ABSTRACT
Abstract
One embodiment described herein provides a system and method for negotiating quantum data keys between first and second entities. During operation, the system performs a mutual authentication between the first and second entities. In response to the mutual authentication succeeding, the first entity receives one or more sets of key-generation parameters from the second entity. In response to validating the sets of key-generation parameters, the first entity sends an acknowledgment message to the second entity, and extracts, from a quantum string shared between the first and second entities, one or more quantum data keys based on the key-generation parameters. A respective quantum data key comprises a number of bits extracted from the quantum string.
Description
RELATED APPLICATION
Under 35 U.S.C. § 119, this application claims the benefit and right of priority of Chinese Patent Application No. 201610900271.1, filed on 14 Oct. 2016.
This application is related to U.S. patent application Ser. No. 15/716,965, entitled âMETHOD AND SYSTEM FOR DATA SECURITY BASED ON QUANTUM COMMUNICATION AND TRUSTED COMPUTING,â by inventor Yingfang Fu, filed 27 Sep. 2017; and U.S. patent application Ser. No. 15/717,729, entitled âMETHOD AND SYSTEM FOR SECURE DATA STORAGE AND RETRIEVAL,â by inventor Yingfang Fu, filed 27 Sep. 2017, the disclosures of which are incorporated herein by reference in their entirety for all purposes.
BACKGROUND
Field
This disclosure is generally related to data security. More specifically, this disclosure is related to a system and method for quantum key distribution based on trusted computing technologies.
Related Art
In recent years, quantum encryption technologies have been developed. In quantum communication, information is transmitted based on quantum states, and the data security can be guaranteed by the laws of quantum mechanics, such as the uncertainty principle, the principle of quantum state measurement, and the no-cloning theorem. It has been shown that quantum cryptography can achieve unconditional data transmission security and detectability against eavesdroppers.
A number of quantum key distribution schemes (e.g., BB84 and E91 schemes) have been developed to allow two communication parties to securely produce and share a secret key known only to them. The two communication parties can then use the shared secret key to communicate with each other.
On the other hand, cloud computing has become a highly demanded service or utility due to the advantages of high computing power, cheap cost of services, high performance, scalability, accessibility as well as availability. In cloud computing, different services, including servers, storage, and application, can be delivered by the service provider to a customer's computers and devices via the Internet. More specifically, cloud computing allows users, and enterprises, with various computing capabilities to store and process data in either a privately owned cloud, or on a third-party server located in a data center in order to make data accessing mechanisms more efficient and reliable.
Although QKD systems may be deployed in cloud computing, they often cannot meet the quantity demand of the large-scale cloud computing, because raw keys produced by QKD schemes often need further optimization before they can be used in batches. Moreover, although the secrecy of the key can be guaranteed, QKD alone cannot provide user authentication and guarantee the integrity of the platforms of the communicating parties.
SUMMARY
One embodiment described herein provides a system and method for negotiating quantum data keys between first and second entities. During operation, the system performs a mutual authentication between the first and second entities. In response to the mutual authentication succeeding, the first entity receives one or more sets of key-generation parameters from the second entity. In response to validating the sets of key-generation parameters, the first entity sends an acknowledgment message to the second entity, and extracts, from a quantum string shared between the first and second entities, one or more quantum data keys based on the key-generation parameters. A respective quantum data key comprises a number of bits extracted from the quantum string.
In a variation on this embodiment, the first and second entities are each equipped with a trusted-computing module, and performing the mutual authentication comprises exchanging a trusted measurement report associated with each of the first and second entities.
In a further variation, the first entity stores the extracted quantum data keys within the trusted-computing module.
In a variation on this embodiment, the quantum string shared between the first and second entities is obtained via a quantum key distribution (QKD) process.
In a variation on this embodiment, a respective set of key-generation parameters specifies a plurality of keys having a same length, and the set of key-generation parameters comprises: a number parameter specifying a number of keys to be generated, a length parameter specifying a bit length of the to-be-generated keys, and a position parameter specifying a starting position of an initial to-be-generated key within the quantum string shared between the first and second entities.
In a variation on this embodiment, a respective set of key-generation parameters specifies a single to-be-generated key, and the set of key-generation parameters indicates the length of the single to-be-generated key and the starting position of the single to-be-generated key.
In a further variation, the lengths and starting positions of at least two keys are specified such that the two keys partially overlap, thereby resulting in a total number of bits in the extracted quantum data keys being more than a total number of bits in the quantum string shared between the first and second entities.
In a variation on this embodiment, while receiving the one or more sets of key-generation parameters, the first entity is configured to receive a hash function calculated by the second entity based on the key-generation parameters and a shared secret; and validating the sets of key-generation parameters comprises comparing the received hash function with a hash function calculated by the first entity.
In a variation on this embodiment, sending the acknowledgment message comprises: calculating a variation of at least one key-generation parameter; encrypting, using an encryption key, the calculated variation to obtain an encrypted message; and sending the encrypted message.
In a variation on this embodiment, the received one or more sets of key-generation parameters are encrypted using an encryption key associated with the first entity.
In a variation on this embodiment, the first and second entities belong to a cloud computing system, and the first or second entity comprises one of: a piece of equipment provided by a cloud provider and a piece of equipment provided by a cloud client.
In a further variation, the first and second entities each receive a trusted certificate and equipment private key from a trusted authorization center associated with the cloud computing system.
In a further variation, the first entity sends an authorization request to the trusted authorization center, which comprises a plurality of trusted control nodes. A respective trusted control node maintains a share of a system private key. The first entity receives from the trusted control nodes a set of subkeys, and generates an equipment private key specific to the first entity based on the received set of subkeys. A respective subkey received from a particular trusted control node is generated based on identity information associated with the first entity, trusted-computing platform information associated with the first entity, and a share of the system private key stored in the particular trusted control node.
BRIEF DESCRIPTION OF THE FIGURES
FIG. 1 illustrates the chain of trust in a PC as defined by the Trusted Computing Group.
FIG. 2 illustrates the architecture of an exemplary secure cloud computing system based on quantum key distribution and trusted computing, according to one embodiment.
FIG. 3A illustrates a simplified diagram of a secure system, according to one embodiment.
FIG. 3B illustrates a simplified diagram of a secure system with a distributed trusted authorization center, according to one embodiment.
FIG. 4 presents a flowchart illustrating an exemplary initialization process of a distributed trusted authorization center, according to one embodiment.
FIG. 5 presents a flowchart illustrating an exemplary process for issuing a trusted certificate and equipment private key, according to one embodiment.
FIG. 6 presents a time-state diagram describing the process of producing shared quantum data keys, according to one embodiment.
FIG. 7 illustrates a block diagram of a trusted control node within the trusted authorization center, according to one embodiment.
FIG. 8 illustrates a block diagram of a trusted entity, according to one embodiment.
FIG. 9 illustrates an exemplary client-server network environment for implementing the disclosed eavesdropping-detection technology, in accordance with some embodiments described herein.
