Quantum network and quantum authentication server

The Quantum Authentication Server addresses the scalability and security issues in QKD systems by generating and managing PSKs, enabling secure communication in quantum networks without manual key installation.

JP7771288B2Active Publication Date: 2025-11-17KK TOSHIBA
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024116983
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-02-25
Filing Date
2024-07-22
Publication Date
2025-11-17
Estimated Expiration
2042-08-29

AI Technical Summary

Technical Problem

Existing quantum key distribution (QKD) systems require manual installation of pre-shared symmetric keys (PSKs) between nodes, which is not scalable for large networks, and existing authentication methods like public key cryptography are vulnerable to quantum computing threats.

Method used

A Quantum Authentication Server (QAS) that generates and manages PSKs using QKD, allowing secure communication by distributing keys through a trusted authority, enabling scalable quantum networks with secure authentication and encryption.

Benefits of technology

Enables secure and scalable quantum networks by eliminating the need for manual key installation and providing secure authentication between nodes, using QKD to generate and manage PSKs for secure communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007771288000002
    Figure 0007771288000002
  • Figure 0007771288000003
    Figure 0007771288000003
  • Figure 0007771288000004
    Figure 0007771288000004
Patent Text Reader

Abstract

To provide a quantum network and a quantum authentication server (QAS), allowing a first user node and a second user node to share a pre-shared key (PSK) using a quantum key distribution (QKD).SOLUTION: A QAS 321 includes an authentication unit / agent 330, a QKD hardware 323, a key management system 325, and a key consuming data encryptor 331. The authentication unit / agent receives a request for authentication of a first channel between the first user node and a server. The QKD hardware distributes a quantum key between the first user node and the server. The key management system provides a first PSK to the first user node for the first user node to authenticate with the second user node. The key consuming data encryptor encrypts the first PSK to be transmitted to the first user node with the quantum key.SELECTED DRAWING: Figure 3B
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] SUMMARY OF THE INVENTION The embodiments described herein relate to quantum networks and Quantum Authentication Servers (QAS). [Background technology]

[0002] Quantum key distribution is a technique for generating a completely random quantum key at two remote nodes, which can be used for data encryption to ensure secure communication. The basic operating principle of QKD relies on encoding and measuring a quantum state, followed by a discussion between the two nodes over an authenticated classical channel.

[0003] Embodiments will now be described with reference to the following drawings: [Brief explanation of the drawings]

[0004] [Figure 1] 1 is a schematic diagram of a QAS according to an embodiment. [Figure 2] FIG. 1 is a schematic diagram showing messages passed between a QAS and two user nodes. [Figure 3A] FIG. 2 is a schematic diagram of a user node. [Figure 3B] FIG. 1 is a schematic diagram of a QAS. [Figure 4A] FIG. 1 is a schematic diagram of a QKD transmitter. [Figure 4B] 1 is a schematic diagram of a QKD receiver. [Figure 5A] 10 is a flowchart illustrating the steps performed by a user node when requesting a PSK. [Figure 5B] 5B is a flowchart illustrating the steps performed by the QAS when responding to a request of the user node of FIG. 5A. [Figure 6] 1 is a schematic diagram of a network with a QAS according to an embodiment; [Figure 7]1 is a schematic diagram of a network comprising a QAS, a quantum computer, and a file server according to an embodiment. [Figure 8] 1 is a schematic diagram of a large network with three sub-networks, each with its own QAS, according to an embodiment. [Figure 9] FIG. 1 is a schematic diagram showing messages passed between a QAS and two user nodes in a sparse network. [Figure 10] FIG. 1 is a schematic diagram illustrating a network in which the key shared between two user nodes comprises PSKs from two QASs. DETAILED DESCRIPTION OF THE INVENTION

[0005] In an embodiment, a server is configured to provide a pre-shared key "PSK" to a first user node to enable the first user node and a second user node to share the PSK, the server comprising: a network interface, an authentication unit, an encryption unit, a key management system, and a quantum key distribution unit; The authentication unit is configured to receive, via the network interface, a request for authentication of a first channel between a first user node and a server; the quantum key distribution unit is configured to enable a quantum key to be distributed between the first user node and the server, the quantum key being shifted using communication over the authenticated first channel to establish a first quantum key for the first user node and the server; the key management system is configured to provide a first PSK to the first user node to enable the first user node to authenticate with the second user node; The encryption unit is configured to encrypt a first PSK with the quantum key for transmission to the first user node via the network interface.

[0006] For PSK encrypted communication, two parties wishing to communicate would both need to have access to the same private pre-shared key. To ensure security, this means that there must be a secure way to install the PSK between two parties wishing to use it.

[0007] Quantum key distribution (QKD) is a technique for generating a completely random quantum key at two remote nodes, which can be used for data encryption to ensure secure communication. The basic operating principle of QKD relies on encoding and measuring a quantum state. This is then followed by a discussion between the two nodes over an authenticated classical channel, which allows the two nodes to detect the presence of an eavesdropper. Part of the discussion is a process called sifting, in which the two nodes discard measurements if the encoding and decoding bases differ.

[0008] A requirement for QKD is therefore that two users be able to authenticate each other. This means that they can undoubtedly demonstrate that a received classical message was sent by the other party and was not tampered with in transit. In other words, this avoids man-in-the-middle attacks. While authentication can be done using public key cryptography (e.g., RSA), this is not the preferred solution due to known vulnerabilities in such approaches to quantum computing. Instead, QKD systems more commonly authenticate each other using pre-shared symmetric keys (PSKs).

[0009] QKD is an emerging technology, and the majority of QKD systems to date operate over a single point-to-point link. Pre-shared key material is therefore installed by the manufacturer when setting up the link, and this is used for initial authentication (many algorithms exist for using pre-shared key material to authenticate messages and users). Once authenticated QKD is initiated, additional PSK material can be established between users and stored for subsequent authentication sessions.

[0010] Quantum networks are the essential next step for QKD technology, in which multiple QKD systems will be interconnected to allow quantum-secure communication between several users. This could be an optically switched network, with each user owning a QKD system and the quantum links between them formed by optical switching. These quantum channels between users could be optical fiber, or alternatively, free-space links, potentially even via satellite between nodes 1000 km apart. However, it is necessary to ensure that classical communication channels are also secured. The process of installing a new QKD user in the network could require the manufacturer to visit each of the other QKD nodes and manually install a pre-shared symmetric key shared with the new QKD system. This is not scalable, as each possible QKD system pairing requires a separate PSK to be installed, requiring N(N-1) / 2 PSKs for a network of N nodes.

[0011] The server described above is a quantum authentication server that allows a PSK to be installed into a user node using QKD. Installing the PSK via QKD maintains security but avoids the need for the PSK to be installed by visiting the node to physically install it. If the quantum authentication server is trusted, it can store / generate or access the PSK that will be provided to the two nodes via QKD, allowing the two nodes to authenticate each other and thus communicate securely over a classical channel.

