Optical path monitoring device and method

By using optical path monitoring methods in optical networks, indistinguishable photons are generated to interfere, and the physical integrity of optical paths is evaluated, the security problems of existing encrypted communication technologies in the face of quantum computer threats are solved, and efficient communication is realized compatible with existing communication networks.

CN120226301APending Publication Date: 2025-06-27THE UNIVERSITY OF QUEENSLAND
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380076856.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-10-05
Filing Date
2023-10-05
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

When existing encrypted communication technologies face the threat of quantum computers, they are difficult to effectively protect information security, and the quantum key distribution (QKD) technology has limited scope, only support point-to-point communication and low data rates.

Method used

By using optical path monitoring methods in an optical network, indistinguishable photons are generated and photons are transmitted and received through optical paths to interfere, quantum interference visibility output is generated to evaluate the physical integrity of the optical path.

Benefits of technology

Continuous monitoring and evaluation of optical paths is realized, the physical integrity of the communication link is ensured, the eavesdropping and tampering are avoided, and it can be compatible with existing communication networks, supports multipoint communication and high data rates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120226301A_ABST
    Figure CN120226301A_ABST
Patent Text Reader

Abstract

An optical path monitoring method comprising the following steps performed by a first node of an optical network: (i) generating photons that are at least partially indistinguishable in frequency, polarization, spatial pattern and temporal distribution; (ii) transmitting a first photon of the generated photons through an optical path to a remote node of the optical network; (iii) receiving the first photon from the remote node through an optical path; and (iv) interfering the received first photon with a second one of the generated photons to generate a quantum interference visibility output; and (v) evaluating the physical integrity of a single or more of the optical paths based on the quantum interference visibility output.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to secure (e.g., encrypted) communications and, in particular, to an optical path monitoring apparatus and method for assessing the physical integrity of an optical path. Background Art

[0002] Secure communications are necessary in many situations. For example, in a military context, secure and protected communications between allies are crucial for countering an opponent's freedom of action. It is well known that the breaking of encryption codes had a significant impact on the outcome of World War II on both major battlefronts. Allied intelligence broke the German Enigma code, reversing the situation in the Atlantic submarine war, while the partial breaking of the JN-25b code gave the US military a decisive advantage in the Battle of Midway.

[0003] Modern communication encryption is based on mathematical algorithms with trapdoor functions - the result of the operation is easy to calculate, but the inverse operation requires exponentially increasing computational resources and is therefore generally considered computationally infeasible. Factorization is such a trapdoor operation and is at the core of the "RSA" code developed by Rivest, Shamir, and Adleman, perhaps the most well-known encryption algorithm currently used to protect information security. Such codes are used to encrypt communication traffic on the World Wide Web, protect credit card transactions during online shopping, and protect information stored locally on shared systems. The early use of these codes was compromised by short password key lengths (40 bits) and poor random seed hygiene: in 1995, two doctoral students at the University of California, Berkeley, demonstrated that a clever malicious agent could check a list of possible random seeds in a matter of minutes, rendering the then-standard encryption in Netscape web browsers ineffective. This demonstration, along with others, overcame export control restrictions and led us to today's 128-bit standard, which is generally considered unbreakable by non-state actors.

[0004] In 1995, quantum mechanics was a small cloud on the horizon in the field of Internet security; by 2015, it had evolved into a major technological storm, prompting the US National Security Agency (NSA) to begin transitioning to a "post-quantum" (i.e., quantum-resistant) era. In 1994, Peter Shor proposed an algorithm for a hypothetical quantum machine that operates using qubits ("quantum bits") and can efficiently find the greatest common divisor. In principle, the security of the RSA algorithm and all encryption codes that use factorization as a security token became vulnerable overnight.

[0005] However, in practice, such a quantum machine is still far from becoming a reality today, but Shor's algorithm has triggered decades of efforts to build such a quantum machine (quantum computer) that can break encryption in a timely manner. Quantum computing was initially mainly driven by academic research groups, and its progress and potential have prompted industry giants such as IBM, Google, and Microsoft to join the ranks of global participants in developing quantum computing technology, along with dedicated startups such as PsiQuantum, Xanadu, and Rigetti.

[0006] In view of these developments, in 2015, the US National Security Agency recommended: "For partners and suppliers who have not yet transitioned to Suite B elliptic curve algorithms, we recommend not investing a large amount of money in the transition at present, but rather preparing for the upcoming transition to quantum-resistant algorithms." (Suite B elliptic curve cryptography algorithms are used to protect information that can be publicly released, US-only information, and sensitive compartmented information). There are two practical obstacles to adopting this recommendation: 1) As of the end of 2020, these codes were still not ready (NIST is conducting a multi-round selection process that lasts for several years); and 2) Quantum-resistant codes require significantly more computing time than existing RSA codes, and thus also significantly more energy, and are therefore slower and more expensive to implement. Recognizing this, in 2019, the US National Security Agency obtained a period of time to replace Suite B with the Commercial National Security Algorithm Suite (CNSA), which uses the same technology but has longer keys.

[0007] Another post-quantum alternative is known as "quantum key distribution" (abbreviated as "QKD"). Although it is far less popular than the former, it creates and distributes one-time keys based on the randomness of quantum measurements, enabling users to create asymptotically secure communication channels. Although QKD is an emerging commercial product, its implementation is hindered by many significant limitations, making it difficult to integrate into existing networks. These limitations include, but are not limited to: limited range (≤100km); only supporting point-to-point communication; requiring dedicated systems for each communication channel and each site, and significantly lower data rates compared to current traditional communications. These limiting factors explain the slow global popularity of QKD, the low attention given to it by the UK Government Communications Headquarters (GCHQ) and the US National Security Agency, and its limitation to a few high-profile test scenarios.

