QKD System Service Continuity Mode Bandwidth
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Quantum Key Distribution (QKD) systems face limitations in bandwidth, particularly in large-scale networks over long distances, leading to potential shortages of usable bits for data transfer, while attempts to increase bandwidth often compromise security.
Innovation Solution
The introduction of a Service Continuity (SC) mode in QKD systems, which combines the QKD protocol with symmetric encryption schemes like Block Cipher algorithms, allowing for higher key delivery rates without compromising the quality of encryption keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If key derivation function or key expansion mechanism is used to increase key size, then bandwidth is increased, but security quality deteriorates due to diluted entropy
Solution Approach 1:
The patent segments the key management process into two distinct parts: (1) QKD generates a master key with full entropy for secure key establishment, and (2) a separate key expansion mechanism generates additional keys derived from this master key. This segmentation allows the system to maintain high security quality through the entropy-preserving QKD process while achieving increased bandwidth through the key expansion mechanism that generates multiple usable keys from the single master key.
2Productivity
If classical key exchange mechanism is used instead of QKD, then bandwidth is increased, but quantum safety deteriorates
Solution Approach 1:
The patent merges two previously separate systems into a hybrid architecture: the QKD system provides quantum-safe master key establishment, while a classical key expansion mechanism provides efficient key generation. This merging allows the system to achieve high bandwidth through the classical key expansion process while maintaining quantum safety through the foundational QKD-based master key, thereby resolving the contradiction between bandwidth and quantum safety.
3Productivity
If post-quantum cryptographic scheme is used instead of QKD, then bandwidth is increased, but security robustness deteriorates due to less understood assumptions
Solution Approach 1:
The patent introduces a key expansion mechanism as an intermediary component between QKD and the final encryption keys. This intermediary takes the securely established QKD master key and efficiently generates additional keys through a controlled expansion process. This intermediary approach allows the system to achieve high bandwidth without relying on post-quantum cryptographic assumptions, thereby maintaining security robustness while improving productivity.
Data Source
Figure 1
Figure 2
AI summary
The present invention relates to a Quantum Key Distribution system comprising an emitter and a receiver adapted to exchange QKD-based key through a service continuity mode comprising: starting (S100) the process and triggering (S101) QKD-based key exchange between the emitter and the receiver, exchanging (S102) a first key K1 between the emitter and the receiver, generating (S103) a second key K2 at the emitter via its QRNG, and encrypting (S104) K2 with K1 as a message C, and send it to the receiver, decrypting (S105) message C with K1 to obtain K2 at the receiver, and delivering (S106, S106') K2 to the respective consumers, characterized in that the QKD exchanged key K1 is a single key with fixed size, and the encrypting and decrypting procedures of K2 are using a symmetric encryption scheme.