ABSTRACT
Abstract
A device and method for quantum key distribution (QKD). The QKD center includes an authentication key sharing unit for sharing authentication keys with QKD client devices; a quantum key generation unit for generating a sifted key for each of the QKD client devices using a quantum state; an error correction unit for generating output bit strings by correcting errors of the sifted keys; and a bit string operation unit for calculating an encryption bit string by performing a cryptographic operation on the authentication keys, the distribution output bit strings and output bit strings received from the QKD client devices. The present invention improves security by preventing the QKD center from being aware of keys shared among users.
Description
CROSS REFERENCE TO RELATED APPLICATION
This application claims the benefit of Korean Patent Application No. 10-2016-0061993 filed May 20, 2016, which is hereby incorporated by reference in its entirety into this application.
BACKGROUND OF THE INVENTION
1. Technical Field
The present invention relates to technology for securing a quantum key generated in a Quantum Key Distribution (QKD) system.
2. Description of the Related Art
A QKD system is configured such that, when a transmission unit transmits a randomly selected quantum state using two nonorthogonal bases, a reception unit receives it and estimates the quantum state using a randomly selected a measurement basis of two bases. Such a QKD system may provide an environment in which secure key distribution is guaranteed because an eavesdropper may be detected in the process of estimating the quantum state.
A QKD system has a limitation as to distance when the system is implemented. In order for two users, father farther apart from each other than the allowable distance, to share encryption keys using a QKD system, a method in which encryption keys are relaxed by a quantum repeater or a trustworthy key distribution center is used. Here, because it is not easy to implement a quantum repeater, a method for relaying encryption keys through a key distribution center is widely used. In this method, encryption keys, individually created by a key distribution center and users, are delivered to users. However, this method is problematic in that a security weak point exists in that the key distribution center is aware of the encryption keys shared among the users.
Meanwhile, Korean Patent Application Publication No. 10-2011-0057448, titled âA method of user-authenticated quantum key distributionâ, discloses a method for authenticating a quantum channel by sharing a position having the same basis without disclosing information about the basis using previously shared secret keys and checking whether there is the same measured outcome at that position in order to guarantee unconditional security of BB84 QKD protocol, which is vulnerable to man-in-the-middle attacks.
This invention was supported by the ICT R&D program of MSIP/IITP [1711028311, Reliable crypto-system standards and core technology development for secure quantum key distribution network] and the R&D Convergence program of NST (National Research Council of Science and Technology) of Republic of Korea (Grant No. CAP-18-08-KRISS).
SUMMARY OF THE INVENTION
An object of the present invention is to improve the security of quantum key distribution by preventing information about the encryption of quantum keys, which are finally distributed to quantum key distribution client devices, from being exposed to a quantum key-distribution center.
Another object of the present invention is to improve the security of quantum key distribution through the process of a cryptographic operation on au authentication key, shared among client devices, and an output bit string, in which an error is corrected.
A further object of the present invention is to distribute a quantum key encrypted with a hash function having improved security.
In order to accomplish the above objects, a QKD center on a quantum network according to an embodiment of the present invention includes an authentication key sharing unit for sharing authentication keys with QKD client devices; a quantum key generation unit for generating sifted keys, corresponding to the QKD client devices, using quantum states; an error correction unit for generating distribution output bit strings by correcting errors of the sifted keys; and a bit string operation unit for calculating an encryption bit string by performing a cryptographic operation on the authentication keys and the distribution output bit strings corresponding to the QKD client devices.
Here, the quantum key generation unit may randomly select bases for quantum states, corresponding to the QKD client devices, using quantum mechanics, compare measurement bases for quantum states, received from the QKD client devices, generate sifted keys, corresponding to bits that remain after checking security of a channel using bits on the same basis, for the respective QKD client devices.
Here, the error correction unit may generate distribution output bit strings by correcting the errors of the sifted keys. The error correction unit may correct the errors of the sifted keys using Hamming code, Winnow algorithm, LDPC or the like.
Here, the bit string operation unit is configured to prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on the first authentication key and the first distribution output bit string to the QKD client device.
Here, the bit string operation unit is configured to prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on the second authentication key and the second distribution output bit string to the QKD client device.
Here, the bit string operation unit may transmit the encryption bit string, calculated by performing a cryptographic operation on the second authentication key, the first distribution output bit siring and the second distribution output bit string, to any one of the first QKD client device and the second QKD client device only when authentication of the QKD center succeeds.
Also, in order to accomplish the above object, a QKD client device on a quantum network according to an embodiment of the present invention includes an authentication key sharing unit for sharing authentication keys with a QKD center and an additional QKD client device; a quantum key generation unit for generating a sifted key, corresponding to the QKD center, using a quantum states; an error correction unit for generating output bit strings by correcting an error of the sifted key in conjunction with the QKD center; a bit string calculation unit for calculating a shared key bit string by performing a cryptographic operation on one or more of a first output bit string, a second output bit string of the additional QKD client device, an inter-client authentication key, which is included in the authentication key and is shared with the additional QKD client device, and an encryption bit string received from the QKD center and a privacy amplification unit for generating a final key bit string by applying a hash function to the shared key bit string.
Here, the quantum key generation unit may select a measurement basis for a quantum state, corresponding to the QKD center, using quantum mechanics, compares a preparation basis for a quantum state, received from the QKD center, and generate a sifted key corresponding to bits that remain after checking security of a channel using bits on the same basis.
Here, the error correction unit may generate output bit strings by correcting the errors of the sifted keys. The error correction unit may correct the errors of the sifted keys using Hamming code, Window algorithm, LDPC or the like.
Here, the bit string calculation unit may authenticate the QKD center to a first QKD client device by comparing a result of a cryptographic operation performed on a first authentication key, which is shared with the first QKD client device, and a first distribution output bit string with a result of a cryptographic operation performed on the first authentication key and a first output bit string, the first authentication key being included in the authentication keys, the first distribution output bit string being included in the distribution output bit strings, and the first output bit string being included in the output bit strings.
Here, the bit string calculation unit may authenticate the QKD center to a second QKD client device by comparing a result of a cryptographic operation performed on a second authentication key, which is shared with the second QKD client device, and a second distribution output bit string with a result of a cryptographic operation performed on the second authentication key and a second output bit string, the second authentication key being included in the authentication keys, the second distribution output bit string being included in the distribution output bit strings, and the second output bit string being included in the output bit strings.
Here the privacy amplification unit may generate a final key bit string by applying a hash function. The privacy amplification unit may delete some of information about a key, leaked to an eavesdropper in the process of error correction.
Here, only when the authentication of the QKD center succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit may receive the encryption bit siring, which is calculated by performing a cryptographic operation on the second authentication key, the first distribution output bit string and the second distribution output bit string, the distribution output bit strings being generated by correcting an error of the sifted key in the QKD center.
Here, only when the authentication of the QKD center succeeds and the QKD client device requests the QKD center to communicate the bit string calculation unit may calculate an encrypted shared key by performing a cryptographic operation on the encryption bit string, the second authentication key and the second output bit string.
Here, only when the authentication of the QKD center succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit may calculate the shared key bit string by performing a cryptographic operation on the encrypted shared key and the inter-client authentication key.
Here, only when the authentication of the QKD center succeeds and the QKD client device is requested to communicate by the QKD center, the bit string calculation unit may calculate the shared key bit siring by performing a cryptographic operation on the first output bit string and the inter-client authentication key.
