Secure distribution of entropy

By employing a quantum entropy generation unit and secure communication channels, the patent addresses the challenge of distributing reliable entropy, ensuring secure and robust cryptographic key generation and communication across a network.

JP2025108453AActive Publication Date: 2025-07-23ORACLE INT CORP
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2025051399
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-02-25
Filing Date
2025-03-26
Publication Date
2025-07-23
Estimated Expiration
2041-03-24

AI Technical Summary

Technical Problem

Existing cryptographic systems face challenges in generating and securely distributing truly random entropy due to the lack of reliable entropy sources and the vulnerability of entropy to tampering during transmission, leading to weak cryptographic keys prone to collisions and side-channel attacks.

Method used

The use of a quantum entropy generation unit to generate high-quality entropy, which is securely transmitted via a direct connection to a first host, and further distributed to other hosts through a secure communication channel established using a portion of the entropy, enabling secure key exchanges and communication channels.

Benefits of technology

Ensures the secure distribution of high-quality entropy across a network, allowing hosts to generate robust cryptographic keys and secure communication channels without direct connection to the entropy source, thereby enhancing security and resilience against tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025108453000001_ABST
    Figure 2025108453000001_ABST
Patent Text Reader

Abstract

To provide a system and a method for securing and distributing an entropy in a distribution environment.SOLUTION: One of computer systems that perform a communication between computer systems is directly connected to a quantum entropy generation part via a link where an entropy is not interfered or exposed to a risk. A true random entropy generated by the faithful entropy generation part uses a secure communication channel provided by using one part of the entropy is used, and is securely transmitted to the other computer system that performs the communication with the computer system. By such a distribution technique, the other computer system can use such an entropy to be generated by a faithful entropy source that cannot be originally used.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross - Reference to Related Applications This international patent application claims priority based on U.S. Patent Application No. 17 / 185,646, titled "Secure Distribution Of Entropy", filed on February 25, 2021, and incorporates by reference all of its disclosure content herein for all purposes.

Background Art

[0002] Background Entropy (also referred to as entropy information) is utilized for various different purposes. For example, entropy is extremely important for cryptographic systems that utilize entropy to generate cryptographic keys for various purposes. However, the trust placed in these cryptographic systems and the keys generated by these systems can be limited by the trustworthiness of the entropy quality that these systems use to generate the keys. First, it is difficult to generate truly random entropy or to find a reliable source capable of generating truly random entropy. Even if such a source is found, it is a significant challenge to transmit entropy from the entropy source to a computer (for example, by a cryptographic system for generating a cryptographic key) while ensuring that the entropy has not been tampered with. If the entropy is tampered with and of low quality, the cryptographic key becomes weak or vulnerable, and is prone to various collisions and side - channel attacks. As a result, most computing devices and applications (for example, programs, virtual machines) are unable to utilize truly random and high - quality entropy.

Summary of the Invention

Means for Solving the Problems

[0003] Summary This disclosure generally relates to secure distribution of entropy. The entropy to be distributed can be quantum entropy generated by a quantum entropy generation unit or source. By the teachings described herein, using a secure communication channel provided using a portion of the entropy, truly random entropy generated by a trusted entropy generation unit can be securely transmitted between computer systems or hosts. This distribution technique enables computer systems and hosts to utilize such entropy generated by a trusted entropy source that would otherwise not be available. Various embodiments are described herein, including methods, systems, programs, code, or instructions executable by one or more processors, and non-transitory computer-readable storage media storing the same.

[0004] In certain embodiments, the method includes a first host receiving entropy information from an entropy source and establishing a communication channel between the first host and a second host using one or more cryptographic keys, all of the one or more cryptographic keys being generated using at least a portion of the entropy information, and further including transmitting another portion of the entropy information from the first host to the second host using the communication channel established between the first host and the second host.

[0005] In yet another embodiment, the communication channel is a second communication channel, and the method further includes establishing a first communication channel between the first host and the second host based on a first set consisting of one or more cryptographic keys generated by the first host using a first portion of the entropy information and a second set consisting of one or more cryptographic keys generated by the second host, and transmitting a second portion of the entropy information from the first host to the second host using the first communication channel.

[0006] ​In yet another embodiment, the step of establishing the second communication channel includes the first host generating a third set of one or more encryption keys using a third portion of the entropy information, the second host generating a fourth set of one or more encryption keys using a first portion of the second portion of the entropy information received by the second host from the first host, and establishing a second communication channel between the first host and the second host based on the third set of one or more encryption keys and the fourth set of one or more encryption keys.

[0007] In yet another embodiment, the method further includes determining that a condition associated with the second communication channel is satisfied, and in response to determining that the condition is satisfied, the first host regenerating a new first set of one or more encryption keys using a fifth portion of the entropy information, the second host regenerating a new second set of one or more encryption keys using a second portion of the second portion of the entropy information received from the first host, and establishing a new communication channel between the first host and the second host based on the new first set of one or more encryption keys and the new second set of one or more encryption keys.

[0008] In yet another embodiment, the step of determining that a condition associated with the second communication channel is satisfied includes determining that a specific period of time has elapsed.

[0009] In yet another embodiment, the step of determining that a condition associated with the second communication channel is satisfied includes determining that a specific number of packets have been exchanged between the first host and the second host.

[0010] In yet another embodiment, the second portion of the entropy information includes "N" bits, and the second host generates a fourth set of one or more encryption keys based on the "N" bits.

[0011] In yet another embodiment, the step of establishing the first communication channel includes performing a first Diffie-Hellman key exchange using a first set consisting of one or more cryptographic keys and a second set consisting of one or more cryptographic keys, and establishing the second communication channel includes performing a second Diffie-Hellman key exchange using a third set consisting of one or more cryptographic keys and a fourth set consisting of one or more cryptographic keys.

[0012] In yet another embodiment, the first Diffie-Hellman key exchange is a first elliptic curve Diffie-Hellman key exchange, and the second Diffie-Hellman key exchange is a second elliptic curve Diffie-Hellman key exchange.

[0013] In yet another embodiment, the entropy source is a quantum entropy generation unit, and the entropy information is quantum entropy.

[0014] In yet another embodiment, the first host is hosted by a first host machine, and the second host is hosted by a second host machine.

[0015] In yet another embodiment, the step of receiving entropy information includes the first host receiving entropy information from the entropy source as a stream of information. 。

[0016] Yet another embodiment is directed to a non-transitory computer-readable storage medium storing computer-executable program instructions that, when executed by a processing device of a computing device, cause the computing device to perform the above-described method.

[0017] Another embodiment is directed to an apparatus comprising means for performing the steps of the above method.

[0018] Yet another embodiment is a computer program product including computer instructions that, when executed by a processor, perform the steps of the above method, and is directed to a computer program product.

[0019] The above features and embodiments, together with other features and embodiments, will become more apparent by referring to the following specification, claims, and attached drawings.

Brief Description of the Drawings

[0020]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

[0021] Detailed Description In the following description, for the sake of convenience of explanation, specific details are described in order to enable a full understanding of a particular embodiment. However, it will be apparent that various embodiments can be implemented without these specific details. The accompanying drawings and description are not limiting. The word "exemplary" as used herein means "serving as an example, a specific example". None of the embodiments or designs described as "exemplary" herein should necessarily be construed as being more preferred or advantageous than other embodiments or designs.

[0022] The present disclosure generally relates to the secure distribution of entropy. The entropy to be distributed can be quantum entropy generated by a quantum entropy generation unit or source. By the teachings described herein, true random entropy generated by a reliable entropy generation unit can be securely transmitted between computer systems or hosts using a secure communication channel provided using a portion of the entropy. This distribution technique enables computer systems and hosts to utilize such entropy generated by a reliable entropy source that would otherwise not be available.

[0023] In certain embodiments, a novel distribution technique for securely transmitting entropy from an entropy source to a computer system directly connected to the entropy source and then further securely transmitting the entropy from this computer system to other computer systems in a distributed environment that may not be directly connected to the entropy source is described. In certain embodiments, a computer system directly connected to an entropy source securely receives entropy information from the entropy source via a secure direct connection. The computer system that has received entropy from the entropy source then transmits or distributes the received entropy or a portion thereof to one or more other computer systems that are communicatively coupled to the computer system but may not be directly connected to the entropy source. The transmission of entropy from the directly connected computer system to other computer systems that may not be directly connected to the entropy source is performed over a secure communication channel. The secure communication channel is established using a portion of the entropy generated by the entropy source and received by the computer system directly connected to the entropy source. And a computer system that has received entropy generated by an entropy source from another computer system may further distribute the entropy or a portion thereof to yet other computer systems via the secure communication channel established using a portion of the received entropy using the method described in this disclosure.

[0024] In certain embodiments, a novel distribution technique for securely transmitting entropy from an entropy source to a host directly connected to the entropy source and then further securely transmitting the entropy from this host to other hosts in a distributed environment that may not be directly connected to the entropy source is described. The host may be a virtual machine computing instance or a bare metal computing instance. In certain embodiments, the host directly connected to the entropy source securely receives entropy information from the entropy source via a secure direct connection. The host that receives entropy from the entropy source then transmits or distributes the received entropy or a portion thereof to one or more other hosts that are communicatively coupled to the first host but are not directly connected to the entropy source. The transmission of entropy from the directly connected host to other hosts that may not be directly connected to the entropy source is performed over a secure communication channel. The secure communication channel is established using a portion of the entropy generated by the entropy source and received by the host directly connected to the entropy source. And a host that receives entropy generated by the entropy source from another host may further distribute the entropy or a portion thereof to other hosts via the secure communication channel established using a portion of the received entropy using the method described in this disclosure.

[0025] For the sake of convenience of this disclosure, the terms "entropy" and "entropy information" are used interchangeably. Various embodiments are described herein that include methods, systems, programs, code, or instructions executable by one or more processors, stored on a non-transitory computer-readable storage medium.

[0026] FIG. 1 is a simplified block diagram of a distributed environment 100 according to some embodiments. . The distributed environment 100 may include a plurality of computer systems communicatively coupled to each other via one or more communication links on one or more communication networks. The distributed environment 100 of FIG. 1 includes a computer system A 110, a computer system B 120, a computer system C 130, a computer system D 140, and a quantum entropy generation unit 105.

[0027] The distributed environment shown in FIG. 1 is merely illustrative and does not unnecessarily limit the scope of the claimed embodiments. Many variations, alternative examples, and modifications are possible. For example, in some embodiments, the distributed environment 100 may have more computer systems or components than shown in FIG. 1, may have fewer computer systems or components than shown in FIG. 1, and may have computer systems and communication lines in a different configuration or arrangement.

[0028] Each of the computer systems shown in FIG. 1 may include computing resources (e.g., one or more processors or CPUs), memory resources (e.g., system memory, non-volatile memory), and network resources (e.g., may include a NIC (Network Interface Card)). The computer system may communicate with one or more other computer systems on one or more communication networks using these network resources. Communication networks include, for example, the Internet, intranet, extranet, LAN (Local Area Network), WAN (Wide Area Network), and other networks that facilitate communication, as well as combinations thereof. Communication may be performed via a wired link or a wireless link using one or more wired communication protocols or wireless communication protocols.

[0029] One or more of the computer systems shown in FIG. 1 may execute one or more applications that utilize entropy information. For example, a computer system may execute an application that generates one or more cryptographic keys, and entropy information is used to generate these keys. The cryptographic keys can be used for different purposes, such as securing stored information, enabling communication with other computer systems, and authenticating / authorizing users. The entropy information used for these purposes would need to be of high quality and truly random entropy. A computer system would not be able to generate such high-quality entropy information on its own.

[0030] There are various types of entropy generation units that can generate different qualities of entropy. Quantum entropy is considered to be high-quality and truly random entropy due to the quantum physics involved in its generation. Therefore, a quantum entropy generation unit can generate high-quality entropy. One such quantum entropy generation unit 105 is shown in FIG. 1. The quantum entropy generation unit 105 is a reliable entropy source for the various computer systems shown in FIG. 1. A specific embodiment of the quantum entropy generation unit 105 is shown in FIG. 2 and will be described later. Although the quantum entropy generation unit is shown in FIG. 5, in other embodiments, other entropy generation units may also be used. Thus, an embodiment may include any suitable reliable entropy source.

[0031] In the embodiment shown in FIG. 1, computer systems A 110 and C 130 are directly connected to the quantum entropy generation unit 105 via links 111 and 131. For example, computer system A 110 may be physically located near the quantum entropy generation unit 105 and may be directly connected to the quantum entropy generation unit 105 by wire. Whether through a direct wired circuit or through another fully reliable communication channel, computer system A 110 is protected from entropy being disrupted or exposed to risks. Without any issues, it is possible to receive entropy from a reliable entropy generation unit. Similarly, the computer system C 130 may be physically located near the quantum entropy generation unit 105 and may be directly connected to the quantum entropy generation unit 105 by wire, enabling it to receive entropy from a reliable entropy generation unit without the entropy being interfered with or exposed to danger.