FIG. 10 conceptually illustrates an electronic system with which some implementations of the subject technology are implemented.
Table 1 illustrates two exemplary mechanical quantity measurement schemes based on using two different sets of quantum states in accordance with one embodiment described herein.
Table 2 shows an exemplary shared secret quantum string, according to one embodiment.
In the figures, like reference numerals refer to the same figure elements.
DETAILED DESCRIPTION
The following description is presented to enable any person skilled in the art to make and use the embodiments, and is provided in the context of a particular application and its requirements. Various modifications to the disclosed embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments and applications without departing from the spirit and scope of the present disclosure. Thus, the present invention is not limited to the embodiments shown, but is to be accorded the widest scope consistent with the principles and features disclosed herein.
Overview
In this disclosure, a method and system for generating a shared secret key using both quantum key distribution and trusted computing technologies are provided. During operation, a shared quantum string can first be generated by two communicating entities using a conventional quantum key distribution (QKD) scheme. The two entities are both trusted-computing-enabled, and can then further negotiate quantum data keys (which can later be used for data encryption) by exchanging and verifying trusted measurement reports. Multiple quantum data keys of same or different lengths can be generated from the same shared quantum string.
Quantum key distribution (QKD) mechanisms can ensure the secrecy of the initial quantum string. Trusted computing can be used for authentication of the client and server and for ensuring the integrity of the client and server. The combination of quantum key distribution and trusted computing can further enhance data security in a cloud computing environment.
In this disclosure, an entity is also referred to as a trusted entity (e.g., a trusted server or a trusted client) if the entity is equipped with modules that can enable trusted computing. Without specifying, it is assumed that all entities that provide or receive cloud computing services are trusted-computing-enabled.
Principles of Quantum Key Distribution
According to quantum physics, some physical quantities of the microscopic world cannot continuously change but take on certain discrete values, and the difference between two adjacent discrete values is referred to as a âquantum,â e.g., a photon is a single quantum of light.
In traditional communication where laws of classical mechanics apply, digital information can be represented as bits, wherein each bit can have two states: e.g., â0sâ and â1s,â or âhighâ and âlowâ voltages. In contrast, in quantum communication where laws of classical mechanics do not apply, information is typically represented as quantum bits (qubits), which are units of quantum information. Each qubit can have two basic states: |0> or â and |1> or
. In this case, the two quantum states |0> and |1> form a quantum state basis, which can be expressed as {|0>, |1>}.
Moreover, a quantum quantity can also take on a mixed state obtained by the superposition of the two basic states with coefficients α, β, respectively. For example, if quantum basis {|0>, |1>} is used, then a mixed state can be expressed as:
|Ï
=α|0>+β|1
For example, mixed quantum state basis {|+
, |â
} can be generated by superpositioning the basic quan
RELATED APPLICATION
Under 35 U.S.C. § 119, this application claims the benefit and right of priority of Chinese Patent Application No. 201610900271.1, filed on 14 Oct. 2016.
This application is related to U.S. patent application Ser. No. 15/716,965, entitled âMETHOD AND SYSTEM FOR DATA SECURITY BASED ON QUANTUM COMMUNICATION AND TRUSTED COMPUTING,â by inventor Yingfang Fu, filed 27 Sep. 2017; and U.S. patent application Ser. No. 15/717,729, entitled âMETHOD AND SYSTEM FOR SECURE DATA STORAGE AND RETRIEVAL,â by inventor Yingfang Fu, filed 27 Sep. 2017, the disclosures of which are incorporated herein by reference in their entirety for all purposes.
BACKGROUND
Field
This disclosure is generally related to data security. More specifically, this disclosure is related to a system and method for quantum key distribution based on trusted computing technologies.
Related Art
In recent years, quantum encryption technologies have been developed. In quantum communication, information is transmitted based on quantum states, and the data security can be guaranteed by the laws of quantum mechanics, such as the uncertainty principle, the principle of quantum state measurement, and the no-cloning theorem. It has been shown that quantum cryptography can achieve unconditional data transmission security and detectability against eavesdroppers.
A number of quantum key distribution schemes (e.g., BB84 and E91 schemes) have been developed to allow two communication parties to securely produce and share a secret key known only to them. The two communication parties can then use the shared secret key to communicate with each other.
On the other hand, cloud computing has become a highly demanded service or utility due to the advantages of high computing power, cheap cost of services, high performance, scalability, accessibility as well as availability. In cloud computing, different services, including servers, storage, and application, can be delivered by the service provider to a customer's computers and devices via the Internet. More specifically, cloud computing allows users, and enterprises, with various computing capabilities to store and process data in either a privately owned cloud, or on a third-party server located in a data center in order to make data accessing mechanisms more efficient and reliable.
Although QKD systems may be deployed in cloud computing, they often cannot meet the quantity demand of the large-scale cloud computing, because raw keys produced by QKD schemes often need further optimization before they can be used in batches. Moreover, although the secrecy of the key can be guaranteed, QKD alone cannot provide user authentication and guarantee the integrity of the platforms of the communicating parties.
SUMMARY
One embodiment described herein provides a system and method for negotiating quantum data keys between first and second entities. During operation, the system performs a mutual authentication between the first and second entities. In response to the mutual authentication succeeding, the first entity receives one or more sets of key-generation parameters from the second entity. In response to validating the sets of key-generation parameters, the first entity sends an acknowledgment message to the second entity, and extracts, from a quantum string shared between the first and second entities, one or more quantum data keys based on the key-generation parameters. A respective quantum data key comprises a number of bits extracted from the quantum string.
In a variation on this embodiment, the first and second entities are each equipped with a trusted-computing module, and performing the mutual authentication comprises exchanging a trusted measurement report associated with each of the first and second entities.
In a further variation, the first entity stores the extracted quantum data keys within the trusted-computing module.
In a variation on this embodiment, the quantum string shared between the first and second entities is obtained via a quantum key distribution (QKD) process.
In a variation on this embodiment, a respective set of key-generation parameters specifies a plurality of keys having a same length, and the set of key-generation parameters comprises: a number parameter specifying a number of keys to be generated, a length parameter specifying a bit length of the to-be-generated keys, and a position parameter specifying a starting position of an initial to-be-generated key within the quantum string shared between the first and second entities.
In a variation on this embodiment, a respective set of key-generation parameters specifies a single to-be-generated key, and the set of key-generation parameters indicates the length of the single to-be-generated key and the starting position of the single to-be-generated key.
In a further variation, the lengths and starting positions of at least two keys are specified such that the two keys partially overlap, thereby resulting in a total number of bits in the extracted quantum data keys being more than a total number of bits in the quantum string shared between the first and second entities.
In a variation on this embodiment, while receiving the one or more sets of key-generation parameters, the first entity is configured to receive a hash function calculated by the second entity based on the key-generation parameters and a shared secret; and validating the sets of key-generation parameters comprises comparing the received hash function with a hash function calculated by the first entity.
In a variation on this embodiment, sending the acknowledgment message comprises: calculating a variation of at least one key-generation parameter; encrypting, using an encryption key, the calculated variation to obtain an encrypted message; and sending the encrypted message.
