Dynamic Authentication in Quantum Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Quantum Key Distribution (QKD) protocols lack effective authentication mechanisms, making them vulnerable to spoofing attacks, man-in-the-middle attacks, and distributed denial of service (DDoS) attacks, and they waste quantum key resources by using a portion of the shared quantum key for authentication.

Innovation Solution

A method for dynamic authentication in QKD processes, where a quantum communication transmitter selects a basis for transmitter authentication information according to a basis selection rule agreed upon with the receiver, and transmits quantum states containing key information and authentication information. The receiver verifies the authentication information using a pre-provisioned algorithm, and if consistent, determines the transmitter is authenticated, allowing for secure key generation without wasting quantum key resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication mechanism is added to QKD protocol, then security against spoofing and man-in-the-middle attacks is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-provisioning authentication algorithms and parameters in the QKD devices before actual key distribution. The authentication mechanism is prepared in advance with pre-shared secrets and authentication algorithms, allowing rapid authentication without adding complex real-time processing during key distribution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between the quantum key distribution process and security verification. The authentication module acts as an intermediary layer that verifies identities using pre-provisioned algorithms, separating the authentication function from the core QKD protocol and reducing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If pre-determined authentication algorithm is used, then authentication speed is improved, but adaptability to different QKD protocols deteriorates

Engineering Contradiction:
Improveauthentication speedVSAvoidprotocol adaptability
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The patent achieves universality by designing pre-provisioned authentication algorithms that can be applied across multiple QKD protocols. The authentication mechanism is protocol-agnostic, allowing the same authentication framework to work with different QKD protocols (such as BB84, E91) without requiring protocol-specific customization, thus maintaining both speed and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies dynamics by allowing the selection of different pre-provisioned authentication algorithms based on the specific QKD protocol being used. While the algorithms are pre-provisioned for speed, the system dynamically selects which algorithm to apply based on protocol requirements, maintaining adaptability without sacrificing authentication performance.

Inventive Principle:
Principle #15Dynamics

3Reliability

If authentication key is dynamically updated, then security against replay attacks is improved, but loss of quantum key resources increases

Engineering Contradiction:
ImprovesecurityVSAvoidquantum key loss
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent applies segmentation by separating authentication keys from quantum key materials. The authentication uses pre-provisioned classical keys that are updated dynamically, while the quantum keys generated during QKD are preserved for their intended purpose. This segmentation allows dynamic authentication key updates without consuming or wasting quantum key resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses copying by creating separate authentication key copies that can be updated independently of the quantum keys. The pre-provisioned authentication algorithms work with copied authentication data rather than the original quantum key materials, allowing dynamic updates of authentication credentials without affecting or depleting the quantum key resources needed for secure communication.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3338430B1Authentication method, apparatus and system used in quantum key distribution process
Publication Date: 2021.09.15 ALIBABA GROUP HOLDING LTD
  • EP3338430B1 patent drawingFigure 1
  • EP3338430B1 patent drawingFigure 2
  • EP3338430B1 patent drawingFigure 3

AI summary

The present application discloses an authentication method used in a QKD process, and further discloses additional authentication methods and corresponding apparatuses, as well as an authentication system The method comprises: selecting, by a transmitter according to a basis selection rule, a basis of preparation for transmitter authentication information that is generated with a first pre-provisioned algorithm and varies dynamically, and transmitting quantum states containing key information and the transmitter authentication information; and measuring, by a receiver, quantum states of the transmitter authentication information according to the basis selection rule, and ending the QKO process if a measurement result is inconsistent with corresponding information calculated with the first pre-provisioned algorithm.