Secure communication for connected systems using post quantum cryptography

The problem of secure communication in aviation communications is solved through cloud-based quantum service computing entities and edge computing systems. Through cloud-based quantum service computing entities and quantum edge computing entities, post-quantum key generation, storage and distribution are used to solve the communication security risks that have not been solved in existing technologies, enhance the secure communication of the communication system, and enhance the security and reliability of the communication system.

CN120785565APending Publication Date: 2025-10-14HONEYWELL INTERNATIONAL INC
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510383559.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-04-04
Filing Date
2025-03-28
Publication Date
2025-10-14

AI Technical Summary

Technical Problem

Existing aviation communication systems lack physical authentication and are vulnerable to quantum computing threats, leading to data leakage, unauthorized control and communication interruptions, especially in communications between aircraft and ground systems.

Method used

Cloud-based quantum service computing entities and quantum edge computing entities are used to provide secure encryption for aviation communication systems through post-quantum cryptographic keys, and quantum key generation, storage and distribution are used to establish secure communication channels and enhance authentication and authorization mechanisms.

Benefits of technology

It achieves secure and reliable communication between the aircraft and the ground system, prevents data leakage and unauthorized access, ensures the integrity and security of communication, prevents data transmission and secure communication of the communication system, and enhances the security and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785565A_ABST
    Figure CN120785565A_ABST
Patent Text Reader

Abstract

The invention relates to secure communication of connected systems using post quantum cryptography. Embodiments of the present disclosure provide techniques for providing secure communications for connected systems. The technique may include receiving a communication session indication associated with a first connected system; authenticating the first connection system based on an IAM policy; encrypting a message based on a post quantum cryptography public key associated with the first connection system to generate an encrypted message; and causing the encrypted message to be transmitted to the second connection system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to systems, apparatuses, methods, and computer program products for secure communications using post-quantum cryptography. Example embodiments relate to systems, apparatuses, methods, and computer program products for establishing secure communications for connected systems. Background Art

[0002] Various embodiments of the present disclosure address technical challenges associated with secure communication of connected systems. Through dedication, ingenuity, and innovation, applicants have addressed the problems associated with secure communication of connected systems by developing the solutions embodied in the present disclosure, which are described in detail below. Summary of the Invention

[0003] In general, embodiments of the present disclosure provide methods, apparatuses, systems, computing devices, and / or computing entities, among others, for providing secure communications for connected aircraft systems using post-quantum cryptography. Additional implementations for secure communications using post-quantum cryptography will be or will become apparent to one skilled in the art upon examination of the following figures and detailed description. All such additional implementations included within this specification are intended to be within the scope of this disclosure and protected by the following claims.

[0004] According to one aspect of the present disclosure, a computer-implemented method for providing secure communications for connected systems is provided. In an example embodiment, the computer-implemented method includes: receiving an indication of a communication session associated with a first connected system; authenticating the first connected system based on an IAM policy; encrypting a message based on a post-quantum cryptography public key associated with the first connected system to generate an encrypted message; and causing the encrypted message to be sent to a second connected system.

[0005] According to another aspect of the present disclosure, a computing system for providing secure communications for connected systems is provided. In an exemplary embodiment, the computing system includes a memory and one or more processors communicatively coupled to the memory, the one or more processors being configured to: receive an indication of a communication session associated with a first connected system; authenticate the first connected system based on an IAM policy; encrypt a message based on a post-quantum cryptography public key associated with the first connected system to generate an encrypted message; and cause the encrypted message to be sent to a second connected system.

[0006] According to another aspect of the present disclosure, one or more non-transitory computer-readable storage media for providing secure communications for connected systems are provided. In some embodiments, the one or more non-transitory computer-readable storage media include instructions that, when executed by one or more processors, cause the one or more processors to: receive an indication of a communication session associated with a first connected system; authenticate the first connected system based on an IAM policy; encrypt a message based on a post-quantum cryptography public key associated with the first connected system to generate an encrypted message; and cause the encrypted message to be sent to a second connected system.

[0007] It should be understood that any and / or all aspects and / or operations of the example computer-implemented methods described herein may be combined with any other aspects and / or operations of any other example computer-implemented methods described herein. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] Having thus generally described embodiments of the present disclosure, reference will now be made to the accompanying drawings, which are not necessarily drawn to scale, and in which:

[0009] Figure 1A An example overview of the architecture according to some embodiments of the present disclosure is provided.

[0010] Figure 1B An example connectivity ecosystem is provided in which at least some embodiments of the present disclosure may operate.

[0011] Figure 1C Provided for Figure 1B Example secure communication process flow for an example connected ecosystem.

[0012] Figure 2 Example apparatuses according to at least some embodiments of the present disclosure are provided.

[0013] Figure 3 Example client computing entities according to some embodiments of the present disclosure are provided.

[0014] Figure 4 A signal diagram illustrating a registration process in accordance with at least some embodiments of the present disclosure is provided.

[0015] Figure 5 Signal diagrams for providing secure communications in accordance with at least some embodiments of the present disclosure are illustrated.

[0016] Figure 6 is a flowchart illustration of an example process for providing secure communications in accordance with at least some embodiments of the present disclosure. DETAILED DESCRIPTION

[0017] Embodiments of the present disclosure will now be described more fully below with reference to the accompanying drawings, in which some (but not all) embodiments of the present disclosure are shown. In fact, embodiments of the present disclosure can be embodied in many different forms and should not be construed as being limited to the embodiments set forth herein; on the contrary, these embodiments are provided so that the present disclosure will satisfy applicable legal requirements. Unless otherwise indicated, the term "or" used herein is both an alternative meaning and a combined meaning. The terms "exemplary" and "example" are examples used for which there is no indication of a quality level. Terms such as "calculate," "determine," "generate," and / or similar words are used interchangeably herein to refer to the creation, modification, or identification of data. In addition, "based on," "partially based on," "at least based on," "based on..." and / or similar words are used interchangeably herein in an open manner such that they do not indicate being based solely on or solely on one or more elements referenced unless so indicated. The same reference numerals always refer to the same elements.

[0018] Overview and technical improvements

[0019] Example embodiments disclosed herein address technical challenges associated with providing secure communications for connected systems within a connected ecosystem. Some example embodiments disclosed herein address technical challenges associated with establishing secure communications for connected aircraft systems, including but not limited to aircraft-to-ground systems (e.g., Aircraft Communications Addressing and Reporting System (ACARS)) communications, communications involving connected flight management systems (FMS) that may communicate using IoT devices and / or data links, connected engines, connected APUs, connected wheels and brakes, or connected enhanced ground proximity warning systems (EGPWS), and the like.

[0020] In aviation, for example, within the FMS framework, the Communications Management Function (CMF) plays a key role in establishing aircraft-to-ground communications. Current aerospace communication systems utilize VHF data link messages to transmit critical flight status updates, airport control instructions, and sensitive information. However, current aviation data link communications lack entity authentication. The onboard management unit (MU) may only verify the CRC and flight registration number in uplink messages. These data link messages are typically transmitted in plain text on public frequencies, making them susceptible to interception or tampering, potentially leading to exposure of private data, unauthorized control, and hijacking.

[0021] Various types of attacks are conceivable, including physical impersonation, man-in-the-middle, surveillance, and data falsification. In a surveillance attack, an attacker could use a radio or a PC equipped with transcription equipment to intercept messages and gather sensitive information such as flight number, origin, and destination airports. In a physical impersonation attack, an attacker could impersonate a ground station and send unauthorized messages to an aircraft, disrupting in-flight communications and potentially allowing them to manipulate the aircraft due to a lack of authentication between the aircraft and the ground station.

[0022] The use of quantum computers, with their unimaginable computing power, is rapidly becoming a reality. Computers based on the unique properties of quantum mechanics can perform calculations exponentially faster than computers composed of classical bits. Recent advances in quantum computing pose a threat to public key primitives due to their ability to solve complex cryptographic problems in polynomial time. For example, in the next-generation aeronautical telecommunications network (ATN) system, attackers could exploit quantum computer ecosystems (such as the Shor algorithm) to use self-signed certificates and trick recipients into trusting them.

[0023] Therefore, even with the advent of the quantum computing era, communication technology (such as, for example, aircraft communication technology) will need to undergo major changes to have secure communications between connected systems (e.g., between ground systems and aircraft systems).

