Dynamically selecting a security technique in a network

The system dynamically selects between QKD and PQC techniques to address vulnerabilities in existing cryptographic systems, ensuring robust quantum-safe cybersecurity through hybrid cryptographic operations.

WO2026062576A2PCT designated stage Publication Date: 2026-03-26L&T SEMICONDUCTOR TECHNOLOGIES LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-19
Publication Date
2026-03-26

AI Technical Summary

Technical Problem

Existing cryptographic systems, such as RSA and ECC, are vulnerable to quantum computers, and both Quantum Key Distribution (QKD) and Post-Quantum Cryptography (PQC) have limitations when used in isolation, necessitating a hybrid solution to ensure secure communications in a quantum era.

Method used

A system that dynamically selects between QKD and PQC techniques based on the type of security request, using a processor to establish quantum communication channels, generate quantum keys, perform digital signatures, and apply authentication procedures, while integrating hardware accelerators for efficient cryptographic operations.

Benefits of technology

Provides enhanced cybersecurity by leveraging both QKD for key exchange and PQC for authentication, addressing vulnerabilities and ensuring robust protection against quantum threats, with modular architecture for adaptability and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000026_0000
    Figure 00000026_0000
  • Figure 00000027_0000
    Figure 00000027_0000
  • Figure 00000028_0000
    Figure 00000028_0000
Patent Text Reader

Abstract

The embodiments herein disclose a quantum-safe security system or gateway, structured as an advanced security architecture that combines Post-Quantum Cryptography and Quantum Key Distribution for securing communications from quantum computing-based threats. The security system dynamically processes security service requests through a security service request identification module, which routes requests to either a QKD post processing module or a PQC processing module based on the nature of the request. The architecture includes a quantum-safe virtual memory and hardware accelerator drivers that enhance the efficiency of cryptographic operations by supporting optimized execution. A QKD node hardware component is included, which integrates a quantum transceiver and a secure element to facilitate secure key exchange and secure key storage. The disclosed embodiments further address known vulnerabilities in QKD systems, including man-in-the-middle attacks and Trojan-horse attacks, thereby delivering an end-to-end quantum-safe communication framework.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DYNAMICALLY SELECTING A SECURITY TECHNIQUE IN A NETWORK

[0002] BACKGROUND

[0003] Technical Field

[0004]

[0001] The embodiments disclosed herein relate to quantum-safe cyber security, and more particularly disclose an integrated quantum-safe software gateway for enhanced cybersecurity.

[0005] Related Art

[0006]

[0002] The rapid advancement of quantum computing poses a significant threat to the cryptographic systems that form the foundation of modem secure communications. Traditional public-key cryptographic methods, such as Rivest-Shamir-Adleman (RSA) and Elliptic Curve Cryptography (ECC), rely on the computational difficulty of problems like integer factorization and discrete logarithms. However, these methods are vulnerable to the capabilities of quantum computers, which can solve these problems efficiently using algorithms like Shor's. As quantum technology continues to evolve, there is a growing concern that these widely used cryptographic techniques will become obsolete, necessitating the development of quantum-resistant cryptographic solutions.

[0007]

[0003] A Quantum Key Distribution (QKD) is one of the emerging technologies designed to secure communications in the quantum era. QKD leverages the principles of quantum mechanics to enable the secure exchange of cryptographic keys between parties. The inherent security of QKD lies in the fact that any attempt to intercept the quantum key may disturb the quantum states, thereby alerting the communicating parties to the presence of an eavesdropper. Despite its theoretical security, practical implementations of QKD has many challenges as these systems are vulnerable to various types of attacks, including side-channel attacks, man-in-the-middle attacks, and other forms of physical and implementation flaws.

[0008]

[0004] In parallel, Post-Quantum Cryptography (PQC) has been developed as a class of cryptographic algorithms designed to resist attacks from quantum computers. PQC algorithms are based on hard mathematical problems that remain secure even against the computational power of quantum computing. These PQC algorithms provide an essential layer of defense to ensure that secure communications can continue in the quantum era, even as traditional cryptographic methods become compromised.

[0005] However, both QKD and PQC have their limitations when used in isolation.

[0009] QKD systems, while theoretically secure, require physical infrastructure and are susceptible to certain types of implementation vulnerabilities. PQC, on the other hand, while resistant to quantum attacks, still operates within the traditional cryptographic framework and may not fully address the unique challenges posed by quantum communication environments.

[0010]

[0006] Therefore, there is a need to address at least the above-mentioned drawbacks and any other shortcomings, or at the very least, provide a valuable alternative to the existing methods and systems.

[0011] SUMMARY

[0012]

[0007] Aspects of the example implementations may include a system for dynamically selecting a security technique in a network. The system includes a processor and a memory operatively coupled with the processor. The memory includes one or more instructions which, when executed, cause the processor to monitor data communication between one or more nodes, detect a security request associated with the data communication and determine a type of the security request. The processor dynamically selects at least one security technique from a plurality of security techniques based on the determination of the type of the service request to apply the at least one security technique in the data communication performed in the network.

[0013]

[0008] In one or more embodiments, the at least one security technique may correspond to a Quantum Key Distribution (QKD) technique and a Post-Quantum Cryptography (PQC) technique.

[0014]

[0009] In one or more embodiments, the type of security request may include an authentication request, a key establishment request, a data integrity assurance request, a confidentiality enforcement request, a secure channel setup request, and a digital signature validation request.

[0015]

[0010] In one or more embodiments, to dynamically select the at least one security technique, the processor may be configured to determine the type of the security request and perform at least one of: select the QKD technique for operations involving a cryptographic key exchange, when the type of security request corresponds to at least one of: the key establishment request, the secure channel setup request, and the confidentiality enforcement request and select the PQC technique for operations involving at least one of: a digital signatures, authentication procedures, and key encapsulation, when the type of security request comprises at least one of: the authentication request, the data integrity assurance request, and the digital signature validation request.

