System and method for performing secure multi-hop quantum key distribution
The method enables secure multi-hop quantum key distribution by encrypting and combining link secrets across intermediate nodes, ensuring efficient and confidential end-to-end key establishment in quantum key distribution networks.
Patent Information
- Application Number
- PCT/CA2025/050083
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-23
- Filing Date
- 2025-01-22
- Publication Date
- 2025-07-31
AI Technical Summary
Existing quantum key distribution networks (QKDNs) face limitations in securely establishing end-to-end keys between endpoints connected via indirect, multi-hop routes due to the lack of direct point-to-point links, which can compromise security and efficiency.
A method for secure multi-hop quantum key distribution involving intermediate nodes that encrypt and combine link secrets using pre-existing communication keys, allowing endpoints to derive an end-to-end key without revealing intermediate node information, augmented by additional key establishment protocols.
Ensures secure and efficient establishment of end-to-end keys across multi-hop networks, maintaining confidentiality and integrity of communication keys.
Smart Images

Figure CA2025050083_31072025_PF_FP_ABST
Abstract
Description
SYSTEM AND METHOD FOR PERFORMING SECURE MULTI-HOP QUANTUM KEY DISTRIBUTIONCROSS-REFERENCE TO RELATED APPLICATION(S)
[0001] This application claims priority to U.S. Provisional Patent Application No. 63 / 623,937 filed on January 23, 2024, the contents of which are incorporated herein by reference in their entirety.TECHNICAL FIELD
[0002] The following generally relates to quantum key distribution and, more particularly, to secure multi-hop quantum key distribution in a quantum key distribution network.BACKGROUND
[0003] Quantum key distribution (QKD) technologies provide a mechanism to distribute symmetric random bit strings as secrets that can be proven to be secure even against an eavesdropper with an unbounded computational ability. To this end, QKD modules are connected pair-wise in point-to-point QKD links and generate QKD secrets using QKD protocols. QKD technologies are limited in range, so in a typical setup, QKD links form the basic building blocks of QKD networks (QKDNs). QKDNs include multiple QKD nodes (each containing one or more QKD modules) connected via QKD links, forming a larger, multi-hop network. As a result, the QKDN bridges longer distances and connects many QKD nodes with each other.
[0004] Typically, there exists a QKDN controller device that functions separately from the QKD nodes to control QKDN resources ensuring secure, stable, efficient, and robust operations of a QKDN. Among other sub-functions, the QKDN controller is responsible for configuration of, and routing between, the QKD nodes in the QKDN. To achieve this in a secure way, the QKDN controller has a security association with all QKD nodes comprising the QKDN, enabling a secure tunnel between the controller and each QKD node. Through these tunnels, the controller device can communicate with each element of the QKDN securely and confidentially.
[0005] Most QKD nodes in a QKDN are not connected via direct point-to-point links. Instead, they are connected via routes (i.e. indirect, multi-hop connections). Herein, pairs of QKD nodes establishing end-to-end keys between each other viasuch routes may be referred to as endpoints. Endpoints are connected through a number of intermediate QKD nodes as configured by the QKDN controller device.SUMMARY
[0006] The following provides a method to securely establish keys between two endpoints connected through a multi-hop QKDN.
[0007] In one aspect, there is provided a method of performing secure multi-hop quantum key distribution in a quantum key distribution network (QKDN) having nodes comprising a primary endpoint, a secondary endpoint, and at least one intermediate node between the primary and secondary endpoints, the method comprising: for each intermediate node, sending an intermediate value to the primary endpoint, the intermediate value combining a pair of link secrets, each shared exclusively with one other node in the network; for at least those intermediate nodes sharing link secrets with the primary or secondary endpoints, respectively, each node securely sending the intermediate value to the primary endpoint by encrypting, prior to sending, the intermediate value using a communication key shared exclusively between that intermediate node and one or both of the primary endpoint and the second endpoint; for at least one node other than the secondary endpoint, securely sending information to the secondary endpoint encrypted using a communication key shared exclusively between that node and one or both of the primary endpoint and the secondary endpoint; and the primary and secondary endpoints deriving a secure end-to-end key from two link secrets, one of the two link secrets being shared by the primary endpoint and an intermediate node and the other one being shared by the secondary endpoint and one of the intermediate nodes.
