ABSTRACT
Abstract
A quantum key distribution system includes a quantum security key management (QSKM) device, a plurality of quantum security key distribution (QSKD) devices, and a quantum security key service (QSKS) device. The QSKD device splits an identity-based system private key into a plurality of system sub-private keys, and distributes the plurality of system sub-private keys to a corresponding number of the QSKD devices. The QSKS device forwards a request for acquiring an authorized private key from a first QSKD device to a predetermined number of second QSKD devices. The predetermined number of second QSKD devices each generate an identity-based authorized sub-private key from the system sub-private key. The first QSKD device acquires, from the predetermined number of second QSKD devices, the identity-based authorized sub-private keys, and reconstructs an identity-based authorized private key based on the identity-based authorized sub-private keys.
Description
CROSS REFERENCE TO RELATED APPLICATION
This application is a continuation of Ser. No. 14/993,643 filed Jan. 12, 2016, which based upon and claims priority to Chinese Application No. 201510033128.2, filed Jan. 22, 2015, both of which are incorporated herein by reference in their entireties.
TECHNICAL FIELD
The present application relates to quantum key technologies, in particular to methods, apparatus, and systems for quantum key distribution.
BACKGROUND
With development of computers and network technologies, systems providing various services for users emerge, including, for example, cloud computing systems that provide applications, data and IT services for users. In such systems, to ensure security of stored static data and generated dynamic data, it is necessary to encrypt the data with an encryption algorithm. For example, in a cloud computing environment, two data encryption modes are typically used: a first encryption mode based on certificate authentication and a second encryption mode based on cloud computing key management.
The basic principle of the certificate-based encryption authentication mode is as follows: a server in the system controls and saves keys by itself; when encrypting and storing the static data, the server uses symmetric keys to encrypt the data, and then uses a digital certificate to encrypt the symmetric keys (i.e., using a public key to encrypt the symmetric keys) and stores the encrypted data; when reading the data, the server or another server first uses a private key to decrypt the symmetric keys and then uses the decrypted symmetric keys to decrypt the data.
Compared with the certificate-based encryption authentication mode, the encryption mode that uses a cloud computing key management system is more widely applied to cloud computing environments, and is also the foundation of the security of cloud data.
FIG. 1 is an exemplary cloud computing key management system. The cloud computing key management system includes two parts, i.e., a cloud computing key client end and a cloud computing key management service end. The cloud computing key client end resides in a cloud computing server and is responsible for providing a key service for cloud computing applications in the cloud computing server. The cloud computing key client end uses a standard key management protocol to apply for management services such as key generation, key recovery and key update to the cloud computing key management service end. The cloud computing key management service end applies for corresponding services to a symmetric password management server according to a service application type, and then returns a key service operation result to the cloud computing key client end, and may also act on behalf of the cloud computing key client end to apply for the corresponding services to a digital certificate center.
Because both modes use classical cryptography based on computational complexity, they can potentially be cracked in light of the emergence of cloud computing, quantum computing, and other computing technologies. In addition, for the first mode, the encrypted key must be kept safe. Once lost or damaged, the key or data cannot be recovered. For the second mode, although handing over the key to the system for central management improves security, administrators of the key management server, who have higher operation permissions, can access user data and keys, may give away the keys and user confidential information.
SUMMARY
One aspect of the present disclosure is directed to a quantum key distribution system. The quantum key distribution system includes a quantum security key management device, a plurality of quantum security key distribution devices connected with the quantum security key management device, and a quantum security key service device connected with the quantum security key management device and the plurality of quantum security key distribution devices. The quantum security key management device splits an identity-based system private key into a plurality of system sub-private keys, and distributes the plurality of system sub-private keys to a corresponding number of the quantum security key distribution devices. The quantum security key service device forwards a request for acquiring an authorized private key from a first quantum security key distribution device of the plurality of quantum security key distribution devices to a predetermined number of second quantum security key distribution devices of quantum security key distribution devices. The predetermined number of second quantum security key distribution devices each generate an identity-based authorized sub-private key from the system sub-private key. The first quantum security key distribution device acquires, from the predetermined number of second quantum security key distribution devices, the identity-based authorized sub-private keys, and reconstructs an identity-based authorized private key based on the identity-based authorized sub-private keys.
Another aspect of the present disclosure is directed to a quantum key distribution method. The quantum key distribution method includes receiving, by a quantum security key service device, a request for acquiring an authorized private key from a first quantum security key distribution device of a requester, the request at least carrying identifier information of the requester, forwarding, by the quantum security key service device, the request to a predetermined number of second quantum security key distribution devices, receiving, by the first quantum security key distribution device of the requester, a plurality of authorized sub-private keys generated, by the predetermined number of second quantum security key distribution devices, based on the identifier information of the requester and a plurality of system sub-private keys, and reconstructing, by the first quantum security key distribution device of the requester, an identity-based authorized private key based on the authorized sub-private keys.
Consistent with some embodiments of the present disclosure, the reconstructing, by the first quantum security key distribution device of the requester, the identity-based authorized private key based on the authorized sub-private keys includes reconstructing, by the first quantum security key distribution device of the requester, the identity-based authorized private key may be implemented by using a threshold secret sharing mechanism.
Consistent with some embodiments of the present disclosure, the quantum key distribution method may further include, before receiving the request by the quantum security key service device, splitting, by a quantum security key management device, an identity-based system private key into the plurality of system sub-private keys by using the threshold secret sharing mechanism, and sharing, by the quantum security key management device, the plurality of system sub-private keys with a corresponding number of quantum security key distribution devices.
Another aspect of the present disclosure is directed to another quantum key distribution method. The quantum key distribution method include splitting, by a quantum security key management device, an identity-based system private key into a plurality of system sub-private keys, distributing, by the quantum security key management device, the plurality of system sub-private keys to a corresponding number of quantum security key distribution devices, receiving, by a quantum security key service device, a request for acquiring an authorized private key from a first quantum security key distribution device of a requester, the request at least carrying identifier information of the requester, forwarding, by the quantum security key service device, the request to a predetermined number of second quantum security key distribution devices of the corresponding number of quantum security key distribution devices, receiving, by the first quantum security key distribution device, a plurality of authorized sub-private keys generated, by the predetermined number of second quantum security key distribution devices, based on the identifier information of the requester and a plurality of system sub-private keys, and reconstructing, by the first quantum security key distribution device of the requester, an identity-based authorized private key based on the authorized sub-private keys.
Consistent with some embodiments of the present disclosure, the quantum key distribution method may further include generating, by the quantum security key management device, the system private key by using a random number generated by a quantum noise source, identifier information of a quantum key distribution system, and timestamp information.
Consistent with some embodiments of the present disclosure, the splitting, by a quantum security key management device, an identity-based system private key into a plurality of system sub-private keys may be implemented by using a threshold secret sharing mechanism based on Lagrange interpolation.
Consistent with some embodiments of the present disclosure, the reconstructing, by the first quantum security key distribution device of the requester, an identity-based authorized private key based on the authorized sub-private keys may be implemented by using a threshold secret sharing mechanism based on Lagrange interpolation.
Another aspect of the present disclosure is directed to a quantum key distribution apparatus. The apparatus includes a private key request receiver unit that receives a request for acquiring an authorized private key from a first quantum security key distribution device of a requester, the request at least carrying identifier information of the requester, a private key request forwarding unit that forwards the request to a predetermined number of second quantum security key distribution devices, an authorized sub-private key sharing unit that generates a plurality of authorized sub-private keys based on the identity of the requester and a plurality of system sub-private keys and that shares the authorized sub-private keys with the first quantum security key distribution device of the requester, and an authorized private key reconstructing unit that reconstructs an identity-based authorized private key based on the authorized sub-private keys.
Another aspect of the present disclosure is directed to a non-transitory computer readable medium storing one or more programs. The one or more programs comprises instructions which, when executed by a computer system including a quantum security key service device and a first quantum security key distribution device, cause the computer system to perform a method comprising: receiving, by the quantum security key service device, a request for acquiring an authorized private key from the first quantum security key distribution device of a requester, the request at least carrying identifier information of the requester, forwarding, by the quantum security key service device, the request to a predetermined number of second quantum security key distribution devices, receiving, by the first quantum security key distribution device of the requester, a plurality of authorized sub-private keys generated, by the predetermined number of second quantum security key distribution devices, based on the identifier information of the requester and a plurality of system sub-private keys, and reconstructing, by the first quantum security key distribution device of the requester, an identity-based authorized private key based on the authorized sub-private keys.
