ConceptioArchiveGoogle Patents
Google Patentsopen access

Method and system for quantum key distribution based on trusted computing — Alibaba Group Holding Limited (US10103880B2)

Alibaba Group Holding Limited · Google Patents
Google Patents · Patents · License: Open Access
Open Source ↗
alibabagroupholdinglimitedyingfangfu
patent, google patents, intellectual property, US10103880B2, Alibaba Group Holding Limited, Yingfang Fu, en, 2018

ABSTRACT

Abstract

One embodiment described herein provides a system and method for negotiating quantum data keys between first and second entities. During operation, the system performs a mutual authentication between the first and second entities. In response to the mutual authentication succeeding, the first entity receives one or more sets of key-generation parameters from the second entity. In response to validating the sets of key-generation parameters, the first entity sends an acknowledgment message to the second entity, and extracts, from a quantum string shared between the first and second entities, one or more quantum data keys based on the key-generation parameters. A respective quantum data key comprises a number of bits extracted from the quantum string.

Description

RELATED APPLICATION

Under 35 U.S.C. § 119, this application claims the benefit and right of priority of Chinese Patent Application No. 201610900271.1, filed on 14 Oct. 2016.

This application is related to U.S. patent application Ser. No. 15/716,965, entitled “METHOD AND SYSTEM FOR DATA SECURITY BASED ON QUANTUM COMMUNICATION AND TRUSTED COMPUTING,” by inventor Yingfang Fu, filed 27 Sep. 2017; and U.S. patent application Ser. No. 15/717,729, entitled “METHOD AND SYSTEM FOR SECURE DATA STORAGE AND RETRIEVAL,” by inventor Yingfang Fu, filed 27 Sep. 2017, the disclosures of which are incorporated herein by reference in their entirety for all purposes.

BACKGROUND

Field

This disclosure is generally related to data security. More specifically, this disclosure is related to a system and method for quantum key distribution based on trusted computing technologies.

Related Art

In recent years, quantum encryption technologies have been developed. In quantum communication, information is transmitted based on quantum states, and the data security can be guaranteed by the laws of quantum mechanics, such as the uncertainty principle, the principle of quantum state measurement, and the no-cloning theorem. It has been shown that quantum cryptography can achieve unconditional data transmission security and detectability against eavesdroppers.

A number of quantum key distribution schemes (e.g., BB84 and E91 schemes) have been developed to allow two communication parties to securely produce and share a secret key known only to them. The two communication parties can then use the shared secret key to communicate with each other.

On the other hand, cloud computing has become a highly demanded service or utility due to the advantages of high computing power, cheap cost of services, high performance, scalability, accessibility as well as availability. In cloud computing, different services, including servers, storage, and application, can be delivered by the service provider to a customer's computers and devices via the Internet. More specifically, cloud computing allows users, and enterprises, with various computing capabilities to store and process data in either a privately owned cloud, or on a third-party server located in a data center in order to make data accessing mechanisms more efficient and reliable.

Although QKD systems may be deployed in cloud computing, they often cannot meet the quantity demand of the large-scale cloud computing, because raw keys produced by QKD schemes often need further optimization before they can be used in batches. Moreover, although the secrecy of the key can be guaranteed, QKD alone cannot provide user authentication and guarantee the integrity of the platforms of the communicating parties.

SUMMARY

One embodiment described herein provides a system and method for negotiating quantum data keys between first and second entities. During operation, the system performs a mutual authentication between the first and second entities. In response to the mutual authentication succeeding, the first entity receives one or more sets of key-generation parameters from the second entity. In response to validating the sets of key-generation parameters, the first entity sends an acknowledgment message to the second entity, and extracts, from a quantum string shared between the first and second entities, one or more quantum data keys based on the key-generation parameters. A respective quantum data key comprises a number of bits extracted from the quantum string.

In a variation on this embodiment, the first and second entities are each equipped with a trusted-computing module, and performing the mutual authentication comprises exchanging a trusted measurement report associated with each of the first and second entities.

In a further variation, the first entity stores the extracted quantum data keys within the trusted-computing module.

In a variation on this embodiment, the quantum string shared between the first and second entities is obtained via a quantum key distribution (QKD) process.

In a variation on this embodiment, a respective set of key-generation parameters specifies a plurality of keys having a same length, and the set of key-generation parameters comprises: a number parameter specifying a number of keys to be generated, a length parameter specifying a bit length of the to-be-generated keys, and a position parameter specifying a starting position of an initial to-be-generated key within the quantum string shared between the first and second entities.

In a variation on this embodiment, a respective set of key-generation parameters specifies a single to-be-generated key, and the set of key-generation parameters indicates the length of the single to-be-generated key and the starting position of the single to-be-generated key.

In a further variation, the lengths and starting positions of at least two keys are specified such that the two keys partially overlap, thereby resulting in a total number of bits in the extracted quantum data keys being more than a total number of bits in the quantum string shared between the first and second entities.

In a variation on this embodiment, while receiving the one or more sets of key-generation parameters, the first entity is configured to receive a hash function calculated by the second entity based on the key-generation parameters and a shared secret; and validating the sets of key-generation parameters comprises comparing the received hash function with a hash function calculated by the first entity.

In a variation on this embodiment, sending the acknowledgment message comprises: calculating a variation of at least one key-generation parameter; encrypting, using an encryption key, the calculated variation to obtain an encrypted message; and sending the encrypted message.

In a variation on this embodiment, the received one or more sets of key-generation parameters are encrypted using an encryption key associated with the first entity.

In a variation on this embodiment, the first and second entities belong to a cloud computing system, and the first or second entity comprises one of: a piece of equipment provided by a cloud provider and a piece of equipment provided by a cloud client.

In a further variation, the first and second entities each receive a trusted certificate and equipment private key from a trusted authorization center associated with the cloud computing system.

In a further variation, the first entity sends an authorization request to the trusted authorization center, which comprises a plurality of trusted control nodes. A respective trusted control node maintains a share of a system private key. The first entity receives from the trusted control nodes a set of subkeys, and generates an equipment private key specific to the first entity based on the received set of subkeys. A respective subkey received from a particular trusted control node is generated based on identity information associated with the first entity, trusted-computing platform information associated with the first entity, and a share of the system private key stored in the particular trusted control node.

BRIEF DESCRIPTION OF THE FIGURES

FIG. 1 illustrates the chain of trust in a PC as defined by the Trusted Computing Group.

FIG. 2 illustrates the architecture of an exemplary secure cloud computing system based on quantum key distribution and trusted computing, according to one embodiment.

FIG. 3A illustrates a simplified diagram of a secure system, according to one embodiment.

FIG. 3B illustrates a simplified diagram of a secure system with a distributed trusted authorization center, according to one embodiment.

FIG. 4 presents a flowchart illustrating an exemplary initialization process of a distributed trusted authorization center, according to one embodiment.

