ConceptioArchiveGoogle Patents
Google Patentsopen access

Quantum key distribution and management in passive optical networks — Cable Television Laboratories, Inc. (US11949783B1)

Cable Television Laboratories, Inc. · Google Patents
Google Patents · Patents · License: Open Access
Open Source ↗
cabletelevisionlaboratories
patent, google patents, intellectual property, US11949783B1, Cable Television Laboratories, Inc., Jing Wang, en, 2024

ABSTRACT

Abstract

Methods, systems, and devices for quantum key distribution (QKD) in passive optical networks (PONs) are described. A PON may be a point-to-multipoint system and may include a central node in communication with multiple remote nodes. In some cases, each remote node may include a QKD transmitter configured to generate a quantum pulse indicating a quantum key, a synchronization pulse generator configured to generate a timing indication of the quantum pulse, and filter configured to output the quantum pulse and the timing indication to the central node via an optical component (e.g., an optical splitter, a cyclic arrayed waveguide grating (AWG) router). The central node may receive the timing indications and quantum pulses from multiple remote nodes. Thus, the central node and remote nodes may be configured to communicate data encrypted using quantum keys.

Description

RELATED APPLICATIONS

This present Application for Patent is a continuation of U.S. Patent Application No. 17,073,207, filed Oct. 16, 2020, which Application claims the benefit of U.S. Provisional Patent Application No. 62/916,553 by Huberman et al., entitled “METHOD FOR CREATING A PROVABLE SECURE TRANSPORT LAYER (TLS) USING QUANTUM KEY DISTRIBUTION,” filed Oct. 17, 2019, U.S. Provisional Patent Application No. 62/928,118 by Huberman et al., entitled “METHOD FOR CREATING A PROVABLE SECURE TRANSPORT LAYER (TLS) USING QUANTUM KEY DISTRIBUTION (QKD) AND QKD-TLS KEY MANAGEMENT,” filed Oct. 30, 2019, and U.S. Provisional Patent Application No. 62/916,562 by Wang et al., entitled “SYSTEMS AND METHODS TO INTEGRATE QUANTUM KEY DISTRIBUTION INTO PASSIVE OPTICAL NETWORKS,” filed Oct. 17, 2019. Each of these applications are assigned to the assignee hereof, and expressly incorporated by reference herein in their entirety.

BACKGROUND

The field of the disclosure relates to quantum keys and more specifically to quantum key distribution (QKD) in passive optical networks (PONs).

PONs may include fiber-optic telecommunications technology for delivering broadband network access to end-customers. Additionally, PONs may implement point-to-multipoint topology, where a central node may serve multiple remote nodes by optical fibers using unpowered (e.g., passive) fiber optic components (e.g., optical splitters, wavelength multiplexers) to divide the fiber bandwidth among the multiple remote nodes. In some cases, a portion of the optical fiber coupling the central node with the multiple remote nodes may bottleneck a data capacity (e.g., a user capacity), decrease a speed of communications (e.g., introduce latency), or otherwise negatively affect a user experience. Additionally, the portion of the optical fiber coupling the central node with the multiple remote nodes may be vulnerable to security threats. That is, a cyber-attack may rely on the broadcast nature of the portion of the optical fiber to eavesdrop on unsecure communication of user data.

SUMMARY

The described techniques relate to improved methods, systems, devices, or apparatuses that support quantum key distribution (QKD) in passive optical networks (PONs). Generally the described techniques provide for distributing quantum keys to encrypt communications between a central node and one or more remote nodes (e.g., within a PON). That is, each of the one or more remote nodes may be coupled with the central node via a classical channel (e.g., for transmitting data) and a QKD channel (e.g., for transmitting quantum keys). In some cases, the classical channel and the QKD channel may rely on a same optical fiber. The remote nodes may each include a QKD transmitter for transmitting the quantum keys. Additionally, the central node may include a QKD receiver for receiving the quantum keys. In some examples, the remote nodes may communicate with the central node according to time division multiplexing. Here, a remote node may communicate a quantum key with the central node via a set of resources that are time division multiplexed with resources associated with one or more other remote nodes communicating with the central node. In another example, the remote nodes may communicate with the central node according to wavelength division multiplexing. Here, a remote node may communicate a quantum key with the central node via a set of resources that are wavelength division multiplexed with resources associated with one or more other remote nodes communicating with the central node. In either example, each of the remote nodes may transmit a quantum key to the central node for encrypting communications between the central node and the remote node. The central node and each of the one or more remote nodes may then communicate encrypted data based on the quantum keys.

Transport layer security (TLS) is a protocol used in networks (e.g., the Internet) for secure data transmissions. Enhancing TLS to support quantum keys as a basis for symmetric encryption and decryption of information may keep the information theoretically or provably secure from eavesdropping parties. Supporting quantum keys in TLS may include a key distribution layer to exchange quantum keys among nodes of the network connected via quantum channels to enable quantum secure communications among each of the nodes, even when not connected directly by a quantum channel. In some instances, a first network node may receive a quantum key from a second network node (e.g., for encrypting communications between the first network node and the second network node) by a QKD client at the first network node. The QKD client may be separate from a protocol stack of the first network node and the QKD client may then transfer the quantum key to an encryption protocol (e.g., TLS protocol) within the protocol stack of the first network node. The first network node may then rely on the quantum key to encrypt and decrypt communications with the second network node. In some cases, the first network node may additionally be configured to exchange secure communications with a third network node using a fourth quantum key. For example, the first network node may receive a second quantum key from the second network node derived from a third quantum key used for communications between the second network node and a third network node, and derive the third quantum key from the first quantum key and the second quantum key. The first network node may then exchange secure communications with the third network node using the fourth quantum key derived from the first key and the second key.

An apparatus configured for optical communications with a central node configured for communications with a set of remote nodes via an optical component coupled with the central node and the set of remote nodes, the set of remote nodes including the apparatus is described. The apparatus may include a QKD transmitter configured to identify resources from a set of resources shared by the set of remote nodes for outputting a quantum pulse indicating a quantum key for optical communications associated with the apparatus, and generate the quantum pulse based at least in part on the identifying. The apparatus may additionally include a synchronization pulse generator configured to generate a timing indication of the quantum pulse indicating the quantum key and a filter coupled with the QKD transmitter and the synchronization pulse generator and configured to output, to the optical component, the timing indication of the quantum pulse and the quantum pulse indicating the quantum key using the identified resources.

In some examples of the apparatus, the identified resources for outputting the quantum pulse are time division multiplexed with resources from the set of resources that are associated with the set of remote nodes, and the optical component is an optical splitter.

In some examples of the apparatus, the identified resources for outputting the quantum pulse are wavelength division multiplexed with resources from the set of resources that are associated with the set of remote nodes, and the optical component is cyclic arrayed waveguide grating (AWG) router.

In some cases, the apparatus may additionally include an optical switch that is configured to selectively couple the filter with the QKD transmitter and the synchronization pulse generator or couple the filter with a data transmitter and a data receiver.

In some instances, the apparatus may additionally include a data transmitter coupled with the filter and configured to identify data for transmission to the central node, encrypt, using the quantum key, the data for transmission to the central node, and communicate the encrypted data to the filter, where the filter is further configured to output the encrypted data to the optical component.

In some examples of the apparatus, the filter is further configured to receive encrypted data from the optical component, and the apparatus further includes a data receiver coupled with the filter and configured to decrypt the encrypted data using the quantum key.

In some cases of the apparatus, the filter is a course wavelength division multiplexer (CWDM).

A method at a remote node for optical communications with a central node that is configured for communications, via an optical component, with a set of remote nodes including the remote node is described. The method may include identifying, from a set of resources shared by the set of remote nodes, resources for outputting a quantum pulse indicating a quantum key for optical communications between the remote node and the central node, generating the quantum pulse and a timing indication of the quantum pulse based on identifying the resources, outputting, to the optical component, the timing indication of the quantum pulse, outputting, to the optical component using the identified resources, the quantum pulse indicating the quantum key based on outputting the timing indication of the quantum pulse, and communicating with the central node based on outputting the quantum pulse indicating the quantum key.

