Quantum key distribution protocol

The described method enhances QKD systems by securely generating quantum-resistant encryption keys through cooperative key agreements and XOR operations, addressing 'one point failure' and inefficiency issues.

WO2025153803A1PCT designated stage expired Publication Date: 2025-07-24ARQIT LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/GB2025/050052
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-16
Filing Date
2025-01-14
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Existing quantum key distribution (QKD) systems are vulnerable to 'one point failure' security breaches and inefficient in generating shared symmetric cryptographic keys, particularly in the face of potential quantum computer attacks.

Method used

A method involving a first and second device cooperating with a third device to agree shared encryption keys, using random number generators to generate additional keys, and combining these keys using XOR operations over secured communication channels to create a quantum computing-resistant final key.

Benefits of technology

The method provides secure, efficient generation of symmetric encryption keys resistant to quantum computer attacks, eliminating single-point vulnerabilities and reducing the need for extensive precursor material communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure GB2025050052_24072025_PF_FP_ABST
    Figure GB2025050052_24072025_PF_FP_ABST
Patent Text Reader

Abstract

A method of key distribution between first and second devices comprising the first device cooperating with a third device to agree a first key and the second device cooperating with the third device to agree a second key. The third device uses the second key to encrypt the first key, and sends the encrypted first key to the second device. The second device uses the second key to decrypt and recover the first key. The first device uses random numbers from an RNG to generate a third key. The second device uses random numbers from an RNG to generate a fourth key. The first device sends the third key to the second device and the second device sends the fourth key to the first device. The first device and the second device each combine the first key, the third key, and the fourth key to generate a fifth key.
Need to check novelty before this filing date? Find Prior Art

Description

QUANTUM KEY DISTRIBUTION PROTOCOL

[0001] The present application relates to a method and system for quantum key distribution using a quantum key distribution protocol.

[0002] Cryptography is used to protect billions of transactions every day from, without limitation, for example Transport Layer Security (TLS) security for online shopping and banking to ultra-secure government communications. These transactions rely on reliable and secure means for at least two or more transacting parties to share a secret key, enabling encryption of data by one party and subsequent decryption by the other party(ies). When commercially usable universal quantum computers become available, a variety of these types of transactions, tasks and applications including, without limitation, for example digital banking, web certification, Know Your own Client (KYC), digital asset transfer, and authentication will be vulnerable. These transactions, tasks and applications are currently provided using software systems that typically use conventional cryptography and / or encryption techniques and protocols that are not sufficiently resilient enough to withstand an attack from such quantum computers (QCs).

[0003] QCs can potentially crack many classical cryptography codes almost effortlessly. There has also been a ground swell in interest in quantum computing within the last year as a result of the success of D-Wave in selling commercial systems. Furthermore, a number of breakthroughs by technology companies such as, without limitation, for example Microsoft (RTM), Intel (RTM), Google (RTM) and others in QC techniques promise to make a universal QC viable in the near future (e.g. five to ten years time). QCs have already become a threat to current cryptography and / or encryption techniques.

[0004] The field of “Quantum Cryptography” aims to address these risks by developing Quantum Key Distribution (QKD) methods. QKD is a method that allows two distant parties to share symmetric cryptographic keys in an information theoretic secure manner that is guaranteed by the laws of physics. Various methods and protocols have been developed for QKD over optical fibres and through free space. The symmetric cryptographic keys may be used to encrypt data in transit or at rest in an information theoretic secure manner.

[0005] There is a desire for a robust, secure and cost effective approach and system for carrying out QKD. However, some proposed approaches suffer from the security problem that a malicious third party compromising a subset of the system, such as a single part of the system, can then use this information to compromise other parts of the system and so"unravel" the security of the system and eventually compromise the shared symmetric cryptographic keys themselves. This problem is commonly referred to as the "one point failure" problem. Further, many proposed approaches to QKD are relatively inefficient, requiring the generation and communication of large amounts of precursor material in order to generate the shared symmetric cryptographic keys.

[0006] The embodiments described below are not limited to implementations which solve any or all of the disadvantages of the known approaches described above.Summary

[0007] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to determine the scope of the claimed subject matter; variants and alternative features which facilitate the working of the invention and / or serve to achieve a substantially similar technical effect should be considered as falling into the scope of the invention disclosed herein.

[0008] In a first aspect of the present invention, there is provided a computer-implemented method of key distribution between a first device and a second device, the method comprising: the first device cooperating with a third device to mutually agree a first shared encryption key; the second device cooperating with the third device to mutually agree a second shared encryption key; the third device using the second shared encryption key to encrypt the first shared encryption key, and sending the encrypted first shared encryption key to the second device; the second device using the second shared encryption key to decrypt the encrypted first shared encryption key to recover the first shared encryption key; the first device using random numbers from a first random number generator (RNG) to generate a third encryption key; the second device using random numbers from a second random number generator (RNG) to generate a fourth encryption key; the first device sending the third encryption key to the second device using a first communication channel secured by an encryption key shared by the first device and the second device; the second device sending the fourth encryption key to the first device using a second communication channel secured by an encryption key shared by the first device and the second device; and each of the first device and the second device combining the first shared encryption key, the third encryption key, and the fourth encryption key to generate a fifth encryption key.

[0009] By implementing the methods described herein, the user of said methods are able to provide symmetric encryption keys in a quantum computing secure manner to the first device (or node) and the second device (or node).

[0010] In some embodiments, the method may further comprise using the fifth encryption key for communication and / or authentication between the first device and the second device .

[0011] In some embodiments, the encryption keys are symmetric encryption keys.

[0012] In some embodiments, the combining the first shared encryption key, the third encryption key, and the fourth encryption key to generate the fifth encryption key is carried out using XOR operations.

[0013] In some embodiments, the first communication channel and the second communication channel are secured by the same encryption key.

[0014] In some embodiments, the first communication channel and the second communication channel are AES channels, and preferably AES-256 channels.

