Quantum Key Distribution Authentication via Wavelength Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional quantum key distribution (QKD) protocols lack effective authentication mechanisms, making them vulnerable to man-in-the-middle and distributed denial of service (DDoS) attacks, and inefficiently utilize quantum key resources.

Innovation Solution

An authentication method for QKD processes where the sender and receiver select a basis for preparing authentication information using a preset algorithm library, apply different wavelengths to send quantum states, and employ a metric to measure authentication information, with reverse authentication information used to verify identities and terminate the process if inconsistent, thereby preventing attacks and optimizing key resource use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If traditional quantum key distribution protocols are used without authentication mechanisms, then the protocol simplicity is maintained, but security against man-in-the-middle and DDoS attacks deteriorates

Engineering Contradiction:
Improveprotocol simplicityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the quantum key distribution protocol into distinct authentication and key distribution phases. The authentication mechanism is separated from the core QKD protocol, allowing independent optimization of security while maintaining protocol modularity. This segmentation enables the integration of robust authentication without completely redesigning the QKD framework.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary authentication actions before the main key distribution process. By performing authentication checks in advance using pre-shared secrets or preliminary quantum exchanges, the system establishes verified communication channels before sensitive key material is transmitted, preventing man-in-the-middle attacks from compromising the entire protocol.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If classical authentication algorithms are used in quantum key distribution, then authentication capability is provided, but vulnerability to cracking attacks increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidcracking vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces classical mechanical authentication systems with quantum-based authentication mechanisms. By utilizing quantum states and measurements for authentication, the system leverages fundamental quantum principles such as no-cloning and measurement disturbance to provide security that is inherently resistant to classical computational attacks, including cracking attempts.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameters of authentication from classical bit-based verification to quantum state-based verification. This parameter change involves using quantum mechanical properties such as polarization states, phase differences, or time-bin encodings as authentication credentials, making the authentication process immune to classical cryptographic breaking methods.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If authentication keys are limited in quantity, then key distribution efficiency is maintained, but resistance to DDoS attacks deteriorates

Engineering Contradiction:
Improvekey distribution efficiencyVSAvoidDDoS resistance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements mechanisms for discarding compromised or expired authentication keys and recovering or regenerating new keys through quantum key distribution. This continuous key lifecycle management allows the system to maintain efficiency by using keys only for their intended purpose while simultaneously building resistance to DDoS attacks through periodic key renewal and the ability to discard compromised keys.

Inventive Principle:
Principle #34Discarding and recovering

Solution Approach 2:

The patent introduces dynamic key management where authentication keys are not static but are continuously updated and renewed through quantum key distribution processes. This dynamic approach allows the system to adapt to attack patterns, maintain efficiency through optimized key usage, and resist DDoS attacks by periodically refreshing authentication credentials.

Inventive Principle:
Principle #15Dynamics

4Reliability

If quantum key resources are used for authentication, then security is improved, but quantum key resource utilization efficiency deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidquantum key resource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies partial action by using only a portion of the quantum key material for authentication purposes while reserving the remaining keys for actual data encryption. This selective use of quantum keys for authentication rather than consuming entire key sets optimizes resource utilization while maintaining the security benefits of quantum-based authentication.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent creates a universal quantum key management system where the same quantum key distribution infrastructure serves multiple functions: authentication verification, key generation for data encryption, and security protocol execution. This multi-functionality eliminates the need for separate dedicated authentication keys, thereby improving overall quantum key resource utilization efficiency while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10999068B2Authentication method, device and system for quantum key distribution process
Publication Date: 2021.05.04 CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
  • US10999068B2 patent drawing
  • US10999068B2 patent drawing
  • US10999068B2 patent drawing

AI summary

An authentication method for a QKD process includes: a sender selects a basis for preparing authentication information according to an algorithm in an algorithms library, and respectively applies different wavelengths to send quantum states of control information and data information according to a preset information format; a receiver filters the received quantum states, employs a basis of measurement corresponding to the algorithm to measure the authentication information quantum state, sends reverse authentication information when the measurement result is in line with the algorithm, and terminates the distribution process otherwise. In addition, the sender terminates the distribution process when its local authentication information is inconsistent with the reverse authentication information.