Quantum Key Distribution Node Architecture for OpenStack Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional OpenStack key management systems rely on envelope encryption, which is insecure against quantum computer decryption, compromising the security of data ciphertexts during cross-node data transmission.

Innovation Solution

A quantum-key-based key management system is introduced, featuring a control node, computing nodes, and Quantum Key Distribution (QKD) nodes. QKD nodes generate root keys, Key Encryption Keys (KEKs), and Data Encryption Keys (DEKs), ensuring secure key distribution and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If envelope encryption is used for cross-node data transmission, then data can be encrypted and transmitted, but the security of data ciphertext is compromised against quantum computer decryption

Engineering Contradiction:
Improvedata securityVSAvoidquantum decryption threat
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional classical encryption mechanisms (envelope encryption using symmetric and asymmetric keys) with quantum key distribution mechanisms. QKD nodes use quantum mechanical principles to generate and distribute encryption keys, providing security that is fundamentally resistant to quantum computer attacks, thus resolving the vulnerability to quantum decryption threats while maintaining data encryption capability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameter of key distribution from classical cryptographic methods to quantum key distribution methods. By introducing QKD nodes that generate keys based on quantum mechanics principles, the system transforms the security model from computationally secure to physically secure, eliminating the harm of quantum decryption threats while preserving encryption functionality

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple QKD nodes are introduced to generate and distribute quantum-secure keys, then security against quantum decryption is improved, but system complexity increases

Engineering Contradiction:
Improvequantum-secure encryptionVSAvoidkey management system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key management system by introducing dedicated QKD nodes that are separate from computing nodes. Each QKD node is responsible for generating and distributing quantum-secure keys to specific computing nodes, creating a modular architecture where security functions are separated from computation functions, thus managing complexity through functional segmentation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces QKD nodes as intermediary components between computing nodes. These intermediary nodes handle the complex task of quantum key generation and distribution, shielding the computing nodes from quantum cryptographic complexity while providing them with secure keys, thus resolving the contradiction between security improvement and system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12225110B2Key management system
Publication Date: 2025.02.11 INSPUR SUZHOU INTELLIGENT TECH CO LTD
  • US12225110B2 patent drawing
  • US12225110B2 patent drawing

AI summary

A key management system is disclosed, including: a control node; multiple computing nodes, all the multiple computing nodes are connected to the control node; and multiple Quantum Key Distribution (QKD) nodes, all the multiple QKD nodes are connected to the control node, and each QKD node is connected to one of the computing nodes, where each QKD node is configured to generate a root key, generate Key Encryption Keys (KEKs) between the QKD node and a plurality of other QKD nodes according to a first instruction sent by the control node, and generate, according to a second instruction sent by the control node, a Data Encryption Key (DEK) corresponding to a user on the computing node connected to the QKD node.