QKD Network Node Key Transmission Using PQC Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current QKD network nodes rely on expensive and potentially insecure SSL-based protocols for data exchange, which may not be sufficient against future quantum computer threats, and there is a need for an alternative method to securely transmit quantum keys within these nodes.

Innovation Solution

Implementing a method that uses Post-Quantum Cryptography (PQC) encryption methods to encrypt quantum keys across multiple structural levels within a QKD-capable network node, ensuring secure transmission and reducing the need for extensive security equipment, with authentication processes and a client-server protocol for key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SSL-based protocols are used for data exchange within QKD network nodes, then security is provided through established cryptographic methods, but the security may no longer be sufficient against future quantum computer threats and extensive security equipment is required

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity equipment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces SSL-based cryptographic protocols with quantum key distribution mechanisms for securing data exchange within QKD network nodes. This substitution transitions from classical cryptographic security to quantum-based security, eliminating the need for extensive SSL security equipment while providing future-proof protection against quantum computer threats. The QKD system generates and distributes quantum keys that secure communication between components without requiring traditional SSL infrastructure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If SSL-based protocols with RSA, Diffie-Hellman, or elliptic curve cryptography are used for encrypting data traffic, then data exchange is secured, but the protection is complex and expensive

Engineering Contradiction:
Improvedata exchange securityVSAvoidsecurity protection
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent substitutes SSL-based encryption protocols with quantum key distribution for securing data exchange. Instead of using RSA, Diffie-Hellman, or elliptic curve cryptography, the system employs quantum-mechanical key generation and distribution to secure communication between QKD network node components. This eliminates the complexity of multiple cryptographic protocols while providing inherent security based on quantum physics principles.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameter of security from classical cryptographic complexity to quantum key properties. By transitioning from mathematical security assumptions to quantum physical principles, the system achieves security without the complex protocol stacks required by SSL-based approaches. The quantum keys generated through QKD provide information-theoretic security that does not rely on computational complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If trusted nodes with specialized monitoring and access control technology are used, then robust security is ensured, but the technology is very expensive

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent replaces expensive trusted node infrastructure with quantum key distribution mechanisms. Instead of relying on specialized monitoring and access control technology, the system uses quantum-secured key exchange to protect data exchange between components. This substitution eliminates the need for costly trusted node hardware while maintaining or enhancing security through quantum physics-based protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3955511B1Secure data transmission within a qkd network node
Publication Date: 2023.06.07 DEUTSCHE TELEKOM AG
  • EP3955511B1 patent drawingFigure 1

AI summary

The invention relates to a solution for cryptographically secured transmission of quantum keys between structural levels (1, 2, 3) and components within a QKD-capable network node. It relates to a network node with a structural level (1) of a manufacturer-specific key management system, i.e., a key management system (6; 6') whose characteristics are determined by the manufacturer of the QKD system, with a structural level (2) of a provider-specific key management system (8; 8'), i.e., a key management system whose characteristics are determined by the operator of the network node, and with an application level (3) to which quantum keys are provided for secure data exchange via one of the layers of the OSI model.According to the invention, one or more quantum keys within the network node, namely from the structure level (1) to be stored in a key memory (7; 7') to the structure level (2) or from the structure level (2) to the application level (3) for the encryption of application data, are each quantum-safe encrypted and transmitted using a PQC encryption method.