FIG. 5 presents a flowchart illustrating an exemplary process for issuing a trusted certificate and equipment private key, according to one embodiment.

FIG. 6 presents a time-state diagram describing the process of producing shared quantum data keys, according to one embodiment.

FIG. 7 illustrates a block diagram of a trusted control node within the trusted authorization center, according to one embodiment.

FIG. 8 illustrates a block diagram of a trusted entity, according to one embodiment.

FIG. 9 illustrates an exemplary client-server network environment for implementing the disclosed eavesdropping-detection technology, in accordance with some embodiments described herein.

FIG. 10 conceptually illustrates an electronic system with which some implementations of the subject technology are implemented.

Table 1 illustrates two exemplary mechanical quantity measurement schemes based on using two different sets of quantum states in accordance with one embodiment described herein.

Table 2 shows an exemplary shared secret quantum string, according to one embodiment.

In the figures, like reference numerals refer to the same figure elements.

DETAILED DESCRIPTION

The following description is presented to enable any person skilled in the art to make and use the embodiments, and is provided in the context of a particular application and its requirements. Various modifications to the disclosed embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments and applications without departing from the spirit and scope of the present disclosure. Thus, the present invention is not limited to the embodiments shown, but is to be accorded the widest scope consistent with the principles and features disclosed herein.

Overview

In this disclosure, a method and system for generating a shared secret key using both quantum key distribution and trusted computing technologies are provided. During operation, a shared quantum string can first be generated by two communicating entities using a conventional quantum key distribution (QKD) scheme. The two entities are both trusted-computing-enabled, and can then further negotiate quantum data keys (which can later be used for data encryption) by exchanging and verifying trusted measurement reports. Multiple quantum data keys of same or different lengths can be generated from the same shared quantum string.

Quantum key distribution (QKD) mechanisms can ensure the secrecy of the initial quantum string. Trusted computing can be used for authentication of the client and server and for ensuring the integrity of the client and server. The combination of quantum key distribution and trusted computing can further enhance data security in a cloud computing environment.

In this disclosure, an entity is also referred to as a trusted entity (e.g., a trusted server or a trusted client) if the entity is equipped with modules that can enable trusted computing. Without specifying, it is assumed that all entities that provide or receive cloud computing services are trusted-computing-enabled.

Principles of Quantum Key Distribution

According to quantum physics, some physical quantities of the microscopic world cannot continuously change but take on certain discrete values, and the difference between two adjacent discrete values is referred to as a “quantum,” e.g., a photon is a single quantum of light.

In traditional communication where laws of classical mechanics apply, digital information can be represented as bits, wherein each bit can have two states: e.g., “0s” and “1s,” or “high” and “low” voltages. In contrast, in quantum communication where laws of classical mechanics do not apply, information is typically represented as quantum bits (qubits), which are units of quantum information. Each qubit can have two basic states: |0> or ↔ and |1> or

. In this case, the two quantum states |0> and |1> form a quantum state basis, which can be expressed as {|0>, |1>}.

Moreover, a quantum quantity can also take on a mixed state obtained by the superposition of the two basic states with coefficients α, β, respectively. For example, if quantum basis {|0>, |1>} is used, then a mixed state can be expressed as:

|φ

=α|0>+β|1

For example, mixed quantum state basis {|+

, |−

} can be generated by superpositioning the basic quan

RELATED APPLICATION

Under 35 U.S.C. § 119, this application claims the benefit and right of priority of Chinese Patent Application No. 201610900271.1, filed on 14 Oct. 2016.

This application is related to U.S. patent application Ser. No. 15/716,965, entitled “METHOD AND SYSTEM FOR DATA SECURITY BASED ON QUANTUM COMMUNICATION AND TRUSTED COMPUTING,” by inventor Yingfang Fu, filed 27 Sep. 2017; and U.S. patent application Ser. No. 15/717,729, entitled “METHOD AND SYSTEM FOR SECURE DATA STORAGE AND RETRIEVAL,” by inventor Yingfang Fu, filed 27 Sep. 2017, the disclosures of which are incorporated herein by reference in their entirety for all purposes.

BACKGROUND

Field

This disclosure is generally related to data security. More specifically, this disclosure is related to a system and method for quantum key distribution based on trusted computing technologies.

Related Art

In recent years, quantum encryption technologies have been developed. In quantum communication, information is transmitted based on quantum states, and the data security can be guaranteed by the laws of quantum mechanics, such as the uncertainty principle, the principle of quantum state measurement, and the no-cloning theorem. It has been shown that quantum cryptography can achieve unconditional data transmission security and detectability against eavesdroppers.

A number of quantum key distribution schemes (e.g., BB84 and E91 schemes) have been developed to allow two communication parties to securely produce and share a secret key known only to them. The two communication parties can then use the shared secret key to communicate with each other.

On the other hand, cloud computing has become a highly demanded service or utility due to the advantages of high computing power, cheap cost of services, high performance, scalability, accessibility as well as availability. In cloud computing, different services, including servers, storage, and application, can be delivered by the service provider to a customer's computers and devices via the Internet. More specifically, cloud computing allows users, and enterprises, with various computing capabilities to store and process data in either a privately owned cloud, or on a third-party server located in a data center in order to make data accessing mechanisms more efficient and reliable.

Although QKD systems may be deployed in cloud computing, they often cannot meet the quantity demand of the large-scale cloud computing, because raw keys produced by QKD schemes often need further optimization before they can be used in batches. Moreover, although the secrecy of the key can be guaranteed, QKD alone cannot provide user authentication and guarantee the integrity of the platforms of the communicating parties.

SUMMARY

One embodiment described herein provides a system and method for negotiating quantum data keys between first and second entities. During operation, the system performs a mutual authentication between the first and second entities. In response to the mutual authentication succeeding, the first entity receives one or more sets of key-generation parameters from the second entity. In response to validating the sets of key-generation parameters, the first entity sends an acknowledgment message to the second entity, and extracts, from a quantum string shared between the first and second entities, one or more quantum data keys based on the key-generation parameters. A respective quantum data key comprises a number of bits extracted from the quantum string.

In a variation on this embodiment, the first and second entities are each equipped with a trusted-computing module, and performing the mutual authentication comprises exchanging a trusted measurement report associated with each of the first and second entities.

In a further variation, the first entity stores the extracted quantum data keys within the trusted-computing module.

In a variation on this embodiment, the quantum string shared between the first and second entities is obtained via a quantum key distribution (QKD) process.

In a variation on this embodiment, a respective set of key-generation parameters specifies a plurality of keys having a same length, and the set of key-generation parameters comprises: a number parameter specifying a number of keys to be generated, a length parameter specifying a bit length of the to-be-generated keys, and a position parameter specifying a starting position of an initial to-be-generated key within the quantum string shared between the first and second entities.