Also, in order to accomplish the above objects, a QKD method on a quantum network according to an embodiment of the present invention includes sharing authentication keys among the QKD center and the QKD client devices; generating sifted keys, corresponding to the QKD center and the QKD client devices, using quantum states; generating output bit strings by correcting errors of the sifted keys; calculating a shared key bit string by performing a cryptographic operation on the output bit strings and an inter-client authentication key; and generating a final key bit string by applying a hash function to the shared key bit string.
Here, the generating the sifted keys may be configured to select a preparation basis and a measurement basis for a quantum state using quantum mechanics, to compare a preparation basis of the QKD center with measurement basis of the QKD client devices, and to generate the sifted keys corresponding to bits that remain after checking security of a quantum channel using bits on the same basis.
Here, the generating output bit strings creates the output bit strings by correcting the errors of the sifted keys. The error correction methods use Hamming code, Winnow algorithm, LDPC or the like.
Here, the calculating the shared key bit string may include calculating an encryption bit string by the QKD center; calculating, by the QKD client device that requests communication, the shared key bit string; and calculating, by the QKD client device that is requested to communicate, the shared key bit string.
Here, the calculating the encryption bit string may be configured to transmit the encryption bit string, calculated using a result of a cryptographic operation performed on the second authentication key and the distribution output bit strings, to any one of the QKD client devices only when authentication of the QKD center succeeds.
Here, the calculating, by the QKD client device that requests communication, the shared key bit string may be configured such that only when authentication of the QKD center succeeds and any one of the QKD client devices requests the QKD center to communicate, the QKD client device that requests communication receives the encryption bit siring and calculates an encrypted shared key by performing a cryptographic operation on the received encryption bit string, the second authentication key and the second output bit string, generated by the QKD client device that requests communication.
Here, the calculating, by the QKD client device that requests communication, the shared key bit string may be configured such that only when authentication of the QKD center succeeds and any one of the QKD client devices requests the QKD center to communicate, the shared key bit siring is calculated by performing a cryptographic operation on the encrypted shared key and the inter-client authentication key, which is included in the authentication keys and shared among the QKD client devices.
Here, the calculating, by the QKD client device that is requested to communicate, the shared key bit string may be configured such that only when authentication of the QKD center succeeds and any one of the QKD client devices is requested to communicate by the QKD center, the shared key bit string is calculated by performing a cryptographic operation on the first output bit string, generated by the QKD client device that is requested to communicate, and the inter-client authentication key.
Here, the generating a final key bit string may be calculated by performing a hash function on the shared key bit string.
Here, the QKD center may not be aware of the shared key bit string, shared among the QKD client devices.
BRIEF DESCRIPTION OF THE DRAWINGS
The above and other objects, features and advantages of the present invention will be more clearly understood from the following detailed description taken in conjunction with the accompanying drawings, in which:
FIG. 1 is a block diagram illustrating a simple quantum key distribution (QKD) system according to an embodiment of the present invention;
FIG. 2 is a block diagram illustrating an example of the QKD center illustrated in FIG. 1 ;
FIG. 3 is a block diagram illustrating an example of the QKD client device illustrated in FIG. 1 ;
FIG. 4 is a block diagram illustrating an example of the QKD system illustrated in FIGS. 1 to 3 ;
FIG. 5 is a block diagram specifically illustrating an example of the quantum key generation unit of the QKD center and an example of the quantum key generation unit of the first QKD client device, illustrated in FIG. 4 ;
FIG. 6 is a block diagram specifically illustrating an example of the bit string calculation unit and an example of the bit string operation unit, illustrated in FIG. 4 ;
FIG. 7 is a block diagram specifically illustrating an example of the privacy amplification unit illustrated in FIG. 4 ;
FIG. 8 is a flowchart illustrating a
CROSS REFERENCE TO RELATED APPLICATION
This application claims the benefit of Korean Patent Application No. 10-2016-0061993 filed May 20, 2016, which is hereby incorporated by reference in its entirety into this application.
BACKGROUND OF THE INVENTION
1. Technical Field
The present invention relates to technology for securing a quantum key generated in a Quantum Key Distribution (QKD) system.
2. Description of the Related Art
A QKD system is configured such that, when a transmission unit transmits a randomly selected quantum state using two nonorthogonal bases, a reception unit receives it and estimates the quantum state using a randomly selected a measurement basis of two bases. Such a QKD system may provide an environment in which secure key distribution is guaranteed because an eavesdropper may be detected in the process of estimating the quantum state.
A QKD system has a limitation as to distance when the system is implemented. In order for two users, father farther apart from each other than the allowable distance, to share encryption keys using a QKD system, a method in which encryption keys are relaxed by a quantum repeater or a trustworthy key distribution center is used. Here, because it is not easy to implement a quantum repeater, a method for relaying encryption keys through a key distribution center is widely used. In this method, encryption keys, individually created by a key distribution center and users, are delivered to users. However, this method is problematic in that a security weak point exists in that the key distribution center is aware of the encryption keys shared among the users.
Meanwhile, Korean Patent Application Publication No. 10-2011-0057448, titled âA method of user-authenticated quantum key distributionâ, discloses a method for authenticating a quantum channel by sharing a position having the same basis without disclosing information about the basis using previously shared secret keys and checking whether there is the same measured outcome at that position in order to guarantee unconditional security of BB84 QKD protocol, which is vulnerable to man-in-the-middle attacks.
This invention was supported by the ICT R&D program of MSIP/IITP [1711028311, Reliable crypto-system standards and core technology development for secure quantum key distribution network] and the R&D Convergence program of NST (National Research Council of Science and Technology) of Republic of Korea (Grant No. CAP-18-08-KRISS).
SUMMARY OF THE INVENTION
An object of the present invention is to improve the security of quantum key distribution by preventing information about the encryption of quantum keys, which are finally distributed to quantum key distribution client devices, from being exposed to a quantum key-distribution center.
Another object of the present invention is to improve the security of quantum key distribution through the process of a cryptographic operation on au authentication key, shared among client devices, and an output bit string, in which an error is corrected.
A further object of the present invention is to distribute a quantum key encrypted with a hash function having improved security.
In order to accomplish the above objects, a QKD center on a quantum network according to an embodiment of the present invention includes an authentication key sharing unit for sharing authentication keys with QKD client devices; a quantum key generation unit for generating sifted keys, corresponding to the QKD client devices, using quantum states; an error correction unit for generating distribution output bit strings by correcting errors of the sifted keys; and a bit string operation unit for calculating an encryption bit string by performing a cryptographic operation on the authentication keys and the distribution output bit strings corresponding to the QKD client devices.
Here, the quantum key generation unit may randomly select bases for quantum states, corresponding to the QKD client devices, using quantum mechanics, compare measurement bases for quantum states, received from the QKD client devices, generate sifted keys, corresponding to bits that remain after checking security of a channel using bits on the same basis, for the respective QKD client devices.
Here, the error correction unit may generate distribution output bit strings by correcting the errors of the sifted keys. The error correction unit may correct the errors of the sifted keys using Hamming code, Winnow algorithm, LDPC or the like.
Here, the bit string operation unit is configured to prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on the first authentication key and the first distribution output bit string to the QKD client device.
Here, the bit string operation unit is configured to prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on the second authentication key and the second distribution output bit string to the QKD client device.
Here, the bit string operation unit may transmit the encryption bit string, calculated by performing a cryptographic operation on the second authentication key, the first distribution output bit siring and the second distribution output bit string, to any one of the first QKD client device and the second QKD client device only when authentication of the QKD center succeeds.
