ConceptioArchiveGoogle Patents
Google Patentsopen access

Apparatus for quantum key distribution on a quantum network and method using … — Electronics And Telecommunications Research Institute (US10958428B2)

Electronics And Telecommunications Research Institute · Google Patents
Google Patents · Patents · License: Open Access
Open Source ↗
patent, google patents, intellectual property, US10958428B2, Electronics And Telecommunications Research Institute, Chang-Ho HONG, en, 2021

ABSTRACT

Abstract

A device and method for quantum key distribution (QKD). The QKD center includes an authentication key sharing unit for sharing authentication keys with QKD client devices; a quantum key generation unit for generating a sifted key for each of the QKD client devices using a quantum state; an error correction unit for generating output bit strings by correcting errors of the sifted keys; and a bit string operation unit for calculating an encryption bit string by performing a cryptographic operation on the authentication keys, the distribution output bit strings and output bit strings received from the QKD client devices. The present invention improves security by preventing the QKD center from being aware of keys shared among users.

Description

CROSS REFERENCE TO RELATED APPLICATION

This application claims the benefit of Korean Patent Application No. 10-2016-0061993 filed May 20, 2016, which is hereby incorporated by reference in its entirety into this application.

BACKGROUND OF THE INVENTION

1. Technical Field

The present invention relates to technology for securing a quantum key generated in a Quantum Key Distribution (QKD) system.

2. Description of the Related Art

A QKD system is configured such that, when a transmission unit transmits a randomly selected quantum state using two nonorthogonal bases, a reception unit receives it and estimates the quantum state using a randomly selected a measurement basis of two bases. Such a QKD system may provide an environment in which secure key distribution is guaranteed because an eavesdropper may be detected in the process of estimating the quantum state.

A QKD system has a limitation as to distance when the system is implemented. In order for two users, father farther apart from each other than the allowable distance, to share encryption keys using a QKD system, a method in which encryption keys are relaxed by a quantum repeater or a trustworthy key distribution center is used. Here, because it is not easy to implement a quantum repeater, a method for relaying encryption keys through a key distribution center is widely used. In this method, encryption keys, individually created by a key distribution center and users, are delivered to users. However, this method is problematic in that a security weak point exists in that the key distribution center is aware of the encryption keys shared among the users.

Meanwhile, Korean Patent Application Publication No. 10-2011-0057448, titled “A method of user-authenticated quantum key distribution”, discloses a method for authenticating a quantum channel by sharing a position having the same basis without disclosing information about the basis using previously shared secret keys and checking whether there is the same measured outcome at that position in order to guarantee unconditional security of BB84 QKD protocol, which is vulnerable to man-in-the-middle attacks.

This invention was supported by the ICT R&D program of MSIP/IITP [1711028311, Reliable crypto-system standards and core technology development for secure quantum key distribution network] and the R&D Convergence program of NST (National Research Council of Science and Technology) of Republic of Korea (Grant No. CAP-18-08-KRISS).

SUMMARY OF THE INVENTION

An object of the present invention is to improve the security of quantum key distribution by preventing information about the encryption of quantum keys, which are finally distributed to quantum key distribution client devices, from being exposed to a quantum key-distribution center.

Another object of the present invention is to improve the security of quantum key distribution through the process of a cryptographic operation on au authentication key, shared among client devices, and an output bit string, in which an error is corrected.

A further object of the present invention is to distribute a quantum key encrypted with a hash function having improved security.

In order to accomplish the above objects, a QKD center on a quantum network according to an embodiment of the present invention includes an authentication key sharing unit for sharing authentication keys with QKD client devices; a quantum key generation unit for generating sifted keys, corresponding to the QKD client devices, using quantum states; an error correction unit for generating distribution output bit strings by correcting errors of the sifted keys; and a bit string operation unit for calculating an encryption bit string by performing a cryptographic operation on the authentication keys and the distribution output bit strings corresponding to the QKD client devices.

Here, the quantum key generation unit may randomly select bases for quantum states, corresponding to the QKD client devices, using quantum mechanics, compare measurement bases for quantum states, received from the QKD client devices, generate sifted keys, corresponding to bits that remain after checking security of a channel using bits on the same basis, for the respective QKD client devices.

Here, the error correction unit may generate distribution output bit strings by correcting the errors of the sifted keys. The error correction unit may correct the errors of the sifted keys using Hamming code, Winnow algorithm, LDPC or the like.

Here, the bit string operation unit is configured to prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on the first authentication key and the first distribution output bit string to the QKD client device.

Here, the bit string operation unit is configured to prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on the second authentication key and the second distribution output bit string to the QKD client device.

Here, the bit string operation unit may transmit the encryption bit string, calculated by performing a cryptographic operation on the second authentication key, the first distribution output bit siring and the second distribution output bit string, to any one of the first QKD client device and the second QKD client device only when authentication of the QKD center succeeds.

Also, in order to accomplish the above object, a QKD client device on a quantum network according to an embodiment of the present invention includes an authentication key sharing unit for sharing authentication keys with a QKD center and an additional QKD client device; a quantum key generation unit for generating a sifted key, corresponding to the QKD center, using a quantum states; an error correction unit for generating output bit strings by correcting an error of the sifted key in conjunction with the QKD center; a bit string calculation unit for calculating a shared key bit string by performing a cryptographic operation on one or more of a first output bit string, a second output bit string of the additional QKD client device, an inter-client authentication key, which is included in the authentication key and is shared with the additional QKD client device, and an encryption bit string received from the QKD center and a privacy amplification unit for generating a final key bit string by applying a hash function to the shared key bit string.

Here, the quantum key generation unit may select a measurement basis for a quantum state, corresponding to the QKD center, using quantum mechanics, compares a preparation basis for a quantum state, received from the QKD center, and generate a sifted key corresponding to bits that remain after checking security of a channel using bits on the same basis.

Here, the error correction unit may generate output bit strings by correcting the errors of the sifted keys. The error correction unit may correct the errors of the sifted keys using Hamming code, Window algorithm, LDPC or the like.

Here, the bit string calculation unit may authenticate the QKD center to a first QKD client device by comparing a result of a cryptographic operation performed on a first authentication key, which is shared with the first QKD client device, and a first distribution output bit string with a result of a cryptographic operation performed on the first authentication key and a first output bit string, the first authentication key being included in the authentication keys, the first distribution output bit string being included in the distribution output bit strings, and the first output bit string being included in the output bit strings.

Here, the bit string calculation unit may authenticate the QKD center to a second QKD client device by comparing a result of a cryptographic operation performed on a second authentication key, which is shared with the second QKD client device, and a second distribution output bit string with a result of a cryptographic operation performed on the second authentication key and a second output bit string, the second authentication key being included in the authentication keys, the second distribution output bit string being included in the distribution output bit strings, and the second output bit string being included in the output bit strings.

Here the privacy amplification unit may generate a final key bit string by applying a hash function. The privacy amplification unit may delete some of information about a key, leaked to an eavesdropper in the process of error correction.

Here, only when the authentication of the QKD center succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit may receive the encryption bit siring, which is calculated by performing a cryptographic operation on the second authentication key, the first distribution output bit string and the second distribution output bit string, the distribution output bit strings being generated by correcting an error of the sifted key in the QKD center.

