Quantum-safe networking

A quantum-safe network using QKD and HSMs with distributed ledger technology addresses vulnerabilities to quantum computers by ensuring secure data storage and access, providing robust protection against cyber threats.

AU2020380554B2Pending Publication Date: 2026-07-16ARQIT LTD

Patent Information

Authority / Receiving Office
AU · AU
Patent Type
Applications
Current Assignee / Owner
ARQIT LTD
Filing Date
2020-11-06
Publication Date
2026-07-16

AI Technical Summary

Technical Problem

Current cryptographic systems are vulnerable to attacks from quantum computers, compromising key exchange protocols and rendering transactions and applications like digital banking and web certification insecure, necessitating a robust and cost-effective quantum-safe solution.

Method used

A quantum-safe network utilizing quantum key distribution (QKD) and hardware security modules (HSMs) with identical quantum distributed keys for secure communication, combined with distributed ledger technology for data storage and access, ensuring secure storage and retrieval of data items.

Benefits of technology

Provides a cost-effective and secure solution against quantum and advanced cyberattacks, enabling reliable data storage and access across various user types, including large organizations and individuals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000001_0000
    Figure 00000001_0000
  • Figure 00000168_0000
    Figure 00000168_0000
  • Figure 00000169_0000
    Figure 00000169_0000
Patent Text Reader

Abstract

Method(s), system(s), apparatus are provided for storing one or more data item(s) in a quantum-safe (QS) network. The QS network comprising one or more QS server(s) and a repository for storing and accessing said data item(s). Each QS server comprising a hardware security module (HSM) for storing an identical set of quantum distributed (QD) keys. The identical set of QD keys having been distributed to each of said QS server(s) in a quantum-safe manner. The QS server(s) are configured to communicate securely with each other and the repository using one or more available QD keys from the identical set of QD keys. A QS server performs generating a quantum reference (QREF) locator based on input data associated with a data item for storage and an available QD key selected from the set of QD keys, and sending the QREF locator along with the data item encrypted with the available QD key to the repository for storage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to a system and method for quantum-safe networking and applications thereto. 5 Background

[0002] Cryptography is used to protect billions of transactions every day from, without limitation, for example Transport Layer Security (TLS) security for online shopping and banking to ultra-secure government communications. These transactions rely on reliable and secure means for at least two or more transacting parties to share a secret key, enabling 10 encryption of data by one party and subsequent decryption by the other party(ies). When commercially usable universal quantum computers become available, a variety of these types of transactions, tasks and applications including, without limitation, for example digital banking, web certification, Know Your own Client (KYC), digital asset transfer, and authentication will be vulnerable, and some are already vulnerable to conventional cyber 15 attacks. These transactions, tasks and applications are currently provided using software systems that typically use conventional cryptography and / or encryption techniques and protocols that are not sufficiently resilient enough to withstand an attack from such quantum computers (QCs) or other advanced cyber attack methods.

[0003] QCs can potentially crack many classical cryptography codes almost effortlessly. 20 There has also been a ground swell in interest in quantum computing within the last year as a result of the success of D-Wave in selling commercial systems. Furthermore, a number of breakthroughs by technology companies such as, without limitation, for example Microsoft (RTM), IBM (RTM), Intel (RTM), Google (RTM) and others in QC techniques promise to make a universal QC viable in the near future (e.g. five to ten years time). QCs have already 25 become a threat to current, in 2016 NIST reported the impact of QCs on common cryptographic algorithms in a report by L. Chen, S Jordan, Y Liu, D Moody, R Peralta, Ray Perlner, D Smith-Tone, "Report on Post-Quantum Cryptography", NISTIR 8105, 2016 (https: / / nvlpubs.nist.gov / nistpubs / ir / 2016 / NIST.IR.8105.pdf). For example, NIST determined, without limitation, for example that the following public key cryptographic 30 algorithms used for digital signatures and / or key exchange are no longer secure including, without limitation, for example Finite Field Cryptography such as, without limitation, for example Digital Signature Algorithm (DSA); Elliptic Curve Cryptography such as, without limitation, for example ECDSA and ECDH, Elliptic curve Diffie Hellman ephemeral-Rivest / Shamir / Adelman (ECDHE-RSA), ECDHE-ECDSA; Rivest / Shamir / Adelman (RSA); 35 and other crypto. NIST also determined that the following hash-functions will require large 1 2020380554   25 May 2026 output or key sizes, without limitation, for example: Secure Hash Algorithm (SHA)-2 (384 bit) and SHA-3. NIST also determined that the following cryptographic algorithms may require larger key sizes, without limitation, for example Advanced Encryption Standard (AES) (256-bit) Galois Counter Mode (GCM) when used for encryption. 5

[0004] This means that cryptographic protocols using these cryptographic algorithms will be vulnerable and no longer secure. For example, such cryptographic protocols include, without limitation, for example, Transport Layer Security (TLS), https, Secure Sockets Layer (SSL), Secure Shell (SSH) used in, without limitation, for example searches, certification and / or banking applications and the like. For example, TLS using ECDHE-RSA, AES (128-bit) GCM 10 and SHA256 for searches / search engines will be broken or weakened. For example, TLS using ECDHE-RSA with AES (256-bit) GCM and SHA (384-bit) for banking applications and the like will be broken or weakened. It is estimated that server certificates, client certificates, and public key cryptography will be broken and insecure.

[0005] For example, current methods to exchange cryptographic keys between two parties 15 are vulnerable to QC attack. If the cryptographic primitives involved in the key-exchange protocol can be broken, the exchanged key is compromised and the encrypted data is revealed to the attacker. Classical key-exchange protocols are based on the hardness of integer factorization (e.g. Diffie-Hellman (DH)) or the discrete logarithm problem (e.g. Elliptic-Curve DH (ECDH)). Neither of these problems is guaranteed to be hard and both problems 20 can be broken by a QC in polynomial time. This is of particular concern to both large and small organisations, corporations and also to individual users of public and private networks (e.g. Internet or corporate Intranets). If one is unable to reliably perform key exchange, then all current transactions, tasks and applications are vulnerable to attack by a QC.

[0006] The field of “Quantum Cryptography” aims to address these risks by developing both 25 quantum secure cryptographic algorithms (so-called quantum-safe algorithms) and Quantum Key Distribution (QKD) techniques. Whilst the combination of both provides the ultimate solution, QKD as a stand-alone technique still has much to offer and is not in itself reliant on the development of quantum-safe algorithms to become widely adopted. However, even reliably performing QKD at scale for a wide range of users from small to large corporations 30 and / or individuals is still a costly and time consuming exercise.

[0007] There is a desire for a robust, secure and cost effective approach for providing a quantum-safe solutions for at least communications, storage and / or access of data items created for and generated by users performing, without limitation, for the above-mentioned communications, transactions, tasks and / or applications and / or, for that matter, any 2020380554   25 May 2026 communication data, transaction, task and / or application vulnerable to a QC attack. Such a solution also provides protection against advanced non-quantum cyberattacks.

[0008] It is desired to address or ameliorate one or more disadvantages or limitations associated with the prior art, provide a computer-implemented method of storing one or more 5 data item(s) in a quantum-safe "QS" network, or to at least provide the public with a useful alternative.

[0009] The embodiments described below are not limited to implementations which solve any or all of the disadvantages of the known approaches described above. Summary 10

[0010] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to determine the scope of the claimed subject matter; variants and alternative features which facilitate the working of the invention and / or serve to achieve a substantially 15 similar technical effect should be considered as falling into the scope of the invention disclosed herein.

[0011] The present disclosure provides systems, apparatus, mechanisms, methods and process(es) for combining a security layer via a QKD network with a data distribution layer for storing and distributing data or data items via a repository or storage management system 20 based on distributed ledger technology, shared ledger technology, cloud storage technologies, and / or centralised storage technologies for providing a quantum-safe or quantum resistant set of services, applications and use cases for a plurality of different types of users (e.g. customers, consumers, large organisations or corporation) in relation to verification, authenticity, authentication, value transfer, privacy, secure storage and / or secure 25 communication capabilities.

[0012] In a first aspect, the present disclosure provides a computer-implemented method of storing one or more data item(s) in a quantum-safe (QS) network, the QS network comprising one or more QS server(s) and a repository for storing and accessing said data item(s), each QS server comprising a hardware security module (HSM) for storing an identical set of 30 quantum distributed (QD) keys, said identical set of QD keys having been distributed to each of said QS server(s) in a quantum-safe manner, and said QS server(s) configured to communicate securely with each other and the repository using one or more available QD keys from the identical set of QD keys, the method performed by a QS server comprising: generating a quantum reference "QREF" locator based on input data associated with a data 2020380554   25 May 2026 item for storage and an available QD key selected from the set of QD keys; and sending the QREF locator along with the data item encrypted with the available QD key to the repository.

[0013] Preferably, the method further comprising: selecting an available QD key from the set of QD keys for encrypting a data item; generating the QREF locator for storing and accessing 5 the data item based on input data associated with the data item and the selected available QD key, wherein the generated QREF locator is unique; linking the QREF locator to the available QD key of the set of QD keys; and sending the QREF locator and encrypted data item to the repository for storage, wherein the encrypted data item is linked to the QREF locator when stored. 10

[0014] Preferably, the method further comprising receiving a set of QD keys using quantum safe key distribution from a quantum key distributor or source.

[0015] Preferably, the input data associated with the data item further comprises one or more input data from the group of: a device identifier; a manufacturer identifier; a user identifier; a user secret; a customer number; and an access control list of users for accessing 15 said data item.

[0016] Preferably, the method further comprising: generating a QREF access token associated with the data item based on the QREF locator; and sending the QREF access token to a device of a user associated with the data item.

[0017] Preferably, the method further comprising: generating a QREF access token for 20 accessing the data item based on the QREF locator using an irreversible function, process or operation, wherein the QREF access token is unique; and sending the QREF access token to a device of a user for enabling the user to access said data item.

[0018] Preferably, the method further comprising: receiving, from a device of a user, a QREF access token requesting access to a data item stored in the repository; identifying a 25 QREF locator based on the QREF access token and input data from the user; and in response to identifying the QREF locator, performing the steps of: retrieving the data item from the repository, wherein the data item is decrypted using the QD key corresponding to the QREF locator; and providing access operations to the user in relation to the decrypted data item. 30

[0019] In a second aspect, the present disclosure provides a computer-implemented method of quantum safe (QS) storage in a QS network, the QS network comprising at least two QS servers and a repository for storing and accessing data items in relation to a plurality of users, wherein each QS server comprises a hardware security module "HSM" with an 2020380554   25 May 2026 identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys, the method comprising: generating a quantum reference (QREF) locator associated with a data item based on input 5 data associated with a first user of the plurality of users and an available QD key selected from the set of QD keys; and storing the data item encrypted with the available QD key in the repository indexed with the QREF locator.

[0020] Preferably, further comprising: generating an QREF access token based on the QREF locator, wherein the QREF access token enables access operations to be performed 10 on the data item stored in the repository; sending the QREF access token to at least said first user of the plurality of users; and in response to receiving an QREF access token from a second user of the plurality of users in relation to a data item stored in the repository performing the steps of: identifying a QREF locator in relation to the access token, and said second user; and providing access operations in relation to the encrypted data item in the 15 repository based on the identified QREF locator and the identified said second user.

[0021] In a third aspect, the present disclosure provides a computer-implemented method of quantum safe (QS) storage and retrieval in a QS network, the QS network comprising one or more QS server(s) and a repository for storing and retrieving one or more data item(s) by a plurality of users, wherein each QS server comprises a hardware security module (HSM) with 20 an identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys, the method performed by a QS server comprising: in response to receiving a data item for storage: generating a quantum reference "QREF" locator based on a user secret of the first user and an available QD key 25 selected from the set of QD keys, wherein the QREF locator indicates the location for storing the data item encrypted with the selected QD key in the repository and an identity of the first user; generating an QREF access token based on the QREF locator, wherein the QREF access token enables access operations to be performed on the data item when stored in the repository; storing the data item in the repository indexed by the QREF locator; and sending 30 the QREF access token to the first user; and in response to receiving an QREF access token for a data item stored in the repository: identifying a QREF locator based on the QREF access token and the identity of the second user; and providing access operations to the second user in relation to the encrypted data item in the repository based on the identified QREF locator. 35

[0022] Preferably, the first, second and third aspects further comprising receiving a request for storing the data item by a first user. 2020380554   25 May 2026

[0023] Preferably, the first user and the second user are the same.

[0024] Preferably, the first user and the second user are different.

[0025] Preferably, the first, second and third aspects, wherein the QS network further comprises one or more user devices, each user device comprising a hardware security 5 module for storing a set of QD keys, wherein the one or more user devices and one or more of the QS servers communicate using quantum key encryption based on the set(s) of QD keys.

[0026] Preferably, the first, second and third aspects, wherein the repository comprises a repository or storage system based on at least one from the group of: distributed ledger 10 technology or network; shared ledger technology or network; blockchain technology or network; publish / subscribe, response / request and / or real-time based digital storage cloud / repository technology; any other secure cloud storage system or platform; any other secure storage system or platform; and any other secure database management system.

[0027] Preferably, each set of QD keys are distributed to each of the QS devices based on 15 at least one from the group of: satellite quantum key distribution; fibre optic quantum key distribution; terrestrial quantum key distribution; optical quantum key distribution; and any other quantum key distribution system capable of distributing an identical set of QD keys to each of the QS server(s) of the QS network.

[0028] Preferably, generating the QREF locator further comprising: receiving a user secret 20 from a device of a first user; receiving an available QD key selected from the set of QD keys from one of the QS server(s); and generating the QREF locator based on a first set of cryptographic or mathematical operations in relation to data representative of the user secret and the received QD key, wherein the QREF locator is unique.

[0029] Preferably, generating the QREF access token further comprising generating the 25 QREF access token based on a second set of cryptographic or mathematical operations in relation to data representative of the QREF locator, wherein the QREF access token is unique.

[0030] Preferably, generating the QREF locator based on the first set of cryptographic or mathematical operations further comprises generating the QREF locator from data 30 representative of the user secret and the received QD key based on any one or more cryptographic or mathematical operations from the group of: one or more one-way functions; one or more hash functions; one or more hash-based message authentication code functions; one or more key derivation functions; one or more of multiplication, subtraction, 2020380554   25 May 2026 addition, division, factorisation and / or any other mathematical operation; any other combination of one or more cryptographic functions, mathematical operations, operable to generate data representative of a QREF locator that is unique, obfuscates the received QD key and user secret and capable of providing an address for locating the associated data 5 item for storing in a repository.

[0031] Preferably, generating the QREF access token based on the second set of cryptographic or mathematical operations further comprises generating the QREF access token from data representative of the QREF locator based on any one or more cryptographic or mathematical operations from the group of: one or more one-way functions; one or more 10 hash functions; one or more hash-based message authentication code functions; one or more key derivation functions; one or more of multiplication, subtraction, addition, division, factorisation and / or any other mathematical operation; any other combination of one or more cryptographic functions, mathematical operations, operable to generate data representative of an QREF access token that is unique, obfuscates the data representative of the QREF 15 locator, and capable of being used by a QS server to identify the QREF locator for providing an address for locating the associated data item stored in a repository.

[0032] Preferably, the method(s) further comprising: receiving an QREF access token from a user; identifying the QREF locator associated with the QREF access token; and in response to identifying the QREF locator, performing one or more access operations in 20 relation to the data item corresponding to the QREF locator stored in the repository and the QREF access token.

[0033] Preferably, the method(s) further comprising: storing a registration record of each user storing a data item in the repository, wherein each registration record includes data representative of: a user identity of said each user; a user secret of said each user; 25 authentication challenges and responses; the QREF locator associated with the data item; a data item reference identifier associated with the data item; a quantum key identifier associated with the QD key used to encrypt the data item; and an access control list associated with the data item; receiving an QREF access token associated with a data item from a second user; retrieving one or more registration records associated with the second 30 user; identifying the QREF locator associated with the QREF access token by: generating, for each retrieved registration record, an QREF access token based on said each retrieved registration record; and matching the generated QREF access token with the received QREF access token; and identifying the QREF locator from the registration record associated with the generated QREF access token matching the received QREF access token; in response 35 to identifying the QREF locator, performing one or more access operations in relation to the 2020380554   25 May 2026 data item corresponding to the QREF locator stored in the repository and the QREF access token.

[0034] Preferably, the first, second and third aspects, the QS network comprising one or more QS registration server(s) and a plurality of registration nodes, wherein a QS registration 5 server connects to a set of registration nodes of the plurality of registration nodes, and one or more QS server(s) distribute one or more groups of QD keys from the set of QD keys to the QS registration servers, each QS registration server distributing one or more QD keys from a group of QD keys to the corresponding set of registration nodes, the method(s) further comprising: receiving, from a QS registration server generating a registration record 10 associated with a user, the registration record of the user, wherein a device of the user is in communication with a registration node coupled to the QS registration server, the registration record including one or more user data representative of: a user identity of said each user; one or more device identifiers associated with the user; user credentials associated with logging into the QS system; a user secret of said each user; authentication challenges and 15 responses; a QREF locator associated with a data item in relation to the user; a data item reference identifier associated with the data item; a QD key identifier associated with the QD key used to encrypt the data item; and an access control list associated with the data item; and storing the registration record of said user in the repository.

[0035] Preferably, the method(s) further comprising: receiving user credentials from a QS 20 registration server associated with a user, wherein a device of the user is in communication with a registration node coupled to the QS registration server; retrieving the registration record associated with the user based on the user credentials; receiving a QREF access token associated with a data item from the user; identifying the QREF locator associated with the QREF access token by: generating, for each retrieved registration record, an QREF 25 access token based on said each retrieved registration record; and matching the generated QREF access token with the received QREF access token; and identifying the QREF locator from the retrieved registration record associated with the generated QREF access token matching the received QREF access token; in response to identifying the QREF locator, performing one or more access operations in relation to the data item corresponding to the 30 QREF locator stored in the repository and the QREF access token.

[0036] Preferably, the repository further comprises a distributed ledger; the QS network further comprising a plurality of QS servers, each QS server comprises a HSM with an identical set of QD keys stored thereon and each QS server of the plurality of QS servers comprising a node for operating the distributed ledger, wherein the nodes of the plurality of 35 QS servers form a QS distributed ledger network configured for providing storage and access to one or more data item(s) stored on the distributed ledger, wherein the method further 2020380554   25 May 2026 comprising: receiving a QREF locator for storing an encrypted data item in the distributed ledger; and storing the encrypted data item in the distributed ledger using the QREF locator as an address for the location of the encrypted data item in the distributed ledger.

[0037] Preferably, wherein: the repository further comprises a shared ledger; the QS 5 network further comprising a plurality of QS servers, each QS server comprises a HSM with an identical set of QD keys stored thereon and each QS server of the plurality of QS servers comprising a node for operating the shared ledger between corresponding nodes, wherein the nodes of the plurality of QS servers form a QS shared ledger network configured for providing storage and access to one or more data item(s) stored on the shared ledger, 10 wherein the method(s) further comprising: receiving a QREF locator for storing the encrypted data item in the shared ledger; and storing the encrypted data item in the shared ledger using the QREF locator as an address for the location of the encrypted data item in the shared ledger.

[0038] Preferably, the method(s) further comprising: receiving an QREF access token from 15 the second user for accessing an encrypted data item stored in the distributed or shared ledger; identifying a QREF locator corresponding to the QREF access token and second user; and accessing the encrypted data item in the distributed or shared ledger using the identified QREF locator based on the access token.

[0039] Preferably, the repository further comprises a digital storage platform using 20 publish / subscribe, request / response and / or real-time based messaging for storing and accessing data items, the QS network further comprising a plurality of QS servers, each QS server comprises a HSM with an identical set of QD keys stored thereon and each QS server of the plurality of QS servers comprising a node for operating digital storage platform messaging between corresponding nodes, wherein the nodes of the plurality of QS servers 25 form the digital storage platform as a QS distributed storage network configured for providing storage and access to one or more data item(s) based on the digital storage platform messaging, wherein the method(s) further comprising: receiving a QREF locator for storing the encrypted data item in the distributed storage platform; and storing the encrypted data item in the shared ledger using the QREF locator as an address for the location of the 30 encrypted data item in the distributed storage platform.

[0040] Preferably, the method(s) further comprising: receiving an QREF access token from the second user for accessing an encrypted data item stored in the distributed storage platform, identifying a QREF locator corresponding to the QREF access token and second user; and accessing the encrypted data item in the distributed storage platform using the 35 identified QREF locator based on the access token. 2020380554   25 May 2026

[0041] Preferably, each QS server comprises a satellite receiver, the method(s) further comprising: receiving, at each of the one or more QS servers of the QS network, one or more sets of QD keys from a satellite quantum key distribution system, the satellite quantum key distribution system comprising at least one satellite configured for generating and distributing 5 a set of QD keys; and storing, on each of the one or more QS servers of the QS network, the received set(s) of QD keys on the corresponding hardware security module, wherein after distribution of a set of QD keys to each of the QS servers, each of the QS servers has stored thereon an identical set of QD keys.

[0042] Preferably, the QS network further comprises one or more user devices, each user 10 device comprising a HSM for storing a set of QD keys, wherein the one or more user devices and one or more of the QS servers communicate using quantum key encryption based on the set(s) of QD keys, wherein each QS user device comprises a satellite receiver, the method further comprising: receiving, at one or more of the user devices, one or more sets of QD keys from the satellite quantum key distribution system, the satellite quantum key distribution 15 system comprising at least one satellite configured for generating and distributing the one or more sets of QD keys; and storing, on each of the one or more QS user devices of the QS network, the received set(s) of QD keys on the corresponding HSM, wherein after distribution of said one or more sets of QD keys to each of the QS user devices, each of the QS user devices has stored thereon an identical set of QD keys. 20

[0043] Preferably, each QS server of the QS network includes a hardware security module (HSM) for storing a set of QD keys, wherein each of the QD keys in the set of QD keys is mapped to a corresponding QD key identifier and stored in the HSM based on data representative of: the QD key identifier for identifying said each QD key; and said each QD key; wherein each set of QD keys stored on each of the QS servers of the QS network have 25 identical mappings between the QD key identifier and each said QD key from the set of QD keys, the method further comprising: receiving a set of QD keys from a quantum key distribution system, each QD key of the set of QD keys mapped to a corresponding QD key identifier; and storing data representative of the set of QD keys and corresponding QD key identifiers. 30

[0044] Preferably, data representative of a mapping of a QREF locator associated with a QD key is stored in the HSM, based on data representative of: the QREF locator; the QD key associated with the QREF locator; and the QD key identifier identifying said selected QD key; wherein each set of QD keys stored on an HSM of each of the QS servers of the QS network are updated based on the data representative of the mapping between the QD key identifier, 35 the QREF locator and corresponding QD key, the method further comprising: receiving a QREF locator and a QD key identifier associated with a QD key, the QD key selected from 2020380554   25 May 2026 the set of QD keys for use in generating the QREF locator and encrypting an associated data item; and storing data representative of the mapping between the QREF locator, QD key identifier and QD key in the HSM of a QS server.

[0045] Preferably, the repository further comprises a plurality of records for storing one or 5 more encrypted data item(s), each record comprising data representative of: a QREF locator associated with an encrypted data item; and the encrypted data item, wherein the data item is encrypted with a QD key associated with the QREF locator.

[0046] Preferably, each record further comprising data representative of: one or more user identities allowed to access the encrypted data item of said each record; and one or more 10 permissions or operations associated with each of the one or more user identities in relation to accessing said encrypted data item.

[0047] Preferably, each record further comprising data representative of an access control list indicating one or more user identities allowed to access the encrypted data item and corresponding permissions and / or operations in relation to each user identity accessing said 15 encrypted data item.

[0048] Preferably, the QREF locator further comprises data representative of: the user secret; a customer number allocated to the user; a data item reference identifier allocated to the data item; and a QD key identifier of the available QD key of the set of QD keys used to encrypt the data item. 20

[0049] Preferably, the QREF locator further comprises data representative of: a user identifier; and an access control list to the data item.

[0050] Preferably, the method(s) comprising: receiving a request to register a user; authenticating the user; receiving user details for registering the user with the QS network in response to positive authentication of the user; receiving a data item from the user for storing 25 in a QS repository of the QS network; generating a unique QREF locator based data representative of the received user details and the data item; associating the generated QREF locator with the registered user details and also the data item; generating a unique QREF access token based on data representative of the QREF locator associated with the data item; storing the QREF locator and the data item in the QS repository of the QS 30 network; and sending the unique QREF access token to the user for use in accessing, in some manner, the data item.

[0051] Preferably, the method(s) further comprising: receiving an QREF access token associated with a data item from a user; authenticating the user; identifying the QREF locator 2020380554   25 May 2026 based on the user registration details and the access token in relation to the user; retrieving the data item associated with the QREF locator from the QS repository; checking the user has permissions to access the data item based on an access control list associated with the data item; and enabling the user access operations to the data item in response to 5 determining the user has permissions to access the data item.

[0052] Preferably, the method(s) comprising: receiving a request to register a user; authenticating the user; receiving user details for registering the user with the QS network in response to positive authentication of the user; receiving a know your own client "KYC" data item from the user for storing in a QS repository of the QS network, the KYC data item 10 including data representative of know your own client details of the user; generating a unique QREF locator based data representative of the received user details and the KYC data item; associating the generated QREF locator with the registered user details and also the KYC data item; generating a unique QREF access token based on data representative of the QREF locator corresponding to the KYC data item and the KYC data item; storing the QREF 15 locator and the KYC data item in the QS repository of the QS network; and sending the unique KYC QREF access token to the user for use in providing KYC data of the user to one or more service providers.

[0053] Preferably, the method(s) further comprising: receiving an QREF access token associated with a data item from a user; authenticating the user; identifying the QREF locator 20 based on the user registration details and the access token; retrieving the data item associated with the QREF locator from the QS repository; checking the user has permissions to access the data item based on an access control list associated with the data item; and enabling the user access to the data item in response to determining the user has permissions to access the data item. 25

[0054] Preferably, the method(s) comprising: receiving a request to register a user; authenticating the user; receiving user details for registering the user with the QS network in response to positive authentication of the user; receiving a certificate data item from the user for storing in a QS repository of the QS network, the certificate data item including data representative of a web certificate for certifying the trustworthiness of a website operated by 30 the user; generating a unique QREF locator based data representative of the received user details and the certificate data item; associating the generated QREF locator with the registered user details and also the certificate data item; generating a unique QREF access token based on data representative of the QREF locator corresponding to the certificate data item and the certificate data item; storing the QREF locator and the certificate data item in the 35 QS repository of the QS network; and sending the unique certificate QREF access token to 2020380554   25 May 2026 the user for use by the website in providing the certificate QREF access token to web browsers of users visiting the website.

[0055] Preferably, the method(s) further comprising: receiving an certificate QREF access token associated with a certificate data item from a web browser of a user; identifying the 5 QREF locator associated with the certificate data item based on certificate data within the certificate QREF access token and the user registration data associated with the certificate access token; retrieving the certificate data item associated with the QREF locator from the QS repository; checking the certificate data item matches the received certificate details of the received certificate access token; and confirming to the web browser of the user that the 10 certificate QREF access token is valid in response to the received certificate details matching the corresponding details of the certificate data item.

[0056] Preferably, the certificate data item is based on data representative of X509 standard and beyond certificates.

[0057] Preferably, the method(s) comprising: establishing QS communication channel with a 15 first device of a first user; receiving, from the first device, a QREF access token associated with a QD key selected from the set of QD keys, the QD key for use in QS communications with a second device of a second user; retrieving the QD key selected from the set of QD keys from the repository based on the received QREF access token; sending the retrieved QD key to the first device and a second device for use in QS communications therebetween. 20

[0058] Preferably, the method(s) comprising: establishing a first communication channel with a first device of a first user; receiving, from the first device, a request for communicating with a second device of a second user via the QS network; establishing a second communication channel with the second device of the second user; receiving a response from the second device of the second user to connect with the first device of the first user; 25 establishing a QS communication channel through the QS network based on an available QD Key selected from the set of QD keys; connecting the first device of the first user with the second device of the second user via a communication path comprising the first communication channel, the QS communication channel and the second communication channel. 30

[0059] Preferably, the first device has a first QD key from the set of QD keys stored thereon for QS communications with the QS network, and the second device has a second QD key stored thereon for QS communications with the QS network, and wherein: the first communication channel is a first QS communication channel connecting the QS network with the first device using the first QD key; the second communication channel is a second QS 2020380554   25 May 2026 communication channel connecting the QS network with the second device using the second QD key.

