Delayed quantum key distribution
Delayed quantum key distribution technology solves the security problem of existing encryption algorithms under the threat of quantum computers by limiting the scope of key use within a specific time window, and achieves efficient use of resources and accurate maintenance of data structures.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- JUNIPER NETWORKS INC
- Filing Date
- 2021-12-03
- Publication Date
- 2026-04-24
AI Technical Summary
Existing mathematically based encryption algorithms are not secure enough against the threat of quantum computers, and the key generation process consumes a lot of resources, so a more secure and efficient key distribution method is needed.
Delayed quantum key distribution technology is adopted, which generates a key through a pair of QKD devices and is only available to the task node and the QKD device within a specific time window. The control node and the verification node obtain the key after the time window expires, ensuring the security of the key and the efficiency of resource utilization.
It improves the security of key distribution, reduces the consumption of computing resources, ensures that keys are used only by authorized devices within a time window, and enhances the accuracy and integrity of data structures.
Smart Images

Figure CN115913523B_ABST
Abstract
Description
Background Technology
[0001] Quantum key distribution (QKD) securely agrees on symmetric encryption keys using quantum physics. To generate a key, two QKD devices exchange quantum states (e.g., using polarized photons) by utilizing a quantum communication channel (e.g., an optical channel) or free space (e.g., a line-of-sight connection between a ground-based QKD device and a QKD device included in a satellite). Summary of the Invention
[0002] Some implementations described herein relate to a method. The method may include a node receiving a first message from a quantum key distribution device, the first message including an identifier associated with a key, wherein the key is associated with a specific time window. The method may include a node sending a second message to another node, the second message including an identifier associated with the key and a request to perform at least one task. The method may include a node receiving a third message from another node, the third message including information associated with the other node performing at least one task and information indicating the time for the other node to perform at least one task. The method may include a node receiving a fourth message from the quantum key distribution device, the fourth message including a key and information indicating a specific time window, wherein the fourth message is received after the specific time window has expired. The method may include a node processing the third message based on the fourth message to determine whether the third message is valid. The method may include a node performing one or more actions based on determining whether the third message is valid.
[0003] Some embodiments described herein relate to a non-transitory computer-readable medium storing an instruction set for a quantum key distribution device. When executed by one or more processors of the quantum key distribution device, the instruction set enables the quantum key distribution device to communicate with another quantum key distribution device to generate a key. When executed by one or more processors of the quantum key distribution device, the instruction set enables the quantum key distribution device to determine an identifier associated with the key. When executed by one or more processors of the quantum key distribution device, the instruction set enables the quantum key distribution device to determine a specific time window associated with the key. When executed by one or more processors of the quantum key distribution device, the instruction set enables the quantum key distribution device to send a first message to a node, the first message including the identifier associated with the key. When executed by one or more processors of the quantum key distribution device, the instruction set enables the quantum key distribution device to send a second message to a node, the second message including the key and information indicating the specific time window.
[0004] Some embodiments described herein relate to a node. The node may include one or more memories and one or more processors. The node may be configured to receive a first message from another node, the first message including an identifier associated with a key and a request to perform at least one task. The node may be configured to send a second message to a quantum key distribution device, the second message including an identifier associated with the key. The node may be configured to receive a third message from the quantum key distribution device, the third message including a key and information indicating a specific time window associated with the key. The node may be configured to perform at least one task based on the request included in the first message. The node may be configured to determine that the time for the node to perform at least one task is within the specific time window. The node may be configured to generate information associated with the node performing at least one task based on the execution of at least one task and the determination that the time for the node to perform at least one task is within the specific time window, and using the key to generate information associated with the node performing at least one task. The node may be configured to send a fourth message to the other node, the fourth message including information associated with the node performing at least one task and information indicating the time for the node to perform at least one task. Attached Figure Description
[0005] Figures 1A to 1F This is a schematic diagram of an example implementation of delayed quantum key distribution described in this article.
[0006] Figure 2 This is a schematic diagram of an example environment in which the systems and / or methods described in this article can be implemented.
[0007] Figures 3 to 4 yes Figure 2 A schematic diagram of example components of one or more devices.
[0008] Figures 5 to 7 This is a flowchart of an example process associated with delayed quantum key distribution. Detailed Implementation
[0009] The following detailed description of the exemplary embodiments is taken with reference to the accompanying drawings. The same reference numerals may identify the same or similar elements in different figures.
[0010] To ensure secure communication between computing devices, typical cryptographic schemes rely on mathematics-based algorithms. However, these algorithms consume significant computational resources (e.g., processing, memory, communication, and / or power), and with the increasing capabilities of quantum computers, data encrypted using such algorithms is highly vulnerable to attack. In some cases, physics-based algorithms, such as quantum key distribution (QKD) schemes, can be used to more securely distribute keys for encrypting and decrypting data. However, key generation can be resource-intensive.
[0011] Some implementations described herein provide delayed quantum key distribution. A pair of QKD devices can communicate to generate a key, and the first QKD device in the pair can be configured to delay the key's disclosure until a specific time window expires (e.g., a 5-minute window, a 12-hour window, or a 7-day window, etc.). The first QKD device can notify one or more verification nodes that the key has been generated, but can only provide the identifier associated with the key (e.g., an alphanumeric text string) to the one or more verification nodes. A control node can request a task node to perform at least one task (e.g., a computation task) and / or can share the identifier with the task node. The task node can communicate with the second QKD device in the pair (based on the identifier) to obtain the key for the specific time window. In this way, within a specific time window, the key is only available to the pair of QKD devices and the task node (rather than to one or more verification nodes).
[0012] A task node can perform at least one task within a specific time window and can use a key to generate information associated with the task node performing at least one task (e.g., to encrypt or sign data associated with the task node performing at least one task). The task node can send a message including the information to a control node and / or one or more verification nodes, which can delay any processing of the message until the specific time window expires. The first QKD device can then determine that the specific time window has expired and can provide the key to each of the control node and / or one or more verification nodes. Each of the control node and / or one or more verification nodes that receives the message from the task node can use the key to determine whether the message from the task node is valid (e.g., by decrypting or verifying the information associated with the task node performing at least one task). Therefore, a specific node among the control node and / or one or more verification nodes that receives the message from the task node can then cause one or more actions to be performed, such as causing a data structure to include at least one entry associated with the task node performing at least one task (e.g., when the message is determined to be valid) or causing a data structure to exclude any entries associated with the task node performing at least one task (e.g., when the message is determined to be invalid).
[0013] In this way, within a specific time window, the key is only available to the devices that need to know it (such as QKD devices and task nodes). Additionally, the first QKD device communicates with the control node and / or one or more verification nodes, and the second QKD device communicates with the task node, preventing cross-communication between QKD devices and nodes. Further, in some implementations, the first QKD device only sends the key to the control node and / or one or more verification nodes, thus not receiving information from the control node and / or one or more verification nodes that might jeopardize the functionality of the first QKD device. Therefore, when the control node and / or one or more verification nodes obtain the key, after the specific time window expires, the control node and / or one or more verification nodes have a high degree of confidence that any message sent by the task node and associated with the task node's execution of a task within the specific time window can be verified using the key. This increases the likelihood that the control node and / or verification nodes correctly determine whether a message is valid (e.g., not fraudulent, deceptive, or invalid), which increases the likelihood that the data structures associated with the control node and / or verification nodes are accurately maintained. Furthermore, some implementations allow keys to be used multiple times within a specific time window (instead of a single use), which saves computational resources (e.g., processing resources, memory resources, communication resources, and / or power resources) that would otherwise be needed to generate, protect, maintain, and / or provide multiple single-use keys within a specific time window.
