Quantum-secure network clock synchronization
A multi-node quantum communication network with entangled photon pairs and closed-loop conditions synchronizes local clocks and detects adversarial attacks, addressing synchronization challenges across multiple nodes and ensuring secure time transfer.
Patent Information
- Application Number
- JP2022577104
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-06-15
- Filing Date
- 2021-06-15
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2041-06-15
AI Technical Summary
Extending clock synchronization in quantum communication networks beyond two nodes is challenging, as existing methods do not effectively address synchronization across multiple nodes without treating each pair as a separate two-node network, making networks vulnerable to adversarial attacks.
A multi-node quantum communication network with a closed-loop configuration using authenticated communication channels and entangled photon pairs to synchronize local clocks and detect Damon attacks by measuring time differences and travel durations between nodes, ensuring secure time transfer and synchronization.
Enables secure, unspoofable time transfer and synchronization across multiple nodes, constraining potential adversarial manipulations and maintaining network security through closed-loop conditions and entanglement-based monitoring.
Smart Images

Figure 0007821748000197 
Figure 0007821748000198 
Figure 0007821748000199
Abstract
Description
[Technical Field]
[0001] This application claims priority to U.S. Provisional Patent Application No. 63 / 039363, filed June 15, 2020, and entitled "Quantum Secure Network Clock Synchronization."
[0002] The present invention relates to quantum communications, and more particularly to quantum communications networks with three or more nodes. [Background technology]
[0003] Quantum communication, i.e., secure optical communication enabled by the use of the quantum properties of photons, is becoming more accepted and moving into the mainstream. While large-scale fiber optic and free-space optical implementations of quantum communication systems have been demonstrated, extending point-to-point, two-node systems to multi-node networks has been difficult to implement. Summary of the Invention [Means for solving the problem]
[0004] A multi-node quantum communication network for providing quantum-secure time transfer with Damon attack detection is described according to one embodiment. The network includes three or more nodes connected via authenticated communication channels that form a closed loop. The network detects Damon attacks, if present, by determining the difference between local times and the duration required for a photon to travel between the three or more nodes. For example, the network imposes a closed-loop condition to detect Damon attacks. The network can also use the local time difference and the duration required for a photon to travel between the nodes to synchronize the local clocks at the three or more nodes of the network.
[0005] According to another embodiment, a multi-node quantum communication network for providing quantum-secure time transfer with Damon attack detection includes a first node, a second node, and a third node. The first node includes a first local clock and a first photon pair source for providing a first entangled photon pair, the first entangled photon pair including a first photon and a second photon. The first node also includes a first capturing device for capturing the first photon at a first local time t1 in the first local clock and a first coupling mechanism for directing the second photon away from the first node. The first node further includes a first measurement device for receiving photons from outside the first node and a first controller for controlling at least the first local clock, the first photon pair source, the first capturing device, the first coupling mechanism, and the first measurement device. The second node includes a second local clock and a second photon pair source for providing a second entangled photon pair, the second entangled photon pair including a third photon and a fourth photon. The second node also includes a second capturing device for capturing the third photon at a second local time t2 in the second local clock and a second coupling mechanism for directing the fourth photon away from the second node. The second node further includes a second measurement device for receiving photons from outside the second node and a second controller for controlling at least the second local clock, the second photon pair source, the second capturing device, the second coupling mechanism, and the second measurement device. The third node includes a third local clock and a third photon pair source for providing a third entangled photon pair, the third entangled photon pair including a fifth photon and a sixth photon. The third node also includes a third capturing device for capturing the fifth photon at a third local time t3 in the third local clock, and a third coupling mechanism for directing the sixth photon away from the third node.The third node additionally includes a third measurement device for receiving photons from outside the third node, and a third controller for controlling at least the third local clock, the third photon pair source, the third capturing device, the third coupling mechanism, and the third measurement device. The network further includes a first authenticated communication channel communicatively connecting the first and second nodes, a second authenticated communication channel communicatively connecting the second and third nodes, and a third authenticated communication channel communicatively connecting the third and first node. The first, second, and third nodes and the first, second, and third authenticated communication channels form a closed loop. The first, second, and third controllers are configured to determine a difference between the first, second, and third local times and to measure durations required for a second photon to travel from the first node to the second node, for a second photon to travel from the first node to the third node, for a fourth photon to travel from the second node to the first node, for a fourth photon to travel from the second node to the third node, for a sixth photon to travel from the third node to the first node, and for a sixth photon to travel from the third node to the second node. The first, second, and third controllers are also configured to use the difference between the first, second, and third local times and the durations so measured to detect a Damon attack, if present.
[0006] According to a further embodiment, the first, second, and third controllers are further configured to detect a Damon attack if a closed-loop condition is not satisfied. In one embodiment, the closed-loop condition is 12 +δ 23 +δ 31 =0, where t1 is the local time at the first node, t2 is the local time at the second node, t3 is the local time at the third node, and δ 12 = t1-t2, δ 23 = t2 - t3, and δ 31 =t3-t1.
[0007] In another embodiment, the first, second, and third photon pair sources are configured to generate polarization-entangled photon pairs.
[0008] In still further embodiments, the difference between the first, second, and third local times and the duration so measured are used to synchronize the first, second, and third local clocks.
[0009] According to another embodiment, a method for determining the presence of a Damon attack in a multi-node quantum communication network for providing quantum-secure time transfer is described. The method includes identifying a closed loop formed by at least three nodes in the network and determining a difference between the local clocks of the at least three nodes. The method further includes imposing a closed-loop condition on the determined difference and detecting the presence of a Damon attack if the closed-loop condition is not satisfied by the determined difference.