[0012] In one embodiment, the key management system itself is configured to generate a PSK for sharing between a first user node and a second user node, which can then be sent to the first user node and the second user node. This allows the network to scale, allowing additional user nodes to be added; only the added node needs to have the PSK installed that allows it to authenticate with the QAS. Once the new node is able to authenticate with the QAS, it can open a secured authenticated channel with all other nodes that also share a PSK with the QAS. This is because the QAS can share a key with any two nodes that can open a secured authenticated channel.

[0013] For example, the authentication unit is configured to send, via the network interface, a request for authentication of a second channel between the second user node and the server; The quantum key distribution unit is configured to enable a quantum key to be distributed between the second user node and the server, and the quantum key is shifted using communication over the authenticated second channel to establish a second quantum key for the second user node and the server; and the encryption unit is configured to encrypt the first PSK with the second quantum key for sending to the second user node via the network interface.

[0014] From this, the key generated by the QAS can be shared between the first user node and the second user node.

[0015] In a further embodiment, the first PSK may be pre-shared with the second user node prior to sending it to the first node. For example, if the QAS and the second user node cannot contact each other to allow the first key to be sent from the QAS to both the first and second user nodes, the QAS may send to the first node the PSK that it has already shared with the second node, allowing the first and second nodes to authenticate each other.

[0016] In an embodiment, once the PSK has been used for authentication it is discarded. Thus, in an embodiment, a new PSK or new PSKs are generated by a QKD process. For example, the first quantum key has a first length, the quantum key distribution unit is configured to distribute keys longer than the first length, and the remainder of the keys is stored as at least one PSK for further authentication between the server and the first user node.

[0017] In an embodiment, the server further comprises an access control unit, the access control unit configured to store information indicating whether two user nodes are allowed to share a PSK, and the server configured to accept or decline a request from a user node to obtain a shared key by referring to the information stored in the access control unit.

[0018] In some embodiments, for example, if a node wishes to contact a relatively distant node, the server may be configured to contact a further server to determine whether to accept or decline a request from the user node to obtain a shared key. The further server may be configured to control access to a subgroup of nodes.

[0019] In a further embodiment, the server further comprises a policy unit configured to provide information for controlling at least one of the quantum key length, the PSK key length, and information to be sent together with the PSK.

[0020] In an embodiment, the quantum key distribution unit comprises: an encoder, the encoder configured to encode information onto the light, the information being encoded by randomly selecting one state from a plurality of states for transmission to the user node, the light leaving the server in pulses containing less than one photon on average; a decoder, the decoder being configured to receive light pulses containing less than one photon on average and to decode information from the light pulses by measuring the light pulses, a measurement basis for the measurements being randomly selected from a set of measurement bases to enable measurement of states used to encode the information; wherein the quantum key distribution unit further comprises a sifting unit configured to enable the server to compare a measurement basis it uses for encoding or decoding with a measurement basis used by the user node for decoding or encoding, and the quantum key distribution unit is configured to discard information from the pulses if the measurement basis for encoding and the measurement basis for decoding do not match.

[0021] From this, the server may comprise an encoder and a user node provided with a decoder (or vice versa). In further embodiments, the server may be provided with a decoder and an encoder, so that QKD can be performed in nodes having only an encoder or only a decoder. The encoder / decoder may be configured to perform QKD using polarization or phase.

[0022] In a further embodiment, there is provided a network comprising a first server, a plurality of user nodes, and at least one switch, the at least one switch configured to enable selective connections between any two of the user nodes and between any of the user nodes and the server, each of the user nodes comprising a quantum key distribution unit, a network interface, and an authentication unit, and the first server being a QAS as described above.

[0023] In a further embodiment, the network may further comprise at least one further server, which at least one further server is also a QAS as described above, and the first server is configured to send a query to the further server upon receiving a request from a user node for a shared PSK that the first server cannot satisfy.

[0024] In the above network, a first user node receives PSKs from two servers in response to a request for PSKs to authenticate with a second user node. The first user node forms a combined PSK from the two servers, and the second user node also derives a combined PSK to enable the first user node and the second user node to authenticate. The two PSKs may be formed by an operation such as an XOR operation. This allows the first and second user nodes to communicate securely even if one of the servers is compromised. The second node may obtain the two PSKs from the two QASs via QKD-encrypted communications, or the PSKs may already be stored on the second user node, for example, if they are PSKs for authentication with the two QASs and the second user node.

[0025] The network may comprise a plurality of further servers, the first server and the plurality of further servers arranged in a hierarchy, and the first server configured to, upon receiving a request from a user node for a shared PSK that the first server cannot fulfill, send a query to another server above it in the hierarchy.

[0026] Communications through the network are controlled by switches, which may be separate components or may be provided within one or more of the QAS and / or user nodes.

[0027] User nodes may also have additional functionality, for example they may be file servers or quantum computers.

[0028] In an embodiment, the network comprises a number of sub-networks, which are linked by a communication channel, which may for example be a long-range channel (>1000 km) or a satellite link.

[0029] In a further embodiment, there is provided a method of sharing a pre-shared key "PSK" between a first node and a second node in a network, the method comprising: authenticating a first channel between a first node and a server; performing QKD between the server and the first node to establish a first quantum key; encrypting a first PSK at a server for sharing between the first node and the second node with the first quantum key; sending the encrypted PSK to the first node; Equipped with.

[0030] As described above, the first PSK may have been pre-shared with the second user node. In yet a further embodiment, the method includes authenticating a second channel between the second node and the server; performing QKD between the server and the second node to establish a second quantum key; encrypting the first PSK at the server for sharing with the second quantum key between the first node and the second node; sending the encrypted PSK to the second user node; It may further comprise:

[0031] This allows a fully secure and scalable quantum network to be realized. This enables an authentication system for QKD networks based on a trusted authority server that generates random numbers that are sent to users over a QKD secure link for use as pre-shared keys (PSKs) for authentication.

[0032] Furthermore, the above QAS enables the provision of a scalable information-theoretic secure communication network that uses PSKs for authentication and QKD to grow keys for use in data encryption, where an initial PSK for user-to-user QKD is obtained through a trusted authority server.

[0033] Optically switched QKD networks have authentication provided through network communications with a trusted authority server.

[0034] The QAS described above provides a trusted authority node for a quantum communications network, possibly including, but not limited to, a quantum random number generator, a key store of PSKs for authentication with users on the network, a database of network users and access control lists defining who can communicate with whom, authentication policy management, and the ability to include metadata in PSKs for policy-controlled authentication such as enforcing timed QKD sessions or handling Quality of Service (QoS) requirements.