[0015] In some embodiments, the first device cooperating with the third device to mutually agree the first shared encryption key comprises: the third device transmitting a first set of random symbols over a quantum communication channel to the second device, and transmitting a basis set used by the third device for transmitting the first set of random symbols to the second device over a classical communication channel; and the first device and the third device communicating over the classical communication channel and another classical communication channel to generate the first shared encryption key based on the transmitted first set of random symbols,

[0016] In some embodiments, the first device and the third device mutually agree the first shared encryption key using a BB-84 QKD protocol.

[0017] In some embodiments, the second device cooperating with the third device to mutually agree the second shared encryption key comprises: the third device transmitting a second set of random symbols over a quantum communication channel to the second device, and transmitting a basis set used by the third device for transmitting the second set of random symbols to the second device over a classical communication channel; and the second device and the third device communicating over the classical communication channel and another classical communication channel to generate the second shared encryption key based on the transmitted second set of random symbols.

[0018] In some embodiments, the second device and the third device mutually agree the second shared encryption key using a BB-84 QKD protocol.

[0019] In some embodiments, the third device using the second shared encryption key to encrypt the first shared encryption key comprises XOR operations; and the second device using the second shared encryption key to decrypt the encrypted first shared encryption key to recover the first shared encryption key comprises XOR operations.

[0020] In some embodiments, the third device is located on a satellite.

[0021] In a second aspect of the present invention, there is provided a system comprising a first device, a second device and a third device, wherein: the first device is arranged to cooperate with the third device to mutually agree a first shared encryption key; the second device is arranged to cooperate with the third device to mutually agree a second shared encryption key; the third device is arranged to use the second shared encryption key to encrypt the first shared encryption key, and to send the encrypted first shared encryption key to the second device; the second device is arranged to use the second shared encryption key to decrypt the encrypted first shared encryption key to recover the first shared encryption key; the first device is arranged to use random numbers from a first random number generator (RNG) to generate a third encryption key; the second device is arranged to use random numbers from a second random number generator (RNG) to generate a fourth encryption key; the first device is arranged to send the third encryption key to the second device using a first communication channel secured by an encryption key shared by the first device and the second device; the second device is arranged to send the fourth encryption key to the first device using a second communication channel secured by an encryption key shared by the first device and the second device; and each of the first device and the second device are arranged to combine the first shared encryption key, the third encryption key, and the fourth encryption key to generate a fifth encryption key.

[0022] In some embodiments, the first device and the second device are arranged to use the fifth encryption key for communication and / or authentication between the first device and the second device.

[0023] In some embodiments, the encryption keys are symmetric encryption keys.

[0024] In some embodiments, the combining the first shared encryption key, the third encryption key, and the fourth encryption key to generate the fifth encryption key is carried out using XOR operations.

[0025] In some embodiments, the first communication channel and the second communication channel are secured by the same encryption key.

[0026] In some embodiments, the first communication channel and the second communication channel are AES channels, and preferably AES-256 channels.

[0027] In some embodiments, the first device is arranged to cooperate with the third device to mutually agree the first shared encryption key by: the third device being arranged to transmit a first set of random symbols over a quantum communication channel to the second device, and to transmit a basis set used by the third device for transmitting the first set of random symbols to the second device over a classical communication channel; and the first device and the third device are arranged to communicate over the classical communication channel and another classical communication channel to generate the first shared encryption key based on the transmitted first set of random symbols.

[0028] In some embodiments, the first device and the third device are arranged to mutually agree the first shared encryption key using a BB-84 QKD protocol.

[0029] In some embodiments, the second device is arranged to cooperate with the third device to mutually agree the second shared encryption key by: the third device being arranged to transmit a second set of random symbols over a quantum communication channel to the second device, and to transmit a basis set used by the third device for transmitting the second set of random symbols to the second device over a classical communication channel; and the second device and the third device being arranged to communicate over the classical communication channel and another classical communication channel to generate the second shared encryption key based on the transmitted second set of random symbols.

[0030] In some embodiments, the second device and the third device are arranged to mutually agree the second shared encryption key using a BB-84 QKD protocol.

[0031] In some embodiments, the third device is arranged to use the second shared encryption key to encrypt the first shared encryption key by XOR operations; and the second device is arranged to use the second shared encryption key to decrypt the encrypted first shared encryption key to recover the first shared encryption key by XOR operations.

[0032] In some embodiments, the third device is located on a satellite.

[0033] In a third aspect of the present invention, there is provided a computer-readable medium comprising code or computer instructions stored thereon, which when executed by a processor unit, causes the processor unit to perform the computer-implemented method according to the first aspect.

[0034] The methods described herein may be performed by software in machine readable form on a tangible storage medium e.g. in the form of a computer program comprising computer program code means adapted to perform all the steps of any of the methods described herein when the program is run on a computer and where the computer program may be embodied on a computer readable medium. Examples of tangible (or non-transitory) storage media include disks, thumb drives, memory cards etc. and do not include propagated signals. The software can be suitable for execution on a parallel processor or a serial processor such that the method steps may be carried out in any suitable order, or simultaneously.

[0035] This application acknowledges that firmware and software can be valuable, separately tradable commodities. It is intended to encompass software, which runs on or controls “dumb” or standard hardware, to carry out the desired functions. It is also intended to encompass software which “describes” or defines the configuration of hardware, such as HDL (hardware description language) software, as is used for designing silicon chips, or for configuring universal programmable chips, to carry out desired functions.

[0036] The preferred features may be combined as appropriate, as would be apparent to a skilled person, and may be combined with any of the aspects of the invention.Brief Description of the Drawings

[0037] Embodiments of the invention will be described, by way of example, with reference to the following drawings, in which:

[0038] Figure 1 is a schematic diagram illustrating an example of a quantum key distribution system useable in an embodiment of the present invention; and

[0039] Figure 2 is a diagram illustrating a method of quantum key distribution useable by the system of figure 1 .

[0040] Common reference numerals are used throughout the figures to indicate similar features.Detailed Description

[0041] Embodiments of the present invention are described below by way of example only. These examples represent the best mode of putting the invention into practice that are currently known to the Applicant although they are not the only ways in which this could be achieved. The description sets forth the functions of the example and the sequence of steps for constructing and operating the example. However, the same or equivalent functions and sequences may be accomplished by different examples.