[0014] Figures 1A to 1F This is a schematic diagram of an example implementation 100 associated with delayed quantum key distribution. (See diagram below.) Figures 1A to 1F As shown, Example Implementation 100 includes a pair of QKD devices (shown as QKD device 1 and QKD device 2), a control node, one or more verification nodes (shown as verification nodes 1 to N, where N≥1) and / or task nodes. The following is in conjunction with... Figures 2 to 4 Describe these devices in more detail.
[0015] like Figure 1A As shown by reference numeral 102, QKD device 1 and QKD device 2 can communicate to generate a key. For example, QKD device 1 and QKD device 2 can be connected via a quantum channel (e.g., an optical channel that allows the transmission of quantum states) and a public channel (e.g., a channel associated with a traditional network, such as the Internet or a wireless network). QKD device 1 and QKD device 2 can then communicate with each other via the quantum channel and the public channel using a QKD protocol (e.g., the BB84 protocol, the E91 protocol, or an entanglement pair generation protocol, etc.) to generate a key. In this way, QKD device 1 and QKD device 2 can generate a key that is known only to QKD device 1 and QKD device 2 at the time of key generation.
[0016] As shown by reference numeral 104 in the attached figure, QKD device 1 can determine an identifier associated with the key. For example, QKD device 1 can generate an identifier associated with the key (e.g., a unique identifier (UID)) and can store the key and identifier in entries of a data structure associated with QKD device 1 (e.g., included in a database, table, or file accessible to QKD device 1 and / or QKD device 1). The identifier can be generated based on the key. For example, the identifier can be a hash of the key or the generation time of the key. The identifier can be used to look up and identify the key (e.g., as an index to an entry in a data structure).
[0017] As shown by reference numeral 106 in the attached figure, QKD device 1 can determine a specific time window associated with a key. The specific time window can indicate the start and end times of the specific time window. When the key is used within the specific time window (e.g., the use occurs between the start and end times), the key may be valid (e.g., for encrypting and signing data, as described elsewhere herein). The specific time window expires after its end time (therefore, the key ceases to be valid after the specific time window expires). The specific time window can be on the order of seconds, minutes, hours, days, weeks, or months. For example, QKD device 1 can determine a specific time window associated with a key (e.g., 5 minutes between the start and end times of the specific time window). The specific time window can occur immediately (e.g., the start time of the specific time window may be the time the specific time window was generated) or in the future (e.g., the start time of the specific time window may occur after the time the specific time window was generated). QKD device 1 can store information indicating the specific time window in entries of a data structure associated with QKD device 1 (e.g., with the key and identifier).
[0018] like Figure 1AAs further illustrated by reference numeral 108, QKD device 1 can send a message to QKD device 2, the message including an identifier and / or information indicating a specific time window. For example, QKD device 1 can send the message to QKD device 2 via a common channel between QKD device 1 and QKD device 2 (e.g., as a unicast, multicast, or broadcast transmission). In some embodiments, even if QKD device 1 does not send a message to QKD device 2, QKD device 2 can determine the identifier and / or information indicating a specific time window. For example, QKD device 2 can perform a hash of a key to determine the identifier and / or can be pre-configured to associate the key with a specific time window. QKD device 2 can store the key, identifier, and / or information indicating a specific time window in entries of QKD device 2's data structures (e.g., included in and / or in databases, tables, or files accessible to QKD device 2). The identifier can be used to look up and identify the key and / or information indicating a specific time window (e.g., as an index to entries in the data structure).
[0019] In some implementations, QKD device 1 can be connected to a control node and / or one or more authentication nodes (e.g., via one or more public or private channels). Figure 1B As shown by reference numeral 110, QKD device 1 can send a message to a control node and / or one or more authentication nodes (e.g., via one or more public or private channels), the message including an identifier associated with a key. For example, QKD device 1 can send a message to each of the control node and / or one or more authentication nodes (e.g., as a broadcast message to each of control node and / or one or more authentication nodes 1 to N). As another example, a control node can send a message to QKD device 1 (e.g., via a public or private channel) including a request for an identifier associated with a key, and QKD device 1 can send a message (e.g., based on a request included in a message sent by a particular authentication node) to the control node (e.g., via a public or private channel) including an identifier associated with a key. In this way (e.g., as described in both examples), QKD device 1 can send a message to the control node including an identifier associated with a key.
[0020] In some implementations, QKD device 1 may send a message, including an identifier associated with a key, to one or more verification nodes before the expiration of a specific time window. For example, QKD device 1 may send a message to a control node and / or one or more verification nodes before the end time of a specific time window. As another example, QKD device 1 may send a message to a control node and / or one or more verification nodes before the start time of a specific time window.
[0021] like Figure 1C As shown by reference numeral 112 in the accompanying drawings, the control node can identify an identifier associated with the key. For example, a specific verification node can process (e.g., parse) messages received from QKD device 1 (e.g., as described herein regarding...). Figure 1B (As described by reference numeral 110 in the attached figure), the message includes an identifier associated with the key to identify the identifier.
[0022] In some implementations, the control node may be a "task request" node. That is, the control node may be configured to request another node, such as a task node, to perform at least one task. For example, at least one task may include performing at least one action (e.g., receiving, processing, storing, routing, and / or providing data) and updating a data structure to include at least one entry associated with at least one action (e.g., as an execution record of at least one action). Thus, as Figure 1C As shown by reference numeral 114 in the accompanying drawings, the control node can send a message to the task node, which includes a request to perform at least one task. Additionally or alternatively, the message may include an identifier associated with a key.
[0023] like Figure 1C As further shown by reference numeral 116, a task node may identify an identifier associated with a key and / or a request to perform at least one task. For example, a task node may process (e.g., parse) a message received from a particular authentication node (e.g., as described herein with respect to reference numeral 114) that includes an identifier associated with a key and / or a request to perform at least one task, to identify the identifier associated with the key and / or the request to perform at least one task.
[0024] In some implementations, the task node may connect to QKD device 2 (e.g., via a public or private channel). As indicated by reference numeral 118, the task node may send messages to QKD device 2 (e.g., via a public or private channel). For example, when the task node has identified an identifier associated with the key, the message may include the identifier associated with the key and / or a request for information associated with the key of QKD device 2. As another example, when the task node has not yet identified an identifier associated with the key (because the message received from the control node only includes a request to perform at least one task), the message may only include a request for information associated with the key (e.g., a request for information associated with the active key). The request for information associated with the key may include key acceptability criteria, such as criteria associated with time window length, time window start time, time window end time, identifier bit pattern, and / or key bit pattern.
[0025] QKD device 2 can process (e.g., parse) messages to identify identifiers associated with keys and / or requests for information associated with keys. Therefore, as indicated by reference numeral 120, QKD device 2 can identify keys. For example, QKD device 2 can search a data structure associated with QKD device 2 based on the identifier associated with the key to identify entries that include the identifier associated with the key, the key, and information indicating a specific time window associated with the key. As another example, QKD device 2 can search a data structure associated with QKD device 2 based on key acceptability criteria included in a request for information associated with the key to identify entries associated with keys that meet the key acceptability rules, such as entries including the identifier associated with the key, the key, and information indicating a specific time window associated with the key.
