ConceptioArchiveGoogle Patents
Google Patentsopen access

Quantum key distribution node apparatus and method for quantum key distribution … — Electronics And Telecommunications Research Institute (US11316677B2)

Electronics And Telecommunications Research Institute · Google Patents
Google Patents · Patents · License: Open Access
Open Source ↗
patent, google patents, intellectual property, US11316677B2, Electronics And Telecommunications Research Institute, Haeng-Seok KO, en, 2022

ABSTRACT

Abstract

A quantum key distribution (QKD) node apparatus and a QKD method therein. The QKD node apparatus may include a QKD module for generating quantum keys and quantum key IDs, a quantum key synchronization management module for storing the quantum keys and the quantum key IDs as outbound and inbound quantum keys in a distributed manner and sharing the outbound and inbound quantum keys with a second QKD node apparatus, and a quantum key orchestration module for delivering a master key and a master key ID to a secure application connected therewith in response to a request for the master key with the ID of a second secure application and delivering a packet including the master key encrypted with the outbound quantum key shared with the second QKD node apparatus, the master key ID, and a quantum key ID, to the second QKD node apparatus.

Description

CROSS REFERENCE TO RELATED APPLICATION

This application claims the benefit of Korean Patent Application No. 10-2020-0082051, filed Jul. 3, 2020, which is hereby incorporated by reference in its entirety into this application.

BACKGROUND OF THE INVENTION

1. Technical Field

The disclosed embodiment relates to Quantum Key Distribution (QKD) technology.

2. Description of Related Art

Key distribution for sharing the same encryption key between two secure applications has traditionally been regarded as a difficult problem. As measures for the security of key distribution, a method using a Pre-Shared Key (PSK) and a public-key cryptography method, which is asymmetric cryptography using different keys for encryption and decryption, are mainly used.

In the pre-shared key method, a shared key is required to be delivered to a secure application by a trusted sender and to be stored and managed by a trusted manager. That is, because security must be ensured throughout the life cycle of the shared key, including generation, delivery, storage, and the like of thereof, it is difficult to manage the shared key.

In the public-key cryptography method, public-key cryptography, based on a pair comprising a private key and a public key, is designed based on the computational difficulty of factorization of the product of two large numbers and a discrete logarithm problem. However, because cryptography keys are expected to be easily deciphered by factorizing a large number and solving a discrete logarithm problem with the advent of quantum computers, public-key cryptography is known to be vulnerable to security issues.

In order to securely distribute cryptography keys against the threats of quantum computers, a lot of research on Post-Quantum Cryptography (PQC) and Quantum Key Distribution (QKD) has been performed.

PQC is secure public-key cryptography using a hard mathematical problem that makes it impossible to discover a cryptography key even though it is calculated using a quantum computer. QKD uses the no-cloning theorem of quantum physics and the phenomenon whereby a quantum state is destroyed after it is measured.

In the case of QKD, when a photon in a quantum state transmitted by a sender is first measured by an eavesdropper, a Quantum Bit Error Rate (QBER) increases, whereby the presence of the eavesdropper is detected. Accordingly, two quantum key distribution modules may securely share a quantum key, and a QKD protocol may ensure unconditional information-theoretic security.

However, a QKD network system has the following problems.

First, whether a secure application entity that is connected with a QKD node as a part of a conventional QKD network system takes a master role or a slave role should be determined in advance before the arrangement thereof, and a key request must first be made by the master. Accordingly, the conventional QKD network system has a problem in which it is necessary to assign a master role or a slave role to a secure application entity and to manage a list of target secure application entities with which the secure application entity can communicate.

Also, when multiple secure application entities are connected with the same QKD node in a conventional QKD network system, the QKD node must sequentially process key requests from the multiple secure application entities. Therefore, when the current key request is processed, the QKD node blocks additional key requests from secure application entities, other than the secure application entity that made the current key request, which may degrade service efficiency related to key requests.

SUMMARY OF THE INVENTION

An object of an embodiment is to solve a problem in which whether a secure application entity takes a sender role or a receiver role needs to be determined in advance in a quantum key distribution network system.

Another object of an embodiment is to solve a problem of degradation of performance in processing key requests from multiple secure application entities in a quantum key distribution network system.

A quantum key distribution (QKD) node apparatus according to an embodiment may include a QKD module for generating quantum keys and quantum key IDs; a quantum key synchronization management module for storing the quantum keys and the quantum key IDs generated by the QKD module as an outbound quantum key and an inbound quantum key in a distributed manner and for sharing the outbound quantum key and the inbound quantum key with a second QKD node apparatus; and a quantum key orchestration module for delivering a master key, generated using a random number, and a master key ID to a secure application connected therewith when the master key is requested by the secure application using the ID of a second secure application, and for transmitting a packet including the master key encrypted with the outbound quantum key shared with the second QKD node apparatus connected with the second secure application, the master key ID, and the quantum key ID to the second QKD node apparatus.

Here, the QKD modules equal in number to the number of quantum key synchronization management modules may be connected therewith in a one-to-one manner, and each of the QKD module and the quantum key synchronization management module may be one or more in number.

Here, the quantum key orchestration module may retrieve a path corresponding to the ID of the second secure application based on an internal routing table, and may transmit a packet, including the master key encrypted with an outbound quantum key shared with a relay QKD node apparatus, the master key ID, information about the path, and a quantum key ID, to the relay QKD node apparatus when the relay QKD node apparatus for relaying is present on the path.

Here, when the second secure application is connected with the QKD node apparatus, the quantum key orchestration module may deliver the master key corresponding to the master key ID when a key request is made by the second secure application using the master key ID.

Here, when a group key is requested by the secure application connected with the QKD node apparatus using the IDs of multiple secure applications as parameters, the quantum key orchestration module may deliver the group key, generated using a random number, and a group key ID to the secure application, retrieve a path along which the group key is transmitted using an internal routing table and the IDs of the multiple secure applications, and transmit a packet including the group key encrypted with an outbound quantum key shared with a next QKD node apparatus on the path, the group key ID, information about the path, the IDs of the multiple secure applications, and a quantum key ID to the next QKD node apparatus on the path.

Here, when a large number of master keys is requested by the secure application connected with the QKD node apparatus, the quantum key orchestration module may encrypt the large number of master keys with the outbound quantum key based on a block cipher.

A quantum key distribution (QKD) node apparatus according to an embodiment may include a QKD module for generating quantum keys and quantum key IDs; a quantum key synchronization management module for storing the quantum keys and the quantum key IDs generated by the QKD module as an outbound quantum key and an inbound quantum key in a distributed manner and sharing the outbound quantum key and the inbound quantum key with a second QKD node apparatus; and a quantum key orchestration module for decrypting a master key included in a packet with the inbound quantum key shared with the second QKD node apparatus upon receiving the packet, including the encrypted master key, a master key ID, and the quantum key ID, from the second QKD node apparatus, and for delivering the master key corresponding to the master key ID to a secure application connected with the QKD node apparatus upon receiving the master key ID from the secure application.

Here, the QKD modules equal in number to the number of quantum key synchronization management modules may be connected therewith in a one-to-one manner, and each of the QKD module and the quantum key synchronization management module may be one or more in number.

Here, the quantum key orchestration module may decrypt the encrypted master key with the inbound quantum key pertaining to the second QKD node apparatus when it is confirmed that the QKD node apparatus is required to relay the master key based on information about a path included in a packet upon receiving the packet from the second QKD node apparatus, encrypt the decrypted master key with an outbound quantum key shared with a third QKD node apparatus, which is a next QKD apparatus on the path, generate a packet including the encrypted master key, the information about the path, the master key ID, and a quantum key ID, and transmit the packet to the third QKD node apparatus.

