Utilizing removable quantum random number generators for network devices
Patent Information
- Application Number
- CN202210711001.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-05-09
- Filing Date
- 2022-06-22
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2042-06-22
Smart Images

Figure CN117081766B_ABST
Abstract
Description
Background Technology
[0001] Cybersecurity is the process of taking physical and software precautions to protect network infrastructure from unauthorized access, misuse, malfunction, modification, damage, inappropriate disclosure, and other threats. Cybersecurity creates a secure platform infrastructure for computing devices, users, software programs, and other components to perform functions within a secure environment. Summary of the Invention
[0002] Some implementations described herein relate to a method. This method may include generating one or more packets with random payloads by a removable quantum random number generator (QRNG) of a network device, and providing one or more packets with random payloads to the network device by the removable QRNG. The method may also include having the component forward one or more packets with random payloads to a destination address.
[0003] Some implementations described herein relate to a network device. The network device may include a removable QRNG, one or more memories, and one or more processors. One or more processors may be configured to generate one or more packets with random payloads by the removable QRNG, and to provide these packets to components of the network device. One or more processors may be configured to have components forward the one or more packets with random payloads to their destination address.
[0004] Some implementations described herein involve storing a non-transitory computer-readable medium for an instruction set used by a network device. When executed by one or more processors of the network device, the instruction set enables the network device to generate one or more packets with random payloads via a removable QRNG, and the removable QRNG to provide the one or more packets with random payloads to components of the network device. When executed by one or more processors of the network device, the instruction set enables the network device to authenticate the random payloads of the one or more packets, and components to forward the one or more packets with random payloads to their destination addresses. Attached Figure Description
[0005] Figures 1A-1F This is an illustration of an example associated with using a removable QRNG for network devices.
[0006] Figure 2 This is a diagram of an example environment in which the systems and / or methods described herein can be implemented.
[0007] Figure 3 and Figure 4 yes Figure 2 An illustration of example components of one or more devices.
[0008] Figure 5 This is a flowchart of an example process for utilizing a removable QRNG for use in network devices. Detailed Implementation
[0009] The following example implementation is described in detail with reference to the accompanying drawings. The same reference numerals in different drawings may identify the same or similar elements.
[0010] Superior network and data security can be provided by leveraging sources of randomness (or cryptographic entropy). Cryptographic systems can use entropy sources to generate cryptographic material (e.g., as keys, during certificate generation, for key derivation, or as part of encryption or decryption algorithms). Partial effectiveness of a cryptographic system can be determined based on the strength of the entropy it utilizes (e.g., unpredictability, independence, consistency of statistical distribution, etc.). The greater the entropy, the stronger the cryptographic system. One possible component of a cryptographic system is a QRNG. QRNGs can utilize the random properties of quantum physics to generate true entropy sources, thereby improving the quality of the generated cryptographic material and thus improving the overall cryptographic system.
[0011] Network devices may require one or more QRNGs to enhance network entropy. In one example, a QRNG can be attached to the network device's main printed circuit board (PCB) and can generate entropy for the network device. However, attaching a QRNG to the network device's main PCB is expensive, and each user of the network device may not utilize the QRNG. In another example, the QRNG can be equipped with a Peripheral Component Fast Interconnect (PCIe) board that can be used with the network device. However, PCIe boards are not suitable for field insertion in security-related platforms. In yet another example, an entropy source (e.g., an entropy beacon equipped with an internal QRNG) can provide entropy traffic to network devices that require this entropy. However, the entropy source creates a constant traffic load on the network device and requires maintenance associated with the on-board and / or off-board network devices for receiving entropy traffic.
[0012] Therefore, current technologies for providing entropy to network devices consume computing resources (e.g., processing resources, memory resources, communication resources, etc.), networking resources, etc., which are associated with installing QRNGs on the PCB of network devices, inserting PCIe boards with QRNGs into network devices in the field, increasing the service load on network devices due to providing entropy services, handling the reduction in network bandwidth associated with increasing service load on the network, and handling the maintenance of network devices used to receive entropy services.
[0013] Some implementations described in this paper involve network devices that utilize removable QRNGs to generate entropy network traffic flows. For example, a network device's removable QRNG can generate one or more packets with random payloads, and these packets can be provided to components of the network device. Components of the network device can authenticate the random payloads of the one or more packets and can then forward these packets to their destination addresses.