[0026] As shown by reference numeral 122 in the accompanying drawings, QKD device 2 can send a message to a task node (e.g., via a public or private channel between the task node and QKD device 2), the message including information associated with a key. The information associated with the key may include the key itself, information indicating a specific time window associated with the key, key derivation information (e.g., information derived cryptographically from the key (e.g., by encrypting the key)), and / or other key-related information.
[0027] like Figure 1D As shown by reference numeral 124 in the accompanying drawings, the task node can identify a key and / or a specific time window. For example, the task node can process (e.g., parse) messages received from QKD device 2 (e.g., as described herein regarding...). Figure 1C (As described by reference numeral 122 in the accompanying figure), the message includes a key and information indicating a specific time window associated with the key to identify the key and the specific time window. In another example, the task node may identify key derivation information included in the message and may process the key derivation information (e.g., may decrypt the key derivation information) to identify the key.
[0028] like Figure 1D As further shown by reference numeral 126 in the accompanying drawings, a task node can perform at least one task (e.g., based on a request received from a specific verification node and included in a message, as described herein). Figure 1C (As described by reference numeral 114). As shown by reference numeral 128, a task node can identify the time when a task node performs at least one task. For example, a task node can identify the time when a task node performs at least one task as the completion time of performing at least one action and / or updating a data structure included in at least one task node.
[0029] like Figure 1DAs further illustrated by reference numeral 130, a task node can determine that the time during which it performs at least one task falls within a specific time window. For example, a task node can determine that the time during which it performs at least one task is after or equal to a start time and at or equal to the end time of the specific time window. Therefore, as shown by reference numeral 132, a task node can generate (e.g., by using a key) information associated with performing at least one task. For example, a task node can generate data (e.g., "proof-of-stake" data and / or data indicating the time during which it performs at least one task) based on the performance of at least one task, and can encrypt the data using the key. In this way, the encrypted data is information associated with the task node performing at least one task. As another example, a task node can generate data based on the performance of at least one task, and can use the key and generate a signature based on the data. In this way, the data and the signature are information associated with the task node performing at least one task.
[0030] In some implementations, the task node may be connected to a control node and / or one or more authentication nodes (e.g., via one or more public channels). Figure 1D As shown by reference numeral 134, a task node can send a message (e.g., via one or more common channels) to a group of nodes, including a control node and / or one or more authentication nodes, comprising information related to the task node performing at least one task and information indicating the time at which the task node performs at least one task. For example, a task node can send a message to each of the control node and / or one or more authentication nodes (e.g., as a broadcast message and / or multicast message to each of the control node and / or one or more authentication nodes 1 to N). As another example, a task node can send a message to the control node (e.g., as a unicast message, such as because the control node requests the execution of at least one task, as described herein with respect to 1C and reference numeral 114). In each example, the message can be relayed to a intended target node (e.g., one or more nodes can route the message to the target node).
[0031] like Figure 1EAs shown by reference numeral 136, QKD device 1 can determine that a specific time window has expired. For example, QKD device 1 can determine that the current time is after the end time of the specific time window. Therefore, as shown by reference numeral 138, QKD device 1 can send a message to the control node and / or one or more authentication nodes (e.g., via one or more public channels between QKD device 1 and one or more authentication nodes), the message including a key, an identifier associated with the key, information indicating a specific time, key derivation information (e.g., information derived cryptographically from the key (e.g., by encrypting the key)) and / or other key-related information. For example, QKD device 1 can send the message to each of the control node and / or one or more authentication nodes (e.g., as a broadcast message to each of one or more authentication nodes 1 to N). In another example, QKD device 1 can send the message to each of a set of nodes that received the message from the task node (e.g., the message includes information associated with the task node performing at least one task and information indicating the time when the task node performs at least one task). As another example, QKD device 1 can send the message only to the control node. In this way, after a specific time window expires, QKD device 1 can send a message to the control node and / or one or more authentication nodes. The message includes a key, an identifier associated with the key, information indicating the specific time window, key derivation information, and / or other key-related information.
[0032] like Figure 1F As shown by reference numeral 140 in the accompanying drawings, a specific node in a set of nodes that receives messages from a task node (such as a control node) can be identified by a key and a specific time window. For example, a specific node can process (e.g., parse) messages received from QKD device 1 (e.g., as described herein regarding...). Figure 1E As described by reference numeral 138 in the accompanying drawings, the message includes a key, an identifier associated with the key, information indicating a specific time window, key derivation information, and / or other key-related information to identify the key, the identifier associated with the key, information indicating a specific time window, key derivation information, and / or other key-related information. In another example, a specific node may identify the key derivation information included in the message and may process the key derivation information (e.g., may decrypt the key derivation information) to identify the key.
[0033] As shown by reference numeral 142 in the attached figure, a specific node can process messages from task nodes (e.g., information associated with the task node performing at least one task and information indicating the time when the task node performs at least one task, as described herein). Figure 1D(As described by reference numeral 134 in the accompanying drawings). For example, a particular node may process (e.g., parse) a message from a task node to identify the time when the task node performed at least one task. The particular node may determine that the time when the task node performed at least one task occurred after a specific time window expired, and therefore may determine that the message from the task node is invalid (e.g., because at least one task was not performed within the specific time window). Additionally or alternatively, the particular node may determine that the time when the task node performed at least one task occurred after the time the message from the task node was received, and therefore may determine that the message from the task node is invalid (e.g., due to the time difference associated with the message).
[0034] As another example, a specific node can process (e.g., parse) messages from task nodes to identify the time when the task node performed at least one task and the information associated with that task node's performance. The specific node can determine that the time when the task node performed at least one task occurred within a specific time window. Therefore, the specific node can use a key to process (e.g., decrypt or verify) the information associated with the task node's performance of at least one task to determine if the task node used the key to generate the information associated with its performance of at least one task, thus determining that the message from the task node is valid. Alternatively, the specific node can use the key to process the information associated with the task node's performance of at least one task to determine if the task node did not use the key to generate the information associated with its performance of at least one task, thus determining that the message from the task node is invalid.
[0035] like Figure 1F As further illustrated by reference numeral 144, a specific node may cause one or more actions to be performed. For example, when a message from a task node is determined to be valid (e.g., as described with respect to reference numeral 142), the specific node may cause a data structure associated with the specific node (e.g., a database, table, or file included in and / or accessible to the specific node) to include at least one entry associated with the task node performing at least one task (e.g., adding at least one entry to the data structure and / or submitting at least one entry to the data structure). For example, at least one entry may include information associated with the task node performing at least one task, information indicating the time when the task node performs at least one task, a key, and / or information indicating a specific time window. As another example, when a message from a task node is determined to be invalid (e.g., as described with respect to reference numeral 142), the specific node may cause a data structure to exclude any entries associated with the task node performing at least one task. Thus, the specific node may prevent any entries associated with the task node performing at least one task from being added to the data structure and / or may delete, discard, or roll back any temporary entries associated with the task node performing at least one task.
