QKD Key Exchange With Public-Key Protection Against Unreliable Key Managers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional QKD networks face security vulnerabilities due to unreliable key management apparatuses, which can compromise the integrity of key information.

Innovation Solution

A key exchange system where hub apparatuses generate a public key and secret key pair, sharing the secret key between themselves and encrypting QKD keys with the public key, thereby concealing the keys from unreliable key management apparatuses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If key management apparatuses relay keys in a QKD network, then key exchange functionality is improved, but security is worsened when key management apparatuses are unreliable

Engineering Contradiction:
Improvekey exchange functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the key management functionality by separating key generation (QKD apparatus) from key distribution (key management apparatus). The QKD apparatus generates keys locally and encrypts them with the hub apparatus's public key before transmission, so the key management apparatus only handles encrypted data without accessing the actual key material, thus maintaining security while enabling key relay functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary encryption mechanism using public key cryptography. The encrypted key serves as an intermediary form that can be safely transmitted through unreliable key management apparatuses without compromising security, as they cannot decrypt or access the actual key information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If QKD keys are transmitted through key management apparatuses, then key distribution capability is improved, but risk of key information leakage increases

Engineering Contradiction:
Improvekey distribution capabilityVSAvoidkey information leakage
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by encrypting the QKD key with the hub apparatus's public key before transmission. This pre-encryption protects the key from potential leakage during transmission through key management apparatuses, counteracting the harmful effect of unreliable intermediaries before the transmission occurs.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The encrypted key acts as a safe intermediary form that enables key distribution through key management apparatuses without exposing the actual key material. The key management apparatus can forward the encrypted data without accessing the plaintext key, thus enabling distribution capability while preventing information leakage.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If public key encryption is used to protect QKD keys, then security against unreliable key management apparatuses is improved, but computational complexity increases

Engineering Contradiction:
Improvesecurity against unreliable key management apparatusesVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by using public key encryption only at specific critical points (key generation and transmission to hub apparatus) rather than throughout the entire key management system. The key management apparatus handles only encrypted data without performing decryption operations, localizing the computational complexity to where it is most needed for security while minimizing overall system complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250300820A1Key exchange system, QKD apparatus, hub apparatus, method, and program
Publication Date: 2025.09.25 NT T INC
  • US20250300820A1 patent drawing
  • US20250300820A1 patent drawing
  • US20250300820A1 patent drawing

AI summary

A key exchange system includes a quantum key distribution (QKD) network including a plurality of QKD apparatuses that performs exchange of a key by using a quantum key distribution protocol and a key management apparatus that relays the key; and a plurality of hub apparatuses that performs encrypted communication by using the key received from the key management apparatus. Each of the QKD apparatuses includes a processor configured to encrypt the key by using a public key of one of the hub apparatuses in a case where the key is exchanged with another QKD apparatus by using the quantum key distribution protocol, and transmit the encrypted key to the key management apparatus. Each of the hub apparatuses includes a processor configured to decrypt the encrypted key by using a secret key corresponding to the public key in a case where the encrypted key is received from the key management apparatus.