[0010] In a further embodiment, the method includes generating, at a respective one of the at least three nodes, an entangled photon pair including a first photon and a second photon entangled with the first photon, and capturing the first photon in a local time for the one of the at least three nodes. The method further includes measuring a travel time for the second photon to travel from one of the at least three nodes to another of the at least three nodes, calculating a difference in the local time from one of the at least three nodes to another of the at least three nodes, and determining whether a local clock at each one of the at least three nodes is synchronized with another of the at least three nodes. The present specification also provides, for example, the following: (Item 1) 1. A multi-node quantum communications network for providing quantum secure time transfer with Damon attack detection, the network comprising: a first node, a first local clock; a first photon pair source for providing a first entangled photon pair, the first entangled photon pair including a first photon and a second photon; a first local time t at the first local clock 1 a first capture device for capturing the first photons; a first coupling mechanism for directing the second photons away from the first node; a first measurement device for receiving photons from outside the first node; a first controller for controlling at least the first local clock, the first photon pair source, the first capture device, the first coupling mechanism, and the first measurement device; a first node including: a second node, a second local clock; a second photon pair source for providing a second entangled photon pair, the second entangled photon pair including a third photon and a fourth photon; a second local time t at the second local clock 2 a second capture device for capturing the third photons in a second coupling mechanism for directing the fourth photons away from the second node; and a second measurement device for receiving photons from outside the second node; a second controller for controlling at least the second local clock, the second photon pair source, the second capture device, the second coupling mechanism, and the second measurement device; a second node including a third node, a third local clock; and a third photon pair source for providing a third entangled photon pair, the third entangled photon pair including a fifth photon and a sixth photon; a third local time t at the third local clock 3 a third capture device for capturing the fifth photon at a third coupling mechanism for directing the sixth photons away from the third node; and a third measurement device for receiving photons from outside the third node; a third controller for controlling at least the third local clock, the third photon pair source, the third capture device, the third coupling mechanism, and the third measurement device; a third node, a first authenticated communication channel communicatively connecting the first and second nodes; a second authenticated communication channel communicatively connecting the second and third nodes; a third authenticated communication channel communicatively connecting the third and first nodes; Equipped with the first, second, and third nodes and the first, second, and third authenticated communication channels form a closed loop; The first, second, and third controllers determining a difference between the first, second, and third local times; For the second photon to travel from the first node to the second node, For the second photon to travel from the first node to the third node, For the fourth photon to travel from the second node to the first node, For the fourth photon to travel from the second node to the third node, for the sixth photon to travel from the third node to the first node; and For the sixth photon to travel from the third node to the second node, measuring the required duration; using the difference between the first, second, and third local times and the duration so measured to detect a Damon attack, if present; A network configured to: (Item 2) 2. The network of claim 1, wherein the first, second, and third controllers are further configured to detect the Damon attack if a closed-loop condition is not satisfied. (Item 3) The closed loop condition is δ 12 +δ 23 +δ 31 = 0, In the formula, δ 12 =t 1 -t 2 , δ 23 =t 2 -t 3 , and δ 31 =t 3 -t 1 3. The network according to item 2, wherein (Item 4) Item 1. The network of item 1, wherein the first, second, and third photon pair sources are configured to generate polarization-entangled photon pairs. (Item 5) 2. The network of claim 1, wherein the difference between the first, second, and third local times and the duration so measured are used to synchronize the first, second, and third local clocks. (Item 6) 1. A method for determining the presence of a Damon attack in a multi-node quantum communication network for providing quantum secure time transfer, the method comprising: identifying a closed loop formed by at least three nodes in the network; determining a difference between the local clocks of the at least three nodes; imposing a closed-loop condition on said difference so determined; detecting the presence of the Damon attack if the closed-loop condition is not satisfied by the difference so determined; A method comprising: (Item 7) Imposing the closed-loop condition includes, at each one of the at least three nodes: generating an entangled photon pair, the entangled photon pair including a first photon and a second photon entangled with the first photon; capturing the first photon at a local time for one of the at least three nodes; measuring a travel time for the second photon to travel from one of the at least three nodes to another of the at least three nodes; calculating a difference in local time from one of the at least three nodes to another of the at least three nodes; determining whether the local clock at each one of the at least three nodes is synchronized with another of the at least three nodes; Item 7. The method according to item 6, comprising: [Brief explanation of the drawings]
[0011] [Figure 1]FIG. 1 illustrates a two-node quantum communication system.
[0012] [Figure 2] FIG. 2 illustrates two nodes of a quantum communication system that enables secure time transfer across multiple nodes, according to one embodiment.
[0013] [Figure 3] FIG. 3 illustrates a configuration for a three-node quantum communication system, according to one embodiment.
[0014] [Figure 4] FIG. 4 illustrates another configuration for a three-node quantum communication system, according to an embodiment.
[0015] [Figure 5] FIG. 5 illustrates a configuration for a four-node quantum communication system, according to one embodiment.
[0016] [Figure 6] FIG. 6 illustrates another configuration for a four-node quantum communication system, according to an embodiment.
[0017] [Figure 7] FIG. 7 illustrates yet another configuration for a four-node quantum communication system, according to an embodiment.
[0018] [Figure 8] FIG. 8 illustrates a configuration for a five-node quantum communication system, according to one embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0019] The present invention will now be described more fully with reference to the accompanying drawings, in which embodiments of the invention are shown. However, the present invention may be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art. In the drawings, the sizes and relative sizes of layers and regions may be exaggerated for clarity. Like numbers refer to like elements throughout.
[0020] Terms such as "first," "second," and "third" may be used herein to describe various elements, components, regions, layers, and / or sections, but it should be understood that these elements, components, regions, layers, and / or sections are not limited by these terms. These terms are merely used to distinguish one element, component, region, layer, or section from another region, layer, or section. Thus, a first element, component, region, layer, or section discussed below could be referred to as a second element, component, region, layer, or section without departing from the teachings of the present invention.
[0021] Spatially relative terms such as "below," "below," "belowside," "below," "above," "upper," and the like may be used herein for ease of explanation to describe the relationship of one element or feature to another element or feature as illustrated in the figures. It should be understood that the spatially relative terms are intended to encompass different orientations of the device in use or operation in addition to the orientation depicted in the figures. For example, if the device in the figures were turned over, elements described as being "below," or "beneath," or "below" other elements or features would therefore be oriented "above" the other elements or features. Thus, the exemplary terms "below" and "below" can encompass both an "above" and "below" orientation. The device may be oriented differently (rotated 90 degrees or in other orientations) and the spatially relative descriptors used herein interpreted accordingly. Additionally, when a layer is referred to as being "between" two layers, it should be understood that this may be the only layer between the two layers, or that one or more intervening layers may also be present.
[0022] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the present invention. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly dictates otherwise. It should be further understood that the terms "comprises" and / or "comprising," as used herein, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items and may be abbreviated as " / ."
