Quantum Entropy Distribution via Software Defined Perimeter
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Server devices in high-security environments face challenges in generating high-quality random numbers for digital certificates and session keys due to entropy starvation, as they lack environmental sensors and are prone to crypto-analytic attacks from pseudorandom number generation methods, while quantum random number generators are expensive and not universally available.
Innovation Solution
Implementing a Software Defined Perimeter (SDP) system with an Entropy-as-a-Service (EaaS) that distributes quantum random numbers generated by a Quantum Random Number Generator (QRNG) via secure SDP connections to client devices, ensuring secure and unpredictable random number generation for certificate creation and session key establishment, thereby preventing entropy exhaustion and crypto-analytic attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If pseudorandom number generation methods are used, then device complexity is reduced, but reliability deteriorates due to vulnerability to crypto-analytic attacks
Solution Approach 1:
The patent introduces a quantum random number generator as an intermediary component that provides true random numbers to the cryptographic system. This mediator bridges the gap between simple pseudorandom generation and secure cryptography by injecting high-entropy quantum random numbers into the system, thereby enhancing security without requiring complete system redesign.
2Reliability
If quantum random number generators are deployed, then reliability improves through high-quality random numbers, but device complexity and cost increase
Solution Approach 1:
The quantum random number generator is designed to serve multiple functions: it provides random numbers for digital certificate generation, session key establishment, and other cryptographic operations. This multi-functionality justifies the added complexity by eliminating the need for separate random number sources for different cryptographic purposes.
Solution Approach 2:
The system performs preliminary generation and storage of quantum random numbers before they are needed for cryptographic operations. By pre-generating and storing high-entropy random numbers, the system ensures availability when needed without requiring complex real-time generation during critical cryptographic operations.
3Ease of operation
If server devices generate random numbers locally, then ease of operation improves, but reliability deteriorates due to entropy starvation
Solution Approach 1:
The patent extracts the quantum random number generation function from the server device and places it in a dedicated quantum random number generator. This separation allows the server to operate easily with simplified software while the specialized QRNG handles the complex task of high-entropy random number generation, resolving the conflict between ease of operation and reliability.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
The SDP system effectively distributes quantum random numbers securely, preventing entropy exhaustion and crypto-analytic attacks, ensuring robust authentication and encryption in high-security environments by using QRNG-generated numbers within the SDP framework.
Implementation Method 1
A computer device may include a quantum random number generator configured to generate a stream of random numbers using quantum phenomena
Data Source
AI summary
A computer device may include a memory storing instructions and processor configured to execute the instructions to receive a request for quantum random numbers from a client device. The processor may be further configured to establish a secure communication channel with the client device; obtain a stream of quantum random numbers from a quantum random number generator appliance; and provide a set of quantum random numbers from the obtained stream of quantum random numbers to the client device via the established secure communication channel.