Here, when the packet includes a group key and the IDs of multiple secure applications and when the ID of the secure application connected with the QKD node apparatus is included in the IDs of the multiple secure applications, the quantum key orchestration module may store the group key and a group key ID and delete path information pertaining to the QKD node apparatus and the ID of the secure application connected with the QKD node apparatus from the packet.

Here, when the master key is present in a large number thereof, the quantum key orchestration module may decrypt the master key based on a block cipher.

A quantum key distribution method according to an embodiment may include delivering, by a quantum key distribution (QKD) node apparatus, a master key generated using a random number and a master key ID to a secure application connected with the QKD node apparatus in response to a request from the secure application for the master key, which is required for quantum cryptographic communication with a second secure application; and when the second secure application is a secure application connected with the QKD node apparatus, delivering, by the QKD node apparatus, the master key corresponding to the master key ID when the master key is requested by the second secure application with the master key ID.

The quantum key distribution method may further include, when the second secure application is not a secure application connected with the QKD node apparatus, encrypting, by the QKD node apparatus, the master key with an outbound quantum key shared with a second QKD node apparatus connected with the second secure application; and delivering, by the QKD node apparatus, a packet including the encrypted master key, the master key ID, and a quantum key ID, to the second QKD node apparatus.

The quantum key distribution method may further include, when receiving the packet including the encrypted master key, the master key ID, and the quantum key ID from the QKD node apparatus, decrypting, by the second QKD node apparatus, the master key included in the packet with an inbound quantum key shared with the QKD node apparatus; storing, by the second QKD node apparatus, the master key; and delivering, by the second QKD node apparatus, the master key corresponding to the master key ID to the second secure application connected with the second QKD node apparatus when the master key is requested by the second secure application using the master key ID.

Here, delivering the packet to the second QKD node apparatus may include, when the second secure application is not a secure application connected with the QKD node apparatus, retrieving a routing path using an internal routing table and the ID of the second secure application; and when a relay QKD node apparatus is present on the routing path, encrypting the master key with an outbound quantum key shared with the relay QKD node apparatus and transmitting a packet including the master key, the master key ID, information about the routing path, and a quantum key ID to the relay QKD node apparatus.

The quantum key distribution method may further include, when the relay QKD node apparatus receives the packet from the QKD node apparatus and confirms that the relay QKD node apparatus is required to relay the master key based on the information about the routing path included in the packet, decrypting, by the relay QKD node apparatus, the encrypted master key with an inbound quantum key pertaining to the QKD node apparatus; encrypting, by the relay QKD node apparatus, the decrypted master key with an outbound quantum key shared with a third QKD node apparatus, which is a next QKD apparatus on the routing path; generating a packet including the encrypted master key, the information about the routing path, the master key ID, and a quantum key ID; and transmitting the packet to the third QKD node apparatus.

The quantum key distribution method may further include, when the third QKD node apparatus receives the packet from the relay QKD node apparatus and confirms that the third QKD node apparatus is a final destination based on the information about the routing path included in the packet, decrypting, by the third QKD node apparatus, the encrypted master key with an inbound quantum key pertaining to the relay QKD node apparatus; and delivering, by the third QKD node apparatus, the master key corresponding to the master key ID to a secure application connected with the third QKD node when the master key is requested by the secure application using the master key ID.

The quantum key distribution method may further include, when a group key is requested by the secure application connected with the QKD node apparatus using the IDs of multiple secure applications as parameters, generating, by the QKD node apparatus, the group key using a random number and delivering the generated group key and a group key ID to the secure application; retrieving, by the QKD node apparatus, a path, along which the group key is to be transmitted, using an internal routing table and the IDs of the multiple secure applications; and delivering, by the QKD node apparatus, a packet including the group key encrypted with an outbound quantum key shared with a next QKD node apparatus on the path, the group key ID, information about the path, the IDs of the multiple secure applications, and a quantum key ID to the next QKD node apparatus on the path.

The quantum key distribution method may further include, when the packet includes the group key and when the IDs of the multiple secure applications include an ID of a secure application connected with the next QKD node apparatus on the path, storing, by the next QKD node apparatus on the path, the group key and the group key ID; and deleting, by the next QKD node apparatus on the path, path information pertaining thereto and the ID of the secure application connected with the next QKD node apparatus on the path from the packet.

Here, when the master key is present in a large number thereof, the master key may be encrypted or decrypted based on a block cipher.

BRIEF DESCRIPTION OF THE DRAWINGS

The above and other objects, features and advantages of the present invention will be more clearly understood from the following detailed description, taken in conjunction with the accompanying drawings, in which:

FIG. 1 is a schematic block diagram of a general quantum key distribution network system;

FIG. 2 is a schematic block diagram of a quantum key distribution network system according to an embodiment;

FIG. 3 is a schematic block diagram of a quantum key distribution node apparatus including multiple quantum key distribution modules and multiple quantum key synchronization management modules according to an embo

CROSS REFERENCE TO RELATED APPLICATION

This application claims the benefit of Korean Patent Application No. 10-2020-0082051, filed Jul. 3, 2020, which is hereby incorporated by reference in its entirety into this application.

BACKGROUND OF THE INVENTION

1. Technical Field

The disclosed embodiment relates to Quantum Key Distribution (QKD) technology.

2. Description of Related Art

Key distribution for sharing the same encryption key between two secure applications has traditionally been regarded as a difficult problem. As measures for the security of key distribution, a method using a Pre-Shared Key (PSK) and a public-key cryptography method, which is asymmetric cryptography using different keys for encryption and decryption, are mainly used.

In the pre-shared key method, a shared key is required to be delivered to a secure application by a trusted sender and to be stored and managed by a trusted manager. That is, because security must be ensured throughout the life cycle of the shared key, including generation, delivery, storage, and the like of thereof, it is difficult to manage the shared key.

In the public-key cryptography method, public-key cryptography, based on a pair comprising a private key and a public key, is designed based on the computational difficulty of factorization of the product of two large numbers and a discrete logarithm problem. However, because cryptography keys are expected to be easily deciphered by factorizing a large number and solving a discrete logarithm problem with the advent of quantum computers, public-key cryptography is known to be vulnerable to security issues.

In order to securely distribute cryptography keys against the threats of quantum computers, a lot of research on Post-Quantum Cryptography (PQC) and Quantum Key Distribution (QKD) has been performed.

PQC is secure public-key cryptography using a hard mathematical problem that makes it impossible to discover a cryptography key even though it is calculated using a quantum computer. QKD uses the no-cloning theorem of quantum physics and the phenomenon whereby a quantum state is destroyed after it is measured.

In the case of QKD, when a photon in a quantum state transmitted by a sender is first measured by an eavesdropper, a Quantum Bit Error Rate (QBER) increases, whereby the presence of the eavesdropper is detected. Accordingly, two quantum key distribution modules may securely share a quantum key, and a QKD protocol may ensure unconditional information-theoretic security.

However, a QKD network system has the following problems.

First, whether a secure application entity that is connected with a QKD node as a part of a conventional QKD network system takes a master role or a slave role should be determined in advance before the arrangement thereof, and a key request must first be made by the master. Accordingly, the conventional QKD network system has a problem in which it is necessary to assign a master role or a slave role to a secure application entity and to manage a list of target secure application entities with which the secure application entity can communicate.

Also, when multiple secure application entities are connected with the same QKD node in a conventional QKD network system, the QKD node must sequentially process key requests from the multiple secure application entities. Therefore, when the current key request is processed, the QKD node blocks additional key requests from secure application entities, other than the secure application entity that made the current key request, which may degrade service efficiency related to key requests.

SUMMARY OF THE INVENTION

An object of an embodiment is to solve a problem in which whether a secure application entity takes a sender role or a receiver role needs to be determined in advance in a quantum key distribution network system.

