IP Library Granted Patent US 12,244,700
Granted Patent B2
US 12,244,700 · App. 18/692,524 · Granted Mar 4, 2025

Method and apparatus for enhancing security of quantum key distribution network

Inventors: Xiongfeng Ma (Beijing, CN); Yizhi Huang (Beijing, CN)
Assignee: TSINGHUA UNIVERSITY
H04L9/0852
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,700
App. No.
18/692,524
Granted
Mar 4, 2025
Kind
B2
Abstract

Provided are a method and an apparatus for enhancing the security of a quantum key distribution network. The quantum key distribution network includes a first node, a second node, and at least one relay node, by means of which the first node and the second node implement a first stage of quantum key distribution; the first node and the second node share a first key pool, which includes at least one key; and the method is executed on either the first node or the second node. The method includes: acquiring a first key obtained after the first stage of quantum key distribution; determining the seed key from the first key pool; generating a first random string by applying, based on the seed key, a first algorithm predetermined with a correspondent node, the first random string having a length equal to that of the first key; and acquiring a second key by performing a preset first bit operation on the first key and the first random string.

Claims (24)

1. A method for enhancing security of a quantum key distribution network, wherein the quantum key distribution network comprises a first node, a second node, and at least one relay node, by means of which the first node and the second node implement a first stage of quantum key distribution, the first node and the second node share a first key pool, which comprises at least one key, and the method is executed on the first node and comprises:

acquiring a first key obtained after the first stage of quantum key distribution;

determining a seed key from the first key pool according to information that is released by the second node and corresponds to the seed key; or determining a seed key from the first key pool and then releasing information corresponding to the seed key to the second node;

generating a first random string by applying, based on the seed key, a first algorithm predetermined with the second node, the first random string having a length equal to that of the first key; and

acquiring a second key by performing a preset first bit operation on the first key and the first random string.

2. The method according to claim 1 , wherein the first algorithm is an advanced encryption standard AES key expansion algorithm.

3. The method according to claim 1 , wherein the first random string is a pseudorandom string.

4. The method according to claim 1 , wherein the first bit operation is an Exclusive OR (XOR) operation, or Exclusive NOR (ENOR) operation.

5. The method according to claim 1 , wherein performing the preset first bit operation on the first key and the first random string comprises: performing the preset first bit operation on every certain number of bits in the first key and corresponding bits in the first random string.

6. The method according to claim 1 , wherein the seed key has a length less than that of the first key.

7. The method according to claim 1 , further comprising saving the second key to the first key pool.

8. The method according to claim 1 , wherein the relay node has an upper limit of computing power which is determined based on the first algorithm.

9. The method according to claim 1 , wherein the first node and the second node sharing the first key pool comprises: the first node and the second node each has a local backup of the first key pool; and

determining the seed key from the first key pool comprises: determining the seed key from the local backup of the first key pool.

10. An apparatus for enhancing security of a quantum key distribution quantum key distribution network, wherein the quantum key distribution network comprises a first node, a second node, and at least one relay node, by means of which the first node and the second node implement a first stage of quantum key distribution, the first node and the second node share a first key pool, which comprises at least one key, and the apparatus is implemented on the first node and comprises:

means for acquiring a first key obtained after the first stage of quantum key distribution;

means for determining a seed key from the first key pool according to information that is released by the second node and corresponds to the seed key, or determining a seed key from the first key pool and then releasing information corresponding to the seed key to the second node;

means for generating a first random string by applying, based on the seed key, a first algorithm predetermined with the second node, the first random string having a length equal to that of the first key; and

means for acquiring a second key by performing a preset first bit operation on the first key and the first random string.

11. A computing device, comprising a memory and a processor, wherein the memory stores an executable code, and the processor, when executing the executable code, implements a method for enhancing security of a quantum key distribution network, wherein the quantum key distribution network comprises a first node, a second node, and at least one relay node, by means of which the first node and the second node implement a first stage of quantum key distribution, the first node and the second node share a first key pool, which comprises at least one key, and the method is executed on the first node and comprises:

acquiring a first key obtained after the first stage of quantum key distribution;

determining a seed key from the first key pool according to information that is released by the second node and corresponds to the seed key; or determining a seed key from the first key pool and then releasing information corresponding to the seed key to the second node;

generating a first random string by applying, based on the seed key, a first algorithm predetermined with the second node, the first random string having a length equal to that of the first key; and

acquiring a second key by performing a preset first bit operation on the first key and the first random string.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2024
From: MA, XIONGFENG; HUANG, YIZHI
To: TSINGHUA UNIVERSITY
Reel/Frame 066802/0233 →
Priority Claims (1)
CN 202111131691.5 · Sep 26, 2021 · national
Continuity (1)
Related Publication 20240333487A1 · Oct 3, 2024
References Cited (6)
US 8774415B2 · Baba · 2014 [cited by examiner]
US 11095439B1 · Vakili · 2021 [cited by applicant]
US 20130051559A1 · Baba · 2013 [cited by examiner]
CN 109756329A · 2019 [cited by applicant]
CN 113179514A · 2021 [cited by applicant]
CN 113765663A · 2021 [cited by applicant]