[0008] In certain example embodiments, the method includes the primary endpoint sending a primary value securely to the secondary endpoint encrypted using a communication key shared exclusively between the primary endpoint and the second endpoint, the primary value combining all intermediate values.
[0009] In certain example embodiments, the method includes, for each intermediate node, sending the intermediate value to the secondary endpoint; and for at least those intermediate nodes sharing link secrets with the primary orsecondary endpoints, respectively, each node securely sending the intermediate value to the secondary endpoint by encrypting, prior to sending, the intermediate value using a communication key shared exclusively between that intermediate node and one or both of the primary endpoint and the secondary endpoint.
[0010] In certain example embodiments, the method includes an entity other than the primary endpoint, the secondary endpoint, or the intermediate nodes, generating at least two provisioning secrets; the entity sending each provisioning secret securely to one or two nodes in the network using a pre-existing security association between the entity and the recipient node to encrypt that secret; and for at least the secondary endpoint and those intermediate nodes sharing link secrets with the primary or secondary endpoints, respectively, each intermediate node establishing a communication key with the primary endpoint derived from provisioning secrets shared between that node and the primary endpoint.
[0011] In certain example embodiments, the method further includes an entity other than the primary endpoint, the secondary endpoint, or the intermediate nodes, generating at least one provisioning secrets; the entity sending each provisioning secret securely to at least one node in the network using a pre-existing security association between the entity and the recipient node to encrypt that secret; and for at least those intermediate nodes sharing link secrets with the primary or secondary endpoints, respectively, each intermediate node establishing a communication key with the primary and secondary endpoints derived from provisioning secrets shared between that intermediate node and the primary and secondary endpoints, respectively.
[0012] In certain example embodiments, the provisioning secrets are augmented with at least one additional secret obtained by executing at least one additional key establishment protocol directly between the respective nodes when deriving the communication key.
[0013] In certain example embodiments, the secrets shared between the primary and secondary endpoints are augmented with at least one additional secret obtained by executing at least one additional key establishment protocol directly between the primary and secondary endpoints when deriving the end-to-end key.
[0014] In certain example embodiments, the method further includes utilizing the end-to-end secret in at least one communication in the QKDN.
[0015] In certain example embodiments, each link secret shared by nodes in the network has a unique identifier.
[0016] In certain example embodiments, the unique identifier is assigned by a QKD model used by a computing device operating in the QKDN.
[0017] In certain example embodiments, the link secrets are combined by computing a bitwise exclusive OR operation applied to those secrets.
[0018] In certain example embodiments, the intermediate values are combined by computing a bitwise exclusive OR operation to those values.
[0019] In certain example embodiments, the primary value and the intermediate values are sent to the primary or secondary endpoint along with explicit or implicit information allowing for identification of particular link secrets combined in these values.
[0020] In certain example embodiments, the provisioning is executed by a controller in the QKDN, the controller being coupled to the nodes.
[0021] In certain example embodiments, each node in the QKDN comprises a QKD module for each link connected to that node.
[0022] In certain example embodiments, the QKDN is a first QKDN in a hierarchical system comprising at least one second QKDN.
[0023] In another aspect, there is provided a method of provisioning a quantum key distribution network (QKDN) for secure multi-hop quantum key distribution, the QKDN having nodes comprising a primary endpoint, a secondary endpoint, and at least one intermediate node between the primary and secondary endpoints, the method comprising: an entity other than the primary endpoint, the secondary endpoint, or the intermediate nodes, generating at least two provisioning secrets; the entity sending each provisioning secret securely to one or two nodes in the network using a pre-existing security association between the entity and the recipient node to encrypt that secret; and for at least the secondary endpoint and those intermediate nodes sharing link secrets with the primary or secondary endpoints, respectively,each intermediate node establishing a communication key with the primary endpoint derived from provisioning secrets shared between that node and the primary endpoint.
[0024] In another aspect, there is provided a method of provisioning a quantum key distribution network (QKDN) for secure multi-hop quantum key distribution, the QKDN having nodes comprising a primary endpoint, a secondary endpoint, and at least one intermediate node between the primary and secondary endpoints, the method comprising: an entity other than the primary endpoint, the secondary endpoint, or the intermediate nodes, generating at least one provisioning secret; the entity sending each provisioning secret securely to at least one node in the network using a pre-existing security association between the entity and the recipient node to encrypt that secret; and for at least those intermediate nodes sharing link secrets with the primary or secondary endpoints, respectively, each intermediate node establishing a communication key with the primary and secondary endpoints derived from provisioning secrets shared between that intermediate node and the primary and secondary endpoints, respectively.
