IP Library › Granted Patent US 12,375,276
Granted Patent B2
US 12,375,276 · App. 18/314,543 · Granted Jul 29, 2025

Providing quantum key distribution key delivery proof of origin and transit

Inventors: Gert Grammel (Ditzingen, DE); Jason R. Pascucci (Milford, MA); Melchior Dirk Frederik Aelmans (Voorschoten, NL); Sabyasachi Mukhopadhyay (Bangalore, IN)
Assignee: Juniper Networks, Inc.
H04L9/3026H04L9/085H04L9/0852
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,276
App. No.
18/314,543
Granted
Jul 29, 2025
Kind
B2
Abstract

A device may generate a first polynomial and a second polynomial, and may generate, based on the first polynomial, a primary path from a first network device to a second network device via a first set of intermediate network devices. The device may generate, based on the second polynomial, a secondary path from the first network device to the second network device via a second set of intermediate network devices, and may assign a point of the first and second polynomials to the device, to each of the first set of intermediate network devices and of the second set of intermediate network devices. The device may cause the primary path to be provided from the first network device to the second network device, and may cause the secondary path to be provided from the first network device to the second network device.

Claims (68)

1. A method, comprising:

generating, by a device, a first polynomial with a degree and a quantity of points and a second polynomial with the degree and the quantity of points;

generating, by the device and based on the first polynomial, a primary path from a first network device to a second network device via a first set of intermediate network devices;

generating, by the device and based on the second polynomial, a secondary path from the first network device to the second network device via a second set of intermediate network devices;

assigning, by the device, a point of the first polynomial, as a share of a secret, to the device and to each of the first set of intermediate network devices;

assigning, by the device, a point of the second polynomial, as a share of the secret, to the device and to each of the second set of intermediate network devices;

causing, by the device, the primary path to be provided from the first network device to the second network device via the first set of intermediate network devices based on assigning the point of the first polynomial; and

causing, by the device, the secondary path to be provided from the first network device to the second network device via the second set of intermediate network devices based on assigning the point of the second polynomial.

2. The method of claim 1 , wherein the first network device is configured to provide a packet to the second network device via the primary path and via the secondary path.

3. The method of claim 1 , wherein the first set of intermediate network devices is configured to calculate a first cumulative value associated with a first key, and

wherein the second set of intermediate network devices is configured to calculate a second cumulative value associated with a second key.

4. The method of claim 3 , further comprising:

receiving the first cumulative value and the second cumulative value from the second network device.

5. The method of claim 4 , further comprising:

determining whether the first cumulative value and the second cumulative value are verified; and

selectively:

validating the first key and the second key based on the first cumulative value and the second cumulative value being verified, or

invalidating the first key or the second key based on the first cumulative value and the second cumulative value not being verified.

6. The method of claim 5 , further comprising:

revoking the first key or the second key based on invalidating the first key or the second key.

7. The method of claim 4 , further comprising:

verifying that the first cumulative value and the second cumulative value are associated with different paths; and

validating the first key and the second key based on verifying that the first cumulative value and the second cumulative value are associated with different paths.

8. A device, comprising:

one or more memories; and

one or more processors to:

generate a first polynomial with a degree and a quantity of points and a second polynomial with the degree and the quantity of points;

generate, based on the first polynomial, a primary path from a first network device to a second network device via a first set of intermediate network devices;

generate, based on the second polynomial, a secondary path from the first network device to the second network device via a second set of intermediate network devices,

wherein the first network device is configured to provide a packet to the second network device via the primary path and via the secondary path;

assign a point of the first polynomial, as a share of a secret, to the device and to each of the first set of intermediate network devices;

assign a point of the second polynomial, as a share of the secret, to the device and to each of the second set of intermediate network devices;

cause the primary path to be provided from the first network device to the second network device via the first set of intermediate network devices based on assigning the point of the first polynomial; and

cause the secondary path to be provided from the first network device to the second network device via the second set of intermediate network devices based on assigning the point of the second polynomial.

9. The device of claim 8 , wherein the first set of intermediate network devices is configured to calculate a first cumulative value associated with a first key,

wherein the second set of intermediate network devices is configured to calculate a second cumulative value associated with a second key, and

wherein the first cumulative value is independent of the first key and the second cumulative value is independent of the second key.

10. The device of claim 9 , wherein the one or more processors are further configured to:

verify, based on the first cumulative value and the second cumulative value, that the first network device retrieved the first key from a different source than a source of the second key retrieved by the second network device.

11. The device of claim 8 , wherein a point of the first polynomial assigned to each of the first set of intermediate network devices corresponds to an intermediate network device of the first set of intermediate network devices provided along the primary path.