[0014] In this way, network devices utilize removable QRNGs to generate entropy network traffic flows. For example, a network device may include a removable QRNG that generates packets with random number payloads (e.g., and is wrapped in a higher-level networking protocol such as IP, MPLS, Virtual LAN (VLAN), etc.). Each packet in the IP / MPLS packet may include an Ethernet header, an Ethernet address, a random payload, a timestamp indicating the validity of the random payload, a cryptographic signature, etc. The removable QRNG can provide IP / MPLS packets to the packet forwarding component and / or routing component (RE) of the network device. Compared to current QRNG implementations designed to interface with microprocessors rather than networks or network devices, the removable QRNG can interface with network devices. The removable QRNG makes entropy networkable, and since the routing component of the network device can terminate IP traffic, the consumption of the entropy generated by the removable QRNG is direct. Therefore, network devices save computing resources, networking resources, etc., which would otherwise be consumed by installing QRNGs on the PCB of network devices, inserting PCIe boards with QRNGs into network devices in the field, increasing the service load on network devices due to providing entropy services, handling the reduction of network bandwidth associated with increasing service load on the network, and handling the maintenance of network devices used to receive entropy services.
[0015] Figures 1A-1F This is an illustration of example 100 associated with utilizing a removable QRNG for use in network devices. (See example 100.) Figures 1A-1F As shown, Example 100 includes one or more endpoint devices and a network with multiple network devices. Further details about endpoint devices, networks, and network devices are provided elsewhere in this document.
[0016] like Figure 1A As shown, and by reference numeral 105, an endpoint device can communicate with another endpoint device via a network having multiple network devices. For example, an endpoint device can communicate with another endpoint device continuously, can communicate with another endpoint device periodically, can communicate with another endpoint device based on a request for communication from another endpoint device, and so on.
[0017] like Figure 1AAs further illustrated, network devices may include removable QRNGs, packet forwarding components, and routing components. A removable QRNG may include a QRNG chip and a packetization module (e.g., a field-programmable gate array (FPGA)) that randomly and continuously generates keys that can be used as entropy sources. The packetization module can use the keys along with packets to generate entropy traffic and can provide the entropy traffic to the packet forwarding component and / or the routing component. The QRNG chip of the removable QRNG can generate streaming of constant random numbers, and the packetization module can generate valid IP / MPLS / Ethernet packets with random payloads. Endpoint devices can receive entropy traffic generated by the removable QRNG. The removable QRNG can utilize the random properties of quantum physics to generate true entropy sources and improve the quality of the generated keys. The removable QRNG can also generate random numbers for certificate generation, key derivation, etc. Removable QRNGs can be removably installed in network devices via pluggable form factors such as Small Form Factor Pluggable (SFP+), Quad Small Form Factor Pluggable (QSFP), QSFP Dual Density (DD) modules, etc.
[0018] A packet forwarding component may include one or more processors (e.g., application-specific integrated circuits (ASICs)) that perform Layer 2 and Layer 3 packet switching, route lookup, packet forwarding, etc. The packet forwarding component can forward packets between the input and output interfaces of a network device.
[0019] The routing component controls route updates and system management associated with network devices. It may include routing protocol software processes executing within a protected memory environment on a general-purpose computer platform. The routing component manages routing protocol processes and other software processes that control the network device's interface, some of the network device's chassis components, the network device's system management, and user access to the network device. These software processes can execute on top of the kernel that interfaces with the packet forwarding component. Routing protocol packets from the network can be directed to the routing component without unnecessarily delaying the packet forwarding component. The routing component can utilize a set of Internet Protocol (IP) features to implement each routing protocol and provides complete flexibility for advertising, filtering, and modifying routes. The routing component can set migration policies based on routing parameters such as prefix, prefix length, and Border Gateway Protocol (BGP) attributes. The routing component can build and maintain one or more routing tables. From the routing tables, the routing component can derive an active routing table called a forwarding table, which can be copied to the packet forwarding component. The forwarding table in the packet forwarding component can be updated without interrupting the forwarding of network devices.
[0020] like Figure 1BAs shown, and via reference numeral 110, a removable QRNG of a network device can generate packets with random payloads and can provide these packets to the packet forwarding and / or routing components of the network device. For example, a removable QRNG can continuously generate valid Ethernet or IP / Multiprotocol Label Switching (MPLS) packets with random payloads. In some implementations, each packet may include an Ethernet header, an Ethernet address, a payload of random numbers generated by the QRNG (e.g., of a specific length in bits), a timestamp indicating the validity time of the payload, etc. In some implementations, the removable QRNG can generate packets at a configured entropy generation rate and with a specific packet size. In some implementations, the removable QRNG may include a clock or be able to receive a clock input (e.g., from the packet forwarding and / or routing components), enabling the QRNG to generate bursts (e.g., bursts) of packets with random payloads at defined times, rather than continuously generating a stream of stable packets. In some implementations, the QRNG can be configured to create greater randomness when greater entropy is required.