In a variation on this embodiment, a respective set of key-generation parameters specifies a single to-be-generated key, and the set of key-generation parameters indicates the length of the single to-be-generated key and the starting position of the single to-be-generated key.

In a further variation, the lengths and starting positions of at least two keys are specified such that the two keys partially overlap, thereby resulting in a total number of bits in the extracted quantum data keys being more than a total number of bits in the quantum string shared between the first and second entities.

In a variation on this embodiment, while receiving the one or more sets of key-generation parameters, the first entity is configured to receive a hash function calculated by the second entity based on the key-generation parameters and a shared secret; and validating the sets of key-generation parameters comprises comparing the received hash function with a hash function calculated by the first entity.

In a variation on this embodiment, sending the acknowledgment message comprises: calculating a variation of at least one key-generation parameter; encrypting, using an encryption key, the calculated variation to obtain an encrypted message; and sending the encrypted message.

In a variation on this embodiment, the received one or more sets of key-generation parameters are encrypted using an encryption key associated with the first entity.

In a variation on this embodiment, the first and second entities belong to a cloud computing system, and the first or second entity comprises one of: a piece of equipment provided by a cloud provider and a piece of equipment provided by a cloud client.

In a further variation, the first and second entities each receive a trusted certificate and equipment private key from a trusted authorization center associated with the cloud computing system.

In a further variation, the first entity sends an authorization request to the trusted authorization center, which comprises a plurality of trusted control nodes. A respective trusted control node maintains a share of a system private key. The first entity receives from the trusted control nodes a set of subkeys, and generates an equipment private key specific to the first entity based on the received set of subkeys. A respective subkey received from a particular trusted control node is generated based on identity information associated with the first entity, trusted-computing platform information associated with the first entity, and a share of the system private key stored in the particular trusted control node.

BRIEF DESCRIPTION OF THE FIGURES

FIG. 1 illustrates the chain of trust in a PC as defined by the Trusted Computing Group.

FIG. 2 illustrates the architecture of an exemplary secure cloud computing system based on quantum key distribution and trusted computing, according to one embodiment.

FIG. 3A illustrates a simplified diagram of a secure system, according to one embodiment.

FIG. 3B illustrates a simplified diagram of a secure system with a distributed trusted authorization center, according to one embodiment.

FIG. 4 presents a flowchart illustrating an exemplary initialization process of a distributed trusted authorization center, according to one embodiment.

FIG. 5 presents a flowchart illustrating an exemplary process for issuing a trusted certificate and equipment private key, according to one embodiment.

FIG. 6 presents a time-state diagram describing the process of producing shared quantum data keys, according to one embodiment.

FIG. 7 illustrates a block diagram of a trusted control node within the trusted authorization center, according to one embodiment.

FIG. 8 illustrates a block diagram of a trusted entity, according to one embodiment.

FIG. 9 illustrates an exemplary client-server network environment for implementing the disclosed eavesdropping-detection technology, in accordance with some embodiments described herein.

FIG. 10 conceptually illustrates an electronic system with which some implementations of the subject technology are implemented.

Table 1 illustrates two exemplary mechanical quantity measurement schemes based on using two different sets of quantum states in accordance with one embodiment described herein.

Table 2 shows an exemplary shared secret quantum string, according to one embodiment.

In the figures, like reference numerals refer to the same figure elements.

DETAILED DESCRIPTION

The following description is presented to enable any person skilled in the art to make and use the embodiments, and is provided in the context of a particular application and its requirements. Various modifications to the disclosed embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments and applications without departing from the spirit and scope of the present disclosure. Thus, the present invention is not limited to the embodiments shown, but is to be accorded the widest scope consistent with the principles and features disclosed herein.

Overview

In this disclosure, a method and system for generating a shared secret key using both quantum key distribution and trusted computing technologies are provided. During operation, a shared quantum string can first be generated by two communicating entities using a conventional quantum key distribution (QKD) scheme. The two entities are both trusted-computing-enabled, and can then further negotiate quantum data keys (which can later be used for data encryption) by exchanging and verifying trusted measurement reports. Multiple quantum data keys of same or different lengths can be generated from the same shared quantum string.

Quantum key distribution (QKD) mechanisms can ensure the secrecy of the initial quantum string. Trusted computing can be used for authentication of the client and server and for ensuring the integrity of the client and server. The combination of quantum key distribution and trusted computing can further enhance data security in a cloud computing environment.

In this disclosure, an entity is also referred to as a trusted entity (e.g., a trusted server or a trusted client) if the entity is equipped with modules that can enable trusted computing. Without specifying, it is assumed that all entities that provide or receive cloud computing services are trusted-computing-enabled.

Principles of Quantum Key Distribution

According to quantum physics, some physical quantities of the microscopic world cannot continuously change but take on certain discrete values, and the difference between two adjacent discrete values is referred to as a “quantum,” e.g., a photon is a single quantum of light.

In traditional communication where laws of classical mechanics apply, digital information can be represented as bits, wherein each bit can have two states: e.g., “0s” and “1s,” or “high” and “low” voltages. In contrast, in quantum communication where laws of classical mechanics do not apply, information is typically represented as quantum bits (qubits), which are units of quantum information. Each qubit can have two basic states: |0> or ↔ and |1> or

. In this case, the two quantum states |0> and |1> form a quantum state basis, which can be expressed as {|0>, |1>}.

Moreover, a quantum quantity can also take on a mixed state obtained by the superposition of the two basic states with coefficients α, β, respectively. For example, if quantum basis {|0>, |1>} is used, then a mixed state can be expressed as:

|φ

=α|0>+β|1

For example, mixed quantum state basis {|+

, |−

} can be generated by superpositioning the basic quantum states |0>/↔ and |1>/

using the following formulae:

 + 〉

=

↔

+ ↕

2

⁢

,

⁢

 - 〉

=

↔

- ↕

2

.

Note that in the above two bases of quantum state representations, states |0> and |1> are orthogonal to each other, while states |+> and |−> are orthogonal to each other.

In quantum mechanics, a given mechanical quantity can be measured using the above-described quantum states, which are also referred to as “measurement basis.” For example, each mechanical quantity can be expressed by a Hermitian operator (or Hermitian matrix). When measuring such a mechanical quantity, the measurement results correspond to the eigenvalues (or the “characteristic values”) of the Hermitian operator for this mechanical quantity. After the measurement, the quantum state being measured collapses to the eigenstates (or the “eigenvectors”) corresponding to the obtained eigenvalues. Table 1 illustrates two exemplary mechanical quantity measurement schemes based on using two different sets of quantum states in accordance with one embodiment described herein.