Another aspect of the present disclosure is directed to a non-transitory computer readable medium storing one or more programs. The one or more programs comprising instructions which, when executed by a computer system including a quantum security key management device, a quantum security key service device, and a first quantum security key distribution device, cause the computer system to perform a method comprising: splitting, by the quantum security key management device, a system private key into a plurality of system sub-private keys, distributing, by the quantum security key management device, the plurality of system sub-private keys to a corresponding number of quantum security key distribution devices, receiving, by the quantum security key service device, a request for acquiring an authorized private key from the first quantum security key distribution device of a requester, the request at least carrying identifier information of the requester, forwarding, by the quantum security key service device, the request to a predetermined number of second quantum security key distribution devices of the corresponding number of quantum security key distribution devices, receiving, by the first quantum security key distribution device, a plurality of authorized sub-private keys generated, by the predetermined number of second quantum security key distribution devices, based on the identifier information of the requester and a plurality of system sub-private keys, and reconstructing, by the first quantum security key distribution device of the requester, an identity-based authorized private key based on the authorized sub-private keys.
Additional features and advantages of the present disclosure will be set forth in part in the following detailed description, and in part will be obvious from the description, or may be learned by practice of the present disclosure. The features and advantages of the present disclosure will be realized and attained by means of the elements and combinations particularly pointed out in the appended claims.
It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only, and are not restrictive of the invention, as claimed.
BRIEF DESCRIPTION OF THE DRAWINGS
The accompanying drawings, which constitute a part of this specification, illustrate several embodiments and, together with the description, serve to explain the disclosed principles.
FIG. 1 is an exemplary cloud computing secured key management system in the prior art.
FIG. 2 is a graphical illustration of a quantum key distribution system, according to an exemplary embodiment.
FIG. 3 is a graphical illustration of another quantum key distribution system, according to another exemplary embodiment.
FIG. 4 is a block diagram illustrating a quantum key distribution system, according to a further exemplary embodiment.
FIG. 5 is a flow diagram illustrating a quantum key distribution method, according to an exemplary embodiment.
FIG. 6 is a flow diagram illustrating a quantum key distribution method, according to another exemplary embodiment.
FIG. 7 is a block diagram illustrating a quantum key distribution apparatus, according to an exemplary embodiment.
DETAILED DESCRIPTION
Reference will now be made in detail to exemplary embodiments, examples of which are illustrated in the accompanying drawings. The following description refers to the accompanying drawings in which the same numbers in different drawings represent the same or similar elements unless otherwise represented. The implementations set forth in the following description of exemplary embodiments consistent with the present invention do not represent all implementations consistent with the invention. Instead, they are merely examples of systems and methods consistent with aspects related to the invention as recited in the appended claims.
Consistent with some embodiments of the present disclosure, a quantum key distribution system is provided. The quantum key distribution system provided in this example includes: a quantum security key management (hereinafter referred to as QSKM) device, a plurality of quantum security key distribution (hereinafter referred to as QSKD) devices, a quantum security key service (hereinafter referred to as
CROSS REFERENCE TO RELATED APPLICATION
This application is a continuation of Ser. No. 14/993,643 filed Jan. 12, 2016, which based upon and claims priority to Chinese Application No. 201510033128.2, filed Jan. 22, 2015, both of which are incorporated herein by reference in their entireties.
TECHNICAL FIELD
The present application relates to quantum key technologies, in particular to methods, apparatus, and systems for quantum key distribution.
BACKGROUND
With development of computers and network technologies, systems providing various services for users emerge, including, for example, cloud computing systems that provide applications, data and IT services for users. In such systems, to ensure security of stored static data and generated dynamic data, it is necessary to encrypt the data with an encryption algorithm. For example, in a cloud computing environment, two data encryption modes are typically used: a first encryption mode based on certificate authentication and a second encryption mode based on cloud computing key management.
The basic principle of the certificate-based encryption authentication mode is as follows: a server in the system controls and saves keys by itself; when encrypting and storing the static data, the server uses symmetric keys to encrypt the data, and then uses a digital certificate to encrypt the symmetric keys (i.e., using a public key to encrypt the symmetric keys) and stores the encrypted data; when reading the data, the server or another server first uses a private key to decrypt the symmetric keys and then uses the decrypted symmetric keys to decrypt the data.
Compared with the certificate-based encryption authentication mode, the encryption mode that uses a cloud computing key management system is more widely applied to cloud computing environments, and is also the foundation of the security of cloud data.
FIG. 1 is an exemplary cloud computing key management system. The cloud computing key management system includes two parts, i.e., a cloud computing key client end and a cloud computing key management service end. The cloud computing key client end resides in a cloud computing server and is responsible for providing a key service for cloud computing applications in the cloud computing server. The cloud computing key client end uses a standard key management protocol to apply for management services such as key generation, key recovery and key update to the cloud computing key management service end. The cloud computing key management service end applies for corresponding services to a symmetric password management server according to a service application type, and then returns a key service operation result to the cloud computing key client end, and may also act on behalf of the cloud computing key client end to apply for the corresponding services to a digital certificate center.
Because both modes use classical cryptography based on computational complexity, they can potentially be cracked in light of the emergence of cloud computing, quantum computing, and other computing technologies. In addition, for the first mode, the encrypted key must be kept safe. Once lost or damaged, the key or data cannot be recovered. For the second mode, although handing over the key to the system for central management improves security, administrators of the key management server, who have higher operation permissions, can access user data and keys, may give away the keys and user confidential information.
SUMMARY
One aspect of the present disclosure is directed to a quantum key distribution system. The quantum key distribution system includes a quantum security key management device, a plurality of quantum security key distribution devices connected with the quantum security key management device, and a quantum security key service device connected with the quantum security key management device and the plurality of quantum security key distribution devices. The quantum security key management device splits an identity-based system private key into a plurality of system sub-private keys, and distributes the plurality of system sub-private keys to a corresponding number of the quantum security key distribution devices. The quantum security key service device forwards a request for acquiring an authorized private key from a first quantum security key distribution device of the plurality of quantum security key distribution devices to a predetermined number of second quantum security key distribution devices of quantum security key distribution devices. The predetermined number of second quantum security key distribution devices each generate an identity-based authorized sub-private key from the system sub-private key. The first quantum security key distribution device acquires, from the predetermined number of second quantum security key distribution devices, the identity-based authorized sub-private keys, and reconstructs an identity-based authorized private key based on the identity-based authorized sub-private keys.
Another aspect of the present disclosure is directed to a quantum key distribution method. The quantum key distribution method includes receiving, by a quantum security key service device, a request for acquiring an authorized private key from a first quantum security key distribution device of a requester, the request at least carrying identifier information of the requester, forwarding, by the quantum security key service device, the request to a predetermined number of second quantum security key distribution devices, receiving, by the first quantum security key distribution device of the requester, a plurality of authorized sub-private keys generated, by the predetermined number of second quantum security key distribution devices, based on the identifier information of the requester and a plurality of system sub-private keys, and reconstructing, by the first quantum security key distribution device of the requester, an identity-based authorized private key based on the authorized sub-private keys.
Consistent with some embodiments of the present disclosure, the reconstructing, by the first quantum security key distribution device of the requester, the identity-based authorized private key based on the authorized sub-private keys includes reconstructing, by the first quantum security key distribution device of the requester, the identity-based authorized private key may be implemented by using a threshold secret sharing mechanism.
Consistent with some embodiments of the present disclosure, the quantum key distribution method may further include, before receiving the request by the quantum security key service device, splitting, by a quantum security key management device, an identity-based system private key into the plurality of system sub-private keys by using the threshold secret sharing mechanism, and sharing, by the quantum security key management device, the plurality of system sub-private keys with a corresponding number of quantum security key distribution devices.
Another aspect of the present disclosure is directed to another quantum key distribution method. The quantum key distribution method include splitting, by a quantum security key management device, an identity-based system private key into a plurality of system sub-private keys, distributing, by the quantum security key management device, the plurality of system sub-private keys to a corresponding number of quantum security key distribution devices, receiving, by a quantum security key service device, a request for acquiring an authorized private key from a first quantum security key distribution device of a requester, the request at least carrying identifier information of the requester, forwarding, by the quantum security key service device, the request to a predetermined number of second quantum security key distribution devices of the corresponding number of quantum security key distribution devices, receiving, by the first quantum security key distribution device, a plurality of authorized sub-private keys generated, by the predetermined number of second quantum security key distribution devices, based on the identifier information of the requester and a plurality of system sub-private keys, and reconstructing, by the first quantum security key distribution device of the requester, an identity-based authorized private key based on the authorized sub-private keys.