Another object of an embodiment is to solve a problem of degradation of performance in processing key requests from multiple secure application entities in a quantum key distribution network system.

A quantum key distribution (QKD) node apparatus according to an embodiment may include a QKD module for generating quantum keys and quantum key IDs; a quantum key synchronization management module for storing the quantum keys and the quantum key IDs generated by the QKD module as an outbound quantum key and an inbound quantum key in a distributed manner and for sharing the outbound quantum key and the inbound quantum key with a second QKD node apparatus; and a quantum key orchestration module for delivering a master key, generated using a random number, and a master key ID to a secure application connected therewith when the master key is requested by the secure application using the ID of a second secure application, and for transmitting a packet including the master key encrypted with the outbound quantum key shared with the second QKD node apparatus connected with the second secure application, the master key ID, and the quantum key ID to the second QKD node apparatus.

Here, the QKD modules equal in number to the number of quantum key synchronization management modules may be connected therewith in a one-to-one manner, and each of the QKD module and the quantum key synchronization management module may be one or more in number.

Here, the quantum key orchestration module may retrieve a path corresponding to the ID of the second secure application based on an internal routing table, and may transmit a packet, including the master key encrypted with an outbound quantum key shared with a relay QKD node apparatus, the master key ID, information about the path, and a quantum key ID, to the relay QKD node apparatus when the relay QKD node apparatus for relaying is present on the path.

Here, when the second secure application is connected with the QKD node apparatus, the quantum key orchestration module may deliver the master key corresponding to the master key ID when a key request is made by the second secure application using the master key ID.

Here, when a group key is requested by the secure application connected with the QKD node apparatus using the IDs of multiple secure applications as parameters, the quantum key orchestration module may deliver the group key, generated using a random number, and a group key ID to the secure application, retrieve a path along which the group key is transmitted using an internal routing table and the IDs of the multiple secure applications, and transmit a packet including the group key encrypted with an outbound quantum key shared with a next QKD node apparatus on the path, the group key ID, information about the path, the IDs of the multiple secure applications, and a quantum key ID to the next QKD node apparatus on the path.

Here, when a large number of master keys is requested by the secure application connected with the QKD node apparatus, the quantum key orchestration module may encrypt the large number of master keys with the outbound quantum key based on a block cipher.

A quantum key distribution (QKD) node apparatus according to an embodiment may include a QKD module for generating quantum keys and quantum key IDs; a quantum key synchronization management module for storing the quantum keys and the quantum key IDs generated by the QKD module as an outbound quantum key and an inbound quantum key in a distributed manner and sharing the outbound quantum key and the inbound quantum key with a second QKD node apparatus; and a quantum key orchestration module for decrypting a master key included in a packet with the inbound quantum key shared with the second QKD node apparatus upon receiving the packet, including the encrypted master key, a master key ID, and the quantum key ID, from the second QKD node apparatus, and for delivering the master key corresponding to the master key ID to a secure application connected with the QKD node apparatus upon receiving the master key ID from the secure application.

Here, the QKD modules equal in number to the number of quantum key synchronization management modules may be connected therewith in a one-to-one manner, and each of the QKD module and the quantum key synchronization management module may be one or more in number.

Here, the quantum key orchestration module may decrypt the encrypted master key with the inbound quantum key pertaining to the second QKD node apparatus when it is confirmed that the QKD node apparatus is required to relay the master key based on information about a path included in a packet upon receiving the packet from the second QKD node apparatus, encrypt the decrypted master key with an outbound quantum key shared with a third QKD node apparatus, which is a next QKD apparatus on the path, generate a packet including the encrypted master key, the information about the path, the master key ID, and a quantum key ID, and transmit the packet to the third QKD node apparatus.

Here, when the packet includes a group key and the IDs of multiple secure applications and when the ID of the secure application connected with the QKD node apparatus is included in the IDs of the multiple secure applications, the quantum key orchestration module may store the group key and a group key ID and delete path information pertaining to the QKD node apparatus and the ID of the secure application connected with the QKD node apparatus from the packet.

Here, when the master key is present in a large number thereof, the quantum key orchestration module may decrypt the master key based on a block cipher.

A quantum key distribution method according to an embodiment may include delivering, by a quantum key distribution (QKD) node apparatus, a master key generated using a random number and a master key ID to a secure application connected with the QKD node apparatus in response to a request from the secure application for the master key, which is required for quantum cryptographic communication with a second secure application; and when the second secure application is a secure application connected with the QKD node apparatus, delivering, by the QKD node apparatus, the master key corresponding to the master key ID when the master key is requested by the second secure application with the master key ID.

The quantum key distribution method may further include, when the second secure application is not a secure application connected with the QKD node apparatus, encrypting, by the QKD node apparatus, the master key with an outbound quantum key shared with a second QKD node apparatus connected with the second secure application; and delivering, by the QKD node apparatus, a packet including the encrypted master key, the master key ID, and a quantum key ID, to the second QKD node apparatus.

The quantum key distribution method may further include, when receiving the packet including the encrypted master key, the master key ID, and the quantum key ID from the QKD node apparatus, decrypting, by the second QKD node apparatus, the master key included in the packet with an inbound quantum key shared with the QKD node apparatus; storing, by the second QKD node apparatus, the master key; and delivering, by the second QKD node apparatus, the master key corresponding to the master key ID to the second secure application connected with the second QKD node apparatus when the master key is requested by the second secure application using the master key ID.

Here, delivering the packet to the second QKD node apparatus may include, when the second secure application is not a secure application connected with the QKD node apparatus, retrieving a routing path using an internal routing table and the ID of the second secure application; and when a relay QKD node apparatus is present on the routing path, encrypting the master key with an outbound quantum key shared with the relay QKD node apparatus and transmitting a packet including the master key, the master key ID, information about the routing path, and a quantum key ID to the relay QKD node apparatus.

The quantum key distribution method may further include, when the relay QKD node apparatus receives the packet from the QKD node apparatus and confirms that the relay QKD node apparatus is required to relay the master key based on the information about the routing path included in the packet, decrypting, by the relay QKD node apparatus, the encrypted master key with an inbound quantum key pertaining to the QKD node apparatus; encrypting, by the relay QKD node apparatus, the decrypted master key with an outbound quantum key shared with a third QKD node apparatus, which is a next QKD apparatus on the routing path; generating a packet including the encrypted master key, the information about the routing path, the master key ID, and a quantum key ID; and transmitting the packet to the third QKD node apparatus.

The quantum key distribution method may further include, when the third QKD node apparatus receives the packet from the relay QKD node apparatus and confirms that the third QKD node apparatus is a final destination based on the information about the routing path included in the packet, decrypting, by the third QKD node apparatus, the encrypted master key with an inbound quantum key pertaining to the relay QKD node apparatus; and delivering, by the third QKD node apparatus, the master key corresponding to the master key ID to a secure application connected with the third QKD node when the master key is requested by the secure application using the master key ID.

The quantum key distribution method may further include, when a group key is requested by the secure application connected with the QKD node apparatus using the IDs of multiple secure applications as parameters, generating, by the QKD node apparatus, the group key using a random number and delivering the generated group key and a group key ID to the secure application; retrieving, by the QKD node apparatus, a path, along which the group key is to be transmitted, using an internal routing table and the IDs of the multiple secure applications; and delivering, by the QKD node apparatus, a packet including the group key encrypted with an outbound quantum key shared with a next QKD node apparatus on the path, the group key ID, information about the path, the IDs of the multiple secure applications, and a quantum key ID to the next QKD node apparatus on the path.

The quantum key distribution method may further include, when the packet includes the group key and when the IDs of the multiple secure applications include an ID of a secure application connected with the next QKD node apparatus on the path, storing, by the next QKD node apparatus on the path, the group key and the group key ID; and deleting, by the next QKD node apparatus on the path, path information pertaining thereto and the ID of the secure application connected with the next QKD node apparatus on the path from the packet.

