IP Library Granted Patent US 12,556,382
Granted Patent B2
US 12,556,382 · App. 17/886,625 · Granted Feb 17, 2026

Quantum network and a quantum authentication server

Inventors: Robert Ian Woodward (Cambridge, GB); Benjamin Marsh (Cambridge, GB); James F. Dynes (Cambridge, GB); Zhiliang Yuan (Cambridge, GB); Andrew James Shields (Cambridge, GB)
Assignee: Kabushiki Kaisha Toshiba
H04L9/0855H04L9/085H04L9/0866
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,382
App. No.
17/886,625
Granted
Feb 17, 2026
Kind
B2
Abstract

A server configured to provide a pre-shared key “PSK” with a first user node, to allow a first user node and a second user node to share a PSK, the server comprising: a network interface; an authentication unit; an encryption unit; a key management system and a quantum key distribution unit, the authentication unit being configured to receive a request for authentication, via the network interface, of a first channel between a first user node and the server, the quantum key distribution unit being configured to allow a quantum key to be distributed between the first user node and the server, the quantum key being sifted using communication over the authenticated first channel to establish a first quantum key for the first user and server, the key management system being configured to provide a first PSK for the first user to allow the first user to authenticate with the second user, the encryption unit being configured to encrypt the first PSK with the quantum key to send to the first user node via the network interface.

Claims (34)

1 . A server configured to provide a pre-shared key (PSK) with a first user node and a second user node, to allow the first user node and the second user node to share the PSK, the server comprising processing circuitry configured to:

receive a request for authentication of a first channel between the first user node and the server;

allow a quantum key to be distributed between the first user node and the server by performing quantum key distribution between the first user node and the server, the quantum key being sifted using communication over the first channel to establish a first quantum key between the first user node and the server;

provide a first PSK for the first user node to allow the first user node to authenticate with the second user node;

encrypt the first PSK with the quantum key to send to the first user node;

send a request for authentication of a second channel between the second user node and the server;

allow a quantum key to be distributed between the second user node and the server by performing quantum key distribution between the second user node and the server, the quantum key being sifted using communication over the second channel to establish a second quantum key between the second user node and the server; and

encrypt the first PSK with the second quantum key to send to the second user node, wherein said server is configured to be arranged in a hierarchy with respect to a plurality of further servers, and said server is further configured to send a query to another server above it in the hierarchy when said server receives a request from a user node for a shared PSK which it cannot satisfy.

2 . The server of claim 1 , wherein the processing circuitry is further configured to generate the first PSK for sharing between the first and second user nodes.

3 . The server of claim 1 , wherein the first quantum key has a first length and the processing circuitry is further configured to distribute a key which is longer than the first length, the remainder of the key being saved as at least one PSK for further authentication between the server and the first user node.

4 . The server of claim 3 , wherein the server is further configured to discard a PSK after a single use.

5 . The server of claim 1 , wherein the processing circuitry is further configured to store information indicating whether two user nodes are allowed to share a PSK, the server being further configured to accept or decline a request from a user node for obtaining a shared key by referring to the information stored in the access control unit.

6 . The server of claim 1 , wherein the server is further configured to contact a further server to determine whether to accept or decline a request from a user node to obtain a shared key.

7 . The server of claim 1 , wherein the processing circuitry is further configured to provide information to control at least one of the quantum key length, a PSK key length and information to be sent with the PSK.

8 . The server of claim 1 , wherein the processing circuitry is further configured to:

encode information on light, wherein the information is encoded by randomly selecting one state from a plurality of states to send to said user node, the light leaving said server in pulses which contain on average less than one photon; and

receive light pulses which contain on average less than one photon and decode information from said light pulses by measuring said light pulses, wherein the measurement basis for the measurement are randomly selected from a set of measurement bases to allow measurement of the states used to encode the information,

allow the server to compare the basis it used for encoding or decoding with that used by the user node for decoding or encoding, and discard the information from pulses where the encoding basis and the decoding measurement basis did not match.

