Optical path monitoring device and process
QLV addresses the vulnerability of optical paths in communication networks by using quantum interference of indistinguishable photons to ensure secure and continuous integrity verification, enhancing physical layer security without affecting data rates or network architecture.
Patent Information
- Application Number
- JP2025519641
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-10-05
- Filing Date
- 2023-10-05
- Publication Date
- 2025-10-03
AI Technical Summary
Existing communication networks are vulnerable to interception and tampering of optical paths due to lack of physical layer security, which current encryption methods like RSA and Quantum Key Distribution (QKD) fail to address effectively.
Implementing Quantum Link Verification (QLV) by superimposing quantum signals onto classical telecommunications systems to perform near-continuous integrity verification of optical paths using indistinguishable photons for interference analysis.
QLV ensures the physical integrity of optical paths, detecting eavesdropping attempts and maintaining secure communication links without disrupting data rates or network architecture limitations, while being adaptable to existing networks.
Smart Images

Figure 2025533114000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to secure (eg, encrypted) communications, and more particularly to light path monitoring devices and processes for assessing the physical integrity of a light path. [Background technology]
[0002] Secure communications are essential in many situations. For example, in military situations, secure and protected communications between allies is paramount in order to operate freely against adversaries. As is well known, the outcome of World War II was greatly influenced by the breaking of encryption codes in both major theaters. The breaking of the German Enigma code by Allied intelligence turned the tide of the U-boat war in the Atlantic, and the partial breaking of the JN-25b code gave the Americans a decisive advantage at the Battle of Midway.
[0003] Modern communications encryption is generally considered uncomputable because it is based on mathematical algorithms with trapdoor functions—operations whose results are easily computed but whose inverse operations require exponentially increasing computational resources. Factorization is one such trapdoor operation and is at the core of the "RSA" code developed by Rivest, Shamir, and Adleman, which is perhaps the most well-known encryption algorithm used to protect information today. Such codes are used to encrypt communications traffic on the World Wide Web, secure credit card transactions during online shopping, and protect locally stored information on shared systems. Early use of these codes was plagued by vulnerabilities due to short encryption key lengths (40 bits) and poor random seed management. In 1995, two doctoral students at Berkeley demonstrated that the then-standard encryption of the Netscape® web browser could be defeated by a sophisticated malicious agent capable of checking a list of possible random seed values in a matter of minutes. This and other demonstrations overcame export control restrictions and established today's 128-bit standard, which is generally considered impossible to crack by non-state actors.
[0004] In 1995, quantum mechanics was a small cloud on the horizon of internet security, but by 2015 it had become a technological storm that prompted the US National Security Agency (NSA) to begin its transition to the "post-quantum" (i.e., secure against quantum attacks) era. In 1994, Peter Shor published an algorithm for a hypothetical quantum machine operating with quantum bits ("qubits") that could efficiently find relatively prime numbers. In principle, the security of the RSA algorithm, and all cryptographic code that uses factorization as its security token, was weakened overnight.
[0005] However, in reality, such quantum machines are still far from reality in terms of capabilities today, but Shor's algorithm triggered a decades-long effort to build quantum machines (quantum computers) that could break encryption in time. While initially driven mostly by academic research groups, the advances and possibilities of quantum computing have led industry giants such as IBM®, Google®, and Microsoft® to join the global list of companies developing quantum computing technology, along with specialized startups such as PsiQuantum, Xanadu, and Rigetti.
[0006] Given these developments, in 2015, NSA recommended that "partners and vendors who have not yet made the transition to Suite B elliptic curve algorithms should refrain from making significant expenditures to do so at this time and instead prepare for the upcoming transition to quantum-resistant algorithms." (Suite B elliptic curve algorithms are used to protect foreign-releasable, U.S.-only, and classified information.) The practical obstacles to following this advice are twofold: 1) as of the end of 2020, these codes are not yet ready (NIST is conducting a multi-year, multi-round selection process); and 2) quantum-resistant codes require significantly more computational time, and therefore energy, than existing RSA codes, making them slower and more expensive to implement. Recognizing this, in 2019, NSA bought itself some time by replacing Suite B with the Commercial National Security Algorithm Suite (CNSA), which uses the same technology with longer keys.
[0007] Another, less favored post-quantum alternative, termed “Quantum Key Distribution” (or “QKD”), creates and distributes one-time keys based on the randomness of quantum measurements, allowing users to create asymptotically secure communication channels. While QKD is an emerging commercial product, its implementation is hampered by a number of significant limitations that make it difficult to integrate into existing networks. These include, but are not limited to, limited range (less than 100 km), restriction to point-to-point communications only, the need for dedicated systems for each communication channel and each site, and significantly lower data rates compared to current classical communications. These limitations explain the slow global adoption of QKD, its low ratings by both the UK’s Government Communications Headquarters (GCHQ) and the NSA, and its limited use to a few, admittedly high-profile, testbed scenarios.