Here, only when the authentication of the QKD center succeeds and the QKD client device requests the QKD center to communicate the bit string calculation unit may calculate an encrypted shared key by performing a cryptographic operation on the encryption bit string, the second authentication key and the second output bit string.

Here, only when the authentication of the QKD center succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit may calculate the shared key bit string by performing a cryptographic operation on the encrypted shared key and the inter-client authentication key.

Here, only when the authentication of the QKD center succeeds and the QKD client device is requested to communicate by the QKD center, the bit string calculation unit may calculate the shared key bit siring by performing a cryptographic operation on the first output bit string and the inter-client authentication key.

Also, in order to accomplish the above objects, a QKD method on a quantum network according to an embodiment of the present invention includes sharing authentication keys among the QKD center and the QKD client devices; generating sifted keys, corresponding to the QKD center and the QKD client devices, using quantum states; generating output bit strings by correcting errors of the sifted keys; calculating a shared key bit string by performing a cryptographic operation on the output bit strings and an inter-client authentication key; and generating a final key bit string by applying a hash function to the shared key bit string.

Here, the generating the sifted keys may be configured to select a preparation basis and a measurement basis for a quantum state using quantum mechanics, to compare a preparation basis of the QKD center with measurement basis of the QKD client devices, and to generate the sifted keys corresponding to bits that remain after checking security of a quantum channel using bits on the same basis.

Here, the generating output bit strings creates the output bit strings by correcting the errors of the sifted keys. The error correction methods use Hamming code, Winnow algorithm, LDPC or the like.

Here, the calculating the shared key bit string may include calculating an encryption bit string by the QKD center; calculating, by the QKD client device that requests communication, the shared key bit string; and calculating, by the QKD client device that is requested to communicate, the shared key bit string.

Here, the calculating the encryption bit string may be configured to transmit the encryption bit string, calculated using a result of a cryptographic operation performed on the second authentication key and the distribution output bit strings, to any one of the QKD client devices only when authentication of the QKD center succeeds.

Here, the calculating, by the QKD client device that requests communication, the shared key bit string may be configured such that only when authentication of the QKD center succeeds and any one of the QKD client devices requests the QKD center to communicate, the QKD client device that requests communication receives the encryption bit siring and calculates an encrypted shared key by performing a cryptographic operation on the received encryption bit string, the second authentication key and the second output bit string, generated by the QKD client device that requests communication.

Here, the calculating, by the QKD client device that requests communication, the shared key bit string may be configured such that only when authentication of the QKD center succeeds and any one of the QKD client devices requests the QKD center to communicate, the shared key bit siring is calculated by performing a cryptographic operation on the encrypted shared key and the inter-client authentication key, which is included in the authentication keys and shared among the QKD client devices.

Here, the calculating, by the QKD client device that is requested to communicate, the shared key bit string may be configured such that only when authentication of the QKD center succeeds and any one of the QKD client devices is requested to communicate by the QKD center, the shared key bit string is calculated by performing a cryptographic operation on the first output bit string, generated by the QKD client device that is requested to communicate, and the inter-client authentication key.

Here, the generating a final key bit string may be calculated by performing a hash function on the shared key bit string.

Here, the QKD center may not be aware of the shared key bit string, shared among the QKD client devices.

BRIEF DESCRIPTION OF THE DRAWINGS

The above and other objects, features and advantages of the present invention will be more clearly understood from the following detailed description taken in conjunction with the accompanying drawings, in which:

FIG. 1 is a block diagram illustrating a simple quantum key distribution (QKD) system according to an embodiment of the present invention;

FIG. 2 is a block diagram illustrating an example of the QKD center illustrated in FIG. 1 ;

FIG. 3 is a block diagram illustrating an example of the QKD client device illustrated in FIG. 1 ;

FIG. 4 is a block diagram illustrating an example of the QKD system illustrated in FIGS. 1 to 3 ;

FIG. 5 is a block diagram specifically illustrating an example of the quantum key generation unit of the QKD center and an example of the quantum key generation unit of the first QKD client device, illustrated in FIG. 4 ;

FIG. 6 is a block diagram specifically illustrating an example of the bit string calculation unit and an example of the bit string operation unit, illustrated in FIG. 4 ;

FIG. 7 is a block diagram specifically illustrating an example of the privacy amplification unit illustrated in FIG. 4 ;

FIG. 8 is a flowchart illustrating a

CROSS REFERENCE TO RELATED APPLICATION

This application claims the benefit of Korean Patent Application No. 10-2016-0061993 filed May 20, 2016, which is hereby incorporated by reference in its entirety into this application.

BACKGROUND OF THE INVENTION

1. Technical Field

The present invention relates to technology for securing a quantum key generated in a Quantum Key Distribution (QKD) system.

2. Description of the Related Art

A QKD system is configured such that, when a transmission unit transmits a randomly selected quantum state using two nonorthogonal bases, a reception unit receives it and estimates the quantum state using a randomly selected a measurement basis of two bases. Such a QKD system may provide an environment in which secure key distribution is guaranteed because an eavesdropper may be detected in the process of estimating the quantum state.

A QKD system has a limitation as to distance when the system is implemented. In order for two users, father farther apart from each other than the allowable distance, to share encryption keys using a QKD system, a method in which encryption keys are relaxed by a quantum repeater or a trustworthy key distribution center is used. Here, because it is not easy to implement a quantum repeater, a method for relaying encryption keys through a key distribution center is widely used. In this method, encryption keys, individually created by a key distribution center and users, are delivered to users. However, this method is problematic in that a security weak point exists in that the key distribution center is aware of the encryption keys shared among the users.

Meanwhile, Korean Patent Application Publication No. 10-2011-0057448, titled “A method of user-authenticated quantum key distribution”, discloses a method for authenticating a quantum channel by sharing a position having the same basis without disclosing information about the basis using previously shared secret keys and checking whether there is the same measured outcome at that position in order to guarantee unconditional security of BB84 QKD protocol, which is vulnerable to man-in-the-middle attacks.

This invention was supported by the ICT R&D program of MSIP/IITP [1711028311, Reliable crypto-system standards and core technology development for secure quantum key distribution network] and the R&D Convergence program of NST (National Research Council of Science and Technology) of Republic of Korea (Grant No. CAP-18-08-KRISS).

SUMMARY OF THE INVENTION

An object of the present invention is to improve the security of quantum key distribution by preventing information about the encryption of quantum keys, which are finally distributed to quantum key distribution client devices, from being exposed to a quantum key-distribution center.

Another object of the present invention is to improve the security of quantum key distribution through the process of a cryptographic operation on au authentication key, shared among client devices, and an output bit string, in which an error is corrected.

A further object of the present invention is to distribute a quantum key encrypted with a hash function having improved security.

In order to accomplish the above objects, a QKD center on a quantum network according to an embodiment of the present invention includes an authentication key sharing unit for sharing authentication keys with QKD client devices; a quantum key generation unit for generating sifted keys, corresponding to the QKD client devices, using quantum states; an error correction unit for generating distribution output bit strings by correcting errors of the sifted keys; and a bit string operation unit for calculating an encryption bit string by performing a cryptographic operation on the authentication keys and the distribution output bit strings corresponding to the QKD client devices.

Here, the quantum key generation unit may randomly select bases for quantum states, corresponding to the QKD client devices, using quantum mechanics, compare measurement bases for quantum states, received from the QKD client devices, generate sifted keys, corresponding to bits that remain after checking security of a channel using bits on the same basis, for the respective QKD client devices.