An apparatus at a remote node for optical communications with a central node that is configured for communications, via an optical component, with a set of remote nodes including the remote node is described. The apparatus may include a processor, memory in electronic communication with the processor, and instructions stored in the memory. The instructions may be executable by the processor to cause the apparatus to identify, from a set of resources shared by the set of remote nodes, resources for outputting a quantum pulse indicating a quantum key for optical communications between the remote node and the central node, generate the quantum pulse and a timing indication of the quantum pulse based on identifying the resources, output, to the optical component, the timing indication of the quantum pulse, output, to the optical component using the identified resources, the quantum pulse indicating the quantum key based on outputting the timing indication of the quantum pulse, and communicate with the central node based on outputting the quantum pulse indicating the quantum key.

Another apparatus at a remote node for optical communications with a central node that is configured for communications, via an optical component, with a set of remote nodes including the remote node is described. The apparatus may include means for identifying, from a set of resources shared by the set of remote nodes, resources for outputting a quantum pulse indicating a quantum key for optical communications between the remote node and the central node, means for generating the quantum pulse and a timing indication of the quantum pulse based on identifying the resources, means for outputting, to the optical component, the timing indication of the quantum pulse, means for outputting, to the optical component using the identified resources, the quantum pulse indicating the quantum key based on outputting the timing indication of the quantum pulse, and means for communicating with the central node based on outputting the quantum pulse indicating the quantum key.

A non-transitory computer-readable medium storing code at a remote node for optical communications with a central node that is configured for communications, via an optical component, with a set of remote nodes including the remote node is described. The code may include instructions executable by a processor to identify, from a set of resources shared by the set of remote nodes, resources for outputting a quantum pulse indicating a quantum key for optical communications between the remote node and the central node, generate the quantum pulse and a timing indication of the quantum pulse based on identifying the resources, output, to the optical component, the timing indication of the quantum pulse, output, to the optical component using the identified resources, the quantum pulse indicating the quantum key based on outputting the timing indication of the quantum pulse, and communicate with the central node based on outputting the quantum pulse indicating the quantum key.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, the identified resources for outputting the quantum pulse may be time division multiplexed with resources from the set of resources that may be associated with the set of remote nodes, and the optical component may be an optical splitter.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, the identified resources for outputting the quantum pulse may be wavelength division multiplexed with resources from the set of resources that may be associated with the set of remote nodes, and the optical component may be cyclic AWG router.

Some examples of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for generating a second quantum pulse indicating a second quantum key for optical communications between the remote node and the central node, and outputting, to the optical component after outputting the quantum pulse to the optical component, the second quantum pulse indicating the second quantum key based on outputting the timing indication, where the timing indication indicates a timing of the quantum pulse and the second quantum pulse.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, identifying resources for outputting the quantum key may include operations, features, means, or instructions for outputting, to the optical component, a request for time resources for outputting the quantum key, and receiving, from the optical component, an indication of the identified resources based on outputting the request for time resources.

Some examples of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for switching, from a first communication mode for communicating the quantum pulse to the central node, to a second communication mode for communicating data with the central node based on outputting the quantum pulse to the optical component, where communicating with the central node may be based on the switching.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, communicating with the central node may include operations, features, means, or instructions for encrypting, using the quantum key, data for transmission to the central node, and outputting the encrypted data to the optical component.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, communicating with the central node may include operations, features, means, or instructions for receiving encrypted data from the optical component, and decrypting, using the quantum key, the encrypted data received from the optical component.

An apparatus configured for optical communications with a set of remote nodes via an optical component coupled with the apparatus and the set of remote nodes is described. The apparatus may include a QKD receiver configured to receive, from a filter of the apparatus via a set of resources, a set of quantum pulses each indicating a quantum key for optical communications associated with one of the set of remote nodes, a synchronization pulse receiver configured to receive, from the filter, a set of timing indications each associated with one of the set of quantum pulses, where the QKD receiver is configured to receive each of the set of quantum pulses based at least in part on the set of timing indications, and the filter coupled with the QKD receiver and the synchronization pulse receiver and configured to receive, from the optical component, the set of quantum pulses and the set of timing indications, communicate the set of quantum pulses to the QKD receiver, and communicate the set of timing indications to the synchronization pulse receiver.

In some examples of the apparatus, each of the set of quantum pulses are received via resources that are time division multiplexed with the resources in the set of resources, and the optical component is an optical splitter.

In some examples of the apparatus, each of the set of quantum pulses are received via resources that are wavelength division multiplexed with resources in the set of resources, and the optical component is cyclic AWG router.

In some examples of the apparatus, the filter is configured to receive

RELATED APPLICATIONS

This present Application for Patent is a continuation of U.S. Patent Application No. 17,073,207, filed Oct. 16, 2020, which Application claims the benefit of U.S. Provisional Patent Application No. 62/916,553 by Huberman et al., entitled “METHOD FOR CREATING A PROVABLE SECURE TRANSPORT LAYER (TLS) USING QUANTUM KEY DISTRIBUTION,” filed Oct. 17, 2019, U.S. Provisional Patent Application No. 62/928,118 by Huberman et al., entitled “METHOD FOR CREATING A PROVABLE SECURE TRANSPORT LAYER (TLS) USING QUANTUM KEY DISTRIBUTION (QKD) AND QKD-TLS KEY MANAGEMENT,” filed Oct. 30, 2019, and U.S. Provisional Patent Application No. 62/916,562 by Wang et al., entitled “SYSTEMS AND METHODS TO INTEGRATE QUANTUM KEY DISTRIBUTION INTO PASSIVE OPTICAL NETWORKS,” filed Oct. 17, 2019. Each of these applications are assigned to the assignee hereof, and expressly incorporated by reference herein in their entirety.

BACKGROUND

The field of the disclosure relates to quantum keys and more specifically to quantum key distribution (QKD) in passive optical networks (PONs).

PONs may include fiber-optic telecommunications technology for delivering broadband network access to end-customers. Additionally, PONs may implement point-to-multipoint topology, where a central node may serve multiple remote nodes by optical fibers using unpowered (e.g., passive) fiber optic components (e.g., optical splitters, wavelength multiplexers) to divide the fiber bandwidth among the multiple remote nodes. In some cases, a portion of the optical fiber coupling the central node with the multiple remote nodes may bottleneck a data capacity (e.g., a user capacity), decrease a speed of communications (e.g., introduce latency), or otherwise negatively affect a user experience. Additionally, the portion of the optical fiber coupling the central node with the multiple remote nodes may be vulnerable to security threats. That is, a cyber-attack may rely on the broadcast nature of the portion of the optical fiber to eavesdrop on unsecure communication of user data.

SUMMARY

The described techniques relate to improved methods, systems, devices, or apparatuses that support quantum key distribution (QKD) in passive optical networks (PONs). Generally the described techniques provide for distributing quantum keys to encrypt communications between a central node and one or more remote nodes (e.g., within a PON). That is, each of the one or more remote nodes may be coupled with the central node via a classical channel (e.g., for transmitting data) and a QKD channel (e.g., for transmitting quantum keys). In some cases, the classical channel and the QKD channel may rely on a same optical fiber. The remote nodes may each include a QKD transmitter for transmitting the quantum keys. Additionally, the central node may include a QKD receiver for receiving the quantum keys. In some examples, the remote nodes may communicate with the central node according to time division multiplexing. Here, a remote node may communicate a quantum key with the central node via a set of resources that are time division multiplexed with resources associated with one or more other remote nodes communicating with the central node. In another example, the remote nodes may communicate with the central node according to wavelength division multiplexing. Here, a remote node may communicate a quantum key with the central node via a set of resources that are wavelength division multiplexed with resources associated with one or more other remote nodes communicating with the central node. In either example, each of the remote nodes may transmit a quantum key to the central node for encrypting communications between the central node and the remote node. The central node and each of the one or more remote nodes may then communicate encrypted data based on the quantum keys.

Transport layer security (TLS) is a protocol used in networks (e.g., the Internet) for secure data transmissions. Enhancing TLS to support quantum keys as a basis for symmetric encryption and decryption of information may keep the information theoretically or provably secure from eavesdropping parties. Supporting quantum keys in TLS may include a key distribution layer to exchange quantum keys among nodes of the network connected via quantum channels to enable quantum secure communications among each of the nodes, even when not connected directly by a quantum channel. In some instances, a first network node may receive a quantum key from a second network node (e.g., for encrypting communications between the first network node and the second network node) by a QKD client at the first network node. The QKD client may be separate from a protocol stack of the first network node and the QKD client may then transfer the quantum key to an encryption protocol (e.g., TLS protocol) within the protocol stack of the first network node. The first network node may then rely on the quantum key to encrypt and decrypt communications with the second network node. In some cases, the first network node may additionally be configured to exchange secure communications with a third network node using a fourth quantum key. For example, the first network node may receive a second quantum key from the second network node derived from a third quantum key used for communications between the second network node and a third network node, and derive the third quantum key from the first quantum key and the second quantum key. The first network node may then exchange secure communications with the third network node using the fourth quantum key derived from the first key and the second key.

