IP Library Granted Patent US 12,574,224
Granted Patent B2
US 12,574,224 · App. 18/501,512 · Granted Mar 10, 2026

Site-to-site tunnel authentication by quantum keys

Inventors: Nageswara S. V. Rao (Oak Ridge, TN); Muneer Alshowkan (Oak Ridge, TN); Anees Al-Najjar (Knoxville, TN); Susan E. Hicks (Kingston, TN); Philip G. Evans (Clinton, TN); Joseph M. Lukens (Knoxville, TN); Nicholas A. Peters (Knoxville, TN)
Assignee: UT-BATTELLE, LLC
H04L9/0852H04L63/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,574,224
App. No.
18/501,512
Granted
Mar 10, 2026
Kind
B2
Abstract

A framework for authenticating firewall and encryption devices (FEDs) as endpoints of a secure tunnel using quantum-based secrets keys are provided. The secure tunnel is between two network sites. A quantum key distribution (QKD) subsystem is collocated, in part, with a first network site in another part, with a second network site. The QKD subsystem generates and shares at least one quantum-based secret key with respective key hosts in the first network site and second network site. Each FED obtains the same quantum-based secret key from the respective key host and authenticate each other as endpoints of the secure tunnel to be established between the first network site and the second network site through the public network. The authentication may be repeated.

Claims (36)

1 . A system for establishing an Internet Protocol Security (IPsec) tunnel through a public network, the system comprising:

a first network site comprising a first firewall and encryption device (FED) and a first key host communicatively coupled with the first FED through a first secure subnetwork;

a second network site comprising a second FED and a second key host communicatively coupled with the second FED through a second secure subnetwork; and

a quantum key distribution (QKD) subsystem collocated, in part, with the first network site and communicatively coupled with the first key host through the first secure subnetwork and, in another part, with the second network site and communicatively coupled with the second key host through the second secure subnetwork, the QKD subsystem configured to:

produce at least one quantum-based secret key; and

share the at least one quantum-based secret key with the first key host and the second key host,

wherein the first and second FEDs are configured to:

obtain a same quantum-based secret key from their respective key hosts;

authenticate each other as endpoints of the IPsec tunnel to be established between the first network site and the second network site through the public network, the authenticating being based on the obtained same quantum-based secret key;

establish the IPsec tunnel having the first FED and the second FED as authenticated endpoints by setting up security associations;

carry out encrypted network traffic between the first network site and the second network site through the established IPsec tunnel based on the security associations; and

repeatedly reauthenticate each other as the endpoints of the IPsec tunnel based on new quantum-based secret keys obtained from their respective key hosts.

2 . The system of claim 1 , wherein

the first key host is connected to a first physical port of the first FED through a first ethernet cable,

the second key host is connected to a first physical port of the second FED through a second ethernet cable, and

the IPsec tunnel is formed between a second physical port of the first FED and a second physical port of the second FED, the first physical port being different from the second physical port.

3 . The system of claim 1 , wherein the first FED and the second FED are configured to reauthenticate each other as the endpoints of the IPsec tunnel on a periodic basis.

4 . The system of claim 1 , further comprising a means for synchronizing a timing at the first key host and the second key host or the first FED and the second FED.

5 . The system of claim 1 , wherein the first key host and the second key host are configured to communicate with the respective parts of the QKD subsystem through an application programming interface.

6 . The system of claim 1 , wherein the first FED and the first key host are connected via a secure shell (SSH) connection and the second FED and the second key host are connected via another SSH connection.

7 . The system of claim 1 , wherein the parts of the QKD subsystem collocated at the respective first and second network sites are connected to each other through a dedicated single-mode optical fiber.

8 . The system of claim 1 , wherein the QKD subsystem is configured to

repeatedly produce at least one additional quantum-based secret key, and

share the at least one additional quantum-based secret key with the first key host and the second key host.

9 . The system of claim 2 , wherein network traffic is transmitted between a first secure network and a second secure network, wherein the first secure network comprises a first router, the first router is connected to a third physical port of the first FED, and the second secure network comprises a second router, the second router is connected to a third physical port of the second FED, the third physical port being different from the first physical port and the second physical port.