[0021] Several source and / or destination addresses or label stacks (MPLS) can be programmed into a QRNG, allowing network devices to act as entropy servers for other network devices by generating different entropy streams (e.g., packet-based) and routing these streams to destination addresses. In some implementations, each packet may include a unicast address, a multicast address, a broadcast address, and so on. In some implementations, the QRNG may encrypt random payloads using IP security (IPsec), Media Access Control security (MACsec), Transport Layer Security (TLS), etc. (e.g., to prevent eavesdropping attempts). The QRNG may include a trusted platform module (e.g., instead of encryption or in addition to encryption) that prevents malicious devices from impersonating the QRNG. The QRNG can analyze the quality of the entropy generated by the packets and can notify network devices of entropy that fails to meet quality thresholds. In some implementations, the QRNG can be removed from its role as a service generator for load testing of hardware components of network devices and / or other network devices.
[0022] A removable QRNG may include a communication interface for communicating with packet forwarding and / or routing components. The removable QRNG can utilize this communication interface to provide packets to the packet forwarding and / or routing components of a network device. The packet forwarding and / or routing components can receive packets from the removable QRNG and can store the packets in data structures (e.g., databases, tables, lists, etc.). In some implementations, the packet forwarding component can forward packets destined for the routing component to the routing component. However, for management purposes (e.g., for fault, configuration, accounting, performance, and security (FCAPS) purposes), the network device's controller may include a control interface to the removable QRNG, which may be relayed by the packet forwarding component.
[0023] like Figure 1C As shown, and via reference numeral 115, a network device can authenticate the random payload of a packet to generate an authenticated packet (e.g., entropy service). For example, the network device may include a hardware security module (e.g., provided on the network device's printed circuit board (PCB)) that authenticates the random payload of packets generated by a removable QRNG. The hardware security module can protect and manage digital keys, perform encryption and decryption functions for digital signatures, and provide strong authentication and other cryptographic functions. The hardware security module can analyze the entropy level of the packet's random payload, and when the analysis indicates that the random payload includes a sufficient entropy level, the hardware security module can authenticate the packet's random payload. Since the packet is provided to packet forwarding components and / or routing components, all the capabilities of the packet forwarding components and / or routing components can be utilized to regulate the packet. For example, the packet forwarding component can rate-limit, inspect, and / or route packets as needed.
[0024] like Figure 1D As shown, and via reference numeral 120, the packet forwarding and / or routing components of a network device can forward packets with random payloads to a destination address. For example, the packet forwarding and / or routing components can forward packets with random payloads to a destination address associated with an endpoint device. The packet forwarding and / or routing components can include the destination address in the packet with random payload and can provide the packet with random payload to one or more other network devices in the network. Other network devices can forward packets with random payloads to the destination address (e.g., the endpoint device) based on the configured or included destination address. The endpoint device associated with the destination address can receive the packet with random payload.
[0025] like Figure 1EAs shown, and via reference numeral 125, the packet forwarding and / or routing components of a network device can provide packets with random payloads to other network devices via encryption. For example, several source and / or destination addresses or label stacks (MPLS) can be programmed into a QRNG, allowing the network device to act as an entropy server for other network devices by generating different entropy streams (e.g., packet-wise) and routing these streams to destination addresses. In some implementations, the destination address can be associated with other network devices that require entropy, and the network device's packet forwarding and / or routing components can provide packets with random payloads to other network devices based on the destination address. In some implementations, the packets with random payloads can be encrypted by a QRNG or encapsulated in an encrypted tunnel by a removable QRNG or packet forwarding component before being provided to other network devices.
[0026] like Figure 1F As shown, and via reference numeral 130, the packet forwarding and / or routing components of a network device can provide packets with random payloads to other network devices for testing purposes. For example, a removable QRNG can be used as a service generator that utilizes packets with random payloads as test services. The packet forwarding and / or routing components of the network device can provide packets with random payloads as test services to other network devices, allowing these devices to utilize them for testing purposes.
