WO2016133724A1 - Method, apparatus, and system for identity authentication - Google Patents

Method, apparatus, and system for identity authentication Download PDF

Info

Publication number
WO2016133724A1
WO2016133724A1 PCT/US2016/016740 US2016016740W WO2016133724A1 WO 2016133724 A1 WO2016133724 A1 WO 2016133724A1 US 2016016740 W US2016016740 W US 2016016740W WO 2016133724 A1 WO2016133724 A1 WO 2016133724A1
Authority
WO
WIPO (PCT)
Prior art keywords
identity authentication
key
information
receiver
quantum
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2016/016740
Other languages
English (en)
French (fr)
Inventor
Yingfang FU
Shuanlin LIU
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alibaba Group Holding Ltd
Original Assignee
Alibaba Group Holding Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alibaba Group Holding Ltd filed Critical Alibaba Group Holding Ltd
Priority to CA2976784A priority Critical patent/CA2976784A1/en
Priority to BR112017017488-0A priority patent/BR112017017488B1/pt
Priority to KR1020177026173A priority patent/KR20170118190A/ko
Priority to EP16752796.9A priority patent/EP3259870A4/en
Priority to JP2017560880A priority patent/JP6619455B2/ja
Priority to AU2016220364A priority patent/AU2016220364B2/en
Publication of WO2016133724A1 publication Critical patent/WO2016133724A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0852Quantum cryptography
    • H04L9/0858Details about key distillation or coding, e.g. reconciliation, error correction, privacy amplification, polarisation coding or phase coding
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/083Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP]
    • H04L9/0833Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] involving conference or group key
    • H04L9/0836Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] involving conference or group key using tree structure or hierarchical structure
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0852Quantum cryptography
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/24Key scheduling, i.e. generating round keys or sub-keys for block encryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/062Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/062Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
    • H04L63/064Hierarchical key distribution, e.g. by multi-tier trusted parties
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/18Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0838Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
    • H04L9/0841Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
    • H04L9/0844Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols with user authentication or key authentication, e.g. ElGamal, MTI, MQV-Menezes-Qu-Vanstone protocol or Diffie-Hellman protocols using implicitly-certified keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0852Quantum cryptography
    • H04L9/0855Quantum cryptography involving additional nodes, e.g. quantum relays, repeaters, intermediate nodes or remote nodes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/088Usage controlling of secret information, e.g. techniques for restricting cryptographic keys to pre-authorized uses, different access levels, validity of crypto-period, different key- or password length, or different strong and weak cryptographic algorithms

