ABSTRACT
Abstract
A trusted node, for quantum key distribution, has a quantum key engine, a quantum key controller and a trusted node controller. The quantum key engine exchanges quantum keys. The quantum key controller directs encryption and decryption. The trusted node controller directs the quantum key controller and the quantum key engine, and has no direct access to keys and data protected by the system, including unencrypted quantum keys.
Description
FIELD OF USE
The present embodiments relate to the field of quantum communication.
BACKGROUND
Quantum Key Distribution (QKD) uses principles of quantum mechanics for secure communication of cryptographic keys, called quantum keys. Distribution of quantum keys occurs over a quantum channel, between a quantum transmitter and a quantum receiver using photons or particles, for example photons in phase modulation, polarization, quantum superposition or quantum entanglement with information transmitted in quantum states. Eavesdropping in the quantum channel, to intercept a key by a hostile third-party, is detectable because measurement of the photon or particle collapses the quantum state and disturbs the quantum system. Existing, practical Quantum Key Distribution systems are limited to about 60 miles or 100 kilometers because of attenuation over practical media such as fiber optics for photons. It is a goal of presently described embodiments to increase the distance over which a key can be distributed using Quantum Key Distribution. It is a further goal of presently described embodiments to improve secure communication technology. It is a still further goal of presently described embodiments to improve security of keys inside nodes of a system.
SUMMARY
A trusted node for quantum key distribution, a method of operating a trusted node for quantum key distribution, and a computer-readable media that has instructions for a processor to perform a method are disclosed herein, among further embodiments.
The trusted node for quantum key distribution has a quantum key engine, a quantum key controller and a trusted node controller. The quantum key engine exchanges quantum keys with other trusted nodes via a quantum channel. The quantum key controller has one or more processors. The quantum key controller handles the quantum keys, directs encryption using the quantum keys, and directs decryption using the quantum keys.
The trusted node controller has one or more processors. The trusted node controller directs the quantum key controller and the quantum key engine to perform quantum key exchanges with other trusted nodes, encrypted communication with other trusted nodes, and encrypted communication among blades in the trusted node. No unencrypted quantum key is accessible to the trusted node controller.
One embodiment is a method of operating a trusted node for quantum key distribution. The method includes exchanging quantum keys with other trusted nodes. A quantum key engine of the trusted node performs the exchanging, by using a quantum channel.
The method includes a quantum key controller of the trusted node handling quantum keys. The method includes a trusted node controller directing the quantum key controller and the quantum key engine. The trusted node controller directs the quantum key controller and the quantum key engine to perform the exchanging of the quantum keys, encrypted communication with other trusted nodes, encryption using the quantum keys and decryption using the quantum keys, and encrypted communication among blades in the trusted node. Each of one or more processors of the trusted node controller cannot and does not read, write, send nor receive an unencrypted quantum key.
The computer-readable media is tangible and non-transitory, and has instructions which, when executed by a processor, cause the processor to perform a method. The method includes a quantum key engine of the trusted node exchanging quantum keys with other trusted nodes, via a quantum channel. The method includes a quantum key controller of the trusted node handling quantum keys. The method includes a trusted node controller directing the quantum key controller in the quantum key engine. The trusted node controller directs the quantum key controller and the quantum key engine to perform the exchanging of the quantum keys, encrypted communication with other trusted nodes, encryption using quantum keys and decryption using quantum keys, and encrypted communication among blades in the trusted node. The trusted node controller has no direct access to keys and data protected by the system, including clear text, unencrypted keys, customer private keys which are transmitted along quantum channels, and quantum keys.
Other aspects and advantages of the embodiments will become apparent from the following detailed description taken in conjunction with the accompanying drawings which illustrate, by way of example, the principles of the described embodiments.
BRIEF DESCRIPTION OF THE DRAWINGS
The described embodiments and the advantages thereof may best be understood by reference to the following description taken in conjunction with the accompanying drawings. These drawings in no way limit any changes in form and detail that may be made to the described embodiments by one skilled in the art without departing from the spirit and scope of the described embodiments.
FIG. 1A illustrates a Quantum Key Distribution system in accordance with present embodiments.
FIG. 1B illustrates a quantum communication network featuring Quantum Key Distribution by a Quantum Key Distribution system in accordance with present embodiments.
FIG. 1C illustrates a quantum key encrypted data system, or more broadly a quantum communication network including a Quantum Key Distribution system, exchanging quantum keys via quantum channels and communicating encrypted data via a network, in accordance with present embodiments.
FIG. 1D illustrates a Quantum Key Distribution system featuring distribution of a customer key using network hops over Trusted Nodes with encryption and decryption by quantum keys in accordance with present embodiments.
FIG. 2 illustrates two nodes with a quantum link for key exchange and a network link for encrypted data, and separation limited by a maximum distance for the quantum link.
FIG. 3 depicts an Alice module transmitting over a quantum channel to a receiving Bob module, using a Coherent One-Way (COW) protocol for quantum communication.
FIG. 4 is a further embodiment of an Alice module and a Bob module, communicating over a quantum channel and an authenticated synchronization and distillation channel.
FIG. 5A is a block diagram of a Trusted Node (TN) that has a shelf, network switches, services, a Trusted Node Controller (TNC), and quantum blades each with a Quantum Key Controller (QKC) and Quantum Key Engine (QKE), which can be used in embodiments of the quantum key distribution and communication systems of FIGS. 1A-1C .
FIG. 5B is a block diagram of a further embodiment of a Trusted Node.
FIG. 5C is a block diagram of a further embodiment of a Trusted Node.
FIG. 6 is a further block diagram of a Trusted Node, depicting network interfaces through which Trusted Nodes in the quantum key distribution and communication systems can communicate via a network such as the Internet.
FIG. 7 depicts interfaces and functional uses of the interfaces, of a Trusted Node.
FIG. 8 depicts components in a Trusted Node, and various connections for power and communication.
FIG. 9 is a block diagram of a Quantum Key Controller that can be used in embodiments of quantum blades as shown in FIG. 5 .
FIG. 10 depicts communication interfaces of a Quantum Key Controller and Quantum Key Engine in a quantum blade as shown in FIG. 5 .
FIG. 11 depicts components of an embodiment of a Quantum Key Controller.
FIG. 12 depicts Quantum Key Controller use cases.
FIG. 13A is a flow diagram of a method of operating a tamper detecting quantum key distribution system, which can be practiced on or by present embodiments.
FIG. 13B is a flow diagram of a method of operating a trusted node of a quantum key distribution system, which can be practiced on or by present embodiments, specifically by an endpoint trusted node or trusted node operating as an endpoint.
FIG. 13C is a flow diagram of a method of operating a trusted node of a quantum key distribution system, which can be practiced on or by present embodiments, specifically by a middle-trusted node or trusted node operating as a trusted node in the middle of a quantum key distribution system.
FIG. 13D is a flow diagram of a method of operating a trusted node of a quantum key distribution system, which can be practiced on or by present embodiments, specifically by an endpoint trusted node or trusted node operating as an endpoint.
FIG. 13E is a flow diagram of a method of operating a trusted node for quantum key distribution, which can be practiced on or by present embodiments.
DETAILED DESCRIPTION
A system described herein uses Quantum Key Distribution for key exchange between neighboring nodes, and a series of hops of encryption, decryption and re-encryption using quantum keys, to send another key from one end point to another endpoint over the series of hops from node to node. The key so transmitted can thus be sent much greater distance than would be possible for a single key exchange in a Quantum Key Distribution which is limited by the maximum attenuation distance of a quantum channel. This key is then used at either end point to encrypt or decrypt data that is sent so encrypted over a regular network, such as the Internet. Quantum communication distance is thus greatly extended, with the encrypted data benefiting from the speed and efficiency of regular network communication and benefiting from the security of Quantum Key Distribution while not being limited to the distance of a quantum channel. System architecture protects the keys from unauthorized access.
FIG. 1A illustrates a Quantum Key Distribution system in accordance with present embodiments. A number of
Trusted Nodes
101 , 103 , 105 are coupled together in a network. Each two neighboring Trusted Nodes (e.g., Trusted Node pair
101 , 103 and Trusted Node pair 103 , 105 ) are separated by less than or equal to a maximum specified distance over which quantum communication is reliable (for example, 100 km or 60 miles, possibly increased in further versions) for each communication hop. The Trusted Nodes perform Quantum Key Distribution among neighboring nodes over a regular network. Each
Trusted Node
101 , 103 , 105 has a Trusted Node Controller, one or more Quantum Key Controllers (QKC) and one or more Quantum Key Engines (QKE). Quantum key engines of neighboring Trusted Nodes use a quantum channel or quantum link, for example fiber-optic cable, to exchange quantum keys, which are used to encrypt data exchanged by Trusted Nodes.