[0032] Via links 111 and 131, the quantum entropy generated by the quantum entropy generation unit 105 can be transmitted securely and safely to the computer systems A 110 and C 130. In certain embodiments, a secure channel may be implemented using an insulated RS-232 serial cable. This cable can be positioned at a 90-degree orthogonal position relative to other cables present in the connection environment. Also, the cable may be located in a position not close to another data cable than the product of the square of the electromagnetic field permeability of the cable's sheath and the maximum signal voltage carried by the cable (e.g., between 3 volts and 15 volts). In yet other embodiments, an optical fiber cable shielded from optical interference may be used to transmit entropy information from the entropy generation unit 105 to a computer system directly connected to the entropy generation unit. In other embodiments, other cables that cannot be physically tampered with may be used, and the signals accumulated by these cables will not be snooped on or tampered with.

[0033] In contrast to computer systems A 110 and C 130, in FIG. 1, computer systems B 120 and D 140 do not have a direct connection to or other pre-established secure communication channel to / with the quantum entropy generation unit 105. Computer systems B 120 and D 140 are located far from the location of the quantum entropy generation unit 105 and can be located, for example, in another city, another state, or even another country, at another geographical location such as these. Therefore, computer systems B 120 and D 140 cannot utilize the secure communication links or channels 111 and 131 that can be used to directly transmit entropy information from the quantum entropy generation unit 105 to computer systems A 110 and C 130. Thus, computer systems B 120 and D 140 cannot receive entropy from a reliable entropy generation unit without the risk of entropy being disrupted or exposed to danger.

[0034] In the embodiment shown in FIG. 1, various computer systems are communicatively connected to each other via a lattice network with a graph clustering rate of 1.0, and each computer system is connected to the other computer systems. The configuration shown in FIG. 1 is not limiting. In another embodiment, other connection configurations are possible between computer systems. In FIG. 1, computer system A 110 is communicatively connected to computer systems B 120, C 130, and computer system D 140. As will be described in detail later, computer system A 110 uses the entropy received from the quantum entropy generation unit 105 to establish a secure communication channel with computer systems B 120, C 130, and / or D 140, and can transmit at least a portion of the entropy information received by computer system A 110 from the quantum entropy generation unit 105 to these other computer systems using the secure communication channel.

[0035] In the embodiment shown in FIG. 1, the computer system C 130 is communicably coupled to the computer systems A 110, B 120, and D 140. According to the technology disclosed in the present disclosure, the computer system C 120 uses the entropy received from the quantum entropy generation unit 105 to establish a secure communication channel with the computer systems A 110, B 120, and / or D 140, and at least a part of the entropy information received by the computer system C 130 from the quantum entropy generation unit 105 can be transmitted to these other computer systems using a secure communication channel.

[0036] In the embodiment shown in FIG. 1, the computer system B 120 is communicably coupled to a plurality of computer systems including the computer system D 140. The computer system B 120 uses the entropy received from the computer system A 110 or C 130 to establish a secure communication channel with the computer system D 140, and at least a part of the entropy information received by the computer system B 120 can be transmitted to the computer system D 140 using a secure communication channel. Similarly, in FIG. 1, the computer system D 140 is communicably coupled to a plurality of computer systems including the computer system B 120. The computer system D 140 uses the entropy received from the computer system A 110 or C 130 to establish a secure communication channel with the computer system B 120, and at least a part of the entropy information received by the computer system D 140 can be transmitted to the computer system B 120.

[0037] FIG. 2 is a diagram showing an example of the quantum entropy generation unit 205 according to a specific embodiment. The quantum entropy generation unit 205 may include a laser 206, a beam splitter 207, a sensor A 250, a sensor B 260, and a sampling unit 270. The quantum entropy generation unit 205 may use various components shown in FIG. 2 to generate high-quality entropy information.

[0038] In a specific embodiment, the laser 206 is a single-photon source capable of generating a short burst of light, such as a faint laser. The laser 206 may emit photons toward the beam splitter 207. The beam splitter 207 is configured to split the photon beam received from the laser 206 such that a part of the photons is reflected and sent to the sensor A 250, and the other light is reflected and sent to the sensor B 260. For example, this can be achieved by using a 50% mirror as the beam splitter 207. The 50% mirror can be arranged at an angle of 45 degrees with respect to the laser 206 and the path of the photons. The two sensors A 250 and B 260 are arranged at accurate positions that are the exits of the photons emitted by the laser 206 and split by the splitter 207. The sampling unit 270 can read which sensor (A 250 or B 260) the photon has reached during observation, and generates a data sequence based on the information received from these two sensors. For example, the sampling unit 270 may create a sequence composed of 0 and 1. Here, the photons detected by the sensor A 250 are interpreted as 0, and the photons detected by the sensor B 260 are interpreted as 1.

[0039] For example, laser 206 may transmit a single photon of light towards splitter 207. Due to the relativistic quantum electrodynamics reflection by the 50% mirror splitter 207, the photon reaches either sensor A 250 or sensor B 260 with a probability of 1:1 that matches the reflectivity of the coating on the 50% mirror. When a photon is received by either sensor, sampling unit 270 adds bits to the previously generated entropy stream as follows. (a) If sensor A 250 receives the photon, sampling unit 270 adds the bit "1" to the entropy stream. (b) If sensor B 260 receives the photon, sampling unit 270 adds the bit "0" to the entropy stream. For example, if the photons generated by laser 206 are received by sensors A and B in the sequence "AABABBABAB" shown below, the entropy stream generated by sampling unit 270 will be "1101001010". In certain embodiments, the entropy generation process is repeated at the maximum Nyquist sampling frequency between laser 206 and the assembly of the sensor / sampling unit. This results in a stream of quantum-grade entropy being generated by quantum entropy generation unit 205. Subsequently, the quantum entropy can be transmitted by quantum entropy generation unit 205 to one or more computer systems directly connected to quantum entropy generation unit 205 via a secure communication channel.

[0040] In each interaction between the photon and beam splitter 207, the transmission or reflection of that photon is a result of quantum mechanics. As a result, a sequence of photon reflections and transmissions is truly random and is a result of quantum entropy. Subsequently, a sequence of photons detected by sensors A 250 and B 260 is a result of quantum entropy, and the data sequence created by sampling unit 270 is a result of quantum entropy. Therefore, the data sequence created by sampling unit 270 can be referred to as quantum entropy.

[0041] The various inventive techniques described in this disclosure can be utilized in a distributed cloud environment. In a cloud environment, a CSP (Cloud Service Provider) can provide one or more cloud services to one or more subscribing customers. The term cloud service is generally used to refer to services provided by a CSP based on requests (e.g., via a subscription model) to users or customers who utilize the systems and infrastructure (cloud infrastructure) provided by the CSP. Typically, the servers and systems that make up the CSP's infrastructure are separate from the customer's own on-premises servers and systems. Thus, a customer can utilize the cloud services provided by the CSP without purchasing separate hardware resources and software resources for the services. Cloud services are designed so that customers who subscribe to obtain the infrastructure used to provide the services can easily and scalably access applications and computing resources without spending money. There are various cloud service providers that offer various types of cloud services. There are various different types and models of cloud services, including SaaS (Software-as-a-Service), PaaS (Platform-as-a-Service), IaaS (Infrastructure-as-a-Service), and others.

[0042] In the IaaS model, the CSP provides infrastructure (referred to as cloud service provider infrastructure or CSPI) that customers can use to build their own customizable private networks called VCNs (Virtual Cloud Networks). Customers can deploy one or more customer resources or workloads, such as computing instances (also referred to as hosts), on these VCNs. Computing instances or hosts are hosted by computer systems (referred to as host machines). The host can be a virtual machine computing instance or a bare metal computing instance. A VM (Virtual Machine) computing instance is an independent virtualized machine that runs on a physical bare metal computer system. Virtualization technologies such as hypervisors enable multiple virtual machine computing instances to be run on the same host machine. A bare metal computing instance is hosted by a bare metal server or host machine without a hypervisor. When a bare metal computing instance is provisioned, one customer or tenant maintains control of the physical CPU, memory, and network interfaces of the host machine hosting the bare metal instance and does not share the host machine with other customers or tenants.

[0043] The entropy distribution technology described in this disclosure can also be used to distribute entropy among computing instances or hosts in a distributed cloud environment. Figure 7 is FIG. 7 is a simplified block diagram of a distributed cloud environment 700 according to some embodiments. The environment shown in FIG. 7 is very similar to the environment shown in FIG. 1, except that FIG. 7 shows a plurality of computing instances or a plurality of hosts instead of the computer system shown in FIG. 1. The above description of the computer system of FIG. 1 is also applicable to the computing instances shown in FIG. 7. The distributed cloud environment shown in FIG. 7 is merely illustrative and does not unnecessarily limit the scope of the claimed embodiments. Many variations, alternative examples, and modifications are possible. For example, in some embodiments, the distributed environment 700 may have more components than shown in FIG. 7, may have fewer components than shown in FIG. 7, and may have hosts and communication lines in a different configuration or arrangement.

[0044] As shown in FIG. 7, the hosts or computing instances include host A 710, host B 720, host C 730, and host D 740 that are communicatively coupled to each other via a lattice network with a graph clustering rate of 1.0, and each host is connected to the other hosts. The configuration shown in FIG. 7 is not limiting. The hosts shown in FIG. 7 may be virtual machine computing instances or bare metal computing instances. In the case of virtual machine computing instances, the computing instances may be hosted by different host machines, or some may be hosted by the same host machine. The hosts in FIG. 7 may belong to one tenant or customer of the cloud service, or multiple different tenants or customers of the cloud service.

[0045] In certain embodiments, the function itself that can receive high-quality entropy information may be provided to customers as a service. Customers may subscribe to such a service, and upon subscribing, the hosts of the subscribing customers using various distribution techniques described in the present disclosure can utilize the high-quality entropy generated by the quantum entropy generation unit 705.

[0046] Hosts A 710 and C 730 are directly connected to the quantum entropy generation unit 705 via links 711 and 731. As described with reference to FIG. 1, links 711 and 731 are of the same kind as links 111 and 131, enabling the entropy generated by the quantum entropy generation unit 705 to be securely transmitted to hosts A 710 and C 730 without being interfered with or exposed to danger.

[0047] In contrast to hosts A 710 and C 730, hosts B 720 and D 740 do not have a direct connection to / with the quantum entropy generation unit 705 or any other pre-established secure communication channel. Hosts B 720 and D 740 are located far from the location of the quantum entropy generation unit 705 and may be located in another geographical location, such as another city, another state, or even another country. Therefore, hosts B 720 and D 740 cannot utilize the secure communication links or channels 711 and 731 that can be used to directly transmit entropy information from the quantum entropy generation unit 705 to hosts A 710 and C 730.

[0048] In FIG. 7, host A 710 is communicatively coupled to computer instances B 720, C 730, and D 740. As will be described in detail later, host A 710 can establish a secure communication channel with hosts B 720, C 730, and / or D 740 using the entropy received from the quantum entropy generation unit 705, and can transmit at least a portion of the entropy information received by host A 710 from the quantum entropy generation unit 705 to these other hosts using this secure communication channel.

[0049] In FIG. 1, host C 730 is communicatively connected to hosts A 710, B 720, and D 740. According to the technology disclosed in the present disclosure, host C 720 can establish a secure communication channel with hosts A 710, B 720, and / or D 740 using the entropy received from the quantum entropy generation unit 705, and utilize this secure communication channel to transmit at least a part of the entropy information received by host C 730 from the quantum entropy generation unit 705 to these other hosts.

[0050] In the embodiment shown in FIG. 1, host B 720 is communicatively connected to a plurality of hosts including host D 740. Host B 720 can establish a secure communication channel with host D 740 using the entropy received from host A 710 or C 730, and utilize this secure communication channel to transmit at least a part of the entropy information received by host B 720 to host D 740. Similarly, in FIG. 7, host D 740 is communicatively connected to a plurality of hosts including host B 720. Host D 740 can establish a secure communication channel with host B 720 using the entropy received from host A 710 or C 730, and transmit at least a part of the entropy information received by host D 740 to host B 720.