Consistent with some embodiments of the present disclosure, the quantum key distribution method may further include generating, by the quantum security key management device, the system private key by using a random number generated by a quantum noise source, identifier information of a quantum key distribution system, and timestamp information.
Consistent with some embodiments of the present disclosure, the splitting, by a quantum security key management device, an identity-based system private key into a plurality of system sub-private keys may be implemented by using a threshold secret sharing mechanism based on Lagrange interpolation.
Consistent with some embodiments of the present disclosure, the reconstructing, by the first quantum security key distribution device of the requester, an identity-based authorized private key based on the authorized sub-private keys may be implemented by using a threshold secret sharing mechanism based on Lagrange interpolation.
Another aspect of the present disclosure is directed to a quantum key distribution apparatus. The apparatus includes a private key request receiver unit that receives a request for acquiring an authorized private key from a first quantum security key distribution device of a requester, the request at least carrying identifier information of the requester, a private key request forwarding unit that forwards the request to a predetermined number of second quantum security key distribution devices, an authorized sub-private key sharing unit that generates a plurality of authorized sub-private keys based on the identity of the requester and a plurality of system sub-private keys and that shares the authorized sub-private keys with the first quantum security key distribution device of the requester, and an authorized private key reconstructing unit that reconstructs an identity-based authorized private key based on the authorized sub-private keys.
Another aspect of the present disclosure is directed to a non-transitory computer readable medium storing one or more programs. The one or more programs comprises instructions which, when executed by a computer system including a quantum security key service device and a first quantum security key distribution device, cause the computer system to perform a method comprising: receiving, by the quantum security key service device, a request for acquiring an authorized private key from the first quantum security key distribution device of a requester, the request at least carrying identifier information of the requester, forwarding, by the quantum security key service device, the request to a predetermined number of second quantum security key distribution devices, receiving, by the first quantum security key distribution device of the requester, a plurality of authorized sub-private keys generated, by the predetermined number of second quantum security key distribution devices, based on the identifier information of the requester and a plurality of system sub-private keys, and reconstructing, by the first quantum security key distribution device of the requester, an identity-based authorized private key based on the authorized sub-private keys.
Another aspect of the present disclosure is directed to a non-transitory computer readable medium storing one or more programs. The one or more programs comprising instructions which, when executed by a computer system including a quantum security key management device, a quantum security key service device, and a first quantum security key distribution device, cause the computer system to perform a method comprising: splitting, by the quantum security key management device, a system private key into a plurality of system sub-private keys, distributing, by the quantum security key management device, the plurality of system sub-private keys to a corresponding number of quantum security key distribution devices, receiving, by the quantum security key service device, a request for acquiring an authorized private key from the first quantum security key distribution device of a requester, the request at least carrying identifier information of the requester, forwarding, by the quantum security key service device, the request to a predetermined number of second quantum security key distribution devices of the corresponding number of quantum security key distribution devices, receiving, by the first quantum security key distribution device, a plurality of authorized sub-private keys generated, by the predetermined number of second quantum security key distribution devices, based on the identifier information of the requester and a plurality of system sub-private keys, and reconstructing, by the first quantum security key distribution device of the requester, an identity-based authorized private key based on the authorized sub-private keys.
Additional features and advantages of the present disclosure will be set forth in part in the following detailed description, and in part will be obvious from the description, or may be learned by practice of the present disclosure. The features and advantages of the present disclosure will be realized and attained by means of the elements and combinations particularly pointed out in the appended claims.
It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only, and are not restrictive of the invention, as claimed.
BRIEF DESCRIPTION OF THE DRAWINGS
The accompanying drawings, which constitute a part of this specification, illustrate several embodiments and, together with the description, serve to explain the disclosed principles.
FIG. 1 is an exemplary cloud computing secured key management system in the prior art.
FIG. 2 is a graphical illustration of a quantum key distribution system, according to an exemplary embodiment.
FIG. 3 is a graphical illustration of another quantum key distribution system, according to another exemplary embodiment.
FIG. 4 is a block diagram illustrating a quantum key distribution system, according to a further exemplary embodiment.
FIG. 5 is a flow diagram illustrating a quantum key distribution method, according to an exemplary embodiment.
FIG. 6 is a flow diagram illustrating a quantum key distribution method, according to another exemplary embodiment.
FIG. 7 is a block diagram illustrating a quantum key distribution apparatus, according to an exemplary embodiment.
DETAILED DESCRIPTION
Reference will now be made in detail to exemplary embodiments, examples of which are illustrated in the accompanying drawings. The following description refers to the accompanying drawings in which the same numbers in different drawings represent the same or similar elements unless otherwise represented. The implementations set forth in the following description of exemplary embodiments consistent with the present invention do not represent all implementations consistent with the invention. Instead, they are merely examples of systems and methods consistent with aspects related to the invention as recited in the appended claims.
Consistent with some embodiments of the present disclosure, a quantum key distribution system is provided. The quantum key distribution system provided in this example includes: a quantum security key management (hereinafter referred to as QSKM) device, a plurality of quantum security key distribution (hereinafter referred to as QSKD) devices, a quantum security key service (hereinafter referred to as QSKS) device, and data devices used as a source end and a destination end of secured data transmission. The QSKM device is connected with the plurality of QSKD devices and the QSKS device, each QSKD device is connected at least with a number of other QSKD devices, and the data device is connected at least with one QSKD device. The QSKM, QSKD, and QSKS devices can be implemented by computers or servers with one or more processors and memories. The memory may be a non-transitory computer-readable storing medium storing instructions, that when executed by the processor, perform functions described below.
In some embodiments, one or more of the plurality of QSKD devices may include the QSKS device. In other words, functions of the QSKD device and the QSKS device may be integrated into one physical device, and may also be implemented by different physical devices respectively.
In addition, in order to meet the requirement of long distance transmission of a quantum key, the quantum key distribution system may further include routing devices configured to relay the quantum key and forward data, so that the QSKM device, the QSKD device and the QSKS device can be interconnected through the routing devices.
FIG. 2 is a graphical illustration of a quantum key distribution system, according to an exemplary embodiment. In this embodiment, two QSKM devices standby for each other are included, functions of the QSKD and the QSKS are integrated into one physical device (represented by QSKD/QSKS), and the QSKM device and the QSKD/QSKS device are connected with each other through a routing device. Although the QSKD and QSKS are integrated into one physical device in some exemplary implementations, the functions implemented by the QSKD and QSKS may be different. Specific functions of the QSKM device, the QSKD device and the QSKM device and their coordination with each other are described from the perspective of functional division.
FIG. 3 is a graphical illustration of another quantum key distribution system, according to an exemplary embodiment. In this embodiment, some QSKD devices are owned by some cloud users and some QSKD devices are rented by some cloud users.
FIG. 4 is a block diagram illustrating a quantum key distribution system 100 shown in FIGS. 2 and 3 , according to an exemplary embodiment. The system 100 includes a number of components, some of which may be optional. The system 100 includes a QSKM device 101 , a plurality of QSKD devices 102 , a QSKS device 103 , a data device 104 , and a routing device 105 all connected through a network 106 . The plurality of QSKD devices 102 include a first QSKD device 112 and a plurality of second QSKD devices 122 . The first QSKD device and the plurality of second QSKD devices may be structurally and functionally similar or identical devices. The grouping/classification of these QSKD devices is for illustration purposes.
In some embodiments, the QSKD device and the QSKS device are integrated in one physical device, and the QSKM device and the QSKD/QSKS device are connected with one another through the routing device. In some embodiments, the system 100 includes two QSKM devices, each being a backup of the other.
In some embodiments, the QSKM device is a manager of the quantum key distribution system, and the system may include one or more QSKM devices to achieve data synchronization and realize centralized management of the system. The QSKM device is responsible for splitting an identity-based system private key into a plurality of system sub-private keys in accordance with a threshold secret sharing mechanism, and respectively distributing the plurality of system sub-private keys to a corresponding number of the QSKD devices in accordance with quantum key agreement.
In some embodiments, the identity-based system private key may be preset in the QSKM device, or may be generated by the QSKM device as follows: the identity-based system private key is generated in accordance with a random number generated by a quantum noise source, identifier information of the system and timestamp information. The reason why the random number generated by the quantum noise source is introduced is to increase security of the system private key by using random characteristics of quantum noise. For example, the system private key can be generated through Formula 1:
S=S r â( BN ID /expire_time)ââFormula 1
in which S r is the random number generated by the quantum noise source, BN ID is the identifier information of the system, expire_time is the timestamp information, and S is the identity-based system private key. The QSKM device can store the system private key (also called system key) in a system key database, which is only accessible to the QSKM device.