Definitions

  • One aspect of the present disclosure is directed to an identity authentication method for a quantum key distribution process and can be
  • the method includes selecting, by the sender, preparation bases for an identity authentication bit string in accordance with a preset basis vector selection rule; sending, by the sender, quantum state information including quantum states of the identity authentication bit string and quantum states of a randomly generated key bit string by using different wavelengths, the identity authentication bit string being interleaved in the key bit string at a random position and with a random length;
  • the identity authentication method described above may further include receiving authentication key position information from the peer device, and selecting an authentication key from the quantum states in the quantum state information in accordance with the
  • identities of the quantum communication devices of both parties which participate in the distribution process are verified dynamically in the quantum key distribution process.
  • a device that selects preparation bases to send quantum state information to a peer device is generally referred to as Alice (A) side, which is called a quantum communication sender device, and called a sender for short;
  • a device that selects measurement bases to measure received quantum state information is generally referred to as Bob (B) side, which is called a quantum communication receiver device, and called a receiver for short.
  • the sender and the receiver may each include a processor and a non- transitory memory storing instructions that, when executed, control the processor to perform steps described below.
  • identity authentication can be dynamically performed in the quantum key distribution process.
  • the quantum communication devices of the sender and the receiver can first verify the identity of the device of the other party via a classic channel, and the subsequent quantum key distribution process can be continued only when the devices of the both parties both pass the verification.
  • an initiator of the quantum key agreement process can initiate a quantum key agreement request at first, in which the request includes account information of the sender, and the account information may include identity information and a signature certificate of the sender.
  • the receiver verifies the signature certificate by using the identity information therein. If the signature certificate passes the verification, response information is returned to the sender, which includes account information of the receiver, and if the certificate does not pass the verification, the quantum key agreement process is ended.
  • the sender can verify the identity of the receiver in the same manner as described above. If the identity of the receiver passes the verification, the
  • the sender intends to send the quantum state information including the quantum states of a binary bit string with a length of n at time points ti, t 2 ... t n , the binary bit string includes two parts, one part being a classic binary bit string randomly generated, which serves as a key bit string, and the other part being an identity authentication bit string associated with a preset basis vector selection rule.
  • a basis vector selection rule that the devices of the sender and the receiver follow can be set by using different policies. For example, it is feasible to select corresponding preparation bases or measurement bases in accordance with positions of identity authentication bits in the quantum state information prepared by the sender. For example, in one embodiment, the following rule is used: a corresponding horizontal polarization basis, vertical polarization basis, left-handed polarization basis or right-handed polarization basis is selected in accordance with different results of position information of each identity authentication bit in the quantum state information mod 4. In some embodiments, each identity authentication bit is prepared with a preparation basis, and different identity authentication bits have different preparation bases. Both scenarios are contemplated in the present application. In the description, although a preparation and measurement basis may be referred to in singular form, they should cover both singular and plural forms.
  • Step 104 The receiver determines if the identity authentication information obtained through measurement corresponds with the basis vector selection rule. If yes, the method proceeds to step 105; otherwise the method proceeds to step 106.
  • the sender and the receiver can, through an interaction process, complete an identity authentication process of the sender and the receiver in accordance with measurement results of the identity authentication quantum states and verification of the shared key preset by both parties, and then continue the subsequent key agreement process in accordance with the quantum key distribution protocol.
  • an alternative example of performing identity authentication in various stages of key agreement is provided.
  • the receiver not only completes measurement of conventional key quantum states, but also verifies the identity of the sender in accordance with measurement results of the identity authentication quantum state information.
  • the process includes sub-steps 201 to 208, and is further described below with reference to FIG. 2.
  • Step 203 Measuring the received quantum state information, and acquiring identity authentication information.
  • the identity authentication quantum state information obtained through measurement by the receiver can be considered or referred to as corresponding with or consistent with the basis vector selection rule.
  • Step 109 The sender uses the corresponding sender authentication key to decrypt the encrypted information received from the receiver.
  • the received information contains the preset shared key. After the sender decrypt the received information, the sender obtains the preset shared key, and compares it with the local preset shared key, and determines whether it is consistent with the local preset shared key.
  • Step 1 10 The quantum key distribution process ends if the received information including the preset shared key is not consistent with the local preset shared key.
  • the sender determines that the identity of the receiver is legal, in accordance with the procedure of the quantum key distribution protocol, the sender can compare the measurement bases made public by the receiver with the preparation bases used by the sender, select correct measurement bases therefrom, select original keys in accordance with the correct measurement bases, and publicize the correct measurement bases to the receiver via a classic channel.
  • identity authentication and data encryption procedures can be performed in alternate in the subsequent distribution process, and such an example is further described below.
  • the sender acquires the auxiliary authentication information after decryption, and after the sender verifies that the identity of the receiver is valid, the sender can first encrypt a variant of the auxiliary authentication information after decryption by using a preset policy, and then, when the correct measurement bases of the key quantum state is published via a classic channel, send the encrypted information after the encryption operation is executed.
  • the preset policy may be preset by both the sender and the receiver, and may also be determined through negotiation.
  • the preset policy may include, for example, executing the encryption operation by using the preset shared key; or executing the encryption operation by using an IDkey.
  • bit error rate is within a certain threshold range
  • an error is corrected by using an error correcting technology.
  • privacy amplification can be further performed on a quantum key that has been error-corrected, so as to eliminate information leakage caused in a communication process and an error correcting process, and finally an unconditionally secure shared quantum key is extracted. If the bit error rate exceeds a certain threshold, the quantum key distribution process can be abandoned.
  • identity authentication on the sender and the receiver is implemented by the quantum key distribution process.
  • key information and identity authentication information are distinguished by using different wavelengths
  • the quantum states of the identity authentication information with a variable length is randomly interleaved in the key quantum states
  • both the sender and the receiver complete an identity authentication process by detecting whether a peer device follows the same basis vector selection rule when selecting preparation bases or measurement bases and whether the peer device has the same preset shared key.
  • the embodiments of the present application achieves identity verification by making full use of security of quantum and performing identity authentication through quantum state information.
  • the disclosed methods not only can effectively defend middle-man attacks and DDOS attacks and guarantee security of the quantum key distribution process, but also will not cause reduction of the quantity of quantum key distribution.
  • Step 303 Receive authentication key position information and encrypted information to be authenticated returned by the peer device.
  • an account information receiving unit configured to receive account information sent by the peer device
  • the information sending unit includes:
  • Fig. 7 is a block diagram illustrating an identity authentication system 700, according to an exemplary embodiment.
  • the system includes: an identity authentication apparatus 701 deployed on a quantum communication sender device, and an identity authentication apparatus 702 deployed on a quantum communication receiver device.
  • the identity authentication apparatuses respectively deployed on the quantum communication devices of the sender and the receiver achieve dynamic verification on the identity of the peer device in the quantum key distribution process by using the identity authentication methods provided in the present application.
  • the received encrypted information to obtain the preset shared key, and determines whether the preset shared key is consistent with a local preset shared key, and if they are consistent, selects original keys, and publicizes correct measurement bases for the key quantum states and encrypted information of a variant of the acquired auxiliary authentication
  • Mutual authentication between A and B can be completed by verifying whether the identity authentication quantum state corresponds with the basis vector selection rule and whether the shared keys preset by A and B are consistent with each other in the links 3), 4) and 5).