[0051] Figures 3 to 8 are diagrams showing various swimcharts and flowcharts illustrating various methods for distributing entropy according to a specific embodiment. In the swimcharts and flowcharts of Figures 3 to 8 and the related descriptions, the distribution of entropy among hosts is described. Here, these hosts may be hosted by one host machine or each may be hosted by a different host machine. The teachings shown in Figures 3 to 8 and the accompanying descriptions are also applicable for securely distributing entropy among various host machines or computer systems, such as among the various computer systems shown in Figure 1. In addition to this, although the distribution of quantum entropy is described in Figures 3 to 8 and the accompanying descriptions, this is not limiting. The teachings described herein can also be used for distributing other types of entropy information generated from other reliable sources, such as radioactive decay, thermal noise, human interaction with computer interface hardware, and / or airflow detection.

[0052] Figure 3 is a diagram showing a simplified swimchart 300 of the process for distributing or transmitting entropy information generated by the quantum entropy generation unit 705 to a plurality of hosts and a plurality of computing instances according to a specific embodiment. The processing shown in Figure 3 may be implemented by software (e.g., code, instructions, programs) executed by one or more processing devices (e.g., processors, cores) of each system, may be implemented using hardware, or may be implemented by a combination thereof. The software may be stored on a non-transitory storage medium (e.g., on a storage device). The method presented and described later in Figure 3 is illustrative and not limiting. Although Figure 3 shows that various processing steps are performed in a specific order or sequence, this is not limiting. In certain other specific embodiments, the processing may be executed in a different order and some steps may be executed in parallel.

[0053] FIG. 3 shows the distribution of entropy among the various components shown in FIG. 7, and the accompanying description in FIG. 2 describes the distribution. More specifically, FIG. 3 and the accompanying description thereof describe the distribution of quantum entropy from the quantum entropy generation unit 705 to host A 710 directly connected to the quantum entropy generation unit 705, and then from host A 710 to host B 720 communicatively coupled to host A 710. The teachings of FIG. 3 are applicable to the distribution of entropy from an entropy source to a computer system directly connected to the entropy source, and from the computer system to another computer system communicatively coupled to the first computer system. For example, in FIG. 1, host A 710 can transmit the entropy received from the quantum entropy generation unit 705 to any of computer systems B 720, C 730, or D 740 communicatively coupled to host A 710 using this method.

[0054] As shown in FIG. 3, in S310, the quantum entropy generation unit 705 (or another suitable reliable source of entropy) can generate quantum entropy. In some embodiments, the quantum entropy generation unit 705 can generate a stream of quantum entropy. The stream of quantum entropy can then be distributable to one or more connected computer systems.

[0055] In S312, the quantum entropy generation unit 705 may send the quantum entropy generated in S310 to host A 710 directly connected to the quantum entropy generation unit 705. In a specific embodiment, the host machine hosting host A 710 may be directly connected to the quantum entropy generation unit 705. Any appropriate amount of the quantum entropy generated by the quantum entropy generation unit 705 may be sent. For example, 128 bits, 256 bits, 512 bits, 1024 bits, 2048 bits, or other appropriate amounts of quantum entropy may be sent to host A 710. In a specific embodiment, the quantum entropy may be sent in the form of a stream of quantum entropy.

[0056] In S312, the entropy information is sent from the quantum entropy generation unit 705 to host A 710 through a reliable connection. For example, the entropy information may be transmitted by a direct local wired connection that is not connected to the Internet and / or other networks between the quantum entropy generation unit 705 and host A 710 (or between the quantum entropy generation unit 705 and the host machine hosting host A 710). The cable used for the wired connection may also be protected from external interference, tampering, or snooping. In addition to or instead of this, the quantum entropy can be sent in an encrypted form. For example, the quantum entropy generation unit 705 may encrypt the quantum entropy generated in S310 and then send the encrypted quantum entropy to host A 710 in S312. When host B 720 receives the encrypted quantum entropy, it may decrypt the encryption.

[0057] In S314, host A 710 distributes or transmits at least a part of the quantum entropy received from the quantum entropy generation unit 705 to host B 720 via a secure communication channel established between host A 710 and host B 720. Here, the secure channel itself is provided using a part of the quantum entropy received by host A 710 from the quantum entropy generation unit 705.

[0058] In a specific embodiment, the secure communication channel is established using a cryptographic key. The cryptographic key itself is generated using a part of the quantum entropy received by host A 710 from the quantum entropy generation unit 705. For example, host A 710 can generate one or more cryptographic keys for use in establishing a secure communication channel with host B 720 using the first part of the quantum entropy received in step S312. Thereafter, host A 710 can transmit the second part of the quantum entropy received in step S312 to host B 720 using the secure communication channel. As a result, even without a direct connection between the quantum entropy generation unit 705 and host B 720, or without a previously existing secure communication channel, host B 720 can receive quantum entropy from the quantum entropy generation unit 705. Thereafter, host B 720 can utilize the second part of the quantum entropy for updating the communication channel between host B 720 and host A 710 and / or for further securing it. In some embodiments, host B 720 can use the second part of the quantum entropy for operating an application, for use in establishing one or more additional communication channels with other computer systems, or for other suitable purposes.

[0059] Examples of the processes executed in step S314 of FIG. 3 according to some embodiments are shown in FIG. 4 and will be described later. FIG. 4 is a diagram showing a simplified swim chart 400 for distributing or transmitting entropy information generated by the quantum entropy generation unit 705 to a plurality of hosts and a plurality of computing instances according to a specific embodiment. The processes shown in FIG. 4 may be implemented by software (e.g., code, instructions, programs) executed by one or more processing devices (e.g., processors, cores) of each system, may be implemented using hardware, or may be implemented by a combination thereof. The software may be stored on a non-transitory storage medium (e.g., on a storage device). The method presented in FIG. 4 and described later is illustrative and not limiting. Although FIG. 4 shows that various processing steps are performed in a specific order or sequence, this is not limiting. In a specific alternative embodiment, the process may be executed in a different order, and some steps may be executed in parallel. In a specific embodiment, such as the embodiment shown in FIG. 1, the processes shown in FIG. 4 may be executed by the quantum entropy generation unit 705, host A 710, and / or host B 720.

[0060] As shown in FIG. 4, in S410, the quantum entropy generation unit 705 (or another suitable reliable source of entropy) may generate quantum entropy. In some embodiments, the quantum entropy generation unit 705 may generate a stream of quantum entropy. The stream of quantum entropy may then be distributable to one or more connected computer systems.

[0061] In S412, the quantum entropy generation unit 705 may transmit the quantum entropy generated in S410 to host A 710 directly connected to the quantum entropy generation unit 705. In a specific embodiment, the host machine hosting host A 710 may be directly connected to the quantum entropy generation unit 705. Any appropriate amount of the quantum entropy generated by the quantum entropy generation unit 705 may be transmitted. For example, 128 bits, 256 bits, 512 bits, 1024 bits, 2048 bits, or other appropriate amounts of quantum entropy may be transmitted to host A 710. In a specific embodiment, the quantum entropy may be transmitted in the form of a stream of quantum entropy.

[0062] In S412, entropy information is transmitted from the quantum entropy generation unit 705 to host A 710 through a reliable connection. For example, the entropy information may be transmitted through a direct local wired connection that is not connected to the Internet and / or other networks between the quantum entropy generation unit 705 and host A 710 (or between the quantum entropy generation unit 705 and the host machine hosting host A 710). The cable used for the wired connection may also be protected from external interference, tampering, or snooping. In addition to or instead of this, the quantum entropy can be transmitted in an encrypted form. For example, the quantum entropy generation unit 705 may encrypt the quantum entropy generated in S310 and then transmit the encrypted quantum entropy to host A 710 in S412. When host B 720 receives the encrypted quantum entropy, it may decrypt the encryption.

[0063] S414, S416, S418, S420, S422, S424, S426, and S The process at 428 is executed to establish a secure communication channel between host A 710 and host B 720 and utilize this secure channel to distribute or transmit a portion of the quantum entropy received by host A 710 from the quantum entropy generation unit 705 to host B 720. The communication channel established between host A 710 and host B 720 is a communication channel through which the entropy transmitted using this channel cannot be snooped, tampered with, or blocked. The quantum entropy itself may be used as secret information, for example, during the generation of an encryption key for providing a communication channel between host A 710 and host B 720.

[0064] The processes of S414, S416, and S418 are executed to establish a first communication channel between host A 710 and host B 720. In S414, host A 710 may generate a first set consisting of one or more encryption keys using the first portion of the quantum entropy received by host A 710 from the quantum entropy generation unit 705. For example, host A 710 may generate a first public key for use in the first key exchange with host B 720 to provide the first communication channel. The size of the first portion of the quantum entropy may be any appropriate size, such as 256-bit or 512-bit quantum entropy.

[0065] In S416, host B 720 may generate a second set consisting of one or more cryptographic keys for use when establishing the first communication channel with host A 710. For example, host B 720 may generate a second public key for use in the first key exchange with host A 710. Since host B 720 still does not have access to the quantum entropy generated by the quantum entropy generation unit 705, other entropy information such as a data string generated by a software-based pseudorandom number generator or another type of potentially untrustworthy entropy source may be used in S416 for the key generation process. The entropy generated by these sources may not be as secure or trustworthy as the quantum entropy generated by the quantum entropy generation unit 705.

[0066] In S418, using the first cryptographic key set generated by host A 710 in S414 and the second cryptographic key set generated by host B 720 in S416, an initial communication channel is established between host A 710 and host B 720. As part of the processing in S418, host A 710 and host B 720 may perform an initial key exchange to create an initial shared key (e.g., a symmetric key). This may include exchanging information based on the first cryptographic key set generated by host A 710 in S414 and exchanging information based on the second cryptographic key set generated by host B 720 in S416. In some embodiments, the information exchange may include an elliptic curve Diffie-Hellman key sharing protocol.

[0067] As described above, the first communication channel is established using the first encryption key set generated by host A 710 using part of the quantum entropy received from the quantum entropy generation unit 705, and using the second encryption key set generated by host B 720 using entropy that is not entropy from the quantum entropy generation unit 705 and thus not as trustworthy. Therefore, the first communication channel is a connection with encryption strength derived from asymmetric entropy. This first communication channel can be a communication channel that is sufficiently reliable to transmit at least some secret information to host B 720 without being interfered with or exposed to danger. Therefore, although described later with respect to S420, the first communication channel is used for host A 710 to transmit part of the quantum entropy received from the quantum entropy generation unit 705 to host B 720.

[0068] In S420, host A 710 transmits a part (second part) of the quantum entropy received from the quantum entropy generation unit 705 to host B 720 via the first communication channel. In a particular embodiment, the first communication channel is a connection with encryption strength derived from asymmetric entropy, where only one encryption key set used to provide the communication channel is generated using the entropy information generated by the quantum entropy generation unit 705, so host A 710 can take precautions to transmit the entropy information in S420. For example, the entropy information can be transmitted on the first communication channel in encrypted form from host A 710 to host B 720. Host A 710 can first encrypt a part (second part) of the quantum entropy to be transmitted to host B 720, and then transmit the encrypted entropy information to host B 720. In a particular embodiment, the entropy information may be encrypted using the first symmetric key created in step S416. When host B 720 receives the second part of the quantum entropy, it can decrypt the encryption using the first symmetric key. The size of the second part of the quantum entropy can be any suitable size, such as 256-bit or 512-bit quantum entropy.

[0069] After S420, both host A 710 and host B 720 can access the entropy information generated by the quantum entropy generation unit 705. Host A 710 has previously received this information at S412, and host B 720 receives the entropy information at S420. Since both have the reliable entropy information generated by the quantum entropy generation unit 705, a connection with cryptographic strength derived from symmetric entropy can be set up between host A 710 and host B 720. This will be described later in steps S422, S424, and S426.

[0070] At S422, host A 710 may generate a third set consisting of one or more cryptographic keys using a part (the third part) of the quantum entropy received from the quantum entropy generation unit 705 at S412. For example, host A 710 may generate a third public key for use in a second key exchange with host B 720 to establish a secure channel. The size of the third part of the quantum entropy can be any appropriate size, such as 256-bit or 512-bit quantum entropy.

[0071] At S424 (which may be executed simultaneously with step S422), host B 720 may generate a fourth set consisting of one or more cryptographic keys using a part of the quantum entropy generated by the quantum entropy generation unit 705 and received by host B 720 at S420. For example, host B 720 may generate a fourth public key for use in a second key exchange with host A 710 to establish a secure communication channel. When generating the fourth set of cryptographic keys, host B 720 may use some or all of the quantum entropy received by host B 720 at S420. For example, if the size of a part of the quantum entropy received by host B 720 at S420 is 512 bits, host B 720 may use all or less than 512 bits of the entropy information to generate a fourth set consisting of one or more public keys.