In some embodiments, the QSKM device splits the identity-based system private key preset or generated as described above into a plurality of system sub-private keys in accordance with a threshold secret sharing mechanism, and respectively distributes the plurality of system sub-private keys to a corresponding number of the QSKD devices in accordance with a quantum key agreement.
The reason why, in some embodiments, the identity-based system private key is split into a plurality of (at least two) identity-based system sub-private keys and distributed to a corresponding number of QSKD devices is to achieve distributed management of keys, and when the first QSKD device (or any other QSKD device) applies for acquiring an authorized private key, a predetermined number of sub-private keys under decentralized management can be combined. In this way, abuse of power caused by excessive centralization of key management rights can be avoided, thus effectively reducing the possibility that the administrator acquires and maliciously gives away user data. Moreover, in the event of key damage, it is also feasible to reacquire the predetermined number of sub-private keys and reconstructs the key.
In some embodiments, the QSKM device splits the system private key into a plurality of identity-based system sub-private keys by using a threshold secret sharing mechanism. The threshold secret sharing mechanism is known as a (n, t) threshold secret sharing mechanism, and the mechanism is defined as follows: a secret S is distributed to n members for sharing through a secret sharing algorithm, so that each member holds a secret sub (a part of the secret S), and the following two conditions are met:
(1) any number of members, the number of which is no less than t, can reconstruct the secret S with the secret subs they hold; and
(2) any number of members, the number of which is less than t, cannot reconstruct the secret S with the secret subs they hold.
There are many schemes for realizing the aforementioned secret sharing mechanism, for example, a threshold secret sharing scheme based on Lagrange interpolation, or a Blakley threshold secret sharing scheme based on multi-dimensional space, and each scheme has its own secret sharing algorithm and a secret reconstruction algorithm corresponding thereto. These schemes are also called secret sharing mechanisms.
In some embodiments, if the system includes n QSKD devices, the QSKM device can split the system private key into n system sub-private keys, according to the preset t value.
In some embodiments, the threshold secret sharing mechanism based on Lagrange interpolation is used. The QSKM device can use the secret sharing algorithm shown in Formula 2 and Formula 3 to split the identity-based system private key S into n sub-private keys S i , in which a prime number Ï in Formula 2 is greater than the total number n of QSKD devices that participate into private key management and is greater than the maximum value that the system private key S may be set, α 0 =h(0)=S, and α tâ1 , . . . , α 1 are random coefficients generated by quantum noise; all the coefficients should be kept secured and are destroyed after n sub key shares s i are generated.
h ( x )=α tâ1 x tâ1 + . . . +α 1 x+α 0 mod ÏââFormula 2
s i =h ( x i )mod Ï x i =i,i= 1, . . . , n ââFormula 3
In this example, the identity-based system private key is split into a corresponding number in accordance with the number n of the QSKD devices, and in some embodiments, distributed management of keys can also be realized as long as the system private key is split into a plurality of system sub-private keys.
In some embodiments, the QSKM device is further configured to, after the split, respectively distribute the plurality of system sub-private keys to a corresponding number of QSKD devices in accordance with the quantum key agreement. If the QSKM obtains n system sub-private keys S 1 , S 2 , . . . S n through splitting, the QSKM shares the S 1 , S 2 , . . . S n with QSKD 1 , QSKD 2 , . . . QSKD n respectively in accordance with the quantum key agreement, e.g. a BB84 protocol.
In some embodiments, in consideration of light loss and bit error rate, in order to ensure that the QSKM device and the QSKD devices can correctly share each system sub-private key, when the S 1 , S 2 , . . . S n are converted to a quantum state for key agreement, a quantum key agreement of redundancy transmission or on-demand retransmission can be used.
The redundancy transmission refers to transmitting the same bit over a certain proportion, that is, transmitting the same bit multiple times, in which the proportion can be determined based on a bit error rate, a transmission distance, a rate of loss and other factors; the on-demand retransmission refers to that a receiver device can know whether there are unreceived photons (for example, effective detection cannot be carried out due to attenuation) through a synchronization mechanism, and can judge which of the received quantum states are wrong by comparing measurement bases of classical channels. The receiver device can send the non-receiving and wrong quantum state information to the QSKM device, so that the QSKM device can repeatedly transmit particular quantum states one or more times in accordance with demands of the receiver device. By using the two methods above, the receiver device may successfully receive the same bit multiple times, and can keep 1 bit in this situation.
In some embodiments, it is also possible to use another method for the quantum key agreement, as long as the method can ensure that the QSKM device and each QSKD device can share each system sub-private key correctly.
In some embodiments, as a manager of the system, the QSKM device needs to communicate with each device of the system so as to realize necessary management functions. In order to increase security of data transmission and facilitate verification of the devices in the system on the identity of the manager, the QSKM device may be further configured to generate an identity-based private key thereof and a corresponding signature certificate by using a random number generated by a quantum noise source, identifier information and timestamp information. The certificate includes identifier information of the QSKM (e.g., ID of the QSKM device), and signature information using the private key thereof. For example, the system may generate an identity-based private key of the QSKM by using Formula 4.
QSKM PK =QSKM r â(QSKM ID /expire_time)ââFormula 4
in which QSKM ID is the identifier information of the QSKM, QSKM r is the random number generated by the QSKM by using a quantum noise source, expire_time is timestamp information, and QSKM PK is the identity-based private key of the QSKM.
The QSKM device can store the identity-based private key and the corresponding signature certificate into its own key/certificate database. As this example uses an identity-based public key encryption technology, identifier information (for example, ID) and the certificate are open through the whole network, while the identity-based private key is confidential and is generally accessible to a device or user that generates or owns the private key and accessible to authorized devices.
In addition, in order to facilitate management and enable generation of the identity-based private key for transmitting secured data, the devices in the quantum key distribution system can have identifier information (for example, ID) that can be distinguished from other devices, and the identifier information may be preset in each device and may also be uniformly assigned and managed by the manager QSKM in the system. In one embodiment, the QSKM device is further configured to, in accordance with a registration request received from the QSKD device or the QSKS device, generate identifier information for the QSKD device or the QSKS device, and issue the identifier information to the corresponding device. If the QSKD device and the QSKS device are integrated into the same physical device, the QSKM may issue one ID for the QSKD device and the QSKS device and may also issue two IDs for the QSKD device and the QSKS device respectively.
In some embodiments, one main function of the QSKS device in the system is forwarding a request for acquiring an authorized private key. When the data device in the system intends to perform data encryption storage or secured data transmission, the QSKD device (e.g., calling it the first QSKD device for illustration purpose) connected therewith can send the request for acquiring an authorized private key to the QSKS device. The request can carry identifier information (for example, ID) of the first QSKD device, and the QSKS device forwards the request to the predetermined number of QSKD devices (e.g., calling them the second QSKD devices for illustration purpose). For example, by using a (n, t) threshold mechanism, the system private key is shared by n QSKD devices, the QSKS device forwards the request for acquiring an authorized private key to any t ones of the n QSKD devices. The t QSKD devices (i.e., the second QSKD devices) and the requester (i.e., the first QSKD device) are directly connected with each other or connected with each other through a routing device having a quantum key relaying function.
In some embodiments, the first QSKD device is configured to acquire, from the t second QSKD devices, identity-based authorized sub-private keys generated in accordance with the plurality of system sub-private keys in accordance with the quantum key agreement, and reconstruct an identity-based authorized private key by using the threshold secret sharing mechanism.
In some embodiments, when a QSKD device is not the requester of the authorized private key, the QSKD device (i.e., a second QSKD devices), after receiving the request for acquiring an authorized private key forwarded by the QSKS device, generates an identity-based authorized sub-private key in accordance with identifier information of the requester of the authorized private key, timestamp information and the system sub-private key that the QSKM device distributes to it. For example, an identity-based authorized sub-private key can be generated by using Formula 5, in which s i
r (value of r is in a range of 1-t) is the system sub-private key, U ID is the identifier information of the first QSKD device that serves as the requester of the authorized private key, expire_time is timestamp information, and S ur is the identity-based authorized sub-private key based on the identifier information of the requester.
S ur =s i
r ( u ID /expire_time)ââFormula 5
In some embodiments, when a QSKD device is a requester of the authorized private key (i.e., the first QSKD device), the QSKD device is configured to acquire, from other QSKD devices, a predetermined number (e.g., t) of identity-based authorized sub-private keys in accordance with quantum key agreement, and reconstruct the identity-based authorized private key by using the threshold secret sharing mechanism. The identifier information of the requester and the identifier information of the first QSKD device are interchangeably used in this application. They can be the same or different. When they are different, they are interchangeable for the purpose in this application.