[0016]

[0011] In one or more embodiments, to perform the operations involving the cryptographic key exchange operations by applying the QKD technique, the processor may be configured to establish a quantum communication channel between the system and the one or more nodes, upon establishing the quantum communication channel, generate raw quantum keys based on quantum state exchanges over the quantum communication channel, process the raw quantum keys using one or more of: key sifting, error correction, privacy amplification, and QKD post-processing techniques and store the processed quantum keys in the memory.

[0017]

[0012] In one or more embodiments, to perform the operations involving the at least one of: the digital signatures, the authentication procedures, and the key encapsulation by applying the PQC technique, the processor may be configured to generate the digital signature using the PQC technique based on lattice-based, code-based, or multivariate polynomial techniques to identify a transmitting node of the one or more nodes of data, verify the digital signature to authenticate an identity of the transmitting node and perform key encapsulation to transmit a wrapped encryption key to a receiving node of the one or more nodes. The processor may be configured to perform key de-capsulation to extract the encapsulated key at the receiving node and apply the authentication procedures using the PQC technique to detect anomalies in the data.

[0018]

[0013] In one or more embodiments, to perform the operations by applying the PQC technique and the QKD technique, the processor may be further configured to establish a quantum communication channel between the one or more nodes, wherein the quantum communication channel is used to enable key generation through quantum state exchanges and generate raw quantum keys by exchanging quantum states over the established quantum communication channel between the system and the one or more nodes. The processor may be configured to process the raw quantum keys using one or more of key sifting, error correction, privacy amplification, and QKD post-processing techniques to derive quantum encryption keys for data communication and generate a digital signature using the PQC technique based on a lattice-based, code-based, or multivariate polynomial technique, wherein the digital signature is generated by incorporating the quantum encryption keys derived from the QKD technique to confirm the identity of a transmitting node involved in the data communication. The processor may be configured to verify the generated digital signature to authenticate the identity of the transmitting node, perform key encapsulation using the PQC technique to wrap an encryption key for transmission to a receiving node, perform key de-capsulation at the receiving node to extract the encryption key from the encapsulated message and apply the quantum keys generated through the QKD technique, along with the outputs of the PQC-based signature and key operations, in securing the data communication between the one or more nodes.

[0019]

[0014] In one or more embodiments, the processor may be configured to allocate storage regions using a safe virtual memory structure, store cryptographic materials within the allocated storage regions, wherein the cryptographic materials comprise the quantum keys, the lattice-based, the code-based, the multivariate polynomial technique, and parameters, control access to the storage regions based on pre-defined policies and apply memory segmentation techniques during read and write operations involving cryptographic material.

[0020]

[0015] In one or more embodiments, the processor may be configured to operate one or more hardware accelerators configured in the system to perform the at least one security technique.

[0021]

[0016] Another aspects of the example implementations may include a method for dynamically selecting a security technique in a network. The method may include monitoring, by a processor associated with a system, data communication between one or more nodes, detecting, by the processor, a security request associated with the data communication, determining, by the processor, a type of the security request and dynamically selecting, by the processor, at least one security technique from a plurality of security techniques based on the determination of the type of the service request to apply the at least one security technique in the data communication performed in the network.

[0022] BRIEF DESCRIPTION OF THE DRAWINGS

[0023]

[0017] The embodiments herein will be better understood from the following detailed description with reference to the drawings, in which:

[0024]

[0018] FIG. 1 illustrates a visual representation of common vulnerabilities in Quantum Key Distribution (QKD) systems, in accordance with prior arts.

[0025]

[0019] FIG. 2 illustrates a block diagram of an example system 202 for dynamically selecting a security technique in a network, in accordance with an embodiment hererin.

[0026]

[0020] FIG. 3 illustrates an architecture of the quantum-safe security system / gateway, which integrates a Post-Quantum Cryptography (PQC) with a QKD to provide quantum-safe cyber security according to an embodiment herein.

[0021] FIG. 4 depicts an integrated architecture of a quantum-safe security system / gateway, which combines the PQC and the QKD algorithms to secure communication across network layers according to an embodiment herein.

[0027]

[0022] FIG. 5 illustrates flow diagrams depicting a method for securing communication across network layers using a quantum-safe security system / gateway, according to an embodiment herein.

[0028]

[0023] FIG. 6 illustrates a flow chart of a method for dynamically selecting the security technique in the network, in accordance with an embodiment hererin.

[0029] DETAILED DESCRIPTION

[0030]

[0024] Various features and configuration options associated with the disclosed embodiments may be understood through non-limiting illustrations and explanations, wherein in an embodiment, a system may monitor data communication between one or more nodes, detect a security request associated with the data communication, determine a type of the security request, and dynamically select at least one security technique from a plurality of security techniques based on the determination of the type of the security request (e.g., dynamically select at least one security technique from a plurality of security techniques based on the determination of the type of the service request to apply the at least one security technique in the data communication performed in the network).

[0031]

[0025] Integration of Post-Quantum Cryptography (PQC) and Quantum Key Distribution (QKD) into a combined security framework may contribute to enhanced protection against quantum-computing -driven threats. The combined use of both QKD and PQC techniques may enable a processor to perform a digital signature operation and also conduct a cryptographic key exchange operation using quantum encryption keys (e.g., apply the quantum keys generated through the QKD technique, along with the outputs of the PQC- based signature and key operations, in securing the data communication between the one or more nodes).

[0032]

[0026] In an embodiment, a quantum-safe security gateway may utilize both PQC and QKD for protecting data flows and communication against adversaries possessing quantum computational capabilities. The processor in the gateway may determine a type of the security request, and may select the QKD technique for a key establishment request, a secure channel setup request, or a confidentiality enforcement request, and select the PQC technique for an authentication request, a data integrity assurance request, or a digital signature validation request (e.g., determine the type of the security request; and perform at least one of: select the QKD technique for operations involving a cryptographic key exchange, when the type of security request corresponds to at least one of: the key establishment request, the secure channel setup request, and the confidentiality enforcement request; and select the PQC technique for operations involving at least one of: a digital signatures, authentication procedures, and key encapsulation, when the type of security request comprises at least one of: the authentication request, the data integrity assurance request, and the digital signature validation request).