[0035] The trusted authority / quantum network design described above is used to control authenticated user access to quantum resources on the network, such as sessions on a file server, quantum computers, or quantum sensing capabilities.

[0036] Quantum communication networks can be created using the above with multiple trusted authorities arranged in a hierarchical fashion and connected through QKD links. Long-distance links can be connected via twin-field QKD or satellite QKD. The quantum networks described above are such that network functions and optical switching are controlled by software, for example using software-defined networking (SDN).

[0037] In a further embodiment, a quantum network is provided that includes at least two trusted authority servers, such that a PSK authentication key is derived between users by performing an XOR operation on two independent PSK keys, mitigating against the threat of a compromised trusted authority.

[0038] FIG. 1 is a schematic diagram of a quantum network according to an embodiment, the network comprising a Quantum Authentication Server "QAS" 1, a first node 3 (called "Alice") and a second node 5 (called "Bob").

[0039] The details of the Alice 3 and Bob 5 nodes will be described later. The QAS, Alice 3 and Bob 5 are connected to each other via a switch 7. The switch 7 is configured so that the QAS 1 can selectively communicate with either Alice 3 or Bob 5, or so that Alice 3 and Bob 5 can communicate with each other.

[0040] In the example of Figure 1, QAS 1, Alice 3, Bob 5, and switch 7 are linked by optical cable. However, one or more of the connections can be provided by free space. Also, in this example, two nodes (Alice 3 and Bob 5) are shown to illustrate the concept in its simplest form. However, the system can be configured to incorporate more than two nodes, and possibly multiple switches and multiple QASs.

[0041] Before considering the arrangement of Figure 1, an overview of quantum communication is given.

[0042] Here, a basic quantum communication protocol using polarized light is described. However, it should be noted that this is not intended to be limiting and other polarization based protocols can also be used. Furthermore, the above server can be used with any QKD system and is not limited to use with polarized light. For example, phase or energy / time based QKD protocols can also be used.

[0043] The protocol uses two bases, each described by two orthogonal states: in this example, horizontal / vertical (H / V) and diagonal / anti-diagonal (D / A) bases. However, a left-handed / right-handed (L / R) basis can also be chosen.

[0044] The sender in the protocol prepares a state with one of H, V, D, or A polarization. In other words, the prepared state is selected from two orthogonal states (H and V or D and A) in one of two bases: H / V and D / A. This can be thought of as sending a signal of 0 and 1 in one of two bases, e.g., H=0, V=1 in the H / V basis and D=0, A=1 in the D / A basis. The pulse is attenuated to comprise less than one photon on average. This means that if a measurement is made on the pulse, it will be destroyed. Also, it is not possible to split the pulse.

[0045] The receiver uses a measurement basis for the polarization of the pulse selected from the H / V basis or the D / A basis. The selection of the measurement basis can be active or passive. In passive selection, the basis is selected using a fixed component such as a beam splitter. In "active" basis selection, the receiver makes the decision on which basis to measure, for example, using a modulator with an electrical control signal. If the basis used to measure the pulse at the receiver is the same as the basis used to encode the pulse, the receiver's measurement of the pulse will be accurate. However, if the receiver selects any other basis to measure the pulse, there will be a 50% error in the result measured by the receiver.

[0046] To establish the key, the sender and receiver compare the bases used to encode and measure (decode). If they match, the result is kept; if they do not match, the result is discarded. The above method is very secure. If an eavesdropper intercepts the pulse and measurement, the eavesdropper must prepare another pulse to send to the receiver. However, the eavesdropper would not know the correct measurement base and would therefore only have a 50% chance of measuring the pulse correctly. Any pulse reproduced by an eavesdropper would cause a larger error rate for the receiver, which can be used to prove the presence of an eavesdropper. The sender and receiver compare small portions of the key to determine the error rate and therefore the presence of an eavesdropper.

[0047] Although the above has been described with reference to polarization, this is by way of example: other systems such as energy / time or other phase-based QKD protocols can be used.

[0048] The above QKD requires two channels: a "quantum channel" used for communication of pulses containing on average one or less photons, and a classical channel used for basis discussion ("shifting"). Also, the classical channel can be used for further communication once a key has been established on the quantum channel. Note that the term "channel" is used to refer to a logical channel. The quantum and classical channels are provided within the same physical fiber.

[0049] However, for the sifting process, the classical channel also needs to be authenticated. This means that it can be proven without question that classical messages communicated between Alice and Bob were sent by the other party and were not tampered with in transit. In other words, this avoids man-in-the-middle attacks. Authentication can be done using public key cryptography (e.g., RSA). However, in an embodiment, Alice and Bob authenticate each other using a pre-shared symmetric key (PSK).

[0050] For completeness, note that when two parties share a private key, they can authenticate each other using many different methods. One method involves the use of a Message Authentication Code (MAC), where a sender (e.g., Alice) and a receiver (e.g., Bob) share a key (PSK).

[0051] Alice then generates a MAC by inputting the message and PSK into a known MAC algorithm. The generated MAC and message are then sent to Bob. Bob then inputs the message and his PSK into a known MAC algorithm and compares the output with the MAC sent by Alice. If they match, he knows that the message and MAC code he received were sent by Alice. Alice can authenticate Bob by asking Bob to repeat the process using a different message and sending a newly generated MAC and message back to Alice. Alice can then input a new message into her algorithm using her key to see if her newly generated MAC code matches the one sent by Bob.

[0052] However, a situation may arise where Alice and Bob do not already share a PSK, or where the PSK they share is known to have been compromised, in which case the QAS in the system of Figure 1 is used to allow Alice and Bob to authenticate.

[0053] Such operation will now be described with reference to FIG.

[0054] To avoid unnecessary repetition, like reference numerals will be used to denote like features.

[0055] In the system of Figure 2, Alice 3 and Bob 5 both share a PSK with QAS 1. The PSK shared between Alice and the QAS allows Alice 3 to perform QKD with the QAS and authenticate with the QAS. The PSK shared between Bob and the QAS allows Bob 5 to perform QKD with the QAS and authenticate with the QAS.

[0056] Alice 3 wants to communicate securely with Bob, but they do not share a PSK. However, they both share a PSK with QAS 1, which can be used to authenticate each other.

[0057] In step 1, switch 7 is configured to connect Alice and the QAS. In an embodiment, each user may have a switch, forming a mesh network. Alternatively, as shown, there is a single centralized switch. The centralized switch may be controlled by the QAS or some other higher-level network controller.

[0058] In this embodiment, symmetric PSK, K AQ is installed on both Alice 3 and QAS 1. Therefore, Alice 3 and QAS 1 can authenticate each other and thus perform QKD to communicate securely. In step 1, Alice 3 requests to communicate with Bob 5, and this request is sent to QAS 1, shown as step 1A.

