Remote Backup Recovery Using QKD Keys and Encrypted RAM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for secure backup management of remote computing machines (RCM) face vulnerabilities due to the storage of encryption keys on the RCM, which compromises data security during backup and recovery processes.

Innovation Solution

Implementing quantum key distribution (QKD) to create and manage symmetric cryptographic keys, ensuring that encryption and decryption operations are confined within the CPU circuit, with keys being transmitted over a quantum channel and stored only on user devices, thereby maintaining security during backup and recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of repair

If the encryption key is stored on the RCM for backup recovery, then the backup recovery process can be performed, but the security of the RCM decreases due to key exposure risk

Engineering Contradiction:
Improvebackup recovery capabilityVSAvoiddata security
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The encryption key is extracted from the RCM and stored on the user device instead. The RCM only retains the ability to encrypt data with the key, but the actual key material resides externally on the user's device, preventing key exposure on the remote computing machine while maintaining backup recovery capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

A quantum key distribution system acts as an intermediary between the user device and RCM. The QKD system generates and manages cryptographic keys, transmitting them securely to both the user device and RCM without the key ever being stored on the RCM itself, thus mediating the security trust relationship.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If the RAM state is encrypted by the central processor, then the encryption process is simplified, but the backup copy becomes vulnerable if the key is stored on the RCM

Engineering Contradiction:
Improveencryption process complexityVSAvoidbackup security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The encryption key storage is extracted from the RCM and placed on the user device. The central processor continues to perform encryption operations with simplified processes, but the key management function is separated and externalized, eliminating the security vulnerability of storing keys on the RCM while maintaining encryption simplicity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system is segmented into distinct functional components: the central processor handles encryption operations, the user device stores the encryption keys, and the QKD system manages key distribution. This segmentation separates the encryption process from key storage, allowing simplified encryption while improving backup security.

Inventive Principle:
Principle #1Segmentation

3Reliability

If quantum key distribution is implemented, then data security is enhanced, but the system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The QKD device serves multiple functions: it generates cryptographic keys, distributes them to both the user device and RCM, and manages key rotation. By consolidating these key management functions into a single multi-functional quantum device, the system achieves enhanced security without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The QKD system operates autonomously to generate and distribute cryptographic keys without requiring manual intervention. The system self-manages the complex key distribution process, automatically establishing secure communication channels and updating keys as needed, thereby reducing the operational complexity burden on users.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances data security by preventing key interception and ensuring secure encryption and decryption processes, even during backup and recovery operations.

Implementation Method 1

a symmetric cryptographic key is created using a QKD device, while one of the keys is transmitted to the user device for storing in the registry, and the second is transmitted to the RCM

Methodology Applied
Scientific EffectQuantum key distribution:

Data Source

PatentUS12481601B2Method and system for secure backup management of remote computing machines using quantum key distribution and encrypted RAM
Publication Date: 2025.11.25 GURIN OLEG DMITRIEVICH
  • US12481601B2 patent drawing
  • US12481601B2 patent drawing
  • US12481601B2 patent drawing

AI summary

This technical solution relates to the field of digital data processing, in particular to the methods of managing backups of computer devices. The technical result is an increase in the security of backups due to using symmetric cryptographic keys transmitted over a quantum channel, each of which corresponds to a specific backup. The technical result is achieved due to a computer-implemented method of secure management of backup copies of RCM, with the function of RAM encryption on the CPU, using quantum key distribution (QKD), under which: a connection is formed between the RCM, at least one user device and a QKD device, while the QKD device creates a quantum channel, which connects the RCM with user devices, and the RCM and the user devices are connected via a data network; QKD device creates symmetric cryptographic keys, one of one of which is transmitted to the user device for storing registry keys, and the second is transferred to RCM, after receiving the key to the RCM, a backup copy (BC) is created with the help of the central processor, state of the processor memory in a given time is encrypted and transferred to a persistent data storage; and the RCM backup is performed through the following stages: a command from user device to restore the BC is sent, and said command contains a cryptographic key, which was used to form the required BC, encrypted using a new symmetric key derived from the QKD device; in response to a received command, the transmission of the BC to the RAM of RCM is performed; the QKD device is used to transmit said new symmetric key to the CPU and decrypt the primary key; the central processor with the relevant cryptographic key for the BC is used to restore the RCM, and said RCM is stored in RAM and contains the relevant state of the encrypted RAM of the RCM.