[0072] In S426, using the third encryption key set generated by host A 710 in S422 and the fourth encryption key set generated by host B 720 in S424, a secure communication channel is established between host A 710 and host B 720. In some embodiments, the amount of entropy information generated by the quantum entropy generation unit transmitted from host A 710 to host B 720 over the first half secure channel in S420 is just enough to facilitate establishing a secure communication channel between host A 710 and host B 720. For example, the amount of entropy information transmitted in S420 may be just enough for host B 720 to generate the fourth encryption key set used to establish a secure communication channel in S426. As part of the processing in S426, host A 710 and host B 720 may perform a second key exchange to create a second shared key (e.g., a symmetric key). This may include exchanging the third encryption key set generated in S422 and exchanging the fourth encryption key set generated in S424. In some embodiments, this may include an elliptic curve Diffie-Hellman exchange.

[0073] Since both of the encryption key sets used to establish the communication channel are generated using the entropy information generated by the quantum entropy generation unit 705, the communication channel established in S426 is a connection with encryption strength derived from symmetric entropy. Thus, the communication channel established in S426 is considered to be a completely secure communication channel. Thereafter, this secure communication channel is used by host A 710 to further transmit a part of the quantum entropy information received by host A 710 from the quantum entropy generation unit 705 to host B 720. This communication channel may also be used for other purposes such as exchanging one or more messages between host A 710 and host B 720.

[0074] In S428, host A 710 may transmit another part (e.g., the fourth part) of the quantum entropy generated by the quantum entropy generation unit to host B 720 via the secure communication channel established in S426. In a particular embodiment, the entropy information may be transmitted as a stream of information. The size of the fourth part of the quantum entropy can be any suitable size, such as 256-bit or 512-bit quantum entropy.

[0075] In S430, host B 720 may use the fourth part of the quantum entropy received from host A 710 via the secure communication channel in S428. For example, host B 720 may use the fourth part of the quantum entropy for the operation of one or more applications.

[0076] In a particular embodiment, to maintain the security of the communication channel established in S426, the cryptographic material (e.g., encryption key) associated with the connection is regenerated itself to maintain a secure communication channel. For example, as shown in FIG. 4, in S432, after certain conditions are met, host A 710 and host B 720 may generate new encryption keys used to update the secure communication channel and / or establish a new secure communication channel. Here, the new encryption keys are also generated using a part of the quantum entropy information available to host A 710 and host B 720. This may be repeated each time the regeneration condition is met or occurs. This may be referred to as key rotation. The encryption key may also be referred to as an ephemeral encryption key because it is only valid for a specific period before being regenerated again.

[0077] In one embodiment, both host A 710 and host B 720 can generate a new set consisting of one or more cryptographic keys using the quantum entropy available to the host. In the case of host A 710, the entropy information used to generate the ephemeral cryptographic key is received from the quantum entropy generation unit 705 via the connection between the quantum entropy generation unit 705 and host A 710. In a particular embodiment, the quantum entropy generation unit 705 may be configured to continuously transmit a stream of quantum entropy information to host A 710. In the case of host B 720, the quantum entropy used to generate the ephemeral cryptographic key may be received by host B 720 from host A 710 via the secure communication channel established at S426.

[0078] Various different conditions may trigger the regeneration of cryptographic material (e.g., cryptographic keys) at S432. In a particular embodiment, the trigger condition may be a time-based condition. For example, a pre-configured period for the connection may be configured, and after that period, it is necessary to regenerate the cryptographic key to maintain the channel. This pre-configured period may be, for example, a specific number of seconds, a specific number of minutes, a specific number of hours, etc. For example, after 30 seconds, 1 minute, 5 minutes, 10 minutes, 30 minutes, etc.

[0079] In some other embodiments, the trigger condition may be based on a preconfigured number of packets or messages being exchanged between host A 710 and B 720. For example, after 1 packet, 2 packets, 5 packets, 10 packets, 20 packets, or generally, after "N" packets, the regeneration of the encryption key may be triggered. Here, "N" varies depending on the degree to which the entropy customer can tolerate the risk. A high value of N corresponds to a low ephemeral key and a high potential risk of entropy tampering. When the risk tolerance is the lowest, the value of N can be set to 1. As a result, the encryption key becomes a very ephemeral encryption key. The encryption key rotation rate may be based on the degree to which the entropy customer desires to be exposed to an acceptable risk. The clustering graph network shown in FIGS. 1 and 7 represents the fastest possible speed of entropy consumption necessary to maintain strong ephemeral keys between all connections between all hosts in the network. This is because the product of the key rotation rate and the clustering coefficient of the graph of the computer network determines the rate at which entropy itself is consumed in the process of distributing entropy to the hosts. For fast key rotation, as the connection time between hosts in the network increases, the trust level of the connection logarithmically increases by a factor of the reciprocal of "N". This connection period is represented by the value of N above, or the number of packets exchanged between these two hosts before the two hosts regenerate the ephemeral key again.

[0080] As described above, the specific order or sequence of the steps shown in FIG. 4 is not limiting. In certain other embodiments, these steps may be performed in a different order or some of the steps may be performed in parallel. For example, steps S420, S422, and S424 are shown as being performed in a specific order in swim chart 400 of FIG. 4, but this is not limiting. In other embodiments, these steps may be performed in any order. In still other embodiments, the processing in S420, S422, and S424 may be overlapping or may be performed in parallel.

[0081] In the embodiment illustrated and described with respect to FIG. 4, the entropy information generated by the quantum entropy generation unit 705 is transmitted to host A 710 at S412. In certain embodiments, this transmission of entropy information from the entropy source to the host directly connected to the entropy source may be performed as a one-time event. In other embodiments, the transmission of quantum entropy information from the entropy source to the host directly connected to the entropy source may be performed periodically. Here, after each period, the new entropy information generated by the entropy source is transmitted to the connected host. In still other embodiments, the transmission of quantum entropy information from the entropy source to the host directly connected to the entropy source may be performed continuously as a stream of entropy information generated by the entropy source and transmitted to the connected host. In some other embodiments, the entropy information may be transmitted from the entropy source to the host when the host requests this information. For example, the host may send a request for entropy information to the entropy source, and then the entropy source may respond to this request by sending the requested entropy information generated by the entropy source to the requesting host. Other transmission mechanisms may be used in other embodiments.

[0082] The transmission of entropy information from one host to another (e.g., from host A 710 to host B 720) may be carried out according to various different modes. In one embodiment, as a one-time event, the first host may transmit entropy information to the second host over a secure communication channel established between these two hosts. In other embodiments, the transmission of quantum entropy information from the first host to the second host may be carried out periodically over a secure communication channel. Here, after each period, new entropy information is transmitted from the first host to the second host. Here, the new entropy information may be part of the entropy information received by the first host from an entropy source or another host. In still other embodiments, the transmission of quantum entropy information from the first host to the second host may be carried out continuously as a stream of entropy information over a secure communication channel established between the hosts. In some other embodiments, the entropy information may be transmitted from the first host to the second host when the second host requests this information. For example, the second host may send a request for entropy information to the first host, and then the first host may respond to this request by transmitting the requested entropy information to the requesting second host. Other transmission mechanisms may be used in other embodiments.

[0083] The process shown in FIG. 4 shows how the entropy generated by the entropy source can be received by a host (e.g., host A 710) directly connected to the entropy source (e.g., quantum entropy generation unit 705), and further, how the host receiving the entropy information can distribute a part of the entropy to one or more other hosts communicably connected to the first host. These other hosts may or may not be connected to the entropy source. Further, the host that has received the entropy information can distribute a part of the received entropy information to other hosts communicably connected to the host. In this way, the entropy information generated by the entropy source can be securely distributed to a plurality of hosts in a distributed network-connected environment. The entropy can be transferred to a host that is some distance away from the entropy source (e.g., from the quantum entropy generation unit 705). For example, after host B 720 receives quantum entropy from host A 710, it transfers a part of the received quantum entropy to host D 740, and host D 740 transfers it to other connected hosts... and so on.

[0084] As described above, even if a host is not directly connected to an entropy source, a host on the network (e.g., on a lattice network) can access entropy information such as quantum entropy generated by a reliable entropy generation source. Since the quality of the quantum entropy information received by the host is high and trusted, the received entropy information can be used for various operations that require high trust. For example, quantum entropy may be used by a host to generate a reliable cryptographic key. These cryptographic keys can be used for various purposes, such as establishing a reliable communication channel between hosts. The present disclosure describes a method for distributing quantum entropy generated by a quantum entropy source through an ephemerally (temporarily) keyed lattice cryptographic network to all hosts (e.g., virtual machine computing instances and / or bare metal computing instances). Here, a host that receives quantum entropy may not be connected to the entropy source and may not have a local source of reliable entropy information.

[0085] FIG. 5 is a diagram showing a simplified flowchart 500 of steps executed by a first host during a process for distributing or transmitting entropy information generated by a quantum entropy generation unit 705 to a plurality of hosts and a plurality of computing instances according to a specific embodiment. The process shown in FIG. 5 may be implemented by software (e.g., code, instructions, programs) executed by one or more processing devices (e.g., processors, cores) of each system, may be implemented using hardware, or may be implemented by a combination thereof. The software is stored on a non-transitory storage medium (e.g., a memory It may be stored on the memory device. The method presented in FIG. 5 and described later is an example and not a limitation. Although FIG. 5 shows various processing steps being performed in a specific order or sequence, this is not a limitation. In certain other embodiments, the processing may be executed in a different order, and some steps may be executed in parallel. In a specific embodiment such as the embodiment shown in FIG. 1, in the specific embodiment, the processing shown in FIG. 5 may be executed by host A 710. In some embodiments, the first host described later in FIG. 5 may represent host A 710, and the second host described later in FIG. 5 may represent host B 720.

[0086] The quantum entropy generation unit 705 (or another suitable reliable source of entropy) may generate quantum entropy. In some embodiments, the quantum entropy generation unit 705 may generate a stream of quantum entropy. The stream of quantum entropy can then be distributed to one or more connected computer systems.

[0087] In S502, the first host receives quantum entropy from the quantum entropy generation unit 705. The first host may be directly connected to the quantum entropy generation unit 705. In a specific embodiment, the host machine hosting the first host may be directly connected to the quantum entropy generation unit 705. Any suitable amount of the quantum entropy generated by the quantum entropy generation unit 705 may be received. For example, 128 bits, 256 bits, 512 bits, 1024 bits, 2048 bits, or other appropriate amounts of quantum entropy may be transmitted by the quantum entropy generation unit 705 and received by the first host. In a specific embodiment, the quantum entropy may be transmitted in the form of a stream of quantum entropy.

[0088] In S502, entropy information is transmitted from the quantum entropy generation unit 705 to the first host via a reliable connection. For example, the entropy information may be transmitted by a direct local wired connection that is not connected to the Internet and / or other networks between the quantum entropy generation unit 705 and the first host (or between the quantum entropy generation unit 705 and the host machine hosting the first host). The cable used for the wired connection may also be protected from external interference, tampering, or snooping. In addition to or instead of this, the quantum entropy can be transmitted in an encrypted form.

[0089] In S503, the first host uses a secure communication channel established using a part of the quantum entropy to transmit a part of the quantum entropy received by the first host in step S502 to the second host. For example, the first host can establish a secure communication channel with the second host using the first part of the quantum entropy received in step S502. Thereafter, using that secure communication channel, the first host can transmit the second part of the quantum entropy received in step S502 (or the quantum entropy received later) to the second host. The communication channel established between the first host and the second host is a communication channel through which the entropy transmitted using this channel cannot be snooped, tampered with, or blocked. The quantum entropy itself may be used as secret information, for example, during the generation of an encryption key for providing a communication channel between the first host and the second host.

[0090] The process of S503 may include the execution of the following steps S504 to S514. The processes of S504 and S506 are executed to establish the first communication channel between the first host and the second host. In S504, the first host may generate a first set consisting of one or more cryptographic keys using the first portion of the quantum entropy received by the first host from the quantum entropy generation unit 705. For example, the first host may generate a first public key for use in the first key exchange with the second host to provide the first communication channel. The size of the first portion of the quantum entropy can be any suitable size, such as 256-bit or 512-bit quantum entropy. In addition to this, simultaneously or at a similar timing, the second host may generate a second set consisting of one or more cryptographic keys for use when establishing the first communication channel with the first host. For example, the second host may generate a second public key for use in the first key exchange with the first host. Since the second host cannot yet access the quantum entropy generated by the quantum entropy generation unit 705, the second host may use other entropy information, such as a data string generated by a software-based pseudo-random number generator or another type of potentially untrustworthy entropy source, for the key generation process. The entropy generated by these sources may not be as secure or trustworthy as the quantum entropy generated by the quantum entropy generation unit 705.