[0059] QAS1 checks its internal database, which will be explained in more detail later, to see if it trusts Bob5 (i.e., it knows Bob and the PSK, K BQ In a further embodiment, QAS1 may also be configured to check rules to see if Alice and Bob are allowed to communicate.

[0060] Once the QAS approves that Alice 3 and Bob 5 can communicate, QAS 1 sends the PSK, K, used by Alice and Bob to authenticate them. AB Generate a random number (e.g., using the internal QRNG) such that

[0061] QAS1 then uses the QKD link between it and Alice 3 to generate QKD keys using a known QKD protocol, for example the basic QKD protocol described above. Communication over a classical channel is then performed by Alice 3 and QAS1 as part of the sifting process, where the classical communication between Alice 3 and QAS1 is AQ Once the QKD key is established between Alice 3 and QAS 1, it is then used to authenticate the QKD key for sending to Alice in step 1B. AB is used to encrypt the

[0062] In step 2, switch 7 connects QAS1 and Bob 5. QAS1 and Bob 5 use the PSK, K, previously installed by the manufacturer. BQ Bob 5 and QAS 1 then perform QKD to establish a QKD key between Bob 5 and QAS 1. The sifting process is BQ Once QKD is performed and the QKD keys are established between Bob5 and QAS1, the PSK key K AB is then encrypted using the quantum key and sent to Bob5.

[0063] From this, Alice and Bob can obtain a symmetric random key K AB Finally, in step 3, switch 7 connects Alice and Bob via an optical link. Alice 3 and Bob 5 now share K AB It uses authentication and performs QKD to communicate securely.

[0064] In the above embodiment, all messages passed over the communication channel in this procedure are encrypted using the QKD key and can be authenticated using a PSK that is either pre-stored or communicated using encryption using QKD, thus ensuring complete security.

[0065] In an embodiment, PSK(KAQ , K. AB , and K BQ ) is used only once. For example, in the case of ITS security using Wegman-Carter style message authentication codes, a PSK should be used only once. Thus, in an embodiment, when two users authenticate and begin performing QKD, they discard the previous PSK between them. They can then reserve some of the newly generated quantum keys in a "PSK key store" ready for future authentication sessions. From this, once authenticated, users can communicate securely using QKD without having to contact QAS1 every time. In other words, when QKD is used to establish a key, part of the key is used to encrypt messages to be sent, and part of the key is reserved to become the authentication key the next time QKD is performed.

[0066] Network management (e.g., signaling the optical switch 7 to reconfigure links) can be performed using the same channel occupied by the quantum signals, or alternatively, a separate public communication channel (e.g., the classical Internet). This is compatible with new network architectures that use software-defined networking (SDN), as well as traditional networks.

[0067] Figure 3A shows in detail the components of one of the nodes, for example Alice 3 or Bob 5. Figure 3B shows in detail the components of QAS1.

[0068] Turning first to the node of Figure 3A, node 301 comprises QKD hardware 303 for generating quantum keys. The QKD hardware may comprise a quantum transmitter and a quantum receiver.

[0069] An example of a possible transmitter is shown as 101 in FIG. 4A. The transmitter can be any type of quantum transmitter capable of emitting polarization-encoded photons. In this particular example, transmitter 101 comprises four lasers 105, 107, 109, and 111, each of which emits horizontally polarized light. The output from laser 105 is provided to polarization combining optics 139. The output from laser 107 is provided to polarization combining optics 139 through a half-wave plate configured to convert the horizontally polarized light to diagonally polarized light. The output from laser 109 is provided to polarization combining optics 139 through a half-wave plate configured to convert the horizontally polarized light to vertically polarized light. The output from laser 111 is provided to polarization combining optics 139 through a half-wave plate configured to convert the horizontally polarized light to diagonally polarized light.

[0070] The polarization combining optics allows different polarizations to be combined into a stream of pulses with randomly varying polarizations. This can be achieved in many different ways. For example, the lasers can be pulsed lasers, and a controller (not shown) is provided to randomly select one laser from lasers 105, 107, 109, and 111 to randomly output pulses, such that one pulse reaches the polarization combining optics at a time. In other embodiments, the polarization combining optics or additional components can be configured to randomly select output from one laser or randomly selectively block output from three lasers to allow a pulsed output stream. The pulses can be generated by a pulsed laser, or a cw laser can be used with additional components to chop the output into pulses.

[0071] An attenuator (not shown) is then used to attenuate the power of the pulses so that they contain less than one photon on average. Alternatively, single-photon emitters can be used in place of lasers 105, 107, 109, and 111.

[0072] A simplified form of the receiver is shown in FIG. 4B. The receiver comprises a 50-50 beam splitter 205 that will direct incoming pulses along either the first measurement channel 207 or the second measurement channel 209. Because pulses contain less than one photon on average, the 50-50 beam splitter 205 will randomly direct pulses along one of the first or second measurement channels. This has the consequence of selecting the measurement basis to be either the X(D / A) basis or the Z(H / V) basis. The non-polarizing beam splitter 205 functions to enable the random selection of one of the two bases.

[0073] The first measurement channel is for the X basis, which corresponds to the D / A basis. Here, a half-wave plate 211 is provided to rotate the polarization by 45 degrees between the two detection branches, i.e., to provide two measurement bases X and Z. The output of half-wave plate 211 is then directed towards polarizing beam splitter 213, which directs pulses with opposite polarity towards opposite-angle detector 215 and pulses with diagonal polarity towards diagonal detector 217. Detectors 215 and 217 are single-photon detectors, for example avalanche photodiodes.

[0074] Pulses directed along the second measurement channel are measured in the Z-base to determine whether they are horizontal or vertical. Here, pulses directed into the second measurement channel are directed towards polarizing beam splitter 219, which directs vertically polarized pulses towards detector 221 and horizontally polarized pulses towards detector 223. Again, detectors 221 and 223 are single photon detectors.

[0075] If a photon polarized in the D / A basis is received and sent randomly to be measured in the Z basis along the second measurement channel 209, one of the detectors 221, 223 is likely to register a count. However, this result cannot be trusted, as a photon received at the polarizing beam splitter 219 has a 50-50 chance of being directed towards either the vertical or horizontal detector.

[0076] In an embodiment, the QKD hardware 303 in node 301 will comprise both a transmitter and a receiver, depending on whether the node functions as a transmitter or a receiver during the QKD process. However, it is possible for a node to include only a transmitter if it only performs QKD with a QAS or multiple nodes with a receiver, and further, a node may include only a receiver if it only performs QKD with a QAS or multiple nodes with a transmitter.