[0024] Example embodiments of the present disclosure utilize a cloud-based quantum service computing entity to provide post-quantum cryptographic services including post-quantum keys (also referred to herein as quantum keys, PQC keys, post-quantum cryptographic keys, or similar terms) via a quantum edge computing entity embodied by a gateway such as an avionics IoT gateway (also referred to herein as a gateway system, a gateway network entity, or similar terms used herein) to enable secure communication between connected systems (e.g., between a CMF system and a ground system, etc.). For example, a gateway system (such as an avionics IoT gateway system associated with an IoT device) may embody a quantum edge computing entity and be communicatively coupled to a cloud-based quantum service computing entity to run / execute IoT applications, data ingress and egress, data loading, or quick access recorder (QAR) data extraction for flight efficiency and flight safety solutions, etc. In some examples, the cloud-based quantum service computing entity may be embodied by the Forge cloud service platform. The cloud-based quantum service computing entity may be configured to perform one or more functionalities associated with establishing secure communication between connected systems as described herein, including but not limited to generating quantum keys, storing quantum keys, distributing quantum keys, and / or other post-quantum services.

[0025] In an example embodiment, a quantum edge computing entity (e.g., embodied by a gateway) is configured to deploy a policy agent and / or key library integrated with the backend services of a cloud-based quantum service computing entity. The policy agent may be configured to act as a local policy agent in the gateway and to receive queries for authorization, authentication, and / or cryptographic operations from a connected system (e.g., an FMS, etc.). For example, the gateway system may be configured to host a cryptographic agent (e.g., a policy agent) that is configured to serve as a client component of a cloud-based quantum service computing entity. In an example embodiment, a cryptographic agent (e.g., a policy agent) is utilized to authenticate communications for each session established between connected systems (such as, for example, between a CMF system and a ground system / ACARS system). In some embodiments, the gateway system may be configured to store post-quantum cryptographic keys and / or use post-quantum cryptographic keys as a proxy to enable various cryptographic operations for connected systems (e.g., CMF systems in the aviation field, etc.).

[0026] In an example embodiment, as described below, cryptographic services (e.g., components of a quantum edge computing entity) may be deployed in a non-authenticated application partition of a gateway. In an example embodiment, the data access partition of a gateway (e.g., an avionics data access partition (ADAP), etc.) may be configured to access a policy agent via one or more APIs. In an example embodiment, a pseudo identity and access management (IAM) layer is created on the gateway (e.g., virtually) using the functionality of a cloud-based quantum service computing entity to protect the communication channel. In an example embodiment, a connection system (such as a CMF) is configured to generate encrypted data (e.g., messages, etc.) using a private key deployed in the gateway system and send the encrypted data / message to one or more other connection systems. In an example embodiment, the ground system may be configured to access a post-quantum cryptographic key to decrypt the encrypted data / message, which is sent on the secure communication channel thus established.

[0027] Example applications of the embodiments of the present disclosure in the aviation field include, but are not limited to: (i) encrypting ACARS communications between the aircraft CMF and ground control by using post-quantum keys and post-quantum cryptographic services provided by a gateway (e.g., via its quantum edge computing entity), which in turn mitigates the attacker from compromising the CMF via the gateway and taking over the ACARS channel; (ii) enabling high-fidelity encrypted data broadcast by using post-quantum keys and post-quantum cryptographic services provided by a gateway (e.g., its quantum edge computing entity) to allow trajectory 4D data (aircraft intent) to be securely shared to ground controllers, which then schedule arrivals / landings at airports (e.g., next generation air traffic management relies on trajectory-based operations (TBO) to optimize terminal air traffic and runway occupancy). In some examples, TBO requires sharing trajectory 4D data to ground controllers, which then schedule arrivals / landings at airports. The success of this operation depends on the fidelity of the received 4D data, and any compromise of this data could seriously jeopardize air traffic); (iii) enabling encryption of weather data and source authentication through the use of post-quantum keys and post-quantum cryptographic services provided by the gateway (e.g., its quantum edge computing entity), which prevents the compromise of weather information, which could lead to catastrophic consequences if an aircraft enters adverse weather conditions without preparation or mitigation (e.g., a pilot may receive live weather information from ground services like XM Weather, IBM Weather Services, etc. for situational awareness and make tactical changes to the flight path to avoid adverse weather conditions). adverse weather, whereby compromised weather information could lead to catastrophic consequences when an aircraft enters adverse weather conditions without preparation or mitigation measures; and (iv) encrypting and authenticating traffic data and source authentication using post-quantum keys and post-quantum cryptographic services provided by the gateway (e.g., its quantum edge computing entity) to prevent compromised traffic information that could lead to major accidents or incidents (e.g., pilots may receive real-time traffic information from ground services such as flight radar, flightaware, etc. for situational awareness and make tactical changes to flight paths to avoid traffic congestion, whereby compromised traffic information could lead to major accidents or incidents).

[0028] By providing secure communications for connected systems using the techniques discussed herein, embodiments of the present disclosure improve various technical fields and systems, including but not limited to communication systems and security systems.

[0029] definition

[0030] Those skilled in the art of the present disclosure that benefit from the teachings presented in the foregoing description and the associated drawings will appreciate many modifications and other embodiments of the present disclosure set forth herein. Therefore, it should be understood that the embodiments are not limited to the specific embodiments disclosed, and modifications and other embodiments are intended to be included within the scope of the appended claims. In addition, although the foregoing description and the associated drawings have described example embodiments in the context of certain example combinations of elements and / or functions, it should be understood that different combinations of elements and / or functions may be provided by alternative embodiments without departing from the scope of the appended claims. In this regard, for example, as may be set forth in some of the appended claims, different combinations of elements and / or functions clearly described above are also contemplated. Although specific terms are employed herein, they are used only in a general and descriptive sense, and not for restrictive purposes.

[0031] As used herein, the term "comprising" means including but not limited to, and should be interpreted in the manner in which it is typically used in a patent context. The use of broader terms such as "including," "comprising," and "having" should be understood to provide support for narrower terms such as "consisting of," "consisting essentially of," and "composed essentially of."

[0032] The phrases "in one embodiment," "according to one embodiment," "in some embodiments," etc. generally mean that the particular feature, structure, or characteristic following the phrase may be included in at least one embodiment of the present disclosure, and may be included in more than one embodiment of the present disclosure (importantly, such phrases are not necessarily referring to the same embodiment).

[0033] The word “example” or “exemplary” is used herein to mean “serving as an example, instance, or illustration.” Any implementation described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other implementations.

[0034] If the specification states that a component or feature "may," "could," "might," "should," "will," "preferably," "likely," "typically," "optionally," "for example," "usually," or "might" (or other such language) be included or have a characteristic, that particular component or feature is not required to be included or have that characteristic. Such a component or feature may optionally be included in some embodiments, or it may be excluded.

[0035] Example systems and apparatus of the present disclosure

[0036] The embodiments of the present disclosure can be implemented in various ways, including as a computer program product including a product, as hardware including circuits configured to perform one or more functions, and / or as a combination of specific hardware and computer program products. Such computer program products may include one or more software components, including, for example, software objects, methods, or data structures. The software components can be decoded in any of a variety of programming languages. An exemplary programming language can be a low-level programming language, such as an assembly language associated with a specific hardware architecture and / or operating system platform. A software component including assembly language instructions may need to be converted into executable machine code by an assembler before being executed by the hardware architecture and / or platform. Another exemplary programming language may be a higher-level programming language that can be transplanted across multiple architectures. A software component including higher-level programming language instructions may need to be converted into an intermediate representation by an interpreter or compiler before execution.

[0037] Other examples of programming languages ​​include, but are not limited to, macro languages, shell or command languages, job control languages, scripting languages, database query or search languages, and / or report writing languages. In one or more example embodiments, a software component comprising instructions in one of the aforementioned examples of a programming language can be directly executed by an operating system or other software component without first being converted into another form. The software component can be stored as a file or other data storage structure. Software components of similar type or function can be stored together, such as in a specific directory, folder, or library. The software component can be static (e.g., pre-established or fixed) or dynamic (e.g., created or modified at execution time).

[0038] A computer program product may include a non-transitory computer-readable storage medium that stores an application, program, program module, script, source code, program code, object code, byte code, compiled code, interpreted code, machine code, and / or executable instructions, etc. (also referred to herein as executable instructions, instructions for execution, computer program product, program code, and / or similar terms used interchangeably herein). Such non-transitory computer-readable storage media include all computer-readable media (including volatile and non-volatile media).

[0039] In some embodiments, the non-volatile computer-readable storage medium may include a floppy disk, a flexible disk, a hard disk, a solid-state storage (SSS) (e.g., a solid-state drive (SSD), a solid-state card (SSC), a solid-state module (SSM)), an enterprise flash drive, a magnetic tape, or any other non-transitory magnetic medium, etc. The non-volatile computer-readable storage medium may also include a punched card, a paper tape, an optical marker sheet (or any other physical medium having a pattern of holes or other optically recognizable markings), a compact disc read-only memory (CD-ROM), a compact disc rewritable (CD-RW), a digital versatile disc (DVD), a Blu-ray disc (BD), and / or any other non-transitory optical medium, etc. Such non-volatile computer-readable storage medium may also include a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory (e.g., serial, NAND, or NOR, etc.), a multimedia memory card (MMC), a secure digital (SD) memory card, a smart media card, a compact flash (CF) card, and / or a memory stick, etc. In addition, the non-volatile computer-readable storage medium may also include conductive bridging random access memory (CBRAM), phase change random access memory (PRAM), ferroelectric random access memory (FeRAM), non-volatile random access memory (NVRAM), magnetoresistive random access memory (MRAM), resistive random access memory (RRAM), silicon-oxide-nitride-oxide-silicon memory (SONOS), floating junction gate random access memory (FJGRAM), millipede memory and / or racetrack memory, etc.

