Method for quantum-secured communication
A method of encryption for quantum-secured communication includes structuring a pair of quantum-enabled hardware security modules to include an interface to a temporarily common quantum channel and an interface to a communication channel. A secret key is shared with the pair of quantum-enabled hardware security modules for a symmetrical encryption between the pair of quantum-enabled hardware security module. The secret key is obtained using quantum key distribution via the temporarily common quantum channel. The temporarily common quantum channel is disconnected from at least one of the pair of quantum-enabled hardware security modules and a communication network is structured to include at least two nodes configured to communicate using symmetrical encryption between the pair of quantum-enabled hardware security modules sharing a same secret key.
1 . A method of encryption for quantum-secured communication, comprising:
providing a pair of quantum-enabled hardware security modules that comprise,
an interface to a temporarily common quantum channel, and
an interface to a communication channel;
obtaining a secret key via the temporarily common quantum channel using quantum key distribution;
sharing the obtained secret key with the pair of quantum-enabled hardware security modules for a symmetrical encryption between the pair of quantum-enabled hardware security modules;
disconnecting the temporarily common quantum channel from at least one of the pair of quantum-enabled hardware security modules; and
providing a communication network that comprises at least two nodes configured to communicate using symmetrical encryption between the pair of quantum-enabled hardware security modules sharing a same secret key,
wherein each of the pair of quantum-enabled hardware security modules transforms a previous master key into a new master key after at least one of: (i) a predetermined period of time; and (ii) a predetermined number of data packages are exchanged between the pair of quantum-enabled hardware security modules, and
wherein the transforming of the previous master key to the new master key is determined by a temporary key negotiated between or computed by the pair of quantum-enabled hardware security modules.
2 . The method of claim 1 , further comprising:
generating a master key from a shared secret key of each of the pair of quantum-enabled hardware security modules, and
deriving session keys for encrypted communication between the pair of quantum-enabled hardware security modules using the master key.
3 . The method of claim 1 , further comprising obtaining the secret key from entangled photons, and providing each of the pair of quantum-enabled hardware security modules with a cryptographic coprocessor for generating session keys and a plurality of photon detectors integrated on a same hardware as the cryptographic coprocessor.
4 . The method of claim 1 , further comprising each of the pair of quantum-enabled hardware security modules generating an initial master key from a symmetric stretching key and the secret key, wherein the initial master key is longer than the secret key.
5 . The method according to claim 1 , wherein transforming the previous master key to the new master key includes at least one of the following steps: (i) deriving a temporary key from a current master key; (ii) transforming with a one-way-permutation and a block cipher using the temporary key; and (iii) deleting the temporary key.
6 . A device for quantum-secured communication, comprising:
a pair of quantum-enabled hardware security modules that each comprise:
a cryptographic coprocessor;
a classical communication channel; and
at least one interface configured for a common quantum channel,
wherein the cryptographic coprocessor of each of the pair of quantum-enabled hardware security modules generates a secret key from received photons exchanged via an interface to the common quantum channel,
wherein the secret key is generated in an initializing step,
wherein the cryptographic coprocessor of each of the pair of quantum-enabled hardware security modules generates a master key based on the secret key,
wherein the cryptographic coprocessor of each of the pair of quantum-enabled hardware security modules is configured for a symmetrically encrypted communication via the classical communication channel between the pair of quantum-enabled hardware security modules in a communication network,
wherein the cryptographic coprocessor of each of the pair of quantum-enabled hardware security modules transforms a previous master key (M i ) into a new master key (M i+1 ) based on a temporary key negotiated between or computed by the pair of quantum-enabled hardware security modules (qHSM) over the symmetrically encrypted channel, and
wherein the cryptographic-coprocessor of each of the pair of quantum-enabled hardware security modules generates session keys based on the master key.
7 . The device for quantum-secured communication according to claim 6 , wherein each of the pair of quantum-enabled hardware security modules further comprises an optical input and a plurality of avalanche photodetectors that are each connected to the optical input of each of the pair of quantum-enabled hardware security modules.
8 . The device for quantum-secured communication according to claim 6 , wherein the cryptographic coprocessor of each of the pair of quantum-enabled hardware security modules is configured to generate an initial master key from a symmetric stretching key and the secret key, wherein the initial master key is longer than the secret key.
9 . The device for quantum-secured communication according to claim 6 , wherein the cryptographic coprocessor of each of the pair of quantum-enabled hardware security modules is configured to transform a previous master key into a new master key after at least one of: (i) a predetermined period of time; and (ii) after a predetermined number of data packages are exchanged between the pair of quantum-enables hardware security modules.
10 . The device for quantum-secured communication according to claim 9 , wherein the cryptographic coprocessor of each of the pair of quantum-enabled hardware security modules is configured to transform the previous master key into a new master key by at least one of: (i) deriving a temporary key from a current master key; (ii) transforming with a one-way-permutation and a block cipher using the temporary key; and (iii) deleting the temporary key.