In some embodiments, Quantum Key Engines generate keys continuously. Keys are transferred securely to Quantum Key Controllers. The Quantum Key Controller handles security (tamper detection, erasing or deleting keys also called key zeroization), encrypting user keys with quantum keys and decrypting using quantum keys. The Trusted Node Controller handles routing, transfer of key-encrypted keys to other Trusted Nodes, and higher-level protocols. But, in this embodiment to prevent the Trusted Node Controller from having access to all of the keys in the Trusted Node and thereby having a vulnerability, the Trusted Node Controller directs Quantum Key Controllers and Quantum Key Engines to handle keys and the Trusted Node Controller never sees or handles a quantum key directly or in unencrypted form. This arrangement keeps keys for one user, client or tenant provably separated from keys of other users, clients or tenants.
Using these mechanisms, the Quantum Key Distribution system of FIG. 1A passes a key, which could be a public key, private key, quantum key or other key, and could be unencrypted plain text, combined, in encrypted form or other form, from one end to the other end in an end-to-end key passing mechanism. In various versions, K 1 , K 1 encrypted by a public key PK, K 1 encrypted by a pre-shared key PSK, K 1 encrypted by another key, K 1 XOR or otherwise combined with another key or data, etc., is treated as data that includes key K 1 . This data that includes key K 1 is encrypted by a quantum key at one trusted node, decrypted by the same quantum key at the next trusted node, re-encrypted with the next quantum key and sent to the next trusted node. This can be repeated for any number of hops of trusted nodes. At the final trusted node, the quantum key encrypted data that includes key K 1 is decrypted by quantum key to recover the data that includes key K 1 . An example is described below. This chain of hops with decryption and re-encryption is extensible as shown in FIGS. 1B and 1C .
In the first Trusted Node Controller 101 labeled âAâ, a key K 1 (diagonal line shading) is encrypted using a quantum key QK 1 (no shading) that the Quantum Key Engine in the first Trusted Node 101 has exchanged with a Quantum Key Engine in the second Trusted Node 103 . The quantum key encrypted key K 1 (e.g., K 1 in some form encrypted by QK 1 , denoted (E(K 1 , QK 1 )) is communicated from the first Trusted Node 101 to the second Trusted Node 103 by a network. In the second Trusted Node 103 labeled âBâ, this encrypted value is decrypted using the quantum key QK 1 , to produce key K 1 in the appropriate form, then re-encrypted using the quantum key QK 2 (no shading) that another Quantum Key Engine i
FIELD OF USE
The present embodiments relate to the field of quantum communication.
BACKGROUND
Quantum Key Distribution (QKD) uses principles of quantum mechanics for secure communication of cryptographic keys, called quantum keys. Distribution of quantum keys occurs over a quantum channel, between a quantum transmitter and a quantum receiver using photons or particles, for example photons in phase modulation, polarization, quantum superposition or quantum entanglement with information transmitted in quantum states. Eavesdropping in the quantum channel, to intercept a key by a hostile third-party, is detectable because measurement of the photon or particle collapses the quantum state and disturbs the quantum system. Existing, practical Quantum Key Distribution systems are limited to about 60 miles or 100 kilometers because of attenuation over practical media such as fiber optics for photons. It is a goal of presently described embodiments to increase the distance over which a key can be distributed using Quantum Key Distribution. It is a further goal of presently described embodiments to improve secure communication technology. It is a still further goal of presently described embodiments to improve security of keys inside nodes of a system.
SUMMARY
A trusted node for quantum key distribution, a method of operating a trusted node for quantum key distribution, and a computer-readable media that has instructions for a processor to perform a method are disclosed herein, among further embodiments.
The trusted node for quantum key distribution has a quantum key engine, a quantum key controller and a trusted node controller. The quantum key engine exchanges quantum keys with other trusted nodes via a quantum channel. The quantum key controller has one or more processors. The quantum key controller handles the quantum keys, directs encryption using the quantum keys, and directs decryption using the quantum keys.
The trusted node controller has one or more processors. The trusted node controller directs the quantum key controller and the quantum key engine to perform quantum key exchanges with other trusted nodes, encrypted communication with other trusted nodes, and encrypted communication among blades in the trusted node. No unencrypted quantum key is accessible to the trusted node controller.
One embodiment is a method of operating a trusted node for quantum key distribution. The method includes exchanging quantum keys with other trusted nodes. A quantum key engine of the trusted node performs the exchanging, by using a quantum channel.
The method includes a quantum key controller of the trusted node handling quantum keys. The method includes a trusted node controller directing the quantum key controller and the quantum key engine. The trusted node controller directs the quantum key controller and the quantum key engine to perform the exchanging of the quantum keys, encrypted communication with other trusted nodes, encryption using the quantum keys and decryption using the quantum keys, and encrypted communication among blades in the trusted node. Each of one or more processors of the trusted node controller cannot and does not read, write, send nor receive an unencrypted quantum key.
The computer-readable media is tangible and non-transitory, and has instructions which, when executed by a processor, cause the processor to perform a method. The method includes a quantum key engine of the trusted node exchanging quantum keys with other trusted nodes, via a quantum channel. The method includes a quantum key controller of the trusted node handling quantum keys. The method includes a trusted node controller directing the quantum key controller in the quantum key engine. The trusted node controller directs the quantum key controller and the quantum key engine to perform the exchanging of the quantum keys, encrypted communication with other trusted nodes, encryption using quantum keys and decryption using quantum keys, and encrypted communication among blades in the trusted node. The trusted node controller has no direct access to keys and data protected by the system, including clear text, unencrypted keys, customer private keys which are transmitted along quantum channels, and quantum keys.
Other aspects and advantages of the embodiments will become apparent from the following detailed description taken in conjunction with the accompanying drawings which illustrate, by way of example, the principles of the described embodiments.
BRIEF DESCRIPTION OF THE DRAWINGS
The described embodiments and the advantages thereof may best be understood by reference to the following description taken in conjunction with the accompanying drawings. These drawings in no way limit any changes in form and detail that may be made to the described embodiments by one skilled in the art without departing from the spirit and scope of the described embodiments.
FIG. 1A illustrates a Quantum Key Distribution system in accordance with present embodiments.
FIG. 1B illustrates a quantum communication network featuring Quantum Key Distribution by a Quantum Key Distribution system in accordance with present embodiments.
FIG. 1C illustrates a quantum key encrypted data system, or more broadly a quantum communication network including a Quantum Key Distribution system, exchanging quantum keys via quantum channels and communicating encrypted data via a network, in accordance with present embodiments.
FIG. 1D illustrates a Quantum Key Distribution system featuring distribution of a customer key using network hops over Trusted Nodes with encryption and decryption by quantum keys in accordance with present embodiments.
FIG. 2 illustrates two nodes with a quantum link for key exchange and a network link for encrypted data, and separation limited by a maximum distance for the quantum link.
FIG. 3 depicts an Alice module transmitting over a quantum channel to a receiving Bob module, using a Coherent One-Way (COW) protocol for quantum communication.
FIG. 4 is a further embodiment of an Alice module and a Bob module, communicating over a quantum channel and an authenticated synchronization and distillation channel.
FIG. 5A is a block diagram of a Trusted Node (TN) that has a shelf, network switches, services, a Trusted Node Controller (TNC), and quantum blades each with a Quantum Key Controller (QKC) and Quantum Key Engine (QKE), which can be used in embodiments of the quantum key distribution and communication systems of FIGS. 1A-1C .
FIG. 5B is a block diagram of a further embodiment of a Trusted Node.
FIG. 5C is a block diagram of a further embodiment of a Trusted Node.
FIG. 6 is a further block diagram of a Trusted Node, depicting network interfaces through which Trusted Nodes in the quantum key distribution and communication systems can communicate via a network such as the Internet.
FIG. 7 depicts interfaces and functional uses of the interfaces, of a Trusted Node.
FIG. 8 depicts components in a Trusted Node, and various connections for power and communication.
FIG. 9 is a block diagram of a Quantum Key Controller that can be used in embodiments of quantum blades as shown in FIG. 5 .