Here, the error correction unit may generate distribution output bit strings by correcting the errors of the sifted keys. The error correction unit may correct the errors of the sifted keys using Hamming code, Winnow algorithm, LDPC or the like.

Here, the bit string operation unit is configured to prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on the first authentication key and the first distribution output bit string to the QKD client device.

Here, the bit string operation unit is configured to prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on the second authentication key and the second distribution output bit string to the QKD client device.

Here, the bit string operation unit may transmit the encryption bit string, calculated by performing a cryptographic operation on the second authentication key, the first distribution output bit siring and the second distribution output bit string, to any one of the first QKD client device and the second QKD client device only when authentication of the QKD center succeeds.

Also, in order to accomplish the above object, a QKD client device on a quantum network according to an embodiment of the present invention includes an authentication key sharing unit for sharing authentication keys with a QKD center and an additional QKD client device; a quantum key generation unit for generating a sifted key, corresponding to the QKD center, using a quantum states; an error correction unit for generating output bit strings by correcting an error of the sifted key in conjunction with the QKD center; a bit string calculation unit for calculating a shared key bit string by performing a cryptographic operation on one or more of a first output bit string, a second output bit string of the additional QKD client device, an inter-client authentication key, which is included in the authentication key and is shared with the additional QKD client device, and an encryption bit string received from the QKD center and a privacy amplification unit for generating a final key bit string by applying a hash function to the shared key bit string.

Here, the quantum key generation unit may select a measurement basis for a quantum state, corresponding to the QKD center, using quantum mechanics, compares a preparation basis for a quantum state, received from the QKD center, and generate a sifted key corresponding to bits that remain after checking security of a channel using bits on the same basis.

Here, the error correction unit may generate output bit strings by correcting the errors of the sifted keys. The error correction unit may correct the errors of the sifted keys using Hamming code, Window algorithm, LDPC or the like.

Here, the bit string calculation unit may authenticate the QKD center to a first QKD client device by comparing a result of a cryptographic operation performed on a first authentication key, which is shared with the first QKD client device, and a first distribution output bit string with a result of a cryptographic operation performed on the first authentication key and a first output bit string, the first authentication key being included in the authentication keys, the first distribution output bit string being included in the distribution output bit strings, and the first output bit string being included in the output bit strings.

Here, the bit string calculation unit may authenticate the QKD center to a second QKD client device by comparing a result of a cryptographic operation performed on a second authentication key, which is shared with the second QKD client device, and a second distribution output bit string with a result of a cryptographic operation performed on the second authentication key and a second output bit string, the second authentication key being included in the authentication keys, the second distribution output bit string being included in the distribution output bit strings, and the second output bit string being included in the output bit strings.

Here the privacy amplification unit may generate a final key bit string by applying a hash function. The privacy amplification unit may delete some of information about a key, leaked to an eavesdropper in the process of error correction.

Here, only when the authentication of the QKD center succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit may receive the encryption bit siring, which is calculated by performing a cryptographic operation on the second authentication key, the first distribution output bit string and the second distribution output bit string, the distribution output bit strings being generated by correcting an error of the sifted key in the QKD center.

Here, only when the authentication of the QKD center succeeds and the QKD client device requests the QKD center to communicate the bit string calculation unit may calculate an encrypted shared key by performing a cryptographic operation on the encryption bit string, the second authentication key and the second output bit string.

Here, only when the authentication of the QKD center succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit may calculate the shared key bit string by performing a cryptographic operation on the encrypted shared key and the inter-client authentication key.

Here, only when the authentication of the QKD center succeeds and the QKD client device is requested to communicate by the QKD center, the bit string calculation unit may calculate the shared key bit siring by performing a cryptographic operation on the first output bit string and the inter-client authentication key.

Also, in order to accomplish the above objects, a QKD method on a quantum network according to an embodiment of the present invention includes sharing authentication keys among the QKD center and the QKD client devices; generating sifted keys, corresponding to the QKD center and the QKD client devices, using quantum states; generating output bit strings by correcting errors of the sifted keys; calculating a shared key bit string by performing a cryptographic operation on the output bit strings and an inter-client authentication key; and generating a final key bit string by applying a hash function to the shared key bit string.

Here, the generating the sifted keys may be configured to select a preparation basis and a measurement basis for a quantum state using quantum mechanics, to compare a preparation basis of the QKD center with measurement basis of the QKD client devices, and to generate the sifted keys corresponding to bits that remain after checking security of a quantum channel using bits on the same basis.

Here, the generating output bit strings creates the output bit strings by correcting the errors of the sifted keys. The error correction methods use Hamming code, Winnow algorithm, LDPC or the like.

Here, the calculating the shared key bit string may include calculating an encryption bit string by the QKD center; calculating, by the QKD client device that requests communication, the shared key bit string; and calculating, by the QKD client device that is requested to communicate, the shared key bit string.

Here, the calculating the encryption bit string may be configured to transmit the encryption bit string, calculated using a result of a cryptographic operation performed on the second authentication key and the distribution output bit strings, to any one of the QKD client devices only when authentication of the QKD center succeeds.

Here, the calculating, by the QKD client device that requests communication, the shared key bit string may be configured such that only when authentication of the QKD center succeeds and any one of the QKD client devices requests the QKD center to communicate, the QKD client device that requests communication receives the encryption bit siring and calculates an encrypted shared key by performing a cryptographic operation on the received encryption bit string, the second authentication key and the second output bit string, generated by the QKD client device that requests communication.

Here, the calculating, by the QKD client device that requests communication, the shared key bit string may be configured such that only when authentication of the QKD center succeeds and any one of the QKD client devices requests the QKD center to communicate, the shared key bit siring is calculated by performing a cryptographic operation on the encrypted shared key and the inter-client authentication key, which is included in the authentication keys and shared among the QKD client devices.

Here, the calculating, by the QKD client device that is requested to communicate, the shared key bit string may be configured such that only when authentication of the QKD center succeeds and any one of the QKD client devices is requested to communicate by the QKD center, the shared key bit string is calculated by performing a cryptographic operation on the first output bit string, generated by the QKD client device that is requested to communicate, and the inter-client authentication key.

Here, the generating a final key bit string may be calculated by performing a hash function on the shared key bit string.

Here, the QKD center may not be aware of the shared key bit string, shared among the QKD client devices.

BRIEF DESCRIPTION OF THE DRAWINGS

The above and other objects, features and advantages of the present invention will be more clearly understood from the following detailed description taken in conjunction with the accompanying drawings, in which:

FIG. 1 is a block diagram illustrating a simple quantum key distribution (QKD) system according to an embodiment of the present invention;

FIG. 2 is a block diagram illustrating an example of the QKD center illustrated in FIG. 1 ;

FIG. 3 is a block diagram illustrating an example of the QKD client device illustrated in FIG. 1 ;

FIG. 4 is a block diagram illustrating an example of the QKD system illustrated in FIGS. 1 to 3 ;

FIG. 5 is a block diagram specifically illustrating an example of the quantum key generation unit of the QKD center and an example of the quantum key generation unit of the first QKD client device, illustrated in FIG. 4 ;

FIG. 6 is a block diagram specifically illustrating an example of the bit string calculation unit and an example of the bit string operation unit, illustrated in FIG. 4 ;

FIG. 7 is a block diagram specifically illustrating an example of the privacy amplification unit illustrated in FIG. 4 ;

FIG. 8 is a flowchart illustrating a QKD method according to an embodiment of the present invention;

FIG. 9 is a flowchart specifically illustrating an example of the step of generating a sifted key, illustrated in FIG. 8 ;

FIG. 10 is a flowchart specifically illustrating an example of the step of generating an output bit string, illustrated in FIG. 8 ;

FIG. 11 is a flowchart specifically illustrating an example of the step of calculating a shared key bit string, illustrated in FIG. 8 ; and

FIG. 12 is a block diagram illustrating a computer system according to an embodiment of the present indention.