[0027] In this way, network devices utilize removable QRNGs to generate entropy network traffic flows. For example, a network device may include a removable QRNG that generates Ethernet or IP / MPLS packets with random number payloads. Each packet in the IP / MPLS packet may include an Ethernet header, an Ethernet address, a random payload, a timestamp indicating the validity of the random payload, etc. The removable QRNG can provide IP / MPLS packets to the network device's packet forwarding and / or routing components (REs). Compared to current QRNG implementations designed to interface with microprocessors rather than networks or network devices, removable QRNGs can interface with network devices. Removable QRNGs enable entropy to become networkable, and since the routing components of a network device can terminate IP traffic, the consumption of entropy generated by the removable QRNG is direct. Therefore, network devices save computing resources and network resources that would otherwise be consumed by installing QRNGs on the network device's PCB, inserting PCIe boards with QRNGs into network devices in the field, increasing the service load on the network device due to providing entropy services, handling the reduction in network bandwidth associated with increasing service load on the network, and handling the maintenance of network devices used to receive entropy services.
[0028] As mentioned above, providing Figures 1A-1F As an example. Other examples may differ from the reference. Figures 1A-1F As described. Figures 1A-1F The number and arrangement of the equipment shown are provided as an example. In fact, with... Figures 1A-1F Compared to those shown, there may be additional equipment, fewer devices, different equipment, or devices arranged differently. Furthermore, Figures 1A-1F The two or more devices shown can be implemented within a single device, or Figures 1A-1F The single device shown can be implemented as multiple distributed devices. Additionally or alternatively, Figures 1A-1F The set of devices shown (e.g., one or more devices) can perform actions described as being performed by Figures 1A-1F The other set of devices shown performs one or more functions.
[0029] Figure 2 This is a diagram of an example environment 200 in which the systems and / or methods described herein can be implemented. (See diagram for example.) Figure 2 As shown, environment 200 may include endpoint device 210, a group of network devices 220 (shown as network devices 220-1 to network devices 220-N), and network 230. The devices in environment 200 may be interconnected via wired connections, wireless connections, or a combination of wired and wireless connections.
[0030] Endpoint device 210 includes one or more devices capable of receiving, generating, storing, processing, and / or providing information (such as the information described herein). For example, endpoint device 210 may include mobile phones (e.g., smartphones or cordless phones), set-top boxes, laptop computers, tablet computers, desktop computers, handheld computers, gaming devices, wearable communication devices (e.g., smartwatches, smart glasses, heart rate monitors, fitness trackers, smart clothing, smart jewelry, or head-mounted displays), network devices (e.g., routers, residential gateways, etc.), or similar types of devices. In some implementations, endpoint device 210 may receive network traffic from other endpoint devices 210 and / or provide network traffic to other endpoint devices 210 via network 230 (e.g., by using network device 220 as an intermediate route for packets).
[0031] Network device 220 includes one or more devices capable of receiving, processing, storing, routing, and / or providing services (e.g., packets or other information or metadata) in the manner described herein. For example, network device 220 may include routers such as label switching routers (LSRs), label edge routers (LERs), ingress routers, egress routers, provider routers (e.g., provider edge routers or provider core routers), virtual routers, route reflectors, area border routers, or other types of routers. Additionally or alternatively, network device 220 may include gateways, switches, firewalls, hubs, bridges, reverse proxies, servers (e.g., proxy servers, cloud servers, or data center servers), load balancers, and / or similar devices. In some implementations, network device 220 may be a physical device implemented within a enclosure, such as a chassis. In some implementations, network device 220 may be a virtual device implemented by one or more computer devices in a cloud computing environment or data center. In some implementations, a group of network devices 220 may be a group of data center nodes used to route service flows through network 230.
[0032] Network 240 includes one or more wired and / or wireless networks. For example, network 240 may include packet-switched networks, cellular networks (e.g., fifth-generation (5G) networks, fourth-generation (4G) networks, such as Long Term Evolution (LTE) networks, third-generation (3G) networks, Code Division Multiple Access (CDMA) networks, Public Land Mobile Networks (PLMN), Local Area Networks (LAN), Wide Area Networks (WAN), Metropolitan Area Networks (MAN), telephone networks (e.g., Public Switched Telephone Network (PSTN)), private networks, self-organizing networks, intranets, the Internet, fiber-optic-based networks, cloud computing networks, etc., and / or combinations of these or other types of networks.
[0033] Figure 2 The number and arrangement of devices and networks shown are provided as examples. In reality, with... Figure 2 Compared to those shown, there may be additional equipment and / or networks, fewer equipment and / or networks, different equipment and / or networks, or equipment and / or networks with different arrangements. Furthermore, Figure 2 The two or more devices shown can be implemented within a single device, or Figure 2 The single device shown can be implemented as multiple distributed devices. Additionally or alternatively, the set of devices in environment 200 (e.g., one or more devices) can perform one or more functions described as being performed by another set of devices in environment 200.
