QKD with shifted post processing for an optical communication system

The QKD system addresses distance limitations by using a post-processing gateway with identical seeds to the QKD transmitter, simplifying communication and reducing computational burden, thereby enhancing security and efficiency in satellite QKD systems.

GB2618989BActive Publication Date: 2025-07-16ARQIT LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
GB2022004181
Authority / Receiving Office
GB · GB
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-24
Publication Date
2025-07-16
Estimated Expiration
2042-03-24

AI Technical Summary

Technical Problem

The loss experienced over terrestrial links in quantum key distribution (QKD) systems limits the achievable distance, and satellite QKD systems face challenges with complex communication links and computational requirements for post-processing, which are inefficient and time-constrained.

Method used

A QKD system design where the post-processing tasks are performed independently of the QKD transmitter by using a post-processing gateway with identical seeds to the QKD transmitter, allowing classical communication links between the user QKD receivers and the gateway, eliminating the need for direct communication with the QKD transmitter.

Benefits of technology

This design simplifies the communication links, reduces computational burden on the satellite, and allows flexible network topologies, enhancing security and efficiency by separating the post-processing tasks from the QKD transmitter.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000001_0000
    Figure 00000001_0000
  • Figure 00000002_0000
    Figure 00000002_0000
  • Figure 00000003_0000
    Figure 00000003_0000
Patent Text Reader

Abstract

The system comprises a quantum key distribution QKD transmitter 102 configured to transmit photons via a first quantum communication channel 108, wherein the photons are encoded based on a seed stored
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to a method, system and software for operating an optical communication system, and in particular a quantum key distribution (QKD) system. Background

[0002] Quantum key distribution (QKD) allows two distant parties to share a key in an information theoretic secure way that is guaranteed by the laws of physics. Significant progress has been carried out in recent years on implementing this over fibre. However, the loss experienced over terrestrial links severely limits the achievable distance. By utilising the negligible loss experienced by photons travelling through most of the atmosphere, satellite QKD can overcome these limitations and enable inter-continental QKD.

[0003] Figure 1 shows a typical QKD system 1 having a QKD transmitter 2 and a QKD receiver 3. The transmitter 2 includes a first post-processing unit 4 and a QKD transmitter unit 6. The QKD transmitter unit 6 includes a faint pulse source (FPS) or single photon source for transmitting photons to the receiver 3. The receiver 3 includes a second post-processing unit 5, and a QKD receiver unit 7, which includes optical receivers and photon detectors. In this example, the QKD elements of the transmitter 2 and the receiver 3, including the QKD transmitter unit 6 and the QKD receiver unit 7 communicate via a quantum channel 8. The first post-processing unit 4 ofthe transmitter2 and the second post-processing unit 5 of the receiver 3 communicate via a classical communication channel 9.

[0004] Preparing and measuring QKD protocols involves the following steps: a) The QKD transmitter 2 (Alice) randomly encodes a classical variable into quantum states and transmits them over the quantum channel 8; b) The QKD Receiver 3 (Bob) measures the incoming signal using randomly selected bases; and c) Key Post Processing occurs at the first and second post-processing units 4 and 5, to generate the mutually agreed secure key by undertaking sifting, error correction and privacy amplification on the public classical communication channel 9.

[0005] Step c) ofthe QKD process above requires the classical communication channel 9 between the Transmitter 2 and Receiver 3. The bandwidth required for this communication link increases with an increase in the quantum detection rate at the receiver 3. In the case of Satellite QKD, usually a high-speed bidirectional free space optical or radio link is employed. However, such communication links require additional complex systems. Further postprocessing on the satellite can impose significant computational and storage requirements on the on-board processor, as well as introducing time constraints on post-processing associated with overpasses.

[0006] It has thus been appreciated that an alternative method of QKD would be advantageous for QKD, whereby the QKD is performed in a manner that allows the endpoints for the quantum transmission &reception to be separated from the endpoints for the postprocessing. In this way, the QKD receiver does not require classical communication links with the QKD transmitter. [0006a] US 2010293380 A1 discloses a method involving exchange of a quantum signal between a first quantum node and a second quantum node as is usual in known quantum key distribution (QKD) scheme. The first quantum node communicates details of the quantum signal it sent or received with a first remote node. The first remote node thus has aii the information to required to take the place of the first quantum node in the key agreement step with the second quantum node. The first quantum node may be arranged to transmit the quantum signal to the second quantum node, in which ease the invention provides a distributed quantum transmitter with the control logic in the first remote node being distributed remotely from the actual quantum transmitter in the first quantum node. Communications between the first remote node and first quantum node may comprise or be protected by a quantum key derived by conventional QKD. [0006b] WO2021028227 A1 discloses a method of performing Quantum Key Distribution for generating a shared secret key, the method comprising, at a first node, preparing or measuring a plurality of non-orthogonal quantum states, each of the plurality of non-orthogonal quantum states being prepared or measured using a respective one of a first set of basis states, and, at a second node, preparing or measuring the plurality of non-orthogonal quantum states each, of the plurality of non-orthogonal quantum states being prepared or measured using a respective one of a second set of basis states, and, at a third node, obtaining an indication of the first set of basis states from the first node and performing a key agreement stage with a fourth node to agree the shared secret key, the key agreement stage involving the first and second sets of basis states. Summary

[0007] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to determine the scope of the claimed subject matter; variants and alternative features which facilitate the working of the invention and / or serve to achieve a substantially similar technical effect should be considered as falling into the scope of the invention disclosed herein.

[0008] In a first aspect, the present disclosure provides a quantum key distribution, QKD, system comprising: a QKD transmitter configured to transmit photons to first and second user QKD receivers, respectively, via first and second quantum communication channels, wherein the photons are encoded based, respectively, on first and second seeds stored by the QKD transmitter; the first user QKD receiver configured to receive and detect the photons transmitted from the QKD transmitter over the first quantum communication channel; the second user QKD receiver configured to receive and detect the photons transmitted from the QKD transmitter over the second quantum communication channel; a post-processing gateway, configured to perform partial post-processing QKD tasks with the first and second user QKD receivers over respective bidirectional classical communication channels between the post-processing gateway and the first and second user QKD receivers, based on the photons detected by the first and second user QKD receivers and, respectively, on first and second seeds stored by the post-processing gateway, wherein the partial post-processing QKD tasks produce a final set of raw bits; wherein, respectively, the first and second seeds stored by the QKD transmitter and the first and second seeds stored by the post-processing gateway are identical, such that the post-processing gateway and the first and second user QKD receivers are configured to perform the post-processing QKD tasks independently of the QKD transmitter, wherein the first and second user QKD receivers are further configured to perform further post-processing tasks between each other to agree a final secure key, independently of the post-processing gateway, wherein the further post-processing tasks comprise sharing measurement bases used to detect the photons by the first and second QKD receivers, error correction and / or privacy amplification between the first and second user QKD receivers.

[0009] Since the post-processing gateway has an identical seed to the seed at the QKD transmitter, post-processing tasks relating to the QKD transmission session can be performed over a classical communication link between the user QKD receiver and the post-processing gateway, independently of the QKD transmitter. This has security benefits, since the transmitter and post-processing gateway can be kept separate, as well as communicational benefits, since it is more efficient and simpler to maintain a communication link between a user QKD receiver and a post-processing gateway than between a user QKD receiver and a QKD transmitter.

[0010] Preferably, the post-processing gateway is located physically separately from the QKD transmitter. The post-processing gateway may be in a secure location.

[0011] Preferably, the QKD transmitter is a satellite. The satellite may or may not be in orbit around the Earth.

[0012] Preferably, the post-processing gateway is ground-based. The post-processing gateway may communicate over the first bi-directional classical communication channel with the user QKD receiver whereby such a channel is a conventional ground-based channel.

[0013] Preferably, the first bidirectional classical communication channel between the postprocessing gateway and the user QKD receiver includes a physical communication link.

[0014] Preferably, the QKD transmitter is configured to encode the photons to transmit to the user QKD receiver based on a sequence of random numbers generated by a random number generator seeded by the seed stored at the QKD transmitter, and wherein the postprocessing gateway is configured to generate an identical sequence of random numbers for use in the post-processing QKD tasks using an identical random number generator seeded by the seed stored at the post-processing gateway.

[0015] Preferably, the first and second user QKD receivers are configured to perform the further post-processing tasks over a confidential channel between the first and second user QKD receivers.

[0016] Preferably, the partial post-processing QKD tasks that the post-processing gateway is configured to perform include an agreement of a first set of raw bits with the first user QKD receiver and an agreement of a second set of raw bits with the second user QKD receiver, wherein the final set of bits are produced by an exclusive OR Boolean logic operation, XOR, of the first and second set of raw bits.

[0017] Preferably, the QKD transmitter stores a plurality of seeds, and the post-processing gateway stores a corresponding plurality of identical seeds, wherein each of the plurality of seeds are unique, and wherein the QKD transmitter and the post-processing gateway are con-figured to use a different seed and corresponding identical seed respectively for each of a plurality of Quantum Transmission sessions with each of the User QKD receivers.

