ConceptioArchiveGoogle Patents
Google Patentsopen access

Quantum key distribution protocol — Arqit Limited (US12021976B2)

Arqit Limited · Google Patents
Google Patents · Patents · License: Open Access
Open Source ↗
arqitlimited
patent, google patents, intellectual property, US12021976B2, Arqit Limited, Barry Childe, en, 2024

ABSTRACT

Abstract

Methods, apparatus, and systems are provided for performing a quantum key distribution (QKD) protocol between a first device, a second device, and an intermediary device. The intermediary device transmitting: a first secret symbol string over a first quantum channel to the first device; a first basis set over a first communication channel to the first device. The intermediary device; a second secret symbol string over a second quantum channel to the second device; a second basis set over a second communication channel to the second device. The intermediary device generating a third symbol string based on combining the first and second secret symbol strings and transmitting to the second device, via the second communication channel, data representative of the third symbol string. The first device and second device perform a quantum key exchange and sifting based on the corresponding received first and second secret symbol strings and first and second basis sets, and a fourth set of symbols generated by the second device generates a fourth set of symbols based on combining the second received secret symbols with the received third symbol string.

Description

This application is the National Stage filing under 35 U.S.C. 371 of International Application No. PCT/GB2020/052826, filed Nov. 6, 2020, claims the benefit of GB Application No. 1916311.2, filed Nov. 8, 2019, the contents of which are all hereby incorporated by reference herein in their entirety.

BACKGROUND

Quantum key distribution (QKD) is a secure communication method which implements a cryptographic QKD protocol involving components of quantum mechanics for distributing cryptographic keys. It enables two parties to produce a shared random secret key or cryptographic key known only to them, which can then be used to encrypt and decrypt messages. The BB84 QKD protocol is a well-known QKD protocol using photon polarisation bases to transmit the information. The BB84 QKD protocol uses a set of bases including least two pairs of conjugate photon polarisation bases (e.g. a set of bases including, without limitation, for example a rectilinear photon basis (e.g. vertical (0°) and horizontal (90°) polarisations) and diagonal photon basis (e.g. 45° and 135° polarisations) or the circular basis of left- and right-handedness etc.) In the BB84 protocol, QKD is performed between a sender device or intermediary device (e.g. referred to as Alice) and a receiver or first device (e.g. referred to as Bob or Carol). The sender device and receiver device are connected by a quantum communication channel which allows quantum information (e.g. quantum states) to be transmitted. The quantum channel may be, without limitation, for example, an optical fibre or optical free space. Furthermore, the sender device and receiver device also communicate over a non-quantum channel or public classical channel, without limitation, for example a fibre optic channel, telecommunications channel, radio channel, broadcast radio or the internet and/or any other wireless or wired communications channel and the like. Sheng-Kai Liao, et. al. “Satellite-to-ground quantum key distribution”, Nature volume 549, pages 43-47, 7 Sep. 2017, describes satellite-based QKD system using the BB84 protocol for distributing keys, where a satellite free-space optical quantum channel is produced using a 300-mm aperture Cassegrain telescope, which sends a light beam from a Micius satellite (e.g. Alice) to a ground station (e.g. Bob), which uses a Ritchey Chretien telescope for receiving the QKD photons over the satellite free-space optical quantum channel.

Although the security of the BB84 protocol comes from judicious use of the quantum and classical communication channels and authentication and the like, both the sender or intermediary device distributing the cryptographic key and the receiver device receiving the cryptographic key know the cryptographic key that the receiver device will eventually use. This means that the sender or intermediary device distributing the cryptographic key to the receiver device has to be a trusted device in a secure location in order for the receiver device to be able to trust that they may use the resulting cryptographic key. This may be fine should both the sender and receiver device use the resulting cryptographic key for cryptographic operations therebetween, e.g. for encrypted communications and the like with each other. However, if the sender or intermediary device is only distributing keys to one or more receiver devices in which the receiver devices may use the resulting cryptographic keys with one or more other receiver devices, then it is often not acceptable that the sender or intermediary device has access to the resulting cryptographic keys, this is an insecure system and cannot be trusted.

There is a desire for a more improved QKD protocol that does not rely on the intermediary device being a fully trusted device by a first device and second device requiring a shared key or shared cryptographic key for cryptographic operations therebetween.

The embodiments described below are not limited to implementations which solve any or all of the disadvantages of the known approaches described above.

SUMMARY

This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to determine the scope of the claimed subject matter; variants and alternative features which facilitate the working of the invention and/or serve to achieve a substantially similar technical effect should be considered as falling into the scope of the invention disclosed herein.

The present disclosure provides method(s), apparatus and system(s) of quantum key distribution between a first device and a second device via an intermediary device using a quantum key distribution protocol. The quantum key distribution protocol enables the intermediary device to send randomly generated first and second secret symbol strings to the first device and second device, respectively, over respective quantum channels. Further processing of the first and second secret symbol strings is performed by the intermediary device via respective classical communication channels with the first and second devices. The intermediary device generates a third symbol string for sending via a classical communication channel to the second device. The third symbol string is based on combining a set of symbols of the first secret symbol string with a set of symbols of the second secret symbol string in such a way that enables the second device to retrieve a fourth set of symbols based on using its received second symbol string. The combining of the set of symbols of the first secret symbol string and the set of symbols of the second secret symbol string may be based on, without limitation, for example one-time-pad encryption/decryption, masking, exclusive OR (XOR) operations on bits when symbols converted to bits, or extended XOR operations on symbols or obfuscated set of the first secret symbols. The second device is configured to perform a reverse set of operations to extract a fourth set of symbols using symbols from the successfully received second secret symbol string. The symbols of the fourth set of symbols correspond to symbols of the first set of symbols. From this, the first and second devices may perform symbol (or bit) sifting using the received first set of symbols at the first device and the fourth set of symbols generated at the second device for determining a common set of sifted symbols from which a cryptographic key may be derived by the first and second devices. The cryptographic key is only known to the first and second devices, thus, they can perform cryptographic operations with each other. The first and second devices can then determine a cryptographic key in a quantum-safe manner even when the intermediary device is not a trusted device.

In a first aspect, the present disclosure provides a computer-implemented method of quantum key distribution between a first device and a second device, the method, performed by an intermediary device, comprising: transmitting a first secret symbol string over a first quantum channel to the first device, each symbol of the first secret symbol string modulated by a basis state randomly selected from a set of bases; transmitting a first basis set over a first communication channel to the first device, the first basis set comprising data representative of the randomly selected bases used to modulate each symbol of the first secret symbol string; transmitting a second secret symbol string over a second quantum channel to the second device, each symbol of the second secret symbol string modulated by a basis state randomly selected from the set of bases; transmitting a second basis set over a second communication channel to the second device, the second basis set comprising data representative of the randomly selected bases used to modulate each symbol of the second secret symbol string; generating a third symbol string based on combining the first and second secret symbol strings; transmitting to the second device, via the second communication channel, data representative of the third symbol string; wherein the first device and second device perform a quantum key exchange based on: the first device using the received first basis set to determine a first received set of secret symbols comprising symbols of the first secret symbol string transmitted over the first quantum channel that were successfully received by the first device; the second device uses the received second basis set to determine a second received set of secret symbols comprising symbols of the second secret symbol string transmitted over the second quantum channel that were successfully received by the second device; the second device generates a fourth set of symbols based on combining the second received set of secret symbols with the received third symbol string, wherein one or more symbols of the fourth set of symbols correspond to one or more symbols of the first symbol string; the first device and second device performing symbol sifting operations over a third communication channel between the based on the first received set of secret symbols at the first device and the fourth set of symbols at the second device for generating a common set of sifted symbols for forming a cryptographic key at the first and second devices.

Preferably, the method further comprising: receiving from the first device, over the first communication channel, data representative of the symbol positions of the symbols in the first secret symbol string transmitted over the first quantum communication channel that were successfully received by the first device; generating a first set of symbols based on those symbols of the first secret symbol string that correspond to the received data representative of the symbol positions of symbols from the first secret symbol string successfully received by the first device; receiving from the second device, over the second communication channel, data representative of the symbol positions of the symbols in the second secret symbol string transmitted over the second quantum communication channel that were successfully received by the second device; generating a second set of symbols based on those symbols of the second secret symbol string that correspond to the received data representative of the symbol positions of symbols from the second secret symbol string successfully received by the second device; and said generating the third symbol string further comprising generating the third symbol string based on combining the first set of symbols and second set of symbols.

Preferably, the method further comprising, prior to transmitting the randomly selected bases to the first device, performing said receiving from the first device, over the first communication channel, data representative of the symbol positions of the symbols in the first secret symbol string transmitted over the first quantum communication channel that were successfully received by the first device.

Preferably, the method further comprising, prior to transmitting the randomly selected bases to the second device, performing said receiving from the second device, over the second communication channel, data representative of the symbol positions of the symbols in the second secret symbol string transmitted over the second quantum communication channel that were successfully received by the second device.