[0036] like Figure 1F As further illustrated, when one or more other nodes (excluding the specific node) in a group of nodes that have received a message from the task node receive the message from the task node, each of the one or more other nodes may identify a key and a specific time window (e.g., as described with respect to reference numeral 140), and each node may process the message from the task node to determine whether the message from the task node is valid (e.g., as described with respect to reference numeral 142). Therefore, the one or more other nodes may communicate with each other and / or with the specific node (e.g., via one or more common channels between the one or more other nodes and / or the specific node) to cause one or more actions to be performed (e.g., as described with respect to reference numeral 144). For example, one of the one or more other nodes (e.g., verification node 1) may communicate with at least one of the one or more other nodes and / or the specific node (e.g., the control node) to determine that at least a majority of the one or more other nodes and / or the specific node have determined that the message from the task node is valid. Therefore, one of the other nodes (e.g., verification node 1) may cause the data structure associated with that other node to include at least one entry associated with the task node performing at least one task. As another example, an additional node may communicate with at least one of one or more other nodes and / or a specific node (e.g., a control node) to determine that at least a majority of the one or more other nodes and / or the specific node have determined that the message from the task node is invalid. Therefore, an additional verification node may cause the data structures associated with that additional verification node to exclude any entries related to the task node performing at least one task.
[0037] As mentioned above, Figures 1A to 1F Provided as an example. Other examples may be related to... Figures 1A to 1F The descriptions are different. Figures 1A to 1F The number and arrangement of the equipment shown are provided as an example. In fact, with... Figures 1A to 1F Compared to the equipment shown, there may be additional equipment, fewer equipment, different equipment, or equipment arranged in a different manner. Furthermore, Figures 1A to 1F The two or more devices shown can be implemented in a single device or Figures 1A to 1F The single device shown can be implemented as multiple distributed devices. Additionally or alternatively, Figures 1A to 1F The set of devices shown (e.g., one or more devices) can perform actions described as being performed by Figures 1A to 1F The other set of devices shown performs one or more functions.
[0038] Figure 2This is a schematic diagram of an example environment 200 that can implement the systems and / or methods described in this document. For example... Figure 2 As shown, environment 200 may include two QKD devices 210 (shown as QKD device 210-1 and QKD device 210-2), one or more verification nodes 220 (shown as nodes 220-1 to 220-N, where N≥1), task node 230, control node 240, and network 250. The devices in environment 200 can be interconnected via wired, wireless, or a combination of wired and wireless connections.
[0039] QKD device 210 includes one or more devices capable of receiving, generating, storing, processing, providing, and / or routing information associated with delayed quantum key distribution, as described elsewhere herein. QKD device 210 may include communication devices and / or computing devices. For example, QKD device 210 may include servers such as application servers, client servers, web servers, database servers, host servers, proxy servers, virtual servers (e.g., executing on computing hardware), or servers in cloud computing systems. In some embodiments, QKD device 210 includes computing hardware used in a cloud computing environment. QKD device 210 can be connected to another QKD device 210, one or more authentication nodes 220, task nodes 230, and / or network 250 via one or more public channels. In some embodiments, QKD device 210 includes waveplates, beam splitters, electro-optic modulators, laser emitters, optical waveform generators, and / or other components associated with key transmission and / or reception. QKD device 210 may be configured to transmit and / or receive modulated light comprising multiple spatial nodes associated with a key. QKD device 210 can be connected to another QKD device 210 via a quantum channel (e.g., an optical channel that allows the transmission of quantum states).
[0040] Verification node 220 includes one or more devices capable of receiving, generating, storing, processing, providing, and / or routing information associated with messages related to verification and delayed quantum key distribution. Verification node 220 may include communication devices and / or computing devices. For example, verification node 220 may include servers such as application servers, client servers, web servers, database servers, host servers, proxy servers, virtual servers (e.g., running on computing hardware), or servers in a cloud computing system. As another example, verification node 220 may include routers such as label switching routers (LSRs), label edge routers (LERs), ingress routers, egress routers, provider routers (e.g., provider edge routers or provider core routers), virtual routers, or another type of router. Additionally or alternatively, verification node 220 may include gateways, switches, firewalls, hubs, bridges, reverse proxies, servers (e.g., proxy servers, cloud servers, data center servers, etc.), load balancers, and / or similar devices. Verification node 220 may be connected to one or more other verification nodes 220, task nodes 230, control nodes 240, and / or networks 250 via one or more public channels.
[0041] Task node 230 includes one or more devices capable of receiving, generating, storing, processing, providing, and / or routing information associated with performing at least one task related to delayed quantum key distribution. Task node 230 may include communication devices and / or computing devices. For example, task node 230 may include servers such as application servers, client servers, web servers, database servers, host servers, proxy servers, virtual servers (e.g., running on computing hardware), or servers in a cloud computing system. As another example, task node 230 may include routers such as LSRs, LERs, ingress routers, egress routers, provider routers (e.g., provider edge routers or provider core routers), virtual routers, or another type of router. Additionally or alternatively, task node 230 may include gateways, switches, firewalls, hubs, bridges, reverse proxies, servers (e.g., proxy servers, cloud servers, data center servers, etc.), load balancers, and / or similar devices. Task node 230 may be connected to one or more authentication nodes 220, control nodes 240, and / or networks 250 via one or more public channels.
[0042] Control node 240 includes one or more devices capable of receiving, generating, storing, processing, providing, and / or routing information associated with a message requesting the execution of at least one task and / or verifying a message associated with delayed quantum key distribution. Control node 240 may include communication devices and / or computing devices. For example, control node 240 may include servers such as application servers, client servers, web servers, database servers, host servers, proxy servers, virtual servers (e.g., running on computing hardware), or servers in a cloud computing system. As another example, task node 240 may include routers such as LSRs, LERs, ingress routers, egress routers, provider routers (e.g., provider edge routers or provider core routers), virtual routers, or another type of router. Additionally or alternatively, control node 240 may include gateways, switches, firewalls, hubs, bridges, reverse proxies, servers (e.g., proxy servers, cloud servers, data center servers, etc.), load balancers, and / or similar devices. Control node 240 may be connected to one or more authentication nodes 220, control nodes 230, and / or networks 250 via one or more public channels.
[0043] Network 250 includes one or more wired and / or wireless networks. For example, network 250 may include cellular networks (e.g., fifth-generation (5G) networks, fourth-generation (4G) networks (such as Long Term Evolution (LTE) networks), third-generation (3G) networks, Code Division Multiple Access (CDDMA) networks, Public Land Mobile Networks (PLMN), Local Area Networks (LAN), Wide Area Networks (WAN), Metropolitan Area Networks (MAN), telephone networks (e.g., Public Switched Telephone Network (PSTN)), private networks, self-organizing networks, intranets, the Internet, fiber-based networks, cloud computing networks, etc.) and / or combinations of these or other types of networks.
[0044] Figure 2 The number and arrangement of devices and networks shown are provided as one or more examples. In fact, with Figure 2 Compared to the devices and / or networks shown, there may be additional devices and / or networks, fewer devices and / or networks, different devices and / or networks, or devices and / or networks arranged in a different manner. Furthermore, Figure 2 The two or more devices shown can be implemented within a single device or Figure 2 The single device shown can be implemented as multiple distributed devices. Additionally or alternatively, a group of devices in environment 200 (e.g., one or more devices) can perform one or more functions described as being performed by another group of devices in environment 200.
[0045] Figure 3This is a schematic diagram of example components of device 300, which may correspond to QKD device 210, verification node 220, task node 230, and / or control node 240. In some embodiments, QKD device 210, verification node 220, task node 230, and / or control node 240 include one or more devices 300 and / or one or more components of device 300. For example... Figure 3 As shown, device 300 may include bus 310, processor 320, memory 330, input component 340, output component 350 and communication component 360.