9 . A network comprising a first server, a plurality of user nodes and at least one switch, the at least one switch being configured to allow selective connection between any two of said user nodes and any of said nodes and the server, the first server being a server in accordance with claim 1 , wherein the network further comprises the plurality of further servers, and wherein the first server and the plurality of further servers are arranged in a hierarchy and the first server is configured to send a query to another server above it in the hierarchy when the first server receives a request from a user node for a shared PSK which it cannot satisfy.

10 . The network of claim 9 , further comprising two servers and wherein the first user node, in response to a request for a PSK to authenticate with a second user node comprises receiving a PSK from the two servers, the first node forming a combined PSK from the two servers, the second user node also deriving the combined PSK to allow the first node and the second node to authenticate.

11 . The network of claim 9 , wherein the at least one switch is located within at least one of a server or a user node.

12 . The network of claim 9 , wherein the user node comprises at least one selected from a file server or a quantum computer.

13 . The network of claim 9 , wherein the network comprises a plurality of sub networks and said sub networks are linked by communication channels.

14 . A method of sharing a pre-shared key (PSK) between a first node and a second node in a network, the network further comprising a first server and a plurality of further servers, the first server and the plurality of further servers being arranged in a hierarchy, the method comprising:

receiving a request from the first user node for obtaining a PSK shared between the first user node and the second user node;

sending a query to another server above the first server in the hierarchy when the first server cannot satisfy the request;

receiving a request for authentication of a first channel between the first user node and the first server;

allowing a quantum key to be distributed between the first user node and the first server by performing quantum key distribution between the first user node and the server, the quantum key being sifted using communication over the first channel to establish a first quantum key between the first user node and the first server;

providing a first PSK for the first user node to allow the first user node to authenticate with the second user node;

encrypting the first PSK with the quantum key to send to the first user node;

sending a request for authentication of a second channel between the second user node and the first server;

allowing a quantum key to be distributed between the second user node and the first server by performing quantum key distribution between the second user node and the first server, the quantum key being sifted using communication over the second channel to establish a second quantum key between the second user node and the first server; and

encrypting the first PSK with the second quantum key to send to the second user node.