In a variation on this embodiment, the received one or more sets of key-generation parameters are encrypted using an encryption key associated with the first entity.
In a variation on this embodiment, the first and second entities belong to a cloud computing system, and the first or second entity comprises one of: a piece of equipment provided by a cloud provider and a piece of equipment provided by a cloud client.
In a further variation, the first and second entities each receive a trusted certificate and equipment private key from a trusted authorization center associated with the cloud computing system.
In a further variation, the first entity sends an authorization request to the trusted authorization center, which comprises a plurality of trusted control nodes. A respective trusted control node maintains a share of a system private key. The first entity receives from the trusted control nodes a set of subkeys, and generates an equipment private key specific to the first entity based on the received set of subkeys. A respective subkey received from a particular trusted control node is generated based on identity information associated with the first entity, trusted-computing platform information associated with the first entity, and a share of the system private key stored in the particular trusted control node.
BRIEF DESCRIPTION OF THE FIGURES
FIG. 1 illustrates the chain of trust in a PC as defined by the Trusted Computing Group.
FIG. 2 illustrates the architecture of an exemplary secure cloud computing system based on quantum key distribution and trusted computing, according to one embodiment.
FIG. 3A illustrates a simplified diagram of a secure system, according to one embodiment.
FIG. 3B illustrates a simplified diagram of a secure system with a distributed trusted authorization center, according to one embodiment.
FIG. 4 presents a flowchart illustrating an exemplary initialization process of a distributed trusted authorization center, according to one embodiment.
FIG. 5 presents a flowchart illustrating an exemplary process for issuing a trusted certificate and equipment private key, according to one embodiment.
FIG. 6 presents a time-state diagram describing the process of producing shared quantum data keys, according to one embodiment.
FIG. 7 illustrates a block diagram of a trusted control node within the trusted authorization center, according to one embodiment.
FIG. 8 illustrates a block diagram of a trusted entity, according to one embodiment.
FIG. 9 illustrates an exemplary client-server network environment for implementing the disclosed eavesdropping-detection technology, in accordance with some embodiments described herein.
FIG. 10 conceptually illustrates an electronic system with which some implementations of the subject technology are implemented.
Table 1 illustrates two exemplary mechanical quantity measurement schemes based on using two different sets of quantum states in accordance with one embodiment described herein.
Table 2 shows an exemplary shared secret quantum string, according to one embodiment.
In the figures, like reference numerals refer to the same figure elements.
DETAILED DESCRIPTION
The following description is presented to enable any person skilled in the art to make and use the embodiments, and is provided in the context of a particular application and its requirements. Various modifications to the disclosed embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments and applications without departing from the spirit and scope of the present disclosure. Thus, the present invention is not limited to the embodiments shown, but is to be accorded the widest scope consistent with the principles and features disclosed herein.
Overview
In this disclosure, a method and system for generating a shared secret key using both quantum key distribution and trusted computing technologies are provided. During operation, a shared quantum string can first be generated by two communicating entities using a conventional quantum key distribution (QKD) scheme. The two entities are both trusted-computing-enabled, and can then further negotiate quantum data keys (which can later be used for data encryption) by exchanging and verifying trusted measurement reports. Multiple quantum data keys of same or different lengths can be generated from the same shared quantum string.
Quantum key distribution (QKD) mechanisms can ensure the secrecy of the initial quantum string. Trusted computing can be used for authentication of the client and server and for ensuring the integrity of the client and server. The combination of quantum key distribution and trusted computing can further enhance data security in a cloud computing environment.
In this disclosure, an entity is also referred to as a trusted entity (e.g., a trusted server or a trusted client) if the entity is equipped with modules that can enable trusted computing. Without specifying, it is assumed that all entities that provide or receive cloud computing services are trusted-computing-enabled.
Principles of Quantum Key Distribution
According to quantum physics, some physical quantities of the microscopic world cannot continuously change but take on certain discrete values, and the difference between two adjacent discrete values is referred to as a âquantum,â e.g., a photon is a single quantum of light.
In traditional communication where laws of classical mechanics apply, digital information can be represented as bits, wherein each bit can have two states: e.g., â0sâ and â1s,â or âhighâ and âlowâ voltages. In contrast, in quantum communication where laws of classical mechanics do not apply, information is typically represented as quantum bits (qubits), which are units of quantum information. Each qubit can have two basic states: |0> or â and |1> or
. In this case, the two quantum states |0> and |1> form a quantum state basis, which can be expressed as {|0>, |1>}.
Moreover, a quantum quantity can also take on a mixed state obtained by the superposition of the two basic states with coefficients α, β, respectively. For example, if quantum basis {|0>, |1>} is used, then a mixed state can be expressed as:
|Ï
=α|0>+β|1
For example, mixed quantum state basis {|+
, |â
} can be generated by superpositioning the basic quantum states |0>/â and |1>/
using the following formulae:
ï + âª
=
â
+ â
2
â¢
,
â¢
ï - âª
=
â
- â
2
.
Note that in the above two bases of quantum state representations, states |0> and |1> are orthogonal to each other, while states |+> and |â> are orthogonal to each other.
In quantum mechanics, a given mechanical quantity can be measured using the above-described quantum states, which are also referred to as âmeasurement basis.â For example, each mechanical quantity can be expressed by a Hermitian operator (or Hermitian matrix). When measuring such a mechanical quantity, the measurement results correspond to the eigenvalues (or the âcharacteristic valuesâ) of the Hermitian operator for this mechanical quantity. After the measurement, the quantum state being measured collapses to the eigenstates (or the âeigenvectorsâ) corresponding to the obtained eigenvalues. Table 1 illustrates two exemplary mechanical quantity measurement schemes based on using two different sets of quantum states in accordance with one embodiment described herein.
TABLE 1
Mechanical Quantity Measurement Using a Set of Quantum States
â
Mechanical
â¢
â¢
Quanitity
Z
=
(
1
0
0
-
1
)
Eigenvalues: 1, â1 Eigenstates: |0â
, |1â
Referred to as measuring using set {|0â
, |1â
}
â
Mechanical
â¢
â¢
Quantity
Z
=
(
0
1
1
0
)
Eigenvalues: 1, 1 Eigenstates: |+â
, |ââ
Referred to as measuring using set {|+â
, |ââ
For example, when using quantum state basis {|0
, |1
} to measure quantum state |Ï
=α|0
+β|1
, wherein |α| 2 +|β| 2 =1, we will obtain a measurement value of 1 with a probability of |α| 2 , wherein after the measurement the quantum state collapses to |0
; and we will obtain a measurement value of â1 with a probability of |β| 2 , wherein after the measurement the quantum state collapses to |1
.
As another example, when using quantum state basis {|0
, |1
} to measure quantum state |0
, we will obtain state |0
with probability 1. Similarly, when using quantum state basis {|+
, |â
} to measure quantum state |+
, we will obtain state |+
with probability 1.