FIG. 10 depicts communication interfaces of a Quantum Key Controller and Quantum Key Engine in a quantum blade as shown in FIG. 5 .
FIG. 11 depicts components of an embodiment of a Quantum Key Controller.
FIG. 12 depicts Quantum Key Controller use cases.
FIG. 13A is a flow diagram of a method of operating a tamper detecting quantum key distribution system, which can be practiced on or by present embodiments.
FIG. 13B is a flow diagram of a method of operating a trusted node of a quantum key distribution system, which can be practiced on or by present embodiments, specifically by an endpoint trusted node or trusted node operating as an endpoint.
FIG. 13C is a flow diagram of a method of operating a trusted node of a quantum key distribution system, which can be practiced on or by present embodiments, specifically by a middle-trusted node or trusted node operating as a trusted node in the middle of a quantum key distribution system.
FIG. 13D is a flow diagram of a method of operating a trusted node of a quantum key distribution system, which can be practiced on or by present embodiments, specifically by an endpoint trusted node or trusted node operating as an endpoint.
FIG. 13E is a flow diagram of a method of operating a trusted node for quantum key distribution, which can be practiced on or by present embodiments.
DETAILED DESCRIPTION
A system described herein uses Quantum Key Distribution for key exchange between neighboring nodes, and a series of hops of encryption, decryption and re-encryption using quantum keys, to send another key from one end point to another endpoint over the series of hops from node to node. The key so transmitted can thus be sent much greater distance than would be possible for a single key exchange in a Quantum Key Distribution which is limited by the maximum attenuation distance of a quantum channel. This key is then used at either end point to encrypt or decrypt data that is sent so encrypted over a regular network, such as the Internet. Quantum communication distance is thus greatly extended, with the encrypted data benefiting from the speed and efficiency of regular network communication and benefiting from the security of Quantum Key Distribution while not being limited to the distance of a quantum channel. System architecture protects the keys from unauthorized access.
FIG. 1A illustrates a Quantum Key Distribution system in accordance with present embodiments. A number of
Trusted Nodes
101 , 103 , 105 are coupled together in a network. Each two neighboring Trusted Nodes (e.g., Trusted Node pair
101 , 103 and Trusted Node pair 103 , 105 ) are separated by less than or equal to a maximum specified distance over which quantum communication is reliable (for example, 100 km or 60 miles, possibly increased in further versions) for each communication hop. The Trusted Nodes perform Quantum Key Distribution among neighboring nodes over a regular network. Each
Trusted Node
101 , 103 , 105 has a Trusted Node Controller, one or more Quantum Key Controllers (QKC) and one or more Quantum Key Engines (QKE). Quantum key engines of neighboring Trusted Nodes use a quantum channel or quantum link, for example fiber-optic cable, to exchange quantum keys, which are used to encrypt data exchanged by Trusted Nodes.
In some embodiments, Quantum Key Engines generate keys continuously. Keys are transferred securely to Quantum Key Controllers. The Quantum Key Controller handles security (tamper detection, erasing or deleting keys also called key zeroization), encrypting user keys with quantum keys and decrypting using quantum keys. The Trusted Node Controller handles routing, transfer of key-encrypted keys to other Trusted Nodes, and higher-level protocols. But, in this embodiment to prevent the Trusted Node Controller from having access to all of the keys in the Trusted Node and thereby having a vulnerability, the Trusted Node Controller directs Quantum Key Controllers and Quantum Key Engines to handle keys and the Trusted Node Controller never sees or handles a quantum key directly or in unencrypted form. This arrangement keeps keys for one user, client or tenant provably separated from keys of other users, clients or tenants.
Using these mechanisms, the Quantum Key Distribution system of FIG. 1A passes a key, which could be a public key, private key, quantum key or other key, and could be unencrypted plain text, combined, in encrypted form or other form, from one end to the other end in an end-to-end key passing mechanism. In various versions, K 1 , K 1 encrypted by a public key PK, K 1 encrypted by a pre-shared key PSK, K 1 encrypted by another key, K 1 XOR or otherwise combined with another key or data, etc., is treated as data that includes key K 1 . This data that includes key K 1 is encrypted by a quantum key at one trusted node, decrypted by the same quantum key at the next trusted node, re-encrypted with the next quantum key and sent to the next trusted node. This can be repeated for any number of hops of trusted nodes. At the final trusted node, the quantum key encrypted data that includes key K 1 is decrypted by quantum key to recover the data that includes key K 1 . An example is described below. This chain of hops with decryption and re-encryption is extensible as shown in FIGS. 1B and 1C .
In the first Trusted Node Controller 101 labeled âAâ, a key K 1 (diagonal line shading) is encrypted using a quantum key QK 1 (no shading) that the Quantum Key Engine in the first Trusted Node 101 has exchanged with a Quantum Key Engine in the second Trusted Node 103 . The quantum key encrypted key K 1 (e.g., K 1 in some form encrypted by QK 1 , denoted (E(K 1 , QK 1 )) is communicated from the first Trusted Node 101 to the second Trusted Node 103 by a network. In the second Trusted Node 103 labeled âBâ, this encrypted value is decrypted using the quantum key QK 1 , to produce key K 1 in the appropriate form, then re-encrypted using the quantum key QK 2 (no shading) that another Quantum Key Engine in the second Trusted Node 103 has exchanged with a Quantum Key Engine in the third Trusted Node 105 . This quantum key encrypted key K 1 (e.g., K 1 in some form encrypted by QK 2 , denoted (E(K 1 , QK 2 )) is communicated over a network from the second Trusted Node 103 to the third Trusted Node 105 labeled âCâ. In the third Trusted Node 105 , this encrypted value is decrypted by a Quantum Key Engine using the quantum key QK 2 , to obtain the key K 1 . Both ends have the key K 1 , as communicated from end to end using quantum keys. Other data besides keys could be communicated the same way in further embodiments (see FIG. 1B ). And, there is a more efficient way of communicating data (see FIG. 1C ), once both endpoints have a key that has been communicated using quantum keys and Quantum Key Distribution.
FIG. 1B illustrates a quantum communication network featuring Quantum Key Distribution by a Quantum Key Distribution system in accordance with present embodiments. This is an example of a Trusted Node connection architecture, and further examples with other connections and numbers of Trusted Nodes, etc., are readily devised. Three
Trusted Nodes
107 , 109 , 111 are coupled to each other similarly to the Quantum Key Distribution system in FIG. 1A , and are also coupled to or include further Alice and Bob modules and encryptors, for a multitenant system. Users representing various customers, alternatively termed tenants, can communicate data over paths protected by quantum communication. This system can handle multiple tenants per node. And, the system can handle multiple nodes per tenant, for example passing communication across multiple nodes between two users for that tenant. The system could disconnect a customer node, move customers relative to nodes, and differentiate which communication goes to which node and for which customer.
âAliceâ is the name commonly given to a quantum transmitter, and âBobâ is the name commonly given to a quantum receiver. Each pair of neighboring Alice and Bob modules, e.g. Alice 115 and Bob 113 , Alice 119 and Bob 117 , Alice 123 and Bob 121 , Alice 129 and Bob 127 , Alice 133 and Bob 131 , Alice 137 and Bob 135 , Alice of Trusted Node 107 labeled âTN-aâ and Bob of Trusted Node 109 labeled âTN-bâ, Alice of Trusted Node 109 and Bob of Trusted Node 125 labeled âTN-dâ, and Alice of Trusted Node 109 and Bob of Trusted Node 111 labeled âTN-câ, has a quantum channel QC and can exchange a quantum key specific to that pair. Encryptors associated with those Alice and Bob modules of a pair can encrypt and decrypt data, using the quantum key shared by that pair.