[0008] It is desired to overcome or mitigate one or more difficulties of the prior art, or at least provide a useful alternative. Summary of the Invention

[0009] According to some embodiments of the present invention, there is provided an optical path monitoring method, including the following steps performed by a first node of an optical network:

[0010] (i) Generate photons that are at least partially indistinguishable in frequency, polarization, spatial mode, and temporal profile;

[0011] (ii) Send a first one of the generated photons to a remote node of the optical network via an optical path;

[0012] (iii) Receive the first photon from the remote node via the optical path; and

[0013] (iv) Interfere the received first photon with a second one of the generated photons to generate a quantum interference visibility output; and

[0014] (v) Evaluate the physical integrity of the single or multiple optical paths based on the quantum interference visibility output.

[0015] In some embodiments, the method includes repeating steps (i) to (v) to provide continuous monitoring of the physical integrity of the single or multiple optical paths.

[0016] In some embodiments, the first photon is sent and returned via the same optical path. In some embodiments, the first photon is sent and returned via different optical paths.

[0017] In some embodiments, the method includes storing the second photon for a duration corresponding to the time delay between sending the first photon to the remote node and receiving the first photon from the remote node.

[0018] In some embodiments, the method includes generating the first photon and the second photon at different times corresponding to the time delay between sending the first photon to the remote node and receiving the first photon from the remote node.

[0019] In some embodiments, the method includes, prior to the interference step (iv):

[0020] Send the second one of the generated photons to a third node of the optical network via an additional optical path; and

[0021] Receive the second photon from the third node via the additional optical path or yet another optical path;

[0022] wherein evaluating the physical integrity of the single or multiple optical paths based on the quantum interference visibility output includes simultaneously evaluating the physical integrity of the additional single or multiple optical paths.

[0023] In some embodiments, the method includes the following steps performed by the remote node:

[0024] Receive the first photon from the first node; and

[0025] Send the first photon to the first node such that there is no complete loss of indistinguishability in each of frequency, polarization, spatial mode, and temporal distribution between the first photon and the second photon.

[0026] In some embodiments, the method further includes the step of multiplexing the first photon of the generated photons with an optical communication signal, wherein the first photon and the optical communication signal are distinguishable in at least one of frequency, polarization, spatial mode, and temporal distribution; and wherein the step of sending the first photon includes sending the multiplexed first photon and optical communication signal to the remote node through the optical path.

[0027] In some embodiments, the method further includes preventing subsequent communication with the remote node on the single or multiple optical paths unless the physical integrity of the single or multiple optical paths is evaluated as undamaged.

[0028] In some embodiments, the method further includes the following steps performed by the remote node:

[0029] Receive the multiplexed first photon and optical communication signal;

[0030] Separate the first photon from the optical communication signal; and

[0031] Send the first photon to the first node such that there is no complete loss of indistinguishability in each of frequency, polarization, spatial mode, and temporal distribution between the first photon and the second photon.

[0032] According to some embodiments of the present invention, there is provided an optical path monitoring device having components configured to perform any one of the above methods.

[0033] According to some embodiments of the present invention, there is provided an optical path monitoring device, the optical path monitoring device including a first node, the first node including:

[0034] A quantum photon source configured to generate photons indistinguishable in frequency, polarization, spatial mode, and temporal distribution;

[0035] One or more optical components configured to send a first photon of the generated photons to a remote node of an optical network through an optical path and receive the first photon from the remote node through the optical path;

[0036] A quantum interference component configured to cause interference between the first photon received from the remote node and a second photon among the generated photons to generate a quantum interference visibility output; and

[0037] A path integrity component configured to evaluate the physical integrity of the single or multiple optical paths based on the quantum interference visibility output.

[0038] In some embodiments, the apparatus is configured to provide continuous monitoring of the physical integrity of the single or multiple optical paths.

[0039] In some embodiments, the first photon is sent and returned through the same optical path. In some embodiments, the first photon is sent and returned through different optical paths.

[0040] In some embodiments, at least one of the optical paths is a corresponding fiber optic path or waveguide. In some embodiments, at least one of the optical paths is a corresponding free space optical path.

[0041] In some embodiments, the one or more optical components include a multiplexer component configured to multiplex a first photon among the generated photons with an optical communication signal, wherein the first photon and the optical communication signal are distinguishable in at least one of frequency, polarization, spatial mode, and temporal distribution, and wherein the first photon and the optical communication signal are sent to the remote node in a multiplexed manner.

[0042] In some embodiments, the path integrity component is configured to prevent subsequent communication with the remote node through the single or multiple optical paths when the physical integrity of the single or multiple optical paths is evaluated as impaired.

[0043] In some embodiments, the apparatus includes a second node remote from the first node, the second node including an optical component configured to receive the first photon from the first node and return the first photon to the first node such that there is no complete loss of indistinguishability in each of frequency, polarization, spatial mode, and temporal distribution between the first photon and the second photon.

[0044] In some embodiments, the apparatus includes a module for storing the second photon for a duration corresponding to the time delay between sending the first photon to the remote node and receiving the first photon from the remote node.

[0045] In some embodiments, the quantum photon source is configured to generate the first photon and the second photon at different times corresponding to a time delay between sending the first photon to the remote node and receiving the first photon from the remote node.