[0077] Node 301 also includes a key management system 305, which manages key exchange and storage. In the example of FIG. 3A, key management system 305 includes a QKD store 307, which stores keys established via QKD to be used to encrypt communications and PSK storage, allocated to store PSKs that users have shared with other network users (and the QAS), which can be used for authentication. Some of these PSKs may be pre-stored in the node prior to use, others may be received from the QAS (encrypted via quantum keys), and other PSKs may be reserved portions of keys generated using QKD.

[0078] The node 301 also comprises a key consuming data encryptor 311. The data encryptor uses the QKD key to encrypt / decrypt data communications (e.g. using a one-time pad or an alternative cipher such as AES).

[0079] The node may also comprise an authentication agent / unit 310 used during authentication. This may be a standalone component or part of any of the other components of the user node 301, for example a key consumption data encryptor.

[0080] 3B shows the components of the QAS 321. The components include QKD hardware 323, key management system 325 (with QKD storage 329 and PSK storage 327), key consumption data encryptor 331, and authentication unit / agent 330. In an embodiment, the QKD hardware 323 of the QAS will be the same as the QKD hardware 303 of the user node 301. However, as explained above, the QKD hardware in the user node 301 may be provided with only a QKD receiver. However, the QKD hardware 323 of the QAS will include a QKD transmitter. In many embodiments, the QKD receiver and transmitter will be provided in the QKD hardware 323 of the QAS 321.

[0081] In an embodiment, the key management system 325 of the QAS will be largely the same as the key management system 305 of the user node 301. However, it is likely that the QAS will store PSKs for more user nodes and other nodes than those stored in the user node.

[0082] In an embodiment, the key consumption data encryptor 331 of the QAS is the same as the key consumption data encryptor 311 of the user node 301 .

[0083] In an embodiment, the authentication unit / agent 330 of the QAS is the same as the authentication unit / agent 310 of the user node 301 .

[0084] Additionally, the QAS may further comprise a database of users and an access control list. The database of users on the network may comprise a database of users who share a PSK for authentication purposes. The access control list is a list that allows a network administrator to define which users are allowed to communicate.

[0085] The QAS 321 may also include a policy management module that allows the QAS to control certain policies, for example, the policy management module can enforce a fixed session length. For example, when the QAS creates a PSK to share between two users, the policy management module 335 can include additional metadata that instructs the users how the key should be used.

[0086] QAS 321 may also include a revocation list (not shown) so that previously trusted hosts can be banned. This feature would allow QAS 321 to securely message all of its trusted (i.e., able to securely authenticate using its PSK) users, telling them not to trust a particular user.

[0087] The QAS also comprises a random number generator 337, which will be used to generate random numbers to form new PSKs that are encrypted and sent to the two nodes to allow them to authenticate each other. The random number generator can also be used to control the transmitter and / or receiver in the QKD hardware 303 to provide underlying random control during QKD.

[0088] 5A and 5B are flowcharts summarizing operations performed by a user node and a QAS, respectively, according to an embodiment.

[0089] A user node, for example, Alice, performs the steps of the method of Figure 5A. In step S351, Alice sends a message to the QAS requesting authentication with a new node (Bob). Alice then needs to authenticate with the QAS. Using the example described above, authentication is performed using a MAC code generated by inputting the message and a PSK (pre-shared between the QAS and Alice). In step S353, Alice generates an authentication MAC to send to the QAS along with the corresponding message, as described above.

[0090] Independently, in step S355, Alice receives an authentication MAC from the QAS along with the message. In this flowchart, step S355 is shown after step S353. However, these steps can be performed in the reverse order or simultaneously. In some cases, one or more of the steps can be performed before sending the message in step S351.

[0091] To determine whether Alice trusts the QAS, Alice authenticates the received message in step S355 by inputting the message and her own PSK key into a pre-agreed algorithm to see if she matches the MAC code.

[0092] Once authentication is performed and Alice knows she can trust the QAS (ensuring there are no man-in-the-middle attacks), Alice and the QAS perform QKD as described above. In this example, Alice receives the QKD signal (i.e., the encoded optical pulses), and it is assumed that the pulses are generated from the QAS. In step S361, Alice then decrypts the QKD signal by modifying her measurement basis. In this embodiment, a key longer than strictly required is extracted from the QKD protocol. Part of the longer key will be used as the QKD key, and another part of the shared key will be saved as a new PSK for Alice and the QAS.

[0093] Once Alice and the QAS have shared the QKD key, Alice then receives a key encrypted with the QKD key in step S363. This key encrypted with the QKD key is what she now uses to connect her to the new node (K AB ) will be shared between Alice and herself. Alice then creates a new key (K AB ) is decrypted.

[0094] Alice then uses K to initiate authentication with the new node (Bob). AB This first step is shown in step S367, where Alice uses the PSK to generate a new authentication MAC and send it to the new node.

[0095] Figure 5B shows the steps performed by the QAS. In step S371, the QAS receives a message from Alice to authenticate with a new node (e.g., Bob), and in step S373, the QAS checks its access control list to see if Alice and Bob are allowed to communicate. If they are allowed, the QAS then obtains a new PSK for Alice and Bob to use. As described with reference to Figure 3B, the QAS can use its random number generator to generate the PSK when it receives the request. However, the QAS may also have a pre-stored random number ready to use as the PSK's.

[0096] The new PSK is AB It will be called.

[0097] In step S377a, the QAS generates an authentication MAC to send to Alice with the corresponding message, and it also receives the authentication MAC from Alice with the message in step S379a. Note that steps S377a and S379a can be performed simultaneously or in reverse order. It is also possible for the authentication steps of S377a and S379a to be performed prior to receiving the message in step S371, or prior to any of the previously described steps.

[0098] When the QAS receives the authentication MAC with the message, it authenticates it in step S381a. To do this, the QAS inputs the received message and the PSK they share with Alice and compares the generated MAC with the one received from Alice.

[0099] Once this is complete, the QAS begins performing QKD with Alice in step S383a. In this embodiment, the QAS sends encrypted optical pulses to Alice. The QAS encrypts the optical pulses by preparing optical pulses with randomly varying bases, as described above. The QAS performs sifting to generate the QKD key in step S385a. The sifting can be prepared by receiving information from Alice over an authenticated channel indicating the measurement bases she used. The QAS then sends information to Alice over a classical channel advising her which results were measured in the correct bases. The QAS then retains only the results of pulses measured in bases that match the prepared bases to generate the QKD key.

[0100] In this example, a longer key than needed for QKD is prepared by the sifting process. The excess key is then stored as one or more PSKs to generate new PSKs K for use the next time the QAS and Alice need to authenticate. AQ’ enables them to have

[0101] The QAS then generates K with the QKD keying material generated by performing QKD between Alice and the QAS. AB and sends it to Alice.

