Information Processing for QKD Key Allocation in 5G-to-Cloud Flows
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in securely and efficiently performing encrypted communication using a QKD network for specific flows in a 5G core network to cloud communication, due to differences in key generation speed and throughput, and the lack of a determined encryption method from the 5G network to the cloud.
Innovation Solution
A quantum cryptographic communication system is implemented with a QKD network architecture comprising quantum, key management, QKD network control, and QKD network management layers, utilizing QKD modules and key management devices to generate and manage application keys for secure communication, specifically encrypting a selected flow from the 5G core network to the cloud using quantum encryption keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If quantum key distribution (QKD) is used for encrypting communication data from 5G core network to cloud, then security against quantum computers is improved, but key generation speed and throughput are insufficient for all data encryption
Solution Approach 1:
The patent segments the encryption task by applying QKD only to specific flow data that requires quantum-level security, rather than attempting to encrypt all data. The system identifies and selects specific communication flows (e.g., sensitive business data transfers) to apply quantum encryption, while other flows can use conventional encryption methods, thus resolving the throughput limitation of QKD.
Solution Approach 2:
The patent implements local quality by applying different encryption methods to different data flows based on their security requirements. Critical flows receive quantum encryption while less critical flows use conventional encryption, optimizing the balance between security enhancement and data throughput.
2Reliability
If quantum encryption is applied to all data flows, then security coverage is improved, but system complexity and processing overhead increase
Solution Approach 1:
The patent segments encryption application by flow type and security requirement. A flow selection mechanism identifies which data streams need quantum encryption based on pre-defined criteria (e.g., data sensitivity, communication protocol), avoiding the complexity of implementing quantum encryption for all flows uniformly.
Solution Approach 2:
The system dynamically adjusts encryption methods based on real-time flow characteristics and security policies. The encryption selection is not static but adapts to changing network conditions and data requirements, simplifying system management.
3Reliability
If QKD network is integrated into 5G core network, then end-to-end secure communication is improved, but key management complexity increases
Solution Approach 1:
The patent introduces key management devices as intermediary components between the QKD network and the 5G core network. These intermediaries handle the complex key distribution, storage, and management tasks, isolating the complexity from the main communication paths while enabling secure end-to-end communication.
Solution Approach 2:
The patent extracts key management functions from the core network and places them in dedicated key management devices. This separation allows the 5G core network to focus on data communication while specialized devices handle the complex cryptographic key operations.
4Productivity
If quantum encryption is applied to specific flows only, then throughput efficiency is improved, but security coverage for all data is reduced
Solution Approach 1:
The patent segments the data traffic into different categories based on security requirements. By analyzing flow characteristics and data sensitivity levels, the system applies quantum encryption only to segments that truly need it, optimizing throughput while maintaining adequate security coverage for critical data.
Solution Approach 2:
The system changes the encryption parameter selection based on flow characteristics. Instead of a uniform encryption approach, the system adjusts encryption methods according to data type, communication protocol, and security policy parameters, achieving efficiency without compromising necessary security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
According to an arrangement, an information processing device (17) includes a processing unit (173). The processing unit (173) is configured to: acquire, from one or more key management devices (10) that share, by an encryption relay using a first encryption key, second encryption keys with another key management device (10), an accumulated amount of the second encryption keys for each sharing destination; notify a control device (6) of a specific rule for specifying a flow to be encrypted by the second encryption keys; acquire flow information on a flow to be encrypted from the control device (6); determine whether the accumulated amount of the second encryption keys to be used by first and second communication devices (14a, 8) is equal to or larger than the amount of communication data; and instruct, among the one or more key management devices (10), a key management device (10) connected to the first communication device (14a) to provide the second encryption keys to the first communication device (14a) when the accumulated amount of the second encryption keys is equal to or larger than the amount of communication data.