Single-Pass QKD System Key Negotiation Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems using quantum key distribution (QKD) face issues with secure data transmission due to missing cryptographic keys, key identity verification, and vulnerability to man-in-the-middle attacks, leading to interrupted data transmission and increased costs from separate interaction channels.

Innovation Solution

A single-pass quantum key distribution system with a transmitting and receiving node, utilizing quantum communication links and local communication links to generate and negotiate authentication and encryption keys, ensuring identical key usage for encryption and decryption, and authenticating service data to enhance security and robustness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If quantum key distribution is used to generate cryptographic keys, then security of transmitted information is improved, but data transmission may be interrupted when keys are missing

Engineering Contradiction:
Improvesecurity of transmitted informationVSAvoiddata transmission continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication of service data (key negotiation messages, error correction data, secrecy enhancement data) before using them for key generation. This ensures that only authenticated and reliable service data is processed, preventing transmission interruptions caused by unauthenticated or corrupted keys.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication mechanism as an intermediary layer between the quantum key distribution process and the actual key usage. Service data is authenticated using authentication keys derived from quantum keys, creating a trusted intermediary verification step that ensures continuity of secure transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If separate classical communication links are used for QKD system and encryptors, then functionality is improved, but system cost and complexity increase

Engineering Contradiction:
Improvefunctionality of key distributionVSAvoidnumber of communication links
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the classical communication channels by allowing encryptors to directly exchange authenticated service data with each other using a shared authentication key. This eliminates the need for separate classical communication links between QKD systems and encryptors, reducing system complexity while maintaining full functionality through direct peer-to-peer authenticated communication.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If key identifiers are transmitted openly for negotiation, then key exchange is simplified, but vulnerability to forcing false key identifiers increases

Engineering Contradiction:
Improvekey exchange processVSAvoidman-in-the-middle attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by authenticating service data (including key identifiers) before they are processed or accepted. Authentication keys derived from quantum keys are used to verify the authenticity of service data, preemptively counteracting potential man-in-the-middle attacks that would otherwise force false key identifiers.

Inventive Principle:
Principle #9Preliminary anti-action

4Productivity

If quantum keys are used directly without authentication, then key generation speed is improved, but integrity and authenticity of service data cannot be ensured

Engineering Contradiction:
Improvekey generation speedVSAvoidintegrity of service data
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent performs preliminary authentication of all service data (key negotiation messages, error correction data, secrecy enhancement data) using authentication keys derived from quantum keys before these data are used in the key generation process. This preliminary verification ensures integrity and authenticity are established before key generation proceeds, maintaining both speed and reliability.

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach ensures improved security, robustness, and reduced costs by authenticating service data and using identical keys for encryption and decryption, maintaining secure data transmission even with temporary key generation interruptions and reducing the need for separate classical communication links.

Implementation Method 1

a transmitting quantum key generation module (5), a receiving quantum key generation module (7) connected to each other by a quantum communication link (9)

Methodology Applied
Scientific EffectQuantum key distribution:

Data Source

PatentUS11728980B2System for secure data transmission in digital data transmission network using single-pass quantum key distribution system and method of key negotiation during operation of the system
Publication Date: 2023.08.15 OTKRYTOE AKTSIONERNOE OBSHCHESTVO INFORMATSIONNYE TEKHNOLOGII I KOMMUNIKATSIONNYE SISTEMY
  • US11728980B2 patent drawing

AI summary

The present invention relates to cryptographic protection of information by using keys derived from quantum keys from an associated quantum key distribution (QKD) system. The system includes a transmitting node and a receiving node of a single-pass QKD system, and two encryptors connected by a classical communication channel. The one encryptor is further connected to the transmitting node of the QKD system by a first local communication link, and the other encryptor is connected to the receiving node of the QKD system by a second local communication link. A method of implementing the system includes generating encryption keys and authentication keys based on quantum keys of a size not less than the one specified in operation of the system, exchanging service data in course of execution of the quantum protocol using the encryption keys and authentication keys, and providing identity of the encryption keys and the authentication keys.