12. The device of claim 8 , wherein a point of the second polynomial assigned to each of the second set of intermediate network devices corresponds to an intermediate network device of the second set of intermediate network devices provided along the secondary path.

13. The device of claim 8 , wherein the first network device is a first key management entity at a first end point of a quantum link, and

wherein the second network device is a second key management entity at a second end point of the quantum link.

14. The device of claim 8 , wherein the primary path is associated with a first quantum link and the secondary path is associated with a second quantum link.

15. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

generate a first polynomial with a degree and a quantity of points and a second polynomial with the degree and the quantity of points;

generate, based on the first polynomial, a primary path from a first network device to a second network device via a first set of intermediate network devices;

generate, based on the second polynomial, a secondary path from the first network device to the second network device via a second set of intermediate network devices,

wherein the primary path is associated with a first quantum link and the secondary path is associated with a second quantum link;

assign a point of the first polynomial, as a share of a secret, to the device and to each of the first set of intermediate network devices;

assign a point of the second polynomial, as a share of the secret, to the device and to each of the second set of intermediate network devices;

cause the primary path to be provided from the first network device to the second network device via the first set of intermediate network devices based on assigning the point of the first polynomial; and

cause the secondary path to be provided from the first network device to the second network device via the second set of intermediate network devices based on assigning the point of the second polynomial.

16. The non-transitory computer-readable medium of claim 15 , wherein the first set of intermediate network devices is configured to calculate a first cumulative value associated with a first key, and

wherein the second set of intermediate network devices is configured to calculate a second cumulative value associated with a second key.

17. The non-transitory computer-readable medium of claim 16 , wherein the one or more instructions further cause the device to:

receive the first cumulative value and the second cumulative value from the second network device.

18. The non-transitory computer-readable medium of claim 17 , wherein the one or more instructions further cause the device to:

determine whether the first cumulative value and the second cumulative value are verified; and

selectively:

validate the first key and the second key based on the first cumulative value and the second cumulative value being verified, or

invalidate the first key or the second key based on the first cumulative value and the second cumulative value not being verified.

19. The non-transitory computer-readable medium of claim 18 , wherein the one or more instructions further cause the device to:

revoke the first key or the second key based on invalidating the first key or the second key.

20. The non-transitory computer-readable medium of claim 17 , wherein the one or more instructions further cause the device to:

verify that the first cumulative value and the second cumulative value are associated with different paths; and

validate the first key and the second key based on verifying that the first cumulative value and the second cumulative value are associated with different paths.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2023
From: GRAMMEL, GERT; PASCUCCI, JASON R.; AELMANS, MELCHIOR DIRK FREDERIK; MUKHOPADHYAY, SABYASACHI
To: JUNIPER NETWORKS, INC.
Reel/Frame 063591/0564 →
Continuity (1)
Related Publication 20240380587A1 · Nov 14, 2024
References Cited (10)
US 11082406B2 · Tzur-David · 2021 [cited by examiner]
US 20160315921A1 · Dara · 2016 [cited by examiner]
US 20180241548A1 · Dolev · 2018 [cited by examiner]
US 20190260667A1 · Aguado · 2019 [cited by examiner]
Aguado, A., et al., “Quantum Cryptography Networks in Support of Path Verification in Service Function Chains,” Journal of Optical Communications and Networking, Apr. 2020, vol. 12(4), 11 Pages. [cited by applicant]
Extended European Search Report for Application No. EP23183137.1, mailed Nov. 24, 2023, 10 Pages. [cited by applicant]
Brockners et al., “Proof of Transit draft-ietf-sfc-proof-of-transit-08,” JPMC, Oct. 31, 2020, 28 Pages. [cited by applicant]
Thakallapelli A., et al., “Real-time Frequency Based Reduced Order Modeling of Large Power Grid,” 2016 IEEE Power and Energy Society General Meeting (PESGM), 5 Pages, Retrieved from the Internet: [URL:https://ieeexplore… [cited by applicant]
“Quantum Key Distribution (QKD); Protocol and data format of REST-based key delivery API,” Website: https://www.etsi.org/deliver/etsi_gs/QKD/001_099/014/01.01.01_60/gs_qkd014v010101p.pdf, Feb. 2019, 22 Pages. [cited by applicant]
“Quantum Key Distribution (QKD); Control Interface for Software Defined Networks,” Websiter: https://www.etsi.org/deliver/etsi_gs/QKD/001_099/015/01.01.01_60/gs_QKD015v010101p.pdf, Mar. 2021, 38 Pages. [cited by applicant]