[0046] In some embodiments, the one or more optical components are configured to send the second photon of the generated photons to a third node of the optical network via an additional optical path and receive the second photon from the third node via the additional optical path or yet another optical path; whereby the path integrity component evaluates the physical integrity of the single or multiple said optical paths and the single or multiple additional said optical paths based on the quantum interference visibility output. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Some embodiments of the present invention are described below by way of example only with reference to the accompanying drawings, wherein:

[0048] Figure 1 is a high-level block diagram of a device for secure communication according to some embodiments of the present invention;

[0049] Figure 2 is a flowchart of a method for secure communication according to some embodiments of the present invention;

[0050] Figure 3 is a block diagram of a device for secure communication according to some embodiments of the present invention;

[0051] Figure 4 is a schematic diagram showing a device for probabilistic photon number resolution detection according to some embodiments of the present invention;

[0052] Figure 5 is a block diagram of a device for secure communication with multiple field nodes by time switching of photons between corresponding communication channels;

[0053] Figure 6 is a block diagram of a device for secure communication with multiple field nodes by simultaneously and parallelly transmitting photons along corresponding communication channels;

[0054] Figure 7 is a schematic block diagram of a device for secure communication with multiple field nodes using a single quantum interference device; and

[0055] Figure 8 is a schematic block diagram of a communication network incorporating multiple instances of a device for secure communication according to an embodiment of the present invention. DETAILED DESCRIPTION

[0056] Embodiments of the present invention constitute a robust solution to the problem of physically secure communication links, thereby allowing the continued use of mature classical communication technologies with their speed and network advantages. Existing physical layer security typically relies on access restrictions at the user terminal, e.g., by using a swipe card or two-factor authentication, which verifies the user as a trusted identity before granting access to the information in the system.

[0057] However, this does not protect the link over which the communication is transmitted, and thus if an adversary can access the network infrastructure, the information remains vulnerable to interception. Embodiments of the present invention address this shortcoming by superimposing quantum signals on the channels of classical telecommunication systems and performing near-continuous integrity verification of the network, also referred to herein for convenience as "quantum link verification" ("OLV").

[0058] Advantages of the quantum link verification described herein over QKD include that it can be used with existing communication networks, is not limited to a point-to-point architecture, and protects communication at current data rates. QLV exploits the fact that the behavior of quantum light (particles of light, photons) is very different from classical intensity light. Specifically, QLV exploits two quantum phenomena:

[0059] (i) "Non-clonable": This ensures that it is impossible to copy a quantum state, such as a single photon, without destroying the state and the information it carries. Thus, an adversary cannot intercept and copy the quantum state. This is used for key distribution to ensure the integrity of individual bits, while QLV uses it to ensure the integrity of the optical communication link; and

[0060] (ii) "Quantum interference": Two indistinguishable single particles of light that meet at a 50% beam splitter do not follow the classical expected and equal probabilities of transmission or reflection at the beam splitter. Instead, the photons coalesce and exit the beam splitter as a pair. This effect, known in the art as Hong-Ou-Mandel ("HOM") interference, is used in quantum photonics to measure the indistinguishability of photons, since the probability of photon coalescence decreases as the two interfering photons become less similar. Perfect interference is represented by a zero rate of coincidence photon measurements after the beam splitter: as the interference decreases, this rate increases.

[0061] Accordingly, embodiments of the present invention include an optical path monitoring method and apparatus capable of assessing the physical integrity of an optical path (i.e., a link) between nodes of an optical network and whether the path may have been compromised. In this specification, the phrase "physical integrity" should be understood to refer to integrity at the level of the physical layer of the optical network, where the term "integrity" does not require or imply any physical break or disruption of the physical communication medium itself (e.g., by cutting or disconnecting an optical fiber, which is typically easily detectable), but rather whether the integrity of the optical path has been compromised; e.g., by eavesdropping or any form of tampering that alters the optical transmission characteristics of the optical path. Monitoring involves generating photons that are at least partially indistinguishable in terms of frequency, polarization, spatial mode, and temporal distribution. Each of these characteristics has a range of possible values, and thus for any two photons, the values may overlap in some of the above characteristics but not others. The phrase "partially distinguishable" (or equivalently "partially indistinguishable") refers to the situation where photons are indistinguishable for some measurements but distinguishable for other measurements. Thus, photons that are "at least partially indistinguishable" in terms of frequency, polarization, spatial mode, and temporal distribution cannot be distinguished by measuring at least one of these characteristics.

[0062] One of these at least partially indistinguishable photons (referred to herein as the "first" photon for ease of reference) is sent by a first node to a second remote node via an optical path and is returned by the remote node via the same or a different optical path to be received by the first node. The first node then causes the first photon to interfere with another of the at least partially indistinguishable photons ("second") to generate an output, which is referred to herein as the "quantum interference visibility" output, which indicates the physical integrity of the optical path (single or multiple).

[0063] In the described embodiments, the first photon and the second photon are generated simultaneously, and during the period in which the first photon is sent to and received from the remote node, the second photon (usually but not necessarily, as described below) is stored at the first node. However, in some alternative embodiments, the first photon and the second photon are generated at different times corresponding to the time delay between sending the first photon to the remote node and receiving the first photon from the remote node. Clearly, such embodiments require a photon source capable of generating a pair of indistinguishable photons at the corresponding different times. Examples of suitable photon sources are described by J.C. Loredo et al. in "Scalable performance in solid-state single-photon sources" (Optica 3, 433, 2016) ("Loredo").