[0091]

[0092] In S506, the first host may establish the first communication channel with the second host using the first set consisting of one or more cryptographic keys generated by the first host in S504 and the second set of cryptographic keys generated by the second host. As part of the process in S506, the first host and the second host may perform the first key exchange to create a first shared key (e.g., a symmetric key). This may include exchanging information based on the first set of cryptographic keys generated by the first host in S504 and exchanging information based on the second set of cryptographic keys generated by the second host. In some embodiments, the information exchange may include the elliptic curve Diffie-Hellman key sharing protocol.

[0093] As described above, using the first set of encryption keys generated by the first host using a part of the quantum entropy received from the quantum entropy generation unit 705, and using the second set of encryption keys generated by the second host using entropy that is not entropy from the quantum entropy generation unit 705 and thus not as reliable, the first communication channel is established. Therefore, the first communication channel is a connection having encryption strength derived from asymmetric entropy. This first communication channel can be a communication channel that is reliable enough to transmit at least some secret information to the second host without being interfered with or exposed to danger. Thus, although described later with respect to S508, the first communication channel is used for the first host to transmit a part of the quantum entropy received from the quantum entropy generation unit 705 to the second host.

[0094] In S508, the first host transmits a part (for example, the second part) of the quantum entropy received from the quantum entropy generation unit 705 to the second host via the first communication channel. In a particular embodiment, the first communication channel is a connection having encryption strength derived from asymmetric entropy, where only one set of encryption keys used to provide the communication channel is generated using the entropy information generated by the quantum entropy generation unit 705, so the first host can take precautions to transmit the entropy information in S508. For example, the entropy information can be transmitted on the first communication channel in an encrypted form from the first host to the second host. The first host can first encrypt a part (the second part) of the quantum entropy to be transmitted to the second host, and then transmit the encrypted entropy information to the second host. In a particular embodiment, the entropy information may be encrypted using the first symmetric key created in step S506. The second host can decrypt the encryption using the first symmetric key when it receives the second part of the quantum entropy.

[0095] The magnitude of the second part of the quantum entropy can be any suitable magnitude, such as 256-bit or 512-bit quantum entropy. In some embodiments, the second part of the quantum entropy can be a part of the quantum entropy received in step S502. In other embodiments, the second part of the quantum entropy may be received directly from the quantum entropy generation unit immediately before executing step S508. Immediately before, it may be received from the quantum entropy generation unit.

[0096] After S508, both the first host and the second host can access the entropy information generated by the quantum entropy generation unit 705. The first host has previously received this information at S502 (and additional entropy information may also be received at this time), and the second host receives the entropy information at S508. Since both have reliable entropy information generated by the quantum entropy generation unit 705, a connection with cryptographic strength derived from symmetric entropy can be established between the first host and the second host. This will be described later in steps S510 and S512.

[0097] At S510, the first host can generate a third set consisting of one or more cryptographic keys using a part of the quantum entropy (e.g., the third part) received from the quantum entropy generation unit 705. For example, the first host can generate a third public key for use in a second key exchange with the second host to establish a secure channel. The magnitude of the third part of the quantum entropy can be any suitable magnitude, such as 256-bit or 512-bit quantum entropy.

[0098] In addition, simultaneously or at a similar timing, the second host may generate a fourth set of one or more cryptographic keys using a part of the quantum entropy generated by the quantum entropy generation unit 705 and received by the second host. For example, the second host may generate a fourth public key for use in a second key exchange with the first host to establish a secure communication channel. The second host may use some or all of the quantum entropy received by the second host when generating the fourth set of cryptographic keys. For example, if the size of a part of the quantum entropy received by the second host is 512 bits, the second host may use all of the 512-bit entropy information or less than that amount of entropy information to generate a fourth set of one or more public keys.

[0099] In S512, the first host may establish a secure communication channel between the first host and the second host using a third set of one or more cryptographic keys generated by the first host in step S510 and a fourth set of one or more cryptographic keys generated by the second host. In some embodiments, the amount of entropy information generated by the quantum entropy generation unit and transmitted from the first host to the second host over the first half-secure channel in S508 is just enough to facilitate establishing a secure communication channel between the first host and the second host. For example, the amount of entropy information transmitted in S508 may be just enough for the second host to generate the fourth set of cryptographic keys used to establish a secure communication channel in S512. As part of the processing in S512, the first host and the second host may perform a second key exchange to create a second shared key (e.g., a symmetric key). This may include exchanging the third set of cryptographic keys generated in S510 and exchanging the fourth set of cryptographic keys generated by the second host. In some embodiments, this may include an elliptic curve Diffie-Hellman exchange.

[0100] Since both of the encryption key sets used to provide the communication channels are generated using the entropy information generated by the quantum entropy generation unit 705, the communication channel established in S512 is a connection having an encryption strength derived from symmetric entropy. Therefore, the communication channel established in S512 is considered to be a completely secure communication channel. Thereafter, this secure communication channel is used by the first host to further transmit a part of the quantum entropy information received by the first host from the quantum entropy generation unit 705 to the second host. This communication channel can also be used for other purposes such as exchanging one or more messages between the first host and the second host.

[0101] In S514, the first host may transmit another part (for example, the fourth part) of the quantum entropy generated by the quantum entropy generation unit to the second host via the secure communication channel established in S512. For example, the first host may encrypt the fourth part of the quantum entropy using the second symmetric key created in step S512, the first host may transmit the encrypted fourth part of the quantum entropy to the second host, and the second host may decrypt the encryption of the fourth part of the quantum entropy using the second symmetric key. In a particular embodiment, the entropy information may be transmitted as a stream of information. The size of the fourth part of the quantum entropy may be any suitable size, such as 256-bit or 512-bit quantum entropy.

[0102] The second host may use the fourth part of the quantum entropy received from the first host via the secure communication channel in S514. For example, the second host may use the fourth part of the quantum entropy for the operation of one or more applications.

[0103] In certain embodiments, to maintain the security of the communication channel established at S512, the cryptographic material (e.g., encryption key) associated with that connection is itself regenerated to maintain a secure communication channel. For example, as shown in FIG. 5, at S516, after certain conditions are met, the first host and the second host may generate new encryption keys used to update the secure communication channel and / or establish a new secure communication channel. Here, the new encryption keys may also be generated using a portion of the quantum entropy information available to the first host and the second host. This may be repeated each time the regeneration condition is met or occurs. This is sometimes referred to as key rotation. Since the encryption keys are only valid for a specific period before being regenerated again, they may also be referred to as ephemeral encryption keys. As described above, the first host and the second host exchange keys (e.g., elliptic curve Diffie-Hellman exchange) to generate a shared key (e.g., symmetric key). Since the exchange process can be repeatedly executed to create ephemeral encryption keys, this exchange may be referred to as an ephemeral Diffie-Hellman exchange or an ephemeral elliptic curve Diffie-Hellman exchange.

[0104] In one embodiment, either the first host or the second host may generate a new set consisting of one or more encryption keys using the quantum entropy available to the host. In the case of the first host, the entropy information used to generate the ephemeral encryption key is received from the quantum entropy generation unit 705 via the connection between the quantum entropy generation unit 705 and the first host. In certain embodiments, the quantum entropy generation unit 705 may be configured to continuously transmit a stream of quantum entropy information to the first host. In the case of the second host, the quantum entropy used to generate the ephemeral encryption key may be received by the second host from the first host via the secure communication channel established at S514.

[0105] A variety of different conditions may trigger the regeneration of cryptographic material (e.g., encryption keys) at S516. In certain implementations, the trigger condition may be a time-based condition. For example, a preconfigured period of time may be configured for the connection after which the encryption keys must be generated again to maintain the channel. This preconfigured period may be, for example, a specific number of seconds, minutes, hours, etc. For example, after 30 seconds, 1 minute, 5 minutes, 10 minutes, 30 minutes, etc.

[0106] In some other embodiments, the trigger condition may be based on a preconfigured number of packets or messages being exchanged between the first and second hosts, for example, rekeying may be triggered after 1 packet, 2 packets, 5 packets, 10 packets, 20 packets, or generally after "N" packets. Here, "N" depends on the entropy customer's acceptable risk exposure. A high value of N corresponds to a low ephemeral key and a high potential risk of entropy tampering. For the lowest risk tolerance, the value of N may be set to 1. This results in a very ephemeral encryption key. The encryption key rotation rate may be based on the entropy customer's desired acceptable risk exposure. The clustering graph network shown in Figure 1 and Figure 7 represents the fastest possible rate of entropy consumption that would be required to maintain strong ephemeral keys among all connections between all hosts in the network. This is because the product of the key rotation rate and the clustering coefficient of the computer network graph determines the rate at which entropy itself is consumed in the process of distributing entropy to hosts. Due to the fast key rotation, as the connection time between hosts in the network increases, the trust level of the connection increases logarithmically by a factor of the inverse of "N". This connection duration is represented by the value of N above, or the number of packets exchanged between the two hosts before they regenerate the ephemeral key.

[0107] As described above, the specific order or sequence of steps shown in FIG. 5 is not limiting. In certain alternative embodiments, these steps may be performed in a different order, or some steps may be performed in parallel.

[0108] In the embodiment described with reference to FIG. 5, the entropy information generated by the quantum entropy generation unit 705 is transmitted to the first host at S502. In certain embodiments, this transmission of entropy information from the entropy source to the host directly connected to the entropy source may be performed as a one-time event. In other embodiments, the transmission of quantum entropy information from the entropy source to the host directly connected to the entropy source may be performed periodically. Here, after each period, the new entropy information generated by the entropy source is transmitted to the connected host. In still other embodiments, the transmission of quantum entropy information from the entropy source to the host directly connected to the entropy source may be performed continuously as a stream of entropy information generated by the entropy source and transmitted to the connected host. In some other embodiments, the entropy information may be transmitted from the entropy source to the host when the host requests this information. For example, the host may send a request for entropy information to the entropy source, and then the entropy source may respond to this request by sending the requested entropy information generated by the entropy source to the requesting host. Other transmission mechanisms may be used in other embodiments.

[0109] The transmission of entropy information from one host to another (e.g., from a first host to a second host) may be performed according to various different modes. In one embodiment, as a one-time event, the first host may transmit entropy information to the second host over a secure communication channel established between these two hosts. In other embodiments, the transmission of quantum entropy information from the first host to the second host may be performed periodically over a secure communication channel. Here, after each period, new entropy information is transmitted from the first host to the second host. Here, the new entropy information may be part of the entropy information received by the first host from an entropy source or another host. In still other embodiments, the transmission of quantum entropy information from the first host to the second host may be performed continuously as a stream of entropy information over a secure communication channel established between the hosts. In some other embodiments, the entropy information may be transmitted from the first host to the second host when the second host requests this information. For example, the second host may send a request for entropy information to the first host, and then the requested entropy information is sent to the requesting second host By doing so, the first host may respond to this request. Other transmission mechanisms may be used in other embodiments.

[0110] The process shown in FIG. 5 shows how the entropy generated by an entropy source can be received by a host (e.g., the first host) directly connected to the entropy source (e.g., the quantum entropy generation unit 705), and further, how the host receiving the entropy information can distribute a part of the entropy to one or more other hosts communicably connected to the first host. These other hosts may or may not be connected to the entropy source. Further, the host that has received the entropy information can distribute a part of the received entropy information to other hosts communicably connected to the host. In this way, the entropy information generated by the entropy source can be securely distributed to a plurality of hosts in a distributed network-connected environment. The entropy can be transferred to a host that is somewhat distant from the entropy source (e.g., from the quantum entropy generation unit 705). For example, after the second host receives quantum entropy from the first host, it transfers a part of the received quantum entropy to the third host, and the third host transfers it to other connected hosts... and so on.

[0111] As described above, even if a host is not directly connected to an entropy source, a host on the network (e.g., on a lattice network) can obtain access to entropy information such as quantum entropy generated by a reliable entropy generation source. Since the quality of the quantum entropy information received by the host is high and trusted, the received entropy information can be used for various operations that require high trust. For example, the quantum entropy may be used by the host to generate a reliable cryptographic key. These cryptographic keys can be used for various purposes, such as establishing a reliable communication channel between hosts. The present disclosure describes a method for distributing quantum entropy generated by a quantum entropy source through an ephemerally (temporarily) keyed lattice cryptographic network to all hosts (e.g., virtual machine computing instances and / or bare metal computing instances). Here, a host that receives the quantum entropy may not be connected to the entropy source and may not have a local source of reliable entropy information.