[0008] It is desired to overcome or alleviate one or more of the problems of the prior art, or at least provide a useful alternative. Summary of the Invention
[0009] According to some embodiments of the present invention, the following steps are performed by a first node of an optical network: (i) generating photons that are at least partially indistinguishable in frequency, polarization, spatial mode, and temporal profile; (ii) transmitting a first one of the generated photons via an optical path to a remote node in the optical network; (iii) receiving a first photon from a remote node via the lightpath; (iv) interfering the received first photons with second ones of the generated photons to generate a quantum interference visualization output; (v) assessing the physical integrity of the optical path based on the quantum interference visualization output; A light path monitoring process is provided, including:
[0010] In some embodiments, the process includes repeating steps (i) through (v) to continuously monitor the physical integrity of the optical path.
[0011] In some embodiments, the first photon is transmitted and returned via the same optical path. In some embodiments, the first photon is transmitted and returned via a different optical path.
[0012] In some embodiments, the process includes storing the second photon for a period of time corresponding to a time delay between transmitting the first photon to the remote node and receiving the first photon from the remote node.
[0013] In some embodiments, the process includes generating the first photon and the second photon at different times corresponding to a time delay between transmitting the first photon to the remote node and receiving the first photon from the remote node.
[0014] In some embodiments, the process further comprises, prior to interfering step (iv): transmitting a second one of the generated photons via an additional optical path to a third node in the optical network; receiving a second photon from the third node via the additional optical path or the further additional optical path; Including, The step of assessing the physical integrity of the optical path based on the quantum interference visualization output includes simultaneously assessing the physical integrity of additional optical paths.
[0015] In some embodiments, the process comprises the following steps performed by the remote node: receiving a first photon from a first node; transmitting the first photon to the first node such that the indistinguishability of the frequency, polarization, spatial mode and temporal profile of each of the first photon and the second photon is not lost; Includes.
[0016] In some embodiments, the process further includes multiplexing a first photon of the generated photons with an optical communication signal, wherein the first photon and the optical communication signal are distinguishable in at least one of frequency, polarization, spatial mode, and temporal profile, and transmitting the first photon includes transmitting the multiplexed first photon and optical communication signal to the remote node via an optical path.
[0017] In some embodiments, the process further includes preventing subsequent communication with the remote node over the lightpath unless the physical integrity of the lightpath is assessed to be intact.
[0018] In some embodiments, the process comprises the following steps performed by the remote node: receiving a multiplexed first photon and an optical communication signal; separating a first photon from the optical communication signal; transmitting the first photon to the first node such that the indistinguishability of the frequency, polarization, spatial mode and temporal profile of each of the first photon and the second photon is not lost; Further includes:
[0019] According to some embodiments of the present invention, there is provided an optical path monitoring apparatus having components configured to perform any one of the above processes.
[0020] According to some embodiments of the present invention, there is provided an optical path monitoring apparatus including a first node, the first node comprising: a quantum photon source configured to generate photons that are indistinguishable in frequency, polarization, spatial mode, and temporal profile; one or more optical components configured to transmit a first one of the generated photons via an optical path to a remote node of the optical network and receive the first photon from the remote node via the optical path; a quantum interference component configured to interfere first photons received from the remote node with second photons of the generated photons to generate a quantum interference visualization output; a path integrity component configured to evaluate the physical integrity of the optical path based on the quantum interference visualization output; An optical path monitoring device is provided, comprising:
[0021] In some embodiments, the device is configured to continuously monitor the physical integrity of the optical path.
[0022] In some embodiments, the first photon is transmitted and returned via the same optical path. In some embodiments, the first photon is transmitted and returned via a different optical path.
[0023] In some embodiments, at least one of the optical paths includes a corresponding optical fiber path or waveguide, hi some embodiments, at least one of the optical paths is a corresponding free space optical path.
[0024] In some embodiments, the one or more optical components include a multiplexer component configured to multiplex a first one of the generated photons with an optical communication signal, wherein the first photon and the optical communication signal are distinguishable in at least one of frequency, polarization, spatial mode, and temporal profile, and the first photon is multiplexed with the optical communication signal and transmitted to the remote node.
[0025] In some embodiments, if the physical integrity of the optical path is assessed to be compromised, the path integrity component is configured to prevent subsequent communication with the remote node over the optical path.
[0026] In some embodiments, the apparatus includes a second node remote from the first node, the second node including optical components configured to receive the first photons from the first node and return the first photons to the first node such that indistinguishability in each of the frequency, polarization, spatial mode, and temporal profile of the first and second photons is not lost.
[0027] In some embodiments, the apparatus includes means for storing the second photon for a period of time corresponding to a time delay between transmitting the first photon to the remote node and receiving the first photon from the remote node.
[0028] In some embodiments, the quantum photon source is configured to generate the first photon and the second photon at different times corresponding to a time delay between transmitting the first photon to the remote node and receiving the first photon from the remote node.
