key for the second user device, wherein the combination key facilitates secure communication between the first user device and the second user device even in the absence of quantum key distribution between the first user device and the second user device.
20. The one or more non-transitory computer-readable storage media of claim 19 wherein the method further comprises, before the quantum key distribution:
receiving biometric indicia for the first user;
encrypting the biometric indicia using a pre-placed secret key; and
transmitting the encrypted biometric indicia to the trusted authority for authentication of the first user to establish the trust relationship between the trusted authority and the first user; wherein the one or more first quantum keys distributed by the quantum key distribution include a new key for use in subsequent authentication of the first user.
21. The one or more non-transitory computer-readable storage media of claim 19 wherein the one or more first quantum keys further include a key derivation key, and wherein the combination key is based at least in part on the key derivation key, the method further comprising:
determining the key for the second user device using the key derivation key and the combination key.
22. The one or more non-transitory computer-readable storage media of claim 19 wherein the method further comprises:
retrieving the reference key authentication value made available by the trusted authority;
as part of the authenticating:
determining a check key authentication value using the key for the second user device and the key authentication key; and
comparing the check key authentication value to the reference key authentication value.
23. A first user device comprising a processor, memory and storage storing computer-executable instructions for causing the first user device to perform a method comprising:
retrieving one or more first quantum keys that result from quantum key distribution with a trusted authority under a trust relationship between the trusted authority and a first user, wherein the one or more first quantum keys include a key authentication key;
retrieving a combination key that is based at least in part upon one of the one or more first quantum keys and a key for a second user device;
authenticating the key for the second user device using the key authentication key and a reference key authentication value made available by the trusted authority; and
communicating with the second user device based at least in part on the key for the second user device, wherein the combination key facilitates secure communication between the first user device and the second user device even in the absence of quantum key distribution between the first user device and the second user device.
24. The first user device of claim 23 wherein the method further comprises, before the quantum key distribution:
receiving biometric indicia for the first user;
encrypting the biometric indicia using a pre-placed secret key; and
transmitting the encrypted biometric indicia to the trusted authority for authentication of the first user to establish the trust relationship between the trusted authority and the first user;
wherein the one or more first quantum keys distributed by the quantum key distribution include a new key for use in subsequent authentication of the first user.
25. The first user device of claim 23 wherein the one or more first quantum keys further include a key derivation key, and wherein the combination key is based at least in part on the key derivation key, the method further comprising:
determining the key for the second user device using the key derivation key and the combination key.
26. The first user device of claim 23 wherein the method further comprises:
retrieving the reference key authentication value made available by the trusted authority;
as part of the authenticating:
determining a check key authentication value using the key for the second user device and the key authentication key; and
comparing the check key authentication value to the reference key authentication value.
US13/912,010
2010-06-15
2013-06-06
Secure multi-party communication with quantum key distribution managed by trusted authority
Active
US8929554B2
( en )
Priority Applications (2)
Application Number
Priority Date
Filing Date
Title
US13/912,010
US8929554B2
( en )
2010-09-30
2013-06-06
Secure multi-party communication with quantum key distribution managed by trusted authority
US14/589,261
US9680640B2
( en )
2010-06-15
2015-01-05
Secure multi-party communication with quantum key distribution managed by trusted authority
Applications Claiming Priority (2)