TABLE 1

Mechanical Quantity Measurement Using a Set of Quantum States

 

Mechanical

⁢

⁢

Quanitity

Z

=

(

1

0

0

-

1

)

Eigenvalues: 1, −1 Eigenstates: |0 

, |1 

Referred to as measuring using set {|0 

, |1 

}

 

Mechanical

⁢

⁢

Quantity

Z

=

(

0

1

1

0

)

Eigenvalues: 1, 1 Eigenstates: |+ 

, |− 

Referred to as measuring using set {|+ 

, |− 

For example, when using quantum state basis {|0

, |1

} to measure quantum state |φ

=α|0

+β|1

, wherein |α| 2 +|β| 2 =1, we will obtain a measurement value of 1 with a probability of |α| 2 , wherein after the measurement the quantum state collapses to |0

; and we will obtain a measurement value of −1 with a probability of |β| 2 , wherein after the measurement the quantum state collapses to |1

.

As another example, when using quantum state basis {|0

, |1

} to measure quantum state |0

, we will obtain state |0

with probability 1. Similarly, when using quantum state basis {|+

, |−

} to measure quantum state |+

, we will obtain state |+

with probability 1.

Furthermore, when using quantum state basis {|0

, |1

} to measure quantum state |+

, we will randomly obtain either state |0

or state |1

. Similarly, when using quantum state basis {|+

, |−

} to measure state |0

, we will randomly obtain either state |+

or state |−

.

Bennett-Brassard-84 (BB84) is a popular quantum key distribution protocol. BB84 uses the polarization states of single photons to transmit information. The usual polarization state pairs used are either the rectilinear basis of vertical (0°) and horizontal (90°), the diagonal basis of 45° and 135° or the circular basis of left- and right-handedness. Any two of these bases are conjugate to each other, so any two can be used in the protocol. In the BB84 scheme, sender Alice wishes to send a private key (e.g., a random string) to receiver Bob. Alice starts by generating a random bit and randomly selects from two quantum bases a quantum basis to encode the binary bit. Alice then transmits a single photon in the state specified to Bob, using the quantum channel. This process is then repeated from the random bit stage, with Alice recording the state, basis and time of each photon sent. Upon receiving a photon, Bob performs measurements using randomly selected basis. Bob does this for each photon he receives, recording the time, measurement basis used, and measurement result. After Bob has measured all the photons, he communicates with Alice over the public classical channel. Alice broadcasts the basis each photon was sent in, and Bob the basis each was measured in. They both discard photon measurements (bits) where Bob used a different basis, which is half on average, leaving half the bits as a shared key.

To check for the presence of an eavesdropper Eve, Alice and Bob can compare a predetermined subset of their remaining bit strings. If a third party has gained any information about the photons' polarization, this introduces errors into Bob's measurements. Other environmental conditions can cause errors in a similar fashion. If the bit error rate is less than a predetermined threshold, error-correction techniques can be used to correct errors, and privacy amplification can be used to reduce Eve's knowledge of the key to an arbitrarily small amount at the cost of reducing the length of the key. If the bit error rate is greater than a predetermined threshold, they abort the key and try again, possibly with a different quantum channel, as the security of the key cannot be guaranteed.

Note that, in addition to the presence of an eavesdropper, other environmental factors (e.g., quality of the quantum channel or transmitting/receiving equipment) may also introduce errors. For example, a channel with high loss may result in increased error rate. Without an accurate estimation of the environmentally induced error rate, a QKD scheme may not be able to produce a shared quantum string, because they are always being discarded. Certain existing system may require that the error rate to be less than 7% in order to produce a shared quantum string.

From the shared quantum string produced via QKD, Alice and Bob can further negotiate one or more quantum data keys, each quantum data key can include a subset of bits selected from the set of bits in the shared quantum string. Note that the quantum data keys are used as encryption keys in actual communications between Alice and Bob.

Trusted Computing

Trusted Computing is an emerging technology developed by the Trusted Computing Group (TCG) towards building trustworthy computer platforms. In trusted computing, the computer will consistently behave in expected ways, and those behaviors will be enforced by computer hardware and software. Enforcing this behavior is achieved by loading the hardware with a unique encryption key inaccessible to the rest of the system. According to the TCG, “trusted component, operation, or process is one whose behavior is predictable under almost any operating condition and which is highly resistant to subversion by application software, viruses, and a given level of physical interference.”

The core of the trusted computing is the root of trust and the chain of trust. In trusted computing, the root of trust can be factory-installed hardware or firmware, such as the Trusted Platform Module (TPM). A TPM can be implemented as dedicated, cost-effective crypto-chips. A TPM can be physically connected to the computation platform and coupled to the CPU (central processing unit) via external buses. For example, the TPM on a personal computer (PC) can be mounted onto the main board of the PC and connected via a Low Pin Count (LPC) bus. In addition to storing the information for authenticating the platform, a TPM can also be used to store platform measurements that help ensure that the platform remains trustworthy. Authentication (ensuring that the platform can prove that it is what it claims to be) and attestation (a process helping to prove that a platform is trustworthy and has not been breached) are necessary steps to ensure safer computing in all environments.

The chain of trust is the iterative means to extend the boundary from the root of trust. The trustworthiness of a currently running component is based on the trustworthiness of a previously running component. Starting from the root of trust (also known as the trust anchor), if each time the computational environment of the platform changes (e.g., the running of certain codes), the trust can be maintained, thus establishing a reliable chain of trust, the platform can be viewed as trustworthy by local and remote entities.

Trusted computing technologies can include trusted measurement, trusted reporting, trusted storage, and trusted networking. FIG. 1 illustrates the chain of trust in a PC as defined by the Trusted Computing Group. More specifically, FIG. 1 shows the chain of trust for measurement, reporting, storage, and logging.

In addition to TPMs, Trusted Platform Control Modules (TPCMs) have also been developed. TPM was a subordinate device and the root of trusted measurement was put into BIOS (as shown in FIG. 1 ), which faces the threat of being tampered with. TPCM incorporates into the module the root of trusted measurement, thus protecting the root and original point of measurement and modifying the boot and measurement sequence. Accordingly, a chain of trust can be established using the TPCM chip as the trust anchor, thus allowing the TPCM chip to control the boot, I/O, and provisioning of the system.

During the operation of the computing platform, the TPCM needs to ensure the integrity of the next level executable code before the system transfers control to the next level executable code. The control of the system continues to be transferred to subsequent levels of executable code, thus establishing the chain of trust. More specifically, the TPCM or the TPM can start the boot process from a trusted condition and extend this trust until the operating system has fully booted and applications are running.

Secure System Architecture

FIG. 2 illustrates the architecture of an exemplary secure cloud computing system based on quantum key distribution and trusted computing, according to one embodiment. A secure cloud computing system 200 can include a number of participating entities, such as the cloud provider and the cloud users. If the trusted certificate is issued by a third party certificate authority (CA), the CA will also be part of secure cloud computing system 200 . A CA is not included in the example shown in FIG. 2 .