[0023] When an element or layer is referred to as being "on," "connected to," "coupled to," or "adjacent to" another element or layer, it is understood that it may be "directly on," "connected to," "coupled to," or "adjacent to" the other element or layer, or that intervening elements or layers may be present. In contrast, when an element is referred to as being "directly on," "directly connected to," "directly coupled to," or "directly adjacent to" another element or layer, no intervening elements or layers are present. Similarly, when light is received or provided "from" an element, it can be received or provided "directly from" that element or an intervening element. On the other hand, when light is received or provided "directly from" an element, no intervening elements are present.
[0024] Embodiments of the present invention are described herein with reference to cross-section illustrations that are schematic illustrations of idealized embodiments (and intermediate structures) of the present invention. As such, variations in the shapes of the illustrations are to be expected as a result, for example, of manufacturing techniques and / or tolerances. Thus, embodiments of the present invention should not be construed as limited to the particular shapes of regions illustrated herein but are to include deviations in shapes that result, for example, from manufacturing. Thus, the regions illustrated in the figures are schematic in nature and their shapes are not intended to illustrate the actual shape of regions of a device and are not intended to limit the scope of the present invention.
[0025] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs. It is further understood that terms such as those defined in commonly used dictionaries should be interpreted to have a meaning consistent with their meaning in the relevant field and / or in the context of this specification, and will not be interpreted in an idealized or overly formal sense unless expressly defined as such herein.
[0026] While some aspects of quantum communication, such as the reliable production of entangled photons, have been reliably demonstrated, other aspects remain challenging. One example is the need for clock synchronization and synchronization across multiple nodes in a quantum communication network. For example, clock synchronization of a two-node quantum network is described in U.S. Patent Publication No. 2020 / 0084033 A1, entitled "Quantum Secure Clock Synchronization Based on Time-Energy and Polarization Entangled Photon Pairs," by Lamas-Linares, et al. While this patent application describes a method for securely synchronizing clocks at two nodes, it does not discuss extending the concept to larger networks with multiple nodes without separately establishing inter-node time transfer for every node combination. That is, while the methods described above discuss synchronizing clocks between two nodes, they do not disclose clock synchronization across a network of three or more nodes without treating the network as a cluster of two-node networks.
[0027] For example, Figure 1 shows a two-node network 100 including node A and node B connected by a bidirectional link (quantum channel) 110. The length of quantum channel 110 may or may not be known. The propagation time for a photon (indicated by arrow 112) to travel from node A to node B is Δt AB and the propagation time for a photon (indicated by arrow 114) to travel from node B to node A is Δt BA In each node, the local time is calculated as t A and t B ) and set frequencies (f A and f B) there are local clocks (120 and 130 at node A and node B, respectively) to operate at f A =f B Assume that the time marker t A and t B Assume that the local clocks 120 and 130 have an unknown relationship to each other, and the relationship between the local clocks 120 and 130 is not known. When the local clocks 120 and 130 are co-located, the time difference can be expressed as:
[0028]
number
[0029]
number
[0030] Continuing with reference to FIG. 1 , an entangled photon pair source (122 and 132 at node A and node B, respectively) produces polarization-entangled photon pairs, for example, by spontaneous parametric downconversion (SPDC) or a similar method. One photon from each photon pair is locally detected by a first detector (124 and 134 at node A and node B, respectively) and detected at a local time (t lA and t lB ) The other photon from each photon pair is sent across quantum channel 110 towards the other node, separated by a circulator (e.g., polarization-maintaining circulators 126 and 136 at nodes A and B, respectively), detected by a second detector (e.g., 128 and 138 at nodes A and B, respectively), and transmitted to the receiving node (e.g., t rA and t rB ) This process of detection and time tagging is called measurement and involves the prediction of the polarization state and destruction of that photon by the detector.
[0031] The photons in each photon pair exhibit a relationship between time markers locally assigned by the producing node and the remote node. This relationship depends on the inherent clock difference and propagation time between the producing node and the remote node. For any given photon pair i produced in node A, this relationship can be expressed as:
[0032]
number
[0033] For all produced photon pairs [ka] An efficient way to obtain τ is to calculate the correlation across all time markers corresponding to photons produced at node A. AB The maximum value of can be expressed as follows:
[0034]
number
[0035] Similarly, for the photon pair originating from node B, the cross-correlation τ BA The maximum value of can be expressed as follows:
[0036]
number
[0037] In principle, Δt AB =Δt BAHowever, when an optical fiber or free-space single-mode optical channel is used as quantum channel 110, it is assumed that photons traveling in directions 112 and 114 are essentially the same except for their direction of propagation. Therefore, in this example, for simplicity, Δt AB =Δt BA Therefore, the time difference δ AB can be expressed as follows:
[0038]
number
[0039] Therefore, regardless of the symmetry of the quantum channel 110, the round trip time can be expressed as:
[0040]
number
[0041] Using the known relationship established in the above equation, the time relationship between the two local clocks 120 and 130 at node A and node B, respectively, can be extracted to synchronize the two local clocks. Clock synchronization is essential for quantum communications (and other communications infrastructures) because relative time readings between uniform atomic clocks can drift within short time frames, and disruptions in time transfer are one indicator of adversarial attacks on the quantum channel. Therefore, time transfer between nodes of a quantum communications network in a secure, unspoofable manner is essential to ensure the security of the overall data transfer. In other words, any two nodes in the network can be synchronized in time in a quantum-secure manner, with the additional assumption that the channels connecting the nodes are symmetric in time due to the propagation of photons, which are produced at random times and whose properties are identical except for the direction of propagation. If a malicious party ("Damon") controls the degree of asymmetry of the quantum channel, he or she can use it to manipulate the measured offset between the two nodes. Nevertheless, in a two-node network, the ability of a malicious party to manipulate the symmetry of a single channel can undermine the security of the procedure and the network operator can be warned against intrusion.
[0042] However, the above discussion is limited to a two-node network. To extend the above approach to quantum communication networks containing more than two nodes, the assumptions and calculations must be repeated for each pair of nodes in the network (i.e., pairwise synchronization). That is, direct application of the above approach for time transfer to multi-node networks beyond two nodes is not trivial.