DESCRIPTION OF THE PREFERRED EMBODIMENTS

The present invention will be described in detail below with reference to the accompanying drawings. Repeated descriptions and descriptions of known functions and configurations which have been deemed to make the gist of the present invention unnecessarily obscure will be omitted below. The embodiments of the present invention are intended to fully describe the present invention to a person having ordinary knowledge in the art to which the present invention pertains. Accordingly, the shapes, sizes, etc. of components in the drawings may be exaggerated in order to make the description clearer.

Hereinafter, a preferred embodiment of the present invention will be described in detail with reference to the accompanying drawings.

FIG. 1 is a block diagram illustrating a QKD system according to an embodiment of the present invention. FIG. 2 is a block diagram specifically illustrating an example of the QKD center illustrated in FIG. 1 . FIG. 3 is a block diagram specifically illustrating an example of the QKD client device illustrated in FIG. 1 . FIG. 4 is a block diagram specifically illustrating an example of the QKD system illustrated in FIGS. 1 to 3 .

Referring to FIGS. 1 to 4 , a QKD system according to an embodiment of the present invention includes a QKD center 100 , a first QKD client device 200 , and a second QKD client device 300 .

The QKD center 100 may share authentication keys and keyed hash functions with the QKD client devices

200 and 300 in advance.

Here, the QKD center 100 may share a first authentication key and keyed hash function with the first QKD client device 200 , and may share a second authentication key and keyed hash function with the second QKD client deice 300 .

Here, the QKD center 100 may generate sifted keys, corresponding to the QKD client devices, using quantum states.

Here, the QKD client device

200 and 300 may authenticate the QKD center 100 , and the QKD center 100 may open a communication channel in response to a request by an authenticated user. Here, in order to authenticate the QKD center, the authentication keys shared with the QKD client devices, the output bit strings, the distribution output bit strings, and keyed hash functions may be used.

The QKD center 100 may generate distribution output bit strings by correcting the errors of the sifted keys. The distribution output bit strings may include a first distribution output bit string and a second distribution output bit string, wherein the first distribution output bit string is acquired in such a way that the QKD center 100 corrects the error of the sifted key, which is generated corresponding to the first QKD client device 200 and the second distribution output bit string is acquired in such a way that the QKD center 100 corrects the error of the sifted key, which is generated corresponding to the second QKD client device 300 .

The QKD center 100 may calculate an encryption bit string by performing a cryptographic operation on the second authentication key, shared with the QKD client 300 , and the distribution output bit strings, acquired by correcting the errors.

Here, the QKD center 100 may transmit the encryption bit string to the QKD client device that requests communication.

The first QKD client device 200 may be the QKD client device that is requested to communicate by the second QKD client device 300 .

The first QKD client device 200 may share authentication keys and keyed hash function with the QKD center 100 and the second QKD client device 300 , and may generate a sifted key corresponding to the QKD center 100 , using a quantum state.

Here, the first QKD client device 200 may share a first authentication key and keyed hash function with the QKD center 100 .

Here, the first QKD client device 200 may share an inter-client authentication key and a hash function with the second QKD client device 300 .

Here, the shared authentication keys, the sifted key, and a keyed hash function may be used for user authentication.

The first QKD client device 200 may generate a first output bit string by correcting the error of the sifted key corresponding to the QKD center 100 .

The first QKD client device 200 may calculate a shared key bit string by performing a cryptographic operation on the first output bit string and the inter-client authentication key, which is shared with the second QKD client device 300 .

The first QKD client device 200 may generate a final key bit string by applying a hash function to the shared key bit string.

The second QKD client device 300 may be the QKD client device that requests the first QKD client device 200 to communicate therewith.

The second QKD client device 300 may share authentication key with the QKD center 100 and the first QKD client device 200 , and may generate a sifted key, corresponding to the QKD center 100 , using a quantum state.

Here, the second QKD client device 300 may share a second authentication key and keyed hash function with the QKD center 100 .

Here, the second QKD client device 300 may share an inter-client authentication key and a hash function with the first QKD client device 200 .

Here, the shared authentication keys, the output bit strings, and a keyed hash function may be used for authentication of the QKD center.

The second QKD client device 300 may generate a second output bit string by correcting the error of the sifted key corresponding to the QKD center 100 .

The second QKD client device 300 may calculate a shared key bit string by performing a cryptographic operation on the second output bit string, the inter-client authentication key and the encryption bit string, which is received from the QKD center 100 .

The second QKD client device 300 may generate a final key bit string by applying a hash function to the shared key bit string.

Referring to FIG. 2 and FIG. 4 , a QKD center according to an embodiment of the present invention includes an authentication key sharing unit 101 , a quantum key generation unit 110 , an error correction unit 120 , and a bit string operation unit 130 .

The authentication key sharing unit 101 may share authentication keys with QKD client devices. Here, the authentication key sharing unit 101 may share a first authentication key Ak A with the first QKD client device 200 and may share a second authentication key Ak B with the second QKD client device 300 .

The quantum key generation unit 110 may generate sifted keys, corresponding to the QKD client devices, using quantum states.

Here, the quantum key generation unit 110 may include a quantum state transmission unit 111 , a random number generator 112 , a classical bit transceiver 113 , and a logic control unit 114 .

The quantum state transmission unit 111 may prepare a quantum state and transmit it via a quantum channel 51 . Here, the quantum state transmission unit 111 may transmit the quantum state through a quantum key distribution protocol such as BB84, B92, or the like.

The random number generator 112 may generate a random signal using quantum mechanics. Here, the random number generator 112 may randomly select a quantum preparation basis (polarization basis) and quantum states.

The classical bit transceiver 113 may receive the measurement basis selected by the random number generator 212 of the first QKD client device 200 , and may transmit the preparation basis, selected by the random number generator 112 .

Here, the logic control unit 114 checks the security of the quantum channel 51 by sharing the information about polarizing plates (preparation bases and measurement bases) with the first QKD client device 200 is a classical channel 52 , and may then transmit the information that remains after checking the security of the quantum channel to the error correction unit 120 ). Here, the classical channel 52 may be a public channel and may be eavesdropped on by anybody. However, in the classical channel 52 , falsification and the addition of additional information may not be allowed. For example, the classical channel 52 may correspond to the concept of a public board such as a newspaper. Here, the classical bit transceiver 113 may guarantee the integrity of information using Message Authentication Code (MAC).

Here, the logic control unit 114 may store information in order to compare the preparation basis for a quantum state, which is randomly selected by the random number generator 112 , with the measurement basis for a quantum state, which is randomly selected by the random, number generator 212 of the first QKD client device 200 .