[0034] Figure 3 yes Figure 2An illustration of example components of one or more devices. Example components may be included in device 300, which may correspond to endpoint device 210 and / or network device 220. In some implementations, endpoint device 210 and / or network device 220 may include one or more devices 300 and / or one or more components of device 300. Figure 3 As shown, device 300 may include bus 310, processor 320, memory 330, input component 340, output component 350 and communication interface 360.
[0035] Bus 310 includes one or more components that enable wired and / or wireless communication between components of device 300. Bus 310 can connect components such as via operative coupling, communicative coupling, electronic coupling, and / or electrical coupling. Figure 3 Two or more components are coupled together. Processor 320 includes a central processing unit, a graphics processing unit, a microprocessor, a controller, a microcontroller, a digital signal processor, a field-programmable gate array, an application-specific integrated circuit, and / or another type of processing component. Processor 320 is implemented in hardware, firmware, or a combination of hardware and software. In some implementations, processor 320 includes one or more processors capable of being programmed to perform one or more operations or processes described elsewhere herein.
[0036] Memory 330 includes volatile and / or non-volatile memory. For example, memory 330 may include random access memory (RAM), read-only memory (ROM), hard disk drive, and / or another type of memory (e.g., flash memory, magnetic storage, and / or optical storage). Memory 330 may include internal memory (e.g., RAM, ROM, or hard disk drive) and / or removable memory (e.g., removable via a universal serial bus). Memory 330 may be a non-transient computer-readable medium. Memory 330 stores information, instructions, and / or software (e.g., one or more software applications) related to the operation of device 300. In some implementations, memory 330 includes one or more memories, such as those coupled to one or more processors (e.g., processor 320) via bus 310.
[0037] Input component 340 enables device 300 to receive input, such as user input and / or sensed input. For example, input component 340 may include a touchscreen, keyboard, keypad, mouse, button, microphone, switch, sensor, GPS sensor, accelerometer, gyroscope, actuator, removable QRNG, etc. Output component 350 enables device 300 to provide output, such as via a display, speaker, and / or light-emitting diode. Communication interface 360 enables device 300 to communicate with other devices via wired and / or wireless connections. For example, communication interface 360 may include a receiver, transmitter, transceiver, modem, network interface card, and / or antenna.
[0038] Device 300 can perform one or more of the operations or procedures described herein. For example, a non-transient computer-readable medium (e.g., memory 330) can store a set of instructions (e.g., one or more instructions or code) for execution by processor 320. Processor 320 can execute the set of instructions to perform one or more of the operations or procedures described herein. In some implementations, execution of the set of instructions by one or more processors 320 causes one or more processors 320 and / or device 300 to perform one or more of the operations or procedures described herein. In some implementations, hardwired circuitry may be used in place of or in combination with instructions to perform one or more of the operations or procedures described herein. Additionally or alternatively, processor 320 may be configured to perform one or more of the operations or procedures described herein. Therefore, the implementations described herein are not limited to any particular combination of hardware circuitry and software.
[0039] Figure 3 The number and arrangement of components shown are provided as an example. Figure 3 Compared to those shown, device 300 may include additional components, fewer components, different components, or components arranged differently. Additionally or alternatively, the set of components of device 300 (e.g., one or more components) may perform one or more functions described as being performed by another set of components of device 300.
[0040] Figure 4 yes Figure 2 An illustration of example components of one or more devices. Example components may be included in device 400. Device 400 may correspond to network device 220. In some implementations, network device 220 may include one or more devices 400 and / or one or more components of device 400. Figure 4As shown, device 400 may include one or more input components 410-1 to 410-B (B≥1) (hereinafter collectively referred to as input components 410, and individually referred to as input components 410), switching component 420, one or more output components 430-1 to 430-C (C≥1) (hereinafter collectively referred to as output components 430, and individually referred to as output components 430), and controller 440.
[0041] Input component 410 may be one or more attachment points for a physical link and may be one or more entry points for incoming traffic such as packets. Input component 410 may process incoming traffic, such as by performing data link layer encapsulation or decapsulation. In some implementations, input component 410 may send and / or receive packets. In some implementations, input component 410 may include an input line card that includes one or more packet processing components (e.g., in the form of an integrated circuit), such as one or more interface cards (IFCs), packet forwarding components, line card controller components, input ports, processors, memory, and / or input queues. In some implementations, device 400 may include one or more input components 410.
[0042] Switching component 420 interconnects input component 410 with output component 430. In some implementations, switching component 420 may be implemented via one or more crossbar switches, via a bus, and / or using shared memory. Shared memory may be used as a temporary buffer to store packets from input component 410 before they are eventually scheduled to be delivered to output component 430. In some implementations, switching component 420 enables input component 410, output component 430, and / or controller 440 to communicate with each other.