[0042] In overview, the present application relates to methods and systems for Quantum Key Distribution (QKD) to provide shared symmetric encryption keys to endpoint devices.

[0043] Figure 1 is a schematic diagram illustrating a quantum key distribution (QKD) system 100 according to an embodiment. Figure 2 is a schematic diagram illustrating a QKD method 200 useable by the QKD system 100 according to the embodiment.

[0044] Quantum Key Distribution (QKD) is a process for generating symmetric Highly- Entropic material in an information theoretic secure manner between two nodes. QKD allows two parties, or nodes, to generating symmetric Highly-Entropic material in an information theoretic secure manner that is guaranteed by the laws of physics. Various methods and protocols have been developed for QKD over fibre and through free space, and using other sources of entropy, such as Quantum Random Number Generators (QRNGs).

[0045] The QKD system 100 is intended to provide symmetric encryption keys in a quantum computing secure manner to a first node or device 102 and a second node or device 104. The first and second devices 102 and 104 may, for example, be endpoint devices, with the first device 102 being a first endpoint device Alice and the second device 104 being a second endpoint device Bob. The QKD system 100 further comprises a third device 106 arranged to cooperate with the first and second devices 102 and 104 to provide symmetric encryption keys to the first device 102 and the second device 104 in a quantum computing secure manner.

[0046] In some examples the QKD system 100 may be a satellite QKD (SQKD) system with the third device 106 located on a satellite. In other examples the QKD system 100 may be a terrestrial QKD system with all of the devices 102 to 106 located on the surface.

[0047] As shown in figure 1 , the third device 106 has a number of communication channels with the first device 102. The communication channels comprise a unidirectional quantum communication channel 108 from the third device 106 to the first device 102, and abidirectional classical communication channel 108 between the third device 106 and the first device 102, the bidirectional classical communication channel 108 comprising a first classical communication channel 110a from the third device 106 to the first device 102 and a second classical communication channel 110b from the first device 102 to the third device 106.

[0048] A quantum communication channel which allows quantum information (e.g. quantum states) to be transmitted. The quantum channel may be, without limitation, for example, an optical fibre or optical free space. A classical communication channel is a non-quantum channel, without limitation, for example a fibre optic channel, telecommunications channel, radio channel, broadcast radio or the internet and / or any other wireless or wired communications channel and the like.

[0049] Similarly, as shown in figure 1 , the third device 106 has a number of communication channels with the second device 104. The communication channels comprise a unidirectional quantum communication channel 1 12 from the third device 106 to the second device 104, and a bidirectional classical communication channel 114 between the third device 106 and the second device 104, the bidirectional classical communication channel 114 comprising a first classical communication channel 114a from the third device 106 to the second device 104 and a second classical communication channel 114b from the second device 104 to the third device 106.

[0050] As shown in figure 1 , the first and second devices 102 and 104 are also linked by communication channels. There is a bidirectional classical communication channel 116 between the first device 102 and the second device 104, the bidirectional classical communication channel 116 comprising a first classical communication channel 116a from the first device 102 to the second device 104 and a second classical communication channel 116b from the second device 104 to the first device 102. The bidirectional classical communication channel 116 between the first device 102 and the second device 104 is securable by encryption using symmetric encryption keys, for example by each of the first classical communication channel 116a and the second classical communication channel 116b being Advanced Encryption Standard (AES) channels, such as AES-256 channels. However, the use of AES-256 is not essential, and other security and encryption methods may be used to secure the first and second classical communication channels 1 16a and 116b.

[0051] It will be understood that each of the first to third devices 102 to 106 comprises the necessary components to support the different communications channels between them and to carry our the necessary processing and data storage to carry out the described methods, including any quantum key exchange / distribution protocols used. For example, opticaltransmitters and receivers, and suitable computing means comprising processing processors and data stores. Further, each of the first and second devices 102 and 104 comprises, or has access to, a secure data store, such as a Hardware Security Module (HSM) for secure storage of encryption keys. Further, as will be explained in more detail below, each of the first and second devices 102 and 104 comprises a respective random number generator (RNG).

[0052] The method 200 of the illustrated embodiment assumes that the first and second devices 102 and 104 have a shared symmetric encryption key mutually available to them at the start of the method 200. As will be described in more detail below, this shared symmetric encryption key is used to secure the first and second classical communication channels 116a and 1 16b between the first and second devices 102 and 104.

[0053] In operation, the QKD method 200 begins at a start block 202. The start block 202, and beginning the QKD method 200, may be carried out in response to a requirement for additional symmetric encryption keys at the first and second devices 102 and 104. In systems 100 where communications between the third device 106 and the first and / or second devices 102 and 104 are intermittent, the start block 202, and beginning the QKD method 200, may be carried out in response to communications between the third device 106 and the first and / or second devices 102 and 104 becoming available. For example, in examples where the QKD system 100 is an SQKD system, the availability of communications between the third device 106 and the first and / or second devices 102 and 104 may depend upon the orbital position of a satellite on which the third device 106 is located.

[0054] The QKD method 200 then continues to a first key agreement block 204 and a second key agreement block 206. In the first key agreement block 204 the first device 102 and the third device 106 use the communication channels between them to mutually agree a first shared symmetric encryption key Ki. The first shared symmetric encryption key Ki may be agreed using any suitable quantum key exchange / distribution protocols. The first shared symmetric encryption key Ki may be referred to as a quantum encryption key.