Here, when the master key is present in a large number thereof, the master key may be encrypted or decrypted based on a block cipher.

BRIEF DESCRIPTION OF THE DRAWINGS

The above and other objects, features and advantages of the present invention will be more clearly understood from the following detailed description, taken in conjunction with the accompanying drawings, in which:

FIG. 1 is a schematic block diagram of a general quantum key distribution network system;

FIG. 2 is a schematic block diagram of a quantum key distribution network system according to an embodiment;

FIG. 3 is a schematic block diagram of a quantum key distribution node apparatus including multiple quantum key distribution modules and multiple quantum key synchronization management modules according to an embodiment;

FIG. 4 is a signal flowchart for explaining a method for sharing a master key and a master key ID for cryptographic communication between a quantum key distribution site A and a quantum key distribution site B that are connected in a point-to-point (P2P) manner according to an embodiment;

FIG. 5 is a schematic block diagram of a quantum key distribution network according to another embodiment;

FIGS. 6 and 7 are signal flowcharts for explaining a method for sharing a master key and a master key ID for cryptographic communication between secure applications through the relay of a quantum key according to an embodiment;

FIG. 8 is a signal flowchart for explaining a method for sharing a master key and a master key ID for cryptographic communication between secure applications in the same quantum key distribution site according to an embodiment;

FIGS. 9 and 10 are signal flowcharts for explaining a method for sharing a group key and a group key ID for cryptographic communication between secure applications in a quantum key distribution network according to an embodiment; and

FIG. 11 is a view illustrating a computer system configuration according to an embodiment.

DESCRIPTION OF THE PREFERRED EMBODIMENTS

The advantages and features of the present invention and methods of achieving them will be apparent from the following exemplary embodiments to be described in more detail with reference to the accompanying drawings. However, it should be noted that the present invention is not limited to the following exemplary embodiments, and may be implemented in various forms. Accordingly, the exemplary embodiments are provided only to disclose the present invention and to let those skilled in the art know the category of the present invention, and the present invention is to be defined based only on the claims. The same reference numerals or the same reference designators denote the same elements throughout the specification.

It will be understood that, although the terms “first,” “second,” etc. may be used herein to describe various elements, these elements are not intended to be limited by these terms. These terms are only used to distinguish one element from another element. For example, a first element discussed below could be referred to as a second element without departing from the technical spirit of the present invention.

The terms used herein are for the purpose of describing particular embodiments only and are not intended to limit the present invention. As used herein, the singular forms are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises,” “comprising,”, “includes” and/or “including,” when used herein, specify the presence of stated features, integers, steps, operations, elements, and/or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and/or groups thereof.

Unless differently defined, all terms used herein, including technical or scientific terms, have the same meanings as terms generally understood by those skilled in the art to which the present invention pertains. Terms identical to those defined in generally used dictionaries should be interpreted as having meanings identical to contextual meanings of the related art, and are not to be interpreted as having ideal or excessively formal meanings unless they are definitively defined in the present specification.

Hereinafter, an apparatus and method for quantum key distribution in a quantum key distribution network system according to an embodiment will be described in detail with reference to FIGS. 1 to 11 .

FIG. 1 is a schematic block diagram of a general quantum key distribution network system.

Referring to FIG. 1 , a quantum key distribution network system includes Secure Application Entities (SAEs) 10 a , 10 b and 10 c and Quantum Key Distribution (QKD)

nodes

20 a , 20 b and 20 c , and quantum cryptography is performed therein.

The

QKD nodes

20 a , 20 b and 20 c and the

SAEs

10 a , 10 b and 10 c are located in securely managed quantum key distribution sites, for example, a QKD site A, a QKD site B and a QKD site C, and the QKD sites are connected with each other, whereby a quantum key distribution network over which a quantum key is transmitted is formed.

The

QKD nodes

20 a , 20 b and 20 c may include respective QKD entities (QKDE) 21 a , 21 b and 21 c and respective key management entities (KME) 22 a , 22 b and 22 c.

The

QKD entities

21 a , 21 b and 21 c generate quantum keys. Here, one

QKD entity

21 a , 21 b or 21 c or two or more QKD entities may be included in each of the

QKD nodes

20 a , 20 b and 20 c . For example, referring to FIG. 1 , the QKD node 20 b may include two or more QKD entities 21 b - 1 , 21 b - n.

Here, the two or more QKD entities 21 b - 1 , . . . , 21 b - n may use the same QKD method, or may use different QKD methods.

Here, the

QKD entities

21 a , 21 b and 21 c included in different sites may be connected through QKD links.

Here, the QKD link may include a quantum channel for delivering a photon and a public channel for delivering information for extracting a key.

Here, the quantum channel generally uses a dedicated optic fiber channel. The QKD entity includes a transmission device for transmitting a photon in which a quantum state is encoded and a reception device for receiving a photon and measuring a quantum state, and a pair comprising a transmission device and a reception device is connected in a P2P manner.

The

KMEs

22 a , 22 b and 22 c store quantum keys and deliver the quantum keys to the

respective SAEs

10 a , 10 b and 10 c in response to a request therefrom. Here, regardless of the number of

QKD entities

21 a , 21 b or 21 c included in each of the

QKD nodes

20 a , 20 b and 20 c , a

single KME

22 a , 22 b or 22 c may be present in each of the

QKD nodes

20 a , 20 b and 20 c.

One or

more SAEs

10 a , 10 b or 10 c may be connected with each of the

QKD nodes

20 a , 20 b and 20 c . Here, the role of each of the

SAEs

10 a , 10 b and 10 c is classified as a master (sender) SAE or a slave (receiver) SAE. Whether each of SAEs takes a master role or a slave role is determined when the SAEs are initially arranged, and the role is fixed.

The master SAE first makes a key request, and the slave SAE requests a key using the key ID received from the master SAE, whereby the two SAEs perform cryptographic communication using the same cryptography key supplied from the respective QKD nodes.

The above-described quantum key distribution network system may operate as follows.

The transmission device of the quantum key distribution network system transmits a photon in a quantum state, in which a randomly selected basis and a random number are encoded, through a quantum channel, and the reception device of the quantum key distribution network system randomly selects a basis and measures the quantum state of the photon. Here, the transmission device transmits the photon randomly mixed with a decoy signal to the reception device in preparation for quantum hacking, such as a photon-number-splitting attack or the like.

The quantum state generated by the transmission device and the quantum state measured by the reception device are stored as a raw key, and the decoy information transmitted by the transmission device, information about the basis selected by each of the transmission device and the reception device, and the like are exchanged with each other through a public channel, whereby a shifted key is generated.

When a Quantum Bit Error Rate (QBER) is measured in this process, whether information is eavesdropped upon may be determined. Then, a secret key is generated from the shifted key using an error correction method, a privacy amplification method, and the like, whereby the two QKD entities connected in a one-to-one manner have the same quantum key.

The same quantum key generated in the two QKD entities is delivered to the respective KMEs.

The KME functions to receive the quantum key from the QKD entity, to store the same in a quantum key buffer, to relay a key, to connect with an SAE, and the like. Because a quantum key generation rate in the QKD entity is slow and is not constant, the KME stores the quantum key in the buffer and delivers the quantum key stored in the buffer in response to a request from the SAE. Here, when two sites are not connected in a P2P manner and when it is necessary to pass through one or more sites in order to share a key with the remote site, the KME also serves to relay the key.

Here, various methods may be used in order for the KME to relay a key, and a method in which a quantum key between P2P sites is delivered by performing an exclusive-OR operation, a method in which a random number generated as a quantum key between P2P sites is delivered by performing an exclusive-OR operation, a method in which a public key is delivered as a quantum key between P2P sites by performing an exclusive-OR operation, and the like may be included.