15 . The method of claim 14 , wherein, by performing quantum key distribution, a key is distributed between the first user node and the first server that is longer than a first length to establish a first quantum key having the first length, and wherein the method further comprises saving the remainder of the key as at least one PSK for further authentication between the first server and the first user node.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE AGREEMENT PREVIOUSLY RECORDED ON REEL 063674 FRAME 0384. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 24, 2023
From: WOODWARD, ROBERT IAN; MARSH, BENJAMIN; DYNES, JAMES F.; SHIELDS, ANDREW JAMES
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 063741/0491 →
CHANGE OF NAME Recorded May 18, 2023
From: TOSHIBA RESEARCH EUROPE LIMITED
To: TOSHIBA EUROPE LIMITED
Reel/Frame 063683/0543 →
CONFIRMATORY ASSIGNMENT Recorded May 18, 2023
From: TOSHIBA EUROPE LIMITED
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 063694/0699 →
DECLARATION NOTICING ASSIGNMENT BY OPERATION OF LAW Recorded May 17, 2023
From: YUAN, ZHILIANG
To: TOSHIBA EUROPE LIMITED
Reel/Frame 063673/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2023
From: WOODWARD, ROBERT IAN; MARSH, BENJAMIN; DYNES, JAMES F.; SHIELDS, ANDREW JAMES
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 063674/0384 →
Priority Claims (1)
GB 2202649 · Feb 25, 2022 · national
Continuity (1)
Related Publication 20230275755A1 · Aug 31, 2023
References Cited (38)
US 7457416B1 · Elliott · 2008 [cited by examiner]
US 8483394B2 · Nordholt et al. · 2013 [cited by applicant]
US 8738898B2 · Herwono et al. · 2014 [cited by applicant]
US 20050259825A1 · Trifonov · 2005 [cited by examiner]
US 20090175452A1 · Gelfond et al. · 2009 [cited by applicant]
US 20090316910A1 · Maeda · 2009 [cited by examiner]
US 20110231665A1 · Wiseman · 2011 [cited by applicant]
US 20130101121A1 · Nordholt · 2013 [cited by examiner]
US 20140089663A1 · Tanizawa · 2014 [cited by examiner]
US 20160218867A1 · Nordholt · 2016 [cited by examiner]
US 20160226846A1 · Fu · 2016 [cited by examiner]
US 20160234009A1 · Li · 2016 [cited by examiner]
US 20170338951A1 · Fu et al. · 2017 [cited by applicant]
US 20190379463A1 · Shields et al. · 2019 [cited by applicant]
US 20190394031A1 · Deng · 2019 [cited by examiner]
US 20220345300A1 · Inamdar · 2022 [cited by examiner]
CN 109787763A · 2019 [cited by applicant]
JP 2008306633A · 2008 [cited by applicant]
JP 2013539324A · 2013 [cited by applicant]
JP 2013544479 · 2013 [cited by applicant]
WO WO2021090025A1 · 2021 [cited by applicant]
British Combined Examination and Search Report issued Jul. 28, 2022 in GB Application No. 2202649.6 filed on Feb. 25, 2022, 5 pages. [cited by applicant]
Peev et al., “The SECOQC quantum key distribution network in Vienna”, New J. Phys. 11, 075001, 2009, 38 pages. [cited by applicant]
Wang et al., “Experimental Authentication of Quantum Key Distribution with Post-quantum Cryptography”, npj: Quantum Information, 7 pages, 2021, arXiv:2009.04662. [cited by applicant]
Constantin et al., “An FPGA Based 4 Mbps Secret Key Distillation Engine for Quantum Key Distribution Systems”, J Sign Process Syst 86, 2017, 15 pages. [cited by applicant]
Cui et al., “An authentication scheme with high throughput based on FPGA for a practical QKD system”, Optik 126, 2015, pp. 4747-4750. [cited by applicant]
Wegman et al., “New hash functions and their use in authentication and set equality”, Journal of Computer and System Sciences 22, 1981, pp. 265-279. [cited by applicant]
Shoup, “On Fast and Provably Secure Message Authentication Based on Universal Hashing”, Advances in Cryptology—CRYPTO'96, Lecture Notes in Computer Science 1109, Dec. 1996, 12 pages. [cited by applicant]
Bernstein, “The Poly1305-AES Message-Authentication Code”, Lecture Notes in Computer Science, vol. 3557, 2005, 18 pages. [cited by applicant]
Carter et al., “Universal classes of hash functions” Journal of computer and system sciences, 18(2), 1979, pp. 143-154. [cited by applicant]
Dynes et al., “Cambridge quantum network”, npj: Quantum Information, 5(1), 2019, 8 pages. [cited by applicant]
Needham et al., “Using encryption for authentication in large networks of computers”, Communications of the ACM, 21(12), Dec. 1978, pp. 993-999. [cited by applicant]
Japanese Office Action issued on Oct. 31, 2023 in Japanese Patent Application No. 2022-136134 (with unedited computer-generated English translation), 12 pages. [cited by applicant]
United Kingdom Examination Report issued Jul. 10, 2024 in United Kingdom Patent Application No. GB2202649.6, 5 pages. [cited by applicant]
Office Action mailed May 27, 2025, in Japanese Application No. 2024-116983 filed Jul. 22, 2024 (w/English translation). [cited by applicant]
Office Action mailed May 1, 2025, in United Kingdom Application No. 2202649.6. [cited by applicant]
Poppe et al., QIT4N-O-035, Draft D2.2 Technical Report on QIT4N use case part 2: Quantum Key Distribution Network (output of 4th FG-QIT4N meeting), Jun. 15-26, 2020, 55 pages. [cited by applicant]
Solomons et al., “Scalable authentication and optimal flooding in a quantum network”, Jan. 28, 2021, 17 pages. [cited by applicant]