Post Quantum Cryptography Migration Management via LLM Bill of Materials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The development of quantum computers poses a significant threat to existing encryption protocols, making it necessary to migrate from vulnerable protocols to post-quantum cryptography protocols to ensure the security of computing systems.

Innovation Solution

A service is developed to manage the migration of encryption protocols by using a large language model application to create a cryptographic bill of materials, which identifies cryptographic primitives and their vulnerabilities, and utilizes blockchain networks to track and facilitate the migration process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing encryption protocols are used, then current security standards are maintained, but vulnerability to quantum computing attacks increases

Engineering Contradiction:
ImprovesecurityVSAvoidquantum computing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary identification and classification of cryptographic primitives vulnerable to quantum attacks before migration is required. By using AI/ML models to analyze codebases and detect vulnerable algorithms in advance, the system enables proactive migration planning and execution, resolving the contradiction between maintaining current security standards and preparing for quantum vulnerability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If migration to post-quantum cryptography is performed, then security against quantum attacks is improved, but complexity of the migration process increases

Engineering Contradiction:
Improvequantum securityVSAvoidmigration process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The migration process is segmented into distinct phases: identification of vulnerable cryptographic primitives, classification by vulnerability level, prioritization based on impact assessment, and staged migration execution. This segmentation breaks down the complex migration task into manageable steps, enabling systematic progression through the transition while maintaining security improvements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements feedback mechanisms through continuous monitoring of migration progress, tracking the status of cryptographic primitives, and providing real-time updates on security posture. This feedback loop enables dynamic adjustment of migration strategies and provides transparency into the complex migration process, reducing overall complexity through informed decision-making.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive scanning of software applications is performed, then identification of vulnerable cryptographic primitives is improved, but time required for analysis increases

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial action by focusing scanning and analysis resources on the most critical cryptographic primitives and codebases first. Through prioritization algorithms that assess vulnerability severity and business impact, the system achieves high detection accuracy for the most important assets without requiring exhaustive analysis of all software components, thereby reducing overall analysis time while maintaining precision where it matters most.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250165251A1Post quantum cryptography migration management
Publication Date: 2025.05.22 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US20250165251A1 patent drawing
  • US20250165251A1 patent drawing
  • US20250165251A1 patent drawing

AI summary

Disclosed are various examples for managing post quantum cryptography migrations of application services. For example, a system can include a computing device that is configured to identify a uniform resource location associated with source code for an application service and identify a cryptographic primitive in the source code by scanning the source code. The computing device can be configured to generate a large language model prompt for a cryptographic bill of materials based at least in part on the cryptographic primitive. The cryptographic bill of materials for the source code can be generated by inputting the large language model prompt to a large language model application. The cryptographic bill of materials can include a list of cryptographic components.