Key Relay Station Distribution Beyond Fiber Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing quantum key distribution (QKD) protocols are limited by the need for fiber connectivity, making it difficult to establish secure cryptographic keys directly with end-users who are not connected to a fiber network, thereby restricting their practicality in high-capacity communication infrastructure.

Innovation Solution

A method involving a key relay station that receives cryptographic secrets from a webserver, authenticates end-users, and securely communicates these secrets to their devices using near-field communication or machine-readable codes, enabling secure storage and encryption for data communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If quantum key distribution protocols use fiber connections between endpoints, then security and cryptographic secret distribution are improved, but adaptability to end-users without fiber connectivity deteriorates

Engineering Contradiction:
Improvecryptographic securityVSAvoidaccessibility to end-users
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a key relay station as an intermediary device between the quantum key distribution network and end-users. This relay station receives cryptographic secrets from the QKD protocol via fiber connection and then transfers them to end-users through alternative channels (display screens,Near Field Communication), thereby bridging the gap between fiber-based quantum networks and end-users without direct fiber connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the cryptographic secret distribution process into two distinct phases: (1) secure generation and initial transmission of cryptographic secrets through fiber-connected key relay stations, and (2) local distribution to end-users through non-fiber channels. This segmentation allows each component to operate within its optimal capabilities while achieving overall system goals

Inventive Principle:
Principle #1Segmentation

2Productivity

If cryptographic secrets are transmitted over networks, then distribution to multiple users is improved, but security against network eavesdropping deteriorates

Engineering Contradiction:
Improvesecret distribution efficiencyVSAvoidtransmission security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent creates a secure copy of the cryptographic secret that is transferred to the end-user's device. The original secret remains on the key relay station, and an identical copy is provided to the user through secure local channels. This copying approach enables distribution to multiple users while maintaining security, as each user receives their own secure copy without the secret traversing vulnerable network channels

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The key relay station acts as a secure intermediary that holds and manages cryptographic secrets before distribution. It authenticates end-users and controls the secret transfer process, ensuring that secrets are only transmitted through secure local channels after proper authentication, thereby preventing network eavesdropping while enabling efficient distribution

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12452046B2Systems and methods for secure cryptographic secret distribution
Publication Date: 2025.10.21 JPMORGAN CHASE BANK NA
  • US12452046B2 patent drawing
  • US12452046B2 patent drawing
  • US12452046B2 patent drawing

AI summary

Systems and methods for secure cryptographic secret distribution are disclosed. In one embodiment, a method for secure cryptographic secret distribution may include: (1) receiving, at a key relay station, a cryptographic secret from a webserver over a first communication network; (2) storing, by the key relay station, the cryptographic secret; (3) authenticating, by the key relay station, an end user via an end user electronic device; and (4) securely communicating, by the key relay station, the cryptographic secret to the end user electronic device. The end user electronic device is configured to store the cryptographic secret in secure storage on the end user electronic device, to encrypt data with the cryptographic secret, and to communicate the encrypted data to the webserver over a second communication network.