IP Library Granted Patent US 10,574,461
Granted Patent B2
US 10,574,461 · App. 15/026,024 · Granted Feb 25, 2020

Streaming authentication and multi-level security for communications networks using quantum cryptography

Inventors: Richard John Hughes (Los Alamos, NM); Jane Elizabeth Nordholt (Los Alamos, NM); Charles Glen Peterson (Los Alamos, NM); Kush T. Tyagi (Los Alamos, NM); Christopher C. Wipf (Los Alamos, NM); Raymond Thorson Newell (Santa Fe, NM); Kevin P. McCabe (Los Alamos, NM); Nicholas Dallmann (Los Alamos, NM)
Assignee: Triad National Security, LLC
H04L9/3226H04L9/0852H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,574,461
App. No.
15/026,024
Granted
Feb 25, 2020
Kind
B2
Abstract

Message authenticators for quantum-secured communications facilitate low-latency authentication with assurances of security. Low-latency message authenticators are especially valuable in infrastructure systems where security and latency constraints are difficult to satisfy with conventional non-quantum cryptography. For example, a message transmitter receives a message and derives an authentication tag for the message based at least in part on an authenticator that uses one or more quantum keys. The message transmitter outputs the message and its authentication tag. A message receiver receives a message and authentication tag for the message. The message receiver derives a comparison tag for the message based at least in part on an authenticator that uses one or more quantum keys. The message receiver checks whether the message is authentic based on a comparison of the authentication tag and the comparison tag. In example implementations, the authenticator uses stream-wise cyclic redundancy code operations.

Claims (60)

1. A computer-implemented method of quantum-secured communications, comprising:

accessing a message;

determining, using an authenticator, an authentication tag for the message, the authentication tag being derived based on at least first and second portions of the message and at least a first quantum key, the first quantum key comprising a random series of bits generated based on measured quantum states of photons, wherein determining the authentication tag comprises:

storing a first portion of the message in a buffer accessible by the authenticator,

after storing the first portion of the message in the buffer and before storing the second portion of the message in the buffer, beginning to determine the authentication tag for the message by processing the first portion of the message using the first quantum key,

storing the second portion of the message in the buffer, and

after storing the second portion of the message in the buffer, continuing to determine the authentication tag for the message by processing the second portion of the message using the first quantum key; and

sending the message and the authentication tag to a second device via a communication medium.

2. The method of claim 1 , wherein the authenticator uses cyclic redundancy code operations.

3. The method of claim 1 , wherein the authenticator employs a function ƒ(α) that uses a binary polynomial α(x) based on the message, an irreducible binary polynomial p of degree b, and a b-bit quantum key k as the first quantum key.

4. The method of claim 3 , wherein bits of the message are coefficients of the binary polynomial a(x) based on the message.

5. The method of claim 3 , wherein the authenticator is based on:

ƒ(α)={[α( x )· x b ]mod p}⊕k,

where x b represents a b-bit shift, and ⊕ represents an XOR operation.

6. The method of claim 3 , wherein the irreducible binary polynomial p is determined by:

receiving a primitive polynomial q of degree b;

determining a random polynomial n using the primitive polynomial q, a primitive element, and another quantum key r of the one or more quantum keys;

constructing a b-bit tuple based on the random polynomial π;

using the b-bit tuple to confirm that the quantum key r will yield a b-degree polynomial that cannot be reduced;

determining a minimum polynomial m of the random polynomial π; and

determining the irreducible polynomial based upon the minimum polynomial m and the primitive polynomial q.

7. The method of claim 3 , wherein the irreducible binary polynomial p is reused in the authenticator for different messages but different values of quantum key k are used in the authenticator for the different messages.

8. The method of claim 1 , wherein a computing device implementing the method is part of one of:

a phasor measurement unit or phasor data concentrator in an electric grid;

a node in a high-speed trading system;

a control station in a water management system; or

a control station in an oil or gas distribution system.

9. The method of claim 1 , wherein quantum key distribution happens concurrently with message authentication.

10. The method of claim 1 , wherein the message and authentication tag are sent to the second device as part of a data stream via a single fiber connection, and wherein the method further comprises repeating the accessing, the determining, and the sending for each of one or more other messages that are sent as part of other data streams multiplexed to support multi-level security on the single fiber connection.