[0046] Bus 310 includes one or more components that enable wired and / or wireless communication between components of device 300. Bus 310 can... Figure 3 Two or more components are coupled together, such as through operational coupling, communication coupling, electronic coupling, and / or electrical coupling. Processor 320 includes a central processing unit, graphics processing unit, microprocessor, controller, microcontroller, digital signal processor, field-programmable gate array, application-specific integrated circuit, or another type of processing component. Processor 320 is implemented in hardware, firmware, or a combination of hardware and software. In some embodiments, processor 320 includes one or more processors capable of being programmed to perform one or more operations or processes described elsewhere herein.
[0047] Memory 330 includes volatile and / or non-volatile memory. For example, memory 330 may include random access memory (RAM), read-only memory (ROM), hard disk drive, and / or another type of memory (e.g., flash memory, magnetic memory, and / or optical memory). Memory 330 may include internal memory (e.g., RAM, ROM, or hard disk drive) and / or removable memory (e.g., removable via a Universal Serial Bus connection). Memory 330 may be a non-transitory computer-readable medium. Memory 330 may store information, instructions, and / or software (e.g., one or more software applications) related to the operation of device 300. In some embodiments, memory 330 includes one or more memories coupled to one or more processors (e.g., processor 320), such as via bus 310.
[0048] Input component 340 enables device 300 to receive input, such as user input and / or sensed input. For example, input component 340 may include a touchscreen, keyboard, keypad, mouse, button, microphone, switch, sensor, GPS sensor, accelerometer, gyroscope, and / or actuator. Output component 350 enables device 300 to provide output, such as through a display, speaker, and / or light-emitting diode. Communication component 360 enables device 300 to communicate with other devices via wired and / or wireless connections. For example, communication component 360 may include a receiver, transmitter, transceiver, modem, network interface card, and / or antenna.
[0049] Device 300 may perform one or more operations or procedures described herein. For example, a non-transitory computer-readable medium (e.g., memory 330) may store a set of instructions (e.g., one or more instructions or code) for execution by processor 320. Processor 320 may execute the set of instructions to perform one or more operations or procedures described herein. In some embodiments, one or more processors 320 execute the set of instructions, causing one or more processors 320 and / or device 300 to perform one or more operations or procedures described herein. In some embodiments, hardwired circuitry is used in place of or in combination with instructions to perform one or more operations or procedures described herein. Additionally or alternatively, processor 320 may be configured to perform one or more operations or procedures described herein. Therefore, the embodiments described herein are not limited to any particular combination of hardware circuitry and software.
[0050] Figure 3 The number and arrangement of components shown are provided as an example. Figure 3 Compared to the components shown, device 300 may also include additional components, fewer components, different components, or components arranged in a different manner. Additionally or alternatively, a set of components of device 300 (e.g., one or more components) may perform one or more functions described as being performed by another set of components of device 300.
[0051] Figure 4 This is a schematic diagram of example components of device 400. Device 400 may correspond to QKD device 210, verification node 220, task node 230, and / or control node 240. In some embodiments, QKD device 210, verification node 220, task node 230, and / or control node 240 may include one or more devices 400 and / or one or more components of device 400. Figure 4As shown, device 400 may include one or more input components 410-1 to 410-B (B≥1) (hereinafter collectively referred to as input component 410 and individually referred to as input component 410), switch component 420, one or more output components 430-1 to 430-C (C≥1) (hereinafter collectively referred to as output component 430 and individually referred to as output component 430), and controller 440.
[0052] Input component 410 may be one or more attachment points of a physical link and may be one or more entry points for incoming traffic (such as packets). Input component 410 may process incoming traffic, such as by performing data link layer encapsulation or decapsulation. In some embodiments, input component 410 may transmit and / or receive packets. In some embodiments, input component 410 may include an input line card, including one or more packet processing components (e.g., in the form of integrated circuits), such as one or more interface cards (IFCs), packet forwarding components, line card controller components, input ports, processors, memory, and / or input queues. In some embodiments, device 400 may include one or more input components 410.
[0053] Switching component 420 interconnects input component 410 with output component 430. In some embodiments, switching component 420 may be implemented via one or more crossbar switches, via a bus, and / or utilizing shared memory. Shared memory may act as a temporary buffer to store packets from input component 410 before they are finally scheduled to be delivered to output component 430. In some embodiments, switching component 420 enables input component 410, output component 430, and / or controller 440 to communicate with each other.
[0054] Output component 430 can store packets and schedule packets for transmission over the output physical link. Output component 430 can support data link layer encapsulation or decapsulation and / or various higher-level protocols. In some embodiments, output component 430 can transmit and / or receive packets. In some embodiments, output component 430 may include an output line card, including one or more packet processing components (e.g., in the form of integrated circuits), such as one or more IFCs, packet forwarding components, line card controller components, output ports, processors, memory, and / or output queues. In some embodiments, device 400 may include one or more output components 430. In some embodiments, input component 410 and output component 430 may be implemented by the same group of components (e.g., and the input / output component may be a combination of input component 410 and output component 430).
[0055] Controller 440 includes a processor in the form of, for example, a CPU, GPU, APU, microprocessor, microcontroller, DSP, FPGA, ASIC, and / or another type of processor. The processor is implemented in hardware, firmware, or a combination of hardware and software. In some embodiments, processor 440 may include one or more processors that can be programmed to perform functions.
[0056] In some implementations, controller 440 may include RAM, ROM and / or another type of dynamic or static storage device (e.g., flash memory, magnetic memory and / or optical memory, etc.) to store information and / or instructions for use by controller 440.
[0057] In some implementations, controller 440 can communicate with other devices, networks, and / or systems connected to device 400 to exchange information about the network topology. Controller 440 can create routing tables based on the network topology information, create forwarding tables based on the routing tables, and forward the forwarding tables to input component 410 and / or output component 430. Input component 410 and / or output component 430 can use the forwarding tables to perform route looks for incoming and / or outgoing packets.
[0058] Controller 440 may execute one or more processes described herein. Controller 440 may execute these processes in response to the execution of software instructions stored in a non-transitory computer-readable medium. A computer-readable medium is defined herein as a non-transitory memory device. A memory device includes memory space in a single physical storage device or memory space diffused across multiple physical storage devices.
[0059] Software instructions can be read from another computer-readable medium or from another device via a communication interface into a memory and / or storage component associated with controller 440. When executed, the software instructions stored in the memory and / or storage component associated with controller 440 can cause controller 440 to perform one or more processes described herein. Additionally or alternatively, hard-wired circuitry may be used in place of or in combination with software instructions to perform one or more processes described herein. Therefore, the embodiments described herein are not limited to any particular combination of hardware circuitry and software.
[0060] Figure 4 The number and arrangement of components shown are provided as an example. In fact, with... Figure 4Compared to the components shown, device 400 may also include additional components, fewer components, different components, or components arranged in a different manner. Additionally or alternatively, a set of components of device 400 (e.g., one or more components) may perform one or more functions described as being performed by another set of components of device 400.