[0043] Output component 430 can store packets and schedule packets for transmission on the output physical link. Output component 430 can support data link layer encapsulation or decapsulation, and / or various higher-level protocols. In some implementations, output component 430 can send and / or receive packets. In some implementations, output component 430 may include an output line card that includes one or more packet processing components (e.g., in the form of integrated circuits), such as one or more IFCs, packet forwarding components, line card controller components, output ports, processors, memory, and / or output queues. In some implementations, device 400 may include one or more output components 430. In some implementations, input component 410 and output component 430 may be implemented from the same set of components (e.g., the input / output component may be a combination of input component 410 and output component 430).
[0044] Controller 440 includes processors in the form of, for example, CPUs, GPUs, APUs, microprocessors, microcontrollers, DSPs, FPGAs, ASICs, and / or other types of processors. The processor is implemented in hardware, firmware, or a combination of hardware and software. In some implementations, controller 440 may include one or more processors that can be programmed to perform functions.
[0045] In some implementations, controller 440 may include RAM, ROM, and / or another type of dynamic or static storage device (e.g., flash memory, magnetic storage, optical storage, etc.). It stores information and / or instructions used by controller 440.
[0046] In some implementations, controller 440 can communicate with other devices, networks, and / or systems connected to device 400 to exchange information about the network topology. Controller 440 can create a routing table based on the network topology information, create a forwarding table based on the routing table, and forward the forwarding table to input component 410 and / or output component 430. Input component 410 and / or output component 430 can use the forwarding table to perform route looks for incoming and / or outgoing packets.
[0047] Controller 440 may execute one or more of the processes described herein. Controller 440 may execute these processes in response to the execution of software instructions stored on a non-transitory computer-readable medium. A computer-readable medium is defined herein as a non-transitory storage device. A memory device includes memory space within a single physical storage device or memory space distributed across multiple physical storage devices.
[0048] Software instructions may be read from another computer-readable medium or from another device via a communication interface into the memory and / or storage components associated with controller 440. When executed, the software instructions stored in the memory and / or storage components associated with controller 440 may cause controller 440 to perform one or more processes described herein. Additionally or alternatively, hardwired circuitry may be used in place of or in combination with the software instructions to perform one or more processes described herein. Therefore, the implementation described herein is not limited to any particular combination of hardware circuitry and software.
[0049] Figure 4 The number and arrangement of components shown are provided as an example. In reality, with... Figure 4 Compared to those shown, device 400 may include additional components, fewer components, different components, or components arranged differently. Additionally or alternatively, the set of components of device 400 (e.g., one or more components) may perform one or more functions described as being performed by another set of components of device 400.
[0050] Figure 5This is a flowchart of example procedure 500 for using a removable QRNG on a network device. In some implementations, Figure 5 One or more processing blocks can be executed by a network device (e.g., network device 220). In some implementations, Figure 5 One or more processing blocks can be performed by another device or a group of devices, either separate from or including the network device, such as an endpoint device (e.g., endpoint device 210). Additionally or alternatively, Figure 5 One or more processing blocks can be executed by one or more components of device 300, such as processor 320, memory 330, input component 340, output component 350, and / or communication interface 360. Additionally or alternatively, Figure 5 One or more processing blocks can be executed by one or more components of the device 400, such as input component 410, switching component 420, output component 430 and / or controller 440.
[0051] like Figure 5 As shown, process 500 may include generating one or more packets with random payloads by a removable QRNG of a network device (box 510). For example, a network device may generate one or more packets with random payloads by a removable QRNG of the network device, as described above. In some implementations, each of the one or more packets includes one or more of the following: an Ethernet header, an Ethernet address, a payload of a random number generated by the removable QRNG, or a timestamp indicating the validity period of the payload. In some implementations, each of the one or more packets is an IP packet or an MPLS packet. In some implementations, generating one or more packets with random payloads includes generating one or more packets with random payloads at a stable rate or at a defined time. In some implementations, each of the one or more packets with random payloads includes a unicast address, a multicast address, or a broadcast address. In some implementations, the removable QRNG includes a cryptographic module.
[0052] like Figure 5 As further shown, process 500 may include a component (box 520) that provides one or more packets with random payloads to the network device via a removable QRNG. For example, the network device may provide one or more packets with random payloads to the network device via a removable QRNG, as described above. In some implementations, this component is one of the network device's packet forwarding or routing components.