[0018] The quantum transmission session is at least a portion of the QKD process whereby encoded photons are transmitted to a user QKD receiver. There may be one or multiple quantum transmission sessions per QKD receiver. By using multiple seeds, the security of the system is improved.

[0019] Preferably, the QKD transmitter further stores a mapping comprising data indicative the plurality of Quantum Transmission sessions and the seeds of the plurality of seeds used for each of the plurality of Quantum Transmission Sessions, wherein the QKD transmitter is configured to send the mapping to the post-processing gateway.

[0020] The mapping may be a table, a list of a particular order, or a labelling of each seed, for example.

[0021] Preferably, the post-processing gateway further comprises a gateway QKD receiver, wherein the gateway QKD receiver is coupled to the QKD transmitter via an additional quantum channel and an additional bidirectional classical communication channel, wherein the QKD transmitter and the gateway QKD receiver are configured to either: perform a QKD process to generate the seeds stored by the QKD transmitter and the post-processing gateway; or perform a QKD process to generate a mutual key between the QKD transmitter and the post-processing gateway, wherein the QKD transmitter is configured to: use the mutual key to encrypt pre-stored seeds stored at the QKD transmitter; and send the encrypted pre-stored seeds to the post-processing gateway.

[0022] The seed or seeds may thus be generated at the QKD transmitter and then sent to the post-processing gateway, or may be generated by both the QKD transmitter and postprocessing gateway during a QKD process.

[0023] Preferably, the QKD transmitter is configured to use the mutual key to encrypt the pre-stored keys using one-time-pad, OTP, encryption. This improves security.

[0024] According to a second aspect, there is provided a QKD post-processing gateway comprising: a gateway QKD receiver for bidirectionally communicating with an external QKD transmitter; a post-processing unit for bidirectionally communicating with an external User QKD receiver; and a memory module; wherein the gateway QKD receiver is configured to: receive quantum information from the QKD transmitter via a first quantum communication channel; based on the quantum information, bidirectionally communicate with the QKD transmitter via a first classical communication channel to generate and / or obtain a shared seed from the QKD transmitter; and store the shared seed in the memory module; wherein the post-processing unit is further configured to: use the shared seed to perform postprocessing QKD tasks with the User QKD receiver over an additional bidirectional classical communication channel between the post-processing gateway and the User QKD receiver, such that the post-processing tasks are performed independently of the QKD transmitter.

[0025] Preferably, the QKD post-processing gateway of claim 13, wherein the postprocessing unit is configured to use the shared seed by: seeding a random number generator with the shared seed to produce a sequence of random numbers; and subsequently using the sequence of random numbers to perform post-processing tasks with the User QKD receiver.

[0026] Preferably, the gateway QKD receiver comprises: an optical receiver and photon detection unit configured to detect photons transmitted over the first quantum communication channel by the QKD transmitter; and a gateway QKD receiver post-processing unit configured to bidirectionally communicate with the QKD transmitter via the first classical communication channel to generate and / or obtain the shared seed with the QKD transmitter.

[0027] Preferably, the post-processing unit comprises: a processor; and a classical communication transceiver; wherein the processor is configured to: obtain the shared seed from the memory module; seed the random-number generator with the shared seed to generate a sequence of random numbers; and via the classical communication transceiver, perform post-processing QKD tasks with the User QKD receiver over the additional bidirectional classical communication channel between the post-processing gateway and the User QKD receiver, such that the post-processing tasks are performed in-dependently of the QKD transmitter.

[0028] Preferably, the post-processing gateway is ground-based.

[0029] Preferably, the post-processing gateway is, further configured to generate and / or obtain a plurality of shared seeds with / from the QKD transmitter.

[0030] Preferably, the post-processing gateway of claim is further configured to receive and store a mapping including data indicative of the plurality of shared seeds against one or more Quantum Transmission sessions be-tween the QKD transmitter and the User QKD receiver in which the shared seeds were used; and wherein the post-processing gateway is configured to: determine a present Post processing session and corresponding Quantum Transmission Session from communication with the User QKD receiver; look up the present Quantum Transmission session in the mapping to determine a corresponding present shared seed; and use the present shared seed to perform post-processing QKD tasks with the User QKD receiver over the additional bidirectional classical communication channel between the postprocessing gateway and the User QKD receiver, such that the post-processing tasks are performed independently of the QKD transmitter.

[0031] According to a fourth aspect, there is provided a QKD transmitter for transmitting an encoded stream of photons to one or more User QKD receivers in one or more Quantum transmission sessions; the QKD transmitter including: a faint pulse source and encoding unit; a memory module configured to store one or more seeds for seeding a random number genera-tor; and a QKD transmitter post processing unit; wherein the faint pulse source and encoding unit is configured to: obtain a seed from the one or more seeds from the memory module; generate a sequence of random numbers by seeding a random number generator with the seed; encode a series of photons using the sequence of random numbers; and transmit the encoded series of photons to one or more User QKD receivers via a first quantum communication channel; wherein the QKD transmitter is configured to either: generate the one or more seeds via a QKD process with a post-processing gateway whereby: the faint pulse source and encoding unit is further configured to transmit a series of separately encoded photons to the post-processing gateway in a QKD process with the post-processing gateway via a second quantum communication channel; the QKD transmitter post processing unit is configured to perform post-processing QKD tasks with the post-processing gateway over a bidirectional classical communication channel be-tween the QKD transmitter and the post-processing gateway, to generate the one or more seeds with the post-processing gateway; or: generate and store the one or more seeds at the QKD transmitter; generate a mutual key via a QKD process with the post-processing gateway whereby: the faint pulse source and encoding unit is further configured to transmit a series of separately encoded photons to the post-processing gateway in a QKD process with the post-processing gateway via a second quantum communication channel; and the QKD transmitter post processing unit is configured to perform post-processing QKD tasks with the post-processing gateway over a bidirectional classical communication channel between the QKD transmitter and the postprocessing gateway, to generate the mutual key with the post-processing gateway; encrypt the one or more seeds using the mutual key; and send the encrypted one or more seeds to the post-processing gateway.

[0032] Preferably, the QKD transmitter is configured to send a mapping to the postprocessing gateway, the mapping indicating an ordering of one or more seeds to be used for one or more respective Quantum transmission sessions between the QKD transmitter and user QKD receiver.

[0033] Preferably, the QKD transmitter is a satellite.

[0034] According to a fifth aspect, there is provided a method of performing quantum key distribution, QKD, the method comprising: transmitting, by a QKD transmitter, photons to first and second user QKD receivers in a quantum transmission session, wherein the photons are encoded, respectively, based on firstand second seeds stored by the QKD transmitter; receiving, at the first user QKD receiver, the photons transmitted from the QKD transmitter; receiving, at the second user QKD receiver, the photons transmitted from the QKD transmitter; performing, at a post-processing gateway, partial post-processing QKD tasks with the first and the second QKD receivers over respective bidirectional classical communication channels between the post-processing gateway and the first and the second user QKD receivers, based on the photons detected by the first and second user QKD receivers and, respectively, on first and second seeds stored by the post-processing gateway, wherein the partial post-processing QKD tasks produce a final set of raw bits; wherein, respectively, the first and second seeds stored by the QKD transmitter and the first and the second seeds stored by the post-processing gateway are identical, such that performing the post-processing QKD tasks occurs independently of the QKD transmitter; performing, between the first and second user QKD receivers, post-processing tasks to agree a final secure key, independently of the post-processing gateway, wherein the further post-processing tasks comprise sharing measurement bases used to detect the photons by the first and second QKD receivers, error correction and / or privacy amplification between the first and second user QKD receivers.

[0035] Preferably, the method further comprises performing, between the first and second user QKD receivers, further post-processing tasks over a confidential channel between the first and second user QKD receivers.

[0036] Preferably, performing the partial post-processing QKD tasks includes agreeing a first set of raw bits with the first user QKD receiver and agreeing of a second set of raw bits with the second user QKD receiver, wherein the final set of bits are produced by an exclusive OR Boolean logic operation, XOR, of the first and second set of raw bits.

[0037] Preferably, the quantum transmission session and post-processing are performed according to the the ARQ19 protocol. These are two types of QKD protocols.

[0038] Preferably, the method further comprises pre-storing each seed at the QKD transmitter and the post-processing gateway.

[0039] Preferably, the method further comprises: generating each seed via a QKD process between the QKD transmitter and the post-processing gateway by: transmitting, from the QKD transmitter, a series of separately encoded photons to the post-processing gateway in a quantum transmission session between the QKD transmitter and the post-processing gateway; performing post-processing QKD tasks between the QKD transmitter and the postprocessing gateway, to generate each seed with the post-processing gateway; and storing each seed at both the QKD transmitter and the post-processing gateway.