[0112] FIG. 6 is a diagram showing a simplified flowchart 600 of steps executed by a second host during a process for distributing or transmitting entropy information generated by a quantum entropy generation unit 705 to a plurality of hosts and a plurality of computing instances according to a specific embodiment. The processes shown in FIG. 6 may be implemented by software (e.g., code, instructions, programs) executed by one or more processing devices (e.g., processors, cores) of each system, may be implemented using hardware, or may be implemented by a combination thereof. The software may be stored on a non-transitory storage medium (e.g., on a storage device). The method presented in FIG. 6 and described hereinafter is illustrative and not limiting. Although FIG. 6 shows various processing steps being performed in a specific order or sequence, this is not limiting. In certain alternative embodiments, the processing may be executed in a different order, and some steps may be executed in parallel. In a specific embodiment, such as the embodiment shown in FIG. 1, the processing shown in FIG. 6 may be executed by host B 720. In some embodiments, the second host described hereinafter in FIG. 6 may represent host B 720, and the first host described hereinafter in FIG. 6 may represent host A 710.

[0113] The quantum entropy generation unit 705 (or another suitable reliable source of entropy) may generate quantum entropy. In some embodiments, the quantum entropy generation unit 705 may generate a stream of quantum entropy. The stream of quantum entropy may then be made distributable to one or more connected computer systems.

[0114] The first host receives quantum entropy from the quantum entropy generation unit 705. The first host may be directly connected to the quantum entropy generation unit 705. In certain embodiments, the host machine hosting the first host may be directly connected to the quantum entropy generation unit 705. Any suitable amount of the quantum entropy generated by the quantum entropy generation unit 705 may be received. For example, 128 bits, 256 bits, 512 bits, 1024 bits, 2048 bits, or other suitable amounts of quantum entropy may be transmitted by the quantum entropy generation unit 705 and received by the first host. In certain embodiments, the quantum entropy may be transmitted in the form of a stream of quantum entropy.

[0115] Entropy information is transmitted from the quantum entropy generation unit 705 to the first host via a reliable connection. For example, the entropy information may be transmitted via a direct local wired connection that is not connected to the Internet and / or other networks between the quantum entropy generation unit 705 and the first host (or between the quantum entropy generation unit 705 and the host machine hosting the first host). The cable used for the wired connection may also be protected from external interference or tampering or snooping. In addition to, or instead of, this, the quantum entropy may be transmitted in an encrypted form.

[0116] The first host may generate a first set of one or more cryptographic keys using a first portion of the quantum entropy received by the first host from the quantum entropy generation unit 705. For example, the first host may generate a first public key for use in an initial key exchange with a second host to establish an initial communication channel. The size of the first portion of the quantum entropy may be any suitable size, such as 256 bits or 512 bits of quantum entropy.

[0117] As shown in FIG. 6, in S602, the second host generates a second set consisting of one or more cryptographic keys for use when establishing the first communication channel with the first host. For example, the second host may generate a second public key for use in the first key exchange with the first host. Since the second host still does not have access to the quantum entropy generated by the quantum entropy generation unit 705, other entropy information such as a data string generated by a software-based pseudo-random number generator or another type of untrusted entropy source may be used for the key generation process. The entropy generated by these sources may not be as secure or trustworthy as the quantum entropy generated by the quantum entropy generation unit 705.

[0118] In S604, the second host may establish the first communication channel with the first host using the first set consisting of one or more cryptographic keys generated by the first host and the second set of cryptographic keys generated in step S602. As part of the processing in S604, the second host and the first host may perform an initial key exchange to create an initial shared key (e.g., a symmetric key). This may include exchanging information based on the first set of cryptographic keys generated by the first host and exchanging information based on the second set of cryptographic keys generated by the second host in S602. In some embodiments, the information exchange may include an elliptic curve Diffie-Hellman key sharing protocol.

[0119] As described above, the first communication channel is established using the first set of cryptographic keys generated by the first host using a part of the quantum entropy received from the quantum entropy generation unit 705, and the second set of cryptographic keys generated by the second host using entropy that is not as trustworthy because it is not the entropy from the quantum entropy generation unit 705. Therefore, the first communication channel is a connection having encryption strength derived from asymmetric entropy. This first communication channel can be a communication channel that is reliable enough to transmit at least some of the secret information to the second host without being disrupted or exposed to danger. Thus, although described later with respect to S508, the first communication channel is used for the first host to transmit a portion of the quantum entropy received from the quantum entropy generation unit 705 to the second host.

[0120] In S606, the second host receives, from the first host via the first communication channel, a portion (e.g., the second portion) of the quantum entropy received by the first host from the quantum entropy generation unit 705. In certain embodiments, the first communication channel is a connection having encryption strength derived from asymmetric entropy, where only one encryption key set used to establish the communication channel is generated using the entropy information generated by the quantum entropy generation unit 705, so the first host can take precautions to transmit the entropy information in S606. For example, the entropy information can be transmitted in encrypted form over the first communication channel from the first host to the second host. The first host can first encrypt a portion (the second portion) of the quantum entropy to be transmitted to the second host and then transmit the encrypted entropy information to the second host. In certain embodiments, the entropy information may be encrypted using the first symmetric key created in step S604. The second host can decrypt the encryption using the first symmetric key when it receives the second portion of the quantum entropy. The size of the second portion of the quantum entropy can be any suitable size, such as 256-bit or 512-bit quantum entropy.

[0121] After S606, both the first host and the second host can access the entropy information generated by the quantum entropy generation unit 705. The first host has previously received this information (and may also receive additional entropy information at this time), and the second host receives the entropy information in S606. Since both have reliable entropy information generated by the quantum entropy generation unit 705, a connection with cryptographic strength derived from symmetric entropy can be set up between the first host and the second host. This will be described later in steps S608 and S610.

[0122] The first host may generate a third set of one or more cryptographic keys using a part (for example, the third part) of the quantum entropy received from the quantum entropy generation unit 705. For example, the first host may generate a third public key for use in a second key exchange with the second host to establish a secure channel. The size of the third part of the quantum entropy can be any appropriate size, such as 256-bit or 512-bit quantum entropy.

[0123] In S608, the second host may generate a fourth set of one or more cryptographic keys using a part of the quantum entropy generated by the quantum entropy generation unit 705 and received by the second host. For example, the second host may generate a fourth public key for use in a second key exchange with the first host to establish a secure communication channel. The second host may use some or all of the quantum entropy received by the second host when generating the fourth set of cryptographic keys. For example, if the size of a part of the quantum entropy received by the second host is 512 bits, the second host may use all of the 512-bit entropy information or less bits (for example, 256 bits) of entropy information to generate a fourth set of one or more public keys.

[0124] In S610, the second host can establish a secure communication channel between the first host and the second host by using a fourth set consisting of one or more encryption keys generated by the second host in step S608 and a third set consisting of one or more encryption keys generated by the first host. In some embodiments, the amount of entropy information generated by the quantum entropy generation unit received by the second host on the first half secure channel in S606 is just enough to facilitate establishing a secure communication channel between the first host and the second host. For example, the amount of entropy information transmitted in S606 can be just enough for the second host to generate a fourth set of encryption keys used to establish a secure communication channel in S610. As part of the processing in S606, the first host and the second host can perform a second key exchange to create a second shared key (e.g., a symmetric key). This can include exchanging the fourth set of encryption keys generated in S608 and exchanging the third set of encryption keys generated by the first host. In some embodiments, this can include an elliptic curve Diffie-Hellman exchange. Since both sets of encryption keys used to establish the communication channel are generated using the entropy information generated by the quantum entropy generation unit 705, the communication channel established in S610 is a connection with encryption strength derived from symmetric entropy. Thus, the communication channel established in S610 is considered to be a completely secure communication channel. Subsequently, this secure communication channel is used by the second host to further receive from the first host a part of the quantum entropy information received by the first host from the quantum entropy generation unit 705. This communication channel can also be used for other purposes such as exchanging one or more messages between the second host and the first host. In some embodiments, the amount of entropy information generated by the quantum entropy generation unit received by the second host on the first half secure channel in S606 is just enough to facilitate establishing a secure communication channel between the first host and the second host. For example, the amount of entropy information transmitted in S606 can be just enough for the second host to generate a fourth set of encryption keys used to establish a secure communication channel in S610. As part of the processing in S606, the first host and the second host can perform a second key exchange to create a second shared key (e.g., a symmetric key). This can include exchanging the fourth set of encryption keys generated in S608 and exchanging the third set of encryption keys generated by the first host. In some embodiments, this can include an elliptic curve Diffie-Hellman exchange.

[0125] Since both sets of encryption keys used to establish the communication channel are generated using the entropy information generated by the quantum entropy generation unit 705, the communication channel established in S610 is a connection with encryption strength derived from symmetric entropy. Thus, the communication channel established in S610 is considered to be a completely secure communication channel. Subsequently, this secure communication channel is used by the second host to further receive from the first host a part of the quantum entropy information received by the first host from the quantum entropy generation unit 705. This communication channel can also be used for other purposes such as exchanging one or more messages between the second host and the first host.

[0126] In S612, the second host may receive, via the secure communication channel established in S610, another part (e.g., the fourth part) of the quantum entropy generated by the received quantum entropy generation unit from the first host. For example, the first host may encrypt the fourth part of the quantum entropy using the second symmetric key created in step S610, the first host may send the encrypted fourth part of the quantum entropy to the second host, and the second host may decrypt the encryption of the fourth part of the quantum entropy using the second symmetric key. In certain embodiments, the entropy information may be transmitted as a stream of information. The size of the fourth part of the quantum entropy may be any suitable size, such as 256-bit or 512-bit quantum entropy.

[0127] The second host may use the fourth part of the quantum entropy received from the first host via the secure communication channel in S612. For example, the second host may use the fourth part of the quantum entropy for the operation of one or more applications.

[0128] In certain embodiments, to maintain the security of the communication channel established in S610, the encryption material (e.g., encryption key) associated with the connection itself is regenerated to maintain a secure communication channel. For example, as shown in FIG. 6, in S614, after certain conditions are met, the first host and the second host may generate new encryption keys used to update the secure communication channel and / or establish a new secure communication channel. Here, the new encryption key is also generated using a part of the quantum entropy information available to the first host and the second host. This may be repeated each time the regeneration condition is met or occurs. This may also be referred to as encryption key rotation. Since the encryption key is only valid for a specific period before being regenerated, it may also be referred to as an ephemeral encryption key.

[0129] In one embodiment, either the second host or the first host may generate a new set consisting of one or more cryptographic keys using the quantum entropy available to the host. In the case of the first host, the entropy information used to generate the ephemeral cryptographic key is received from the quantum entropy generation unit 705 via the connection between the quantum entropy generation unit 705 and the first host. In a particular embodiment, the quantum entropy generation unit 705 may be configured to continuously transmit a stream of quantum entropy information to the first host. In the case of the second host, the quantum entropy used to generate the ephemeral cryptographic key may be received from the first host via the secure communication channel established in S610 by the second host through the secure communication channel established.

[0130] Various different conditions may trigger the regeneration of cryptographic material (e.g., cryptographic keys) in S610. In a particular embodiment, the trigger condition may be a time-based condition. For example, a pre-configured period for the connection may be configured, and after that period, it is necessary to regenerate the cryptographic key to maintain the channel. This pre-configured period may be, for example, a specific number of seconds, a specific number of minutes, a specific number of hours, etc. For example, after 30 seconds, 1 minute, 5 minutes, 10 minutes, 30 minutes, etc.

[0131] In some other embodiments, the trigger condition may be based on a pre-configured number of packets or messages being exchanged between the first host and the second host. For example, after 1 packet, 2 packets, 5 packets, 10 packets, 20 packets, or generally, after "N" packets, the regeneration of the encryption key may be triggered. Here, "N" varies depending on the degree to which the entropy customer can tolerate the risk. A high value of N corresponds to a low ephemeral key and a high potential risk of entropy tampering. In the case of the lowest risk tolerance, the value of N can be set to 1. This results in the encryption key being a very ephemeral encryption key. The encryption key rotation rate can be based on the degree to which the entropy customer desires to be exposed to an acceptable risk. The clustering graph network shown in FIGS. 1 and 7 represents the fastest possible rate of entropy consumption required to maintain strong ephemeral keys between all connections between all hosts in the network. This is because the product of the key rotation rate and the clustering coefficient of the graph of the computer network determines the rate at which entropy itself is consumed in the process of distributing entropy to the hosts. For fast key rotation, as the connection time between hosts in the network increases, the trust level of the connection increases logarithmically by a factor of the reciprocal of "N". This connection period is represented by the value of N above, or the number of packets exchanged between these two hosts before the two hosts regenerate the ephemeral key again.

[0132] As described above, the specific order or sequence of the steps shown in FIG. 6 is not limiting. In certain other embodiments, these steps may be executed in a different order, and some steps may be executed in parallel.