10 . The system of claim 9 , wherein the first FED is configured for different security zones including a first security zone and a second security zone, the first security zone comprising devices connected to the third physical port and the second security zone comprising devices connected to the first physical port, and wherein the second FED is configured for different security zones including a first security zone and a second security zone, the first security zone comprising devices connected to the third physical port and the second security zone comprising devices connected to the first physical port.

11 . The system of claim 10 , where the different security zones further comprise a third security zone comprising the IPsec tunnel.

12 . The system of claim 1 , wherein encrypted network traffic is exchanged while the endpoints of the IPsec tunnel are reauthenticated.

13 . The system of claim 1 , wherein each quantum-based secret key has a unique identifier, wherein the same quantum-based secret key is determined using the unique identifier.

14 . The system of claim 3 , wherein a repetition time for the periodic basis is defined via a user interface.

15 . The system of claim 14 , wherein the repetition time is a multiple of a time for authenticating the endpoints.

16 . The system of claim 1 , wherein the first network site and the second network site are different locations of a same company.

17 . The system of claim 1 , wherein the first network site and the second network site are different locations of sensor networks or data centers.

18 . The system of claim 1 , wherein the first key host communicates with the first FED with an application program interface and the second key host communicates with the second FED with an application program interface.

19 . The system of claim 4 , wherein the first key host and the second key host simultaneously pushes the same quantum-based secret key to the first FED and the second FED, respectively.

20 . The system of claim 1 , wherein the first key host and the second key host are configured to mark each quantum-based secret key as being used in a memory once the quantum-based secret key is obtained and restrict the quantum-based secret key from being reused.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 10, 2025
From: AL-NAJJAR, ANEES
To: UT-BATTELLE, LLC
Reel/Frame 073169/0619 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2025
From: RAO, NAGESWARA S. V.; ALSHOWKAN, MUNEER; HICKS, SUSAN E.; EVANS, PHILIP G.; LUKENS, JOSEPH M.; PETERS, NICHOLAS A.
To: UT-BATTELLE, LLC
Reel/Frame 072971/0531 →
CONFIRMATORY LICENSE Recorded Mar 14, 2024
From: UT-BATTELLE, LLC
To: U. S. DEPARTMENT OF ENERGY
Reel/Frame 066776/0139 →
Continuity (2)
Provisional Application 63422756 · Nov 4, 2022
Related Publication 20240154794A1 · May 9, 2024
References Cited (9)
US 11791994B1 · Sinha · 2023 [cited by examiner]
US 20230269075A1 · Bakopoulos · 2023 [cited by examiner]
Bennett, C. et al., “Quantum cryptography: Public key distribution and coin tossing”, Theoretical Computer Science, 2014, pp. 7-11, vol. 560. [cited by applicant]
Choi, I. et al., “Field trial of a quantum secured 10 Gb/s DWDM transmission system over a single installed fiber”, Opt Express, Sep. 2014, pp. 23121-23128, vol. 22, No. 19. [cited by applicant]
Lopez, D. et al., “Demonstration of Software Defined Network Services Utilizing Quantum Key Distribution Fully Integrated with Standard Telecommunication Network”, Quantum Rep., 2020, pp. 453-458, vol. 2, No. 3. [cited by applicant]
Wang, S. et al., “Field and long-term demonstration of a wide area quantum key distribution network”, Opt. Express, Sep. 2014, pp. 21739-21756, vol. 22, No. 18. [cited by applicant]
Evans, P. et al., “Trusted node QKD at an electrical utility”, IEEE Access, 2021, pp. 105220-105229, vol. 9. [cited by applicant]
Alshowkan, M. et al., “Reconfigurable quantum local area network over deployed fiber”, PRX Quantum, Oct. 2021, pp. 040304-1 to 040304-13, vol. 2. [cited by applicant]
Mason, A., “IPSec Overview Part Four: Internet Key Exchange (IKE)”, Cisco Press, Feb. 22, 2002, pp. 1-5. [cited by applicant]