[0033]

[0027] In an embodiment, a modular architecture may be incorporated in the quantum-safe security gateway to support flexible deployment and allow introduction of new cryptographic protocols, enabling the system to remain functional and effective as quantumresistant algorithms evolve (e.g., the modular construction of the quantum-safe security gateway allows for its incorporation into pre-existing security infrastructures).

[0034]

[0028] In an embodiment, the QKD functionality may involve establishing a quantum communication channel, generating raw quantum keys based on quantum state exchanges, processing the raw quantum keys using key sifting, error correction, privacy amplification, and QKD post-processing techniques (e.g., establish a quantum communication channel between the system and the one or more nodes; upon establishing the quantum communication channel, generate raw quantum keys based on quantum state exchanges over the quantum communication channel; process the raw quantum keys using one or more of: key sifting, error correction, privacy amplification, and QKD post-processing techniques).

[0035]

[0029] In an embodiment, the PQC module may operate using Round 5 algorithms to generate digital signatures and perform authentication protocols, where the processor may generate a digital signature using the PQC technique based on lattice -based, code-based, or multivariate polynomial techniques, verify the digital signature, perform key encapsulation and decapsulation operations, and apply authentication procedures using the PQC technique (e.g., generate the digital signature using the PQC technique based on lattice-based, codebased, or multivariate polynomial techniques to identify a transmitting node).

[0036]

[0030] In an embodiment, a software stack may manage recognition and processing of security requests, and coordinate quantum key establishment, quantum signature, and quantum node authentication units to enable appropriate cryptographic responses (e.g., coordination among the modules ensures that a suitable cryptographic response is matched to each service request type).

[0037]

[0031] In an embodiment, a secure element may support the QKD node, wherein the secure element may be configured to execute PQC routines, perform post-processing of QKD outputs, and manage secure storage of cryptographic materials including keys and certificates (e.g., allocate storage regions using a safe virtual memory structure; store cryptographic materials within the allocated storage regions). In an embodiment, the secure element may comply with high-assurance standards such as EAL CC certification and may resist physical tampering and side-channel attacks, contributing to the reliability of cryptographic operations.

[0038]

[0032] In an embodiment, a quantum transceiver may generate and capture quantum signals, and may operate in coordination with the secure element to ensure protection during key generation processes (e.g., establish a quantum communication channel between the one or more nodes, wherein the quantum communication channel is used to enable key generation through quantum state exchanges).

[0039]

[0033] In an embodiment, additional cryptographic functionalities may be provided by the security gateway to prevent data exposure, and the gateway may act as a cryptographic intermediary in a network to enforce quantum-safe protections in inter-node communications.

[0040]

[0034] In an embodiment, the modular structure of the gateway may allow incremental adoption of quantum-resilient protocols in financial infrastructures, and protect sensitive transaction data using QKD-generated keys and PQC authentication mechanisms. In an embodiment, a monitoring and management unit may oversee execution of cryptographic operations in real time and provide capabilities such as performance tracking, anomaly detection, logging, and audit trails for compliance. In an embodiment, design considerations for scalability and adaptability may be applied to allow integration of new algorithms into the gateway and maintain long-term security in view of quantum advancements.

[0041]

[0035] Various embodiments with respect to the present disclosure will be explained in detail with reference to FIGs. 1-6.

[0042]

[0036] FIG. 1 represents an example scenario 100 of QKD systems demonstrating security vulnerabilities that may arise due to the absence of strong authentication protocols and exploitable implementation flaws. Node A 102 and Node B 104 symbolize two legitimate communication endpoints intended to establish a secure quantum link via quantum and classical channels. Quantum channels are depicted with solid lines, while classical channels are represented with dashed lines.

[0043]

[0037] The lack of an effective authentication mechanism is indicated as a vulnerability point 106, which potentially allows an adversary to intervene in the QKD handshake process. As a result of this vulnerability, Node A 108 and Node B 110 become susceptible to external manipulation. Attack Node 112 is shown intercepting communications between Node A 108 and Node B 110, simulating a man-in-the -middle attack where both quantum and classical channels are compromised. Implementation flaws are marked 114, indicating system weaknesses such as hardware design gaps, side-channel leakage, or protocol inconsistencies. These flaws create an entry point for adversaries to introduce malicious behavior without being detected. Trojan-horsed Node A 116 and Trojan-horsed Node B 1 represent tampered versions of the original nodes. Multiple quantum communication attacks are illustrated here. A bright-light attack is indicated as an adversarial technique that blinds photon detectors through high-intensity light pulses. The manipulation of quantum states through multiple phases (ph 1, ph 2,... ph n) demonstrates an example of a multi-photon attack. A time-shift attack is indicated through the shifting of photon arrival times to exploit detector inefficiencies.

[0044]

[0038] Identified attacks depicted in FIG. 1 include man-in-the-middle attacks, Trojan-horse attacks, bright-light attacks, multi-photon attacks, time-shift attacks, and other implementation-related vulnerabilities. The absence of robust authentication and integrity mechanisms makes QKD systems vulnerable to exploitation. These points of failure are significant risks that require cryptographic reinforcement.

[0045]

[0039] Integration of Post-Quantum Cryptography (PQC) with QKD, as highlighted in the proposed security gateway architecture, contributes to addressing the identified vulnerabilities. The combination of QKD for secure key distribution and PQC for authentication, digital signatures, and encapsulation creates a layered cryptographic defense model. This hybrid integration improves the robustness of the quantum communication framework against both quantum-specific and classical attack vectors.

[0046]

[0040] FIG. 2 illustrates a block diagram 200 of an example system 202 for dynamically selecting a security technique in a network, in accordance with an embodiment hererin.