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Physics & Mathematics (AREA)
  • Electromagnetism (AREA)
  • Theoretical Computer Science (AREA)
  • Optical Communication System (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Collating Specific Patterns (AREA)
PCT/US2016/016740 2015-02-16 2016-02-05 Method, apparatus, and system for identity authentication Ceased WO2016133724A1 (en)

Priority Applications (6)

Application Number Priority Date Filing Date Title
CA2976784A CA2976784A1 (en) 2015-02-16 2016-02-05 Method, apparatus, and system for identity authentication
BR112017017488-0A BR112017017488B1 (pt) 2015-02-16 2016-02-05 Método de autenticação de identidade para um processo de distribuição de chave quântica, dispositivo de autenticação de identidade para um processo de distribuição de chave quântica, e meio de armazenamento legível por computador não transitório
KR1020177026173A KR20170118190A (ko) 2015-02-16 2016-02-05 신원 인증 방법, 장치 및 시스템
EP16752796.9A EP3259870A4 (en) 2015-02-16 2016-02-05 Method, apparatus, and system for identity authentication
JP2017560880A JP6619455B2 (ja) 2015-02-16 2016-02-05 アイデンティティ認証のための方法、装置、及びシステム
AU2016220364A AU2016220364B2 (en) 2015-02-16 2016-02-05 Method, apparatus, and system for identity authentication

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510084941.2A CN105991285B (zh) 2015-02-16 2015-02-16 用于量子密钥分发过程的身份认证方法、装置及系统
CN201510084941.2 2015-02-16

Publications (1)

Publication Number Publication Date
WO2016133724A1 true WO2016133724A1 (en) 2016-08-25

Family

ID=56621447

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2016/016740 Ceased WO2016133724A1 (en) 2015-02-16 2016-02-05 Method, apparatus, and system for identity authentication

Country Status (9)

Country Link
US (2) US10038554B2 (enExample)
EP (1) EP3259870A4 (enExample)
JP (1) JP6619455B2 (enExample)
KR (1) KR20170118190A (enExample)
CN (1) CN105991285B (enExample)
AU (1) AU2016220364B2 (enExample)
CA (1) CA2976784A1 (enExample)
TW (1) TWI689837B (enExample)
WO (1) WO2016133724A1 (enExample)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109327308A (zh) * 2018-10-30 2019-02-12 成都信息工程大学 一种具有双向身份认证功能的量子密钥分发方法及系统
TWI738836B (zh) * 2016-10-14 2021-09-11 香港商阿里巴巴集團服務有限公司 量子資料密鑰協商系統及量子資料密鑰協商方法