[0055] In an example, in the first key agreement block 206, the agreement of the first symmetric encryption key Ki between the first device 102 and the third device 106 may be based on a quantum key exchange protocol comprising at least the steps of: transmitting, by the third device 102, a first set of random symbols over the quantum communication channel 108 to the first device 102; transmitting, from the third device 106 to the first device 102 over the first classical communication channel 110a, the basis set used by the third device 106 for transmitting the first set of random symbols over the quantum communication channel 108. Further, the agreement may further comprise the first device 102 and the third device 106communicating over the first and second classical communication channels 110a and 110b as necessary in the quantum key exchange / distribution protocol used to generate a shared encryption key based on the transmitted first set of random symbols, by conducting a reconciliation of random symbols transmitted and received by the third and first devices 106 and 102 respectively to form a common set of symbols, error correction and / or privacy amplification or eavesdropper detection and the like of said common set of symbols, and / or agreeing which symbols (or bits) of the common set of symbols may be used as the final shared symmetric encryption key Ki between the first and third devices 102 and 106. In some examples, the first shared symmetric encryption key Ki may be agreed using a modified or hybrid-BB84 based version of the BB84 protocol. However, this is not essential, and other protocols may be used. The random symbols of the first set of random symbols may be bits.

[0056] In the second key agreement block 206 the second device 104 and the third device 106 use the communication channels between them to mutually agree a second shared symmetric encryption key K2. The second shared symmetric encryption key K2 may be agreed using any suitable quantum key exchange / distribution protocols. The second shared symmetric encryption key K2 may be referred to as a quantum encryption key.

[0057] In an example, in the second key agreement block 206, the agreement of the second symmetric encryption key K2 between the second device 104 and the third device 106 may be based on a quantum key exchange protocol comprising at least the steps of: transmitting, by the third device 102, a first set of random symbols over the quantum communication channel 112 to the second device 104; transmitting, from the third device 106 to the second device 104 over the first classical communication channel 114a, the basis set used by the third device 106 for transmitting the first set of random symbols over the quantum communication channel 112. Further, the agreement may further comprise the second device 104 and the third device 106 communicating over the first and second classical communication channels 114a and 114b as necessary in the quantum key exchange / distribution protocol used to generate a shared encryption key based on the transmitted second set of random symbols by conducting a reconciliation of random symbols transmitted and received by the third and second devices 106 and 104 respectively to form a common set of symbols, error correction and / or privacy amplification or eavesdropper detection and the like of said common set of symbols, and / or agreeing which symbols (or bits) of the common set of symbols may be used as the final second shared encryption key K2 between the second and third devices 104 and 106. In some examples, the second shared symmetric encryption key K2 may be agreed using a modified or hybrid-BB84 based version of the BB84 protocol. However, this is not essential, and other protocols may be used. The random symbols of the second set of random symbols may be bits.

[0058] Conveniently, the same quantum key exchange protocol maybe used in the first and second key agreement blocks 204 and 206. This may simplify the third device 106 by only requiring that it supports use of a single quantum key exchange protocol. Alternatively, different quantum key exchange protocols may be used in the first and second key agreement blocks 204 and 206. This may be desirable to improve security by system diversity, or may be required if the first and second devices 102 and 104 are not able to support a common quantum key exchange protocol.

[0059] Examples of quantum key exchange / distribution protocols may include one or more quantum key exchange / distribution protocols from the group of, without limitation, for example: a QKD protocol from the Bennett and Brassard 1984 (BB84) family of QKD protocols; the BB84 QKD protocol; the Bennet 1992 (B92) QKD protocol; the Six-State Protocol (SSP) QKD protocol; the Scarani Acin Ribordy Gisin 2004 (SARG04) QKD protocol; the Doherty Parrilo Spedalieri 2002 (DPS02) QKD protocol; the differential phase shift (DPS) QKD protocol; the Eckert 1991 (E91) QKD protocol; the coherent one-way (COW) QKD protocol; the Khan Murphy Beige 2009 (KMB09) QKD protocol; the Esteban Serna 2009 (S09) QKD protocol; the Serna 2013 (S13) QKD protocol; the A Abushgra K Elleithy 2015 (AK15) QKD protocol; any one or more other entanglement based QKD protocols; any one or more future QKD protocols; and any other suitable QKD protocol for exchanging QKD keys between endpoint devices using quantum transmissions and classical transmissions; combinations thereof; modifications thereto; as herein described, and / or as the application demands.

[0060] It will be understood that following the completion of the first and second key agreement blocks 204 and 206 the first and third devices 102 and 106 mutually share the first shared symmetric encryption key Ki , and the second and third devices 104 and 106 mutually share the second shared symmetric encryption key K2.

[0061] In figure 2 the first and second key agreement blocks 204 and 206 are shown in parallel to indicate that these blocks may be caried out in any order, or at the same, or overlapping, times.

[0062] Following completion of the first and second key agreement blocks 204 and 206, in a encrypt first key block 208 the third device 106 uses the second shared symmetric encryption key K2 to encrypt the first shared symmetric encryption key Ki. In an example, this encryption is carried out using an exclusive OR (XOR) operation, by the third device 106 calculating Ki XOR K2 (i.e., Ki ® K2), where, when the first and second encryption keys Ki and K2 are bit strings and / or bits or are converted into a bit string / bits, then a bitwise XOR may beperformed in which XOR on a pair of bits has its standard meaning of: 0 XOR 0 = 0; 0 XOR 1 = 1 ; 1 XOR 0 = 1 ; and 1 XOR 1 = 0. Although a bitwise XOR operation is described herein, this is by way of example only and the invention is not so limited, the person skilled in the art would understand that any other type of symmetric encryption operation may be performed such as, without limitation, for example XOR-type operations performed on symbols, and / or any suitable type of cryptographic operation.

[0063] In other examples, the encryption of the first shared symmetric encryption key Ki using the second shared symmetric encryption key K2 may be carried out in a secure but reversible manner using cryptographic operations such as, without limitation, for example: exclusive or (XOR) operations on these sets of symbols (e.g. converting the sets of symbols into bit strings and performing bitwise XOR); extended XOR operations on these sets of symbols (e.g. using a mathematically defined extended set of "symbol XOR" operations on symbols that preserve the mathematical properties of bitwise XOR operations); one-time-pad encryption of these sets of symbols; any other classical, post-quantum resistant, or quantum encryption / decryption operation on these sets of symbols such that a device is able to decrypt and retrieve one of the sets of symbols using the other of the sets of symbols used to encrypt both sets of symbols; modifications thereto; and combinations thereof.