[0040] In some embodiments, the volatile computer-readable storage medium may include random access memory (RAM), dynamic random access memory (DRAM), static random access memory (SRAM), fast page mode dynamic random access memory (FPM DRAM), extended data-out dynamic random access memory (EDO DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), double data rate type two synchronous dynamic random access memory (DDR2 SDRAM), double data rate type three synchronous dynamic random access memory (DDR3 SDRAM), Rambus dynamic random access memory (RDRAM), two-transistor RAM (TTRAM), thyristor RAM (T-RAM), zero capacitor (Z-RAM), Rambus embedded memory module (RIMM), dual in-line memory module (DIMM), single in-line memory module (SIMM), video random access memory (VRAM), cache memory (including various levels), flash memory and / or register memory, etc. It will be appreciated that where embodiments are described as using computer-readable storage media, other types of computer-readable storage media may be used in place of or in addition to the computer-readable storage media described above.

[0041] It should be understood that various embodiments of the present disclosure may also be implemented as one or more of a method, apparatus, system, computing device (e.g., a connection system, a server, etc.), and / or computing entity, etc. Thus, embodiments of the present disclosure may take the form of an apparatus, system, computing device, and / or computing entity, etc., that executes instructions stored on one or more computer-readable storage media to perform certain steps or operations. Thus, embodiments of the present disclosure may also take the form of an entirely hardware embodiment, an entirely computer program product embodiment, and / or an embodiment that includes a combination of a computer program product and hardware that performs certain steps or operations.

[0042] The embodiments of the present disclosure are described below with reference to block diagrams and flow charts. Therefore, it should be understood that each block of the block diagrams and flow charts can be implemented in the following forms: a computer program product, a complete hardware embodiment, a combination of hardware and a computer program product and / or an apparatus, system, computing device, computing entity, etc. that implements instructions, operations, steps, and similar words (e.g., executable instructions, instructions for execution and / or program codes, etc.) for execution on a computer-readable storage medium. For example, the retrieval, loading, and execution of the code can be performed sequentially so that an instruction is retrieved, loaded, and executed once. In some example embodiments, retrieval, loading, and / or execution can be performed in parallel so that multiple instructions are retrieved, loaded, and / or executed together. Therefore, such embodiments can produce a machine that performs a specific configuration of the steps or operations specified in the block diagrams and flow charts. In the embodiments describing specific hardware, it should be understood that such specific hardware can work in conjunction with the foregoing content according to the various examples described herein. Therefore, the block diagrams and flow charts illustrate various combinations of embodiments supporting the execution of specified instructions, operations, or steps.

[0043] In this regard, Figure 1A An example overview of an architecture 100 according to some embodiments of the present disclosure is provided. The depiction of the example architecture 100 is not intended to limit or otherwise constrain the embodiments described and contemplated herein to any particular configuration of components or systems, nor is it intended to exclude any alternative configurations or systems from the set of configurations and systems that may be used in conjunction with embodiments of the present disclosure. Instead, only examples of the present invention are presented. Figure 1A and the architecture 100 disclosed herein to provide an example basis and context for facilitating some of the features, aspects, and uses of the methods, apparatus, computer-readable media, and computer program products disclosed and contemplated herein. It will be understood that while Figure 1A Many of the aspects and components presented in the drawings are shown as discrete, separate elements, but other configurations may be used in conjunction with the methods, apparatus, computer-readable media, and computer programs described herein, including configurations that combine, omit, separate, and / or add aspects and / or components.

[0044] Architecture 100 includes a computing system 101 configured to facilitate secure communication of connection systems 102. In some embodiments, computing system 101 can communicate with connection systems 102 using one or more communication networks. Examples of communication networks include any wired or wireless communication network, including, for example, a wired or wireless local area network (LAN), a personal area network (PAN), a metropolitan area network (MAN), or a wide area network (WAN), among others, as well as any hardware, software, and / or firmware necessary to implement the same, such as, for example, network routers, among others. In some embodiments, computing system 101 can communicate with connection systems 102 via one or more application programming interfaces 104 (APIs).

[0045] In some embodiments, connection systems 102 are systems configured to communicate with each other over the Internet. For example, a first connection system 102A (e.g., a sender connection system) can be configured to communicate a message to a second connection system 102B (e.g., a receiver connection system) over the Internet. In some embodiments, connection systems 102 can utilize one or more communication systems to communicate with each other. For example, in the aviation domain, a communication system can include a data link system, such as an Aircraft Communications Addressing and Reporting System (ACARS). As described below with reference to FIG. 2, a data link system can be configured to facilitate communication between an aircraft and a ground control and / or between an aircraft and other connection systems in an aviation ecosystem and / or between a ground control and other connection systems in an aviation ecosystem and / or between other connection systems in an aviation ecosystem. Figure 1B Further described, a data link system is configured to facilitate communication between an aircraft and a ground control and / or between an aircraft and other connection systems in an aviation ecosystem and / or between a ground control and other connection systems in an aviation ecosystem and / or between other connection systems in an aviation ecosystem. For example, in the aviation domain, at least one connection system 102 can be on-board an aircraft. In the aviation domain, example connection systems include or are associated with, but are not limited to, a connected flight management system (connected FMS), a connected engine, a connected APU, a connected radar, or a connected wheel and brake, among others. In some embodiments, connection systems 102 can include a client computing entity configured to perform various functions associated with a connection system.

[0046] It should be appreciated that while some example embodiments are described herein with reference to the aviation domain, example architecture 100 can be used in multiple domains and is not limited to any particular application as disclosed herein. Multiple domains can include aviation, banking, health care, industry, manufacturing, education, retail, among others.

[0047] The computing system 101 can include a quantum edge computing entity 106 and a quantum service computing entity 108. In some embodiments, the quantum edge computing entity 106 can comprise a first subsystem of the computing system 101 and the quantum service computing entity 108 can comprise a second subsystem of the computing system 101. In some embodiments, the quantum edge computing entity 106 is embodied by or associated with a gateway network entity. For example, in the aviation domain, the quantum edge computing entity 106 can be embodied by or implemented in an avionics IoT gateway. In some embodiments, the avionics IoT gateway can include an authenticated portion and a non-authenticated portion. In some embodiments, the quantum edge computing entity 106 can be embodied by or implemented in the non-authenticated portion of the avionics IoT gateway. In some embodiments, the gateway network entity, such as an avionics gateway, is configured to connect two networks. For example, the gateway network entity can be configured to connect a connecting system of one network to another network. For example, in the aviation domain, an on-board gateway network entity (e.g., including the quantum edge computing entity 106) can be on an aircraft.

[0048] In some embodiments, the quantum service computing entity 108 is a cloud-based quantum service computing entity 108. For example, the quantum service computing entity 108 can be implemented in the cloud. In some embodiments, the quantum edge computing entity 106 and the quantum service computing entity 108 are configured to communicate with each other using one or more wired and / or wireless communication technologies. The respective systems can be specially configured to perform one or more steps / operations of one or more techniques described herein. For example, the quantum service computing entity 108 can be configured to perform post-quantum key management services, including but not limited to generating post-quantum cryptographic keys, providing the post-quantum cryptographic keys to one or more connecting systems 102 via the quantum edge computing entity 106. The quantum edge computing entity 106 can be configured to store the post-quantum cryptographic keys for the connecting systems, use the post-quantum cryptographic keys as an identity and access (IAM) agent for authentication and authorization. In some embodiments, the quantum edge computing entity 106 can utilize the post-quantum cryptographic keys to provide authentication and authorization between avionics components (e.g., a communication satellite or an avionics cloud, etc.). In some embodiments, the quantum edge computing entity 106 can be configured to use the post-quantum cryptographic keys to facilitate and / or perform message encryption / encapsulation to establish secure communications between connecting systems 102 (e.g., a sender connecting system 102A and a receiver connecting system 102B) via a communication network, channel, or system that can otherwise be insecure. The sender connecting system 102A can be a connecting system 102 that transmits a message, and the receiver connecting system 102 can be a connecting system that receives or intends to receive the message.

[0049] In some embodiments, the quantum service computing entity 108 includes one or more engines, services, databases, and / or other components configured to facilitate and / or perform various functions associated with providing secure communications within the connectivity system 102 and / or within a communications system, such as a data link system.