Application Number
Priority Date
Filing Date
Title
US12/895,367
US8483394B2
( en )
2010-06-15
2010-09-30
Secure multi-party communication with quantum key distribution managed by trusted authority
US13/912,010
US8929554B2
( en )
2010-09-30
2013-06-06
Secure multi-party communication with quantum key distribution managed by trusted authority
Related Parent Applications (1)
Application Number
Title
Priority Date
Filing Date
US12/895,367
Continuation
US8483394B2
( en )
2010-06-15
2010-09-30
Secure multi-party communication with quantum key distribution managed by trusted authority
Related Child Applications (1)
Application Number
Title
Priority Date
Filing Date
US14/589,261
Continuation
US9680640B2
( en )
2010-06-15
2015-01-05
Secure multi-party communication with quantum key distribution managed by trusted authority
Publications (2)
Publication Number
Publication Date
US20130272524A1
US20130272524A1 ( en )
2013-10-17
US8929554B2
true
US8929554B2 ( en )
2015-01-06
Family
ID=45893753
Family Applications (3)
Application Number
Title
Priority Date
Filing Date
US12/895,367
Expired - Fee Related
US8483394B2
( en )
2010-06-15
2010-09-30
Secure multi-party communication with quantum key distribution managed by trusted authority
US13/912,010
Active
US8929554B2
( en )
2010-06-15
2013-06-06
Secure multi-party communication with quantum key distribution managed by trusted authority
US14/589,261
Active
2031-02-13
US9680640B2
( en )
2010-06-15
2015-01-05
Secure multi-party communication with quantum key distribution managed by trusted authority
Family Applications Before (1)
Application Number
Title
Priority Date
Filing Date
US12/895,367
Expired - Fee Related
US8483394B2
( en )
2010-06-15
2010-09-30
Secure multi-party communication with quantum key distribution managed by trusted authority
Family Applications After (1)
Application Number
Title
Priority Date
Filing Date
US14/589,261
Active
2031-02-13
US9680640B2
( en )
2010-06-15
2015-01-05
Secure multi-party communication with quantum key distribution managed by trusted authority
Country Status (5)
Country
Link
US
( 3 )
US8483394B2
( en )
EP
( 1 )
EP2622784B1
( en )
JP
( 1 )
JP2013539324A
( en )
ES
( 1 )
ES2875888T3
( en )
WO
( 1 )
WO2012044855A2
( en )
Cited By (11)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20150036825A1
( en )
*
2013-08-01
2015-02-05
Kabushiki Kaisha Toshiba
Communication apparatus, computer program product, and communication system
US10313114B2
( en )
2015-07-31
2019-06-04
Alibaba Group Holding Limited
Authentication method, device and system for quantum key distribution process
US10389525B2
( en )
2014-10-30
2019-08-20
Alibaba Group Holding Limited
Method, apparatus, and system for quantum key distribution, privacy amplification, and data transmission
US10484352B2
( en )
2017-03-31
2019-11-19
Microsoft Technology Licensing, Llc
Data operations using a proxy encryption key
US10505724B2
( en )
2015-08-18
2019-12-10
Alibaba Group Holding Limited
Authentication method, apparatus and system used in quantum key distribution process
US11228430B2
( en )
2019-09-12
2022-01-18
General Electric Technology Gmbh
Communication systems and methods
US20230239154A1
( en )
*
2020-06-25
2023-07-27
British Telecommunications Public Limited Company
Secure communication of user device data
US20250233671A1
( en )
*
2021-10-18
2025-07-17
Arqit Limited
Optical switching for quantum key distribution
US12386687B2
( en )
2022-10-25
2025-08-12
Bank Of America Corporation
Technology and protocol agnostic key-value pair based user interface and data rendering to support a transaction
US20250274271A1
( en )
*
2024-02-26
2025-08-28
Jpmorgan Chase Bank, N.A.
Systems and methods for quantum-safe key infrastructures
US12519624B2
( en )
*
2023-01-25
2026-01-06
Nokia Technologies Oy
Identity authentication for QKD protocols
Families Citing this family (119)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
KR100981419B1
( en )
*
2008-01-31
2010-09-10
주ìíì¬ í¬í
How to join user domain and exchange information for digital rights management
GB201001421D0
( en )
*
2010-01-29
2010-03-17
Hewlett Packard Development Co
Quantum key distribution method and apparatus
GB201001422D0
( en )
*
2010-01-29
2010-03-17
Hewlett Packard Development Co
Quantum key distribution method and apparatus
US9002009B2
( en )
2010-06-15
2015-04-07
Los Alamos National Security, Llc
Quantum key distribution using card, base station and trusted authority
US8483394B2
( en )
2010-06-15
2013-07-09
Los Alamos National Security, Llc
Secure multi-party communication with quantum key distribution managed by trusted authority
EP2555466B1
( en )
*
2011-08-05
2014-07-02
SELEX ES S.p.A.