The cloud provider is responsible for providing the cloud control platform and the various cloud infrastructures, including both hardware and software components. In the example shown in FIG. 2 , the entire cloud computing system can be divided into two realms, the one controlled by the cloud provider (shown as the shaded area) and the one controlled by the cloud users (shown as the hatched area).

In some embodiments, trusted computing is implemented in both the cloud provider realm and the user realm. For example, equipment provided by the cloud provider, which can include servers (e.g., clusters of servers 202 and 204 ), cloud control nodes (e.g., nodes 206 and 208 ), and hardware security modules (HSMs) (e.g., pool of HSMs 210 ), can be equipped with modules that enforce trusted computing, such as TPMs. These TPMs can be implemented as hardware, firmware, and software modules. Moreover, user-controlled equipment, such as client machines, databases (e.g., database 212 ), and cloud-HSMs (e.g., pool of cloud-HSMs 214 ) can also be equipped with TPMs. Note that a cloud-HSM can refer to a dedicated HSM appliance owned or controlled by the customer but collocated in the cloud. The TPMs in the cloud and on the user machines ensure dynamic trust measurement and trusted storage.

In addition to trusted computing, QKD technologies can also be implemented in both the cloud provider realm and the user realm. More specifically, quantum key exchange can be enabled among the cloud nodes, as shown by the key logos. On the other hand, two types of user may exist: one group of users is equipped with QKD modules (e.g., user group 216 ), whereas the other group of users (e.g., user group 218 ) does not have the quantum key exchange capability. In the example shown in FIG. 2 , communication channels that also include a quantum channel to enable QKD are shown in solid lines (e.g., communication channel 222 ), whereas communication channels that do not include a quantum channel are shown in dashed lines (e.g., communication channel 224 ). More specifically, on the QKD-enabled communication channels, communication partners can negotiate encryption keys (also referred to as quantum data keys) using the quantum channel and then use the negotiated keys for secure communication. For example, a user within user group 216 can communicate with the cloud servers using the quantum-enhanced secure channel. Moreover, the user can perform initial configuration of his cloud-

CLAIMS

Claims ( 26 )

What is claimed is:

1. A computer-implemented method for negotiating quantum data keys between first and second entities, the method comprising:

performing a mutual authentication between the first and second entities;

in response to the mutual authentication succeeding, receiving, by the first entity, one or more sets of key-generation parameters from the second entity;

in response to validating the sets of key-generation parameters, sending an acknowledgment message to the second entity;

extracting, from a quantum string shared between the first and second entities, one or more quantum data keys based on the key-generation parameters, wherein a respective quantum data key comprises a number of bits extracted from the quantum string; and

establishing a quantum-enhanced secure communication channel between the first and second entities.

2. The computer-implemented method of claim 1 , wherein the first and second entities are each equipped with a trusted-computing module, and wherein performing the mutual authentication comprises exchanging a trusted measurement report associated with each of the first and second entities.

3. The computer-implemented method of claim 2 , further comprising storing the extracted quantum data keys within the trusted-computing module.

4. The computer-implemented method of claim 1 , wherein the quantum string shared between the first and second entities is obtained via a quantum key distribution (QKD) process.

5. The computer-implemented method of claim 1 , wherein a respective set of key-generation parameters specifies a plurality of keys having a same length, and wherein the set of key-generation parameters comprises:

a number parameter specifying a number of keys to be generated;

a length parameter specifying a bit length of the to-be-generated keys; and

a position parameter specifying a starting position of an initial to-be-generated key within the quantum string shared between the first and second entities.

6. The computer-implemented method of claim 1 , wherein a respective set of key-generation parameters specifies a single to-be-generated key, and wherein the set of key-generation parameters indicates the length of the single to-be-generated key and the starting position of the single to-be-generated key.

7. The computer-implemented method of claim 6 , wherein the lengths and starting positions of at least two keys are specified such that the two keys partially overlap, thereby resulting in a total number of bits in the extracted quantum data keys being more than a total number of bits in the quantum string shared between the first and second entities.

8. The computer-implemented method of claim 1 , wherein while receiving the one or more sets of key-generation parameters, the first entity is configured to receive a hash function calculated by the second entity based on the key-generation parameters and a shared secret; and

wherein validating the sets of key-generation parameters comprises comparing the received hash function with a hash function calculated by the first entity.

9. The computer-implemented method of claim 1 , wherein sending the acknowledgment message comprises:

calculating a variation of at least one key-generation parameter;

encrypting, using an encryption key, the calculated variation to obtain an encrypted message; and

sending the encrypted message.

10. The computer-implemented method of claim 1 , wherein the received one or more sets of key-generation parameters are encrypted using an encryption key associated with the first entity.

11. The computer-implemented method of claim 1 , wherein the first and second entities belong to a cloud computing system, and wherein the first or second entity comprises one of:

a piece of equipment provided by a cloud provider; and

a piece of equipment provided by a cloud client.

12. The computer-implemented method of claim 11 , wherein the first and second entities each receive a trusted certificate and equipment private key from a trusted authorization center associated with the cloud computing system.

13. The computer-implemented method of claim 12 , further comprising:

sending, by the first entity to the trusted authorization center, an authorization request, wherein the trusted authorization center comprises a plurality of trusted control nodes, and wherein a respective trusted control node maintains a share of a system private key;

receiving from the trusted control nodes a set of subkeys, wherein a respective subkey received from a particular trusted control node is generated based on identity information associated with the first entity, trusted-computing platform information associated with the first entity, and a share of the system private key stored in the particular trusted control node; and

generating an equipment private key specific to the first entity based on the received set of subkeys.

14. A network entity, comprising:

a processor; and

a storage device coupled to the processor and storing instructions which when executed by the processor cause the processor to perform a method for negotiating quantum data keys between the network entity and a second network entity, wherein the method comprises:

performing a mutual authentication between the network entity and the second network entity;

in response to the mutual authentication succeeding, receiving one or more sets of key-generation parameters from the second network entity;

in response to validating the sets of key-generation parameters, sending an acknowledgment message to the second network entity;

extracting, from a quantum string shared between the network entity and the second network entity, one or more quantum data keys based on the key-generation parameters, wherein a respective quantum data key comprises a number of bits extracted from the quantum string; and

establishing a quantum-enhanced secure communication channel between the first and second entities.

15. The network entity of claim 14 , wherein the network entity and the second network entity are each equipped with a trusted-computing module, and wherein performing the mutual authentication comprises exchanging a trusted measurement report associated with each of the network entity and the second network entity.

16. The network entity of claim 15 , wherein the method further comprises storing the extracted quantum data keys within the trusted-computing module.

17. The network entity of claim 14 , wherein the quantum string shared between the network entity and the second network entity is obtained via a quantum key distribution (QKD) process.