[0102] The above has been described with respect to communications with Alice. However, the QAS also performs the same steps for communications with Bob. In the flowchart of FIG. 5B , steps S377b, S379b, S381b, S383b, S385b, and S387b correspond to steps S377a, S379a, S381a, S383a, S385a, and S387a, respectively, except that steps with the suffix "a" refer to steps performed by the QAS in relation to Alice, and steps with the suffix "b" refer to steps performed by the QAS in relation to Bob. Steps S377b, S379b, S381b, S383b, S385b, and S387b may be performed simultaneously with, alternately with, before, or after steps S377a, S379a, S381a, S383a, S385a, and S387a.

[0103] Alice calculates the PSK K in step S387a. AB and Bob receives the PSK K in step 387b. AB , which allows Alice and Bob to authenticate their classical channel.

[0104] The network of Figure 1 is scalable. Figure 6 shows a network 401 according to a further embodiment, which includes a single QAS server 403 but has three switches 405, 406, and 407, which in this example support five user nodes: Alice 409, Bob 411, Charlie 413, David 415, and Frank 417.

[0105] Alice 409 and Bob 411 are connected to switch 405, and David 415 and Frank 417 are connected to switch 407. Switch #1 405 and switch #3 407 are connected to switch #2 406, with Charlie 413 also connected to switch #2 406. This arrangement means that Alice can communicate with Bob via switch #1 405, and Alice can communicate with QAS 403 via switch #1 405 and switch #2 406, both of which need to be controlled to allow both classical and QKD communications to take place between Alice 409 and QAS 403.

[0106] The network of Figure 6 can be used as a metro-scale network where each user is in a different building with five users and three optical switches, and a single QAS. Authentication between any pair of users is possible using the protocol outlined previously, where the QAS 403 establishes a PSK between the users.

[0107] The above embodiments relate to the use of a QAS for authentication, and in particular for authentication of classical channels for use in QKD. However, other uses exist, such as sessions on a quantum computer or access to a network file server. The QAS can also be used to provide authentication for users to access these resources, where the ability to include user management and access control within the QAS allows for simple network administration.

[0108] The network of Figure 7 relates to a network similar to that of Figure 6, but also includes a file server and a quantum computer. The network of Figure 7 includes a single QAS server 503 and has three switches 505, 506, and 507, which in this example support three user nodes: Alice 509, Bob 511, and Frank 517. The network also includes a quantum computer 515 and a file server 513.

[0109] Alice 509 and Bob 511 are connected to switch #1 505, and quantum computer 515 and Frank 517 are connected to switch #3 507. Switch #1 505 and switch #3 507 are connected to switch #2 506, along with file server 513 which is also connected to switch #2 506. This arrangement means that Alice can communicate with Bob via switch #1 505, and Alice can communicate with QAS 503 via switch #1 505 and switch #2 506, both of which need to be controlled to allow both classical and QKD communications to take place between Alice 509 and QAS 503.

[0110] Alice 509 can communicate with file server 513 via switch #1 505 and switch #2 506. File server 513 can communicate with QAS 503 via switch #2 506. The above embodiments have discussed using a PSK for authentication. However, in Figure 7, file server 513 can perform QKD with the QAS, which can then provide the PSK to both Alice 509 and file server 513 in the same manner as described above in connection with communications between Alice and Bob.

[0111] File server 513 can then use the PSK to authenticate messages received from Alice, Alice can authenticate messages received from file server 513 to ensure that she is sending the message to file server 513, and file server 513 can authenticate messages from Alice to ensure that communications it believes to be from Alice are indeed from Alice.

[0112] Alice 509 can also communicate with quantum computer 515 via switch #1 505, switch #2 506, and switch #3 507. Quantum computer 515 can communicate with QAS 503 via switch #2 506 and switch #3 507. The above embodiments have discussed using a PSK for authentication. However, in FIG. 7 , quantum computer 515 can perform QKD with the QAS, which can then provide the PSK to both Alice 509 and quantum computer 515 in the same manner as described above in connection with communications between Alice and Bob.

[0113] Quantum computer 515 can then authenticate messages received from Alice using the PSK, Alice can authenticate messages received from quantum computer 515 to ensure that she is sending the message to quantum computer 515, and quantum computer 515 can authenticate messages from Alice to ensure that communications it believes to be from Alice are indeed from Alice.

[0114] The above has been described with reference to Alice. However, any of Alice 509, Bob 511, or Frank 517 can communicate with file server 513 and / or quantum computer 515. File server 513 and quantum computer 515 may also want to authenticate each other, for example, when quantum computer 515 needs to access file server 513.

[0115] Communications between a user, for example, Alice, and either the file server 513 or the quantum computer 515 can be performed using a PSK shared by the QAS 503. In other embodiments, Alice communicates with either the file server 513 or the quantum computer 515 using QKD. This means that Alice communicates with them by establishing a quantum key as described above (the shared PSK is used to authenticate the classical channel), and then all communications for the session are encrypted using the shared PSK from the QAS. A new PSK can be generated from the key established during QKD as described above.

[0116] The network is highly scalable as shown in Figure 8. In this case, multiple QASs 802, 803, 805, and 807 are included in the network. The arrangement shown in Figure 8 can be viewed as three local networks 813, 815, and 817, each with its own QAS (803, 805, and 807, respectively). The three local networks 813, 815, and 817 are connected to a QAS 802, referred to as the "root" QAS 802. The root QAS 802 and the local QASs 803, 805, and 807 form a hierarchy with the root QAS 802 at the top of the hierarchy.

[0117] In this embodiment, the first network 813 has three switches 809a, 809b, and 809c, and the second switch 809b of the first network 803 is connected to the QAS 805 of the second network via a switch 821. The switch 821 is connected to the first network 813 and the second network 815 via a long-haul QKD link. The long-haul QKD link can be continuous optical fiber or optical fiber with quantum repeaters. The switch 821 is also connected to the root QAS 802.

[0118] A third local network 801 is connected to the root QAS 802 via a satellite link.

[0119] When a user, for example, user 811, requests to authenticate another user with a QAS, the request is first sent to its local QAS 803. If this QAS 803 does not have the PSK for the requested user in its database, it can relay the request to another QAS (similar to how the classical Internet infrastructure works). In an embodiment, multiple QASs are arranged in a hierarchical fashion, with all requests that cannot be serviced through the local QAS being sent to the root QAS 802. QAS servers may be linked by long-distance QKD optical fiber links, or even satellites, enabling wide-scale quantum networks. Quantum repeaters may be used in long-distance QKD links to allow long distances to be achieved.

[0120] In an embodiment, a "root" QAS server can be operated on-premise at a QKD manufacturer. This allows the manufacturer to securely install the PSK into the root QAS for all its new manufactured systems (assuming the manufacturer's premises is a trusted, secure location, which is a common assumption for QKD hardware). This PSK material for that system can then be distributed over QKD links from the manufacturer's premises to various metro networks to remote metro networks, each with its own local QAS.

