Quantum Entropy for Secure VPN Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems are vulnerable due to the predictability of public key infrastructure (PKI) certificates and public keys generated from low-entropy random number sources, leading to increased chances of network attacks and resource wastage in monitoring and correcting security issues.

Innovation Solution

A security platform utilizing quantum entropy to generate secure on-demand virtual private network (VPN) connections by creating quantum random numbers for encryption keys, providing a secure peer-to-peer communication channel between client devices, and conserving resources by reducing the need for continuous security monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional PKI certificates and public keys are generated from low-entropy random number sources, then device complexity and resource consumption are reduced, but network security reliability deteriorates due to predictability and vulnerability to attacks

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the fundamental parameter of randomness generation from classical low-entropy sources to quantum high-entropy sources. By utilizing quantum mechanical processes (such as photon detection or quantum random number generators), the system generates cryptographically secure random numbers with significantly higher entropy, making predicted keys impossible and thereby resolving the security reliability issue without requiring complex post-processing or mitigation measures

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces mechanical or software-based random number generators (which rely on algorithmic processes and are predictable) with quantum-based random number generation. This substitution fundamentally changes the source of randomness from a deterministic or pseudo-random process to a truly random quantum process, eliminating the predictability vulnerability while maintaining system efficiency

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If continuous security monitoring and correction measures are implemented to address PKI vulnerabilities, then network security reliability improves, but resource consumption and time loss increase

Engineering Contradiction:
Improvenetwork securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies preliminary action by implementing quantum random number generation at the key creation stage itself, rather than relying on post-creation security monitoring and correction. By embedding high-entropy quantum randomness in the initial key generation process, the system prevents security vulnerabilities before they can occur, eliminating the need for continuous monitoring and correction resources

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the inherent unpredictability of quantum processes, which was previously a challenge for deterministic systems, into a security benefit. The fundamental randomness of quantum mechanics, which cannot be predicted or controlled, becomes the foundation for unbreakable cryptographic keys, transforming a potential harm (unpredictability) into the greatest security advantage

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If quantum random numbers are generated for encryption keys, then network security against quantum computer attacks improves, but device complexity and computational overhead increase

Engineering Contradiction:
Improveresistance to quantum attacksVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the entropy parameter from classical low-entropy sources to quantum high-entropy sources, fundamentally improving resistance to quantum attacks. By utilizing quantum mechanical processes that generate true randomness rather than pseudo-randomness, the system creates keys that are computationally infeasible to break even with quantum computing power, without requiring complex additional security layers

Inventive Principle:
Principle #35Parameter changes

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The solution enhances network security by providing unpredictable encryption keys that are resistant to attacks, even from quantum computers, thereby reducing resource wastage and improving computing and network security.

Implementation Method 1

The security platform may generate a plurality of quantum random numbers based on establishing the connection with the first server device and based on the request to establish the peer-to-peer connection

Methodology Applied
Scientific EffectQuantum entropy:

Data Source

PatentUS11153079B2Systems and methods for utilizing quantum entropy for secure virtual private network connections
Publication Date: 2021.10.19 VERIZON PATENT & LICENSING INC
  • US11153079B2 patent drawing
  • US11153079B2 patent drawing
  • US11153079B2 patent drawing

AI summary

A device may establish a connection with a first server device based on a request to establish a peer-to-peer connection between a first client device, associated with the first server device, and a second client device associated with a second server device, and may generate a plurality of quantum random numbers based on establishing the connection with the first server device and based on the request to establish the peer-to-peer connection. The device may generate encryption keys for the first client device and the second client device based on the plurality of quantum random numbers, and may provide the encryption keys to the first client device and the second client device to cause an encrypted peer-to-peer connection to be established between the first client device and the second client device, via an interface provided between the first server device and the second server device.