Preferably, the method further comprising the first device and second device performing a quantum key exchange based on: the first device forms the first received set of secret symbols based on the received first basis set and the symbols that were successfully received from the first secret symbol string transmitted over the first quantum communication channel, wherein each symbol of the first received set of secret symbols is a symbol of the first secret symbol string that was successfully received by the first device in which the basis used for receiving said symbol matches the corresponding basis in the received first basis set used to transmit said symbol; the second device forms the second received set of secret symbols based on the received second basis set and the symbols that were successfully received from the second secret symbol string transmitted over the second quantum communication channel, wherein each symbol of the second received set of secret symbols is a symbol of the second secret symbol string that was successfully received by the second device in which the basis used for receiving said symbol matches the corresponding basis in the received second basis set used to transmit said symbol; the second device generates the fourth set of symbols based combining the second received set of secret symbols with the received third symbol string, wherein one or more symbols of the fourth set of symbols correspond to one or more symbols of the first set of symbols; the first device and second device performing symbol sifting operations over the third communication channel therebetween based on the first received set of secret symbols at the first device and the fourth set of symbols at the second device for generating a common set of sifted symbols for forming a cryptographic key at the first and second devices.

Preferably, said generating the third symbol string further comprising: in response to determining the length of the first set of symbols is less than the length of the second set of symbols: truncating the second set of symbols to the length of the first set of symbols; and generating the third symbol string based on combining the first set of symbols with the truncated second set of symbols; and in response to determining the length of the second set of symbols is less than the length of the first set of symbols: truncating the first set of symbols to the length of the second set of symbols; and generating the third symbol string based on combining the truncated first set of symbols with the second set of symbols.

Preferably, said generating the third symbol string further comprising: in response to determining the length of the first set of symbols is less than the length of the second set of symbols: adjusting the second set of symbols by removing an agreed set of symbols from the second set of symbols until the adjusted length of the adjusted second set of symbols is the same as the first set of symbols; and generating the third symbol string based on combining the first set of symbols with the adjusted second set of symbols; and in response to determining the length of the second set of symbols is less than the length of the first set of symbols: adjusting the first set of symbols by removing an agreed set of symbols from the first set of symbols until the adjusted length of the adjusted first set of symbols is the same as the second set of symbols; and generating the third symbol string based on combining the adjusted first set of symbols with the second set of symbols.

Preferably, generating the third symbol string further comprises one or more from the group of: generating the third symbol string based on performing an XOR operation using data representative of a first set of bits and a second set of bits, the first set of bits based on converting each of the symbols in the first set of symbols to a string of bits and the second set of bits based on converting each of the symbols in the second set of symbols to a string of bits; generating the third bit string based on performing one time pad encryption operation(s) using data representative of, at least in part, the first set of symbols and the second set of symbols; and generating the third symbol string based on performing any other type of operation for obfuscating one or more symbols of the first set of symbols using the second set of symbols.

Preferably, the second device generating the fourth symbol string further comprises one or more from the group of: generating the fourth symbol string based on performing an XOR operation using the second received set of secret symbols and the received third symbol string; generating the fourth symbol string based on performing one time pad decryption operation(s) using the received second set of secret symbols and the third secret symbol string; and generating the fourth symbol string based on performing any other type of operation for extracting one or more symbols of the first secret symbol string using the second received set of secret symbols and the third symbol string.

Preferably, generating the third symbol string further comprises one or more from the group of: generating the third symbol string based on performing an XOR operation using data representative of, at least in part, the first secret symbol string and the second secret symbol string; generating the third symbol string based on performing one time pad encryption operation(s) using data representative of, at least in part, the first secret symbol string and the second secret symbol string; and generating the third symbo

This application is the National Stage filing under 35 U.S.C. 371 of International Application No. PCT/GB2020/052826, filed Nov. 6, 2020, claims the benefit of GB Application No. 1916311.2, filed Nov. 8, 2019, the contents of which are all hereby incorporated by reference herein in their entirety.

BACKGROUND

Quantum key distribution (QKD) is a secure communication method which implements a cryptographic QKD protocol involving components of quantum mechanics for distributing cryptographic keys. It enables two parties to produce a shared random secret key or cryptographic key known only to them, which can then be used to encrypt and decrypt messages. The BB84 QKD protocol is a well-known QKD protocol using photon polarisation bases to transmit the information. The BB84 QKD protocol uses a set of bases including least two pairs of conjugate photon polarisation bases (e.g. a set of bases including, without limitation, for example a rectilinear photon basis (e.g. vertical (0°) and horizontal (90°) polarisations) and diagonal photon basis (e.g. 45° and 135° polarisations) or the circular basis of left- and right-handedness etc.) In the BB84 protocol, QKD is performed between a sender device or intermediary device (e.g. referred to as Alice) and a receiver or first device (e.g. referred to as Bob or Carol). The sender device and receiver device are connected by a quantum communication channel which allows quantum information (e.g. quantum states) to be transmitted. The quantum channel may be, without limitation, for example, an optical fibre or optical free space. Furthermore, the sender device and receiver device also communicate over a non-quantum channel or public classical channel, without limitation, for example a fibre optic channel, telecommunications channel, radio channel, broadcast radio or the internet and/or any other wireless or wired communications channel and the like. Sheng-Kai Liao, et. al. “Satellite-to-ground quantum key distribution”, Nature volume 549, pages 43-47, 7 Sep. 2017, describes satellite-based QKD system using the BB84 protocol for distributing keys, where a satellite free-space optical quantum channel is produced using a 300-mm aperture Cassegrain telescope, which sends a light beam from a Micius satellite (e.g. Alice) to a ground station (e.g. Bob), which uses a Ritchey Chretien telescope for receiving the QKD photons over the satellite free-space optical quantum channel.

Although the security of the BB84 protocol comes from judicious use of the quantum and classical communication channels and authentication and the like, both the sender or intermediary device distributing the cryptographic key and the receiver device receiving the cryptographic key know the cryptographic key that the receiver device will eventually use. This means that the sender or intermediary device distributing the cryptographic key to the receiver device has to be a trusted device in a secure location in order for the receiver device to be able to trust that they may use the resulting cryptographic key. This may be fine should both the sender and receiver device use the resulting cryptographic key for cryptographic operations therebetween, e.g. for encrypted communications and the like with each other. However, if the sender or intermediary device is only distributing keys to one or more receiver devices in which the receiver devices may use the resulting cryptographic keys with one or more other receiver devices, then it is often not acceptable that the sender or intermediary device has access to the resulting cryptographic keys, this is an insecure system and cannot be trusted.

There is a desire for a more improved QKD protocol that does not rely on the intermediary device being a fully trusted device by a first device and second device requiring a shared key or shared cryptographic key for cryptographic operations therebetween.

The embodiments described below are not limited to implementations which solve any or all of the disadvantages of the known approaches described above.

SUMMARY

This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to determine the scope of the claimed subject matter; variants and alternative features which facilitate the working of the invention and/or serve to achieve a substantially similar technical effect should be considered as falling into the scope of the invention disclosed herein.

The present disclosure provides method(s), apparatus and system(s) of quantum key distribution between a first device and a second device via an intermediary device using a quantum key distribution protocol. The quantum key distribution protocol enables the intermediary device to send randomly generated first and second secret symbol strings to the first device and second device, respectively, over respective quantum channels. Further processing of the first and second secret symbol strings is performed by the intermediary device via respective classical communication channels with the first and second devices. The intermediary device generates a third symbol string for sending via a classical communication channel to the second device. The third symbol string is based on combining a set of symbols of the first secret symbol string with a set of symbols of the second secret symbol string in such a way that enables the second device to retrieve a fourth set of symbols based on using its received second symbol string. The combining of the set of symbols of the first secret symbol string and the set of symbols of the second secret symbol string may be based on, without limitation, for example one-time-pad encryption/decryption, masking, exclusive OR (XOR) operations on bits when symbols converted to bits, or extended XOR operations on symbols or obfuscated set of the first secret symbols. The second device is configured to perform a reverse set of operations to extract a fourth set of symbols using symbols from the successfully received second secret symbol string. The symbols of the fourth set of symbols correspond to symbols of the first set of symbols. From this, the first and second devices may perform symbol (or bit) sifting using the received first set of symbols at the first device and the fourth set of symbols generated at the second device for determining a common set of sifted symbols from which a cryptographic key may be derived by the first and second devices. The cryptographic key is only known to the first and second devices, thus, they can perform cryptographic operations with each other. The first and second devices can then determine a cryptographic key in a quantum-safe manner even when the intermediary device is not a trusted device.

