Quantum Key Distribution Authentication via Portable Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing quantum key distribution (QKD) methods are vulnerable to man-in-the-middle attacks and require shared secret data for authentication, limiting their applicability in network nodes without initial shared keys, and involve inefficient key distribution and maintenance processes.

Innovation Solution

A method and apparatus for authenticating network nodes using a portable quantum key device that establishes a quantum link with a node and performs an authentication step over an encrypted channel, allowing nodes to agree a quantum key without pre-shared secrets, enabling secure key distribution and initialization of new nodes within a communication network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If quantum key distribution is used without authentication, then key material can be distributed, but the system becomes vulnerable to man-in-the-middle attacks

Engineering Contradiction:
Improvekey distribution efficiencyVSAvoidsecurity against man-in-the-middle attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing authentication before quantum key distribution. The system uses pre-shared authentication keys to verify identities of communicating parties before they engage in QKD protocols, ensuring that only authenticated parties can establish quantum keys. This preliminary authentication step prevents man-in-the-middle attacks while maintaining efficient key distribution.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If pre-shared secret data is required for authentication, then security is improved, but the system becomes less adaptable to nodes without initial shared keys

Engineering Contradiction:
Improveauthentication securityVSAvoidnode integration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a key management centre as an intermediary that facilitates authentication and key distribution. The KMC acts as a trusted mediator that can issue authentication keys to nodes and manage the distribution of quantum keys throughout the network. This intermediary structure allows nodes without direct pre-shared secrets to be integrated into the network through the KMC, improving adaptability while maintaining security through centralized authentication management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables secure key distribution and authentication of network nodes without pre-shared secrets, facilitating the integration of new nodes and reducing maintenance-related key updates, while preventing man-in-the-middle attacks through quantum key agreement protocols.

Implementation Method 1

agreeing a quantum key between the first node and the remote node based on a quantum signal transmitted or received by the first node

Methodology Applied
Scientific EffectQuantum signal transmission:

Data Source

PatentEP2356772B1Quantum key distribution
Publication Date: 2020.04.08 QUBITEKK
  • EP2356772B1 patent drawingFigure 1~2
  • EP2356772B1 patent drawingFigure 3a~4

AI summary

The invention relates to methods and apparatus for Quantum key distribution. Such methods comprise authenticating a first node in a communications network with a remote node in the communications network. The authentication may include connecting an authentication device (302) to the first node, agreeing a quantum key between the first node and the remote node based on a quantum signal transmitted or received by the first node and performing an authentication step between the authentication device (302) and the remote node on an encrypted channel. Authentication between the authentication device (302) and remote node may be taken as authentication of the first node.