[0064] Those skilled in the art should understand that there are different ways to store the second photon while retaining the ability to utilize the Hong - Ou - Mandel interference with the first photon. The most straightforward method is to send the second photon through an optical fiber delay line. Such examples are described by Loredo, M. Rambach, etc. in "Hectometer Revivals of Quantum Interference" (Physical Review Letters 121, 093603 (2018)).

[0065] An alternative is to use a cavity ring, examples of which have been described by F. Kaneda et al. in "Time - multiplexed heralded single - photon source" (Optica 2, 1010 (2015)). This scheme involves sending the second photon into a cavity formed by a high - reflector mirror and an electro - optical switch. Inside the cavity, the second photon travels back and forth between the two mirrors multiple times. When the total number of round - trips corresponds to the total distance traveled by the first photon (allowing the second photon to pass through the cavity by making round - trips), the electro - optical switch will controllably release the second photon so that it can interfere with the first photon.

[0066] Another alternative is to temporarily store the second photon in a quantum memory and then release it so that it can interfere with the first photon. Details of single - photon storage in a quantum memory are described by Jean Michael Mo et al. in "Quantum memories for fundamental science in space" (Quantum Science and Technology, 8, 024006 (2023)).

[0067] Embodiments of the present invention also include secure communication devices and methods, where optical path monitoring is combined with optical communication to evaluate whether those communications are likely to be compromised; for example, by eavesdropping. Thus, in some embodiments, the first photon is multiplexed with a communication signal, and the resulting multiplexed signal is sent to a remote node. The remote node separates the first photon from the communication signal and returns the separated first photon to the first node so that the integrity of the communication can be evaluated. Unless the first node evaluates that the communication is not compromised, it can block further communication with the remote node. In some embodiments, the (non - multiplexed) first photon is sent to the remote node before any such communication signal, so that the latter is only sent to the remote node after the optical link(s) have been evaluated as unimpaired.

[0068] Suitable methods for multiplexing the first photon with the communication signal include standard methods known to those skilled in the art, and either or both of the second photon and the communication signal can be coupled on and / or outside the optical link(s) (single or multiple). By way of example, some of the best-known standard methods include:

[0069] (i) Wavelength division multiplexing, where the first photon has a wavelength (single or multiple) slightly different from the wavelength(s) of the communication channel signal(s);

[0070] (ii) Time division multiplexing, where the second photon and the communication signal are sent in different time slices (e.g., when the communication signal is absent, the second photon can be coupled on or outside the channel, either because it is briefly interrupted to allow coupling or opportunistically when there is a pause in the signal traffic on the channel, as described by Wen Tan Fang et al. in “Towards high-capacity quantum communications by combining wavelength and time-division multiplexing technologies” (SPIE 10771, quantum communications and quantum Imaging XVI, 1077112 (2018));

[0071] (iii) Mode division multiplexing, where the second photon and the communication signal are coupled to different channel modes (e.g., the spatial mode of a waveguide or the propagation mode in free space), and appropriate filters, mode converters or other differentiating elements are used to selectively couple the second photon on or outside the channel while allowing the communication signal to pass through (as described, for example, by J. Carpenter et al. in “Mode multiplexed single-photon and classical channels in a few-mode fiber” (Optics Express 23, 28794 (2013)); and

[0072] (iv) Spatial path multiplexing, where the second photon is coupled to a spatial path slightly different from the communication signal. For example, there may be a small difference in the optical axis of the second photon relative to the communication signal (e.g., by spatial translation or angle), or the second photon can be coupled to a waveguide structure or different parts of different waveguides in a multi-guided beam.

[0073] These are just some of the more prominent multiplexing methods, and according to the present disclosure, other suitable methods will be apparent to those skilled in the art.

[0074] In some embodiments, the apparatus and method use a pair of indistinguishable photons. One (‘first’) photon is retained in a delay loop at a trusted entry to a link, which is referred to herein as home node A, and thus for convenience the retained photon is also referred to herein as the ‘A photon’. The other (‘second’) photon is sent to a remote or ‘field’ node B of the link, and is thus also referred to as the ‘B photon’, where it is then reflected back to node A and interferes with the first or A photon. When the delay at node A is selected or tuned to match the link length, the coincidence rate drops to zero: this is the output signal indicating a fully secure link. Any attempt by an eavesdropper to intercept the link partially or fully will cause the B photon to become distinguishable from the A photon by non-clonable quantum phenomena, which will cause the coincidence rate to become non-zero through quantum interference, indicating the presence of eavesdropping.

[0075] Figure 1 is a high-level block diagram of an apparatus for secure communication according to some embodiments of the present invention, and Figure 2 is a flowchart of a method for secure communication according to some embodiments of the present invention. As Figure 1 shown, a first or ‘home’ node A 102 communicates with a remote or ‘field’ second node B 104 via at least one optical path (e.g., at least one optical fiber, waveguide, or free space path) 106, which is a physical path (or “link”) verified by quantum link verification. The two nodes 102, 104 include optical transceivers and signal generators for communicating using classical communication protocols (shown aggregated as Ccom 108 and Ccom 110 at nodes 102, 104 respectively for simplicity).

[0076] The home node A 102 includes a quantum light source (“QLS”) 112, which is a non-classical photon source that generates a quantum state of light in at least two different optical modes at step 202 of the secure communication method. As an example of the described case for a pair of single photons, one photon in each of two optical modes, referred to herein as ‘home’ and ‘traveling’ photons respectively. The home and traveling photons must have some slight degree of indistinguishability in each optical property of frequency, polarization, spatial mode, and temporal distribution, and are thus described herein as being at least partially indistinguishable in each of these properties.

