Multi-factor authentication using quantum communication

US9887976B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9887976-B2
Application numberUS-201314424295-A
CountryUS
Kind codeB2
Filing dateAug 16, 2013
Priority dateAug 30, 2012
Publication dateFeb 6, 2018
Grant dateFeb 6, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Multi-factor authentication using quantum communication (“QC”) includes stages for enrollment and identification. For example, a user enrolls for multi-factor authentication that uses QC with a trusted authority. The trusted authority transmits device factor information associated with a user device (such as a hash function) and user factor information associated with the user (such as an encrypted version of a user password). The user device receives and stores the device factor information and user factor information. For multi-factor authentication that uses QC, the user device retrieves its stored device factor information and user factor information, then transmits the user factor information to the trusted authority, which also retrieves its stored device factor information. The user device and trusted authority use the device factor information and user factor information (more specifically, information such as a user password that is the basis of the user factor information) in multi-factor authentication that uses QC.

First claim

Opening claim text (preview).

We claim: 1. A method of multi-factor authentication that uses quantum communication with a computer system that implements a trusted authority, the method comprising, with a user device: receiving, from the trusted authority, measuring bases specifying polarization bases that the trusted authority used to measure quantum signals received from the user device in a quantum communication session between the user device and the trusted authority, wherein the measuring bases have been obscured by device factor information associated with the user device and user factor information, wherein the device factor information is information for a hash function and the user factor information is a user password; recovering the measuring bases using the device factor information and the user factor information; and deriving secret bits that are shared between the user device and the trusted authority using the recovered measuring bases. 2. The method of claim 1 , the method further comprising, with the user device: retrieving, from the memory of the user device, an encrypted version of the user password and the device factor information; and as part of the multi-factor authentication, transmitting the encrypted version of the user password for use by the trusted authority to recover the user password. 3. The method of claim 1 wherein the multi-factor authentication includes: transmitting pulses of photons; receiving a message signed by the trusted authority; retrieving verification information from the memory of the user device; verifying the trusted authority using the verification information and the signed message. 4. The method of claim 1 wherein the recovering the measuring bases comprises: applying the hash function to the user password; and computing an exclusive-OR of the obscured measuring bases received from the trusted authority and results of applying the hash function to the user password. 5. The method of claim 1 wherein the multi-factor authentication further comprises: exchanging information for two hash functions with the trusted authority; applying one of the two hash functions to shared secret bits resulting from quantum communication and the other of the two hash functions to a user password for the user factor information to produce a verification value; transmitting the verification value; and receiving an indication of success or failure of the multi-factor authentication. 6. A computer system that implements a trusted authority, wherein the computer system is adapted to perform a method of multi-factor authentication that uses quantum communication, the computer system comprising: at least one communication connection configured to receive, from a user device, user factor information associated with a user; at least one memory; and at least one processing unit configured to: retrieve, from the memory of the computer system, device factor information associated with the user device, wherein the device factor information is information for a hash function; apply the hash function to a user password derived from the user factor information; obscure, based on the device factor information and the user factor information, measuring bases specifying polarization bases that the computer system used to measure quantum signals received from the user device in a quantum communication session with the user device, wherein the measuring bases are obscured based on results of applying the hash function to the user password; send the obscured measuring bases to the user device; and derive secret bits that are shared between the computer system and the user device using the measuring bases, wherein the secret bits are derived based on a received indication of which of the measuring bases match sending bases for the quantum communication session. 7. The computer system of claim 6 wherein the user factor information is an encrypted version of a user password, and wherein the at least one processing unit is further configured to: recover the user password from the encrypted version of the user password using a secret encryption key of the trusted authority. 8. The computer system of claim 6 wherein the at least one processing unit is configured to obscure the measuring bases based on an exclusive-OR of information indicating the measuring bases and the results of applying the hash function to the user password. 9. The computer system of claim 6 wherein the at least one processing unit is further configured to: exchange information for two hash functions with the user device; apply one of the two hash functions to the shared secret bits resulting from quantum communication and apply the other of the two hash functions to a user password derived from the user factor information to produce a comparison value; receive a verification value; compare the verification value to the comparison value; and transmit an indication of success or failure of the multi-factor authentication. 10. The computer system of claim 6 wherein functions of the trusted authority are distributed across two or more physical nodes using quantum secret sharing, and wherein the quantum communication with the user device includes quantum secret sharing between the user device and the two or more physical nodes constituting the trusted authority.

Assignees

Inventors

Classifications

  • User authentication · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • using cryptographic hash functions · CPC title

  • Electricity · mapped topic

  • Quantum cryptography (transmission systems employing electromagnetic waves other than radio waves, e.g. light, infrared H04B10/00; wavelength-division multiplex systems H04J14/02; WDM arrangements H04J14/03) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9887976B2 cover?
Multi-factor authentication using quantum communication (“QC”) includes stages for enrollment and identification. For example, a user enrolls for multi-factor authentication that uses QC with a trusted authority. The trusted authority transmits device factor information associated with a user device (such as a hash function) and user factor information associated with the user (such as an encry…
Who is the assignee on this patent?
Los Alamos Nat Security Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/08. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 06 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).