Families Citing this family (100)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105871538B (zh) * 2015-01-22 2019-04-12 阿里巴巴集团控股有限公司 量子密钥分发系统、量子密钥分发方法及装置
CN106411521B (zh) * 2015-07-31 2020-02-18 阿里巴巴集团控股有限公司 用于量子密钥分发过程的身份认证方法、装置及系统
CN106470101B (zh) * 2015-08-18 2020-03-10 阿里巴巴集团控股有限公司 用于量子密钥分发过程的身份认证方法、装置及系统
CN106470345B (zh) 2015-08-21 2020-02-14 阿里巴巴集团控股有限公司 视频加密传输方法和解密方法、装置及系统
CN107086907B (zh) 2016-02-15 2020-07-07 阿里巴巴集团控股有限公司 用于量子密钥分发过程的密钥同步、封装传递方法及装置
CN107086908B (zh) 2016-02-15 2021-07-06 阿里巴巴集团控股有限公司 一种量子密钥分发方法及装置
CN107347058B (zh) 2016-05-06 2021-07-23 阿里巴巴集团控股有限公司 数据加密方法、数据解密方法、装置及系统
CN107370546B (zh) 2016-05-11 2020-06-26 阿里巴巴集团控股有限公司 窃听检测方法、数据发送方法、装置及系统
CN107404461B (zh) 2016-05-19 2021-01-26 阿里巴巴集团控股有限公司 数据安全传输方法、客户端及服务端方法、装置及系统
CN107959656B (zh) 2016-10-14 2021-08-31 阿里巴巴集团控股有限公司 数据安全保障系统及方法、装置
CN107959567B (zh) 2016-10-14 2021-07-27 阿里巴巴集团控股有限公司 数据存储方法、数据获取方法、装置及系统
US10164778B2 (en) 2016-12-15 2018-12-25 Alibaba Group Holding Limited Method and system for distributing attestation key and certificate in trusted computing
CN106961417B (zh) * 2016-12-23 2020-05-22 中国银联股份有限公司 基于密文的身份验证方法
CN107070643B (zh) * 2016-12-26 2023-04-25 清华大学 一种量子密钥分发装置及方法
US10447472B2 (en) * 2017-02-21 2019-10-15 Bank Of America Corporation Block computing for information silo
US10454892B2 (en) 2017-02-21 2019-10-22 Bank Of America Corporation Determining security features for external quantum-level computing processing
CN108667608B (zh) 2017-03-28 2021-07-27 阿里巴巴集团控股有限公司 数据密钥的保护方法、装置和系统
CN108667773B (zh) 2017-03-30 2021-03-12 阿里巴巴集团控股有限公司 网络防护系统、方法、装置及服务器
CN108736981A (zh) 2017-04-19 2018-11-02 阿里巴巴集团控股有限公司 一种无线投屏方法、装置及系统
CN107257283B (zh) * 2017-04-26 2019-11-08 中南大学 基于量子图态的指纹认证方法
CN111052204B (zh) * 2017-08-22 2023-05-02 日本电信电话株式会社 份额生成装置、份额变换装置、秘密计算系统、它们的方法及记录介质
KR101953720B1 (ko) * 2017-09-06 2019-03-04 경희대학교 산학협력단 양자 채널 예측을 수행하는 양자 시스템 및 양자 채널 모델링 방법
CN109510701B (zh) * 2017-09-15 2021-10-01 华为技术有限公司 连续变量量子密钥分发设备及方法
CN107911211B (zh) * 2017-10-23 2020-11-17 浙江神州量子网络科技有限公司 基于量子通信网络的二维码认证系统
KR102028098B1 (ko) * 2018-01-29 2019-10-02 한국전자통신연구원 양자암호통신 인증 장치 및 방법
WO2019198516A1 (ja) * 2018-04-11 2019-10-17 日本電信電話株式会社 鍵配信システム、端末装置、鍵配信方法、及びプログラム
CN109450620B (zh) 2018-10-12 2020-11-10 创新先进技术有限公司 一种移动终端中共享安全应用的方法及移动终端
CN109412797B (zh) * 2018-11-05 2020-09-25 北京捷安通科技有限公司 基于误码率判决状态基的密钥协商方法和客户端
US11343084B2 (en) * 2019-03-01 2022-05-24 John A. Nix Public key exchange with authenticated ECDHE and security against quantum computers
GB2582900A (en) 2019-03-18 2020-10-14 Pqshield Ltd Cryptography using a cryptographic state
US11258601B1 (en) * 2019-06-04 2022-02-22 Trend Micro Incorporated Systems and methods for distributed digital rights management with decentralized key management
WO2020250269A1 (ja) * 2019-06-10 2020-12-17 日本電信電話株式会社 秘密除算システム、秘密計算装置、秘密除算方法、およびプログラム
CN110336720B (zh) * 2019-06-29 2021-08-20 华为技术有限公司 设备控制方法和设备
US11240014B1 (en) 2019-09-10 2022-02-01 Wells Fargo Bank, N.A. Systems and methods for post-quantum cryptography optimization
US11626983B1 (en) 2019-09-10 2023-04-11 Wells Fargo Bank, N.A. Systems and methods for post-quantum cryptography optimization
US11477016B1 (en) 2019-09-10 2022-10-18 Wells Fargo Bank, N.A. Systems and methods for post-quantum cryptography optimization
US11343270B1 (en) 2019-09-10 2022-05-24 Wells Fargo Bank, N.A. Systems and methods for post-quantum cryptography optimization
US11451383B2 (en) * 2019-09-12 2022-09-20 General Electric Company Communication systems and methods
CN112994890B (zh) * 2019-12-17 2023-03-21 中国电信股份有限公司 身份认证方法、物联网设备和计算机可读存储介质