18. The network entity of claim 14 , wherein a respective set of key-generation parameters specifies a plurality of keys having a same length, and wherein the set of key-generation parameters comprises:

a number parameter specifying a number of keys to be generated;

a length parameter specifying a bit length of the to-be-generated keys; and

a position parameter specifying a starting position of an initial to-be-generated key within the quantum string shared between the network entity and the second network entity.

19. The network entity of claim 14 , wherein a respective set of key-generation parameters specifies a single to-be-generated key, and wherein the set of key-generation parameters indicates the length of the single to-be-generated key and the starting position of the single to-be-generated key.

20. The network entity of claim 19 , wherein the lengths and starting positions of at least two keys are specified such that the two keys partially overlap, thereby resulting in a total number of bits in the extracted quantum data keys being more than a total number of bits in the quantum string shared between the network entity and the second network entity.

21. The network entity of claim 14 , wherein receiving the one or more sets of key-generation parameters further comprises receiving a hash function calculated by the second network entity based on the key-generation parameters and a shared secret, and

wherein validating the sets of key-generation parameters comprises comparing the received hash function with a hash function calculated by the network entity.

22. The network entity of claim 14 , wherein sending the acknowledgment message comprises:

calculating a variation of at least one key-generation parameter;

encrypting, using an encryption key, the calculated variation to obtain an encrypted message; and

sending the encrypted message.

23. The network entity of claim 14 , wherein the received one or more sets of key-generation parameters are encrypted using an encryption key associated with the network entity.

24. The network entity of claim 14 , wherein the network entity and the second network entity belong to a cloud computing system, and wherein the network entity or the second network entity comprises one of:

a piece of equipment provided by a cloud provider; and

a piece of equipment provided by a cloud client.

25. The network entity of claim 24 , wherein the network entity and the second network entity each receive a trusted certificate and equipment private key from a trusted authorization center associated with the cloud computing system.

26. The network entity of claim 25 , wherein the method further comprise:

sending, by the network entity to the trusted authorization center, an authorization request, wherein the trusted authorization center comprises a plurality of trusted control nodes, and wherein a respective trusted control node maintains a share of a system private key; receiving from the trusted control nodes a set of subkeys, wherein a respective subkey received from a particular trusted control node is generated based on identity information associated with the network entity, trusted-computing platform information associated with the network entity, and a share of the system private key stored in the particular trusted control node; and

generating an equipment private key specific to the network entity based on the received set of subkeys.

US15/717,553

2016-10-14

2017-09-27

Method and system for quantum key distribution based on trusted computing

Active

US10103880B2

( en )

Priority Applications (2)

Application Number

Priority Date

Filing Date

Title

JP2019507255A

JP7033120B2

( en )

2016-10-14

2017-09-28

Methods and systems for quantum key distribution based on trusted computing

PCT/US2017/054117

WO2018071195A1

( en )

2016-10-14

2017-09-28

Method and system for quantum key distribution based on trusted computing

Applications Claiming Priority (3)

Application Number

Priority Date

Filing Date

Title

CN201610900271

2016-10-14

CN201610900271.1A

CN107959566A

( en )

2016-10-14

2016-10-14

Quantal data key agreement system and quantal data cryptographic key negotiation method

CN201610900271.1

2016-10-14

Publications (2)

Publication Number

Publication Date

US20180109372A1

US20180109372A1 ( en )

2018-04-19

US10103880B2

true

US10103880B2 ( en )

2018-10-16

Family

ID=61902766

Family Applications (1)

Application Number

Title

Priority Date

Filing Date

US15/717,553

Active

US10103880B2

( en )

2016-10-14

2017-09-27

Method and system for quantum key distribution based on trusted computing

Country Status (5)

Country

Link

US

( 1 )

US10103880B2

( en )

JP

( 1 )

JP7033120B2

( en )

CN

( 1 )

CN107959566A

( en )

TW

( 1 )

TWI738836B

( en )

WO

( 1 )

WO2018071195A1

( en )

Cited By (7)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US10756889B2

( en )

*

2018-06-11

2020-08-25

Korea Institute Of Science And Technology

Certificated quantum cryptography system and method

US10887100B2

( en )

*

2018-11-09

2021-01-05

Ares Technologies, Inc.

Systems and methods for distributed key storage

US11258580B2

( en )

2019-10-04

2022-02-22

Red Hat, Inc.

Instantaneous key invalidation in response to a detected eavesdropper

US11423141B2

( en )

2020-02-10

2022-08-23

Red Hat, Inc.

Intruder detection using quantum key distribution

US20250007700A1

( en )

*

2021-07-20

2025-01-02

The Research Foundation For The State University Of New York

System and method for quantum-secure microgrids

GB2634920A

( en )

*

2023-10-25

2025-04-30

Toshiba Kk

A node for a quantum communication network, a quantum communication network and a method of producing a signed message

US12301708B2

( en )

*

2023-03-27

2025-05-13

Red Hat, Inc.

Cryptographic key management for distributed quantum computing systems

Families Citing this family (55)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US10903997B2

( en )

*

2017-10-19

2021-01-26

Autnhive Corporation

Generating keys using controlled corruption in computer networks

KR102028098B1

( en )

*

2018-01-29

2019-10-02

한국전자통신연구원

Apparatus and method for authenticating using quantum cryptography communication

EP3562115A1

( en )

*

2018-04-25

2019-10-30

Siemens Aktiengesellschaft

Protected transmission of data using post-quantum cryptography

US11290436B2

( en )

2018-09-21

2022-03-29

Cisco Technology, Inc.

Mechanism for encryption key distribution in computer networks

CN109088729B

( en )

*

2018-09-28

2021-03-26

北京金山安全软件有限公司

Key storage method and device

CN109302284B

( en )

*

2018-09-28

2021-10-22

北京金山安全软件有限公司

Hardware wallet

CN109194465B

( en )

*

2018-09-30

2022-02-18

巍乾全球技术有限责任公司

Method for managing keys, user equipment, management device and storage medium

CN109450641B

( en )

*

2018-10-25

2021-12-07

山东达创网络科技股份有限公司

Access control method for high-end mold information management system

US11316668B2

( en )

*

2018-11-16

2022-04-26

Safetech Bv

Methods and systems for cryptographic private key management for secure multiparty storage and transfer of information

CN109660340B

( en )

*

2018-12-11

2021-11-26

北京安御道合科技有限公司

Application system based on quantum key and use method thereof

CN109672537B

( en )

*

2019-01-18

2021-08-10

如般量子科技有限公司

Anti-quantum certificate acquisition system and method based on public key pool

CN110012074B

( en )

*

2019-03-12

2021-11-30

北京可信华泰信息技术有限公司

Cloud environment trusted context management method

CN111756675B

( en )

*

2019-03-28

2023-04-07

钉钉控股(开曼)有限公司

Data processing method, device, equipment and system

CN110190952A

( en )

*

2019-05-09

2019-08-30

浙江神州量子通信技术有限公司

It is a kind of based on quantum random number to the encrypted transmission method of Internet of Things safety