In a first aspect, the present disclosure provides a computer-implemented method of quantum key distribution between a first device and a second device, the method, performed by an intermediary device, comprising: transmitting a first secret symbol string over a first quantum channel to the first device, each symbol of the first secret symbol string modulated by a basis state randomly selected from a set of bases; transmitting a first basis set over a first communication channel to the first device, the first basis set comprising data representative of the randomly selected bases used to modulate each symbol of the first secret symbol string; transmitting a second secret symbol string over a second quantum channel to the second device, each symbol of the second secret symbol string modulated by a basis state randomly selected from the set of bases; transmitting a second basis set over a second communication channel to the second device, the second basis set comprising data representative of the randomly selected bases used to modulate each symbol of the second secret symbol string; generating a third symbol string based on combining the first and second secret symbol strings; transmitting to the second device, via the second communication channel, data representative of the third symbol string; wherein the first device and second device perform a quantum key exchange based on: the first device using the received first basis set to determine a first received set of secret symbols comprising symbols of the first secret symbol string transmitted over the first quantum channel that were successfully received by the first device; the second device uses the received second basis set to determine a second received set of secret symbols comprising symbols of the second secret symbol string transmitted over the second quantum channel that were successfully received by the second device; the second device generates a fourth set of symbols based on combining the second received set of secret symbols with the received third symbol string, wherein one or more symbols of the fourth set of symbols correspond to one or more symbols of the first symbol string; the first device and second device performing symbol sifting operations over a third communication channel between the based on the first received set of secret symbols at the first device and the fourth set of symbols at the second device for generating a common set of sifted symbols for forming a cryptographic key at the first and second devices.

Preferably, the method further comprising: receiving from the first device, over the first communication channel, data representative of the symbol positions of the symbols in the first secret symbol string transmitted over the first quantum communication channel that were successfully received by the first device; generating a first set of symbols based on those symbols of the first secret symbol string that correspond to the received data representative of the symbol positions of symbols from the first secret symbol string successfully received by the first device; receiving from the second device, over the second communication channel, data representative of the symbol positions of the symbols in the second secret symbol string transmitted over the second quantum communication channel that were successfully received by the second device; generating a second set of symbols based on those symbols of the second secret symbol string that correspond to the received data representative of the symbol positions of symbols from the second secret symbol string successfully received by the second device; and said generating the third symbol string further comprising generating the third symbol string based on combining the first set of symbols and second set of symbols.

Preferably, the method further comprising, prior to transmitting the randomly selected bases to the first device, performing said receiving from the first device, over the first communication channel, data representative of the symbol positions of the symbols in the first secret symbol string transmitted over the first quantum communication channel that were successfully received by the first device.

Preferably, the method further comprising, prior to transmitting the randomly selected bases to the second device, performing said receiving from the second device, over the second communication channel, data representative of the symbol positions of the symbols in the second secret symbol string transmitted over the second quantum communication channel that were successfully received by the second device.

Preferably, the method further comprising the first device and second device performing a quantum key exchange based on: the first device forms the first received set of secret symbols based on the received first basis set and the symbols that were successfully received from the first secret symbol string transmitted over the first quantum communication channel, wherein each symbol of the first received set of secret symbols is a symbol of the first secret symbol string that was successfully received by the first device in which the basis used for receiving said symbol matches the corresponding basis in the received first basis set used to transmit said symbol; the second device forms the second received set of secret symbols based on the received second basis set and the symbols that were successfully received from the second secret symbol string transmitted over the second quantum communication channel, wherein each symbol of the second received set of secret symbols is a symbol of the second secret symbol string that was successfully received by the second device in which the basis used for receiving said symbol matches the corresponding basis in the received second basis set used to transmit said symbol; the second device generates the fourth set of symbols based combining the second received set of secret symbols with the received third symbol string, wherein one or more symbols of the fourth set of symbols correspond to one or more symbols of the first set of symbols; the first device and second device performing symbol sifting operations over the third communication channel therebetween based on the first received set of secret symbols at the first device and the fourth set of symbols at the second device for generating a common set of sifted symbols for forming a cryptographic key at the first and second devices.

Preferably, said generating the third symbol string further comprising: in response to determining the length of the first set of symbols is less than the length of the second set of symbols: truncating the second set of symbols to the length of the first set of symbols; and generating the third symbol string based on combining the first set of symbols with the truncated second set of symbols; and in response to determining the length of the second set of symbols is less than the length of the first set of symbols: truncating the first set of symbols to the length of the second set of symbols; and generating the third symbol string based on combining the truncated first set of symbols with the second set of symbols.

Preferably, said generating the third symbol string further comprising: in response to determining the length of the first set of symbols is less than the length of the second set of symbols: adjusting the second set of symbols by removing an agreed set of symbols from the second set of symbols until the adjusted length of the adjusted second set of symbols is the same as the first set of symbols; and generating the third symbol string based on combining the first set of symbols with the adjusted second set of symbols; and in response to determining the length of the second set of symbols is less than the length of the first set of symbols: adjusting the first set of symbols by removing an agreed set of symbols from the first set of symbols until the adjusted length of the adjusted first set of symbols is the same as the second set of symbols; and generating the third symbol string based on combining the adjusted first set of symbols with the second set of symbols.

Preferably, generating the third symbol string further comprises one or more from the group of: generating the third symbol string based on performing an XOR operation using data representative of a first set of bits and a second set of bits, the first set of bits based on converting each of the symbols in the first set of symbols to a string of bits and the second set of bits based on converting each of the symbols in the second set of symbols to a string of bits; generating the third bit string based on performing one time pad encryption operation(s) using data representative of, at least in part, the first set of symbols and the second set of symbols; and generating the third symbol string based on performing any other type of operation for obfuscating one or more symbols of the first set of symbols using the second set of symbols.

Preferably, the second device generating the fourth symbol string further comprises one or more from the group of: generating the fourth symbol string based on performing an XOR operation using the second received set of secret symbols and the received third symbol string; generating the fourth symbol string based on performing one time pad decryption operation(s) using the received second set of secret symbols and the third secret symbol string; and generating the fourth symbol string based on performing any other type of operation for extracting one or more symbols of the first secret symbol string using the second received set of secret symbols and the third symbol string.

Preferably, generating the third symbol string further comprises one or more from the group of: generating the third symbol string based on performing an XOR operation using data representative of, at least in part, the first secret symbol string and the second secret symbol string; generating the third symbol string based on performing one time pad encryption operation(s) using data representative of, at least in part, the first secret symbol string and the second secret symbol string; and generating the third symbol string based on performing any other type of operation for obfuscating one or more symbols of the first secret symbol string using the second secret symbol string.

Preferably, the second device generating the fourth symbol string further comprises one or more from the group of: generating the fourth symbol string based on performing an XOR operation using data representative of, at least in part, the second secret symbol string and the third symbol string; generating the fourth symbol string based on performing one time pad decryption operation(s) using data representative, of at least in part, the second secret symbol string and the third secret symbol string; and generating the fourth symbol string based on performing any other type of operation for extracting one or more symbols of the first secret symbol string using data representative of, at least in part, the second secret symbol string and the third symbol string.

Preferably, the first device and second device performing symbol sifting operations over the third communication channel therebetween based on: the first device forms a first matching basis set based on the first received set of secret symbols, wherein the first matching basis set includes all the basis states the first device used to receive the symbols of the first received set of secret symbols that match the corresponding basis states of the received first basis set used to transmit said symbol of the first set of symbols; and the first device sends over the third communication channel data representative of the first matching basis set to the second device; the second device forms a second matching basis set based on the second received set of secret symbols, wherein the second matching basis set includes all the basis states the second device used to receive the symbols of the second received set of secret symbols that match the corresponding basis states of the received second basis set used to transmit said symbol of the second set of symbols; the second device sends over the third communication channel data representative of the second matching basis set to the first device; the first device generates a first common set of sifted symbols based on discarding each symbol in the first received set of secret symbols in which the corresponding basis in the first matching basis set is different to the corresponding basis in the received second matching basis set; the second device generates a second common set of sifted symbols based on discarding each symbol in the fourth set of symbols in which the corresponding basis in the received first matching basis set is different to the corresponding basis in the second matching basis set; and the first and second devices forming a cryptographic key based on the first and second common set of sifted symbols, respectively.

Preferably, the first and second device perform error detection and/or correction on the first and second common sets of sifted bits.

In a second aspect, the present disclosure provides a computer-implemented method of quantum key distribution between a first device and a second device, the method, performed by the first device, comprising: receiving, from an intermediary device, over a quantum channel a first secret symbol string, wherein the intermediary device modulated each symbol of the first secret symbol string using a basis state of a basis selected at random from a set of bases for transmission over the quantum channel; demodulating the received first secret symbol string, where each received first secret symbol is demodulated using a basis state of a basis selected at random from the set of bases; receiving, from the intermediary device, data representative of a first basis set over a first communication channel, the first basis set comprising data representative of the randomly selected bases used by the intermediary device to modulate each symbol of the first secret symbol string; determining a first received set of secret symbols from the received first secret symbol string that are successfully received using the received first basis set; performing sifting operation(s) with the second device using the first received set of secret symbols of the first device and another set of secret symbols determined by the second device for generating a common sifted set of symbols for forming a cryptographic key with the second device, wherein the other set of secret symbols are associated with the first received set of secret symbols; and the second device determines the other set of secret symbols based on, at least in part, a second secret symbol string received by the second device over a second quantum channel from the intermediary device and, at least in part, a third secret symbol string received by the second device over a second communication channel from the intermediary device, wherein the third secret symbol string is based on a combination of, at least in part, the second secret symbol string and the first secret symbol string, and the second device generates the other set of secret symbols based on a combination of the received third secret symbol string and, at least in part, the second secret symbol string.