[0040] Preferably, the method further comprises generating and storing each seed at the QKD transmitter; generating a mutual key by: transmitting, from the QKD transmitter, a series of separately encoded photons to the post-processing gateway in a quantum transmission session between the QKD transmitter and the post-processing gateway; performing postprocessing QKD tasks between the QKD transmitter and the post-processing gateway, to generate the mutual key between the QKD transmitter and the post-processing gateway; encrypting, at the QKD transmitter, each seed using the mutual key; and sending the encrypted seed to the post-processing gateway.

[0041] Preferably, there is a plurality of seeds.

[0042] Preferably, the method further comprises transmitting, by a QKD transmitter, photons to each user QKD receiver in a plurality of quantum transmission sessions, wherein the photons of each quantum transmission session are encoded using a unique seed of a plurality of seeds; storing, by the QKD transmitter, a mapping that indicates the unique seed used for encoding the photons for each transmission session; and sending mapping to postprocessing gateway.

[0043] Preferably, the method further comprises sending the mapping to the post-processing gateway before or after the plurality of quantum transmission sessions between the QKD transmitter and each user QKD receiver.

[0044] The user QKD receiver may be any QKD receiver that is not the post-processing gateway QKD receiver.

[0045] The methods described herein may be performed by software in machine readable form on a tangible storage medium e.g. in the form of a computer program comprising computer program code means adapted to perform all the steps of any of the methods described herein when the program is run on a computer and where the computer program may be embodied on a computer readable medium. Examples of tangible (or non-transitory) storage media include disks, thumb drives, memory cards etc. and do not include propagated signals. The software can be suitable for execution on a parallel processor or a serial processor such that the method steps may be carried out in any suitable order, or simultaneously.

[0046] The computer program or instructions may be executed by a processor. The processor may be a microcontroller, a system on chip or a CPU for example, and may form part of a computing device having a memory. There may be more than one computer program executed. For example, the QKD transmitter, the post-processing gateway, and the user QKD receiver may each include a processor and / or computer, each configured to execute the method steps performed at each of those apparatuses. Furthermore, each of the configurations and functions of the apparatuses and devices according to the first, second, third and fourth aspects above may be implemented or initiated as method steps or instructions in a computer program executed by a processor.

[0047] This application acknowledges that firmware and software can be valuable, separately tradable commodities. It is intended to encompass software, which runs on or controls “dumb" or standard hardware, to carry out the desired functions. It is also intended to encompass software which “describes" or defines the configuration of hardware, such as HDL (hardware description language) software, as is used for designing silicon chips, or for configuring universal programmable chips, to carry out desired functions,

[0048] The preferred features may be combined as appropriate, as would be apparent to a skilled person, and may be combined with any of the aspects of the invention. Brief Description of the Drawings

[0049] Embodiments of the invention will be described, by way of example, with reference to the following drawings, in which:

[0050] Figure 1 is a schematic diagram illustrating a typical satellite quantum key distribution system;

[0051] Figure 2 is a schematic diagram illustrating a satellite quantum key distribution system according to an embodiment of the invention;

[0052] Figure 3 is a schematic diagram illustrating a satellite quantum key distribution system according to an embodiment of the invention;

[0053] Figure 4 is a timing chart illustrating a first method of operating a satellite quantum key distribution system according to an embodiment of the invention;

[0054] Figure 5 is a timing chart illustrating a second method of operating a satellite quantum key distribution system according to an embodiment of the invention;

[0055] Figure 6 a schematic diagram illustrating an expanded satellite quantum key distribution system according to an embodiment of the invention;

[0056] Common reference numerals are used throughout the figures to indicate similar features. Detailed Description

[0057] Embodiments of the present invention are described below by way of example only. These examples represent the best mode of putting the invention into practice that are currently known to the Applicant although they are not the only ways in which this could be achieved. The description sets forth the functions of the example and the sequence of steps for constructing and operating the example. However, the same or equivalent functions and sequences may be accomplished by different examples.

[0058] Typical prepare and measure QKD Systems such as the example system 1 illustrated in figure 1 have a QKD transmitter sending encoded quantum states to a QKD receiver at a particular repetition rate. Random numbers are used for encoding the transmitted photons that provide the quantum information. In free space QKD implementations this typically involves randomising the bit, polarisation basis, intensity and, in some cases, phase associated with each photon produced by the faint pulse source. The random numbers used for encoding the photons are again used during the post-processing phase to agree a key with the receiver. In some examples, a local true entropy source such as a quantum random number generator (QRNG) is used to seed a cryptographically secured pseudo-random number generator (CSPRNG) to produce the random number stream used for encoding. Other methods or configurations for producing a random number stream for encoding may also be implemented.

[0059] Figure 2 shows a schematic overview of a QKD system 100 according to an embodiment. The system 100 includes a QKD transmitter 102, a QKD receiver 104, and a post-processing gateway 106.

[0060] The QKD transmitter 102 includes a random number generator 114a. The random number 114a generator is configured to produce a stream of random numbers for encoding the quantum information to be transmitted via photons to the QKD receiver 104. The random number generator 114a may be a CSPRNG for example. The QKD transmitter further includes pulse electronics 116 for controlling a faint pulse source (FPS) 118. The FPS 118 is configured to transmit encoded quantum information in photons via the quantum channel 108 to the QKD receiver 104. The FPS 118 may be a single photon source.

[0061] The QKD receiver 104 includes an optical receiver and detector subsystem 120 configured to receive and detect the photons transmitted by the QKD transmitter 102 over the quantum channel 108. The QKD receiver 104 further includes a post-processing unit 122 for performing post-processing tasks, including generating a mutually agreed secure key by, for example, undertaking sifting, error correction and / or privacy amplification. Post-processing may also include coincidence detection, parameter estimation, information reconciliation, and / or message authentication. The exact form of post-processing depends on the protocol being employed. The post-processing unit 122 includes a computer or processor 124 configured to operate or otherwise implement post-processing software, and a classical communication transceiver 126.

[0062] The post-processing gateway 106 includes a random number 114b generator configured to produce a stream of random numbers for use in post-processing tasks with the QKD receiver 104. The post-processing gateway 106 also includes a post-processing unit 128 including a computer or processor 130 configured to operate or otherwise implement post-processing software, and a classical communication transceiver 132. The postprocessing gateway 106 and the QKD receiver are configured to communicate via a bidirectional classical communication channel 110.

[0063] The random number generator 114a of the QKD transmitter 102 and the random number generator 114b of the post-processing gateway 106 are identical in type and configuration, and are provided with identical shared entropy 112 to seed the random number generators 114a and 114b. This ensures that the random number generators 114a and 114b provide an identical stream of random numbers in both the QKD transmitter 102 and the postprocessing gateway 106. This effectively provides the post-processing gateway 106 with the full information used for encoding the photons as at the QKD transmitter 102, such as basis, intensity, and value. This knowledge, together with the post-processing elements included at the post-processing gateway 106, allows the post-processing gateway 106 to perform postprocessing tasks with the QKD receiver 104 independently of the QKD transmitter 102. This provides a number of advantages.

[0064] Firstly, a bidirectional classical communication channel is not required directly between the QKD transmitter 102 and QKD receiver 104 to perform post-processing tasks, since these post-processing tasks can take place between the QKD receiver 104 and the post-processing gateway 106 directly, without intervention from the QKD transmitter 102.

[0065] Secondly, the post-processing gateway 106 can be located independently of the QKD transmitter 102. Since the full information used for encoding the photons at the QKD transmitter 102 (e.g. the shared entropy 112 and the random number generator 114a) are shared with the post-processing gateway 106, there is no requirement to co-locate the QKD transmitter 102 and the post-processing gateway 106 to perform post-processing tasks. In satellite QKD systems, whereby the QKD transmitter 102 is a satellite, the post-processing gateway 106 can be placed on the ground, which allows the bidirectional classical communication channel 110 between the post-processing gateway 106 and the QKD receiver 104 to be implemented over higher-bandwidth permanently available communication systems, such as fibre, rather than over high-speed bidirectional free space optical laser or radio links that are required when post-processing tasks are performed between a satellite transmitter and a ground receiver. The presence of the post-processing gateway 106 in a satellite QKD system means that each QKD receiver 104 does not require a bidirectional free space optical laser or radio links to the QKD transmitter satellite.

[0066] Thirdly, splitting the post-processing elements from the QKD transmitter 102 in this way allows the post-processing tasks to be performed at any time after the photon transmission by the QKD transmitter 102 to the QKD Receiver.

[0067] The post-processing elements of the QKD transmitter 102 are effectively included within the post-processing gateway 106, such that the post-processing steps can take place between the QKD receiver 104 and the post-processing gateway 106 over the classical communication channel 110. To ensure that the shared entropy 112 at the QKD transmitter 102 is identical to the shared entropy 112 at the post-processing gateway 106, the shared entropy 112 is either pre-stored in each of the QKD transmitter 102 and the post-processing gateway 106, or is shared from the QKD transmitter 102 directly with the post-processing gateway 106, in a standard QKD process. The shared entropy 112 is divided into portions of pre-defined sizes called seeds for seeding the random number generators 114a and 114b. In some examples, the shared entropy 112 includes a plurality of seeds, each seed being used for a different quantum transmission session between the QKD transmitter 102 and the QKD receiver 104. Using a unique seed for each quantum transmissions session such as this improves security. Different seeds may also be used for different QKD receivers 104, where there is more than one QKD receiver 104 in the QKD Network.

