QKD Apparatus Authentication for Secure Network Expansion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Quantum key distribution (QKD) systems face limitations in communicable distance and are restricted to one-to-one key sharing, requiring additional key management (KM) apparatuses for network expansion, and lack effective authentication mechanisms for secure connection and operation.

Innovation Solution

The QKD apparatus performs inter-QKD-apparatus and KM-QKD connection authentications to ensure legitimate connections, utilizing authentication processing units and management systems to validate QKD and KM apparatuses, enabling secure cryptographic key sharing between arbitrary nodes in a network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If QKD systems use additional key management (KM) apparatuses for network expansion, then network versatility is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork expansion capabilityVSAvoidsystem structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The QKD system is segmented into distinct functional components: QKD apparatus for key generation and KM apparatus for key management and distribution. This segmentation allows independent optimization of each component while enabling network expansion through modular addition of more KM apparatuses without redesigning the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The KM apparatus acts as an intermediary between multiple QKD apparatuses, managing cryptographic keys centrally. This mediator role enables network expansion by allowing arbitrary QKD apparatuses to connect through the KM apparatus without requiring direct peer-to-peer configurations, thus improving versatility while managing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If QKD systems implement authentication processing for secure connections, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improveconnection securityVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication functionality is merged into the existing QKD and KM apparatuses as integrated functions rather than separate external systems. The QKD apparatus includes authentication processing for connecting to KM apparatuses, and the KM apparatus includes authentication processing for connecting to QKD apparatuses, combining security verification with key management operations to improve reliability without proportionally increasing complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication mechanism implements feedback loops where authentication results directly control system behavior: successful authentication enables QKD function activation and cryptographic key sharing, while failed authentication prevents these operations. This feedback-based control ensures reliable secure connections while maintaining manageable complexity through clear conditional logic.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240039713A1QKD apparatus, QKD system, QKD start control method, and computer program product
Publication Date: 2024.02.01 KK TOSHIBA
  • US20240039713A1 patent drawing
  • US20240039713A1 patent drawing
  • US20240039713A1 patent drawing

AI summary

According to an embodiment, a quantum key distribution (QKD) apparatus includes one or more hardware processors configured to: perform inter-QKD-apparatus connection authentication indicating authentication processing with an opposing QKD apparatus, and key manager (KM)-QKD connection authentication indicating authentication processing with an opposing KM apparatus; and enable a QKD function in a case where the inter-QKD-apparatus connection authentication is successful and the KM-QKD connection authentication is successful.