[0050] In some embodiments, the quantum service computing entity 108 includes an identity and access management policy database 110 (e.g., such as the illustrated IAM policy database), an identity and access management service 112 (e.g., such as the illustrated IAM service), a key store 114, a quantum key management service 116, a quantum key distribution service 118, a quantum secure cryptogram library 120, a quantum service 122, a node manager 124, a rules engine 126, a quantum computing virtual machine 128, and / or one or more dashboards 130. Figure 1A Figure 1A In some embodiments, the identity and access management service 112, one or more of the hardware, software, and / or firmware, are configured to individually or collectively control access to one or more other components of the architecture 100. For example, the identity and access management service 112 can be configured to define, store, retrieve, and / or update the authentication and authorization policies in the identity and access management policy database 110. In this regard, the identity and access management service 112 can be configured to ensure that only authorized entities have access to quantum cryptographic keys and related processes.

[0051] In some embodiments, the identity and access management policy database 110 can be configured to manage and organize rules that prescribe user identification identities and privileges / permissions within a connectivity ecosystem. In some embodiments, the connectivity ecosystem describes an environment and / or ecosystem of connectivity systems configured to communicate with one another over the Internet, such as, for example, an aviation environment / ecosystem having a plurality of connectivity systems (e.g., a connected aviation ecosystem). The identity and access management policy database 110 can include a repository that stores quantum-resistant authentication and authorization policies configured to enhance the security of information / data exchanges between the connectivity systems 102 by efficiently managing access and permissions for various entities operating within the ecosystem, including but not limited to connectivity systems, gateway network entities, and / or other entities configured to facilitate communications between connectivity systems. For example, the identity and access management policy database 110 can store roles, updates, and / or other privileges for each of a plurality of entities in the connectivity ecosystem.

[0052] In some embodiments, the identity and access management service 112, one or more of the hardware, software, and / or firmware, are configured to individually or collectively control access to one or more other components of the architecture 100. For example, the identity and access management service 112 can be configured to define, store, retrieve, and / or update the authentication and authorization policies in the identity and access management policy database 110. In this regard, the identity and access management service 112 can be configured to ensure that only authorized entities have access to quantum cryptographic keys and related processes.

[0053] ​In some embodiments, the key vault 114 is a repository configured to securely store and manage post-quantum cryptographic keys (e.g., using principles of quantum mechanics). The key vault 114 can utilize post-quantum key distribution protocols to generate, store, and retrieve quantum cryptographic keys that possess inherent capabilities to resist eavesdropping or unauthorized access, which ensures a high level of security and key management for information shared between connected systems (e.g., including sensitive information).

[0054] In some embodiments, the quantum key management service 116 includes one or more of hardware, software, and / or firmware configured to individually or collectively allocate / distribute post-quantum cryptographic keys, deallocate post-quantum cryptographic keys (e.g., rework post-quantum cryptographic keys), and update post-quantum cryptographic keys (e.g., update expired post-quantum cryptographic keys). For example, the quantum key management service 116 can be a layer on top of the key vault 114 and can be configured to facilitate secure generation and / or storage of post-quantum cryptographic keys using principles of quantum mechanics. In this regard, the quantum key management service 116 can provide a resilient key management process that enhances security of a communication system (e.g., a data link system, etc.) or otherwise enhances communication security between connected systems by leveraging quantum principles to prevent eavesdropping threats and unauthorized access threats.

[0055] In some embodiments, the quantum key distribution service 118 includes one or more of hardware, software, and / or firmware configured to individually or collectively distribute post-quantum cryptographic keys between various entities within a connected ecosystem (e.g., acting as a broker). For example, quantum cryptographic key distribution protocols can be implemented via the quantum key distribution service 118 to ensure secure encryption, key generation, key distribution, and key management. Thus, by mitigating risks associated with classical eavesdropping techniques, enhanced network security is provided within the connected ecosystem. For example, the quantum key distribution service 118 can facilitate secure post-quantum cryptographic key exchange between connected systems 102 via communication channels and / or communication systems that can otherwise be insecure utilizing quantum principles.

[0056] In some embodiments, the quantum secure cryptographic library 120 can be configured to provide cryptographic algorithms that are resistant to quantum computing threats. For example, the quantum secure cryptographic library 120 can be configured for performing quantum-level hashing. In this regard, the quantum secure cryptographic library 120 can be used to harden devices, systems, and / or other components within a connected ecosystem (e.g., an avionics system, etc.) against potential security vulnerabilities caused by quantum computers, thereby ensuring that encryption methods remain robust and secure even when faced with evolving quantum technologies.

[0057] In some embodiments, the quantum service 122 may include one or more APIs configured to allow communication between the quantum service computing entity 108 and the quantum edge computing entity 106. The quantum service 122 (e.g., Forge quantum service in some implementations) may be configured to provide advanced security solutions (including functionality such as quantum key distribution, secure communication protocols, and real-time analytics) to protect sensitive information. For example, the quantum service 122 may utilize principles of quantum cryptography.

[0058] In some embodiments, the node manager 124 includes one or more of hardware, software, and / or firmware that are configured to oversee, individually or collectively, the deployment and coordination of quantum key distribution nodes within the connected ecosystem. For example, the node manager can be configured to facilitate and / or perform management of the generation, exchange, and / or storage of quantum keys (e.g., post-quantum cryptographic keys). Thus, by implementing quantum-safe cryptographic protocols to ensure secure communications and / or secure communication channels, the overall cybersecurity of connected systems in the connected ecosystem is enhanced. For example, in the aviation field, the node manager 124 can be configured to manage flight equipment and can utilize the rule engine 126.

[0059] In some embodiments, the rule engine 126 can be configured to cooperate with the node manager 124 to implement and execute predefined policies that govern the behavior and interactions of quantum key distribution nodes within the connected ecosystem. The rule engine 126 can be configured to act as a dynamic control mechanism to facilitate the consistent implementation of security protocols and ensure the coordinated operation of quantum cryptographic processing to enhance the overall integrity of communications (e.g., avionics communications in the aviation field).

[0060] In some embodiments, each of the services may be run in a quantum sandbox (e.g., using a quantum computing ecosystem in a cloud environment). The quantum computing virtual machine 128 may be configured to provide secure data processing using quantum computing principles. In an example embodiment, the quantum computing virtual machine 128 may be configured to create a controlled and isolated space in which quantum cryptographic operations may be performed. In this regard, the quantum computing virtual machine 128 may be configured to enhance the security of various devices and / or systems within the connected ecosystem by leveraging the computational properties of quantum computing in a virtualized setting. For example, the quantum computing virtual machine 128 may include a virtualized environment that employs quantum computing principles. In some embodiments, the dashboard 130 may be configured to present one or more graphical user interfaces.

[0061] In some embodiments, the quantum edge computing entity 106 includes one or more engines, services, databases, and / or other components (e.g., edge components) configured to facilitate and / or perform various functions associated with providing secure communications for the connection system 102 and / or within a communication system (such as a data link system). In some embodiments, the quantum edge computing entity 106 includes a message bus 132, a quantum agent 134, a node agent 136, a software development kit 138, an identity and access management shadow database 140 (e.g., such as Figure 1A exemplified IAM shadow database), context processing engine 142, rule engine 144, context data 146, security keystore 148, policy agent 150, and / or key generator 152.

[0062] In some embodiments, the message bus 132 can be a centralized data bus that implements a complex event processing runtime. One or more components embodied by or otherwise associated with the quantum edge computing entity 106 can utilize the message bus to exchange information with each other.

[0063] In some embodiments, the quantum agent 134 includes one or more of hardware, software, and / or firmware that are configured to manage, individually or collectively, client-side services associated with the quantum service computing entity 108. For example, the quantum agent 134 can be configured to manage and control quantum-related components and service versions deployed in a quantum edge computing entity 106 runtime (e.g., a gateway network entity runtime). The quantum agent 134 can be configured to communicate with the quantum service computing entity 108 (e.g., the quantum service 122 of the quantum service computing entity 108) to inject input related to the quantum service into the message bus 132.

[0064] In some embodiments, the node agent 136 includes one or more of hardware, software, and / or firmware that are configured to register, configure, deregister, cancel, initialize, blacklist, and / or update the quantum edge computing entity 106 runtime (e.g., gateway network entity runtime). For example, the node agent 136 can be configured to inject hardware-related information (e.g., include gateway network entity-related information into the message bus 132). For example, the node agent 136 can act as a device manager.

[0065] In some embodiments, the software development kit 138 may include a software runtime configured to enable development and deployment of various applications in a gateway network entity embodying the quantum edge computing entity 106 to implement a variety of use cases associated with protecting various external components (e.g., off-board components, etc.).