[0025] In another aspect, there is provided a computer-readable medium storing computer-executable instructions that, when executed by a processor of a computing device, cause the computing device to perform any one of the above methods.
[0026] In another aspect, there is provided a system for providing a quantum key distribution network (QKDN), the system comprising a controller device and at least one QKD module, the QKDN comprising at least one processor and memory, the memory storing computer executable instructions that when executed by the processor, cause the controller device to perform any one of the above methods.BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Embodiments will now be described with reference to the appended drawings wherein:
[0028] FIG. 1 illustrates an example of a QKDN have two endpoints and a pair of intermediate nodes.
[0029] FIG. 2 is a flow chart illustrating a multi-hop quantum key distribution process.
[0030] FIG. 3 is a flow chart illustrating further details of the process shown in FIG. 2, in one example embodiment.
[0031] FIG. 4 illustrates an example of a configuration for a computing device that may be configured to operate within the computing environment of FIG. 1 as one or more of the entities shown.DETAILED DESCRIPTION
[0032] The method described herein can be applied to applications, scenarios and configurations where two endpoints establish end-to-end keys via a route having n intermediate QKD nodes (with n being a natural number).
[0033] The method includes two phases, a provisioning phase and an operational phase. In the provisioning phase, a controller device configures the endpoints and any intermediate QKD nodes such that the endpoints can establish end-to-end keys between each other. Subsequently, in the operational phase, endpoints establish these end-to-end keys, using information from the intermediate QKD nodes, in a secure way such that neither any intermediate QKD node by itself nor the controller device by itself have enough information to determine the established end-to-end keys.
[0034] Referring now to the figures, FIG. 1 illustrates an example of a QKDN 10 that is at least in part operated by or with a controller device, referred to herein as the “controller” and denoted by numeral 12. In the example shown in FIG. 1 , two endpoints 14, 16, namely Endpoint A denoted by numeral 14 and Endpoint B denoted by numeral 16, are connected to intermediate QKD nodes C and D, each denoted numeral 18. That is, there are QKD links 20 between Endpoint A and QKD node C (denoted LAC), QKD nodes C and D (LCD), and QKD node D and endpoint B (LDB), respectively. The controller 12 may communicate with the endpoints 14, 16 and intermediate QKD nodes 18 using secure tunnels 22 as described in greater detail below. Moreover, Endpoint B may establish channels 24 between itself and Endpoint A and the QKD nodes 18 to exchange combined values obtained by performing XOR operations as also further described below.
[0035] FIG. 2 illustrates the proposed method that may be executed using a configuration such as that shown in FIG. 1. In FIG. 2, the provisioning stage is denoted by numeral 26 and the operation stage is denoted by numeral 28. At block 30, the provisioning stage 26 is initiated, e.g., by the controller 12. The provisioning stage begins with provisioning the route at block 32 to configure the primary endpoint 16 and provisioning an intermediate QKD node 18 at block 34. At block 36, the controller 12 determines if additional intermediate QKD nodes 18 are to be provisioned. If so, block 34 repeats until all intermediate QKD nodes 18 in this particular end-to-end communication path are provisioned. Once all intermediate QKD nodes 18 have been provisioned, the secondary endpoint 14 is provisioned at block 38.
[0036] At block 40, the controller 12 can proceed by initiating the operation stage 28. The operation stage 28 begins at block 42 with producing secrets between the intermediate QKD nodes 18 as discussed in greater detail by way of example below. Then, at block 44, the secrets are combined and the combined value is sent to the primary endpoint 16, in this example, Endpoint B. At block 46, all such values are combined again, and at block 48, the final combined value is sent to the secondary endpoint 14, in this example Endpoint A. At block 50 the controller 12 (or some other function) has both endpoints 14, 16 compute the final end-to-end key to enable the operation phase 28 to continue at block 52 by enabling communications using such an end-to-end key.