When a master SAE requests a key (Get Key) from the KME to which the master SAE pertains, the KME sends a quantum key and a key ID corresponding to the quantum key to the master SAE (STEP 1 ). Then, the master SAE transmits the key ID to a slave SAE (STEP 2 ) and prepares for cryptographic communication using the quantum key received from the KME.

The slave SAE receives the key ID from the master SAE and requests a key from the KME, to which the slave SAE pertains, with the key ID (Get Key with Key ID). The KME receiving the key request with the key ID retrieves a quantum key corresponding to the key ID and sends the quantum key to the slave SAE (STEP 3 ).

Through this key-sharing transaction, the master SAE and the slave SAE share the same quantum key and the same key ID and perform cryptographic communication using the shared quantum key as a master key.

Generally, Transport Layer Security (TLS) is used in the communication channel between the SAE and the KME, whereby the communication channel is protected. Also, the SAE and the KME are mounted in a single server rack in the same site, and are securely managed through physical security.

However, the general quantum key distribution system described above has the following problems.

First, when the role of the SAE is fixed as a master role or a slave role as describe above, constraints may occur in the operation thereof.

The slave SAE is not able to first make a key request, and the master SAE is not able to acquire a quantum key using a key ID. If cryptographic communication is performed without determining the roles of the SAEs in the quantum key distribution system, when an SAE starts a key request process before a key-sharing transaction requested by another SAE is completed, synchronization of a quantum key is broken depending on the sequence of the requested quantum keys, and a race condition or a deadlock may be caused. In order to prevent this, the SAE connected with the QKD node is operated by fixing the role so as to take a master role or a slave role.

However, assuming that SAEs are used for secure video calls, the conventional method imposes selection of the SAE to make a video call. That is, because it is necessary to previously identify the SAE to make a video call and the SAE to receive the video call, the efficiency of the SAEs is degraded, and the operation thereof is awkward.

Also, when multiple SAEs are used by being connected with a single QKD node in the conventional quantum key distribution network system, performance in processing quantum key requests may be degraded.

Conventional QKD nodes were designed such that the QKD nodes are used for SAEs for a link in order to protect a high-speed link. Generally, when a single SAE for a link is used by being connected with a single QKD node and when whether the SAE takes a master role or a slave role is determined in advance, there is no problem in operation. However, because a QKD node is an expensive device, it is desirable to connect multiple SAEs therewith. However, when multiple SAEs are used by being connected with a conventional QKD node, processing performance is degraded.

It may be assumed that QKD nodes are respectively installed in a site A and a site B and that multiple video phones are installed and operated in each of the sites.

When an SAE in the site A requests a quantum key from the QKD node and intends to perform cryptographic communication with an SAE in the site B by transmitting a key ID thereto, if an additional SAE in the site A requests a quantum key before the key-sharing transaction is finished, the sequence of the quantum keys managed in the QKD node may be broken. Specifically, when the key-sharing transaction is terminated abnormally due to an error or a timeout, the key ID in the site A becomes different from the key ID in the site B, whereby key synchronization may be broken. This is because the site A already provides a quantum key to the additional SAE that made the key request before the key-sharing transaction is finished. In order to prevent this situation, when an SAE requests a key, the QKD node blocks other key requests until the current key-sharing transaction is finished, thereby preventing an additional SAE from making a key request. Due to this blocking, the additional SAE is not able to use the QKD node until the transaction is completed, which may degrade the performance and efficiency of the QKD node.

In order to enable the conventional quantum key distribution network system to be more widely used, any SAE connected with a QKD node should be allowed to first start a key-sharing transaction without determining in advance whether the SAE takes a master role or a slave role.

Also, in order to enable a QKD node to process a key request without a delay in an environment in which multiple SAEs are connected with the QKD node, the structure of the QKD node and a protocol therefor should be configured not to block a key request even when a key-sharing transaction is being processed.

Accordingly, the present invention proposes a quantum key distribution node apparatus and a quantum key distribution method therein in order to solve the above-described problems.

As described above, the conventional quantum key distribution network system applies a method in which a quantum key is delivered from a QKD entity to an SAE via a KME. This method makes it difficult to maintain key synchronization because the QKD entity, the KME, and the SAE use the same quantum key together in the process of generating and using the quantum key. The structure of a QKD node apparatus and a quantum key distribution method therein according to an embodiment are configured to separate an outbound quantum key from an inbound quantum key and to use the quantum keys only in a quantum key orchestration module, whereby synchronization of the quantum key may be easily maintained.

FIG. 2 is a schematic block diagram of a quantum key distribution network system according to an embodiment, and FIG. 3 is a schematic block diagram of a quantum key distribution node apparatus including multiple quantum key distribution modules and multiple quantum key synchronization management modules according to an embodiment.

Referring to FIG. 2 , a quantum key distribution network system may include Quantum Key Distribution (QKD) nodes

100 a and 100 b and Secure Applications

10 a and 10 b.

Here, the QKD node 100 a and the secure application 10 a may be located in a QKD site A, and the QKD node 100 b and the secure application 10 b may be located in a QKD site B. The QKD site A and the QKD site B are securely managed quantum key distribution sites and are connected with each other, whereby a quantum key distribution network over which a quantum key is transmitted may be formed.

In the two QKD sites A and B, the QKD nodes

100 a and 100 b are connected with the respective secure applications

10 a and 10 b . Here, one or more secure applications may be connected with a QKD node.

That is, referring to FIG. 3 , one or more secure applications 10 - 1 , 10 - 2 , . . . , 10 -N may be connected with a single QKD node 100 .

The secure applications

10 a and 10 b may use secure applications for links, secure applications for video calls, Virtual Private Networks (VPNs), or the like depending on the purposes thereof, and may acquire a master key from the respective QKD nodes

100 a and 100 b , thereby performing cryptographic communication therebetween.

That is, the secure application 10 a in the site A may acquire a master key and a master key ID from a quantum key orchestration module 130 a , and may transmit the master key ID to the secure application 10 b in the site B through a public channel. The secure application 10 b in the site B requests a key from a quantum key orchestration module 130 b in the site B using the received master key ID, thereby acquiring the master key.

Accordingly, the two secure applications

10 a and 10 b possess the same master key and the same master key ID and perform cryptographic communication therebetween using a session key generated using the master key.

Referring again to FIG. 2 , the QKD nodes

100 a and 100 b may include respective QKD modules

110 a and 110 b , respective quantum key synchronization management modules

120 a and 120 b , and respective quantum key orchestration modules

130 a and 130 b.

The QKD modules

110 a and 110 b may be connected with each other through a QKD link. Here, the QKD link may include a quantum channel for transmitting a photon in a quantum state and a public channel for transmitting decoy information, basis information, and the like.

The QKD modules

110 a and 110 b form a set comprising a sender and a receiver connected in a P2P manner, and generate a quantum key and a quantum key ID shared therebetween by acquiring a raw key from a random value, which is generated by the transmission device and measured by the reception device, by acquiring a shifted key from the raw key, and by performing privacy amplification.

Here, the QKD modules

110 a and 110 b may use any of various quantum key distribution protocols, such as BB-84 QKD, MDI QKD, and the like.

The QKD modules

110 a and 110 b deliver the quantum key and the quantum key ID to the quantum key synchronization management modules

120 a and 120 b based on the quantum key distribution protocol.

Here, each of the QKD nodes

100 a and 100 b may operate one or more QKD modules

110 a or 110 b.

Here, a number of QKD modules ( 110 a or 110 b ) equal to the number of quantum key synchronization management modules may be connected with the quantum key synchronization management modules ( 120 a or 120 b ) in a P2P manner.