System for distributing cryptographic keys
US9287994B2
( en )
2011-09-30
2016-03-15
Los Alamos National Security, Llc
Great circle solution to polarization-based quantum communication (QC) in optical fiber
US9866379B2
( en )
2011-09-30
2018-01-09
Los Alamos National Security, Llc
Polarization tracking system for free-space optical communication, including quantum communication
US8627076B2
( en )
*
2011-09-30
2014-01-07
Avaya Inc.
System and method for facilitating communications based on trusted relationships
EP2817917B1
( en )
*
2012-02-20
2018-04-11
KL Data Security Pty Ltd
Cryptographic method and system
KR102026898B1
( en )
*
2012-06-26
2019-09-30
ì¼ì±ì ì주ìíì¬
Method and apparatus for secure communication between transmitter and receiver, method and apparatus for determining the secure information
EP2682785B1
( en )
*
2012-07-05
2023-08-30
Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V.
Concept for data authentication and secured localization based on a satellite navigation signal
EP2885886B1
( en )
2012-08-17
2019-02-13
Triad National Security, LLC
Quantum communications system with integrated photonic devices
EP2891267B1
( en )
*
2012-08-30
2022-04-06
Triad National Security, LLC
Multi-factor authentication using quantum communication
JP5734934B2
( en )
*
2012-09-07
2015-06-17
æ ªå¼ä¼ç¤¾æ±è
Communication node, key synchronization method, key synchronization system
JP6336581B2
( en )
2013-05-23
2018-06-06
ãã¥ã¼ãããã¯ï¼ã¤ã³ã³ã¼ãã¬ã¤ããã
Non-damaged public key using quantum encryption technology for secure wired and wireless communications
CN108923918B
( en )
2013-06-28
2022-07-15
æ¥æ¬çµæ°æ ªå¼ä¼ç¤¾
User equipment and communication method
US10574461B2
( en )
2013-09-30
2020-02-25
Triad National Security, Llc
Streaming authentication and multi-level security for communications networks using quantum cryptography
KR101466204B1
( en )
*
2013-10-25
2014-11-27
ìì¤ì¼ì´ í ë 콤주ìíì¬
Method for Dealing with Double Click Events for Guaranteeing Security of Quantum Key Distribution System
US10177933B2
( en )
2014-02-05
2019-01-08
Apple Inc.
Controller networks for an accessory management system
JP6165646B2
( en )
*
2014-01-30
2017-07-19
æ ªå¼ä¼ç¤¾æ±è
Quantum key distribution apparatus, quantum key distribution system, and quantum key distribution method
CN105981352B
( en )
2014-02-05
2018-03-13
è¹æå ¬å¸
Controller, accessory controlled by controller and communication method
JP6378349B2
( en )
*
2014-02-14
2018-08-22
ãã㢠ãã¯ããã¸ã¼ãº ãªãµã±ã¦ã¤ãã¢
Key distribution in wireless systems
JP6359285B2
( en )
*
2014-02-17
2018-07-18
æ ªå¼ä¼ç¤¾æ±è
Quantum key distribution apparatus, quantum key distribution system, and quantum key distribution method
WO2015184387A1
( en )
2014-05-30
2015-12-03
Apple Inc.
Accessory management system using environment model
US9954837B2
( en )
*
2015-01-07
2018-04-24
Cyph, Inc.
Method of multi-factor authenication during encrypted communications
US20220360573A1
( en )
*
2015-01-07
2022-11-10
Cyph Inc.
Encrypted group communication method
KR101705244B1
( en )
*
2015-01-23
2017-02-09
ìì¸ì립ëíêµ ì°ííë ¥ë¨
Mobile commerce with quantum cryptography enhanced security and authentification method therefor
KR101718782B1
( en )
*
2015-01-23
2017-03-22
ìì¸ì립ëíêµ ì°ííë ¥ë¨
Secure payment and authentification system having enhanced security with quantum crypyography
US10206170B2
( en )
2015-02-05
2019-02-12
Apple Inc.