[0037] FIG. 3 shows a particular embodiment of a sequence of messages between the parties shown in FIG. 1 . The order of the messages in the provisioning phase 26 as well as the order of the XOR messages in the operational phase 28 are just examples. That is, other ordering may be implemented while yielding the same result.Provisioning Phase
[0038] Initially, in the provisioning phase 26, the controller function obtains n+1 random secrets, where n is the number of intermediate QKD nodes 18, e.g., using a random number generator. In one embodiment depicted in FIG. 3 (based on configuration illustrated in FIG. 1), these secrets are denoted SA, SC and SD for thepurpose of the present disclosure. The controller 12 arbitrarily assigns one endpoint (e.g., Endpoint B in this example) as the primary endpoint 16 and the other (e.g., Endpoint A in this example) as the secondary endpoint 14 and configures the endpoints 14, 16 and intermediate QKD nodes 18 as follows.
[0039] To provision the route, the controller 12 sends information to the primary endpoint 16 through a secure tunnel 22, which may be established using an existing security association between the parties. This operation is referred to in FIG. 3 as the Provision Route message. The ProvisionRoute message contains the information that a new route between the endpoints 14, 16 is established utilizing the indicated intermediate QKD nodes 18, the link to be used for the new route (LDB), the n+1 secrets described above, as well as explicit or implicit information providing a way to associate each intermediate QKD node 18 as well as the secondary endpoint 14 with one secret in a one-to-one mapping.
[0040] The controller 12 sends information to each intermediate QKD node 18, again through a secure tunnel 22 as above. In this example, these operations are referred to as ProvisionNode messages and one is sent to QKD Node C and one to QKD Node D in this example. The ProvisionNode message contains information denoting the primary endpoint 16, the associated secret, and which links are connected in the new route.
[0041] The controller 12 sends information to the secondary endpoint 14, also through a secure tunnel 22. In this example, this operation may be referred to as the ProvisionEndpoint message. The ProvisionEndpoint message contains information denoting the primary endpoint 16, the associated secret (SA), and the link to be used by the secondary endpoint 14 for the new route (LAC).
[0042] Using the provisioned secrets, the primary endpoint 16 can derive communication keys for the secondary endpoint 14 and each of the intermediate QKD nodes 18 that are part of the new route. In the example shown in FIG. 3, KD may be derived from SD, KC may be derived from sc, and KA may be derived from SA. Similarly, each intermediate QKD node 18 and the secondary endpoint 14 can derive a matching communication key each (using their associated secret) for the primary endpoint 16.
[0043] The shared secrets provisioned by the controller 12 may be augmented with additional secrets obtained by executing additional key establishment protocols directly between the respective communication parties.Operational Phase
[0044] During operation, the QKD links 20 produce QKD secrets between the QKD nodes, e.g. LAC (between endpoint A and QKD node C) produces a secret denoted SAC, known exclusively to nodes A and C (i.e. the nodes connected through that link). Each secret has a unique identifier (e.g. I DAC in this example) assigned by the QKD modules used by the computing devices operating in the computing environment QKDN 10.
[0045] Each intermediate QKD node 18 computes the bitwise exclusive OR operation (denoted XOR in the following) of two QKD secrets (one each from the two links specified in the ProvisionNode message). The respective intermediate QKD node 18 sends the resulting value along with explicit or implicit information allowing for identification of the particular secrets used to compute this value, to the primary endpoint 16 through a secure tunnel 24. This secure tunnel 24 provides confidentiality and authentication using the communication key established by the intermediate QKD node 18 and the primary endpoint 16 in the provisioning phase 26. This exchange may be referred to herein as the XOR message.
[0046] When the primary endpoint 16 has received XOR messages from all intermediate QKD nodes 18 in the route, it can compute the combined XOR of all the values received (denoted XAB in FIG. 3).
[0047] The primary endpoint 16 sends XAB to the secondary endpoint 14 along with explicit or implicit information allowing for identification of the particular QKD secret (produced by the QKD link 20 specified in the ProvisionEndpoint message) that was used to compute XAB (again using a secure tunnel 24 established with the communication key derived by both endpoints 14, 16 in the provisioning phase). This exchange may be referred to herein as the EstablishKey message as illustrated in FIG. 3.
[0048] The secondary endpoint 14 can now use XAB and the QKD secret identified in the EstablishKey message to compute the value of the particular QKDsecret (produced by the QKD link specified in the ProvisionRoute message) that was used in the computation of XAB (SDB in this example). In the same manner, the primary endpoint 16 can compute the value of the particular QKD secret (produced by the QKD link specified in the ProvisionEndpoint message) that was used in the computation of XAB (SAC in this example).
