Quantum Key Distribution Trusted Node Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current QKD technologies face limitations in distance due to unavoidable loss in optical waveguides and the inability to use optical amplifiers, leading to restricted communication ranges, and Trusted Nodes store final keys, posing a security risk and key management challenges, especially when multiple users share intermediate nodes.
Innovation Solution
Integrating Post-Quantum Cryptography (PQC) in the Encrypted Key Relay (EKR) mode within QKD networks, using a method that ensures the Trusted Node does not access confidential data without increasing key consumption, by employing symmetric encryption and classical channels for key agreement, maintaining quantum-safe confidentiality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Length of stationary object
If Trusted Nodes store final keys for key relay, then distance limitation is overcome and QKD networks can span long ranges, but security risk increases and key management challenges arise
Solution Approach 1:
The patent extracts the confidential key material from the Trusted Node by implementing key consumption at the endpoints (Alice and Bob) rather than storing it centrally. The Trusted Node only handles encrypted representations or key material that cannot reconstruct the final key, removing the security vulnerability of central key storage while maintaining the distance-extension capability.
Solution Approach 2:
The key management function is segmented between endpoints and intermediate nodes. Alice and Bob perform key consumption operations locally, while the Trusted Node performs only forwarding and routing functions. This segmentation eliminates the need for the Trusted Node to possess the final key, reducing security risks while enabling long-distance communication through multiple intermediate nodes.
2Ease of operation
If Trusted Nodes fully store and manage final keys, then key distribution is simplified, but key overhead increases and efficiency decreases
Solution Approach 1:
The endpoints (Alice and Bob) perform self-service key consumption operations using their private keys and the key material received from the Trusted Node. This eliminates the need for the Trusted Node to perform complex key management operations such as key generation, storage, and distribution, simplifying its role to routing and forwarding while improving overall key efficiency.
3Adaptability or versatility
If Trusted Nodes are shared between multiple users, then network resource utilization improves, but confidentiality of exchanged keys deteriorates
Solution Approach 1:
The patent extracts the confidential key material from the Trusted Node's processing domain. Each user consumes their own key material independently at their endpoint using their private key, ensuring that the Trusted Node never possesses or processes other users' key material. This enables secure multi-user sharing while maintaining strict confidentiality isolation.
Solution Approach 2:
Each user's key consumption operation is segmented and performed independently at their endpoint. The Trusted Node handles only public or encrypted representations that cannot reveal other users' key material. This segmentation ensures that multi-user sharing does not compromise the confidentiality of any individual user's keys.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The present invention relates to a QKD communication method between a first node A and a second node B through at least one intermediary node T, comprising the steps of generating, at the first node A, a key K, which is symmetrically encrypted using a key K' to create a resulting encrypted key m, encrypting, at the first node A, said message m with a key K1 and sending this encrypted message as well as K1 to said intermediary node T, decrypting, at said intermediary node T, the message sent from said first node A with K1 to obtain m and then OTP-encrypting said message m with a key K2 and sending this encrypted message as well as the key K2 to said second node B, and decrypting, at the second Node B, the message sent from T with K2 to obtain m and symmetrically decrypts m with the key K' to recover the key K, characterized in that K' is obtained by the steps of generating, at the first node A, a key K' and a message m' to be sent to the second node B, sending the message m' to the at least one intermediary node T via a classical communication channel, which in turn forwards it to the second node B, and obtaining, at the second node, the key K' by using a private key and the message m'.