[0043] It is recognized herein that with an appropriate set of adjustments to the operation and functionality of the hardware at each node, time transfer between multiple nodes in a quantum communications network can be greatly simplified in a secure, unspoofable manner.
[0044] A multi-node quantum communication network is described. The network includes three or more nodes connected via a quantum channel and is configured to enable quantum-secure time transfer across all nodes in the network. The network is also configured to provide synchronization and entrainment of local clocks in the three or more nodes. A method of operating a multi-mode quantum communication network with quantum-secure time transfer is also described.
[0045] In particular, the present disclosure provides quantum-secure clock synchronization and synchronization hardware and procedures for secure time transfer between clocks in a network of three or more nodes, each of which contains:
[0046] a local clock (e.g., local clock 120 in FIG. 1 ) with an initially unknown offset relative to other clocks in the network;
[0047] - a polarization-entangled photon pair source (e.g., source 122) with high intrinsic time correlation, for example based on SPDC;
[0048] a capture device for one of the down-conversion modes (e.g., the first detector 124), containing one member of the entangled photon pair;
[0049] a coupling mechanism (e.g., quantum channel 110) by which the other member of the entangled photon pair is introduced into a single optical mode connecting the producing node to another receiving node;
[0050] a measurement device (e.g., a circulator 126 and a second detector 128) connected to the input signal from the quantum channel;
[0051] - an authenticated communication channel between each member of the node and the rest of the network (sometimes referred to as a classical channel, which can function simultaneously with the quantum channel described above);
[0052] A controller (e.g., controller 220 in FIG. 2) configured for managing the above components for each node and enabling secure time transfer throughout the multi-node network.
[0053] The various components of the nodes in the network are illustrated in Figure 2. As shown in Figure 2, network portion 200 includes two nodes A and B, each of which includes a controller (e.g., controllers 220 and 230 at nodes A and B, respectively) and connections to additional nodes in addition to the two-node network shown in Figure 1. Controllers 220 and 230 provide additional functionality to enable quantum-secure time transfer between the various nodes in the network.
[0054] In a multi-node network, a pairwise synchronization procedure between any two nodes in the network, such as that described above, can provide a set of relationships between possible channel operations that Damon can implement before resulting in non-transiency due to an additional set of constraints arising from the network topology. In non-mathematical terms, it is recognized herein that these constraints imply that Damon must simultaneously control different sections of the entire network and introduce equal magnitude and opposite sign asymmetries in different channels. It is further recognized herein that the detailed mathematical structure also illustrates that not all pairwise exchanges are necessary to ensure secure time transfer throughout a multi-node network, and thus provides a constructive approach for determining the minimum number of pairwise exchanges, and thus determining useful and optimal network topologies and system structures.
[0055] In the network configuration described below, the constraints imposed by the network topology are available to all nodes via authenticated communication channels and can be constantly monitored for consistency. Any inconsistencies in the monitored values associated with these constraints can result in a modification of the derived confidence level of the time transfer procedure. The topology conditions can also be extended with any additional knowledge of the network channels and the laws of physics. For example, for two Earth-based, non-moving, stationary nodes whose relative distance is known, it is a safe assumption, among other assumptions, that the minimum propagation time between the nodes is equal to or higher than the speed of light in a vacuum, and that all propagation times should be higher than zero. For links between nodes in a spatial environment, the links themselves can be remotely monitored for attempts at interference and therefore assumed to be identical with respect to symmetry-breaking attacks, although this can be very complex. In dynamic networks where nodes are added and removed ad hoc over the network's lifetime, the constraints on the operation of a Damon attack change as the topology changes and propagate throughout the network, thus posing additional challenges for successful hacking.
[0056] Furthermore, in the network configuration described below, the authenticity of the time signals themselves (i.e., the entangled photons being exchanged) can be guaranteed by the ability of the sending and receiving nodes to perform Bell inequality analysis on the photon pairs. Due to the quantum no-cloning theorem of quantum mechanics and the monogamy of entanglement, it is essentially impossible for a Daemon attack by forging (i.e., spoofing) the time signal to manipulate the synchronization process in this manner. In other words, the present disclosure provides a method for incorporating additional knowledge about network properties (e.g., limitations on propagation time) for quantum time transfer networks to bound possible modifications introduced by malicious parties targeting the time transfer procedure.
[0057] In one embodiment, synchronization of clocks at multiple nodes applies to both time transfer and synchronization between clocks. That is, the process described herein is applicable to both clock synchronization (i.e., setting different clocks to read the same time at a given moment) and clock synchronization (i.e., setting clocks to the same frequency or rate regardless of the time they display). It should be recognized that while clocks may be synchronized with respect to a given moment, they will drift away from each other due to slight differences in their time-keeping devices. Also, clocks can be synchronized to compensate for these slight differences in their time-keeping devices in some way, but they may still read different times on their faces. The disclosed network implementation enables both secure synchronization and synchronization across a network involving two or more nodes. Secure synchronization can be achieved, for example, by comparing the time intervals between successful paired detections at the two nodes. The ability for secure synchronization can provide advantages, particularly for large-scale mesh and secure network communications, required, for example, for 5G applications and military applications. In other words, the quantum communication systems described herein can be used "natively" to keep various clocks well synchronized so that there is no significant relative drift that would affect the accuracy of the time transfer. That is, clock frequencies throughout the network are essentially the same, so that clock drift relative to other clocks can be constantly corrected during operation.
[0058] One way in which the distribution of entangled photons can be used is to generate secure keys between two nodes so that these keys can be used to encode information transmitted in an open channel, thus helping to obscure timing conclusions from unauthorized passive listeners or eavesdroppers. For example, by using the network configurations described herein to secure positioning, navigation, and timing (PNT)-related procedures, a communication system provides built-in protection of information gleaned from synchronization procedures.
[0059] Turning now to Figure 3, a simple three-node quantum communication network 200 is illustrated. Nodes A, B, and C each contain the node components illustrated in Figure 2, for example. The various propagation times between the nodes are shown in Figure 2. As in the two-node example discussed above, there is no guarantee that the links are symmetric in their propagation times (e.g., Δt AB does not necessarily mean Δt BA is not equal to ).