An apparatus configured for optical communications with a central node configured for communications with a set of remote nodes via an optical component coupled with the central node and the set of remote nodes, the set of remote nodes including the apparatus is described. The apparatus may include a QKD transmitter configured to identify resources from a set of resources shared by the set of remote nodes for outputting a quantum pulse indicating a quantum key for optical communications associated with the apparatus, and generate the quantum pulse based at least in part on the identifying. The apparatus may additionally include a synchronization pulse generator configured to generate a timing indication of the quantum pulse indicating the quantum key and a filter coupled with the QKD transmitter and the synchronization pulse generator and configured to output, to the optical component, the timing indication of the quantum pulse and the quantum pulse indicating the quantum key using the identified resources.

In some examples of the apparatus, the identified resources for outputting the quantum pulse are time division multiplexed with resources from the set of resources that are associated with the set of remote nodes, and the optical component is an optical splitter.

In some examples of the apparatus, the identified resources for outputting the quantum pulse are wavelength division multiplexed with resources from the set of resources that are associated with the set of remote nodes, and the optical component is cyclic arrayed waveguide grating (AWG) router.

In some cases, the apparatus may additionally include an optical switch that is configured to selectively couple the filter with the QKD transmitter and the synchronization pulse generator or couple the filter with a data transmitter and a data receiver.

In some instances, the apparatus may additionally include a data transmitter coupled with the filter and configured to identify data for transmission to the central node, encrypt, using the quantum key, the data for transmission to the central node, and communicate the encrypted data to the filter, where the filter is further configured to output the encrypted data to the optical component.

In some examples of the apparatus, the filter is further configured to receive encrypted data from the optical component, and the apparatus further includes a data receiver coupled with the filter and configured to decrypt the encrypted data using the quantum key.

In some cases of the apparatus, the filter is a course wavelength division multiplexer (CWDM).

A method at a remote node for optical communications with a central node that is configured for communications, via an optical component, with a set of remote nodes including the remote node is described. The method may include identifying, from a set of resources shared by the set of remote nodes, resources for outputting a quantum pulse indicating a quantum key for optical communications between the remote node and the central node, generating the quantum pulse and a timing indication of the quantum pulse based on identifying the resources, outputting, to the optical component, the timing indication of the quantum pulse, outputting, to the optical component using the identified resources, the quantum pulse indicating the quantum key based on outputting the timing indication of the quantum pulse, and communicating with the central node based on outputting the quantum pulse indicating the quantum key.

An apparatus at a remote node for optical communications with a central node that is configured for communications, via an optical component, with a set of remote nodes including the remote node is described. The apparatus may include a processor, memory in electronic communication with the processor, and instructions stored in the memory. The instructions may be executable by the processor to cause the apparatus to identify, from a set of resources shared by the set of remote nodes, resources for outputting a quantum pulse indicating a quantum key for optical communications between the remote node and the central node, generate the quantum pulse and a timing indication of the quantum pulse based on identifying the resources, output, to the optical component, the timing indication of the quantum pulse, output, to the optical component using the identified resources, the quantum pulse indicating the quantum key based on outputting the timing indication of the quantum pulse, and communicate with the central node based on outputting the quantum pulse indicating the quantum key.

Another apparatus at a remote node for optical communications with a central node that is configured for communications, via an optical component, with a set of remote nodes including the remote node is described. The apparatus may include means for identifying, from a set of resources shared by the set of remote nodes, resources for outputting a quantum pulse indicating a quantum key for optical communications between the remote node and the central node, means for generating the quantum pulse and a timing indication of the quantum pulse based on identifying the resources, means for outputting, to the optical component, the timing indication of the quantum pulse, means for outputting, to the optical component using the identified resources, the quantum pulse indicating the quantum key based on outputting the timing indication of the quantum pulse, and means for communicating with the central node based on outputting the quantum pulse indicating the quantum key.

A non-transitory computer-readable medium storing code at a remote node for optical communications with a central node that is configured for communications, via an optical component, with a set of remote nodes including the remote node is described. The code may include instructions executable by a processor to identify, from a set of resources shared by the set of remote nodes, resources for outputting a quantum pulse indicating a quantum key for optical communications between the remote node and the central node, generate the quantum pulse and a timing indication of the quantum pulse based on identifying the resources, output, to the optical component, the timing indication of the quantum pulse, output, to the optical component using the identified resources, the quantum pulse indicating the quantum key based on outputting the timing indication of the quantum pulse, and communicate with the central node based on outputting the quantum pulse indicating the quantum key.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, the identified resources for outputting the quantum pulse may be time division multiplexed with resources from the set of resources that may be associated with the set of remote nodes, and the optical component may be an optical splitter.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, the identified resources for outputting the quantum pulse may be wavelength division multiplexed with resources from the set of resources that may be associated with the set of remote nodes, and the optical component may be cyclic AWG router.

Some examples of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for generating a second quantum pulse indicating a second quantum key for optical communications between the remote node and the central node, and outputting, to the optical component after outputting the quantum pulse to the optical component, the second quantum pulse indicating the second quantum key based on outputting the timing indication, where the timing indication indicates a timing of the quantum pulse and the second quantum pulse.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, identifying resources for outputting the quantum key may include operations, features, means, or instructions for outputting, to the optical component, a request for time resources for outputting the quantum key, and receiving, from the optical component, an indication of the identified resources based on outputting the request for time resources.

Some examples of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for switching, from a first communication mode for communicating the quantum pulse to the central node, to a second communication mode for communicating data with the central node based on outputting the quantum pulse to the optical component, where communicating with the central node may be based on the switching.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, communicating with the central node may include operations, features, means, or instructions for encrypting, using the quantum key, data for transmission to the central node, and outputting the encrypted data to the optical component.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, communicating with the central node may include operations, features, means, or instructions for receiving encrypted data from the optical component, and decrypting, using the quantum key, the encrypted data received from the optical component.

An apparatus configured for optical communications with a set of remote nodes via an optical component coupled with the apparatus and the set of remote nodes is described. The apparatus may include a QKD receiver configured to receive, from a filter of the apparatus via a set of resources, a set of quantum pulses each indicating a quantum key for optical communications associated with one of the set of remote nodes, a synchronization pulse receiver configured to receive, from the filter, a set of timing indications each associated with one of the set of quantum pulses, where the QKD receiver is configured to receive each of the set of quantum pulses based at least in part on the set of timing indications, and the filter coupled with the QKD receiver and the synchronization pulse receiver and configured to receive, from the optical component, the set of quantum pulses and the set of timing indications, communicate the set of quantum pulses to the QKD receiver, and communicate the set of timing indications to the synchronization pulse receiver.

In some examples of the apparatus, each of the set of quantum pulses are received via resources that are time division multiplexed with the resources in the set of resources, and the optical component is an optical splitter.

In some examples of the apparatus, each of the set of quantum pulses are received via resources that are wavelength division multiplexed with resources in the set of resources, and the optical component is cyclic AWG router.

In some examples of the apparatus, the filter is configured to receive the set of quantum pulses from the optical component via a first fiber, and the filter is configured to receive the set of timing indications from the optical component via a second fiber different from the first fiber.

In some cases the apparatus may further include a gate coupled with the QKD receiver and configured to selectively couple the QKD receiver with the filter based at least in part on the set of timing indications.

In some instances the apparatus may further include an optical switch that is configured to selectively couple the filter with the QKD receiver and the synchronization pulse receiver or couple the filter with a data transmitter and a data receiver.

In some examples the apparatus may further include a narrowband optical filter coupled with the filter and the QKD receiver and configured to communicate the set of quantum pulses from the filter to the QKD receiver.

In some cases the apparatus may further include a data transmitter coupled with the filter and configured to identify data for transmission to one remote node of the set of remote nodes, encrypt, using the quantum key for optical communications associated with the one remote node, the data for transmission to the one remote node, and communicate the encrypted data to the filter, where the filter is further configured to output the encrypted data to the optical component.