[0066] In some embodiments, the identity and access management shadow database 140 may include a local database that is used for local authorization and authentication in the absence of cloud services (e.g., in the absence of Internet on an airplane, etc.). Copies of authentication and authorization policies may be stored in the identity and access management shadow database 140 and used for authentication and authorization in the absence of cloud services. Decisions may be made using the rules engine 144 and contextual data 146.

[0067] In some embodiments, the context processing engine 142 includes one or more of hardware, software, and / or firmware that are configured to individually or collectively identify the current runtime context of the quantum edge computing entity 106. The output of the context processing engine 142 may include a possible state or set of states of the device or system under consideration. The context data 146 may include data defined by the context processing engine 142. The context data 146 may be input to one or more other components of the quantum edge computing entity 106, for example, to operate under desired runtime conditions.

[0068] In some embodiments, the rules engine 144 includes one or more of hardware, software, and / or firmware that are configured to, individually or collectively, store and / or manage rule sets that have been received (e.g., downloaded, etc.) from the quantum service computing entity 108 and enable seamless operation of various components (e.g., in aviation, while an aircraft is in the air).

[0069] In some embodiments, the policy agent 150 includes one or more of hardware, software, and / or firmware that are configured to individually or collectively track centralized policies received (e.g., downloaded, etc.) from the computing system 101 environment (e.g., a central server environment). In some embodiments, the key generator 152 includes one or more of hardware, software, and / or firmware that are configured to individually or collectively generate and / or retrieve keys required for the quantum edge computing entity 106 runtime (e.g., the gateway network entity runtime).

[0070] In some embodiments, the secure keystore 114 may comprise a hardware-backed repository configured to store offline keys and certificates that may be used to authenticate and authorize various software services in real time while the aircraft is airborne.

[0071] In some embodiments, as further described below, computing system 101 utilizes lattice-based post-quantum cryptography techniques, such as a key encapsulation method, to generate and send post-quantum cryptographic keys to provide secure communications between connected systems 102. The key encapsulation method can be configured to send a key over an insecure communication channel, where the key is encapsulated in an encryption layer before being sent to an intended recipient (e.g., a recipient connected system) so that secure communications are established.

[0072] Figure 1B An example connectivity ecosystem is provided in which at least some embodiments of the present disclosure may operate. Specifically, Figure 1B An example connected aviation ecosystem is illustrated. Figure 1B As shown, the connectivity ecosystem includes a gateway 186 (e.g., a gateway network entity), a flight management system 188, and an electronic flight bag (EFB) onboard an aircraft 182, which is configured to communicate with a ground control system 184 via a data link communication channel 198 (e.g., ACARS). The flight management system 188 may include a communication management function (CMF) system that the aircraft 182 utilizes to communicate with the ground control system 184. The gateway 186 may be embodied as a quantum edge computing entity 106 that includes various components, including a quantum agent 134 (also known as a PQC agent or cryptographic agent), a key repository 114, a policy agent 150, and the like. As described above, the key repository 114 may be configured to store post-quantum cryptographic keys 192 and use them as an agent to implement various cryptographic operations of the CMF system. The policy agent may be accessed via an API using an Epic-Lan TCP / IP connection and an end-to-end connector to the CMF via an avionics data access partition (e.g., ADAP). For each session (e.g., communication session) established by the CMF to the ground using ACARS, the quantum agent 134 can be used to authenticate the communication. For example, a pseudo IAM layer is virtually created in the gateway 186 (e.g., its quantum edge computing entity 106), which has the capabilities of the quantum service computing entity 108 deployed in the cloud and is configured to provide post-quantum cryptographic services to the cloud-based system (e.g., Forge Cloud) to protect the communication channel or otherwise protect the communication sent via the communication channel. The CMF can use the private key (e.g., post-quantum private key) in the gateway 186 (e.g., its quantum edge computing entity 106) to generate encrypted data / messages and send them to the ground control system 184 via the communication channel. The ground control system 184 can be configured to access the PQC key via the quantum service computing entity 108 to decrypt the data received via the communication channel.

[0073] Figure 1C Provided for Figure 1BAn example of a secure communication process flow for an example connected ecosystem. Figure 1C As shown, the Forge system provides PQC key and password services. The PQC agent acts as a local policy agent in the gateway. The FMS queries the local policy agent for authorization and authentication. Based on the response, the CMF enables or disables communication.

[0074] Example devices of the present disclosure

[0075] Having discussed example systems according to the present disclosure, example devices according to the present disclosure will now be described.

[0076] Figure 2 1 illustrates a block diagram of an apparatus 200 according to some example embodiments. For example, in some embodiments, if computing system 101 (or one or more portions thereof) is embodied in a particular embodiment, it may be embodied by one or more apparatuses 200. However, it should be noted that, hereinafter, Figure 2 The components or elements illustrated in and described with respect to the figure may not be mandatory, and thus one or more components or elements may be omitted in certain embodiments. Additionally, some embodiments may include Figure 2 In some embodiments, the functionality of computing system 101 or any subset thereof can be performed by a single apparatus 200 or a plurality of apparatuses 200. In some embodiments, apparatus 200 can include one or more physical devices.

[0077] Device 200 may include a processor 202, a memory 204, input / output circuitry 206, a communication circuit 208, a quantum edge circuit 210, and / or a quantum service circuit 212. Device 200 may be configured to perform the operations described herein. Although these components 202-212 are described with respect to functional limitations, it should be understood that a particular implementation necessarily involves the use of specific hardware. It should also be understood that some of these components 202-212 may include similar or common hardware. For example, both sets of circuits may use the same processor, network interface, or storage medium to perform their associated functions, so that each set of circuits does not require duplicate hardware.

[0078] In some embodiments, the processor 202 (and / or a coprocessor or any other processing circuitry assisting the processor or otherwise associated with the processor) may communicate with the memory 204 via a bus for transferring information between components of the device. The memory 204 is non-transitory and may include, for example, one or more volatile and / or non-volatile memories. In other words, the memory 204 may be, for example, an electronic storage device (e.g., a computer-readable storage medium). The memory 204 may be configured to store information, data, content, applications, instructions, etc. for enabling the device to perform various functions according to example embodiments of the present invention.

[0079] The processor 202 can be embodied in a variety of different ways and can, for example, include one or more processing devices configured to execute independently. In some preferred and non-limiting embodiments, the processor 202 can include one or more processors configured in series via a bus to enable independent execution of instructions, pipelining, and / or multithreading. The use of the term "processing circuitry" can be understood to include a single-core processor, a multi-core processor, multiple processors within a device, and / or a remote or "cloud" processor.

[0080] In some preferred and non-limiting embodiments, the processor 202 may be configured to execute instructions stored in the memory 204 or otherwise accessible to the processor 202. In some preferred and non-limiting embodiments, the processor 202 may be configured to execute hard-coded functionality. Thus, whether configured by hardware or software methods, or by a combination thereof, the processor 202 may represent an entity (e.g., physically embodied in circuit form) capable of performing operations in accordance with embodiments of the present invention while being configured accordingly. Alternatively, for example, when the processor 202 is embodied as an executor of software instructions, these instructions may specifically configure the processor 202 to perform the algorithms and / or operations described herein when executing these instructions.

[0081] In some embodiments, the apparatus 200 may include input / output circuitry 206, which in turn may communicate with the processor 202 to provide output to a user and, in some embodiments, receive indications of user input. The input / output circuitry 206 may include a user interface and may include a display and may include a web user interface, a mobile application, a query-initiating computing device, an information kiosk, etc. In some embodiments, the input / output circuitry 206 may also include a keyboard, a mouse, a joystick, a touch screen, a touch area, soft keys, a microphone, a speaker, or other input / output mechanisms. The processor and / or user interface circuitry including the processor may be configured to control one or more functions of one or more user interface elements via computer program instructions (e.g., software and / or firmware) stored on a memory accessible to the processor (e.g., memory 204, etc.).

[0082] The communication circuitry 208 can be any component (such as a device or circuit embodied in hardware or a combination of hardware and software) that is configured to receive and / or send data from and / or to a network and / or any other device, circuit, or module that communicates with the apparatus 200. In this regard, the communication circuitry 208 may include, for example, a network interface for enabling communication with a wired or wireless communication network. For example, the communication circuitry 208 may include one or more network interface cards, antennas, buses, switches, routers, modems, and supporting hardware and / or software or any other device suitable for enabling communication via a network. Additionally or alternatively, the communication circuitry 208 may include circuitry for interacting with an antenna to cause signals to be transmitted via the antenna or to process signals received via the antenna.

