Cryptographic Communication System Key ID Embedding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic communication systems using quantum key distribution (QKD) face challenges in achieving high-speed communication due to the need for a communication protocol for key ID notification, which complicates network requirements and makes key pre-fetching difficult, especially when using interfaces like ETSI GS QKD 014.
Innovation Solution
A cryptographic communication system that pre-fetches encryption keys without requiring a communication protocol for key ID notification by utilizing a key management system with an interface that provides key IDs, allowing for high-speed communication between sites using quantum key distribution technology, where encryption and decryption keys are shared and embedded within data packets for efficient transmission and decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If a communication protocol for key ID notification is implemented to enable key pre-fetching, then communication speed can be improved, but device complexity and network requirements increase
Solution Approach 1:
The patent extracts the key ID notification function from a separate communication protocol and integrates it directly into the data packet structure. The key ID is embedded within the packet itself, allowing the decryption device to obtain the key ID along with the ciphertext without requiring additional notification messages or protocol exchanges.
Solution Approach 2:
The patent merges the key ID notification function with the data transmission function by embedding the key ID within the data packet. This combines what were previously separate operations (transmitting data and notifying of key ID) into a single unified packet structure, eliminating the need for separate protocol messages.
2Productivity
If key pre-fetching is implemented using existing key management interfaces, then communication efficiency can be improved, but ease of operation deteriorates due to additional network requirements
Solution Approach 1:
The patent extracts the key ID from the key management system interface and embeds it directly in the data packet. This eliminates the need for the encryption device to separately notify the decryption device of the key ID through complex network protocols, simplifying the overall system operation.
Solution Approach 2:
The data packet structure is designed to be self-sufficient by including the key ID within the packet itself. The decryption device can obtain all necessary information (ciphertext and key ID) from a single packet without requiring additional network interactions or complex configuration, making the system easier to operate.
3Reliability
If a separate key ID notification protocol is used, then key management can be achieved, but loss of time occurs due to additional communication overhead
Solution Approach 1:
The patent merges the key ID notification with the ciphertext transmission by embedding the key ID within the data packet. This allows the decryption device to receive both the ciphertext and the corresponding key ID in a single communication act, eliminating the time required for separate notification messages and reducing overall communication overhead.
Data Source
AI summary
According to one embodiment, a transmitting device includes an encryption key pre-fetching unit and an encryption chunk generation unit. The encryption key pre-fetching unit acquires the encryption key for encrypting plaintext data from a key management system before receiving the plaintext data. The encryption chunk generation unit generates a packet in which first encrypted data acquired by encrypting first plaintext data using a first encryption key and a first key ID of the first encryption key are stored, and a second key ID of a second encryption key used for encrypting second plaintext data transmitted after the first plaintext data, is embedded. A receiving device includes an encryption chunk analysis unit and a decryption key pre-fetching unit. The encryption chunk analysis unit analyzes the packet and reads the second key ID. The decryption key pre-fetching unit acquires the second encryption key corresponding to the second key ID read by the encryption chunk analysis unit from the key management system.