[0064] Then, in a transmit first key block 210, the third device 106 sends the encrypted first encryption key (In this example Ki ® K2) to the second device 104 using the first classical communication channel 114a.

[0065] Then, in a decrypt first key block 212, the second device 104 uses the second key K2 to decrypt the received encrypted first key, and so recovers the first shared symmetric encryption key Ki. In examples where the encryption was carried out by the third device 106 using an XOR operation the decryption may be carried out by the second device 104 carrying out a further XOR operation using the second shared symmetric encryption key K2, and calculating (Ki XOR K2) XOR K2 = Ki (i.e. , (Ki ® K2) ® K2 = Ki). In examples where alternative encryption methods were used a corresponding suitable decryption method is used.

[0066] It will be understood that following the completion of the decrypt first key block 212 all of the first to third devices 102 to 106 mutually share the first shared symmetric encryption key Ki. Further, it will be understood that the first and second shared symmetric encryption keys Ki and K2 are no longer required by the third device 106. Accordingly, the third device 106 may delete the first and second shared symmetric encryption keys Ki and K2. Althoughthis is not essential, it may improve security and reduce data storage requirements at the third device.

[0067] In a first random key generation block 214 the first device 102 uses random numbers, such as a random bit string, from a random number generator 102a of the first device 102 to generate a third encryption key KA.

[0068] In a second random key generation block 216 the second device 104 uses random numbers, such as a random bit string, output from a random number generator 104a of the second device 104 to generate a fourth encryption key KB.

[0069] As mentioned above, the first and second devices 102 and 104 have an already shared symmetric encryption key KOLD mutually available to them at the start of the method 200. The already shared symmetric encryption key KOLD may have been provided to the first and second devices 102 and 104 in any convenient manner. For example, the already shared symmetric encryption key KOLD may have been provided when the first and second devices 102 and 104 were first commissioned and the system 100 set up, and / or may have been provided at some time during operation of the system 100.

[0070] Then, after the first random key generation block 214, in a first random key communication block 218 the first device 102 sends the third encryption key KA IO the second device 104 using the first classical communication channel 116a, with the first classical communication channel 116a being cryptographically secured using the shared symmetric encryption key KOLD. In the illustrated example the first classical communication channel 116a is an AES channel, such as an AES-256 channel, secured by the shared symmetric encryption key KOLD, and carrying the third encryption key KA, SO that this communication using the first classical communication channel 116a may be described as (KA, KOLD) .

[0071] Similarly, after the second random key generation block 216, in a second random key communication block 220 the second device 104 sends the fourth encryption key KB to the first device 102 using the second classical communication channel 116b, with the second classical communication channel 116b being cryptographically secured using the shared symmetric encryption key KOLD. In the illustrated example the first classical communication channel 116b is an AES channel, such as an AES-256 channel, secured by the shared symmetric encryption key KOLD, and carrying the fourth encryption key KB, SO that this communication using the second classical communication channel 116b may be described as (KB, KOLD).

[0072] Since the shared symmetric encryption key KOLD is mutually available to both the first device 102 and the second device 104, the first device 102 is able to recover the fourth encryption key KB received from the second device 104 through the second classical communication channel 116b and the second device 104 is able to recover the third encryption key KA received from the first device 102 through the first classical communication channel 116a.

[0073] In figure 2 the first and second random key generation blocks 214 and 216, and the first and second random key communication blocks 218 and 220, are shown in parallel to indicate that these blocks may be caried out in any order, or at the same, or overlapping, times.

[0074] It will be understood that following the completion of the first random key communication block 218 and the second random key communication block 220, each of the first and second devices 102 and 104 will mutually share the first shared symmetric encryption key Ki , the third encryption key KA, and the fourth encryption key KB.

[0075] Then, in a generate final key block 222, each of the first and second devices 102 and 104 uses the first shared symmetric encryption key Ki , the third encryption key KA, and the fourth encryption key KB to generate a fifth, and final, shared encryption key KF. This combination to generate the final shared encryption key KF may be carried out in any suitable manner. In the illustrated embodiment, the first and second devices 102 and 104 each use a series of XOR operations to combine the first shared symmetric encryption key Ki , the third encryption key KA, and the fourth encryption key KB to generate the final shared encryption key KF, SO that (Ki XOR KA) XOR KB = KF (i.e. , (Ki ® KA) ® KB = KF) . It will be understood that due to the nature of XOR operations the order in which the different encryption keys are combined is not important. However, the use of XOR operations is not essential, and other methods may be used to combine the different encryption keys to generate the final shared encryption key KF. The final shared encryption key KF is generated, at least in part, from the first shared symmetric encryption key Ki. Accordingly, the final shared encryption key KF comprises entropy generated by the quantum key exchange / distribution protocols used, and is accordingly resistant to cryptographic attack using quantum computers.

[0076] The first and second devices 102 and 104 may then use the final shared encryption key KF as desired to encrypt and decrypt communications between them, or for other security related purposes such as authentication, as desired.

[0077] In order to obtain the final key KF, an attacker would need to compromise the third device 106, tap the bidirectional classical communication channel 116, and also recover the shared symmetric encryption key KOLD. Alternatively, the attacker would need to compromise the third device 106, compromise the RNG 102a of the first device 102, and also compromise the RNG 104a of the second device 104. Accordingly, the disclosed system is not subject to any possible one point failure, so that the present disclosure provides improved security compared to some known approaches. Further, because the method comprises communicating encryption keys to and between the first and second devices 102 and 104, the method is relatively efficient, and does not requiring the generation and communication of large amounts of precursor material in order to generate the final shared symmetric cryptographic key KF. In contrast, methods which rely on the communication of the precursor material itself may be up to orders of magnitude less efficient, requiring the generation and communication of very large amounts of precursor material, which may render such methods uneconomic, or even impractical.