[0133] In the embodiment described with reference to FIG. 6, the entropy information generated by the quantum entropy generation unit 705 is transmitted to the first host. In a particular embodiment, the transmission of this entropy information from the entropy source to the host directly connected to the entropy source may be performed as a one-time event. In other embodiments, the transmission of the quantum entropy information from the entropy source to the host directly connected to the entropy source may be performed periodically. Here, after each period, the new entropy information generated by the entropy source is transmitted to the connected host. In still other embodiments, the transmission of the quantum entropy information from the entropy source to the host directly connected to the entropy source may be performed continuously as a stream of entropy information generated by the entropy source and transmitted to the connected host. In some other embodiments, the entropy information may be transmitted from the entropy source to the host when the host requests this information. For example, the host may send a request for entropy information to the entropy source, and then the entropy source may respond to this request by sending the requested entropy information generated by the entropy source to the requesting host. Other transmission mechanisms may be used in other embodiments.

[0134] The transmission of entropy information from one host to another (e.g., from a first host to a second host) may be performed according to various different modes. In one embodiment, as a one-time event, the first host may transmit entropy information to the second host over a secure communication channel established between these two hosts. In other embodiments, the transmission of quantum entropy information from the first host to the second host may be performed periodically over a secure communication channel. Here, after each period, new entropy information is transmitted from the first host to the second host. Here, the new entropy information may be part of the entropy information received by the first host from an entropy source or another host. In still other embodiments, the transmission of quantum entropy information from the first host to the second host may be performed continuously as a stream of entropy information over a secure communication channel established between the hosts. In some other embodiments, the entropy information may be transmitted from the first host to the second host when the second host requests this information. For example, the second host may send a request for entropy information to the first host, and then the first host may respond to this request by transmitting the requested entropy information to the requesting second host. Other transmission mechanisms may be used in other embodiments.

[0135] The process shown in FIG. 6 shows how the entropy generated by an entropy source can be received by a host (e.g., the second host) from another host (e.g., the first host) communicatively coupled to the second host. Here, the first host initially receives entropy from an entropy source (e.g., the quantum entropy generation unit 705). The second host may or may not be connected to the entropy source. The second host that has received the entropy information may distribute a part of the received entropy information to other hosts communicatively coupled to the second host. In this way, the entropy information generated by the entropy source can be securely distributed to a plurality of hosts in an environment with a distributed network connection. The entropy can be transferred to a host that is some distance away from the entropy source (e.g., from the quantum entropy generation unit 705). For example, after the second host receives quantum entropy from the first host, the second host transfers a part of the received quantum entropy to the third host, and the third host transfers it to other connected hosts... and so on.

[0136] As described above, even if the host is not directly connected to the entropy source, a host on the network (e.g., on a lattice network) can obtain access to entropy information such as quantum entropy generated by a reliable entropy generation source. Since the quality of the quantum entropy information received by the host is high and trustworthy, the received entropy information can be used for various operations that require high reliability. For example, the quantum entropy may be used by the host to generate a reliable encryption key. These encryption keys can be used for various purposes, such as establishing a reliable communication channel between hosts. The present disclosure describes a method for distributing quantum entropy generated by a quantum entropy source through an ephemerally (temporarily) keyed lattice cryptographic network to all hosts (e.g., virtual machine computing instances and / or bare metal computing instances). Here, the host that receives the quantum entropy may not be connected to the entropy source and may not have a local source of reliable entropy information.

[0137] FIG. 8 is a diagram showing an exemplary computer system 800 that can be used to implement a particular embodiment. For example, in some embodiments, the computer system 800 is utilized to implement any of the hosts or computer systems shown in FIGS. 1 and / or 7, as well as the various servers and computer systems described above. As shown in FIG. 8, the computer system 800 includes a plurality of other subsystems that communicate with a processing subsystem 804 via a bus subsystem 802, and includes various subsystems. These other subsystems may include a processing acceleration device 806, an I / O subsystem 808, a storage subsystem 818, and a communication subsystem 824. The storage subsystem 818 includes a non-transitory computer-readable storage medium including a storage medium 822 and a system memory 810. As shown in FIG. 8, the computer system 800 includes a plurality of other subsystems that communicate with a processing subsystem 804 via a bus subsystem 802, and includes various subsystems. These other subsystems may include a processing acceleration device 806, an I / O subsystem 808, a storage subsystem 818, and a communication subsystem 824. The storage subsystem 818 includes a non-transitory computer-readable storage medium including a storage medium 822 and a system memory 810.

[0138] The bus subsystem 802 provides a mechanism for enabling the various components and subsystems of the computer system 800 to communicate with each other as intended. Although the bus subsystem 802 is illustrated as a single bus, other embodiments of the bus subsystem may utilize multiple buses. The bus subsystem 802 may be any of several types of bus structures including a memory bus or memory controller using various bus architectures, a peripheral bus, a local bus, and the like. For example, such architectures may include an ISA (Industry Standard Architecture) bus, an MCA (Micro Channel Architecture) bus, an EISA (Enhanced ISA) bus, a VESA (Video Electronics Standards Association) local bus, and a PCI (Peripheral Component Interconnect) bus, which may be implemented as a Mezzanine bus manufactured in accordance with standards such as the IEEE P1386.1 standard.

[0139] The processing subsystem 804 controls the operation of the computer system 800 and may include one or more processors, application specific integrated circuits (ASICs), or field programmable gate arrays (FPGAs). These processors may be single-core processors or multi-core processors. The processing resources of the computer system 800 may be grouped together in one or more processing devices 832, 834, etc. The processing device may include one or more processors, one or more cores from the same or different processors, a combination of cores and processors, or other combinations of cores and processors. In some embodiments, the processing subsystem 1704 may include one or more dedicated coprocessors such as a graphics processor, a digital signal processor (DSP), etc. In some embodiments, some or all of the processing devices of the processing subsystem 804 may be implemented using custom circuits such as ASICs (application specific integrated circuits) or FPGAs (field programmable gate arrays).

[0140] In some embodiments, the processing device in the processing subsystem 804 may execute instructions stored in the system memory 810 or instructions stored on the computer-readable storage medium 822. In various embodiments, the processing device can execute various programs or code instructions and can maintain multiple simultaneously executing programs or processes. At any time, some or all of the program code being executed may be present in the system memory 810 and / or, optionally, on one or more storage devices, may be present on the computer-readable storage medium 822. With appropriate programming, the processing subsystem 804 can provide the various functions described above. If the computer system 800 is executing one or more virtual machines, one or more processing devices may be assigned to each virtual machine.

[0141] In certain embodiments, a processing acceleration device 806 may optionally be provided to reduce the load of some of the processes executed by the processing subsystem 804 for executing customized processing or to speed up the overall processing executed by the computer system 800.

[0142] The I / O subsystem 808 may include devices and mechanisms for inputting information into the computer system 800 and / or devices and mechanisms for outputting information via or from the computer system 800. Generally, the term "input device" is intended to include any type of device and mechanism for inputting information into the computer system 800. User interface input devices may include, for example, a keyboard, a pointing device such as a mouse or trackball, a touchpad or a touch screen incorporated into a display, a scroll wheel, a click wheel, a dial, a button, a switch, a keypad, a voice input device having a voice command recognition system, a microphone, and other types of input devices. Also, the user interface input devices may include motion detection devices and / or gesture recognition devices such as the Microsoft Kinect (registered trademark) motion sensor that enable a user to control and interact with the input device, the Microsoft Xbox (registered trademark) 360 game controller, and devices that provide an interface for receiving input using gesture commands and voice commands. Further, the user interface input devices may include eye gesture recognition devices such as the Google Glass (registered trademark) blink detection device that detects a user's eye movement (e.g., a "blink" while taking a photo and / or making a menu selection) and transforms the eye behavior into an input to the input device (e.g., Google Glass (registered trademark)). In addition to this, the user interface input devices may include a voice recognition detection device that enables a user to interact with a voice recognition system (e.g., the Siri (registered trademark) navigator) by voice commands.

[0143] Examples of other user interface input devices include, but are not limited to, 3D mice, joysticks or pointing sticks, game pads, graphic tablets, and audio / visual devices such as speakers, digital cameras, digital camcorders, portable media players, webcams, image scanners, fingerprint scanners, barcode readers, 3D scanners, 3D printers, laser rangefinders, and eye-tracking devices. In addition to these, the user interface input device may include, for example, medical image input devices such as computed tomography, magnetic resonance imaging, positron emission tomography, and ultrasonic examination devices. Also, the user interface input device may include, for example, audio input devices such as MIDI keyboards, digital musical instruments, and the like.

[0144] In general, the use of the term "output device" is intended to include any type of device and mechanism for outputting information from the computer system 800 to the user or another computer. The user interface output device may include non-visual display devices such as a display subsystem, indicator lights, or audio output devices. The display subsystem may be a flat panel display device such as one using a CRT (cathode ray tube), LCD (liquid crystal display), or plasma display, a projection device, a touch screen, or the like. For example, the user interface output device may include, but is not limited to, various display devices for visually conveying text, graphics, and audio / video information, such as monitors, printers, speakers, headphones, automotive navigation systems, plotting devices, audio output devices, and modems.

[0145] The storage subsystem 818 provides a repository or data store for storing the information and data used by the computer system 800. The storage subsystem 818 provides a tangible non-transitory computer-readable storage medium for storing the basic programming structures and data structures that provide the functionality of some embodiments. It does so. The storage subsystem 818 stores software (e.g., programs, code modules, instructions) that provides the above-described functions when executed by the processing subsystem 804. The software can be executed by one or more processing devices of the processing subsystem 804. Also, the storage subsystem 818 can provide a repository for storing data used in accordance with the teachings of the present disclosure.

[0146] The storage subsystem 818 may include one or more non-transitory memory elements, including volatile and non-volatile memory elements. As shown in FIG. 8, the storage subsystem 818 includes a system memory 810 and a computer-readable storage medium 822. The system memory 810 may include several memories, including a volatile main RAM (Random Access Memory) for storing instructions and data during program execution, and a non-volatile ROM (Read Only Memory) or flash memory in which fixed instructions are stored. In some implementations, the BIOS (Basic Input / Output System), including basic routines that assist in transferring information between elements within the computer system 800, such as during startup, may typically be stored in the ROM. The RAM typically includes data and / or program modules that the processing subsystem 804 is currently operating on and executing. In some implementations, the system memory 810 may include multiple different types of memories, such as SRAM (Static Random Access Memory) or DRAM (Dynamic Random Access Memory).

[0147] As an example, as shown in FIG. 8, the system memory 810 may load, but is not limited to, a running application program 812 (which may include various applications such as a web browser, a mid-tier application, a relational database management system (RDBMS), etc.), program data 814, and an operating system 816. As an example, the operating system 816 may include various versions of Microsoft Windows (registered trademark), Apple Macintosh (registered trademark), and / or Linux (registered trademark) operating systems, various distributed UNIX (registered trademark) or UNIX-like operating systems (including, but not limited to, various GNU / Linux operating systems, Google Chrome (registered trademark) OS, etc.), and / or mobile operating systems such as iOS, Windows (registered trademark) Phone, Android (registered trademark) OS, BlackBerry (registered trademark) OS, Palm (registered trademark) OS, and others.

[0148] The computer-readable storage medium 822 can store programming structures and data structures that provide the functionality of some embodiments. The computer-readable medium 822 can provide storage for computer-readable instructions, data structures, program modules, and other data for the computer system 800. Software (programs, code modules, instructions) that provides the above-described functionality when executed by the processing subsystem 804 can be stored in the storage subsystem 818. As an example, the computer-readable storage medium 822 may include non-volatile memory such as a hard disk drive, a magnetic disk drive, an optical disk drive such as a CD ROM, a DVD, a Blu-Ray (registered trademark) disk, or other optical media. The computer-readable storage medium 822 may include, but is not limited to, a Zip (registered trademark) drive, a flash memory card, a USB (Universal Serial Bus) flash drive, an SD (Secure Digital) card, a DVD disk, a digital video tape, etc. The computer-readable storage medium 822 may include SSDs (Solid-State Drives s) based on non-volatile memory such as flash memory-based SSDs, enterprise flash drives, solid-state ROMs, SSDs based on volatile memory such as solid-state RAM, dynamic RAM, static RAM, DRAM-based SSDs, magnetoresistive RAM (MRAM) SSDs, and hybrid SSDs that use a combination of DRAM-based SSDs and flash memory-based SSDs.

[0149] In certain embodiments, the storage subsystem 800 may include a computer-readable storage medium reader 820 that can be further connected to the computer-readable storage medium 822. The reader 820 may be configured to receive and read data from a storage device such as a disk, a flash drive, etc.