In some instances of the apparatus, the filter is further configured to receive, from the optical component, encrypted data associated with one remote node of the set of remote nodes, and the apparatus further includes a data receiver coupled with the filter and configured to decrypt the encrypted data using the quantum key for optical communications associated with the one remote node.

In some examples of the apparatus, the QKD may include a single photon detector (SPD).

In some cases of the apparatus, the filter is a CWDM.

A method at a central node for optical communications with a set of remote nodes via an optical component coupled with each of the set of remote nodes. The method may include receiving, from the optical component, a set of timing indications each associated with one of a set of quantum pulses each indicating a quantum key for optical communications associated with one of the set of remote nodes, receiving, from the optical component, the set of quantum pulses via a set of resources based on receiving the set of timing indications, and communicating with the set of remote nodes based on receiving the set of quantum pulses each indicating the quantum key for optical communications associated with one of the set of remote nodes.

An apparatus at a central node for optical communications with a set of remote nodes via an optical component coupled with each of the set of remote nodes. The apparatus may include a processor, memory in electronic communication with the processor, and instructions stored in the memory. The instructions may be executable by the processor to cause the apparatus to receive, from the optical component, a set of timing indications each associated with one of a set of quantum pulses each indicating a quantum key for optical communications associated with one of the set of remote nodes, receive, from the optical component, the set of quantum pulses via a set of resources based on receiving the set of timing indications, and communicate with the set of remote nodes based on receiving the set of quantum pulses each indicating the quantum key for optical communications associated with one of the set of remote nodes.

Another apparatus at a central node for optical communications with a set of remote nodes via an optical component coupled with each of the set of remote nodes. The apparatus may include means for receiving, from the optical component, a set of timing indications each associated with one of a set of quantum pulses each indicating a quantum key for optical communications associated with one of the set of remote nodes, means for receiving, from the optical component, the set of quantum pulses via a set of resources based on receiving the set of timing indications, and means for communicating with the set of remote nodes based on receiving the set of quantum pulses each indicating the quantum key for optical communications associated with one of the set of remote nodes.

A non-transitory computer-readable medium storing code at a central node for optical communications with a set of remote nodes via an optical component coupled with each of the set of remote nodes. The code may include instructions executable by a processor to receive, from the optical component, a set of timing indications each associated with one of a set of quantum pulses each indicating a quantum key for optical communications associated with one of the set of remote nodes, receive, from the optical component, the set of quantum pulses via a set of resources based on receiving the set of timing indications, and communicate with the set of remote nodes based on receiving the set of quantum pulses each indicating the quantum key for optical communications associated with one of the set of remote nodes.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, each of the set of quantum pulses may be received via resources that may be time division multiplexed with the resources in the set of resources, and the optical component may be an optical splitter.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, each of the set of quantum pulses may be received via resources that may be wavelength division multiplexed with resources in the set of resources, and the optical component may be cyclic AWG router.

Some examples of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for receiving, from the optical component, a request for time resources for one of the set of quantum pulses, and outputting, to the optical component, an indication of time resource within the set of resources for the one of the set of quantum pulses, where receiving the set of quantum pulses may be based on outputting the indication.

Some examples of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for switching, from a first communication mode for receiving the set of quantum pulses, to a second communication mode for communicating data with the set of remote nodes based on receiving the set of quantum pulses from the optical component, where communicating with the set of remote nodes may be based on the switching.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, communicating with the set of remote nodes may include operations, features, means, or instructions for identifying data for transmission to one remote node of the set of remote nodes, encrypting, using the quantum key for optical communications associated with the one remote node, the data for transmission to the central node, and communicating the encrypted data to the one remote node via the optical component.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, communicating with the set of remote nodes may include operations, features, means, or instructions for receiving, from the optical component, encrypted data associated with one remote node of the set of remote nodes, and decrypting, using the quantum key for optical communications associated with the one remote node, the encrypted data received from the optical component.

A method at a first network node including a protocol stack and a QKD client distinct from the protocol stack is described. The method may include receiving, by the QKD client, a first quantum key and a first quantum key identifier from a second network node, transferring the first quantum key and the first quantum key identifier from the QKD client of the first network node to the protocol stack of the first network node, and communicating, by an encryption protocol of the protocol stack, encrypted data with the second network node, where the encrypted data is encrypted using the first quantum key and includes an indication of the first quantum key identifier.

An apparatus at a first network node including a protocol stack and a QKD client distinct from the protocol stack is described. The apparatus may include a processor, memory in electronic communication with the processor, and instructions stored in the memory. The instructions may be executable by the processor to cause the apparatus to receive, by the QKD client, a first quantum key and a first quantum key identifier from a second network node, transfer the first quantum key and the first quantum key identifier from the QKD client of the first network node to the protocol stack of the first network node, and communicate, by an encryption protocol of the protocol stack, encrypted data with the second network node, where the encrypted data is encrypted using the first quantum key and includes an indication of the first quantum key identifier.

Another apparatus at a first network node including a protocol stack and a QKD client distinct from the protocol stack is described. The apparatus may include means for receiving, by the QKD client, a first quantum key and a first quantum key identifier from a second network node, means for transferring the first quantum key and the first quantum key identifier from the QKD client of the first network node to the protocol stack of the first network node, and means for communicating, by an encryption protocol of the protocol stack, encrypted data with the second network node, where the encrypted data is encrypted using the first quantum key and includes an indication of the first quantum key identifier.

A non-transitory computer-readable medium storing code at a first network node including a protocol stack and a QKD client distinct from the protocol stack is described. The code may include instructions executable by a processor to receive, by the QKD client, a first quantum key and a first quantum key identifier from a second network node, transfer the first quantum key and the first quantum key identifier from the QKD client of the first network node to the protocol stack of the first network node, and communicate, by an encryption protocol of the protocol stack, encrypted data with the second network node, where the encrypted data is encrypted using the first quantum key and includes an indication of the first quantum key identifier.

Some examples of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for receiving, from the second network node, a message including a second quantum key derived from a third quantum key associated with communications between the second network node and a third network node, identifying the third quantum key based on the second quantum key and the first quantum key, and communicating, by the encryption protocol of the protocol stack, second encrypted data with the third network node, where the second encrypted data may be encrypted using the first quantum key and the third quantum key.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, transferring the first quantum key and the first quantum key identifier may include operations, features, means, or instructions for transferring the first quantum key and the first quantum key identifier from the QKD client of the first network node to a key management layer of the first network node, and storing the first quantum key and the first quantum key identifier at a server associated with the key management layer, where communicating encrypted data with the second network node may be based on the storing.

Some examples of the method, apparatuses, and non-transitory computer-readable medium described herein may further include operations, features, means, or instructions for transmitting, by a key management layer of the first network node, a request for the first quantum key to a corresponding key management layer of the second network node, where receiving the first quantum key by the QKD client of the first network node may be based on transmitting the request.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, communicating encrypted data with the second network node further may include operations, features, means, or instructions for identifying data for transmission to the second network node, encrypting, by the encryption protocol of the protocol stack, the data for transmission to the second network node using the first quantum key, and transmitting, by the encryption protocol of the protocol stack, the encrypted data and the indication of the first quantum key identifier to the second network node.

In some examples of the method, apparatuses, and non-transitory computer-readable medium described herein, communicating encrypted data with the second network node further may include operations, features, means, or instructions for receiving, by the encryption protocol of the protocol stack, encrypted data from the second network node, where the encrypted data includes the indication of the first quantum key identifier, retrieving, by the encryption protocol of the protocol stack, the first quantum key from a server associated with a key management layer of the first network node based on the indication of the first quantum key identifier, and decrypting, by the encryption protocol of the protocol stack, the encrypted data using the first quantum key based on retrieving the first quantum key.

A first network node is described. The first network node may include a QKD client configured to receive, from a second network node, a first quantum key and a first quantum key identifier, a protocol stack distinct from and coupled with the QKD client, where the protocol stack includes an encryption protocol configured to receive the first quantum key and the first quantum key identifier from the QKD client, and communicate encrypted data with the second network node, where the encrypted data is encrypted using the first quantum key and includes an indication of the first quantum key identifier.

In some examples of the first network node, the protocol stack is configured to receive, from the second network node, a message including a second quantum key derived from a third quantum key associated with communications between the second network node and a third network node, identify the third quantum key based at least in part on the first quantum key and the second quantum key, and communicate second encrypted data with the third network node, where the second encrypted data is encrypted using the first quantum key and the third quantum key.