In some embodiments, after t second QSKD devices generate the authorized sub-private keys based on the identity of the requester as described above, they share the authorized sub-private keys with the requester (i.e. the first QSKD device), respectively in accordance with the quantum key agreement, so that the requester acquires t identity-based system sub-private keys. It is also feasible to use redundancy transmission or on-demand retransmission, so as to ensure that the second QSKD devices correctly share the generated authorized sub-private keys with the first QSKD device.
In some embodiments, when the first QSKD device reconstructs the identity-based authorized private key, a secret reconstruction algorithm corresponding to the secret sharing algorithm used by the QSKM device to split the identity-based system private key is adopted. In one example, the QSKM adopts a secret sharing algorithm of a threshold secret sharing mechanism based on Lagrange interpolation, and corresponding thereto, the requester (i.e. the first QSKD device) adopts a reconstruction algorithm of the threshold secret sharing mechanism based on Lagrange interpolation to reconstruct the identity-based authorized private key.
In some embodiments, in accordance with t S ur acquired from t second QSKD devices, which is equivalent to knowing coordinates of any t points, i.e., (x i1 , S u1 ), (x i2 , s u2 ) . . . (x it , S ut ), a corresponding f(x) can be obtained by using a Lagrange interpolation formula, and the reconstructed authorized private key S u =f(0). Based on the foregoing principle, the reconstructed identity-based authorized private key S u can be obtained by using Formula 6 and Formula 7.
â¢
S
=
â
r
=
1
t
â¢
â¢
(
â
j
â
r
,
j
=
1
t
â¢
â¢
x
-
x
i
j
x
i
r
-
x
i
j
)
â¢
s
i
r
Formula
â¢
â¢
6
s
u
=
s
â¡
(
u
ID
/
expire_time
)
=
â
r
=
1
t
â¢
â¢
(
â
j
â
r
,
j
=
1
t
â¢
â¢
x
-
x
i
j
x
i
r
-
x
i
j
)
â¢
s
i
r
â¡
(
u
ID
/
expire_time
)
Formula
â¢
â¢
7
The requester (i.e. the first QSKD device) can be further configured to generate an identity-based signature certificate in accordance with the reconstructed authorized private key, so that the requester acquires the identity-based authorized private key and the certificate.
In some embodiments, as the QSKS device, the QSKD device and the QSKM device may communicate with one another because of management demands inside the system, and in order to ensure security of the communication, the QSKS device and the QSKD device may also generate their own identity-based private keys.
In some embodiments, the QSKD devices and the QSKS device are further configured to: acquire a random number generated by a quantum noise source and timestamp information from the QSKM device in accordance with the quantum key agreement, and generate identity-based private keys in accordance with the foregoing information and their own identifier information. For example, the QSKD devices and the QSKS device can generate their own identity-based private keys by using Formula 8, in which U r is a random number generated by the QSKM device for the QSKD devices or the QSKS device by using the quantum noise source, expire_time is timestamp information, and U ID is identifier information (for example, ID) of the QSKD devices or the QSKS device, in which the identifier information may be preset or may be issued thereto by the QSKM device.
U PK =U r â( U ID /expire_time)ââFormula 8
In one embodiment, the QSKM device can also compute U Pk for the QSKD devices or the QSKS device by using Formula 8, and it is also feasible by the QSKM device to use the U Pk as a shared key between the QSKM device and the QSKD devices or the QSKS device to perform secured data transmission therebetween.
In some embodiments, the quantum key distribution system is applied to a cloud network architecture, including a cloud backbone network (data center) and a cloud user.
For example, the quantum key distribution system can be deployed in a cloud backbone network (e.g., cloud computing data center), the data device refers to a server of the cloud computing data center, and the QSKM device inside the system can distribute the plurality of system sub-private keys to QSKD devices inside the system in advance. When a certain server of the cloud computing data center needs to acquire an identity-based authorized private key before data storage or transmission, a QSKD device connected therewith can acquire a predetermined number of identity-based authorized sub-private keys from other QSKD devices, reconstruct the identity-based authorized private key by using a threshold secret sharing mechanism and generate a signature certificate.
In another example, the system further includes a cloud user that accesses the system, and the cloud user can have his/her own QSKD device or rent a QSKD device in the system.
For the cloud user that has a QSKD device, his/her QSKD device is connected with one routing device of the cloud computing data center. The QSKD device of the cloud user is configured to send a request for acquiring an authorized private key to a QSKS device of the cloud computing data center, acquire a predetermined number of identity-based authorized sub-private keys from QSKD devices of the cloud computing center in accordance with a quantum key agreement, reconstruct an identity-based authorized private key by using a threshold secret sharing mechanism, and generate an identity-based signature certificate.
When the QSKD device of the cloud user sends the request for acquiring an authorized private key to the QSKS device of the cloud computing data center. The request can carry identifier information of the QSKD device and/or the cloud user that uses the QSKD device. The identifier information can be registered to a QSKM device of the cloud computing data center or issued by the QSKM device.
For the cloud user that rents a QSKD device of the cloud computing data center, a request for acquiring an authorized private key can be sent to a QSKS device of the cloud computing data center. The QSKS device is configured to forward the request to a predetermined number of QSKD devices connected therewith. The QSKD devices share identity-based authorized sub-private keys with the rented QSKD device in accordance with a quantum key agreement. The rented QSKD device then reconstructs an identity-based authorized private key. The QSKD device can also generates an identity-based signature certificate. The QSKD device may store the key and certificate locally to allow the cloud user to access and use. Similar to the cloud user that has a QSKD device, identifier information of the cloud user that rents a QSKD device can be issued by a QSKM device of the cloud computing data center.
In some embodiments, the quantum key distribution system provided by combining a quantum key distribution technology with a threshold secret sharing mechanism, not only can effectively reduce the risk that the classical cryptography is cracked, but also can decentralize management rights due to distributed management over the key, thus effectively reducing the possibility that an administrator acquires and maliciously gives away user data and further guaranteeing security of the user data. Especially when the system is applied to a cloud computing environment, as a user private key is generated by a cloud backbone network in a distributed manner and is finally synthesized by a QSKD device of the user or a QSKD device trusted by the user, the trust problems of cloud users for cloud providers can be solved, and after an encrypted key of user data is lost, the key can be retrieved from the cloud backbone network, so as to recover the user data.
FIG. 5 is a flow diagram illustrating a quantum key distribution method 200 , according to an exemplary embodiment. Some steps may be optional.
At step 201 , a QSKS device receives a request for acquiring an authorized private key from a QSKD device of a requester (e.g., called a first QSKD device for illustration purpose), the request carrying identifier information of the first QSKD device or the requester (assuming the requester for this example).
At step 202 , the QSKS device forwards the request to a predetermined number of QSKD devices (e.g., called second QSKD devices for illustration purpose).
At step 203 , the predetermined number of second QSKD devices generate a plurality of authorized sub-private keys based on the identifier information of the requester and from a plurality of system sub-private keys.
In some embodiments, after a second QSKD device receives the request forwarded by the QSKS device, the second QSKD device first verifies validity of the identity of the requester through the QSKM device; if the requester does not pass the identity verification, execution of the method is ended. The second QSKD devices generate the authorized sub-private keys in accordance with the identifier information of the requester, the pre-acquired system sub-private keys and timestamp information. For example, the authorized sub-private keys are generated by using the following formula:
S ur =s i
r (<
CLAIMS
Claims ( 20 )
What is claimed is:
1. A quantum key distribution method, comprising:
transmitting, by a first quantum security key distribution device of a requester, a request for acquiring an identity-based authorized private key to a quantum security key service device, wherein the request includes identifier information of the requester and is forwarded by the quantum security key service device to a predetermined number of second quantum security key distribution devices;
receiving, by the first quantum security key distribution device, a plurality of identity-based authorized sub-private keys generated, by the predetermined number of second quantum security key distribution devices, based on the identifier information and a plurality of system sub-private keys that have been split from an identity-based system private key using a threshold secret sharing mechanism and that have been shared with a corresponding number of quantum key distribution devices; and
reconstructing, by the first quantum security key distribution device of the requester, an identity-based authorized private key based on the authorized sub-private keys.
2. The quantum key distribution method of claim 1 , wherein at least one of the plurality of second quantum security key distribution devices includes the quantum security key service device.