Dynamic connection path detection and selection for wireless controllers and accessories
CN105991285B
( en )
*
2015-02-16
2019-06-11
é¿éå·´å·´é墿§è¡æéå ¬å¸
Identity authentication method, device and system for quantum key distribution process
JP6478749B2
( en )
*
2015-03-24
2019-03-06
æ ªå¼ä¼ç¤¾æ±è
Quantum key distribution apparatus, quantum key distribution system, and quantum key distribution method
KR101562311B1
( en )
*
2015-04-06
2015-10-21
(주) ì¤ì¤ìì¤í¼
Transmitting/receiving device of security gateway of physically unidirectional communication capable of security tunneling and re-transmitting data, and method of transferring data using the same
GB201506045D0
( en )
*
2015-04-09
2015-05-27
Vodafone Ip Licensing Ltd
SIM security
CN106161402B
( en )
*
2015-04-22
2019-07-16
é¿éå·´å·´é墿§è¡æéå ¬å¸
Encryption equipment key injected system, method and device based on cloud environment
US9866383B2
( en )
*
2015-10-28
2018-01-09
Cisco Technology, Inc.
Key management for privacy-ensured conferencing
US20170244687A1
( en )
*
2016-02-24
2017-08-24
Whitewood Encryption Systems, Inc.
Techniques for confidential delivery of random data over a network
US10701514B2
( en )
*
2016-03-15
2020-06-30
Dialog Semiconductor B.V.
Determining the distance between devices in a wireless data exchange protocol
US11019037B2
( en )
2016-03-15
2021-05-25
Dialog Semiconductor B.V.
Security improvements in a wireless data exchange protocol
WO2017167549A1
( en )
*
2016-03-30
2017-10-05
British Telecommunications Public Limited Company
Untrusted code distribution
KR101830339B1
( en )
*
2016-05-20
2018-03-29
íêµì ìíµì ì°êµ¬ì
Apparatus for quantum key distribution on a quantum network and method using the same
JP2018033079A
( en )
*
2016-08-26
2018-03-01
æ ªå¼ä¼ç¤¾æ±è
Communication device, communication system and communication method
US10219157B1
( en )
*
2016-10-05
2019-02-26
Symantec Corporation
Secure verified attribute exchange between parties in physical proximity
JP7158693B2
( en )
*
2016-12-06
2022-10-24
æ ªå¼ä¼ç¤¾ ã¨ããã£ã¼ã¢ã¤
Communication system, server device, user device, method, computer program
US11010485B1
( en )
*
2017-03-02
2021-05-18
Apple Inc.
Cloud messaging system
US10476854B2
( en )
*
2017-04-20
2019-11-12
Bank Of America Corporation
Quantum key distribution logon widget
US10432663B2
( en )
2017-04-25
2019-10-01
Bank Of America Corporation
Electronic security keys for data security based on quantum particle states that indicates type of access
US10644882B2
( en )
*
2017-04-25
2020-05-05
Bank Of America Corporation
Electronic security keys for data security based on quantum particle states
US10496508B2
( en )
2017-06-02
2019-12-03
Apple Inc.
Accessory communication control
US11082432B2
( en )
*
2017-12-05
2021-08-03
Intel Corporation
Methods and apparatus to support reliable digital communications without integrity metadata
US11457042B1
( en )
2018-02-27
2022-09-27
Wells Fargo Bank, N.A.
Multi-tiered system for detecting and reducing unauthorized network access
CN108847927B
( en )
*
2018-03-05
2020-11-24
æµæ±å·¥å大å¦
A single-photon-based annular semi-quantum secret sharing method that does not require classical communicators to have measurement capabilities
CN110247881B
( en )
*
2018-03-09
2021-08-13
å±±ä¸éåç§å¦ææ¯ç ç©¶é¢æéå ¬å¸
Wearable device-based identity authentication method and system
US10728029B1
( en )
2018-03-09
2020-07-28
Wells Fargo Bank, N.A.
Systems and methods for multi-server quantum session authentication
CN118944911A
( en )
*
2018-03-09
2024-11-12
å±±ä¸éåç§å¦ææ¯ç ç©¶é¢æéå ¬å¸
Identity authentication method and system based on wearable device
US11025416B1
( en )
*
2018-03-09
2021-06-01
Wells Fargo Bank, N.A.
Systems and methods for quantum session authentication
US11343087B1
( en )
2018-03-09
2022-05-24
Wells Fargo Bank, N.A.