[0060] With such a three-node network, the first step in the analysis is to determine three quantities: AB =t A -t B , δ BC =t B -t C , and δ CA =t C -t A As in the two-node case, we obtain the following measured pairwise quantities:
[0061]
number
[0062]
number
[0063]
number
[0064]
number
[0065]
number
[0066]
number
[0067] In addition to the pairwise relationships in equations 8-13, the relationships between clocks in the closed loop provide the following additional constraints:
[0068]
number
[0069] This additional loop constraint provides a possible asymmetry in the system that could potentially be introduced into a Damon attack without detection. Combining equation 14 with equations 8-13 gives:
[0070]
number
[0071]
number
[0072]
number
[0073] For convenience, ε AB =(Δt AB -Δt BA ) and m AB =(τ AB -τ BA ), and similarly assume equal quantities between other nodes. The parameter ε corresponds to the asymmetry of each quantum channel between nodes, and m corresponds to the difference between the cross-correlations occurring between two nodes in each direction. Combining the above equations and constraints, we obtain:
[0074]
number
[0075] Equation 18 implies that even the most powerful Daemons will be constrained in how they may be able to manipulate the quantum channel. Also, such manipulation will need to be performed across the entire network and maintain consistency to avoid detection. In other words, in a three-node network, it is recognized herein that two additional pieces of information are sufficient to completely determine the system. For example, if any two channels are symmetric (e.g., Δt AB =Δt BA and Δt AC =Δt CA ), there are no longer any modifications that can be implemented by the Daemon that do not destroy at least one of the known relationships defined in the above equations, thus ensuring that time transmission within the network is secure.
[0076] As the number of nodes is increased, the number of closed loops that can be defined in the network increases, further constraining the Daemon's ability to arbitrarily manipulate the measured time differences. This property, combined with available physical information about sections of the network, can be used to establish confidence intervals on measured time differences throughout the network, even when the additional information pertains only to the local section. Examples of suitable additional information include, among others, knowledge that a particular channel / link is symmetric, knowledge that the propagation time cannot be negative, and knowledge that the propagation speed of light cannot be faster than the speed of light. Furthermore, topology and connectivity are incorporated into constraints in networks with four or more nodes, as will be discussed below.
[0077] Rewriting equations 8-13 with unknowns on the left side of the equation and known values (or measurable quantities) on the right side, the following equations hold for a three-node network:
[0078]
number
[0079]
number
[0080]
number
[0081]
number
[0082]
number
[0083]
number
[0084] Defining a quantum channel as symmetric, the symmetric relation between each pair of nodes when its corresponding ε value is zero can be rewritten as follows:
[0085]
number
[0086]
number
[0087]
number
[0088] When ε is non-zero, the channel is defined as asymmetric. These equations can be rewritten in matrix form Mx=r, which takes the following form:
[0089]
number
[0090] M can also be divided into the following four block submatrices:
[0091]
number
[0092] In Equation 29, A=I is the 2n×2n (6×6) identity matrix, and C=B T (i.e., C is the transpose of B), and D=0 is an n×n (3×3) zero matrix. Therefore, M can be re-expressed as:
[0093]
number
[0094] The inverse of M can be calculated using a block-wise inversion with the help of the Schur complement of A.
[0095]
number
[0096] In certain cases, the value B T B=2I, and its reciprocal [ka] Recognizing that, Equation 31 can be further simplified to:
[0097]
number
[0098] To solve for the unknown x in Equation 28, Mx=r is -1 is multiplied by to get:
[0099]
number
[0100] Written another way, it is:
[0101]
number
[0102] Equation 34 can be divided according to submatrix blocks.
[0103]
number
[0104]
number
[0105] Inserting various known values, we get the following:
[0106]
number
[0107]
number
[0108]
number
[0109]
number
[0110]
number
[0111]
number
[0112]
number
[0113] Therefore, in terms of clock time difference:
[0114]
number
[0115]
number
[0116]
number
[0117]
number
[0118] The symmetry relations used above can be substituted in other limits. Referring again to equations 8-13, for a network of three nodes, the unknowns are grouped on the left side of the equation and the known values (or measurable quantities) on the right side.
[0119]
number
[0120]
number
[0121]
number
[0122]
number
[0123]
number
[0124]
number
[0125] Regarding the symmetry relation, equation 14 is substituted into the final closure relation.
[0126]
number
[0127]
number
[0128]
number
[0129] Again, a quantum channel is defined as symmetric when its corresponding ε value is zero. When ε is non-zero, the channel is considered as asymmetric. In this particular example, due to the substitution, Δt CA and Δt AC There are no restrictions on the relationship between m and r, i.e., the channel connecting nodes A and C can be arbitrarily asymmetric. The system of equations can be rewritten in matrix form Mx=r, which takes the following form:
[0130]
number
[0131] It is no longer possible to simplify the inverse of M as in equations 29-32, but [ka] A solution can be guaranteed to exist as long as A and the Schur complement of A in have inverses. Thus, A will always remain identity no matter what loop closure relation is substituted. The Schur complement of A for this system has the form:
[0132]
number
[0133] Equation 58 has an inverse and remains well-conditioned.
[0134] Such loop closure equations can be extended for networks with larger numbers of nodes. As an example, the formulation of the closure relation can be generalized to the following matrix form:
[0135]
number
[0136] As defined above, each δ is defined as the time difference between any two colocated clocks. For three-node networks, ordering is therefore a matter of convention.
[0137]
number
[0138]
number
[0139]
number
[0140] Equations 60-62 can be arranged in matrix form.
[0141]
number
[0142] Due to the underlying loop (or cycle) structure of the matrix Γ, the matrix has rank r = n - 1 = 2. In order for the right-hand side δ to lie in the column space of the matrix Γ, there will be a set of constraints imposed on the δ values. To generate these constraints, the extended matrix [ka] is formed and linear operations can be performed on the rows of this matrix until it is in a shortened row echelon form.
[0143]
number
[0144] First, add row 1 to row 3 and remove the leading -1.
[0145]
number
[0146] Then add row 2 to row 1 and eliminate the -1 in the second column.