US11429519B2 (en) 2019-12-23 2022-08-30 Alibaba Group Holding Limited System and method for facilitating reduction of latency and mitigation of write amplification in a multi-tenancy storage drive
US11322050B1 (en) * 2020-01-30 2022-05-03 Wells Fargo Bank, N.A. Systems and methods for post-quantum cryptography optimization
US11533175B1 (en) 2020-01-30 2022-12-20 Wells Fargo Bank, N.A. Systems and methods for post-quantum cryptography on a smartcard
US11838410B1 (en) 2020-01-30 2023-12-05 Wells Fargo Bank, N.A. Systems and methods for post-quantum cryptography optimization
US11449799B1 (en) 2020-01-30 2022-09-20 Wells Fargo Bank, N.A. Systems and methods for post-quantum cryptography optimization
KR102222080B1 (ko) * 2020-02-24 2021-03-04 한국전자통신연구원 양자 개체 인증 장치 및 방법
CA3174231A1 (en) 2020-03-30 2021-10-07 Psiquantum, Corp. Encoded fusion measurements with local adaptivity
US12088702B2 (en) * 2020-04-10 2024-09-10 Cyborn Limited Systems and methods for adaptive recursive descent data redundancy
US11329806B1 (en) * 2020-12-04 2022-05-10 The Florida International University Board Of Trustees Systems and methods for authentication and key agreement in a smart grid
GB2603113B (en) * 2021-01-13 2023-12-20 Arqit Ltd System and method for key establishment
EP4285543A1 (en) * 2021-01-29 2023-12-06 Arqit Limited Key exchange protocol for satellite based quantum network
WO2022179677A1 (en) * 2021-02-23 2022-09-01 Telefonaktiebolaget Lm Ericsson (Publ) Method and apparatus for a software defined network
WO2022187369A1 (en) * 2021-03-02 2022-09-09 Sri International Attribute based encryption with bounded collusion resistance
US12192318B2 (en) * 2021-03-10 2025-01-07 Quantropi Inc. Quantum-safe cryptographic method and system
CN113038468B (zh) * 2021-04-07 2022-09-09 东南大学 一种物联网无线终端量子密钥分发与协商方法
CN112953714B (zh) * 2021-04-14 2022-12-06 上海循态量子科技有限公司 基于连续变量量子密钥分发的身份认证方法、系统、介质及设备
US12301710B2 (en) * 2021-05-10 2025-05-13 Electronics And Telecommunications Research Institute Method and apparatus for key relay control based on software defined networking in quantum key distribution network
CN113285800B (zh) * 2021-05-14 2022-10-25 上海循态量子科技有限公司 基于相干态的连续变量量子身份认证方法和系统
EP4335050A4 (en) * 2021-05-31 2024-07-24 Huawei Technologies Canada Co., Ltd. METHODS AND SYSTEMS FOR A 2-QUBIT MULTI-USER QUANTUM KEY DISTRIBUTION PROTOCOL
CN113537982B (zh) * 2021-06-15 2023-06-23 郑州科技学院 金融设备的安全校验方法、装置、设备及存储介质
US11882441B2 (en) * 2021-06-21 2024-01-23 T-Mobile Innovations Llc Quantum authentication for wireless user equipment (UE)
US12052350B2 (en) * 2021-07-08 2024-07-30 Cisco Technology, Inc. Quantum resistant secure key distribution in various protocols and technologies
GB2608999A (en) * 2021-07-15 2023-01-25 Pqshield Ltd Cryptographic system for post-quantum cryptographic operations
AU2022314600A1 (en) * 2021-07-20 2024-01-18 The Research Foundation For The State University Of New York System and method for quantum-secure microgrids
US11743037B2 (en) * 2021-07-29 2023-08-29 QuNu Labs Private Ltd Quantum key distribution system and method for performing differential phase shift in a quantum network
CN113395158B (zh) * 2021-08-18 2022-01-18 北京中创为南京量子通信技术有限公司 一种消息认证密钥生成方法、装置及消息认证系统
CN113645619B (zh) * 2021-09-16 2023-09-19 四川灵通电讯有限公司 一种一对多密钥分发方法与装置
CN113852616B (zh) * 2021-09-16 2023-07-14 国科量子通信网络有限公司 一种量子安全设备的互认证方法和系统
US12267421B2 (en) * 2021-10-18 2025-04-01 International Business Machines Corporation Post quantum secure ingress/egress network communication