In some cases of the first network node, the first network node includes a key management layer coupled with the encryption protocol, where the key management layer is configured to store the first quantum key and the first quantum key identifier at a server associated with the key management layer, provide the first quantum key and the first quantum key identifier to the encryption protocol, where communicating encrypted data with the second network node is based at least in part on the storing.

In some instances of the first network node, the first network node includes a key management layer coupled with the encryption protocol configured to transmit a request for the first quantum key, where receiving the first quantum key by the QKD client of the first network node is based at least in part on transmitting the request.

In some examples of the first network node, the encryption protocol is further configured to identify data for transmission to the second network node, encrypt the data for transmission to the second network node using the first quantum key, and transmit the encrypted data and the indication of the first quantum key identifier to the second network node, where communicating encrypted data with the second network node is based at least in part on transmitting the encrypted data and the indication of the first quantum key identifier to the second network node.

In some cases of the first network node, the encryption protocol is further configured to receive, from the second network node, encrypted data including the indication of the first quantum key identifier, where communicating encrypted data with the second network node is based at least in part on receiving the encrypted data from the second network node, retrieve the first quantum key from a server associated with a key management layer of the first network node based at least in part on the indication of the first quantum key identifier, and decrypt the encrypted data using the first quantum key based at least in part on retrieving the first quantum key.

BRIEF DESCRIPTION OF THE DRAWINGS

FIG. 1 illustrates an example of a system that supports quantum key distribution (QKD) in passive optical networks (PONs) in accordance with examples as disclosed herein.

FIG. 2 A illustrates an example of a system that supports QKD in PONs in accordance with examples as disclosed herein.

FIG. 2 B illustrates an example of a wavelength plan that supports QKD in PONs in accordance with examples as disclosed herein.

FIG. 3 A illustrates an example of a system that supports QKD in PONs in accordance with examples as disclosed herein.

FIG. 3 B illustrates an example of a wavelength plan that supports QKD in PONs in accordance with examples as disclosed herein.

FIG. 4 A illustrates an example of a system that supports QKD in PONs in accordance with examples as disclosed herein.

FIG. 4 B illustrates an example of a wavelength plan that supports QKD in PONs in accordance with examples as disclosed herein.

FIG. 5 A illustrates an example of a system that supports QKD in PONs in accordance with examples as disclosed herein.

FIG. 5 B illustrates an example of a wavelength plan that supports QKD in PONs in accordance with examples as disclosed herein.

FIGS. 6 and 7 illustrates an example of a system that supports QKD in PONs in accordance with examples as disclosed herein.

FIG. 8 illustrates an example of a process flow that supports QKD in PONs in accordance with examples as disclosed herein.

FIG. 9 shows a block diagram of a remote node that supports QKD in PONs in accordance with aspects of the present disclosure.

FIG. 10 shows a block diagram of a central node that supports QKD in PONs in accordance with aspects of the present disclosure.

FIG. 11 shows a block diagram of a network node that supports QKD in PONs in accordance with aspects of the present disclosure.

FIGS. 12 through 15 show flowcharts illustrating a method or methods that support QKD in PONs in accordance with examples as disclosed herein.

DETAILED DESCRIPTION

A core network may be configured to provide data connectivity to one or more customers. In some cases, the core network may utilize a passive optical network (PON) to communicate data between a central node associated with the core network and one or more remote nodes (e.g., each associated with a customer). In an example of a point-to-multipoint PON, the central node may be configured to serve multiple remote nodes by optical fibers using unpowered (e.g., passive) fiber optic components (e.g., optical splitters, optical multiplexers) to divide the fiber bandwidth among the multiple remote nodes. Here, the central node may be configured to broadcast data to multiple remote nodes via a fiber optic component. In some instances, the central node and the remote nodes may encrypt data for communications in order to decrease a security risk associated with the broadcasted data. Some PONs may utilize symmetric encryption based on an advanced encryption standard (AES), which may encrypt data for each individual remote node (e.g., data for each individual user). In order for the keys to be communicated between the central and remote nodes, the PON may deliver a classical encryption key by public key infrastructure (PKI). Delivering a classical encryption key by PKI may include using asymmetric or public encryption to protect the key. However, security of classical encryption keys delivered by PKI may be vulnerable (e.g., against the advent of quantum computers).

To increase security associated with key distribution, a PON may use a quantum key distribution (QKD) (e.g., instead of a PKI). Here, a central node or remote node may utilize QKD to deliver quantum keys (e.g., by communicating various bits of logical value ‘0’ or ‘1’) to a different central node or a remote node. QKD may be more secure when compared to the classical ways of distributing keys. In some instances however, QKD may be sensitive to channel loss and noise, as QKD relies on single photons to carry qubits. As a result, QKD may be limited based on physical distance. For example, QKD may be relatively successful at fiber distances less than 500 kilometers and the key rate decreases as fiber distances increase. In some instances, decreasing an amount of noise from classical channels may increase a success of QKD. That is, utilizing a dedicated point-to-point fiber between a remote node and a central node for QKD may increase a success of QKD. Additionally, QKD distance may be extended (e.g., suitable for most long-haul, core, and metro area networks) by combining the dedicated point-to-point fiber with a trusted relay or satellite relay. Here, the data communicated via each hop (e.g., the communication of data from one device or node to another device or node) may be decrypted and re-encrypted, as each hop may be associated with individual keys. As a result, these options for improving a success of QKD may not be compatible with point-to-multipoint PONs (e.g., where a single central node communicates with multiple remote nodes).

In order to provide QKD for point-to-multipoint PONs, each remote node may be configured to include a quantum key transmitter to communicate a quantum key to a central node. That is, the central node may receive one or more quantum keys from various remote nodes via a single fiber and may utilize the quantum keys for secure communications with the various remote nodes. In some examples, the remote nodes may communicate with the central node according to time division multiplexing. Here, a remote node may communicate a quantum key with the central node via a set of resources that are time division multiplexed with resources associated with one or more other remote nodes communicating with the central node. In another example, the remote nodes may communicate with the central node according to wavelength division multiplexing. Here, a remote node may communicate a quantum key with the central node via a set of resources that are wavelength division multiplexed with resources associated with one or more other remote nodes communicating with the central node. In either example, each of the remote nodes may transmit a quantum key to the central node for encrypting communications between the central node and the remote node. The central node and each of the one or more remote nodes may then communicate encrypted data based on the quantum keys.

Network nodes that rely on quantum keys to encrypt data may enable the network nodes to rely on the quantum key as a basis for symmetric encryption and decryption of information. Additionally, communicating the data encrypted by quantum keys may be secure from eavesdropping parties. In some cases, a transport layer security (TLS) protocol (e.g., used in the internet for secure data transmissions) may rely on computationally difficult algorithms for symmetric encryption and decryption of information, which may less secure when compared to quantum key encryption and decryption. In some instances, a first network node may receive a quantum key from a second network node (e.g., for encrypting communications between the first network node and the second network node) by a QKD client at the first network node. The QKD client may be separate from a protocol stack of the first network node and the QKD client may then transfer the quantum key to an encryption protocol (e.g., TLS protocol) within the protocol stack of the first network node. The first network node may then rely on the quantum key to encrypt and decrypt communications with the second network node. The network nodes may additionally be configured to perform trusted relay of quantum keys. In some cases, the first network node may additionally be configured to exchange secure communications with a third network node using a fourth quantum key. For example, the first network node then receive a second key from the second network node derived from a third key used for communications between the second network node and a third network node, and derive the third key from the first key and the second key. The first network node may then exchange secure communications with the third network node using the fourth key derived from the first key and the second key.

Features of the disclosure are initially described in the context of systems and dies as described with reference to FIGS. 1 - 2 . Features of the disclosure are described in the context systems, wavelength plans, and a process flow as described with reference to FIGS. 2 A- 8 . These and other features of the disclosure are further illustrated by and described with reference to an apparatus diagram and flowcharts that relate to QKD in PONs as described with reference to FIGS. 9 - 15 .

FIG. 1 illustrates an example of a system 100 that supports QKD in a PON in accordance with various aspects of the present disclosure. The system 100 may be an example of a point-to- multipoint PON system 100 configured to communicate data between a central node 105 and multiple remote nodes 110 that is encrypted using quantum keys. The system 100 may include an optical component 115 , which may be an example of a power splitter or a wavelength multiplexer. Communications between the central node 105 and the optical component 115 may be via a feeder fiber and communications between the optical component 115 and each of the remote nodes 110 may be via drop fibers.