[0060] Preferably, a first device has a first QD key from the set of QD keys stored thereon for QS communications with the QS network, and a second device has a second QD key 5 stored thereon for QS communications with the QS network, the method(s) further comprising: establishing a first QS communication channel with the first device using the first QD key; receiving, from the first device, the request for QS communications with the second device; establishing a second QS communication channel with the second device using the second QD key; receiving, from the second device, a response to establish QS 10 communications with the first device; allocating a QD key from the set of QD keys for QS communications between the first and second device; and sending via the established first and second QS channels the third QD key to the first and second device, respectively, for use in QS communications therebetween.

[0061] Preferably, the method(s) further comprising registering a device for use with the QS 15 network, wherein registering the device further comprising: connecting with the device over a direct wired connection with a QS server of the QS network; selecting an available QD key from the set of QD keys for use by the device; uploading the selected QD key to secure storage of the device via the direct wired connection; and storing and registering an association between the device and the available QD key in the repository of the QS network. 20

[0062] Preferably, the method(s) further comprising registering a user with the QS network, wherein registering the user further comprising: associating the user with a device registered for use with the QS network; and storing and registering the association between the user and the registered device in the repository of the QS network.

[0063] Preferably, the method(s) further comprising: registering the first user with the QS 25 network and associating the first user with the first device; and registering the second user with the QS network and associating the second user with the second device.

[0064] Preferably, the method(s) further comprising: assigning a further QD key from the set of QD keys for use in QS communications between the first device and the second device, wherein the further QD key is to be stored as a QD key data item in the QS repository; 30 generating a QREF locator associated with the QD key data item and an available QD key for encrypting the QD key data item; generating a QREF access token associated with the QD key data item based on the QREF locator; linking the QREF locator with the available QD key; associating the QREF locator with the registrations of the first user and the second user to form a communication pair; storing the QD key data item encrypted with the available QD 2020380554   25 May 2026 key in the QS repository with the QREF locator; and sending the QREF access token to the first device and the second device for use in QS communications therebetween.

[0065] Preferably, the method(s) further comprising: selecting an available QD key for forming a communication pair between the first and second device; and storing the available 5 QD key as a QD key data item for use when the first and second device request QS communication therebetween.

[0066] Preferably, the method(s) further comprising: in response to storing a QK key data item associated with a communication pair between a first device and a second device: generating a quantum reference "QREF" locator based on a user secret of the first and 10 second users and an available QD key selected from the set of QD keys for encrypting the QD key data item, wherein the QREF locator indicates the location of the QD Key data item encrypted with the selected QD key in the repository; generating an QREF access token based on the QREF locator, wherein the QREF access token enables access operations to be performed on the QD key data item stored in the repository; providing the QREF locator to 15 the repository for storing the encrypted QD key data item in the repository; and sending the QREF access token to the first device of the first user and the second device of the second user; and in response to receiving a request for accessing the QD Key data item from the repository by the first or the second user: receiving an QREF access token from the first user or the second user; identifying a QREF locator based on the QREF access token and the 20 identity of the first user or the second user; and providing access to the encrypted QD key data item in the repository to the first user or the second user in response to identifying the QREF locator.

[0067] Preferably, the method(s) further comprising: establishing a first QS communication channel with the first device using the first QD key; receiving, from the first device, a QREF 25 access token corresponding to a QD key data item associated with a communication pair between the first user and the second user; identifying the QREF locator associated with the QREF access token based on the communication pair between the first and second users; providing access to a decrypted QD key data item in the repository via the first QS communication channel with the first device of the first user in response to identifying the 30 QREF locator; establishing a second QS communication channel with the second device of the second user using the second QD key; receiving, from the second device, a QREF access token corresponding to a QD key data item associated with a communication pair between the first user and the second user; identifying the QREF locator associated with the QREF access token based on the communication pair between the first and second users; 35 and providing access to a decrypted QD key data item in the repository via the second QS 2020380554   25 May 2026 communication channel with the second device of the second user in response to identifying the QREF locator.

[0068] In a fourth aspect, the present disclosure provides a computer-implemented method of quantum safe (QS) storage and retrieval in a QS network, the QS network comprising one 5 or more QS server(s) and a repository for storing and retrieving one or more data item(s) by a plurality of users, wherein each QS server comprises a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys, the method performed by an end- 10 point device of a user comprising: sending a data item for storage in a repository of the QS network, wherein a QS server is configured, in response to receiving the data item, to: generate a quantum reference "QREF" locator based on a user secret of the user and an available QD key selected from the set of QD keys, wherein the QREF locator indicates the location for storing the data item encrypted with the selected QD key in the repository and an 15 identity of the user; generate a QREF access token based on the QREF locator, wherein the QREF access token enables access operations to be performed on the data item when stored in the repository; store the data item in the repository indexed by the QREF locator; and send the QREF access token to the end-point device of the user; and receiving a QREF access token corresponding to the data item stored in the repository; storing the QREF 20 access token for use in accessing the data item stored in the QS system.

[0069] In a fifth aspect, the present disclosure provides a computer-implemented method of quantum safe (QS) storage and retrieval in a QS network, the QS network comprising one or more QS server(s) and a repository for storing and retrieving one or more data item(s) by a plurality of users, wherein each QS server comprises a hardware security module (HSM) with 25 an identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys, the method performed by an endpoint device of a user comprising: receiving a QREF access token corresponding to a data item stored in the repository of the QS system, wherein a QS server is configured, in 30 response to receiving the data item, to: generate a quantum reference (QREF) locator based on a user secret of a user submitting the data item and an available QD key selected from the set of QD keys, wherein the QREF locator indicates the location for storing the data item encrypted with the selected QD key in the repository and an identity of the user submitting the data item; generate a QREF access token based on the QREF locator, wherein the 35 QREF access token enables access operations to be performed on the data item when stored in the repository; sending the QREF access token corresponding to the data item stored in the repository and user credentials to the QS system, wherein a QS server is 16 2020380554   25 May 2026 configured, in response to receiving the QREF access token, to: identify a QREF locator based on the QREF access token and the identity of the user; and receiving access in relation to the data item stored in the QS system when the QS server identifies the QREF locator. 5

[0070] In a sixth aspect, the present disclosure provides an apparatus comprising a processor unit, a memory unit and a communication interface, the processor unit connected to the memory unit and the communication unit, wherein the apparatus is configured to implement the computer-implemented method according to any of the first, second, third, fourth and / or fifth aspects, one or more features thereof, one or more features herein, 10 combinations thereof, modifications thereto and / or as described herein.

[0071] In a seventh aspect, the present disclosure provides a computer-readable medium comprising code or computer instructions stored thereon, which when executed by a processor unit, causes the processor unit to perform the computer-implemented method according to any of the first, second, third, fourth and / or fifth aspects, one or more features 15 thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[0072] In a eighth aspect, the present disclosure provides an end-point device comprising a processor unit, a memory unit and a communication interface, the processor unit connected to the memory unit and the communication unit, wherein the apparatus is configured to 20 implement the computer-implemented method according to any of the fourth and / or fifth aspects, one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[0073] In a ninth aspect, the present disclosure provides a computer-readable medium comprising code or computer instructions stored thereon, which when executed by a 25 processor unit, causes the processor unit to perform the computer-implemented method according to any of the fourth and / or fifth aspects, one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[0074] In a tenth aspect, the present disclosure provides a QS system comprising: a QS network comprising at least two QS servers according to the sixth aspect, each of the QS 30 servers comprising a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon; a plurality of users with end-point devices according to eighth aspect; and a repository for storing and accessing data items associated with users of the end-point devices; wherein the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the 35 set of QD keys. 17 2020380554   25 May 2026

[0075] In a eleventh aspect, the present disclosure provides a computer-implemented method of quantum safe (QS) communication between a first device and a second device using a QS network, the QS network comprising at least two QS servers and a repository for storing and accessing data items associated with users of the first and second devices, 5 wherein each QS server comprises a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys, the method comprising: establishing QS communication channel with the first device of a first user; receiving, from the first device, a QREF access 10 token associated with a QD key selected from the set of QD keys, the QD key for use in QS communications with a second device of a second user; retrieving the QD key selected from the set of QD keys from the repository based on the received QREF access token; sending the retrieved QD key to the first and second devices for use in QS communications therebetween. 15

[0076] In a twelfth aspect, the present disclosure provides a computer-implemented method of quantum safe (QS) communication between a first device and a second device using a QS network, the QS network comprising at least two QS servers and a repository for storing and accessing data items associated with users of the first and second devices, wherein each QS server comprises a hardware security module (HSM) with an identical set of quantum 20 distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys, the method comprising: establishing a first communication channel with a first device of a first user; receiving, from the first device, a request for communicating with a second device of a second user via the QS network; establishing a second 25 communication channel with the second device of the second user; receiving a response from the second device of the second user to connect with the first device of the first user; establishing a QS communication channel through the QS network based on an available QD Key selected from the set of QD keys; connecting the first device of the first user with the second device of the second user via a communication path comprising the first 30 communication channel, the QS communication channel and the second communication channel.

[0077] Preferably, the first device has a first QD key from the set of QD keys stored thereon for QS communications with the QS network, and the second device has a second QD key stored thereon for QS communications with the QS network, and wherein: the first 35 communication channel is a first QS communication channel connecting the QS network with the first device using the first QD key; the second communication channel is a second QS 2020380554   25 May 2026 communication channel connecting the QS network with the second device using the second QD key.

[0078] Preferably, the first device has a first QD key from the set of QD keys stored thereon for QS communications with the QS network, and the second device has a second QD key 5 stored thereon for QS communications with the QS network, the method further comprising: establishing a first QS communication channel with the first device using the first QD key; receiving, from the first device, the request for QS communications with the second device; establishing a second QS communication channel with the second device using the second QD key; receiving, from the second device, a response to establish QS communications with 10 the first device; allocating a QD key from the set of QD keys for QS communications between the first and second device; and sending via the established first and second QS channels the third QD key to the first and second device, respectively, for use in QS communications therebetween.

[0079] Preferably, the method further comprising registering a device for use with the QS 15 network, wherein registering the device further comprising: connecting with the device over a direct wired connection with a QS server of the QS network; selecting an available QD key from the set of QD keys for use by the device; uploading the selected QD key to secure storage of the device via the direct wired connection; and storing and registering an association between the device and the available QD key in the repository of the QS network. 20

[0080] Preferably, method further comprising registering a user with the QS network, wherein registering the user further comprising: associating the user with a device registered for use with the QS network; and storing and registering the association between the user and the registered device in the repository of the QS network.

[0081] Preferably, the method further comprising: registering the first user with the QS 25 network and associating the first user with the first device; and registering the second user with the QS network and associating the second user with the second device.

[0082] Preferably, the method further comprising: assigning a further QD key from the set of QD keys for use in QS communications between the first device and the second device, wherein the further QD key is to be stored as a QD key data item in the QS repository; 30 generating a QREF locator associated with the QD key data item and an available QD key for encrypting the QD key data item; generating a QREF access token associated with the QD key data item based on the QREF locator; linking the QREF locator with the available QD key; associating the QREF locator with the registrations of the first user and the second user to form a communication pair; storing the QD key data item encrypted with the available QD 2020380554   25 May 2026 key in the QS repository with the QREF locator; and sending the QREF access token to the first device and the second device for use in QS communications therebetween.

[0083] Preferably, the method further comprising: selecting an available QD key for forming a communication pair between the first and second device; and storing the available QD key 5 as a QD key data item for use when the first and second device request QS communication therebetween.

[0084] Preferably, the method further comprising: in response to storing a QK key data item associated with a communication pair between a first device and a second device; generating a quantum reference (QREF) locator based on a user secret of the first and second users 10 and an available QD key selected from the set of QD keys for encrypting the QD key data item, wherein the QREF locator indicates the location of the QD Key data item encrypted with the selected QD key in the repository; generating an QREF access token based on the QREF locator, wherein the QREF access token enables access operations to be performed on the QD key data item stored in the repository; providing the QREF locator to the repository 15 for storing the encrypted QD key data item in the repository; and sending the QREF access token to the first device of the first user and the second device of the second user; and in response to receiving a request for accessing the QD Key data item from the repository by the first or the second user: receiving an QREF access token from the first user or the second user; identifying a QREF locator based on the QREF access token and the identity of 20 the first user or the second user; and providing access to the encrypted QD key data item in the repository to the first user or the second user in response to identifying the QREF locator.

[0085] Preferably, the method further comprising: establishing a first QS communication channel with the first device using the first QD key; receiving, from the first device, a QREF access token corresponding to a QD key data item associated with a communication pair 25 between the first user and the second user; identifying the QREF locator associated with the QREF access token based on the communication pair between the first and second users; providing access to a decrypted QD key data item in the repository via the first QS communication channel with the first device of the first user in response to identifying the QREF locator; establishing a second QS communication channel with the second device of 30 the second user using the second QD key; receiving, from the second device, a QREF access token corresponding to a QD key data item associated with a communication pair between the first user and the second user; identifying the QREF locator associated with the QREF access token based on the communication pair between the first and second users; and providing access to a decrypted QD key data item in the repository via the second QS 35 communication channel with the second device of the second user in response to identifying the QREF locator. 2020380554   25 May 2026

[0086] In a thirteenth aspect, the present disclosure provides a computer-implemented method of quantum safe (QS) communication between a first device and a second device using a QS network, the QS network comprising at least two QS servers and a repository for storing and accessing data items associated with users of the first and second devices, 5 wherein each QS server comprises a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys, the method performed by the first device comprising: establishing a first QS communication channel with a first QS server of the QS network; 10 transmitting a QREF access token associated with a QD key selected from the set of QD keys for use in QS communications with a second device of a second user; receiving the retrieved QD key from the QS server for use in QS communications with the second device therebetween; establishing a third QS communication channel with the second device of the second user based on the received QD key, wherein, prior to establishing the third QS 15 communication channel, the second device receives the retrieved QD key by establishing a second QS communication channel with a second QS server of the QS network and transmitting the QREF access token corresponding to the QD key.

[0087] In fourteenth aspect, the present disclosure provides a computer-implemented method of quantum safe (QS) communication between a first device and a second device 20 using a QS network, the QS network comprising at least two QS servers and a repository for storing and accessing data items associated with users of the first and second devices, wherein each QS server comprises a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available 25 QD keys from the set of QD keys, the method performed by the first device comprising: establishing a first communication channel with a first QS server of the QS network; transmitting, to the first QS server, a request for communicating with a second device of a second user; establishing a second communication channel with the second device of the second user; receiving a response from the second device of the second user to connect with 30 the first device of the first user; establishing a QS communication channel through the QS network based on an available QD Key selected from the set of QD keys; communicating with the second device of the second user based on a communication path comprising the first communication channel, a QS communication channel through the QS network and a second communication channel between the second device and the QS network. 35

[0088] In a fifteenth aspect, the present disclosure provides a computer-implemented method of quantum safe (QS) communication between a first device and a second device using a QS network, the QS network comprising at least two QS servers and a repository for 21 2020380554   25 May 2026 storing and accessing data items associated with users of the first and second devices, wherein each QS server comprises a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available 5 QD keys from the set of QD keys, the method performed by the first device comprising: establishing a first communication channel with the first QS server of the QS network; receiving, from the first QS server, a connection request from the second device of the second user; in response to accepting the connection request, communicating with the second device of the second user based on a communication path comprising the first 10 communication channel, a QS communication channel through the QS network and a second communication channel between the second device and the QS network.

[0089] Preferably, the thirteenth, fourteenth, and / or fifteenth aspects, where the first device has a first QD key from the set of QD keys stored thereon for QS communications with the QS network, and the second device has a second QD key stored thereon for QS 15 communications with the QS network, and wherein: the first communication channel is a first QS communication channel connecting the QS network with the first device using the first QD key; the second communication channel is a second QS communication channel connecting the QS network with the second device using the second QD key.

[0090] Preferably, wherein the first device has a first QD key from the set of QD keys stored 20 thereon for QS communications with the QS network, and the second device has a second QD key stored thereon for QS communications with the QS network, the method further comprising: establishing a first QS communication channel with the first QS server using the first QD key; transmitting, to the first QS server, a request for QS communications with the second device; receiving via the established first QS channel the third QD key from the first 25 QS server for use in QS communications with the second device, wherein the second device receives via an established second QS channel the third QD key from a second QS server in response to the request.

[0091] Preferably, the method(s) further comprising registering a device of a user for use with the QS network, wherein registering the device further comprising: connecting the device 30 over a direct wired connection with a QS server of the QS network; downloading an available QD key from the set of QD keys to secure storage on the device for use by the device in QS communications with the QS network; registering the association between the device and the user for storage in the repository of the QS network. 2020380554   25 May 2026

[0092] Preferably, registering the user with the QS network, wherein registering the user further comprising providing user credentials and the device identifier of the device for registering the user and associated device for use with the QS network.

[0093] Preferably, the method further comprising: receiving a QREF access token 5 corresponding to a further QD key for use in QS communications between the first device and the second device, wherein the QS server is configured to perform the steps of: assigning a further QD key from the set of QD keys for use in QS communications between the first device and the second device, wherein the further QD key is to be stored as a QD key data item in the QS repository; generating a QREF locator associated with the QD key 10 data item and an available QD key for encrypting the QD key data item; generating a QREF access token associated with the QD key data item based on the QREF locator; linking the QREF locator with the available QD key; associating the QREF locator with the registrations of the first user and the second user to form a communication pair; storing the QD key data item encrypted with the available QD key in the QS repository with the QREF locator; and 15 sending the QREF access token to the first device and the second device for use in QS communications therebetween.

[0094] Preferably, the QS network is configured to select an available QD key for forming a communication pair between the first and second device, and store the available QD key as a QD key data item for use when the first and second device request QS communication 20 therebetween, the method(s) further comprising: sending a request for QS communications with a second device of a second user; receiving a QD key for use in QS communications with the second device; and establishing QS communications with the second device based on the received QD key.

[0095] Preferably, the method(s) further comprising: transmitting a QREF access token for 25 accessing a QD Key data item from the repository for use in QS communications between the first device of the first user and second device of a second user; receiving access to the QD Key data item, wherein the QD Key data item comprises data representative of a QD Key selected from a set of QD Keys for use by the first and second devices in QS communications therebetween; establishing QS communications with the second device 30 using the QD Key, wherein the second device receives access to the QD Key data item by transmitting the QREF access token for accessing the QD Key data item.

[0096] Preferably, the method(s) further comprising: establishing a first QS communication channel with the first QS server using the first QD key; transmitting, to the first QS server, a QREF access token corresponding to a QD key data item associated with a communication 35 pair between the first user and the second user; receiving access to a decrypted QD key data 2020380554   25 May 2026 item in the repository via the first QS communication channel with the first QS server in response to the first QS server identifying the QREF locator associated with the QREF access token; establishing a QS communication channel with the second device of the second user using the decrypted QD key, wherein the second device of the second user 5 receives receiving access to a decrypted QD key data item in the repository via a second QS communication channel with a second QS server in response to the first QS server identifying the QREF locator associated with the QREF access token.

[0097] In a sixteenth aspect, the present disclosure provides an apparatus comprising a processor unit, a memory unit and a communication interface, the processor unit connected 10 to the memory unit and the communication unit, wherein the apparatus is configured to implement the computer-implemented method according to any of the eleventh and / or twelfth aspect(s), one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[0098] In a seventeenth aspect, the present disclosure provides a computer-readable 15 medium comprising code or computer instructions stored thereon, which when executed by a processor unit, causes the processor unit to perform the computer-implemented method according to any of the eleventh and / or twelfth aspect(s), one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein. 20

[0099] In a eighteenth aspect, the present disclosure provides an end-point device comprising a processor unit, a memory unit and a communication interface, the processor unit connected to the memory unit and the communication unit, wherein the apparatus is configured to implement the computer-implemented method according to any of the thirteenth, fourteenth, and / or fifteenth aspect(s), one or more features thereof, one or more 25 features herein, combinations thereof, modifications thereto and / or as described herein.

[00100] In a nineteenth aspect, the present disclosure provides a computer-readable medium comprising code or computer instructions stored thereon, which when executed by a processor unit, causes the processor unit to perform the computer-implemented method according to any of the eleventh, twelfth, thirteenth, fourteenth, and / or fifteenth aspect(s), one 30 or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[00101] In a twentieth aspect, the present disclosure provides a QS system comprising: a QS network comprising at least two QS servers according to the apparatus of the sixteenth aspect, one or more features thereof, one or more features herein, combinations thereof, 35 modifications thereto and / or as described herein, each of the QS servers comprising a 24 2020380554   25 May 2026 hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon; a plurality of end-point devices according to the eighteenth aspect, one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein; a repository for storing and accessing data items 5 associated with users of the end-point devices; wherein the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys.

[00102] In a twenty first aspect, the present disclosure provides a computer-implemented method of quantum safe (QS) communication between a first device and a second device 10 using a QS network, the QS network comprising at least two QS servers and a repository for storing and accessing data items associated with users of the first and second devices, wherein each QS server comprises a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available 15 QD keys from the set of QD keys, wherein the first device has a first QD key from the set of QD keys stored thereon and the second device has a second QD key from the set of QD keys stored thereon, the method comprising: establishing a first QS communication channel with the first device using the first QD key; receiving, from the first device, a request for QS communications with the second device; establishing a second QS communication channel 20 with the second device using the second QD key; receiving, from the second device, a response to establish QS communications with the first device; allocating a third QD key from the set of QD keys for QS communications between the first and second device; and sending via the established first and second QS channels the third QD key to the first and second device, respectively, for use in QS communications therebetween. 25

[00103] Preferably, the method further comprising registering a device for use with the QS network, wherein registering the device further comprising: connecting with the device over a direct wired connection with a QS server of the QS network; selecting an available QD key from the set of QD keys for use by the device; uploading the selected QD key to secure storage of the device via the direct wired connection; and storing and registering an 30 association between the device and the selected available QD key in the repository of the QS network.

[00104] Preferably, the method further comprising registering a user with the QS network, wherein registering the user further comprising: associating the user with a device registered for use with the QS network; and storing and registering the association between the user 35 and the registered device in the repository of the QS network. 2020380554   25 May 2026

[00105] Preferably, the method further comprising: registering the first user with the QS network and associating the first user with the first device; and registering the second user with the QS network and associating the second user with the second device.

[00106] In a twenty second aspect, the present disclosure provides a computer-implemented 5 method of quantum-safe (QS) transaction or message signing using a QS network, the QS network comprising at least two QS servers and a repository for storing and accessing data items associated with users of one or more end-point devices, wherein each QS server comprises a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the 10 repository using quantum encryption based on one or more available QD keys from the set of QD keys, the method comprising: receiving, from a device of a user, a transaction or message requiring a digital signature associated with the user to be applied thereto; receiving, from a device of a user, a QREF access token associated with a data item stored in the repository, the data item is associated with a signing key for use in digitally signing the 15 received transaction or message; identifying a QREF locator based on the QREF access token and input data from the user; and in response to identifying the QREF locator, performing the steps of: retrieving the data item from the repository, wherein the data item is decrypted using the QD key corresponding to the QREF locator; and digitally signing the received transaction or message using a digital signature algorithm based on the retrieved 20 data item; and sending the digitally signed transaction or digitally signed message.

[00107] Preferably, the method further comprising: generating a quantum reference "QREF" locator based on input data associated with a data item for storage and an available QD key selected from the set of QD keys, wherein the data item is associated with a signing key from a set of signing keys and the generated QREF locator is unique; and sending the QREF 25 locator along with the data item encrypted with the available QD key to the repository.

[00108] Preferably, the method further comprising: generating a QREF access token for accessing the data item based on the QREF locator using an irreversible function, process or operation, wherein the QREF access token is unique; and sending the QREF access token to a device of a user. 30

[00109] Preferably, the method further comprising: receiving a set of signing keys associated with a user of an end-point device; generating, for each key in the set of signing keys, a QREF locator based on user data of the user and an available QD key from the set of QD keys, wherein a set of QREF locators is generated corresponding to the set of signing keys; linking each QREF locator in the set of QREF locators to the corresponding available QD key 35 of the set of QD keys; generating, for each QREF locator in the set of QREF locators, a 2020380554   25 May 2026 QREF access token based on said each QREF locator, wherein a set of QREF access tokens are generated corresponding to the set of signing keys; sending, for each QREF locator in the set of QREF locators, said each QREF locator and an encrypted data item, the encrypted data item comprising a data item representative of a key from the set of signing 5 keys corresponding to said each QREF locator and encrypted with a QD key corresponding to said each QREF locator, to the repository for storage, wherein the encrypted data item is linked to the QREF locator when stored; sending the set of QREF access tokens to a device of the user associated with the set of signing keys.

[00110] Preferably, wherein receiving a set of signing keys associated with a user of an end-10 point device further comprises generating a set of signing keys associated with a user based on one or more available QD keys from the set of QD keys.

[00111] Preferably, the method further comprising sending the digitally signed transaction or digitally signed message to the device of the user.

[00112] Preferably, the method further comprising sending the digitally signed transaction or 15 digitally signed message to another device of another user that is a counter-party to the transaction or is addressed for receiving the digitally signed message, wherein the request for signing the transaction.

[00113] Preferably, the method further comprising sending the digitally signed transaction or digitally signed message to a system configured for processing and / or storing the digitally 20 signed transaction or digitally signed message on behalf of the device of the user.

[00114] Preferably, the method further comprising sending the digitally signed transaction or digitally signed message to a DLT system configured for processing and / or storing the digitally signed transaction or digitally signed message on behalf of the device of the user.

[00115] Preferably, the system comprises a system or service based on at least one from the 25 group of: distributed ledger technology; shared ledger technology; and blockchain technology.

[00116] Preferably, the system comprises a system or service using a consensus method or process for verifying whether one or more digitally signed transactions are stored in the distributed ledger, shared ledger and / or blockchain associated with said system or service. 30

[00117] Preferably, the method performed by a QS server of the QS network further comprising performing the QS storage and / or access of data items based on the computer-implemented method according to any of first, second, third, fourth, and / or fifth aspect(s), one or more features thereof, one or more features herein, combinations thereof, modifications 27 2020380554   25 May 2026 thereto and / or as described herein, wherein the data items corresponding to one or more signing keys.

[00118] Preferably, further comprising registering permissions for one or more users to access data items based on one or more QREF access token(s) corresponding to one or 5 more data item(s) representing one or more signing key(s) stored in the repository.

[00119] Preferably, further comprising sending the one or more QREF access token(s) to the devices associated with the one or more users.

[00120] Preferably, further comprising: transmitting the set of signing keys over the QS network to one or more load-balanced geographically located HSMs, wherein the set of 10 signing keys are stored in the repository accessible by the HSMs via the QS network; sending the corresponding QREF access tokens associated with the set of signing keys to one or more devices of users with permissions to use the QREF access tokens.

[00121] Preferably, the set of signing keys are a set of master keys or secrets associated with two or more systems requiring interoperability, further comprising registering 15 permissions for one or more devices or apparatus of the two or more systems to access data items based on one or more QREF access token(s) corresponding to one or more data item(s) representing said one or more master key(s) or secrets stored in the repository.

[00122] Preferably, further comprising sending the one or more QREF access token(s) to the devices. 20

[00123] Preferably, the set of signing keys are a set of master keys, the method further comprising registering permissions for one or more users to access data items based on one or more QREF access token(s) corresponding to one or more data item(s) representing one or more signing key(s) stored in the repository.

[00124] Preferably, further comprising sending the one or more QREF access token(s) to 25 the devices associated with the one or more users.

[00125] Preferably, further comprising: transmitting the set of master keys over the QS network to one or more load-balanced geographically located HSMs, wherein the set of master keys are stored in the repository accessible by the HSMs via the QS network; sending the corresponding QREF access tokens associated with the set of master keys to one or 30 more devices of users with permissions to use the QREF access tokens.