That is, as shown in FIG. 3 , a single QKD node 100 may include a single quantum <figure-callout id="130" label="key orchestra

CLAIMS

Claims ( 13 )

What is claimed is:

1. A quantum key distribution (QKD) node apparatus, comprising:

at least one processor, and a memory having instructions stored thereon, which, when executed by the at least one processor, cause the at least one processor to perform:

a QKD module for generating quantum keys and quantum key IDs;

a quantum key synchronization management module for storing the quantum keys and the quantum key IDs generated by the QKD module as an outbound quantum key and an inbound quantum key in a distributed manner and for sharing the outbound quantum key and the inbound quantum key with a second QKD node apparatus; and

a quantum key orchestration module for delivering a master key, generated using a random number, and a master key ID to a secure application connected therewith when the master key is requested by the secure application using an ID of a second secure application, and for transmitting a packet including the master key encrypted with the outbound quantum key shared with the second QKD node apparatus connected with the second secure application, the master key ID, and the quantum key ID to the second QKD node apparatus,

wherein the QKD modules equal in number to a number of quantum key synchronization management modules are connected therewith in a one-to-one manner, and each of the QKD module and the quantum key synchronization management module is one or more in number,

wherein the quantum key orchestration module is configured to:

retrieve a path corresponding to the ID of the second secure application based on an internal routing table, and

transmit a packet, including the master key encrypted with an outbound quantum key shared with a relay QKD node apparatus, the master key ID, information about the path, and a quantum key ID, to the relay QKD node apparatus when the relay QKD node apparatus for relaying is present on the path.

2. The QKD node apparatus of claim 1 , wherein, when the second secure application is connected with the QKD node apparatus, the quantum key orchestration module delivers the master key corresponding to the master key ID when a key request is made by the second secure application using the master key ID.

3. The QKD node apparatus of claim 1 , wherein, when a group key is requested by the secure application connected with the QKD node apparatus using IDs of multiple secure applications as parameters, the quantum key orchestration module delivers the group key generated using a random number and a group key ID to the secure application, retrieves a path along which the group key is transmitted using an internal routing table and the IDs of the multiple secure applications, and transmits a packet including the group key encrypted with an outbound quantum key shared with a next QKD node apparatus on the path, the group key ID, information about the path, the IDs of the multiple secure applications, and a quantum key ID to the next QKD node apparatus on the path.

4. The QKD node apparatus of claim 1 , wherein, when a large number of master keys is requested by the secure application connected with the QKD node apparatus, the quantum key orchestration module encrypts the large number of master keys with the outbound quantum key based on a block cipher.

5. A quantum key distribution (QKD) node apparatus, comprising:

at least one processor, and a memory having instructions stored thereon, which, when executed by the at least one processor, cause the at least one processor to perform:

a QKD module for generating quantum keys and quantum key IDs;

a quantum key synchronization management module for storing the quantum keys and the quantum key IDs generated by the QKD module as an outbound quantum key and an inbound quantum key in a distributed manner and sharing the outbound quantum key and the inbound quantum key with a second QKD node apparatus; and

a quantum key orchestration module for decrypting a master key included in a packet with the inbound quantum key shared with the second QKD node apparatus upon receiving the packet, including the encrypted master key, a master key ID, and the quantum key ID, from the second QKD node apparatus, and for delivering the master key corresponding to the master key ID to a secure application connected with the QKD node apparatus upon receiving the master key ID from the secure application,

wherein the QKD modules equal in number to a number of quantum key synchronization management modules are connected therewith in a one-to-one manner, and each of the QKD module and the quantum key synchronization management module is one or more in number,

wherein the quantum key orchestration module is configured to:

decrypt the encrypted master key with the inbound quantum key pertaining to the second QKD node apparatus when it is confirmed that the QKD node apparatus is required to relay the master key based on information about a path included in a packet upon receiving the packet from the second QKD node apparatus,

encrypt the decrypted master key with an outbound quantum key shared with a third QKD node apparatus, which is a next QKD apparatus on the path,

generate a packet including the encrypted master key, the information about the path, the master key ID, and a quantum key ID, and

transmit the packet to the third QKD node apparatus.

6. The QKD node apparatus of claim 5 , wherein:

when the packet includes a group key and IDs of multiple secure applications and when an ID of the secure application connected with the QKD node apparatus is included in the IDs of the multiple secure applications, the quantum key orchestration module stores the group key and a group key ID and deletes path information pertaining to the QKD node apparatus and the ID of the secure application connected with the QKD node apparatus from the packet.

7. The QKD node apparatus of claim 5 , wherein, when the master key is present in a large number thereof, the quantum key orchestration module decrypts the master key based on a block cipher.

8. A quantum key distribution method, comprising:

delivering, by a quantum key distribution (QKD) node apparatus, a master key, generated using a random number, and a master key ID to a secure application connected with the QKD node apparatus in response to a request from the secure application for the master key, which is required for quantum cryptographic communication with a second secure application;

when the second secure application is a secure application connected with the QKD node apparatus, delivering, by the QKD node apparatus, the master key corresponding to the master key ID when the master key is requested by the second secure application with the master key ID; and

when the second secure application is not a secure application connected with the QKD node apparatus, encrypting, by the QKD node apparatus, the master key with an outbound quantum key shared with a second QKD node apparatus connected with the second secure application, and delivering, by the QKD node apparatus, a packet including the encrypted master key, the master key ID, and a quantum key ID, to the second QKD node apparatus,

wherein the delivering the packet to the second QKD node apparatus comprises:

when the second secure application is not a secure application connected with the QKD node apparatus, retrieving a routing path using an internal routing table and an ID of the second secure application; and

when a relay QKD node apparatus is present on the routing path, encrypting the master key with an outbound quantum key shared with the relay QKD node apparatus and transmitting a packet including the master key, the master key ID, information about the routing path, and a quantum key ID to the relay QKD node apparatus,

wherein when the relay QKD node apparatus receives the packet from the QKD node apparatus and confirms that the relay QKD node apparatus is required to relay the master key based on the information about the routing path included in the packet, the quantum key distribution method further comprises:

decrypting, by the relay QKD node apparatus, the encrypted master key with an inbound quantum key pertaining to the QKD node apparatus;

encrypting, by the relay QKD node apparatus, the decrypted master key with an outbound quantum key shared with a third QKD node apparatus, which is a next QKD apparatus on the routing path;

generating a packet including the encrypted master key, the information about the routing path, the master key ID, and a quantum key ID; and

transmitting the packet to the third QKD node apparatus.

9. The quantum key distribution method of claim 8 , further comprising: when receiving the packet including the encrypted master key, the master key ID, and the quantum key ID from the QKD node apparatus, decrypting, by the second QKD node apparatus, the master key included in the packet with an inbound quantum key shared with the QKD node apparatus, storing, by the second QKD node apparatus, the master key, and delivering, by the second QKD node apparatus, the master key corresponding to the master key ID to the second secure application connected with the second QKD node apparatus when the master key is requested by the second secure application using the master key ID.

10. The quantum key distribution method of claim 8 , further comprising:

when the third QKD node apparatus receives the packet from the relay QKD node apparatus and confirms that the third QKD node apparatus is a final destination based on the information about the routing path included in the packet,

decrypting, by the third QKD node apparatus, the encrypted master key with an inbound quantum key pertaining to the relay QKD node apparatus; and

delivering, by the third QKD node apparatus, the master key corresponding to the master key ID to a secure application connected with the third QKD node when the master key is requested by the secure application using the master key ID.