[0078] The illustrated method 200 of figure 2 describes the generation of a single final shared symmetric cryptographic key KF. The method 200 of figure 2 may be repeated as often as required in order to produce any desired number of final shared symmetric cryptographic keys. During such repetition it is not necessary to complete each instance of the method 200 before starting another, multiple different instances of the method 200 may be executed simultaneously. It will be understood that when the method 200 of figure 2 is repeated to produce a plurality of final shared symmetric cryptographic keys it is not necessary to use a different already shared symmetric encryption key KOLD for each repetition. However, it may be preferred to replace the already shared symmetric encryption key KOLD from time to time, for example periodically, for improved security. At least an initial shared symmetric encryption key KOLD will need to be available to the first and second devices 102 and 104 on commissioning to enable the generation of a first final shared symmetric cryptographic key KF. In some examples the first and second devices 102 and 104 may have a stored stock of multiple initial shared symmetric encryption key KOLD available on commissioning. In some examples the initial shared symmetric encryption key(s) KOLD may be replaced using a portion of the final shared symmetric cryptographic keys KF generated in operation. In alternative examples the initial stored stock of shared symmetric encryption key(s) KOLD may be large enough for the lifetime of the first and second devices 102 and 104. In other alternative examples the first and second devices 102 and 104 may be provided with additional shared symmetric encryption key(s) KOLD by some external means.

[0079] In the illustrated example the designation of the two devices 102 and 104 as "first" and "second" is merely a matter of nomenclature to enable the two devices to beunambiguously identified and to improve clarity. The identification of a device as a first device or a second device is based only upon the functions they perform in the method, and is otherwise arbitrary.

[0080] In some examples the roles of the first device 102 and the second device 104 could be reversed so that in the encrypt first key block 208 the third device 106 uses the first shared symmetric encryption key Ki to encrypt the second shared symmetric encryption key K2 and then sends the encrypted second encryption key to the first device 102 the first classical communication channel 110a. Then, in the decrypt key block 212, the first device 102 can uses the first key Ki to decrypt the received encrypted second key, and so recover the second shared symmetric encryption key K2. All of the first to third devices 102 to 106 will then mutually share the second shared symmetric encryption key K2, and the blocks 214 to 222 can be carried out as set out above, but with the second shared symmetric encryption key K2 taking the place of the first shared symmetric encryption key K1 , so that the second shared symmetric encryption key K2, the third encryption key KA, and the fourth encryption key KB are combined to generate the fifth, and final, shared encryption key KF. It will be understood that this allows the first device 102 to operate as a "second" device, and allows the second device 104 to operate as a "first" device. In some examples it may be preferred to reverse the roles (that is, operating as a first device or a second device) of the first device 102 and the second device 104 from time to time, such as periodically, to improve security by obscuring which parts of the system are performing what functions, or for load balancing.

[0081] The illustrated example of figure 1 may be incorporated into a larger quantum key management system, as required in any specific implementation.

[0082] In the illustrated example the first and second classical communication channels 116a and 116b are cryptographically secured using the shared symmetric encryption key KOLD. This is not essential. In other examples these communication channels may be secured by different shared symmetric encryption keys.

[0083] The RNGs 102a and 104a of the first and second devices may be deterministic RNGs (that is, pseudo-random number generators). This may provide the advantages of reduced cost and complexity. Alternatively, the RNGs 102a and 104a may be quantum random number generators (QRNGs). This may provide the advantage of increased security.

[0084] In the illustrated example the first and second devices 102 and 104 are each communicatively connected to the third device 106 by a respective unidirectional quantum communication channel and bidirectional classical communication channel. This arrangementof communications channels is not essential. This arrangement of communication channels is a minimum required by the described exemplary method of generating the first and second shared symmetric encryption keys Ki and K2. However, different arrangements of communication channels may be used in other examples, as required by the methods used to generate the first and second shared symmetric encryption keys.

[0085] In the illustrated example the system comprises a single third device arranged for communication with both of the first and second devices. In other examples the single third device may be replaced by two third devices, each third device being arranged for communication with one of the first and second devices and the different third devices being arranged for mutual communication. This may be advantageous to increase the spatial separation between the first and second devices which can be accommodated by the system.

[0086] The present disclosure is agnostic of the specific generation and distribution mechanics used in the system 100 used to generate the first and second shared symmetric encryption keys Ki and K2. However, as an illustrative example, the system 100 may operate as a satellite quantum key distribution (SQKD) system. Satellite quantum key distribution (SQKD) is a specific implementation of a QKD system that uses a number of satellites to provide global or near-global coverage. This may be beneficial for enabling key distribution to first and second devices separated over a large geospatial area. In alternative examples the system 100 may operate as a terrestrial QKD system, with the different devices of the system 100 communicatively connected by terrestrial means, for example by optical fibres.

[0087] The generated final shared encryption key may have any desired length or type, as required for the intended use of the keys. In general, the size of the generated final shared encryption key should be determined as appropriate to the intended usage of the key, for example those laid out by NIST Key Management Recommendations. The disclosed method allows for the generation of final shared encryption keys having a wide range of sizes.

[0088] Some examples of the classical communication channels are disclosed above. Additionally, each classical communications channel may be based on one or more types of communication channels from the group of: optical communication channel; free-space optical communication channel; wireless communication channel; wired communication channel; radio communication channel; microwave communication channel; satellite communication channel; terrestrial communication channel; optical fibre communication channel; optical laser communication channel; any other type of one or more optical, wireless and / or wired communication channel(s) for transmitting data between devices; and two ormore optical, wireless and / or wired communication channel(s) that form a composite communication channel for transmitting data between devices.

[0089] Some examples of the quantum communication channels are disclosed above. Additionally, each quantum communications channel may be based on one or more types of quantum communication channels from the group of: optical quantum communications; free- space optical quantum communications; optical fibre quantum communications; optical laser quantum communications; quantum entanglement communications; any other type of quantum communications for transmitting data over a quantum communication channel between devices.

[0090] The embodiments described above are fully automatic. In some examples a user or operator of the system may manually instruct some steps of the method to be carried out.