Furthermore, when using quantum state basis {|0
, |1
} to measure quantum state |+
, we will randomly obtain either state |0
or state |1
. Similarly, when using quantum state basis {|+
, |â
} to measure state |0
, we will randomly obtain either state |+
or state |â
.
Bennett-Brassard-84 (BB84) is a popular quantum key distribution protocol. BB84 uses the polarization states of single photons to transmit information. The usual polarization state pairs used are either the rectilinear basis of vertical (0°) and horizontal (90°), the diagonal basis of 45° and 135° or the circular basis of left- and right-handedness. Any two of these bases are conjugate to each other, so any two can be used in the protocol. In the BB84 scheme, sender Alice wishes to send a private key (e.g., a random string) to receiver Bob. Alice starts by generating a random bit and randomly selects from two quantum bases a quantum basis to encode the binary bit. Alice then transmits a single photon in the state specified to Bob, using the quantum channel. This process is then repeated from the random bit stage, with Alice recording the state, basis and time of each photon sent. Upon receiving a photon, Bob performs measurements using randomly selected basis. Bob does this for each photon he receives, recording the time, measurement basis used, and measurement result. After Bob has measured all the photons, he communicates with Alice over the public classical channel. Alice broadcasts the basis each photon was sent in, and Bob the basis each was measured in. They both discard photon measurements (bits) where Bob used a different basis, which is half on average, leaving half the bits as a shared key.
To check for the presence of an eavesdropper Eve, Alice and Bob can compare a predetermined subset of their remaining bit strings. If a third party has gained any information about the photons' polarization, this introduces errors into Bob's measurements. Other environmental conditions can cause errors in a similar fashion. If the bit error rate is less than a predetermined threshold, error-correction techniques can be used to correct errors, and privacy amplification can be used to reduce Eve's knowledge of the key to an arbitrarily small amount at the cost of reducing the length of the key. If the bit error rate is greater than a predetermined threshold, they abort the key and try again, possibly with a different quantum channel, as the security of the key cannot be guaranteed.
Note that, in addition to the presence of an eavesdropper, other environmental factors (e.g., quality of the quantum channel or transmitting/receiving equipment) may also introduce errors. For example, a channel with high loss may result in increased error rate. Without an accurate estimation of the environmentally induced error rate, a QKD scheme may not be able to produce a shared quantum string, because they are always being discarded. Certain existing system may require that the error rate to be less than 7% in order to produce a shared quantum string.
From the shared quantum string produced via QKD, Alice and Bob can further negotiate one or more quantum data keys, each quantum data key can include a subset of bits selected from the set of bits in the shared quantum string. Note that the quantum data keys are used as encryption keys in actual communications between Alice and Bob.
Trusted Computing
Trusted Computing is an emerging technology developed by the Trusted Computing Group (TCG) towards building trustworthy computer platforms. In trusted computing, the computer will consistently behave in expected ways, and those behaviors will be enforced by computer hardware and software. Enforcing this behavior is achieved by loading the hardware with a unique encryption key inaccessible to the rest of the system. According to the TCG, âtrusted component, operation, or process is one whose behavior is predictable under almost any operating condition and which is highly resistant to subversion by application software, viruses, and a given level of physical interference.â
The core of the trusted computing is the root of trust and the chain of trust. In trusted computing, the root of trust can be factory-installed hardware or firmware, such as the Trusted Platform Module (TPM). A TPM can be implemented as dedicated, cost-effective crypto-chips. A TPM can be physically connected to the computation platform and coupled to the CPU (central processing unit) via external buses. For example, the TPM on a personal computer (PC) can be mounted onto the main board of the PC and connected via a Low Pin Count (LPC) bus. In addition to storing the information for authenticating the platform, a TPM can also be used to store platform measurements that help ensure that the platform remains trustworthy. Authentication (ensuring that the platform can prove that it is what it claims to be) and attestation (a process helping to prove that a platform is trustworthy and has not been breached) are necessary steps to ensure safer computing in all environments.
The chain of trust is the iterative means to extend the boundary from the root of trust. The trustworthiness of a currently running component is based on the trustworthiness of a previously running component. Starting from the root of trust (also known as the trust anchor), if each time the computational environment of the platform changes (e.g., the running of certain codes), the trust can be maintained, thus establishing a reliable chain of trust, the platform can be viewed as trustworthy by local and remote entities.
Trusted computing technologies can include trusted measurement, trusted reporting, trusted storage, and trusted networking. FIG. 1 illustrates the chain of trust in a PC as defined by the Trusted Computing Group. More specifically, FIG. 1 shows the chain of trust for measurement, reporting, storage, and logging.
In addition to TPMs, Trusted Platform Control Modules (TPCMs) have also been developed. TPM was a subordinate device and the root of trusted measurement was put into BIOS (as shown in FIG. 1 ), which faces the threat of being tampered with. TPCM incorporates into the module the root of trusted measurement, thus protecting the root and original point of measurement and modifying the boot and measurement sequence. Accordingly, a chain of trust can be established using the TPCM chip as the trust anchor, thus allowing the TPCM chip to control the boot, I/O, and provisioning of the system.
During the operation of the computing platform, the TPCM needs to ensure the integrity of the next level executable code before the system transfers control to the next level executable code. The control of the system continues to be transferred to subsequent levels of executable code, thus establishing the chain of trust. More specifically, the TPCM or the TPM can start the boot process from a trusted condition and extend this trust until the operating system has fully booted and applications are running.
Secure System Architecture
FIG. 2 illustrates the architecture of an exemplary secure cloud computing system based on quantum key distribution and trusted computing, according to one embodiment. A secure cloud computing system 200 can include a number of participating entities, such as the cloud provider and the cloud users. If the trusted certificate is issued by a third party certificate authority (CA), the CA will also be part of secure cloud computing system 200 . A CA is not included in the example shown in FIG. 2 .
The cloud provider is responsible for providing the cloud control platform and the various cloud infrastructures, including both hardware and software components. In the example shown in FIG. 2 , the entire cloud computing system can be divided into two realms, the one controlled by the cloud provider (shown as the shaded area) and the one controlled by the cloud users (shown as the hatched area).
In some embodiments, trusted computing is implemented in both the cloud provider realm and the user realm. For example, equipment provided by the cloud provider, which can include servers (e.g., clusters of servers 202 and 204 ), cloud control nodes (e.g., nodes 206 and 208 ), and hardware security modules (HSMs) (e.g., pool of HSMs 210 ), can be equipped with modules that enforce trusted computing, such as TPMs. These TPMs can be implemented as hardware, firmware, and software modules. Moreover, user-controlled equipment, such as client machines, databases (e.g., database 212 ), and cloud-HSMs (e.g., pool of cloud-HSMs 214 ) can also be equipped with TPMs. Note that a cloud-HSM can refer to a dedicated HSM appliance owned or controlled by the customer but collocated in the cloud. The TPMs in the cloud and on the user machines ensure dynamic trust measurement and trusted storage.