Systems and methods for server-side quantum session authentication
US10812258B1
( en )
*
2018-03-09
2020-10-20
Wells Fargo Bank, N.A.
Systems and methods for quantum session authentication
US10855454B1
( en )
2018-03-09
2020-12-01
Wells Fargo Bank, N.A.
Systems and methods for quantum session authentication
CN108494550B
( en )
*
2018-03-12
2021-08-06
é¿æ¥å¤§å¦
A secure unlocking method for mobile terminals based on quantum keys
CN110505063B
( en )
*
2018-05-17
2022-08-02
广ä¸å½ç¾éåç§ææéå ¬å¸
Method and system for ensuring security of financial payment
US11805009B2
( en )
2018-06-03
2023-10-31
Apple Inc.
Configuring accessory network connections
US10595073B2
( en )
*
2018-06-03
2020-03-17
Apple Inc.
Techniques for authorizing controller devices
CN108989028A
( en )
*
2018-07-16
2018-12-11
åå°æ»¨å·¥ä¸å¤§å¦ï¼æ·±å³ï¼
Group cipher distribution management method, apparatus, electronic equipment and storage medium
US11683168B2
( en )
2018-08-03
2023-06-20
Istanbul Teknik Universites!
Systems and methods for generating shared keys, identity authentication and data transmission based on simultaneous transmission on wireless multiple-access channels
US11190349B1
( en )
2018-08-20
2021-11-30
Wells Fargo Bank, N.A.
Systems and methods for providing randomness-as-a-service
US10552120B1
( en )
2018-08-20
2020-02-04
Wells Fargo Bank, N.A.
Systems and methods for single chip quantum random number generation
US11240013B1
( en )
2018-08-20
2022-02-01
Wells Fargo Bank, N.A.
Systems and methods for passive quantum session authentication
US10855457B1
( en )
2018-08-20
2020-12-01
Wells Fargo Bank, N.A.
Systems and methods for single chip quantum random number generation
US10855453B1
( en )
2018-08-20
2020-12-01
Wells Fargo Bank, N.A.
Systems and methods for time-bin quantum session authentication
US11095439B1
( en )
2018-08-20
2021-08-17
Wells Fargo Bank, N.A.
Systems and methods for centralized quantum session authentication
US10540146B1
( en )
2018-08-20
2020-01-21
Wells Fargo Bank, N.A.
Systems and methods for single chip quantum random number generation
US11546138B2
( en )
*
2018-09-28
2023-01-03
Benjamin Allan Mord
Information integrity in blockchain and related technologies
EP3742664A1
( en )
*
2019-05-23
2020-11-25
ID Quantique S.A.
System and method for quantum key distribution over hybrid quantum channel
CN110166238A
( en )
*
2019-06-03
2019-08-23
å京æºè¯å¾®çµåç§ææéå ¬å¸
The generation method and device of quantum key
PT115616B
( en )
2019-06-28
2021-07-09
Univ Aveiro
METHOD, TRANSMITTER DEVICE AND RECEIVER DEVICE TO PROTECT CHANNEL TRAINING IN A NON-ORTHOGONAL POWER DOMAIN MULTIPLE ACCESS SYSTEM
CN110190961B
( en )
*
2019-07-02
2021-10-15
æ´é³å¸èå¦é¢
A Verifiable Method for Quantum Secret Sharing
US20220263651A1
( en )
*
2019-07-12
2022-08-18
Benjamin Allan Mord
Custodial integrity for virtual digital assets and related technologies
US11483140B2
( en )
*
2019-08-02
2022-10-25
Quantumxchange, Inc.
Secure out-of-band symmetric encryption key delivery
US11436517B2
( en )
2019-08-26
2022-09-06
Bank Of America Corporation
Quantum-tunneling-enabled device case
US10839060B1
( en )
*
2019-08-27
2020-11-17
Capital One Services, Llc
Techniques for multi-voice speech recognition commands
US11228431B2
( en )
2019-09-20
2022-01-18
General Electric Company
Communication systems and methods for authenticating data packets within network flow
CN110493010B
( en )
*
2019-09-24
2022-03-15