[0047]

[0041] Referring to FIG. 2, the system 202 may include a processor 204, a memory 206, and an interface(s) 208. The processor 204 may be implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logic circuitries, and / or any devices that manipulate data based on operational instructions. Among other capabilities, the processor 204 may be configured to fetch and execute computer-readable instructions stored in the memory 206 of the system 202. The memory 206 may store one or more computer-readable instructions or routines, which may be fetched and executed the operations. The memory 206 may include any non- transitory storage device including, for example, volatile memory such as Random-Access Memory (RAM), or non-volatile memory such as Erasable Programmable Read-Only Memory (EPROM), flash memory, and the like. The interface(s) 208 may comprise a variety of interfaces, for example, interfaces for data input and output devices, referred to as I / O devices, storage devices, and the like. The interface(s) 208 may facilitate communication of the system 202 with various devices coupled to it. The interface(s) 208 may also provide a communication pathway for one or more components of the system 202. Examples of such components include, but are not limited to, processing engine(s) 210, and a database 212. The database 212 may include data that is either stored or generated as a result of functionalities implemented by any of the components of the processing engine(s) 210.

[0048]

[0042] In an embodiment, the processing engine(s) 210 may be implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processing engine(s) 210. In the examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the processing engine(s) 210 may be processor-executable instructions stored on a non-transitory machine-readable storage medium, and the hardware for the processor 204 may comprise a processing resource (for example, one or more processors), to execute such instructions. In the present examples, the machine -readable storage medium may store instructions that, when executed by the processing resource, implement the processing engine(s) 210. In such examples, the system 202 may comprise the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine-readable storage medium may be separate but accessible to the system 202 and the processing resource. In other examples, the processing engine(s) 210 may be implemented by an electronic circuitry. The processing engine(s) 210 may include a data communication monetization module 214, a security request detection module 216, a security technique selection module 218, a security operation performance module 220, and other module(s) 222. The other module(s) 220 may implement functionalities that supplement applications / functions performed by the processing engine(s) 210.

[0049]

[0043] To dynamically select a security technique in a network, the data communication monetization module 214 may monitor data communication exchanged between one or more nodes. For example, the data communication monetization module 214 may analyze real-time traffic patterns, data sizes, or protocol types used in a communication session between an loT sensor and a cloud server. Further, the security request detection module 216 may detect a security request associated with the data communication. For instance, the security request detection module 216 may identify an authentication request initiated by a node attempting to access a secure service.

[0050]

[0044] Further, the security technique selection module 218 may determine a type of the security request and dynamically select at least one security technique from a plurality of security techniques based on the determination of the type of the security request to apply the selected technique in the data communication performed in the network. In an embodiment, the plurality of security techniques may comprise a Quantum Key Distribution (QKD) technique and a Post-Quantum Cryptography (PQC) technique.

[0051]

[0045] In an embodiment, the type of security request may include, but is not limited to, an authentication request initiated when a remote user logs into a secure portal, a key establishment request during private network session setup, a data integrity assurance request when transmitting firmware updates, a confidentiality enforcement request for transmitting medical records, a secure channel setup request between data centers, and a digital signature validation request during document signing.

[0052]

[0046] In an embodiment, to dynamically select the at least one security technique, the security technique selection module 218 may determine the type of the security request. In an embodiment, when the type of the security request corresponds to at least one of: the key establishment request, the secure channel setup request, or the confidentiality enforcement request, the security technique selection module 218 may select the QKD technique for cryptographic key exchange operations. For instance, the QKD technique may be selected when a hospital system exchanges sensitive patient data with a remote lab over a quantum-safe channel.

[0053]

[0047] In an embodiment, when the type of the security request comprises at least one of: the authentication request, the data integrity assurance request, or the digital signature validation request, the security technique selection module 218 may select the PQC technique for operations involving at least one of: digital signatures, authentication procedures, and key encapsulation. For example, the PQC technique may be selected when a blockchain-based system needs to verify transaction signatures using lattice-based algorithms.

[0054]

[0048] In an embodiment, to perform cryptographic key exchange operations using the QKD technique, a security operation performance module 220 may establish a quantum communication channel between a system and the one or more nodes. For instance, the quantum communication channel may be set up between a government server and a satellite. Upon establishing the quantum communication channel, the security operation performance module 220 may generate raw quantum keys based on quantum state exchanges, such as photon polarization, over the channel.

[0055]

[0049] In an embodiment, the security operation performance module 220 may process the raw quantum keys using one or more of: key sifting to filter matching bits, error correction to remove transmission noise, privacy amplification to eliminate partial knowledge of an attacker, and QKD post-processing techniques, and store the processed quantum keys in a memory 106.

[0056]

[0050] In an embodiment, to perform the operations involving at least one of: digital signatures, authentication procedures, and key encapsulation by applying the PQC technique, the security operation performance module 220 may generate a digital signature using the PQC technique based on lattice-based, code-based, or multivariate polynomial techniques to identify a transmitting node of the one or more nodes and verify the digital signature to authenticate the identity of the transmitting node. For example, a digital signature generated using a lattice-based technique may be applied to secure messages transmitted between smart grid components.

[0057]

[0051] Further, the security operation performance module 220 may perform key encapsulation to transmit a wrapped encryption key to a receiving node of the one or more nodes and perform key de-capsulation to extract the encapsulated key at the receiving node. In an embodiment, the security operation performance module 220 may apply authentication procedures using the PQC technique to detect anomalies such as forged identity tokens or unauthorized access attempts in the data.

[0058]

[0052] In an embodiment, to perform operations using both the PQC technique and the QKD technique, the security operation performance module 220 may establish the quantum communication channel between the one or more nodes. The quantum communication channel may be used to enable key generation through quantum state exchanges, and the module may generate raw quantum keys by exchanging quantum states such as quantum bits encoded in photons between the system 102 and the one or more nodes.