11. The quantum key distribution method of claim 8 , further comprising:

when a group key is requested by the secure application connected with the QKD node apparatus using IDs of multiple secure applications as parameters,

generating, by the QKD node apparatus, the group key using a random number and delivering the generated group key and a group key ID to the secure application;

retrieving, by the QKD node apparatus, a path along which the group key is to be transmitted using an internal routing table and the IDs of the multiple secure applications; and

delivering, by the QKD node apparatus, a packet including the group key encrypted with an outbound quantum key shared with a next QKD node apparatus on the path, the group key ID, information about the path, the IDs of the multiple secure applications, and a quantum key ID to the next QKD node apparatus on the path.

12. The quantum key distribution method of claim 11 , further comprising:

when the packet includes the group key and when the IDs of the multiple secure applications include an ID of a secure application connected with the next QKD node apparatus on the path,

storing, by the next QKD node apparatus on the path, the group key and the group key ID; and

deleting, by the next QKD node apparatus on the path, path information pertaining thereto and the ID of the secure application connected with the next QKD node apparatus on the path from the packet.

13. The quantum key distribution method of claim 9 , wherein, when the master key is present in a large number thereof, the master key is encrypted or decrypted based on a block cipher.

US17/069,073

2020-07-03

2020-10-13

Quantum key distribution node apparatus and method for quantum key distribution thereof

Active

2040-11-25

US11316677B2

( en )

Applications Claiming Priority (2)

Application Number

Priority Date

Filing Date

Title

KR1020200082051A

KR102592873B1

( en )

2020-07-03

2020-07-03

Quantum Key Distribution Node Apparatus and Method for Quantum Key Distribution thereof

KR10-2020-0082051

2020-07-03

Publications (2)

Publication Number

Publication Date

US20220006627A1

US20220006627A1 ( en )

2022-01-06

US11316677B2

true

US11316677B2 ( en )

2022-04-26

Family

ID=79167108

Family Applications (1)

Application Number

Title

Priority Date

Filing Date

US17/069,073

Active

2040-11-25

US11316677B2

( en )

2020-07-03

2020-10-13

Quantum key distribution node apparatus and method for quantum key distribution thereof

Country Status (2)

Country

Link

US

( 1 )

US11316677B2

( en )

KR

( 1 )

KR102592873B1

( en )

Cited By (2)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US12278894B2

( en )

*

2023-04-06

2025-04-15

Morgan Stanley Services Group Inc.

Systems and methods for secure authentication between application in quantum computing

US20250350450A1

( en )

*

2024-05-10

2025-11-13

Bank Of America Corporation

Decision Engine Consistency Verification System

Families Citing this family (38)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

KR102222080B1

( en )

*

2020-02-24

2021-03-04

한국전자통신연구원

Apparatus and method for authenticating quantum entity

US11664983B2

( en )

2020-09-22

2023-05-30

Mellanox Technologies, Ltd.

Hybrid quantum key distribution link for an optical transceiver

US11895233B2

( en )

2020-12-28

2024-02-06

Mellanox Technologies, Ltd.

Quantum key distribution enabled intra-datacenter network

DE102021214904A1

( en )

2020-12-28

2022-06-30

Mellanox Technologies Ltd.

QUANTUM KEY DISTRIBUTION-READY INTERNAL DATA CENTER NETWORK

US11711210B2

( en )

*

2020-12-28

2023-07-25

Mellanox Technologies, Ltd.

Quantum key distribution-based key exchange orchestration service

US12556377B2

( en )

*

2021-08-10

2026-02-17

International Business Machines Corporation

Internal key management for a storage subsystem encrypting data in the cloud

US12008147B2

( en )

2021-10-29

2024-06-11

Mellanox Technologies, Ltd.

Co-packaged switch with integrated quantum key distribution capabilities

US11848711B2

( en )

2022-02-18

2023-12-19

Mellanox Technologies, Ltd.

Network interface card for quantum computing over classical and quantum communication channels

US12413391B2

( en )

*

2022-02-23

2025-09-09

Mellanox Technologies, Ltd.

Devices, systems, and methods for integrating encryption service channels with a data path

US12362913B2

( en )

2022-03-16

2025-07-15

Honeywell Limited Honeywell Limitée

Method and system for secure distribution of symmetric encryption keys using quantum key distribution (QKD)

JP7679330B2

( en )

*

2022-03-22

2025-05-19

株式会社東芝

Key management device, quantum cryptography communication system and program

US11791994B1

( en )

*

2022-03-31

2023-10-17

Juniper Networks, Inc.

Quantum cryptography in an internet key exchange procedure

US12592924B2

( en )

*

2022-04-11

2026-03-31

At&amp;T Intellectual Property I, L.P.

Smart hub quantum key distribution and security management in advanced networks

WO2023198877A1

( en )

*

2022-04-15

2023-10-19

Just Technology Shpk

Methods and systems for performing secure transactions

CN114531238B

( en )

*

2022-04-24

2022-07-19

中电信量子科技有限公司

Secret key safe filling method and system based on quantum secret key distribution

KR102814559B1

( en )

*

2022-05-30

2025-05-29

한국과학기술정보연구원

Network apparatus for quantum key distribution, and operation method for quantum key distribution network

GB2619913B

( en )

*

2022-06-14

2024-10-09

Arqit Ltd

Group key sharing

KR102609406B1

( en )

*

2022-06-17

2023-12-04

한국과학기술정보연구원

Communication apparatus based on transport layer security protocol, shared key extension method

CN114844639B

( en )

*

2022-07-04

2022-09-06

中国长江三峡集团有限公司

Data transmission method, system and storage medium based on quantum key

US12229296B2

( en )

2022-07-13

2025-02-18

Mellanox Technologies, Ltd.

Systems, methods, and apparatuses for securing ownership of objects in a digital ledger

KR102811863B1

( en )

*

2022-08-03

2025-05-23

경희대학교 산학협력단

Apparatus and method of anayzing quantum consensus protocols in quantum network

CN115567192B

( en )

*

2022-09-29

2025-07-01

中电信量子科技有限公司

Method and system for transparent encryption and decryption of multicast data using quantum key distribution

JP7717672B2

( en )

*

2022-10-24

2025-08-04

株式会社東芝

Encrypted communication system, encrypted communication device, encrypted communication method, and encrypted communication program

IL298938A

( en )

2022-12-08

2024-07-01

Mellanox Technologies Ltd

Measurement based methods for accessing and characterizing quantum communication channels

EP4418605B1

( en )

*

2023-02-17

2025-04-16

Quantum Blockchains Sp. z o.o.

Post-quantum encryption key distribution method and a device

CN116506119B

( en )

*

2023-05-23

2024-01-26

中安网脉(北京)技术股份有限公司

Key distribution network construction method based on route addressing

US20240396719A1

( en )

*

2023-05-24

2024-11-28

Richard D&#39;Souza

Quantum key distribution (qkd) based secure communication system using artificial intelligence

CN116865966B

( en )

*

2023-09-04

2023-12-05

中量科(南京)科技有限公司

Encryption method, device and storage medium for generating working key based on quantum key

WO2025063749A1

( en )

*

2023-09-22

2025-03-27

주식회사 큐심플러스

Method and apparatus for controlling mobile quantum key distribution for multi-user quantum cryptography communication

CN117176345B

( en )

*

2023-10-31

2024-01-09

中电信量子科技有限公司

Quantum cryptography network key relay dynamic routing method, device and system

CN117241267B

( en )

*

2023-11-15

2024-01-12

合肥工业大学

Quantum group key distribution method applicable to V2I scene based on blockchain

WO2025233621A1

( en )

*

2024-05-09

2025-11-13

The University Court Of The University Of Edinburgh

Method of securely agreeing a secret key

CN118368492B

( en )

*

2024-06-20

2024-09-17

南京数脉动力信息技术有限公司

Quantum encryption trusted audio/video communication system based on 5G VoNR and IMS data channels and communication method thereof

US12627481B2

( en )

