Bilocation Key Establishment for Cloud-Based Quantum Key Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The high upfront costs and complexities associated with leasing and maintaining Optical Ground Receivers (OGRs) for Quantum Key Distribution (QKD) systems make them inaccessible to most consumers and organizations, limiting the use of secure quantum communication methods.
Innovation Solution
A method and system for establishing a shared key between two parties using a quantum-secure network with key nodes accessible via a cloud service, allowing devices to derive their key information from a server and securely obtain it from a key serving node, enabling the generation of a Final Key through Bilocation Keys and anti-replay nonces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Optical Ground Receivers (OGRs) are leased and installed for Quantum Key Distribution, then secure quantum communication is achieved, but upfront costs and operational complexities become prohibitive for most consumers and organizations
Solution Approach 1:
The patent introduces a Quantum Key Distribution Service Provider (QKD SP) as an intermediary that operates the OGR infrastructure and provides quantum-safe keys to customers via standardized interfaces. This mediator absorbs the complexity of OGR management, allowing end users to access quantum security without directly handling complex hardware
Solution Approach 2:
The patent enables customers to obtain copies of quantum-safe cryptographic keys generated by the QKD system without needing to possess or maintain the physical OGR infrastructure. Multiple parties can receive identical secure keys through the service provider's distribution network, eliminating the need for each user to deploy their own OGR
2Reliability
If Optical Ground Receivers (OGRs) are installed for direct quantum key harvesting, then quantum-safe keys are obtained, but the high upfront costs make it inaccessible to the majority of consumers and organizations
Solution Approach 1:
The QKD Service Provider acts as an intermediary that absorbs the high infrastructure costs of OGR deployment and maintenance, offering quantum key distribution as a service to multiple customers. This business model transforms capital-intensive infrastructure investment into accessible service subscriptions
Solution Approach 2:
The patent creates a universal QKD service infrastructure that can serve multiple different customers and applications through standardized interfaces. The same underlying quantum infrastructure supports diverse use cases including secure communications, key management, and cryptographic services across organizational boundaries
3Adaptability or versatility
If a cloud-based QKD infrastructure is provided by a trusted party, then quantum key distribution becomes accessible to more parties, but the key must remain unknown or underivable even to the trusted party hosting the service
Solution Approach 1:
The patent segments the quantum key distribution system into separate functional components: key generation at the OGR, key management at the QKD service provider, and key usage at customer systems. This segmentation allows the trusted service provider to manage distribution without having access to or control over the actual cryptographic keys
Solution Approach 2:
The QKD service provider functions as a mediator that facilitates key exchange between parties without knowing the keys themselves. The system uses cryptographic protocols where the intermediary can verify and manage the key exchange process while the actual quantum-safe keys remain unknown even to the service provider
Data Source
AI summary
A computer-implemented method of establishing a key between a first and a second device in a network including a first and a second key node, the first and second key nodes with access to a same set of keys, the method including receiving, at the first device, data representative of first key establishment data from the first key node and the second device for calculating a Bilocation Key from a selected key from the set of keys; and receiving, at the second device, data representative of second key establishment data from the first device for requesting the Bilocation Key from the second key node, wherein the Bilocation Key is calculated based on the selected key from the set of keys; and wherein the first and second devices use corresponding Bilocation Keys to each generate a Final Key based on an agreed portion of the first and second key establishment data.