JP7612557B2 (ja) * 2021-11-11 2025-01-14 株式会社東芝 量子暗号ストレージシステム、分散制御装置及びプログラム
US12069166B2 (en) * 2022-01-07 2024-08-20 Oracle International Corporation Quorum-based authorization
US12050678B2 (en) 2022-01-07 2024-07-30 Oracle International Corporation Authorization brokering
US12452305B2 (en) * 2022-02-15 2025-10-21 Hewlett Packard Enterprise Development Lp Adaptive enforcement of security within a network
US12413391B2 (en) * 2022-02-23 2025-09-09 Mellanox Technologies, Ltd. Devices, systems, and methods for integrating encryption service channels with a data path
CN114553419B (zh) * 2022-03-24 2024-05-17 上海循态量子科技有限公司 基于连续变量量子密钥分发的量子身份认证方法及系统
US12212668B2 (en) * 2022-03-29 2025-01-28 Verizon Patent And Licensing Inc. Mobile edge network cryptographic key delivery using quantum cryptography
CN114499862A (zh) * 2022-04-06 2022-05-13 北京微芯感知科技有限公司 一种基于量子秘钥分发的对称秘钥池加密及传输方法
US20230353349A1 (en) * 2022-04-27 2023-11-02 Qusecure, Inc Forward secrecy qsl
US20230388289A1 (en) * 2022-05-30 2023-11-30 Vmware, Inc. Bypassing a user passcode when accessing a gateway of a virtual disktop infrastructure system
CN115242490B (zh) * 2022-07-19 2023-09-26 北京计算机技术及应用研究所 一种可信环境下群密钥安全分发方法和系统
CN115314198B (zh) * 2022-08-08 2025-02-14 矩阵时光数字科技有限公司 一种量子安全网络权限管理系统及方法
CN115426106B (zh) * 2022-08-26 2023-05-23 北京海泰方圆科技股份有限公司 一种身份认证方法、装置、系统、电子设备及存储介质
EP4597918A1 (en) * 2022-09-26 2025-08-06 LG Electronics Inc. Method for carrying out user authentication by applying pre-shared key to basis selection in quantum communication system, and device therefor
US12200116B1 (en) 2022-11-18 2025-01-14 Wells Fargo Bank, N.A. Systems and methods for measuring one or more metrics of a cryptographic algorithm in a post-quantum cryptography system
JP7753277B2 (ja) * 2023-03-17 2025-10-14 株式会社東芝 鍵管理装置、量子暗号通信システム、qkdn制御装置、情報処理装置、鍵管理方法、qkdn制御方法、情報処理方法及びプログラム
CN116506122B (zh) * 2023-06-26 2023-10-31 广东广宇科技发展有限公司 一种基于量子密钥分发的认证方法
CN116707807B (zh) * 2023-08-09 2023-10-31 中电信量子科技有限公司 分布式零信任微隔离访问控制方法及系统
US20250106012A1 (en) * 2023-09-26 2025-03-27 Ciena Corporation Quantum key distribution in an optical network and quantum-secured optical channels
US20250119734A1 (en) * 2023-10-06 2025-04-10 T-Mobile Innovations Llc Method for Device Security Gateway Function
US20250132904A1 (en) * 2023-10-18 2025-04-24 Google Llc Reusing Resumption Secrets Obtained from Post-Quantum Ciphers
US20250175329A1 (en) * 2023-11-27 2025-05-29 T-Mobile Innovations Llc Data communication with network slices that deliver quantum capabilities
US20250184126A1 (en) * 2023-11-30 2025-06-05 Cisco Technology, Inc. Native continuous-variable quantum repeater
US20250298908A1 (en) * 2024-03-21 2025-09-25 Nvidia Corporation Application programming interface to encrypt
US20250350450A1 (en) * 2024-05-10 2025-11-13 Bank Of America Corporation Decision Engine Consistency Verification System
CN118209783B (zh) * 2024-05-17 2024-09-03 江苏西欧电子有限公司 一种基于li-fi通讯技术的安全电能表
TWI869283B (zh) * 2024-05-17 2025-01-01 中華電信股份有限公司 基於後量子密碼學的隱式憑證方法、匿名憑證方法、隱式憑證系統、匿名憑證系統、後量子密碼學金鑰產製及加速方法及模組
CN118473667A (zh) * 2024-07-15 2024-08-09 国网江西省电力有限公司电力科学研究院 一种基于量子密钥分发的安全轻量级组网与通信方法
US12450952B1 (en) 2024-11-26 2025-10-21 Daon Technology Methods and systems for enhancing detection of morphed biometric modality data
US12413402B1 (en) * 2025-01-23 2025-09-09 Daon Technology Methods and systems for enhancing detection of fraudulent authentication data
CN119788280B (zh) * 2025-03-11 2025-08-01 北京全路通信信号研究设计院集团有限公司 一种车地通信密钥生成方法、装置、设备及存储介质
CN120528598B (zh) * 2025-07-17 2025-11-04 云南电网有限责任公司 一种电子印章的管控方法及系统

Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070036353A1 (en) * 2005-05-31 2007-02-15 Interdigital Technology Corporation Authentication and encryption methods using shared secret randomness in a joint channel
US20080101612A1 (en) * 2004-08-31 2008-05-01 Hideki Imai Quantum Key Distribution Protocol
US20100260161A1 (en) * 2009-04-11 2010-10-14 Qualcomm Incorporated Apparatus and methods for interleaving in a forward link only system
US20110126011A1 (en) * 2009-11-24 2011-05-26 Electronics And Telecommunications Research Institute Method of user-authenticated quantum key distribution
US20110213979A1 (en) * 2008-10-27 2011-09-01 Qinetiq Limited Quantum key distribution
US20130068186A1 (en) * 2010-03-31 2013-03-21 Haldor Topsoe A/S Method and system for operating a pressure ignition engine
US20130083926A1 (en) * 2011-09-30 2013-04-04 Los Alamos National Security, Llc Quantum key management
US20130315306A1 (en) * 2007-09-14 2013-11-28 General Instrument Corporation Personal Video Recorder

Family Cites Families (35)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5515438A (en) * 1993-11-24 1996-05-07 International Business Machines Corporation Quantum key distribution using non-orthogonal macroscopic signals
JP2000201144A (ja) * 1999-01-05 2000-07-18 Nippon Telegr & Teleph Corp <Ntt> 認証通信方法および認証通信装置
US7403623B2 (en) * 2002-07-05 2008-07-22 Universite Libre De Bruxelles High-rate quantum key distribution scheme relying on continuously phase and amplitude-modulated coherent light pulses
FR2853894B1 (fr) * 2003-04-16 2007-02-23 Cerexagri Procede de fabrication d'hydroxosulfates de cuivre et compositions fongicides cupriques les contenant
JP2005117511A (ja) 2003-10-10 2005-04-28 Nec Corp 量子暗号通信システム及びそれに用いる量子暗号鍵配布方法
US7359512B1 (en) * 2004-03-10 2008-04-15 Verizon Corporate Services Group Inc. Authentication in a quantum cryptographic system
US7181011B2 (en) 2004-05-24 2007-02-20 Magiq Technologies, Inc. Key bank systems and methods for QKD
US8315387B2 (en) * 2004-11-05 2012-11-20 Nucrypt Llc System and method for data transmission over arbitrary media using physical encryption
GB0512229D0 (en) 2005-06-16 2005-07-27 Hewlett Packard Development Co Quantum key distribution apparatus & method
GB2430123B (en) * 2005-09-09 2008-01-23 Toshiba Res Europ Ltd A quantum communication system
US7889868B2 (en) 2005-09-30 2011-02-15 Verizon Business Global Llc Quantum key distribution system
JP2007116216A (ja) * 2005-10-18 2007-05-10 Hitachi Ltd 量子認証方法およびシステム
US7248695B1 (en) 2006-02-10 2007-07-24 Magiq Technologies, Inc. Systems and methods for transmitting quantum and classical signals over an optical network
JP2009534923A (ja) 2006-04-18 2009-09-24 マジック テクノロジーズ,インコーポレーテッド 量子暗号ネットワークに対するユーザ認証と鍵管理
CA2648780C (en) 2006-04-25 2013-07-16 Stephen Laurence Boren Dynamic distributed key system and method for identity management, authentication servers, data security and preventing man-in-the-middle attacks
US8270841B2 (en) 2006-08-04 2012-09-18 Mitsubishi Electric Corporation Quantum communication apparatus, quantum communication system and quantum communication method
US9253643B2 (en) * 2009-03-05 2016-02-02 Interdigital Patent Holdings, Inc. Method and apparatus for H(e)NB integrity verification and validation
GB0917060D0 (en) * 2009-09-29 2009-11-11 Qinetiq Ltd Methods and apparatus for use in quantum key distribution
KR101351012B1 (ko) * 2009-12-18 2014-01-10 한국전자통신연구원 다자간 양자 통신에서의 사용자 인증 방법 및 장치
US8433070B2 (en) * 2010-05-17 2013-04-30 Raytheon Bbn Technologies Corp. Systems and methods for stabilization of interferometers for quantum key distribution
US8483394B2 (en) * 2010-06-15 2013-07-09 Los Alamos National Security, Llc Secure multi-party communication with quantum key distribution managed by trusted authority
TW201201556A (en) 2010-06-29 2012-01-01 Chunghwa Telecom Co Ltd Construction structure of quantum encryption service network
EP2518932A3 (en) 2010-10-05 2015-11-18 Brandenburgische Technische Universität Cottbus-Senftenberg A method of password-based authentication and session key agreement for secure data transmission, a method for securely transmitting data, and an electronic data transmission system
KR20120071883A (ko) * 2010-12-23 2012-07-03 한국전자통신연구원 양자 비밀 공유 프로토콜을 위한 양자 인증 방법 및 장치
US9480241B2 (en) * 2011-07-05 2016-11-01 Eric James Holmstrom Retractable leash system
US8699712B2 (en) 2011-09-02 2014-04-15 Blackberry Limited Randomization of plain text for GSM SACCH
US8693691B2 (en) 2012-05-25 2014-04-08 The Johns Hopkins University Embedded authentication protocol for quantum key distribution systems
WO2014035696A2 (en) * 2012-08-30 2014-03-06 Los Alamos National Security, Llc Multi-factor authentication using quantum communication
CN102946313B (zh) * 2012-10-08 2016-04-06 北京邮电大学 一种用于量子密钥分配网络的用户认证模型和方法
CN102904726B (zh) * 2012-11-08 2015-07-01 中国科学院信息工程研究所 用于量子密钥分配系统的经典信道消息认证方法和装置
CN103338448A (zh) * 2013-06-07 2013-10-02 国家电网公司 一种基于量子密钥分发的无线局域网安全通信方法
US10291399B2 (en) * 2013-09-30 2019-05-14 Traid National Security, LLC Quantum-secured communications overlay for optical fiber communications networks
US10574461B2 (en) * 2013-09-30 2020-02-25 Triad National Security, Llc Streaming authentication and multi-level security for communications networks using quantum cryptography
JP6165637B2 (ja) * 2014-01-08 2017-07-19 株式会社東芝 量子通信装置、量子通信方法及びプログラム
US9577825B2 (en) * 2014-07-22 2017-02-21 Raytheon Company Quantum key distribution via pulse position modulation