[0061] Figure 5 This is a flowchart of an example process 500 associated with delayed quantum key distribution. In some implementations, Figure 5 One or more process frames can be executed by a node (e.g., verification node 220). In some implementations, Figure 5 One or more process frames are executed by another device or a group of devices separate from or including the node, such as a quantum key distribution device (e.g., QKD device 210) and / or one or more other nodes (e.g., one or more other verification nodes 220 and / or task nodes 230). Additionally or alternatively, Figure 5 One or more process frames may be executed by: one or more components of device 300, such as processor 320, memory 330, input component 340, output component 350 and / or communication component 360; one or more components of device 400, such as input component 410, switch component 420, output component 430 and / or controller 440; or one or more components of another device.
[0062] like Figure 5 As shown, process 500 may include receiving a first message from a quantum key distribution device, the first message including an identifier associated with a key, wherein the key is associated with a specific time window (box 510). For example, a node may receive the first message from the quantum key distribution device, the first message including an identifier associated with a key. In some implementations, the key is associated with a specific time window.
[0063] like Figure 5 As further shown, process 500 may include sending a second message to another node, the second message including at least one of the following: an identifier associated with a key or a request to perform at least one task (box 520). For example, a node may send a second message to another node, the second message including at least one of the following: an identifier associated with a key or a request to perform at least one task, as described above.
[0064] like Figure 5As further shown, process 500 may include receiving a third message from the other node, the third message including information associated with the other node performing at least one task and information indicating the time when the other node performs at least one task (box 530). For example, a node may receive a third message from the other node, the third message including information associated with the other node performing at least one task and information indicating the time when the other node performs at least one task, as described above.
[0065] like Figure 5 As further shown, process 500 may include receiving a fourth message from the quantum key distribution device, the fourth message including a key and information indicating a specific time window, wherein the fourth message is received after the specific time window has expired (box 540). For example, a node may receive the fourth message from the quantum key distribution device, the fourth message including a key and information indicating a specific time window. In some embodiments, the fourth message is received after the specific time window has expired.
[0066] like Figure 5 As further shown, process 500 may include processing the third message based on the fourth message to determine whether the third message is valid (box 550). For example, a node may process the third message based on the fourth message to determine whether the third message is valid, as described above.
[0067] like Figure 5 As further shown, process 500 may include performing one or more actions based on determining whether a third message is valid (box 560). For example, a node may perform one or more actions based on determining whether a third message is valid, as described above.
[0068] Process 500 may include additional implementations, such as any single implementation or any combination of implementations described below and / or in conjunction with one or more other process descriptions described elsewhere herein.
[0069] In the first embodiment, processing the third message to determine whether the third message is valid includes: processing the third message to identify the time when the other node performs at least one task, processing the fourth message to identify a specific time window, determining that the time when the other node performs at least one task occurs after the specific time window expires, and determining that the third message is invalid based on determining that the time when the other node performs at least one task occurs after the specific time window expires.
[0070] In the second embodiment, processing the third message to determine whether the third message is valid, either alone or in combination with the first embodiment, includes: processing the third message to identify the time when the other node performs at least one task and information associated with the other node performing at least one task; processing the fourth message to identify a specific time window and a key; determining that the time when the other node performs at least one task occurs within the specific time window; using the key to process the information associated with the other node performing at least one task to determine that the other node uses the key to generate the information associated with the other node performing at least one task; and determining that the third message is valid based on determining that the time when the other node performs at least one task occurs within the specific time window and determining that the other node uses the key to generate the information associated with the other node performing at least one task.
[0071] In the third embodiment, processing a third message to determine whether the third message is valid, either alone or in combination with one or more embodiments of the first and second embodiments, includes: processing the third message to identify the time when the other node performs at least one task and information associated with the other node performing at least one task; processing a fourth message to identify a specific time window and a key; determining that the time when the other node performs at least one task occurs within the specific time window; using the key to process the information associated with the other node performing at least one task to determine that the other node does not use the key to generate the information associated with the other node performing at least one task; and determining that the third message is invalid based on determining that the time when the other node performs at least one task occurs within the specific time window and determining that the other node does not use the key to generate the information associated with the other node performing at least one task.
[0072] In the fourth embodiment, alone or in combination with one or more embodiments of the first to third embodiments, the information associated with the other node performing at least one task includes at least one of the following: information generated by the other node in connection with the other node performing at least one task and encrypted by the other node using a key; or a signature generated by the other node in connection with the other node performing at least one task using a key.
[0073] In the fifth embodiment, a second message is sent to the other node, either alone or in combination with one or more embodiments of the first to fourth embodiments, so that the other node obtains a key from another quantum key distribution device.
[0074] In the sixth embodiment, a second message is sent to the other node, either alone or in combination with one or more embodiments of the first to fifth embodiments, so that the other node obtains a key from another quantum key distribution device and generates information associated with the other node performing at least one task based on the key.
[0075] In the seventh embodiment, the third message being determined to be valid and causing one or more actions to be performed, either alone or in combination with one or more embodiments of the first to sixth embodiments, includes: causing the data structure to include at least one entry associated with the other node performing at least one task.
[0076] In the eighth embodiment, the third message being determined to be invalid, alone or in combination with one or more embodiments of the first to seventh embodiments, and causing one or more actions to be performed, includes: causing the data structure to exclude any entries associated with the other node performing at least one task.
[0077] although Figure 5 An example block of process 500 is shown, but in some implementations, it is different from... Figure 5 Compared to the depicted boxes, process 500 includes additional boxes, fewer boxes, different boxes, or boxes arranged in a different manner. Additionally or alternatively, two or more boxes of process 500 can be executed in parallel.
[0078] Figure 6 This is a flowchart of an example process 600 associated with delayed quantum key distribution. In some implementations, Figure 6 One or more process frames are executed by a quantum key distribution device (e.g., QKD device 210). In some implementations, Figure 6 One or more process frames are executed by another device or a group of devices separate from or including the quantum key distribution device, such as one or more nodes (e.g., one or more verification nodes 220 and / or task nodes 230). Additionally or alternatively, Figure 6 One or more process frames may be executed by: one or more components of device 300, such as processor 320, memory 330, input component 340, output component 350 and / or communication component 360; one or more components of device 400, such as input component 410, switch component 420, output component 430 and / or controller 440; and / or one or more components of another device.
[0079] like Figure 6As shown, process 600 may include communicating with another quantum key distribution device to generate a key (box 610). For example, the quantum key distribution device may communicate with another quantum key distribution device to generate a key, as described above.
[0080] like Figure 6 As further shown, process 600 may include determining an identifier associated with the key (box 620). For example, a quantum key distribution device may determine an identifier associated with the key as described above.
[0081] like Figure 6 As further shown, process 600 may include determining a specific time window associated with the key (box 630). For example, a quantum key distribution device may determine a specific time window associated with the key, as described above.
[0082] like Figure 6 As further shown, process 600 may include sending a first message to the node, the first message including an identifier associated with the key, wherein the first message is sent to the node before a specific time window expires (box 640). For example, a quantum key distribution device may send a first message to the node, the first message including an identifier associated with the key, as described above. In some embodiments, the first message is sent to the node before a specific time window expires.
[0083] like Figure 6 As further shown, process 600 may include sending a second message to the node, the second message including a key and information indicating a specific time window, wherein the second message is sent to the node after the specific time window has expired (box 650). For example, a quantum key distribution device may send a second message to the node, the second message including a key and information indicating a specific time window, as described above. In some embodiments, the second message is sent to the node after the specific time window has expired.