[0049] As a result, both endpoints 14, 16 (and only those two endpoints 14, 16) are able to derive the final end-to-end key KAB from both secrets described above. It can be appreciated that these secrets may be augmented with additional secrets obtained by executing additional key establishment protocols directly between the endpoints when deriving their final end-to-end key.
[0050] Once the end-to-end key KAB has been established, secure communications may be executed between the endpoints 14, 16.
[0051] The example described above details how two endpoints can derive an end-to-end secret using a route that includes n QKD links directly connecting an endpoint and an intermediate node or two intermediate nodes, respectively.However, it can be appreciated that the principles described above can be applied in a hierarchical way.
[0052] For example, consider a QKDN 10 that includes a controller C1 , endpoints A1 and B1 connected through intermediate nodes 11 and J1. Then, a system can apply the above method to establish an end-to-end key between A1 and B1 .Similarly, consider a second QKDN 10, including a controller C2, and endpoints A2 and B2 connected through intermediate nodes I2 and J2. Then, the system can apply the above method in the same way to establish an end-to-end key between A2 and B2.
[0053] Now, assume a QKD link between B1 and A2 exists. Then, the system could have a third QKDN 10 that includes a controller C3, endpoints A1 and B2 with intermediate nodes B1 and A2. Between A1 and B1 , as well as A2 and B2, the system does not have direct QKD link, but still has shared secrets (after applying the above method). As indicated, there is a direct QKD link between A2 and B1 . As such, the system can apply the method a third time (using the secrets established before). Conceptually, the third QKDN is a layer above the first two, hence may beembodied or envisioned as a hierarchical system that includes a plurality of QKDNs 10.
[0054] Referring now to FIG. 4, it can be appreciated that the controller 12, endpoints 14, 16 and QKD nodes 18 may be implemented using computing devices that include cryptographic capabilities, for example, using a QKD component of a cryptographic module. FIG. 4 shows an example of a computing device 70 which may be utilized by any of the entities shown in FIGS. 1 and 3 and be adapted for the corresponding role of that entity. In this example, the computing device 70 includes one or more processors 72 (e.g., a microprocessor, microcontroller, embedded processor, digital signal processor (DSP), central processing unit (CPU), media processor, graphics processing unit (GPU) or other hardware-based processing units) and one or more network interfaces 74 (e.g., a wired or wireless transceiver device connectable to a network via a communication connection). Examples of such communication connections can include wired connections such as twisted pair, coaxial, Ethernet, fiber optic, etc. and / or wireless connections such as LAN, WAN, PAN and / or via short-range communications protocols such as Bluetooth, WiFi, NFC, IR, etc.
[0055] The computing device 70 also includes an application 82, a data store 86, application data 88, and cryptographic keys 90. The data store 86 may in part include secure storage element(s) such as a hardware security module (HSM) and the like. It can be appreciated that the application 82 may represent an application that utilizes the QKDN 10 to send and receive secure messages. The application 82 may represent an application provided or used by a user device, an enterprise device, or any other entity configured to operate within the QKDN 10.
[0056] The data store 86 may represent a database or library or other computer- readable medium configured to store data and permit retrieval of data by the computing device 70. The data store 86 may be read-only or may permit modifications to the data. The data store 86 may also store both read-only and write accessible data in the same memory allocation. In this example, the data store 86 stores the application data 88 for the application 82 that is configured to be executed by the computing device 70 for a particular role or purpose as well as any cryptographic keys 90.
[0057] While not delineated in FIG. 4, the computing device 70 includes at least one memory or memory device that can include a tangible and non-transitory computer-readable medium having stored therein computer programs, sets of instructions, code, or data to be executed by processor(s) 72. The processor(s) 72 and network interface(s) 74 are connected to each other via a data bus or other communication backbone to enable components of the computing device 70 to operate together as described herein. FIG. 4 illustrates examples of modules and applications stored in memory on the computing device 70 and executed by the processor(s) 72.
[0058] It can be appreciated that any of the modules and applications shown in FIG. 4 may be hosted externally and be available to the computing device 70, e.g., via a network interface 74.
