Key Orchestration Service for Quantum Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current key exchange approaches, such as Diffie-Hellman and RSA, are insecure against quantum computers, and Quantum Key Distribution (QKD) systems are costly and limited in capacity, failing to meet the high demand for secure key distribution in modern datacenters.

Innovation Solution

A secure computing system that uses QKD devices connected via optical fibers to pre-cache cryptographic keys and labels, managed by a key orchestration system that monitors demand and proactively generates and distributes keys through an optically-switched network, ensuring secure communication among endpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If QKD devices are deployed to provide quantum-safe key distribution, then security against quantum computers is improved, but device cost and system complexity increase

Engineering Contradiction:
Improvequantum-safe securityVSAvoidQKD device deployment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key orchestration system as an intermediary layer between QKD devices and applications. This orchestration system manages key caching, generation, and distribution across multiple QKD devices, abstracting the complexity of direct QKD device deployment and enabling scalable integration without requiring each application to directly interface with expensive QKD hardware

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the key distribution function into separate components: QKD devices that generate raw key material, a key orchestration system that manages caching and distribution, and application interfaces that request keys. This segmentation allows independent optimization of each component and reduces the complexity burden on any single element of the system

Inventive Principle:
Principle #1Segmentation

2Reliability

If QKD devices are used for key distribution, then security is improved, but the number of devices required increases due to limited capacity

Engineering Contradiction:
Improvequantum-safe securityVSAvoidnumber of QKD devices
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system implements preliminary key generation and caching by the key orchestration system before applications actually need the keys. QKD devices generate and distribute key material in advance, which is then cached in the orchestration system. This preliminary action allows a smaller number of QKD devices to serve multiple applications over time, reducing the total device count required

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges the functions of multiple QKD devices through a centralized key orchestration system that aggregates key material from various devices. The orchestration system combines keys generated by different QKD devices and manages their distribution, effectively pooling the capacity of multiple devices to serve a larger number of applications than any single device could handle alone

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If keys are generated and exchanged on demand, then system simplicity is maintained, but key exchange speed and security response time worsen

Engineering Contradiction:
Improvekey exchange architectureVSAvoidkey exchange speed
Core Design Contradiction:
Device complexityVSSpeed

Solution Approach 1:

The key orchestration system performs preliminary key caching by pre-generating and storing cryptographic keys before applications request them. When applications need keys for secure communication, they are retrieved from the cache immediately rather than generated in real-time. This preliminary action dramatically speeds up key exchange while maintaining system simplicity through automated cache management

Inventive Principle:
Principle #10Preliminary action

4Reliability

If frequent key updates are implemented to counter quantum threats, then security is improved, but key exchange demand and system load increase

Engineering Contradiction:
Improvecryptographic securityVSAvoidkey exchange throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements preliminary key generation and caching to prepare multiple keys in advance before they are needed. The key orchestration system maintains a cache of pre-generated cryptographic keys that can be rapidly distributed to applications. This allows frequent key updates to be implemented without proportionally increasing the load on QKD devices, as the orchestration system can serve multiple keys from its cache

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system segments the key update workload between QKD devices that generate raw key material at a relaxed pace and the key orchestration system that manages rapid key distribution from cache. This segmentation allows frequent key updates to applications without requiring proportionally frequent QKD device operations, decoupling security update frequency from QKD device throughput requirements

Inventive Principle:
Principle #1Segmentation

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides a scalable and secure key exchange mechanism that meets the high demand for secure communication in datacenters, reducing the number of required QKD devices and improving total cost of ownership (TCO) while ensuring secure communication across endpoints.

Implementation Method 1

A plurality of quantum key distribution (QKD) devices connected via respective optical fiber connections, and configured to securely distribute the generated cryptographic keys among the computer clusters

Methodology Applied
Scientific EffectQuantum key distribution:

Implementation Method 2

QKD devices connected via optical fibers to pre-cache cryptographic keys and labels

Methodology Applied
Scientific EffectOptical fiber transmission: Optical Fibre

Data Source

PatentUS11711210B2Quantum key distribution-based key exchange orchestration service
Publication Date: 2023.07.25 MELLANOX TECHNOLOGIES LTD(IL)
  • US11711210B2 patent drawing
  • US11711210B2 patent drawing
  • US11711210B2 patent drawing

AI summary

In one embodiment, a secure computing system comprises a key generation sub-system configured to generate cryptographic keys and corresponding key labels for distribution to computer clusters, each computer cluster including a plurality of respective endpoints, a plurality of quantum key distribution (QKD) devices connected via respective optical fiber connections, and configured to securely distribute the generated cryptographic keys among the computer clusters, and a key orchestration sub-system configured to manage caching of the cryptographic keys in advance of receiving key requests from applications running on ones of the endpoints, and provide respective ones of the cryptographic keys to the applications to enable secure communication among the applications.