*

2024-10-11

2026-05-12

Bank Of America Corporation

System and method for quantum-based data encryption and transmission

WO2026095078A1

( en )

*

2024-10-28

2026-05-07

엘지전자 주식회사

Apparatus and method for performing quantum secure direct communication and quantum authentication on basis of quantum key exchange in quantum communication system

CN119382880A

( en )

*

2024-10-30

2025-01-28

中电信量子科技有限公司

Key distribution method, system and electronic device

CN119766442B

( en )

*

2024-12-27

2025-10-10

中电信量子科技有限公司

Centralized quantum key relay network and key storage method thereof

CN119835041B

( en )

*

2024-12-30

2025-11-04

中移互联网有限公司

Information encryption methods, devices, electronic devices, storage media and software products

Citations (7)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US20160315768A1

( en )

*

2015-04-22

2016-10-27

Alibaba Group Holding Limited

Method, apparatus, and system for cloud-based encryption machine key injection

US20170237559A1

( en )

2016-02-15

2017-08-17

Alibaba Group Holding Limited

Efficient quantum key management

KR101776137B1

( en )

2014-10-30

2017-09-19

에스케이 텔레콤주식회사

Method and Apparatus for Supplying Key to Multiple Devices in Quantum Key Distribution System

US20180062836A1

( en )

*

2016-08-26

2018-03-01

Kabushiki Kaisha Toshiba

Communication device, communication system, and communication method

US20190149327A1

( en )

*

2017-11-14

2019-05-16

Alibaba Group Holding Limited

Method and system for quantum key distribution and data processing

US20200351086A1

( en )

*

2019-05-03

2020-11-05

Quantum Xchange, Inc.

Method of operation of a quantum key controller

US20210083864A1

( en )

*

2019-09-12

2021-03-18

General Electric Company

Communication systems and methods

2020

2020-07-03

KR

KR1020200082051A

patent/KR102592873B1/en

active

Active

2020-10-13

US

US17/069,073

patent/US11316677B2/en

active

Active

Patent Citations (8)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

KR101776137B1

( en )

2014-10-30

2017-09-19

에스케이 텔레콤주식회사

Method and Apparatus for Supplying Key to Multiple Devices in Quantum Key Distribution System

US10382198B2

( en )

2014-10-30

2019-08-13

ID Quantique

Device and method for supplying key to plurality of devices in quantum key distribution system

US20160315768A1

( en )

*

2015-04-22

2016-10-27

Alibaba Group Holding Limited

Method, apparatus, and system for cloud-based encryption machine key injection

US20170237559A1

( en )

2016-02-15

2017-08-17

Alibaba Group Holding Limited

Efficient quantum key management

US20180062836A1

( en )

*

2016-08-26

2018-03-01

Kabushiki Kaisha Toshiba

Communication device, communication system, and communication method

US20190149327A1

( en )

*

2017-11-14

2019-05-16

Alibaba Group Holding Limited

Method and system for quantum key distribution and data processing

US20200351086A1

( en )

*

2019-05-03

2020-11-05

Quantum Xchange, Inc.

Method of operation of a quantum key controller

US20210083864A1

( en )

*

2019-09-12

2021-03-18

General Electric Company

Communication systems and methods

Cited By (2)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US12278894B2

( en )

*

2023-04-06

2025-04-15

Morgan Stanley Services Group Inc.

Systems and methods for secure authentication between application in quantum computing

US20250350450A1

( en )

*

2024-05-10

2025-11-13

Bank Of America Corporation

Decision Engine Consistency Verification System

Also Published As

Publication number

Publication date

US20220006627A1

( en )

2022-01-06

KR102592873B1

( en )

2023-10-25

KR20220004877A

( en )

2022-01-12

Similar Documents

Publication

Publication Date

Title

US20220006627A1

( en )

2022-01-06

Quantum key distribution node apparatus and method for quantum key distribution thereof

US11101999B2

( en )

2021-08-24

Two-way handshake for key establishment for secure communications

EP3293934B1

( en )

2020-02-26

Cloud storage method and system

US6941457B1

( en )

2005-09-06

Establishing a new shared secret key over a broadcast channel for a multicast group based on an old shared secret key

KR101498323B1

( en )

2015-03-03

Secure communications in computer cluster systems

US7978858B2

( en )

2011-07-12

Terminal device, group management server, network communication system, and method for generating encryption key

US8600063B2

( en )

2013-12-03

Key distribution system

US6987855B1

( en )

2006-01-17

Operational optimization of a shared secret Diffie-Hellman key exchange among broadcast or multicast groups

US8694783B2

( en )

2014-04-08

Lightweight secure authentication channel

KR20190005878A

( en )

2019-01-16

Method and system for secure data transmission

US20050204161A1

( en )

2005-09-15

Method and apparatus for hybrid group key management

EP2634991A1

( en )

2013-09-04

Content-centric networking

US20170149748A1

( en )

2017-05-25

Secure Group Messaging and Data Steaming

US10015144B2

( en )

2018-07-03

Method and system for protecting data using data passports

KR102266654B1

( en )

2021-06-18

Method and system for mqtt-sn security management for security of mqtt-sn protocol

CN109981584A

( en )

2019-07-05

A kind of distributed social contact method based on block chain

CN111480313B

( en )

2023-11-03

Communication terminals, server devices, recording media

JP7212697B2

( en )

2023-01-25

Communication terminal, communication system, and program

JP2023138927A

( en )

2023-10-03

System and method for managing data-file transmission and access right to data file

CN119276468B

( en )

2025-04-01

Group key negotiation method, communication method and device based on double ratchet algorithm

CN118157943A

( en )

2024-06-07

Access method, device, equipment and medium based on file access system

JP5491713B2

( en )

2014-05-14

ENCRYPTION DEVICE, ENCRYPTION PROGRAM, AND METHOD

CN116016529A

( en )

2023-04-25

IPSec VPN equipment load balancing management method and device

US9369442B2

( en )

2016-06-14

System and method for the safe spontaneous transmission of confidential data over unsecure connections and switching computers

Hsiao et al.

2024

Security among UPFs belonging to different 5G/B5G/6G networks

Legal Events

Date

Code

Title

Description

2020-10-13

AS

Assignment

Owner name : ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE, KOREA, REPUBLIC OF

Free format text : ASSIGNMENT OF ASSIGNORS INTEREST;ASSIGNORS:KO, HAENG-SEOK;JI, SE WAN;JEONG, YOUNCHANG;AND OTHERS;REEL/FRAME:054037/0633

Effective date : 20201005

2020-10-13

FEPP

Fee payment procedure

Free format text : ENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: BIG.); ENTITY STATUS OF PATENT OWNER: SMALL ENTITY

2020-11-03

FEPP

Fee payment procedure

Free format text : ENTITY STATUS SET TO SMALL (ORIGINAL EVENT CODE: SMAL); ENTITY STATUS OF PATENT OWNER: SMALL ENTITY

2021-08-20

STPP

Information on status: patent application and granting procedure in general

Free format text : DOCKETED NEW CASE - READY FOR EXAMINATION

2022-02-02

STPP

Information on status: patent application and granting procedure in general

Free format text : NOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONS

2022-03-21

STPP

Information on status: patent application and granting procedure in general

Free format text : PUBLICATIONS -- ISSUE FEE PAYMENT VERIFIED

2022-04-06

STCF

Information on status: patent grant

Free format text : PATENTED CASE

2025-09-22

MAFP

Maintenance fee payment

Free format text : PAYMENT OF MAINTENANCE FEE, 4TH YR, SMALL ENTITY (ORIGINAL EVENT CODE: M2551); ENTITY STATUS OF PATENT OWNER: SMALL ENTITY

Year of fee payment : 4

Related documents

Record · ID 607387
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.