[0059] As shown in FIG. 4, the computing device 70 may, optionally (e.g., when configured as a user device 22), include a display 76 and one or more input device(s) 78 that may be utilized via an input / output (I / O) module 80. That is, such components may be omitted when the computing device 70 does not interact with a user.
[0060] For simplicity and clarity of illustration, where considered appropriate, reference numerals may be repeated among the figures to indicate corresponding or analogous elements. In addition, numerous specific details are set forth in order to provide a thorough understanding of the examples described herein. However, it will be understood by those of ordinary skill in the art that the examples described herein may be practiced without these specific details. In other instances, well-known methods, procedures and components have not been described in detail so as not to obscure the examples described herein. Also, the description is not to be considered as limiting the scope of the examples described herein.
[0061] It will be appreciated that the examples and corresponding diagrams used herein are for illustrative purposes only. Different configurations and terminology can be used without departing from the principles expressed herein. For instance, components and modules can be added, deleted, modified, or arranged with differing connections without departing from these principles.
[0062] It will also be appreciated that any module or component exemplified herein that executes instructions may include or otherwise have access to computer readable media such as transitory or non-transitory storage media, computer storage media, or data storage devices (removable and / or non-removable) such as, for example, magnetic disks, optical disks, or tape. Computer storage media may include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information, such as computer readable instructions, data structures, program modules, or other data. Examples of computer storage media include RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transitory computer readable medium which can be used to store the desired information and which can be accessed by an application, module, or both. Any such computer storage media may be part of the QKDN computing environment 10, any component of or related thereto, etc., or accessible or connectable thereto. Any application or module herein described may be implemented using computer readable / executable instructions that may be stored or otherwise held by such computer readable media.
[0063] The steps or operations in the flow charts and diagrams described herein are provided by way of example. There may be many variations to these steps or operations without departing from the principles discussed above. For instance, the steps may be performed in a differing order, or steps may be added, deleted, or modified.
[0064] Although the above principles have been described with reference to certain specific examples, various modifications thereof will be apparent to those skilled in the art as having regard to the appended claims in view of the specification as a whole.
Claims
Claims:1 . A method of performing secure multi-hop quantum key distribution in a quantum key distribution network (QKDN) having nodes comprising a primary endpoint, a secondary endpoint, and at least one intermediate node between the primary and secondary endpoints, the method comprising: for each intermediate node, sending an intermediate value to the primary endpoint, the intermediate value combining a pair of link secrets, each shared exclusively with one other node in the network; for at least those intermediate nodes sharing link secrets with the primary or secondary endpoints, respectively, each node securely sending the intermediate value to the primary endpoint by encrypting, prior to sending, the intermediate value using a communication key shared exclusively between that intermediate node and one or both of the primary endpoint and the second endpoint; for at least one node other than the secondary endpoint, securely sending information to the secondary endpoint encrypted using a communication key shared exclusively between that node and one or both of the primary endpoint and the secondary endpoint; and the primary and secondary endpoints deriving a secure end-to-end key from two link secrets, one of the two link secrets being shared by the primary endpoint and an intermediate node and the other one being shared by the secondary endpoint and one of the intermediate nodes.
2. The method of claim 1 , comprising: the primary endpoint sending a primary value securely to the secondary endpoint encrypted using a communication key shared exclusively between the primary endpoint and the second endpoint, the primary value combining all intermediate values.
3. The method of claim 1 comprising: for each intermediate node, sending the intermediate value to the secondary endpoint; andfor at least those intermediate nodes sharing link secrets with the primary or secondary endpoints, respectively, each node securely sending the intermediate value to the secondary endpoint by encrypting, prior to sending, the intermediate value using a communication key shared exclusively between that intermediate node and one or both of the primary endpoint and the secondary endpoint.
4. The method of claim 2, further comprising: an entity other than the primary endpoint, the secondary endpoint, or the intermediate nodes, generating at least two provisioning secrets; the entity sending each provisioning secret securely to one or two nodes in the network using a pre-existing security association between the entity and the recipient node to encrypt that secret; and for at least the secondary endpoint and those intermediate nodes sharing link secrets with the primary or secondary endpoints, respectively, each intermediate node establishing a communication key with the primary endpoint derived from provisioning secrets shared between that node and the primary endpoint.