CN112291179B

( en )

*

2019-07-22

2022-04-12

科大国盾量子技术股份有限公司

Method, system and device for realizing equipment authentication

CN112468287B

( en )

*

2019-09-09

2022-02-22

科大国盾量子技术股份有限公司

Key distribution method, system, mobile terminal and wearable device

GB2587438A

( en )

*

2019-09-30

2021-03-31

Governing Council Univ Toronto

Key generation for use in secured communication

US12143481B2

( en )

2019-09-30

2024-11-12

The Governing Council Of The University Of Toronto

Method and system for key generation

CN110738767A

( en )

*

2019-10-29

2020-01-31

安徽问天量子科技股份有限公司

electronic forbidden authentication method based on quantum true random key

CN110932870B

( en )

*

2019-12-12

2023-03-31

南京如般量子科技有限公司

Quantum communication service station key negotiation system and method

CN113132323B

( en )

*

2019-12-31

2022-11-18

华为技术有限公司

Communication method and device

CN111490878B

( en )

*

2020-04-09

2021-07-27

腾讯科技(深圳)有限公司

Key generation method, apparatus, device and medium

US11374975B2

( en )

*

2020-07-02

2022-06-28

International Business Machines Corporation

TLS integration of post quantum cryptographic algorithms

CN111884798B

( en )

*

2020-07-22

2023-04-07

全球能源互联网研究院有限公司

Electric power business quantum encryption system

CN112152817B

( en )

*

2020-09-25

2022-07-12

国科量子通信网络有限公司

Quantum key distribution method and system for authentication based on post-quantum cryptography algorithm

CN114448638B

( en )

*

2020-11-02

2024-02-13

如般量子科技有限公司

Witness-based quantum secure communication network key management communication method and system

CN112751858B

( en )

*

2020-12-30

2023-04-07

恒安嘉新(北京)科技股份公司

Data encryption communication terminal method, device, terminal, server and storage medium

CN112822010B

( en )

*

2021-01-28

2022-08-26

成都信息工程大学

Removable storage medium management method based on quantum key and block chain

CN113014379B

( en )

*

2021-02-05

2022-05-17

南阳理工学院

Three-party authentication and key agreement method, system and computer storage medium supporting cross-cloud domain data sharing

CN113067699B

( en )

*

2021-03-04

2021-12-03

深圳科盾量子信息科技有限公司

Data sharing method and device based on quantum key and computer equipment

CN114362928B

( en )

*

2021-03-23

2023-11-24

长春大学

A quantum key distribution and reconstruction method for multi-node encryption

CN113449343B

( en )

*

2021-05-31

2024-03-26

国科量子通信网络有限公司

Trusted computing system based on quantum technology

CN113595722B

( en )

*

2021-06-28

2023-11-07

阿里巴巴新加坡控股有限公司

Quantum security key synchronization method, device, electronic equipment and storage medium

CN113346996B

( en )

*

2021-07-13

2022-07-12

郑州轻工业大学

Quantum-based content-centric network privacy protection method

US12105804B2

( en )

*

2021-07-17

2024-10-01

International Business Machines Corporation

Securely executing software based on cryptographically verified instructions

CN113765660B

( en )

*

2021-09-06

2022-08-02

东南大学

A method for on-demand distribution of quantum keys for IoT terminal devices

EP4156001A1

( en )

*

2021-09-27

2023-03-29

ARRIS Enterprises LLC

Method and apparatus for two-step data signing

US11895234B2

( en )

2021-09-30

2024-02-06

Juniper Networks, Inc.

Delayed quantum key-distribution

CN113890732B

( en )

*

2021-10-14

2022-10-14

成都信息工程大学

Block chain-based secret communication method and security event tracing method thereof

CN114124372B

( en )

*

2021-11-01

2024-06-04

易迅通科技有限公司

Quantum key distribution-based network jump generation device and method

CN113810432B

( en )

*

2021-11-19

2022-06-17

阿里云计算有限公司

Quantum-safe data encryption method, encryption equipment and storage medium

WO2023096586A2

( en )

*

2021-11-29

2023-06-01

Han Chuen LIM

Quantum key generation method and system

CN114244513B

( en )

*

2021-12-31

2024-02-09

日晷科技(上海)有限公司

Key negotiation method, device and storage medium

CN114398627B

( en )

*

2022-01-26

2025-10-21

南京南瑞国盾量子技术有限公司

A quantum cryptography cloud application system and method for power dispatching based on zero trust

US12225111B2

( en )

*

2022-03-08

2025-02-11

SanDisk Technologies, Inc.

Authorization requests from a data storage device to multiple manager devices

US12362913B2

( en )

2022-03-16

2025-07-15

Honeywell Limited Honeywell Limitée

Method and system for secure distribution of symmetric encryption keys using quantum key distribution (QKD)

CN115276981B

( en )

*

2022-07-28

2025-01-03

国家电网有限公司信息通信分公司

Quantum key distribution method, device and computer readable storage medium

WO2024034699A1

( en )

*

2022-08-08

2024-02-15

엘지전자 주식회사

Method for carrying out user authentication in quantum communication system, and device therefor

US12425202B2

( en )

*

2022-09-30

2025-09-23

Ut-Battelle, Llc

Authentication of smart grid communications using quantum key distribution

JP2025542096A

( en )

2022-11-15

2025-12-25

クォンタム ブリッジ テクノロジーズ インコーポレイテッド

System and method for distribution of key generation data in a secure network

US12355871B2

( en )

*

2023-03-30

2025-07-08

Qualcomm Incorporated

Pairwise key establishment between two measurement states

US12476984B2

( en )

*

2023-08-15

2025-11-18

Wells Fargo Bank, N.A.

Quantum-based information protection

CN118282654B

( en )

*

2024-06-04

2024-08-23

国网浙江省电力有限公司信息通信分公司

Quantum communication method, edge device and quantum communication system

CN118631457B

( en )

*

2024-08-15

2024-12-03

中电信量子信息科技集团有限公司

Quantum-resistant security enhancement method of security assertion marking protocol

CN120729634B

( en )

*

2025-08-25

2025-10-31

贵州电网有限责任公司

Quantum key-based secondary authentication method, device and medium for digital terminal of power system

Citations (42)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

EP0962070A2

( en )

1997-12-24

1999-12-08

Koninklijke Philips Electronics N.V.