Preferably, the method further comprising transmitting, to the intermediary device, over the first communication channel, data representative of the symbol positions of the symbols in the first secret symbol string that were successfully received by the first device over the quantum communication channel.

Preferably, the method further comprising, prior to receiving the first basis set, performing said transmitting from the first device to the intermediary device over the first communication channel data representative of the symbol positions of the symbols in the first secret symbol string successfully received by the first device over the quantum communication channel.

Preferably, the method further comprising the first device and second device performing a quantum key exchange based on: forming the first received set of secret symbols based on the received first basis set and the symbols that were successfully received from the first secret symbol string transmitted by the intermediary device over the quantum communication channel, wherein each symbol of the first received set of secret symbols is a symbol of the first secret symbol string that was successfully received by the first device in which the basis used for receiving said symbol matches the corresponding basis in the received first basis set used to transmit said symbol; wherein the second device forms a second received set of secret symbols based on a received second basis set and the symbols that were successfully received from the second secret symbol string transmitted by the intermediary device over the second quantum channel, wherein each symbol of the second received set of secret symbols is a symbol of the second secret symbol string that was successfully received by the second device in which the basis used for receiving said symbol matches the corresponding basis in the received second basis set used to transmit said symbol; and the second device generates the other set of symbols based on combining the second received set of secret symbols with the received third symbol string, wherein one or more symbols of the other set of symbols correspond to one or more symbols of the first set of symbols; and performing symbol sifting operations with the second device over the third communication channel based on the first received set of secret symbols at the first device and the other set of symbols at the second device for generating a common set of sifted symbols for forming a cryptographic key at the first and second devices.

Preferably, the combination of the second secret symbol string and the first secret symbol string comprises generating the third symbol string using an XOR operation on data representative of the second secret symbol string and the first secret symbol string.

Preferably, generating the third symbol string further comprises one or more from the group of: generating the third symbol string based on performing an XOR operation using data representative of, at least in part, the first secret symbol string and the second secret symbol string; generating the third symbol string based on performing one time pad encryption operation(s) using data representative of, at least in part, the first secret symbol string and the second secret symbol string; and generating the third symbol string based on performing any other type of operation for obfuscating one or more symbols of the first secret symbol string using the second secret symbol string.

Preferably, the second device generating the other symbol string further comprises one or more from the group of: generating the other symbol string based on performing an XOR operation using data representative of, at least in part, the received second secret symbol string and the received third symbol string; generating the other symbol string based on performing one time pad decryption operation(s) using data representative, of at least in part, the received second secret symbol string and the received third secret symbol string; and generating the other symbol string based on performing any other type of operation for extracting one or more symbols of the first secret symbol string using data representative of, at least in part, the received second secret symbol string and the received third symbol string.

Preferably, performing the symbol sifting operations with the second device over the third communication channel further comprising: forming a first matching basis set based on the first received set of secret symbols, wherein the first matching basis set includes all the basis states the first device used to receive the symbols of the first received set of secret symbols that match the corresponding basis states of the received first basis set used by the intermediary device to transmit said symbol of the first secret symbol string; and transmitting to the second device over the third communication channel data representative of the first matching basis set, wherein: receiving from the second device over the third communication channel data representative of a second matching basis set, wherein the second device forms the second matching basis set based on the second received set of secret symbols, wherein the second matching basis set includes all the basis states the second device used to receive the symbols of the second received set of secret symbols that match the corresponding basis states of the received second basis set used by the intermediary device to transmit said symbol of the second secret symbol string; generating a first common set of sifted symbols based on discarding each symbol in the first received set of secret symbols in which the corresponding basis in the first matching basis set is different to the corresponding basis in the received second matching basis set, wherein the second device generates a second common set of sifted symbols based on discarding each symbol in the other set of secret symbols in which the corresponding basis in the received first matching basis set is different to the corresponding basis in the second matching basis set; and forming a cryptographic key based on the first common set of sifted symbols, wherein the second device forms the cryptographic key based on the second common set of sifted symbols.

Preferably, the method further comprising performing error detection and/or correction with the second device on the first and second common sets of sifted symbols.

In a third aspect, the present disclosure provides a computer-implemented method of quantum key distribution between a first device and a second device, the method, performed by the second device, comprising: receiving, from an intermediary device, over a quantum channel a second secret symbol string, wherein the intermediary device modulated each symbol of the second secret symbol string using a basis state of a basis selected at random from a set of bases; demodulating the received second secret symbol string, where each received second secret symbol is demodulated using a basis state of a basis selected at random from the set of bases; receiving data representative of the randomly selected bases used to modulate each symbol of the second secret symbol string by the intermediary device; determining a second set of secret symbols from the received second secret symbol string that are validly received based on comparing the randomly selected bases used to demodulate the second secret symbol string and the received randomly selected bases used to modulate the second secret symbol string; receiving, from the intermediary device, data representative of a third symbol string, the third symbol string generated by the intermediary device based on a combination of, at least in part, the second secret symbol string and a first secret symbol string, the first secret symbol string sent from the intermediary device to the first device over another quantum channel; determining a fourth set of secret symbols based on combining, at least in part, the received third symbol string with the received second set of secret symbols; and performing sifting with the first device using the fourth set of secret symbols and another set of secret symbols determined by the first device for generating a common sifted set of symbols for forming a cryptographic key, wherein the other set of secret symbols are associated with the first secret symbol string that is determined to be validly received by the first device.

Preferably, the method further comprising transmitting, to the intermediary device, over the second communication channel, data representative of the symbol positions of the symbols in the second secret symbol string that were successfully received over the quantum channel.

Preferably, the method further comprising, prior to receiving the second basis set, performing said transmitting from the second device to the intermediary device over the second communication channel data representative of the symbol positions of the symbols in the second secret symbol string successfully received by the second device over the quantum communication channel.

Preferably, the method further comprising the first device and second device performing a quantum key exchange based on: forming a second received set of secret symbols based on the received second basis set and the symbols that were successfully received from the second secret symbol string transmitted by the intermediary device over the second quantum channel, wherein each symbol of the second received set of secret symbols is a symbol of the second secret symbol string that was successfully received by the second device in which the basis used for receiving said symbol matches the corresponding basis in the received second basis set used to transmit said symbol; and the second device generates the fourth set of symbols based on combining the second received set of secret symbols with the received third symbol string, wherein one or more symbols of the fourth set of symbols correspond to one or more symbols of the first set of symbols; and wherein the first device forms the first received set of secret symbols based on a received first basis set and the symbols that were successfully received from the first secret symbol string transmitted by the intermediary device over the other quantum communication channel to the first device, wherein each symbol of the first received set of secret symbols is a symbol of the first secret symbol string that was successfully received by the first device in which the basis used for receiving said symbol matches the corresponding basis in the received first basis set used to transmit said symbol; performing symbol sifting operations with the first device over the third communication channel based on the first received set of secret symbols at the first device and the fourth set of symbols at the second device for generating a common set of sifted symbols for forming a cryptographic key at the first and second devices.

Preferably, the combination of the second secret symbol string and the first secret symbol string comprises generating the third symbol string using an XOR operation on data representative of the second secret symbol string and the first secret symbol string.

Preferably, generating the third symbol string by the intermediary device further comprises one or more from the group of: generating the third symbol string based on performing an XOR operation using data representative of, at least in part, the first secret symbol string and the second secret symbol string; generating the third symbol string based on performing one time pad encryption operation(s) using data representative of, at least in part, the first secret symbol string and the second secret symbol string; and generating the third symbol string based on performing any other type of operation for obfuscating one or more symbols of the first secret symbol string using the second secret symbol string.

Preferably, generating the fourth symbol string further comprises one or more from the group of: generating the fourth symbol string based on performing an XOR operation using data representative of, at least in part, the received second secret symbol string and the received third symbol string; generating the fourth symbol string based on performing one time pad decryption operation(s) using data representative, of at least in part, the received second secret symbol string and the received third secret symbol string; and generating the fourth symbol string based on performing any other type of operation for extracting one or more symbols of the first secret symbol string using data representative of, at least in part, the received second secret symbol string and the received third symbol string.

Preferably, performing the symbol sifting operations with the first device over the third communication channel further comprising: the first device forming a first matching basis set based on a first received set of secret symbols, wherein the first matching basis set includes all the basis states the first device used to receive the symbols of the first received set of secret symbols that match the corresponding basis states of the received first basis set used by the intermediary device to transmit said symbol of the first secret symbol string; and receiving at the second device over the third communication channel data representative of the first matching basis set; transmitting to the first device over the third communication channel data representative of a second matching basis set, wherein the second device forms the second matching basis set based on the second received set of secret symbols, wherein the second matching basis set includes all the basis states the second device used to receive the symbols of the second received set of secret symbols that match the corresponding basis states of the received second basis set used by the intermediary device to transmit said symbol of the second secret symbol string; generating a second common set of sifted symbols based on discarding each symbol in the fourth set of secret symbols in which the corresponding basis in the received first matching basis set is different to the corresponding basis in the second matching basis set, wherein the first device generates a first common set of sifted symbols based on discarding each symbol in the first received set of secret symbols in which the corresponding basis in the first matching basis set is different to the corresponding basis in the received second matching basis set; and forming a cryptographic key based on the first common set of sifted symbols, wherein the second device forms the cryptographic key based on the second common set of sifted symbols.