Here, the logic control unit 114 compares the preparation basis for the quantum state with the measurement basis for the quantum state through communication between the classical bit transceiver 113 and the classical bit transceiver 213 of the first QKD client device 200 , and may check whether a channel is secure using some bits of the bit string on the same basis.

Here, the logic control unit 114 may output a sifted key based on the bits remaining after checking the security of the channel.

The above-mentioned process of generating the sifted key, performed by the quantum key generation unit 110 , may be applied not only to the first QKD client device 200 but also to the second QKD client device 300 .

The error correction unit 120 may generate distribution output bit strings by correcting the errors of the sifted keys. Here, the error correction unit 120 may correct the errors of the sifted keys using Hamming code, Winnow algorithm, LDPC or the like. Specifically, the error correction unit 120 divides the bit string to be transmitted into multiple blocks, and may transmit the parity bit of each of the blocks to the error correction unit

220 or 320 of the QKD client device via the classical channel

53 or 63 . The error correction unit

220 or 320 of the QKD client device may detect a block containing a data, error by checking the parity bit of the block. Then, the error correction unit 120 subdivides the block contain big the data, error, which is detected and announced by the error correction unit

220 or 320 of the QKD client device, and the parity of the subdivided block is repeatedly checked by the error correction unit

220 or 320 of the QKD client device. Through the repetition of this process, when the length of the block containing the parity error becomes the length to which Hamming code can be applied, the bit containing the error may be determined and corrected by applying Hamming code thereto. Here, the bit string generated by this error-correction process may correspond to a common output bit string between the error correction unit 120 and the error correction unit 220 of the first QKD client device 200 or a common output bit string between the error correction unit 120 and the error correction unit 320 of the second QKD client device 300 .

Here, the error correction unit 120 may output a first distribution output bit string Rk A ′ by correcting the error of the sifted key corresponding to the first QKD client device 200 .

Here, the error correction unit 120 may output a second distribution output bit string Rk B ′ by correcting the error of the sifted key corresponding to the second QKD client device 300 .

Here, the error correction unit 220 of the first QKD client device 200 may output a first output bit string Rk A by correcting the error of the sifted key corresponding to the QKD center 100 .

Here, the error correction unit 320 of the second QKD client device 300 may output a second output bit string Rk B by correcting the error of the sifted key corresponding to the QKD center 100 .

The bit siring operation unit 130 may prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on the first authentication key and the first distribution output bit string to the QKD client device.

The bit string operation unit 130 may prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on the second authentication key and the second distribution output bit string to the QKD client device.

The bit siring operation unit 130 may calculate an encryption bit string by performing a cryptographic operation on the second authentication key and the distribution output bit strings in which the error has been corrected.

The bit string operation unit 130 may transmit the encryption bit string, calculated by performing a cryptographic operation on the second authentication key, the first distribution output bit string and the second distribution output bit string, to any one of the first QKD client device and the second QKD client device only when authentication of the QKD center succeeds.

Here, the bit string operation unit 130 authenticates own identity to the QKD client devices, and may open a communication channel in response to the requests by users (QKD clients). Here, in order to prove own identity, the authentication keys, the distribution output bit strings, output bit strings, and a keyed hash function may be used.

The bit string operation unit 130 may include memory units

131 and 132 and an operation unit 135 .

The memory unit 131 may store the first distribution output bit string Rk A ′, which is received from the error correction unit 120 . Here, the memory unit 231 may receive a bit string, acquired by performing an operation on the first authentication key Ak A and the first distribution output bit string Rk A ′, from the QKD center 100 via a channel 54 , and may store the received bit string therein for a authentication of the <figure-callout id="100" label="QKD center" filenames="US10958428-20210323-D00000.png,US10958428-2021

CLAIMS

Claims ( 15 )

What is claimed is:

1. A Quantum Key Distribution (QKD) center on a quantum network, comprising:

one or more processors; and

a memory having instructions stored thereon executed by the one or more processors to perform;

an authentication key sharing unit sharing authentication keys with QKD client devices;

a quantum key generation unit generating sifted keys, corresponding to the QKD client devices, using quantum states;

an error correction unit generating distribution output bit strings by correcting errors of the sifted keys, wherein the error correction unit corrects the errors of the sifted keys using Hamming code when a length of a block containing the errors becomes the length to which the Hamming code can be applied; and

a bit string operation unit calculating an encryption bit string by performing a cryptographic operation on the authentication keys and the distribution output bit strings corresponding to the QKD client devices,

wherein the bit string operation unit transmits the encryption bit string, calculated by performing a cryptographic operation on a second one of the authentication keys Ak B , a first one of the distribution output bit strings Rk A ′ and a second one of the distribution output bit strings Rk B ′, to any one of a first one of the QKD client devices and a second one of the QKD client devices only when authentication of the QKD center succeeds, wherein the cryptographic operation is as follows:

( Rk A ′⊕Rk B ′)∥ h AkB ( Rk A ′⊕Rk B ′)

where ⊕ corresponds to an XOR operation, ∥ corresponds to a concatenation and h AkB corresponds to a keyed hash function using the second authentication key Ak B .

2. The QKD center of claim 1 , wherein the quantum key generation unit randomly selects bases for quantum states corresponding to the QKD client devices using quantum mechanics, compares measurement bases for quantum states received from the QKD client deices, and generates sifted keys corresponding to bits that remain after checking security of a channel using bits on the same basis for the respective QKD client devices.

3. The QKD center of claim 1 , wherein the bit string operation unit is configured to prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on a first one of the authentication keys and a first one of the distribution output bit strings to a first one of the QKD client devices.

4. The QKD center of claim 1 , wherein the bit string operation unit is configured to prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on a second one of the authentication keys and a second one of the distribution output bit strings to a second one of the QKD client devices.

5. A Quantum Key Distribution (QKD) client device on a quantum network, comprising:

one or more processors; and

a memory having instructions stored thereon executed by the one or more processors to perform;

an authentication key sharing unit sharing authentication keys with a QKD center and an additional QKD client device;

a quantum key generation unit generating a sifted key, corresponding to the QKD center, using quantum states;

an error correction unit generating distribution output bit strings by correcting an error of the sifted key in conjunction with the QKD center, wherein the error correction unit corrects the errors of the sifted keys using Hamming code when a length of a block containing the errors becomes the length to which the Hamming code can be applied;

a bit string calculation unit calculating a shared key bit string by performing a cryptographic operation on one or more of a first distribution output bit string of the distribution output bit strings, a second distribution output bit string of the additional QKD client device, an inter-client authentication key, which is included in the authentication keys and is shared with the additional QKD client device, and an encryption bit string received from the QKD center, and

a privacy amplification unit generating a final key bit string by applying a hash function to the shared key bit string,

wherein, only when the authentication succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit receives the encryption bit string, which is calculated by performing a cryptographic operation on a second authentication key included in the authentication keys, the first distribution output bit string and the second distribution output bit string, the first distribution output bit string being generated by correcting an error of the sifted key in the QKD center, and the second distribution output bit string being generated by correcting an error of a sifted key of the additional QKD client device in the QKD center,

wherein the cryptographic operation is as follows:

( Rk A ′⊕Rk B ′)∥ h AkB ( Rk A ′⊕Rk B ′)

where ⊕ corresponds to an XOR operation, ∥ corresponds to a concatenation and h AkB corresponds to a keyed hash function using the second authentication key Ak B .