[0029] In some embodiments, the one or more optical components are configured to transmit a second one of the generated photons to a third node of the optical network via an additional optical path and receive the second photon from the third node via the additional optical path or a further additional optical path, whereby the path integrity component evaluates the physical integrity of the optical path and the additional optical path based on the quantum interference visualization output. [Brief explanation of the drawings]
[0030] Some embodiments of the invention are herein described, by way of example only, with reference to the accompanying drawings, in which:
[0031] [Figure 1] 1 is a high-level block diagram of an apparatus for secure communications in accordance with some embodiments of the present invention; [Figure 2] FIG. 1 is a flow diagram of a process for secure communication according to some embodiments of the present invention. [Figure 3] 1 is a block diagram of an apparatus for secure communication according to some embodiments of the present invention. [Figure 4] FIG. 1 is a schematic diagram illustrating an apparatus for stochastic photon number resolved detection according to some embodiments of the present invention. [Figure 5] FIG. 1 is a block diagram of an apparatus for secure communication with multiple field nodes by temporal switching of photons between respective communication channels. [Figure 6] FIG. 1 is a block diagram of an apparatus for secure communication with multiple field nodes by simultaneous and parallel transmission of photons along respective communication channels. [Figure 7] FIG. 1 is a schematic block diagram of an apparatus for secure communication with multiple field nodes using a single quantum interference device. [Figure 8] 1 is a schematic block diagram of a communication network incorporating multiple instances of an apparatus for secure communications according to an embodiment of the present invention; DETAILED DESCRIPTION OF THE INVENTION
[0032] Embodiments of the present invention constitute a robust solution to the problem of physically securing communication links, thereby enabling the continued use of mature classical communication technologies with their speed and network advantages. Existing physical layer security typically relies on access restriction at the user terminal, for example through the use of swipe cards or two-factor authentication, to verify the user as a trusted identity before granting access to information within the system.
[0033] However, this does not protect the link over which communications are transmitted, leaving the information vulnerable to interception if an adversary gains access to the network infrastructure. Embodiments of the present invention address this shortcoming by superimposing quantum signals onto the channels of classical telecommunications systems to perform near-continuous integrity verification of the network (also referred to herein for convenience as "Quantum Link Verification" ("QLV").
[0034] The advantages of quantum link verification described herein over QKD include its use in existing communication networks, its lack of limitation to point-to-point architectures, and its ability to communicate securely at current data rates. QLV exploits the fact that quantum light (particles of light, photons) behaves quite differently from classical intensity light. In particular, QLV exploits two quantum phenomena: (i) "No Cloning": This ensures that a quantum state (such as a single photon) cannot be copied without destroying the state and information it holds. It is therefore impossible for an adversary to intercept and replicate a quantum state. This is used for key distribution to ensure the integrity of individual bits, whereas QLV is used to ensure the integrity of optical communication links. (ii) "Quantum Interference": Two indistinguishable single particles of light meeting at a 50% beam splitter do not follow the classically expected equal probability of being transmitted or reflected at the beam splitter. Instead, the photons coalesce and exit the beam splitter as a pair. This effect is known in the art as Hong-Ou-Mandel ("HOM") interference and is used in quantum photonics to measure the indistinguishability of photons because the probability of photon coalescence decreases as the two interfering photons become less similar. Perfect interference is indicated by a measured photon coincidence rate of zero after the beam splitter; as interference decreases, this rate increases.
[0035] Accordingly, embodiments of the present invention include optical path monitoring processes and apparatus that can assess the physical integrity of optical paths (i.e., links) between nodes of an optical network and whether that optical path may have been compromised. As used herein, the phrase "physical integrity" is understood to refer to integrity at the level of the optical network's physical layer, and the term "integrity" does not require or imply physical destruction or damage to the physical communication medium itself (e.g., by cutting or breaking an optical fiber, which is typically easy to detect), but rather whether the integrity of the optical path has been compromised, e.g., by eavesdropping or some form of tampering that changes the optical transmission characteristics of the optical path. Monitoring involves generating photons that are at least partially indistinguishable in frequency, polarization, spatial mode, and temporal profile. Each of these characteristics has a variety of possible values, and as a result, for any two photons, these values may overlap for some of the above characteristics and not for others. The phrase "partially distinguishable" (or equivalently "partially indistinguishable") refers to a situation where photons are indistinguishable in some measurements but distinguishable in others. Thus, photons that are "at least partially indistinguishable" in frequency, polarization, spatial mode, and temporal profile are indistinguishable in the measurement of at least one of these properties.
[0036] One of these at least partially indistinguishable photons (referred to herein for ease of reference as the "first" photon) is transmitted by the first node over an optical path to a second, remote node, returned by the remote node over the same or a different optical path, and received by the first node. The first node then interferes the first photon with another at least partially indistinguishable ("second") photon to produce an output referred to herein as a "quantum interference visualization" output, which indicates the physical integrity of the optical path.
[0037] In the described embodiments, the first and second photons are generated simultaneously, and the second photon is stored at the first node during the period in which the first photon is transmitted to and received from the remote node (typically, but not necessarily, as described below). However, in some alternative embodiments, the first and second photons are generated at different times corresponding to the time delay between transmitting the first photon to the remote node and receiving the first photon from the remote node. Clearly, such embodiments require a photon source capable of generating indistinguishable pairs of photons at different times. Examples of suitable photon sources are described in "Scalable performance in solid-state single-photon sources," J.C. Loredo, et al., Optica 3, 433, 2016 ("Loredo").
[0038] As will be appreciated by those skilled in the art, there are various means of storing the second photon in a manner that preserves the ability to use Hong-Ou-Mandel interference with the first photon. The easiest way to accomplish this is to send the second photon through a fiber optic delay line. An example of this is described in Loredo and Hectometer Revivals of Quantum Interference, M. Rambach et al., Physical Review Letters 121, pp. 93603 (2018).