Preferably, performing error detection and/or correction with the second device on the first and second common sets of sifted symbols.

In a fourth aspect, the present disclosure provides a computer-implemented method of quantum key distribution between a first device and a second device, the method comprising: transmitting, by an intermediary device, a first secret symbol string over a first quantum channel to the first device, each symbol of the first secret symbol string modulated by a basis state randomly selected from a set of bases; transmitting, by the intermediary device, a first basis set over a first communication channel to the first device, the first basis set comprising data representative of the randomly selected bases used to modulate each symbol of the first secret symbol string; transmitting, by the intermediary device, a second secret symbol string over a second quantum channel to the second device, each symbol of the second secret symbol string modulated by a basis state randomly selected from the set of bases; transmitting, by the intermediary device, a second basis set over a second communication channel to the second device, the second basis set comprising data representative of the randomly selected bases used to modulate each symbol of the second secret symbol string; generating, by the intermediary device, a third symbol string based on combining the first and second secret symbol strings; transmitting, by the intermediary device, to the second device, via the second communication channel, data representative of the third symbol string; determining, by the first device, a first received set of secret symbols using the received first basis set, the first received set of secret symbols comprising symbols of the first secret symbol string transmitted over the first quantum channel that were successfully received by the first device; determining, by the second device, a second received set of secret symbols using the received second basis set, the second received set of secret symbols comprising symbols of the second secret symbol string transmitted over the second quantum channel that were successfully received by the second device; generating, by the second device, a fourth set of symbols based on combining the second received set of secret symbols with the received third symbol string, wherein one or more symbols of the fourth set of symbols correspond to one or more symbols of the first symbol string; performing, by the first device and second device, symbol sifting operations over a third communication channel the based on the first received set of secret symbols at the first device and the fourth set of symbols at the second device for generating a common set of sifted symbols for forming a cryptographic key at the first and second devices.

Preferably, the method further comprising: transmitting, by the first device, over the first communication channel to the intermediary device data representative of the symbol positions of the symbols in the first secret symbol string transmitted by the intermediary device over the first quantum communication channel that were successfully received by the first device; generating, at the intermediary device, a first set of symbols based on those symbols of the first secret symbol string that correspond to the data representative of the symbol positions of symbols from the first secret symbol string successfully received by the first device; transmitting, by the second device, over the second communication channel to the intermediary device data representative of the symbol positions of the symbols in the second secret symbol string transmitted by the intermediary device over the second quantum communication channel that were successfully received by the second device; generating, at the intermediary device, a second set of symbols based on those symbols of the second secret symbol string that correspond to the received data representative of the symbol positions of symbols from the second secret symbol string successfully received by the second device; and said generating, by the intermediary device, the third symbol string further comprising generating, by the intermediary device, the third symbol string based on combining the first set of symbols and second set of symbols.

Preferably, the method further comprising: prior to transmitting the randomly selected bases to the first device, performing said receiving from the first device, over the first communication channel, data representative of the symbol positions of the symbols in the first secret symbol string transmitted over the first quantum communication channel that were successfully received by the first device; and prior to transmitting the randomly selected bases to the second device, performing said receiving from the second device, over the second communication channel, data representative of the symbol positions of the symbols in the second secret symbol string transmitted over the second quantum communication channel that were successfully received by the second device.

Preferably, the method further comprising the first device and second device performing a quantum key exchange by: determining, by the first device, a first received set of secret symbols based on the received first basis set and the symbols that were successfully received from the first secret symbol string transmitted over the first quantum communication channel, wherein each symbol of the first received set of secret symbols is a symbol of the first secret symbol string that was successfully received by the first device in which the basis used for receiving said symbol matches the corresponding basis in the received first basis set used to transmit said symbol; determining, by the second device, a second received set of secret symbols based on the received second basis set and the symbols that were successfully received from the second secret symbol string transmitted over the second quantum communication channel, wherein each symbol of the second received set of secret symbols is a symbol of the second secret symbol string that was successfully received by the second device in which the basis used for receiving said symbol matches the corresponding basis in the received second basis set used to transmit said symbol; generating, by the second device, the fourth set of symbols based combining the second received set of secret symbols with the received third symbol string, wherein one or more symbols of the fourth set of symbols correspond to one or more symbols of the first set of symbols; performing sifting operations between the first device and second device over the third communication channel based on the first received set of secret symbols at the first device and the fourth set of symbols at the second device for generating a common set of sifted symbols for forming a cryptographic key at the first and second devices.

Preferably, said generating the third symbol string further comprising: in response to determining the length of the first set of symbols is less than the length of the second set of symbols: truncating the second set of symbols to the length of the first set of symbols; and generating the third symbol string based on combining the first set of symbols with the truncated second set of symbols; and in response to determining the length of the second set of symbols is less than the length of the first set of symbols: truncating the first set of symbols to the length of the second set of symbols; and generating the third symbol string based on combining the truncated first set of symbols with the second set of symbols.

Preferably, said generating the third symbol string further comprising: in response to determining the length of the first set of symbols is less than the length of the second set of symbols: adjusting the second set of symbols by removing an agreed set of symbols from the second set of symbols until the adjusted length of the adjusted second set of symbols is the same as the first set of symbols; and generating the third symbol string based on combining the first set of symbols with the adjusted second set of symbols; and in response to determining the length of the second set of symbols is less than the length of the first set of symbols: adjusting the first set of symbols by removing an agreed set of symbols from the first set of symbols until the adjusted length of the adjusted first set of symbols is the same as the second set of symbols; and generating the third symbol string based on combining the adjusted first set of symbols with the second set of symbols.

Preferably, generating the third symbol string further comprises one or more from the group of: generating the third symbol string based on performing an XOR operation using data representative of a first set of symbols and a second set of symbols, the first set of symbols based on converting each of the symbols in the first set of symbols to a string of symbols and the second set of symbols based on converting each of the symbols in the second set of symbols to a string of symbols; generating the third symbol string based on performing one time pad encryption operation(s) using data representative of, at least in part, the first set of symbols and the second set of symbols; and generating the third symbol string based on performing any other type of operation for obfuscating one or more symbols of the first set of symbols using the second set of symbols.

Preferably, the second device generating the fourth symbol string further comprises one or more from the group of: generating the fourth symbol string based on performing an XOR operation using the second received set of secret symbols and the received third symbol string; generating the fourth symbol string based on performing one time pad decryption operation(s) using the received second set of secret symbols and the third secret symbol string; and generating the fourth symbol string based on performing any other type of operation for extracting one or more symbols of the first secret symbol string using the second received set of secret symbols and the third symbol string.

Preferably, generating the third symbol string further comprises one or more from the group of: generating the third symbol string based on performing an XOR operation using data representative of, at least in part, the first secret symbol string and the second secret symbol string; generating the third symbol string based on performing one time pad encryption operation(s) using data representative of, at least in part, the first secret symbol string and the second secret symbol string; and generating the third symbol string based on performing any other type of operation for obfuscating one or more symbols of the first secret symbol string using the second secret symbol string.

Preferably, the second device generating the fourth symbol string further comprises one or more from the group of: generating the fourth symbol string based on performing an XOR operation using data representative of, at least in part, the second secret symbol string and the third symbol string; generating the fourth symbol string based on performing one time pad decryption operation(s) using data representative, of at least in part, the second secret symbol string and the third secret symbol string; and generating the fourth symbol string based on performing any other type of operation for extracting one or more symbols of the first secret symbol string using data representative of, at least in part, the second secret symbol string and the third symbol string.

Preferably, the first device and second device performing symbol sifting operations over the third communication channel therebetween based on: the first device forms a first matching basis set based on the first received set of secret symbols, wherein the first matching basis set includes all the basis states the first device used to receive the symbols of the first received set of secret symbols that match the corresponding basis states of the received first basis set used to transmit said symbol of the first set of symbols; and the first device sends over the third communication channel data representative of the first matching basis set to the second device; the second device forms a second matching basis set based on the second received set of secret symbols, wherein the second matching basis set includes all the basis states the second device used to receive the symbols of the second received set of secret symbols that match the corresponding basis states of the received second basis set used to transmit said symbol of the second set of symbols; the second device sends over the third communication channel data representative of the second matching basis set to the first device; the first device generates a first common set of sifted symbols based on discarding each symbol in the first received set of secret symbols in which the corresponding basis in the first matching basis set is different to the corresponding basis in the received second matching basis set; the second device generates a second common set of sifted symbols based on discarding each symbol in the fourth set of secret symbols in which the corresponding basis in the received first matching basis set is different to the corresponding basis in the second matching basis set; and the first and second devices forming a cryptographic key based on the first and second common set of sifted symbols, respectively.

