Key Management Device Using HSM for Quantum Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Quantum cryptographic communication systems face security threats due to unauthorized access during key generation, storage, and transfer, as application keys often exist in plaintext form, making them vulnerable to theft.

Innovation Solution

Implementing a hardware security module (HSM) within the key management system to generate, store, and encrypt application keys, ensuring they remain protected throughout the transmission process by using double encryption and secure key sharing methods like Diffie-Hellman or RSA.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If application keys are stored and transmitted in plaintext form for ease of access and usage, then operational convenience is improved, but security against unauthorized access and key theft deteriorates

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The key management system is segmented into multiple functional modules: key generation unit, key storage unit, key transmission unit, and key usage unit. Each module performs a specific function in the key lifecycle, allowing the system to maintain security while enabling operational convenience through specialized components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary encryption layer and secure transmission protocol between key storage and key usage. Instead of direct plaintext access, keys are transmitted through encrypted channels and decrypted only at the point of usage, acting as a mediator that preserves both security and accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If quantum encryption keys are shared between multiple QKD devices for enhanced cryptographic capability, then system functionality is improved, but vulnerability to unauthorized access during key transfer increases

Engineering Contradiction:
Improvecryptographic capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary key generation and secure distribution to multiple QKD devices before cryptographic operations begin. Keys are pre-shared through secure quantum channels, establishing cryptographic capability in advance while minimizing the window of vulnerability during key transfer operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs disposable quantum encryption keys that are generated, used, and discarded in short cycles. Each key is used for a specific cryptographic operation and then destroyed, preventing long-term storage vulnerabilities and reducing the risk associated with key sharing across multiple devices.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS20230299953A1Quantum cryptographic communication system, key management device, and key management method
Publication Date: 2023.09.21 KK TOSHIBA
  • US20230299953A1 patent drawing
  • US20230299953A1 patent drawing
  • US20230299953A1 patent drawing

AI summary

According to an embodiment, a quantum cryptographic communication system includes a first quantum key distribution (QKD) device, and a first key management device. The first QKD device that shares a quantum encryption key with a second QKD device through QKD. The first key management device includes a reception unit and a first hardware security module (HSM). The reception unit receives the quantum encryption key from the first QKD device. The first HSM includes a storage unit, a generation unit, and a first encryption unit. The storage unit stores a first encryption key therein. The generation unit generates an application key used in an encryption process by a cryptographic application. The first encryption unit that encrypts, with the first encryption key, the application key transmitted to a second key management device connected to the second QKD device.