[0039] One alternative is to use a cavity loop, an example of which is described in "Time-multiplexed heralded single-photon source," F. Kaneda et al., Optica 2, 1010 (2015). This involves sending a second photon into a cavity formed by a highly reflective mirror and an electro-optical switch. Within the cavity, the second photon makes multiple round trips between the mirrors. When the total number of round trips matches the total distance traveled by the first photon (allowing the second photon to travel into and out of the cavity), the electro-optical switch is then controlled to emit the second photon, thereby allowing it to interfere with the first photon.
[0040] Another alternative is to temporarily store a second photon in a quantum memory and then release it, thereby causing the second photon to interfere with the first photon. Details of single-photon storage in quantum memory are described in Quantum memories for fundamental science in space, Jean Michael Mo et al., Quantum Science and Technology, 8, 024006 (2023).
[0041] Embodiments of the present invention also include secure communication devices and processes that combine light path monitoring with optical communications to assess whether communications may be compromised, for example, by eavesdropping. Thus, in some embodiments, a first photon is multiplexed with a communication signal, and the resulting multiplexed signal is transmitted to a remote node. The remote node can assess the integrity of the communication by separating the first photon from the communication signal and transmitting the separated first photon back to the first node. Unless the first node assesses that the communication is uncompromised, further communication with the remote node can be prevented. In some embodiments, the (unmultiplexed) first photon is transmitted to the remote node before any such communication signal, such that such communication signal is transmitted to the remote node only after the optical link is, or has been assessed to be, uncompromised.
[0042] Suitable methods for multiplexing the first photons with the communication signal include standard methods known to those skilled in the art, such that either or both of the second photons and the communication signal can be coupled into and / or removed from the optical link. By way of example, some of the most well-known standard methods include the following: (i) wavelength division multiplexing, in which the first photons have a wavelength slightly different from that of the communication channel signal; (ii) time-division multiplexing, in which the second photon and the communication signal are transmitted in different time slices (e.g., as described in Towards high-capacity quantum communications by combining wavelength and time-division multiplexing technologies, Wen-Tan Fang et al., Proc. SPIE 10771, Quantum Communications and Quantum Imaging XVI, 1077112 (2018)), in which the communication signal is temporarily interrupted to allow coupling, so that the second photon can be coupled into or out of the channel at appropriate times when there is no communication signal or a lull in signal traffic on the channel); (iii) mode division multiplexing (e.g., as described in "Mode multiplexed single-photon and classical channels in a few-mode fiber," J. Carpenter et al., Optics Express 23, 28794 (2013)"), in which the second photon and the communication signal are coupled into different channel modes (e.g., spatial modes of the waveguide or propagation modes in free space), and appropriate filters, mode converters, or other discriminators are used to selectively couple the second photon into or out of the channel while passing the communication signal; and (iv) Spatial path multiplexing, where the second photon is coupled into a slightly different spatial path than the communication signal. For example, there may be a slight difference in the optical axis of the second photon relative to the communication signal (e.g., by spatial translation or angle), or the second photon may be coupled into a different portion of a waveguide structure or into a different waveguide of a multi-guide bundle.
[0043] These are merely some of the more prominent multiplexing methods; other suitable methods will be apparent to those of skill in the art in light of this disclosure.
[0044] In some embodiments, the apparatus and process use a pair of indistinguishable photons. One (the "first") photon is retained in a delay loop at the trusted entrance to the link, referred to herein as home node A, and therefore this retained photon is also referred to herein for convenience as the "A photon." The other (the "second") photon is transmitted to the link's remote or "field" node B, and therefore also referred to as the "B photon," where it is reflected back to node A and interfered with either the first or A photon. When the delay at node A is selected or adjusted to match the link length, the coincidence rate drops to zero: this is the output signal indicative of a fully protected link. Any attempt by an eavesdropper to partially or completely eavesdrop on the link will cause the B photon to become distinguishable from the A photon, via no-cloning quantum phenomena, which will cause the coincidence rate to become non-zero via quantum interference, indicating an interception.
[0045] Figure 1 is a high-level block diagram of an apparatus for secure communications according to some embodiments of the present invention, and Figure 2 is a flow diagram of a process for secure communications according to some embodiments of the present invention. As shown in Figure 1, a first or "home" node A 102 communicates with a remote or "field" second node B 104 via at least one optical path (e.g., at least one optical fiber, waveguide, or free space path) 106, which is a physical path (or "link") verified by quantum link verification. The two nodes 102, 104 include optical transceivers and signal generators (shown collectively as CCom 108 and CCom 110 in nodes 102, 104, respectively, for simplicity) for communication using a classical communications protocol.
[0046] Home node A 102 includes a quantum light source ("QLS") 112, which is a non-classical photon source that generates quantum states of light in at least two different optical modes in step 202 of the secure communication process. This document uses as an example the case of a pair of single photons, one in each of the two optical modes, referred to as a "home" photon and a "travel" photon, respectively. The home and travel photons must have some minimum indistinguishability in each of the optical properties of frequency, polarization, spatial mode, and temporal profile, and are therefore described herein as being at least partially indistinguishable in each of these properties.
[0047] The optical classical telecommunications signals (OCTS) and “travel” photons generated by the CCom 108 of home node A 102 are received by a “Joiner” component 114, which multiplexes one of the optical classical telecommunications signals (OCTS) with the travel photons in step 204. These are then transmitted over the optical path or link 106 in step 206. The OCTS and travel photons must be distinguishable in at least one of the same four characteristics described above: frequency, polarization, spatial mode, and temporal profile. For example, in various embodiments, the OCTS and travel photons have orthogonal polarizations and / or non-overlapping frequency modes. Any attempt to intercept or otherwise access the classical telecommunications signals also affects the travel photons.