[0059]

[0053] Further, the security operation performance module 220 may process the raw quantum keys using one or more of key sifting, error correction, privacy amplification, and QKD post-processing techniques to derive quantum encryption keys for data communication. In an embodiment, the security operation performance module 220 may generate a digital signature using the PQC technique based on a lattice-based, code-based, or multivariate polynomial technique, wherein the digital signature may incorporate the quantum encryption keys derived from the QKD technique to confirm the identity of a transmitting node involved in the data communication.

[0060]

[0054] Further, the security operation performance module 220 may verify the generated digital signature to authenticate the identity of the transmitting node, and perform key encapsulation using the PQC technique to wrap an encryption key for transmission to a receiving node. Further, the security operation performance module 220 may perform key decapsulation at the receiving node to extract the encryption key from the encapsulated message and may apply the quantum keys generated through the QKD technique, along with the outputs of the PQC-based signature and key operations, in securing the data communication between the one or more nodes.

[0061]

[0055] In an embodiment, the system 102 may allocate storage regions using a safe virtual memory structure and store cryptographic materials within the allocated storage regions. The cryptographic materials may comprise the quantum keys, the lattice-based technique, the code-based technique, the multivariate polynomial technique, and corresponding parameters. For example, the safe memory may prevent unauthorized access to secret keys used in QKD sessions.

[0062]

[0056] Further, the system 102 may control access to the storage regions based on pre-defined policies such as role-based access control and apply memory segmentation techniques during read and write operations involving the cryptographic material. In an embodiment, the system 102 may be configured to operate one or more hardware accelerators embedded within the system 102 to perform at least one security technique. For instance, a lattice-based cryptographic algorithm may be accelerated using a dedicated arithmetic unit to reduce signing latency during high-volume transaction processing.

[0063]

[0057] FIG. 3 illustrates an architecture 300 of the quantum-safe security system / gateway, which integrates Post-Quantum Cryptography (PQC) with Quantum Key Distribution (QKD) to provide quantum-safe cyber security (e.g., dynamically select at least one security technique from a plurality of security techniques based on the determination of the type of the service request). In an embodiment, the architecture includes QKD post processing and PQC processing components. In an embodiment, the QKD post processing component manages the post-processing of quantum keys generated through a Measurement- Device-Independent Quantum Key Distribution (MDI-QKD) algorithm. In an embodiment, the QKD post processing component performs operations such as error correction and privacy amplification (e.g., process the raw quantum keys using one or more of: key sifting, error correction, privacy amplification, and QKD post-processing techniques). In an embodiment, the PQC processing component performs cryptographic operations using Round 5 algorithms (e.g., generate the digital signature using the PQC technique based on latticebased, code-based, or multivariate polynomial techniques).

[0064]

[0058] In an embodiment, the quantum-safe security system evaluates incoming security service requests, and determines whether to invoke the MDI-QKD algorithm or the PQC processing (e.g., determine the type of the security request; and perform at least one of: select the QKD technique for operations involving a cryptographic key exchange when the type of security request comprises at least one of: a key establishment request, a secure channel setup request, or a confidentiality enforcement request; and select the PQC technique for operations involving at least one of: a digital signature, authentication procedures, or key encapsulation, when the type of security request comprises at least one of: an authentication request, a data integrity assurance request, or a digital signature validation request). In an embodiment, this evaluation enables the dynamic selection of the appropriate quantum-safe cryptographic method (e.g., dynamically select at least one security technique from a plurality of security techniques).

[0065]

[0059] In an embodiment, the quantum-safe security system includes a security service request identification module 302 (e.g., detect a security request associated with the data communication), a QKD post processing module 304, and a PQC processing module 306. In an embodiment, the security service request identification module 302 continuously monitors incoming security service requests and determines a specific cryptographic operation required (e.g., determine a type of the security request). In an embodiment, quantum key establishment 302A, quantum node authentication 302B, and quantum signature generation 302C are considered as request types (e.g., the type of security request comprises an authentication request, a key establishment request, a digital signature validation request).

[0066]

[0060] In an embodiment, once the type of request is identified, the quantum-safe security system routes the request to the QKD post processing module 304 (e.g., select the QKD technique for operations involving a cryptographic key exchange, when the type of security request corresponds to at least one of: the key establishment request, the secure channel setup request, and the confidentiality enforcement request). In an embodiment, the QKD post processing module 304 manages requests related to quantum key distribution and performs error correction and privacy amplification.

[0067]

[0061] In an embodiment, the PQC processing module 306 manages cryptographic operations related to Post-Quantum Cryptography (e.g., select the PQC technique for operations involving at least one of: a digital signature, authentication procedures, and key encapsulation, when the type of security request comprises at least one of: the authentication request, the data integrity assurance request, and the digital signature validation request). In an embodiment, the PQC processing module 306 utilizes Round 5 algorithms for node authentication and digital signature generation.

[0068]

[0062] In an embodiment, FIG. 3 includes a detailed view of cryptographic schemes within the Round 5 algorithm, showing interrelationships for securing communications (e.g., perform key encapsulation to transmit a wrapped encryption key to a receiving node of the one or more nodes). In an embodiment, the quantum-safe security system manages these processes for performing post-quantum cryptographic operations.

[0069]

[0063] In an embodiment, a r5_cpa_pke scheme is employed for encrypting data under chosen plaintext attack resistance (e.g., perform operations involving the digital signature, the authentication procedures, and the key encapsulation by applying the PQC technique). In an embodiment, r5_cpa_pke provides encryption security even if plaintext is chosen by an adversary.

[0070]

[0064] In an embodiment, the r5_cpa_kem generates cryptographic keys for secure transmission (e.g., generate a digital signature using a lattice-based scheme to confirm the identity of a transmitting node; perform key encapsulation to securely transmit an encryption key to a receiving node; apply the authentication procedures for verifying node identity based on the generated signature). In an embodiment, the system enables transition from r5_cpa_kem to r5_cca_kem for added ciphertext attack resistance.