[0068] As noted above, the shared entropy 112 including the one or more seeds is either pre-stored at both of the QKD transmitter 102 and the post-processing gateway 106, or is shared between the QKD transmitter 102 and the post-processing gateway 106 in a QKD session. This process is explained in more detail below.

[0069] Figure 3 shows a schematic overview of the QKD system 100 of figure 2 with additional detail and components used to share the shared entropy using a QKD process. The system 100 includes the QKD transmitter 102, the QKD receiver 104, and the postprocessing gateway 106. These components include the same features as indicated above with reference to figure 2. However, instead of the shared entropy 112 being pre-stored on the QKD transmitter 102 and the post-processing gateway 106, as illustrated in figure 2, the QKD transmitter 102 and the post-processing gateway 106 are configured to undertake a QKD process to create and share one or more seeds that form the shared entropy 112. For this purpose, the QKD transmitter includes a Local true entropy source such as a QRNG 133, a post-processing unit 134 and a seed store 136. The post-processing unit 134 is similar to the post-processing units 124 and 128 of the post-processing gateway 106 and the QKD receiver 104, and is defined as a module for performing QKD post-processing, which also requires knowledge of the random number sequence or string used to encode the photons in the FPS 118. The seed store 136 is a memory or storage configured to store the shared entropy 112 once it is created and shared. In this case a local true entropy source such as a QRNG is used to seed the random number generator 114a in the QKD transmitter 102 for the purposes of performing the QKD session with the post-processing gateway 106 for the purpose of generating the shared entropy.

[0070] Similarly, instead ofthe shared entropy 112 being pre-stored in the post-processing gateway 106, the post-processing gateway 106 also includes a seed store 144 and further includes a gateway QKD receiver 138. The gateway QKD receiver 138 includes an optical receiver and detector subsystem 140, and a post-processing unit 142.

[0071] A shared entropy block has been replaced with a seed store database which is used to store the mapping of seeds used for CSPRNG to drive the encoding of photons transmissions to the User QKD Receivers.

[0072] A standard QKD process is performed between the QKD transmitter 102 and the gateway QKD receiver 138 ofthe post-processing gateway 106 to create one or more seeds which are used to form the shared entropy 112 for each ofthe QKD transmitter 102 and the post-processing gateway 106. In particular, the a local true entropy source such as a QRNG 133 is configured to seed the random number generator 114a, to produce a random number sequence or string used to encode photons in the FPS 118 in the QKD transmitter 102. These photons are then transmitted, over an additional quantum channel 146 between the QKD transmitter 102 and the gateway QKD receiver 138. The optical receiver and detector subsystem 140 ofthe gateway QKD receiver 138 is configured to receive and detect these photons. In some examples, the random number generator 114a is not required in the standard QKD process between the QKD transmitter 102 and the post-processing gateway 106, and instead the local true entropy source such as a QRNG 133 may be used directly for producing a random number sequence or string to encode photons in the FPS 118.

[0073] The post-processing unit 142 ofthe gateway QKD receiver 138 in the postprocessing gateway 106 is configured to use a further bidirectional classical communication channel 148 to communicate with the post-processing unit 132 included in the QKD transmitter 102. The post-processing unit 134 ofthe QKD transmitter 102 and the post processing unit 142 ofthe gateway QKD receiver 138 use this further bidirectional classical communication channel 148 to perform QKD post-processing based on the transmitted / received photons, to generate the shared entropy which is used to create one or more seeds. Once these one or more seeds are agreed by the QKD process, they are stored as identical seeds in the seed store 136 in the QKD transmitter 102 and the seed store 144 in the post-processing gateway 106. These stored seeds are then used as the shared entropy as explained above with reference to figure 2.

[0074] In particular, once the post-processing gateway 106 obtains the shared entropy 112 identical to the shared entropy 112 at the QKD transmitter 102, and has exchanged the mapping between the seeds and the Quantum transmissions sessions between the QKD Transmitter 102 and User QKD Receiver 104, the post-processing gateway 106 is able to reconstruct the encoding values used by the QKD transmitter 102, from knowledge of the shared entropy 112 and the use of the identical random number generator 114b. This allows the post-processing gateway 106 to perform post-processing tasks with the User QKD receiver 104, including for example, mutually agreeing a key, independently and on behalf of the QKD transmitter 102. This means that the User QKD receiver 104 is not required to use high-speed bidirectional free space optical or radio links for post-processing tasks with the QKD transmitter 102.

[0075] The security of the sharing of the one or more seeds that form the shared entropy 112 is guaranteed by the use of the standard QKD process between the QKD transmitter 102 and the gateway QKD receiver 138 of the post-processing gateway 106.

[0076] The standard QKD process between the QKD transmitter 102 and the postprocessing gateway 106, used to create and share the one or more seeds forming the shared entropy 112, may occur at different times and may repeat as required.

[0077] In one example, the standard QKD process occurs initially, before QKD sessions between the QKD transmitter 102 and the QKD receiver 104. This means that, by time the QKD transmitter 102 transmits encoded information to the QKD receiver 104, the shared entropy 112 already exists at both of the QKD transmitter 102 and the post-processing gateway 106. This allows the QKD receiver 104 to perform post-processing with the postprocessing gateway 106, to agree a key for example, any time after the encoded information is received from the QKD transmitter 102.

[0078] In a further example, the standard QKD process does not occur before the QKD transmitter 102 transmits encoded information to the QKD receiver 104. In this example, one or more QKD transmission sessions between the QKD transmitter 102 and the user QKD receiver 104 may occur before the post-processing gateway 106 agrees the shared entropy 112 with the QKD transmitter 102. In this example, the random number generator 114a at the QKD transmitter 102 is not seeded with shared entropy 112 (since this has not been agreed prior). Instead, the random number generator 114a is seeded with a seed generated by a local true entropy source such as a QNRG. This seed is stored against a record of the transmission of the encoded photons. The QKD receiver 104 is not able to perform post processing with the post-processing gateway 106 when it receives encoded information from the QKD transmitter, because the shared entropy 112 is not present at the post-processing gateway 106 at this time. As such, the encoded information received at the QKD receiver 104 is stored at the QKD receiver 104. When the standard QKD process is eventually performed between the QKD transmitter 102 and the post-processing gateway 106, the QKD process may, instead of being used to generate shared entropy 112, be used to generate a mutual key between the QKD transmitter 102 and the post-processing gateway 106. This generated key may then be used by the QKD transmitter 102 for encryption e.g. one-time-pad (OTP) encryption to send the seeds used for the quantum transmissions sessions to the postprocessing gateway 106. Post-processing can then occur between the QKD receiver 104, and the post-processing gateway 106, which can use the seeds received from the QKD transmitter 102 for determining the encoding bases and the stored information received at the QKD receiver 104.

[0079] When multiple Quantum transmission sessions have occurred from the QKD transmitter 102 prior to the QKD process between the QKD transmitter 102 and the postprocessing gateway 106, different seeds are generated for each Quantum transmission session. During the QKD process between the QKD transmitter 102 and the post-processing gateway 106, each of these seeds may be sent to the post-processing gateway 106 and may be encrypted using OTP encryption using the keys generated during the QKD process and sent, together with the mapping of seeds with the corresponding Quantum transmission session. In this way, the post-processing gateway 106 can identify seeds used by the random number generator 114a for each Quantum transmission Session, which can be mapped and used in one or more post-processing sessions with the user QKD receiver 104.

[0080] When there is more than one seed agreed by the standard QKD process between the QKD transmitter 102 and the post-processing gateway 106, the QKD transmitter 102 and the post-processing gateway 106 may agree a mapping or ordering of the plurality of seeds that form the shared entropy 112. This ensures that, when multiple seeds are stored in each of the seed stores 136 and 144, the same seed is accessed and used at each of the QKD transmitter 102 and the post-processing gateway 106 for a Quantum transmission Session and corresponding Post Processing session to the QKD receiver 104. It is to be understood that the mapping process may be performed at a later time to the original QKD process to agree the plurality of seeds forming the shared entropy 112. In particular, once the plurality of seeds have been agreed, either the QKD transmitter 102 may decide the mapping or ordering of the seeds with respect to QKD sessions that have occurred with the QKD receiver 104, and inform the post-processing gateway 106 accordingly, orthe post-processing gateway 106 assigns the order of seeds for QKD sessions to the QKD Transmitter 102. In either case, only after the post-processing gateway 106 and the QKD Transmitter 102 have shared the mapping information, the post-processing gateway 106 is able to perform post-processing tasks with the QKD receiver 104. The mapping may be implemented by labelling each seed with an identification number of simply by ordering the seeds in an ordered list, for example.