[0048] At the remote field node B 104, the optical signal is received by a splitter component 116, which spatially separates the travel photons from the OCTS in step 208. The OCTS is transmitted to the receiver CCom 110, and the travel photons are transmitted to a "photon return device" ("PRD") 118, which returns the travel photons to the home node A 102 via either the same optical path or a different optical path. The return transmission must be such that the indistinguishability of the four properties mentioned above is not completely lost. This can be verified, for example, by Hong-Ou-Mandel interferometry, which yields a non-zero non-classical interference result.
[0049] If the system drifts outside the range where nonclassical interference can be observed, it can be recovered by either (i) using adaptive optics to reverse the channel change or (ii) stabilizing the channel and isolating it from the environment. For example, if there is a drift in polarization (e.g., as determined by monitoring one of the classical communication channels), applying appropriately correlated compensation to the quantum and monitoring channels to compensate for the polarization rotation of the classical monitoring signal will also return the quantum interference signal to its original level, assuming no other changes have occurred. In this way, by monitoring all "normal" methods and compensating as necessary, the system can be maintained in a state where quantum interference occurs and / or returned to a state where quantum interference occurs.
[0050] In step 210, the returning travel photons are received at home node A 102 by a quantum interference device (“QID”) 120 which also receives home photons so that a quantum interference visualization output can be generated in step 212. In step 214, the output of QID 120 is received by control component 122 which assesses the physical integrity of the light path, and thereby the security of communications, and optionally prevents further communications if the quantum interference visualization results are outside of acceptable limits, indicating that the light path is compromised.
[0051] 3 is a schematic diagram illustrating one embodiment of an apparatus for secure communication using telecommunications fiber between a home node 302 and a remote field node 304. Photon pairs 305 are generated at 1550 nm by a commercially available photon downconversion device (“PDC”) 306 (e.g., an optically nonlinear crystal) pumped by a 775 nm laser 304. In the described embodiment, the photon downconversion device 306 is a NuCrypt EPS-1000 photon source as described at http: / / nucrypt.net / EPS-1000.html, although alternative downconversion devices will be apparent to those skilled in the art.
[0052] One photon of each pair (the "first photon" or "home photon") is held at the home node 302, the trusted entry point to the link, by being coupled to a variable delay line 310. The variable delay line 310 consists of both a fixed fiber delay and an adjustable free-space element to ensure that the path length matches within the coherence length of the photon (typically tens to hundreds of microns, depending on bandwidth). Because the home photon is never transmitted and never leaves the home node, it is not always accessible to an adversary.
[0053] The other photon of the pair (the "second photon" or "field photon") is routed via optical circulator 312 to wavelength division multiplexer ("WDM") 310, where it is combined with a classical communication signal generated by signal generator ("COM") 318 onto a single optical fiber 316. This fiber 316 connects home node 302 to field node 304. At field node 304, a second WDM 320 splits the classical communication from the single photon signal. The separated single photon is then returned to the second WDM 320 by a further circulator 322 and then sent back down the same optical fiber 316 to home node 302. The WDM 314 and circulator 312 at home node 302 split the returned field photon and route it to a 50% beam splitter ("50:50 BS") 324 to perform a quantum interference measurement with the delayed home photon. 3, this measurement is accomplished using a pair of single-photon detectors 326. By monitoring the single and coincidence count rate (“C”) 328 between the two single-photon detectors 326, any physical interference with the optical fiber between the home node 302 and the field node 304 can be detected.
[0054] It will be apparent that the home photons must be delayed by a time equivalent to the effective round-trip time of the field photons, which could cause them to interfere with each other. In practice, this is achieved by making an initial measurement of the field photon delay time once the optical path has been assessed to be safe (e.g., by physically inspecting the entire length of fiber during equipment commissioning), and then calibrating the home photon delay time to be the same as the measured field photon delay time. Once the delay times have been measured and calibrated, any change in the length of the optical path between the two nodes (and / or any change in the time spent by the field photon within the remote node) will change the effective round-trip time of the field photon, thereby preventing or at least reducing mutual interference between the home and field photons.
[0055] QLV is wavelength independent and can be used in optical fiber or free space communication networks utilizing five wavelength bands from 1260 to 1625 nm, typically near-infrared (780 nm) or infrared (1550 nm) wavelengths. As known by those skilled in the art, photon sources suitable for these wavelength ranges are well developed and commercially available.
[0056] Modern telecommunications utilizes multiple frequencies within each single optical path or link. In telecommunications, each link is an optical fiber, and information is routed in and out of the fiber by wavelength division multiplexing (WDM). In free space, the optical paths / links are defined by bulk optics, and the same technology is used, but when the carrier is wireless or 4G, it is called frequency division multiplexing (FDM) because the carrier is traditionally described by frequency, but the physical principles are the same.