[0084] Process 600 may include additional implementations, such as any single implementation or any combination of implementations described below and / or in conjunction with one or more other process descriptions described elsewhere herein.
[0085] In a first embodiment, process 600 includes receiving a third message from a node before sending a first message, the third message including a request for an identifier associated with a key, wherein the first message is sent based on the request included in the third message.
[0086] In the second embodiment, alone or in combination with the first embodiment, process 600 includes sending a first message to one or more other nodes, wherein the first message is sent to one or more other nodes before a specific time window expires.
[0087] In the third embodiment, alone or in combination with one or more embodiments of the first and second embodiments, process 600 includes sending a second message to one or more other nodes, wherein the second message is sent to one or more other nodes after a specific time window has expired.
[0088] In the fourth embodiment, either alone or in combination with one or more embodiments of the first to third embodiments, a first message is sent to a node, causing the node to send a third message to another node, the third message including a request to perform at least one task, and a second message is sent to the node, causing the node to process the fourth message based on the second message to determine whether the fourth message is valid, wherein the fourth message includes information associated with the other node performing at least one task and information indicating the time when the other node performs at least one task.
[0089] although Figure 6 An example block of process 600 is shown, but in some implementations, it is different from... Figure 6 Compared to the depicted boxes, process 600 includes additional boxes, fewer boxes, different boxes, or boxes arranged in a different manner. Alternatively or additionally, two or more boxes of process 600 may be executed in parallel.
[0090] Figure 7 This is a flowchart of an example process 700 associated with delayed quantum key distribution. In some implementations, Figure 7 One or more process frames are executed by a node (e.g., task node 230). In some implementations, Figure 7 One or more process frames are performed by another device or a group of devices separate from or including the node, such as a quantum key distribution device (e.g., QKD device 210) and / or one or more other nodes (e.g., one or more other verification nodes 220). Additionally or alternatively, Figure 7 One or more process frames may be executed by: one or more components of device 300, such as processor 320, memory 330, input component 340, output component 350 and / or communication component 360; one or more components of device 400, such as input component 410, switch component 420, output component 430 and / or controller 440; and / or one or more components of another device.
[0091] like Figure 7As shown, process 700 may include receiving a first message from another node, the first message including an identifier associated with a key and a request to perform at least one task (box 710). For example, a node may receive a first message from another node, the first message including an identifier associated with a key and a request to perform at least one task, as described above.
[0092] like Figure 7 As further shown, process 700 may include sending a second message to the quantum key distribution device, the second message including an identifier associated with the key (box 720). For example, a node may send a second message to the quantum key distribution device, the second message including an identifier associated with the key, as described above.
[0093] like Figure 7 As further shown, process 700 may include receiving a third message from the quantum key distribution device, the third message including a key and information indicating a specific time window associated with the key (box 730). For example, a node may receive a third message from the quantum key distribution device, the third message including a key and information indicating a specific time window associated with the key, as described above.
[0094] like Figure 7 As further shown, process 700 may include performing at least one task based on a request included in the first message (box 740). For example, a node may perform at least one task based on a request included in the first message, as described above.
[0095] like Figure 7 As further shown, process 700 may include determining that the time for a node to perform at least one task falls within a specific time window (box 750). For example, a node may determine that the time for a node to perform at least one task falls within a specific time window, as described above.
[0096] like Figure 7 As further shown, process 700 may include generating information associated with the execution of at least one task based on the execution of at least one task and determining that the time when the node performs at least one task falls within a specific time window, and using a key to generate information associated with the node performing at least one task, as described above.
[0097] like Figure 7As further shown, process 700 may include sending a fourth message to the other node, the fourth message including information associated with the node performing at least one task and information indicating the time for the node to perform at least one task (box 770). For example, a node may send a fourth message to the other node, the fourth message including information associated with the node performing at least one task and information indicating the time for the node to perform at least one task, as described above.
[0098] Process 700 may include additional implementations, such as any single implementation or any combination of implementations described below and / or in conjunction with one or more other process descriptions described elsewhere herein.
[0099] In the first embodiment, a fourth message is sent to the other node, which then uses a key to process the fourth message to determine whether the fourth message is valid, wherein the key is received by the other node from another quantum key distribution device after a specific time window has expired.
[0100] In a second implementation, generating information associated with a node performing at least one task, either alone or in combination with the first implementation, includes: generating data based on the performance of at least one task, and encrypting the data using a key, wherein the encrypted data is information associated with the node performing at least one task.
[0101] In the third embodiment, generating information associated with a node performing at least one task, either alone or in combination with one or more embodiments of the first and second embodiments, includes: generating data based on the performance of at least one task, and generating a signature using a key and based on the data, wherein the data and the signature are information associated with the node performing at least one task.
[0102] In the fourth embodiment, alone or in combination with one or more embodiments of the first to third embodiments, process 700 includes sending a fourth message to one or more additional nodes.
[0103] In the fifth embodiment, either alone or in combination with one or more embodiments from the first to the fourth embodiments, a fourth message is sent to one or more additional nodes, each of the one or more additional nodes using a key to process the fourth message to determine whether the fourth message is valid, wherein the key will be received by one or more additional nodes from another quantum key distribution device after a specific time window expires.
[0104] although Figure 7 An example block of process 700 is shown, but in some implementations, it is different from... Figure 7Compared to the depicted boxes, process 700 includes additional boxes, fewer boxes, different boxes, or boxes arranged in a different manner. Additionally or alternatively, two or more boxes of process 700 can be executed in parallel.
[0105] The foregoing disclosure provides illustrations and descriptions, but is not intended to be exhaustive or to limit the embodiments to the precise forms disclosed. Modifications and variations can be made based on the foregoing disclosure or can be obtained from the practice of the embodiments.
[0106] As used herein, the term "component" is intended to be broadly interpreted as hardware, firmware, or a combination of hardware and software. It is clear that the systems and / or methods described herein can be implemented in various forms of hardware, firmware, or combinations of hardware and software. The actual dedicated control hardware or software code used to implement these systems and / or methods is not limited to any particular implementation. Therefore, the operation and behavior of the systems and / or methods are described herein without reference to specific software code—it should be understood that software and hardware can be used to implement the systems and / or methods based on the descriptions herein.
[0107] Although specific combinations of features are described in the claims and / or disclosed in the specification, these combinations are not intended to limit the disclosure of the various embodiments. In fact, many of these features can be combined in ways not specifically described in the claims and / or disclosed in the specification. While each dependent claim listed below can only directly depend on one claim, the disclosure of the various embodiments includes each dependent claim in combination with each other claim in the group of claims. As used herein, the phrase “at least one of” in the list of items refers to any combination of these items, including individual elements. As an example, “at least one of a, b, or c” is intended to cover a, b, c, ab, ac, bc, and abc, as well as any combination having multiple identical items.
[0108] Elements, actions, or instructions used herein should not be considered essential or indispensable unless explicitly stated otherwise. Similarly, as used herein, the articles “a” and “one” are intended to include one or more items and may be used interchangeably with “one or more.” Furthermore, as used herein, the article “the” is intended to include one or more items referenced in combination with the article “the” and may be used interchangeably with “one or more.” Additionally, as used herein, the term “set” is intended to include one or more items (e.g., related items, irrelevant items, or a combination of related and irrelevant items) and may be used interchangeably with “one or more.” In cases referring to only one item, the phrase “only one” or similar language is used. Similarly, as used herein, the terms “have,” “possess,” “with,” etc., are intended to be open-ended terms. Further, the phrase “based on” is intended to mean “at least partially based on” unless explicitly stated otherwise. Likewise, as used herein, the term “or” when used in a series is intended to be inclusive and may be used interchangeably with “and / or” unless explicitly stated otherwise (e.g., if used in combination with “any one” or “only one”).