[0147]
number
[0148] Therefore, equation 66 becomes: [ka] The shortened line echelon form of [ka] The bottom row with only zeros can be interpreted as follows:
[0149]
number
[0150] The left hand side reduces to zero. Then, for the system to remain consistent and have a corresponding solution, and therefore meet equation 14 above, the following conditions hold:
[0151]
number
[0152] In other words, recognition of these specific requirements and limitations of the present system enables quantum-secure time transfer across all three nodes. Implementation of such requirements can be handled by a controller at each node, such as controllers 220 and 230 shown in FIG. 2.
[0153] This method of quantum-secure time transfer can be further extended to networks with any number of nodes, as will be explained below. While trivial for the three-node case, for larger numbers of nodes the loop closure relation benefits from having a procedural generation method such as that described above. For any network, a matrix Γ may be generated for each quantum channel defined between any two network nodes. The extended matrix [ka] can be formed and rewritten in shortened row echelon form (rref): Any row containing all zeros in the left column of the expanded matrix will provide a constraint on the value of δ.
[0154] For a network without a closed loop, such as the three-node network 400 illustrated in FIG. 4, where nodes A and C do not share a quantum channel between them, the matrix for the equation expressing the connected system Γt=δ with t and δ as defined above is relatively simple.
[0155]
number
[0156] Using Equation 69, [ka] When this occurs, it leads to the following:
[0157]
number
[0158] In equation 70 [ka] Note that there are no rows containing only zeros in δ. That is, there are no free variables in the system. As a result, other external constraints, such as symmetry in both directions of propagation time in the quantum channel, should be imposed to ensure the security of the network. In other words, from a graph-theoretic perspective, the process of finding constraints can be summarized as finding a cycle basis for the underlying network graph. Constraints on the values of δ arise from drawing linearly independent sets of simple cycles that form a basis in the cycle space of the graph. For the network shown in FIG. 3, the cycle basis spans a vector containing all nodes in the triangular network, and constraints can be generated by summing the values of δ between nodes in a cycle, e.g., A → B → C → A. In the case of the three-node network shown in FIG. 4, there are no cycles in the underlying graph, and therefore no corresponding cycle exists, and no corresponding constraints on the values of δ cannot be imposed. Alternative methods, such as finding cycle bases in polynomial time, can be used to form the basic δ constraint equations for such networks.
[0159] A similar analysis can be performed when extending the implementation of quantum-secure time transfer to a four-node network, such as the four-node network 500 shown in Figure 5. For the network topology shown in Figure 5, assuming, as mentioned above, that there is no explicit guarantee that the links are symmetric in their propagation times, the relationship between the various propagation times can be written as follows:
[0160]
number
[0161]
number
[0162]
number
[0163]
number
[0164]
number
[0165]
number
[0166]
number
[0167]
number
[0168] The symmetric relationship between each pair of nodes can be written as follows:
[0169]
number
[0170]
number
[0171]
number
[0172]
number
[0173] Again, a quantum channel is defined as symmetric when its corresponding ε value is zero. When ε is non-zero, the channel is asymmetric. As usual, the relevant system of equations takes the form
[0174]
number
[0175] A=I is a 2n×2n (i.e., 8×8) identity matrix, where n=number of nodes, and C=B T , i.e., C n×2n (i.e., 4×8) matrix is the transpose of B 2n×n (i.e., 8×4) matrix, and D=0 is an n×n (i.e., 4×4) zero matrix. The vector of unknowns and right-hand side can then be expressed as follows:
[0176]
number
[0177] The solution takes the same form as equations 35 and 36 above.
[0178] In the topology of the four-node network 500, there can be only one loop around the ring, defined as the path that traverses A → B → C → D → A. Again, the value of δ can be expressed as:
[0179]
number
[0180]
number
[0181]
number
[0182]
number
[0183] Equations 85-88 are added to obtain one loop closure relation.
[0184]
number
[0185] Note that this closure relation involves all nodes of the network. Alternatively, the connected system Γt=δ can be considered such that:
[0186]
number
[0187] Augmented matrix [ka] can be written as follows:
[0188]
number
[0189] Reduced row echelon form matrix [ka] then becomes:
[0190]
number
[0191] Note that equation 92 imposes the same constraints on the δ values as equation 89. One of the symmetry relations can then be substituted into this closure relation instead, and the C and D submatrices in equation 83 can be modified accordingly.
[0192]
number
[0193] The above considerations and requirements can be implemented in each of nodes A, B, C, and D to enable quantum-secure time transfer across all four nodes shown in FIG. 5.
[0194] The analysis can be further extended to add additional quantum channels in a four-node network. In the four-node network 600 shown in Figure 6, a quantum channel is added connecting nodes A and C. As mentioned above, there is no guarantee that the links are symmetric in their propagation times. The relationship between the various propagation times can be described as follows:
[0195]
number
[0196]
number
[0197]
number
[0198]
number
[0199]
number
[0200]
number
[0201]
number
[0202]
number
[0203]
number
[0204]
number
[0205] The symmetric relationship between each pair of nodes can be written as follows:
[0206]
number
[0207]
number
[0208]
number
[0209]
number
[0210]
number
[0211] Again, a quantum channel is defined as symmetric when its corresponding ε value is zero. When ε is non-zero, the channel is asymmetric. As usual, the relevant system of equations takes the form
[0212]
number
[0213] In this case, A=I is a (2n+2)×(2n+2) (i.e., 10×10) identity matrix, and C=B T , i.e., the C (n+1)×2(n+1) (i.e., 5×10) matrix is the transpose of the B (2n+2)×(n+1) (i.e., 10×5) matrix, and D=0 is the (n+1)×(n+1) (i.e., 5×5) zero matrix. The vector of unknowns and the right-hand side can then be expressed as follows:
[0214]
number
[0215] Even with an additional quantum channel between node A and node C, the structure of the matrix M is preserved, since the new quantum channel is independent of other already established channels. Constructing the connection system Γt=δ yields:
[0216]
number
[0217] Augmented matrix [ka] can be written as follows:
[0218]
number
[0219] Reduced row echelon form matrix [ka] then becomes:
[0220]
number
[0221] The new quantum channel between node A and node B creates an additional loop closure relation, as can be seen in the bottom two lines of equation 113.
[0222]
number
[0223]
number
[0224] The other submatrices C and D can then be written as:
[0225]
number
[0226] The Schuler complement of matrix M has an inverse and remains well-conditioned.