[0121] In another possible embodiment, an intermediate trusted node between two users (or two QASs) can be used to relay a global key between them, where this global key can later be used as a PSK for authentication.

[0122] In some circumstances, it may not be possible for all users to form an optical link to the QAS, for example, due to network congestion (i.e., busy optical switches) or when users are connected in a sparse mesh with few links between them.

[0123] 9 shows a possible embodiment, where a QAS 901 can provide its own PSK with the target user to any trusted user who requests it. For example, consider a network in which Alice 903 wants to communicate with Bob 905, but Bob 905 cannot be optically connected to QAS 901.

[0124] In this case, Alice 903 authenticates herself with the QAS 901 and requests a PSK with Bob. The QAS checks its policies and user access control lists and, if allowed, gives Alice the PSK, K, to share with Bob. BQ (communicated over a QKD secured link (i.e. encrypted using the QKD key generated between Alice and the QAS)). To avoid reusing keys, the QAS can discard the PSK from its database.

[0125] Alice and Bob now share a symmetric PSK. From this, an optical switch can connect a quantum link between them, and they share the PSK K BQ From this, they can perform QKD and generate a new quantum key to use for secure communications. The final step in this embodiment is that some of the generated QKD keying material is reserved as a new PSK that Bob will use to authenticate the QAS. After completing QKD with Bob, Alice reconnects with the QAS and uses the new PSK, K, that was shared with Bob. BQ’ otherwise, if this last step is skipped, the QAS will not be able to authenticate Bob in future sessions (since it gave Alice its PSK first).

[0126] This embodiment has the benefit of requiring fewer quantum links to be used between users for secure communication. However, a downside is that if a network failure occurs before the process is complete, the QAS may be left without the PSK for authentication with Bob. The previously described embodiment is therefore in fact a more robust approach. However, we have also outlined this concept to illustrate that our approach and photonic quantum network scheme can be adapted to many network topologies and use cases.

[0127] It is worth noting that by establishing the authentication PSK through the QAS, the QAS also knows the value of the PSK. Therefore, Alice and Bob can use the K issued by the QAS to AB When authenticating using a QKD protocol, the user must implicitly assume that the QAS is trusted, as the QAS could potentially perform a man-in-the-middle attack to read the secure communications between Alice and Bob. This is a reasonable assumption, as the QAS will typically be securely located and managed (e.g., by the network operator or QKD manufacturer).

[0128] 10 shows a further embodiment with two QASs 951 and 953; this assumption can be relaxed by using two QASs in the network (or two nodes in a peer-to-peer scenario). Alice and Bob now obtain a PSK from each QAS (following the method outlined previously), and now combine these PSKs K1 and K2 coming from QKD with QAS servers 1 and 2, respectively. AB and K2 AB Alice and Bob then use these two keys to perform an XOR operation to determine their actual PSK, K AB Form:

number

[0129] This means that they share a symmetric shared key, but where this key is not shared by QAS1 or QAS2, providing resilience (against man-in-the-middle attacks) if either of these servers is compromised.

[0130] The above embodiments allow any remote user to perform authenticated communications so that they can initiate a QKD session to generate additional keying material. This QKD keying material can then be used for secure communications of arbitrarily large data sizes. We propose that our invention covers both the authentication system and the resulting optically switched quantum communication network design.

[0131] This avoids the need to manually install a PSK into each pair of QKD systems, as the above provides a solution where authentication is performed using a network link, rather than manually installing keys at each location by a trusted courier.

[0132] In addition to greatly simplifying authentication enforcement, the QAS system provides additional network management features such as the ability to enforce access policies such as user access control lists (including revocation if a user is compromised) and even enforce timed sessions through key metadata. This concept is therefore broadly applicable to quantum networks, connecting both users for authenticated data communication and providing trusted access management to network services such as file servers, quantum computing and quantum sensing nodes.

[0133] The above embodiments allow users on a quantum network to communicate securely without the manual installation of authentication keys.

[0134] Furthermore, they provide a scalable design for networks, and even networks of networks over large geographic areas (compatible with various QKD protocols, e.g., TF-QKD for long-distance or satellite QKD). The above networks are compatible with free-space and optical fiber communication channels. Furthermore, various embodiments of the concept are possible, supporting a variety of network topologies.

[0135] Furthermore, the above also provides the ability to support network and user management features, as well as robustness against the unlikely event of a compromised authorized server via XOR of multiple PSKs. Compared to classical / PQC approaches to authentication, the above embodiments are robust against advances in cryptanalysis and quantum computer cryptographic attacks.

[0136] While certain specific embodiments have been described, these embodiments are presented by way of example only and are not intended to limit the scope of the invention. Indeed, the novel devices and methods described herein may be embodied in a variety of other forms, and further, various omissions, substitutions, and changes in the form of the devices, methods, and products described herein may be made without departing from the spirit of the invention. The accompanying claims and their equivalents are intended to cover such forms and modifications as are within the scope and spirit of the invention.

Claims

1. A system comprising: a first user node; a second user node; and a server, The server comprises a network interface, an authentication unit, an encryption unit, a key management system including a first pre-shared key (PSK) shared with a first user node, and a quantum key distribution unit; the authentication unit is configured to receive, via the network interface, a request from the first user node to authenticate a first channel between the first user node and the server using the first PSK; the quantum key distribution unit is configured to enable a quantum key to be distributed between the first user node and the server, the quantum key being decrypted using communication over the authenticated first channel, a measurement basis being changed, a first quantum key for the first user node and the server being established, and the first PSK being discarded; the first user node encrypts a message requesting communication with the second user node with the first quantum key and sends the message to the server; The server receives the message and determines whether communication between the first user node and the second user node is permitted based on the message; the key management system is configured to generate a new PSK to be shared by the first user node and the second user node, and provide the new PSK to the first user node, to enable the first user node to authenticate with the second user node if the communication is allowed; the encryption unit is configured to encrypt the new PSK with the first quantum key for transmission to the first user node via the network interface; the server sends the new PSK encrypted with the first quantum key to a first user node; the key management system further includes a second PSK shared with a second user node; the authentication unit is configured to send a request to the second user node via the network interface for authentication of a second channel between the second user node and the server using the second PSK; the quantum key distribution unit is configured to enable a quantum key to be distributed between the second user node and the server, the quantum key being decrypted using communication over the authenticated second channel, a measurement basis being changed, a second quantum key for the second user node and the server being established, and the second PSK being discarded; the encryption unit is configured to encrypt the new PSK with the second quantum key for transmission to the second user node via the network interface; the server transmits the new PSK encrypted with the second quantum key to a second user node; the first user node authenticates with the second user node using the new PSK, a third quantum key is established for the first user node and the second user node, the first user node discards the new PSK, and communicates with the second user node by encrypting messages to be communicated with the third quantum key.

