IP Library › Granted Patent US 12,231,548
Granted Patent B2
US 12,231,548 · App. 18/078,223 · Granted Feb 18, 2025

Adaptive qubit-based threshold handshaking for quantum safe protocols

Inventors: Ashish Kundu (San Jose, CA); Ramana Rao V. R. Kompella (Cupertino, CA)
Assignee: Cisco Technology, Inc.
H04L9/0852H04L9/0816H04L63/02H04L63/029H04L63/0464
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,548
App. No.
18/078,223
Granted
Feb 18, 2025
Kind
B2
Abstract

In one embodiment, a first device in a network receives a quantum computing power metric indicative of a maximum available compute power of quantum computers. The first device receives, from a second device in the network, a listing of cryptographic suites available on the second device. The first device selects, based on the quantum computing power metric, a particular cryptographic suite from among the listing of cryptographic suites available on the second device. The first device sends, to the second device via the network, an indication that the particular cryptographic suite is to be used to encrypt and decrypt traffic exchanged between the first device and the second device.

Claims (43)

1. A method comprising:

receiving, at a first device in a network, a quantum computing power metric indicative of a maximum available compute power of quantum computers;

receiving, at the first device and from a second device in the network, a listing of cryptographic suites available on the second device;

selecting, by the first device and based on the quantum computing power metric, a particular cryptographic suite from among the listing of cryptographic suites available on the second device; and

sending, by the first device and to the second device via the network, an indication that the particular cryptographic suite is to be used to encrypt and decrypt traffic exchanged between the first device and the second device.

2. The method as in claim 1 , further comprising:

caching, by the first device, an association between the second device and the particular cryptographic suite for use in a future traffic session.

3. The method as in claim 1 , further comprising:

forming, by the first device, encrypted traffic by encrypting at least a portion of the traffic using the particular cryptographic suite; and

transmitting, by the first device, the encrypted traffic to the second device via the network, wherein the second device uses the particular cryptographic suite to decrypt the encrypted traffic based in part on the indication sent by the first device.

4. The method as in claim 1 , wherein the maximum available compute power of quantum computers comprises a maximum qubit volume usable by any quantum computer currently available.

5. The method as in claim 1 , wherein the maximum available compute power of quantum computers comprises a maximum number of qubits usable by any quantum computer currently available.

6. The method as in claim 1 , wherein each of the listing of cryptographic suites has an associated quantum computing power threshold above which that cryptographic suite is considered vulnerable to malicious decryption.

7. The method as in claim 6 , wherein selecting the particular cryptographic suite comprises:

comparing the associated quantum computing power threshold of each of the listing of cryptographic suites to the quantum computing power metric received by the first device.

8. The method as in claim 1 , wherein the first device receives the quantum computing power metric via a secure connection with a remote service.

9. The method as in claim 1 , wherein the first device selects the particular cryptographic suite based in part on an amount of time that contents of the traffic is considered to be confidential.

10. The method as in claim 1 , wherein the first device and the second device comprise network routers.

11. An apparatus, comprising:

one or more network interfaces;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

receive a quantum computing power metric indicative of a maximum available compute power of quantum computers;

receiving, from a remote device in a network, a listing of cryptographic suites available on the remote device;

select, based on the quantum computing power metric, a particular cryptographic suite from among the listing of cryptographic suites available on the remote device; and

send, to the remote device via the network, an indication that the particular cryptographic suite is to be used to encrypt and decrypt traffic exchanged between the apparatus and the remote device.

12. The apparatus as in claim 11 , wherein the process when executed is further configured to:

cache an association between the remote device and the particular cryptographic suite for use in a future traffic session.

13. The apparatus as in claim 11 , wherein the process when executed is further configured to:

form encrypted traffic by encrypting at least a portion of the traffic using the particular cryptographic suite; and

transmit the encrypted traffic to the remote device via the network, wherein the remote device uses the particular cryptographic suite to decrypt the encrypted traffic based in part on the indication sent by the apparatus.

14. The apparatus as in claim 11 , wherein the maximum available compute power of quantum computers comprises a maximum qubit volume usable by any quantum computer currently available.

15. The apparatus as in claim 11 , wherein the maximum available compute power of quantum computers comprises a maximum number of qubits usable by any quantum computer currently available.

16. The apparatus as in claim 11 , wherein each of the listing of cryptographic suites has an associated quantum computing power threshold above which that cryptographic suite is considered vulnerable to malicious decryption.

17. The apparatus as in claim 16 , wherein the apparatus selects the particular cryptographic suite by:

comparing the associated quantum computing power threshold of each of the listing of cryptographic suites to the quantum computing power metric received by the apparatus.

18. The apparatus as in claim 11 , wherein the apparatus receives the quantum computing power metric via a secure connection with a remote service.

19. The apparatus as in claim 11 , wherein the apparatus selects the particular cryptographic suite based in part on an amount of time that contents of the traffic is considered to be confidential.