[0071]

[0065] In an embodiment, r5_cca_pke extends public key encryption functionality to include chosen ciphertext attack resistance (e.g., verify the digital signature to authenticate an identity of the transmitting node). In an embodiment, r5_cca_pke is supported by r5_cca_kem and a data encapsulation mechanism to securely decrypt data (e.g., perform key decapsulation to extract the encapsulated key at the receiving node).

[0072]

[0066] In an embodiment, error correction and public matrix functions support the cryptographic operations, ensuring accuracy and robustness (e.g., process the raw quantum keys using one or more post-processing operations including error correction and privacy amplification; apply memory segmentation techniques during read and write operations to optimize secure data flow).

[0073]

[0067] In an embodiment, the quantum-safe security system applies all Round 5 schemes including r5_cpa_pke, r5_cpa_kem, r5_cca_kem, and r5_cca_pke in an integrated manner to defend against chosen plaintext and chosen ciphertext attacks (e.g., generate a digital signature using the PQC technique; verify the digital signature to authenticate the transmiting node; perform key encapsulation to wrap an encryption key; perform key decapsulation to extract the key at the receiver; apply the quantum keys generated through the QKD technique to secure the data communication between the one or more nodes).

[0074]

[0068] FIG. 4 depicts an integrated architecture 400 of a quantum-safe security system / gateway, which may combine a Post-Quantum Cryptography (PQC) technique and a Quantum Key Distribution (QKD) technique to secure communication across network layers, according to an embodiment. In an embodiment, the quantum-safe security system may integrate both PQC and QKD techniques for secure communication across network layers (e.g., dynamically select at least one security technique from a plurality of security techniques based on the determination of the type of the service request to apply the at least one security technique in the data communication performed in the network).

[0075]

[0069] In an embodiment, the quantum-safe security system may interact with an Open Systems Interconnection (OSI) Layer Stack at 402. The interaction may enable application of quantum-safe security measures across all layers of network communication protocols (e.g., the type of security request comprises an authentication request, a key establishment request, a data integrity assurance request, a confidentiality enforcement request, a secure channel setup request, and a digital signature validation request).

[0076]

[0070] In an embodiment, the quantum-safe security system may include a security service request identification module 302 (e.g., detect a security request associated with the data communication). The security service request identification module 302 may continuously monitor incoming data to determine a type of a security service request (e.g., determine the type of the security request). Based on the type of security request, the security service request identification module 302 may instruct the processor to dynamically select either the PQC or QKD technique (e.g., select the QKD technique for operations involving a cryptographic key exchange, when the type of security request corresponds to at least one of: the key establishment request, the secure channel setup request, and the confidentiality enforcement request; and select the PQC technique for operations involving at least one of: a digital signature, authentication procedures, and key encapsulation, when the type of security request comprises at least one of: the authentication request, the data integrity assurance request, and the digital signature validation request).

[0077]

[0071] In an embodiment, the quantum-safe security system may include a QKD Post Processing module 304, which may manage a quantum key establishment process (e.g., establish a quantum communication channel between the system and the one or more nodes; generate raw quantum keys by exchanging quantum states; process raw quantum keys using key sifting, error correction, privacy amplification, and QKD post-processing techniques; store the processed quantum keys in memory). The QKD Post Processing module 304 may apply a Measurement-Device-Independent Quantum Key Distribution (MDI-QKD) method, which may reduce vulnerabilities such as side-channel attacks.

[0078]

[0072] In an embodiment, the quantum-safe security system may include a PQC Processing module 306, which may perform Post-Quantum Cryptographic operations for digital signatures and authentication (e.g., generate a digital signature using a PQC technique based on lattice-based, code-based, or multivariate polynomial techniques; verify the digital signature to authenticate the identity of a transmitting node; perform key encapsulation and decapsulation; apply the authentication procedures using the PQC technique to detect anomalies in the data).

[0079]

[0073] In an embodiment, the quantum-safe security system may include a Safe Virtual Memory 404 (e.g., allocate storage regions using a safe virtual memory structure; store cryptographic materials such as the quantum keys, lattice -based, code-based, multivariate polynomial techniques, and parameters; control access to storage regions based on policies; apply memory segmentation techniques). The Safe Virtual Memory 404 may enable secure management of cryptographic materials.

[0080]

[0074] In an embodiment, the quantum-safe security system may include hardware accelerator drivers 406, which may operate between the software stack and underlying hardware (e.g., operate one or more hardware accelerators configured in the system to perform the at least one security technique). The hardware accelerator drivers 406 may enable efficient execution of cryptographic operations.

[0081]

[0075] In an embodiment, the quantum-safe security system may include QKD node hardware 408, which may include a secure element 410 and a quantum transceiver 412. The secure element 410 may execute cryptographic operations and manage sensitive data (e.g., cryptographic keys and certificates), ensuring tamper resistance and protection against physical and logical attacks. In an embodiment, the secure element 410 may comply with high security standards such as EAL CC certification. The secure element 410 may handle PQC processing and QKD post-processing operations securely (e.g., maintain trustworthiness and security of cryptographic operations).

[0082]

[0076] In an embodiment, the quantum transceiver 412 may facilitate QKD operations (generating, encoding, and transmitting single photons for high-security key distribution). Secure Element 410 apply the quantum keys generated through the QKD technique, along with the outputs of the PQC-based signature and key operations, in securing the data communication between the one or more nodes). The secure element 410 and the quantum transceiver 412 may provide foundational support for the integrated architecture of the quantum-safe security system.

[0083]

[0077] FIG. 5 illustrates a flow diagram 500 depicting a method for securing communication across network layers using a quantum-safe security system or gateway, according to an embodiment. At 502, a quantum-safe security system may continuously monitor incoming security service requests using a Security Service Request Identification module. In an embodiment, the module may determine a type of the security request, such as an authentication request, a key establishment request, a data integrity assurance request, a confidentiality enforcement request, a secure channel setup request, or a digital signature validation request (e.g., determine a type of the security request). Based on the determined type, at 504, the quantum-safe security system may dynamically select at least one security technique from a plurality of security techniques, including a Post-Quantum Cryptography (PQC) process and a Quantum Key Distribution (QKD) process (e.g., dynamically select at least one security technique from a plurality of security techniques).

