Dynamic Authentication in Quantum Key Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Quantum Key Distribution (QKD) protocols lack effective authentication mechanisms, making them vulnerable to spoofing attacks, man-in-the-middle attacks, and distributed denial of service (DDoS) attacks, and they waste quantum key resources by using a portion of the shared quantum key for authentication.
Innovation Solution
A method for dynamic authentication in QKD processes, where a quantum communication transmitter selects a basis for transmitter authentication information according to a basis selection rule agreed upon with the receiver, and transmits quantum states containing key information and authentication information. The receiver verifies the authentication information using a pre-provisioned algorithm, and if consistent, determines the transmitter is authenticated, allowing for secure key generation without wasting quantum key resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication mechanism is added to QKD protocol, then security against spoofing and man-in-the-middle attacks is improved, but device complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-provisioning authentication algorithms and parameters in the QKD devices before actual key distribution. The authentication mechanism is prepared in advance with pre-shared secrets and authentication algorithms, allowing rapid authentication without adding complex real-time processing during key distribution.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that mediates between the quantum key distribution process and security verification. The authentication module acts as an intermediary layer that verifies identities using pre-provisioned algorithms, separating the authentication function from the core QKD protocol and reducing overall system complexity.
2Speed
If pre-determined authentication algorithm is used, then authentication speed is improved, but adaptability to different QKD protocols deteriorates
Solution Approach 1:
The patent achieves universality by designing pre-provisioned authentication algorithms that can be applied across multiple QKD protocols. The authentication mechanism is protocol-agnostic, allowing the same authentication framework to work with different QKD protocols (such as BB84, E91) without requiring protocol-specific customization, thus maintaining both speed and adaptability.
Solution Approach 2:
The patent applies dynamics by allowing the selection of different pre-provisioned authentication algorithms based on the specific QKD protocol being used. While the algorithms are pre-provisioned for speed, the system dynamically selects which algorithm to apply based on protocol requirements, maintaining adaptability without sacrificing authentication performance.
3Reliability
If authentication key is dynamically updated, then security against replay attacks is improved, but loss of quantum key resources increases
Solution Approach 1:
The patent applies segmentation by separating authentication keys from quantum key materials. The authentication uses pre-provisioned classical keys that are updated dynamically, while the quantum keys generated during QKD are preserved for their intended purpose. This segmentation allows dynamic authentication key updates without consuming or wasting quantum key resources.
Solution Approach 2:
The patent uses copying by creating separate authentication key copies that can be updated independently of the quantum keys. The pre-provisioned authentication algorithms work with copied authentication data rather than the original quantum key materials, allowing dynamic updates of authentication credentials without affecting or depleting the quantum key resources needed for secure communication.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present application discloses an authentication method used in a QKD process, and further discloses additional authentication methods and corresponding apparatuses, as well as an authentication system The method comprises: selecting, by a transmitter according to a basis selection rule, a basis of preparation for transmitter authentication information that is generated with a first pre-provisioned algorithm and varies dynamically, and transmitting quantum states containing key information and the transmitter authentication information; and measuring, by a receiver, quantum states of the transmitter authentication information according to the basis selection rule, and ending the QKO process if a measurement result is inconsistent with corresponding information calculated with the first pre-provisioned algorithm.