IP Library Granted Patent US 11,424,918
Granted Patent B2
US 11,424,918 · App. 16/403,462 · Granted Aug 23, 2022

Method of operation of a trusted node software in a quantum key distribution system

Inventors: Eric Hay (Arlington, VA); Nino Walenta (Geneva, CH); Donald T. Hayford (Columbus, OH)
Assignee: QUANTUMXCHANGE, INC.
H04L9/0855G06F9/45558H04L9/0822H04L9/0838H04L9/0858H04L9/14H04L63/062G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,424,918
App. No.
16/403,462
Granted
Aug 23, 2022
Kind
B2
Abstract

A trusted node, for quantum key distribution, has a quantum key engine, a quantum key controller and a trusted node controller. The quantum key engine exchanges quantum keys. The quantum key controller directs encryption and decryption. The trusted node controller directs the quantum key controller and the quantum key engine, and has no direct access to keys and data protected by the system, including unencrypted quantum keys.

Claims (46)

1. A trusted node (TN) for quantum key distribution (QKD), comprising:

a quantum key engine (QKE) to exchange quantum keys with other trusted nodes via a quantum channel;

a quantum key controller (QKC) comprising one or more processors to handle the quantum keys, direct encryption using the quantum keys and direct decryption using the quantum keys;

a trusted node controller (TNC) comprising one or more processors to direct the quantum key controller and the quantum key engine to perform quantum key exchanges with other trusted nodes, encrypted communication with other trusted nodes, and encrypted communication among blades in the trusted node, wherein no unencrypted quantum key is accessible to the trusted node controller;

the trusted node controller is to direct a first blade, comprising a first quantum key controller and a first quantum key engine, in the trusted node, to receive data comprising a first key, encrypted by a first quantum key exchanged with a preceding trusted node, decrypt using the first quantum key, re-encrypt using a shelf key, and send the data comprising the first key encrypted by the shelf key to a second blade comprising a second quantum key controller and a second quantum key engine in the trusted node; and

the trusted node controller is to direct the second blade to decrypt using the shelf key, the data comprising the first key encrypted by the shelf key, re-encrypt using a second quantum key exchanged with a succeeding trusted node, and send the data comprising the first key encrypted using the second quantum key to the succeeding trusted node.

2. The trusted node of claim 1 , wherein shelf keys are used for the encrypted communication among the blades in the trusted node.

3. The trusted node of claim 1 , further comprising:

the trusted node controller is to support multiple tenants per trusted node and multiple trusted nodes per tenant in a quantum communication network comprising the trusted node and further trusted nodes.

4. The trusted node of claim 1 , further comprising:

a routing manager, cooperative with the trusted node controller to manage node discovery, route tables and routing of key transactions for a quantum communication network comprising the trusted node and further trusted nodes.

5. The trusted node of claim 1 , further comprising:

the trusted node controller implemented as a virtual machine.

6. The trusted node of claim 1 , further comprising:

two or more switch processors to control switches of the trusted node and host the trusted node controller as fault-tolerant.

7. A method of operating a trusted node (TN) for quantum key distribution (QKD), comprising:

exchanging, through a quantum key engine (QKE) of the trusted node and via a quantum channel, quantum keys with other trusted nodes;

handling, through a quantum key controller (QKC) of the trusted node, the quantum keys;

directing, through a trusted node controller (TNC), the quantum key controller and the quantum key engine to perform the exchanging the quantum keys, encrypted communication with the other trusted nodes, encryption using the quantum keys and decryption using the quantum keys, and encrypted communication among blades in the trusted node, wherein each of one or more processors of the trusted node controller cannot and does not read, write, send nor receive an unencrypted quantum key;

directing, by the trusted node controller, a first blade, comprising a first quantum key controller and a first quantum key engine, in the trusted node, to receive data comprising a first key, encrypted by a first quantum key exchanged with a preceding trusted node, decrypt using the first quantum key, re-encrypt using a shelf key, and send the data comprising the first key encrypted by the shelf key to a second blade comprising a second quantum key controller and a second quantum key engine in the trusted node; and

directing, by the trusted node controller, the second blade to decrypt using the shelf key, the data comprising the first key encrypted by the shelf key, re-encrypt using a second quantum key exchanged with a succeeding trusted node, and send the data comprising the first key encrypted using the second quantum key to the succeeding trusted node.

8. The method of claim 7 , further comprising:

using one or more shelf keys for the encrypted communication among the blades in the trusted node.

9. The method of claim 7 , further comprising:

supporting multiple tenants per trusted node and multiple trusted nodes per tenant in a quantum communication network comprising the trusted node and further trusted nodes.

10. The method of claim 7 , further comprising:

managing, through the trusted node controller, node discovery, route tables and routing of key transactions for a quantum communication network comprising the trusted node and further trusted nodes.

11. The method of claim 7 , further comprising:

hosting, through two or more switch processors of the trusted node, the trusted node controller as a fault-tolerant virtual machine.

12. A tangible, non-transitory, computer-readable media having instructions thereupon which, when executed by a processor, cause the processor to perform a method comprising:

exchanging, through a quantum key engine (QKE) of the trusted node and via a quantum channel, quantum keys with other trusted nodes;

handling, through a quantum key controller (QKC) of the trusted node, the quantum keys;

directing, through a trusted node controller (TNC), the quantum key controller and the quantum key engine to perform the exchanging the quantum keys, encrypted communication with the other trusted nodes, encryption using the quantum keys and decryption using the quantum keys, and encrypted communication among blades in the trusted node, wherein the trusted node controller has no direct access to unencrypted quantum keys;

directing, by the trusted node controller, a first blade in the trusted node, to receive data comprising a first key, encrypted by a first quantum key exchanged with a preceding trusted node, decrypt using the first quantum key, re-encrypt using a shelf key, and send the data comprising the first key encrypted by the shelf key to a second blade in the trusted node; and

directing, by the trusted node controller, the second blade to decrypt using the shelf key, the data comprising the first key encrypted by the shelf key, re-encrypt using a second quantum key exchanged with a succeeding trusted node, and send the data comprising the first key encrypted using the second quantum key to the succeeding trusted node.

13. The computer-readable media of claim 12 , wherein the method further comprises:

using one or more shelf keys for the encrypted communication among the blades in the trusted node.

14. The computer-readable media of claim 12 , wherein the method further comprises:

supporting multiple tenants by the trusted node and multiple trusted nodes per tenant in a quantum communication network comprising the trusted node and further trusted nodes.

15. The computer-readable media of claim 12 , wherein the method further comprises:

managing, through the trusted node controller, node discovery, route tables and routing of key transactions for a quantum communication network comprising the trusted node and further trusted nodes.

16. The computer-readable media of claim 12 , wherein the method further comprises:

hosting the trusted node controller as a virtual machine.

17. The computer-readable media of claim 12 , wherein the method further comprises:

controlling switches of the trusted node; and

hosting the trusted node controller as fault-tolerant.

Assignments (2)
SECURITY INTEREST Recorded Jan 11, 2021
From: QUANTUMXCHANGE, INC.
To: M/C INVESTORS LLC, AS COLLATERAL AGENT
Reel/Frame 054882/0037 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2020
From: HAY, ERIC; WALENTA, NINO; HAYFORD, DONALD T.
To: QUANTUMXCHANGE, INC.
Reel/Frame 052336/0981 →
Continuity (1)
Related Publication 20210044433A1 · Feb 11, 2021
Cited By (3)
US 12,341,880 US 12,348,623 US 12,706,741