[0053] like Figure 5As further shown, process 500 may include a component causing one or more packets with random payloads to be forwarded to a destination address (box 530). For example, a network device may cause this component to forward one or more packets with random payloads to a destination address, as described above.
[0054] In some implementations, process 500 includes authenticating the random payload of one or more packets before forwarding them to a destination address. In some implementations, process 500 includes encrypting the one or more packets with random payloads to generate one or more encrypted packets, and providing these encrypted packets to one or more other network devices. In some implementations, process 500 includes having a component of a network device forward the one or more packets with random payloads to one or more other network devices for testing purposes.
[0055] In some implementations, process 500 includes examining one or more packets with random payloads, identifying one or more routes to one or more other network devices based on the examination of the one or more packets, and providing the one or more packets with random payloads to the one or more other network devices via the one or more routes. In some implementations, process 500 includes determining the rate at which the one or more packets with random payloads are provided to the one or more other network devices, and providing the one or more packets with random payloads to the one or more other network devices based on the rate. In some implementations, process 500 includes determining the entropy quality associated with the one or more packets, and generating a notification indicating the entropy quality associated with the one or more packets.
[0056] although Figure 5 An example box for process 500 is shown, but in some implementations, it differs from... Figure 5 Compared to those described herein, process 500 may include additional boxes, fewer boxes, different boxes, or boxes arranged differently. Additionally or alternatively, two or more boxes of process 500 may be executed in parallel.
[0057] The foregoing disclosure provides illustrations and descriptions, but is not intended to be exhaustive or to limit implementation to the precise form disclosed. Modifications can be made based on the foregoing disclosure, or modifications can be derived from practical implementation.
[0058] As used herein, the term "component" is intended to be broadly interpreted as hardware, firmware, or a combination of hardware and software. Clearly, the systems and / or methods described herein can be implemented in various forms of hardware, firmware, and / or combinations of hardware and software. The actual dedicated control hardware or software code used to implement these systems and / or methods is not a limitation on the implementation. Therefore, this document describes the operation and behavior of the systems and / or methods without referring to any specific software code—it should be understood that the systems and / or methods can be implemented using software and hardware based on the description herein.
[0059] Although specific combinations of features are recited in the claims and / or disclosed in the specification, these combinations are not intended to limit the disclosure of various implementations. In fact, many of these features can be combined in ways not specifically recited in the claims and / or not disclosed in the specification. Although each dependent claim listed below may depend directly on only one claim, the disclosure of various implementations includes each dependent claim in combination with every other claim in the claim set.
[0060] Unless explicitly stated otherwise, no element, action, or instruction used herein should be construed as critical or necessary. Furthermore, as used herein, the articles “a” and “an” are intended to include one or more items and are interchangeable with “one or more.” Furthermore, as used herein, the article “the” is intended to include one or more items referenced in combination with the article “the” and is interchangeable with “the one or more.” Furthermore, as used herein, the term “set” is intended to include one or more items (e.g., related items, unrelated items, a combination of related and unrelated items, etc.) and is interchangeable with “one or more.” If only one item is intended, the phrase “only one” or similar language is used. Furthermore, as used herein, the terms “have,” “possess,” “contain,” etc., are intended to be open-ended terms. Furthermore, the phrase “based on” is intended to mean “at least partially based on” unless explicitly stated otherwise. Furthermore, as used herein, when used in a series, the term “or” is intended to be inclusive and is interchangeable with “and / or” unless explicitly stated otherwise (e.g., if used in combination with “any one” or “only one”).
[0061] Various exemplary embodiments have been described in the foregoing description with reference to the accompanying drawings. However, it will be apparent that various modifications and changes can be made thereto, and additional embodiments can be implemented without departing from the broader scope of the invention as set forth in the appended claims. Therefore, the description and drawings should be considered illustrative rather than restrictive.
Claims
1. A method for communication, comprising: A removable quantum random number generator (QRNG) of a network device generates one or more packets with random payloads based on a clock input received at a defined time. Each of the one or more groups includes: a payload of random numbers generated by the removable QRNG, and a timestamp indicating the valid time for the payload; The QRNG generates entropy for network traffic flows by generating one or more packets with the random payload; and The removable QRNG is configured to create greater randomness when greater entropy is required; the network device provides the one or more packets with the random payload to the components of the network device; The components of the network device cause the one or more packets carrying the random payload to be forwarded to the destination address; and The removable QRNG provides one or more packets with the random payload to one or more other network devices via encryption.
2. The method according to claim 1, wherein the component is one of the packet forwarding component or the routing component of the network device.