[0081] Additional QKD processes between the QKD transmitter 102 and the post-processing gateway 106 may occur if further seeds are required. Multiple secret seeds may be shared during the same or distinct QKD processes and are stored in the seed stores 134 and 144 for future use as the shared entropy 112. The seeds are preferably used only once during a Quantum Transmission session with the QKD receiver 104, meaning the same seed shall never be re-used. This improves security but means that new seeds may need to be created after the seeds stored in the seed stores 136 and 144 have been used. The seeding interval, which is the number of bits after which the random number generators 114a and 114b are reseeded by a new seed, is configurable by the system or user. This is determined by trading off the performance / capacity ofthe system against the required level of quantum entropy in the final key.

[0082] Once the standard QKD process between the QKD transmitter 102 and the gateway QKD receiver 138 ofthe post-processing gateway 106 is complete, and the shared entropy 112 is stored at the post-processing gateway 106, the QKD transmitter 102 is not required to communicate further with the post-processing gateway 106 unless further seeds need to be generated.

[0083] It is to be understood that the QRNG is not essential for the purposes ofthe standard QKD process and may be replaced with any other local true random number generator.

[0084] Figure 4 shows a chronological timing table that indicates the sequence of steps of the method of running a QKD session according to various embodiments. The steps are illustrated with respect to the components ofthe QKD system 100, which are responsible for performing said steps. In figure 4, these components include the QKD transmitter 102, the post-processing gateway 106, a first QKD receiver 104a and a second QKD receiver 104b. The first and second QKD receivers 104a and 104b are both ofthe type as described above with reference to the QKD receiver 104. Although figure 4 indicates that there is a first and a second QKD receiver 104a and 104b, it is to be understood that there may one, two, or three or more QKD receivers 104.

[0085] In a first step S1, a QKD session is established for generating and sharing the one or more seeds that form the shared entropy 112 between the QKD transmitter 102 and the gateway QKD receiver 138 ofthe post-processing gateway 106. The result of this step is that the shared entropy 112 is identical at the QKD transmitter 102 and the post-processing gateway 106, such that the post-processing gateway 106 is able to generate an identical sequence of random numbers as the sequence of random numbers generated at the QKD transmitter 102 used for the purpose of encoding photons to be transmitted to the first and second QKD receivers 104a and 104b. As noted above, seeds may be pre-shared or post shared with respect to QKD sessions with the first and / or second QKD receivers 104a, 104b. Both of these approaches are acceptable given that the post-processing gateway 106 knows the seeds used for encoding prior to a respective post-processing session between the postprocessing gateway 106 and the first or second QKD receivers 104a, 104b.

[0086] In a second step S2, preferably after the generation of the shared entropy 112 is completed, the QKD transmitter 102 is configured to transmit encoded photons to the first user QKD receiver 104a in a first Quantum transmission session, over a quantum channel such as the quantum channel 108 as shown in figure 3. The first QKD receiver 104a includes optical receivers and photon detectors as described above with reference to the QKD receiver 104 shown in figure 3. In step S2, the first QKD receiver 104a receives and detects the photons transmitted by the QKD transmitter 102. The first QKD Receiver 104a stores the Ids of the detected photons, the measured polarisations, and the measurement bases used for detection.

[0087] In a third step S3, the QKD transmitter 102 transmits encoded photons to the second QKD receiver 104b in a second Quantum transmission session using a different seed. The second QKD receiver 104b receives and detects the photons transmitted by the QKD transmitter 102. The second QKD Receiver 104b also stores the Ids of the detected photons, the measured polarisations, and the measurement bases used for detection.

[0088] Whilst different seeds are used for each of the Quantum Transmission sessions with the first QKD receiver 104a and the second QKD receiver 104b, the seeds used for the random number generators 114a and 114b may also be updated periodically based upon number of encoded photons per seed bits. The QKD transmitter 102 and the post-processing gateway 1-106 agree / share the start / end index of the seed bits used for each QKD session and the photon encoding rate per second. Multiple seeds may be used for each QKD transmission session.

[0089] In a fourth step S4, the QKD transmitter 102 shares a mapping with the postprocessing gateway 106, wherein the mapping maps each respective Quantum Transmission session of the first and second QKD Receiver with the seed of the shared entropy 112 used for each of these Quantum Transmission sessions. The seed used is different for each of the first Quantum Transmission session and the second Quantum Transmission session. Furthermore, the seed may be unique according to the QKD receiver 104a or 104b involved in the Quantum Transmission session. The mapping indicates which seed the postprocessing gateway 106 should use in post-processing tasks corresponding to each Quantum Transmission session. The mapping can be shared in advance of, or after the Quantum Transmission sessions with the first and second QKD receivers 104a and 104b. The mapping may be sent via a classical communication channel. The mapping provides detail as to what seeds are to be used / have been used for each Quantum Transmission session with each receiver 104a and 104b, such as the start and end position of the shared entropy 112 used as a seed for each transmission session, the random number generator 114a rate of generation, and / or the Photon / Pulse transmission rate, for example.

[0090] In an alternative example, the mapping is not shared directly between the QKD transmitter 102 and the post-processing gateway 106 and is instead shared via or by a centralised scheduling system (not shown in the figures) which collects and shares information between the QKD transmitter 102 and the post-processing gateway 106 as part of the Quantum Transmission Sessions scheduling.

[0091] Although illustrated as coming after the Quantum Transmission sessions in the second and third steps S2 and S3 in figure 4, the fourth step S4 that shares the mapping may be performed earlier than the second and third steps S2 and S3 to allow the first and second QKD receivers 104a and 104b to communicate with the Post Processing Gateway 106 immediately after the respective QKD sessions in the second and third steps S3 and S4. In other words, the post-processing gateway 106 may have prior knowledge of the mapping before the second and third steps S3 and S4.

[0092] In a fifth step S5, once the post-processing gateway 106 has obtained the mapping from the previous step S4, and thus has knowledge of the seeds of the shared entropy 112 applicable to each Quantum Transmission session, the post-processing gateway 106 performs post-processing tasks with the first QKD receiver 104a via a classical communication channel. The post-processing gateway uses the seed indicated by the mapping as corresponding to the first Quantum Transmission session. The post-processing tasks include, sending, from the first QKD receiver 104a to the post-processing gateway 106, one or more of photon time tags and the measurement bases, error correction and privacy amplification relating to the photons detected in the first Quantum Transmission session between the QKD transmitter 102 and the first QKD receiver 104a. The post-processing tasks further include agreeing, based on the photon time tags, the measurement bases, error correction, parameter estimation and privacy amplification, a final first secure key in a bidirectional manner between the first QKD receiver 104a and the post-processing gateway 106.

[0093] In a sixth step S6, the same process as in the previous step S5 is carried out with respect to the second Quantum Transmission session and the second QKD receiver 104b. The post-processing gateway uses the seed indicated by the mapping as corresponding to the second Quantum Transmission session. The post-processing tasks include, sending, from the second QKD receiver 104b to the post-processing gateway 106, one or more of photon time tags and the measurement bases, error correction, parameter estimation and privacy amplification relating to the photons detected in the second Quantum Transmission session between the QKD transmitter 102 and the second QKD receiver 104b. The post-processing tasks further include agreeing, based on the photon time tags, the measurement bases, error correction, parameter estimation and privacy amplification, a final second secure key in a bidirectional manner between the second QKD receiver 104b and the post-processing gateway 106.

[0094] In a seventh step S7, the exclusive OR Boolean logic operation (XOR) of the first final key and the second final key are sent from the post-processing gateway 106 to the second QKD receiver 104b which can then perform the exclusive OR Boolean logic operation (XOR) to know the Final Key of the first QKD Receiver 104a, resulting in a common known shared key between the first and second QKD receivers 104a and 104b.

[0095] The above method as illustrated in figure 4 uses the BB84 QKD protocol. Alternatively, an ARQ19 protocol may be used, as illustrated in figure 5. In the ARQ19 Shifted Post Processing implementation, only raw key bits are agreed between the post-processing gateway 106 and each of the first and second QKD receivers 104a and 104b. Key post processing is performed substantially between the first and second QKD receivers 104a and 104b in a confidential channel and not with the post-processing gateway 106. This means that the post-processing gateway 106 is not privy to the final secure key. The ARQ19 protocol is explained in more detail in granted UK patent no. GB2590064B.

[0096] Figure 5 shows a chronological timing table that indicates the sequence of steps of a second method of running a QKD session according to various embodiments. The steps are illustrated with respect to the components of the QKD system 100, which are responsible for performing said steps. In figure 5, these components include the QKD transmitter 102, the post-processing gateway 106, the first QKD receiver 104a and the second QKD receiver 104b. Although figure 5 indicates that there is a first and a second QKD receiver 104a and 104b, it is to be understood that there may one, two, or three or more QKD receivers 104. These receivers may represent end-user receivers.

