Quantum Key Distribution Center Authentication and Encryption Logic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Quantum Key Distribution (QKD) systems face limitations in distance and security, particularly due to the vulnerability of key distribution centers being aware of shared encryption keys, which compromises the security of key distribution.

Innovation Solution

The implementation of a QKD system that includes an authentication key sharing unit, a quantum key generation unit, an error correction unit, and a bit string operation unit to securely generate and distribute quantum keys using cryptographic operations and hash functions, ensuring that the QKD center remains unaware of the shared key among client devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Length of stationary object

If a key distribution center is used to relay encryption keys between distant users, then the distance limitation of QKD is overcome, but a security weak point is created where the key distribution center is aware of the encryption keys shared among users

Engineering Contradiction:
ImprovedistanceVSAvoidsecurity
Core Design Contradiction:
Length of stationary objectVSReliability

Solution Approach 1:

The patent extracts the encryption key information from the key distribution center's knowledge scope. The QKD center only manages authentication keys and performs cryptographic operations, but the final encryption keys are generated and held exclusively by the terminal devices, removing the security vulnerability where the center knew the encryption keys.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the key distribution function into two independent parts: authentication key management (handled by QKD center) and encryption key generation (handled by terminal devices). This segmentation allows the system to overcome distance limitations through the center while maintaining security through decentralized encryption key ownership.

Inventive Principle:
Principle #1Segmentation

2Reliability

If previously shared secret keys are used for authentication in QKD, then unconditional security can be guaranteed, but the system becomes vulnerable to man-in-the-middle attacks

Engineering Contradiction:
Improveunconditional securityVSAvoidman-in-the-middle attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary authentication using shared secret keys before the actual QKD process. This preliminary action establishes the identity of legitimate parties, preventing man-in-the-middle attacks from succeeding, while the subsequent QKD process maintains unconditional security through quantum mechanics.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the QKD center as an intermediary that facilitates authentication without exposing the quantum key material. The center mediates the authentication process using classical cryptographic operations on authentication keys, while the actual encryption keys remain distributed between terminals through quantum channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If encryption keys are individually created by a key distribution center and delivered to users, then key distribution can be achieved, but the key distribution center must be aware of all shared encryption keys creating a security risk

Engineering Contradiction:
Improvekey distributionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent enables terminal devices to self-generate their own encryption keys through local cryptographic operations on authentication keys and quantum-generated random numbers. Each device serves itself in key generation, eliminating the need for the QKD center to create or store encryption keys, thus maintaining ease of distribution while improving security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The QKD center acts as an intermediary that provides authentication keys and facilitates the key generation process, but does not possess the final encryption keys. This intermediary role enables centralized coordination for ease of operation while maintaining decentralized security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach enhances the security of quantum key distribution by preventing exposure of encryption information to the QKD center, ensuring unconditional security and reliability of the key distribution process.

Implementation Method 1

generating sifted keys, corresponding to the QKD client devices, using quantum states

Methodology Applied
Scientific EffectQuantum mechanics:

Data Source

PatentUS10958428B2Apparatus for quantum key distribution on a quantum network and method using the same
Publication Date: 2021.03.23 ELECTRONICS & TELECOMM RES INST
  • US10958428B2 patent drawing
  • US10958428B2 patent drawing
  • US10958428B2 patent drawing

AI summary

A device and method for quantum key distribution (QKD). The QKD center includes an authentication key sharing unit for sharing authentication keys with QKD client devices; a quantum key generation unit for generating a sifted key for each of the QKD client devices using a quantum state; an error correction unit for generating output bit strings by correcting errors of the sifted keys; and a bit string operation unit for calculating an encryption bit string by performing a cryptographic operation on the authentication keys, the distribution output bit strings and output bit strings received from the QKD client devices. The present invention improves security by preventing the QKD center from being aware of keys shared among users.