In addition to trusted computing, QKD technologies can also be implemented in both the cloud provider realm and the user realm. More specifically, quantum key exchange can be enabled among the cloud nodes, as shown by the key logos. On the other hand, two types of user may exist: one group of users is equipped with QKD modules (e.g., user group 216 ), whereas the other group of users (e.g., user group 218 ) does not have the quantum key exchange capability. In the example shown in FIG. 2 , communication channels that also include a quantum channel to enable QKD are shown in solid lines (e.g., communication channel 222 ), whereas communication channels that do not include a quantum channel are shown in dashed lines (e.g., communication channel 224 ). More specifically, on the QKD-enabled communication channels, communication partners can negotiate encryption keys (also referred to as quantum data keys) using the quantum channel and then use the negotiated keys for secure communication. For example, a user within user group 216 can communicate with the cloud servers using the quantum-enhanced secure channel. Moreover, the user can perform initial configuration of his cloud-
CLAIMS
Claims ( 26 )
What is claimed is:
1. A computer-implemented method for negotiating quantum data keys between first and second entities, the method comprising:
performing a mutual authentication between the first and second entities;
in response to the mutual authentication succeeding, receiving, by the first entity, one or more sets of key-generation parameters from the second entity;
in response to validating the sets of key-generation parameters, sending an acknowledgment message to the second entity;
extracting, from a quantum string shared between the first and second entities, one or more quantum data keys based on the key-generation parameters, wherein a respective quantum data key comprises a number of bits extracted from the quantum string; and
establishing a quantum-enhanced secure communication channel between the first and second entities.
2. The computer-implemented method of claim 1 , wherein the first and second entities are each equipped with a trusted-computing module, and wherein performing the mutual authentication comprises exchanging a trusted measurement report associated with each of the first and second entities.
3. The computer-implemented method of claim 2 , further comprising storing the extracted quantum data keys within the trusted-computing module.
4. The computer-implemented method of claim 1 , wherein the quantum string shared between the first and second entities is obtained via a quantum key distribution (QKD) process.
5. The computer-implemented method of claim 1 , wherein a respective set of key-generation parameters specifies a plurality of keys having a same length, and wherein the set of key-generation parameters comprises:
a number parameter specifying a number of keys to be generated;
a length parameter specifying a bit length of the to-be-generated keys; and
a position parameter specifying a starting position of an initial to-be-generated key within the quantum string shared between the first and second entities.
6. The computer-implemented method of claim 1 , wherein a respective set of key-generation parameters specifies a single to-be-generated key, and wherein the set of key-generation parameters indicates the length of the single to-be-generated key and the starting position of the single to-be-generated key.
7. The computer-implemented method of claim 6 , wherein the lengths and starting positions of at least two keys are specified such that the two keys partially overlap, thereby resulting in a total number of bits in the extracted quantum data keys being more than a total number of bits in the quantum string shared between the first and second entities.
8. The computer-implemented method of claim 1 , wherein while receiving the one or more sets of key-generation parameters, the first entity is configured to receive a hash function calculated by the second entity based on the key-generation parameters and a shared secret; and
wherein validating the sets of key-generation parameters comprises comparing the received hash function with a hash function calculated by the first entity.
9. The computer-implemented method of claim 1 , wherein sending the acknowledgment message comprises:
calculating a variation of at least one key-generation parameter;
encrypting, using an encryption key, the calculated variation to obtain an encrypted message; and
sending the encrypted message.
10. The computer-implemented method of claim 1 , wherein the received one or more sets of key-generation parameters are encrypted using an encryption key associated with the first entity.
11. The computer-implemented method of claim 1 , wherein the first and second entities belong to a cloud computing system, and wherein the first or second entity comprises one of:
a piece of equipment provided by a cloud provider; and
a piece of equipment provided by a cloud client.
12. The computer-implemented method of claim 11 , wherein the first and second entities each receive a trusted certificate and equipment private key from a trusted authorization center associated with the cloud computing system.
13. The computer-implemented method of claim 12 , further comprising:
sending, by the first entity to the trusted authorization center, an authorization request, wherein the trusted authorization center comprises a plurality of trusted control nodes, and wherein a respective trusted control node maintains a share of a system private key;
receiving from the trusted control nodes a set of subkeys, wherein a respective subkey received from a particular trusted control node is generated based on identity information associated with the first entity, trusted-computing platform information associated with the first entity, and a share of the system private key stored in the particular trusted control node; and
generating an equipment private key specific to the first entity based on the received set of subkeys.
14. A network entity, comprising:
a processor; and
a storage device coupled to the processor and storing instructions which when executed by the processor cause the processor to perform a method for negotiating quantum data keys between the network entity and a second network entity, wherein the method comprises:
performing a mutual authentication between the network entity and the second network entity;
in response to the mutual authentication succeeding, receiving one or more sets of key-generation parameters from the second network entity;
in response to validating the sets of key-generation parameters, sending an acknowledgment message to the second network entity;
extracting, from a quantum string shared between the network entity and the second network entity, one or more quantum data keys based on the key-generation parameters, wherein a respective quantum data key comprises a number of bits extracted from the quantum string; and
establishing a quantum-enhanced secure communication channel between the first and second entities.
15. The network entity of claim 14 , wherein the network entity and the second network entity are each equipped with a trusted-computing module, and wherein performing the mutual authentication comprises exchanging a trusted measurement report associated with each of the network entity and the second network entity.
16. The network entity of claim 15 , wherein the method further comprises storing the extracted quantum data keys within the trusted-computing module.
17. The network entity of claim 14 , wherein the quantum string shared between the network entity and the second network entity is obtained via a quantum key distribution (QKD) process.
18. The network entity of claim 14 , wherein a respective set of key-generation parameters specifies a plurality of keys having a same length, and wherein the set of key-generation parameters comprises:
a number parameter specifying a number of keys to be generated;
a length parameter specifying a bit length of the to-be-generated keys; and
a position parameter specifying a starting position of an initial to-be-generated key within the quantum string shared between the network entity and the second network entity.
19. The network entity of claim 14 , wherein a respective set of key-generation parameters specifies a single to-be-generated key, and wherein the set of key-generation parameters indicates the length of the single to-be-generated key and the starting position of the single to-be-generated key.
20. The network entity of claim 19 , wherein the lengths and starting positions of at least two keys are specified such that the two keys partially overlap, thereby resulting in a total number of bits in the extracted quantum data keys being more than a total number of bits in the quantum string shared between the network entity and the second network entity.
21. The network entity of claim 14 , wherein receiving the one or more sets of key-generation parameters further comprises receiving a hash function calculated by the second network entity based on the key-generation parameters and a shared secret, and
wherein validating the sets of key-generation parameters comprises comparing the received hash function with a hash function calculated by the network entity.
22. The network entity of claim 14 , wherein sending the acknowledgment message comprises:
calculating a variation of at least one key-generation parameter;
encrypting, using an encryption key, the calculated variation to obtain an encrypted message; and
sending the encrypted message.