[00126] In a twenty third aspect, the present disclosure provides a computer-implemented method of quantum-safe (QS) transaction or message signing using a QS network, the QS 28 2020380554   25 May 2026 network comprising at least two QS servers and a repository for storing and accessing data items associated with users of one or more end-point devices, wherein each QS server comprises a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the 5 repository using quantum encryption based on one or more available QD keys from the set of QD keys, the method performed by a device of a user comprising: receiving a transaction or message requiring a digital signature associated with the user to be applied thereto; sending data representative of the received transaction or message and a QREF access token associated with a data item stored in the repository, the data item comprising a signing key 10 for use in digitally signing the transaction or message; receiving a digitally signed transaction or digitally signed message comprising the transaction or message digitally signed using a digital signature algorithm based on the data item; sending the digitally signed transaction for further processing or storage; and indicating to the user of the device that the QREF access token has been used. 15

[00127] Preferably, wherein the digitally signed transaction or digitally signed message corresponds to the transaction or message having been processed by a QS server of the QS network configured to: identify a QREF locator based on the QREF access token and input data from the user; and in response to identifying the QREF locator, the QS server is configured to: retrieve the data item from the repository, wherein the data item is decrypted 20 using the QD key corresponding to the QREF locator; and digitally sign the received transaction or message using a digital signature algorithm based on the retrieved data item; and send the digitally signed transaction or digitally signed message.

[00128] Preferably, the method further comprising: transmitting a set of signing keys associated with the user of the end-point device; and receiving a set of QREF access tokens 25 associated with the set of signing keys.

[00129] Preferably, the method further comprising: transmitting a request for a set of signing keys associated with the user of the end-point device; and receiving a set of QREF access tokens associated with a generated set of signing keys, wherein the generated set of signing keys are stored in encrypted form in the repository and each key in the set of signing keys is 30 linked to a QREF locator corresponding to a QREF access token of the set of QREF access tokens, wherein a QREF access token is generated by an irreversible operation or function based on the QREF locator.

[00130] Preferably, the generated set of signing keys are generated by an HSM based on one or more available QD keys from the set of QD keys. 2020380554   25 May 2026

[00131] Preferably, a QS server is configured to generate the set of QREF access tokens, the QS server configured to: generate, for each key in the set of signing keys, a QREF locator based on user data of the user and an available QD key from the set of QD keys, wherein a set of QREF locators is generated corresponding to the set of signing keys; link 5 each QREF locator in the set of QREF locators to the corresponding available QD key of the set of QD keys; generate, for each QREF locator in the set of QREF locators, a QREF access token based on said each QREF locator, wherein a set of QREF access tokens are generated corresponding to the set of signing keys; send, for each QREF locator in the set of QREF locators, said each QREF locator and an encrypted data item, the encrypted data item 10 comprising a data item representative of a key from the set of signing keys corresponding to said each QREF locator and encrypted with a QD key corresponding to said each QREF locator, to the repository for storage, wherein the encrypted data item is linked to the QREF locator when stored; and send the set of QREF access tokens associated with the set of signing keys to a device associated with the user. 15

[00132] Preferably, the method further comprising receiving the digitally signed transaction or digitally signed message at the device of the user.

[00133] Preferably, the method further comprising sending the digitally signed transaction or digitally signed message to another device of another user that is a counter-party to the transaction or is addressed for receiving the digitally signed message, wherein the request 20 for signing the transaction.

[00134] Preferably, the method further comprising sending the digitally signed transaction or digitally signed message to a system configured for processing and / or storing the digitally signed transaction or digitally signed message on behalf of the device of the user.

[00135] Preferably, the method further comprising sending the digitally signed transaction or 25 digitally signed message to a DLT system configured for processing and / or storing the digitally signed transaction or digitally signed message on behalf of the device of the user.

[00136] Preferably, the system comprises a system or service based on at least one from the group of: distributed ledger technology; shared ledger technology; and blockchain technology. 30

[00137] Preferably, the method comprising performing the quantum-safe communications with a QS server or another device or system based on the computer-implemented method according to any of eleventh, twelfth, thirteenth, fourteenth, and / or fifteenth aspect(s), one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein. 2020380554   25 May 2026

[00138] Preferably, the method performed by a client DLT application executing on the device of the user, the client application configured for signing DLT transactions and sending signed DLT to a DLT system.

[00139] In a twenty fourth aspect, the present disclosure provides an apparatus comprising a 5 processor unit, a memory unit and a communication interface, the processor unit connected to the memory unit and the communication unit, wherein the apparatus is configured to implement the computer-implemented method according to any of the twenty second and / or twenty third aspect(s), one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein. 10

[00140] In a twenty fifth aspect, the present disclosure provides a computer-readable medium comprising code or computer instructions stored thereon, which when executed by a processor unit, causes the processor unit to perform the computer-implemented method according to any of the twenty second and / or twenty third aspect(s), one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as 15 described herein.

[00141] In a twenty sixth aspect, the present disclosure provides an end-point device comprising a processor unit, a memory unit and a communication interface, the processor unit connected to the memory unit and the communication unit, wherein the end-point device or apparatus is configured to implement the computer-implemented method according to any 20 of the twenty third aspect(s), one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[00142] Preferably, the end-point device further comprising a secure enclave for implementing the computer-implemented method according to any of the twenty second and / or twenty third aspect(s), one or more features thereof, one or more features herein, 25 combinations thereof, modifications thereto and / or as described herein.

[00143] In a twenty seventh aspect, the present disclosure provides an computer-readable medium comprising code or computer instructions stored thereon, which when executed by a processor unit, causes the processor unit to perform the computer-implemented method according to any of the twenty second and / or twenty third aspect(s), one or more features 30 thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[00144] In a twenty eighth aspect, the present disclosure provides a QS system comprising: a QS network comprising at least two QS servers according to the apparatus of the twenty fourth aspect, one or more features herein, combinations thereof, modifications thereto 2020380554   25 May 2026 and / or as described herein, each of the QS servers comprising a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon; a plurality of end-point devices according to any of the twenty sixth aspect, one or more features herein, combinations thereof, modifications thereto and / or as described herein; a repository for 5 storing and accessing data items associated with users of the end-point devices; wherein the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys.

[00145] In a twenty ninth aspect, the present disclosure provides a computer-implemented method of quantum-safe (QS) cryptographic processing of a data item, transaction or 10 message using a QS network, the QS network comprising at least two QS servers and a repository for storing and accessing data items associated with users of one or more endpoint devices, wherein each QS server comprises a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based 15 on one or more available QD keys from the set of QD keys, the method comprising: receiving a data item, transaction or message requiring a cryptographic processing associated with a user or system; receiving a QREF access token associated with a data item stored in the repository, the data item is associated with a cryptographic key for use in cryptographically processing the received data item, transaction or message; identifying a QREF locator based 20 on the QREF access token and input data from the user or system; and in response to identifying the QREF locator, performing the steps of: retrieving the data item from the repository, wherein the data item is decrypted using the QD key corresponding to the QREF locator; and processing the received data item, transaction or message using one or more cryptographic operations based on the retrieved data item; and sending the cryptographically 25 processed data item, cryptographically processed transaction or cryptographically processed message.

[00146] Preferably, the method further comprising: generating a quantum reference (QREF) locator based on input data associated with a data item for storage and an available QD key selected from the set of QD keys, wherein the data item is associated with a cryptographic 30 key from a set of cryptographic keys and the generated QREF locator is unique; and sending the QREF locator along with the data item encrypted with the available QD key to the repository.

[00147] Preferably, the method further comprising: generating a QREF access token for accessing the data item based on the QREF locator using an irreversible function, process or 35 operation, wherein the QREF access token is unique; and sending the QREF access token to a device of a user. 2020380554   25 May 2026

[00148] Preferably, the method further comprising: receiving a set of cryptographic keys associated with the system or the user of an end-point device; generating, for each key in the set of signing keys, a QREF locator based on system data of the system or user data of the user and an available QD key from the set of QD keys, wherein a set of QREF locators is 5 generated corresponding to the set of cryptographic keys; linking each QREF locator in the set of QREF locators to the corresponding available QD key of the set of QD keys; generating, for each QREF locator in the set of QREF locators, a QREF access token based on said each QREF locator, wherein a set of QREF access tokens are generated corresponding to the set of cryptographic keys; sending, for each QREF locator in the set of 10 QREF locators, said each QREF locator and an encrypted data item, the encrypted data item comprising a data item representative of a key from the set of cryptographic keys corresponding to said each QREF locator and encrypted with a QD key corresponding to said each QREF locator, to the repository for storage, wherein the encrypted data item is linked to the QREF locator when stored; sending the set of QREF access tokens to the system or a 15 device of the user associated with the set of cryptographic keys.

[00149] Preferably, receiving a set of cryptographic keys associated with a system or a user of an end-point device further comprises generating a set of cryptographic keys associated with the system or the user based on one or more available QD keys from the set of QD keys. 20

[00150] Preferably, the method further comprising sending the cryptographically processed transaction or cryptographically processed signed message to the system or a device of the user.

[00151] Preferably, the method further comprising sending the cryptographically processed data item, cryptographically processed transaction or cryptographically processed message 25 to another system or another device of another user that is a counter-party to the transaction or is addressed for receiving the cryptographically processed message.

[00152] Preferably, the method further comprising sending the cryptographically processed data item, cryptographically processed transaction or cryptographically processed message to the system or another system configured for using, processing and / or storing the 30 cryptographically processed data item, cryptographically processed transaction or cryptographically processed message.

[00153] Preferably, the method further comprising sending the cryptographically processed data item, cryptographically processed transaction or cryptographically processed message to a DLT system configured for using, processing and / or storing the cryptographically 2020380554   25 May 2026 processed data item, cryptographically processed transaction or cryptographically processed message on behalf of the device of the user.

[00154] Preferably, wherein the system comprises a system or service based on at least one from the group of: distributed ledger technology; shared ledger technology; and blockchain 5 technology.

[00155] Preferably, wherein the system or said another system is configured to use a consensus method or process for verifying whether one or more cryptographically processed data item(s), cryptographically processed transaction(s) or cryptographically processed message(s) are stored in a distributed ledger, shared ledger and / or blockchain associated 10 with said system or said another system.

[00156] Preferably, the method performed by a QS server of the QS network further comprising performing the QS storage and / or access of data items based on the computer-implemented method according to any of first, second third, fourth and / or fifth aspects one or more features thereof, one or more features herein, combinations thereof, modifications 15 thereto and / or as described herein, wherein the data items corresponding to one or more cryptographic keys.

[00157] Preferably, wherein the cryptographic operations comprise one or more cryptographic operations based on the group of: encryption, digital signing, decryption, authentication, hashing, authenticated encryption. 20

[00158] Preferably, wherein the cryptographic keys comprise one or more cryptographic keys for use with said one or more cryptographic operations.

[00159] Preferably, wherein the set of cryptographic keys are a set of cryptographic signing keys associated with the system or the user for use with said one or more cryptographic operations, said one or more cryptographic operations corresponding to one or more digital 25 signature cryptographic operation(s) or algorithm(s) associated with digitally signing one or more data item(s), transaction(s), or message(s) using a signing key associated with a QREF access token, and the set of cryptographic key(s) are a set of signing key(s).

[00160] Preferably, further comprising registering permissions for one or more systems or one or more users to access data items based on one or more QREF access token(s) 30 corresponding to one or more data item(s) representing one or more signing key(s) of the set of signing key(s) stored in the repository.

[00161] Preferably, further comprising sending the one or more QREF access token(s) to the one or more systems, or one or more devices associated with the one or more users. 34 2020380554   25 May 2026

[00162] Preferably, further comprising: transmitting the set of signing keys over the QS network to one or more load-balanced geographically located HSMs, wherein the set of signing keys are stored in the repository accessible by the HSMs via the QS network; sending the corresponding QREF access tokens associated with the set of signing keys to 5 one or more systems, or one or more devices of users located in relation to the geographically located HSMs, with permissions to use the QREF access tokens.

[00163] Preferably, the set of cryptographic keys are a set of master keys or secrets associated with two or more systems requiring interoperability, further comprising registering permissions for the two or more systems to access data items based on one or more QREF 10 access token(s) corresponding to one or more data item(s) representing said one or more master key(s) or secrets stored in the repository for use in cryptographic operations on one or more received data items, received transactions or messages that enable interoperability between the two or more systems.

[00164] Preferably, further comprising sending the one or more QREF access token(s) to the 15 two or more system and / or devices of users associated with the two or more systems.

[00165] Preferably, wherein the set of cryptographic keys are a set of master keys, the method further comprising registering permissions for one or more users to access data items based on one or more QREF access token(s) corresponding to one or more data item(s) representing one or more master key(s) stored in the repository for use in 20 cryptographic operations on one or more received data items, received transactions or messages using one or more master keys corresponding to the one or more QREF access token(s).

[00166] Preferably, further comprising sending the one or more QREF access token(s) to the devices or systems associated with the one or more users. 25

[00167] Preferably, the set of master keys are a set of master hierarchical deterministic (HD) keys further comprising sending the one or more QREF access token(s) to the devices or systems associated with the one or more users.

[00168] Preferably, the set of cryptographic keys comprise a set of cryptographic encryption keys associated with the system or the user for use with said one or more cryptographic 30 operations, said one or more cryptographic operations corresponding to one or more encryption cryptographic operation(s) or algorithm(s) associated with encrypting one or more data item(s), transaction(s), or message(s) using the cryptographic encryption key corresponding to a QREF access token. 2020380554   25 May 2026

[00169] Preferably, wherein the set of cryptographic keys comprise a set of cryptographic decryption keys associated with the system or the user for use with said one or more cryptographic operations, said one or more cryptographic operations corresponding to one or more decryption cryptographic operation(s) or algorithm(s) associated with decrypting one or 5 more encrypted data item(s), encrypted transaction(s), or encrypted message(s) using the cryptographic decryption key corresponding to a QREF access token.

[00170] Preferably, wherein the one or more data items comprise data representative of a set of data required to be backed-up and / or archived, and the set of cryptographic keys comprise a set of cryptographic encryption keys associated with the system or the user for use with 10 said one or more cryptographic operations for encrypting the one or more data items.

[00171] In a thirtieth aspect, the present disclosure provides a computer-implemented method of quantum-safe (QS) cryptographic processing of a data item, transaction or message using a QS network, the QS network comprising at least two QS servers and a repository for storing and accessing data items associated with users of one or more end- 15 point devices, wherein each QS server comprises a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys, the method comprising: receiving a data item, transaction or message requiring cryptographic processing associated with a 20 user or system; sending data representative of the received data item, transaction or message and a QREF access token associated with another data item stored in the repository, the other data item comprising a cryptographic key for use in cryptographically processing the received data item, transaction or message; and receiving a cryptographically processed data item, transaction or message comprising the received data item, transaction 25 or message cryptographically processed using one or more cryptographic operations based on the other data item.

[00172] Preferably, further comprising sending the cryptographically processed data item, transaction or message to a system or user with a device for further processing or storage.

[00173] Preferably, wherein the cryptographically processed data item, transaction or 30 message corresponds to the transaction or message having been cryptographically processed by a QS server of the QS network, the QS server configured to: identify a QREF locator based on the QREF access token and input data from the user; and in response to identifying the QREF locator, the QS server is configured to: retrieve the other data item from the repository, wherein the retrieved data item is decrypted using the QD key corresponding 35 to the QREF locator; and process the received data item, transaction or message using one 2020380554   25 May 2026 or more cryptographic operations based on the retrieved data item; and send the cryptographically processed data item, cryptographically processed transaction or cryptographically processed message.

[00174] Preferably, the method further comprising: transmitting a set of cryptographic keys 5 associated with the system or user of the end-point device; and receiving a set of QREF access tokens associated with the set of cryptographic keys.

[00175] Preferably, the method further comprising: transmitting a request for a set of cryptographic keys associated with the system or user of the end-point device; and receiving a set of QREF access tokens associated with a generated set of cryptographic keys, wherein 10 the generated set of cryptographic keys are stored in encrypted form in the repository and each key in the set of cryptographic keys is linked to a QREF locator corresponding to a QREF access token of the set of QREF access tokens, wherein a QREF access token is generated by an irreversible operation or function based on the QREF locator.

[00176] Preferably, the generated set of cryptographic keys are generated by an HSM based 15 on one or more available QD keys from the set of QD keys.

[00177] Preferably, wherein a QS server is configured to generate the set of QREF access tokens, the QS server configured to: generate, for each key in the set of cryptographic keys, a QREF locator based on user data of the user and an available QD key from the set of QD keys, wherein a set of QREF locators is generated corresponding to the set of cryptographic 20 keys; link each QREF locator in the set of QREF locators to the corresponding available QD key of the set of QD keys; generate, for each QREF locator in the set of QREF locators, a QREF access token based on said each QREF locator, wherein a set of QREF access tokens are generated corresponding to the set of cryptographic keys; send, for each QREF locator in the set of QREF locators, said each QREF locator and an encrypted data item, the 25 encrypted data item comprising a data item representative of a key from the set of cryptographic keys corresponding to said each QREF locator and encrypted with a QD key corresponding to said each QREF locator, to the repository for storage, wherein the encrypted data item is linked to the QREF locator when stored; and send the set of QREF access tokens associated with the set of cryptographic keys to the system, or device 30 associated with the user.

[00178] Preferably, the method further comprising receiving the cryptographically processed data item, transaction or message at the device of the user.

[00179] Preferably, the method further comprising sending the cryptographically processed data item, transaction or message to one or more from the group of: another system for 2020380554   25 May 2026 processing or storage; a device of another user that is a counter-party to the transaction; a device of another user or system addressed for receiving the cryptographically processed data item, transaction or message.

[00180] Preferably, the method further comprising sending the cryptographically processed 5 data item, transaction or message to a system configured for processing and / or storing the cryptographically processed data item, transaction or message.

[00181] Preferably, the method further comprising sending the cryptographically processed data item, transaction or message to a DLT system configured for processing and / or storing the cryptographically processed data item, transaction or message. 10

[00182] Preferably, wherein the system or the another system comprises a system or service based on at least one from the group of: distributed ledger technology; shared ledger technology; and blockchain technology.

[00183] Preferably, the method comprising performing the quantum-safe communications with a QS server or another device or system based on the computer-implemented method 15 according to any of claims eleventh, twelfth, thirteenth, fourteenth, and / or fifteenth aspects, one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[00184] Preferably, the method performed by a client DLT application executing on the device of the user, the client application configured for signing DLT transactions and sending 20 signed DLT to a DLT system.

[00185] Preferably, wherein the set of cryptographic keys are a set of cryptographic signing keys associated with the system or the user for use with said one or more cryptographic operations, said one or more cryptographic operations corresponding to one or more digital signature cryptographic operation(s) or algorithm(s) associated with digitally signing one or 25 more data item(s), transaction(s), or message(s) using a signing key associated with a QREF access token.

[00186] Preferably, further comprising registering permissions for one or more systems or one or more users to access data items based on one or more QREF access token(s) corresponding to one or more data item(s) representing one or more signing key(s) of the set 30 of signing key(s) stored in the repository.

[00187] Preferably, further comprising sending the one or more QREF access token(s) to the one or more systems, or one or more devices associated with the one or more users. 2020380554   25 May 2026

[00188] Preferably, wherein the QS server is configured to transmit the set of signing keys over the QS network to one or more load-balanced geographically located HSMs, wherein the set of signing keys are stored in the repository accessible by the HSMs via the QS network, the method comprising receiving the corresponding QREF access tokens 5 associated with the set of signing keys of one or more systems, or one or more devices of users located in relation to the geographically located HSMs, with permissions to use the QREF access tokens.

[00189] Preferably, wherein the set of cryptographic keys are a set of master keys or secrets associated with two or more systems requiring interoperability, further comprising registering 10 permissions for the two or more systems to access data items based on one or more QREF access token(s) corresponding to one or more data item(s) representing said one or more master key(s) or secrets stored in the repository for use in cryptographic operations on one or more received data items, received transactions or messages that enable interoperability between the two or more systems. 15

[00190] Preferably, further comprising receiving the one or more QREF access token(s) at the two or more system and / or devices of users associated with the two or more systems.

[00191] Preferably, wherein the set of cryptographic keys are a set of master keys, the method further comprising registering permissions for a system or one or more users to access data items based on one or more QREF access token(s) corresponding to one or 20 more data item(s) representing one or more master key(s) stored in the repository for use in cryptographic operations on one or more received data items, received transactions or messages using one or more master keys corresponding to the one or more QREF access token(s).

[00192] Preferably, further comprising receiving the one or more QREF access token(s) at 25 the systems, or devices or systems associated with the one or more users.

[00193] Preferably, wherein the set of master keys are a set of master hierarchical deterministic (HD) keys further comprising sending the one or more QREF access token(s) to the devices or systems associated with the one or more users.

[00194] Preferably, wherein the set of cryptographic keys comprise a set of cryptographic 30 encryption keys associated with the system or the user for use with said one or more cryptographic operations, said one or more cryptographic operations corresponding to one or more encryption cryptographic operation(s) or algorithm(s) associated with encrypting one or more data item(s), transaction(s), or message(s) using the cryptographic encryption key corresponding to a QREF access token. 2020380554   25 May 2026

[00195] Preferably, wherein the set of cryptographic keys comprise a set of cryptographic decryption keys associated with the system or the user for use with said one or more cryptographic operations, said one or more cryptographic operations corresponding to one or more decryption cryptographic operation(s) or algorithm(s) associated with decrypting one or 5 more encrypted data item(s), encrypted transaction(s), or encrypted message(s) using the cryptographic decryption key corresponding to a QREF access token.

[00196] Preferably, further comprising sending one or more data items comprising data representative of a set of data required to be backed-up and / or archived, wherein the set of cryptographic keys comprise a set of cryptographic encryption keys associated with the 10 system or the user for use with said one or more cryptographic operations for encrypting said one or more data items.

[00197] In a thirty first aspect, the present disclosure provides an apparatus comprising a processor unit, a memory unit and a communication interface, the processor unit connected to the memory unit and the communication unit, wherein the apparatus is configured to 15 implement the computer-implemented method according to twenty ninth aspect, one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[00198] In a thirty second aspect, the present disclosure provides a computer-readable medium comprising code or computer instructions stored thereon, which when executed by a 20 processor unit, causes the processor unit to perform the computer-implemented method according to twenty ninth aspect, one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[00199] In a thirty third aspect, the present disclosure provides an end-point device comprising a processor unit, a memory unit and a communication interface, the processor 25 unit connected to the memory unit and the communication unit, wherein the apparatus is configured to implement the computer-implemented method according to thirtieth aspect, one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[00200] Preferably, the end-point device further comprising a secure enclave for 30 implementing the computer-implemented method according to the thirtieth aspect, one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[00201] In a thirty fourth aspect, the present disclosure provides a computer-readable medium comprising code or computer instructions stored thereon, which when executed by a 2020380554   25 May 2026 processor unit, causes the processor unit to perform the computer-implemented method according to thirtieth aspect, one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein.

[00202] In a thirty fifth aspect, the present disclosure provides a QS system comprising: a QS 5 network comprising at least two QS servers according to the apparatus of the thirty first aspect, one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein, each of the QS servers comprising a hardware security module (HSM) with an identical set of quantum distributed (QD) keys stored thereon; a plurality of end-point devices according to according to thirty third aspect, 10 one or more features thereof, one or more features herein, combinations thereof, modifications thereto and / or as described herein; a repository for storing and accessing data items associated with users of the end-point devices; wherein the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys. 15

[00203] In another aspect, the present disclosure provides a computer-implemented method of storing one or more data item(s) in a quantum-safe "QS" network, the QS network comprising one or more QS server(s) and a repository for storing and accessing said data item(s), each QS server comprising a hardware security module "HSM" for storing an identical set of quantum distributed "QD" keys, said identical set of QD keys having been 20 distributed to each of said QS server(s) using a quantum key distribution process, and said QS server(s) configured to communicate securely with each other and the repository using one or more available QD keys from the identical set of QD keys, the method performed by a QS server comprising: selecting an available QD key from the set of QD keys for encrypting a data item; generating a quantum reference "QREF" locator based on input data associated 25 with the data item for storage and the available QD key selected from the set of QD keys, wherein the generated QREF locator is unique, and wherein the QREF locator is a logical address or a physical address for storing and accessing the data item in the repository; linking the QREF locator to the available QD key of the set of QD keys; storing the link between the QREF locator to the available QD key of the set of QD keys in the HSM; and 30 sending the QREF locator along with the data item encrypted with the available QD key to the repository for storage, wherein the encrypted data item is linked to the QREF locator when stored.

[00204] In another aspect, the present disclosure provides a computer-implemented method of quantum safe “QS” storage and retrieval in a QS network, the QS network comprising one 35 or more QS server(s) and a repository for storing and retrieving one or more data item(s) by a plurality of users, wherein each QS server comprises a hardware security module “HSM” with 2020380554   25 May 2026 an identical set of quantum distributed “QD” keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys, the method performed by a QS server comprising: in response to receiving a data item for storage: generating a quantum 5 reference “QREF” locator based on a user secret of the first user and an available QD key selected from the set of QD keys, wherein the generated QREF locator is unique, and wherein the QREF locator indicates a logical address or a physical address for storing and accessing the data item encrypted with the selected QD key in the repository and an identity of the first user; linking the QREF locator to the available QD key of the set of QD keys; 10 storing the link between the QREF locator to the available QD key of the set of QD keys in the HSM; generating an QREF access token based on the QREF locator, wherein the QREF access token enables access operations to be performed on the data item when stored in the repository; storing the data item in the repository indexed by the QREF locator; and sending the QREF access token to the first user; and in response to receiving an QREF access token 15 for a data item stored in the repository; identifying a QREF locator based on the QREF access token and the identity of the second user; and providing access operations to the second user in relation to the encrypted data item in the repository based on the identified QREF locator.

[00205] In another aspect, the present disclosure provides a computer-readable medium 20 comprising code or computer instructions stored thereon, which when executed by a processor unit, causes the processor unit to perform the computer-implemented method described herein.

[00206] The methods described herein may be performed by software in machine readable form on a tangible storage medium e.g. in the form of a computer program comprising 25 computer program code means adapted to perform all the steps of any of the methods described herein when the program is run on a computer and where the computer program may be embodied on a computer readable medium. Examples of tangible (or non-transitory) storage media include disks, thumb drives, memory cards etc. and do not include propagated signals. The software can be suitable for execution on a parallel processor or a serial 30 processor such that the method steps may be carried out in any suitable order, or simultaneously.

[00207] This application acknowledges that firmware and software can be valuable, separately tradable commodities. It is intended to encompass software, which runs on or controls “dumb” or standard hardware, to carry out the desired functions. It is also intended 35 to encompass software which “describes” or defines the configuration of hardware, such as 2020380554   25 May 2026 HDL (hardware description language) software, as is used for designing silicon chips, or for configuring universal programmable chips, to carry out desired functions.

[00208] The preferred features may be combined as appropriate, as would be apparent to a skilled person, and may be combined with any of the aspects of the disclosure. 5

[00209] The term “comprising” as used in the specification and claims means “consisting at least in part of.” When interpreting each statement in this specification that includes the term “comprising,” features other than that or those prefaced by the term may also be present. Related terms “comprise” and “comprises” are to be interpreted in the same manner.