2. 2. The system of claim 1, wherein the first quantum key has a first length, the quantum key distribution unit is configured to distribute keys longer than the first length, and the remainder of the keys is stored as at least one PSK for further authentication between the server and the first user node.

3. The system of claim 1 , wherein the new PSK is pre-shared with the second user node.

4. 2. The system of claim 1, further comprising an access control unit configured to store information indicating whether two user nodes are allowed to share a PSK, and the server configured to accept or decline a request from a user node to obtain a shared key by referring to the information stored in the access control unit.

5. The system of claim 1 , wherein the server is configured to contact a further server to determine whether to accept or decline a request from a user node to obtain a shared key.

6. 10. The system of claim 1, wherein the server further comprises a policy unit configured to provide information for controlling at least one of a quantum key length, a PSK key length, and information to be sent with the PSK.

7. The quantum key distribution unit an encoder configured to encode information onto light, the information being encoded by randomly selecting one state from a plurality of states for transmission to the user node, the light leaving the server in pulses containing less than one photon on average; a decoder, the decoder being configured to receive light pulses containing less than one photon on average and to decode information from the light pulses by measuring the light pulses, a measurement basis for the measurements being randomly selected from a set of measurement bases to enable measurement of the states used to encode the information; wherein the quantum key distribution unit further comprises a sifting unit configured to enable the server to compare a measurement basis used for encoding or decoding with a measurement basis used by the user node for decoding or encoding, and the quantum key distribution unit is configured to discard the information from a pulse if a measurement basis for the encoding and a measurement basis for the decoding do not match.

8. a network comprising a first server, a plurality of user nodes, and at least one switch, the at least one switch being configured to enable selective connectivity between any two of the user nodes and between any of the user nodes and the server, each of the user nodes comprising a node quantum key distribution unit, a node network interface, and a node authentication unit; the first server comprising a server network interface, a server authentication unit, an encryption unit, a key management system including a first pre-shared key (PSK) shared with the first user node, and a server quantum key distribution unit; the server authentication unit is configured to receive, via the server network interface, a request from the first user node to authenticate a first channel between the first user node and the server using the first PSK; the server quantum key distribution unit is configured to enable a quantum key to be distributed between the first user node and the server, the quantum key being decrypted using communication over the authenticated first channel, a measurement basis being changed, a first quantum key for the first user node and the server being established, and discarding the first PSK; the first user node encrypts a message requesting communication with a second user node with the first quantum key and sends the message to the server; The server receives the message and determines whether communication between the first user node and the second user node is permitted based on the message; the key management system is configured to generate a new PSK to be shared by the first user node and the second user node, and provide the new PSK to the first user node, to enable the first user node to authenticate with the second user node if the communication is allowed; the encryption unit is configured to encrypt the new PSK with the first quantum key for transmission to the first user node via the server network interface; the server sends the new PSK encrypted with the first quantum key to a first user node; the key management system further includes a second PSK shared with a second user node; the server authentication unit is configured to send a request to the second user node via the server network interface for authentication of a second channel between the second user node and the server using the second PSK; the server quantum key distribution unit is configured to enable a quantum key to be distributed between the second user node and the server, the quantum key being decrypted using communication over the authenticated second channel, a measurement basis being changed, a second quantum key for the second user node and the server being established, and discarding the second PSK; the encryption unit is configured to encrypt the new PSK with the second quantum key for transmission to the second user node via the server network interface; the server transmits the new PSK encrypted with the second quantum key to a second user node; the first user node authenticates with the second user node using the new PSK, a third quantum key is established for the first user node and the second user node, discards the new PSK, and communicates with the second user node by encrypting messages to be communicated with the third quantum key; the plurality of user nodes includes the first user node and the second user node; network.

9. 9. The network of claim 8, further comprising at least one further server, said at least one further server also comprising an identical configuration to said first server, said first server being configured to send a query to said further server upon receiving a request from a user node for a shared PSK that said first server cannot satisfy.

10. The network described in claim 8, further comprising a plurality of further servers having an identical configuration to the first server, the first server and the plurality of further servers being arranged in a hierarchy, and the first server being configured to send a query to another server above it in the hierarchy when it receives a request from a user node for a shared PSK that the first server cannot satisfy.

11. 9. The network of claim 8, comprising two servers, the first user node receiving PSKs from the two servers in response to a request for a PSK to authenticate with a second user node, the first user node forming a combined PSK from the two PSKs generated from the two servers, and the second user node also deriving the combined PSK to enable the first user node and the second user node to authenticate.

12. The network of claim 8 , wherein the at least one switch is located within at least one of a server or a user node.

13. The network of claim 8 , wherein the user nodes comprise at least one selected from a file server or a quantum computer.

14. The network of claim 8 , wherein the network comprises a plurality of sub-networks, the plurality of sub-networks being linked by a communication channel.

15. 1. A method for sharing a pre-shared key (PSK) between a first node and a second node in a network, the method comprising: The server stores a first PSK shared with the first node; authenticating a first channel between the first node and the server using the first PSK; performing quantum key distribution (QKD) between the server and the first node, using communication over the authenticated first channel to change a measurement basis for decryption, establishing a first quantum key for the first node and the server, and discarding the first PSK; the first node encrypting a message with the first quantum key to request communication with the second node and sending the message to the server; the server receives the message and determines whether communication between the first node and the second node is permitted based on the message; generating a new PSK at the server to be shared by the first node and the second node to enable authentication between the first node and the second node if the communication is permitted, providing the new PSK to the first node by the server, and encrypting the new PSK at the server with the first quantum key to send to the first node; the server sending the encrypted PSK to the first node; further including a second PSK that the server shares with a second node; the server sending a request to the second node to authenticate a second channel between the second node and the server using the second PSK; the server allows a quantum key to be distributed between the second node and the server, the quantum key being decrypted using communication over the authenticated second channel, a measurement basis being changed, a second quantum key for the second node and the server being established, and discarding the second PSK; the server encrypts the new PSK sent to the second node with the second quantum key; the server transmitting the new PSK encrypted with the second quantum key to a second node; the first node authenticates with the second node using the new PSK, a third quantum key is established for the first node and the second node, discards the new PSK, and communicates with the second node by encrypting messages to be communicated with the third quantum key; A method comprising:

16. 16. The method of claim 15, wherein the new PSK is pre-shared with the second node.

Citation Information

Patent Citations

  • Method and apparatus for managing encryption key in private communication network

    JP2008306633A

  • Secure multi-party communication with quantum key distribution managed by a communications trust organization.

    JP2013539324A

  • Quantum bond delivery

    JP2013544479A

  • Key distribution center for quantum cryptographic key distribution networks

    US7457416B1

  • Quantum key distribution protocol

    WO2021090025A1