Patent Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080101612A1 (en) * 2004-08-31 2008-05-01 Hideki Imai Quantum Key Distribution Protocol
US20070036353A1 (en) * 2005-05-31 2007-02-15 Interdigital Technology Corporation Authentication and encryption methods using shared secret randomness in a joint channel
US20130315306A1 (en) * 2007-09-14 2013-11-28 General Instrument Corporation Personal Video Recorder
US20110213979A1 (en) * 2008-10-27 2011-09-01 Qinetiq Limited Quantum key distribution
US20100260161A1 (en) * 2009-04-11 2010-10-14 Qualcomm Incorporated Apparatus and methods for interleaving in a forward link only system
US20110126011A1 (en) * 2009-11-24 2011-05-26 Electronics And Telecommunications Research Institute Method of user-authenticated quantum key distribution
US20130068186A1 (en) * 2010-03-31 2013-03-21 Haldor Topsoe A/S Method and system for operating a pressure ignition engine
US20130083926A1 (en) * 2011-09-30 2013-04-04 Los Alamos National Security, Llc Quantum key management

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3259870A4 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI738836B (zh) * 2016-10-14 2021-09-11 香港商阿里巴巴集團服務有限公司 量子資料密鑰協商系統及量子資料密鑰協商方法
CN109327308A (zh) * 2018-10-30 2019-02-12 成都信息工程大学 一种具有双向身份认证功能的量子密钥分发方法及系统

Also Published As

Publication number Publication date
AU2016220364B2 (en) 2020-05-14
CN105991285A (zh) 2016-10-05
EP3259870A4 (en) 2018-03-28
AU2016220364A2 (en) 2019-02-14
TW201631509A (zh) 2016-09-01
TWI689837B (zh) 2020-04-01
US10038554B2 (en) 2018-07-31
JP2018509117A (ja) 2018-03-29
CN105991285B (zh) 2019-06-11
US20160241396A1 (en) 2016-08-18
CA2976784A1 (en) 2016-08-25
EP3259870A1 (en) 2017-12-27
JP6619455B2 (ja) 2019-12-11
US10432396B2 (en) 2019-10-01
AU2016220364A1 (en) 2017-09-28
US20190052460A1 (en) 2019-02-14
BR112017017488A2 (pt) 2018-04-17
KR20170118190A (ko) 2017-10-24

Similar Documents

Publication Publication Date Title
US10432396B2 (en) Method, apparatus, and system for identity authentication
CN106411521B (zh) 用于量子密钥分发过程的身份认证方法、装置及系统
US10389525B2 (en) Method, apparatus, and system for quantum key distribution, privacy amplification, and data transmission
CN106470101B (zh) 用于量子密钥分发过程的身份认证方法、装置及系统
CN111147225A (zh) 基于双密值和混沌加密的可信测控网络认证方法
HK1229575A1 (en) Identity authentication methods, devices and system applied to quantum key distribution process
HK1229575A (en) Identity authentication methods, devices and system applied to quantum key distribution process
BR112017017488B1 (pt) Método de autenticação de identidade para um processo de distribuição de chave quântica, dispositivo de autenticação de identidade para um processo de distribuição de chave quântica, e meio de armazenamento legível por computador não transitório
HK1229575B (zh) 用於量子密钥分发过程的身份认证方法、装置及系统
HK1233792A1 (en) Authentication method, device and system for quantum key distribution process
HK1233792A (en) Authentication method, device and system for quantum key distribution process
HK1233792B (zh) 用於量子密钥分发过程的身份认证方法、装置及系统
HK1234915A (en) Authentication method, apparatus and system used in quantum key distribution process
HK1234915A1 (en) Authentication method, apparatus and system used in quantum key distribution process

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16752796

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2976784

Country of ref document: CA

ENP Entry into the national phase

Ref document number: 2017560880

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

REG Reference to national code

Ref country code: BR

Ref legal event code: B01A

Ref document number: 112017017488

Country of ref document: BR

ENP Entry into the national phase

Ref document number: 20177026173

Country of ref document: KR

Kind code of ref document: A

REEP Request for entry into the european phase

Ref document number: 2016752796

Country of ref document: EP

ENP Entry into the national phase

Ref document number: 2016220364

Country of ref document: AU

Date of ref document: 20160205

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 112017017488

Country of ref document: BR

Kind code of ref document: A2

Effective date: 20170815