Continuing with the example in FIG. 1B , a user representing customer 1 (Cust-1) has the Alice module 115 cooperate with the encryptor to encrypt data using the quantum key exchanged with the neighboring Bob module 113 . The Bob module 113 works with the encryptor to decrypt the data, which is then communicated to the Trusted Node 107 TN-a. Trusted node 107 encrypts the data using the quantum key exchanged between the Alice module of the Trusted Node 107 and the Bob module of the Trusted Node 109 , TN-b. At the Trusted Node 109 TN-b, the Bob module decrypts the data using the quantum key exchanged between that Bob module and the preceding Alice module (of Trusted Node 107 TN-a), and an Alice module of the Trusted Node 109 TN-b re-encrypts the data using the quantum key exchanged between that Alice module and the Bob module of the succeeding or following Trusted Node 111 TN-c. That Trusted Node 111 TN-c hands the data to the encryptor and Bob module 131 , where the data is encrypted using the quantum key exchanged between that Bob module 131 and the succeeding Alice module 133 . That quantum key encrypted data is communicated to the next encryptor and decrypted with the cooperation of the Alice module 133 and the quantum key shared with the preceding Bob module 131 . Another user for customer 1 (Cust-1) can then access the decrypted data. Users for customer 1 can readily transmit data in the reverse direction, using the same quantum key encryption/decryption process and passed in the reverse of the direction described above. Users for customer 2 can communicate data over related paths, in both directions, as can users for customer 3. For example, the users for customer 2 communicate over a path defined by the Alice module 119 , Bob module 117 , Trusted Node 107 , Trusted Node 109 , Trusted Node 111 , Bob module 135 and Bob module 137 , in either direction. The users for customer 3 communicate over a path defined by the Alice module 123 , Bob module 121 , Trusted Node 107 , Trusted Node 109 , Bob module of Trusted Node 125 TN-d, Bob module 127 and Alice module 129 .
In the example of FIG. 1B , each of the Alice and Bob modules is in a corresponding blade, an Alice blade or a Bob blade. Data can be communicated between blades encrypted by a quantum key, encrypted by another key such as a shelf key used among blades on a shelf in a Trusted Node, or encrypted by another key. In some embodiments, data communicated between or among modules is always encrypted by some key, be it a quantum key or a shelf key, so that plain text data is never visible on an inter-module bus or network connection. However, in further embodiments, it is possible that data could be communicated in plain text form between modules.
FIG. 1C illustrates a quantum key encrypted data system, or more broadly a quantum communication network including a Quantum Key Distribution system, exchanging quantum keys via quantum channels and communicating encrypted data via a network, in accordance with present embodiments. Enclosures for various components in this and other embodiments are not shown but readily devised. The system uses a number of Trusted Nodes (TN) 104 , 106 , 108 , 110 , 112 , 114 , 116 coupled together in a network. As in the system shown in FIGS. 1A and 1B , each two neighboring Trusted Nodes are separated by less than or equal to a maximum specified distance over which quantum communication is reliable (for example, 100 km or 60 miles, possibly increased in further versions) for each communication hop. The Trusted Nodes perform Quantum Key Distribution among neighboring nodes over a quantum channel or quantum link, for example fiber-optic cable, and communicate data encrypted by quantum key over a standard network, for example ethernet, local area networks, wireless and/or wired networks, the Internet, etc., as further described below. Quantum keys, and existing Quantum Key Distribution protocols are considered known, and it is further contemplated that variations of the present system could use further quantum key generation and Quantum Key Distribution protocols and components while retaining relevant aspects of the presently described system and architecture.
Although a single end to end chain is shown in FIG. 1C , various further network configurations are readily devised and usable for embodiments of the system (see, e.g., FIG. 1B ). Each Trusted Node has a Trusted Node Controller (TNC) and one or more Alice modules and one or more Bob modules. An exception to this is that an endpoint Trusted Node
104 , 116 could have just one Alice module or just one Bob module. Each neighboring pair of Trusted Nodes, connected by a quantum channel (depicted as a solid line), exchanges a quantum key, by an Alice module transmitting to a Bob module over the quantum channel. Thus, an Alice module and a Bob module, connected by a quantum channel, perform Quantum Key Distribution or quantum key exchange, so that each generates and has a quantum key that is used by the respective Trusted Node to encrypt or decrypt data transmitted separately over a network. For example, the Alice module and Bob module could use BB84 (Charles H. Bennett and Gilles Brossard, 1984) protocol or E91 (Arthur Eckert, 1991) protocol and suitable photonics and communication over suitable service channel(s). Each paired Alice module and Bob module, in companion Trusted Nodes separated by a hop distance, generates a quantum key or series of quantum keys shared by the paired Alice module and Bob module, but distinct from quantum keys generated by other Alice module and Bob module pairs across the trusted network. The quantum key exchanged by a neighboring pair of Trusted Nodes is not known to any other nodes in the system. In various embodiments described below, the data that is encrypted and decrypted using a quantum key is itself a key, in some embodiments a quantum key (e.g., generated with a quantum random number generator), and this key is thereby passed from one Trusted Node to another Trusted Node, starting at one endpoint Trusted Node and ending at another endpoint Trusted Node. This key, passed by a series of encryption, decryption, re-encryption, etc., using quantum keys at each hop, is then used by an endpoint Trusted Node to encrypt data and used by the other endpoint Trusted Node to decrypt the data.
Here is a guide to the nomenclature for key handling functions in FIG. 1C .
Key handling functions
E(x,y)âSymmetric encryption of x by y
PK<#> is a key that is exchanged, for example using FIPS-validated key exchange methods
QK<#> is a set of bits generated by QKD systems, a quantum key
C(t) and D(t) are encrypted and plain-text data streams, respectively
In the scenario depicted in FIG. 1C , the first endpoint Trusted Node 104 transmits the quantum key QK 1 through a quantum channel to the first of a number of middle-Trusted Nodes, Trusted Node 106 . There could be just about any number of Trusted Nodes, termed middle-Trusted Nodes, between two endpoint Trusted Nodes
104 , 116 in further examples readily devised. That first one of the Trusted Nodes in the middle, Trusted node 106 , transmits quantum key QK 2 to the next Trusted Node 108 . Trusted Node 108 transmits quantum key QK 3 to the next Trusted Node 110 . Trusted Node 110 transmits quantum key QK 4 to the next Trusted Node 112 . Trusted Node 112 transmits quantum key QK 5 to the next Trusted Node QK 114 . And, Trusted Node QK 114 transmits quantum key QK 6 to the second endpoint Trusted Node 116 . These quantum key exchanges can be done in parallel, and need not be done in sequence. Any of the quantum key transmission, sharing or exchanges could be done in the opposite direction, with appropriately paired quantum key engines.
Meanwhile, at any time before, during or after these quantum key exchanges, the two endpoint Trusted Nodes
104 , 116 perform a public key exchange of keys PK 1 and PK 2 , over a network (depicted as a dot dashed line). It is not necessary that these keys be exchanged using Quantum Key Distribution, although in a further embodiment, they could be, for example using key passing through encryption, decryption and re-encryption with quantum keys as described above.
The first endpoint Trusted Node 104 generates a key K 1 , also at any time during this process. For example, this key could be generated using a random number generator, a deterministic random number generator, a quantum random number generator, or a number from a quantum random number generator used as a seed for a deterministic random number generator, etc. A key that is based in some way on a quantum random number generator is called a quantum key.
