IP Library Granted Patent US 12,250,300
Granted Patent B2
US 12,250,300 · App. 17/886,528 · Granted Mar 11, 2025

Authentication method and system, a quantum communication network, and a node for quantum communication

Inventors: Robert Ian Woodward (Cambridge, GB); Benjamin Marsh (Cambridge, GB); Joseph Dolphin (Cambridge, GB); James F. Dynes (Cambridge, GB); Zhiliang Yuan (Cambridge, GB); Andrew James Shields (Cambridge, GB)
Assignee: Kabushiki Kaisha Toshiba
H04L9/0852H04L9/3228H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,250,300
App. No.
17/886,528
Granted
Mar 11, 2025
Kind
B2
Abstract

An authentication method for quantum communication between two nodes, the method comprising: applying a hash function to a message to obtain a hash code, wherein the hash function is a Poly1305; applying a one-time pad cipher to the hash code to obtain a message authentication code (MAC); and authenticating the message exchanged between the two nodes using the MAC.

Claims (67)

1. An authentication method for quantum communication between two nodes, the method comprising:

applying a hash function to a message to obtain a hash code;

applying a one-time pad cipher to the hash code to obtain a message authentication code (MAC); and

authenticating the message exchanged between the two nodes using the MAC,

wherein the hash function is applied using a first key,

the one-time pad cipher is applied using a second key, and

each of the first key and the second key is a secret key that is shared between the two nodes.

2. The method according to claim 1 , wherein the two nodes are connected via a quantum communication channel, wherein information is encoded on weak light pulses, wherein the two nodes are connected via a classical communication channel, and wherein the message is exchanged via the classical communication channel.

3. The method according to claim 1 , wherein the hash function is applicable to a message of any length and wherein the hash function is configured to produce a fixed length hash code.

4. The method according to claim 1 , wherein applying the hash function comprises:

processing each block of the message, wherein the message comprises a plurality of blocks;

accumulating the result of the processing for each block in an accumulator; and

deriving the hash code from the accumulator.

5. The method according to claim 1 , wherein authenticating the message comprises:

transmitting an authentication frame interleaved with a data frame,

wherein the authentication frame comprises the MAC, and

wherein the data frame comprises the message.

6. The method according to claim 5 , wherein authenticating the message further comprises:

transmitting a subsequent authentication frame interleaved with a subsequent data frame, the subsequent authentication frame comprising a subsequent MAC, wherein the subsequent MAC is used to authenticate the subsequent data frame and the authentication frame.

7. The method according to claim 5 , wherein authenticating the message further comprises:

transmitting a replica of the authentication and data frame, wherein, responsive to the authentication and data frame failing authentication, the replica of the authentication and data frame is authenticated.

8. The method according to claim 7 , wherein the replica of the authentication and data frames each comprise a label indicating that said frame is a replica.

9. The method according to claim 1 , wherein the first key is unique.

10. The method according to claim 1 , further comprising:

exchanging the first key and/or the second key using quantum key distribution.

11. A method for quantum communication between two nodes, the method comprising:

exchanging a quantum key distribution key on a quantum communication channel, wherein information exchanged on the quantum communication channel is encoded on weak light pulses;

exchanging a message on a classical communication channel; and

authenticating the exchanged message, wherein authenticating the exchanged message comprises:

applying a hash function to the message to obtain a hash code, wherein applying the hash function comprises:

processing each block of the message, wherein the message comprises a plurality of blocks, accumulating each processed block in an accumulator, and deriving the hash code from the accumulator;

applying a one-time pad cipher to the hash code to obtain a message authentication code (MAC); and

authenticating the message exchanged between the two nodes using the MAC,

wherein the hash function is applied using a first key,

the one-time pad cipher is applied using a second key, and

each of the first key and the second key is a secret key that is shared between the two nodes.

12. The method according to claim 11 , further comprising:

deriving a result from the exchanged message;

authenticating the message according to the method of claim 11 ; and

responsive to the message being authenticated, indicating that the result is useable.