[0057] C-band telecommunications, spanning the wavelength range of 1530–1565 nm, uses dense WDM (DWDM), which bundles 80 frequency channels onto a single optical fiber. More recently, ultra-dense WDM has achieved 320 channels, and moving to the L-band, from 1565–1625 nm, effectively doubles these capacities. In any such implementation, the QLV signal requires only one of these channel frequencies, leaving the rest for full-capacity classical communications. In practice, an additional channel is reserved for measuring link length using optical time-domain reflectometry (or equivalent), providing the information necessary to adjust variable delays at the home node. Thus, the link can be continuously verified as secure, but at the cost of a slight reduction in achievable information capacity, from 2.5% (C-band, DWDM) to 0.3% (L-band, UDWDM).
[0058] The secure communication processes and apparatus described herein are effective in detecting hostile eavesdropper activity on optical communications between nodes of a communications network. For example, consider Eve, an eavesdropper attempting to access a communications link in each of three different attack scenarios:
[0059] Attack 1: Signal Splitting In this attack, Eve connects to a fiber beam splitter with a low splitting ratio to siphon off a small amount of the classical signal field (which Eve processes with her WDM to extract information) while shifting most of the signal toward the field node. This type of attack can be detected as an increase in coincidence counts or a decrease in non-classical visualization, as the total path length is changed by the presence of the fiber beam splitter. The changes in coincidence counts and non-classical visualization can be correlated with the signal splitting ratio.
[0060] Attack 2: Channel Selection In this attack scenario, Eve attempts to avoid detection by utilizing a WDM before her fiber beam splitter and not routing the quantum signal channel through that siphon beam splitter. After siphoning the classical communication signal, Eve utilizes a second WDM to recombine the quantum channel and the signal and transmit the recombined signal to the field node. This type of attack is more difficult, but can be countered by randomly switching the quantum signal to a different WDM channel at the home node, thus obviating Eve's evasion strategy and detecting her presence through reduced nonclassical interference or increased coincidence counts, as in Attack 1. The field node does not need to know which WDM channel provides the quantum signal, since it returns a portion of the signal received on all WDM channels to the home node, and the home node naturally knows which of these channels provide a portion of the returned quantum signal.
[0061] Attack 3: Blocking the quantum channel A quantum channel blocking attack exploits the fact that a simple successful link verification is indicated by a zero coincidence rate in quantum interference measurements. Eve's strategy is to exploit this by using WDM and fiber beam splitters, similar to the channel selection attack above, but here we simply block the quantum channel transmission. Because the second photon does not return, the coincidence rate remains at background levels.
[0062] There are two ways to counter this attack. First, the random switching used to defeat Attack 2 also works here. Additionally or alternatively, we can monitor both the single photon rate and the coincidence count rate. By blocking returning single photons, Eve reduces the amount of single photons that can be detected at the home node by half. After establishing a link, this is a clear indication of eavesdropping.
[0063] The secure communication process and device can also detect whether Eve has established unauthorized hardware in the link before the initial calibration. In this case, the secure communication device uses detectors that can distinguish between single and two-photon events. If and when Eve blocks the quantum signal, the secure communication device measures a significant decrease in the rate of two-photon events at each detector due to the non-classical interference that Eve is eliminating, but continues to observe some single-photon detection rate. In practice, probabilistic photon number resolution can be robustly achieved by a compound detector 400 consisting of a 50% beam splitter 402 with single-photon detectors 408, 410 at their respective outputs, as shown in Figure 4. The fiber beam splitter 402 probabilistically splits the two incoming photons 404, 406 into different output modes, allowing the two non-photon-number-resolving detectors 408, 410 to correctly identify the presence of the two photons 404, 406. Two-photon events manifest as coincidences between the two local detectors 408, 410 in the compound detector 400. When these stop, the non-classical interference is switched off and an interception has been detected.
[0064] Quantum verification of multi-node communication networks Real-world communication architectures are often not simply point-to-point connections; ring and star network architectures are common. Figures 5 and 6 are block diagrams of respective embodiments of secure communication apparatus for use in a multi-node communication network, each showing one trusted home node 502 (or 602) and (for simplicity only) two untrusted field nodes 504, 506 (or 604, 606), the field nodes communicatively coupled to the home node in a point-to-point fashion by respective dedicated optical paths (e.g., fibers) 508, 510 (or 608, 610).
[0065] As shown in FIG. 5, in a random switching quantum link embodiment, home node 502 includes dedicated WDMs (or “joiners”) 512, 514 for respective optical paths 508, 510. Switch 516 dynamically and pseudo-randomly selects one of WDMs 512, 514 to receive a quantum signal generated by quantum photon source (“QLS”) 518, thereby validating either link 508, 510. A classical communication device CCOM 520 encrypts and decrypts the communication signal, and a quantum interference device (“QID”) 522 performs quantum interference measurements using a beam splitter and a detector. In the FIG. 5 embodiment, a control component 524 is included to disable CCOM 520 at home node 502 to prevent further communication if the output of QID 522 indicates interception. Classical communication lines are shown as solid lines, while quantum state paths are shown as dashed lines. Communication and quantum signals between the home node 502 and each of the field nodes 504, 506 travel together along the same optical fiber 508, 510.