Also, in order to accomplish the above object, a QKD client device on a quantum network according to an embodiment of the present invention includes an authentication key sharing unit for sharing authentication keys with a QKD center and an additional QKD client device; a quantum key generation unit for generating a sifted key, corresponding to the QKD center, using a quantum states; an error correction unit for generating output bit strings by correcting an error of the sifted key in conjunction with the QKD center; a bit string calculation unit for calculating a shared key bit string by performing a cryptographic operation on one or more of a first output bit string, a second output bit string of the additional QKD client device, an inter-client authentication key, which is included in the authentication key and is shared with the additional QKD client device, and an encryption bit string received from the QKD center and a privacy amplification unit for generating a final key bit string by applying a hash function to the shared key bit string.
Here, the quantum key generation unit may select a measurement basis for a quantum state, corresponding to the QKD center, using quantum mechanics, compares a preparation basis for a quantum state, received from the QKD center, and generate a sifted key corresponding to bits that remain after checking security of a channel using bits on the same basis.
Here, the error correction unit may generate output bit strings by correcting the errors of the sifted keys. The error correction unit may correct the errors of the sifted keys using Hamming code, Window algorithm, LDPC or the like.
Here, the bit string calculation unit may authenticate the QKD center to a first QKD client device by comparing a result of a cryptographic operation performed on a first authentication key, which is shared with the first QKD client device, and a first distribution output bit string with a result of a cryptographic operation performed on the first authentication key and a first output bit string, the first authentication key being included in the authentication keys, the first distribution output bit string being included in the distribution output bit strings, and the first output bit string being included in the output bit strings.
Here, the bit string calculation unit may authenticate the QKD center to a second QKD client device by comparing a result of a cryptographic operation performed on a second authentication key, which is shared with the second QKD client device, and a second distribution output bit string with a result of a cryptographic operation performed on the second authentication key and a second output bit string, the second authentication key being included in the authentication keys, the second distribution output bit string being included in the distribution output bit strings, and the second output bit string being included in the output bit strings.
Here the privacy amplification unit may generate a final key bit string by applying a hash function. The privacy amplification unit may delete some of information about a key, leaked to an eavesdropper in the process of error correction.
Here, only when the authentication of the QKD center succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit may receive the encryption bit siring, which is calculated by performing a cryptographic operation on the second authentication key, the first distribution output bit string and the second distribution output bit string, the distribution output bit strings being generated by correcting an error of the sifted key in the QKD center.
Here, only when the authentication of the QKD center succeeds and the QKD client device requests the QKD center to communicate the bit string calculation unit may calculate an encrypted shared key by performing a cryptographic operation on the encryption bit string, the second authentication key and the second output bit string.
Here, only when the authentication of the QKD center succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit may calculate the shared key bit string by performing a cryptographic operation on the encrypted shared key and the inter-client authentication key.
Here, only when the authentication of the QKD center succeeds and the QKD client device is requested to communicate by the QKD center, the bit string calculation unit may calculate the shared key bit siring by performing a cryptographic operation on the first output bit string and the inter-client authentication key.
Also, in order to accomplish the above objects, a QKD method on a quantum network according to an embodiment of the present invention includes sharing authentication keys among the QKD center and the QKD client devices; generating sifted keys, corresponding to the QKD center and the QKD client devices, using quantum states; generating output bit strings by correcting errors of the sifted keys; calculating a shared key bit string by performing a cryptographic operation on the output bit strings and an inter-client authentication key; and generating a final key bit string by applying a hash function to the shared key bit string.
Here, the generating the sifted keys may be configured to select a preparation basis and a measurement basis for a quantum state using quantum mechanics, to compare a preparation basis of the QKD center with measurement basis of the QKD client devices, and to generate the sifted keys corresponding to bits that remain after checking security of a quantum channel using bits on the same basis.
Here, the generating output bit strings creates the output bit strings by correcting the errors of the sifted keys. The error correction methods use Hamming code, Winnow algorithm, LDPC or the like.
Here, the calculating the shared key bit string may include calculating an encryption bit string by the QKD center; calculating, by the QKD client device that requests communication, the shared key bit string; and calculating, by the QKD client device that is requested to communicate, the shared key bit string.
Here, the calculating the encryption bit string may be configured to transmit the encryption bit string, calculated using a result of a cryptographic operation performed on the second authentication key and the distribution output bit strings, to any one of the QKD client devices only when authentication of the QKD center succeeds.
Here, the calculating, by the QKD client device that requests communication, the shared key bit string may be configured such that only when authentication of the QKD center succeeds and any one of the QKD client devices requests the QKD center to communicate, the QKD client device that requests communication receives the encryption bit siring and calculates an encrypted shared key by performing a cryptographic operation on the received encryption bit string, the second authentication key and the second output bit string, generated by the QKD client device that requests communication.
Here, the calculating, by the QKD client device that requests communication, the shared key bit string may be configured such that only when authentication of the QKD center succeeds and any one of the QKD client devices requests the QKD center to communicate, the shared key bit siring is calculated by performing a cryptographic operation on the encrypted shared key and the inter-client authentication key, which is included in the authentication keys and shared among the QKD client devices.
Here, the calculating, by the QKD client device that is requested to communicate, the shared key bit string may be configured such that only when authentication of the QKD center succeeds and any one of the QKD client devices is requested to communicate by the QKD center, the shared key bit string is calculated by performing a cryptographic operation on the first output bit string, generated by the QKD client device that is requested to communicate, and the inter-client authentication key.
Here, the generating a final key bit string may be calculated by performing a hash function on the shared key bit string.
Here, the QKD center may not be aware of the shared key bit string, shared among the QKD client devices.
BRIEF DESCRIPTION OF THE DRAWINGS
The above and other objects, features and advantages of the present invention will be more clearly understood from the following detailed description taken in conjunction with the accompanying drawings, in which:
FIG. 1 is a block diagram illustrating a simple quantum key distribution (QKD) system according to an embodiment of the present invention;
FIG. 2 is a block diagram illustrating an example of the QKD center illustrated in FIG. 1 ;
FIG. 3 is a block diagram illustrating an example of the QKD client device illustrated in FIG. 1 ;
FIG. 4 is a block diagram illustrating an example of the QKD system illustrated in FIGS. 1 to 3 ;
FIG. 5 is a block diagram specifically illustrating an example of the quantum key generation unit of the QKD center and an example of the quantum key generation unit of the first QKD client device, illustrated in FIG. 4 ;
FIG. 6 is a block diagram specifically illustrating an example of the bit string calculation unit and an example of the bit string operation unit, illustrated in FIG. 4 ;
FIG. 7 is a block diagram specifically illustrating an example of the privacy amplification unit illustrated in FIG. 4 ;
FIG. 8 is a flowchart illustrating a QKD method according to an embodiment of the present invention;
FIG. 9 is a flowchart specifically illustrating an example of the step of generating a sifted key, illustrated in FIG. 8 ;
FIG. 10 is a flowchart specifically illustrating an example of the step of generating an output bit string, illustrated in FIG. 8 ;
FIG. 11 is a flowchart specifically illustrating an example of the step of calculating a shared key bit string, illustrated in FIG. 8 ; and
FIG. 12 is a block diagram illustrating a computer system according to an embodiment of the present indention.
