Proxy Server Key Retrieval via Broker-Mediated Quantum-Secure Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securely distributing encryption keys to proxy servers are laborious, time-consuming, and expensive, especially as they rely on manual keyfill and are vulnerable to quantum computer attacks, making them inefficient for large-scale distributed computing systems.

Innovation Solution

A method for distributing encryption keys to proxy servers using a third-party service to agree common encryption keys and IDs between a client device and a broker device, storing these at both ends, and enabling secure key retrieval via a shared memory, database, or pipes, without manual keyfill or asymmetric-primitive exchanges, ensuring quantum security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual keyfill is used to distribute encryption keys to proxy servers, then security is maintained, but the process becomes laborious, time-consuming, and expensive

Engineering Contradiction:
ImprovesecurityVSAvoidtime-consuming
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary key agreement between the client device and broker device before the actual communication session. The encryption keys are established in advance through quantum key distribution, stored securely, and made available for rapid retrieval during proxy server operations, eliminating the need for manual keyfill at the time of deployment

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A broker device is introduced as an intermediary between the client device and proxy server. The broker facilitates automatic key distribution by receiving key requests from the proxy server, verifying them against pre-agreed keys, and automatically providing the appropriate encryption keys, thereby replacing manual key management operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual keyfill is used for key distribution, then security is maintained, but device complexity and operational difficulty increase as systems scale

Engineering Contradiction:
ImprovesecurityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The proxy server is configured to automatically request and receive encryption keys from the broker device without human intervention. The system performs self-service key management by automatically initiating key requests, verifying key IDs, and retrieving appropriate keys, thereby reducing operational complexity and eliminating manual keyfill operations even in large-scale distributed systems

Inventive Principle:
Principle #25Self-service

3Ease of operation

If asymmetric-primitive key-exchange protocols are used between proxy server and client, then key distribution is simplified, but quantum security is compromised

Engineering Contradiction:
Improvekey distribution simplicityVSAvoidquantum security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Quantum key distribution is performed in advance between the client device and broker device to establish encryption keys before any asymmetric-primitive key exchange would occur. This preliminary quantum key agreement ensures that when the proxy server needs keys, they are already securely established through quantum-resistant methods, allowing the system to avoid vulnerable asymmetric protocols entirely

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The broker device acts as a quantum-secure intermediary that receives key requests from the proxy server and provides keys that were pre-established through quantum key distribution. This intermediary architecture allows the proxy server to obtain quantum-secure keys automatically without needing to implement asymmetric-primitive key exchange protocols, maintaining both simplicity and quantum security

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250350446A1Key distribution to a proxy server
Publication Date: 2025.11.13 ARQIT LTD
  • US20250350446A1 patent drawing
  • US20250350446A1 patent drawing
  • US20250350446A1 patent drawing

AI summary

A system and method for distributing an encryption key to a proxy server configured to operate as a proxy for a third-party, including agreeing, between a client device (CD) and a broker device (BD), a common encryption key (CEK) using a third party service and a key ID corresponding to the CEK; storing, at the CD and the BD, respective copies of the encryption keys and the key IDs; transmitting, from the CD to the proxy server, a request, based on one of the key IDs, to establish a secure connection between the CD and the proxy server; transmitting, from the proxy server to the BD, a request for an encryption key based on the key ID associated with the request transmitted from the CD to the BD; verifying that the key ID corresponds to CEK; and after successful verification, receiving, at the proxy server, the corresponding CEK.