Administration and utilization of secret fresh random numbers in a networked environment

US20050259825A1

( en )

2004-05-24

2005-11-24

Alexei Trifonov

Key bank systems and methods for QKD

US20060026693A1

( en )

2004-07-29

2006-02-02

International Business Machines Corporation

Method, apparatus, and product for asserting physical presence with a trusted platform module in a hypervisor environment

US20070016794A1

( en )

2005-06-16

2007-01-18

Harrison Keith A

Method and device using one-time pad data

US20070076889A1

( en )

2005-09-29

2007-04-05

International Business Machines Corporation

Pre-generation of generic session keys for use in communicating within communications environments

US20070147292A1

( en )

2005-12-23

2007-06-28

Alcatel Lucent

Resource admission control for customer triggered and network triggered reservation requests

US20080114983A1

( en )

2006-11-15

2008-05-15

Research In Motion Limited

Client credential based secure session authentication method and apparatus

US20080123859A1

( en )

2006-11-27

2008-05-29

Rajesh Mamidwar

Method and system for encrypting and decrypting a transport stream using multiple algorithms

US20080165973A1

( en )

2007-01-09

2008-07-10

Miranda Gavillan Jose G

Retrieval and Display of Encryption Labels From an Encryption Key Manager

US20080219449A1

( en )

2007-03-09

2008-09-11

Ball Matthew V

Cryptographic key management for stored data

US20090034733A1

( en )

2007-07-31

2009-02-05

Shankar Raman

Management of cryptographic keys for securing stored data

US20090092252A1

( en )

2007-04-12

2009-04-09

Landon Curt Noll

Method and System for Identifying and Managing Keys

US20090106551A1

( en )

2006-04-25

2009-04-23

Stephen Laurence Boren

Dynamic distributed key system and method for identity management, authentication servers, data security and preventing man-in-the-middle attacks

US20090271634A1

( en )

2008-04-25

2009-10-29

The Regents Of The University Of Colorado & Securics, Inc.

Bio-Cryptograhpy : Secure cryptographic protocols with bipartite biotokens

US20100211787A1

( en )

2009-02-19

2010-08-19

Leonid Bukshpun

Chaotic cipher system and method for secure communication

US20100265077A1

( en )

2009-04-16

2010-10-21

Humble Travis S

Tampering Detection System Using Quantum-Mechanical Systems

US20110069972A1

( en )

2008-05-19

2011-03-24

Qinetiq Limited

Multiplexed quantum key distribution

US20110231615A1

( en )

2010-03-19

2011-09-22

Ober Robert E

Coherent storage network

US20120177201A1

( en )

2009-09-29

2012-07-12

Qinetiq Limited

Methods and apparatus for use in quantum key distribution

WO2012098543A2

( en )

2011-01-18

2012-07-26

Fortress Gb Ltd.

System and method for computerized negotiations based on coded integrity

US20120265892A1

( en )

2009-12-01

2012-10-18

Azuki Systems, Inc.

Method and system for secure and reliable video streaming with rate adaptation

WO2013026086A1

( en )

2011-08-19

2013-02-28

Quintessencelabs Pty Ltd

Virtual zeroisation system and method

US20130083926A1

( en )

2011-09-30

2013-04-04

Los Alamos National Security, Llc

Quantum key management

US20130101119A1

( en )

2010-06-15

2013-04-25

Los Alamos National Security Llc

Quantum key distribution using card, base station and trusted authority

US20130227286A1

( en )

2006-04-25

2013-08-29

Andre Jacques Brisson

Dynamic Identity Verification and Authentication, Dynamic Distributed Key Infrastructures, Dynamic Distributed Key Systems and Method for Identity Management, Authentication Servers, Data Security and Preventing Man-in-the-Middle Attacks, Side Channel Attacks, Botnet Attacks, and Credit Card and Financial Transaction Fraud, Mitigating Biometric False Positives and False Negatives, and Controlling Life of Accessible Data in the Cloud

US20130251145A1

( en )

2010-12-02

2013-09-26

Qinetiq Limited

Quantum key distribution

US20140259138A1

( en )

2013-03-05

2014-09-11

Alibaba Group Holding Limited

Method and system for distinguishing humans from machines

US20140281511A1

( en )

2013-03-15

2014-09-18

Microsoft Corporation

Secure data processing on sensitive data using trusted hardware

US20140331050A1

( en )

2011-04-15

2014-11-06

Quintessence Labs Pty Ltd.

Qkd key management system

US20140351915A1

( en )

2010-02-17

2014-11-27

Nokia Coporation

Method and apparatus for providing an authentication context-based session

US20150046709A1

( en )

2003-09-15

2015-02-12

Telecommunication Systems, Inc.

Encapsulation of Secure Encrypted Data in a Deployable, Secure Communication System Allowing Benign, Secure Commercial Transport

US20150181308A1

( en )

2012-02-08

2015-06-25

Vixs Systems, Inc.

Container agnostic decryption device and methods for use therewith

US20150236852A1

( en )

2014-02-17

2015-08-20

Kabushiki Kaisha Toshiba

Quantum key distribution device, quantum key distribution system, and quantum key distribution method

US20150288542A1

( en )

2014-04-04

2015-10-08

Solyman Ashrafi

System and method for communication using orbital angular momentum with multiple layer overlay modulation

US20150381363A1

( en )

2014-01-31

2015-12-31

Teixem Corp.

System and method for performing secure communications

US20160021068A1

( en )

2007-01-22

2016-01-21

Spyrus, Inc.

Encryption device with configurable security functionality using network authorization code

US9323901B1

( en )

2007-09-28

2016-04-26

Emc Corporation

Data classification for digital rights management

WO2016070141A1

( en )

2014-10-30

2016-05-06

Alibaba Group Holding Limited

Method, apparatus, and system for quantum key distribution, privacy amplification, and data transmission

US20160226846A1

( en )

2015-01-22

2016-08-04

Alibaba Group Holding Limited

Method, apparatus, and system for quantum key distribution

US20160241396A1

( en )

2015-02-16

2016-08-18

Alibaba Group Holding Limited

Method, apparatus, and system for identity authentication

US20160248581A1

( en )

2015-01-08

2016-08-25

Alibaba Group Holding Limited

Quantum key distribution system, method and apparatus based on trusted relay

US20160294783A1

( en )

2015-04-06

2016-10-06

At&T Intellectual Property I, L.P.

Decentralized and distributed secure home subscriber server device

Family Cites Families (7)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

JP2007019789A

( en )

2005-07-07

2007-01-25

Nec Corp

Random number sharing system and method therefor

GB0801395D0

( en )

2008-01-25

2008-03-05

Qinetiq Ltd

Network having quantum key distribution

WO2014074194A2

( en )

2012-08-24

2014-05-15

Los Alamos National Security, Llc

Scalable software architecture for quantum cryptographic key management

CN103856477B

( en )

*

2012-12-06

2018-01-02

阿里巴巴集团控股有限公司

A kind of credible accounting system and corresponding authentication method and equipment

CN103491531B

( en )

*

2013-08-23

2016-07-06

中国科学技术大学

Power system WiMAX wireless communication networks uses the method that quantum key improves power information transmission security

WO2015048783A1

( en )

2013-09-30

2015-04-02

Nordholt, Jane,

Related documents

Record · ID 607398
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.