3. The quantum key distribution method of claim 1 , wherein the identity-based authorized private key is reconstructed by using a threshold secret sharing mechanism.
4. The quantum key distribution method of claim 1 , wherein the plurality of system sub-private keys have been shared with the corresponding number of second quantum security key distribution devices in accordance with the quantum key agreement, the quantum key agreement being a redundancy transmission quantum key agreement or an on-demand retransmission quantum key agreement.
5. The quantum key distribution method of claim 4 , wherein the identity-based system private key is generated based on a random number generated by a quantum noise source, identifier information of a quantum key distribution system, and timestamp information.
6. The quantum key distribution method of claim 5 , wherein the identity-based system private key was generated by a quantum security key management based on a formula:
S=S r â( BN ID /expire_time)
wherein Sr is the random number generated by the quantum noise source, BN ID is the identifier information of the quantum key distribution system, expire_time is the timestamp information, and S is the identity-based system private key.
7. The quantum key distribution method of claim 1 , wherein the identity-based system private key is generated based on a random number generated by a quantum noise source, identifier information of a quantum key distribution system, and timestamp information.
8. The quantum key distribution method of claim 1 , further comprising:
sending a registration request to a quantum security key management device,
receiving a random number generated by a quantum noise source and timestamp information, wherein the random number and timestamp information was sent from a quantum security key management which:
received the registration request,
generated identifier information in response to the registration request, and
distributed the generated identifier information; and
generating an identity-based private key in accordance with the identifier information, the random number, and the timestamp information.
9. The quantum key distribution method of claim 1 , wherein the identifier information of the requester included in the transmitted request is verified as valid by a quantum security key management device.
10. The quantum key distribution method of claim 1 , wherein the plurality of identity-based authorized sub-private keys are generated based on timestamp information.
11. The quantum key distribution method of claim 10 , wherein the identity-based authorized sub-private keys are generated through a formula:
S ur =s i
r ( u ID /expire_time)
wherein s i
r is a system sub-private key, U ID is the identifier information of the requester, expire_time is the timestamp information, and S ur is an identity-based authorized sub-private key.
12. The quantum key distribution method of claim 1 , wherein:
the plurality of system sub-private keys have been split from the system private key using the threshold secret sharing mechanism based on Lagrange interpolation; and
the identity-based authorized private key is reconstructed based on the identity-based authorized sub-private keys by using the threshold secret sharing mechanism based on Lagrange interpolation.
13. The quantum key distribution method of claim 1 , further comprising generating an identity-based signature certificate in accordance with the reconstructed identity-based authorized private key.
14. A non-transitory computer readable medium that stores a set of instructions that are executable by at least one processor of a quantum key distribution apparatus to cause the quantum key distribution apparatus to perform a method for quantum key distribution, the method comprising:
transmitting a request for acquiring an identity-based authorized private key to a quantum security key service device, wherein the request includes identifier information of the requester and is forwarded by the quantum security key service device to a predetermined number of second quantum security key distribution devices;
receiving a plurality of identity-based authorized sub-private keys generated, by the predetermined number of second quantum security key distribution devices, based on the identifier information and a plurality of system sub-private keys that have been split from an identity-based system private key using a threshold secret sharing mechanism and that have been shared with a corresponding number of quantum key distribution devices; and
reconstructing an identity-based authorized private key based on the identity-based authorized sub-private keys.
15. The non-transitory computer readable medium of claim 14 , wherein at least one of the plurality of second quantum security key distribution devices includes the quantum security key service device.
16. The non-transitory computer readable medium according to claim 14 , wherein the identity-based authorized private key is reconstructed by using a threshold secret sharing mechanism.
17. The non-transitory computer readable medium of claim 14 , wherein the plurality of system sub-private keys have been shared with the corresponding number of second quantum security key distribution devices in accordance with the quantum key agreement, the quantum key agreement being a redundancy transmission quantum key agreement or an on-demand retransmission quantum key agreement.
18. The non-transitory computer readable medium of claim 14 , wherein the identity-based system private key is generated based on a random number generated by a quantum noise source, identifier information of a quantum key distribution system, and timestamp information.
19. The non-transitory computer readable medium of claim 14 , wherein the set of instructions that are executable by at least one processor of the quantum key distribution apparatus to cause the quantum key distribution apparatus to further perform:
sending a registration request to a quantum security key management device,
receiving a random number generated by a quantum noise source and timestamp information, wherein the random number and timestamp information was sent from a quantum security key management which:
received the registration request,
generated identifier information in response to the registration request, and
distributed the generated identifier information; and
generating an identity-based private key in accordance with the identifier information, the random number, and the timestamp information.
20. A quantum key distribution apparatus, comprising:
a memory storing a set of instructions;
one or more processors configured to execute the set of instructions to cause the apparatus to perform:
transmitting, by a requester, a request for acquiring an identity-based authorized private key to a quantum security key service device, wherein the request includes identifier information of the requester and is forwarded by the quantum security key service device to a predetermined number of second quantum security key distribution devices;
receiving a plurality of identity-based authorized sub-private keys generated, by the predetermined number of second quantum security key distribution devices, based on the identifier information and a plurality of system sub-private keys that have been split from an identity-based system private key using a threshold secret sharing mechanism and that have been shared with a corresponding number of quantum key distribution devices; and
reconstructing an identity-based authorized private key based on the identity-based authorized sub-private keys.
US16/418,191
2015-01-22
2019-05-21
Method, apparatus, and system for quantum key distribution
Active
US10757083B2
( en )
Priority Applications (1)
Application Number
Priority Date
Filing Date
Title
US16/418,191
US10757083B2
( en )
2015-01-22
2019-05-21
Method, apparatus, and system for quantum key distribution
Applications Claiming Priority (5)
Application Number
Priority Date
Filing Date
Title
CN201510033128
2015-01-22
CN201510033128.2
2015-01-22
CN201510033128.2A
CN105871538B
( en )
2015-01-22
2015-01-22
Quantum key distribution system, quantum key delivering method and device
US14/993,643
US10305873B2
( en )
2015-01-22
2016-01-12
Method, apparatus, and system for quantum key distribution
US16/418,191
US10757083B2
( en )
2015-01-22
2019-05-21
Method, apparatus, and system for quantum key distribution
Related Parent Applications (1)
Application Number
Title
Priority Date
Filing Date
US14/993,643
Continuation
US10305873B2
( en )
2015-01-22
2016-01-12
Method, apparatus, and system for quantum key distribution
Publications (2)
Publication Number
Publication Date
US20190281034A1
US20190281034A1 ( en )
2019-09-12
US10757083B2
true
US10757083B2 ( en )
2020-08-25
Family
ID=56417595
Family Applications (2)
Application Number
Title
Priority Date
Filing Date
US14/993,643
Active
2037-05-13
US10305873B2
( en )
2015-01-22
2016-01-12
Method, apparatus, and system for quantum key distribution
US16/418,191
Active
US10757083B2
( en )
2015-01-22
2019-05-21
Method, apparatus, and system for quantum key distribution
Family Applications Before (1)
Application Number
Title
Priority Date
Filing Date
US14/993,643
Active
2037-05-13
US10305873B2
( en )
2015-01-22
2016-01-12
Method, apparatus, and system for quantum key distribution
Country Status (7)
Country
Link
US
( 2 )
US10305873B2
( en )
EP
( 1 )
EP3248310B1
( en )
JP
( 2 )
JP6680791B2
( en )
KR
( 1 )
KR102738037B1
( en )
CN
( 1 )
CN105871538B
( en )
TW
( 1 )
TW201628369A
( en )
WO
( 1 )
WO2016118359A1
( en )
Cited By (2)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20230099471A1
( en )
*
2021-09-30
2023-03-30
Juniper Networks, Inc.
Delayed quantum key-distribution
US12088704B1
( en )
2022-03-30
2024-09-10
Wells Fargo Bank, N.A.