DESCRIPTION OF THE PREFERRED EMBODIMENTS
The present invention will be described in detail below with reference to the accompanying drawings. Repeated descriptions and descriptions of known functions and configurations which have been deemed to make the gist of the present invention unnecessarily obscure will be omitted below. The embodiments of the present invention are intended to fully describe the present invention to a person having ordinary knowledge in the art to which the present invention pertains. Accordingly, the shapes, sizes, etc. of components in the drawings may be exaggerated in order to make the description clearer.
Hereinafter, a preferred embodiment of the present invention will be described in detail with reference to the accompanying drawings.
FIG. 1 is a block diagram illustrating a QKD system according to an embodiment of the present invention. FIG. 2 is a block diagram specifically illustrating an example of the QKD center illustrated in FIG. 1 . FIG. 3 is a block diagram specifically illustrating an example of the QKD client device illustrated in FIG. 1 . FIG. 4 is a block diagram specifically illustrating an example of the QKD system illustrated in FIGS. 1 to 3 .
Referring to FIGS. 1 to 4 , a QKD system according to an embodiment of the present invention includes a QKD center 100 , a first QKD client device 200 , and a second QKD client device 300 .
The QKD center 100 may share authentication keys and keyed hash functions with the QKD client devices
200 and 300 in advance.
Here, the QKD center 100 may share a first authentication key and keyed hash function with the first QKD client device 200 , and may share a second authentication key and keyed hash function with the second QKD client deice 300 .
Here, the QKD center 100 may generate sifted keys, corresponding to the QKD client devices, using quantum states.
Here, the QKD client device
200 and 300 may authenticate the QKD center 100 , and the QKD center 100 may open a communication channel in response to a request by an authenticated user. Here, in order to authenticate the QKD center, the authentication keys shared with the QKD client devices, the output bit strings, the distribution output bit strings, and keyed hash functions may be used.
The QKD center 100 may generate distribution output bit strings by correcting the errors of the sifted keys. The distribution output bit strings may include a first distribution output bit string and a second distribution output bit string, wherein the first distribution output bit string is acquired in such a way that the QKD center 100 corrects the error of the sifted key, which is generated corresponding to the first QKD client device 200 and the second distribution output bit string is acquired in such a way that the QKD center 100 corrects the error of the sifted key, which is generated corresponding to the second QKD client device 300 .
The QKD center 100 may calculate an encryption bit string by performing a cryptographic operation on the second authentication key, shared with the QKD client 300 , and the distribution output bit strings, acquired by correcting the errors.
Here, the QKD center 100 may transmit the encryption bit string to the QKD client device that requests communication.
The first QKD client device 200 may be the QKD client device that is requested to communicate by the second QKD client device 300 .
The first QKD client device 200 may share authentication keys and keyed hash function with the QKD center 100 and the second QKD client device 300 , and may generate a sifted key corresponding to the QKD center 100 , using a quantum state.
Here, the first QKD client device 200 may share a first authentication key and keyed hash function with the QKD center 100 .
Here, the first QKD client device 200 may share an inter-client authentication key and a hash function with the second QKD client device 300 .
Here, the shared authentication keys, the sifted key, and a keyed hash function may be used for user authentication.
The first QKD client device 200 may generate a first output bit string by correcting the error of the sifted key corresponding to the QKD center 100 .
The first QKD client device 200 may calculate a shared key bit string by performing a cryptographic operation on the first output bit string and the inter-client authentication key, which is shared with the second QKD client device 300 .
The first QKD client device 200 may generate a final key bit string by applying a hash function to the shared key bit string.
The second QKD client device 300 may be the QKD client device that requests the first QKD client device 200 to communicate therewith.
The second QKD client device 300 may share authentication key with the QKD center 100 and the first QKD client device 200 , and may generate a sifted key, corresponding to the QKD center 100 , using a quantum state.
Here, the second QKD client device 300 may share a second authentication key and keyed hash function with the QKD center 100 .
Here, the second QKD client device 300 may share an inter-client authentication key and a hash function with the first QKD client device 200 .
Here, the shared authentication keys, the output bit strings, and a keyed hash function may be used for authentication of the QKD center.
The second QKD client device 300 may generate a second output bit string by correcting the error of the sifted key corresponding to the QKD center 100 .
The second QKD client device 300 may calculate a shared key bit string by performing a cryptographic operation on the second output bit string, the inter-client authentication key and the encryption bit string, which is received from the QKD center 100 .
The second QKD client device 300 may generate a final key bit string by applying a hash function to the shared key bit string.
Referring to FIG. 2 and FIG. 4 , a QKD center according to an embodiment of the present invention includes an authentication key sharing unit 101 , a quantum key generation unit 110 , an error correction unit 120 , and a bit string operation unit 130 .
The authentication key sharing unit 101 may share authentication keys with QKD client devices. Here, the authentication key sharing unit 101 may share a first authentication key Ak A with the first QKD client device 200 and may share a second authentication key Ak B with the second QKD client device 300 .
The quantum key generation unit 110 may generate sifted keys, corresponding to the QKD client devices, using quantum states.
Here, the quantum key generation unit 110 may include a quantum state transmission unit 111 , a random number generator 112 , a classical bit transceiver 113 , and a logic control unit 114 .
The quantum state transmission unit 111 may prepare a quantum state and transmit it via a quantum channel 51 . Here, the quantum state transmission unit 111 may transmit the quantum state through a quantum key distribution protocol such as BB84, B92, or the like.
The random number generator 112 may generate a random signal using quantum mechanics. Here, the random number generator 112 may randomly select a quantum preparation basis (polarization basis) and quantum states.
The classical bit transceiver 113 may receive the measurement basis selected by the random number generator 212 of the first QKD client device 200 , and may transmit the preparation basis, selected by the random number generator 112 .
Here, the logic control unit 114 checks the security of the quantum channel 51 by sharing the information about polarizing plates (preparation bases and measurement bases) with the first QKD client device 200 is a classical channel 52 , and may then transmit the information that remains after checking the security of the quantum channel to the error correction unit 120 ). Here, the classical channel 52 may be a public channel and may be eavesdropped on by anybody. However, in the classical channel 52 , falsification and the addition of additional information may not be allowed. For example, the classical channel 52 may correspond to the concept of a public board such as a newspaper. Here, the classical bit transceiver 113 may guarantee the integrity of information using Message Authentication Code (MAC).
Here, the logic control unit 114 may store information in order to compare the preparation basis for a quantum state, which is randomly selected by the random number generator 112 , with the measurement basis for a quantum state, which is randomly selected by the random, number generator 212 of the first QKD client device 200 .
Here, the logic control unit 114 compares the preparation basis for the quantum state with the measurement basis for the quantum state through communication between the classical bit transceiver 113 and the classical bit transceiver 213 of the first QKD client device 200 , and may check whether a channel is secure using some bits of the bit string on the same basis.
Here, the logic control unit 114 may output a sifted key based on the bits remaining after checking the security of the channel.
The above-mentioned process of generating the sifted key, performed by the quantum key generation unit 110 , may be applied not only to the first QKD client device 200 but also to the second QKD client device 300 .