Each of the remote nodes 110 may be in communication with the central node 105 via the optical component 115 and using a set of resources. In some examples, the central node 105 may assign resources to the remote nodes 110 . Additionally, one or more remote nodes 110 may transmit a request (e.g., to the central node 105 ) for resources and the central node 105 may assign the resources in response to the request. In some cases, the remote nodes 110 may be in communication with the central node 105 using time division multiplexing (TDM). Here, each remote node 110 may be assigned resources for communication with the central node 105 that are associated with a time slot. In the example of TDM, packets associated with communications between the central node 105 and different remote nodes 110 may be multiplexed in the time domain. When the system 100 employs TDM for communications between the remote nodes 110 and the central node 105 , the system 100 may be referred to as a time division multiplexing-PON (TDM-PON). In some instances, TDM-PONs may be standardized in Ethernet PON (EPON), Gigabit PON (GPON), 10G-EPON, or XG-PON. In some other cases, the remote nodes 110 may be in communication with the central node 105 using wavelength-division multiplexing (WDM). Here, each remote node 110 may be assigned a dedicated wavelength (or wavelengths). When the system 100 employs WDM for communications between the remote nodes 110 and the central node 105 , the system 100 may be referred to as a WDM-PON.

The central node 105 and the remote nodes 110 may use quantum keys to encrypt communications between the central node 105 and the remote nodes 110 . That is, the central node 105 and the remote nodes 110 may use quantum keys to encrypt and decrypt both downstream data 120 and upstream data 135 . For example, the remote node 110 - a and central node 105 may use a quantum key (e.g., associated with communications between the remote node 110 - a and the central node 105 ) to encrypt and decrypt communications between the central node 105 and the remote node 110 - a . Each of the remote nodes 110 - a may include a QKD transmitter configured to generate and transmit the quantum pulses 130 to the central node 105 . Additionally, the central node 105 may include a QKD receiver configured to detect quantum pulses 130 from each of the remote nodes 110 . The QKD receiver may use single photon detectors (SPDs) (e.g., two SPDs, four SPDs, eight SPDs) for detecting single photons (e.g., the quantum pulses 130 ).

Prior to transmitting a quantum pulse 130 to the central node 105 , a remote node 110 may first communicate a timing indication 125 to the <figure-callout id="105" label="central node" filenames="US11949783

CLAIMS

Claims ( 20 )

What is claimed is:

1. A method, comprising:

performing quantum key distribution to generate and distribute a cryptographic key that is shared by a remote node of a passive optical network and a central node of the passive optical network, wherein said performing comprises:

generating, by the remote node, a quantum pulse and a timing indication that indicates the quantum pulse;

transmitting, by the remote node, the timing indication to a passive optical component of the passive optical network; and

transmitting, by the remote node and based on said transmitting the timing indication, the quantum pulse to the passive optical component.

2. The method of claim 1 , wherein said transmitting the timing indication and said transmitting the quantum pulse are performed using time-division multiplexing.

3. The method of claim 1 , wherein said transmitting the timing indication and said transmitting the quantum pulse are performed using wavelength-division multiplexing.

4. The method of claim 1 , wherein:

the remote node is one of a plurality of remote nodes, of the passive optical network, that share a set of resources; and

the method further comprises identifying allocated resources, of the set of resources, for quantum communications between the remote node and the central node.

5. The method of claim 4 , wherein:

said identifying comprises:

transmitting, by the remote node and to the passive optical component, a request for resources; and

receiving, by the remote node and from the passive optical component, an indication of the allocated resources; and

said transmitting the timing indication and said transmitting the quantum pulse are performed using the allocated resources.

6. The method of claim 1 ,

further comprising switching, by the remote node, from a first communication mode for quantum communication with the central node to a second communication mode for classical communication with the central node;

wherein said transmitting the timing indication and said transmitting the quantum pulse occur during the first communication mode.

7. The method of claim 1 , further comprising communicating with the central node via the passive optical component and based on the cryptographic key.

8. The method of claim 7 , wherein said communicating comprises:

encrypting, using the cryptographic key, unencrypted data to generate encrypted data; and

transmitting the encrypted data to the passive optical component.

9. The method of claim 7 , wherein said communicating comprises:

receiving encrypted data from the passive optical component; and

decrypting the encrypted data using the cryptographic key.

10. A method, comprising:

performing quantum key distribution to generate and distribute a cryptographic key that is shared by a remote node of a passive optical network and a central node of the passive optical network, wherein said performing comprises:

receiving, by the central node and from a passive optical component of the passive optical network, a timing indication indicating a quantum pulse; and

receiving, by the central node and from the passive optical component, the quantum pulse based on the timing indication.

11. The method of claim 10 , wherein said receiving the timing indication and said receiving the quantum pulse are performed with time-division multiplexing.

12. The method of claim 10 , wherein said receiving the timing indication and said receiving the quantum pulse are performed with wavelength-division multiplexing.

13. The method of claim 10 , wherein

the remote node is one of a plurality of remote nodes, of the passive optical network, that share a set of resources; and

receiving, from the passive optical component, a request for resources;

identifying, in response to said receiving the request, allocated resources of the set of resources for quantum communications between the remote node and the central node; and

transmitting, to the passive optical component, an indication of the allocated resources.

14. The method of claim 10 ,

further comprising switching, by the central node, from a first communication mode for quantum communication with the remote node to a second communication mode for classical communication with the remote node; and

wherein said receiving the timing indication and said receiving the quantum pulse occur during the first communication mode.

15. The method of claim 10 , further comprising communicating with the remote node via the passive optical component and based on the cryptographic key.

16. The method of claim 10 , further comprising gating, based on the timing indication, a quantum receiver of the central node such that the quantum receiver receives the quantum pulse during said gating.

17. The method of claim 16 , wherein said gating the quantum receiver comprises gating a single-photon detector of the quantum receiver.

18. The method of claim 16 , wherein said gating comprises driving an optical switch to couple the quantum pulse into the quantum receiver.

19. The method of claim 16 , further comprising detecting the quantum pulse with the quantum receiver simultaneously with said gating.

20. The method of claim 10 , further comprising spectrally filtering the quantum pulse prior to the quantum receiver.

US18/108,787

2019-10-17

2023-02-13

Quantum key distribution and management in passive optical networks

Active

US11949783B1

( en )

Priority Applications (1)

Application Number

Priority Date

Filing Date

Title

US18/108,787

US11949783B1

( en )

2019-10-17

2023-02-13

Quantum key distribution and management in passive optical networks

Applications Claiming Priority (5)

Application Number

Priority Date

Filing Date

Title

US201962916562P

2019-10-17

2019-10-17

US201962916553P

2019-10-17

2019-10-17

US201962928118P

2019-10-30

2019-10-30

US17/073,207

US11582031B2

( en )

2019-10-17

2020-10-16

Quantum key distribution and management in passive optical networks

US18/108,787

US11949783B1

( en )

2019-10-17

2023-02-13

Quantum key distribution and management in passive optical networks

Related Parent Applications (1)

Application Number

Title

Priority Date

Filing Date

US17/073,207

Continuation

US11582031B2

( en )

2019-10-17

2020-10-16

Quantum key distribution and management in passive optical networks

Publications (1)

Publication Number

Publication Date

US11949783B1

true

US11949783B1 ( en )

2024-04-02

Family

ID=75491439

Family Applications (3)

Application Number

Title

Priority Date

Filing Date

US17/073,187

Abandoned

US20210119787A1

( en )

2019-10-17

2020-10-16

Quantum key distribution and management in passive optical networks

US17/073,207

Active

2041-05-28

US11582031B2

( en )

2019-10-17

2020-10-16

Quantum key distribution and management in passive optical networks

US18/108,787

Active

US11949783B1

( en )

2019-10-17

2023-02-13

Quantum key distribution and management in passive optical networks

Family Applications Before (2)

Application Number

Title

Priority Date

Filing Date

US17/073,187

Abandoned

US20210119787A1

( en )

2019-10-17

2020-10-16

Quantum key distribution and management in passive optical networks

US17/073,207

Active

2041-05-28

US11582031B2

( en )

2019-10-17

2020-10-16

Quantum key distribution and management in passive optical networks

Country Status (5)

Country

Link

US

( 3 )

US20210119787A1

( en )

EP

( 1 )

EP4045967A4

( en )

CN

( 1 )

CN114631049B

( en )

CA

( 2 )

CA3299380A1

( en )

WO

( 1 )

WO2021077030A1

( en )

Cited By (1)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US20240039711A1

( en )

*

2022-08-01

2024-02-01

Mellanox Technologies, Ltd.

