Quantum Network Authentication via Third-Node Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In quantum cryptography networks, replacing Key Management Centres (KMCs) or intermediate nodes is a slow and expensive process due to the need to update authentication keys across the entire network, and memory limitations restrict the size of the network as each node must store authentication keys with every KMC, leading to inefficiencies in key management and re-keying processes.

Innovation Solution

A method where authentication between network nodes is facilitated through a third network node sharing authentication keys with both nodes, allowing for dynamic updating of authentication keys and reducing the number of keys stored in each node, enabling faster re-keying and maintenance by only updating keys between KMCs and using a single authentication key for multiple KMCs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each node stores authentication keys with every KMC to enable direct authentication, then authentication reliability is improved, but memory requirements and device complexity increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a third node as an intermediary that facilitates authentication between the first and second nodes. Each node stores authentication keys only with the third node, not with each other. The third node mediates the authentication process by verifying identities and enabling secure communication, thereby reducing the key management complexity from O(n²) to O(n) while maintaining authentication reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The third node serves multiple functions: it acts as an authentication authority for both the first and second nodes, manages the authentication keys, and facilitates the authentication process. This multi-functional role eliminates the need for direct key pairs between all node combinations, reducing overall system complexity while preserving security

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If authentication keys are updated across the entire network when replacing a KMC, then security is improved, but the replacement process becomes slower and more expensive

Engineering Contradiction:
ImprovesecurityVSAvoidKMC replacement time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The third node serves as a stable intermediary that remains in place during KMC replacement. When a KMC is replaced, only the authentication keys between the third node and the new KMC need to be updated, not the keys between the third node and all other nodes. This localized key update approach maintains security while dramatically reducing replacement time and cost

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication key management is segmented into separate key pairs: one between the first node and third node, and another between the second node and third node. This segmentation allows independent management and replacement of KMCs without requiring network-wide key updates, enabling faster and more cost-effective maintenance while preserving security

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If each node stores multiple authentication keys for different KMCs, then network adaptability is improved, but memory usage increases

Engineering Contradiction:
Improvenetwork adaptabilityVSAvoidmemory usage
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The third node acts as a universal intermediary that enables communication with multiple KMCs. Each node only needs to store authentication keys with the third node, not with each KMC individually. The third node handles the adaptability to different KMCs, allowing nodes to communicate with any KMC through the third node without increasing local memory requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The third node provides universal access to multiple KMCs, making the authentication system adaptable to different KMCs without requiring each node to store multiple keys. The third node's multi-functional role in managing relationships with different KMCs enables network adaptability while keeping individual node memory usage minimal

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2366232B1Method of performing authentication between network nodes
Publication Date: 2019.08.28 QUBITEKK
  • EP2366232B1 patent drawingFigure 1~2
  • EP2366232B1 patent drawingFigure 3~4
  • EP2366232B1 patent drawingFigure 5~6

AI summary

A method of authentication between first (QNodeX) and second (QNodeY) network nodes within a network suitable for implementing quantum cryptography comprises steps in which the first and second nodes each generate a cryptographic hash ([MXY]AI, [MYX]AJ) of a message ([MXY], [MYX]) using respective authentication keys (AI, AJ) shared with a third network node (QNodeW). The messages may be those exchanged between the first and second nodes during agreement of a quantum key to be used between the nodes. An authentication key to be shared by the first and second nodes may be established using the quantum key. The invention therefore allows an authentication key to be established and shared between the first and second network nodes without direct physical intervention. Networks having large numbers of network nodes may be re-keyed following replacement or maintenance of a network node much more quickly and easily than is the case where re-keying is achieved by physically supplying shared authentication keys.