The error correction unit 120 may generate distribution output bit strings by correcting the errors of the sifted keys. Here, the error correction unit 120 may correct the errors of the sifted keys using Hamming code, Winnow algorithm, LDPC or the like. Specifically, the error correction unit 120 divides the bit string to be transmitted into multiple blocks, and may transmit the parity bit of each of the blocks to the error correction unit
220 or 320 of the QKD client device via the classical channel
53 or 63 . The error correction unit
220 or 320 of the QKD client device may detect a block containing a data, error by checking the parity bit of the block. Then, the error correction unit 120 subdivides the block contain big the data, error, which is detected and announced by the error correction unit
220 or 320 of the QKD client device, and the parity of the subdivided block is repeatedly checked by the error correction unit
220 or 320 of the QKD client device. Through the repetition of this process, when the length of the block containing the parity error becomes the length to which Hamming code can be applied, the bit containing the error may be determined and corrected by applying Hamming code thereto. Here, the bit string generated by this error-correction process may correspond to a common output bit string between the error correction unit 120 and the error correction unit 220 of the first QKD client device 200 or a common output bit string between the error correction unit 120 and the error correction unit 320 of the second QKD client device 300 .
Here, the error correction unit 120 may output a first distribution output bit string Rk A â² by correcting the error of the sifted key corresponding to the first QKD client device 200 .
Here, the error correction unit 120 may output a second distribution output bit string Rk B â² by correcting the error of the sifted key corresponding to the second QKD client device 300 .
Here, the error correction unit 220 of the first QKD client device 200 may output a first output bit string Rk A by correcting the error of the sifted key corresponding to the QKD center 100 .
Here, the error correction unit 320 of the second QKD client device 300 may output a second output bit string Rk B by correcting the error of the sifted key corresponding to the QKD center 100 .
The bit siring operation unit 130 may prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on the first authentication key and the first distribution output bit string to the QKD client device.
The bit string operation unit 130 may prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on the second authentication key and the second distribution output bit string to the QKD client device.
The bit siring operation unit 130 may calculate an encryption bit string by performing a cryptographic operation on the second authentication key and the distribution output bit strings in which the error has been corrected.
The bit string operation unit 130 may transmit the encryption bit string, calculated by performing a cryptographic operation on the second authentication key, the first distribution output bit string and the second distribution output bit string, to any one of the first QKD client device and the second QKD client device only when authentication of the QKD center succeeds.
Here, the bit string operation unit 130 authenticates own identity to the QKD client devices, and may open a communication channel in response to the requests by users (QKD clients). Here, in order to prove own identity, the authentication keys, the distribution output bit strings, output bit strings, and a keyed hash function may be used.
The bit string operation unit 130 may include memory units
131 and 132 and an operation unit 135 .
The memory unit 131 may store the first distribution output bit string Rk A â², which is received from the error correction unit 120 . Here, the memory unit 231 may receive a bit string, acquired by performing an operation on the first authentication key Ak A and the first distribution output bit string Rk A â², from the QKD center 100 via a channel 54 , and may store the received bit string therein for a authentication of the <figure-callout id="100" label="QKD center" filenames="US10958428-20210323-D00000.png,US10958428-2021
CLAIMS
Claims ( 15 )
What is claimed is:
1. A Quantum Key Distribution (QKD) center on a quantum network, comprising:
one or more processors; and
a memory having instructions stored thereon executed by the one or more processors to perform;
an authentication key sharing unit sharing authentication keys with QKD client devices;
a quantum key generation unit generating sifted keys, corresponding to the QKD client devices, using quantum states;
an error correction unit generating distribution output bit strings by correcting errors of the sifted keys, wherein the error correction unit corrects the errors of the sifted keys using Hamming code when a length of a block containing the errors becomes the length to which the Hamming code can be applied; and
a bit string operation unit calculating an encryption bit string by performing a cryptographic operation on the authentication keys and the distribution output bit strings corresponding to the QKD client devices,
wherein the bit string operation unit transmits the encryption bit string, calculated by performing a cryptographic operation on a second one of the authentication keys Ak B , a first one of the distribution output bit strings Rk A â² and a second one of the distribution output bit strings Rk B â², to any one of a first one of the QKD client devices and a second one of the QKD client devices only when authentication of the QKD center succeeds, wherein the cryptographic operation is as follows:
( Rk A â²âRk B â²)⥠h AkB ( Rk A â²âRk B â²)
where â corresponds to an XOR operation, ⥠corresponds to a concatenation and h AkB corresponds to a keyed hash function using the second authentication key Ak B .
2. The QKD center of claim 1 , wherein the quantum key generation unit randomly selects bases for quantum states corresponding to the QKD client devices using quantum mechanics, compares measurement bases for quantum states received from the QKD client deices, and generates sifted keys corresponding to bits that remain after checking security of a channel using bits on the same basis for the respective QKD client devices.
3. The QKD center of claim 1 , wherein the bit string operation unit is configured to prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on a first one of the authentication keys and a first one of the distribution output bit strings to a first one of the QKD client devices.
4. The QKD center of claim 1 , wherein the bit string operation unit is configured to prove the identity of the QKD center by transmitting a result of a cryptographic operation performed on a second one of the authentication keys and a second one of the distribution output bit strings to a second one of the QKD client devices.
5. A Quantum Key Distribution (QKD) client device on a quantum network, comprising:
one or more processors; and
a memory having instructions stored thereon executed by the one or more processors to perform;
an authentication key sharing unit sharing authentication keys with a QKD center and an additional QKD client device;
a quantum key generation unit generating a sifted key, corresponding to the QKD center, using quantum states;
an error correction unit generating distribution output bit strings by correcting an error of the sifted key in conjunction with the QKD center, wherein the error correction unit corrects the errors of the sifted keys using Hamming code when a length of a block containing the errors becomes the length to which the Hamming code can be applied;
a bit string calculation unit calculating a shared key bit string by performing a cryptographic operation on one or more of a first distribution output bit string of the distribution output bit strings, a second distribution output bit string of the additional QKD client device, an inter-client authentication key, which is included in the authentication keys and is shared with the additional QKD client device, and an encryption bit string received from the QKD center, and
a privacy amplification unit generating a final key bit string by applying a hash function to the shared key bit string,
wherein, only when the authentication succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit receives the encryption bit string, which is calculated by performing a cryptographic operation on a second authentication key included in the authentication keys, the first distribution output bit string and the second distribution output bit string, the first distribution output bit string being generated by correcting an error of the sifted key in the QKD center, and the second distribution output bit string being generated by correcting an error of a sifted key of the additional QKD client device in the QKD center,
wherein the cryptographic operation is as follows:
( Rk A â²âRk B â²)⥠h AkB ( Rk A â²âRk B â²)
where â corresponds to an XOR operation, ⥠corresponds to a concatenation and h AkB corresponds to a keyed hash function using the second authentication key Ak B .
6. The QKD client device of claim 5 , wherein the quantum key generation unit selects a measurement basis for a quantum state corresponding to the QKD center using quantum mechanics, compares a preparation basis for a quantum state, received from the QKD center, and generates the sifted key, the sifted key corresponding to bits that remain after checking security of a channel using bits on the same basis.
7. The QKD client device of claim 5 , wherein the bit string calculation unit authenticates the QKD center to a first QKD client device by comparing a result of a cryptographic operation performed on a first authentication key, which is shared with the first QKD client device, and the first distribution output bit string with a result of a cryptographic operation performed on the first authentication key and the first distribution output bit string, the first authentication key being included in the authentication keys, the first distribution output bit string being included in the distribution output bit strings, and the first output bit string being included in the output bit strings.