6. The QKD client device of claim 5 , wherein the quantum key generation unit selects a measurement basis for a quantum state corresponding to the QKD center using quantum mechanics, compares a preparation basis for a quantum state, received from the QKD center, and generates the sifted key, the sifted key corresponding to bits that remain after checking security of a channel using bits on the same basis.

7. The QKD client device of claim 5 , wherein the bit string calculation unit authenticates the QKD center to a first QKD client device by comparing a result of a cryptographic operation performed on a first authentication key, which is shared with the first QKD client device, and the first distribution output bit string with a result of a cryptographic operation performed on the first authentication key and the first distribution output bit string, the first authentication key being included in the authentication keys, the first distribution output bit string being included in the distribution output bit strings, and the first output bit string being included in the output bit strings.

8. The QKD client device of claim 5 , wherein the bit string calculation unit authenticates the QKD center to a second QKD client device by comparing a result of a cryptographic operation performed on a second authentication key, which is shared with the second QKD client device, and the second distribution output bit string with a result of a cryptographic operation performed on the second authentication key and the second distribution output bit string, the second authentication key being included in the authentication keys, the second distribution output bit string being included in the distribution output bit strings, and the second output bit string being included in the output bit strings.

9. The QKD client device of claim 5 , wherein the privacy amplification unit deletes some of information about a key, leaked to an eavesdropper in the process of error correction.

10. The QKD client device of claim 5 , wherein, only when the authentication succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit calculates an encrypted shared key by performing a cryptographic operation on the encryption bit string, the second authentication key and the second distribution output bit string.

11. The QKD client device of claim 10 , wherein, only when the authentication succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit calculates the shared key bit string by performing a cryptographic operation on the encrypted shared key and the inter-client authentication key.

12. The QKD client device of claim 10 , wherein, only when the authentication succeeds and the QKD client device is requested to communicate by the QKD center, the bit siring calculation unit calculates the shared key bit string by performing a cryptographic operation on the first distribution output bit string and the inter-client authentication key.

13. A quantum key distribution (QKD) method on a quantum network, comprising:

sharing authentication keys among a QKD center and a plurality of QKD client devices;

generating sifted keys, corresponding to the QKD center and the QKD client devices, using quantum states;

generating output bit strings by correcting errors of the sifted keys, wherein the errors of the sifted keys are corrected using Hamming code when a length of a block containing the errors becomes the length to which the Hamming code can be applied;

calculating a shared key bit string by performing a cryptographic operation on the output bit strings and an inter-client authentication key; and

generating a final key bit string by applying a hash function to the shared key bit string,

wherein the encryption bit string is calculated by performing a cryptographic operation on a second one of the authentication keys AkB, a first one of the distribution output bit strings Rk A ′ and a second one of the distribution output bit strings Rk B ′, to any one of a first one of the QKD client devices and a second one of the QKD client devices only when authentication of the QKD center succeeds, wherein the cryptographic operation is as follows:

( Rk A ′⊕Rk B ′)∥ h AkB ( Rk A ′⊕Rk B ′)

where ⊕ corresponds to an XOR operation, ∥ corresponds to a concatenation and h AkB corresponds to a keyed hash function using the second authentication key Ak B .

14. The QKD method of claim 13 , wherein the generating the sifted keys comprises selecting a preparation basis and a measurement basis for a quantum state using quantum mechanics, comparing a preparation basis of the QKD center with measurement basis of the QKD client devices, and generating the sifted keys corresponding to bits that remain after checking security of a quantum channel using bits on the same basis.

15. The QKD method of claim 13 , wherein the calculating the shared key bit string comprises:

calculating an encryption bit string by the QKD center,

calculating, by a QKD client device of the plurality of QKD client devices that requests communication, the shared key bit string, and

calculating, by a QKD client device of the plurality of QKD client devices that is requested to communicate, the shared key bit string.

US15/350,376

2016-05-20

2016-11-14

Apparatus for quantum key distribution on a quantum network and method using the same

Active

2037-05-18

US10958428B2

( en )

Applications Claiming Priority (2)

Application Number

Priority Date

Filing Date

Title

KR1020160061993A

KR101830339B1

( en )

2016-05-20

2016-05-20

Apparatus for quantum key distribution on a quantum network and method using the same

KR10-2016-0061993

2016-05-20

Publications (2)

Publication Number

Publication Date

US20170338952A1

US20170338952A1 ( en )

2017-11-23

US10958428B2

true

US10958428B2 ( en )

2021-03-23

Family

ID=60330590

Family Applications (1)

Application Number

Title

Priority Date

Filing Date

US15/350,376

Active

2037-05-18

US10958428B2

( en )

2016-05-20

2016-11-14

Apparatus for quantum key distribution on a quantum network and method using the same

Country Status (2)

Country

Link

US

( 1 )

US10958428B2

( en )

KR

( 1 )

KR101830339B1

( en )

Cited By (2)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US12088703B2

( en )

2021-05-10

2024-09-10

Electronics And Telecommunications Research Institute

Method and apparatus for control action based on software defined networking associated with quantum key distribution network management in quantum key distribution network

US12301710B2

( en )

2021-05-10

2025-05-13

Electronics And Telecommunications Research Institute

Method and apparatus for key relay control based on software defined networking in quantum key distribution network

Families Citing this family (62)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

KR102028098B1

( en )

*

2018-01-29

2019-10-02

한국전자통신연구원

Apparatus and method for authenticating using quantum cryptography communication

US10728029B1

( en )

*

2018-03-09

2020-07-28

Wells Fargo Bank, N.A.

Systems and methods for multi-server quantum session authentication

US10855454B1

( en )

2018-03-09

2020-12-01

Wells Fargo Bank, N.A.

Systems and methods for quantum session authentication

US10812258B1

( en )

2018-03-09

2020-10-20

Wells Fargo Bank, N.A.

Systems and methods for quantum session authentication

US11025416B1

( en )

*

2018-03-09

2021-06-01

Wells Fargo Bank, N.A.

Systems and methods for quantum session authentication

US11343087B1

( en )

2018-03-09

2022-05-24

Wells Fargo Bank, N.A.

Systems and methods for server-side quantum session authentication

CN108809636B

( en )

*

2018-04-26

2020-12-01

如般量子科技有限公司

Communication system for realizing message authentication between members based on group type quantum key card

CN108599943B

( en )

*

2018-05-03

2020-10-09

浙江工商大学

Multi-party quantum privacy comparison method suitable for strangers based on d-level single photons

KR102011042B1

( en )

*

2018-06-11

2019-08-14

한국과학기술연구원

Certificated quantum cryptosystem amd method

US12567981B2

( en )

2018-08-01

2026-03-03

Cable Television Laboratories, Inc.

Systems and methods for data authentication using composite keys and signatures

US11095439B1

( en )

2018-08-20

2021-08-17

Wells Fargo Bank, N.A.

Systems and methods for centralized quantum session authentication

US10855457B1

( en )

2018-08-20

2020-12-01

Wells Fargo Bank, N.A.

Systems and methods for single chip quantum random number generation

US10855453B1

( en )

2018-08-20

2020-12-01

Wells Fargo Bank, N.A.

Systems and methods for time-bin quantum session authentication

US10552120B1

( en )

2018-08-20

2020-02-04

Wells Fargo Bank, N.A.