[00210] The reference in this specification to any prior publication (or information derived 10 from it), or to any matter which is known, is not, and should not be taken as, an acknowledgement or admission or any form of suggestion that that prior publication (or information derived from it) or known matter forms part of the common general knowledge in the field of endeavour to which this specification relates. Brief Description of the Drawings 15

[00211] Embodiments of the invention will be described, by way of example, with reference to the following drawings, in which:

[00212] Figure 1a is a schematic diagram illustrating an example quantum-safe (QS) system according to the disclosure;

[00213] Figure 1b is a flow diagram illustrating an example process of storing data items in a 20 QS system according to the disclosure;

[00214] Figure 1c is a flow diagram illustrating another example process of storing data items in a QS system according to the disclosure;

[00215] Figure 1d is a flow diagram illustrating an example process of accessing data items stored in a QS system according to the disclosure; 25

[00216] Figure 1e is a flow diagram illustrating another example process of accessing data items in a QS system according to the disclosure;

[00217] Figure 1f is a flow diagram illustrating an example process of storing data items using the QS system of figure 1a according to the disclosure;

[00218] Figure 1g is a flow diagram illustrating an example process of accessing data items 30 using the QS system of figure 1a according to the disclosure; 43 2020380554   25 May 2026

[00219] Figure 1h is another schematic diagram illustrating another example QS system according to the disclosure;

[00220] Figure 1i is another schematic diagram illustrating a preferred example QS system using satellite quantum key distribution (SQKD) according to the disclosure; 5

[00221] Figure 1j is another schematic diagram illustrating an example QS system of figures 1a to 1i using SQKD and configured with registration servers and nodes according to the disclosure;

[00222] Figure 1k is another schematic diagram illustrating another preferred example QS system of figures 1a to 1j using SQKD and configured with registration servers and nodes 10 according to the disclosure;

[00223] Figure 1l is a further schematic diagram illustrating an example preferred QS system using terrestrial quantum key distribution according to the disclosure;

[00224] Figure 2a is a schematic diagram illustrating a quantum reference locator engine for use in the QS system(s) illustrated in figures 1a-1l according to the disclosure; 15

[00225] Figure 2b is a schematic diagram illustrating a QREF access token engine for use in the QS system(s) illustrated in figures 1a-1l according to the disclosure;

[00226] Figure 2c is a flow diagram illustrating a process for accessing a data item using QREF access token in QS system(s) illustrated in figures 1a-1l according to the disclosure;

[00227] Figure 3a is a flow diagram illustrating a process of storing and retrieving data items 20 using an example QS system as illustrated in figures 1a-1l when configured with distributed ledger technology (DLT) according to the disclosure;

[00228] Figure 3b is a flow diagram illustrating a process for a web certification service using a preferred example QS system of figure 1e according to the disclosure;

[00229] Figure 3c is a flow diagram illustrating a process for a KYC service using a preferred 25 example QS system of figure 1e according to the disclosure;

[00230] Figure 4a is a flow diagram illustrating a process for another example data storage and retrieval service using a preferred example QS system of figure 1e according to the disclosure; 2020380554   25 May 2026

[00231] Figure 4b is a flow diagram illustrating a process for another example web certification service using a preferred example QS system of figure 1e according to the disclosure;

[00232] Figure 5a is a schematic diagram illustrating an example of quantum-safe end-point 5 communications using a QS system according to the disclosure;

[00233] Figure 5b is a flow diagram illustrating an example end-point registration process for QS communication using the QS system according to the disclosure;

[00234] Figure 5c is a flow diagram illustrating an example end-point registration process for QS communication using the QS system according to the disclosure; 10

[00235] Figure 5d is a flow diagram illustrating an example user registration process for QS communication using the QS system based on a registered end-point according to the disclosure;

[00236] Figure 5e is a flow diagram illustrating an example QS communication set-up process between at least two devices using the QS system according to the disclosure; 15

[00237] Figure 5f is a flow diagram illustrating another example QS communication set-up process between at least two devices using the QS system according to the disclosure;

[00238] Figure 5g is a flow diagram illustrating an example QS key assignment process 550 for use in setting up a QS communication channel between at least two end-point devices according to the disclosure; 20

[00239] Figure 5h is a flow diagram illustrating a QD key update process after a further QD key has been assigned during process of figure 5g according to the disclosure;

[00240] Figure 5i is a signal flow diagram illustrating an example QS communications establishment process according to the disclosure;

[00241] Figure 5j is a signal flow diagram illustrating another example QS communications 25 establishment process according to the disclosure;

[00242] Figure 6a is a flow diagram illustrating an example QS key sharing / transaction signing process using a QS system according to the disclosure;

[00243] Figure 6b is another flow diagram illustrating another example QS key sharing / transaction signing process using a QS system according to the disclosure; 2020380554   25 May 2026

[00244] Figure 6c is a further flow diagram illustrating a further example QS key sharing / transaction signing DLT process using a QS system according to the disclosure;

[00245] Figure 6d is a flow diagram illustrating an example QS cryptographic process for performing QS cryptographic processing of a data item according to the disclosure; 5

[00246] Figure 7a is a schematic diagram of a computing device according to the disclosure;

[00247] Figure 7b is a schematic diagram of another example QS system according to the disclosure;

[00248] Common reference numerals are used throughout the figures to indicate similar features. 10 Detailed Description

[00249] Embodiments of the present invention are described below by way of example only. These examples represent the best mode of putting the invention into practice that are currently known to the Applicant although they are not the only ways in which this could be achieved. The description sets forth the functions of the example and the sequence of steps 15 for constructing and operating the example. However, the same or equivalent functions and sequences may be accomplished by different examples.

[00250] The present disclosure provides method(s), apparatus and system(s) for quantumsafe (QS) storage, retrieval, access, use or application of data items or data and QS and / or quantum-resistant communications using a QS system comprising a quantum key 20 distribution layer and a transaction layer, wherein the transaction layer is separated from the key distribution layer. The transaction layer including a QS network formed by a plurality of QS server(s) / node(s) and one or more repository(ies) and / or ledger(s) and the like for storing, managing, retrieving and / or using the data items, and / or setting up one or more QS communication channels and the like, the QS server(s) / node(s) (herein referred to as QS 25 server(s)) communicate with each other in a quantum-safe manner. Each QS server includes an identical set of quantum distributed (QD) keys securely stored thereon, which are used by the QS servers to communicate with each other, and also the repository(ies) and / or ledger(s) and the like in a quantum-safe manner. The key distribution layer includes a plurality of quantum key distribution (QKD) sources, where each QKD source distributes an 30 identical set of QD key(s) to each of the QS server(s) using a group quantum key distribution (QKD) or multi-casting QKD protocol in a quantum-safe manner. A QD key or quantum key may comprise or represent data representative of a key and / or cryptographic key that has been distributed from a QKD source using a QKD protocol in a quantum-safe manner. A 2020380554   25 May 2026 quantum-safe (QS) communication channel or QS channel may comprise or represent an encrypted communication channel that is encrypted by one or more QD key(s) such that the encrypted communication channel is quantum-safe.

[00251] One or more of the QS server(s) include components that are configured to perform 5 and / or control the registration of users, storage, retrieval, access and / or use or application of data items, and / or QS communications between, without limitation, for example devices, servers, or end-points of the users and / or customers and the like. Users of end-point devices, servers, communication devices may connect and / or register with the QS system via one or more QS server(s) for registering, storing, retrieving, accessing, using applications 10 associated with data items stored within the repository(ies) and / or ledger(s) and the like and / or for establishing QS communications channels with the QS network and / or other devices of users registered in the QS network and the like and / or as the application demands. Additionally or alternatively, without limitation, for example end-point devices, servers, communication devices may be configured to connect and / or register with the QS 15 system via one or more QS server(s) for registering, storing, retrieving, accessing, using applications associated with data items stored within the repository(ies) and / or ledger(s) and the like and / or for establishing QS communications channels with the QS network and / or other devices registered in the QS network and the like and / or as the application demands.

[00252] A repository or repositories or repository storage systems may comprise or represent 20 any type of storage system or platform for storing data items and / or accessing data items stored thereon. The storage system or platform may be based on, without limitation, for example distributed storage technologies, centralised storage technologies and / or both as the application demands. Examples of a repository, storage system and / or platform as described herein according to the disclosure may include, without limitation, for example one 25 or more storage systems or platforms based on one or more from the group of: distributed ledger technologies and / or network(s); shared ledger technologies and / or network(s); blockchain technologies and / or network(s); cloud storage technologies and / or platform(s); distributed storage server(s); centralised storage server(s); content delivery network; geographically distributed network of servers and / or data centers; PUSH technology (RTM)-30 style digital repository / cloud technologies; publish / subscribe, request / response and / or realtime based digital storage and / or data access platforms, cloud / repository platforms and / or systems; publish / subscribe, request / response and / or real-time based digital distributed storage and / or data access platforms; database management systems; secure cloud storage systems; secure storage system or platforms; secure database management system; and / or 2020380554   25 May 2026 any other system for storing and accessing data items and the like and / or as the application demands.

[00253] A quantum channel or quantum communication channel(s) may comprise or represent a communication channel capable of transmitting and / or receiving at least quantum 5 information. Examples of a quantum channel or quantum communication channel or quantum channel that may be used according to the disclosure may include or be based on, without limitation, for example on one or more types of quantum communication channels associated with the group of: optical quantum communications; free-space optical quantum communications; optical fibre quantum communications; optical laser quantum 10 communications; communications using electromagnetic waves such as, without limitation, for example radio, microwave, infra-red, gigahertz, terahertz and / or any other type of electromagnetic wave communications; communications based on electron spin and the like; any other type of quantum communications for transmitting and receiving data over a quantum communication channel between devices. It is noted that one or more types of 15 quantum communication channel(s) may be capable of transmitting and / or receiving nonquantum or classical information.

[00254] A communication channel or standard, classical or non-quantum communication channel(s) may comprise or represent any communication channel between two devices that at least is capable of transmitting and / or receiving non-quantum information. Examples of a 20 communication channel, and / or standard, classical and / or non-quantum communication channels according to the disclosure may include or be based on, without limitation, for example on one or more types of communication channels from the group of: any one or more physical communication channel(s); optical communication channel; free-space optical communication channel; wireless communication channel; wired communication channel; 25 radio communication channel; microwave communication channel; satellite communication channel; terrestrial communication channel; optical fibre communication channel; optical laser communication channel; telecommunications channels; 2G to 6G and beyond telecommunications channels; logical channels such as, without limitation, for example Internet Protocol (IP) channels; any other type of logical channel being provided over any 30 standard, classical or non-quantum physical communication channel; one or more other physical communications or carriers of data such as, without limitation, for example avian carriers, paper, sealed briefcases, courier or other delivery service and the like; any other type of one or more optical, wireless and / or wired communication channel(s) for transmitting data between devices; and / or two or more optical, wireless and / or wired communication 35 channel(s) that form a composite communication channel for transmitting data between devices; and / or any combination of two or more standard, classical or non-quantum communication channel(s) that form a composite communication channel for transmitting 48 2020380554   25 May 2026 and / or carrying data between devices; combinations thereof, modifications thereto, and / or as described herein and the like and / or as the application demands. It is noted that one or more types of communication channels, standard, classical or non-quantum communication channel(s) may be capable of transmitting and / or receiving quantum information. As 5 described, a quantum-safe (QS) communication channel comprises or represents a communication channel that is encrypted using a quantum safe key or a quantum-distributed (QD) cryptographic key or QD key.

[00255] The QS servers, the identical sets of QD keys and the repository / ledger are combined and configured in a manner that enables for, without limitation, for example secure 10 collection, secure storage, transmission of data items, secure communications, and also interaction with those data items by its users. For example, for each data item to be stored, a QS server may be configured to generate a unique quantum reference (QREF) locator, which may be based on input data associated with the data item, and assign an available or useable QD key from the set of QD keys for encrypting said data item. The encrypted data 15 item is stored in the repository / ledger of the QS system with the QREF locator. Each assigned QD key is mapped to the corresponding QREF locator. A QREF access token may be generated based on the QREF locator and / or the input data using an irreversible or oneway function, operation and / or process. The QREF access token may be distributed to allow users access to the data item in some manner. Submission of the QREF access token along 20 with identifying / authentication data from the user may enable the QS system to identify the QREF locator and allow the user to access and / or perform access operations in some manner depending on the QREF access token, the data item. The QS system according to the disclosure enables a host of applications to be deployed to users from QS certificates, QS KYC, QS-depository through to quantum-resistant and / or QS end-to-end communications 25 between end-point devices of users registered with the QS system.

[00256] For example, accessing a data item in some manner may include, without limitation, for example allowing users via their user devices to perform one or more access operations associated with accessing the data item which may include, without limitation, for example direct access operations on the data item, read access operations on the data item, write 30 access operations on the data item, indirect access operations on the data item e.g. query access operations in which the data item is only allowed to be queried by the user using the QREF access token rather than directly accessed by the user (e.g. avoiding transmission of the data item over unsafe networks). User's access to the data item may be based on the QREF access token. The QREF access token may be further used to define and / or provide 35 access permissions to the user in relation to the data item, the access permissions may include, without limitation, for example include, without limitation, for example read access, write access, query access, one or more geolocation access permissions that are compliant 49 2020380554   25 May 2026 with geolocation rules associated with the data item ensuring the data item is only, without limitation, for example accessible and / or viewable in certain geolocations / geographies and the like and / or as the application demands.

[00257] The QS system is configured for receiving an identical set of QD keys at each QS 5 server that are distributed from a QKD source in a quantum-safe manner. For example, for QS servers located or positioned in a large geographic region (e.g. one or more of a plurality of QS servers are located in numerous geographic regions / countries / jurisdictions around the world to form a world-wide QS network), the QKD source may use Satellite Quantum Key Distribution for distributing an identical set of QD keys to each of the plurality of QS server(s) 10 and / or one or more subsets of the plurality of QS server(s) using a group and / or multi-cast QKD protocol. Furthermore, the QS system may use a repository / ledger that is configured for storing and / or retrieving one or more data item(s) using distributed ledger technology (e.g. shared ledger software technology), in which multiple QS server(s) of the plurality of QS server(s) include DLT node functionality and form a DLT repository / ledger within the QS 15 system / network for providing a Quantum Safe, or “Provably Secure” method for the secure storage, collection, retrieval, transmission of data items, and / or providing applications associated with the data items stored in the QS network and interaction with that data / data item(s) by its users. Use cases of the QS system range from quantum-resistant to quantumsafe communications between end-point devices, messaging to web certification, 20 authentication to digital asset custody and / or trading, data or document repository, DLT signature and verification to digital wallets for DLT / blockchain system and many others.

[00258] For example, an advantage of the configuration of the QS system according to the present disclosure is that it enables two users to quickly and remotely establish a quantumsafe communication channel and / or at least a quantum-resistant communication channel 25 between them using any communication device, end-point device or computing device such as, without limitation, for example a laptop, desktop computer, personal computer, mobile phone, smart-phone, or Internet of Things (IoT) device, user server, and / or any other computing or communication device. For example, two counterparties or users that are previously unknown to each other and have no prior connection may use the QS system to 30 quickly and remotely establish a quantum safe communication channel between them using any end point device. In another example, two counterparties or users that are previously known to each other and have a prior connection may use the QS system to also quickly and remotely establish a quantum safe communication channel between them using their end point devices. In another example, at least two different IoT devices that are previously 35 unknown to each other and have no prior connection may use the QS system to quickly and remotely establish a quantum safe communication channel therebetween (e.g. a quantum safe communication between a first IoT device and a second IoT device, server and / or any 50 2020380554   25 May 2026 other device). In another example, at least two IoT devices that are previously known to each other and have a prior connection may use the QS system to also quickly and remotely establish a quantum safe communication channel therebetween. The IoT devices may be associated with defined control systems or reporting systems in cloud computing, FOG 5 computing architectures and / or FOG networking architectures and the like and / or as the application demands, and / or any other system using IoT devices that require quantum-safe communications therebetween. Although the user end point devices and / or computing / communication devices with users are described, this is for simplicity and by way of example only and the invention is not so limited, it is to be appreciated by the skilled 10 person that user end point device or communication devices with users are only example devices that may operate with the QS system enabling QS communications and / or other use cases as described herein, and the skilled person would appreciate that any the user end point device and examples thereof are applicable to any other device with or without a user or operator / control system that is capable of communicating over a communication channel 15 with one or more other devices such as, without limitation, for example IoT devices, sensor devices, robotics devices, smart devices, laptop, desktop computer, personal computer, mobile phone and / or any other computing or communication device and the like as the application demands.

[00259] In another example, an advantage of the configuration of the QS system according to 20 the disclosure is that it enables the deposit, storage and / or retrieval / access to data items and / or use of data items and / or application of data items in a quantum-safe manner. For example, registered users of the QS system such as, without limitation, for example customers, individual users, and / or corporate users of the QS system can deposit and store data items / data (e.g. identity records, documents, and / or any data and / or information of value 25 to a user) within the QS network of the QS system in a manner which is quantum-safe (QS). Once stored in the QS network (e.g. within a repository / ledger of the QS network), these data items / data may be queried, retrieved, accessed and / or used in applications by the users and / or third parties in a QS manner. For example, counterparties can instruct, execute and settle the transfer of digital assets in an entirely QS manner. 30

[00260] In another example, one or more QS server(s) of the QS system may include a QS DLT signing / verification mechanism / application that uses QD keys from the identical set of QD keys distributed using QKD and stored in a QS manner by the QS server(s) (e.g. unbreakable QD keys) such that, without limitation, for example user transactions can be submitted to the QS system for QS DLT signing prior to submission to the counterparty to the 35 transaction and / or prior to submission into, for example, an external DLT and / or blockchain systems. The QS system eliminates the need or requirement for users to have their private / public keys for signing / verifying blockchain / DLT transactions stored on their end-point 51 2020380554   25 May 2026 device, but rather enables the user to have their private / public keys and / or even a set of private / public QD keys assigned from the set of QD keys on a QS server to be securely stored and accessible in a QS manner. This enables QS signing / verification of blockchain / DLT transactions, which substantially mitigates malevolent actors or hackers 5 misuse / stealing transactions or digital assets or submitting false transactions from private / public keys stolen from a user's end-point device or conventional digital wallet.

[00261] An example QS system according to the disclosure is now briefly described. Although some specific components, devices, mechanisms, apparatus, system(s) and / or elements are described in the following example QS system, this is by way of example only 10 and the invention is not so limited, the skilled person in the art would understand that the following example QS system may include other elements, components and the like and / or be combined, merged, and / or modified with the other example QS systems, use cases and the like as described with reference to the figures and / or as described herein. An example of the QS system according to the disclosure may include, without limitation, for example the 15 following components and / or elements. The example QS system includes a QS network formed by a plurality of QS server(s) and / or QS repository / ledgers storage system that communicate with each over communication channels using the same set of QD keys in a quantum-safe manner.

[00262] For example, the QS system may store data items / data in a disaggregated manner in 20 the repository / ledger storage system using such as, without limitation, for example a Redundant Array of Inexpensive / Independent Disks or Drives (RAID) system coupled with distributed ledger of geographically dispersed QS servers that have DLT node functionality. Each QS server of the QS network may include a QKD communication system that is configured to enable distribution of the same set of quantum distributed (QD) keys, or a so- 25 called identical set of QD keys from a QKD source using quantum channels and the like. For example, each QS server of the QS network may include an Satellite QKD (SQKD) communication system (e.g. an On-Ground Communication Satellite Receiver) that connects to a satellite network that enables via a QKD multi-cast or group mode (or protocol) the QKD communication system to receive from a satellite of the satellite network the same set of 30 quantumly generated random number encryption keys, a so-called identical set of QD keys, as the other QS servers. The QD keys may be distributed using QKD via a satellite quantum optical channel from the satellite. In another example, each QS server of the QS network may include a terrestrial QKD communication system (e.g. an optical fibre communication receiver) connected to a QS optical fibre network that is configured to enable reception from 35 a QKD source connected to the optical fibre network of a set of quantumly generated random number encryption keys, so-called QD keys, from the QKD source over the optical fibre network via a fibre optical quantum channel. Although SQKD and terrestrial QKD has been 52 2020380554   25 May 2026 described, by way of example only and not limited to, as described herein, it is to be appreciated by the skilled person that the QKD source may be any other type of QKD source or source(s) configured for distributing the same or similar sets of QD keys to each of the QS servers of the QS network and / or as the application demands. 5

[00263] The QD keys may be paired with a quantum-safe and / or symmetrical algorithm such as, without limitation, for example One Time Pad (OTP), Bit-Flipping Key Encapsulation (BIKE) and variants thereof and the like, AES 512 and the like, other provably secure cryptographic algorithms from National Institute of Standards and Technology (NIST) and / or any other similar cryptographic standards bodies, and / or any other provably secure 10 cryptographic algorithm in a post-quantum world, that can guarantee that the set-up of quantum-safe communication channels (even communication channels over standard telecommunication links) between the QS server(s) of the QS network that are provably secure and, may be configured, to be quantum-safe. It is to be appreciated by the person skilled in the art that the cryptographic algorithm used with the QD keys (also referred to as 15 quantum keys) to form the QS communications channels may be any suitable cryptographic algorithm that is provably secure and / or quantum-safe. In the QS system, the plurality or a majority or subset of the QS server(s) of the QS network may form a private or intranet-type QS network and is configured not to be directly Internet accessible or publicly accessible. That is, a QS server of the private QS network may only communicate with other QS 20 server(s) over a QKD connected private circuit in meshed configuration, and that communication only happens over quantum-safe communication channels (or QS channels), which are telecommunications or communications channels of a communication network encrypted using one or more provably secure cryptographic algorithms with one or more of the available or usable QD keys (or quantum keys) from the set of QD keys distributed from 25 the QKD source to each QS server of the QS network. The "private" QS network creates a “Quantum Safe Boundary” within which data items are stored and accessible in a quantumsafe manner.In order to enable users and / or customers to store and / or access data items within the QS network, one or more of the QS servers may act as or include the functionality of at least a QS registration server. The QS registration server may be connected over 30 quantum-safe channels to one or more registration nodes, which a user or customer may connect to for registering with the QS system, storing and / or depositing data into the QS system. The QS registration server may be coupled to one or more registration nodes (or registration computing devices) over quantum-safe channels. Each registration node may be allocated or assigned an available QD key from the set of QD keys for establishing a QS 35 communication channel in a quantum-safe manner with the corresponding QS registration server. Alternatively or additionally, each QS server / node may include the functionality of a QS registration server and also gateway functionality, where the QS registration server is connected via the gateway functionality to one nor more registration nodes and the like. The 53 2020380554   25 May 2026 gateway functionality providing a secure interface between the QS registration server and the one or more registration nodes and the like.

[00264] Registration nodes may be accessible to users of the QS system either via communication channels over the Internet and / or public network or via visiting a registration 5 node in person. For example, a user may be required to visit a registration node to, without limitation, for example securely register themselves as a user of the QS system, securely receive one or more QS system applications or software for operating their end-point device in a QS manner with the QS system, securely receive one or more assigned QD Keys from the set of QD keys for storage in a secure enclave on their end-point device for use in 10 quantum-safe communications with the QS system over the public network, and / or for securely submitting data items / digital data via a direct secure physical link with the registration node.

[00265] As mentioned, the repository / ledger storage system that may be implemented using the QS servers and / or by separate QS storage servers may use, without limitation, for 15 example a RAID format or variant thereof for storing data items, which identifiable by a unique address or locator value, a so-called QREF locator, which is generated or created by an algorithm using input data associated with the data item and / or user and a QD key assigned for encrypting the data item. The assigned QD key is extracted from the available QD keys of the set of QD keys securely stored on a QS server, without limitation, for example 20 in a hardware security module (HSM). Each QS server has an identical set of QD keys stored on a corresponding HSM, in which the QS network forms a Meshed HSM or HSM Mesh. As an example, an SQKD system may distribute an identical set of QD keys to each QS server for storage in a corresponding HSM of the QS server. This may be achieved by a group or multi-cast QKD protocol by the satellite, which stores the identical set of QD keys 25 and uni-casts the data representative of the identical set of QD keys to each QS server as it passes over. Once all the required QS servers have received data representative of an identical set of QD keys, the satellite removes or deletes said data representative of the identical set of QD keys. This may be repeated for updating each QS server with further identical sets of QKD keys as and when required. 30

[00266] For example, the input data may include, without limitation, for example the user’s private key or user secret and the assigned QD key extracted from the Meshed HSM of the QS network and are combined using the QREF algorithm to generate a unique QREF locator for storing the encrypted data item (encrypted with the assigned QD key) in the repository / ledger system of the QS network. A linking or mapping of the QREF locator to the 35 QD key assigned to the data item is stored each HSM of the QS network, i.e. in the Meshed HSM. The mapping between the assigned QD key and QREF locator stored in the Meshed 2020380554   25 May 2026 HSM and the storage of the encrypted data item within the QS repository / ledger system of the QS system using the QREF locator creates a QS “Locker” or storage location for the data item. The encrypted data item is stored in the QS system in such a manner that it can only be retrieved, accessed, decrypted and / or used and the like with knowledge of the QREF 5 locator used to store it. The QS "Locker" or storage location of the data item can only be accessed with the corresponding QREF locator. Given this, the QS system only stores data representative of the QREF locator linked with the assigned QD key within the HSM of the QS servers of the QS network. Thus, the QREF locator is securely stored in the HSM of the QS servers of the QS network and is not distributed or accessible otherwise. That is, the 10 QREF locator is inaccessible to users of the QS system and is not distributed outside the Meshed HSM of the QS system or even the QS boundary of the QS network.

[00267] An HSM of a QS server may comprise or represent a physical computing device, component or apparatus that is configured to safeguard and manage, without limitation, for example cryptographic or QD keys, and provide, without limitation, for example secure 15 execution of core modules / components such as, without limitation, for example critical instructions, code, computer-implemented methods / process(es) and the like implementing core functionality of a QS server associated with generation of QREF locators, QREF access tokens, identification of QREF locators from QREF access tokens, encryption / decryption operations and / or secure storage of one or more sets of QD keys, and data items. The HSM 20 includes anti-tampering technology that may, without limitation, for example wipe secrets / QD keys and the like in case of physical and / or software breach and the like.

[00268] A user or customer end-point device or device may comprise or represent any device, computing device and / or communications device capable of communicating over a communication network, where the device / computing device and / or communication device is 25 associated with the user or customer. Examples of end-point devices and / or devices may include, without limitation, for example a laptop, desktop computer, personal computer, mobile phone, smart-phone, or Internet of Things (IoT) device and the like, user server, customer server(s), and / or any other computing or communication device. Users and / or customer end-point devices and / or communications devices may establish a quantum-safe 30 communication channel with the QS system, within the QS system and / or end-to-end quantum-safe communication channel with other user and / or customer end-point devices. This may be achieved through the end-point device connecting to a QS server and / or a corporate network hosting a QS server that includes, without limitation, for example an SKQD system and so has a set of QD keys, one or more of which may be assigned to the end-point 35 device of the user and stored in a secure enclave or secure memory on the end-point device. The end-point device may use the one or more assigned QD keys to establish a QS channel 2020380554   25 May 2026 with the QS system, and hence, may establish a QS channel to other one or more similarly configured end-point device(s) and the like.

[00269] Alternatively or additionally, one or more end-point devices may be registered with the QS system through a registration process (e.g. a QREF Device Registration Process) in 5 which one or more QD keys from the set of QD keys may be assigned and / or installed in a secure memory / enclave of the end-point devices. The QD keys assigned to the end-point device may be stored as one or more data items in the QS repository of the QS system along with a corresponding QREF locator for each data item. When a user receives the end-point device with a QD key installed thereon, the user may register via a QS registration server of 10 the QS system (e.g. via a web portal and / or web interface) or directly at a registration node in which the QS system updates the registry in relation to the end-point device as being associated with the registered user. The user of the end-point device may then use a QREF application to establish a quantum-safe communication channel between the end-point device and the QS system using the previously assigned QD keys stored in the secure 15 enclave of the end-point device. Each user, once signed into the QS system, via their endpoint devices and having established a QS channel may then request a call or connection with one or more other users of the QS system, in which their end-point devices also establish a quantum-safe communication channel with the QS system, and so the QS system may facilitate the establishment of a quantum-safe communication pipe (series of channels) 20 through he QS network to each end-point device in relation to the requested call or connection. The QS system may thus build up a user directory or registry and, over time, establish the user connection or contact lists for each user allowing said each user to contact other users in a quantum-safe manner.

[00270] Another aspect of the QS system includes generating a QREF access token when a 25 QREF locator is generated during storage of a data item in the QS repository / ledger of the QS network / system. The QREF locator may be linked in the HSM to those users given permission to access the data item in some manner. When a QREF locator is generated in relation to a data item that is to be accessed or used by one or more users, a QREF access token is generated based on the QREF locator using an irreversible or one-way function, 30 operation and / or process (e.g. a hash of the QREF access token). The QREF access token may be distributed to users of the QS system and enables those users with permissions to access to the data item in some manner to do so by presenting the QREF access token to the QS system. On presenting the QREF access token to the QS system (e.g. a QS registration server and / or registration nodes), a user is required to register (if not already 35 registered with the QS system) and / or login to the QS system which requires user credentials / authentication data / passwords and / or other input data that may be associated with generating the QREF locator and / or associated with those users with permissions to 56 2020380554   25 May 2026 access the data item in some manner. Thus, with the submission of the QREF access token along with identifying / authentication data from the user, a QS server may use a QREF identification algorithm, which is securely executed, to identify the QREF locator associated with the QREF access token, whilst also checking that the user is who they say they are and 5 are allowed or have permissions to access the data item corresponding to the identified QREF locator. Once this is confirmed, the user is allowed to access, in some manner depending on the QREF access token and permissions given to the user, the data item corresponding to the identified QREF locator. For example, the QREF identification algorithm may be configured to identify the user submitting the QREF access token by 10 requesting the user credentials of the user.

[00271] Although the QREF access token may be sent over a quantum-safe channel to the user of an end-point device that is already registered with the QS system as outlined above, there are also various applications in which a QREF access token may simply be sent over a non-quantum-safe channel to the user of an end-point device. That is, the QREF access 15 token is designed such that it cannot be used by anyone other than users with permissions to use the QREF access token. Furthermore, although the QREF access token is derived from the QREF locator, the QREF access token is created or generated in such a way that the QREF locator cannot be determined from the QREF access token. Thus, the QREF access token may be sent to third parties or other users over traditional communications networks, in 20 which these users may have limited access or permissions to use or query the corresponding data item stored in the QS system.