Systems and methods for quantum entangled random key exchange
Families Citing this family (83)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
CN106161402B
( en )
*
2015-04-22
2019-07-16
é¿éå·´å·´é墿§è¡æéå ¬å¸
Encryption equipment key injected system, method and device based on cloud environment
CN106470345B
( en )
2015-08-21
2020-02-14
é¿éå·´å·´é墿§è¡æéå ¬å¸
Video encryption transmission method, video decryption method, video encryption transmission device, video decryption device and video encryption transmission system
CN107086907B
( en )
2016-02-15
2020-07-07
é¿éå·´å·´é墿§è¡æéå ¬å¸
Key synchronization and packaging transfer method and device for quantum key distribution process
CN107086908B
( en )
2016-02-15
2021-07-06
é¿éå·´å·´é墿§è¡æéå ¬å¸
A kind of quantum key distribution method and device
CN107347058B
( en )
2016-05-06
2021-07-23
é¿éå·´å·´é墿§è¡æéå ¬å¸
Data encryption method, data decryption method, device and system
CN107370546B
( en )
2016-05-11
2020-06-26
é¿éå·´å·´é墿§è¡æéå ¬å¸
Eavesdropping detection method, data transmission method, device and system
CN107404461B
( en )
2016-05-19
2021-01-26
é¿éå·´å·´é墿§è¡æéå ¬å¸
Data secure transmission method, client and server method, device and system
US10476846B2
( en )
*
2016-08-05
2019-11-12
The Boeing Company
Data-at-rest (DAR) encryption for integrated storage media
CN106357396B
( en )
*
2016-09-23
2019-11-12
æµæ±ç¥å·éåç½ç»ç§ææéå ¬å¸
Digital signature method and system and quantum key card
CN107959567B
( en )
*
2016-10-14
2021-07-27
é¿éå·´å·´é墿§è¡æéå ¬å¸
Data storage method, data acquisition method, device and system
CN107959566A
( en )
2016-10-14
2018-04-24
é¿éå·´å·´é墿§è¡æéå ¬å¸
Quantal data key agreement system and quantal data cryptographic key negotiation method
CN107959656B
( en )
*
2016-10-14
2021-08-31
é¿éå·´å·´é墿§è¡æéå ¬å¸
Data security assurance system, method and device
CN112217637B
( en )
2016-11-04
2024-03-15
åä¸ºææ¯æéå ¬å¸
A quantum key relay method and device based on centralized management and control network
CN108123795B
( en )
2016-11-28
2020-01-10
广ä¸å½ç¾éåç§ææéå ¬å¸
Quantum key chip issuing method, application method, issuing platform and system
US10164778B2
( en )
2016-12-15
2018-12-25
Alibaba Group Holding Limited
Method and system for distributing attestation key and certificate in trusted computing
CN108270557B
( en )
*
2016-12-30
2021-02-19
ç§å¤§å½ç¾éåææ¯è¡ä»½æéå ¬å¸
Backbone network system based on quantum communication and relay method thereof
CN106656512B
( en )
*
2017-01-17
2019-07-09
æ¦æ±ç工大å¦
Support the SM2 digital signature generation method and system of threshold cryptography
CN106886920A
( en )
*
2017-02-16
2017-06-23
æ¹å大å¦
Based on the shared bicycle Secure Billing method that home is proved
US10454892B2
( en )
2017-02-21
2019-10-22
Bank Of America Corporation
Determining security features for external quantum-level computing processing
US10447472B2
( en )
*
2017-02-21
2019-10-15
Bank Of America Corporation
Block computing for information silo
US10824737B1
( en )
*
2017-02-22
2020-11-03
Assa Abloy Ab
Protecting data from brute force attack
CN107066893B
( en )
2017-02-28
2018-11-09
è ¾è®¯ç§æï¼æ·±å³ï¼æéå ¬å¸
The treating method and apparatus of account information in block chain
CN107086902A
( en )
*
2017-03-22
2017-08-22
å京ç工大å¦
It is a kind of that tripartite's examination ï¼ verification and the cloud storage system of file duplicate removal are supported based on dynamic threshold password
CN108667608B
( en )
2017-03-28
2021-07-27
é¿éå·´å·´é墿§è¡æéå ¬å¸
Data key protection method, device and system
CN108667773B
( en )
2017-03-30
2021-03-12
é¿éå·´å·´é墿§è¡æéå ¬å¸
Network protection system, method, device and server
CN108736981A
( en )
2017-04-19
2018-11-02
é¿éå·´å·´é墿§è¡æéå ¬å¸
It is a kind of wirelessly to throw screen method, apparatus and system
CN108133370B
( en )
*
2017-06-23
2021-07-20
广ä¸ç½éæ§è¡è¡ä»½æéå ¬å¸
A secure payment method and system based on quantum key distribution network
GB201710176D0
( en )
*
2017-06-26
2017-08-09
Nchain Holdings Ltd
Computer-implemented system and method
CN107359994A
( en )
*
2017-07-19
2017-11-17
å½å®¶çµç½å ¬å¸
The integrated encryption device that a kind of quantum cryptography blends with classical password
CN113765657B
( en )
2017-08-28
2023-10-24
åæ°å è¿ææ¯æéå ¬å¸
A key data processing method, device and server
CN109561047B
( en )
*
2017-09-26
2021-04-13
å®å¾½é®å¤©éåç§æè¡ä»½æéå ¬å¸
Encrypted data storage system and method based on key remote storage
CN111585760B
( en )
*
2017-10-27
2023-04-18
è´¢ä»éæ¯ä»ç§ææéå ¬å¸
Key retrieving method, device, terminal and readable medium
CN109842485B
( en )
*
2017-11-26
2021-07-20
æé½é¶å éåç§ææéå ¬å¸
A Centralized Quantum Key Service Network System
CN108023732B
( en )
*
2017-12-15
2020-02-14
åäº¬æ·±ææ°ç¾ç§æè¡ä»½æéå ¬å¸
Data protection method, device, equipment and storage medium
CN110290094B
( en )
2018-03-19
2022-03-11
åä¸ºææ¯æéå ¬å¸
A method and device for controlling data access authority
KR102172688B1
( en )
*
2018-06-04
2020-11-02
차보ì
The multi-function matrix hash function block chain smart block panel its system
KR102172693B1
( en )
*
2018-06-04
2020-11-02
차보ì
The Quantum code block chain of the matrix hash function the smart greed panel anti-disaster CCTV and its controlling system
KR102153317B1
( en )
*
2018-06-20
2020-09-08
ìì·ë©ì£¼ìíì¬
Encryption apparatus based on quantum random number
CN109088725B
( en )
*
2018-07-18
2021-04-09
å京ç工大å¦
Network key distribution method, device and system based on cascade disturbance computational imaging
CN109218012B
( en )
*
2018-09-11
2021-07-16
éåºé®çµå¤§å¦
Distributed smart meter electricity selling method and system with concentrator
CN109299618B
( en )
*
2018-09-20
2020-06-16
å¦è¬éåç§ææéå ¬å¸
Quantum-resistant computing cloud storage method and system based on quantum key card
CN109450620B
( en )
2018-10-12
2020-11-10
åæ°å è¿ææ¯æéå ¬å¸
Method for sharing security application in mobile terminal and mobile terminal
CN109614802B
( en )
*
2018-10-31
2020-11-27
å¦è¬éåç§ææéå ¬å¸
Anti-quantum-computation signature method and signature system
CN109543367B
( en )
*
2018-11-14
2020-11-10
èå·ç§è¾¾ç§æè¡ä»½æéå ¬å¸
Quantum encryption-based software authorization method and device and storage medium
HK1254273A2
( en )
*
2018-12-03
2019-07-12
Foris Limited
Secure distributed key management system
CN109672537B
( en )
*
2019-01-18
2021-08-10
å¦è¬éåç§ææéå ¬å¸
Anti-quantum certificate acquisition system and method based on public key pool
US11177946B2
( en )
*
2019-06-21
2021-11-16
Verizon Patent And Licensing Inc.
Quantum entropy distributed via software defined perimeter connections
CN110190961B
( en )
*
2019-07-02
2021-10-15
æ´é³å¸èå¦é¢
A Verifiable Method for Quantum Secret Sharing
CN112367162A
( en )
*
2019-09-01
2021-02-12
æé½éå®åºåé¾ç§ææéå ¬å¸
Application method and device of quantum relay node
CN112367163B
( en )
*
2019-09-01
2023-09-26
æé½éå®åºåé¾ç§ææéå ¬å¸
Quantum network virtualization method and device
CN110830242A
( en )
*
2019-10-16
2020-02-21
è好çç§æè¡ä»½æéå ¬å¸
Key generation and management method and server
GB2602208B
( en )
*
2019-11-08
2022-12-14
Arqit Ltd
Quantum-safe networking
CN110932870B
( en )
*
2019-12-12
2023-03-31
å京å¦è¬éåç§ææéå ¬å¸
Quantum communication service station key negotiation system and method
US11429519B2
( en )
2019-12-23
2022-08-30
Alibaba Group Holding Limited
System and method for facilitating reduction of latency and mitigation of write amplification in a multi-tenancy storage drive
CN111815816B
( en )
*
2020-06-22
2022-07-05
åè¥æºè¾ç©ºé´ç§ææéè´£ä»»å ¬å¸
Electronic lock security system and key distribution method thereof
US11233636B1
( en )
*
2020-07-24
2022-01-25
Salesforce.Com, Inc.