[0084]

[0078] In an embodiment, the PQC process may be selected for operations involving digital signatures, authentication procedures, and key encapsulation when the request type comprises at least one of: an authentication request, a data integrity assurance request, and a digital signature validation request (e.g., select the PQC technique for operations involving at least one of: digital signatures, authentication procedures, and key encapsulation). The PQC process may utilize lattice-based, code-based, or multivariate polynomial cryptographic techniques to resist quantum attacks. In an embodiment, the QKD process may be selected for cryptographic key exchange operations when the type of security request comprises at least one of: a key establishment request, a secure channel setup request, or a confidentiality enforcement request (e.g., select the QKD technique for operations involving a cryptographic key exchange). The QKD process may involve establishing a quantum communication channel between nodes, generating raw quantum keys based on quantum state exchanges, processing the raw quantum keys using key sifting, error correction, privacy amplification, and QKD post-processing, and storing the processed quantum keys in memory (e.g., perform the operations involving the cryptographic key exchange operations by applying the QKD technique).

[0085]

[0079] At 506, the quantum-safe security system may interface with an Open Systems Interconnection (OSI) Layer Stack to apply quantum-safe security measures across multiple network layers, from the physical layer to the application layer. In an embodiment, at 508, quantum-safe cryptographic operations may be executed using a QKD Post Processing module and a PQC Processing module (e.g., perform the operations by applying the PQC technique and the QKD technique). The QKD Post Processing module may manage quantum key generation and secure distribution, while the PQC Processing module may handle digital signature generation, authentication, and key encapsulation.

[0086]

[0080] At 510, memory operations may be managed using a safe virtual memory structure to protect the confidentiality and integrity of cryptographic materials, including quantum keys and PQC-related parameters (e.g., allocate storage regions using a safe virtual memory structure; store cryptographic materials within the allocated storage regions). The safe virtual memory may enable memory segmentation techniques during read and write operations and control access based on predefined policies.

[0087]

[0081] At 512, hardware accelerator drivers may optimize performance by interfacing software operations with specialized hardware accelerators configured to perform cryptographic tasks (e.g., operate one or more hardware accelerators configured in the system to perform the at least one security technique). In an embodiment, hardware acceleration may ensure efficient cryptographic processing with low latency.

[0088]

[0082] At 514, a quantum transceiver may enable the physical transmission and reception of quantum signals between nodes. In an embodiment, a tamper-resistant Secure Element may securely generate and store quantum keys in conjunction with the quantum transceiver (e.g., establish a quantum communication channel between the one or more nodes). At 516, the Secure Element may provide a secure environment that defends against side-channel attacks, fault injection, and physical tampering, ensuring secure cryptographic operations.

[0089]

[0083] The described method may allow a quantum-safe security system to apply layered cryptographic techniques to secure communication between network nodes, leveraging both QKD and PQC mechanisms to defend against classical and quantum threats. In an embodiment, a processor may monitor network communication, detect the presence of security service requests, determine the request type, and apply the appropriate cryptographic technique accordingly (e.g., monitor data communication between one or more nodes; detect a security request associated with the data communication). Algorithmic steps presented in the embodiments may represent defined operations on tangible data, resulting in tangible outcomes suitable for implementation within computing systems.

[0090]

[0084] FIG. 6 illustrate a flow chart of a method 600 for dynamically selecting the security technique in the network, in accordance with an embodiment herein.

[0085] Referring to FIG. 6. at 602, the method 600 may include monitoring, by a processor 204 associated with the system 202, data communication between one or more nodes. At 604, the method 600 may include detecting 604, by the processor 204, a security request associated with the data communication. At 606, the method 600 may include determining, by the processor 204, a type of the security request. At 608, the method 600 may include dynamically selecting 608, by the processor 204, at least one security technique from a plurality of security techniques based on the determination of the type of the service request to apply the at least one security technique in the data communication performed in the network.

[0091]

[0086] The foregoing description of the specific embodiments will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify and / or adapt for various applications such specific embodiments without departing from the generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Therefore, while the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modification within the spirit and scope.

Claims

We Claim:

1. A system for dynamically selecting a security technique in a network, comprising: a processor; and a memory operatively coupled with the processor, wherein the memory comprises one or more instructions which, when executed, cause the processor to: monitor data communication between one or more nodes; detect a security request associated with the data communication; determine a type of the security request; and dynamically select at least one security technique from a plurality of security techniques based on the determination of the type of the service request to apply the at least one security technique in the data communication performed in the network.

2. The system of claim 1, wherein the at least one security technique corresponds to a Quantum Key Distribution (QKD) technique and a Post-Quantum Cryptography (PQC) technique.

3. The system of claim 1 , wherein the type of security request comprises an authentication request, a key establishment request, a data integrity assurance request, a confidentiality enforcement request, a secure channel setup request, and a digital signature validation request.

4. The system of claim 3, wherein to dynamically select the at least one security technique, the processor is configured to: determine the type of the security request; and perform at least one of: select a QKD technique for operations involving a cryptographic key exchange, when the type of the security request corresponds to at least one of: the key establishment request, the secure channel setup request, and the confidentiality enforcement request; and select a PQC technique for operations involving at least one of: digital signatures, authentication procedures, and key encapsulation, when the type of the security request comprises at least one of: the authentication request, the data integrity assurance request, and the digital signature validation request.

5. The system of claim 4, wherein to perform the operations involving the cryptographic key exchange operations by applying the QKD technique, the processor is configured to: establish a quantum communication channel between the system and the one or more nodes; upon establishing the quantum communication channel, generate raw quantum keys based on quantum state exchanges over the quantum communication channel; process the raw quantum keys using one or more of: key sifting, error correction, privacy amplification, and QKD post-processing techniques; and store the processed quantum keys in the memory.

