Quantum Key Delivery Proof of Origin and Transit via Polynomial Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current quantum key distribution systems face challenges in extending link distance, validating secure keys generated by different key management entities, and identifying compromised trusted nodes, leading to resource consumption and increased vulnerability to attacks.

Innovation Solution

A controller device generates polynomials to create disjoint paths through a network of intermediate devices, assigning secret points to each device, and verifies cumulative values to ensure secure keys originate from different key management entities and traverse distinct paths, providing proof of origin and transit.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Length of stationary object

If quantum key distribution uses intermediate trusted nodes to extend link distance, then the link distance is improved, but the security vulnerability increases due to potential compromise of trusted nodes

Engineering Contradiction:
Improvelink distanceVSAvoidsecurity vulnerability
Core Design Contradiction:
Length of stationary objectVSReliability

Solution Approach 1:

The patent divides the quantum key distribution system into multiple independent polynomial shares, each distributed to different intermediate nodes. Instead of relying on a single trusted node, the secret is segmented into multiple shares that require collaboration to reconstruct, reducing the security vulnerability of individual nodes while enabling extended link distance through multiple intermediates.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested verification mechanisms where cumulative values are embedded within key confirmation messages. The verification process nests multiple layers of validation (cumulative value verification, polynomial share verification, path verification) within the key distribution protocol, providing security validation at multiple levels to mitigate risks from intermediate nodes.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If the system validates secure keys from different key management entities, then the security is improved, but the computing resources are consumed

Engineering Contradiction:
Improvesecurity validationVSAvoidcomputing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary actions by pre-distributing polynomial shares to intermediate nodes before actual key distribution. The cumulative values are pre-calculated and embedded in the path information, so that during key distribution, nodes can quickly verify authenticity without intensive real-time computation, reducing computing resource consumption while maintaining security validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service verification where intermediate nodes automatically verify cumulative values against their stored polynomial shares and validate key provenance without requiring external arbitration. Each node uses its own stored shares to verify the authenticity of keys passing through it, eliminating the need for additional validation infrastructure and reducing overall computing resource requirements.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If the system uses polynomial shares for path verification, then the proof of origin and transit is improved, but the device complexity increases

Engineering Contradiction:
Improveproof of origin and transitVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal polynomial share structure that serves multiple functions: it provides proof of origin, verifies path integrity, enables cumulative value verification, and confirms key authenticity. This single mathematical structure performs all verification tasks, reducing the need for separate validation mechanisms and simplifying the overall system despite the enhanced proof capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If multiple disjoint paths are used for key distribution, then the security against attacks is improved, but the network complexity increases

Engineering Contradiction:
Improveattack resistanceVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key distribution into multiple independent polynomial shares distributed along different disjoint paths. Each path carries a portion of the secret information, and the segmentation allows the system to tolerate path compromise while maintaining security. The polynomial share structure naturally accommodates multiple paths without requiring complex coordination between them.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12375276B2Providing quantum key distribution key delivery proof of origin and transit
Publication Date: 2025.07.29 JUNIPER NETWORKS INC
  • US12375276B2 patent drawing
  • US12375276B2 patent drawing
  • US12375276B2 patent drawing

AI summary

A device may generate a first polynomial and a second polynomial, and may generate, based on the first polynomial, a primary path from a first network device to a second network device via a first set of intermediate network devices. The device may generate, based on the second polynomial, a secondary path from the first network device to the second network device via a second set of intermediate network devices, and may assign a point of the first and second polynomials to the device, to each of the first set of intermediate network devices and of the second set of intermediate network devices. The device may cause the primary path to be provided from the first network device to the second network device, and may cause the secondary path to be provided from the first network device to the second network device.