[00272] When the user or customer of the QS system wishes to access the data item in future, or grant third party access to the data item or perform some transaction on the data item, it can only do so if that user, customer and / or third party has a QREF access token 25 associated with the data item. This may be generated by the QS system as described above, or on request by the user and / or customer of the QS system that submitted the original data item for QS storage and access in the QS system. At a later stage or time, the user, customer and / or third party may then deliver their QREF access token to the QS system, e.g. via one or more QS registration servers or nodes, along with its private key and 30 authentication. The QS system uses a QREF identification algorithm that then deduces from the QREF access token (e.g. a one-way hash of the QREF locator) the QREF locator (or address) and thus recovering the QD key from the QS server's HSM used to encrypt the data item. This enables the QS system to refer to the data item stored in the QS repository / ledger system using the identified QREF locator and access it for the requested purpose (e.g. 2020380554   25 May 2026 returning a required answer to a query on the data item, and / or any other access operation that the original user set).

[00273] In some applications the QREF access token is presented to all QS servers operating Nodes in the distributed ledger network of the QS system, which all have access to 5 the same QD Keys (e.g. same Quantum Keys), where each node is configured to operate to deduce the QREF locator from the QREF access token, where the Nodes form a consensus by performing the same operations on the QREF access token to confirm that the resulting QREF locator is correct and the request is valid. In some applications the Hash is presented to all Nodes in the distributed ledger network of the QS system, which all have access to the 10 same Quantum Keys, and Nodes form a consensus by performing the same operation on the Hash to confirm that the request is valid. This approach for what is already a quantum safe operation provides operational and network reliability advantages.

[00274] The QS system according to the disclosure enables a host of applications to be deployed to users from QS certificates, QS KYC, QS-depository through to quantum-resistant 15 and / or QS end-to-end communications between end-point devices of users registered with the QS system.

[00275] Figure 1a is a schematic diagram illustrating another example quantum-safe (QS) system 100 and QS network 101 according to the disclosure. It is to be appreciated by the skilled person that QS system 100 can be adapted, modified and / or combined with one or 20 more other QS systems described herein with reference to the figures and / or as described herein. Referring to figure 1a, the QS system includes a QS network 101 and a non-QS network 102. The QS network 101 is formed by a plurality of quantum-safe (QS) servers 103a-103l and a QS repository 107 for storing and accessing data items in relation to a first plurality of users 104a-104m and a second plurality of users 105a-105n. The QS network 25    101 requires that each of the QS servers 103a-103l includes a hardware security module (HSM) of a plurality of HSMs 106a-106l in which each HSM of the plurality of HSMs 106a-106l includes at least a set of quantum distributed (QD) keys (also referred to as quantum keys) stored thereon that enable the QS servers to communicate securely in a quantum-safe manner with each other, the QS repository 107 and / or one or more user devices using one or 30 more available QD key(s) from the identical set of QD keys stored on each HSM 106a-106l.

[00276] As described, each of the QS servers 103a-103l has an HSM 106a-106l that includes a set of QD keys stored thereon. The set of QD keys stored on each of the HSMs 106a-106l may be an identical set of QD keys stored thereon, which enables the QS server(s) 103c-103l to communicate with each other over quantum-safe (QS) communication channels 35    108a-108p (e.g. using symmetric encryption). For example, each of the QS servers 103a- 2020380554   25 May 2026 103l uses a QD key from the set of QD keys to form a QS communication channel with one or more of the other QS servers 103a-103l and the QS repository 107 by encrypting a communication channel (e.g. IP channel) of a communication network (e.g. the Internet or any other communication network) using said QD key. Thus, the QS servers 103a-103l and 5 QS repository 107 when connected and / or in communication with each other via QS channels forms the QS network 101. Alternatively or additionally, each of the HSMs 106a-106l may have a set of QD keys stored thereon in which a subset of the set of QD keys are identical with a corresponding set of QD keys of one or more of the other HSMs 106a-106l, where the identical QD keys of the subset may be used for quantum-safe communications 10 over the communications network using QS channels 108a-108p. In any event, each of the HSMs 106a-106l includes an identical set of QD keys or an identical subset of QD keys stored thereon that enable the QS servers 103a-103l to communicate securely over one or more QS channels 108a-108p in a quantum-safe manner with each other, the QS repository 107, and / or one or more user devices using one or more available QD keys from the identical 15 set / subset of QD keys. The QS server(s) 103a-103l when communicating over quantum-safe communication channel(s) form the QS network 101 with a quantum safe boundary within which quantum-safe communications occurs between the QS server(s) 103a-103l, repository 107 and / or one or more user QS servers, devices and the like within the QS network 101. Furthermore, each of the QS servers or devices of the first plurality of users 104a-104m may 20 also have a hardware security module (HSM) that also includes an identical set / subset of QD keys stored thereon enabling these user QS servers or devices to communicate securely in a quantum-safe manner with the QS servers 103a-103l of the QS network 101 and / or the QS repository 107 using one or more available QD keys from the set / subset of QD keys.

[00277] Alternatively or additionally, each HSM 106a-106l may receive a set of QD keys 25 based on a quantum key distribution (QKD) protocol / process and the like, where each set of QD keys includes at least an identical subset of QD keys to one or more other sets of QD keys received by one or more other HSMs. Each HSM may file or submit their set of QD keys for storage in the QS repository 107. Each unique QD key is stored in the QS repository 107 may be assigned a corresponding unique quantum key identifier (e.g. QKID). 30 When a set of QD keys are submitted or filed, they may be compared with previously submitted sets of QD keys so duplicate QD keys are discarded and only unique QD keys are stored against a unique quantum key identifier in the QS repository 107. The unique quantum key identifier may be used or sent to one or more QS servers requiring a quantumsafe communication channel with each other or other devices over a communication network. 35 The QS servers use the unique quantum key identifier to retrieve the corresponding QD key 2020380554   25 May 2026 from the QS repository 107 and / or corresponding HSM 106a-106l for setting up a quantumsafe communication channel.

[00278] A quantum-safe (QS) device / node or server 103a-103l may comprise or represent any computing device, node, apparatus, hardware or server with a set of QD keys (or set of 5 quantum keys) stored thereon and configured with the capability of performing quantum-safe (QS) communications with each other and / or with one or more user device(s) over a communication network, and / or configured with the capability of receiving one or more sets of QD keys from a QKD source using QKD, quantum channels (e.g. channels that transmit quantum information) and the like. For example, a QS server may be configured to, by way 10 of example only but is not limited to, serve and / or distribute QD keys to one or more user device(s) via quantum-safe communications channels (e.g. a communication channel encrypted by a QD key) over a communication network enabling such user device(s) to communicate in a quantum-safe manner; serve and / or process one or more user requests associated with registration, storing and / or accessing data items within the QS network; 15 serve and / or process one or more user requests for quantum-safe communication between user device(s) of users of the QS network and / or QS servers and the like; receiver and / or process data representative of one or more QD keys (or QD keys) distributed in a quantumsafe manner form a QKD source using a QKD protocol and / or quantum channels and the like. 20

[00279] Each of the HSMs 106a-106l may be configured to securely manage and / or store cryptographic keys such as, but not limited to, for example QD keys or a set of QD keys such that any unauthorised attempts to extract the QD keys are blocked and / or detected. An HSM may include one or more tamper-resistance and / or tamper-detection sensors such as, by way of example only but not limited to, wire cages surrounding encapsulated memory 25 modules, detection of over- or under- voltages and / or temperatures, or any other sensor or software for detecting tampering and / or unauthorized access of a QD key etc. An HSM may also be configured to provide restricted and authenticated communications interfaces to the cryptographic systems of end users such as QS server(s) of the QS network. In essence, an HSM 106a-106l comprises or represents a computing device or apparatus configured for at 30 least securely storing one or more cryptographic or digital keys for use in, for example, authentication and / or cryptographic operations / processing and the like. Examples of HSM(s) that may be used by the invention as described herein may include or be based on, by way of example only but is not limited to, any apparatus, hardware, cryptographic module, memory unit, platform, device and / or processor configured to at least securely store, manage and / or 35 protect cryptographic and / or digital keys and the like; dedicated cryptographic hardware comprising one or more processor(s), processing unit(s), chip(s), module(s) and / or memory with tamper resistant, tamper evidence or tamper responsive functionality and / or packaging 60 2020380554   25 May 2026 for securely storing cryptographic and / or digital keys; apparatus or hardware comprising one or more secure cryptoprocessor chips configured to prevent tampering and / or probing whilst storing, protecting and / or managing one or more cryptographic keys stored thereon; apparatus or hardware including a one or more processor(s) or processor units (e.g. 5 microprocessor(s) and the like) in a module that is protected by the tamper evident, tamper resistant, or tamper responsive packaging; any other hardware or apparatus configured for at least securely storing, managing, and / or protecting cryptographic and / or digital keys and the like that are compliant or internationally certified with one or more computer security standards such as, by way of example only but not limited to, Common Criteria for 10 Information Technology Security Evaluation (e.g. Common Criteria) or FIPS 140; and / or one or more modifications thereof, one or more combinations thereof and the like, and / or as the application demands.

[00280] The QS network 101 may further include a QD key or quantum key assignment mechanism, component and / or controller (now shown) configured and / or operable to ensure 15 each of the QS servers 103a-103l requesting one or more available QD keys from the identical set of QD keys stored in the corresponding HSM(s) 106a-106l and / or in the QS repository 107 are not already in use. For example, each QD key in the identical set of QD keys stored on each HSM 106a-106l and / or QS repository 107 may be assigned a unique quantum key identifier (e.g. QKID), where the QD key assignment mechanism / controller 20 manages the assignment of the QD keys from the set of QD keys based on the quantum key identifiers in response to a request for one or more available QD keys. A QS server 103a-103l may thus request one or more available QD key(s) and the QD key assignment mechanism / controller allocates one or more quantum key identifiers of available QD keys that the QS server can use. The HSM 106a-106l of the QS server 103a-103l may provide 25 access to the QD keys corresponding to the allocated quantum key identifiers.

[00281] For example, the QS servers 103a-103l can use the identical sets of QD keys stored in the corresponding HSMs 106a-106l or QS repository 107 to set up quantum safe communication channels with each other and with the QS repository 107 using quantum encryption based on one or more available QD keys from the set of QD keys. The set of QD 30 keys are distributed to each of the QS servers 103a-103l in a quantum-safe manner, by way of example only but not limited to, satellite quantum key distribution, optical quantum key distribution, fibre optic quantum key distribution, and / or any other quantum key distribution scheme capable of delivering a set of QD keys to a plurality of QS servers 103a-103l in a quantum-safe manner. Whatever QKD scheme is used, updated sets of QD keys may be 35 delivered when required and / or according to a schedule and the like, and / or as the application demands. 2020380554   25 May 2026

[00282] Each of the first plurality of users 104a-104m have, without limitation, a QS server and / or QS device that is part of the QS network 101. The QS server and / or devices of the first plurality of users 104a-104m may include a HSM with a set of QD keys (or a set of quantum keys) stored thereon, which have been distributed to these devices using QKD 5 scheme used to deliver the set of QD keys to the QS servers 103a-103l of the QS network 101. For example, the QS servers and / or QS devices of each of the first plurality of users 104a-104m may communicate securely in a quantum-safe manner with the QS servers 103a-103l and / or the QS repository 107 using one or more available QD keys from the set of QD keys. 10

[00283] Each of the second plurality of users 105a-105m have, without limitation, a user server, user device, end-point device and / or communication device that is part of the non-QS network 102. The non-QS network 102 includes, by way of example only but is not limited to, any communication network that is outside the QS network 101 such as, without limitation, the Internet, public networks, telecommunications network, conventional private network(s) 15 and the like, which typically use conventional cryptography techniques for securing communications. The user devices of the second plurality of users 105a-105m may communicate with each other over the non-QS network 102. The user devices of the second plurality of users 105a-105m may also communicate and / or transact with one or more QS servers 103a-103l that are on the edge or boundary of the QS network 101 in relation to data 20 items stored in the QS repository 107. These one or more QS servers 103a-103l form a QS boundary or region.

[00284] The QS system 100 is configured for enabling the secure storage, access and / or retrieval of data items by one or more of the plurality of users 104a-104m and / or 105a-105n in a manner that prevents any non-QS user from directly accessing the data items stored in 25 the QS repository 107. Data items are stored in the QS repository 107 using an available QD key from the set of QD keys to encrypt each data item. Since the QS repository 107 is stored on a QS network 101 with QS servers 103a-103l that are connected exclusively by quantum safe communications channels, the data items held in the QS repository are not publicly accessible over the non-QS network 102 such as, without limitation, for example the Internet 30 or other public network. The QS system 100 thus manages, via the QS network 101, secure storage and access and / or retrieval of data items stored in the QS repository 107 whilst ensuring the data items remain quantum safe.

[00285] In particular, the QS system 100 manages storage of data items to the QS repository 107 using so-called a unique quantum reference (QREF) locator for each data item. A 35 unique QREF locator is generated for each data item using one or more cryptographic primitives and / or operations on at least in part data representative of the available QD key 2020380554   25 May 2026 used to encrypt the data item for storage in the QS repository 107 and a user secret of the user requesting storage of the data item. The QREF locator is used as an address for storing the data item within the QS repository 107 and is also used to the identify the user associated with the data item and / or the identities of users provided permission to access the data item 5 and the like. The QREF locator is stored in a QS manner in the QS network 101 on one or more of the QS servers 103a-103l of the QS network 101. The QS system 100 also manages access, access operations and / or retrieval to one or more data items stored in the QS repository 107 using so-called access tokens associated with each data item stored in the QS repository 107. The access token(s) for a data item are generated based on the 10 QREF locator used to store the data item in the QS repository 107. The access token(s) are unique and generated in a one-way manner in which data representative of the QREF locator cannot be derived or determined. The access tokens may be provided to the user of the data item and / or other users of the first and / or second plurality of users 104a-104m and / or 105a-105n to enable these users to, without limitation, access or perform access operations, 15 and / or retrieve the data items from the QS repository 107.

[00286] Figure 1b is a flow diagram illustrating an example QS storage process 110 of storing data items in the QS system 100 using the QS network 101 of figure 1a according to the disclosure. The QS network 101 including a plurality of QS servers 103a-103l and a QS repository 107 is used for storing data items of one or more of the plurality of users 104a- 20   104m and 105a-105n in a quantum-safe manner. Each of the QS servers 103a-103l may include an secure memory (not shown) (e.g. a hardware security module) for storing an identical set of quantum distributed (QD) keys, said identical set of QD keys having been distributed to each of said QS server(s) in a quantum-safe manner, and said QS server(s) 103a-103l configured to communicate securely with each other via one or more QS channels 25 and the QS repository 107 using one or more available QD keys from the identical set of QD keys.

[00287] The QS storage process 110, which may be performed by one or more of the QS servers 103a-103l and the like, may include one or more of the following steps of: In step 112, receiving a data item for storage in the QS repository. In step 114, generating a 30 quantum reference (QREF) locator item based on input data associated with the data item for storage and an available QD key selected from the set of QD keys. The QREF locator is a unique identifier that may be used as a logical address for storing the data item in the QS repository. In step 116, sending the QREF locator along with the data item encrypted with the available QD key to the QS repository using said one or more QS channels. 35

[00288] Figure 1c is another flow diagram illustrating another example QS storage process 120 of storing data items in the QS system 100 using the QS network 101 of figure 1a 2020380554   25 May 2026 according to the disclosure. The QS network 101 including a plurality of QS servers 103a-103l and a QS repository 107 is used for storing data items of one or more of the plurality of users 104a-104m and 105a-105n in a quantum-safe manner. Each of the QS servers 103a-103l may include a secure memory (not shown) (e.g. a hardware security module or secure 5 processor enclave such as Intel Software Guard Extensions on Intel x86 Processors and the like) for storing an identical set of quantum distributed (QD) keys, said identical set of QD keys having been distributed to each of said QS server(s) in a quantum-safe manner, and said QS server(s) 103a-103l configured to communicate securely with each other via one or more QS channels and the QS repository 107 using one or more available QD keys from the 10 identical set of QD keys.

[00289] The QS storage process 120, which may be performed by one or more of the QS servers 103a-103l and the like, may include one or more of the following steps of: In step 122, receiving a data item for storage in the QS repository. The data item may be associated with a user and / or the QS server on behalf of a user, and / or one or more components of a 15 QS server and the like. In step 123, selecting an available QD key from the set of QD keys for encrypting the data item. In step 124, generating a quantum reference (QREF) locator item based on input data associated with the data item for storage and an available QD key selected from the set of QD keys. The QREF locator is a unique identifier that may be used as a logical address for storing the data item in the QS repository. 20

[00290] In step 125, the QREF locator is mapped to the QD key and also the QREF locator is mapped to the data item when encrypted with the selected QD key and stored in the QS repository. This enables the encrypted data item to be located based on the QREF locator and for the encrypted data item to be decrypted.

[00291] In step 125a, linking the QREF locator to the available QD key of the set of QD keys. 25 This may involve mapping the QREF locator to the QD key from the set of QD keys. For example, this may be performed by having a QREF-QD key data structure, schema, table or list that includes a plurality of records in which each record includes, without limitation, for example a QREF locator field and a QD key identifier field. A QREF locator may be mapped to a QD key by populating a record by inserting the QREF locator into the QREF locator field 30 and inserting the QD key identifier of the selected QD key from the set of QD keys. Thus, a QREF locator may be mapped to a selected QD key. The QREF-QD key data structure may be stored in the secure memory along with the set of QD keys in each of the QS servers 103a-103l.

[00292] In step 125b, linking the QREF locator to the encrypted data item when stored in the 35 QS repository, which may include a QREF-Data Item data structure, schema, list or table 2020380554   25 May 2026 stored by the QS repository, in which the QREF locator is mapped to the data item. For example, the QREF locator may be mapped to the physical address of where the data item is being stored in the QS repository.

[00293] In step 126, encrypting the data item using the selected QD key and, in step 127, 5 sending the QREF locator and encrypted data item via one or more QS channels to the QS repository for storage, where the encrypted data item is linked / mapped to the QREF locator when stored.

[00294] Figure 1d is a flow diagram illustrating an example process 130 of accessing data items stored in a QS system using process 110 according to the disclosure. It is assumed 10 that a QREF locator has already been generated in relation to a data item as described, without limitation, for example, in process(es) 110 and 120. The process 130 for enabling a data item to be accessed when stored in the QS repository with a QS locator may include following steps of: In step 132, generating a QREF access token for accessing the data item based on the QREF locator using an irreversible function, process or operation. The QREF 15 access token is a unique number from which the QREF locator cannot be derived. In step 134, sending the generated QREF access token to a device of a user for enabling the user to access said data item. The user may submit the QREF access token to the QS system, which may identify the QREF locator that corresponds to the QREF access token based on user verification and / or authentication and the like. The QS system may then retrieve or 20 provide access operations to the user in relation to the data item associated with the identified QREF locator.

[00295] Figure 1e is a flow diagram illustrating another example process 140 of accessing data items in a QS system in relation to process(es) 110 and / or 120 according to the disclosure. It is assumed that a QREF locator has already been generated in relation to 25 storing a data item as described, without limitation, for example, in process(es) 110 and 120. It is also assumed that a QREF access token has been generated and delivered to a user as described, without limitation, for example in process 130. The process 140 for retrieving or accessing a data item when stored in the QS repository with a QREF locator may include following steps of: In step 142, receiving, from a device of a user, a QREF access token 30 requesting access to a data item stored in the repository. In step 144, identifying a QREF locator based on the QREF access token and input data from the user. This may include, without limitation, for example, identifying set of QREF locators that may be associated with the user. For each QREF locator in the set of QREF locators, a temporary QREF access token may be generated using said each QREF locator in the same process used to create 35 the received access token. Each temporary QREF access token is compared with the received QREF access token and the QREF locator corresponding to the temporary QREF 2020380554   25 May 2026 access token that matches the received QREF access token is the identified QREF locator. In step 144, is it determined whether a QREF locator has been identified in relation to the QREF access token. In response to identifying the QREF locator, (e.g. Y), proceeding to step 145. In response to not identifying the QREF locator, (e.g. N), proceeding to step 147. 5 In step 145, retrieving the encrypted data item from the QS repository, where the data item is decrypted using the QD key corresponding to the QREF locator. The data item may be decrypted in the secure memory of a QS server to prevent the data item from being revealed or exposed to insecure memory and / or other processes and the like. In step 146, providing access operations to the user in relation to the decrypted data item. For example, the access 10 operations may include, without limitation, for example simply confirming that the data item exists; providing an answer to a query associated with the data item; where the query may be submitted with the QREF access token, or as part of the QREF access token, or submitted separately and the like; retrieving and sending the data item to the user (e.g. using QS communications or quantum resistant communications); any other processing operation 15 performed on the data item that provides an output to the user; any other processing operation performed on the data item that provides an output to the user without revealing the data item. In step 147, the QREF locator is not identified from the access token, which may mean that the user was unable to verify and / or authenticate themselves, and hence may have been a malicious actor. In which case, a notification is issued in relation the attempted 20 access to a data item associated with the QREF access token. This may involve sending a notification to one or more users associated with the QREF access token.

[00296] Figure 1f is a flow diagram illustrating another example QS storage process 150 of storing data items in the QS system 100 using the QS network 101 of figure 1a according to the disclosure. The QS network 101 including a plurality of QS servers 103a-103l and a QS 25 repository 107 is used for storing data items of one or more of the plurality of users 104a- 104m and 105a-105n in a quantum-safe manner. The QS storage process 150 may include one or more of the following steps of:

[00297] In step 151, receiving a request for storing a data item by a first user of the plurality of users 104a-104m and / or 105a-105m. 30

[00298] In step 152, in response to receiving a request for storing a data item by the first user, generating a QREF locator based on a user secret of the first user and an available QD key selected from the set of QD keys. The first user may be a corporate user and / or a public user such as, by way of example only but not limited to, Internet users and the like. For example, a corporate user may have access to QS servers and / or QS devices that directly 35 connect to within the QS network. For example, a public user may have access to computing devices and / or endpoints that may connect over a public communications network to a QS 2020380554   25 May 2026 server(s) of the QS network. The QREF locator indicates at least data representative of the location of the data item encrypted with the selected QD key in the QS repository 107 and an identity of the first user. The first user may be a corporate user using a QS server within the QS network 101, and / or may be a user using a computing device over the non-QS network 5    102.

[00299] Registration data of the first user may include, without limitation, for example the QREF locator, identifier of the first user and / or customer number, user secret of the first user, identifier of the data item, access control data such as, without limitation, for example allowed access operations and / or access permissions including identifiers of one or more other users 10 allowed to access the data item and the like, and / or any other data associated with the user and / or data item excluding the data item itself that may be stored in a user record associated with the first user in a user registry or database in the QS repository 107 and / or one or more QS servers 103a-103l of the QS network 101. The user registry or database is only accessible by the QS servers 103a-103l of the QS network 101 and are used to identify the 15 QREF locator associated with the data item based on the QREF access token that is used to access the data item in a quantum safe manner.

[00300] In step 153, generating an QREF access token based on the QREF locator, where the QREF access token enables access operations to be performed on the data item stored in the QS repository 107. An access operation may include, without limitation, for example 20 queries in relation to the data item, updates in relation to the data item, retrieving information associated with the data item, answers to questions in relation to the data item and / or any other type of access operation associated with the data item.

[00301] For example, an QREF access token may be provided by a user to the QS network 101 via a QS server 103a. Registration user data may be used to identify the QREF locator 25 corresponding to the access token. For example, if the user is the first user, then the QS server 103a may retrieve and / or search the registration data of the first user to identify a set of one or more registration records associated with the first user. Each registration record in the set includes a QREF locator corresponding to a data item the first user has stored or has been provided permission to access in the QS repository 107. The set of one or more 30 registration records may also be linked to one or more other users that also have access permissions to access the data items pointed to by the corresponding QREF locators therein. Each registration record in the set of registration records associated with the first user is used to generate an access token, and the registration record that generates an QREF access token that matches the received QREF access token is used to identify the QREF locator and 35 hence the encrypted data item stored in the QS repository 107 that is associated with the received access token. At the same time, the registration record is used to check whether 2020380554   25 May 2026 the user presenting the QREF access token is allowed to access the data item in some manner.

[00302] In step 154, providing the QREF locator and encrypted data item to the QS repository 107 for storing with the encrypted data item in the QS repository 107. The one or 5 more QS servers 103a-103l of the QS network 101 may use the user registry or database when an QREF access token associated with a data item is received to determine the QREF locator corresponding to the data item and so the location of where the data item is stored in the QS repository 107 and / or whether the user providing the QREF access token is allowed to, without limitation, for example access, retrieve and / or perform access operations on the 10 corresponding data item and the like or as the application demands.

[00303] In step 155, the generated QREF access token associated with the data item is sent to the device of the first user. The first user may use the QREF access token to access the data item in the QS repository 107 and / or provide the QREF access token to one or more other users of the plurality of users 104a-104m or 105a-105n for accessing or having access 15 operations performed on the data item and the like. In which case, the first user may have granted on registration or updated their registration in relation to the data item with access controls in relation to one or more other users they have or will provide the QREF access token to. This enables the QS system 100 and QS network 101 to determine whether the user is allowed to use the QREF access token in relation to the data item that is stored in a 20 QS manner on the QS repository 107.

[00304] Figure 1g is a flow diagram illustrating an example QS access process 160 of accessing data items in the QS system 100 using the QS network 101 of figure 1a according to the disclosure. The QS network 101 including a plurality of QS servers 103a-103l and a QS repository 107 is used for storing and enabling access of the data items of one or more of 25 the plurality of users 104a-104m and 105a-105n in a quantum-safe manner. The QS access process 160 may include one or more of the following steps of:

[00305] In step 161, receiving a request for accessing a data item stored in the QS repository 107 based on QS storage process(es) 110, 120 and / or 150 by a second user of the plurality of users 104a-104m and 105a-105m. The request may include an QREF access token 30 associated with a data item that has been stored in the QS repository 107 based on QS storage process(es) 110, 120, and / or 150. The second user may be the same as the first user as described in QS storage process(es) 120 and / or 150. Alternatively or additionally, the second user may be a different user to that of the first user as described in the QS storage process 120 and / or 150. For example, the first user of the QS storage process 110 35 may be a corporation or corporate user that is storing a data item in the QS repository 107 in 2020380554   25 May 2026 a QS manner. The first user may then provide an QREF access token to those other users (e.g. employees or other users) that the first user wishes to have access or a form of access / access operations with the encrypted data item stored in QS repository in a QS manner. Thus, the QREF access token may have been distributed by the first user to one or 5 more other users of the QS system 100. In any event, a QS server 103a of the QS network 101 receives the QREF access token from the second user corresponding to a data item stored in the QS repository 107.

[00306] In step 162, the QS server 103a is configured for identifying the QREF locator based on the received QREF access token and the identity of the second user. The user that 10 stored the data item in the QS repository 107 has a user registration record or data stored in the QS network 101 or QS repository 107, which may include data representative of, without limitation, for example the QREF locator, identifier of the first user or customer number, user secret of the first user, identifier of the data item, access control data such as allowed access operations and / or access permissions and the like including identifiers of one or more other 15 users allowed to access the data item, and / or any other data associated with the user and / or data item excluding the data item itself may be stored in a user record associated with the first user in a user registry or database in the QS repository 107 and / or one or more QS servers 103a-103l of the QS network 101. The QS server 103a may retrieve all the user registration records associated with the second user and use this information to determine 20 the QREF locator associated with the received QREF access token and whether the second user has permission to access the data item stored in the QS repository 107 and / or permissions associated with using the data item such as, without limitation, for example permissions to read, write, update, delete, query, retrieve and / or any other type of access permissions or use permissions associated with the data item and / or as the application 25 demands.