Systems and methods for single chip quantum random number generation

US11190349B1

( en )

2018-08-20

2021-11-30

Wells Fargo Bank, N.A.

Systems and methods for providing randomness-as-a-service

US10540146B1

( en )

2018-08-20

2020-01-21

Wells Fargo Bank, N.A.

Systems and methods for single chip quantum random number generation

US11240013B1

( en )

*

2018-08-20

2022-02-01

Wells Fargo Bank, N.A.

Systems and methods for passive quantum session authentication

CN109104428A

( en )

*

2018-08-28

2018-12-28

南京航空航天大学

Internet of things data quantum encrypted transmission equipment and transmission method

US10887048B2

( en )

*

2018-09-27

2021-01-05

Apple Inc.

Bluetooth transmission using low density parity check

KR102148861B1

( en )

*

2018-11-05

2020-10-14

한국과학기술연구원

Method for authenticating using authentication qubit and quantum communication system thereof

CN109586909B

( en )

*

2019-01-21

2020-08-04

成都信息工程大学

Bell state quantum database access control and bidirectional identity authentication method

GB2581528B

( en )

*

2019-02-22

2022-05-18

Toshiba Kk

A method, a communication network and a node for exchanging a cryptographic key

CN110557252A

( en )

*

2019-09-30

2019-12-10

南方电网调峰调频发电有限公司信息通信分公司

Quantum security gateway key offline updating method

US11258580B2

( en )

*

2019-10-04

2022-02-22

Red Hat, Inc.

Instantaneous key invalidation in response to a detected eavesdropper

GB2590064B

( en )

*

2019-11-08

2022-02-23

Arqit Ltd

Quantum key distribution protocol

CN111294204B

( en )

*

2020-02-11

2022-01-11

苏州大学

Method for preparing cluster state based on five-bit brown state

CN111510289B

( en )

*

2020-04-14

2021-12-03

苏州大学

Bidirectional single-bit state preparation method based on Brown state and network coding

CN111555876B

( en )

*

2020-05-15

2021-08-31

苏州大学

A combined cycle remote state preparation method based on N-square control of non-maximally entangled channels

CN111555877B

( en )

*

2020-05-18

2022-01-11

苏州大学

Method for remotely preparing three-bit state based on five-bit Brown state controlled multi-party combination

CN111786681B

( en )

*

2020-06-08

2022-07-05

中国电子科技集团公司第三十研究所

Cascade decoding method suitable for data post-processing of CV-QKD system

CN111541539B

( en )

*

2020-06-23

2020-12-04

北京中创为南京量子通信技术有限公司

Method and device for improving error correction efficiency of quantum key distribution system

US12200122B1

( en )

*

2020-08-06

2025-01-14

Cable Television Laboratories, Inc.

Systems and methods for advanced quantum-safe PKI credentials for authentications

CN112769561B

( en )

*

2020-12-31

2022-10-04

广东国腾量子科技有限公司

Private key amplification method and system for multi-degree-of-freedom modulation QKD

GB2603113B

( en )

*

2021-01-13

2023-12-20

Arqit Ltd

System and method for key establishment

EP4298757B1

( en )

*

2021-02-23

2024-08-21

Telefonaktiebolaget LM Ericsson (publ)

Method and apparatus for a software defined network

US12627465B2

( en )

*

2021-03-02

2026-05-12

Sri International

Attribute based encryption with bounded collusion resistance

KR20240021193A

( en )

*

2021-05-31

2024-02-16

후아웨이 테크놀로지스 캐나다 컴퍼니, 리미티드

Method and system for two-qubit multi-user quantum key distribution protocol

CN113364586B

( en )

*

2021-06-17

2022-06-07

中南大学

Data coordination method of continuous variable quantum key distribution system

EP4374541A4

( en )

*

2021-07-20

2025-05-28

The Research Foundation for The State University of New York

SYSTEM AND METHOD FOR QUANTUM-SECURE MICRONETWORKS

CN113395158B

( en )

*

2021-08-18

2022-01-18

北京中创为南京量子通信技术有限公司

Message authentication key generation method and device and message authentication system

WO2023096586A2

( en )

*

2021-11-29

2023-06-01

Han Chuen LIM

Quantum key generation method and system

CN114362947B

( en )

*

2022-03-17

2022-12-02

成都量安区块链科技有限公司

Wide-area quantum key service method and system

CN114553419B

( en )

*

2022-03-24

2024-05-17

上海循态量子科技有限公司

Quantum identity authentication method and system based on continuous variable quantum key distribution

JP7848865B2

( en )

*

2022-05-11

2026-04-21

Ntt株式会社

Key exchange system, base station equipment, QKD equipment, method, and program

KR102564375B1

( en )

*

2022-05-23

2023-08-09

서울과학기술대학교 산학협력단

BLOCKCHAIN BASED DISTRIBUTED QUANTUM NETWORK SYSTEM AND METHOD FOR IoT NETWORK

US12549536B2

( en )

*

2022-05-30

2026-02-10

Omnissa, Llc

Bypassing a user passcode when accessing a gateway of a virtual disktop infrastructure system

CN117616788A

( en )

*

2022-06-22

2024-02-27

北京小米移动软件有限公司

A direct communication method and device for positioning services

JP7714507B2

( en )

*

2022-07-27

2025-07-29

株式会社東芝

KM device, QKD system, key management initiation control method and program

JP7728232B2

( en )

*

2022-07-27

2025-08-22

株式会社東芝

QKD device, QKD system, QKD start control method and program

US20260101188A1

( en )

*

2022-09-26

2026-04-09

Lg Electronics Inc.

Method for carrying out user authentication by applying pre-shared key to basis selection in quantum communication system, and device therefor

CN116032609A

( en )

*

2022-12-28

2023-04-28

国科量子通信网络有限公司

Login method and electronic equipment of quantum cloud desktop

JP2024118747A

( en )

*

2023-02-21

2024-09-02

日本電気株式会社

Receiver, shared information generation method, communication control method, and program in continuous quantum key distribution system

JP7753277B2

( en )

*

2023-03-17

2025-10-14

株式会社東芝

Key management device, quantum cryptography communication system, QKDN control device, information processing device, key management method, QKDN control method, information processing method, and program

US12543039B2

( en )

2023-06-16

2026-02-03

T-Mobile Innovations Llc

Authentication management method for non-3GPP access of a UE device to a 5G network

US12362942B2

( en )

*

2023-07-07

2025-07-15

Jpmorgan Chase Bank, N.A.

Systems and methods for secure client-server authentication with key recycling

US20250106012A1

( en )

*

2023-09-26

2025-03-27

Ciena Corporation

Quantum key distribution in an optical network and quantum-secured optical channels

US20250119734A1

( en )

*

2023-10-06

2025-04-10

T-Mobile Innovations Llc

Method for Device Security Gateway Function

CN117177239B

( en )

*

2023-11-03

2024-01-02

合肥工业大学

A quantum key-based data encryption communication system and method for TSP platform

US12574226B2

( en )

*

2023-11-30

2026-03-10

Cisco Technology, Inc.