[0077] The optical classical telecommunication signal (OCTS) generated by CCom 108 of the home node A 102 and the "travelling" photon are received by the "adapter" component 114, which multiplexes one of the optical classical telecommunication signals (OCTS) with the travelling photon in step 204. In step 206, these signals are then sent via the optical path or link 106. The OCTS and the travelling photon must be distinguishable in at least one of the above four characteristics, namely: frequency, polarization, spatial mode, and temporal distribution. For example, in various embodiments, the OCTS and the travelling photon have orthogonal polarizations and / or non-overlapping frequency patterns. Any attempt to intercept or otherwise obtain the classical communication signal will also affect the travelling photon.

[0078] At the remote field node B 104, the optical signal is received by the beam splitter component 116, which spatially separates the travelling photon from the OCTS at step 208. The OCTS is sent to the receiver CCom110, and the travelling photon is sent to the "photon return device ("PRD")" 118, which returns the travelling photon to the home node A 102 via the same or a different optical path. The return transmission must be such that the indistinguishability in the above four characteristics is not completely lost. This can be verified, for example, by Hong-Ou-Mandel interferometry that produces a non-zero non-classical interference result.

[0079] If the system has drifted outside the range where non-classical interference can be observed, this can be restored by: (i) using compensating optics to undo the changes in the channel, or (ii) stabilizing and isolating the channel from the environment. For example, if the drift is in polarization (e.g., determined by monitoring one of the classical communication channels), then appropriate relevant compensation is applied to the quantum channel and the monitoring channel to compensate for the polarization rotation of the classical monitoring signal, which will also return the quantum interference signal to its original level in the absence of other changes. Thus, by monitoring and, if necessary, compensating all "normal" methods, the system can be maintained in and / or returned to a state where quantum interference will occur.

[0080] In step 210, the returned travelling photon is received at the home node A 102 by the quantum interference device ("QID") 120, which also receives the home photon, such that a quantum interference visibility output can be generated in step 212. In step 214, the output of the QID 120 is received by the control component 122, which evaluates the physical integrity of the optical path(s) and thus evaluates the security of the communication, and optionally, if the quantum interference visibility result is outside the acceptable limits (indicating that a single optical path has been (or multiple paths have been) compromised), further communication is blocked.

[0081] Figure 3

[0081] is a schematic diagram showing an embodiment of an apparatus for secure communication using a telecommunication optical fiber between a home node 302 and a remote field node 304. Photon pairs 305 are generated at 1550 nm by a commercially available photon down-conversion device (“PDC”) 306 (e.g., an optical nonlinear crystal) pumped by a 775 nm laser 304. In the described embodiment, the photon down-conversion device 306 is a NuCrypt EPS-1000 photon source, as described at htt: / / nucrypt.net / EPS-1000.html, but alternative down-conversion devices will be apparent to those skilled in the art.

[0082] Figure 3 One photon in each pair (“first” or “home photon”) is held at a trusted entry to the link (home node 302) by coupling it into a variable delay line 310. The variable delay line 310 consists of a fixed fiber delay and a tunable free-space element to ensure that the path length match is within the photon coherence length (typically 10 to 100 microns, depending on the bandwidth). Since the home photon is never sent and never leaves the home node, an attacker can never access the home photon at any time.

[0083] The other photon in the pair (“second” or “field photon”) is routed via an optical circulator 312 into a wavelength division multiplexer (“WDM”) 310, where it is superimposed onto a single optical fiber 316 together with a classical communication signal generated by a signal generator (“COM”) 318. This optical fiber 316 connects the home node 302 to the field node 304. At the field node 304, a second WDM 320 separates the classical communication from the single-photon signal. The separated single photon then returns to the second WDM 320 via an additional circulator 322 and is then sent back to the home node 302 via the same optical fiber 316. The WDM 314 and circulator 312 at the home node 302 separate the returned field photon and route it to a 50% beam splitter (“50:50 BS”) 324 to perform a quantum interference measurement using the delayed home photon. In Figure 3

[0082] the embodiment, a pair of single-photon detectors 326 are used to implement this measurement. Monitoring the single and coincidence count rates (“C”) 328 between the two single-photon detectors 326 allows detection of any physical interference with the optical fiber between the home node 302 and the field node 304.

[0084] Obviously, the home photons need to be delayed by a time corresponding to the effective round-trip time of the local photons so that the two photons can interfere with each other. In practice, this is achieved by performing an initial measurement of the local photon delay period when the optical path (single or multiple) is evaluated as safe (e.g., by physically inspecting the entire length of the optical fiber(s) during commissioning of the device), and then calibrating the home photon delay period by making it the same as the measured local photon delay period. Once the delay periods are measured and calibrated, any change in the length(s) of the optical path(s) between the two nodes (and / or any change in the time taken by the local photons within the remote node) will cause a change in the effective round-trip time of the local photons, thus preventing or at least suppressing the interference between the home photons and the local photons.

[0085] QLV is wavelength agnostic and can be equivalently used in optical fibers employing five wavelength bands between 1260 nm and 1625 nm or in free-space communication networks typically operating at near-infrared (780 nm) or infrared (1550 nm) wavelengths. As is known to those skilled in the art, suitable photon sources are well developed and indeed commercially available for these wavelength ranges.

[0086] Modern telecommunication uses a large number of frequencies within each individual optical path or link: in telecommunications, each link is an optical fiber, and information is routed into and out of the optical fiber by wavelength-division multiplexing (WDM). In free space, the optical path / link is defined by bulk optics and the same technique is used, but if the carrier is radio or 4G, it is called frequency-division multiplexing (FDM) - since the carrier is typically described by frequency - but the physical principle is the same.

