QKD Identity Authentication Using Indexed Qubit Subsequences

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing QKD protocols lack an effective identity authentication mechanism that is not compromised by a compromised classical channel and does not require trust in a third-party quantum channel.

Innovation Solution

A method and apparatus for identity authentication using quantum and classical channels, where qubits are shared between entities to generate sequences of binary axis identifiers and bit values, with subsequences encrypted and decrypted using shared cryptographic keys, allowing authentication based on error analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If classical identity authentication mechanisms are used on the classical channel, then identity authentication can be performed, but the authentication is compromised if the classical channel is compromised

Engineering Contradiction:
Improveidentity authentication reliabilityVSAvoidvulnerability to classical channel compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces quantum-generated sequences as an intermediary authentication mechanism. Instead of relying solely on classical channel authentication, the system uses quantum-generated bit sequences and axis identifiers that are exchanged through the classical channel but authenticated through quantum mechanical properties. This intermediary quantum-based verification layer protects against classical channel compromise.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces classical cryptographic authentication mechanisms with quantum mechanical-based authentication. By using quantum-generated sequences and measuring quantum correlations through the classical channel, the system substitutes traditional mechanical/cryptographic authentication with quantum-based verification that remains secure even when the classical channel is compromised.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If other quantum channels different from the quantum communication channel are used for authentication, then identity authentication can be achieved, but trust in a third party is required

Engineering Contradiction:
Improveidentity authentication reliabilityVSAvoidrequirement for third-party quantum channel
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the primary quantum communication channel serve multiple functions: both quantum key distribution and identity authentication. The same quantum channel that establishes the cryptographic key also provides the quantum sequences用于authentication, eliminating the need for separate authentication quantum channels and third-party infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the authentication function with the existing quantum communication channel. By combining key generation and authentication into a single integrated process using the same quantum channel, the system eliminates the need for separate authentication infrastructure and third-party quantum channels.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If quantum-generated sequences are exchanged through the classical channel without encryption, then authentication can be performed, but the communication is vulnerable to eavesdropping

Engineering Contradiction:
Improveauthentication functionalityVSAvoidvulnerability to eavesdropping on classical channel
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies partial encryption by encrypting only the critical authentication elements (axis identifiers or bit values) rather than the entire communication sequence. This selective encryption approach provides sufficient protection against eavesdropping while maintaining authentication functionality and minimizing the impact of potential classical channel compromise.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12519624B2Identity authentication for QKD protocols
Publication Date: 2026.01.06 NOKIA TECHNOLOGIES OY
  • US12519624B2 patent drawing
  • US12519624B2 patent drawing
  • US12519624B2 patent drawing

AI summary

For Bob's authentication to Alice, Alice sends to Bob randomly selected indexes via the classical channel between Alice and Bob. In response, Bob extracts, from the sequences of qubit-related data generated by Bob and based on the randomly selected indexes received from Alice, subsequences of qubit-related data (e.g. including binary axis identifiers and bit values) and Bob sends the extracted subsequences via the classical channel. At least one of sent subsequences may be encrypted with a shared secret cryptographic key. Then Alice can authenticate Bob on the basis of a number of errors computed based on the decrypted subsequences received from Bob.