Network Link Transition Using Key-ID Channels and Data Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a potential security breach during the transition to a quantum-secure environment due to a window of time when data links are not quantum-secured between network devices, making sensitive user data vulnerable to interception before quantum keys are applied.
Innovation Solution
Implementing a method where initial user-configured keys on network devices are set to non-matching configurations to block data exchange, using separate logical links for user traffic and key identifier exchange, ensuring no data is transmitted until quantum keys are acquired and applied, thereby securing the data link.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If quantum key distribution is implemented to secure data links, then long-term security and future-proofing are improved, but a security vulnerability window exists during key retrieval and application
Solution Approach 1:
The system performs preliminary actions by establishing the data link and preparing for quantum key distribution in advance, but implements a blocking mechanism during the key retrieval phase to prevent any data transmission. This ensures that even if traditional encryption keys are compromised, no sensitive data can be intercepted during the transition to quantum-secured communication.
Solution Approach 2:
The patent introduces an intermediary blocking mechanism that acts as a mediator between the data link establishment and quantum key application. This intermediary prevents data transmission during the vulnerable window, effectively decoupling the key retrieval process from active data exchange and eliminating the security vulnerability.
2Productivity
If data transmission begins immediately after link establishment, then productivity is improved, but security is compromised during the key retrieval window
Solution Approach 1:
The system performs preliminary setup actions (link establishment, key retrieval initiation) before actual data transmission begins. The blocking mechanism ensures that productivity is not significantly impacted because the key retrieval and application process is optimized to be as fast as possible, while maintaining security by preventing transmission during this brief window.
Solution Approach 2:
The patent implements a mechanism to rush through the key retrieval and application process as quickly as possible. By minimizing the duration of the blocking window and optimizing the key distribution workflow, the system reduces the impact on productivity while maintaining security during the critical transition phase.
3Ease of operation
If traditional encryption keys are used initially, then ease of operation is improved, but security vulnerability increases before quantum keys are applied
Solution Approach 1:
The system applies preliminary anti-action by implementing a blocking mechanism that counteracts the security risk introduced by using traditional encryption keys during initial setup. Even though traditional keys are used for ease of operation, the blocking mechanism ensures that compromised keys cannot be exploited, as no data transmission occurs during the vulnerable period.
Solution Approach 2:
The patent converts the potential harm of using traditional encryption keys during setup into a benefit by implementing the blocking mechanism. The presence of traditional keys enables ease of operation and quick setup, while the blocking mechanism transforms the associated security risk into an opportunity to demonstrate the effectiveness of quantum key distribution by eliminating the vulnerability window.
Data Source
AI summary
A physical link is split between network devices into a first logical link and a second logical link. The first logical link is designated for communicating user data. The second logical link is designated for exchanging key identifiers (key IDs) only. The second logical link is left open and unencrypted and the key IDs are exchanged over the second logical link. Using the key IDs, quantum keys are acquired, by an agent on each respective network device, from a quantum key distribution network or subsystem. The quantum keys thus acquired are then applied to the physical link between the network devices to thereby transition the physical link between the network devices to a quantum-secure environment and open the first logical link for communicating the user data in the quantum-secure environment.