[0227]
number
[0228] Thus, adding another connection to the four-node network of FIG. 4 resulted in another loop closure relation available for use in defining system symmetry and conditions. Essentially, if a cycle (or multiple cycles) is added to a given network, another closure equation can be generated if the new cycle is not within the linear hull of the current cycle basis. For a network with n nodes, n-1 = 3 channel symmetry constraints are still imposed on the network. It should be recognized that this condition results in a reduction from the total of five quantum channels present in the topology illustrated in FIG. 6.
[0229] The quantum-secure time transfer method can be further extended to the maximally connected network shown in Figure 7. As discussed above, the addition of another quantum channel results in the emergence of another loop closure relation, and this quantum channel does not need to be symmetrically constrained.
[0230] 7, a four-node network 700 includes quantum channels between four nodes in all possible pairwise combinations. As mentioned above, the relationship between the various propagation times can be expressed as follows:
[0231]
number
[0232]
number
[0233]
number
[0234]
number
[0235]
number
[0236]
number
[0237]
number
[0238]
number
[0239]
number
[0240]
number
[0241]
number
[0242]
number
[0243] The symmetric relationship between each pair of nodes can be written as follows:
[0244]
number
[0245]
number
[0246]
number
[0247]
number
[0248]
number
[0249]
number
[0250] Again, a quantum channel is defined as symmetric when its corresponding ε value is zero. When ε is non-zero, the channel is asymmetric. As usual, the relevant system of equations takes the form
[0251]
number
[0252] In this case, A=I is the identity matrix of n(n-1)×n(n-1) (i.e., 12×12), and C=B T , i.e., C n(n-1) / 2×n(n-1) / 2 (i.e., 6×12) matrix is the transpose of B n(n-1)×n(n-1) / 2 (i.e., 12×6) matrix, and D=0 is an n(n-1) / 2×n(n-1) / 2 (i.e., 6×6) zero matrix. The vector of unknowns and right-hand side can then be expressed as follows:
[0253]
number
[0254] The δ equation in this case is as follows:
[0255]
number
[0256]
number
[0257]
number
[0258]
number
[0259]
number
[0260]
number
[0261] When described by a connection system Γt = δ matrix, it takes the following form:
[0262]
number
[0263] After the operation, the reduced row echelon form matrix [ka] then becomes:
[0264]
number
[0265] Next, [ka] We can use the three loop closure relations formed in the bottom three lines of the expanded shortened line echelon form of
[0266]
number
[0267]
number
[0268]
number
[0269] An alternative method for finding linearly independent sets of loop closure relations is to use graph theory. For example, using the NetworkX Python library, cycles in this graph can be calculated. Using this method, a basis set can be defined.
[0270] Loop 1 closure relationship (A → B → C → A)
[0271]
number
[0272] Loop 2 closure relationship (C → D → A → C)
[0273]
number
[0274] Loop 3 closure relationship (B→C→D→B)
[0275]
number
[0276] The C and D submatrices can then be written as:
[0277]
number
[0278] The Schur complement of A has an inverse and remains well-conditioned.
[0279]
number
[0280] It is recognized herein that n-1=3 symmetry closure relations need to be provided regardless of the number of quantum channels added in the network. These relations can be provided, for example, in the form of symmetry constraints for light propagating back and forth within a particular quantum channel. With such relations defined, it is possible to have networks with nodes that have more than two quantum channel connections (not counting the channels themselves) and do not need to stipulate that the channels are symmetric.
[0281] As another example, consider the requirements for enabling quantum-secure time transfer within a five-node network. One embodiment of a time transfer network 800 is shown in Figure 8. As mentioned above, the relationship between the various propagation times can be expressed as follows:
[0282]
number
[0283]
number
[0284]
number
[0285]
number
[0286]
number
[0287]
number
[0288]
number
[0289]
number
[0290]
number
[0291]
number
[0292]
number
[0293]
number
[0294] The symmetric relationship between each pair of nodes can be written as follows:
[0295]
number
[0296]
number
[0297]
number
[0298]
number
[0299]
number
[0300]
number
[0301] As mentioned above, a quantum channel is defined as symmetric when its corresponding ε value is zero. When ε is non-zero, the channel is asymmetric. As usual, the relevant system of equations takes the form:
[0302]
number
[0303] In this case, A=I is a 12x12 identity matrix, and C=B T is the 6x12 matrix transpose of B (a 12x6 matrix), and D=0 is the (n+1)x(n+1) (i.e., 6x6) zero matrix. The vector of unknowns and right-hand side can then be expressed as:
[0304]
number
[0305] The δ equation in this case is as follows:
[0306]
number
[0307]
number
[0308]
number
[0309]
number
[0310]
number
[0311]
number
[0312] When described by a connection system Γt = δ matrix, it takes the following form:
[0313]
number
[0314] Also, the usual loop closure relation is [ka] can be found by deriving the extended shortened row echelon form of . Thus, the present method of computing the required constraints and implementing them is scalable for use in multi-mode network systems for quantum-secure time transfer throughout the network.
[0315] Note that in the above analysis, an assumption was made that the local clocks at the nodes in a given network all run at the same frequency and that the nodes are static with respect to one another, so that transmission times between nodes do not change over time. While the assumption of synchronized clocks (i.e., clocks that all run at the same frequency) is likely not justified in an absolute sense, clocks are generally well characterized, and strict bounds on the relative drift of their frequencies can be obtained. For example, the effect of clock drift is to make the peak of the cross-correlation function less pronounced, so that if the relative drift is too rapid, the peak may be difficult to detect from the background. However, if the peak is localizable, even with some frequency drift, pairs of entangled photons can still be identified, and the interval between successful detections can be measured so that the precise trend of clock drift can be monitored. Thus, clock synchronization can be maintained while achieving time transfer between nodes in a secure manner.
[0316] Furthermore, while the networks illustrated in Figures 3-8 were assumed to be static, the methods discussed above can be extended to quantum-secure time transfer in non-static networks as well. For example, relative motion of nodes can have an effect similar to drifting clocks, in that correlation measurements become "smeared" from propagation time variations to the extent that maximum cross-correlation values can be difficult to refine. However, like clock drift, relative motion can be measured by comparing the time intervals between successive events in connected nodes, so that the relative motion can also be taken into account by controllers at the nodes.