[0083] In some embodiments, the apparatus 200 includes a quantum edge circuit 210. The quantum edge circuit 210 may include hardware components, software components, and / or combinations thereof configured to perform one or more functions associated with the quantum edge computing entity 106 (as described above with reference to FIG. 1 ) in conjunction with the processor 202, the memory 204, the input / output circuit 206, and / or the communication circuit 208. Figure 1A(as described). In some embodiments, the quantum edge circuit 210 can be configured to receive data and / or objects, etc. from one or more components of the device 200 and / or send such data and / or objects, etc. to one or more components of the device 200, for example, using an application or API executed by a processor (such as processor 202). It should also be understood that in some embodiments, the quantum edge circuit 210 may include a separate processor, a specially configured field programmable gate array (FPGA), or an application specific interface circuit (ASIC) to provide or otherwise facilitate access to such data and / or objects, etc. used by one or more other components of the device 200. The quantum edge circuit 210 may also provide communication with other components of the device, system, and / or external systems via a network interface provided by the communication circuit 208.

[0084] In some embodiments, the apparatus 200 includes a quantum service circuit 212. The quantum service circuit 212 may include hardware components, software components, and / or combinations thereof that are configured to perform one or more functions associated with the quantum service computing entity 108 (as described above with reference to FIG. 1 ) in conjunction with the processor 202, the memory 204, the input / output circuit 206, and / or the communication circuit 208. Figure 1A (as described above). In some embodiments, the quantum service circuit 212 may be configured to receive data and / or objects, etc. from one or more components of the device 200 and / or send such data and / or objects, etc. to one or more components of the device 200, for example, using an application or API executed by a processor (such as the processor 202). It should also be understood that in some embodiments, the quantum service circuit 212 may include a separate processor, a specially configured field programmable gate array (FPGA), or an application specific interface circuit (ASIC) to provide or otherwise facilitate access to such data and / or objects, etc. used by one or more other components of the device 200. The quantum service circuit 212 may also provide communication with other components of the device, system, and / or external systems via a network interface provided by the communication circuit 208.

[0085] Additionally or alternatively, in some embodiments, two or more of the sets of circuits embodying processor 202, memory 204, input / output circuitry 206, communication circuitry 208, quantum edge circuitry 210, and / or quantum service circuitry 212 are combined. Additionally or alternatively, in some embodiments, one or more of the sets of circuits perform some or all of the functionality described in connection with another component. For example, in some embodiments, two or more of the sets of circuits embodied by processor 202, memory 204, input / output circuitry 206 and communication circuitry 208, quantum edge circuitry 210, and / or quantum service circuitry 212 are combined into a single module embodied in hardware, software, firmware, and / or a combination thereof. Similarly, in some embodiments, one or more of the sets of circuits (e.g., quantum edge circuitry 210 and / or quantum service circuitry 212) are combined with processor 202 such that processor 202 performs one or more of the operations described above for each of these sets of circuits embodied by quantum edge circuitry 210 and / or quantum service circuitry 212.

[0086] It is also noted that all or part of the information discussed herein may be based on data received, generated, and / or maintained by one or more components of the device 200. In some embodiments, one or more external systems (such as remote cloud computing and / or data storage systems) may also be utilized to provide at least some of the functionality discussed herein.

[0087] Sample Client Compute Entity

[0088] Now refer to Figure 3 The client computing entity may be composed of one or more computing systems (such as Figure 3 The depiction of the device 300 is not intended to limit or otherwise constrain the embodiments described and contemplated herein to any particular configuration of components, circuits, or systems, nor is it intended to exclude any alternative configurations, circuits, or systems. Figure 3 and the apparatus 300 disclosed therein are merely intended to provide an example basis and context for facilitating some of the features, aspects, and techniques disclosed herein.

[0089] The apparatus 300 can include a processor 302, a memory 304, input / output circuitry 306, and communication circuitry 308. While these components 302-308 are described with respect to functional limitations, it will be appreciated that a particular implementation will necessarily include use of particular hardware. It will also be appreciated that certain of these components 302-308 can comprise similar or common hardware. For example, both sets of circuitry can use the same processor, network interface, or storage media, etc. to perform their associated functions, such that each set of circuitry does not require duplicative hardware.

[0090] In some embodiments, the processor 302 (and / or co-processors or any other processing circuitry assisting or otherwise associated with the processor) can be in communication with the memory 304 via a bus for passing information among components of the apparatus. The memory 304 is a non-transitory memory and can include, for example, one or more volatile and / or non-volatile storage components. In other words, for example, the memory 304 can be an electronic storage device (e.g., a computer readable storage medium). The memory 304 can include one or more databases. In addition, the memory 304 can be configured to store information, data, content, applications, instructions, or the like for enabling the apparatus 300 to perform various functions in accordance with embodiments of the present application.

[0091] The processor 302 can be embodied in a number of different ways, and can be, for example, one or more processing devices configured to independently execute instructions. In some preferred and non-limiting embodiments, the processor 302 can include one or more processors in a serial or parallel configuration configured to independently execute instructions, pipelines, and / or multithreaded instructions. The use of the term“processing circuitry” is intended to encompass a single processor, multiple processors, multiple processors in a single or distributed device, and / or remote or“cloud” processors.

[0092] In some preferred and non-limiting embodiments, the processor 302 can be configured to execute instructions stored in the memory 304 or otherwise accessible to the processor 302. In some preferred and non-limiting embodiments, the processor 302 can be configured to execute hard coded functionality. As such, whether configured by hardware or software methods, or by a combination thereof, the processor 302 can represent an entity capable of performing operations according to embodiments of the present application while configured accordingly. Alternatively, as another example, when the processor 302 is embodied as an executor of software instructions, the instructions can specifically configure the processor 302 to perform the algorithms and / or operations described herein when the instructions are executed.

[0093] In some embodiments, the device 300 can include input / output circuitry 306, which can in turn be in communication with the processor 302 to provide output to the user and, in some embodiments, receive indications of user input. The input / output circuitry 306 can include a user interface and can include a display, and can include a web user interface, a mobile application, a query initiation computing device, a kiosk, or the like.

[0094] In embodiments in which the device 300 is embodied by a limited interaction device, the input / output circuitry 306 includes a touch screen and does not include, or at least does not operatively engage, other input accessories such as a tactile keypad, trackpad, mouse, or the like (i.e., when configured in tablet mode). In other embodiments in which the device is embodied by a non-limited interaction device, the input / output circuitry 306 can include at least one of a tactile keypad (e.g., also referred to herein as a keypad), a mouse, a joystick, a touch screen, a touch area, soft keys, and other input / output mechanisms. The processor and / or user interface circuitry comprising the processor can be configured to control one or more functions of one or more user interface elements through computer program instructions (e.g., software and / or firmware) stored on a memory accessible to the processor (e.g., the memory 304, or the like).

[0095] The communication circuitry 308 can be any means such as a device or circuitry embodied in either hardware or a combination of hardware and software that is configured to receive and / or transmit data from / to any other device, circuitry, or module in communication with the device 300, and / or a network. In this regard, the communication circuitry 308 can include, for example, a network interface for enabling communications with a wired or wireless communication network. For example, the communication circuitry 308 can include one or more network interface cards, antennas, buses, switches, routers, modems, and supporting hardware and / or software, or any other device suitable for enabling communications via a network. Additionally or alternatively, the communication circuitry 308 can include circuitry suitable for interacting with an antenna for transmitting signals to and / or for receiving signals from an antenna.

[0096] It is also noted that all or a portion of the information discussed herein can be based on data received, generated, and / or maintained by one or more components of the device 300. In some embodiments, one or more external systems, such as remote cloud computing and / or data storage systems, can also be utilized to provide at least some of the functionality discussed herein.

[0097] Example System Operation

[0098] Figure 4 A signal diagram illustrating a registration process in accordance with at least some embodiments of the present disclosure is illustrated. Specifically, Figure 4A signal diagram 400 illustrating a registration process for a connectivity system 102A and / or a quantum edge gateway computing entity 106 associated with the connectivity system is illustrated. As described above, embodiments of the present disclosure utilize post-quantum principles to provide secure communications between connectivity systems 102, such as for example, between an aircraft system and a ground system. In some embodiments, a lattice-based post-quantum cryptography technique, such as a post-quantum cryptography based on a key encapsulation method (e.g., KEM), is utilized to secure communication channels and / or communication systems utilized by the connectivity system 102.

[0099] In some embodiments, as illustrated, the quantum edge computing entity 106 registers 402 the connectivity system 102A and / or the quantum edge computing entity 106 with the quantum service computing entity 108. For example, the quantum edge computing entity 108 can transmit a registration request to the quantum service computing entity 108. In response, the quantum service computing entity 108 performs registration 402 and / or configuration 404 for the connectivity system 102A and / or the quantum edge computing entity 106. The quantum edge computing entity 106 can transmit a parameter query request 406 to the connectivity system 102A and store parameters received from the connectivity system 102A. In the aviation domain, example parameters can include a tail number of an aircraft, a current route of an aircraft, a flight identification, pilot information, or CDLC parameters, among others. Figure 2

[0100] The quantum service computing entity 108 can select lattice parameters and a cryptographic scheme 408 using a specially configured algorithm. In some embodiments, the lattice parameters can include, but are not limited to, a lattice structure, a dimension, a modulus, a standard deviation of noise. For example, the lattice parameters can include L, n, m, q, s (lattice, dimension, modulus, standard deviation of noise). In some embodiments, the cryptographic scheme includes a lattice-based cryptographic scheme, such as a learning with errors (LWE) or a ring learning with errors (RLWE) problem, among others.