Bi-directional quantum interconnects

Families Citing this family (22)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US12567981B2

( en )

2018-08-01

2026-03-03

Cable Television Laboratories, Inc.

Systems and methods for data authentication using composite keys and signatures

US20210119787A1

( en )

*

2019-10-17

2021-04-22

Cable Television Laboratories, Inc.

Quantum key distribution and management in passive optical networks

US12200122B1

( en )

2020-08-06

2025-01-14

Cable Television Laboratories, Inc.

Systems and methods for advanced quantum-safe PKI credentials for authentications

GB2600446A

( en )

*

2020-10-29

2022-05-04

Airbus Sas

Free space optical communications terminal

PL436177A1

( en )

*

2020-11-30

2022-06-06

Uniwersytet Warszawski

Optical communication method for information transmission and cryptographic key distribution, and system for implementing the method

CN113364588B

( en )

*

2021-07-12

2022-05-17

中国科学技术大学

Quantum key distribution method and quantum key distribution system

EP4149049B8

( en )

*

2021-09-14

2025-02-19

Terra Quantum AG

Method for determining a quantum communication setup, quantum communication setup, computer program, and data processing system

GB2613330B

( en )

*

2021-10-18

2024-02-07

Arqit Ltd

Optical switching for quantum key distribution

US11831765B2

( en )

*

2021-12-30

2023-11-28

Ahp-Tech Inc.

System and method for protecting conventional quantum key distribution protocols

CN114499685B

( en )

*

2022-01-28

2023-10-20

中国科学技术大学

Signal processing methods, transmitter systems, electronic equipment and storage media

US12192328B1

( en )

2022-05-10

2025-01-07

Wells Fargo Bank, N.A.

Systems and methods for secure communication based on random key derivation

KR102814559B1

( en )

*

2022-05-30

2025-05-29

한국과학기술정보연구원

Network apparatus for quantum key distribution, and operation method for quantum key distribution network

CN117616788A

( en )

*

2022-06-22

2024-02-27

北京小米移动软件有限公司

A direct communication method and device for positioning services

CN115276981B

( en )

*

2022-07-28

2025-01-03

国家电网有限公司信息通信分公司

Quantum key distribution method, device and computer readable storage medium

US20240047229A1

( en )

*

2022-08-02

2024-02-08

Advanced Micro Devices, Inc.

Organic package core for a substrate with high density plated holes

CN115174078B

( en )

*

2022-08-08

2025-02-28

中兴通讯股份有限公司

Quantum key negotiation method, device, computer equipment and readable medium

JP7753277B2

( en )

*

2023-03-17

2025-10-14

株式会社東芝

Key management device, quantum cryptography communication system, QKDN control device, information processing device, key management method, QKDN control method, information processing method, and program

US20250286706A1

( en )

*

2024-03-05

2025-09-11

Transportation Ip Holdings, Llc

Communication system and method

DE102024204281A1

( en )

2024-05-07

2025-11-13

Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung eingetragener Verein

Optical communication nodes, optical communication network and methods for optical communication

CN118784214B

( en )

*

2024-06-17

2026-03-17

中国联合网络通信集团有限公司

A quantum-encrypted transmission method, system, and computer-readable storage medium

CN121367586A

( en )

*

2024-07-17

2026-01-20

科大国盾量子技术股份有限公司

Quantum key distribution system and method capable of tolerating high noise link

CN119834967B

( en )

*

2024-12-27

2025-09-26

中国科学技术大学

A data protection method integrating quantum keys into TLS

Citations (21)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US20060136714A1

( en )

*

2003-05-19

2006-06-22

Fujitsu Limited

Method and apparatus for encryption and decryption, and computer product

US20060222180A1

( en )

2002-10-15

2006-10-05

Elliott Brig B

Chip-scale transmitter for quantum cryptography

JP2007288694A

( en )

*

2006-04-19

2007-11-01

Nec Corp

Secret communication system and channel control method

US20080031459A1

( en )

2006-08-07

2008-02-07

Seth Voltz

Systems and Methods for Identity-Based Secure Communications

EP1927209A1

( en )

2005-09-19

2008-06-04

The Chinese University Of Hong Kong

System and method for quantum key distribution over wdm links

US20090016736A1

( en )

*

2006-02-10

2009-01-15

Magiq Technologies, Inc.

Systems and methods for transmitting quantum and classical signals over an optical network

US20090316910A1

( en )

*

2007-06-11

2009-12-24

Nec Corporation

Method and device for managing cryptographic keys in secret communications network

EP2164189A1

( en )

*

2008-09-12

2010-03-17

Hitachi, Ltd.

Passive optical network system and fault determination method

WO2011134507A1

( en )

2010-04-28

2011-11-03

Telefonaktiebolaget L M Ericsson (Publ)

Optical access network

JP2012080229A

( en )

*

2010-09-30

2012-04-19

Hitachi Information &amp; Communication Engineering Ltd

Receiver, reception control method, and communication system

US20120177201A1

( en )

*

2009-09-29

2012-07-12

Qinetiq Limited

Methods and apparatus for use in quantum key distribution

US20140289520A1

( en )

2013-03-25

2014-09-25

Kabushiki Kaisha Toshiba

Communication device, communication system, communication method, and computer program product

US20150310221A1

( en )

2014-04-28

2015-10-29

Intuit Inc.

Method and apparatus to rotate data encryption keys in databases with no down time

WO2016073552A1

( en )

2014-11-04

2016-05-12

Akamai Technologies, Inc.

Providing forward secrecy in a terminating ssl/tls connection proxy using ephemeral diffie-hellman key exchange

US20170214525A1

( en )

*

2013-06-08

2017-07-27

Quantumctek Co., Ltd.

Mobile secret communications method based on quantum key distribution network

CN107204812A

( en )

2016-03-18

2017-09-26

国科量子通信网络有限公司

Quantum key distribution and the method and device of passive optical access network fusion

US20170338951A1

( en )

2016-05-19

2017-11-23

Alibaba Group Holding Limited

Method and system for secure data transmission

US20180262243A1

( en )

2014-10-13

2018-09-13

Nxgen Partners Ip, Llc

System and method for combining mimo and mode-division multiplexing

EP3432509A1

( en )

2017-07-21

2019-01-23

ID Quantique S.A.

Quantum enhanced application security

US20210119788A1

( en )

*

2019-10-17

2021-04-22

Cable Television Laboratories, Inc.

Quantum key distribution and management in passive optical networks

US11616645B1

( en )

*

2019-05-08

2023-03-28

Cable Television Laboratories, Inc.

Encrypted data transmission in optical- and radio-access networks based on quantum key distribution

Family Cites Families (9)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US5768378A

( en )

*

1993-09-09

1998-06-16

British Telecommunications Public Limited Company

Key distribution in a multiple access network using quantum cryptography

US20060056630A1

( en )

*

2004-09-13

2006-03-16

Zimmer Vincent J

Method to support secure network booting using quantum cryptography and quantum key distribution

WO2014068959A1

( en )

*

2012-11-01

2014-05-08

日本電気株式会社

Light-receiving device in optical communication system, photon-detector control method and device, and photon-detector dark-count-rate evaluation method

CN104092538B

( en )

*

2014-07-15

2017-04-12

华南师范大学

Multi-user wavelength division multiplexing QKD network system and secret key distributing and sharing method thereof

CN104202157B

( en )

*

2014-09-16

2018-01-02

科大国盾量子技术股份有限公司

A synchronization method and device for a quantum key distribution system

CN104660602B

( en )

*

2015-02-14

2017-05-31

山东量子科学技术研究院有限公司

A kind of quantum key transfer control method and system

CN105162584B

( en )

*

2015-07-28

2018-11-27

中国科学技术大学

A kind of quantum key distribution system and method

CN108337088B

( en )

*

2018-02-08

2021-01-22

中国人民解放军战略支援部队信息工程大学

Single-fiber fusion quantum key distribution system, method and related system and method

GB2574597B

( en )

*

2018-06-08

2021-10-20

Toshiba Kk

A Quantum communication network

2020

2020-10-16

US

US17/073,187

patent/US20210119787A1/en

not_active

Abandoned

2020-10-16

WO

PCT/US2020/056172

patent/WO2021077030A1/en

not_active

Ceased

2020-10-16

US

US17/073,207

patent/US11582031B2/en

active

Active

2020-10-16

CA

CA3299380A

patent/CA3299380A1/en

active

Pending

2020-10-16

CA

CA3154434A

patent/CA3154434A1/en

active

Pending

2020-10-16

CN

CN202080072266.0A

patent/CN114631049B/en

active

Active

2020-10-16

EP

EP20876637.8A

patent/EP4045967A4/en

active

Pending

2023

2023-02-13

US

US18/108,787

patent/US11949783B1/en

active

Active

Patent Citations (21)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US20060222180A1

( en )

2002-10-15

2006-10-05

Elliott Brig B

Chip-scale transmitter for quantum cryptography

US20060136714A1

( en )

*

2003-05-19

2006-06-22

Fujitsu Limited

Method and apparatus for encryption and decryption, and computer product

EP1927209A1

( en )

2005-09-19

2008-06-04

The Chinese University Of Hong Kong

System and method for quantum key distribution over wdm links

US20090016736A1

( en )

*

2006-02-10

2009-01-15

Magiq Technologies, Inc.