[0150] In certain embodiments, computer system 800 may be adapted to, but not limited to, virtualization techniques including virtualization of processing resources and memory resources. For example, computer system 800 may provide support for running one or more virtual machines. In certain embodiments, computer system 800 may execute a program such as a hypervisor that facilitates the configuration and management of virtual machines. Memory, computers (e.g., processors, cores), I / O, and networking resources may be allocated to each virtual machine. Each virtual machine generally operates independently of other virtual machines. A virtual machine may execute its own operating system. This operating system may be the same as or different from the operating systems executed by other virtual machines executed by computer system 800. Thus, in some cases, multiple operating systems may be executed simultaneously by computer system 800.

[0151] Communication subsystem 824 provides an interface to other computer systems and networks. Communication subsystem 824 functions as an interface for receiving data from computer system 800 and transmitting data from computer system 800 to other systems. For example, communication subsystem 824 enables computer system 800 to establish a communication channel to one or more client devices via the Internet for receiving and transmitting information with the client devices. For example, the communication subsystem may be used to establish a communication channel and / or transmit quantum entropy to other computers.

[0152] The communication subsystem 824 may support both wired and / or wireless communication protocols. For example, in certain embodiments, the communication subsystem 824 may include RF (Radio Frequency) transceiver components, GPS (Global Positioning System) receiver components, and / or other components for accessing a wireless voice network and / or data network (e.g., using cellular phone technology, next-generation data network technologies such as 3G, 4G, or EDGE (Enhanced Data Rates For Global Evolution), WiFi (IEEE802.XX family of standard specifications), other mobile communication technologies, or any combination thereof). In some embodiments, the communication subsystem 824 may provide wired network connectivity (e.g., Ethernet (registered trademark)) in addition to, or instead of, a wireless interface.

[0153] The communication subsystem 824 can send and receive data in various formats. For example, in some embodiments, in addition to other formats, the communication subsystem 824 may receive an input communication message in the form of structured and / or unstructured data feeds 826, event streams 828, event updates 830, etc. For example, the communication subsystem 824 may be configured to receive (or send) data feeds 826 in real time from users of social media networks and / or other communication services, such as Twitter (registered trademark) feeds, Facebook (registered trademark) updates, web feeds such as RSS (Rich Site Summary) feeds, and / or real-time updates from one or more third-party information sources.

[0154] In certain embodiments, communication subsystem 824 may be configured to receive data in the form of a continuous data stream, which may include an event stream 828 of continuous or infinite real-time events and / or event updates 830 that are essentially without a distinct end. Examples of applications that generate continuous data may include sensor data applications, tickers, network performance measurement tools (e.g., network monitoring and traffic management applications), clickstream analysis tools, automotive traffic monitoring, and the like.

[0155] Also, communication subsystem 824 may be configured to transmit data from computer system 800 to other computer systems or networks. This data may be transmitted to one or more databases that may be in communication with one or more streaming data source computers connected to computer system 800 in various different formats, such as structured and / or unstructured data feeds 826, event streams 828, event updates 830, and the like.

[0156] Computer system 800 can be one of various types, including a palm-sized portable device (e.g., an iPhone® mobile phone, an iPad® computing tablet, a PDA), a wearable device (e.g., a Google Glass® head-mounted display), a personal computer, a workstation, a mainframe, a kiosk, a server rack, or other data processing systems. Due to the ever-changing nature of computers and networks, the description of computer system 800 shown in FIG. 8 is merely illustrative. Many other configurations with more or fewer components than the system shown in FIG. 8 are possible.

[0157] While specific embodiments have been described, various modifications, alternatives, alternative configurations, and equivalents are also possible. Embodiments are not limited to operating within a specific data processing environment and can operate freely within multiple data processing environments. In addition to this, while specific embodiments have been described using a particular sequence of transactions and steps, this is not limiting. There were also flowcharts showing the operations as sequential processes, but many of these operations may be executed in parallel or simultaneously. In addition to this, the order of the operations may be rearranged. The process may have additional steps not included in the figures.

[0158] Furthermore, while specific embodiments have been described using a particular combination of hardware and software, it should be recognized that other combinations of hardware and software are also possible. A particular embodiment may be implemented using only hardware, only software, or a combination thereof. The various processes described herein can be implemented on the same processor or on different processors in any combination.

[0159] Where a device, system, component, or module is described as being configured to perform a particular operation or function, such a configuration can be achieved, for example, by designing an electronic circuit to perform this operation, by programming a programmable electronic circuit (such as a microprocessor) to execute a computer instruction or code to perform this operation, or by designing a processor or core programmed to execute code or instructions stored on a non-transitory memory medium, or by any combination thereof. Processes can communicate using a variety of techniques including, but not limited to, prior art for inter-process communication, and different pairs of processes may use different techniques, and the same pair of processes may use different techniques at different times. While specific embodiments have been described using a particular combination of hardware and software, it should be recognized that other combinations of hardware and software are also possible. A particular embodiment may be implemented using only hardware, only software, or a combination thereof. The various processes described herein can be implemented on the same processor or on different processors in any combination.

[0160] Specific details have been set forth in this disclosure in order to provide a thorough understanding of the embodiments. However, the embodiments could be practiced without these specific details. For example, well-known circuits, processes, algorithms, structures, and techniques have been illustrated without unnecessary detail in order not to obscure the embodiments. This description is merely providing exemplary embodiments and does not limit the scope of the claims, the availability, or the configuration of other embodiments. Rather, the description of the above embodiments provides an enabling description for implementing various embodiments. Various changes may be made to the functions and arrangements of the elements.

[0161] Accordingly, the specification and drawings should be regarded as illustrative rather than restrictive. However, it will be apparent that additions, subtractions, deletions, as well as other changes and modifications may be made to the specification and drawings without departing from the broader spirit and scope of the appended claims. Thus, while specific embodiments have been described, these are not limiting. Various variations and equivalents are included within the scope of the appended claims.

Claims

1. A method comprising: a first host receiving entropy information from an entropy source; establishing a communication channel between the first host and a second host using one or more encryption keys, all of the one or more encryption keys being generated using at least a portion of the entropy information; further comprising transmitting, via the communication channel established between the first host and the second host, another portion of the entropy information from the first host to the second host.

2. The method according to claim 1, wherein the entropy source is a quantum entropy generation unit and the entropy information is quantum entropy.

3. The method according to claim 1 or 2, wherein the first host is hosted by a first host machine and the second host is hosted by a second host machine.

4. The communication channel is a second communication channel, establishing a first communication channel between the first host and the second host based on a first set of one or more encryption keys generated by the first host using a first portion of the entropy information and based on a second set of one or more encryption keys generated by the second host; further comprising transmitting, via the first communication channel, a second portion of the entropy information from the first host to the second host.

5. Establishing the second communication channel comprises: the first host generating a third set of one or more encryption keys using a third portion of the entropy information; the second host generating a fourth set of one or more encryption keys using a first portion of the second portion of the entropy information received by the second host from the first host; establishing the second communication channel between the first host and the second host based on the third set of one or more encryption keys and the fourth set of one or more encryption keys.

6. Establishing the first communication channel includes performing a first ephemeral Diffie-Hellman key exchange using a first set consisting of the one or more cryptographic keys and a second set consisting of the one or more cryptographic keys. Establishing the second communication channel includes performing a second ephemeral Diffie-Hellman key exchange using a third set consisting of the one or more cryptographic keys and a fourth set consisting of the one or more cryptographic keys. The method according to claim 5.

7. The first ephemeral Diffie-Hellman key exchange is a first ephemeral elliptic curve Diffie-Hellman key exchange, and the second ephemeral Diffie-Hellman key exchange is a second ephemeral elliptic curve Diffie-Hellman key exchange. The method according to claim 6.

8. The second part of the entropy information includes "N" bits, and the second host generates a fourth set consisting of the one or more cryptographic keys based on the "N" bits. The method according to claim 4, 5, 6, or 7.

9. Determining that conditions related to the second communication channel are satisfied; In response to determining that the conditions are satisfied; The first host regenerates a new first set consisting of one or more cryptographic keys using a fifth part of the entropy information; The second host regenerates a new second set consisting of one or more cryptographic keys using a second part of the second part of the entropy information received from the first host; The method according to claim 5, 6, 7, or 8, further including updating the second communication channel between the first host and the second host based on the new first set consisting of the one or more cryptographic keys and the new second set consisting of the one or more cryptographic keys.

10. Determining that the conditions related to the second communication channel are satisfied includes determining that a specific period has elapsed. The method according to claim 9.

11. Determining that the conditions related to the second communication channel are satisfied includes determining that a specific number of packets have been exchanged between the first host and the second host. The method according to claim 9.

12. The method according to any one of claims 1 to 11, wherein both the first host and the second host are hosted by a first host machine.

13. A non-transitory computer-readable storage medium storing computer-executable instructions, which when executed, cause one or more processors of a computer system at a first host to execute a method, the method comprising: receiving entropy information from an entropy source; establishing a communication channel between the first host and a second host using one or more cryptographic keys, all of the one or more cryptographic keys being generated using at least a portion of the entropy information, the method further comprising: transmitting the other portion of the entropy information to the second host using the communication channel established between the first host and the second host.

14. The communication channel is a second communication channel, establishing a first communication channel between the first host and the second host based on a first set of one or more cryptographic keys generated by the first host using a first portion of the entropy information and based on a second set of one or more cryptographic keys generated by the second host; The non-transitory computer-readable storage medium according to claim 13, further comprising transmitting a second portion of the entropy information from the first host to the second host using the first communication channel.

15. Establishing the second communication channel comprises: generating a third set of one or more cryptographic keys using a third portion of the entropy information, the second host generating a fourth set of one or more cryptographic keys using a first portion of the second portion of the entropy information received from the first host, and establishing the second communication channel further comprises: establishing the second communication channel between the first host and the second host based on the third set of one or more cryptographic keys and the fourth set of one or more cryptographic keys. The non-transitory computer-readable storage medium according to claim 14.

16. The method further comprises: determining that conditions associated with the second communication channel are satisfied. In response to determining that the condition is satisfied, re - generating a new first set consisting of one or more encryption keys using the fifth part of the entropy information, and the second host re - generates a new second set consisting of one or more encryption keys using the second part of the second part of the entropy information received from the first host, and in response to determining that the condition is satisfied, further establishing a new communication channel between the first host and the second host based on the new first set consisting of the one or more encryption keys and the new second set consisting of the one or more encryption keys. The non - transitory computer - readable storage medium according to claim 15.

17. A first computer system, comprising a processor and a memory configured to store a plurality of instructions executable by the processor, and when the plurality of instructions are executed by the processor, cause a process to be executed, and the process receives entropy information from an entropy source, and establishes a communication channel between the first computer system and a second computer system using one or more encryption keys, and all of the one or more encryption keys are generated using at least a part of the entropy information, and the process further transmits the other part of the entropy information to the second computer system using the communication channel established between the first computer system and the second computer system. The first computer system.

18. The communication channel is a second communication channel, and the process establishes a first communication channel between the first computer system and the second computer system based on a first set consisting of one or more encryption keys generated by the first computer system using the first part of the entropy information and a second set consisting of one or more encryption keys generated by the second computer system, and further includes transmitting the second part of the entropy information from the first computer system to the second computer system using the first communication channel. The first computer system according to claim 17.

19. Establishing the second communication channel generating a third set of one or more cryptographic keys using the third portion of the entropy information, wherein the second computer system generates a fourth set of one or more cryptographic keys using a first portion of the second portion of the entropy information received from the first computer system, and establishing the second communication channel further comprises establishing the second communication channel between the first computer system and the second computer system based on the third set of one or more cryptographic keys and the fourth set of one or more cryptographic keys, the first computer system according to claim 18.

20. The plurality of instructions further comprise determining that conditions associated with the second communication channel are met, and in response to determining that the conditions are met, regenerating a new first set of one or more cryptographic keys using a fifth portion of the entropy information, wherein the second computer system regenerates a new second set of one or more cryptographic keys using a second portion of the second portion of the entropy information received from the first computer system, and the plurality of instructions further comprise in response to determining that the conditions are met, updating the second communication channel between the first computer system and the second host based on the new first set of one or more cryptographic keys and the new second set of one or more cryptographic keys, the first computer system according to claim 19.

21. An apparatus comprising means for performing the steps of the method according to any one of claims 1 to 12.

22. A computer program product comprising computer instructions which, when executed by a processor, perform the steps of the method according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Encrypted message transmission / reception method and system, and transmitter device, receiver device, key server

    JP2007295366A

  • How to establish a private key between two nodes in a communication network

    JP2009545264A

  • Communication method and communication system

    JP2013179443A

  • Software-based switch for providing products and / or services to users without compromising their privacy - Patent Application 20070122963

    JP2019533852A

  • Multi-source entropy and randomness aggregation and distribution network

    US10402172B1