IP Library Granted Patent US 8,762,728
Granted Patent B2
US 8,762,728 · App. 13/130,897 · Granted Jun 24, 2014

Method of performing authentication between network nodes

Inventor: Simon Robert Wiseman (Malvern, GB)
Assignee: Qinetiq Limited
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,762,728
App. No.
13/130,897
Granted
Jun 24, 2014
Kind
B2
Abstract

A method of authentication between first (QNodeX) and second (QNodeY) network nodes within a network suitable for implementing quantum cryptography comprises steps in which the first and second nodes each generate a cryptographic hash ([MXY]AI, [MYX]AJ) of a message ([MXY], [MYX]) using respective authentication keys (AI, AJ) shared with a third network node (QNodeW). The messages may be those exchanged between the first and second nodes during agreement of a quantum key to be used between the nodes. An authentication key to be shared by the first and second nodes may be established using the quantum key. The invention therefore allows an authentication key to be established and shared between the first and second network nodes without direct physical intervention. Networks having large numbers of network nodes may be re-keyed following replacement or maintenance of a network node much more quickly and easily than is the case where re-keying is achieved by physically supplying shared authentication keys.

Claims (23)

1. A method of establishing a plurality of shared authentication keys within a network comprising first and second key management centres (KMCs) and a plurality of other network nodes, each of which shared authentication keys is to be shared by the first KMC and a respective network node, the method comprising the steps of:

(i) supplying the first and second KMCs with a shared authentication key;

(ii) establishing a shared authentication key between the first KMC and a network node by performing authentication between the first KMC and the network node, the network node not being the second KMC, the first KMC and the network node each sharing a respective authentication key with the second KMC, and wherein

(a) each of the first KMC and the network node generates a respective message and encrypts the message using the authentication key shared with the second; KMC, wherein the first KMC and the network node directly exchange the encrypted messages and subsequently pass the exchanged encrypted messages to the second KMC;

(b) at the second KMC, the message generated and encrypted at the first KMC is decrypted, re-encrypted using the authentication key shared by the network node and the second KMC, and passed to the network node for decryption; and

(c) at the second KMC, the message generated and encrypted at the network node is decrypted, re-encrypted using the authentication key shared by the first and second KMCs, and passed to the first KMC for decryption; and

(iii) repeating step (ii) for all other network nodes.

2. A method of establishing a quantum key between first and second network nodes, the first and second network nodes sharing respective authentication keys with a third network node, the method comprising a quantum exchange step, a key agreement step and an authentication step, wherein

in the quantum exchange step, a quantum signal is exchanged between network nodes,

in the key agreement step, the first and second network nodes generate messages, the first and second network nodes exchange the messages according to the authentication step, and the first and second nodes agree a quantum key using the exchanged messages, and

in the authentication step:

(i) each of the first and second network nodes generates a respective cryptographic hash of the message it generates in the key agreement step using the authentication key shared with the third network node;

(ii) at the third network node, the cryptographic hash generated by the first network node is decrypted, re-encrypted using the authentication key shared by the second and third network nodes and passed to the second network node; and

(iii) at the third network node, the cryptographic hash generated by the second network node is decrypted, re-encrypted using the authentication key shared by the first and third network nodes and passed to the first network node,

wherein the first and second network nodes directly exchange the respective cryptographic hashes before passing them to the third network node for execution of steps (ii) and (iii).

3. A method according to claim 2 wherein the first and second network nodes each pass a respective cryptographic hash to the third network node prior to execution of steps (ii) and (iii).

4. A method according to claim 2 further comprising the step of using at least part of the quantum key to generate or update an authentication key shared by the first and second network nodes.

5. A method according to claim 2 in which the quantum signal is exchanged between the first and second network nodes.

6. The method according to claim 1 , wherein the first KMC and the network node directly exchange the respective messages before passing them to the second KMC for execution of steps (ii) and (iii).

7. The method according to claim 1 , wherein the first KMC and the network node each pass a respective message to the second KMC prior to execution of steps (ii) and (iii).

8. The method according to claim 1 , wherein

the shared authentication key between the first KMC and the network node is different than the shared authentication key between the first KMC and the second KMC, and

the shared authentication key between the first KMC and the network node is different than the shared authentication key between the network node and the second KMC.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2025
From: QUBITEKK, INC.
To: IONQ, INC.
Reel/Frame 071425/0018 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CORRECT ASSIGNMENT DOCUMENT PREVIOUSLY RECORDED AT REEL: 048853 FRAME: 0638. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 7, 2019
From: QINETIQ LIMITED
To: QUBITEKK, INC.
Reel/Frame 049988/0945 →
SECURITY INTEREST Recorded Jun 4, 2019
From: QUBITEKK, INC.
To: QINETIQ LIMITED
Reel/Frame 049362/0495 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2019
From: QINETIQ LIMITED
To: QUBITEKK, INC.
Reel/Frame 048853/0638 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2011
From: WISEMAN, SIMON ROBERT
To: QINETIQ LIMITED
Reel/Frame 026796/0346 →
Priority Claims (1)
GB 0822254.9 · Dec 5, 2008 · national
Continuity (2)
Provisional Application 61120181 · Dec 5, 2008
Related Publication 20110231665A1 · Sep 22, 2011