Preferably, the first device and second device performing symbol sifting operations over the third communication channel therebetween based on: generating, by the first device, a first basis flag set based on the first received set of secret symbols and the received first basis set, wherein the first basis flag set includes an indication of each valid and invalid symbol of the first received set of secret symbols based on comparing the received first basis set with the basis set used by the first device to demodulate the symbols associated with the first received set of secret symbols; and sending, from the first device over the third communication channel, data representative of the first basis flag set to the second device; generating, by the second device, a second basis flag set based on the second received set of secret symbols and the received second basis set, wherein the second basis flag set includes an indication of each valid and invalid symbol of the second received set of secret symbols based on comparing the received second basis set with the basis set used by the second device to demodulate the symbols associated with the second received set of secret symbols; sending, from the second device over the third communication channel, data representative of the second basis flag set to the first device; generating, by the first device, a first common set of sifted symbols based on discarding each symbol in the first received set of secret symbols in which the corresponding indication in the first basis flag set is different to the corresponding indication in the received second basis flag set; generating, by the second device, a second common set of sifted symbols based on discarding each symbol in the fourth set of secret symbols in which the corresponding indication in the second basis flag set is different to the corresponding indication in the received first basis flag set; performing error detection and correction between the first and second common sets of sifted symbols to generate a common set of sifted symbols; and generating a cryptographic key at the first and second devices based on the common set of sifted symbols.

Preferably, each symbol represents 2 n binary bits, for n>1.

Preferably, each symbol represents a binary bit for n=1.

Preferably, the method of the first, second, third or fourth aspects further comprising generating a first secret symbol string by randomly selecting a symbols using a random number generator.

Preferably, the method of the first, second, third or fourth aspects further comprising generating a second secret symbol string by randomly selecting symbols using a random number generator.

Preferably, the random number generator is based on one or more from the group of: a cryptographic random number generator; a quantum qubit random number generator; or any suitable random number generator.

Preferably, the set of bases comprises at least two bases, each basis comprising at least two basis states, wherein the at least two basis states of each basis are orthogonal and the at least two basis states of said each basis are non-orthogonal to the at least two basis states of another basis of the set of bases.

Preferably, the set of bases comprises two bases and each basis of the set of bases comprises two basis states.

Preferably, the set of bases for modulating symbols for transmission over the first or second quantum channel comprises at least two bases from the group of: a rectilinear basis; a diagonal basis; a spherical basis; a circular basis; and/or any other type of basis comprising at least two basis states.

Preferably, the first and second quantum channels are optical quantum channels and the set of bases comprises at least two bases from the group of: a rectilinear photon polarisation basis; a diagonal photon polarisation basis; a spherical photon polarisation basis; a circular photon polarisation basis; and any other type of photon basis comprising two basis states.

Preferably, the first communication channel is based on a classical communication channel formed between the intermediary device and the first device.

Preferably, the method of the first, second, third or fourth aspects, the second communication channel is based on a classical communication channel formed between the intermediary device and the second device.

Preferably, the classical communication channel is based on one or more types of communication channels from the group of: optical communication channel; free-space optical communication channel; wireless communication channel; wired communication channel; radio communication channel; microwave communication channel; satellite communication channel; terrestrial communication channel; optical fibre communication channel; optical laser communication channel; any other type of one or more optical, wireless and/or wired communication channel(s) for transmitting data between devices; and two or

CLAIMS

Claims ( 20 )

The invention claimed is:

1. A computer-implemented method of quantum key distribution between a first device and a second device, the method, performed by an intermediary device, comprising:

transmitting a first secret symbol string over a first quantum channel to the first device, each symbol of the first secret symbol string modulated by a basis state randomly selected from a set of bases;

transmitting a first basis set over a first communication channel to the first device, the first basis set comprising data representative of the randomly selected bases used to modulate each symbol of the first secret symbol string;

transmitting a second secret symbol string over a second quantum channel to the second device, each symbol of the second secret symbol string modulated by a basis state randomly selected from the set of bases;

transmitting a second basis set over a second communication channel to the second device, the second basis set comprising data representative of the randomly selected bases used to modulate each symbol of the second secret symbol string;

generating a third symbol string based on combining the first and second secret symbol strings;

transmitting to the second device, via the second communication channel, data representative of the third symbol string;

wherein the first device and second device perform a quantum key exchange based on:

the first device using the received first basis set to determine a first received set of secret symbols comprising symbols of the first secret symbol string transmitted over the first quantum channel that were successfully received by the first device;

the second device uses the received second basis set to determine a second received set of secret symbols comprising symbols of the second secret symbol string transmitted over the second quantum channel that were successfully received by the second device;

the second device generates a fourth set of symbols based on combining the second received set of secret symbols with the received third symbol string, wherein one or more symbols of the fourth set of symbols correspond to one or more symbols of the first symbol string;

the first device and second device performing symbol sifting operations over a third communication channel between the based on the first received set of secret symbols at the first device and the fourth set of symbols at the second device for generating a common set of sifted symbols for forming a cryptographic key at the first and second devices.

2. The computer-implemented method according to claim 1 , further comprising:

receiving from the first device, over the first communication channel, data representative of the symbol positions of the symbols in the first secret symbol string transmitted over the first quantum communication channel that were successfully received by the first device;

generating a first set of symbols based on those symbols of the first secret symbol string that correspond to the received data representative of the symbol positions of symbols from the first secret symbol string successfully received by the first device;

receiving from the second device, over the second communication channel, data representative of the symbol positions of the symbols in the second secret symbol string transmitted over the second quantum communication channel that were successfully received by the second device;

generating a second set of symbols based on those symbols of the second secret symbol string that correspond to the received data representative of the symbol positions of symbols from the second secret symbol string successfully received by the second device; and

said generating the third symbol string further comprising generating the third symbol string based on combining the first set of symbols and second set of symbols.

3. The computer-implemented method according to claim 2 , wherein said generating the third symbol string further comprising:

in response to determining the length of the first set of symbols is less than the length of the second set of symbols:

truncating the second set of symbols to the length of the first set of symbols; and

generating the third symbol string based on combining the first set of symbols with the truncated second set of symbols;

in response to determining the length of the second set of symbols is less than the length of the first set of symbols:

truncating the first set of symbols to the length of the second set of symbols; and

generating the third symbol string based on combining the truncated first set of symbols with the second set of symbols.

4. The computer-implemented method according to claim 2 , wherein said generating the third symbol string further comprising:

in response to determining the length of the first set of symbols is less than the length of the second set of symbols:

adjusting the second set of symbols by removing an agreed set of symbols from the second set of symbols until the adjusted length of the adjusted second set of symbols is the same as the first set of symbols; and

generating the third symbol string based on combining the first set of symbols with the adjusted second set of symbols;

in response to determining the length of the second set of symbols is less than the length of the first set of symbols:

adjusting the first set of symbols by removing an agreed set of symbols from the first set of symbols until the adjusted length of the adjusted first set of symbols is the same as the second set of symbols; and

generating the third symbol string based on combining the adjusted first set of symbols with the second set of symbols.

5. The computer-implemented method according to claim 2 , wherein generating the third symbol string further comprises one or more from the group of:

generating the third symbol string based on performing an XOR operation using data representative of a first set of bits and a second set of bits, the first set of bits based on converting each of the symbols in the first set of symbols to a string of bits and the second set of bits based on converting each of the symbols in the second set of symbols to a string of bits;

generating the third bit string based on performing one time pad encryption operation(s) using data representative of, at least in part, the first set of symbols and the second set of symbols; and

generating the third symbol string based on performing any other type of operation for obfuscating one or more symbols of the first set of symbols using the second set of symbols.

6. The computer-implemented method according to claim 2 , wherein the second device generating the fourth symbol string further comprises one or more from the group of:

generating the fourth symbol string based on performing an XOR operation using the second received set of secret symbols and the received third symbol string;

generating the fourth symbol string based on performing one time pad decryption operation(s) using the received second set of secret symbols and the third secret symbol string; and

generating the fourth symbol string based on performing any other type of operation for extracting one or more symbols of the first secret symbol string using the second received set of secret symbols and the third symbol string.

7. The computer-implemented method according to claim 1 , the method further comprising, prior to transmitting the randomly selected bases to the first device, performing said receiving from the first device, over the first communication channel, data representative of the symbol positions of the symbols in the first secret symbol string transmitted over the first quantum communication channel that were successfully received by the first device.

8. The computer-implemented method according to claim 1 , the method further comprising, prior to transmitting the randomly selected bases to the second device, performing said receiving from the second device, over the second communication channel, data representative of the symbol positions of the symbols in the second secret symbol string transmitted over the second quantum communication channel that were successfully received by the second device.