Claims
1. A method for quantum key distribution, comprising: A node receives a first message from one of a pair of quantum key distribution devices, the first message including an identifier associated with the key. The key is associated with a specific time window; The node sends a second message to another node, the second message including at least one of the following: the identifier associated with the key, and a request to perform at least one task; The second message is sent to the other node so that the other node obtains the key from the other quantum key distribution device in the pair of quantum key distribution devices; The node receives a third message from the other node, the third message including information associated with the other node performing the at least one task and information indicating the time when the other node performs the at least one task; The node receives a fourth message from the quantum key distribution device, the fourth message including the key and information indicating the specific time window; The fourth message is received after the specific time window has expired; The node processes the third message based on the fourth message by identifying the time when the other node performed the at least one task to determine whether the third message is valid; as well as The node determines whether the third message is valid to cause one or more actions to be executed by the other node.
2. The method of claim 1, wherein processing the third message to determine whether the third message is valid comprises: Process the fourth message to identify the specific time window; The time at which the other node performs the at least one task occurs after the specific time window has expired; as well as The third message is determined to be invalid based on the fact that the time at which the other node performs the at least one task occurs after the specific time window has expired.
3. The method of claim 1, wherein processing the third message to determine whether the third message is valid comprises: The third message is processed to identify the information associated with the execution of the at least one task by the other node; Process the fourth message to identify the specific time window and the key; The time at which the other node performs the at least one task occurs after the specific time window has expired; The key is used to process the information associated with the execution of the at least one task by the other node, to determine that the other node uses the key to generate the information associated with the execution of the at least one task by the other node; as well as The third message is determined to be valid based on the determination that the time when the other node performs the at least one task occurs within the specific time window and the determination that the other node uses the key to generate the information associated with the execution of the at least one task by the other node.
4. The method of claim 1, wherein processing the third message to determine whether the third message is valid comprises: The third message is processed to identify the information associated with the execution of the at least one task by the other node; Process the fourth message to identify the specific time window and the key; The time at which the other node performs the at least one task occurs after the specific time window has expired; The key is used to process the information associated with the execution of the at least one task by the other node, to determine that the other node does not use the key to generate the information associated with the execution of the at least one task by the other node; as well as Based on the determination that the time when the other node performs the at least one task occurs within the specific time window and the determination that the other node does not use the key to generate the information associated with the execution of the at least one task by the other node, the third message is determined to be invalid.
5. The method of claim 1, wherein the information associated with the execution of the at least one task by the other node includes at least one of the following: The information is generated by the other node in association with the execution of the at least one task by the other node and encrypted by the other node using the key; or The signature is generated by the other node using the key in association with the execution of the at least one task by the other node.
6. The method of claim 1, wherein the third message is determined to be valid, and The execution of the one or more actions includes: Enable another node to communicate with one or more other nodes and the node to determine that at least a portion of the one or more other nodes and the node has determined that the message from the task node is valid.
7. The method of claim 1, wherein sending the second message to the other node causes the other node to: Based on the key, information associated with the execution of the at least one task by the other node is generated.
8. The method of claim 1, wherein the third message is determined to be valid, and The execution of the one or more actions includes: The data structure includes at least one entry associated with the execution of the at least one task by the other node.
9. The method of claim 1, wherein the third message is determined to be invalid, and The execution of the one or more actions includes: The data structure is made to exclude any entries associated with the execution of the at least one task by the other node.
10. A non-transitory computer-readable medium storing an instruction set, the instruction set comprising: One or more instructions, when executed by one or more processors of a quantum key distribution device, cause the quantum key distribution devices in a pair of quantum key distribution devices to: Communicating with the other quantum key distribution device in the pair of quantum key distribution devices to generate a key; Determine the identifier associated with the key; Determine a specific time window associated with the key; A first message is sent to the node, the first message including the identifier associated with the key. The first message is sent to the node before the specific time window expires; and A second message is sent to the node, the second message including the key and information indicating the specific time window. The second message is sent to the node after the specific time window has expired.
11. The non-transitory computer-readable medium of claim 10, wherein the one or more instructions, when executed by the one or more processors, further cause the key distribution device to: Before sending the first message, a third message is received from the node, the third message including a request for the identifier associated with the key. The first message is sent based on the request included in the third message.
12. The non-transitory computer-readable medium of claim 10, wherein the one or more instructions, when executed by the one or more processors, further cause the key distribution device to: Send the first message to one or more other nodes. The first message is sent to the one or more other nodes before the specific time window expires.
13. The non-transitory computer-readable medium of claim 10, wherein the one or more instructions, when executed by the one or more processors, further cause the key distribution device to: Send the second message to one or more other nodes. The second message is sent to the one or more other nodes after the specific time window has expired.
14. The non-transitory computer-readable medium according to claim 10, wherein: The first message is sent to the node, causing the node to send a third message to another node, the third message including a request to perform at least one task; as well as The second message is sent to the node, causing the node to process the fourth message based on the second message to determine whether the fourth message is valid. The fourth message includes information associated with the execution of the at least one task by the other node and information indicating the time when the at least one task is executed by the other node.
15. A node, comprising: One or more memory units; as well as One or more processors, used to: Receive a first message from another node, the first message including an identifier associated with a key and a request to perform at least one task; A second message is sent to the key distribution device in a pair of quantum key distribution devices, the second message including the identifier associated with the key; Receive a third message from the key distribution device, the third message including the key and information indicating a specific time window associated with the key; Based on the request included in the first message, perform the at least one task; The time for the node to perform the at least one task is determined to be within the specific time window; Based on the execution of the at least one task and the determination of the time when the node executes the at least one task within the specific time window, and by using the key, information associated with the execution of the at least one task by the node is generated; as well as A fourth message is sent to the other node, the fourth message including the information associated with the node performing the at least one task and information indicating the time when the node performs the at least one task.
16. The node of claim 15, wherein the one or more processors, when sending the fourth message to the other node, cause the other node to use the key to process the fourth message to determine whether the fourth message is valid. The key will be received by the other node from another key distribution device after the specific time window expires.
17. The node of claim 15, wherein the one or more processors, when generating the information associated with the execution of the at least one task by the node, use to: Data is generated based on the execution of at least one of the tasks; and Use the key to encrypt the data. The encrypted data is information associated with the execution of the at least one task by the node.
18. The node of claim 15, wherein the one or more processors, when generating the information associated with the execution of the at least one task by the node: Data is generated based on the execution of at least one of the tasks; and A signature is generated using the key and based on the data. The data and the signature are the information associated with the execution of the at least one task by the node.
19. The node of claim 15, wherein the one or more processors further: The fourth message is sent to one or more additional nodes.
20. The node of claim 19, wherein when the one or more processors send the fourth message to the one or more additional nodes, each of the one or more additional nodes uses the key to process the fourth message to determine whether the fourth message is valid. The key will be received by the one or more additional nodes from another quantum key distribution device after the specific time window expires.
Citation Information
Patent Citations
Encrypted data communication method and device, equipment and medium
CN112131564A
Communication systems and methods
US20210083864A1