8. The QKD client device of claim 5 , wherein the bit string calculation unit authenticates the QKD center to a second QKD client device by comparing a result of a cryptographic operation performed on a second authentication key, which is shared with the second QKD client device, and the second distribution output bit string with a result of a cryptographic operation performed on the second authentication key and the second distribution output bit string, the second authentication key being included in the authentication keys, the second distribution output bit string being included in the distribution output bit strings, and the second output bit string being included in the output bit strings.
9. The QKD client device of claim 5 , wherein the privacy amplification unit deletes some of information about a key, leaked to an eavesdropper in the process of error correction.
10. The QKD client device of claim 5 , wherein, only when the authentication succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit calculates an encrypted shared key by performing a cryptographic operation on the encryption bit string, the second authentication key and the second distribution output bit string.
11. The QKD client device of claim 10 , wherein, only when the authentication succeeds and the QKD client device requests the QKD center to communicate, the bit string calculation unit calculates the shared key bit string by performing a cryptographic operation on the encrypted shared key and the inter-client authentication key.
12. The QKD client device of claim 10 , wherein, only when the authentication succeeds and the QKD client device is requested to communicate by the QKD center, the bit siring calculation unit calculates the shared key bit string by performing a cryptographic operation on the first distribution output bit string and the inter-client authentication key.
13. A quantum key distribution (QKD) method on a quantum network, comprising:
sharing authentication keys among a QKD center and a plurality of QKD client devices;
generating sifted keys, corresponding to the QKD center and the QKD client devices, using quantum states;
generating output bit strings by correcting errors of the sifted keys, wherein the errors of the sifted keys are corrected using Hamming code when a length of a block containing the errors becomes the length to which the Hamming code can be applied;
calculating a shared key bit string by performing a cryptographic operation on the output bit strings and an inter-client authentication key; and
generating a final key bit string by applying a hash function to the shared key bit string,
wherein the encryption bit string is calculated by performing a cryptographic operation on a second one of the authentication keys AkB, a first one of the distribution output bit strings Rk A â² and a second one of the distribution output bit strings Rk B â², to any one of a first one of the QKD client devices and a second one of the QKD client devices only when authentication of the QKD center succeeds, wherein the cryptographic operation is as follows:
( Rk A â²âRk B â²)⥠h AkB ( Rk A â²âRk B â²)
where â corresponds to an XOR operation, ⥠corresponds to a concatenation and h AkB corresponds to a keyed hash function using the second authentication key Ak B .
14. The QKD method of claim 13 , wherein the generating the sifted keys comprises selecting a preparation basis and a measurement basis for a quantum state using quantum mechanics, comparing a preparation basis of the QKD center with measurement basis of the QKD client devices, and generating the sifted keys corresponding to bits that remain after checking security of a quantum channel using bits on the same basis.
15. The QKD method of claim 13 , wherein the calculating the shared key bit string comprises:
calculating an encryption bit string by the QKD center,
calculating, by a QKD client device of the plurality of QKD client devices that requests communication, the shared key bit string, and
calculating, by a QKD client device of the plurality of QKD client devices that is requested to communicate, the shared key bit string.
US15/350,376
2016-05-20
2016-11-14
Apparatus for quantum key distribution on a quantum network and method using the same
Active
2037-05-18
US10958428B2
( en )
Applications Claiming Priority (2)
Application Number
Priority Date
Filing Date
Title
KR1020160061993A
KR101830339B1
( en )
2016-05-20
2016-05-20
Apparatus for quantum key distribution on a quantum network and method using the same
KR10-2016-0061993
2016-05-20
Publications (2)
Publication Number
Publication Date
US20170338952A1
US20170338952A1 ( en )
2017-11-23
US10958428B2
true
US10958428B2 ( en )
2021-03-23
Family
ID=60330590
Family Applications (1)
Application Number
Title
Priority Date
Filing Date
US15/350,376
Active
2037-05-18
US10958428B2
( en )
2016-05-20
2016-11-14
Apparatus for quantum key distribution on a quantum network and method using the same
Country Status (2)
Country
Link
US
( 1 )
US10958428B2
( en )
KR
( 1 )
KR101830339B1
( en )
Cited By (2)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US12088703B2
( en )
2021-05-10
2024-09-10
Electronics And Telecommunications Research Institute
Method and apparatus for control action based on software defined networking associated with quantum key distribution network management in quantum key distribution network
US12301710B2
( en )
2021-05-10
2025-05-13
Electronics And Telecommunications Research Institute
Method and apparatus for key relay control based on software defined networking in quantum key distribution network
Families Citing this family (62)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
KR102028098B1
( en )
*
2018-01-29
2019-10-02
íêµì ìíµì ì°êµ¬ì
Apparatus and method for authenticating using quantum cryptography communication
US10728029B1
( en )
*
2018-03-09
2020-07-28
Wells Fargo Bank, N.A.
Systems and methods for multi-server quantum session authentication
US10855454B1
( en )
2018-03-09
2020-12-01
Wells Fargo Bank, N.A.
Systems and methods for quantum session authentication
US10812258B1
( en )
2018-03-09
2020-10-20
Wells Fargo Bank, N.A.
Systems and methods for quantum session authentication
US11025416B1
( en )
*
2018-03-09
2021-06-01
Wells Fargo Bank, N.A.
Systems and methods for quantum session authentication
US11343087B1
( en )
2018-03-09
2022-05-24
Wells Fargo Bank, N.A.
Systems and methods for server-side quantum session authentication
CN108809636B
( en )
*
2018-04-26
2020-12-01
å¦è¬éåç§ææéå ¬å¸
Communication system for realizing message authentication between members based on group type quantum key card
CN108599943B
( en )
*
2018-05-03
2020-10-09
æµæ±å·¥å大å¦
Multi-party quantum privacy comparison method suitable for strangers based on d-level single photons
KR102011042B1
( en )
*
2018-06-11
2019-08-14
íêµê³¼í기ì ì°êµ¬ì
Certificated quantum cryptosystem amd method
US12567981B2
( en )
2018-08-01
2026-03-03
Cable Television Laboratories, Inc.
Systems and methods for data authentication using composite keys and signatures
US11095439B1
( en )
2018-08-20
2021-08-17
Wells Fargo Bank, N.A.
Systems and methods for centralized quantum session authentication
US10855457B1
( en )
2018-08-20
2020-12-01
Wells Fargo Bank, N.A.
Systems and methods for single chip quantum random number generation
US10855453B1
( en )
2018-08-20
2020-12-01
Wells Fargo Bank, N.A.
Systems and methods for time-bin quantum session authentication
US10552120B1
( en )
2018-08-20
2020-02-04
Wells Fargo Bank, N.A.
Systems and methods for single chip quantum random number generation
US11190349B1
( en )
2018-08-20
2021-11-30
Wells Fargo Bank, N.A.
Systems and methods for providing randomness-as-a-service
US10540146B1
( en )
2018-08-20
2020-01-21
Wells Fargo Bank, N.A.
Systems and methods for single chip quantum random number generation
US11240013B1
( en )
*
2018-08-20
2022-02-01
Wells Fargo Bank, N.A.
Systems and methods for passive quantum session authentication
CN109104428A
( en )
*
2018-08-28
2018-12-28
å京èªç©ºèªå¤©å¤§å¦
Internet of things data quantum encrypted transmission equipment and transmission method
US10887048B2
( en )
*
2018-09-27
2021-01-05
Apple Inc.