5. The method of claim 3, further comprising: an entity other than the primary endpoint, the secondary endpoint, or the intermediate nodes, generating at least one provisioning secrets; the entity sending each provisioning secret securely to at least one node in the network using a pre-existing security association between the entity and the recipient node to encrypt that secret; and for at least those intermediate nodes sharing link secrets with the primary or secondary endpoints, respectively, each intermediate node establishing a communication key with the primary and secondary endpoints derived from provisioning secrets shared between that intermediate node and the primary and secondary endpoints, respectively.
6. The method of claim 4 or claim 5, wherein the provisioning secrets are augmented with at least one additional secret obtained by executing at least oneadditional key establishment protocol directly between the respective nodes when deriving the communication key.
7. The method of any one of claims 1 to 6, wherein the secrets shared between the primary and secondary endpoints are augmented with at least one additional secret obtained by executing at least one additional key establishment protocol directly between the primary and secondary endpoints when deriving the end-to-end key.
8. The method of any one of claims 1 to 7, further comprising: utilizing the end-to-end secret in at least one communication in the QKDN.
9. The method of any one of claims 1 to 8, wherein each link secret shared by nodes in the network has a unique identifier.
10. The method of claim 9, wherein the unique identifier is assigned by a QKD model used by a computing device operating in the QKDN.11 . The method of any one of claims 1 to 10, wherein the link secrets are combined by computing a bitwise exclusive OR operation applied to those secrets.
12. The method of any one of claims 1 to 11 , wherein the intermediate values are combined by computing a bitwise exclusive OR operation to those values.
13. The method of any one of claims 1 to 12, wherein the primary value and the intermediate values are sent to the primary or secondary endpoint along with explicit or implicit information allowing for identification of particular link secrets combined in these values.
14. The method of claim 4 or claim 5, wherein the provisioning is executed by a controller in the QKDN, the controller being coupled to the nodes.
15. The method of any one of claims 1 to 14, wherein each node in the QKDN comprises a QKD module for each link connected to that node.
16. The method of any one of claims 1 to 15, wherein the QKDN is a first QKDN in a hierarchical system comprising at least one second QKDN.
17. A method of provisioning a quantum key distribution network (QKDN) for secure multi-hop quantum key distribution, the QKDN having nodes comprising a primary endpoint, a secondary endpoint, and at least one intermediate node between the primary and secondary endpoints, the method comprising: an entity other than the primary endpoint, the secondary endpoint, or the intermediate nodes, generating at least two provisioning secrets; the entity sending each provisioning secret securely to one or two nodes in the network using a pre-existing security association between the entity and the recipient node to encrypt that secret; and for at least the secondary endpoint and those intermediate nodes sharing link secrets with the primary or secondary endpoints, respectively, each intermediate node establishing a communication key with the primary endpoint derived from provisioning secrets shared between that node and the primary endpoint.
18. A method of provisioning a quantum key distribution network (QKDN) for secure multi-hop quantum key distribution, the QKDN having nodes comprising a primary endpoint, a secondary endpoint, and at least one intermediate node between the primary and secondary endpoints, the method comprising: an entity other than the primary endpoint, the secondary endpoint, or the intermediate nodes, generating at least one provisioning secret; the entity sending each provisioning secret securely to at least one node in the network using a pre-existing security association between the entity and the recipient node to encrypt that secret; andfor at least those intermediate nodes sharing link secrets with the primary or secondary endpoints, respectively, each intermediate node establishing a communication key with the primary and secondary endpoints derived from provisioning secrets shared between that intermediate node and the primary and secondary endpoints, respectively.
19. A computer-readable medium storing computer-executable instructions that, when executed by a processor of a computing device, cause the computing device to perform the method of any one of claims 1 to 16 or claim 17 or claim 18.
20. A system for providing a quantum key distribution network (QKDN), the system comprising a controller device and at least one QKD module, the QKDN comprising at least one processor and memory, the memory storing computer executable instructions that when executed by the processor, cause the controller device to perform the method of any one of claims 1 to 16 or claim 17 or claim 18.
Citation Information
Patent Citations
Method for Quantum Cryptography for Network Combining Ring and Star Structure
KR1020160050912A
Secure communication network
US20200274701A1
Quantum key distribution system and method for securely distributing quantum keys in a network
US20230034274A1
System and method for key establishment
WO2022153051A1