[0101] The quantum service computing entity 108 generates a PQC public-private key pair 412 using a specially configured algorithm. For example, the quantum service computing entity 108 can compute a lattice basis (e.g., B <- GenBasis(L, n)) and generate a PQC public-private key pair based on the lattice basis. For example, the PQC public-private key pair can include a private key based on s <- SampleShort(B, s) and a public key based on A <- s.B + e, where e can represent a noise term. In some embodiments, where the lattice-based cryptographic scheme is an RLWE scheme, the private key can be a short vector in the lattice and the public key can be derived from the private key.

[0102] ​The quantum service computing entity 108 provides 414 the private key to the quantum edge computing entity 106. The quantum edge computing entity 106 stores the private key 416 for use when the communication session is initiated by the connection system 102A. The quantum service computing entity 108 shares 418 the public key with the connection system 102B. For example, the connection system 102B stores the public key in an application. The quantum service computing entity 108 reads 420 the IAM policy and shares 422 the IAM data with the quantum edge computing entity 106. The quantum edge computing entity 106 may store 424 the IAM data in an IAM shadow database and transmit a registration success message 426 to the quantum service computing entity 108.

[0103] Figure 5 5 illustrates a signal diagram 500 for providing secure communications according to at least some embodiments of the present disclosure. Specifically, Figure 5 Illustrated is a signal diagram 500 that provides secure communications based on encapsulating / encrypting messages using post-quantum cryptographic keys and lattice-based techniques, such as key encapsulation methods.

[0104] In some embodiments, connection system 102A initiates 502 a communication session. Quantum edge computing entity 106 may receive a communication session indication indicating a communication session associated with connection system 102A. For example, connection system 102A may send a signal or data indicating a request to initiate a communication session to quantum edge computing entity 106. In some embodiments, an IAM policy associated with connection system 102A is verified with quantum service computing entity 108 via quantum edge computing entity 106. For example, connection system 102A may send a signal or data indicating an IAM verification request 504 to quantum edge computing entity 106. In response, quantum edge computing entity 106 may communicate with quantum service computing entity 108 to verify the IAM policy. For example, quantum edge computing entity 106 may transmit 506 a verification request to quantum service computing entity 108. Quantum service computing entity 108 may update 508 the IAM policy.

[0105] In some embodiments, after verifying the IAM policy, the quantum edge computing entity 106 transmits a parameter request 510 to the connection system 102A. For example, the quantum edge computing entity 106 may query the connection system 102A for parameters that may be used for key encryption. In some embodiments, the connection system 102 may provide one or more parameters to the quantum edge computing entity 106. In the aviation field, example parameters may include the tail number of the aircraft, the current route of the aircraft, itinerary identification, pilot information, or CDLC parameters.

[0106] In some embodiments, in response to receiving the one or more parameters, the quantum edge computing entity 106 generates random data 512 (e.g., comprising a random value) and provides the random data to the connection system 102A. In some embodiments, generating the random data includes selecting a random noise vector (e.g., r←SampleUniform(L,m,q)). In some embodiments, the random data can be configured to create errors in lattice-based encryption.

[0107] In some embodiments, the connection system 102A transmits a ciphertext request 516 to the quantum edge computing entity 106. In some embodiments, the quantum edge computing entity 106 uses a specially configured algorithm to calculate 518 a ciphertext using post-quantum cryptography and transmits the ciphertext 520 to the connection system 102A. The ciphertext may encapsulate a shared secret key (e.g., a private key) using a public key. In some embodiments, the quantum edge computing entity 106 calculates the ciphertext by combining the public key and random data. For example, the ciphertext may include a perturbed version of the public key, where the random data acts as noise. The encrypted message may then be sent 524 to the recipient connection system 102 via the communication channel. The specially configured algorithm for calculating the ciphertext may, for example, include calculating a public key perturbed by noise (e.g., u←A+r) and calculating the ciphertext based on the public key perturbed by noise (e.g., c←u.B+mG), where G is a generator matrix.

[0108] In certain embodiments, the connection system 102A (e.g., with the support of the quantum edge computing entity 106) encrypts / encodes the message to be sent using a lattice-based PQC public-private key and transmits the message to the connection system 102B via the communication channel. For example, the message may be encoded into the lattice points using a specially configured algorithm, which may include mapping the bits of the message into the lattice points using a selected encoding technique.

[0109] In some embodiments, the recipient connection system 102B calculates 526 the shared secret and decodes 528 the message. In some embodiments, the recipient connection system 102B may use the private key and the ciphertext to calculate the shared secret. For example, the recipient connection system 102B may use lattice-based techniques to filter out noise introduced during encryption / encoding of the message, as described above. The lattice structure may be configured to ensure efficient recovery of the shared secret even in the presence of added noise. The shared secret may then be extracted from the lattice points to decode the message. In some embodiments, decoding the message may include mapping the lattice points back to the original shared secret / message.

[0110] In some embodiments, the connection system 102B may send a signal, data, or the like to the connection system 102A via the communication channel indicating receipt of the confirmation 530 message.

[0111] Figure 6 is a flowchart illustration of an example process 600 for providing secure communications, in accordance with at least some embodiments of the present disclosure. Figure 6 The example process 600 is illustrated for purposes of explanation. Although the example process 600 depicts a particular sequence of steps / operations, this sequence may be varied without departing from the scope of the present disclosure. For example, some of the depicted steps / operations may be performed in parallel or in a different sequence without substantially affecting the functionality of the process 600. In other examples, different components of the example device or system implementing the process 600 may perform functions substantially simultaneously or in a particular sequence.

[0112] In some embodiments, the process includes receiving a communication session indication associated with the first connection system at step / operation 602. For example, the computing system 101 (e.g., via its quantum edge computing entity 106) may receive a communication session indication associated with the first connection system.

[0113] In some embodiments, the process includes authenticating the first connected system at step / operation 604. For example, the computing system 101 (e.g., via its quantum edge computing entity 106) may authenticate the first connected system based on an IAM policy.

[0114] In some embodiments, process 600 includes encrypting a message associated with the first connected system at step / operation 606. For example, computing system 101 (e.g., via its quantum edge computing entity 106) may authenticate the message associated with the first connected system to generate an encrypted message based on a post-quantum cryptography public key associated with the first connected system.

[0115] In some embodiments, the computing system 101 (e.g., via the quantum service computing entity 108) may be configured to generate a post-quantum cryptography public key. For example, the computing system 101 (e.g., via the quantum service computing entity 108) may be configured to generate a post-quantum cryptography public key-private key pair comprising a post-quantum cryptography public key and a post-quantum cryptography private key. In some embodiments, the computing system 101 (e.g., via the quantum service computing entity 108) may generate a post-quantum cryptography public key-private key pair during registration of the first connection system. For example, the post-quantum cryptography public key-private key pair may include an initial post-quantum cryptography public key-private key pair for the first connection system. In some embodiments, the post-quantum cryptography public key-private key pair may be an updated / reworked post-quantum cryptography public key-private key pair.

[0116] In some embodiments, a key encapsulation method (as described above) is used to generate a post-quantum cryptography public key-private key pair. In some embodiments, encryption includes ciphertext. For example, a key encapsulation method can be used to generate ciphertext based on the message to be sent and the post-quantum cryptography public key of the post-quantum cryptography public key-private key pair. In some embodiments, one or more of the post-quantum cryptography public key or the post-quantum cryptography private key is stored in a key library (e.g., a secure key library 148 hosted by the quantum edge computing entity 106). In some embodiments, one or more of the post-quantum cryptography public key or the post-quantum cryptography private key is shared with the second connection system.

[0117] In some embodiments, the process includes causing the encrypted message to be sent to the second connection system at step / operation 608. For example, the computing system 101 (e.g., via its quantum edge computing entity 106) may cause the encrypted message to be sent to the second connection system via a communication channel. In some embodiments, the communication channel may be an unsecured communication channel. In some embodiments, the encrypted message is configured to be decrypted using a post-quantum cryptography private key in a post-quantum cryptography public key-private key pair. In some embodiments, the computing system 101 (e.g., via the quantum service computing entity 108) provides the post-quantum cryptography private key to the second connection system to facilitate decryption of the encrypted message. In some embodiments, the first connection system is associated with an onboard flight management system on an aircraft, and the second connection system is associated with an air traffic control system.