Bluetooth transmission using low density parity check
KR102148861B1
( en )
*
2018-11-05
2020-10-14
íêµê³¼í기ì ì°êµ¬ì
Method for authenticating using authentication qubit and quantum communication system thereof
CN109586909B
( en )
*
2019-01-21
2020-08-04
æé½ä¿¡æ¯å·¥ç¨å¤§å¦
Bell state quantum database access control and bidirectional identity authentication method
GB2581528B
( en )
*
2019-02-22
2022-05-18
Toshiba Kk
A method, a communication network and a node for exchanging a cryptographic key
CN110557252A
( en )
*
2019-09-30
2019-12-10
åæ¹çµç½è°å³°è°é¢åçµæéå ¬å¸ä¿¡æ¯éä¿¡åå ¬å¸
Quantum security gateway key offline updating method
US11258580B2
( en )
*
2019-10-04
2022-02-22
Red Hat, Inc.
Instantaneous key invalidation in response to a detected eavesdropper
GB2590064B
( en )
*
2019-11-08
2022-02-23
Arqit Ltd
Quantum key distribution protocol
CN111294204B
( en )
*
2020-02-11
2022-01-11
èå·å¤§å¦
Method for preparing cluster state based on five-bit brown state
CN111510289B
( en )
*
2020-04-14
2021-12-03
èå·å¤§å¦
Bidirectional single-bit state preparation method based on Brown state and network coding
CN111555876B
( en )
*
2020-05-15
2021-08-31
èå·å¤§å¦
A combined cycle remote state preparation method based on N-square control of non-maximally entangled channels
CN111555877B
( en )
*
2020-05-18
2022-01-11
èå·å¤§å¦
Method for remotely preparing three-bit state based on five-bit Brown state controlled multi-party combination
CN111786681B
( en )
*
2020-06-08
2022-07-05
ä¸å½çµåç§æéå¢å ¬å¸ç¬¬ä¸åç ç©¶æ
Cascade decoding method suitable for data post-processing of CV-QKD system
CN111541539B
( en )
*
2020-06-23
2020-12-04
å京ä¸å为å京éåéä¿¡ææ¯æéå ¬å¸
Method and device for improving error correction efficiency of quantum key distribution system
US12200122B1
( en )
*
2020-08-06
2025-01-14
Cable Television Laboratories, Inc.
Systems and methods for advanced quantum-safe PKI credentials for authentications
CN112769561B
( en )
*
2020-12-31
2022-10-04
广ä¸å½è ¾éåç§ææéå ¬å¸
Private key amplification method and system for multi-degree-of-freedom modulation QKD
GB2603113B
( en )
*
2021-01-13
2023-12-20
Arqit Ltd
System and method for key establishment
EP4298757B1
( en )
*
2021-02-23
2024-08-21
Telefonaktiebolaget LM Ericsson (publ)
Method and apparatus for a software defined network
US12627465B2
( en )
*
2021-03-02
2026-05-12
Sri International
Attribute based encryption with bounded collusion resistance
KR20240021193A
( en )
*
2021-05-31
2024-02-16
íìì¨ì´ í í¬ëë¡ì§ì¤ ìºëë¤ ì»´í¼ë, 리미í°ë
Method and system for two-qubit multi-user quantum key distribution protocol
CN113364586B
( en )
*
2021-06-17
2022-06-07
ä¸å大å¦
Data coordination method of continuous variable quantum key distribution system
EP4374541A4
( en )
*
2021-07-20
2025-05-28
The Research Foundation for The State University of New York
SYSTEM AND METHOD FOR QUANTUM-SECURE MICRONETWORKS
CN113395158B
( en )
*
2021-08-18
2022-01-18
å京ä¸å为å京éåéä¿¡ææ¯æéå ¬å¸
Message authentication key generation method and device and message authentication system
WO2023096586A2
( en )
*
2021-11-29
2023-06-01
Han Chuen LIM
Quantum key generation method and system
CN114362947B
( en )
*
2022-03-17
2022-12-02
æé½éå®åºåé¾ç§ææéå ¬å¸
Wide-area quantum key service method and system
CN114553419B
( en )
*
2022-03-24
2024-05-17
䏿µ·å¾ªæéåç§ææéå ¬å¸
Quantum identity authentication method and system based on continuous variable quantum key distribution
JP7848865B2
( en )
*
2022-05-11
2026-04-21
ï¼®ï½ï½æ ªå¼ä¼ç¤¾
Key exchange system, base station equipment, QKD equipment, method, and program
KR102564375B1
( en )
*
2022-05-23
2023-08-09
ìì¸ê³¼í기ì ëíêµ ì°ííë ¥ë¨
BLOCKCHAIN BASED DISTRIBUTED QUANTUM NETWORK SYSTEM AND METHOD FOR IoT NETWORK
US12549536B2
( en )
*
2022-05-30
2026-02-10
Omnissa, Llc
Bypassing a user passcode when accessing a gateway of a virtual disktop infrastructure system
CN117616788A
( en )
*
2022-06-22
2024-02-27
å京å°ç±³ç§»å¨è½¯ä»¶æéå ¬å¸
A direct communication method and device for positioning services
JP7714507B2
( en )
*
2022-07-27
2025-07-29
æ ªå¼ä¼ç¤¾æ±è
KM device, QKD system, key management initiation control method and program
JP7728232B2
( en )
*
2022-07-27
2025-08-22
æ ªå¼ä¼ç¤¾æ±è
QKD device, QKD system, QKD start control method and program
US20260101188A1
( en )
*
2022-09-26
2026-04-09
Lg Electronics Inc.
Method for carrying out user authentication by applying pre-shared key to basis selection in quantum communication system, and device therefor
CN116032609A
( en )
*
2022-12-28
2023-04-28
å½ç§éåéä¿¡ç½ç»æéå ¬å¸
Login method and electronic equipment of quantum cloud desktop
JP2024118747A
( en )
*
2023-02-21
2024-09-02
æ¥æ¬é»æ°æ ªå¼ä¼ç¤¾
Receiver, shared information generation method, communication control method, and program in continuous quantum key distribution system
JP7753277B2
( en )
*
2023-03-17
2025-10-14
æ ªå¼ä¼ç¤¾æ±è
Key management device, quantum cryptography communication system, QKDN control device, information processing device, key management method, QKDN control method, information processing method, and program
US12543039B2
( en )
2023-06-16
2026-02-03
T-Mobile Innovations Llc
Authentication management method for non-3GPP access of a UE device to a 5G network
US12362942B2
( en )
*
2023-07-07
2025-07-15
Jpmorgan Chase Bank, N.A.
Systems and methods for secure client-server authentication with key recycling
US20250106012A1
( en )
*
2023-09-26
2025-03-27
Ciena Corporation
Quantum key distribution in an optical network and quantum-secured optical channels
US20250119734A1
( en )
*
2023-10-06
2025-04-10
T-Mobile Innovations Llc
Method for Device Security Gateway Function
CN117177239B
( en )
*
2023-11-03
2024-01-02
åè¥å·¥ä¸å¤§å¦
A quantum key-based data encryption communication system and method for TSP platform
US12574226B2
( en )
*
2023-11-30
2026-03-10
Cisco Technology, Inc.
