QKDN KSA Key Relay with Central Cipher Conversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing quantum key distribution networks lack operational flexibility and require high implementation effort in relaying key supply agent keys, with vulnerabilities allowing attackers to recover the keys.

Innovation Solution

A method involving a hybrid cipher conversion path that includes both in-path and off-path conversions, using a central cipher collector to bypass transit nodes and reduce the need for trusted nodes, thereby enhancing flexibility and reducing implementation effort.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional in-path cipher conversion method is used where transit QKD nodes convert ciphers sequentially, then the KSA key can be relayed through the network, but the implementation requires high effort and creates security vulnerabilities where attackers can recover keys at transit nodes

Engineering Contradiction:
ImprovesecurityVSAvoidimplementation effort
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Central Cipher Collector (CCC) as an intermediary component that centralizes the cipher conversion function. Instead of each transit QKD node performing cipher conversion (which creates security vulnerabilities), the CCC collects all necessary KMA keys and performs the cipher conversion in a centralized, secure location. This eliminates the security vulnerability at transit nodes while managing the complexity centrally rather than distributed across multiple nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple trusted transit QKD nodes are deployed to securely relay KSA keys, then security is improved, but the network flexibility and adaptability are reduced

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the cipher conversion function from the transit QKD nodes and relocates it to the Central Cipher Collector. This extraction allows transit nodes to operate without performing sensitive key operations, eliminating the need for them to be trusted nodes. Consequently, the network gains flexibility in node deployment and configuration while maintaining security through the centralized CCC architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If KSA keys are relayed through multiple transit nodes with sequential cipher conversions, then the key reaches the target node, but the process introduces high latency and delays

Engineering Contradiction:
Improvekey relay speedVSAvoidlatency
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the Central Cipher Collector pre-collect all necessary KMA keys from various transit nodes before the actual KSA key relay operation. When a KSA key needs to be relayed, the CCC already has all required keys available, enabling immediate cipher conversion without sequential waiting. This preliminary key collection significantly reduces the latency associated with key relay operations.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If a centralized cipher collection approach is used, then network flexibility and reduced latency are achieved, but the complexity of key management at the central collector increases

Engineering Contradiction:
Improveoperational flexibilityVSAvoidkey management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The Central Cipher Collector is designed as a universal component that handles multiple functions: collecting KMA keys from various transit nodes, managing different cipher conversion algorithms, supporting multiple KSA key relay operations simultaneously, and interfacing with different QKD node types. This multi-functionality consolidates complexity into a single versatile component rather than requiring complex configurations at each transit node, thereby improving operational flexibility while managing complexity centrally.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach allows for flexible and economical operation of quantum key distribution networks with reduced latency, improved security, and integration of different networks.

Implementation Method 1

a source QKD node of a QKDN transmits a KSA key as a source cipher via the QKDN to a target QKD node of the QKDN and the target QKD node receives the KSA key as a target cipher, the QKDN converting the source cipher into the target cipher

Methodology Applied
Scientific EffectQuantum key distribution:

Data Source

PatentEP4597919A1A method of relaying a KSA key within a qkdn
Publication Date: 2025.08.06 DEUTSCHE TELEKOM AG
  • EP4597919A1 patent drawingFigure 1
  • EP4597919A1 patent drawingFigure 2~3
  • EP4597919A1 patent drawingFigure 4

AI summary

A method of relaying a key supply agent, KSA, key within a quantum key distribution, QKD, network, QKDN, wherein, controlled by a QKDN controller of the QKDN, a source QKD node of a QKDN transmits a KSA key as a source cipher via the QKDN to a target QKD node of the QKDN and the target QKD node receives the KSA key as a target cipher, the QKDN converting the source cipher into the target cipher; a QKDN central ciper converter, CCC, for a QKDN, a QKDN, a QKDN system and a computer program product.