Native continuous-variable quantum repeater

US20250286706A1

( en )

*

2024-03-05

2025-09-11

Transportation Ip Holdings, Llc

Communication system and method

CN119696783B

( en )

*

2025-02-21

2025-06-06

深圳市高斯通通信股份有限公司

Device-side deployment method and system for quantum key distribution and ICT integration

CN119788280B

( en )

*

2025-03-11

2025-08-01

北京全路通信信号研究设计院集团有限公司

Vehicle-ground communication key generation method, device, equipment and storage medium

Citations (16)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US20060056630A1

( en )

*

2004-09-13

2006-03-16

Zimmer Vincent J

Method to support secure network booting using quantum cryptography and quantum key distribution

KR100596404B1

( en )

2004-04-13

2006-07-03

한국전자통신연구원

Quantum key distribution method between multiparty or multigroup

US20070230688A1

( en )

*

2005-08-18

2007-10-04

Nec Corporation

Secret communication system and method for generating shared secret information

US20080147820A1

( en )

*

2006-12-19

2008-06-19

Nec Corporation

Method and system for managing shared information

US7889868B2

( en )

*

2005-09-30

2011-02-15

Verizon Business Global Llc

Quantum key distribution system

KR20110057448A

( en )

2009-11-24

2011-06-01

한국전자통신연구원

User Authentication Quantum Key Distribution Method

US20130101121A1

( en )

*

2010-06-15

2013-04-25

Los Alamos National Security Llc

Secure multi-party communication with quantum key distribution managed by trusted authority

US20130315395A1

( en )

*

2012-05-25

2013-11-28

The Johns Hopkins University

Embedded Authentication Protocol for Quantum Key Distribution Systems

US8681982B2

( en )

2008-12-05

2014-03-25

Qinetiq Limited

Method of establishing a quantum key for use between network nodes

KR20140054647A

( en )

2012-10-29

2014-05-09

에스케이텔레콤 주식회사

Method for enhancing security of secret key generated in quantum key distribution system

US20140372812A1

( en )

*

2011-09-12

2014-12-18

Norbert Lütkenhaus

System and method for quantum key distribution

US20150215122A1

( en )

*

2014-01-30

2015-07-30

Kabushiki Kaisha Toshiba

Quantum key distribution device, quantum key distribution system, and quantum key distribution method

US20150222619A1

( en )

*

2012-08-30

2015-08-06

Los Alamos National Security, Llc

Multi-factor authentication using quantum communication

US20150349920A1

( en )

*

2014-05-28

2015-12-03

Samsung Display Co., Ltd

Methods to transport forward error correction codes in a symbol encoded transmission stream

KR20150145238A

( en )

2013-04-22

2015-12-29

차이나 유니온페이 컴퍼니 리미티드

Offline pin authentication method and system for ic card

US9519796B1

( en )

*

2015-05-29

2016-12-13

Yoti Ltd

Systems and methods for electronic ticket management

2016

2016-05-20

KR

KR1020160061993A

patent/KR101830339B1/en

active

Active

2016-11-14

US

US15/350,376

patent/US10958428B2/en

active

Active

Patent Citations (19)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

KR100596404B1

( en )

2004-04-13

2006-07-03

한국전자통신연구원

Quantum key distribution method between multiparty or multigroup

US7496203B2

( en )

*

2004-04-13

2009-02-24

Electronics And Telecommunications Research Institute

Quantum-key distribution method between a plurality of users or groups

US20060056630A1

( en )

*

2004-09-13

2006-03-16

Zimmer Vincent J

Method to support secure network booting using quantum cryptography and quantum key distribution

US20070230688A1

( en )

*

2005-08-18

2007-10-04

Nec Corporation

Secret communication system and method for generating shared secret information

US7889868B2

( en )

*

2005-09-30

2011-02-15

Verizon Business Global Llc

Quantum key distribution system

US20080147820A1

( en )

*

2006-12-19

2008-06-19

Nec Corporation

Method and system for managing shared information

US8681982B2

( en )

2008-12-05

2014-03-25

Qinetiq Limited

Method of establishing a quantum key for use between network nodes

KR20110057448A

( en )

2009-11-24

2011-06-01

한국전자통신연구원

User Authentication Quantum Key Distribution Method

US8639927B2

( en )

2009-11-24

2014-01-28

Electronics And Telecommunications Research Institute

Method of user-authenticated quantum key distribution

US20130101121A1

( en )

*

2010-06-15

2013-04-25

Los Alamos National Security Llc

Secure multi-party communication with quantum key distribution managed by trusted authority

US20140372812A1

( en )

*

2011-09-12

2014-12-18

Norbert Lütkenhaus

System and method for quantum key distribution

US20130315395A1

( en )

*

2012-05-25

2013-11-28

The Johns Hopkins University

Embedded Authentication Protocol for Quantum Key Distribution Systems

US20150222619A1

( en )

*

2012-08-30

2015-08-06

Los Alamos National Security, Llc

Multi-factor authentication using quantum communication

KR20140054647A

( en )

2012-10-29

2014-05-09

에스케이텔레콤 주식회사

Method for enhancing security of secret key generated in quantum key distribution system

KR20150145238A

( en )

2013-04-22

2015-12-29

차이나 유니온페이 컴퍼니 리미티드

Offline pin authentication method and system for ic card

US20160071081A1

( en )

2013-04-22

2016-03-10

China Union-Pay Co., Ltd.

Offline pin authentication method and system for ic card

US20150215122A1

( en )

*

2014-01-30

2015-07-30

Kabushiki Kaisha Toshiba

Quantum key distribution device, quantum key distribution system, and quantum key distribution method

US20150349920A1

( en )

*

2014-05-28

2015-12-03

Samsung Display Co., Ltd

Methods to transport forward error correction codes in a symbol encoded transmission stream

US9519796B1

( en )

*

2015-05-29

2016-12-13

Yoti Ltd

Systems and methods for electronic ticket management

Cited By (2)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US12088703B2

( en )

2021-05-10

2024-09-10

Electronics And Telecommunications Research Institute

Method and apparatus for control action based on software defined networking associated with quantum key distribution network management in quantum key distribution network

US12301710B2

( en )

2021-05-10

2025-05-13

Electronics And Telecommunications Research Institute

Method and apparatus for key relay control based on software defined networking in quantum key distribution network

Also Published As

Publication number

Publication date

US20170338952A1

( en )

2017-11-23

KR20170130964A

( en )

2017-11-29

KR101830339B1

( en )

2018-03-29

Similar Documents

Publication

Publication Date

Title

US20170338952A1

( en )

2017-11-23

Apparatus for quantum key distribution on a quantum network and method using the same

US10432396B2

( en )

2019-10-01

Method, apparatus, and system for identity authentication

KR101314210B1

( en )

2013-10-02

A method of User-authenticated Quantum Key Distribution

CN109600350B

( en )

2021-10-29

System and method for secure communication between controllers in a vehicle network

CN106411521B

( en )

2020-02-18

Identity authentication method, device and system for quantum key distribution process

KR102063031B1

( en )

2020-01-07

Apparatus and method for quantum direct communication using single qubits

KR101999188B1

( en )

2019-07-11

Secure personal devices using elliptic curve cryptography for secret sharing

US10389525B2

( en )

2019-08-20

Method, apparatus, and system for quantum key distribution, privacy amplification, and data transmission

KR100979576B1

( en )

2010-09-01

Method and computer readable medium for realizing a new password

JP7440108B2

( en )

2024-02-28

Method and system for quantum key distribution

CA2747891C

Related documents

Record · ID 607396
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.