13. The method according to claim 12 , wherein indicating that the result is authenticated comprises:

labelling the result as unauthenticated and then removing the label after authentication; or

labelling the result as authenticated after authentication.

14. The method according to claim 11 , wherein the message comprises at least one of: quantum key distribution protocol information; a quantum key distribution hardware control signal; and an application message.

15. The method according to claim 11 , wherein authenticating the exchanged message comprises:

transmitting the message and the obtained MAC;

determining a further MAC from the received message, wherein determining the further MAC comprises:

obtaining a further hash code by applying the hash function to the received message using the first key; and

applying a one-time pad cipher to the further hash code using the second key to obtain a further MAC; and

comparing the further MAC with the received MAC, such that the message is authenticated when the further MAC corresponds to the received MAC.

16. A quantum communication network for communication between two nodes comprising:

a quantum communication channel that connects the two nodes, wherein information is encoded on weak light pulses;

a classical communication channel that connect the two nodes; and

an authentication engine configured to authenticate the classical communication channel using the authentication method according to claim 1 .

17. A node for quantum communication, the node comprising:

a quantum key distribution system; and

an authentication engine,

wherein the authentication engine is configured to perform the method according to claim 1 .

18. A node for quantum communication, the node comprising:

a quantum key distribution system; and

an authentication engine,

wherein the authentication engine is configured to:

receive a message and a MAC;

determine a further MAC from the received message, wherein determining the further MAC comprises:

obtaining a further hash code by applying a hash function to the received message using a first key; and

applying a one-time pad cipher to the further hash code using a second key to obtain a further MAC; and

compare the further MAC with the received MAC, such that the message is authenticated when the further MAC corresponds to the received MAC.