To initiate key passing, the initiating or first transmitting node, endpoint Trusted Node 104 , combines K 1 with PK 1 . For example, K 1 could encrypted by PK 1 , forming E(K 1 ,PK 1 ) (as shown in FIG. 1C ), or otherwise combined with PK 1 in a decryptable, recoverable or extractable manner as readily devised. The resulting key is called combined key K 1 , as the Trusted Node has no knowledge of anything other than that it has been passed a key. Endpoint Trusted Node 104 generates encrypted combined key K 1 by encrypting combined key K 1 with QK 1 , a quantum key exchanged by neighboring trusted nodes
104 , 106 , forming E(E(K 1 ,PK 1 ),QK 1 ). Then, the endpoint Trusted Node sends this encrypted combined key K 1 to the next Trusted Node 106 over a network (depicted in FIG. 1C as large dashed line for key transmission). Trusted node 106 uses QK 1 to decrypt the encrypted combined key K 1 to recover the combined key K 1 , then encrypts the combined key K 1 using a similarly generated QEK 2 to form E(E(K 1 ,PK 1 ),QK 2 ) and sends this encrypted combined key K 1 over a network to the next Trusted Node 108 with which the Trusted Node 106 has shared QK 2 . Trusted Node 108 uses QK 2 to decrypt the encrypted combined key K 1 to recover combined key K 1 , then re-encrypts this using a similarly generated QK 3 to form E(E(K 1 ,PK 1 ),QK 3 ) and sends this encrypted combined key K 1 to the next Trusted Node 110 with which Trusted Node 108 has exchanged QK 3 . This procedure of decryption using one quantum key shared with the previous Trusted Node and re-encryption using another quantum key shared with a subsequent or following Trusted Node repeats through however many nodes and hops are needed to get to the other end point, e.g., Trusted Node 116 . The other endpoint, Trusted Node 116 , which has received QK 6 through a quantum channel from preceding Trusted Node 114 , decrypts the encrypted combined key QK 1 received as E(E(K 1 ,PK 1 ),QK 6 ), using a similarly generated QK 6 , to produce combined key K 1 as E(K 1 ,PK 1 ). This other or second endpoint Trusted Node 116 , also has the key PK 1 as described above in the public key exchange with the first endpoint Trusted Node 104 , and uses PK 1 to decrypt the combined key K 1 (i.e., E(K 1 ,PK 1 ) or K 1 encrypted with PK 1 ), extracting or otherwise forming K 1 . Now both endpoint Trusted nodes
104 , 116 have key K 1 , and can use K 1 to encrypt and decrypt data. For additional security, and compliance with FIPS requiring the use of an FIPS-validated key, the two endpoints also use key PK 2 , to encrypt and decrypt data. Specifically, in this embodiment each endpoint forms a key as E(K 1 ,PK 2 ) and uses that key to encrypt or decrypt. One endpoint Trusted Node encrypts data D(T) with the key E(K 1 , PK 2 ) and transmits the encrypted data C(T)=E(D(T),E(K 1 ,PK 2 )) over a network, depicted in FIG. 1 as the small dashed line for encrypted data between encryptor/ router 118 coupled to Trusted node 116 , and encryptor/ router 102 connected to Trusted Node 104 . The other endpoint Trusted Node receives that encrypted data and decrypts with the key E(K 1 ,PK 2 ). This encrypted data transmission can go in either direction to or from either endpoint Trusted Node
104 , 116 .
In one scenario, using FIG. 1C , customer nodes are trusted nodes
104 and 116 . With this use, the customer nodes (trusted nodes 104 , 116 ) are exchanging key PK 1 . One customer node, trusted node 104 , generates key K 1 , and encrypts K 1 with PK 1 to form E(K 1 , PK 1 ). The customer node, trusted node 104 , exchanges quantum key QK 1 with the first trusted node 106 of a trusted node network (formed by or including trusted
nodes
106 , 108 , 110 , 112 , 114 ). The customer node, trusted node 104 , then encrypts E(K 1 , PK 1 ) with quantum key QK 1 to form E(E(K 1 , PK 1 ), QK 1 ), and transmits this encrypted value to trusted node 106 of the trusted node network. Decryption and encryption hops using quantum keys proceed as described previously, so that the encrypted value E(K 1 , PK 1 ) ends up at the other customer node, trusted node 116 . This other customer node, trusted node 116 , then decrypts E(K 1 , PK 1 ), using PK 1 , to recover K 1 . The two customer nodes, trusted nodes
104 , 116 then communicate as described previously and shown in FIG. 1C , using E(K 1 , PK 2 ) to encrypt and decrypt data. With this scenario, only the customer nodes, trusted nodes
104 , 116 , handle keys K 1 and PK 2 directly. The trusted
nodes
106 , 108 , 110 , 112 , 114 in the trusted node network never see key K 1 in unencrypted form, and never see PK 2 in unencrypted form.
In summary, FIG. 1C depicts a quantum key distribution system, which could also be termed a quantum communication network system, or quantum key encrypted data system, that exchanges quantum keys between neighboring Trusted Nodes, and passes a key from one endpoint Trusted node to another endpoint Trusted Node through a series of hops to Trusted Nodes with encryption, decryption and re-encryption using quantum keys. The key, which can be a quantum key in some embodiments, is then used by endpoint Trusted Nodes for encrypting and decrypting data that is transmitted from one endpoint Trusted Node to the other endpoint Trusted Node over a network. Further component and system details, variations, software and hardware in various functions, and further keys and types of security are described below.
FIG. 1D illustrates a Quantum Key Distribution system featuring distribution of a customer key using network hops over
Trusted Nodes
130 , 136 , 140 with encryption and decryption by quantum keys in accordance with present embodiments. Customer nodes
120 , 150 , each labeled âCust-1â are at opposed endpoints of the network depicted in FIG. 1D , and exchange key PK 1 with each other over a network, for example using known key exchange techniques over a standard network that is not required to have a quantum channel. Customer node 120 , at the lower left FIG. 1D , generates, receives or otherwise obtains customer key K 1 , which should never be sent in unencrypted form over any network. Using key PK 1 and encryption module 124 , customer node 120 encrypts key K 1 to obtain E(K 1 , PK 1 ), which can be called encrypted key K 1 . This is one possible way to pass keys, and other ways of passing keys are applicable in further embodiments. Neighboring Alice and Bob modules exchange quantum keys, all across the network through quantum channels. The Alice module 122 coupled to the customer node 120 exchanges quantum key QK 0 with the Bob module 128 of trusted node 130 labeled âTN-aâ over their quantum channel. Alice module 132 of trusted node 130 labeled âTN-aâ exchanges quantum key QK 1 with Bob module 134 of trusted node 136 labeled âTN-bâ. An Alice module (not shown) of trusted node 136 âTN-bâ exchanges quantum key QK 2 with Bob module 138 of trusted node 140 âTN-câ. And, Bob module 142 coupled to trusted node 140 âTn-câ exchanges quantum key QK 3 with Alice module 146 coupled to customer node 150 . Alternatively, the Alice and Bob modules of any neighboring quantum channel-connected pair could be swapped in various embodiments. Further, the quantum channel-connected network (i.e., network of quantum tunnels) could be expanded wi
CLAIMS
Claims ( 17 )
What is claimed is:
1. A trusted node (TN) for quantum key distribution (QKD), comprising:
a quantum key engine (QKE) to exchange quantum keys with other trusted nodes via a quantum channel;
a quantum key controller (QKC) comprising one or more processors to handle the quantum keys, direct encryption using the quantum keys and direct decryption using the quantum keys;
a trusted node controller (TNC) comprising one or more processors to direct the quantum key controller and the quantum key engine to perform quantum key exchanges with other trusted nodes, encrypted communication with other trusted nodes, and encrypted communication among blades in the trusted node, wherein no unencrypted quantum key is accessible to the trusted node controller;
the trusted node controller is to direct a first blade, comprising a first quantum key controller and a first quantum key engine, in the trusted node, to receive data comprising a first key, encrypted by a first quantum key exchanged with a preceding trusted node, decrypt using the first quantum key, re-encrypt using a shelf key, and send the data comprising the first key encrypted by the shelf key to a second blade comprising a second quantum key controller and a second quantum key engine in the trusted node; and
the trusted node controller is to direct the second blade to decrypt using the shelf key, the data comprising the first key encrypted by the shelf key, re-encrypt using a second quantum key exchanged with a succeeding trusted node, and send the data comprising the first key encrypted using the second quantum key to the succeeding trusted node.
2. The trusted node of claim 1 , wherein shelf keys are used for the encrypted communication among the blades in the trusted node.
3. The trusted node of claim 1 , further comprising:
the trusted node controller is to support multiple tenants per trusted node and multiple trusted nodes per tenant in a quantum communication network comprising the trusted node and further trusted nodes.
4. The trusted node of claim 1 , further comprising:
a routing manager, cooperative with the trusted node controller to manage node discovery, route tables and routing of key transactions for a quantum communication network comprising the trusted node and further trusted nodes.
5. The trusted node of claim 1 , further comprising:
the trusted node controller implemented as a virtual machine.
6. The trusted node of claim 1 , further comprising:
two or more switch processors to control switches of the trusted node and host the trusted node controller as fault-tolerant.
7. A method of operating a trusted node (TN) for quantum key distribution (QKD), comprising:
exchanging, through a quantum key engine (QKE) of the trusted node and via a quantum channel, quantum keys with other trusted nodes;
handling, through a quantum key controller (QKC) of the trusted node, the quantum keys;
directing, through a trusted node controller (TNC), the quantum key controller and the quantum key engine to perform the exchanging the quantum keys, encrypted communication with the other trusted nodes, encryption using the quantum keys and decryption using the quantum keys, and encrypted communication among blades in the trusted node, wherein each of one or more processors of the trusted node controller cannot and does not read, write, send nor receive an unencrypted quantum key;
directing, by the trusted node controller, a first blade, comprising a first quantum key controller and a first quantum key engine, in the trusted node, to receive data comprising a first key, encrypted by a first quantum key exchanged with a preceding trusted node, decrypt using the first quantum key, re-encrypt using a shelf key, and send the data comprising the first key encrypted by the shelf key to a second blade comprising a second quantum key controller and a second quantum key engine in the trusted node; and
directing, by the trusted node controller, the second blade to decrypt using the shelf key, the data comprising the first key encrypted by the shelf key, re-encrypt using a second quantum key exchanged with a succeeding trusted node, and send the data comprising the first key encrypted using the second quantum key to the succeeding trusted node.