[0091] In the described embodiments of the invention parts of the system may be implemented as a form of a computing and / or electronic device. Such a device may comprise one or more processors which may be microprocessors, controllers or any other suitable type of processors for processing computer executable instructions to control the operation of the device in order to gather and record routing information. In some examples, for example where a system on a chip architecture is used, the processors may include one or more fixed function blocks (also referred to as accelerators) which implement a part of the method in hardware (rather than software or firmware). Platform software comprising an operating system or any other suitable platform software may be provided at the computing-based device to enable application software to be executed on the device.

[0092] Various functions described herein can be implemented in hardware, software, or any combination thereof. If implemented in software, the functions can be stored on or transmitted over as one or more instructions or code on a computer-readable medium. Computer- readable media may include, for example, computer-readable storage media. Computer- readable storage media may include volatile or non-volatile, removable or non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. A computer-readable storage media can be any available storage media that may be accessed by a computer. By way of example, and not limitation, such computer-readable storage media may comprise RAM, ROM, EEPROM, flash memory or other memory devices, CD-ROM or other optical disc storage, magnetic disc storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Disc and disk, as used herein, includecompact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and blu- ray disc (BD). Further, a propagated signal is not included within the scope of computer- readable storage media. Computer-readable media also includes communication media including any medium that facilitates transfer of a computer program from one place to another. A connection, for instance, can be a communication medium. For example, if the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of communication medium. Combinations of the above should also be included within the scope of computer-readable media.

[0093] Alternatively, or in addition, the functionality described herein can be performed, at least in part, by one or more hardware logic components. For example, and without limitation, hardware logic components that can be used may include Field-programmable Gate Arrays (FPGAs), Program-specific Integrated Circuits (ASICs), Program-specific Standard Products (ASSPs), System-on-a-chip systems (SOCs), Complex Programmable Logic Devices (CPLDs), etc.

[0094] Although illustrated as a single system, it is to be understood that a computing device may be a distributed system. Thus, for instance, several devices may be in communication by way of a network connection and may collectively perform tasks described as being performed by the computing device. Although illustrated as a local device it will be appreciated that the computing device may be located remotely and accessed via a network or other communication link (for example using a communication interface).

[0095] The term 'computer' is used herein to refer to any device with processing capability such that it can execute instructions. Those skilled in the art will realise that such processing capabilities are incorporated into many different devices and therefore the term 'computer' includes PCs, servers, mobile telephones, personal digital assistants and many other devices.

[0096] Those skilled in the art will realise that storage devices utilised to store program instructions can be distributed across a network. For example, a remote computer may store an example of the process described as software. A local or terminal computer may access the remote computer and download a part or all of the software to run the program.Alternatively, the local computer may download pieces of the software as needed, or execute some software instructions at the local terminal and some at the remote computer (or computer network). Those skilled in the art will also realise that by utilising conventional techniques known to those skilled in the art that all, or a portion of the software instructionsmay be carried out by a dedicated circuit, such as a DSP, programmable logic array, or the like.

[0097] It will be understood that the benefits and advantages described above may relate to one embodiment or may relate to several embodiments. The embodiments are not limited to those that solve any or all of the stated problems or those that have any or all of the stated benefits and advantages. Variants should be considered to be included into the scope of the invention.

[0098] Any reference to 'an' item refers to one or more of those items. The term 'comprising' is used herein to mean including the method steps or elements identified, but that such steps or elements do not comprise an exclusive list and a method or apparatus may contain additional steps or elements.

[0099] As used herein, the terms "component" and "system" are intended to encompass computer-readable data storage that is configured with computer-executable instructions that cause certain functionality to be performed when executed by a processor. The computerexecutable instructions may include a routine, a function, or the like. It is also to be understood that a component or system may be localized on a single device or distributed across several devices.

[0100] Further, as used herein, the term "exemplary" is intended to mean "serving as an illustration or example of something".

[0101] Further, to the extent that the term "includes" is used in either the detailed description or the claims, such term is intended to be inclusive in a manner similar to the term "comprising" as "comprising" is interpreted when employed as a transitional word in a claim.

[0102] The figures illustrate exemplary methods. While the methods are shown and described as being a series of acts that are performed in a particular sequence, it is to be understood and appreciated that the methods are not limited by the order of the sequence. For example, some acts can occur in a different order than what is described herein. In addition, an act can occur concurrently with another act. Further, in some instances, not all acts may be required to implement a method described herein.

[0103] Moreover, the acts described herein may comprise computer-executable instructions that can be implemented by one or more processors and / or stored on a computer-readable medium or media. The computer-executable instructions can include routines, sub-routines,programs, threads of execution, and / or the like. Still further, results of acts of the methods can be stored in a computer-readable medium, displayed on a display device, and / or the like.

[0104] The order of the steps of the methods described herein is exemplary, but the steps may be carried out in any suitable order, or simultaneously where appropriate. Additionally, steps may be added or substituted in, or individual steps may be deleted from any of the methods without departing from the scope of the subject matter described herein. Aspects of any of the examples described above may be combined with aspects of any of the other examples described to form further examples without losing the effect sought.

[0105] It will be understood that the above description of a preferred embodiment is given by way of example only and that various modifications may be made by those skilled in the art.What has been described above includes examples of one or more embodiments. It is, of course, not possible to describe every conceivable modification and alteration of the above devices or methods for purposes of describing the aforementioned aspects, but one of ordinary skill in the art can recognize that many further modifications and permutations of various aspects are possible. Accordingly, the described aspects are intended to embrace all such alterations, modifications, and variations that fall within the scope of the appended claims.

Claims

Claims1 . A computer-implemented method of key distribution between a first device and a second device, the method comprising: the first device cooperating with a third device to mutually agree a first shared encryption key; the second device cooperating with the third device to mutually agree a second shared encryption key; the third device using the second shared encryption key to encrypt the first shared encryption key, and sending the encrypted first shared encryption key to the second device; the second device using the second shared encryption key to decrypt the encrypted first shared encryption key to recover the first shared encryption key; the first device using random numbers from a first random number generator (RNG) to generate a third encryption key; the second device using random numbers from a second random number generator (RNG) to generate a fourth encryption key; the first device sending the third encryption key to the second device using a first communication channel secured by an encryption key shared by the first device and the second device; the second device sending the fourth encryption key to the first device using a second communication channel secured by an encryption key shared by the first device and the second device; and each of the first device and the second device combining the first shared encryption key, the third encryption key, and the fourth encryption key to generate a fifth encryption key.