Native continuous-variable quantum repeater
US20250286706A1
( en )
*
2024-03-05
2025-09-11
Transportation Ip Holdings, Llc
Communication system and method
CN119696783B
( en )
*
2025-02-21
2025-06-06
æ·±å³å¸é«æ¯ééä¿¡è¡ä»½æéå ¬å¸
Device-side deployment method and system for quantum key distribution and ICT integration
CN119788280B
( en )
*
2025-03-11
2025-08-01
åäº¬å ¨è·¯éä¿¡ä¿¡å·ç 究设计é¢é墿éå ¬å¸
Vehicle-ground communication key generation method, device, equipment and storage medium
Citations (16)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US20060056630A1
( en )
*
2004-09-13
2006-03-16
Zimmer Vincent J
Method to support secure network booting using quantum cryptography and quantum key distribution
KR100596404B1
( en )
2004-04-13
2006-07-03
íêµì ìíµì ì°êµ¬ì
Quantum key distribution method between multiparty or multigroup
US20070230688A1
( en )
*
2005-08-18
2007-10-04
Nec Corporation
Secret communication system and method for generating shared secret information
US20080147820A1
( en )
*
2006-12-19
2008-06-19
Nec Corporation
Method and system for managing shared information
US7889868B2
( en )
*
2005-09-30
2011-02-15
Verizon Business Global Llc
Quantum key distribution system
KR20110057448A
( en )
2009-11-24
2011-06-01
íêµì ìíµì ì°êµ¬ì
User Authentication Quantum Key Distribution Method
US20130101121A1
( en )
*
2010-06-15
2013-04-25
Los Alamos National Security Llc
Secure multi-party communication with quantum key distribution managed by trusted authority
US20130315395A1
( en )
*
2012-05-25
2013-11-28
The Johns Hopkins University
Embedded Authentication Protocol for Quantum Key Distribution Systems
US8681982B2
( en )
2008-12-05
2014-03-25
Qinetiq Limited
Method of establishing a quantum key for use between network nodes
KR20140054647A
( en )
2012-10-29
2014-05-09
ìì¤ì¼ì´í ë 콤 주ìíì¬
Method for enhancing security of secret key generated in quantum key distribution system
US20140372812A1
( en )
*
2011-09-12
2014-12-18
Norbert Lütkenhaus
System and method for quantum key distribution
US20150215122A1
( en )
*
2014-01-30
2015-07-30
Kabushiki Kaisha Toshiba
Quantum key distribution device, quantum key distribution system, and quantum key distribution method
US20150222619A1
( en )
*
2012-08-30
2015-08-06
Los Alamos National Security, Llc
Multi-factor authentication using quantum communication
US20150349920A1
( en )
*
2014-05-28
2015-12-03
Samsung Display Co., Ltd
Methods to transport forward error correction codes in a symbol encoded transmission stream
KR20150145238A
( en )
2013-04-22
2015-12-29
ì°¨ì´ë ì ëì¨íì´ ì»´í¼ë 리미í°ë
Offline pin authentication method and system for ic card
US9519796B1
( en )
*
2015-05-29
2016-12-13
Yoti Ltd
Systems and methods for electronic ticket management
2016
2016-05-20
KR
KR1020160061993A
patent/KR101830339B1/en
active
Active
2016-11-14
US
US15/350,376
patent/US10958428B2/en
active
Active
Patent Citations (19)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
KR100596404B1
( en )
2004-04-13
2006-07-03
íêµì ìíµì ì°êµ¬ì
Quantum key distribution method between multiparty or multigroup
US7496203B2
( en )
*
2004-04-13
2009-02-24
Electronics And Telecommunications Research Institute
Quantum-key distribution method between a plurality of users or groups
US20060056630A1
( en )
*
2004-09-13
2006-03-16
Zimmer Vincent J
Method to support secure network booting using quantum cryptography and quantum key distribution
US20070230688A1
( en )
*
2005-08-18
2007-10-04
Nec Corporation
Secret communication system and method for generating shared secret information
US7889868B2
( en )
*
2005-09-30
2011-02-15
Verizon Business Global Llc
Quantum key distribution system
US20080147820A1
( en )
*
2006-12-19
2008-06-19
Nec Corporation
Method and system for managing shared information
US8681982B2
( en )
2008-12-05
2014-03-25
Qinetiq Limited
Method of establishing a quantum key for use between network nodes
KR20110057448A
( en )
2009-11-24
2011-06-01
íêµì ìíµì ì°êµ¬ì
User Authentication Quantum Key Distribution Method
US8639927B2
( en )
2009-11-24
2014-01-28
Electronics And Telecommunications Research Institute
Method of user-authenticated quantum key distribution
US20130101121A1
( en )
*
2010-06-15
2013-04-25
Los Alamos National Security Llc
Secure multi-party communication with quantum key distribution managed by trusted authority
US20140372812A1
( en )
*
2011-09-12
2014-12-18
Norbert Lütkenhaus
System and method for quantum key distribution
US20130315395A1
( en )
*
2012-05-25
2013-11-28
The Johns Hopkins University
Embedded Authentication Protocol for Quantum Key Distribution Systems
US20150222619A1
( en )
*
2012-08-30
2015-08-06
Los Alamos National Security, Llc
Multi-factor authentication using quantum communication
KR20140054647A
( en )
2012-10-29
2014-05-09
ìì¤ì¼ì´í ë 콤 주ìíì¬
Method for enhancing security of secret key generated in quantum key distribution system
KR20150145238A
( en )
2013-04-22
2015-12-29
ì°¨ì´ë ì ëì¨íì´ ì»´í¼ë 리미í°ë
Offline pin authentication method and system for ic card
US20160071081A1
( en )
2013-04-22
2016-03-10
China Union-Pay Co., Ltd.
Offline pin authentication method and system for ic card
US20150215122A1
( en )
*
2014-01-30
2015-07-30
Kabushiki Kaisha Toshiba
Quantum key distribution device, quantum key distribution system, and quantum key distribution method
US20150349920A1
( en )
*
2014-05-28
2015-12-03
Samsung Display Co., Ltd
Methods to transport forward error correction codes in a symbol encoded transmission stream
US9519796B1
( en )
*
2015-05-29
2016-12-13
Yoti Ltd
Systems and methods for electronic ticket management
Cited By (2)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US12088703B2
( en )
2021-05-10
2024-09-10
Electronics And Telecommunications Research Institute
Method and apparatus for control action based on software defined networking associated with quantum key distribution network management in quantum key distribution network
US12301710B2
( en )
2021-05-10
2025-05-13
Electronics And Telecommunications Research Institute
Method and apparatus for key relay control based on software defined networking in quantum key distribution network
Also Published As
Publication number
Publication date
US20170338952A1
( en )
2017-11-23
KR20170130964A
( en )
2017-11-29
KR101830339B1
( en )
2018-03-29
Similar Documents
Publication
Publication Date
Title
US20170338952A1
( en )
2017-11-23
Apparatus for quantum key distribution on a quantum network and method using the same
US10432396B2
( en )
2019-10-01
Method, apparatus, and system for identity authentication
KR101314210B1
( en )
2013-10-02
A method of User-authenticated Quantum Key Distribution
CN109600350B
( en )
2021-10-29
System and method for secure communication between controllers in a vehicle network
CN106411521B
( en )
2020-02-18
Identity authentication method, device and system for quantum key distribution process
KR102063031B1
( en )
2020-01-07
Apparatus and method for quantum direct communication using single qubits
KR101999188B1
( en )
2019-07-11
Secure personal devices using elliptic curve cryptography for secret sharing
US10389525B2
( en )
2019-08-20
Method, apparatus, and system for quantum key distribution, privacy amplification, and data transmission
KR100979576B1
( en )
2010-09-01
Method and computer readable medium for realizing a new password
JP7440108B2
( en )
2024-02-28
Method and system for quantum key distribution
CA2747891C