23. The network entity of claim 14 , wherein the received one or more sets of key-generation parameters are encrypted using an encryption key associated with the network entity.
24. The network entity of claim 14 , wherein the network entity and the second network entity belong to a cloud computing system, and wherein the network entity or the second network entity comprises one of:
a piece of equipment provided by a cloud provider; and
a piece of equipment provided by a cloud client.
25. The network entity of claim 24 , wherein the network entity and the second network entity each receive a trusted certificate and equipment private key from a trusted authorization center associated with the cloud computing system.
26. The network entity of claim 25 , wherein the method further comprise:
sending, by the network entity to the trusted authorization center, an authorization request, wherein the trusted authorization center comprises a plurality of trusted control nodes, and wherein a respective trusted control node maintains a share of a system private key; receiving from the trusted control nodes a set of subkeys, wherein a respective subkey received from a particular trusted control node is generated based on identity information associated with the network entity, trusted-computing platform information associated with the network entity, and a share of the system private key stored in the particular trusted control node; and
generating an equipment private key specific to the network entity based on the received set of subkeys.
US15/717,553
2016-10-14
2017-09-27
Method and system for quantum key distribution based on trusted computing
Active
US10103880B2
( en )
Priority Applications (2)
Application Number
Priority Date
Filing Date
Title
JP2019507255A
JP7033120B2
( en )
2016-10-14
2017-09-28
Methods and systems for quantum key distribution based on trusted computing
PCT/US2017/054117
WO2018071195A1
( en )
2016-10-14
2017-09-28
Method and system for quantum key distribution based on trusted computing
Applications Claiming Priority (3)
Application Number
Priority Date
Filing Date
Title
CN201610900271
2016-10-14
CN201610900271.1A
CN107959566A
( en )
2016-10-14
2016-10-14
Quantal data key agreement system and quantal data cryptographic key negotiation method
CN201610900271.1
2016-10-14
Publications (2)
Publication Number
Publication Date
US20180109372A1
US20180109372A1 ( en )
2018-04-19
US10103880B2
true
US10103880B2 ( en )
2018-10-16
Family
ID=61902766
Family Applications (1)
Application Number
Title
Priority Date
Filing Date
US15/717,553
Active
US10103880B2
( en )
2016-10-14
2017-09-27
Method and system for quantum key distribution based on trusted computing
Country Status (5)
Country
Link
US
( 1 )
US10103880B2
( en )
JP
( 1 )
JP7033120B2
( en )
CN
( 1 )
CN107959566A
( en )
TW
( 1 )
TWI738836B
( en )
WO
( 1 )
WO2018071195A1
( en )
Cited By (7)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US10756889B2
( en )
*
2018-06-11
2020-08-25
Korea Institute Of Science And Technology
Certificated quantum cryptography system and method
US10887100B2
( en )
*
2018-11-09
2021-01-05
Ares Technologies, Inc.
Systems and methods for distributed key storage
US11258580B2
( en )
2019-10-04
2022-02-22
Red Hat, Inc.
Instantaneous key invalidation in response to a detected eavesdropper
US11423141B2
( en )
2020-02-10
2022-08-23
Red Hat, Inc.
Intruder detection using quantum key distribution
US20250007700A1
( en )
*
2021-07-20
2025-01-02
The Research Foundation For The State University Of New York
System and method for quantum-secure microgrids
GB2634920A
( en )
*
2023-10-25
2025-04-30
Toshiba Kk
A node for a quantum communication network, a quantum communication network and a method of producing a signed message
US12301708B2
( en )
*
2023-03-27
2025-05-13
Red Hat, Inc.
Cryptographic key management for distributed quantum computing systems
Families Citing this family (55)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
US10903997B2
( en )
*
2017-10-19
2021-01-26
Autnhive Corporation
Generating keys using controlled corruption in computer networks
KR102028098B1
( en )
*
2018-01-29
2019-10-02
íêµì ìíµì ì°êµ¬ì
Apparatus and method for authenticating using quantum cryptography communication
EP3562115A1
( en )
*
2018-04-25
2019-10-30
Siemens Aktiengesellschaft
Protected transmission of data using post-quantum cryptography
US11290436B2
( en )
2018-09-21
2022-03-29
Cisco Technology, Inc.
Mechanism for encryption key distribution in computer networks
CN109088729B
( en )
*
2018-09-28
2021-03-26
å京éå±±å®å ¨è½¯ä»¶æéå ¬å¸
Key storage method and device
CN109302284B
( en )
*
2018-09-28
2021-10-22
å京éå±±å®å ¨è½¯ä»¶æéå ¬å¸
Hardware wallet
CN109194465B
( en )
*
2018-09-30
2022-02-18
å·ä¹¾å ¨çææ¯æéè´£ä»»å ¬å¸
Method for managing keys, user equipment, management device and storage medium
CN109450641B
( en )
*
2018-10-25
2021-12-07
å±±ä¸è¾¾åç½ç»ç§æè¡ä»½æéå ¬å¸
Access control method for high-end mold information management system
US11316668B2
( en )
*
2018-11-16
2022-04-26
Safetech Bv
Methods and systems for cryptographic private key management for secure multiparty storage and transfer of information
CN109660340B
( en )
*
2018-12-11
2021-11-26
å京å®å¾¡éåç§ææéå ¬å¸
Application system based on quantum key and use method thereof
CN109672537B
( en )
*
2019-01-18
2021-08-10
å¦è¬éåç§ææéå ¬å¸
Anti-quantum certificate acquisition system and method based on public key pool
CN110012074B
( en )
*
2019-03-12
2021-11-30
å京å¯ä¿¡åæ³°ä¿¡æ¯ææ¯æéå ¬å¸
Cloud environment trusted context management method
CN111756675B
( en )
*
2019-03-28
2023-04-07
ééæ§è¡ï¼å¼æ¼ï¼æéå ¬å¸
Data processing method, device, equipment and system
CN110190952A
( en )
*
2019-05-09
2019-08-30
æµæ±ç¥å·éåéä¿¡ææ¯æéå ¬å¸
It is a kind of based on quantum random number to the encrypted transmission method of Internet of Things safety
CN112291179B
( en )
*