20. A tangible, non-transitory, computer-readable medium storing program instructions that cause a first device in a network to execute a process comprising:

receiving, at the first device in the network, a quantum computing power metric indicative of a maximum available compute power of quantum computers;

receiving, at the first device and from a second device in the network, a listing of cryptographic suites available on the second device;

selecting, by the first device and based on the quantum computing power metric, a particular cryptographic suite from among the listing of cryptographic suites available on the second device; and

sending, by the first device and to the second device via the network, an indication that the particular cryptographic suite is to be used to encrypt and decrypt traffic exchanged between the first device and the second device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2022
From: KUNDU, ASHISH; KOMPELLA, RAMANA RAO V. R.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 062038/0001 →
Continuity (1)
Related Publication 20240195612A1 · Jun 13, 2024
References Cited (32)
US 7853020B2 · Beal et al. · 2010 [cited by applicant]
US 9692595B2 · Lowans et al. · 2017 [cited by applicant]
US 9923923B1 · Sharifi Mehr · 2018 [cited by examiner]
US 10091170B2 · Shankar · 2018 [cited by examiner]
US 11240014B1 · Maganti et al. · 2022 [cited by applicant]
US 11322050B1 · Arbajian · 2022 [cited by examiner]
US 11399017B1 · Stapleton · 2022 [cited by examiner]
US 11695796B1 · Chen · 2023 [cited by examiner]
US 11736281B1 · Maganti · 2023 [cited by examiner]
US 20170289104A1 · Shankar · 2017 [cited by examiner]
US 20200403978A1 · Allen et al. · 2020 [cited by applicant]
US 20220101164A1 · Majumdar · 2022 [cited by examiner]
US 20220182413A1 · Benson et al. · 2022 [cited by applicant]
US 20230291555A1 · Berta · 2023 [cited by examiner]
“Post-quantum Cryptography”, online: https://www.microsoft.com/en-us/research/project/post-quantum-cryptography/, 6 pages, accessed Nov. 10, 2022, Microsoft Research. [cited by applicant]
“Quantum Volume”, online: https://en.wikipedia.org/wiki/Quantum_volume, Oct. 22, 2022, 3 pages, Wikimedia Foundation, Inc. [cited by applicant]
“Shor's Algorithm”, online: https://en.wikipedia.org/wiki/Shor%27s_algorithm, Nov. 5, 2022, 9 pages, Wikimedia Foundation, Inc. [cited by applicant]
“Post-Quantum Cryptography”, online: https://en.wikipedia.org/wiki/Post-quantum_cryptography, Nov. 8, 2022, 15 pages, Wikimedia Foundation, Inc. [cited by applicant]
Huelsing, et al, “XMSS: eXtended Merkle Signature Scheme”, Request for Comments 8391, May 2018, 74 pages, IETF Trust. [cited by applicant]
Alagic, et al, “Status Report on the Third Round of the NIST Post-Quantum Cryptography Standardization Process”, online: https://doi.org/10.6028/NIST.IR.8413-upd1, NIST IR 8413-upd1, Jul. 2022 and Sep. 2022, 102 pages, … [cited by applicant]
“Post-Quantum Cryptography”, online: https://csrc.nist.gov/projects/post-quantum-cryptography, Nov. 2022, 4 pages, National Institute of Standards and Technology. [cited by applicant]
Chu, et al., “Avoiding the Post-Quantum Cyber Apocalypse”, online: https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2021/avoiding-the-post-quantum-cyber-apocalypse, Mar. 2021, 5 pages. [cited by applicant]
Koussa, Sherif, “How to Quickly Audit Your Cryptography Usage?”, online: https://www.softwaresecured.com/how-to-quickly-audit-your-cryptography-usage/, Jul. 2015, 5 pages. [cited by applicant]
“Cryptography Audit in CI”, online: https://cryptosense.com/analyzer/cryptography-audit, accessed Dec. 2021, 2 pages. [cited by applicant]
“Automating Cryptography Inventory”, online: https://cryptosense.com/analyzer/cryptography-inventory, accessed Dec. 6, 2021, 3 pages. [cited by applicant]
“Cryptography Inventory—Building, Maintaining and Exploiting a Useful Inventory”, Whitepaper v1.0, Feb. 2020, 13 pages, Cryptosense. [cited by applicant]
“Eliminating Obsolete Transport Layer Security (TLS) Protocol Configurations”, Version 1.0, National Security Agency, Cybersecurity Information, Jan. 2021, 6 pages. [cited by applicant]
“IS Auditing Procedure Evaluation of Management Controls Over Encryption Methodologies”, Information Systems Audit and Control Association, Document p. 9, 2004, 7 pages. [cited by applicant]
“Quantum Computing and Post-Quantum Cryptography”, pp. 21-1120, National Security Agency, Quantum Computing and Post-Quantum Cryptography, Aug. 2021, 8 pages. [cited by applicant]
Fernandez-Carames, et al., “Teaching and Learning IoT Cybersecurity and Vulnerability Assessment with Shodan through Practical Use Cases”, May 2020, 25 pages, Sensors 2020, 20, 3048. [cited by applicant]
“8.4. Auditing the encryption used for FTPS, SFTP, SCP and HTTPS connections”, online: https://www.sftpplus.com/documentation/sftpplus/latest/guides/connection-security-audit.html, accessed Dec. 6, 2021, 3 pages. [cited by applicant]
“Actionable and Automated CryptographyThanks to Cryptosense!”, online: https://www.venafi.com/blog/actionable-and-automated-cryptography-thanks-cryptosense, accessed Dec. 6, 2021, 6 pages. [cited by applicant]