[0118] in conclusion

[0119] Although an example processing system has been described above, specific implementations of the subject matter and functional operations described herein may be implemented in other types of digital electronic circuitry, or in computer software, firmware, or hardware (including the structures disclosed in this specification and their structural equivalents), or in a combination of one or more of them.

[0120] The embodiments of the themes and operations described herein may be implemented in digital electronic circuits, or in computer software, firmware, or hardware (including the structures disclosed in this specification and their structural equivalents), or in a combination of one or more thereof. The embodiments of the themes described herein may be implemented as one or more computer programs (i.e., one or more modules of computer program instructions) encoded on a computer storage medium for execution by an information / data processing device or for controlling the operation of an information / data processing device. Alternatively or additionally, the program instructions may be encoded on an artificially generated propagation signal (e.g., a machine-generated electrical signal, optical signal, or electromagnetic signal) that is generated to encode information / data to be sent to a suitable receiver device for execution by an information / data processing device. The computer storage medium may be a computer-readable storage device, a computer-readable storage substrate, a random access memory array or device, or a serial access memory array or device, or a combination of one or more thereof, or may be included in a computer-readable storage device, a computer-readable storage substrate, a random access memory array or device, or a serial access memory array or device, or a combination of one or more thereof. Furthermore, although a computer storage medium is not a propagated signal, a computer storage medium can be a source or destination of computer program instructions encoded in an artificially generated propagated signal. A computer storage medium can also be, or be included in, one or more separate physical components or media (e.g., multiple CDs, disks, or other storage devices).

[0121] The operations described herein may be implemented as operations performed by an information / data processing apparatus on information / data stored on one or more computer-readable storage devices or received from other sources.

[0122] The term "data processing apparatus" encompasses all kinds of apparatuses, devices, and machines for processing data, including, for example, a programmable processor, a computer, a system on a chip, or one or a combination of the foregoing. The apparatus may include dedicated logic circuitry, such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC). In addition to hardware, the apparatus may also include code that creates an execution environment for the computer program in question, such as code constituting processor firmware, a protocol stack, a repository management system, an operating system, a cross-platform runtime environment, a virtual machine, or a combination of one or more of these. The apparatus and execution environment may implement a variety of different computing model infrastructures, such as web services, distributed computing infrastructures, and grid computing infrastructures.

[0123] A computer program (also referred to as a program, software, software application, script, or code) can be written in any form of programming language (including compiled or interpreted languages, declarative languages, or procedural languages), and it can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program may, but need not, correspond to a file in a file system. A program may be stored in a portion of a file that holds other programs or information / data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program in question, or in multiple coordinated files (e.g., files storing one or more modules, subroutines, or portions of code). A computer program may be deployed to execute on a single computer, or on multiple computers located at one location or distributed across multiple locations and interconnected by a communications network.

[0124] The process and logic flow described herein can be performed by one or more programmable processors executing one or more computer programs to perform actions by operating on input information / data and generating output. For example, processors suitable for executing computer programs include any one or more processors of general-purpose microprocessors and special-purpose microprocessors and digital computers of any type. Generally speaking, the processor will receive instructions and information / data from a read-only memory or a random access memory or both. The basic element of a computer is a processor for performing actions according to instructions and one or more memories for storing instructions and data. Generally speaking, a computer will also include or be operably coupled to one or more mass storage devices (e.g., magnetic disks, magneto-optical disks or optical disks) for storing data, to receive information / data from the one or more mass storage devices or to transfer information / data to the one or more mass storage devices, or both. However, a computer does not need to have such devices. Devices suitable for storing computer program instructions and information / data include all forms of non-volatile memory, media, and storage devices, including, by way of example, semiconductor memory devices such as EPROM, EEPROM, and flash memory devices; magnetic disks, such as internal hard disks or removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The processor and memory can be supplemented by, or incorporated in, special purpose logic circuitry.

[0125] To provide for interaction with a user, embodiments of the subject matter described herein may be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information / data to the user, as well as a keyboard and a pointing device (e.g., a mouse or trackball through which the user can provide input to the computer). Other types of devices may be used to provide for interaction with the user; for example, feedback provided to the user may be any form of sensory feedback, such as visual feedback, auditory feedback, or tactile feedback; and input from the user may be received in any form, including acoustic input, voice input, or tactile input. In addition, a computer may interact with a user by transmitting documents to and receiving documents from a device used by the user; for example, by transmitting a web page to a web browser on a user's client device in response to a request received from the web browser.

[0126] Embodiments of the subject matter described herein can be implemented in a computing system that includes a back-end component (e.g., as an information / data server), or includes a middleware component (e.g., an application server), or includes a front-end component (e.g., a client computer with a graphical user interface or a web browser through which a user can interact with a specific implementation of the subject matter described herein), or any combination of one or more such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital information / data communication (e.g., a communication network). Examples of communication networks include local area networks ("LANs") and wide area networks ("WANs"), interconnections (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks).

[0127] The computing system may include a client and a server. The client and the server are usually remote from each other and typically interact through a communication network. The relationship between the client and the server is generated by means of computer programs running on respective computers that have a client-server relationship with each other. In some embodiments, the server sends information / data (e.g., an HTML page) to the client device (e.g., for the purpose of displaying information / data to a user interacting with the client device and receiving user input from the user interacting with the client device). The information / data generated at the client device (e.g., the result of the user interaction) can be received from the client device at the server.

[0128] Although this specification includes many specific implementation details, these details should not be interpreted as limiting the scope of any disclosed or claimable content, but rather as descriptions of features specific to a particular disclosed embodiment. Certain features described herein in the context of a separate embodiment may also be implemented in combination in a single embodiment. On the contrary, the various features described in the context of a single embodiment may also be implemented in multiple embodiments or in any suitable sub-combination. In addition, although features may be described above as working in certain combinations and even initially claimed as such, in some cases, one or more features from the claimed combination may be deleted from the combination, and the claimed combination may be directed to a sub-combination or a variation of the sub-combination.

[0129] Similarly, although operations are depicted in a particular order in the accompanying drawings, this should not be understood as requiring that such operations be performed in the particular order shown or in a sequential order, or that all of the illustrated operations be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Furthermore, the separation of various system components in the embodiments described above should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems may generally be integrated together in a single software product or grouped into multiple software products.

[0130] Thus, specific embodiments of the present subject matter have been described. Other embodiments are within the scope of the following claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the particular order or sequential order shown to achieve the desired results. In some implementations, multitasking and parallel processing may be advantageous.

Claims

1. A computer-implemented method for providing secure communications for a connected system, the computer-implemented method comprising: receiving an indication of a communication session associated with a first connection system; authenticating the first connected system based on an IAM policy; encrypting a message based on a post-quantum cryptography public key associated with the first connection system to generate an encrypted message; as well as The encrypted message is caused to be sent to the second connected system.

2. The computer-implemented method of claim 1 , further comprising: A post-quantum cryptography public key-private key pair is generated, comprising the post-quantum cryptography public key and the post-quantum cryptography private key.

3. The computer-implemented method of claim 2 , further comprising: The post-quantum cryptography private key is provided to the second connection system to facilitate decryption of the encrypted message.

4. The computer-implemented method of claim 2, wherein the post-quantum cryptography public-private key pair is generated using a key encapsulation method.

5. The computer-implemented method of claim 2, wherein the post-quantum cryptography public-private key pair is generated via a cloud-based quantum service computing entity.

6. The computer-implemented method of claim 5 , further comprising: One or more of the post-quantum cryptography public key or the post-quantum cryptography private key is stored in a key store.

7. The computer-implemented method of claim 6, wherein the key store is hosted by a quantum edge computing entity associated with a gateway network entity, wherein the quantum edge computing entity is communicatively coupled to the cloud-based quantum service computing entity.

8. The computer-implemented method of claim 1, wherein the encrypted message comprises ciphertext.

9. A computing system for providing secure communications for a connected system, the computing system comprising a memory and one or more processors communicatively coupled to the memory, the one or more processors configured to: receiving an indication of a communication session associated with a first connection system; authenticating the first connected system based on an IAM policy; encrypting a message based on a post-quantum cryptography public key associated with the first connection system to generate an encrypted message; as well as The encrypted message is caused to be sent to the second connected system.

10. One or more non-transitory computer-readable storage media for providing secure communications for a connected system, the one or more non-transitory computer-readable storage media comprising instructions that, when executed by one or more processors, cause the one or more processors to: receiving an indication of a communication session associated with a first connection system; authenticating the first connected system based on an IAM policy; encrypting a message based on a post-quantum cryptography public key associated with the first connection system to generate an encrypted message; as well as The encrypted message is caused to be sent to the second connected system.

Citation Information

Cited By

  • System and methods for persistently implementing post-quantum security via service workers

    US20250254032A1