[0097] Steps S11, S12, S13 and S14 of figure 5 correspond to method steps S1, S2, S3 and S4 as explained above with reference to figure 4, respectively.

[0098] In a fifth step S15, once the post-processing gateway 106 has obtained the mapping from the previous step S14, and thus has knowledge of the shared entropy 112 and the seeds applicable to each Quantum Transmission session, the post-processing gateway 106 performs partial post-processing tasks (as per the ARQ19 protocol) with the first QKD receiver 104a via a classical communication channel. This results in the agreement of first raw bits between the first QKD receiver 104a and the post-processing gateway 106. The postprocessing gateway uses the seed indicated by the mapping as corresponding to the first Quantum Transmission session. The post-processing tasks include, sending, from the first QKD receiver 104a to the post-processing gateway 106, photon time tags relating to the photons detected in the first Quantum Transmission session between the QKD transmitter 102 and the first QKD receiver 104a. The post-processing gateway 106 sends photon encoding bases and decoy and pol states to the first QKD receiver 104a.

[0099] In step S16, the same process as in the previous step S15 is carried out with respect to the second Quantum Transmission session and the second QKD receiver 104b, to agree on second set of raw bits.

[00100] In step S17, the exclusive OR Boolean logic operation (XOR) of the raw bits are sent from the post-processing gateway 106 to the first and second QKD receivers 104a and 104b respectively.

[00101] In step S18, further post-processing tasks (as per the ARQ19 protocol) are performed between the first and second QKD receivers 104a and 104bto agree on a final secure key. For each receiver, measurement bases, error correction and privacy amplification are shared between the first and second QKD receivers 104a and 104bin order to agree on a final secure key.

[00102] The above methods rely on the post processing gateway 106 having access to a means or configuration for generating identical strings of random numbers given the same seed as the QKD transmitter 102. For example, if a CS-PRNG is utilised at the QKD transmitter 102 for providing random numbers for real-time encoding, then a second CSPRNG is used at the post-processing gateway 106 for performing the post-processing with the QKD receivers 104a and 104b.

[00103] The embodiments explained above can be expanded to define a system of postprocessing gateways 106, each in communication with a plurality of QKD receivers 104. Such an expanded system is shown in figure 6.

[00104] Figure 6 shows a schematic diagram of an expanded system 200 according to various embodiments. The system 200 includes a common QKD transmitter 102, a first network 200a and a second network 200b. The first network 200a includes a first postprocessing gateway 106a and a plurality of QKD receivers 104-1a to 104-1n. The second network 200b includes a second post-processing gateway 106b and a plurality of QKD receivers 104-2a to 104-2n. There may be n QKD receivers in either or both of the first and second network 200a and 200b, whereby n is a positive integer number. The QKD transmitter 102 is configured to transmit encoded photons to each of the plurality of QKD receivers 104-1a to 104-1n of the first network 200a and the plurality of QKD receivers 104-2a to 104-2n of the second network 200b via a plurality of respective quantum channels 208. The QKD transmitter 102 is configured to transmit encoded photons to each of the first and second post-processing gateways 106a and 106b via respective quantum channels 210a and 210b. The QKD transmitter 102 is further configured to communicate with each of the first and second post-processing gateways 106a and 106b via a classical bidirectional communication channel 212a and 212b. The first post-processing gateway is configured to communicate with each of the plurality of QKD receivers 104-1ato 104-1n via a plurality of classical bidirectional communication channels 214a within the first network 200a. The second post-processing gateway 106b is configured to communicate with each of the plurality of QKD receivers 104-2a to 104-2n via a plurality of classical bidirectional communication channels 214b. With this configuration, the common QKD transmitter 102 is not required to communicate with the plurality of QKD receivers 104-1 a to 104-1n in the first network 200a or the plurality of QKD receivers 104-2ato 104-2n in the second network 200b over classical communication channels to perform post-processing tasks, because the first and second post-processing gateways 106a and 106b are configured to perform these post-processing tasks for the receivers in the first and second networks 200a and 200b respectively.

[00105] The components of the system 200 have the same configuration and include the same features as the corresponding components explained above with reference to figures 1 to 5.

[00106] The first post-processing gateway 106a includes the shared entropy 112 as present in the QKD transmitter 102. As explained with reference to figures 3 to 5 above, the QKD transmitter 102 undertakes a standard QKD process with the first post-processing gateway 106a to generate the shared entropy 112. The shared entropy 112 includes a plurality of seeds, wherein a different seed may be used for transmitting encoded photons to each QKD receiver and / or each network. The seed may also be different for each Quantum Transmission session performed by the QKD transmitter 102. As such, multiple seeds may be stored and shared in the standard QKD process by the QKD transmitter.

[00107] In figure 6, there are two post-processing gateways 106a and 106b. The QKD transmitter 102 thus undertakes a standard QKD process for both the first and the second post-processing gateways 106a and 106b. 112. With respect to the second post-processing gateway 106b, a similar QKD process is undertaken between the QKD transmitter 102 and the second post-processing gateway 106b in order to generate the shared entropy 112. In this way, the first post-processing gateway 106a can perform post-processing with the plurality of QKD receivers 104-1 a to 104-1n, using different seeds, on behalf and independently of the QKD transmitter 102. The second post-processing gateway 106b can perform postprocessing with the plurality of QKD receivers 104-2a to 104-2n, using different seeds, on behalf and independently of the QKD transmitter 102. The shared entropy 112 agreed by the second post-processing gateway 106b and the QKD transmitter 102 may be different from the shared entropy 112 agreed between the first post-processing gateway 106a and the QKD transmitter 102. The QKD transmitter 102 shares a first mapping 250a to the first postprocessing gateway 106a and a second mapping 250b to the second post-processing gateway. The mappings 250a and 250b provide the post-processing gateways 106a and 106b with details concerning Quantum Transmission sessions with the QKD receivers 104-1 and 104-2 and the seeds used forthose respective sessions, so that the post-processing gateways 106a and 106b can perform post-processing using the correct seed.

[00108] Splitting the expanded system into a first network 200a and a second network 200b allows each network to contain one or more post-processing gateways to manage the shared entropy and the seeds included therein for post-processing tasks of their own respective networks. It is to be understood that there may be more than one post-processing gateway per network, and there may be more than two networks. Furthermore, each network may have different configurations and parameters concerning post-processing tasks.

[00109] The embodiments explained above enable simplification of QKD receivers by removing the need for a bidirectional communication between a QKD transmitter and the receiver. In satellite systems, wherein the QKD transmitter is a satellite, this means that the need for space-to-ground classical communication links is removed, significantly reducing the complexity of user QKD receivers.

[00110] Having only a post-processing gateway communicate bidirectionally with the QKD receiver is more secure since the post-processing gateway can be contained within a separate secure boundary if desired. Since all of the information regarding received Photon Ids, Received Measurement Bases and the like are only shared between QKD receiver and post processing gateway, the QKD transmitter does not require this information.

[00111] The level of trust required for the QKD transmitter can thus be reduced if the postprocessing channel is confidential.

[00112] The presence of the post-processing gateway introduces flexibility into QKD network topology, supporting central post-processing gateways in star-network topologies for example.

[00113] Further examples and alternatives relating to the embodiments described above will now be set out below.

[00114] In an example, the QKD system 100 or 200 is a satellite system. In this example, the post-processing gateway 106 can be located on the ground, such that the QKD Receiver 104 or is configured to communicate with the post-processing gateway 106 on the ground using the classical communication channel 110. In this example, the classical communication channel may be a terrestrial classical channel such as fibre, which thus eliminates the need for more complex communication channels with less bandwidth, such as bidirectional classical Laser communication channels between the QKD transmitter 102 and the QKD receiver 104 in the case of Space to Ground QKD.

[00115] The QKD receiver explained above may be a user QKD receiver, whereby a user may use the user QKD receiver to partake in a QKD session with the QKD transmitter. In this case, the post-processing gateway may be secure and operated by a separate party such as a provider. Removing the bidirectional classical communication functionality between the QKD transmitter and the user QKD receiver makes the QKD transmitter more secure, since only authorised classical communication may occur between the post-processing gateway and the QKD transmitter.

[00116] The post-processing classical communication channel between the post processing gateway and any QKD receiver may also be kept confidential from the QKD Transmitter through independent encryption, which will allow the level of trust required for the QKD transmitter to be reduced. This requires that the communication channel be encrypted as well as authenticated as in conventional QKD.

[00117] One post-processing gateway may service multiple user QKD receivers. For example, the system may form a star network topology whereby one or more post-processing gateways service a plurality of user QKD receivers.

[00118] Since the post-processing gateway is the only component of the system that is able to communicate via a bidirectional classical communication channel with the QKD transmitter, the gateway QKD receiver of the post processing gateway could be designed for higher performance, with a much larger aperture telescope for example, to allow significant quantum sources or seed entropy to be shared supporting several user QKD receivers.