[0066] In a further embodiment, as shown in Figure 6, multi-band downconversion quantum link verification is used to simultaneously verify multiple links to each field node 604, 606 of a multi-node network. By utilizing the frequency range of the downconverted signal, photons are generated within the home node 602 by the QLS 612 in multiple wavelength channels. The WDM 614 splits these into respective outputs and routes them to respective further WDMs (or "joiners") 616, 618 for superposition with classical communication signals generated by respective CCOMs 620, 622. The advantage of this configuration is that links 608, 610 between the home node 602 and all field nodes 604, 606 are continuously verified, at the cost of requiring additional physical resources at the home node 602 to perform verification when a single photon returns from the field node 604, 606 to the home node 602 (specifically, a corresponding dedicated circulator 624, 626 and QID 628 for each link 608, 610).
[0067] As is clear from the above, the advantage of random switching (Fig. 5) over multi-band verification (Fig. 6) is that with random switching, the home node needs only one circulator and QID, regardless of which link 508, 510 is being verified. The disadvantage is that by temporarily switching verification operations between different links 508, 510, the entire network is not continuously monitored, as in the point-to-point configuration (Fig. 6).
[0068] The advantage of multi-band downconversion is that the entire network is continuously verified, but it comes at the cost of adding an additional WDM and circulators to route different quantum signals to different field nodes, and additional quantum interference components at the home node (delay lines as well as beam splitters and detection and analysis components).
[0069] For more complex network topologies or use cases, different combinations of the two configurations can be used.
[0070] In an alternative embodiment, as shown in Figure 7, a single quantum interference device QID 702 is used to simultaneously assess the physical integrity of optical paths 704, 706 to multiple field nodes 708, 710. While requiring fewer components than the configuration shown in Figure 6, this configuration cannot identify which optical paths 704, 706 have been obstructed by an eavesdropper.
[0071] Quantum link verification is described above for a point-to-point communication link between a home node and multiple field nodes. However, if two home nodes are connected to the same field node, the entire network link can be verified by independent verification of each subsegment link, or by bypassing one signal through multiple nodes. In this way, large networks can be monitored and verified, as shown in Figure 8.
[0072] While some embodiments of the present invention have been described above in the context of optical fiber link verification, it will be apparent that the processes and apparatus described herein can be readily adapted to verify line-of-sight free-space optical links using free-space transceivers to transmit and receive free-space optical signals. Free-space optical links are a rapidly growing part of modern telecommunications infrastructure, being used as backhaul for both LTE and 5G networks; to connect base stations; as "last mile" connections in deployments complicated by geography, urbanization, or political conditions; in airports; by the military; and for temporary wireless connections in domestic or international disaster recovery.
[0073] A potential problem particularly relevant to free-space communications is when the initial photons return to the home node altered by environmental factors rather than being intercepted. However, it is expected that environmental factors can be distinguished from intercepts by monitoring transient occurrences to determine correlations with environmental events such as changes in weather conditions (e.g., humidity, air pressure) or switching on heating, ventilation, and air conditioning (HVAC) in a data center.
[0074] For example, one or more of the following methods, and combinations thereof, can be used to distinguish between environmental influences and eavesdropping attacks:
[0075] The quantum interference signal can be monitored as a function of time and evaluated using time series statistics to identify events and infer the time scales on which they occur, with long duration events indicating an attacker. In some embodiments, the fast Fourier transform of the quantum interference signal is analyzed to identify spectral changes. Similarly, the autocorrelation of the quantum interference signal can be used to distinguish between normal and abnormal events.
[0076] Fluctuations in the communication signal can also be monitored and correlated with changes in the quantum interference signal to assess the likelihood of the latter cause.
[0077] A secondary probe signal can be introduced into the optical path to estimate path loss and timing and provide a calibration of the return rate of the first photons.
[0078] Machine learning can be applied to quantum interference signals to infer characteristic patterns that distinguish between different sources of variation in the quantum interference signal.
[0079] Using causal and non-causal filters, later data can inform the reliability of earlier data. At high photon speeds, this may only delay the analysis by a few milliseconds. At the other extreme, signals can be post-processed to identify likely past intrusion events.
[0080] Periodic self-calibration can be performed by sending photon pairs along the channel with different time delays to collect statistics of random fluctuations, which can then be compared with the QLV signal to help eliminate false positives caused by these fluctuations.
[0081] An alert process can be used to filter the results of any or all of the above methods. For example, an alert threshold can be set by an operator so that an alert is only generated if the threshold is exceeded. The threshold level can be selected depending on the desired level of security; the higher the security level, the greater the risk of false positives if no other steps are taken to distinguish between causes of changes in the quantum interference signal output.
[0082] The device may include or be coupled to components or systems that monitor and compensate for environmental changes. For example, in free-space applications, adaptive optics elements may be used to compensate for optical distortions caused by the atmosphere, as described in "Adaptive Optics for Astronomy," R. Davies, and M. Kasper, Annual Review of Astronomy and Astrophysics 50, 305 (2012)."
[0083] For optical fiber links subjected to mechanical stress, changes in photon properties can be compensated for using active fiber polarization controllers and dispersion. This method was recently used to demonstrate the feasibility of preserving the properties of single photons propagating over distances of over 1000 km in optical fiber cables (Experimental Twin-Field Quantum Key Distribution over 1000 km Fiber Distance, Yang Liu et al., Physical Review Letters 130, 210801 (2023)).
[0084] Many modifications will be apparent to those skilled in the art without departing from the scope of the invention.