[00307] For example, an QREF access token may be provided by the second user to the QS network 101 via QS server 103a. Given that registration user data is stored each time a user submits or requests storage of a data item in the QS repository 107 and associated access permissions, then the registration user data may be used to identify the QREF locator 30 corresponding to the access token. For example, if the second user is the first user, then the QS server 103a may retrieve and / or search the registration data of the first user to identify a set of one or more registration records associated with the first user. If the second user is another user other than the first user, the QS server 103a may retrieve a set of registration user records associated with the second user. Each registration record in the set of 35 registration records includes a QREF locator corresponding to a data item the first user has stored in the QS repository 107 and provided the second user with access permissions to access the data item, or a QREF locator corresponding to a data item that the second user 69 2020380554   25 May 2026 has stored in the QS repository 107 and has permission to access. One or more registration records may also be linked to one or more other users that also have access permissions to access the data items pointed to by the corresponding QREF locators therein. In any event, each registration record in the retrieved set of registration records associated with the second 5 user is used to generate an QREF access token, and the registration record that generates an QREF access token that matches the received QREF access token is used to identify the QREF locator and hence the encrypted data item stored in the QS repository 107 that is associated with the received access token. At the same time, the registration record is used to check whether the second user presenting the QREF access token is allowed to access 10 the data item in some manner.

[00308] In step 162a, it is determined whether a QREF locator is identified that is associated with the QREF access token and whether the user has permission to access the encrypted data item stored in the QS repository 107. If the QREF locator corresponding to the QREF access token is identified and the user has permission to access the encrypted data item 15    (e.g. Y) then the process 120 proceeds to step 123. On the other hand, if the QREF locator corresponding to the QREF access token is not identified or the user does not have permission to access the encrypted data item (e.g. N) then the process 120 proceeds to step 124.

[00309] In step 163, access / access operations may be provided in some manner to the 20 encrypted data item in the repository to the second user in response to identifying the QREF locator. For example, the encrypted data item is decrypted using the associated QD key and access and / or access operations may be permitted by the user on the decrypted data item.

[00310] In step 164, as the QREF locator is not identified or the user does not have permission to access the encrypted data item associated with the QREF locator and access 25 token, then access is not provided to the user. An error message may be sent to the device of the user to inform them that access will not be provided. Alternatively, or additionally, a notification to the user associated with the data item may be generated to notify them of who tried to access the data item and / or give them an opportunity to give permission to allow the user access to the data item. Alternatively, or additionally, a notification may be sent to the 30 owner and / or user of the data item that an invalid attempt was made to access the data item.

[00311] Figure 1h is a schematic diagram illustrating another example QS system 165 including a QS network 101 for use with the QS storage process 110, 120, and / or 150 of figures 1b, 1c and / or 1f and / or QS access process 130, 140 and / or 160 of figures 1d, 1e and / or 1f according to the disclosure. For simplicity, reference numerals as used in figure 1a 35 for similar or the same features, components or items will be re-used in figure 1h. The QS 2020380554   25 May 2026 network 101 is formed using at least QS channels 108a-108c between a plurality of quantumsafe (QS) servers 103a-103c in which the QS repository 107 of figure 1a has been replaced with QS Distributed Ledger Technology network (DLT) 167 (or distributed ledger network and / or shared ledger network) for storing and accessing data items in relation to a first 5 plurality of users 104a-104m and a second plurality of users 105a-105n. In this example, a plurality of the QS server(s) 103a-103c includes a plurality of DLT nodes 166a-166c and / or user server of user 104a includes DLT node 166d, where the DLT nodes 166a-166d operate to form the QS DLT network 167 (referred to as QS DLT) for storing and / or accessing data items and the like. The QS DLT 167 may be based on at least one or more DLTs from, 10 without limitation, for example the group of: a distributed ledger; a shared ledger; a blockchain; publish / subscribe and / or response / request management system or platform; and / or any other secure distributed database management system and the like; and / or as the application demands. In this example, the QS DLT 167 may include a distributed ledger and / or a shared ledger for storing, by way of example only but is not limited to, the data items 15 of the plurality of users 104a-104m and / or 105a-105n and the like; data items associated with the plurality of users 104a-104m and / or 105a-105n; registration data items associated with the plurality of users 104a-104m and / or 105a-105n; any other data items associated with the plurality of users 104a-104m, 105a-105n, and / or the QS server(s) 103a-103c for maintaining and / or operating the QS system 130 and the like. In essence, a distributed ledger creates an 20 identical copy of a ledger of every node 166a-166d in the system by the operation of consensus amongst nodes 166a-166d (or a subset of the nodes 166a-166d) to agree that newly created data or data item(s) are always approved and stored identically. All nodes 166a-166d can see all data and / or data items. A shared ledger broadcasts a copy of data or data items to only those nodes of the plurality of nodes 166a-166d involved in the transaction 25 plus any required notary nodes, where different nodes of the plurality of nodes 166a-166d can see different subsets of the data / data items through, by way of example only but not limited to, a permissions engine or other type of permissions system and the like.

[00312] An advantage of using a DLT network based on QS DLT 167 (referred to as QS DLT) rather than a centralised QS repository is that the QS system 100 and the QS network 30 may be easily scaled up with an increasing number of users 104a-104, 105a-105n and / or QS server(s) 103a-103c storing data items and accessing data items stored in the QS DLT 167. QS DLT 167 also adds an extra layer of security when storing and / or accessing data items to / from the QS DLT 167, which requires consensus typically from a majority of the plurality of DLT nodes 166a-166d and / or from a majority of a set of jury or notary nodes of the plurality 35 of DLT nodes 166a-166d and the like, which enhances data integrity, security and authorised access. Jury nodes and / or notary nodes may be a trusted subset of DLT nodes 166a-166d with the functionality of forming a consensus in relation to storing one or more data items and / or accessing one or more data items and the like. Further advantages of the use of DLT 71 2020380554   25 May 2026 include, without limitation, for example, 1) enabling an added layer of security to the registration and data retrieval process through the operation of a consensus system whereby a majority of nodes must simultaneously agree upon or approve of a transaction, which is extremely difficult to spoof in real time; 2) enabling multiple parties to come together to 5 operate an application of the QS storage / access process of the QS system 130 according to the disclosure (e.g. also known as the QRef application) where the parties do not wish the QRef application and / or QS system 130 to be under the control of a single central actor, as may be the case in some collaborative cross-industry system; and / or 3) efficiency where the plurality of nodes 166a-166d can be used to host multiple different instantiations and / or 10 applications of the QS system and / or QRef application(s) by multiple DLT Node infrastructure operators and the like.

[00313] Referring to figure 1d, in this regard, each QS server 103a of the plurality of QS servers 103a-103c of the QS network 101 includes a hardware security module (HSM) 106a with an identical set of QD keys stored thereon and each QS server 103a of the plurality of 15 QS servers 103a-103c includes distributed ledger technology (DLT) node 166a or functionality for operating the QS DLT 167, e.g. for operating the distributed ledger and / or shared ledger for storing and / or accessing the encrypted data items. In essence, the DLT nodes 166a-166b of the plurality of QS servers 103a-103c form a QS DLT network 167 configured for, without limitation, for example providing secure storage and access to one or 20 more data item(s) stored on the distributed and / or shared ledger(s). The process 150 of figure 1f in step 154 of providing the QREF locator may be further modified to include receiving a QREF locator for storing the encrypted data item in the distributed and / or shared ledger(s) of the QS DLT 167, and storing the encrypted data item in the distributed and / or shared ledger(s) using the QREF locator as an address for the location of the encrypted data 25 item in the distributed and / or shared ledger(s). Furthermore, the process 160 of figure 1g in steps 161-162 may be further modified to include receiving an QREF access token from the second user for accessing an encrypted data item stored in the distributed and / or shared ledger(s) of the QS DLT 167, identifying a QREF locator corresponding to the QREF access token and second user, and accessing the encrypted data item in the distributed and / or 30 shared ledger(s) of the QS DLT 167 using the identified QREF locator associated with the QREF access token.

[00314] The QS network 101 requires that the hardware security modules (HSMs) 106a-106c of each of the QS servers 103a-103c includes at least an identical subset of QD keys or an identical set of QD keys stored thereon enabling the QS servers to communicate securely in 35 a quantum-safe manner with each other and the QS DLT 167 using one or more available QD keys from the set of QD keys. For example, the QS servers 103a-103c can use the identical subsets of QD keys to set up quantum safe communication channels (e.g. using 72 2020380554   25 May 2026 symmetric encryption) with each other and with the QS DLT 167 using quantum encryption based on one or more available QD keys from the subsets of QD keys. An identical set of QD keys or at least an identical subset of QD keys are distributed to each of the QS servers 103a-103c in a quantum-safe manner using quantum key distribution (QKD) based on, by 5 way of example only but not limited to, satellite quantum key distribution (SQKD), optical quantum key distribution, fibre optic quantum key distribution, and / or any other quantum key distribution scheme capable of delivering an identical set or subset of QD keys to a plurality of QS servers 103a-103c in a secure and / or quantum-safe manner. Whatever QKD scheme is used, updated sets or subsets of QD keys may be delivered to each of the QS server(s) 10    103a-103c and / or users 104a-104m when required and / or according to a schedule and the like, and / or as the application demands.

[00315] Furthermore, each of a first set of the plurality of users 104a-104m may also have, without limitation, a QS server and / or QS device that is part of the QS network 101. The QS server and / or QS device of each of the first set of the plurality of users 104a-104m may 15 include functionality of a QS registration server / node. The QS server and / or QS device of each of the first set of the plurality of users 104a-104m may include functionality associated with QKD schemes for receiving a set of QD keys from a QKD source over a quantum channel and the like. The QS server and / or devices of the first set of users 104a-104m may include a HSM with a set of QD keys stored thereon, which have been distributed to these 20 devices using QKD scheme used to deliver the set of QD keys to the QS servers 103a-103c of the QS network 101. For example, the QS servers and / or QS devices of each of the first set of users 104a-104m may communicate securely in a quantum-safe manner with the QS servers 103a-103c. One or more of the first set of users 104a-104m may also include a DLT node 166d and form part of the DLT network 167, which may operate with DLT node 25 functionality when encrypted data items are stored and / or access from the QS DLT 167.

[00316] Although QS system 165 includes a QS DLT 167, where the QS servers 103a-103c are configures to operates, without limitation, for example, a distributed and / or shared ledger network and the like, it is to be appreciated by the skilled person that other distributed and / or cloud based technologies may be used for storing and / or accessing data items as described 30 with reference to figure 1h and / or as described herein with reference to one or more of figures 1a to 7b. For example, the QS DLT 167 may be, without limitation, for example a repository system and / or storage system based on a digital storage platform using publish / subscribe, request / response and / or real-time based messaging (e.g. PUSH Technologies (RTM) Diffusion Platform (RTM) with Diffusion platform messaging) for storing 35 and accessing data items. The QS network 101 further including the plurality of QS servers 103a-103c, where each QS server 103a-103c includes an HSM with an identical set of QD keys stored thereon. In this example, each QS server of the plurality of QS servers 103a-73 2020380554   25 May 2026 103c may include a digital storage platform node for operating / communicating digital storage platform messaging between corresponding nodes for storing / accessing data items. The digital storage platform nodes of the plurality of QS servers 103a-103c actually form the digital storage platform, which is distributed and since QS communication channels are used 5 between the QS servers 103a-103c, this forms a QS distributed storage network (e.g. a QS Diffusion powered network) configured for providing storage and access to one or more data item(s) based on the digital storage platform messaging.

[00317] Thus, storing a data item in the QS distributed storage network of the distributed storage platform may include: receiving, a node, a QREF locator for storing the encrypted 10 data item in the distributed storage platform; and storing the encrypted data item in the shared ledger using the QREF locator as an address for the location of the encrypted data item in the distributed storage platform. Accessing a data item in the QS distributed storage network of the distributed storage platform may include: receiving a QREF access token from a second user for accessing an encrypted data item stored in the distributed storage 15 platform, identifying a QREF locator corresponding to the QREF access token and second user; and accessing the encrypted data item in the distributed storage platform using the identified QREF locator based on the access token.

[00318] Figure 1i is another schematic diagram illustrating a preferred example QS system 165 and QS network 101 for use with the QS storage process 110, 120, 150 of figures 1b, 1c, 20 and 1f and / or QS access process 130, 140, 160 of figures 1d, 1e and 1g according to the disclosure. For simplicity, reference numerals as used in figures 1a-1h for similar or the same features, components or items will be re-used in figure 1i. In this example, the QS system 170 uses both a QS DLT 167 for storing and / or accessing encrypted data items and also satellite quantum key distribution (SQKD) using a plurality of QS satellites 171a-171c 25 configured for generating and distributing one or more sets of QD keys to QS servers 103a-103c and / or QS servers and / or devices of the first plurality of users 104a-104c of the QS network 101. Each of the QS servers 103a-103c and QS servers or devices of the first plurality of users 104a-104c further include one of the plurality of QS ground satellite receivers or QS on-ground receiver complexes (OGRCs) 172a-172f for receiving the sets of 30 QD keys distributed from one or more of the QS satellites 171a-171c to the QS servers 103a-103c and QS servers or devices of the first plurality of users 104a-104c. For example, QS server 103a includes an HSM 106a, a DLT node 166a, and an OGRC 172a coupled together.

[00319] Each of the QS servers 103a-103c has a hardware security module (HSM) 106a- 106c that includes a set of QD keys stored thereon. Each of the HSMs 106a-106c may have 35 an identical set of QD keys stored thereon. Alternatively or additionally, each of the HSMs 106a-106c may have a set of QD keys stored thereon in which a subset of the set of QD keys 2020380554   25 May 2026 are identical with a corresponding set of QD keys of one or more of the other HSMs 106a-106c. In any event, each of the HSMs 106a-106c includes an identical set of QD keys or an identical subset of QD keys stored thereon that enable the QS servers 103a-103c to communicate securely in a quantum-safe manner with each other and the QS DLT 167 using 5 one or more available QD keys from the identical set / subset of QD keys to form the QS network 101 with a quantum safe boundary within which quantum-safe communications occurs between the QS server(s) 103a-103c, QS DLT 167 and the like. Furthermore, each of the QS servers or devices of the first plurality of users 104a-104c also has a hardware security module (HSM) 106d-106f that also includes an identical set / subset of QD keys 10 stored thereon enabling these QS servers or devices to communicate securely in a quantumsafe manner with the QS servers 103a-103c of the QS network 101 and / or the QS DLT 167 using one or more available QD keys from the set / subset of QD keys. For example, the QS servers 103a-103c can use the identical sets / subsets of QD keys to set up quantum safe communication channels with each other and with the QS DLT 167 using quantum encryption 15   (e.g. symmetric encryption) based on one or more available QD keys from the set of QD keys. The identical sets of QD keys are generated and distributed from one or more of the QS satellites 171a-171c using, without limitation, for example a group QKD protocol in which at least the QS servers 103a-103c of the QS network 101 have delivered to them an identical set or subset of QD keys. The sets of QD keys are removed from the QS satellites 171a- 20    171c once they have been distributed to all of the required QS servers 103a-103c of the QS system 170.

[00320] For example, the SQKD technology includes one or more QS satellites 171a-171c, which may be low orbit satellites that pass over geographical locations in which the QS servers 103a-103c and / or QS servers and / or devices of the users 104a-104c of the QS 25 system 140 are located. QS satellite 171a generates one or more sets of QD keys for distribution to each of the required QS server(s) 103a-103c and / or 104a-104c and the like. As the QS satellite 171a passes over each QS server 103a-103c and / or 104a-104c, the QS satellite 171a may distribute an identical set of QD keys (or subset of QD keys) to each of the HSMs 106a-106f of the QS servers 103a-103c and / or 104a-104c via the on-ground receiver 30 complexes (OGRCs) 172a-172f. Each of the QS servers 103a-103c may include, for example, an one of the OGRCs 172a-172c, an HSM 106a-106c, and a DLT Node 166a-166c, and one or more QS applications capable of at least storing and / or accessing data items in relation to the plurality of users 104a-104c and 105a-105n. Each of the OGRCs 172a-172c also includes, without limitation, for example on-ground receiver (OGR) and / or photon 35 controller for communicating with one of the satellites 171a-171c when performing, without limitation, for example a QKD protocol for receiving QD keys. The QS application(s) may act as an interface between the users 104a-104c and 105a-105n and the QS DLT 167 network of the QS network 101. The QS servers 103a-103c form the backbone of the QS network 75 2020380554   25 May 2026 101 and may be operated by a QS network provider. Each of the OGRCs 172d-172f of the QS servers / devices of the first plurality of users 104a-104c may also include an OGR, photon controller for communicating with one of the satellites 171a-171c when performing, without limitation, for example a QKD protocol for receiving QD keys. Each of the QS 5 servers / devices of the first plurality of users 104a-104c includes one of the OGRCs 172d-172f, an HSM 106d-106e, and DLT node 166d-166f coupled together.

[00321] The SQKD for the QS system 170 uses a group quantum key distribution (GQKD) protocol (also called a multi-cast protocol) that enables a single QD key, an identical set of QD keys, and / or an identical subset of QD keys to be delivered in a quantum safe manner 10 QS servers 103a-103c and / or QS servers or QS devices of users 104a-104c are situated in many individual / different geographical locations or sites. In particular, the purpose of the GQKD protocol may be for key sharing such as, without limitation, for example sharing an identical set of QD keys or an plurality of QD keys with two or more or a multiple of QS servers 103a-103c and / or 104a-104c and / or QS enabled devices and the like. The GQKD 15 protocol is achieved by the QS system 170 in which a QS satellite 171a generates and establishes one or more QD keys or an identical set of QD keys between the QS satellite 171a and one or more QS servers 103a-103c or QS servers of users 104a-104c. For example, the QS satellite 171a stores a digital copy of the QD key(s) and then distributes, in a quantum safe manner, the QD key(s) or set of QD key(s) to a first QS server 103a, and 20 then distributes and shares the same QD key(s) or identical set of QD key(s) that it distributed to the first QS server 103a with one or more subsequent QS servers 103b-103c and / or QS servers of one or more users 104a-104c when the QS satellite 171a passes over or comes in range of these said subsequent QS servers 103b-103c and / or QS servers of one or more users 104a-104c. The QD key(s), or set of QD keys stored in the QS satellite 171a 25 are deleted once all intended QS servers 103a-103c and / or QS servers / device of users 104a-104c have received them.

[00322] The QS network 101 is formed by the plurality of QS servers 103a-103c, QS servers and / or devices of the first plurality of users 104a-104c, and the QS Distributed Ledger Technology (DLT) 167 for storing and accessing data items in relation to a first plurality of 30 users 104a-104c and a second plurality of users 105a-105n. The QS network 101 requires that the hardware security modules (HSMs) 106a-106e of each of the QS servers 103a-103c and / or QS servers and / or devices of the first plurality of users 104a-104c includes a set of QD keys stored thereon in which at least an subset of the QD keys are identical with a corresponding subset of QD keys on other HSMs. This enables the QS servers / devices to 35 communicate securely in a quantum-safe manner (e.g. using symmetric quantum-safe encryption) with each other and with the QS DLT 167 using one or more available QD keys from the set of QD keys. For example, the QS servers 103a-103c can use the identical sets 76 2020380554   25 May 2026 of QD keys, each QD key being associated with a unique QD key identifier that is the same for each HSM, to set up quantum safe communication channels with each other and with the QS DLT 167 using quantum encryption algorithms and / or cryptographic algorithms based on one or more available QD keys from the set of QD keys. 5

[00323] The QS DLT 167 may be, without limitation, for example a distributed ledger and / or a shared ledger for storing the data items of the plurality of users 104a-104c and / or 105a-105n and the like. Each QS server 103a of the plurality of QS servers 103a-103c of the QS network 101 includes a hardware security module (HSM) 106a with an identical set of QD keys (or an identical subset of QD keys) stored thereon and each QS server 103a of the 10 plurality of QS servers 103a-103c includes distributed ledger technology (DLT) node 166a or functionality for operating the QS DLT 167 when storing and / or accessing the encrypted data items stored thereon. In this example, in addition to the QS servers 103a-103c including a DLT node 166a-166c or DLT node functionality for operating the QS DLT 167, each of a first set of the plurality of users 104a-104c may also have, without limitation, a QS server and / or 15 QS device that is part of the QS network 101. The QS server and / or devices of the first set of users 104a-104c may include a HSM 106d-106e with a set of QD keys stored thereon, and a DLT node 166d-166e. Thus, the QS servers 103a-103c including a DLT node 166a-166c or DLT node functionality for operating the QS DLT 167 and each of the first set of the plurality of users 104a-104c including a DLT node 166d-166f or DLT node functionality for operating 20 the QS DLT 167 and so form a QS DLT network. In essence, the DLT nodes 166a-166f of the plurality of QS servers 103a-103c and 104a-104c form a QS DLT network 167 configured for providing secure storage and access to one or more data item(s) stored on the distributed and / or shared ledger(s).

[00324] As an example, the distributed ledger (DLT) nodes 166a-166f are configured to form 25 the QS DLT 167 of the QS network 101 of the QS system 140 and the corresponding QS servers 103a-103c and 104a-104c form QS network 101 because they are connected via QS communications channels using satellite quantum key distributed (SQKD) keys (e.g. QSD keys) and create QS communications channels for the DLT nodes 166a-166f to communicate over etc. Thus, the QS servers 103a-103c and 104a-104c may communicate with each other 30 via these QS communications channels forming the QS network 101. The QS DLT 167 is secured using SQKD allowing the QS servers 103a-103c and / or 104a-104c of the DLT nodes 166a-166f to operate QS dynamic communication channels. All of the QS servers 103a-103c and 104a-104c form the QS network 101 in which any communications between the QS servers 103a-103c, 104a-104c is secured by a QS communication channel, which means 35 any data in transit within the QS network 101 or in storage within the QS DLT 167 (essentially stored in a distributed / shared ledger on the DLT nodes 166a-166e) is protected and quantum-safe. 77 2020380554   25 May 2026

[00325] The second plurality of users 105a-105n may be subscribers to one or more of the QS application(s) provided by the QS servers 103a-103c that use the QS DLT 167 for storage and retrieval and / or access to data items stored thereon. The devices and / or servers used by the second plurality of users 105a-105n are not QS because these devices typically 5 are not capable of QKD, in particular SQKD using the QS satellites 171a-171c. Thus, the devices / servers of the plurality of users 105a-105n operate in the non-QS network 102 (e.g. Internet, public network(s) with unencrypted traffic and / or using non-QS encrypted traffic etc.) and may interface with the QS network 101 via the QS application(s) operating on one or more of the QS servers 103a-103c of the QS network. The QS servers 103a-103c that 10 interface, e.g. via QS applications, with the devices of one or more of the users 105a-105n may are considered to be on the "Quantum Safe Boundary" of the QS network 101.

[00326] The QS system 170 provides the advantage of mitigating the risk of a Denial of Service attack on the individual QS server(s) and / or the individual quantum receivers (e.g. OGRs) on the ground since there are many QS servers 103a-103c and / or QS servers of 15 users 104a-104c with identical SQKD infrastructure, which renders a simultaneous attack on the QS system 170 and / or QS network 101 impractical for most if not all adversaries. Furthermore, Denial of Service attack is only really possible by physically obscuring the ground receivers (e.g. OGRs) of the QS server(s) 103a-103c and / or QS server(s) of users 104a-104c and their ability to see the QS satellites 171a-171c. However, even though the 20 OGRs may be obscured, this is immediately obvious to the QS provider of the QS network 101, which can be further mitigated through the use of camera and tamper switches built into each OGR, and / or manual human or drone access control and inspections of the OGRs of each QS server 103a-103c and / or QS server(s) of users 104a-104c. Furthermore, given most if not all QS servers 103a-103c have a DLT node 166a-166c this creates a large scale 25 duplication of the DLT records and / or data items stored in the QS DLT 167 through many DLT nodes 166a-166c. This also makes a simultaneous universal DoS attack impractical.

[00327] The QS systems 100, 165 and 170 may be further modified in which each QREF locator is divided or broken up into multiple atomic units in which each atomic unit of the QREF locator is stored on a different QS server 103a-103c of the QS network 101. For 30 example, the QREF locator may be broken into three atomic units and, the QS DLT 167 is configured to operate such that each atomic unit of the QREF locator is stored on a different subset of DLT nodes 166a-166f of QS server 103a-103c or 104a-104e of the QS DLT 167. For example, for a QREF locator that is divided into atomic units A, B and C, the atomisation is replicated such that, by way of example only but is not limited to, the QS DLT 167 may 35 include a DLT Node network of, without limitation, for example 99 nodes, and operates in a manner in which, without limitation, for example 33 of the DLT nodes store unit atomic A, 33 of the DLT nodes store atomic unit C and 33 of the DLT nodes store atomic unit C. Thus, in 78 2020380554   25 May 2026 the style of a RAID5 (RTM) concept, the QS DLT 167 is configured to store with each one third atomic unit (A, B or C) a hash of one of the other atomic units (A, B, or C), where each atomic unit requires its own unique QKD code or QD key. Although the dividing the QREF locator into atomic units is described, this is by way of example only but the invention is not 5 so limited, and it is to be appreciated by the skilled person that securely storing and / or accessing a QREF locator as atomic units may be implemented in various ways and / or based on RAID concepts (e.g. RAID 0-6), parity function(s) and / or methods thereto, single parity system(s) and / or general parity system(s) and / or methods thereto, methods for distributing, replicating and securely storing data as chunks, combinations thereof, 10 modifications thereof, and the like and / or as described herein and / or as the application demands.

[00328] Figure 1j is another schematic diagram illustrating an example QS system 175 of figures 1a to 1i using SQKD and configured with registration servers and nodes according to the disclosure. The QS system 175 and QS network 101 may be configured for use with the 15 QS storage process(es) 110, 120, 150 of figures 1b, 1c, and 1f and / or QS access process(es) 130, 140, 160 of figures 1d, 1e and 1g according to the disclosure. For simplicity, reference numerals as used in figures 1a-1i for similar or the same features, components or items will be re-used in figure 1j. In this example, the QS system 175 uses both a QS DLT 167 for storing and / or accessing encrypted data items and also satellite 20 quantum key distribution (SQKD) using a plurality of QS satellites (not shown) configured for generating and distributing one or more sets of QD keys to a plurality of QS servers 103a-103c and 176a-176b of the QS network 101. Each of the QS servers 103a-103c and 176a-176b further include, without limitation, for example one of the plurality of QS ground satellite receivers (not shown) for receiving the sets of identical QD keys distributed from one or more 25 of the QS satellites to the QS servers 103a-103c and 176a-176b.

[00329] In this example, some of the QS servers 103a-103c and 176a-176b are configured to be registration servers, which may be a QS server with an HSM and also a registration module / storage and / or application. For example, QS servers 176a and 176b are configured to be registration servers 176a-176b that handle, without limitation, for example registration, 30 maintenance, verification and authentication of registered users 105a-105n and their corresponding user accounts within the QS system 175. The registration server 176a is communicatively coupled to a plurality of registration nodes 177a-177p, and the registration server 176b is communicatively coupled to a plurality of registration node 178a-178r. The registration nodes 177a-177p and 178a-178r and registration servers 176a and 176b are 35 configured to, without limitation, for example at least handle set up of the user account and registration of the user with the QS system 175. As well, when a data item associated with a user is stored in the QS DLT 167, the corresponding QREF locator associated with the data 79 2020380554   25 May 2026 item is linked or issued against the users account. Thus, each time a user submits a data item for storage, or if someone else gives the user permissions for accessing a data item in some manner, the corresponding QREF locators associated with those data items are linked to the users account. That is, the user is issued a QREF locator against their registered 5 account. This enables a QS server or a registration server to identify all of the QREF locators associated with a user and thus, to perform, using a secure memory or hardware security module QREF locator identification as described with reference to access process(es) 130, 140, 150, 160 with reference to figures 1d to 1g. Essentially, each of the registration servers 176a-176b provides a first point of contact or communication point for 10 each of the one or more registered users of the plurality of users 105a-105n external to the QS system 175 and QS network 101.

[00330] In addition to issuing or linking QREF locators to a user account or linking QREF locators to a user account in relation to data items associated with the registered user stored in the QS DLT 167, the registration nodes 177a-177p and / or 178a-178r and registration 15 servers 176a-176b are used to identify the registered user with their account in the QS system and subsequently issue a data item in relation to that registered user, if they have permissions to do so. For example, when a user submits one or more QREF access tokens for accessing data items from the QS DLT 167 requested by a user, the registration server 176a of the QS system 175 is configured to perform authentication and / or verification of the 20 user submitting the QREF access token, which may include two-factor authentication and the like. This is to firstly to securely identify the user and their account and ensure the user is a registered user with the QS system 175, and secondly to identify a set of one or more QREF locators issued against the registered user. This set of one or more QREF locators may be used to identify the QREF locator that generates the submitted QREF access token as 25 described herein. The data item corresponding to the QREF locator may be retrieved and / or accessed, and the user issued with access to the data item in relation to their registration.