8. The method of claim 7 , further comprising:
using one or more shelf keys for the encrypted communication among the blades in the trusted node.
9. The method of claim 7 , further comprising:
supporting multiple tenants per trusted node and multiple trusted nodes per tenant in a quantum communication network comprising the trusted node and further trusted nodes.
10. The method of claim 7 , further comprising:
managing, through the trusted node controller, node discovery, route tables and routing of key transactions for a quantum communication network comprising the trusted node and further trusted nodes.
11. The method of claim 7 , further comprising:
hosting, through two or more switch processors of the trusted node, the trusted node controller as a fault-tolerant virtual machine.
12. A tangible, non-transitory, computer-readable media having instructions thereupon which, when executed by a processor, cause the processor to perform a method comprising:
exchanging, through a quantum key engine (QKE) of the trusted node and via a quantum channel, quantum keys with other trusted nodes;
handling, through a quantum key controller (QKC) of the trusted node, the quantum keys;
directing, through a trusted node controller (TNC), the quantum key controller and the quantum key engine to perform the exchanging the quantum keys, encrypted communication with the other trusted nodes, encryption using the quantum keys and decryption using the quantum keys, and encrypted communication among blades in the trusted node, wherein the trusted node controller has no direct access to unencrypted quantum keys;
directing, by the trusted node controller, a first blade in the trusted node, to receive data comprising a first key, encrypted by a first quantum key exchanged with a preceding trusted node, decrypt using the first quantum key, re-encrypt using a shelf key, and send the data comprising the first key encrypted by the shelf key to a second blade in the trusted node; and
directing, by the trusted node controller, the second blade to decrypt using the shelf key, the data comprising the first key encrypted by the shelf key, re-encrypt using a second quantum key exchanged with a succeeding trusted node, and send the data comprising the first key encrypted using the second quantum key to the succeeding trusted node.
13. The computer-readable media of claim 12 , wherein the method further comprises:
using one or more shelf keys for the encrypted communication among the blades in the trusted node.
14. The computer-readable media of claim 12 , wherein the method further comprises:
supporting multiple tenants by the trusted node and multiple trusted nodes per tenant in a quantum communication network comprising the trusted node and further trusted nodes.
15. The computer-readable media of claim 12 , wherein the method further comprises:
managing, through the trusted node controller, node discovery, route tables and routing of key transactions for a quantum communication network comprising the trusted node and further trusted nodes.
16. The computer-readable media of claim 12 , wherein the method further comprises:
hosting the trusted node controller as a virtual machine.
17. The computer-readable media of claim 12 , wherein the method further comprises:
controlling switches of the trusted node; and
hosting the trusted node controller as fault-tolerant.
US16/403,462
2019-05-03
2019-05-03
Method of operation of a trusted node software in a quantum key distribution system
Active
2040-05-31
US11424918B2
( en )
Priority Applications (2)
Application Number
Priority Date
Filing Date
Title
US16/403,462
US11424918B2
( en )
2019-05-03
2019-05-03
Method of operation of a trusted node software in a quantum key distribution system
PCT/US2020/030572
WO2020226981A1
( en )
2019-05-03
2020-04-29
Method of operation of a trusted node software in a quantum key distribution system
Applications Claiming Priority (1)
Application Number
Priority Date
Filing Date
Title
US16/403,462
US11424918B2
( en )
2019-05-03
2019-05-03
Method of operation of a trusted node software in a quantum key distribution system
Publications (2)
Publication Number
Publication Date
US20210044433A1
US20210044433A1 ( en )
2021-02-11
US11424918B2
true
US11424918B2 ( en )
2022-08-23
Family
ID=70775530
Family Applications (1)
Application Number
Title
Priority Date
Filing Date
US16/403,462
Active
2040-05-31
US11424918B2
( en )
2019-05-03
2019-05-03
Method of operation of a trusted node software in a quantum key distribution system
Country Status (2)
Country
Link
US
( 1 )
US11424918B2
( en )
WO
( 1 )
WO2020226981A1
( en )
Cited By (2)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20240097892A1
( en )
*
2020-12-10
2024-03-21
Abn Amro Bank N.V.
Orchestrated quantum key distribution
US20240097890A1
( en )
*
2020-12-07
2024-03-21
National University Of Singapore
Quantum key token
Families Citing this family (29)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US12483397B1
( en )
*
2018-04-13
2025-11-25
Hushmesh Inc.
Use of cryptographic twins for secure storage and access of entity data
US12567981B2
( en )
2018-08-01
2026-03-03
Cable Television Laboratories, Inc.
Systems and methods for data authentication using composite keys and signatures
US11483140B2
( en )
2019-08-02
2022-10-25
Quantumxchange, Inc.
Secure out-of-band symmetric encryption key delivery
US20220294618A1
( en )
*
2019-08-12
2022-09-15
British Telecommunications Public Limited Company
Improvements to qkd methods
US11436517B2
( en )
2019-08-26
2022-09-06
Bank Of America Corporation
Quantum-tunneling-enabled device case
KR102595369B1
( en )
*
2019-09-16
2023-10-30
주ìíì¬ ì¼ì´í°
Method, apparatus and system for quantum cryptography key distribution
US11985235B2
( en )
*
2019-09-16
2024-05-14
Quantum Technologies Laboratories, Inc.
Quantum communication system
US11228431B2
( en )
*
2019-09-20
2022-01-18
General Electric Company
Communication systems and methods for authenticating data packets within network flow
US11569989B2
( en )
2019-10-23
2023-01-31
Bank Of America Corporation
Blockchain system for hardening quantum computing security
US11468356B2
( en )
2019-10-31
2022-10-11
Bank Of America Corporation
Matrix-based quantum-resilient server-cluster
US11251946B2
( en )
*
2019-10-31
2022-02-15
Bank Of America Corporation
Quantum key synchronization within a server-cluster
US11467644B2
( en )
*
2020-05-01
2022-10-11
Dell Products, Lp
Systems and methods for detecting battery removal while an information handling system is in an off state
US12200122B1
( en )
*
2020-08-06
2025-01-14
Cable Television Laboratories, Inc.
Systems and methods for advanced quantum-safe PKI credentials for authentications
CN111953487B
( en )
*
2020-08-14
2022-04-22
èå·æµªæ½®æºè½ç§ææéå ¬å¸
Key management system
US11476932B2
( en )
*
2020-11-30
2022-10-18
At&T Intellectual Property I, L.P.
Quantum tampering threat management
CN112787807B
( en )
*
2020-12-31
2022-03-18
æ¸ å大å¦
Quantum communication method and communication network based on secure relay
CN114978477B
( en )
*
2021-02-18
2025-03-14
å½ç§éåéä¿¡ç½ç»æéå ¬å¸
An open key distribution network based on physical system
US11469889B1
( en )
*
2021-05-20
2022-10-11
Sprint Communications Company L.P.
Quantum authentication in wireless communication networks
GB2609898B
( en )
*
2021-07-22
2024-10-16
Arqit Ltd
Quantum key distribution protocol adapter
CN114244500B
( en )
*
2021-11-15
2022-10-04
å京大å¦
Quantum key negotiation method, quantum key negotiation system, quantum digital signature method and quantum digital signature system
EP4555667A1
( en )
*
2022-07-12
2025-05-21
British Telecommunications public limited company
Improved qkd arrangement
CN115426105B
( en )
*
2022-08-16
2024-12-24
å½ç§éåéä¿¡ç½ç»æéå ¬å¸
Quantum cryptographic card device based on quantum key and its application
US20240291640A1
( en )
*
2023-02-27
2024-08-29
Jpmorgan Chase Bank, N.A.
Systems and methods for quantum key distribution secured vault-based application-to-application communication
US12452046B2
( en )
*
2023-04-21
2025-10-21
Jpmorgan Chase Bank, N.A.