11. The method of claim 1 , wherein the authenticator uses hashing operations with Toeplitz matrices.

12. A computing device, comprising:

a receiver operable to receive a stream of data units corresponding to a message;

an authenticator configured to determine an authentication tag for the message, the authentication tag being derived based at least in part on at least a portion of the message and at least a first quantum key, the first quantum key comprising a random series of bits generated based at least in part on measured quantum states of photons, wherein the authenticator is further configured to use stream wise operations to derive the authentication tag by:

receiving, at the receiver, at least a first one of the data units in the message,

after the first one of the data units in the message has been received at the receiver and before at least a second one of the data units in the message has been received at the receiver, processing at least a first one of the data units in the message with the first quantum key, and

after processing the first one of the data units with the first quantum key, receiving, at the receiver, at least the second one of the data units, and

after receiving the second one of the data units at the receiver, processing at least the second one of the data units with the first quantum key; and

a transmitter configured to send the message and the authentication tag to a second device via a communication medium.

13. The computing device of claim 12 , wherein the authenticator is further configured to use cyclic redundancy code operations.

14. The computing device of claim 12 , wherein the authenticator is further configured to employ a function ƒ(α) that uses a binary polynomial α(x) based on the message, an irreducible binary polynomial p of degree b, and a b-bit quantum key k as the first quantum key.

15. The computing device of claim 14 , wherein the authenticator is further configured to employ bits of the message as coefficients of the binary polynomial α(x) based on the message.

16. The computing device of claim 14 , wherein the authenticator is based on:

ƒ(α)={[α( x )· x b ]mod p}⊕k,

where x b represents a b-bit shift, and ⊕ represents an XOR operation.

17. The computing device of claim 14 , wherein the authenticator is further configured to determine the irreducible binary polynomial p by:

receiving a primitive polynomial q of degree b;

determining a random polynomial n using the primitive polynomial q, a primitive element, and another quantum key r of the one or more quantum keys;

constructing a b-bit tuple based on the random polynomial π;

using the b-bit tuple to confirm that the quantum key r will yield a b-degree polynomial that cannot be reduced;

determining a minimum polynomial m of the random polynomial π; and

determining the irreducible polynomial based upon the minimum polynomial m and the primitive polynomial q.

18. The computing device of claim 14 , wherein the authenticator is further configured to reuse the irreducible binary polynomial p for different messages but to use different values of quantum key k for the different messages.

19. The computing device of claim 12 , wherein the computing device is configured to be implemented as part of one of:

a phasor measurement unit or phasor data concentrator in an electric grid;

a node in a high-speed trading system;

a control station in a water management system; or

a control station in an oil or gas distribution system.

20. The computing device of claim 12 , wherein the computing device is configured to implement quantum key distribution concurrently with message authentication.

21. The computing device of claim 12 , wherein the transmitter is further configured to send the message and authentication tag to the second device as part of a data stream via a single fiber connection.

22. The computing device of claim 12 , wherein the authenticator is further configured to use hashing operations with Toeplitz matrices.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2018
From: LOS ALAMOS NATIONAL SECURITY, LLC
To: TRIAD NATIONAL SECURITY, LLC
Reel/Frame 047354/0821 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2016
From: HUGHES, RICHARD JOHN; NORDHOLT, JANE ELIZABETH; PETERSON, CHARLES GLEN; TYAGI, KUSH T.; WIPF, CHRISTOPHER C.; NEWELL, RAYMOND THORSON; MCCABE, KEVIN P.; DALLMANN, NICHOLAS
To: LOS ALAMOS NATIONAL SECURITY, LLC
Reel/Frame 040344/0455 →
CONFIRMATORY LICENSE Recorded Jun 3, 2016
From: LOS ALAMOS NATIONAL SECURITY
To: U.S. DEPARTMENT OF ENERGY
Reel/Frame 038794/0838 →
Continuity (2)
Provisional Application 61884753 · Sep 30, 2013
Related Publication 20160248586A1 · Aug 25, 2016
Cited By (3)
US 12,309,125 US 12,341,880 US 12,580,750