[0087] C-band telecommunications in the wavelength range of 1530 - 1565 nm uses dense WDM (DWDM) to combine 80 frequency channels into a single optical fiber. Recently, ultra-dense WDM has achieved 320 channels, and moving to the L-band (1565 - 1625 nm) will effectively double these capacities. In any such embodiment, the QLV signal only requires one of these channel frequencies, leaving the rest for full-capacity classical communication. In practice, one or more channels are reserved for measuring the link length by an optical time-domain reflectometer (or equivalent), providing the information needed to tune the variable delay in the home node. Thus, the link can be continuously verified as safe at the cost of a small reduction in achievable information capacity from 2.5% (C-band, DWDM) to 0.3% (L-band, UDWDM).

[0088] The secure communication methods and apparatuses described herein effectively detect the actions of adversarial eavesdroppers on optical communications between nodes of a communication network. For example, consider an eavesdropper Eve, who attempts to gain access to the communication link in each of the following three different attack scenarios.

[0089] Attack 1: Signal Splitting

[0090] In this attack, Eve attempts to splice into a fiber optic beam splitter with a low splitting ratio to siphon off a small amount of the classical signal field, which Eve processes on her own WDM to extract information while forwarding most of the signal onward to the field node. This type of attack can be detected as an increase in coincidence or a decrease in non-classical visibility because the entire path length is changed due to the presence of the fiber optic beam splitter. The changes in coincidence and non-classical visibility can be correlated with the signal splitting ratio.

[0091] Attack 2: Channel Selection

[0092] In this attack scenario, Eve employs a WDM before her fiber optic beam splitter, attempting to evade detection by not routing the quantum signal's channel to her siphoning beam splitter. After siphoning off the classical communication signal, Eve uses a second WDM to recombine the signal with the quantum channel and sends the recombined signal to the field node. Such an attack is more challenging, but can be addressed by randomly switching the quantum signal to different WDM channels at the home node, which eliminates Eve's evasion strategy and detects Eve's presence based on reduced non-classical interference or increased coincidence as in Attack 1. The field node does not need to know which WDM channel provides the quantum signal because it returns a portion of the signals received on all WDM channels to the home node, which of course knows which of those channels provided the returned portion of the quantum signal.

[0093] Attack 3: Quantum Channel Blocking

[0094] The quantum channel blocking attack exploits the fact that a simply successful link verification is indicated by a zero rate of coincidence in a quantum interference measurement. Eve's strategy is to take advantage of this by using the WDM and fiber optic beam splitter in the channel selection attack described above, but now simply blocking the quantum channel from sending. Since no second photon returns, the coincidence rate will remain at the background level.

[0095] There are two ways to counter this attack. First, the random switching used to defeat Attack 2 will also work here. Additionally or alternatively, both the single photon rate and the coincidence counting rate can be monitored. By blocking the returned single photons, Eve reduces the amount of single photons that might be detected at the home node by half. After the link is established, this will be a clear indication of eavesdropping.

[0096] The secure communication method and apparatus can also detect whether Eve has established a secret hardware in the link before initial calibration. In this case, the secure communication apparatus uses a detector capable of distinguishing single photons and two photons. If and when Eve blocks the quantum signal, the secure communication apparatus measures a significant reduction in the rate of two-photon events at each detector - since these are eliminated by Eve - but will continue to see a certain rate of single-photon detections caused by non-classical interference. In fact, as Figure 4 shown, probabilistic photon number resolution can be robustly achieved by a composite detector 400 consisting of a 50% beam splitter 402 with single-photon detectors 408, 410 at the corresponding outputs. The fiber optic beam splitter 402 probabilistically divides two incoming photons 404, 406 into different output modes, thus allowing two non-photon number resolving detectors 408, 410 to correctly identify the presence of two photons 404, 406. Two-photon events are shown as coincidences between two local detectors 408, 410 within the composite detector 400: when these stop, the non-classical interference has been turned off and eavesdropping has been detected.

[0097] Quantum Verification of Multi-Node Telecommunication Networks

[0098] Real-world communication architectures are usually more than just point-to-point connections, where ring and star network architectures are common. Figure 5 and Figure 6 are block diagrams of corresponding embodiments of secure communication apparatuses for use in a multi-node communication network, each secure communication apparatus being shown as having one trusted home node 502 (or 602) and (for simplicity, only) two untrusted field nodes 504, 506 (or 604, 606), the field nodes being communicatively coupled to the home node in a point-to-point manner via corresponding dedicated optical paths (e.g., optical fibers) 508, 510 (or 608, 610).

[0099] As Figure 5 shown, in the random switching quantum link embodiment, the home node 502 includes corresponding dedicated WDMs (or "adapters") 512, 514 for the optical paths 508, 510. The switch 516 dynamically and quasi-randomly selects one of the WDMs 512, 514 to receive the quantum signal generated by the quantum photon source ("QLS") 518, and thus selects which of the links 508, 510 is to be verified. The classical communication device CCOM 520 encrypts and decrypts the communication signals, and the quantum interference device ("QID") 522 uses beam splitters and detectors to perform quantum interference measurements. In Figure 5In an embodiment, if the output of QID 522 indicates eavesdropping to prevent further communication, the control component 524 is included to disable the CCOM 520 of the home node 502. The classical communication lines are shown as solid lines, while the paths of the quantum states are shown as dashed lines. The communication and quantum signals between the home node 502 and each of the field nodes 504, 506 travel together along the same optical fibers 508, 510.