Authentication using key agreement
CN111708721B
( en )
*
2020-08-24
2020-12-01
ä¸åç工大å¦
Distributed data secret processing system and device based on electronic information
NL2027091B1
( en )
*
2020-12-10
2022-07-08
Abn Amro Bank N V
Orchestrated quantum key distribution
CN114362928B
( en )
*
2021-03-23
2023-11-24
é¿æ¥å¤§å¦
A quantum key distribution and reconstruction method for multi-node encryption
US11695552B2
( en )
2021-03-25
2023-07-04
International Business Machines Corporation
Quantum key distribution in a multi-cloud environment
US20230275751A1
( en )
*
2021-07-19
2023-08-31
Workgraph, Inc.
Decentralized Cryptography
KR102345419B1
( en )
*
2021-07-27
2021-12-30
ëìí°ìì´ (주)
Internal Communication of Railway Control System and Operation Method Using Quantum Cryptographic Communication Technology
CN113347009B
( en )
*
2021-08-05
2022-01-07
æé½é£æºå·¥ä¸ï¼éå¢ï¼æéè´£ä»»å ¬å¸
Certificateless threshold signcryption method based on elliptic curve cryptosystem
KR102341801B1
( en )
*
2021-08-20
2021-12-21
êµë¯¼ëíêµì°ííë ¥ë¨
Quantum security communication device integrated visual observation system and method
KR102499530B1
( en )
*
2021-08-20
2023-02-14
êµë¯¼ëíêµì°ííë ¥ë¨
Quantum security communication device integrated supervisory control and data acquisition system and method
KR102356152B1
( en )
*
2021-08-20
2022-02-08
êµë¯¼ëíêµì°ííë ¥ë¨
Quantum security communication device integrated intelligent traffic signal control system and method
CN114091064A
( en )
*
2021-11-23
2022-02-25
å¥å®ä¿¡ç§æéå¢è¡ä»½æéå ¬å¸
Data transfer method, device, equipment and storage medium
CN114244513B
( en )
*
2021-12-31
2024-02-09
æ¥æ·ç§æ(䏿µ·)æéå ¬å¸
Key negotiation method, device and storage medium
CN114095183B
( en )
*
2022-01-23
2022-05-03
æå·åèä¿¡æ¯ææ¯æéå ¬å¸
Client dual authentication method, terminal equipment and storage medium
GB2616047A
( en )
*
2022-02-25
2023-08-30
Toshiba Kk
A quantum network and a quantum authentication server
CN114531238B
( en )
*
2022-04-24
2022-07-19
ä¸çµä¿¡éåç§ææéå ¬å¸
Secret key safe filling method and system based on quantum secret key distribution
CN115378585B
( en )
*
2022-08-22
2024-11-12
å®å¾½çæå æºè½ç§ææéå ¬å¸
A quantum key lifecycle management system
CN115811395B
( en )
*
2022-11-17
2026-04-17
å京天èä¿¡ç½ç»å®å ¨ææ¯æéå ¬å¸
Methods, apparatus, electronic devices, and readable storage media for generating shared keys
CN115499125B
( en )
*
2022-11-18
2023-03-24
å京å®çä¿¡æ¯ææ¯è¡ä»½æéå ¬å¸
Method, system, medium and device for secure multi-tenant key distribution in cloud environment
CN116155487B
( en )
*
2022-12-16
2026-02-06
å®å¾½é®å¤©éåç§æè¡ä»½æéå ¬å¸
Quantum encryption system, quantum key distribution method and encryption method for multiparty mobile communication
CN116469198B
( en )
*
2023-04-20
2025-08-05
西å®çµåç§æå¤§å¦
An IoT intelligent hotel access control system based on NFC technology
CN116996237B
( en )
*
2023-09-29
2023-12-08
å±±ä¸é«é建设管çé墿éå ¬å¸
A distributed management method and system based on quantum threshold signature
CN117119449B
( en )
*
2023-10-20
2024-01-19
é¿æ±éå(æ¦æ±)ç§ææéå ¬å¸
Vehicle cloud safety communication method and system
CN118764200B
( en )
*
2024-09-09
2024-12-31
å½ç½ä¸æµ·è½æºäºèç½ç ç©¶é¢æéå ¬å¸
Electric power secondary system business safety protection system and method
CN119519951A
( en )
*
2024-11-08
2025-02-25
ä¸å½ç§»å¨éä¿¡æéå ¬å¸ç ç©¶é¢
Quantum key distribution method, device, related equipment, storage medium and computer program product
CN119155042B
( en )
*
2024-11-13
2025-02-07
æè¿ éç§ææéå ¬å¸
Flow charging information signature verification method and system based on quantum digital signature
CN119675856A
( en )
*
2024-11-26
2025-03-21
åäº¬è®¡ç®æºææ¯ååºç¨ç ç©¶æ
A quantum key distribution method based on threshold idea
CN120934757B
( en )
*
2025-09-30
2026-02-10
ä¸çµä¿¡éåä¿¡æ¯ç§æé墿éå ¬å¸
Key distribution method, device, equipment and medium for quantum security infrastructure
Citations (35)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20020199108A1
( en )
2001-04-26
2002-12-26
Isaac Chuang
Quantum digital signatures
US20030112970A1
( en )
2001-08-26
2003-06-19
Arindam Mitra
How to generate unbreakable key through any communication channel
JP2004032520A
( en )
2002-06-27
2004-01-29
Nippon Telegr & Teleph Corp <Ntt>
Quantum information dispersion generation method, apparatus and program
US20050078826A1
( en )
2003-10-10
2005-04-14
Nec Corporation
Quantum cryptography communication system and quantum cryptography key distributing method used in the same
US20050259825A1
( en )
2004-05-24
2005-11-24
Alexei Trifonov
Key bank systems and methods for QKD
JP2007060161A
( en )
2005-08-23
2007-03-08
Ntt Docomo Inc
ENCRYPTION SYSTEM, TERMINAL DEVICE, AND ENCRYPTION METHOD
US20070076884A1
( en )
2005-09-30
2007-04-05
Mci, Inc.
Quantum key distribution system
US20070192598A1
( en )
2006-01-09
2007-08-16
Gregory Troxel
Pedigrees for quantum cryptography
US20080144836A1
( en )
2006-12-13
2008-06-19
Barry Sanders
Distributed encryption authentication methods and systems
JP2008250931A
( en )
2007-03-30
2008-10-16
Toshiba Corp
Distributed information restoration system, information utilization device, and verification device
US20090106551A1
( en )
2006-04-25
2009-04-23
Stephen Laurence Boren
Dynamic distributed key system and method for identity management, authentication servers, data security and preventing man-in-the-middle attacks
US20090175452A1
( en )
2006-04-18
2009-07-09
Robert Gelfond
Key Management and User Authentication for Quantum Cryptography Networks
CN101599826A
( en )
2009-07-10
2009-12-09
é西çå·¥å¦é¢
Scalable multi-user quantum key distribution network system and its key distribution method
CN201430596Y
( en )
2009-07-10
2010-03-24
é西çå·¥å¦é¢
Scalable multi-user quantum key distribution network system
US20100226659A1
( en )
2006-08-04
2010-09-09
Mitsubishi Electric Corporation
Quantum communication apparatus, quantum communication system and quantum communication method
US20100299526A1
( en )
2008-01-25
2010-11-25
Qinetiq Limited
Network having quantum key distribution
US20100329459A1
( en )
2008-01-25
2010-12-30
Qinetiq Limited
Multi-community network with quantum key distribution
US7864958B2
( en )
2005-06-16
2011-01-04
Hewlett-Packard Development Company, L.P.
Quantum key distribution method and apparatus
US20110085666A1
( en )
2008-05-19
2011-04-14
Qinetiq Limited
Quantum key device
US20110213979A1
( en )
2008-10-27
2011-09-01
Qinetiq Limited
Quantum key distribution
US20110317836A1
( en )
2010-06-29
2011-12-29
Chunghwa Telecom Co., Ltd.
Quantum cryptography service network implementation structure
US20120082312A1
( en )
2010-10-05
2012-04-05
Brandenburgische Technische Universitaet Cottbus
Method of authentication and session key agreement for secure data transmission, a method for securely transmitting data, and an electronic data transmission system
US20120177201A1
( en )
2009-09-29
2012-07-12
Qinetiq