QKD Key Exchange With Public-Key Protection Against Unreliable Key Managers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional QKD networks face security vulnerabilities due to unreliable key management apparatuses, which can compromise the integrity of key information.
Innovation Solution
A key exchange system where hub apparatuses generate a public key and secret key pair, sharing the secret key between themselves and encrypting QKD keys with the public key, thereby concealing the keys from unreliable key management apparatuses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If key management apparatuses relay keys in a QKD network, then key exchange functionality is improved, but security is worsened when key management apparatuses are unreliable
Solution Approach 1:
The patent segments the key management functionality by separating key generation (QKD apparatus) from key distribution (key management apparatus). The QKD apparatus generates keys locally and encrypts them with the hub apparatus's public key before transmission, so the key management apparatus only handles encrypted data without accessing the actual key material, thus maintaining security while enabling key relay functionality.
Solution Approach 2:
The patent introduces an intermediary encryption mechanism using public key cryptography. The encrypted key serves as an intermediary form that can be safely transmitted through unreliable key management apparatuses without compromising security, as they cannot decrypt or access the actual key information.
2Productivity
If QKD keys are transmitted through key management apparatuses, then key distribution capability is improved, but risk of key information leakage increases
Solution Approach 1:
The patent applies preliminary anti-action by encrypting the QKD key with the hub apparatus's public key before transmission. This pre-encryption protects the key from potential leakage during transmission through key management apparatuses, counteracting the harmful effect of unreliable intermediaries before the transmission occurs.
Solution Approach 2:
The encrypted key acts as a safe intermediary form that enables key distribution through key management apparatuses without exposing the actual key material. The key management apparatus can forward the encrypted data without accessing the plaintext key, thus enabling distribution capability while preventing information leakage.
3Reliability
If public key encryption is used to protect QKD keys, then security against unreliable key management apparatuses is improved, but computational complexity increases
Solution Approach 1:
The patent applies local quality by using public key encryption only at specific critical points (key generation and transmission to hub apparatus) rather than throughout the entire key management system. The key management apparatus handles only encrypted data without performing decryption operations, localizing the computational complexity to where it is most needed for security while minimizing overall system complexity.
Data Source
AI summary
A key exchange system includes a quantum key distribution (QKD) network including a plurality of QKD apparatuses that performs exchange of a key by using a quantum key distribution protocol and a key management apparatus that relays the key; and a plurality of hub apparatuses that performs encrypted communication by using the key received from the key management apparatus. Each of the QKD apparatuses includes a processor configured to encrypt the key by using a public key of one of the hub apparatuses in a case where the key is exchanged with another QKD apparatus by using the quantum key distribution protocol, and transmit the encrypted key to the key management apparatus. Each of the hub apparatuses includes a processor configured to decrypt the encrypted key by using a secret key corresponding to the public key in a case where the encrypted key is received from the key management apparatus.