[00119] The quantum source is In some examples, a CSPRNG is not necessary. Furthermore, although a QRNG is described with respect to the standard QKD process between the QKD transmitter and the post-processing gateway, any other random source may be used, such as a true entropy source.

[00120] Post-processing tasks include for example, generating a mutually agreed secure key by undertaking sifting, error correction and / or privacy amplification.

[00121] In the QKD process or session, the QKD transmitter transmits encoded photons to the QKD receiver, whereby the QKD receiver stores detected photon identifications, measurement bases and intensity.

[00122] In the embodiments described above the system is a quantum key distribution system. In other examples, other cryptographic items could be distributed / delivered in addition to, or as an alternative to, encryption keys. Examples of such other cryptographic items include cryptographic tokens, cryptographic coins, or value transfers.

[00123] In the described embodiments of the invention parts of the system may be implemented as a form of a computing and / or electronic device. Such a device may comprise one or more processors which may be microprocessors, controllers or any other suitable type of processors for processing computer executable instructions to control the operation of the device in order to gather and record routing information. In some examples, for example where a system on a chip architecture is used, the processors may include one or more fixed function blocks (also referred to as accelerators) which implement a part of the method in hardware (rather than software or firmware). Platform software comprising an operating system or any other suitable platform software may be provided at the computing-based device to enable application software to be executed on the device.

[00124] Various functions described herein can be implemented in hardware, software, or any combination thereof. If implemented in software, the functions can be stored on or transmitted over as one or more instructions or code on a computer-readable medium. Computer-readable media may include, for example, computer-readable storage media. Computer-readable storage media may include volatile or non-volatile, removable or non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. A computer-readable storage media can be any available storage media that may be accessed by a computer. By way of example, and not limitation, such computer-readable storage media may comprise RAM, ROM, EEPROM, flash memory or other memory devices, CD-ROM or other optical disc storage, magnetic disc storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Disc and disk, as used herein, include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and blu-ray disc (BD). Further, a propagated signal is not included within the scope of computer-readable storage media. Computer-readable media also includes communication media including any medium that facilitates transfer of a computer program from one place to another. A connection, for instance, can be a communication medium. For example, if the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of communication medium. Combinations of the above should also be included within the scope of computer-readable media.

[00125] Alternatively, or in addition, the functionality described herein can be performed, at least in part, by one or more hardware logic components. For example, and without limitation, hardware logic components that can be used may include Field-programmable Gate Arrays (FPGAs), Program-specific Integrated Circuits (ASICs), Program-specific Standard Products (ASSPs), System-on-a-chip systems (SOCs), Complex Programmable Logic Devices (CPLDs), etc.

[00126] Although illustrated as a single system, it is to be understood that a system may be a distributed system.

[00127] It will be understood that the benefits and advantages described above may relate to one embodiment or may relate to several embodiments. The embodiments are not limited to those that solve any or all of the stated problems orthose that have any or all of the stated benefits and advantages. Variants should be considered to be included into the scope of the invention.

[00128] Any reference to 'an' item refers to one or more of those items. The term 'comprising' is used herein to mean including the method steps or elements identified, but that such steps or elements do not comprise an exclusive list and a method or apparatus may contain additional steps or elements.

[00129] As used herein, the terms "component" and "system" are intended to encompass computer-readable data storage that is configured with computer-executable instructions that cause certain functionality to be performed when executed by a processor. The computerexecutable instructions may include a routine, a function, or the like. It is also to be understood that a component or system may be localized on a single device or distributed across several devices.

[00130] Further, as used herein, the term "exemplary" is intended to mean "serving as an illustration or example of something".

[00131] Further, to the extent that the term "includes" is used in either the detailed description or the claims, such term is intended to be inclusive in a manner similar to the term "comprising" as "comprising" is interpreted when employed as a transitional word in a claim.

[00132] The figures illustrate exemplary methods. While the methods are shown and described as being a series of acts that are performed in a particular sequence, it is to be understood and appreciated that the methods are not limited by the order of the sequence. For example, some acts can occur in a different order than what is described herein. In addition, an act can occur concurrently with another act. Further, in some instances, not all acts may be required to implement a method described herein.

[00133] Moreover, the acts described herein may comprise computer-executable instructions that can be implemented by one or more processors and / or stored on a computer-readable medium or media. The computer-executable instructions can include routines, sub-routines, programs, threads of execution, and / or the like. Still further, results of acts of the methods can be stored in a computer-readable medium, displayed on a display device, and / or the like.

[00134] The order of the steps of the methods described herein is exemplary, but the steps may be carried out in any suitable order, or simultaneously where appropriate. Additionally, steps may be added or substituted in, or individual steps may be deleted from any of the methods without departing from the subject matter described herein. Aspects of any of the examples described above may be combined with aspects of any of the other examples described to form further examples without losing the effect sought.

[00135] It will be understood that the above description of preferred embodiments is given by way of example only and that various modifications may be made by those skilled in the art. What has been described above includes examples of one or more embodiments. It is, of course, not possible to describe every conceivable modification and alteration of the above 5 devices or methods for purposes of describing the aforementioned aspects, but one of ordinary skill in the art can recognize that many further modifications and permutations of various aspects are possible. 11 09 24

Claims

1. A quantum key distribution, QKD, system comprising:a QKD transmitter configured to transmit photons to first and second user QKD receivers, respectively, via first and second quantum communication channels, wherein the photons are encoded based, respectively, on first and second seeds stored by the QKD transmitter;the first user QKD receiver configured to receive and detect the photons transmitted from the QKD transmitter over the first quantum communication channel;the second user QKD receiver configured to receive and detect the photons transmitted from the QKD transmitter over the second quantum communication channel;a post-processing gateway, configured to perform partial post-processing QKD taskswith the first and second user QKD receiver over respective bidirectional classical communication channels between the post-processing gateway and the first and second user QKD receivers, based on the photons detected by the first and second user QKD receivers and, respectively, on first and second seeds stored by the post-processing gateway, wherein the partial post-processing QKD tasks produce a final set of raw bits;wherein, respectively, the first and second seeds stored by the QKD transmitter and the first and second seeds stored by the post-processing gateway are identical, such that the post-processing gateway and the first and second user QKD receivers are configured to perform the post-processing QKD tasks independently of the QKD transmitter,wherein the first and second user QKD receivers are further configured to perform further post-processing tasks between each other to agree a final secure key, independently of the post-processing gateway, wherein the further post-processing tasks comprise sharing measurement bases used to detect the photons by the first and second QKD receivers, error correction and / or privacy amplification between the first and second user QKD receivers2. The QKD system of claim 1, wherein the first and second user QKD receivers are configured to perform the further post-processing tasks over a confidential channel between the first and second user QKD receivers.

3. The system of any preceding claim wherein the partial post-processing QKD tasks that the post-processing gateway is configured to perform include an agreement of a first set of raw bits with the first user QKD receiver and an agreement of a second set of raw bits with the second user QKD receiver, wherein the final set of bits are produced by an exclusive OR Boolean logic operation, XOR, of the first and second set of raw bits.

4. The QKD system of any preceding claim, wherein the post-processing gateway is located physically separately from the QKD transmitter.

5. The QKD system of claim 4, wherein the QKD transmitter is a satellite.

6. The QKD system of any preceding claim wherein the post-processing gateway isground-based.

7. The QKD system of claim 6, wherein the respective bidirectional classical communication channels between the post-processing gateway and the first and second user QKD receivers include a physical communication link.

8. The QKD system of any preceding claim, wherein the QKD transmitter is configured to encode the photons to transmit to the first and the second user QKD receivers based on a sequence of random numbers generated by the random number generator seeded, respectively, by the first and second seeds stored at the QKD transmitter, and wherein the post-processing gateway is configured to generate an identical sequence of random numbers for use in the post-processing QKD tasks using an identical random number generator seeded by the first and second seeds stored at the post-processing gateway.

9. The QKD system of any preceding claim, wherein the QKD transmitter stores a plurality of seeds, and the post-processing gateway stores a corresponding plurality of identical seeds, wherein each of the plurality of seeds are unique, and wherein the QKD transmitter and the post-processing gateway are configured to use a different seed and corresponding identical seed respectively for each of a plurality of Quantum Transmission sessions with each of the User QKD receivers.

10. The QKD system of claim 9, wherein the QKD transmitter further stores a mapping comprising data indicative the plurality of Quantum Transmission sessions and the seeds of the plurality of seeds used for each of the plurality of Quantum Transmission Sessions, wherein the QKD transmitter is configured to send the mapping to the post-processing gateway.

11. The QKD system of any preceding claim, wherein the post-processing gateway further comprises a gateway QKD receiver, wherein the gateway QKD receiver is coupled to the QKD transmitter via an additional quantum channel and an additional bidirectional classical communication channel, wherein the QKD transmitter and the gateway QKD receiver are configured to either:perform a QKD process to generate the seeds stored by the QKD transmitter and the post-processing gateway; orperform a QKD process to generate a mutual key between the QKD transmitter and the post-processing gateway, wherein the QKD transmitter is configured to:use the mutual key to encrypt pre-stored seeds stored at the QKD transmitter; and send the encrypted pre-stored seeds to the post-processing gateway.

