Key Manager Authentication for Quantum Key Distribution Scalability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current quantum key distribution (QKD) systems have limitations in communicable distance and are restricted to one-to-one key sharing, necessitating the introduction of a key manager (KM) apparatus to facilitate cryptographic key sharing between arbitrary nodes in a network, while ensuring security through authentication processes.

Innovation Solution

The key manager apparatus performs inter-KM-apparatus and KM-QKD connection authentication, enabling the KM function by relaying cryptographic keys between KM apparatuses and ensuring the legitimacy of connections within the QKD system, thereby expanding key sharing capabilities beyond the traditional one-to-one limitation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a key manager apparatus is introduced to enable cryptographic key sharing between arbitrary nodes in a network, then key sharing capability and network scalability are improved, but system complexity and authentication requirements increase

Engineering Contradiction:
Improvekey sharing capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The key manager apparatus serves as an intermediary component between QKD apparatuses, managing cryptographic keys and coordinating authentication processes. This mediator role enables arbitrary nodes to share keys through the key manager without requiring direct peer-to-peer key management, thus improving key sharing capability while managing system complexity through centralized coordination

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The key manager apparatus performs multiple functions including key generation, key storage, key distribution, and authentication coordination. This multi-functionality allows a single apparatus to handle various key management tasks across the network, improving versatility while avoiding the need for separate specialized components for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If authentication processing is performed between KM apparatuses and QKD apparatuses, then connection security is improved, but processing time and operational complexity increase

Engineering Contradiction:
Improveconnection securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication processing is performed in advance before cryptographic key sharing begins. The key manager apparatus and QKD apparatus complete mutual authentication and establish secure connections beforehand, ensuring security requirements are met before actual key operations commence, thus preventing security issues rather than reacting to them

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the KM function is enabled only after successful authentication, then system security is improved, but operational flexibility decreases

Engineering Contradiction:
Improvesystem securityVSAvoidoperational flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The KM function is dynamically enabled or disabled based on authentication status. The system transitions between different operational states: unauthorized (KM function disabled), authenticated (KM function enabled), and key sharing active. This dynamic control ensures security requirements are met while allowing flexible operation when authentication succeeds

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240039710A1Km apparatus, QKD system, key management start control method, and computer program product
Publication Date: 2024.02.01 KK TOSHIBA
  • US20240039710A1 patent drawing
  • US20240039710A1 patent drawing
  • US20240039710A1 patent drawing

AI summary

According to an embodiment, a key manager (KM) apparatus includes one or more hardware processors configured to: perform inter-KM-apparatus connection authentication indicating authentication processing with an opposing KM apparatus, and KM-quantum key distribution (QKD) connection authentication indicating authentication processing with an opposing QKD apparatus; and enable a KM function in a case where the inter-KM-apparatus connection authentication is successful and the KM-QKD connection authentication is successful.