[0100] In another embodiment, as Figure 6 shown, multi-band down-conversion quantum link verification is used to simultaneously verify multiple links to the respective field nodes 604, 606 of a multi-node network. By leveraging the width of the frequency down-converted signal, the QLS 612 generates photons within the home node 602 in multiple wavelength channels. The WDM 614 separates them into respective outputs and routes them to the respective additional WDMs (or "adapters") 616, 618 to overlay the classical communication signals generated by the respective CCOMs 620, 622. The advantage of this configuration is that the links 608, 610 between the home node 602 and all the field nodes 604, 606 are continuously verified (although at the cost of additional physical resources at the home node 602, specifically, the corresponding dedicated circulators 624, 626 and QIDs 628, 630 for each link 608, 610) to perform the verification once the single photons return from the field nodes 604, 606 to the home node 602.

[0101] It is obvious from the above that the advantage of random switching ( Figure 5 ) over multi-band verification ( Figure 6 ) is that in the former, the home node only requires one circulator and QID, regardless of which link 508, 510 is being verified. The disadvantage is that, unlike the point-to-point configuration ( Figure 6 ), by temporarily switching the verification actions across different links 508, 510, the network as a whole is not continuously monitored.

[0102] The advantage of multi-band down-conversion is that the entire network is continuously verified, but at the cost of requiring an additional WDM and additional circulators to route the different quantum signals to different field nodes, as well as additional quantum interference components at the home node - not only delay lines, but also beam splitters and detection and analysis components.

[0103] For more complex network topologies or use cases, different combinations of the two configurations can be used.

[0104] In an alternative embodiment, as Figure 7 shown, a single quantum interference device QID 702 is used to simultaneously evaluate the physical integrity of the optical paths 704, 706 to multiple field nodes 708, 710. Although it requires more than Figure 6The configuration shown has fewer components, but this configuration does not allow identification of which optical path(s) 704, 706 is / are being interfered with by an eavesdropper.

[0105] Quantum link verification has been described above for point-to-point communication links between a home node and multiple field nodes. However, if two home nodes are connected to the same field node, the cross-network link can be verified either by independent verification of each sub-segment link or by bypassing a signal through multiple nodes. In this way, large networks such as Figure 8 shown can be monitored and verified.

[0106] Although some embodiments of the present invention have been described above in the context of fiber optic link verification, it is apparent that the methods and apparatus described herein can be readily adapted to use free space transceivers to transmit and receive free space optical signals to verify line-of-sight free space optical links. Free space optical links are a rapidly growing part of modern telecommunication infrastructure and are used as backhaul for both LTE and 5G networks; for connecting base stations; as "last-mile" connections in deployments complicated by geography, urban geometry, or political landscapes; in airports; by the military; and for temporary wireless connections in disaster recovery, both domestic and international.

[0107] A potential problem particularly relevant to free space communication is that the first photon returns to the home node in an altered state due to environmental factors rather than eavesdropping. However, it is expected that environmental factors can be distinguished from eavesdropping by monitoring the temporal occurrence of environmental factors and determining their correlation with environmental events such as changes in weather conditions (e.g., humidity, pressure), heating, ventilation, and air conditioning (HVAC) switching, etc. in a data center.

[0108] For example, one or more of the following methods and their combinations can be used to distinguish environmental effects and eavesdropping attacks.

[0109] The quantum interference signal can be monitored over time and time series statistics can be used to evaluate the quantum interference signal to identify events and infer the time scale on which they occur, with long-term events indicating an attacker. In some embodiments, the fast Fourier transform of the quantum interference signal is analyzed to identify spectral changes. Similarly, the autocorrelation of the quantum interference signal can be used to distinguish normal events from abnormal events.

[0110] Fluctuations in the communication signal can also be monitored and correlated with changes in the quantum interference signal to evaluate the possible causes of the latter.

[0111] A secondary detection signal can be introduced into the optical path to evaluate path loss and timing and to provide calibration for the return rate of the first photon.

[0112] Machine learning can be applied to quantum interference signals to infer characteristic patterns that distinguish different causes of changes in the quantum interference signals.

[0113] Causal or non-causal filters can be used to allow later data to inform the reliability of earlier data. At high photon rates, this may introduce only a few milliseconds of delay in the analysis. At the other extreme, the signal can be post-processed to identify possible past intrusion events.

[0114] Periodic self-calibration can be performed by sending pairs of photons along channels with different time delays to collect statistical data on random fluctuations. This is compared with the QLV signal to help suppress false alarms caused by these fluctuations.

[0115] An alert process can be used to filter the results of any or all of the above methods. For example, an alert threshold can be set by the operator such that an alert is raised only when the threshold is exceeded. The threshold level can be selected according to the desired security level, and a higher security level runs the risk of more false alarms if no other steps are taken to distinguish the causes of changes to the output of the quantum interference signal.

[0116] The apparatus can include or be coupled to components or systems that monitor and compensate for environmental changes. For example, in free-space applications, adaptive optical elements can be used to compensate for optical distortions caused by the atmosphere, as described by R. Davies and M. Kasper in "Adaptive Optics for Astronomy" (Annual Review of Astronomy and Astrophysics 50, 305 (2012)).

[0117] In the case where a fiber optic link is subject to mechanical stress, an active fiber polarization controller can be used to compensate for changes in photon characteristics, and this method has recently been used to demonstrate the feasibility of protecting the characteristics of single photons propagating over distances of more than 1000 km in a fiber optic cable ("Experimental Twin-Field Quantum Key Distribution over 1000 km Fiber Distance" (Yang Liu et al., Physical Review Letters 130, 210801 (2023))).