Claims
1. 1. A lightpath monitoring process, comprising the following steps performed by a first node of an optical network: (i) generating photons that are at least partially indistinguishable in frequency, polarization, spatial mode, and temporal profile; (ii) transmitting a first one of the generated photons via an optical path to a remote node of the optical network; (iii) receiving the first photon from the remote node via a lightpath; (iv) interfering the received first photons with second ones of the generated photons to generate a quantum interference visualization output; (v) assessing the physical integrity of the optical path based on the quantum interference visualization output; The process includes:
2. 10. The process of claim 1, comprising repeating steps (i) through (v) to continuously monitor the physical integrity of the optical path.
3. 3. The process of claim 1 or 2, wherein the first photons are transmitted and returned via the same optical path.
4. The process of claim 1 or 2, wherein the first photons are transmitted and returned via different optical paths.
5. 5. The process of claim 1, further comprising storing the second photon for a period corresponding to a time delay between transmitting the first photon to the remote node and receiving the first photon from the remote node.
6. 5. The process of claim 1, comprising generating the first photon and the second photon at different times corresponding to a time delay between transmitting the first photon to the remote node and receiving the first photon from the remote node.
7. Before the interfering step (iv), transmitting the second one of the generated photons via an additional optical path to a third node of the optical network; receiving the second photon from the third node via the additional optical path or a further additional optical path; Including, 5. The process of claim 1, wherein the step of evaluating the physical integrity of the optical path based on the quantum interference visualization output comprises simultaneously evaluating the physical integrity of the additional optical path.
8. The following steps are performed by the remote node: receiving the first photon from the first node; transmitting the first photon to the first node such that the indistinguishability of each of the frequency, polarization, spatial mode and temporal profile of the first photon and the second photon is not lost; The process according to any one of claims 1 to 7, comprising:
9. 9. The process of claim 1, further comprising the step of multiplexing the first of the generated photons with an optical communication signal, wherein the first photon and the optical communication signal are distinguishable in at least one of frequency, polarization, spatial mode, and temporal profile, and wherein transmitting the first photon comprises transmitting the multiplexed first photon and the optical communication signal to the remote node via the optical path.
10. 10. The process of claim 9, comprising preventing subsequent communication with the remote node over the lightpath unless the physical integrity of the lightpath is assessed to be intact.
11. The following steps are performed by the remote node: receiving the multiplexed first photons and the optical communication signal; separating the first photons from the optical communication signal; transmitting the first photon to the first node such that the indistinguishability of each of the frequency, polarization, spatial mode and temporal profile of the first photon and the second photon is not lost; 11. The process of claim 9 or 10, comprising:
12. An optical path monitoring device having components configured to carry out the process of any one of claims 1 to 11.
13. An optical path monitoring apparatus including a first node, the first node comprising: a quantum photon source configured to generate photons that are indistinguishable in frequency, polarization, spatial mode, and temporal profile; one or more optical components configured to transmit a first one of the generated photons to a remote node of an optical network via an optical path and to receive the first photon from the remote node via an optical path; a quantum interference component configured to interfere the first photons received from the remote node with second ones of the generated photons to generate a quantum interference visualization output; a path integrity component configured to assess the physical integrity of the optical path based on the quantum interference visualization output; 1. An apparatus comprising:
14. The apparatus of claim 13 , wherein the apparatus is configured to continuously monitor the physical integrity of the optical path.
15. 15. The apparatus of claim 13 or 14, wherein the first photons are transmitted and returned via the same optical path.
16. 15. Apparatus according to claim 13 or 14, wherein the first photons are transmitted and returned via different optical paths.
17. 17. Apparatus according to any one of claims 13 to 16, wherein at least one of the optical paths is a corresponding optical fiber path or a waveguide.
18. Apparatus according to any one of claims 13 to 17, wherein at least one of the optical paths is a corresponding free space optical path.
19. 19. The apparatus of claim 13, wherein the one or more optical components include a multiplexer component configured to multiplex a first one of the generated photons with an optical communication signal, the first photon and the optical communication signal being distinguishable in at least one of frequency, polarization, spatial mode, and temporal profile, and the first photon is multiplexed with the optical communication signal and transmitted to the remote node.
20. 20. The apparatus of claim 19, wherein if the physical integrity of the optical path is assessed to be compromised, the path integrity component is configured to prevent subsequent communication with the remote node over the optical path.
21. 21. The apparatus of claim 13, comprising a second node remote from the first node, the second node comprising optical components configured to receive the first photons from the first node and return the first photons to the first node such that indistinguishability in each of frequency, polarization, spatial mode and temporal profile of the first photons and the second photons is not lost.
22. 22. The apparatus of claim 13, comprising means for storing the second photon for a period corresponding to a time delay between transmitting the first photon to the remote node and receiving the first photon from the remote node.
23. 22. The apparatus of any one of claims 13 to 21, wherein the quantum photon source is configured to generate the first photon and the second photon at different times corresponding to a time delay between transmitting the first photon to the remote node and receiving the first photon from the remote node.
24. 22. The apparatus of claim 13, wherein the one or more optical components are configured to transmit the second one of the generated photons to a third node of the optical network via an additional optical path, and to receive the second photon from the third node via the additional optical path or a further additional optical path, whereby the path integrity component evaluates physical integrity of the optical path and the additional optical path based on the quantum interference visualization output.