2019-07-22
2022-04-12
ç§å¤§å½ç¾éåææ¯è¡ä»½æéå ¬å¸
Method, system and device for realizing equipment authentication
CN112468287B
( en )
*
2019-09-09
2022-02-22
ç§å¤§å½ç¾éåææ¯è¡ä»½æéå ¬å¸
Key distribution method, system, mobile terminal and wearable device
GB2587438A
( en )
*
2019-09-30
2021-03-31
Governing Council Univ Toronto
Key generation for use in secured communication
US12143481B2
( en )
2019-09-30
2024-11-12
The Governing Council Of The University Of Toronto
Method and system for key generation
CN110738767A
( en )
*
2019-10-29
2020-01-31
å®å¾½é®å¤©éåç§æè¡ä»½æéå ¬å¸
electronic forbidden authentication method based on quantum true random key
CN110932870B
( en )
*
2019-12-12
2023-03-31
å京å¦è¬éåç§ææéå ¬å¸
Quantum communication service station key negotiation system and method
CN113132323B
( en )
*
2019-12-31
2022-11-18
åä¸ºææ¯æéå ¬å¸
Communication method and device
CN111490878B
( en )
*
2020-04-09
2021-07-27
è ¾è®¯ç§æï¼æ·±å³ï¼æéå ¬å¸
Key generation method, apparatus, device and medium
US11374975B2
( en )
*
2020-07-02
2022-06-28
International Business Machines Corporation
TLS integration of post quantum cryptographic algorithms
CN111884798B
( en )
*
2020-07-22
2023-04-07
å ¨çè½æºäºèç½ç ç©¶é¢æéå ¬å¸
Electric power business quantum encryption system
CN112152817B
( en )
*
2020-09-25
2022-07-12
å½ç§éåéä¿¡ç½ç»æéå ¬å¸
Quantum key distribution method and system for authentication based on post-quantum cryptography algorithm
CN114448638B
( en )
*
2020-11-02
2024-02-13
å¦è¬éåç§ææéå ¬å¸
Witness-based quantum secure communication network key management communication method and system
CN112751858B
( en )
*
2020-12-30
2023-04-07
æå®åæ°ï¼å京ï¼ç§æè¡ä»½å ¬å¸
Data encryption communication terminal method, device, terminal, server and storage medium
CN112822010B
( en )
*
2021-01-28
2022-08-26
æé½ä¿¡æ¯å·¥ç¨å¤§å¦
Removable storage medium management method based on quantum key and block chain
CN113014379B
( en )
*
2021-02-05
2022-05-17
åé³çå·¥å¦é¢
Three-party authentication and key agreement method, system and computer storage medium supporting cross-cloud domain data sharing
CN113067699B
( en )
*
2021-03-04
2021-12-03
æ·±å³ç§ç¾éåä¿¡æ¯ç§ææéå ¬å¸
Data sharing method and device based on quantum key and computer equipment
CN114362928B
( en )
*
2021-03-23
2023-11-24
é¿æ¥å¤§å¦
A quantum key distribution and reconstruction method for multi-node encryption
CN113449343B
( en )
*
2021-05-31
2024-03-26
å½ç§éåéä¿¡ç½ç»æéå ¬å¸
Trusted computing system based on quantum technology
CN113595722B
( en )
*
2021-06-28
2023-11-07
é¿éå·´å·´æ°å 塿§è¡æéå ¬å¸
Quantum security key synchronization method, device, electronic equipment and storage medium
CN113346996B
( en )
*
2021-07-13
2022-07-12
éå·è½»å·¥ä¸å¤§å¦
Quantum-based content-centric network privacy protection method
US12105804B2
( en )
*
2021-07-17
2024-10-01
International Business Machines Corporation
Securely executing software based on cryptographically verified instructions
CN113765660B
( en )
*
2021-09-06
2022-08-02
ä¸å大å¦
A method for on-demand distribution of quantum keys for IoT terminal devices
EP4156001A1
( en )
*
2021-09-27
2023-03-29
ARRIS Enterprises LLC
Method and apparatus for two-step data signing
US11895234B2
( en )
2021-09-30
2024-02-06
Juniper Networks, Inc.
Delayed quantum key-distribution
CN113890732B
( en )
*
2021-10-14
2022-10-14
æé½ä¿¡æ¯å·¥ç¨å¤§å¦
Block chain-based secret communication method and security event tracing method thereof
CN114124372B
( en )
*
2021-11-01
2024-06-04
æè¿ éç§ææéå ¬å¸
Quantum key distribution-based network jump generation device and method
CN113810432B
( en )
*
2021-11-19
2022-06-17
é¿éäºè®¡ç®æéå ¬å¸
Quantum-safe data encryption method, encryption equipment and storage medium
WO2023096586A2
( en )
*
2021-11-29
2023-06-01
Han Chuen LIM
Quantum key generation method and system
CN114244513B
( en )
*
2021-12-31
2024-02-09
æ¥æ·ç§æ(䏿µ·)æéå ¬å¸
Key negotiation method, device and storage medium
CN114398627B
( en )
*
2022-01-26
2025-10-21
å京åçå½ç¾éåææ¯æéå ¬å¸
A quantum cryptography cloud application system and method for power dispatching based on zero trust
US12225111B2
( en )
*
2022-03-08
2025-02-11
SanDisk Technologies, Inc.
Authorization requests from a data storage device to multiple manager devices
US12362913B2
( en )
2022-03-16
2025-07-15
Honeywell Limited Honeywell Limitée
Method and system for secure distribution of symmetric encryption keys using quantum key distribution (QKD)
CN115276981B
( en )
*
2022-07-28
2025-01-03
å½å®¶çµç½æéå ¬å¸ä¿¡æ¯éä¿¡åå ¬å¸
Quantum key distribution method, device and computer readable storage medium
WO2024034699A1
( en )
*
2022-08-08
2024-02-15
ìì§ì ì 주ìíì¬
Method for carrying out user authentication in quantum communication system, and device therefor
US12425202B2
( en )
*
2022-09-30
2025-09-23
Ut-Battelle, Llc
Authentication of smart grid communications using quantum key distribution
JP2025542096A
( en )
2022-11-15
2025-12-25
ã¯ã©ã³ã¿ã ããªã㸠ãã¯ããã¸ã¼ãº ã¤ã³ã³ã¼ãã¬ã¤ããã
System and method for distribution of key generation data in a secure network
US12355871B2
( en )
*
2023-03-30
2025-07-08
Qualcomm Incorporated
Pairwise key establishment between two measurement states
US12476984B2
( en )
*
2023-08-15
2025-11-18
Wells Fargo Bank, N.A.
Quantum-based information protection
CN118282654B
( en )
*
2024-06-04
2024-08-23
å½ç½æµæ±ççµåæéå ¬å¸ä¿¡æ¯éä¿¡åå ¬å¸
Quantum communication method, edge device and quantum communication system
CN118631457B
( en )
*
2024-08-15
2024-12-03
ä¸çµä¿¡éåä¿¡æ¯ç§æé墿éå ¬å¸
Quantum-resistant security enhancement method of security assertion marking protocol
CN120729634B
( en )
*
2025-08-25
2025-10-31
è´µå·çµç½æéè´£ä»»å ¬å¸
Quantum key-based secondary authentication method, device and medium for digital terminal of power system
Citations (42)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
EP0962070A2
( en )
1997-12-24
1999-12-08
Koninklijke Philips Electronics N.V.
