PQC-TLS Quantum Security Channel Through Legacy TLS Intermediaries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication devices face challenges in implementing quantum security due to the presence of intermediate devices that do not support post-quantum cryptography (PQC)-transport layer security (TLS) protocols, leading to exposure to quantum threats like harvest now decrypt later (HNDL).

Innovation Solution

A communication method and device that form a general security channel using a first TLS protocol, establish an application layer communication channel via a web socket protocol, and then create a quantum security channel through a PQC-TLS handshake procedure, enabling secure communication even with intermediate devices that do not support PQC-TLS.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a PQC-TLS protocol is implemented to provide quantum security, then security against quantum threats is improved, but compatibility with intermediate devices that do not support PQC-TLS deteriorates

Engineering Contradiction:
Improvequantum securityVSAvoidcompatibility with intermediate devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the communication path into multiple channels: a control channel using traditional TLS protocol for compatibility with intermediate devices, and a data channel using PQC-TLS protocol for quantum security. This allows different protocol versions to coexist without requiring all devices to support PQC-TLS.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an application layer as an intermediary between the transport layer (where traditional TLS operates) and the quantum security layer (where PQC-TLS operates). This intermediary enables PQC-TLS handshakes to occur through the application layer while maintaining compatibility with intermediate devices at the transport layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PQC-TLS modules are installed on all devices including intermediate devices, then quantum security is improved, but implementation cost and time increase

Engineering Contradiction:
Improvequantum securityVSAvoidmigration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements PQC-TLS partially by applying it only to end devices (clients and servers) while leaving intermediate devices to use traditional TLS. This partial implementation achieves quantum security for critical data transmission without requiring universal deployment across all network devices.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If PQC-TLS protocol is used directly at transport layer, then quantum security is improved, but system complexity increases due to intermediate device limitations

Engineering Contradiction:
Improvequantum securityVSAvoidcommunication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent moves the PQC-TLS handshake from the traditional transport layer to the application layer, adding a new dimensional layer to the communication architecture. This allows PQC-TLS to operate in a dimension (application layer) where intermediate devices do not interfere, avoiding the complexity of modifying transport layer protocols across all devices.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12513193B2Communication method for quantum security and communication device supporting the same
Publication Date: 2025.12.30 SAMSUNG SDS CO LTD
  • US12513193B2 patent drawing
  • US12513193B2 patent drawing
  • US12513193B2 patent drawing

AI summary

There is provided a communication device. The communication device may comprise one or more processors; a communication interface; and a memory that stores a computer program executed by the one or more processors, wherein the computer program includes instructions for operations of: forming a general security channel according to a first transport layer security (TLS) protocol that does not support a post-quantum cryptography algorithm with another communication device; forming a communication channel of an application layer (L7) with another communication device through the general security channel; forming a quantum security channel by performing a handshake procedure according to a second TLS protocol that supports the post-quantum cryptography algorithm with another communication device through the communication channel; and communicating with another communication device through the quantum security channel.