3. The method according to claim 1, further comprising: Before the one or more packets with the random payload are forwarded to the destination address, the random payload of the one or more packets with the random payload is authenticated.
4. The method of claim 1, wherein the destination address associated with the one or more other network devices requires entropy. The network device provides the one or more packets with the random payload to the one or more other network devices based on the destination address.
5. The method according to claim 1, further comprising: The components of the network device cause the one or more packets with the random payload to be forwarded to the one or more other network devices for testing purposes.
6. The method of claim 1, wherein each of the one or more packets having the random payload comprises one or more of the following: Ethernet header, or Ethernet address.
7. The method of claim 1, wherein each of the one or more packets having the random payload is an Internet Protocol packet or a Multiprotocol Label Switching packet.
8. A network device, comprising: Removable quantum random number generator (QRNG); One or more memory units; as well as One or more processors, for: The removable QRNG generates one or more packets with random payloads based on clock input at a defined time. Each of the one or more groups having the random payload includes: a payload of random numbers generated by the removable QRNG, and a timestamp indicating the valid time for the payload; The QRNG generates entropy for network traffic flows by generating one or more packets with the random payload; and The removable QRNG is configured to create greater randomness when greater entropy is required; and The removable QRNG provides one or more packets with the random payload to the network device. The one or more packets with the said random payload are forwarded to the destination address; and The removable QRNG provides the one or more packets with the random payload to one or more other network devices via encryption.
9. The network device of claim 8, wherein the one or more processors are further configured to: Inspect the one or more packets having the said random payload; and One or more routes to one or more other network devices are identified by examining one or more packets with the random payload.
10. The network device of claim 8, wherein the one or more processors are further configured to: Determine the rate at which the one or more packets with the said random payload are provided to the one or more other network devices; and Based on the rate, the one or more packets with the random payload are provided to the one or more other network devices.
11. The network device of claim 8, wherein the one or more processors are configured to generate the one or more packets having the random payload, for one of the following: Generate the one or more packets with the random payload at a stable rate; or Generate the one or more packets with the defined random payload at the defined time.
12. The network device of claim 8, wherein each of the one or more packets having the random payload includes a unicast address, a multicast address, or a broadcast address.
13. The network device of claim 8, wherein the removable QRNG includes a cryptographic module.
14. The network device of claim 8, wherein the one or more processors are further configured to: Determine the entropy quality associated with the one or more packets having the said random payload; and Generate a notification indicating the entropy quality associated with the one or more packets having the random payload.
15. A non-transient computer-readable medium storing an instruction set, the instruction set comprising: One or more instructions, when executed by one or more processors of the network device, cause the network device to: The removable quantum random number generator (QRNG) of the network device generates one or more packets with random payloads based on a clock input; Each of the one or more groups having the random payload includes: a payload of random numbers generated by the removable QRNG, and a timestamp indicating the valid time for the payload; The QRNG generates entropy for network traffic flows by generating one or more packets with the random payload; and The removable QRNG is configured to create greater randomness when greater entropy is required; and The removable QRNG provides one or more packets with the random payload to the network device. Authenticate the random payload of the one or more packets having the random payload; The one or more packets with the said random payload are forwarded to the destination address; and The removable QRNG provides the one or more packets with the random payload to one or more other network devices via encryption.
16. The non-transient computer-readable medium of claim 15, wherein the destination address associated with the one or more other network devices requires entropy, and The network device provides the one or more packets with the random payload to the one or more other network devices based on the destination address.
17. The non-transient computer-readable medium of claim 15, wherein the one or more instructions provided with the one or more packets having the random payload cause the network device to: The one or more packets with the random payload are provided to the one or more other network devices for testing purposes.
18. The non-transient computer-readable medium of claim 15, wherein one or more instructions further cause the network device to: Inspect the one or more packets having the random payload; One or more routes to one or more other network devices are identified based on the inspection of one or more packets having the random payload; as well as The one or more packets with the random payload are provided to the one or more other network devices via the one or more routes.
19. The non-transient computer-readable medium of claim 15, wherein one or more instructions further cause the network device to: Determine the rate at which the one or more packets with the said random payload are provided to the one or more other network devices; and Based on the rate, the one or more packets with the random payload are provided to the one or more other network devices.
20. The non-transient computer-readable medium of claim 15, wherein one or more instructions further cause the network device to: Determine the entropy quality associated with the one or more packets having the said random payload; and Generate a notification indicating the entropy quality associated with the one or more packets having the random payload.
Citation Information
Patent Citations
Generating network packet centric signatures
US11076025B1
Method and system for providing quantum random number on basis of quantum entropy source
WO2021054734A1