Systems and methods for secure cryptographic secret distribution
CN116599665A
( en )
*
2023-07-03
2023-08-15
ä¸å½é¶è¡è¡ä»½æéå ¬å¸
A blockchain data transmission method and related device
EP4498636A1
( en )
*
2023-07-28
2025-01-29
Airbus S.A.S.
Quantum key distribution (qkd) method, qkd end-node and qkd network
WO2025087609A1
( en )
*
2023-10-25
2025-05-01
British Telecommunications Public Limited Company
Improved qkd network
US12541579B2
( en )
*
2024-01-01
2026-02-03
Bank Of America Corporation
Tracking quantum-based interactions
JP2025138206A
( en )
*
2024-03-11
2025-09-25
æ ªå¼ä¼ç¤¾æ±è
Information processing device, quantum cryptography communication system, information processing method and program
Citations (32)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US6185680B1
( en )
*
1995-11-30
2001-02-06
Kabushiki Kaisha Toshiba
Packet authentication and packet encryption/decryption scheme for security gateway
US20040184603A1
( en )
*
2003-03-21
2004-09-23
Pearson David Spencer
Systems and methods for quantum cryptographic key transport
US20050078826A1
( en )
2003-10-10
2005-04-14
Nec Corporation
Quantum cryptography communication system and quantum cryptography key distributing method used in the same
US20050286723A1
( en )
2004-06-28
2005-12-29
Magiq Technologies, Inc.
QKD system network
US7113598B2
( en )
2003-05-14
2006-09-26
Science Research Laboratory, Inc.
Methods and systems for high-data-rate quantum cryptography
US7181011B2
( en )
2004-05-24
2007-02-20
Magiq Technologies, Inc.
Key bank systems and methods for QKD
US7430295B1
( en )
2003-03-21
2008-09-30
Bbn Technologies Corp.
Simple untrusted network for quantum cryptography
US7457416B1
( en )
2002-07-17
2008-11-25
Bbn Technologies Corp.
Key distribution center for quantum cryptographic key distribution networks
US7646873B2
( en )
2004-07-08
2010-01-12
Magiq Technologies, Inc.
Key manager for QKD networks
US7706535B1
( en )
2003-03-21
2010-04-27
Bbn Technologies Corp.
Systems and methods for implementing routing protocols and algorithms for quantum cryptographic key transport
US7792288B2
( en )
2002-11-22
2010-09-07
Arc Seibersdorf Research Gmbh
Communication system using quantum cryptography and comprising switching stations
US20100293380A1
( en )
2008-01-25
2010-11-18
Qinetiq Limited
Quantum cryptography apparatus
US20100299526A1
( en )
2008-01-25
2010-11-25
Qinetiq Limited
Network having quantum key distribution
US7889868B2
( en )
2005-09-30
2011-02-15
Verizon Business Global Llc
Quantum key distribution system
US20120198441A1
( en )
*
2011-01-28
2012-08-02
Blue Coat Systems, Inc.
Bypass Mechanism for Virtual Computing Infrastructures
US20140006793A1
( en )
*
2012-06-28
2014-01-02
International Business Machines Corporation
Trusted System Network
US8681982B2
( en )
2008-12-05
2014-03-25
Qinetiq Limited
Method of establishing a quantum key for use between network nodes
US8903094B2
( en )
2011-08-05
2014-12-02
Selex Sistemi Integrati S.P.A.
Cryptographic key distribution system
US8964989B2
( en )
2012-11-20
2015-02-24
Ut-Battelle Llc
Method for adding nodes to a quantum key distribution system
US20150236900A1
( en )
*
2012-08-31
2015-08-20
Bce Inc.
Ip mpls pop virtualization and fault tolerant virtual router
US9264225B1
( en )
2013-02-27
2016-02-16
The Boeing Company
Quantum communication using quantum teleportation
EP3007478A1
( en )
2013-06-08
2016-04-13
Quantumctek Co., Ltd.
Mobile secret communications method based on quantum key distribution network
US20160248581A1
( en )
*
2015-01-08
2016-08-25
Alibaba Group Holding Limited
Quantum key distribution system, method and apparatus based on trusted relay
US20160285629A1
( en )
*
2015-03-24
2016-09-29
Kabushiki Kaisha Toshiba
Quantum key distribution device, quantum key distribution system, and quantum key distribution method
US9698979B2
( en )
2011-04-15
2017-07-04
Quintessencelabs Pty Ltd.
QKD key management system
US20180109377A1
( en )
2016-10-14
2018-04-19
Alibaba Group Holding Limited
Method and system for data security based on quantum communication and trusted computing
US10291400B2
( en )
2016-03-14
2019-05-14
Kabushiki Kaisha Toshiba
Quantum key distribution device, quantum key distribution system, and quantum key distribution method
US10432395B2
( en )
2017-10-04
2019-10-01
The Boeing Company
Recipient-driven data encryption
US10554397B2
( en )
2017-09-27
2020-02-04
The Boeing Company
Quantum-based data encryption
US20200076807A1
( en )
*
2018-09-04
2020-03-05
International Business Machines Corporation
Controlling access between nodes by a key server
US20200076595A1
( en )
*
2018-09-04
2020-03-05
International Business Machines Corporation
Automatic re-authentication of links using a key server
US20200076600A1
( en )
*
2018-09-04
2020-03-05
International Business Machines Corporation
Shared key processing by a host to secure links
2019
2019-05-03
US
US16/403,462
patent/US11424918B2/en
active
Active
2020
2020-04-29
WO
PCT/US2020/030572
patent/WO2020226981A1/en
not_active
Ceased
Patent Citations (35)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US6185680B1
( en )
*
1995-11-30
2001-02-06
Kabushiki Kaisha Toshiba
Packet authentication and packet encryption/decryption scheme for security gateway
US7457416B1
( en )
2002-07-17
2008-11-25
Bbn Technologies Corp.
Key distribution center for quantum cryptographic key distribution networks
US7792288B2
( en )
2002-11-22
2010-09-07
Arc Seibersdorf Research Gmbh
Communication system using quantum cryptography and comprising switching stations
US7512242B2
( en )
2003-03-21
2009-03-31
Bbn Technologies Corp.
Systems and methods for quantum cryptographic key transport
US20040184603A1
( en )
*
2003-03-21
2004-09-23
Pearson David Spencer
Systems and methods for quantum cryptographic key transport
US7706535B1
( en )
2003-03-21
2010-04-27
Bbn Technologies Corp.
Systems and methods for implementing routing protocols and algorithms for quantum cryptographic key transport
US7430295B1
( en )
2003-03-21
2008-09-30
Bbn Technologies Corp.
Simple untrusted network for quantum cryptography
US7113598B2
( en )
2003-05-14
2006-09-26
Science Research Laboratory, Inc.
Methods and systems for high-data-rate quantum cryptography
US7178277B2
( en )
2003-10-10
2007-02-20
Nec Corporation
Quantum cryptography communication system and quantum cryptography key distributing method used in the same
US20050078826A1
( en )
2003-10-10
2005-04-14
Nec Corporation
Quantum cryptography communication system and quantum cryptography key distributing method used in the same
US7181011B2
( en )
2004-05-24
2007-02-20
Magiq Technologies, Inc.
Key bank systems and methods for QKD
US20050286723A1
( en )
2004-06-28
2005-12-29
Magiq Technologies, Inc.
QKD system network
US7646873B2
( en )
2004-07-08
2010-01-12
Magiq Technologies, Inc.
Key manager for QKD networks
US7889868B2
( en )
2005-09-30
2011-02-15
Verizon Business Global Llc
Quantum key distribution system
US8650401B2
( en )
2008-01-25
2014-02-11
Qinetiq Limited
Network having quantum key distribution
US20100293380A1
( en )
2008-01-25
2010-11-18
Qinetiq Limited
Quantum cryptography apparatus
US20100299526A1
( en )
2008-01-25
2010-11-25
Qinetiq Limited
Network having quantum key distribution
US8681982B2
( en )
2008-12-05
2014-03-25
Qinetiq Limited
Method of establishing a quantum key for use between network nodes
US20120198441A1
( en )
*
2011-01-28
2012-08-02
Blue Coat Systems, Inc.
Bypass Mechanism for Virtual Computing Infrastructures
US9698979B2
( en )
2011-04-15
2017-07-04
Quintessencelabs Pty Ltd.
QKD key management system
US8903094B2
( en )
2011-08-05
2014-12-02
Selex Sistemi Integrati S.P.A.