6. The system of claim 4, wherein to perform the operations involving the at least one of: the digital signatures, the authentication procedures, and the key encapsulation by applying the PQC technique, the processor is configured to: generate the digital signature using the PQC technique based on lattice-based, code-based, or multivariate polynomial techniques to identify a transmitting node of the one or more nodes of data; verify the digital signature to authenticate an identity of the transmitting node; perform key encapsulation to transmit a wrapped encryption key to a receiving node of the one or more nodes; perform key de-capsulation to extract the encapsulated key at the receiving node; and apply the authentication procedures using the PQC technique to detect anomalies in the data.

7. The system of claim 1, wherein to perform the operations by applying the PQC technique and the QKD technique, the processor is further configured to: establish a quantum communication channel between the one or more nodes, wherein the quantum communication channel is used to enable key generation through quantum state exchanges; generate raw quantum keys by exchanging quantum states over the established quantum communication channel between the system and the one or more nodes; process the raw quantum keys using one or more of key sifting, error correction, privacy amplification, and QKD post-processing techniques to derive quantumencryption keys for data communication; generate a digital signature using the PQC technique based on a lattice-based, code-based, or multivariate polynomial technique, wherein the digital signature is generated by incorporating the quantum encryption keys derived from the QKD technique to confirm the identity of a transmitting node involved in the data communication; verify the generated digital signature to authenticate the identity of the transmitting node; perform key encapsulation using the PQC technique to wrap an encryption key for transmission to a receiving node; perform key de- capsulation at the receiving node to extract the encryption key from the encapsulated message; and apply the quantum keys generated through the QKD technique, along with the outputs of the PQC-based signature and key operations, in securing the data communication between the one or more nodes.

8. The system of claim 1, wherein processor is configured to: allocate storage regions using a safe virtual memory structure; store cryptographic materials within the allocated storage regions, wherein the cryptographic materials comprise the quantum keys, the lattice-based, the code-based, the multivariate polynomial technique, and parameters; control access to the storage regions based on pre-defined policies; and apply memory segmentation techniques during read and write operations involving cryptographic material.

9. The system of claim 1, wherein the processor is configured to operate one or more hardware accelerators configured in the system to perform the at least one security technique.

10. A method for dynamically selecting a security technique in a network, comprising: monitoring, by a processor associated with a system, data communication between one or more nodes; detecting, by the processor, a security request associated with the data communication; determining, by the processor, a type of the security request; anddynamically selecting, by the processor, at least one security technique from a plurality of security techniques based on the determination of the type of the service request to apply the at least one security technique in the data communication performed in the network.

11. The method of claim 10, wherein for dynamically selecting, by the processor, the at least one security technique, the method comprises: determining, by the processor, the type of the security request; and performing, by the processor, at least one of: selecting a QKD technique for operations involving a cryptographic key exchange, when the type of the security request corresponds to at least one of: a key establishment request, a secure channel setup request, and a confidentiality enforcement request; and selecting a PQC technique for operations involving at least one of: digital signatures, authentication procedures, and key encapsulation, when the type of the security request comprises at least one of: an authentication request, a data integrity assurance request, and a digital signature validation request.

12. The method of claim 11, wherein for performing, by the processor, the operations involving the cryptographic key exchange operations by applying the QKD technique, the method comprises: establishing, by the processor, a quantum communication channel between the system and the one or more nodes; upon establishing the quantum communication channel, generating, by the processor, raw quantum keys based on quantum state exchanges over the quantum communication channel; processing, by the processor, the raw quantum keys using one or more of: key sifting, error correction, privacy amplification, and QKD post-processing techniques; and storing, by the processor, the processed quantum keys in the memory.

13. The method of claim 11, wherein for performing, by the processor, the operations involving the at least one of: the digital signatures, the authentication procedures, and the key encapsulation by applying the PQC technique, the method comprises:generating, by the processor, the digital signature using the PQC technique based on lattice-based, code-based, or multivariate polynomial techniques to identify a transmitting node of the one or more nodes of data; verifying, by the processor, the digital signature to authenticate an identity of the transmitting node; performing, by the processor, key encapsulation to transmit a wrapped encryption key to a receiving node of the one or more nodes; performing, by the processor, key de-capsulation to extract the encapsulated key at the receiving node; and applying, by the processor, the authentication procedures using the PQC technique to detect anomalies in the data.

14. The method of claim 11, wherein for performing, by the processor, the operations by applying the PQC technique and the QKD technique, the method comprises: establishing, by the processor, a quantum communication channel between the one or more nodes, wherein the quantum communication channel is used to enable key generation through quantum state exchanges; generating, by the processor, raw quantum keys by exchanging quantum states over the established quantum communication channel between the system and the one or more nodes; processing, by the processor, the raw quantum keys using one or more of key sifting, error correction, privacy amplification, and QKD post-processing techniques to derive quantum encryption keys for data communication; generating, by the processor, a digital signature using the PQC technique based on a lattice-based, code-based, or multivariate polynomial technique, wherein the digital signature is generated by incorporating the quantum encryption keys derived from the QKD technique to confirm the identity of a transmitting node involved in the data communication; verifying, by the processor, the generated digital signature to authenticate the identity of the transmitting node; performing, by the processor, key encapsulation using the PQC technique to wrap an encryption key for transmission to a receiving node;performing, by the processor, key de-capsulation at the receiving node to extract the encryption key from the encapsulated message; and applying, by the processor, the quantum keys generated through the QKD technique, along with the outputs of the PQC-based signature and key operations, in securing the data communication between the one or more nodes.

15. The method of claim 10, wherein the method further comprises: allocating, by the processor, storage regions using a safe virtual memory structure; storing, by the processor, cryptographic materials within the allocated storage regions, wherein the cryptographic materials comprise the quantum keys, the latticebased, the code-based, the multivariate polynomial technique, and parameters; controlling, by the processor, access to the storage regions based on pre-defined policies; and applying, by the processor, memory segmentation techniques during read and write operations involving cryptographic material.