Quantum Key Distribution for Cloud Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cloud storage methods face security risks due to the ease of intercepting principal and component keys during transmission, and the vulnerability of mathematical algorithms to cracking as computer technology advances, leading to serious data security issues.
Innovation Solution
A cloud storage method and system utilizing a quantum key distribution (QKD) system to generate and manage quantum keys over a quantum network, combining these keys with a predetermined encryption algorithm to create a secure combined key for data encryption and decryption, ensuring that only authorized parties can access the data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If mathematical algorithms are used to divide and distribute encryption keys, then key management becomes feasible, but the keys become vulnerable to interception during transmission and future cracking
Solution Approach 1:
The patent replaces mathematical algorithms with quantum mechanics principles. Instead of using classical cryptographic algorithms to generate and distribute keys, the system employs quantum key distribution (QKD) protocols where quantum states encode key information. This substitution fundamentally changes the security basis from computational difficulty to physical law, making key distribution secure against both current and future computational attacks.
Solution Approach 2:
The patent changes the fundamental parameter of key representation from classical bits to quantum states. By encoding encryption keys in quantum mechanical properties (such as photon polarization or phase), the system transforms the nature of key storage and transmission. This parameter change enables security based on quantum no-cloning and measurement disturbance principles, preventing interception and future cracking that plague classical systems.
2Adaptability or versatility
If encryption keys are transmitted between terminal and cloud server, then data can be encrypted and decrypted, but the transmitted keys are easily intercepted by malicious attackers
Solution Approach 1:
The patent introduces quantum channels as intermediaries between the terminal and cloud server for key distribution. Instead of directly transmitting classical encryption keys through vulnerable networks, the system uses quantum-secured communication channels that leverage quantum mechanical properties to detect and prevent eavesdropping. This intermediary quantum channel acts as a secure bridge that eliminates the interception vulnerability of direct key transmission.
Solution Approach 2:
The patent applies preliminary anti-action by using quantum key distribution to establish secure keys before any data transmission occurs. The QKD protocol proactively detects any attempted interception during key establishment, and if eavesdropping is detected, the system aborts the key generation and alerts the users. This preliminary security check prevents malicious attackers from successfully intercepting keys before data encryption takes place.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach significantly enhances data security by making it difficult for malicious attackers to intercept and crack the quantum keys, thereby protecting the integrity of cloud-stored data.
Implementation Method 1
generating, by the QKD system and a QKD system on at least one cloud server side, at least one quantum key over a quantum network
Data Source
AI summary
A cloud storage method and a cloud storage system are provided. The method includes: generating, by a QKD system on a terminal side and a QKD system on at least one cloud server side, at least one quantum key over a quantum network; sending, by the QKD system, the at least one quantum key to the key management terminal for storage; and obtaining, by a cloud storage client, the at least one quantum key from the key management terminal, and processing the at least one quantum key to generate a combined key by a predetermined encryption algorithm.