9. The computer-implemented method according to claim 1 , the method further comprising the first device and second device performing a quantum key exchange based on:

the first device forms the first received set of secret symbols based on the received first basis set and the symbols that were successfully received from the first secret symbol string transmitted over the first quantum communication channel, wherein each symbol of the first received set of secret symbols is a symbol of the first secret symbol string that was successfully received by the first device in which the basis used for receiving said symbol matches the corresponding basis in the received first basis set used to transmit said symbol;

the second device forms the second received set of secret symbols based on the received second basis set and the symbols that were successfully received from the second secret symbol string transmitted over the second quantum communication channel, wherein each symbol of the second received set of secret symbols is a symbol of the second secret symbol string that was successfully received by the second device in which the basis used for receiving said symbol matches the corresponding basis in the received second basis set used to transmit said symbol;

the second device generates the fourth set of symbols based combining the second received set of secret symbols with the received third symbol string, wherein one or more symbols of the fourth set of symbols correspond to one or more symbols of the first set of symbols;

the first device and second device performing symbol sifting operations over the third communication channel therebetween based on the first received set of secret symbols at the first device and the fourth set of symbols at the second device for generating a common set of sifted symbols for forming a cryptographic key at the first and second devices.

10. The computer-implemented method according to claim 1 , wherein generating the third symbol string further comprises one or more from the group of:

generating the third symbol string based on performing an XOR operation using data representative of, at least in part, the first secret symbol string and the second secret symbol string;

generating the third symbol string based on performing one time pad encryption operation(s) using data representative of, at least in part, the first secret symbol string and the second secret symbol string; and

generating the third symbol string based on performing any other type of operation for obfuscating one or more symbols of the first secret symbol string using the second secret symbol string.

11. The computer-implemented method according to claim 1 , wherein the second device generating the fourth symbol string further comprises one or more from the group of:

generating the fourth symbol string based on performing an XOR operation using data representative of, at least in part, the second secret symbol string and the third symbol string;

generating the fourth symbol string based on performing one time pad decryption operation(s) using data representative, of at least in part, the second secret symbol string and the third secret symbol string; and

generating the fourth symbol string based on performing any other type of operation for extracting one or more symbols of the first secret symbol string using data representative of, at least in part, the second secret symbol string and the third symbol string.

12. The computer-implemented method according to claim 1 , wherein the first device and second device performing symbol sifting operations over the third communication channel therebetween based on:

the first device forms a first matching basis set based on the first received set of secret symbols, wherein the first matching basis set includes all the basis states the first device used to receive the symbols of the first received set of secret symbols that match the corresponding basis states of the received first basis set used to transmit said symbol of the first set of symbols; and

the first device sends over the third communication channel data representative of the first matching basis set to the second device;

the second device forms a second matching basis set based on the second received set of secret symbols, wherein the second matching basis set includes all the basis states the second device used to receive the symbols of the second received set of secret symbols that match the corresponding basis states of the received second basis set used to transmit said symbol of the second set of symbols;

the second device sends over the third communication channel data representative of the second matching basis set to the first device;

the first device generates a first common set of sifted symbols based on discarding each symbol in the first received set of secret symbols in which the corresponding basis in the first matching basis set is different to the corresponding basis in the received second matching basis set;

the second device generates a second common set of sifted symbols based on discarding each symbol in the fourth set of symbols in which the corresponding basis in the received first matching basis set is different to the corresponding basis in the second matching basis set; and

the first and second devices forming a cryptographic key based on the first and second common set of sifted symbols, respectively.

13. The computer-implemented method according to claim 12 , wherein the first and second device perform error detection and/or correction on the first and second common sets of sifted bits.

14. The computer-implemented method according to claim 1 , further comprising generating a first secret symbol string and/or a second secret symbol string by randomly selecting a symbols using a random number generator.

15. The computer-implemented method according to claim 1 , wherein the set of bases comprises at least two bases, each basis comprising at least two basis states, wherein the at least two basis states of each basis are orthogonal and the at least two basis states of said each basis are non-orthogonal to the at least two basis states of another basis of the set of bases.

16. The computer-implemented method according to claim 1 , wherein the first and/or second communication channel is based on a classical communication channel formed between the intermediary device and the first device.

17. The computer-implemented method according to claim 1 , wherein the first and second communications channels are encrypted communication channels.

18. A computer-implemented method of quantum key distribution between a first device and a second device, the method, performed by the first device, comprising:

receiving, from an intermediary device, over a quantum channel a first secret symbol string, wherein the intermediary device modulated each symbol of the first secret symbol string using a basis state of a basis selected at random from a set of bases for transmission over the quantum channel;

demodulating the received first secret symbol string, where each received first secret symbol is demodulated using a basis state of a basis selected at random from the set of bases;

receiving, from the intermediary device, data representative of a first basis set over a first communication channel, the first basis set comprising data representative of the randomly selected bases used by the intermediary device to modulate each symbol of the first secret symbol string;

determining a first received set of secret symbols from the received first secret symbol string that are successfully received using the received first basis set;

performing sifting operation(s) with the second device using the first received set of secret symbols of the first device and another set of secret symbols determined by the second device for generating a common sifted set of symbols for forming a cryptographic key with the second device, wherein the other set of secret symbols are associated with the first received set of secret symbols; and

the second device determines the other set of secret symbols based on, at least in part, a second secret symbol string received by the second device over a second quantum channel from the intermediary device and, at least in part, a third secret symbol string received by the second device over a second communication channel from the intermediary device, wherein the third secret symbol string is based on a combination of, at least in part, the second secret symbol string and the first secret symbol string, and the second device generates the other set of secret symbols based on a combination of the received third secret symbol string and, at least in part, the second secret symbol string.

19. The computer-implemented method according to claim 18 , wherein performing the symbol sifting operations with the second device over the third communication channel further comprising:

forming a first matching basis set based on the first received set of secret symbols, wherein the first matching basis set includes all the basis states the first device used to receive the symbols of the first received set of secret symbols that match the corresponding basis states of the received first basis set used by the intermediary device to transmit said symbol of the first secret symbol string; and

transmitting to the second device over the third communication channel data representative of the first matching basis set, wherein:

receiving from the second device over the third communication channel data representative of a second matching basis set, wherein the second device forms the second matching basis set based on the second received set of secret symbols, wherein the second matching basis set includes all the basis states the second device used to receive the symbols of the second received set of secret symbols that match the corresponding basis states of the received second basis set used by the intermediary device to transmit said symbol of the second secret symbol string;

generating a first common set of sifted symbols based on discarding each symbol in the first received set of secret symbols in which the corresponding basis in the first matching basis set is different to the corresponding basis in the received second matching basis set, wherein the second device generates a second common set of sifted symbols based on discarding each symbol in the other set of secret symbols in which the corresponding basis in the received first matching basis set is different to the corresponding basis in the second matching basis set; and

forming a cryptographic key based on the first common set of sifted symbols, wherein the second device forms the cryptographic key based on the second common set of sifted symbols.

20. A computer-implemented method of quantum key distribution between a first device and a second device, the method, performed by the second device, comprising:

receiving, from an intermediary device, over a quantum channel a second secret symbol string, wherein the intermediary device modulated each symbol of the second secret symbol string using a basis state of a basis selected at random from a set of bases;

demodulating the received second secret symbol string, where each received second secret symbol is demodulated using a basis state of a basis selected at random from the set of bases;

receiving data representative of the randomly selected bases used to modulate each symbol of the second secret symbol string by the intermediary device;

determining a second set of secret symbols from the received second secret symbol string that are validly received based on comparing the randomly selected bases used to demodulate the second secret symbol string and the received randomly selected bases used to modulate the second secret symbol string;

receiving, from the intermediary device, data representative of a third symbol string, the third symbol string generated by the intermediary device based on a combination of, at least in part, the second secret symbol string and a first secret symbol string, the first secret symbol string sent from the intermediary device to the first device over another quantum channel;

determining a fourth set of secret symbols based on combining, at least in part, the received third symbol string with the received second set of secret symbols; and

performing sifting with the first device using the fourth set of secret symbols and another set of secret symbols determined by the first device for generating a common sifted set of symbols for forming a cryptographic key, wherein the other set of secret symbols are associated with the first secret symbol string that is determined to be validly received by the first device.