12. The QKD system of claim 11, wherein the QKD transmitter is configured to use the mutual key to encrypt the pre-stored keys using one-time-pad, OTP, encryption.

13. A QKD post-processing gateway comprising:a gateway QKD receiver for bidirectionally communicating with an external QKD transmitter;a post-processing unit for bidirectionally communicating with an external User QKD receiver; anda memory module;wherein the gateway QKD receiver is configured to:receive quantum information from the QKD transmitter via a first quantum communication channel;based on the quantum information, bidirectionally communicate with the QKD transmitter via a first classical communication channel to generate and / or obtain a shared seed from the QKD transmitter; andstore the shared seed in the memory module;wherein the post-processing unit is further configured to:use the shared seed to perform post-processing QKD tasks with the User QKD receiver over an additional bidirectional classical communication channel between the post-processing gateway and the User QKD receiver, such that the post-processing tasks are performed independently of the QKD transmitter.

14. The QKD post-processing gateway of claim 13, wherein the post-processing unit is configured to use the shared seed by:seeding a random number generator with the shared seed to produce a sequence of random numbers; andsubsequently using the sequence of random numbers to perform post-processing tasks with the User QKD receiver.

15. The post-processing gateway of claim 13 or 14, wherein the gateway QKD receiver comprises:an optical receiver and photon detection unit configured to detect photons transmitted over the first quantum communication channel by the QKD transmitter; anda gateway QKD receiver post-processing unit configured to bidirectionally communicate with the QKD transmitter via the first classical communication channel to generate and / or obtain the shared seed with the QKD transmitter.

16. The post-processing gateway of any of claims 14 to 15, wherein the post-processing unit comprises:a processor; anda classical communication transceiver;wherein the processor is configured to:obtain the shared seed from the memory module;seed the random-number generator with the shared seed to generate a sequence of random numbers; andvia the classical communication transceiver, perform post-processing QKD tasks with the User QKD receiver over the additional bidirectional classical communication channel between the post-processing gateway and the User QKD receiver, such that the postprocessing tasks are performed independently of the QKD transmitter.

17. The post-processing gateway of any of claims 12 to 15, wherein the post-processing gateway is ground-based.

18. The post-processing gateway of any of claims 12 to 16, further configured to generate and / or obtain a plurality of shared seeds with / from the QKD transmitter.

19. The post-processing gateway of claim 18, further configured to receive and store a mapping including data indicative of the plurality of shared seeds against one or more Quantum Transmission sessions between the QKD transmitter and the User QKD receiver in which the shared seeds were used; andwherein the post-processing gateway is configured to:determine a present Post processing session and corresponding Quantum Transmission Session from communication with the User QKD receiver;look up the present Quantum Transmission session in the mapping to determine a corresponding present shared seed; anduse the present shared seed to perform post-processing QKD tasks with the User QKD receiver over the additional bidirectional classical communication channel between the postprocessing gateway and the User QKD receiver, such that the post-processing tasks are performed independently of the QKD transmitter.

20. A QKD transmitter for transmitting an encoded stream of photons to one or more User QKD receivers in one or more Quantum transmission sessions; the QKD transmitter including:a faint pulse source and encoding unit;a memory module configured to store one or more seeds for seeding a random number generator; anda QKD transmitter post processing unit;wherein the faint pulse source and encoding unit is configured to:obtain a seed from the one or more seeds from the memory module;generate a sequence of random numbers by seeding a random number generator with the seed;encode a series of photons using the sequence of random numbers; andtransmit the encoded series of photons to one or more User QKD receivers via a first quantum communication channel;wherein the QKD transmitter is configured to either:generate the one or more seeds via a QKD process with a post-processing gateway whereby:the faint pulse source and encoding unit is further configured to transmit a series of separately encoded photons to the post-processing gateway in a QKD process with the postprocessing gateway via a second quantum communication channel;the QKD transmitter post processing unit is configured to perform post-processing QKD tasks with the post-processing gateway over a bidirectional classical communication channel between the QKD transmitter and the post-processing gateway, to generate the one or more seeds with the post-processing gateway;or:generate and store the one or more seeds at the QKD transmitter;generate a mutual key via a QKD process with the post-processing gateway whereby: the faint pulse source and encoding unit is further configured to transmit a series of separately encoded photons to the post-processing gateway in a QKD process with the postprocessing gateway via a second quantum communication channel; andthe QKD transmitter post processing unit is configured to perform post-processing QKD tasks with the post-processing gateway over a bidirectional classical communication channel between the QKD transmitter and the post-processing gateway, to generate the mutual key with the post-processing gateway;encrypt the one or more seeds using the mutual key; andsend the encrypted one or more seeds to the post-processing gateway.

21. The QKD transmitter of claim 20 further configured to send a mapping to the postprocessing gateway, the mapping indicating an ordering of one or more seeds to be used for one or more respective Quantum transmission sessions between the QKD transmitter and user QKD receiver.

22. The QKD transmitter of claims 20 or 21 wherein the QKD transmitter is a satellite.

23. A method of performing quantum key distribution, QKD, the method comprising:transmitting, by a QKD transmitter, photons to first and second user QKD receivers in a quantum transmission session, wherein the photons are encoded, respectively, based on first and second seeds stored by the QKD transmitter;receiving, at the first user QKD receiver, the photons transmitted from the QKD transmitter;receiving, at the second user QKD receiver, the photons transmitted from the QKD transmitter;performing, at a post-processing gateway, partial post-processing QKD tasks with the first and the second QKD over respective bidirectional classical communication channels between the post-processing gateway and the first and the second user QKD receivers, based on the photons detected by the first and second user QKD receivers and, respectively, on first and second seeds stored by the post-processing gateway, wherein the partial postprocessing QKD tasks produce a final set of raw bits;wherein, respectively, the first and second seeds stored by the QKD transmitter and the first and the second seeds stored by the post-processing gateway are identical, such that performing the post-processing QKD tasks occurs independently of the QKD transmitter;performing, between the first and second user QKD receivers, post-processing tasks to agree a final secure key, independently of the post-processing gateway, wherein the further post-processing tasks comprise sharing measurement bases used to detect the photons by the first and second QKD receivers, error correction and / or privacy amplification between the first and second user QKD receivers.24 The method of claim 22, wherein the method further comprises performing, between the first and second user QKD receivers, further post-processing tasks over a confidential channel between the first and second user QKD receivers.

25. The method of any of claims 22 or 23, wherein performing the partial post-processing QKD tasks includes agreeing a first set of raw bits with the first user QKD receiver and agreeing of a second set of raw bits with the second user QKD receiver, wherein the final setof bits are produced by an exclusive OR Boolean logic operation, XOR, of the first and second set of raw bits.

26. The method of claim 23, wherein the quantum transmission session and postprocessing are performed according to the ARQ19 protocol.

27. The method of any of claims 23 to 26, further comprising:pre-storing each seed at the QKD transmitter and the post-processing gateway.

28. The method of any of claims any of claims 23 to 26, further comprising:generating each seed via a QKD process between the QKD transmitter and the postprocessing gateway by:transmitting, from the QKD transmitter, a series of separately encoded photons to the post-processing gateway in a quantum transmission session between the QKD transmitter and the post-processing gateway;performing post-processing QKD tasks between the QKD transmitter and the postprocessing gateway, to generate each seed with the post-processing gateway; andstoring eachseed at both the QKD transmitter and the post-processing gateway.

29. The method of any of claims 23 to 26, further comprising:generating and storing each seed at the QKD transmitter;generating a mutual key by:transmitting, from the QKD transmitter, a series of separately encoded photons to the post-processing gateway in a quantum transmission session between the QKD transmitter and the post-processing gateway;performing post-processing QKD tasks between the QKD transmitter and the postprocessing gateway, to generate the mutual key between the QKD transmitter and the postprocessing gateway;encrypting, at the QKD transmitter, each seed using the mutual key; and sending the encrypted seed to the post-processing gateway.

30. The method of any of claims 23 to 29, wherein there is a plurality of seeds.

31. The method of claim 30, further comprising:transmitting, by the QKD transmitter, photons to each user QKD receiver in a plurality of quantum transmission sessions, wherein the photons of each quantum transmission session are encoded using a unique seed of a plurality of seeds;1015storing, by the QKD transmitter, a mapping that indicates the unique seed used for encoding the photons for each transmission session; andsending mapping to post-processing gateway.

32. The method of claim 31, comprising:sending the mapping to the post-processing gateway before or after the plurality of quantum transmission sessions between the QKD transmitter and each user QKD receiver.11 09 24

Citation Information

Patent Citations

  • Quantum cryptography apparatus

    US20100293380A1

  • Quantum key distribution method and apparatus

    US20130163759A1

  • Improvements to QKD methods

    WO2021028227A1