Cryptographic key distribution system
US20140006793A1
( en )
*
2012-06-28
2014-01-02
International Business Machines Corporation
Trusted System Network
US20150236900A1
( en )
*
2012-08-31
2015-08-20
Bce Inc.
Ip mpls pop virtualization and fault tolerant virtual router
US8964989B2
( en )
2012-11-20
2015-02-24
Ut-Battelle Llc
Method for adding nodes to a quantum key distribution system
US9264225B1
( en )
2013-02-27
2016-02-16
The Boeing Company
Quantum communication using quantum teleportation
EP3007478A1
( en )
2013-06-08
2016-04-13
Quantumctek Co., Ltd.
Mobile secret communications method based on quantum key distribution network
US20160248581A1
( en )
*
2015-01-08
2016-08-25
Alibaba Group Holding Limited
Quantum key distribution system, method and apparatus based on trusted relay
US20160285629A1
( en )
*
2015-03-24
2016-09-29
Kabushiki Kaisha Toshiba
Quantum key distribution device, quantum key distribution system, and quantum key distribution method
US10291400B2
( en )
2016-03-14
2019-05-14
Kabushiki Kaisha Toshiba
Quantum key distribution device, quantum key distribution system, and quantum key distribution method
US20180109377A1
( en )
2016-10-14
2018-04-19
Alibaba Group Holding Limited
Method and system for data security based on quantum communication and trusted computing
US10554397B2
( en )
2017-09-27
2020-02-04
The Boeing Company
Quantum-based data encryption
US10432395B2
( en )
2017-10-04
2019-10-01
The Boeing Company
Recipient-driven data encryption
US20200076807A1
( en )
*
2018-09-04
2020-03-05
International Business Machines Corporation
Controlling access between nodes by a key server
US20200076595A1
( en )
*
2018-09-04
2020-03-05
International Business Machines Corporation
Automatic re-authentication of links using a key server
US20200076600A1
( en )
*
2018-09-04
2020-03-05
International Business Machines Corporation
Shared key processing by a host to secure links
Non-Patent Citations (29)
* Cited by examiner, â Cited by third party
Title
Aguado, Alejandro, et al. " Quantum-aware software defined networks. " Int. Conf. on Quantum Cryptography (QCrypt). 2016. (Year: 2016).
*
Aguado, Alejandro, et al. " Secure NFV orchestration over an SDN-controlled optical network with time-shared quantum key distribution resources. " Journal of Lightwave Technology 35.8 (2017): 1357-1362. (Year: 2017).
*
Aguado, Alejandro, Victor Lopez, Jesus Martinez-Mateo, Momtchil Peev, Diego Lopez, and Vicente Martin, " Virtual Network Function Deployment and Service Automation to Provide End-to-End Quantum Encryption, " J. Opt. Commun. Netw. 10, 421-430 (2018) (Year: 2018).
*
Dijkstra, E.W., " A Note on Two Problems in Connexion with Graphs, " Numerische Mathematik, Jun. 11, 1959, pp. 269-271, vol. 1, Amsterdam.
ETSI QKD Industry Specification Group, Sep. 24, 2015, <https://web.archive.org/web/20150924015201/http://www.etsi.org/technologies-clusters/technologies/quantum-key-distribution>.
Final Office Action dated Jan. 18, 2022 for U.S. Appl. No. 16/403,474, 26 pages.
Gisin, et al., " Quantum cryptography, " Reviews of Modern Physics, Jan. 2002, pp. 145-195, vol. 74, The American Physical Society.
Hughes, et al., " Network-Centric Quantum Communications with Application to Critical Infrastructure Protection, " 2013.
Langer, et al., " Standardization of quantum key distribution and the ETSI standardization initiative ISG-QKD, " New Journal of Physics, Jan. 26, 2009, 17 pgs., vol. 11, IOP Publishing Ltd and Deutsche Physikalische Gesellschaft.
N. Amaya, G. S. Zervas and D. Simeonidou, " Architecture on demand for transparent optical networks, " 2011 13th International Conference on Transparent Optical Networks, 2011, pp. 1-4, doi: 10.1109/ICTON.2011.5970836. (Year: 2011).
*
Non-Final Office Action dated Jun. 9, 2021 for U.S. Appl. No. 16/403,474, 21 pages.
Non-Final Office Action dated Nov. 10, 2021 for U.S. Appl. No. 16/403,467, 11 pages.
Peev, et al., " The SECOQC quantum key distribution network in Vienna, " New Journal of Physics, Mar. 25, 2009, 38 pgs., vol. 11.
Sasaki, et al., " Field test of quantum key distribution in the Tokyo QKD Network, " Optics Express, May 23, 2011, pp. 10387-10409, vol. 19, No. 11.
Stucki, et al., " Long-term performance of the SwissQuantum quantum key distribution network in a field environment, " New Journal of Physics, Dec. 1, 2011, 19 pgs., vol. 13, IOP Publishing Ltd and Deutsche Physikalische Gesellschaft.
The International Preliminary Report on Patentability of the International Searching Authority for PCT Application No. PCT/US2020/030889 dated Nov. 2, 2021, 8 pages.
The International Preliminary Report on Patentability of the International Searching Authority for PCT Application No. PCT/US2020/031155 dated Nov. 2, 2021, 7 pages.
The International Preliminary Report on Patentability of the International Searching Authority for PCT Application No. PCT/US2020/046150 dated Feb. 8, 2022, 7 pages.
The International Search Report and Written Opinion of the International Searching Authority for PCT Application No. PCT/US2020/030572 dated Jul. 3, 2020, 9 pages.
The International Search Report and Written Opinion of the International Searching Authority for PCT Application No. PCT/US2020/031155 dated Sep. 2, 2020, 10 pages.
Tysowski, Piotr K., et al. " The engineering of a scalable multi-site communications system utilizing quantum key distribution (QKD). " Quantum Science and Technology 3.2 (2018): 024001. (Year: 2018).
*
Walenta Nino et al.: " Practical aspects of security certification for commercial quantum technologies, " Proceedings of SPIE, IEEE, US, vol. 9648, Oct. 13, 2015 (Oct. 13, 2015), pp. 96480U-9648OU, XP060062690, DOI: 10.1117/12.2193776, ISBN: 978-1-62841-730-2, pp. 2, 8, 9; figure 4.
WALENTA NINO; SOUCARROS MATHILDE; STUCKI DAMIEN; CASELUNGHE DARIO; DOMERGUE MATHIAS; HAGERMAN MICHAEL; HART RANDALL; HAYFORD DON; : " Practical aspects of security certification for commercial quantum technologies ", PROCEEDINGS OF SPIE, IEEE, US, vol. 9648, 13 October 2015 (2015-10-13), US , pages 96480U - 96480U-11, XP060062690, ISBN: 978-1-62841-730-2, DOI: 10.1117/12.2193776
Walenta, et al., " A fast and versatile quantum key distribution system with hardware key distillation and wavelength multiplexing, " New Journal of Physics, Jan. 23, 2014, 21 pgs., vol. 16, IOP Publishing Ltd and Deutsche Physikalische Gesellschaft.
Walenta, et al., " Towards a North American QKD Backbone with Certifiable Security, " QCrypt2015, 5th International Conference on Quantum Cryptography, Sep. 28, 2015, 15 pgs., Tokyo, Japan, Slides only.
Walenta, et al., " Towards a North American QKD Backbone with Certifiable Security, " QCrypt2015, 5th International Conference on Quantum Cryptography, Sep. 28, 2015, 3 pgs., Tokyo, Japan, Abstract only.
Walenta, et al., " Towards a North American QKD Backbone with Certifiable Security, " QCrypt2015, 5th International Conference on Quantum Cryptography, Sep. 28, 2015, Tokyo, Japan, Screen grab only. <https://www.youtube.com/watch?v=P1MYAOgLLx0>.
Wang, et al., " Field and long-term demonstration of a wide area quantum key distribution network, " Optics Express, Sep. 8, 2014, 18 pgs., vol. 22, No. 18.
Y. Cao et al., " Experimental Demonstration of End-to-End Key on Demand Service Provisioning Over Quantum Key Distribution Networks with Software Defined Networking, " 2019 Optical Fiber Communications Conference and Exhibition (OFC), 2019, pp. 1-3. (Year: 2019).
*
Cited By (4)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20240097890A1
( en )
*
2020-12-07
2024-03-21
National University Of Singapore
Quantum key token
<span