[00331] Thus, the QS network 101 is formed by the plurality of QS servers 103a-103c, registration servers 176a-176b, registration nodes 177a-177p and 178a-178r, and the QS Distributed Ledger Technology (DLT) 167 for storing and accessing data items in relation to a 30 first plurality of users (not shown) and the second plurality of users 105a-105n. The QS network 101 requires that the hardware security modules (HSMs) of each of the QS servers 103a-103c and / or registration servers 176a-176b includes a set of QD keys stored thereon in which at least an subset of the QD keys are identical with a corresponding subset of QD keys on other HSMs. This enables the QS servers / registration servers and registration nodes to 35 communicate securely in a quantum-safe manner (e.g. using symmetric quantum-safe encryption) with each other. It is noted that the registration servers 176a-176b act as a secure gateway between the QS DLT 167 and the plurality of registration nodes 177a-177p 80 2020380554   25 May 2026 and 178a-178r. Thus, only QS servers 103a-103l and registration servers 176a-176b may directly connect to the QS DLT 167 using one or more available QD keys from the set of QD keys. For example, the QS servers 103a-103l can use the identical sets of QD keys, each QD key being associated with a unique quantum key identifier that is the same for each 5 HSM, to set up quantum safe communication channels with each other and with the QS DLT 167 using quantum encryption based on one or more available QD keys from the set of QD keys. Similarly, the registration servers 176a-176b can use the identical sets of QD keys to those used by QS servers 103a-103l, each QD key being associated with a unique quantum key identifier that is the same for each HSM, to set up quantum safe communication 10 channels with each other and with the QS DLT 167 and also with one or more QS servers 103a-103l using quantum encryption based on one or more available QD keys from the set of QD keys.

[00332] Furthermore, the registration servers 176a-176b each connect to a plurality of registration nodes 177a-177p and 178a-178r, respectively. The registration nodes 177a- 15    177p are connected via QS channels to the registration server 176a. The registration server 176a uses its HSM to provide an available QD Key form the set of QD keys to each of the registration nodes 177a-177p. Thus, each registration node 177a-177p, when deployed, can form a QS communication channel to the corresponding registration server 176a. Similarly, the registration server 176b each connects to the plurality of registration nodes 178a-178r. 20 The registration nodes 178a-178r are connected via QS channels to the registration server 176b. The registration server 176b may use its HSM to provide an available QD Key form the set of QD keys to each of the registration nodes 178a-178r. Thus, each registration node 178a-178r, when deployed, can form a QS communication channel to the corresponding registration server 176b. The registration nodes 177a-177p and 178a-178r may form part of 25 the QS boundary that separates the users 105a-105n from the QS network 101 and QS system. Alternatively or additionally, prior to deployment, one or more of the registration nodes 177a-178r may be directly connected to a QS server 103a-103l and / or the registration server 176a or 176b for configuration and upload of one or more available QD keys from the identical set of QD keys stored in the HSM of each of the QS servers 103a-103l and / or 30 registration servers 176a-176b. Thus, when the registration nodes 177a-177p and / or 178a-178r are deployed, they can connect over the public telecommunications network and form QS channels using the QD keys provided during configuration.

[00333] Each of the registration nodes 177a-177p or 178a-178r may be located in a different place, for example, a shop and / or a building in which users may connect to in a myriad of 35 ways. For example, registration nodes may be used to perform a registration process to register devices with the QS system 175 prior to deployment of the devices to corresponding users. Additionally, the registration nodes 177a-177p or 178a-178r, as part of the registration 81 2020380554   25 May 2026 process, may be configured to physically connect to a device and upload one or more QD keys from the set of QD keys onto a secure memory area (e.g. a secure enclave) on the device, where the one or more QD keys are registered against the device identifier. Thus, the device may be able to set up a QS communication channel with a registration node 5 and / or registration server after it is delivered to a user. This may ensure QS communications can be achieved for the user of the device and the user may use the QS system 175 as described herein in a QS manner.

[00334] The registration process may be carried out either at the point of shipment of the devices such as, without limitation, for example at the manufacturer, which may have a QS 10 server and / or registration node capable of registering the devices prior to shipment. Alternatively or additionally, the registration process may be carried out at the point of sale, or prior to deployment, such as, without limitation, for example, a retail shop with a QS server and / or a registration node. In any event, these locations (e.g. manufacturer and / or retail ship) may be referred to as registration locations, each registration location (e.g. registration 15 node) is required to have access to a set of QD keys. In this case, either the registration nodes have the capability of a QS server 103a-103l, effectively making them a registration server, or the registration nodes are deployed with a set of QD keys to enable them to communicate via a QS channel with a registration server and / or QS servers and so may have a set of QD keys delivered at regular intervals or a schedule and the like. During the 20 registration process, the device is connected to a registration node 177a or registration server 176a via a physical connection that allows the registration node 177a or server 176a to deposit (or upload) one or more QD keys into the secure memory (e.g. a secure enclave of the device) of the device. At this point, the registration node 177a or server 176a may also upload or preload a QS or QREF application that configures the device to use the one or 25 more QD keys stored in the secure memory to establish a QS communication channel with the QS system via one or more registration nodes 177a-177p or 178a-178r, registration servers 176a-176b and / or QS servers 103a-103l. The QREF application may enable a user of the device to establish QS communication channels and store, access data items in the QS system 175. 30

[00335] Once the device is received by a user 105i, the user 105i can use the device to establish a QS connection using a previously uploaded QD key with the QS system via registration node 177p. Once connected the user can register themselves and obtain a QREF account that is set-up by the registration server 176a. The QREF account may be associated with the device via the device identifier, such that the QD keys on the device are 35 registered with the user's QREF account. Alternatively or additionally, the QREF account may be associated with the loaded QREF application on the device. Once the user has registered and has a QREF account on the QS system 175, they can use the QREF 82 2020380554   25 May 2026 application and retrieve QD Keys stored in the secure memory of the device to establish a QS communication channel with the QS system 175 and use its QD Key along with a symmetrical algorithm hosted within the QREF Application to establish a quantum safe communication channel with the QS system 175. The established quantum safe channel can 5 be used by the user to engage in any use case and / or application (e.g. access data items, store data items, KCY, QREF certificates, depositories, quantum safe communications with registered users of the QS system) and the like in relation to the QS system

[00336] In another example, one or more registration nodes 177a-177p and / or registration server 176a may be configured to configure a device of a user (e.g. mobile phone user) retro-10 actively to be able to install a QREF application or firmware modifications that enable a user to operate the device to establish a QS communication connection with the QS system 175 and / or QS network 101 accessing and / or using the QS system 175 in a quantum-safe manner, or at the very least in a quantum-resistant manner.

[00337] In another example, in order for a user 105a to register with the QS system and / or 15 receive a device that is capable of establishing a QS connection with the QS system over the public network, the user 105a may need to visit a shop or retail outlet with a registration node 177a (e.g. a QREF enabled shop). The registration node may be a secure single purpose device that includes an HSM with a single physical output connection (e.g. a single USB port out (OUT ONLY)) with a simple user interface screen. In some embodiments, the registration 20 node may be configured to only allow an operator to press a button to export a numbered QD Key from a set of QD keys on the HSM via the physical output connection to a user device. In this manner, the device may be pre-loaded with a finite number of pre-agreed QD keys. This enables a user 105a to buy and receive a device from the shop with the registration node 177a in which the device is pre-loaded with QD Keys so that they can use 25 the device to set up a generic QS channel in which they can then register with the QS system and establish a QREF account associated with the user. Alternatively or additionally, a user may take their device into the shop with the registration node 176a, where a number of one or more QD Keys may be uploaded to the device via the physical output connection of the registration node 177a. The user of the device may then operate the device to use the 30 uploaded one or more QD Keys to establish a quantum safe channel inside of which the user 105 sets up a QREF account associated with the user 105a in the QS system 175. The user may then use the QS channel to retrieve further personalised QD keys and the like.

[00338] In another example, rather than the user 105a being required to visit a retail outlet or shop with a registration server 177a, a secure storage medium with one or more QD keys 35 stored thereon may be sent to the user. The secure storage medium may be sent via, without limitation, for example the postal system, post, courier and / or delivery service, secure 2020380554   25 May 2026 data delivery service, and / or any other suitable secure data delivery, transportation and / or logistical support infrastructure for delivering sensitive and / or confidential materials, data, and the like. For example, the secure storage medium may be, without limitation, for example a single use dongle, a Secure Digital (SD) card and the like, a secured USB stick, a mobile 5 telephony SIM card, a password encrypted flash drive, portable HSM and / or tamper-proof / resistant hard drive, and / or any other suitable secure storage medium and / or storage medium that may be secured and made tamper-proof and / or tamper-proof or resistant storage medium and the like and / or as the application demands. In any event, the user 105a receives the secure storage medium with one or more QD keys stored thereon. 10

[00339] The secure storage medium may be configured for a single use with a one-time generic QD key stored thereon. This will enable the user 105a to connect the secure storage medium to their device and configure their device to set up a quantum safe channel using the one-time generic QD key and / or with various two-factor-authentication and / or other authentication mechanisms for use in, without limitation, for example registering a user 15 account for the user 105a, registering the device of the user 105a, and / or uploading / downloading a QREF application for the device and further set of one or more QD keys assigned by registration server 176a and sent to the device of the user 105a via registration node 177a over the QS channel.

[00340] In a further example, the device of a user 105b may be registered with the QS 20 system using a quantum-resistant pathway based on using 2 factor authentication and / or any other secure, multiple path and / or encrypted authentication protocol / mechanism. In this case, the QS system 175 via one or more components or modules in the QS server(s) 103a-103l and / or registration servers 176a-176b may have a random number generator such as, without limitation, for example a quantum random number generator, a Cryptographically 25 Secure Pseudo Random Number Generator (CSPRNG), a CSPRNG called NIST Light (RTM), any other suitable CSPRNG and the like and / or as the application demands. Furthermore, a client QS application software (e.g. a QREF Application) may be installed a device of the user 105b to enable the user 105b to establish a QS channel with the QS system 175 via registration nodes 177b and / or registration servers 176a-176b and the like. 30 The client QS application software may include further functionality such as, without limitation, a random number generator suitable for the device such as, without limitation, for example a client CSPRNG and / or a CSPRNG called NIST Light, and / or any other suitable CSPRNG for use on a device of the user 105b.

[00341] When the QREF Application is installed, the CSPRNG of the device of the user 105b 35 may have a corresponding CSPRNG operating within the QS system 175. In particular, the QREF application may include an application programming interface (API) that enables the 2020380554   25 May 2026 CSRNG functionality to be installed on a secure memory / processing unit of the device of the user 105b. For example, the API may make use of, without limitation, for example Software Guard Extension(s) (SGX) (RTM) and / or other client HSM type solution suitable for the device of the user 105b, which enables the API to embed a CSRNG functionality into the 5 secure memory / processing unit of the device. For example, the QREF application maybe configured to embed, when installed on the device of the user 105b, without limitation, for example the CSRNG NIST Lite random number generator into the secure memory / processing unit such as a secure chipset or secure enclave of the chipset of the device of the user 105b (e.g. an Intel Chipset with Intel Software Guard Extensions (SGX) is 10 regarded by security / cryptographers as being very secure). Intel (RTM) SGX includes a set of instructions or code for increasing security of application software and data providing increased protection against disclosure, modification, and / or tampering etc. Sensitive information may be partitioned into one or more enclaves, which are designated areas of execution in memory with more security protection. Although a secure memory / processing 15 unit may include a secure enclave or secure chipset such as the Intel Chipset with SGX as described herein, this is by way of example only and the invention is not so limited, it is to be appreciated by the skilled person that the secure memory / processing unit may be implemented using any other suitable type of secure chipset / memory / system / enclave / HSM / components and the like and / or as the application demands. 20

[00342] The registration process may include the following steps of: the user 105a may use the device to browse the public Internet and access a secure website and / or secure webserver operating with a registration node 177b and / or registration server 176a to register an account with the QS system 175 and to also configure and / or set-up their device for QS communications, QS storage and access, and / or any other use cases suitable for operating 25 with the QS system 175. During registration via the webserver, the user simultaneously communicates over another second one or more transmission pathway(s) (e.g. makes a cellphone call from the device or another device of the user, e.g. a mobile phone or landline phone) with the QS system and delivers two-factor authentication of or from the user to the QS system 175 during registration of the user and set up of the user account on the QS 30 system 175. The device of the user 105b is registered with the user account. The two factor authentication may be delivered by the user using voice commands during the communication over the second one or more transmission pathways.

[00343] The registration node 177b or registration server 176a may be configured to process the 2FA elements from the user 105b to display a number displayed on the website on the 35 screen of the device of the user 105b. This may be used to verify that the user 105b is who they say they are and to arrange for the device to receive a QREF application that enables the user 105b to use the device to establish a QS communication channel with the QS 85 2020380554   25 May 2026 system 175. The registration server 176a or a QS server 103a-103l may assign a QD key to the user 105a for use with their device. The assigned QD key is embedded into the QREF application for the device, and / or delivered with the download of the QREF application to the device of user 105b. When the device receives the QREF application download from the 5 webserver and / or registration node 177b or registration server 176a, the QREF application operates to install or embed the CSPRNG (e.g. CSPRNG NIST Lite) into the secure memory of the device. For example, the QREF application inserts the CSPRNG NISL Lite (RTM) into the Software Guard extension of the device, if the device has a suitable Intel (RTM) Chip. The QREF application is then configured to insert or input the QD Key into the CSPRNG 10 embedded in the secure memory / processor of the device.

[00344] The QS system 175 also sends a QR Code or image to the device of the user 105a and / or to another device of the user 105a for display on the screen of the device. The QR Code or image represents the user's two-factor authentication. The user inputs data representative of the QR code or image into the CSRNG embedded in the secure 15 memory / processor. The CSRNG processes the input QD Key and also the input data representative of the QR Code or image. For example, the user 105b may view a QR Code on the screen of their device representing their 2FA. The user 105b may, without limitation, for example photograph the QR Code displayed on the screen, take a screenshot or produce an image of the QR Code displayed on the screen in a suitable manner. The user 105b 20 inputs the photograph of the QR Code into the QREF application, which inserts the QR Code and the QD Key into the CSRNG of the secure memory (e.g. secure enclave). The CSRNG outputs a new QREF key or number. At the same time or in a similar manner, a QS server 103a-103l, a registration server 176a-176b and / or a registration node 177a-177p and / or 178a-178r, may be configured to input the data representative of the 2FA of the user 105b 25 and the QD Key assigned to the QREF application for the device of the user 105b into a corresponding CSRNG to output a new QREF key or number, which is associated with the user account of the user 105b.

[00345] The CSRNG embedded on the device and the corresponding CSRNG of the QS system 175 both produce the same QREF key or number. Given this, the QREF application 30 is configured to use the output QREF key or number to establish a quantum-safe communication channel with the QS system 175. This is performed by the QREF application logging the user 105b into the QS system 175 via a registration node 177b, by logging into the QS system 175, the registration node 177b may retrieve the user account details and the associated QREF key or number that the QS System 175 computed previously, which is the 35 same as the QREF key or number computed by the CSRNG embedded on the device of the user 105b. This then allows the registration node 177b and the device of the user 105b to establish the QS communication channel with both sides using the same QREF key or 86 2020380554   25 May 2026 number. The channel may be encrypted using symmetric encryption with the QREF key or number.

[00346] Once the QS channel has been established between the device and the registration node 177b of the QS system 175, one or more new dedicated QD Key for the device of the 5 user 105b, or even a set of dedicated QD key(s) for the device of the user 105b, is created and / or assigned from the set of QD keys in the HSM mesh of the QS server(s) 1034a-103l. The one or more new dedicated QD Keys may be assigned or mapped to the user account or associated with the user 105b for use in current / future QS communications between the device and the QS system 175. The one or more new dedicated QD Key(s) and / or set of 10 dedicated QD keys, are transmitted over the established QS communication channel to the QREF application executing on the device of the user 105b. The QREF application is configured to receive the one or more new dedicated QD Key(s) and deposit them into the secure memory / processor (or secure enclave etc.) of the device of the user 105b. For example, the QS system 1765 may send the one or more new dedicated QD keys inside the 15 QS communication channel to the device of the user 105b and deposits them into the Software Guard extension, when the device has an Intel Chipset. The QREF application may be configured to use the one or more new dedicated QD keys to establish further secure QS communications channels with the QS system 175 (e.g. via registration nodes 177a-177p or 178a-178r). 20

[00347] Figure 1k is another schematic diagram illustrating another preferred example QS system 180 according to the disclosure based on the QS systems of figures 1a to 1j in which SQKD is used and where the QS system 180 is configured to include a QS security gateway / registration server 182 and registration nodes 184a-184p. In this example, the QS system 180 includes a plurality of QS servers 103a-103l associated with the QS system 180, 25 a plurality of QS servers operated by users 104a-104c (corporations, customers that require a QS server and the like), a QS security gateway / registration server 182, and a distributed ledger 167, and a plurality of satellites 171a-172c comprising, without limitation, for example a low orbit satellite constellation. These are connected together over QS channels to create, over public communications infrastructure or other networks and / or dark fibre and the like, 30 the QS network 101. The QS network 101 is considered a QS domain. Each QS server 103a of the plurality of QS servers 103a-103l and / or QS servers operated by users 104a-104c may comprise a DLT node 166a-166l, one or more registration applications, and an SQKD on ground receiver or ~OGRC 172a-172l and HSM (not shown). As described with reference to figure 1i, this enables the QS servers 103a-103l and QS servers operated by 35 users 104a-104c to receive one or more identical sets of QD keys that are multicast from one of the satellites 171a of the satellite constellation to the corresponding OGRs 172a-172l as the satellite 171a passes over said OGRC 172a-172l of each QS server 103a-103l. 87 2020380554   25 May 2026

[00348] A plurality of users 105a-105n may operate devices over a public network 102 (e.g. Internet, and / or any other type of communication network) or non-QS network / domain 102. The plurality of users 105a-105n may be registered with the QS system 180 via registration nodes 184a-184p and security gateway / registration servers 182. The security 5 gateway / registration server 182 is configured to provide the necessary network security (e.g. user authentication, verification, 2FA and the like) to ensure only those users 105a-105l that are registered users of the QS system 180 have access to the services and / or applications of the QS system 180, but that any other user is blocked from accessing the QS system 180 and / or the services / applications. Such users will need to register for a user account on the 10 QS system 180 via registration nodes 184a-184p. Once registered, each user 105a of the plurality of users 105a-105n and / or one or more devices of said each user 105a may be associated with a user account stored in the DLT 167 of the QS system 180. A user 105a may use a registered device to enter their credentials into a QS website or QS webserver operated by one or more registration nodes 184a-184p associated with In a similar manner, 15 the QS system 180 may be operated and / or used as described with reference to figures 1a to 1j and / or as described herein.

[00349] There are different types of users that may use the QS system 180. For example, users 104a-104c may operate QS servers / devices that include an OGRC 172m-172o installed at their end-point and so receive sets of QD keys and operate via QS channels 20 within the QS network 101 of the QS system 180. These may be large scale customers such as organisations, corporations and the like that can operate the necessary technology and equipment required to be part of the QS network 101. These users 104a-104c that host an OGRC 172m-172o and / or HSM (not shown) can use this for registration and QD key delivery via the satellites 171a-172c and / or via the QS servers 103a-103l of the QS network 101. The 25   end-points / servers of users 104a-104c may also include DLT nodes 166m-166o and may assist in operating / forming the QS DLT 167.

[00350] Users 105a-105n may operate with in a public network 102 outside the QS network 101 or QS domain. Such users 105a-105n may use user or customer end-point devices such as, without limitation, for example, mobile phones, smart-phones, laptops, server(s), IoT 30 devices, and / or computing / communication equipment and / or devices, and the like, but which to not have the capabilities or equipment required for operating an OGRC and / or HSM and the like and so rely on registration nodes 184a-184p for registering and delivery of dedicated QD keys for establishing a QS communication channel with the QS system 180 and / or QS network 101. By contrast, the users 104a-104c are essentially guaranteed (because they 35 can form QS channels) that their devices / servers and the like may make use of QS communications, QS storage and / or access to data items using QREF locators and access tokens, and / or other QREF locator / access token use cases as described herein, 88 2020380554   25 May 2026 combinations thereof, modifications thereto and / or as described herein. However, users 105a-105n and / or their corresponding devices need to be registered with the QS system 180 and also get access, in a quantum safe manner, to corresponding QD keys and the like before being able to make use of, without limitation, QS communications and the like. 5

[00351] As previously described with reference to figure 1j, for users 105a-105n there are several options for registering with the QS system 180 and QS network 101 and ensuring their devices have the capability of QS communications, QS storage and / or access to data items using QREF locators and access tokens, and / or other QREF locator / access token use cases as described herein, combinations thereof, modifications thereto and / or as described 10 herein. One option is to receive a device or end-point device shipped from a manufacturer or retail outlet that has been pre-loaded with a QREF application and / or one or more QD Keys from the set of QD keys for establishing QS communications with the QS system. Another option is for the device of a user 105b (or end-point device) to download the QREF application and / or software, which is configured to, without limitation, for example register the 15 user 105b and / or establish QS communication with QS system. A further option may be that, without limitation, for example a retail shop or other service / outlet hosts an HSM which is used to inject or pre-load QREF application and / or one or more QD keys into the user device or user end-point device through a hard wired connection. This may be achieved using a retail shop device in which the user device is connected by a hard wired connection to the 20 retail shop device. The retail shop device may be a tamper-proof and / or temper resistant device and may include, without limitation, an operator button (e.g. a simple push button) that the retail shop operator or the user presses / pushes, causing the retail shop device to perform only one task, which is the injection of one or more QD keys and / or QREF application into the secure storage / processing unit (e.g. secure enclave or Intel SGX (RTM)) of the user device 25 and / or end-point device. The one task button and the retail device are designed to prevent an operator or other malevolent actor from accessing or attempting to access the QD keys and / or QREF application when they are injected / downloaded into the user device or endpoint device.

[00352] For example, as previously described with reference to figure 1j, as an option, a 30 device of a user 105a of the plurality of users 105a-105n may be shipped new from the manufacturer with a QREF Application pre-loaded onto the Operating System of the device. The device may be configured to have a secure enclave with a QD key stored thereon, which the QREF application may use within the secure enclave top establish a QS communication channel with a registration node 184a of the QS system 180. Thus, the device is configured, 35 once shipped to a user 105a to operate the QREF Application via the secure enclave on the device and use the QD key and the like for establishing an anonymised preliminary QS communication channel between the device of the user and a registration node 184a. This 89 2020380554   25 May 2026 QS communication channel allows the user 105a of the device to register and / or set up a QS user account in the QS system 180 using the preliminary QS safe channel. From this, the user 105a may be assigned QD keys and the like, which are associated with their user account in the QS system 180, and downloaded via the preliminary QS channel to the secure 5 enclave on the device. This allows the user 105a to establish QS channels with the QS system enabling them to use their devices in, without limitation, for example, QS communications, QS storage and / or access to data items using QREF locators and access tokens, and / or other QREF locator / access token use cases according to the disclosure and / or as described with reference to figures 1a-7c, combinations thereof, modifications 10 thereto and / or as described herein.

[00353] Furthermore, as previously described with reference to figure 1j, in the other option the registration process may involve, without limitation, for example a device of a user 105b downloading a QREF application or software, which is configured to establish a QS channel between the device of the user 105b and the QS system 180 and register the user 105b with 15 the QS system 180. The device of a user 105b may connect to a registration node 184a and download a QREF Application for registering and establishing a QS connection with the QS system 180. When the device of a user 105b downloads the QREF Application, the device of the user 105b is configured to combine the use of a quantum safe channel created with the QREF Application and a set of 2-factor authentication (2FA) challenges to create a new 20 quantum safe channel. Given that the download of the QREF Application is typically not quantum-safe, the establishment of a new quantum safe channel is quantum-safe because it uses a combination of 2FA (e.g. via voice commands) and transient user registration data provided by the user 105b during registration and in the 2FA set-up and authentication process. The QREF application and the 2FA challenges may be used to create a 25 symmetrical QREF key at the device and also the same QREF key at the QS system 180 such that symmetrical encryption using the same QREF key may be used to establish the QS channel between the device of the user 105b and the QS network via a registration node 184a and the security gateway / registration server 182 and the like. This allows the user 105a to use an existing device with a secure enclave and / or secure memory / processor to 30 establish QS channels with the QS system enabling them to use their devices in, without limitation, for example, QS communications, QS storage and / or access to data items using QREF locators and access tokens, and / or other QREF locator / access token use cases according to the disclosure and / or as described with reference to figures 1a-7c, combinations thereof, modifications thereto and / or as described herein. 35

[00354] Figure 1l is a further schematic diagram illustrating an example QS system 190 using terrestrial quantum key distribution according to the disclosure. The QS system 190 includes a plurality of QS servers 103a-103c, a QS DLT repository 167, one or more security 90 2020380554   25 May 2026 gateways / registration servers 182a-182m, and a plurality of registration nodes 184a-184m that are connected together via QS channels established using a plurality of QD keys from a set of QD Keys stored in one or more HSMs (not shown) within one or more QS servers 103a-103c and / or one or more security gateways / registration servers 182a-182m and the 5 like. The QS network 101 with QS channels formed between the plurality of QS servers 103a-103c, the QS DLT repository 167, the one or more security gateways / registration servers 182a-182m and a plurality of registration nodes 184a-184m forms a QS boundary within which QS communications occurs between at least the plurality of QS servers 103a-103c and the QS DLT repository. The plurality of registration nodes 184a-184m form the 10 edges of the QS network 101 and are the point of contact for a plurality of users 105a-105n operating devices within public telecommunication infrastructure, so-called non-quantum safe network 102, such as, without limitation, for example the public Internet, telecommunications networks, public service telecommunication network(s) and the like.

[00355] Rather than having a satellite constellation with a plurality of satellites 171a-171c as 15 described with reference to figures 1i to 1k, the QS system 190 forms a QS network 101 based on at least the plurality of QS servers 103a-103c in which each QS server 103a of the plurality of QS servers 103a-103c includes a terrestrial QKD transceiver 193a-193c for creating and distributing one or more sets of QD keys to the HSMs (not shown) of each QS server 103a-103c across QS channels over the public infrastructure, without limitation, for 20 example the Internet and / or dark fibre networks and the like. It is preferred to use dark fibre for communicating between QS servers 103a-103c and / or QS DLT repository 167. This reuses fibre optic resources that have already been deployed but not in use, but also allows the use of quantum key exchange using optical photons and the like and the generation of sets of QD Keys for use by the QS system 190. Although the terrestrial QS system 190 uses 25 terrestrial QKD transceivers 192a-192c across dark fibre, this can limit the transmission distance of the dark fibre between datacentres of the QS network 101 and the like. Thus, the terrestrial QS system 190 may be deployed in metropolitan areas and / or city centres and the like until future improved dark fibre enables longer or larger transmission distances, and / or secure repeaters / routers can be used to extend to larger areas / regions and the like. 30 Alternatively or additionally, although the terrestrial QS system 190 is described with reference to using terrestrial QKD transceivers and establishing QS channels over dark fibre communication infrastructure, this is by way of example only and the invention is not so limited, it is to be appreciated by the skilled person that the terrestrial QS system 190 may be combined and / or modified to use one or more features of one or more other QS systems 100, 35    165, 170, 175, 180 as described with reference to figures 1a to 1k, and / or as the application demands. 2020380554   25 May 2026

[00356] Users 105a-105l may register and / or use the QS system 190 in a similar or the same manner as described with reference to figures 1a to 1k by connecting to one or more registration nodes 184a-184m, or when allowed with one or more registration servers and / or QS servers, which may include registration node and / or registration server applications and 5 the like for establishing a connection with the devices of said one or more users 105a-105l. Preferably, user devices or end-point devices of users 105a-105l may connect to the QS system by connecting to a registration node of the plurality of registration nodes 184a-184m for performing without limitation, for example QS communications, QS storage and / or access to data items using QREF access tokens as described herein, and / or other QREF access 10 token use cases according to the disclosure and / or as described with reference to figures 1a- 7c, combinations thereof, modifications thereto and / or as described herein. The registration nodes 184a-184m connect and communicate over QS communication channels with a registration server, where the registration server communicates with a DLT node and / or HSM of a QS server for storing and / or accessing data items stored in the DLT network / distributed 15 ledger and / or for performing, without limitation, for example QS communications, QS storage and / or access to data items using QREF locators and access tokens as described herein, and / or other QREF locator / access token use cases according to the disclosure and / or as described with reference to figures 1a-7c, combinations thereof, modifications thereto and / or as described herein. 20

[00357] Thus, as described with reference to figures 1a to 1k, a user 105a of a plurality of users 105a-105l may use a device or end-point device with a secure enclave and / or secure memory / processor to, without limitation, for example establish QS communication channels with the QS system, and perform, without limitation, for example QS communications, QS storage and / or access to data items using QREF locators and access tokens as described 25 herein, and / or other QREF locator / access token use cases according to the disclosure and / or as described with reference to figures 1a-7c, combinations thereof, modifications thereto and / or as described herein.