[0118] Many modifications will be apparent to those skilled in the art without departing from the scope of the present invention.

Claims

1. An optical path monitoring method, comprising the following steps performed by a first node of an optical network: (i) generating photons that are at least partially indistinguishable in frequency, polarization, spatial mode, and temporal distribution; (ii) sending a first one of the generated photons to a remote node of the optical network via an optical path; (iii) receiving the first photon from the remote node via the optical path; and (iv) interfering the received first photon with a second one of the generated photons to generate a quantum interference visibility output; and (v) evaluating the physical integrity of the single or multiple optical paths based on the quantum interference visibility output.

2. The method according to claim 1, comprising repeating steps (i) to (v) to provide continuous monitoring of the physical integrity of the single or multiple optical paths.

3. The method according to claim 1 or 2, wherein The first photon is sent and returned via the same optical path.

4. The method according to claim 1 or 2, wherein The first photon is sent and returned via different optical paths.

5. The method according to any one of claims 1-4, comprising storing the second photon for a duration corresponding to a time delay between sending the first photon to the remote node and receiving the first photon from the remote node.

6. The method according to any one of claims 1-4, comprising generating the first photon and the second photon at different times corresponding to a time delay between sending the first photon to the remote node and receiving the first photon from the remote node.

7. The method according to any one of claims 1-4, comprising, prior to the interference step (iv): sending the second one of the generated photons to a third node of the optical network via an additional optical path; and receiving the second photon from the third node via the additional optical path or another optical path; Among them, evaluating the physical integrity of the single or multiple optical paths based on the quantum interference visibility output includes simultaneously evaluating the physical integrity of additional single or multiple optical paths.

8. The method according to any one of claims 1-7, comprising the following steps performed by the remote node: receiving the first photon from the first node; and sending the first photon to the first node such that the indistinguishability in each of frequency, polarization, spatial mode, and temporal distribution of the first photon and the second photon is not completely lost.

9. The method according to any one of claims 1-8, further comprising the step of multiplexing the first photons of the generated photons with an optical communication signal, wherein, The first photon and the optical communication signal are distinguishable in at least one of frequency, polarization, spatial mode, and temporal distribution; and wherein the step of sending the first photon comprises sending the multiplexed first photon and optical communication signal to the remote node via the optical path.

10. The method according to claim 9, comprising preventing subsequent communication with the remote node on the single or multiple optical paths unless the physical integrity of the single or multiple optical paths is evaluated as undamaged.

11. The method according to claim 9 or 10, comprising the following steps performed by the remote node: Receive the multiplexed first photon and the optical communication signal; Separate the first photon from the optical communication signal; and Send the first photon to the first node such that the indistinguishability in each of the frequency, polarization, spatial mode, and temporal distribution of the first photon and the second photon is not completely lost.

12. An optical path monitoring device having components configured to perform the method according to any one of claims 1 to 11.

13. An optical path monitoring device, comprising a first node, the first node including: A quantum photon source configured to generate photons that are indistinguishable in frequency, polarization, spatial mode, and temporal distribution; One or more optical components configured to send a first photon among the generated photons to a remote node of an optical network through an optical path and receive the first photon from the remote node through the optical path; A quantum interference component configured to interfere the first photon received from the remote node with a second photon among the generated photons to generate a quantum interference visibility output; And A path integrity component configured to evaluate the physical integrity of the single or multiple optical paths based on the quantum interference visibility output.

14. The apparatus according to claim 13, wherein The device is configured to provide continuous monitoring of the physical integrity of the single or multiple optical paths.

15. The device according to claim 13 or 14, wherein, The first photon is sent and returned through the same optical path.

16. The device according to claim 13 or 14, wherein, The first photon is sent and returned through different optical paths.

17. The device according to any one of claims 13-16, wherein, At least one of the optical paths is a corresponding fiber optic path or waveguide.

18. The device according to any one of claims 13 - 17, wherein At least one of the optical paths is a corresponding free space optical path.

19. The apparatus according to any one of claims 13 - 18, wherein, The one or more optical components include a multiplexer component configured to multiplex a first photon among the generated photons with an optical communication signal, wherein the first photon and the optical communication signal are distinguishable in at least one of frequency, polarization, spatial mode, and temporal distribution, and wherein the first photon and the optical communication signal are sent to the remote node in a multiplexed manner.

20. The apparatus according to claim 19, wherein, The path integrity component is configured to prevent subsequent communication with the remote node through the single or multiple optical paths in the case where the physical integrity of the single or multiple optical paths is evaluated as impaired.

21. The device according to any one of claims 13 - 20, including a second node remote from the first node, the second node including an optical component configured to receive the first photon from the first node and return the first photon to the first node such that the indistinguishability in each of the frequency, polarization, spatial mode, and temporal distribution of the first photon and the second photon is not completely lost.

22. The device according to any one of claims 13 - 21, including a module for storing the second photon for a duration corresponding to the time delay between sending the first photon to the remote node and receiving the first photon from the remote node.

23. The device according to any one of claims 13-21, wherein, The quantum photon source is configured to generate the first photon and the second photon at different times corresponding to a time delay between sending the first photon to the remote node and receiving the first photon from the remote node.

24. The device according to any one of claims 13-21, wherein, The one or more optical components are configured to send the second photon of the generated photons to a third node of the optical network via an additional optical path and receive the second photon from the third node via the additional optical path or yet another optical path; whereby the path integrity component evaluates the physical integrity of the single or multiple said optical paths and the additional single or multiple said optical paths based on the quantum interference visibility output.