Administration and utilization of secret fresh random numbers in a networked environment
US20050259825A1
( en )
2004-05-24
2005-11-24
Alexei Trifonov
Key bank systems and methods for QKD
US20060026693A1
( en )
2004-07-29
2006-02-02
International Business Machines Corporation
Method, apparatus, and product for asserting physical presence with a trusted platform module in a hypervisor environment
US20070016794A1
( en )
2005-06-16
2007-01-18
Harrison Keith A
Method and device using one-time pad data
US20070076889A1
( en )
2005-09-29
2007-04-05
International Business Machines Corporation
Pre-generation of generic session keys for use in communicating within communications environments
US20070147292A1
( en )
2005-12-23
2007-06-28
Alcatel Lucent
Resource admission control for customer triggered and network triggered reservation requests
US20080114983A1
( en )
2006-11-15
2008-05-15
Research In Motion Limited
Client credential based secure session authentication method and apparatus
US20080123859A1
( en )
2006-11-27
2008-05-29
Rajesh Mamidwar
Method and system for encrypting and decrypting a transport stream using multiple algorithms
US20080165973A1
( en )
2007-01-09
2008-07-10
Miranda Gavillan Jose G
Retrieval and Display of Encryption Labels From an Encryption Key Manager
US20080219449A1
( en )
2007-03-09
2008-09-11
Ball Matthew V
Cryptographic key management for stored data
US20090034733A1
( en )
2007-07-31
2009-02-05
Shankar Raman
Management of cryptographic keys for securing stored data
US20090092252A1
( en )
2007-04-12
2009-04-09
Landon Curt Noll
Method and System for Identifying and Managing Keys
US20090106551A1
( en )
2006-04-25
2009-04-23
Stephen Laurence Boren
Dynamic distributed key system and method for identity management, authentication servers, data security and preventing man-in-the-middle attacks
US20090271634A1
( en )
2008-04-25
2009-10-29
The Regents Of The University Of Colorado & Securics, Inc.
Bio-Cryptograhpy : Secure cryptographic protocols with bipartite biotokens
US20100211787A1
( en )
2009-02-19
2010-08-19
Leonid Bukshpun
Chaotic cipher system and method for secure communication
US20100265077A1
( en )
2009-04-16
2010-10-21
Humble Travis S
Tampering Detection System Using Quantum-Mechanical Systems
US20110069972A1
( en )
2008-05-19
2011-03-24
Qinetiq Limited
Multiplexed quantum key distribution
US20110231615A1
( en )
2010-03-19
2011-09-22
Ober Robert E
Coherent storage network
US20120177201A1
( en )
2009-09-29
2012-07-12
Qinetiq Limited
Methods and apparatus for use in quantum key distribution
WO2012098543A2
( en )
2011-01-18
2012-07-26
Fortress Gb Ltd.
System and method for computerized negotiations based on coded integrity
US20120265892A1
( en )
2009-12-01
2012-10-18
Azuki Systems, Inc.
Method and system for secure and reliable video streaming with rate adaptation
WO2013026086A1
( en )
2011-08-19
2013-02-28
Quintessencelabs Pty Ltd
Virtual zeroisation system and method
US20130083926A1
( en )
2011-09-30
2013-04-04
Los Alamos National Security, Llc
Quantum key management
US20130101119A1
( en )
2010-06-15
2013-04-25
Los Alamos National Security Llc
Quantum key distribution using card, base station and trusted authority
US20130227286A1
( en )
2006-04-25
2013-08-29
Andre Jacques Brisson
Dynamic Identity Verification and Authentication, Dynamic Distributed Key Infrastructures, Dynamic Distributed Key Systems and Method for Identity Management, Authentication Servers, Data Security and Preventing Man-in-the-Middle Attacks, Side Channel Attacks, Botnet Attacks, and Credit Card and Financial Transaction Fraud, Mitigating Biometric False Positives and False Negatives, and Controlling Life of Accessible Data in the Cloud
US20130251145A1
( en )
2010-12-02
2013-09-26
Qinetiq Limited
Quantum key distribution
US20140259138A1
( en )
2013-03-05
2014-09-11
Alibaba Group Holding Limited
Method and system for distinguishing humans from machines
US20140281511A1
( en )
2013-03-15
2014-09-18
Microsoft Corporation
Secure data processing on sensitive data using trusted hardware
US20140331050A1
( en )
2011-04-15
2014-11-06
Quintessence Labs Pty Ltd.
Qkd key management system
US20140351915A1
( en )
2010-02-17
2014-11-27
Nokia Coporation
Method and apparatus for providing an authentication context-based session
US20150046709A1
( en )
2003-09-15
2015-02-12
Telecommunication Systems, Inc.
Encapsulation of Secure Encrypted Data in a Deployable, Secure Communication System Allowing Benign, Secure Commercial Transport
US20150181308A1
( en )
2012-02-08
2015-06-25
Vixs Systems, Inc.
Container agnostic decryption device and methods for use therewith
US20150236852A1
( en )
2014-02-17
2015-08-20
Kabushiki Kaisha Toshiba
Quantum key distribution device, quantum key distribution system, and quantum key distribution method
US20150288542A1
( en )
2014-04-04
2015-10-08
Solyman Ashrafi
System and method for communication using orbital angular momentum with multiple layer overlay modulation
US20150381363A1
( en )
2014-01-31
2015-12-31
Teixem Corp.
System and method for performing secure communications
US20160021068A1
( en )
2007-01-22
2016-01-21
Spyrus, Inc.
Encryption device with configurable security functionality using network authorization code
US9323901B1
( en )
2007-09-28
2016-04-26
Emc Corporation
Data classification for digital rights management
WO2016070141A1
( en )
2014-10-30
2016-05-06
Alibaba Group Holding Limited
Method, apparatus, and system for quantum key distribution, privacy amplification, and data transmission
US20160226846A1
( en )
2015-01-22
2016-08-04
Alibaba Group Holding Limited
Method, apparatus, and system for quantum key distribution
US20160241396A1
( en )
2015-02-16
2016-08-18
Alibaba Group Holding Limited
Method, apparatus, and system for identity authentication
US20160248581A1
( en )
2015-01-08
2016-08-25
Alibaba Group Holding Limited
Quantum key distribution system, method and apparatus based on trusted relay
US20160294783A1
( en )
2015-04-06
2016-10-06
At&T Intellectual Property I, L.P.
Decentralized and distributed secure home subscriber server device
Family Cites Families (7)
* Cited by examiner, â Cited by third party
Publication number
Priority date
Publication date
Assignee
Title
JP2007019789A
( en )
2005-07-07
2007-01-25
Nec Corp
Random number sharing system and method therefor
GB0801395D0
( en )
2008-01-25
2008-03-05
Qinetiq Ltd
Network having quantum key distribution
WO2014074194A2
( en )
2012-08-24
2014-05-15
Los Alamos National Security, Llc
Scalable software architecture for quantum cryptographic key management
CN103856477B
( en )
*
2012-12-06
2018-01-02
é¿éå·´å·´é墿§è¡æéå ¬å¸
A kind of credible accounting system and corresponding authentication method and equipment
CN103491531B
( en )
*
2013-08-23
2016-07-06
ä¸å½ç§å¦ææ¯å¤§å¦
Power system WiMAX wireless communication networks uses the method that quantum key improves power information transmission security
WO2015048783A1
( en )
2013-09-30
2015-04-02
Nordholt, Jane,