PQC-TLS Quantum Security Channel Through Legacy TLS Intermediaries
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication devices face challenges in implementing quantum security due to the presence of intermediate devices that do not support post-quantum cryptography (PQC)-transport layer security (TLS) protocols, leading to exposure to quantum threats like harvest now decrypt later (HNDL).
Innovation Solution
A communication method and device that form a general security channel using a first TLS protocol, establish an application layer communication channel via a web socket protocol, and then create a quantum security channel through a PQC-TLS handshake procedure, enabling secure communication even with intermediate devices that do not support PQC-TLS.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a PQC-TLS protocol is implemented to provide quantum security, then security against quantum threats is improved, but compatibility with intermediate devices that do not support PQC-TLS deteriorates
Solution Approach 1:
The patent segments the communication path into multiple channels: a control channel using traditional TLS protocol for compatibility with intermediate devices, and a data channel using PQC-TLS protocol for quantum security. This allows different protocol versions to coexist without requiring all devices to support PQC-TLS.
Solution Approach 2:
The patent introduces an application layer as an intermediary between the transport layer (where traditional TLS operates) and the quantum security layer (where PQC-TLS operates). This intermediary enables PQC-TLS handshakes to occur through the application layer while maintaining compatibility with intermediate devices at the transport layer.
2Reliability
If PQC-TLS modules are installed on all devices including intermediate devices, then quantum security is improved, but implementation cost and time increase
Solution Approach 1:
The patent implements PQC-TLS partially by applying it only to end devices (clients and servers) while leaving intermediate devices to use traditional TLS. This partial implementation achieves quantum security for critical data transmission without requiring universal deployment across all network devices.
3Reliability
If PQC-TLS protocol is used directly at transport layer, then quantum security is improved, but system complexity increases due to intermediate device limitations
Solution Approach 1:
The patent moves the PQC-TLS handshake from the traditional transport layer to the application layer, adding a new dimensional layer to the communication architecture. This allows PQC-TLS to operate in a dimension (application layer) where intermediate devices do not interfere, avoiding the complexity of modifying transport layer protocols across all devices.
Data Source
AI summary
There is provided a communication device. The communication device may comprise one or more processors; a communication interface; and a memory that stores a computer program executed by the one or more processors, wherein the computer program includes instructions for operations of: forming a general security channel according to a first transport layer security (TLS) protocol that does not support a post-quantum cryptography algorithm with another communication device; forming a communication channel of an application layer (L7) with another communication device through the general security channel; forming a quantum security channel by performing a handshake procedure according to a second TLS protocol that supports the post-quantum cryptography algorithm with another communication device through the communication channel; and communicating with another communication device through the quantum security channel.