US17/775,210

2019-11-08

2020-11-06

Quantum key distribution protocol

Active

2041-06-05

US12021976B2

( en )

Applications Claiming Priority (4)

Application Number

Priority Date

Filing Date

Title

GB1916311

2019-11-08

GB1916311.2

2019-11-08

GB1916311.2A

GB2590064B

( en )

2019-11-08

2019-11-08

Quantum key distribution protocol

PCT/GB2020/052826

WO2021090025A1

( en )

2019-11-08

2020-11-06

Quantum key distribution protocol

Publications (2)

Publication Number

Publication Date

US20220407688A1

US20220407688A1 ( en )

2022-12-22

US12021976B2

true

US12021976B2 ( en )

2024-06-25

Family

ID=69062165

Family Applications (1)

Application Number

Title

Priority Date

Filing Date

US17/775,210

Active

2041-06-05

US12021976B2

( en )

2019-11-08

2020-11-06

Quantum key distribution protocol

Country Status (6)

Country

Link

US

( 1 )

US12021976B2

( en )

EP

( 1 )

EP4055770A1

( en )

JP

( 1 )

JP2023502349A

( en )

AU

( 1 )

AU2020381167B2

( en )

GB

( 1 )

GB2590064B

( en )

WO

( 1 )

WO2021090025A1

( en )

Families Citing this family (24)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

GB2604326B

( en )

*

2021-01-29

2023-07-12

Arqit Ltd

QKD switching system

US12483396B2

( en )

2021-01-29

2025-11-25

Arqit Limited

Key exchange protocol for satellite based quantum network

WO2022162382A1

( en )

*

2021-01-29

2022-08-04

Arqit Limited

Qkd switching system and protocols

CA3206803A1

( en )

2021-01-29

2022-08-04

Arqit Limited

Key exchange protocol for satellite based quantum network

US20240333398A1

( en )

*

2021-07-14

2024-10-03

General Electric Company

System and Method for Implementing Quantum-Secure Wireless Networks

GB2616047A

( en )

*

2022-02-25

2023-08-30

Toshiba Kk

A quantum network and a quantum authentication server

GB2618989B

( en )

2022-03-24

2025-07-16

Arqit Ltd

QKD with shifted post processing for an optical communication system

JP2023149074A

( en )

*

2022-03-30

2023-10-13

国立研究開発法人情報通信研究機構

Encryption key sharing system

GB2619272A

( en )

2022-05-23

2023-12-06

Arqit Ltd

Key distribution to a proxy server

GB2619914B

( en )

*

2022-06-14

2025-04-23

Arqit Ltd

Group key sharing

GB2631356A

( en )

*

2022-06-14

2025-01-01

Arqit Ltd

Group key sharing

GB2619913B

( en )

2022-06-14

2024-10-09

Arqit Ltd

Group key sharing

GB2619776B

( en )

*

2022-06-17

2024-06-05

Arqit Ltd

Quantum key distribution protocol

US12381722B2

( en )

*

2022-08-01

2025-08-05

Mellanox Technologies, Ltd.

Bi-directional quantum interconnects

EP4548534A4

( en )

*

2022-08-31

2025-10-22

Photonic Inc

Methods, devices and systems for securely transmitting and receiving data and for refilling advanced keys

US12132846B2

( en )

2023-03-24

2024-10-29

Symmera Inc.

System and method for extended attributes in certificates for dynamic authorization

US12476793B2

( en )

2023-03-24

2025-11-18

Symmera Inc.

System and method to securely distribute authenticated and trusted data streams to AI systems

US11968302B1

( en )

2023-03-24

2024-04-23

Srinivas Kumar

Method and system for pre-shared key (PSK) based secure communications with domain name system (DNS) authenticator

US12015721B1

( en )

2023-03-24

2024-06-18

Srinivas Kumar

System and method for dynamic retrieval of certificates with remote lifecycle management

DE102023131881A1

( en )

2023-11-15

2025-05-15

Jonathan Rogers

ENCRYPTOR, DECRYPTOR, COMMUNICATION SYSTEM, METHOD, COMMUNICATION METHOD

FR3157741B1

( en )

*

2023-12-21

2025-12-26

Thales Sa

Centralized method for pairing quantum cryptographic keys via satellite

US12567972B2

( en )

*

2024-01-24

2026-03-03

Cisco Technology, Inc.

Messaging layer security (MLS) protocol-based secure channels

US12519627B2

( en )

2024-02-22

2026-01-06

Wells Fargo Bank, N.A.

Key establishment and secure communications using satellite-provided random number values

US12621134B2

( en )

2024-02-22

2026-05-05

Wells Fargo Bank, N.A.

Key establishment and secure communications based on satellite entropy sources

Citations (5)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US20040184603A1

( en )

*

2003-03-21

2004-09-23

Pearson David Spencer

Systems and methods for quantum cryptographic key transport

US8650401B2

( en )

*

2008-01-25

2014-02-11

Qinetiq Limited

Network having quantum key distribution

US8855316B2

( en )

*

2008-01-25

2014-10-07

Qinetiq Limited

Quantum cryptography apparatus

US9887976B2

( en )

*

2012-08-30

2018-02-06

Los Alamos National Security, Llc

Multi-factor authentication using quantum communication

WO2019115984A1

( en )

2017-12-13

2019-06-20

Arqit Limited

Quantum protection of telemetry tracking and command links

Family Cites Families (2)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

JP2007189517A

( en )

*

2006-01-13

2007-07-26

Nec Corp

Quantum cryptography device

KR101830339B1

( en )

*

2016-05-20

2018-03-29

한국전자통신연구원

Apparatus for quantum key distribution on a quantum network and method using the same

2019

2019-11-08

GB

GB1916311.2A

patent/GB2590064B/en

active

Active

2020

2020-11-06

EP

EP20804655.7A

patent/EP4055770A1/en

active

Pending

2020-11-06

JP

JP2022527063A

patent/JP2023502349A/en

active

Pending

2020-11-06

WO

PCT/GB2020/052826

patent/WO2021090025A1/en

not_active

Ceased

2020-11-06

US

US17/775,210

patent/US12021976B2/en

active

Active

2020-11-06

AU

AU2020381167A

patent/AU2020381167B2/en

active

Active

Patent Citations (5)

* Cited by examiner, † Cited by third party

Publication number

Priority date

Publication date

Assignee

Title

US20040184603A1

( en )

*

2003-03-21

2004-09-23

Pearson David Spencer

Systems and methods for quantum cryptographic key transport

US8650401B2

( en )

*

2008-01-25

2014-02-11

Qinetiq Limited

Network having quantum key distribution

US8855316B2

( en )

*

2008-01-25

2014-10-07

Qinetiq Limited

Quantum cryptography apparatus

US9887976B2

( en )

*

2012-08-30

2018-02-06

Los Alamos National Security, Llc

Multi-factor authentication using quantum communication

WO2019115984A1

( en )

2017-12-13

2019-06-20

Arqit Limited

Quantum protection of telemetry tracking and command links

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party

Title

Examination Report of Canadian Patent Application No. 3,157,137, dated Aug. 31, 2023.

Hughes, et al., Quantum computing: the final frontier, IEEE Intelligent Systems, IEEE Service Center, New York, NY, US, vol. 15, No. 5, Sep. 1, 2000, pp. 10-18.

Also Published As

Publication number

Publication date

GB201916311D0

( en )

2019-12-25

GB2590064A

( en )

2021-06-23

JP2023502349A

( en )

2023-01-24

WO2021090025A1

( en )

2021-05-14

AU2020381167A1

( en )

2022-06-02

CA3157137A1

( en )

2021-05-14

AU2020381167B2

( en )

2026-02-05

EP4055770A1

( en )

2022-09-14

GB2590064B

( en )

2022-02-23

US20220407688A1

( en )

2022-12-22

Similar Documents

Publication

Publication Date

Title

AU2020381167B2

( en )

2026-02-05

Quantum key distribution protocol

US12519629B2

( en )

2026-01-06

Key exchange protocol for satellite based quantum network

US12483396B2

( en )

2025-11-25

Key exchange protocol for satellite based quantum network

US7577257B2

( en )

2009-08-18

Large scale quantum cryptographic key distribution network

JP4829788B2

( en )

2011-12-07

Quantum cryptography with quantum channel check

US20200313879A1

( en )

2020-10-01

Apparatus and method for quantum direct communication using single qubits

US20240048371A1

( en )

2024-02-08

Secure relay-based quantum communication method and communication network

GB2604664A

( en )

2022-09-14

Improved key exchange using a quantum key distribution protocol

US20160248586A1

( en )

2016-08-25

Streaming authentication and multi-level security for communications networks using quantum cryptography

US20250023720A1

( en )

2025-01-16

Quantum key generation method and system

US20210351936A1

( en )

2021-11-11

Qds-based mail system and transceiving method

US12609820B2

( en )

2026-04-21

System and method for generating a secure secret key

CN112564918B

( en )

2022-08-12

A Lightweight Active Cross-Layer Authentication Approach in Smart Grid

WO2023242550A1

( en )

2023-12-21

Group key sharing

CA3157137C

( en )

2025-08-12

Quantum key distribution protocol

US20260046120A1

( en )

2026-02-12

Quantum distribution methods and associated telecommunication devices

US20250365140A1

( en )

2025-11-27

Quantum key distribution protocol

US20250358105A1

( en )

2025-11-20

Group key sharing

US20250038970A1

( en )

2025-01-30

Quantum key distribution (qkd) method, qkd end-node and qkd network

Roediger et al.

2015

Quantum cryptography over the FSO channel with PPM and FSK modulations

Legal Events

Date

Code

Title

Description

2022-09-26

STPP

Information on status: patent application and granting procedure in general

Free format text : DOCKETED NEW CASE - READY FOR EXAMINATION

2024-02-21

STPP

Information on status: patent application and granting procedure in general

Free format text : NOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONS

2024-05-23

STPP

Information on status: patent application and granting procedure in general

Free format text : PUBLICATIONS -- ISSUE FEE PAYMENT VERIFIED

2024-06-05

STCF

Information on status: patent grant

Free format text : PATENTED CASE

Related documents

Record · ID 607399
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.