Quantum Entropy Distribution via Segmented Secure Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems face challenges in generating and securely distributing high-quality true random entropy, which is essential for generating secure cryptographic keys, due to difficulties in finding trusted entropy sources and ensuring the integrity of entropy during communication.

Innovation Solution

The method involves using a quantum entropy generator to produce quantum entropy, which is securely distributed among computer systems through established communication channels using cryptographic keys generated from the entropy, allowing systems without direct access to the entropy source to receive and securely communicate the entropy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a quantum entropy generator is used to produce high-quality true random entropy, then the quality and trustworthiness of cryptographic keys are improved, but the difficulty of securely distributing the entropy to multiple computer systems increases

Engineering Contradiction:
Improvequality of cryptographic keysVSAvoidcomplexity of entropy distribution system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The entropy distribution system is segmented into multiple independent communication channels, each established between the entropy source and a specific computer system. This segmentation allows the high-quality entropy to be distributed to multiple systems without requiring a complex centralized distribution mechanism, as each system receives entropy through its own dedicated secure channel.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses cryptographic keys as an intermediary mechanism to secure the entropy distribution process. The cryptographic keys, generated from the quantum entropy, mediate the secure communication between the entropy source and computer systems, enabling trusted distribution without requiring direct physical security or complex centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic keys are generated using entropy information to establish secure communication channels, then the security of the communication channel is improved, but the risk of key compromise and tampering increases

Engineering Contradiction:
Improvesecurity of communication channelVSAvoidvulnerability to tampering and compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent employs parameter changes by continuously regenerating cryptographic keys at predetermined intervals or upon detecting specific conditions. This dynamic key regeneration changes the security parameters over time, ensuring that even if one key is compromised, the system can quickly transition to new keys, thereby maintaining communication security while mitigating the impact of potential compromises.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements periodic key regeneration and communication channel re-establishment at predetermined intervals. This periodic action ensures that cryptographic keys are regularly refreshed, reducing the window of opportunity for attackers to compromise keys and limiting the damage from any single key compromise event.

Inventive Principle:
Principle #19Periodic action

3Adaptability or versatility

If entropy information is communicated from one computer system to another using established channels, then access to high-quality entropy is improved for systems without direct source access, but the risk of entropy tampering during transmission increases

Engineering Contradiction:
Improveaccess to entropy for multiple systemsVSAvoidrisk of tampering during transmission
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent uses securely established communication channels, protected by cryptographic keys derived from the same quantum entropy source, as intermediaries to transmit entropy information between computer systems. This intermediary protection ensures that entropy can be shared adaptively across multiple systems while the cryptographic intermediaries prevent tampering during transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system incorporates feedback mechanisms to detect and respond to potential tampering during entropy transmission. By monitoring the integrity of transmitted entropy and the health of communication channels, the system can identify compromise attempts and trigger key regeneration or channel re-establishment, thereby maintaining security while enabling versatile entropy distribution.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12088705B2Secure distribution of entropy
Publication Date: 2024.09.10 ORACLE INT CORP
  • US12088705B2 patent drawing
  • US12088705B2 patent drawing
  • US12088705B2 patent drawing

AI summary

Techniques are disclosed for securely distributing entropy in a distributed environment. The entropy that is distributed may be quantum entropy that is generated by a quantum entropy generator or source. The true random entropy generated by a trusted entropy generator can be communicated securely among computer systems or hosts using secure communication channels that are set up using a portion of the entropy. The distribution techniques enable computer systems and hosts, which would otherwise not have access to such entropy generated by the trusted entropy source, to have access to the entropy.