[0317] In principle, distinguishing between the effects of relative motion and drifting clocks can be difficult, but the nature of the quantum clock synchronization networks discussed herein can allow the effects of the two variables to be distinguished from each other. For example, in a two-node network, if the network is static, the round-trip time for a photon to travel between two nodes can be obtained simply by adding the time it takes for the photon to travel from node A to node B and the time it takes for the photon to travel from node B to node A. The network also allows direct measurement of round-trip time by reflecting several photons originating from node A to node B. Thus, node A can directly measure the round-trip time of a photon according to a local clock at A. The concatenation of several such measurements can provide information about the speed at which node A is moving relative to node B, and the effect can be subtracted from other measurements to obtain the relative clock drift due to both motion and drift.
[0318] The foregoing is illustrative of the present invention and should not be construed as limiting thereof. Although several exemplary embodiments of the present invention have been described, those skilled in the art will readily appreciate that many modifications are possible in the exemplary embodiments without substantially departing from the novel teachings and advantages of the present invention.
[0319] Thus, many different embodiments arise from the above description and drawings. It is understood that literally describing and illustrating every combination and subcombination of these embodiments would be unduly repetitive and ambiguous. Therefore, the specification, including the drawings, shall be construed as constituting a complete written description of all combinations and subcombinations of the embodiments described herein, and the modes and processes for making and using them, and shall support claims to any such combination or subcombination.
[0320] Although disclosed embodiments of the invention are present herein and specific terms are employed, they are used in a generic and descriptive sense only, and not for purposes of limitation. While several exemplary embodiments of the invention have been described, those skilled in the art will readily appreciate that many modifications are possible in the exemplary embodiments without substantially departing from the novel teachings and advantages of the invention. Accordingly, all such modifications are intended to be included within the scope of the invention as defined in the claims. Accordingly, it is to be understood that the foregoing is illustrative of the invention and should not be construed as limited to the specific embodiments disclosed, and that modifications to the disclosed embodiments and other embodiments are intended to be included within the scope of the appended claims. The invention is defined by the following claims, with equivalents of the claims being included therein.
Claims
1. 1. A multi-node quantum communications network for providing quantum secure time transfer with Damon attack detection, the network comprising: a first node, a first local clock; a first photon pair source for providing a first entangled photon pair, the first entangled photon pair including a first photon and a second photon; a first local time t in the first local clock 1 a first capture device for capturing the first photons in a first coupling mechanism for directing the second photons away from the first node; a first measurement device for receiving photons from outside the first node; a first controller for controlling at least the first local clock, the first photon pair source, the first capture device, the first coupling mechanism, and the first measurement device; a first node including: a second node, a second local clock; a second photon pair source for providing a second entangled photon pair, the second entangled photon pair including a third photon and a fourth photon; a second local time t at the second local clock 2 a second capture device for capturing the third photons at a second coupling mechanism for directing the fourth photons away from the second node; a second measurement device for receiving photons from outside the second node; a second controller for controlling at least the second local clock, the second photon pair source, the second capture device, the second coupling mechanism, and the second measurement device; a second node including: a third node, a third local clock; a third photon pair source for providing a third entangled photon pair, the third entangled photon pair including a fifth photon and a sixth photon; a third local time t at the third local clock 3 a third capture device for capturing the fifth photon at a third coupling mechanism for directing the sixth photons away from the third node; and a third measurement device for receiving photons from outside the third node; a third controller for controlling at least the third local clock, the third photon pair source, the third capture device, the third coupling mechanism, and the third measurement device; a third node, a first authenticated communication channel communicatively connecting the first and second nodes; a second authenticated communication channel communicatively connecting the second and third nodes; a third authenticated communication channel communicatively connecting the third and first nodes; Equipped with the first, second, and third nodes and the first, second, and third authenticated communication channels form a closed loop; The first, second, and third controllers determining a difference between the first, second, and third local times; For the second photon to travel from the first node to the second node, For the second photon to travel from the first node to the third node, For the fourth photon to travel from the second node to the first node, For the fourth photon to travel from the second node to the third node, for the sixth photon to travel from the third node to the first node; and For the sixth photon to travel from the third node to the second node, measuring the required duration; using the difference between the first, second, and third local times and the duration so measured to detect a Damon attack, if present; A network configured to:
2. 2. The network of claim 1, wherein the first, second, and third controllers are further configured to detect the Damon attack when a closed-loop condition is not satisfied, and the closed-loop condition is not satisfied when a difference between the first, second, and third local times and a sum of the durations are non-zero.
3. The network of claim 1 , wherein the first, second, and third photon pair sources are configured to generate polarization-entangled photon pairs.
4. 2. The network of claim 1, wherein the difference between the first, second, and third local times and the duration so measured are used to synchronize the first, second, and third local clocks.
5. 1. A method for determining the presence of a Damon attack in a multi-node quantum communications network for providing quantum-secure time transfer, the method comprising: identifying a closed loop formed by at least three nodes in the network; determining a difference between the local clocks of the at least three nodes; imposing a closed-loop condition on said difference so determined; detecting the presence of the Damon attack if the closed-loop condition is not satisfied by the difference so determined; Including, The method of claim 1, wherein the closed-loop condition is not satisfied if the sum of the differences between the local clocks of the at least three nodes and the duration of travel of a photon between the at least three nodes is non-zero.
6. Imposing the closed-loop condition includes, at each one of the at least three nodes: generating an entangled photon pair, the entangled photon pair including a first photon and a second photon entangled with the first photon; capturing the first photon at a local time for one of the at least three nodes; measuring a travel time for the second photon to travel from one of the at least three nodes to another of the at least three nodes; calculating a difference in local time from one of the at least three nodes to another of the at least three nodes; determining whether the local clock at each one of the at least three nodes is synchronized with another of the at least three nodes; The method of claim 5 , comprising:
Citation Information
Patent Citations
Method of synchronization in quantum network
KR1020180128646A
Quantum communication apparatus, quantum communication system and quantum communication method
US20100226659A1
Quantum-authenticated clock signal
US20170317814A1
Quantum Secure Clock Synchronization Based On Time-Energy And Polarization Entangled Photon Pairs
US20200084033A1