IP Library Granted Patent US 11,743,049
Granted Patent B2
US 11,743,049 · App. 16/799,116 · Granted Aug 29, 2023

Streaming authentication and multi-level security for communications networks using quantum cryptography

Inventors: Richard J. Hughes (Los Alamos, NM); Jane E. Nordholt (Los Alamos, NM); Charles G. Peterson (Los Alamos, NM); Kush T. Tyagi (Los Alamos, NM); Christopher C. Wipf (Los Alamos, NM); Raymond T. Newell (Los Alamos, NM); Kevin P. McCabe (Los Alamos, NM); Nicholas Dallmann (Los Alamos, NM)
Assignee: Triad National Security, LLC
H04L9/3226H04L9/0852H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,743,049
App. No.
16/799,116
Granted
Aug 29, 2023
Kind
B2
Abstract

Message authenticators for quantum-secured communications facilitate low-latency authentication with assurances of security. Low-latency message authenticators are especially valuable in infrastructure systems where security and latency constraints are difficult to satisfy with conventional non-quantum cryptography. For example, a message transmitter receives a message and derives an authentication tag for the message based at least in part on an authenticator that uses one or more quantum keys. The message transmitter outputs the message and its authentication tag. A message receiver receives a message and authentication tag for the message. The message receiver derives a comparison tag for the message based at least in part on an authenticator that uses one or more quantum keys. The message receiver checks whether the message is authentic based on a comparison of the authentication tag and the comparison tag. In example implementations, the authenticator uses stream-wise cyclic redundancy code operations.

Claims (34)

1. A computer-implemented method of quantum-secured communications comprising:

receiving a concatenation of a message and an authentication tag for the message, wherein the authentication tag is formed based on the message;

using at least one or more quantum keys in stream-wise operations to derive a comparison tag for the message, the stream-wise operations avoiding buffering, wherein derivation of the comparison tag is based on the least one or more quantum keys and occurs within an authenticator; and

checking whether the message is authentic based on a comparison of the authentication tag and the comparison tag.

2. The method of claim 1 wherein the authenticator uses cyclic redundancy code operations.

3. The method of claim 1 wherein the authenticator is a function ƒ(α) that uses a binary polynomial α(x) based on the message, an irreducible binary polynomial p of degree b, and a b-bit quantum key k of the one or more quantum keys.

4. The method of claim 3 wherein bits of the message are coefficients of the binary polynomial α(x) based on the message.

5. The method of claim 3 wherein the authenticator is based on:

ƒ(α)={[α(x)·x b ]mod p}⊕k,

where x b represents a b-bit shift, and ⊕ represents an XOR operation.

6. The method of claim 3 wherein the irreducible binary polynomial p is determined by:

receiving a primitive polynomial q of degree b;

determining a random polynomial π using the primitive polynomial q, a primitive element, and another quantum key r of the one or more quantum keys;

constructing a b-bit tuple based on the random polynomial π;

using the b-bit tuple to confirm that the quantum key r will yield a b-degree polynomial that cannot be reduced;

determining a minimum polynomial m of the random polynomial π; and

determining the irreducible polynomial based upon the minimum polynomial m and the primitive polynomial q.

7. The method of claim 3 wherein the irreducible binary polynomial p is reused in the authenticator for different messages but different values of quantum key k are used in the authenticator for the different messages.

8. The method of claim 1 wherein the computing device is part of one of:

a phasor measurement unit or phasor data concentrator in an electric grid;

a node in a high-speed trading system;

a control station in a water management system; and

a control station in an oil or gas distribution system.

9. The method of claim 1 wherein distribution of the at least one or more quantum keys occurs after the message is received.

10. The method of claim 1 wherein the message is received as part of a data stream on a single fiber connection, and wherein the method further comprises repeating the receiving, the deriving and the checking for each of one or more other messages that are received as part of other data streams multiplexed to support multi-level security on the single fiber connection.

11. The method of claim 1 wherein the authenticator uses hashing operations with Toeplitz matrices.

12. A computer-implemented method of quantum-secured communications comprising:

receiving a concatenation of a message and an authentication tag for the message, wherein the authentication tag is formed based on the message, wherein the authentication tag in derived based at least in part on at least a portion of the message and at least a first quantum key, the first quantum key comprising a random series of bits generated based at least in part on measured quantum states of photons;

using at least one or more quantum keys in stream-wise operations to derive a comparison tag for the message, the stream-wise operations avoiding buffering, wherein derivation of the comparison tag based on the least one or more quantum keys occur within an authenticator; and

checking whether the message is authentic based on a comparison of the authentication tag and the comparison tag.

13. A computer-implemented method of quantum-secured communications comprising:

receiving a concatenation of a message and an authentication tag for the message, wherein the authentication tag is formed based on the message;

using at least one or more quantum keys in stream-wise operations without holding back of the message to derive a comparison tag for the message, wherein derivation of the comparison tag based on the least one or more quantum keys occur within an authenticator; and

checking whether the message is authentic based on a comparison of the authentication tag and the comparison tag.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2020
From: HUGHES, RICHARD JOHN; NORDHOLT, JANE ELIZABETH; PETERSON, CHARLES GLEN; TYAGI, KUSH T.; WIPF, CHRISTOPHER C.; NEWELL, RAYMOND THORSON; MCCABE, KEVIN P.; DALLMANN, NICHOLAS
To: LOS ALAMOS NATIONAL SECURITY, LLC
Reel/Frame 054178/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 27, 2020
From: LOS ALAMOS NATIONAL SECURITY, LLC
To: TRIAD NATIONAL SECURITY, LLC
Reel/Frame 054180/0498 →
Continuity (3)
Continuation 15026024
Provisional Application 61884753 · Sep 30, 2013
Related Publication 20200252215A1 · Aug 6, 2020