Assignments (4)
CHANGE OF NAME Recorded May 18, 2023
From: TOSHIBA RESEARCH EUROPE LIMITED
To: TOSHIBA EUROPE LIMITED
Reel/Frame 063683/0543 →
CONFIRMATORY ASSIGNMENT Recorded May 18, 2023
From: TOSHIBA EUROPE LIMITED
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 063694/0699 →
DECLARATION NOTICING ASSIGNMENT BY OPERATION OF LAW Recorded May 17, 2023
From: YUAN, ZHILIANG
To: TOSHIBA EUROPE LIMITED
Reel/Frame 063672/0991 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2023
From: WOODWARD, ROBERT IAN; MARSH, BENJAMIN; DOLPHIN, JOSEPH; DYNES, JAMES F.; SHIELDS, ANDREW JAMES
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 063673/0637 →
Priority Claims (1)
GB 2202652 · Feb 25, 2022 · national
Continuity (1)
Related Publication 20230275752A1 · Aug 31, 2023
References Cited (41)
US 7457416B1 · Elliott · 2008 [cited by applicant]
US 20030028672A1 · Goldstein · 2003 [cited by applicant]
US 20090316910A1 · Maeda et al. · 2009 [cited by applicant]
US 20130101121A1 · Nordholt et al. · 2013 [cited by applicant]
US 20130251145A1 · Lowans · 2013 [cited by examiner]
US 20140310530A1 · Oguma et al. · 2014 [cited by applicant]
US 20180084412A1 · Alfred · 2018 [cited by examiner]
US 20200274701A1 · Yuan · 2020 [cited by examiner]
US 20220294616A1 · Parry · 2022 [cited by examiner]
US 20230113906A1 · Montaner · 2023 [cited by examiner]
CN 114065249A · 2022 [cited by applicant]
GB 2581528A · 2020 [cited by applicant]
JP 2003196244A · 2003 [cited by applicant]
JP 2008306633A · 2008 [cited by applicant]
JP 2013098719A · 2013 [cited by applicant]
JP 2013539324A · 2013 [cited by applicant]
WO WO2015048783A1 · 2015 [cited by applicant]
Office Action issued Oct. 31, 2023, in corresponding Japanese Patent Application No. 2022-136134 (with English Translation), 12 pages. [cited by applicant]
United Kingdom Combined Search Report and Examination Report issued Aug. 23, 2022 in GB Patent Application No. 2202652.0, 6 pages. [cited by applicant]
Abidin, “On Security of Universal Hash Function Based Multiple Authentication”, Information and Communications Security: 14th International Conference ICICS 2012, Springer, 2012, pp. 303-310. [cited by applicant]
Internet Research Task Force, Y Nir and A Langley, “Request for Comments: 8439. ChaCha20 and Poly1305 for IETF Protocols”, Jun. 2018, pp. 1-46. [cited by applicant]
Delignat-Lavaud et al., “Implementing and Proving the TLS 1.3 Record Layer”, 2017 IEEE Symposium on Security and Privacy, IEEE, 2017, pp. 463-482. [cited by applicant]
Peev et al., “The SECOQC quantum key distribution network in Vienna”, New J. Phys. 11, 075001, 2009, 38 pages. [cited by applicant]
Wang et al., “Experimental Authentication of Quantum Key Distribution with Post-quantum Cryptography”, npj: Quantum Information, 7 pages, 2021, arXiv:2009.04662. [cited by applicant]
Constantin et al., “An FPGA Based 4 Mbps Secret Key Distillation Engine for Quantum Key Distribution Systems”, J Sign Process Syst 86, 2017, 15 pages. [cited by applicant]
Cui et al., “An authentication scheme with high throughput based on FPGA for a practical QKD system”, Optik 126, 2015, pp. 4747-4750. [cited by applicant]
Wegman et al., “New hash functions and their use in authentication and set equality”, Journal of Computer and System Sciences 22, 1981, pp. 265-279. [cited by applicant]
Shoup, “On Fast and Provably Secure Message Authentication Based on Universal Hashing”, Advances in Cryptology—CRYPTO'96, Lecture Notes in Computer Science 1109, Dec. 1996, 12 pages. [cited by applicant]
Bernstein, “The Poly1305—AES Message-Authentication Code”, Lecture Notes in Computer Science, vol. 3557, 2005, 18 pages. [cited by applicant]
Portmann, “Key recycling in authentication”, IEEE Transactions on Information Theory, 60(7), 2014, 20 pages. [cited by applicant]
Carter et al., “Universal classes of hash functions” Journal of computer and system sciences, 18(2), 1979, pp. 143-154. [cited by applicant]
Dynes et al., “Cambridge quantum network”, npj: Quantum Information, 5(1), 2019, 8 pages. [cited by applicant]
Needham et al., “Using encryption for authentication in large networks of computers”, Communications of the ACM, 21(12), Dec. 1978, pp. 993-999. [cited by applicant]
Extended European Search Report issued May 15, 2023 in European Patent Application No. 22190003.8, 7 pages. [cited by applicant]
Bibak et al., “Quantum Key Distribution with PRF (Hash, Nonce) achieves everlasting security”, Quantum Information Processing, vol. 20, No. 7, Jul. 1, 2021, pp. 1-18, XP 037528280. [cited by applicant]
Fujiwara et al., “High Secure Network Switch with Quantum Key Distribution System”, 2013 Conference on Lasers and Electro-Optics Pacific Rim (CLEO-PR), Jun. 30, 2023, pp. 1-2, XP 032481634. [cited by applicant]
Pacher et al., “Attacks on quantum key distribution protocols that employ non-ITS authentication”, Quantum Information Processing, vol. 15, No. 1, Nov. 13, 2015, pp. 327-362, XP 035593389. [cited by applicant]
Office Action issued Oct. 31, 2023, in Japanese Patent Application No. 2022-136105, with English-language Translation. [cited by applicant]
Bibak, K. et al., “Authentication of Variable Length Messages in Quantum Key Distribution”, EPJ Quantum Technology, 2022, 9:8, pp. 1-20. [cited by applicant]
Karonen, et al., “Is Poly1305 an Information—Theoretically Secure MAC”, Cryptography Stack Exchange, [online], 2020, pp. 2-6. [cited by applicant]
DI Management, Poly135 Authenticator, Published Jan. 28, 2015, pp. 2-4. [cited by applicant]