Systems and methods for transmitting quantum and classical signals over an optical network

JP2007288694A

( en )

*

2006-04-19

2007-11-01

Nec Corp

Secret communication system and channel control method

US20080031459A1

( en )

2006-08-07

2008-02-07

Seth Voltz

Systems and Methods for Identity-Based Secure Communications

US20090316910A1

( en )

*

2007-06-11

2009-12-24

Nec Corporation

Method and device for managing cryptographic keys in secret communications network

EP2164189A1

( en )

*

2008-09-12

2010-03-17

Hitachi, Ltd.

Passive optical network system and fault determination method

US20120177201A1

( en )

*

2009-09-29

2012-07-12

Qinetiq Limited

Methods and apparatus for use in quantum key distribution

WO2011134507A1

( en )

2010-04-28

2011-11-03

Telefonaktiebolaget L M Ericsson (Publ)

Optical access network

JP2012080229A

( en )

*

2010-09-30

2012-04-19

Hitachi Information &amp; Communication Engineering Ltd

Receiver, reception control method, and communication system

US20140289520A1

( en )

2013-03-25

2014-09-25

Kabushiki Kaisha Toshiba

Communication device, communication system, communication method, and computer program product

US20170214525A1

( en )

*

2013-06-08

2017-07-27

Quantumctek Co., Ltd.

Mobile secret communications method based on quantum key distribution network

US20150310221A1

( en )

2014-04-28

2015-10-29

Intuit Inc.

Method and apparatus to rotate data encryption keys in databases with no down time

US20180262243A1

( en )

2014-10-13

2018-09-13

Nxgen Partners Ip, Llc

System and method for combining mimo and mode-division multiplexing

WO2016073552A1

( en )

2014-11-04

2016-05-12

Akamai Technologies, Inc.

Providing forward secrecy in a terminating ssl/tls connection proxy using ephemeral diffie-hellman key exchange

CN107204812A

( en )

2016-03-18

2017-09-26

国科量子通信网络有限公司

Quantum key distribution and the method and device of passive optical access network fusion

US20170338951A1

( en )

2016-05-19

2017-11-23

Alibaba Group Holding Limited

Method and system for secure data transmission

EP3432509A1

( en )

2017-07-21

2019-01-23

ID Quantique S.A.

Quantum enhanced application security

US11616645B1

( en )

*

2019-05-08

2023-03-28

Cable Television Laboratories, Inc.

Encrypted data transmission in optical- and radio-access networks based on quantum key distribution

US20210119788A1

( en )

*

2019-10-17

2021-04-22

Cable Television Laboratories, Inc.

Quantum key distribution and management in passive optical networks

Non-Patent Citations (6)

* Cited by examiner, † Cited by third party

Title

Amaral Gustavo C., et al: " WDM-PON Monitoring with Tunable Photon Counting OTDR, " IEEE Photonics Technology Letters, IEEE, USA, vol. 26, No. 13, Jul. 1, 2014 (Jul. 1, 2014), pp. 1279-1282, XOP011550969, ISSN: 1041-1135, DOI: 10.1109/LPT.2014.2320871 [retrieved on Jun. 10, 2014] *abstract*.

Chen et al; Metropolitan all-pass and inter-city quantum communication network; Dec. 2010; Optical society of America; pp. 1-9. (Year: 2010).

Choi, P. S. et al: " Quantum key distribution on a 10Gb/s WDM-PON, " Optical Fiber Communication (OFC), Collocated National Fiber Optic Engineers Conference, 2010 Conference on (OFC/NFOEC), IEEE, Piscataway, NJ, USA, Mar. 21, 2010 (Mar. 21, 2010), pp. 1-3, XP03167683.

Elboukhari, Mohamed et al. " Integration of Quantum Key Distribution in the TLS Protocol. " IJCSNS International Journal of Computer Science and Network Security, vol. 9. No. 12, (2009). (Year: 2009).

Kumavor P. D., et al: " Comparison of Four Multi-User Quantum Key Distribution Schemes Over Passive Optical Networks, " Journal of Lightwave Technology, IEEE, USA, vol. 23, No. 1, Jan. 1, 2005 (Jan. 1, 2005), pp. 168- j276, XP001227328, ISSN: 0733-8724, DOI: 10.1109/JLT.2004.834481 *abstract*.

Luo et al; Time Synchronization over Ethernet Passive Optical Networks; Oct. 2012; IEEE; pp. 1-7. (Year: 2012).

*

Cited By (2)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US20240039711A1

( en )

*

2022-08-01

2024-02-01

Mellanox Technologies, Ltd.

Bi-directional quantum interconnects

US12381722B2

( en )

*

2022-08-01

2025-08-05

Mellanox Technologies, Ltd.

Bi-directional quantum interconnects

Also Published As

Publication number

Publication date

CA3299380A1

( en )

2026-03-02

CA3154434A1

( en )

2021-04-22

EP4045967A4

( en )

2023-11-15

US11582031B2

( en )

2023-02-14

EP4045967A1

( en )

2022-08-24

WO2021077030A1

( en )

2021-04-22

US20210119787A1

( en )

2021-04-22

CN114631049A

( en )

2022-06-14

US20210119788A1

( en )

2021-04-22

CN114631049B

( en )

2025-07-25

Similar Documents

Publication

Publication Date

Title

US11582031B2

( en )

2023-02-14

Quantum key distribution and management in passive optical networks

US8483391B2

( en )

2013-07-09

Optical communication system and method for secure data communication using quantum key distribution

US11616645B1

( en )

2023-03-28

Encrypted data transmission in optical- and radio-access networks based on quantum key distribution

US8582769B2

( en )

2013-11-12

Secure communication over passive optical network (PON) with quantum encryption

US7248695B1

( en )

2007-07-24

Systems and methods for transmitting quantum and classical signals over an optical network

Berrevoets et al.

2022

Deployed measurement-device independent quantum key distribution and Bell-state measurements coexisting with standard internet data and networking equipment

US10348493B2

( en )

2019-07-09

Quantum key distribution system, method and apparatus based on trusted relay

JP5784612B2

( en )

2015-09-24

Method and apparatus for use in quantum key distribution

US10313113B2

( en )

2019-06-04

Quantum communication system and a quantum communication method

US20130051800A1

( en )

2013-02-28

System for integration of channels with quantum information in communication networks

CN101292455A

( en )

2008-10-22

Quantum Key Distribution System

CN103118308B

( en )

2016-02-24

A kind of soft exchange passive network supporting quantum communications

Nweke et al.

2005

Experimental characterization of the separation between wavelength-multiplexed quantum and classical communication channels

US20250150268A1

( en )

2025-05-08

Systems and methods for advanced quantum-safe pki credentials for authentications

Zhao et al.

2019

Quantum Key Distribution (QKD) over Software-Defined Optical

KR102194434B1

( en )

2020-12-24

Method for forming quantum key distribution network

Dibaj et al.

2024

Traffic-aware trusted node placement and resource allocation in multi-band EONs secured with QKD

Aleksic et al.

2014

Towards a smooth integration of quantum key distribution in metro networks

Dolejsky et al.

2023

Flexible reconfigurable entanglement-based quantum key distribution network

Aleksic et al.

2013

Distribution of quantum keys in optically transparent networks: Perspectives, limitations and challenges

Related documents

Record · ID 607397
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.