[00358] Figures 2a and 2b are schematic diagrams illustrating an example QREF locator system 200 and QREF access token system 205 for generating a QREF locator and access 30 token, respectively, for storing and accessing, in some manner, a data item according to the disclosure. For simplicity, reference numerals of figures 1a-1l may be referenced, used for similar or the same components, and / or used for illustrative purposes in figures 2a and 2b.

[00359] Referring to figure 2a, the QREF locator system 200 generates the QREF locator 203 by receiving, without limitation, for example, at least data representative of: the user 35 secret 201a from a device of a user that is submitting a data item for storage in, without limitation, for example the QS repository 107 of the QS network 101; and an available QD 2020380554   25 May 2026 key selected from the set of QD keys from one of the QS server(s) 103a-103l of the QS system. A QREF locator engine 202 is configured to generate a unique QREF locator 203 based on one or more of a first set of cryptographic or mathematical operations performed on the data representative of at least the received user secret 201a and the received QD key 5   201n (e.g. QS_KEY). Although a user secret 201a and QD key 201n (e.g. QS_KEY) are described, this is for simplicity and by way of example only and the invention is not so limited, it is to be appreciated by the skilled person that any other information may be input to the QREF locator engine 202 as the application demands such as, without limitation, for example a user secret, a customer number allocated to the user, a data item reference identifier 10 allocated to the data item that will be associated with the generated QREF locator 203, the received QD key, a QD key identifier of the received QD key, a user identifier, and / or an access control list to the data item, and / oir any other information useful or suitable for generating the QREF locator. Although several examples of the cryptographic or mathematical operations of QREF locator engine 202 are provided, these are by way of 15 example only and the invention is not so limited, it will be appreciated by the skilled person that the cryptographic or mathematical operations of the QREF locator engine 202 may be changed depending on the use case and / or service / application process that uses the QS system according to the disclosure. For example, the QREF locator engine 202 may be a plug-in module or software that may be selected from a set of QREF locator engines 20 depending on use case. Each QREF engine 202 from the set of QREF locator engines may have a different set of cryptographic of mathematical operations and / or different input data depending on use case for generating a QREF locator in relation to that use case.

[00360] The QREF locator engine 202 is configured to generate the QREF locator 203 based on the first set of cryptographic or mathematical operations on QREF locator input data 25 representative of, without limitation, for example at least data representative of the received user secret 201a and the received QD key 201n, or any other input data associated with the user, data item and / or QD key such as, by way of example only but not limited to, data representative of user secret, customer number, user identifier, data item reference, quantum key identifier, QD key and the like or as the application demands. The QREF locator engine 30   202 processes the input data using any one or more cryptographic operations, mathematical operations and / or functions and / or combinations thereof, without limitation, for example, one or more cryptographic operations, mathematical operations and / or functions and / or combination thereof from the group of: one or more one-way functions; one or more hash functions; one or more hash-based message authentication code functions; one or more key 35 derivation functions; one or more of multiplication, subtraction, addition, division, factorisation and / or any other mathematical operation; any other one or more cryptographic functions, mathematical operations, and / or combinations thereof that are operable to generate, from the input data, data representative of a QREF locator 203 that is unique, obfuscates the received 93 2020380554   25 May 2026 QD key 201n and / or the received user secret 201a and / or other input data, and is capable of providing an address for locating the associated data item for storing in, without limitation, for example a QS repository 107 and / or QS DLT 167 and the like. As an example, the QREF locator engine 202 may perform a one way hash on the input data such as, without limitation, 5 for example at least data representative of the received user secret 201a and the received QD key 201n. In another example, the QREF locator engine 202 may perform a one way hash on input data such as, without limitation, for example at least data representative of the received user secret 201a and the received QD key 201n. In another example, the QREF locator engine 202 may perform a one way hash on the received input data such as, without 10 limitation, for example, data representative of a customer number (or user identifier), customer data item reference (e.g. reference or name of data item for storage), and a quantum key identifier of the received QD key 201n.

[00361] Referring to figure 2b, the QREF access token system 205 is configured to generate a unique QREF access token 207 by receiving a QREF locator 203. An QREF access token 15 engine 206 is configured to generate the unique QREF access token 207 based on a second set of cryptographic or mathematical operations performed on the received QREF locator 203. The QREF access token engine 206 that is configured to generate the QREF access token 207 based on the second set of cryptographic and / or mathematical operations may further include generating the QREF access token 207 from data representative of the QREF 20 locator 203 based on any one or more cryptographic, mathematical operations, functions and / or combinations thereof from the group of: one or more one-way functions; one or more hash functions; one or more one-way forward hash functions; one or more hash-based message authentication code functions; one or more key derivation functions; one or more of multiplication, subtraction, addition, division, factorization and / or any other mathematical 25 operation; any one or more cryptographic functions, mathematical operations, functions, and / or combinations thereof that are operable to generate data representative of an QREF access token 207 that is unique, obfuscates the data representative of the QREF locator 203, and capable of being used by a QS server 103a-103l to identify the QREF locator 203 for providing an address for locating the associated data item stored in, without limitation, for 30 example a QS repository 107 or QS DLT 167. Preferably, the second set of cryptographic operations and / or mathematical operations used to generate the QREF access token 207 from the QREF locator 203 is an irreversible process such that the QREF locator 203 cannot be derived from the data representative of the QREF access token 207. In a preferred example, the QREF access token is calculated using a one-way hash of the QREF locator. 35

[00362] Although a hash function is described herein for calculating a QREF locator from input data and / or an QREF access token from the QREF locator, this is by way of example only but the invention is not so limited, it is to be appreciated by the skilled person that there 94 2020380554   25 May 2026 any variation of or one or more cryptographic operations or algorithms, mathematical operations or algorithm, functions and / or combinations thereof may be used to generate a QREF locator and / or QREF access token with the above-mentioned properties as described above, and / or herein as the application demands. For example, there are a number of 5 operations and / or algorithms that can be used to calculate a QREF locator and / or an QREF access token, in which the input data may be used as a seed, without limitation, for example using one or more cryptography operations or algorithms from the group of: lattice-based cryptography, multivariate cryptography, code-based cryptography, supersingular elliptic curve isogeny cryptography, and the like. 10

[00363] Figure 2c is a flow diagram illustrating an example QS access process 210 for a user requesting access to a data item using an QREF access token generated in figure 2b. For simplicity, reference numerals of figures 1a-1l may be referenced, used for similar or the same components, and / or used for illustrative purposes in figure 2c. During storage of a data item in the QS repository 107 or DLT 131, the QS server 103a may generate a registration 15 record of the user storing the data item in the QS repository 107 or QS DLT 167. Each user registration record may include, without limitation, for example data representative of: a user identity of said user; a user secret of said user; the quantum reference (QREF) locator 203 associated with the data item; a data item reference identifier associated with the data item; a quantum key identifier associated with the QD key used to encrypt the data item; and an 20 access control list associated with the data item, which may include user identities of the users given access to the data item, and / or any other data. The QS access process 210 may include the following steps of: In step 211, receiving an QREF access token associated with a data item from a device of a user. The user may not be the same use that stored the data item in the QS repository 107 or QS DLT 167. In step 212, retrieving one or more registration 25 records associated with the user.

[00364] In step 213, identifying the QREF locator associated with the QREF access token by performing the following steps of: In step 214, generating, for each retrieved registration record, an QREF access token based on the data of said each retrieved registration record. In step 215, determining, for each retrieved registration record, whether the generated QREF 30 access token matches with the received access token. In step 216, identifying the QREF locator from the retrieved registration record corresponding with the generated QREF access token that matches the received access token. In step 216, outputting the QREF locator from the retrieved record that generated the matching access token.

[00365] In step 217, in response to identifying the QREF locator, performing one or more 35 access operations or actions and the like in relation to the data item corresponding to the 2020380554   25 May 2026 identified QREF locator stored in the repository and the access token. The access operations or actions are use case dependent.

[00366] Figure 3a is a flow diagram illustrating an example service / application process 300 for storing and / or accessing data items in, without limitation, for example an QKD system 5 such as, without limitation, for example QS systems 165, 170, 175 and 180 as described with reference to figures 1j to 1k. For simplicity, reference numerals of figures 1j to 1k may be used for the same or similar components. The QS systems 165, 170, 175 and 180 combines QKD or SQKD with QS DLT 167 to enable quantum-safe (QS) storage and retrieval of publicly accessible data in a manner that is regarded as quantum safe. As described, the QS 10 systems 170, 175 and 180 uses, without limitation, for example: 1) quantum safe keys or QD keys delivered to HSMs 106a-106c by a QS Satellite system including a plurality of QS satellites 171a-171c; 2) a user's / customer’s public key or shared secret; to create through the operation of an QREF locator algorithm a unique QREF number or locator. The QREF locator is used as a locator to the location of a data item (or DLT data record or data locker) 15 stored on the QS DLT 167, which may be a distributed ledger and / or shared ledger. The QS DLT 167 is stored on the QS network 101 using DLT nodes 166a-166d, which are connected exclusively by quantum safe communications channels, in which the DLT nodes 166a-166d may use QD keys from the set of quantum safe keys stored in each HSM 106a-106c of a QS server 103a-103c. The QS DLT 167 is not publicly accessible over the non-quantum safe 20 network 102 (e.g. a public network or the Internet). When DLT nodes 166a-166d exchange information to store information in the QS DLT 167, raise queries or updates or retrieve information or answers to questions, such information stored in the QS DLT 167 is always quantum safe.

[00367] In this example, one of the users 104a-104c are customers of the QS provider of QS 25 systems 165, 170, 175, 180 and may use the QS system 165, 170, 175, 180 for a variety of applications and / or use cases. As described, the user 104a has an QS server that may be configured for use with an SQKD system by including, without limitation, for example, OGRC 172d, HSM 106d and / or DLT node functionality 166d. The QS server of the user 104a connects within the QS network 101 using quantum safe channels to QS server(s) 103a-103c 30 and / or QS DLT 167. The user 104a may store their data items in a QS manner via a DLT record (or "Locker") on a distributed ledger and / or shared ledger operated by QS DLT 167 and DLT nodes 166a-166f using service / application process 300 based on the following steps of:

[00368] In step 301, the user 104a using their QS server / device connects to one of the QS 35 server(s) 103a-103c with DLT Nodes 166a-166c using a QS communication channel initiated using a QD key set up with the relevant QS server 103a with DLT Node 166a. 2020380554   25 May 2026

[00369] In step 302, the user 104a may provide (as dictated by the service) their public / private key (e.g. user secret or customer secret) to the QS server 103a-103c.

[00370] In step 303, the QS server 103a retrieves an available QD key from the set of QD keys (e.g. a quantum key) stored in the HSM 106a of QS server 103a, and injects the 5 retrieved QD key along with the user secret or user's private key along with Customer’s private key into a QREF locator generation engine (e.g. QREF locator engine 202 of figure 2a) for generating a QREF locator associated with a data item the user 104a requires stored on the QS DLT 167. The QREF locator generation engine produces a “Locator” or a unique reference number that indicates the location or address of a DLT record (or "Locker") in 10 which the data item will be stored at on the distributed or shared ledger(s) of QS DLT 167.

[00371] In step 304, the data item of user 104a is stored in the DLT record (or "Locker") including data representative of the data item and also the QREF locator. The QREF locator may be, without limitation, for example used as an index or location of the data item stored in the QS DLT. 15

[00372] In step 305, the QS server 103a also generates an QREF access token (e.g. QREF access token engine 206 of figure 2a) for the user 104a. This enables whoever has the QREF access token to access the data item stored in the QS DLT 167. For example, the QREF access token engine 205 may be a simple hash function in which the QREF access token is a hash of the QREF locator corresponding to the data item. 20

[00373] In step 306, the user 104a receives the QREF access token corresponding to the data item stored by the QS DLT 167. The user 104a may use the QREF access token in public and also direct other users 104b-105n to the data item using the access token.

[00374] Thus, with the data item safely stored in the QS DLT 167 in a QS manner, the user 104a is able to share information relating to the QREF locator with one or more users 104b- 25    105n for any given application by providing the QREF access token hash of the Locator, which combines the reference number to the HSM QKD key used plus his private key. This can be delivered in the or of a certificate or token

[00375] Given a QS DLT 167 is used, all the QS servers 103a-103c with DLT nodes 166a-166c of the QS systems 165, 170, 175, or 180 will be updated as necessary as to the 30 location of the data item and the QREF locator of the user 104a. Thus, any request for access to the data item based on the QREF access token that is received by any QS server 103a-103c can use the QREF access token to locate the data item. The QS system 165, 179, 175 or 180 may be interrogated to produce a summary of the data item, partial records associated with the data item, or a Boolean to a query associated with the data item, and / or 2020380554   25 May 2026 any of a variety of results produces as required by the given application in relation to the data item.

[00376] It is apparent that the QS system provides various advantages including handling of data items in a quantum safe manner since all communications between QS servers 103a- 5    103c and / or QS servers of users 104a-104c are quantum safe based on, without limitation, for example SQKD. Another advantage is that a user of the plurality of users 105a-105n with devices operating in the non-quantum safe network 102 outside the quantum safe boundary of QS network 101 is not required to perform any authentication in the applications under consideration, and so no quantum safety is required from them. These users are not party to 10 any secrets or QD keys of the QS system, and so cannot compromise the data items held in the QS DLT 167. For example, depending on the application and use of the access token(s) and permissions thereto associated with one or more data items held in the QS DLT 167, a user 105a-105n outside the quantum safe boundary of the QS network 101 may only be able to use the QREF access token to get Boolean answers or partial data strings in relation to 15 data items held in the QS DLT 167 and so is not able to compromise the data items held in the ledger of the QS DLT 167. In addition, all QS servers 103a-103c with DLT nodes 166a-166c that operate the QS DLT 167 are quantum safe, even though information passes between them in IP over the public internet as raw encrypted data that is encrypted using the QD keys of the set of QD keys distributed to each QS server 103a-103c via QSKD and / or 20 any other suitable QKD technique. Such encrypted data is only capable of being read by the intended recipient QS server 103a-103c with the relevant QD key.

[00377] Figure 3b is a flow diagram illustrating another example service / application process 310 for performing web certification with certificate data items that are stored and accessed using, without limitation, for example an SQKD system such as, without limitation, for 25 example QS systems 170, 175, or 180 as described with reference to figures 1i to 1k. For simplicity, reference numerals of figures 1i to 1k may be used for the same or similar components. As described with reference to figures 1a to 3a, the QS system 170, 175, or 180 combines SQKD with QS DLT 167 to enable quantum-safe (QS) storage and retrieval of publicly accessible data in a manner that is regarded as quantum safe. The QREF locator 30 may be used to provide a QS web certification service in which a user 104a with a QS server hosting a website can use for authenticating their website to users 105a-105n and the like. The service / application process 310 may include the following steps of:

[00378] In step 311, receiving a request from the user 104a of the QS server hosting the website to set up a QREF locator using a QS server 103a configured for providing a web 35 certification service. This includes, without limitation, for example, the user 104a of the QS server hosting the website providing their Know Your own Client (KYC) details or KYC data 2020380554   25 May 2026 (e.g. corporate details of the corporation's website) for forming and / or storing a KYC data item.

[00379] In step 312, a QREF locator is created / generated based on a user secret associated with the user 104a and an available QD key provided by an HSM 106a of QS server 103a. 5

[00380] In step 313, the user KYC data / details are stored as a KYC data item along with the QREF locator in a DLT record (or "Locker") of the QS DLT 167, which is replicated on all QS server(s) 103a-103c with DLT node functionality 166a-166c using SQKD safe communications channels (or QS channels).

[00381] In step 314, a certificate QREF access token is generated with the hash of the QREF 10 locator, as well, at least a portion of the user's KYC data may be included in the certificate access token.

[00382] In step 315, when a web browser of a user 105a in the non-QS network 102 (e.g. Internet or public network and the like) wants to verify the website of the user 104a is authentic, the web browser of user 105a receives the certificate access token from the 15 website of user 104a and sends the received certificate access token to QS server 103a of QS system 140 for determining whether website of user 104a is authentic.

[00383] In step 316, the QS server 103a takes the certificate access token and identifies that it is associated with user 104a (e.g. based on identifying the QREF locator from a QREF access token as described herein with reference to figures 1a to 7b), and from this retrieves 20 the QREF locator corresponding to the KYC data item.

[00384] In step 317, the QS server 103a retrieves the KYC data item from the QS DLT 167 using the QREF locator, and checks the KYC information from the QS DLT 167 matches the KYC data of the certificate access token.

[00385] In step 318, return confirmation whether website authentic to web browser. For 25 example, if there is a match, then the QS server 103a returns a confirmation (e.g. YES) to the web browser of user 105a indicating that there is a match and the website the user 105a is visiting is authentic. If there is not a match, then the QS server 103a returns a negative confirmation (e.g. NO) to the web browser of user 105a indicating that there is not a match and the website the user 105a is visiting is not authentic. 30

[00386] Figure 3c is a flow diagram illustrating another example KYC service / application process 320 for provision of KYC data that is stored and accessed using, without limitation, for example an SQKD system such as, without limitation, for example QS system(s) 170, 175 or 180 as described with reference to figures 1i to 1k. For simplicity, reference numerals of 99 2020380554   25 May 2026 figures 1i to 1k may be used for the same or similar components. As described with reference to figures 1a to 3a, the QS system(s) 170, 175 or 180 combines SQKD with QS DLT 167 to enable quantum-safe (QS) storage and retrieval of publicly accessible data in a manner that is regarded as quantum safe. The QREF locator may be used to provide a QS 5 KYC service for users 104a-104c and / or users 105a-105n. In this example, a QREF locator and KYC access token associated with a KYC data item of a user 105a from the plurality of users 105a-105n are used to contr...

Claims

1. A computer-implemented method of storing one or more data item(s) in a quantumsafe "QS" network, the QS network comprising one or more QS server(s) and a repository for storing and accessing said data item(s), each QS server comprising a hardware security5 module "HSM" for storing an identical set of quantum distributed "QD" keys, said identical set of QD keys having been distributed to each of said QS server(s) using a quantum key distribution process, and said QS server(s) configured to communicate securely with each other and the repository using one or more available QD keys from the identical set of QD keys, the method performed by a QS server comprising:10           selecting an available QD key from the set of QD keys for encrypting a data item;generating a quantum reference "QREF" locator based on input data associated with the data item for storage and the available QD key selected from the set of QD keys, wherein the generated QREF locator is unique, and wherein the QREF locator is a logical address or a physical address for storing and accessing the data item in the repository;15           linking the QREF locator to the available QD key of the set of QD keys;storing the link between the QREF locator to the available QD key of the set of QD keys in the HSM; andsending the QREF locator along with the data item encrypted with the available QD key to the repository for storage, wherein the encrypted data item is linked to the QREF 20 locator when stored.

2. The computer-implemented method of claim 1, the method further comprisingreceiving a set of QD keys using quantum safe key distribution from a quantum key distributor or source.

253. The computer-implemented method of claim 1 or claim 2, the method furthercomprising:generating a QREF access token associated with the data item based on the QREF locator; and30           sending the QREF access token to a device of a user associated with the data item.

4. The computer-implemented method of any one of claims 1 to 3, the method furthercomprising:generating a QREF access token for accessing the data item based on the QREF35 locator using an irreversible function, process or operation, wherein the QREF access token is unique; andsending the QREF access token to a device of a user for enabling the user to access said data item.1592020380554   25 May 20265.     The computer-implemented method of any one of claims 1 to 4, the method furthercomprising:receiving, from a device of a user, a QREF access token requesting access to a data item stored in the repository;5           identifying a QREF locator based on the QREF access token and input data from theuser; andin response to identifying the QREF locator, performing the steps of: retrieving the data item from the repository, wherein the data item is decrypted using the QD key corresponding to the QREF locator; and10                   providing access operations to the user in relation to the decrypted data item.

6. The computer-implemented method as claimed in any one of claims to 1 to 5, furthercomprising receiving a request for storing the data item by a first user.

7. The computer-implemented method as claimed in any one of claims 1 to 6, whereinthe QS network further comprises one or more user devices, each user device comprising a 15 hardware security module for storing a set of QD keys, wherein the one or more user devicesand one or more of the QS servers communicate using quantum key encryption based on the set(s) of QD keys.

8. The computer-implemented method as claimed in any one of the preceding claims,wherein the repository comprises a repository or storage system based on at least one from 20 the group of:distributed ledger technology or network;shared ledger technology or network;blockchain technology or network;publish / subscribe, response / request and / or real-time based digital storage25 cloud / repository technology;any other secure cloud storage system or platform;any other secure storage system or platform; and any other secure database management system.

9. The computer-implemented method as claimed in any one of the preceding claims,30 wherein generating the QREF locator further comprising:receiving a user secret from a device of a first user;receiving an available QD key selected from the set of QD keys from one of the QS server(s); and2020380554   25 May 2026generating the QREF locator based on a first set of cryptographic or mathematical operations in relation to data representative of the user secret and the received QD key, wherein the QREF locator is unique.5    10.    The computer-implemented method as claimed in any one of the preceding claims,wherein generating the QREF access token further comprising generating the QREF access token based on a second set of cryptographic or mathematical operations in relation to data representative of the QREF locator, wherein the QREF access token is unique.

11. The computer-implemented method as claimed in any one of the preceding claims,10 the method further comprising:receiving an QREF access token from a user;identifying the QREF locator associated with the QREF access token; andin response to identifying the QREF locator, performing one or more access operations in relation to the data item corresponding to the QREF locator stored in the15 repository and the QREF access token.

12. The computer-implemented method as claimed in claim 11, the method furthercomprising:storing a registration record of each user storing a data item in the repository, wherein each registration record includes data representative of:20                   a user identity of said each user;a user secret of said each user;authentication challenges and responses;the QREF locator associated with the data item;a data item reference identifier associated with the data item;25                  a quantum key identifier associated with the QD key used to encrypt the dataitem; andan access control list associated with the data item;receiving an QREF access token associated with a data item from a second user; retrieving one or more registration records associated with the second user;30           identifying the QREF locator associated with the QREF access token by:generating, for each retrieved registration record, an QREF access token based on said each retrieved registration record; andmatching the generated QREF access token with the received QREF access token; and35                   identifying the QREF locator from the registration record associated with thegenerated QREF access token matching the received QREF access token;2020380554   25 May 2026in response to identifying the QREF locator, performing one or more access operations in relation to the data item corresponding to the QREF locator stored in the repository and the QREF access token.

13. The computer-implemented method as claimed in claim 12, the QS network5 comprising one or more QS registration server(s) and a plurality of registration nodes, wherein a QS registration server connects to a set of registration nodes of the plurality of registration nodes, and one or more QS server(s) distribute one or more groups of QD keys from the set of QD keys to the QS registration servers, each QS registration server distributing one or more QD keys from a group of QD keys to the corresponding set of10 registration nodes, the method further comprising:receiving, from a QS registration server generating a registration record associated with a user, the registration record of the user, wherein a device of the user is in communication with a registration node coupled to the QS registration server, the registration record including one or more user data representative of:15                   a user identity of said each user;one or more device identifiers associated with the user;user credentials associated with logging into the QS system;a user secret of said each user;authentication challenges and responses;20                   a QREF locator associated with a data item in relation to the user;a data item reference identifier associated with the data item;a QD key identifier associated with the QD key used to encrypt the data item; andan access control list associated with the data item; and25            storing the registration record of said user in the repository.

14. The computer-implemented method as claimed in claim 13, the method furthercomprising:receiving user credentials from a QS registration server associated with a user, wherein a device of the user is in communication with a registration node coupled to the QS 30 registration server;retrieving the registration record associated with the user based on the user credentials;receiving a QREF access token associated with a data item from the user;identifying the QREF locator associated with the QREF access token by:35                   generating, for each retrieved registration record, an QREF access tokenbased on said each retrieved registration record; and2020380554   25 May 2026matching the generated QREF access token with the received QREF access token; andidentifying the QREF locator from the retrieved registration record associated with the generated QREF access token matching the received QREF access token;5                   in response to identifying the QREF locator, performing one or more accessoperations in relation to the data item corresponding to the QREF locator stored in the repository and the QREF access token.

15. The computer-implemented method as claimed in any one of the preceding claims,wherein:10            the repository further comprises a distributed ledger;the QS network further comprising a plurality of QS servers, each QS server comprises a HSM with an identical set of QD keys stored thereon and each QS server of the plurality of QS servers comprising a node for operating the distributed ledger, wherein the nodes of the plurality of QS servers form a QS distributed ledger network configured for15 providing storage and access to one or more data item(s) stored on the distributed ledger, wherein the method further comprising:receiving a QREF locator for storing an encrypted data item in the distributed ledger; andstoring the encrypted data item in the distributed ledger using the QREF locator as 20 an address for the location of the encrypted data item in the distributed ledger.

16. The computer-implemented method as claimed in any one of the preceding claims,wherein:the repository further comprises a shared ledger;the QS network further comprising a plurality of QS servers, each QS server25 comprises a HSM with an identical set of QD keys stored thereon and each QS server of the plurality of QS servers comprising a node for operating the shared ledger between corresponding nodes, wherein the nodes of the plurality of QS servers form a QS shared ledger network configured for providing storage and access to one or more data item(s) stored on the shared ledger, wherein the method further comprising:30           receiving a QREF locator for storing the encrypted data item in the shared ledger;andstoring the encrypted data item in the shared ledger using the QREF locator as an address for the location of the encrypted data item in the shared ledger.2020380554   25 May 202617.    The computer-implemented method as claimed in any one of the preceding claims,wherein:the repository further comprises a digital storage platform using publish / subscribe, request / response and / or real-time based messaging for storing and accessing data items,5 the QS network further comprising a plurality of QS servers, each QS server comprises a HSM with an identical set of QD keys stored thereon and each QS server of the plurality of QS servers comprising a node for operating digital storage platform messaging between corresponding nodes, wherein the nodes of the plurality of QS servers form the digital storage platform as a QS distributed storage network configured for providing storage and10 access to one or more data item(s) based on the digital storage platform messaging, wherein the method further comprising:receiving a QREF locator for storing the encrypted data item in the distributed storage platform; andstoring the encrypted data item in the shared ledger using the QREF locator as an 15 address for the location of the encrypted data item in the distributed storage platform.

18. A computer-implemented method of quantum safe “QS” storage and retrieval in a QSnetwork, the QS network comprising one or more QS server(s) and a repository for storing and retrieving one or more data item(s) by a plurality of users, wherein each QS server comprises a hardware security module “HSM” with an identical set of quantum distributed20 “QD” keys stored thereon and the QS servers communicate securely with each other and the repository using quantum encryption based on one or more available QD keys from the set of QD keys, the method performed by a QS server comprising:in response to receiving a data item for storagegenerating a quantum reference “QREF” locator based on a user secret of25           the first user and an available QD key selected from the set of QD keys, wherein thegenerated QREF locator is unique, and wherein the QREF locator indicates a logical address or a physical address for storing and accessing the data item encrypted with the selected QD key in the repository and an identity of the first user;linking the QREF locator to the available QD key of the set of QD keys;30                      storing the link between the QREF locator to the available QD key of theset of QD keys in the HSM;generating an QREF access token based on the QREF locator, wherein the QREF access token enables access operations to be performed on the data item when stored in the repository;35                      storing the data item in the repository indexed by the QREF locator; andsending the QREF access token to the first user; andin response to receiving an QREF access token for a data item stored in the repository;1642020380554   25 May 202610identifying a QREF locator based on the QREF access token and theidentity of the second user; andproviding access operations to the second user in relation to the encrypted data item in the repository based on the identified QREF locator.

19. A computer-readable medium comprising code or computer instructions storedthereon, which when executed by a processor unit, causes the processor unit to perform the computer-implemented method according to any one of claims 1 to 18.