2. The method as claimed in claim 1 , further comprising using the fifth encryption key for communication and / or authentication between the first device and the second device.

3. The method as claimed in claim 1 or claim 2, wherein the encryption keys are symmetric encryption keys.

4. The method as claimed in any preceding claim, wherein the combining the first shared encryption key, the third encryption key, and the fourth encryption key to generate the fifth encryption key is carried out using XOR operations.

5. The method as claimed in any preceding claim, wherein the first communication channel and the second communication channel are secured by the same encryption key.

6. The method as claimed in any preceding claim, wherein the first communication channel and the second communication channel are AES channels, and preferably AES-256 channels.

7. The method as claimed in any preceding claim, wherein, the first device cooperating with the third device to mutually agree the first shared encryption key comprises: the third device transmitting a first set of random symbols over a quantum communication channel to the second device, and transmitting a basis set used by the third device for transmitting the first set of random symbols to the second device over a classical communication channel; and the first device and the third device communicating over the classical communication channel and another classical communication channel to generate the first shared encryption key based on the transmitted first set of random symbols.

8. The method as claimed in claim 7, wherein the first device and the third device mutually agree the first shared encryption key using a BB-84 QKD protocol.

9. The method as claimed in any preceding claim, wherein, the second device cooperating with the third device to mutually agree the second shared encryption key comprises: the third device transmitting a second set of random symbols over a quantum communication channel to the second device, and transmitting a basis set used by the third device for transmitting the second set of random symbols to the second device over a classical communication channel; and the second device and the third device communicating over the classical communication channel and another classical communication channel to generate the second shared encryption key based on the transmitted second set of random symbols.

10. The method as claimed in claim 8, wherein the second device and the third device mutually agree the second shared encryption key using a BB-84 QKD protocol.11 . The method as claimed in any preceding claim, wherein the third device using the second shared encryption key to encrypt the first shared encryption key comprises XOR operations; andthe second device using the second shared encryption key to decrypt the encrypted first shared encryption key to recover the first shared encryption key comprises XOR operations.

12. The method as claimed in any preceding claim, wherein the third device is located on a satellite.

13. A system comprising a first device, a second device and a third device, wherein: the first device is arranged to cooperate with the third device to mutually agree a first shared encryption key; the second device is arranged to cooperate with the third device to mutually agree a second shared encryption key; the third device is arranged to use the second shared encryption key to encrypt the first shared encryption key, and to send the encrypted first shared encryption key to the second device; the second device is arranged to use the second shared encryption key to decrypt the encrypted first shared encryption key to recover the first shared encryption key; the first device is arranged to use random numbers from a first random number generator (RNG) to generate a third encryption key; the second device is arranged to use random numbers from a second random number generator (RNG) to generate a fourth encryption key; the first device is arranged to send the third encryption key to the second device using a first communication channel secured by an encryption key shared by the first device and the second device; the second device is arranged to send the fourth encryption key to the first device using a second communication channel secured by an encryption key shared by the first device and the second device; and each of the first device and the second device are arranged to combine the first shared encryption key, the third encryption key, and the fourth encryption key to generate a fifth encryption key.

14. The system as claimed in claim 13, wherein the first device and the second device are arranged to use the fifth encryption key for communication and / or authentication between the first device and the second device.

15. The system as claimed in claim 13 or claim 14, wherein the encryption keys are symmetric encryption keys.

16. The system as claimed in any one of claims 13 to 15, wherein the combining the first shared encryption key, the third encryption key, and the fourth encryption key to generate the fifth encryption key is carried out using XOR operations.

17. The system as claimed in any one of claims 13 to 16, wherein the first communication channel and the second communication channel are secured by the same encryption key.

18. The system as claimed in any one of claims 13 to 17, wherein the first communication channel and the second communication channel are AES channels, and preferably AES-256 channels.

19. The system as claimed in any one of claims 13 to 18, wherein, the first device is arranged to cooperate with the third device to mutually agree the first shared encryption key by: the third device being arranged to transmit a first set of random symbols over a quantum communication channel to the second device, and to transmit a basis set used by the third device for transmitting the first set of random symbols to the second device over a classical communication channel; and the first device and the third device are arranged to communicate over the classical communication channel and another classical communication channel to generate the first shared encryption key based on the transmitted first set of random symbols.

20. The system as claimed in claim 19, wherein the first device and the third device are arranged to mutually agree the first shared encryption key using a BB-84 QKD protocol.21 . The system as claimed in any one of claims 13 to 20, wherein, the second device is arranged to cooperate with the third device to mutually agree the second shared encryption key by: the third device being arranged to transmit a second set of random symbols over a quantum communication channel to the second device, and to transmit a basis set used by the third device for transmitting the second set of random symbols to the second device over a classical communication channel; and the second device and the third device being arranged to communicate over the classical communication channel and another classical communication channel to generate the second shared encryption key based on the transmitted second set of random symbols.

22. The system as claimed in claim 21 , wherein the second device and the third device are arranged to mutually agree the second shared encryption key using a BB-84 QKD protocol.

23. The system as claimed in any one of claims 13 to 22, wherein the third device is arranged to use the second shared encryption key to encrypt the first shared encryption key by XOR operations; and the second device is arranged to use the second shared encryption key to decrypt the encrypted first shared encryption key to recover the first shared encryption key by XOR operations.

24. The system as claimed in any preceding claim, wherein the third device is located on a satellite.

25. A computer-readable medium comprising code or computer instructions stored thereon, which when executed by a processor unit, causes the processor unit to perform the computer-implemented method according to any one of claims 1 to 12.