Quantum Key Distribution for Cloud Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data security measures in cloud storage are inadequate for ensuring the secure storage and retrieval of sensitive data due to risks of unauthorized access and data breaches, as they fail to meet the unique security requirements of cloud storage environments.

Innovation Solution

A system and method utilizing quantum data keys and trusted computing to securely store and retrieve data, where client devices and storage servers negotiate and share quantum data keys, perform mutual authentication, and encrypt data using these keys, ensuring secure storage and retrieval through trusted measurement reports and hash validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is distributed to multiple storage locations in cloud storage, then storage capacity and accessibility are improved, but the risk of unauthorized physical access and data breaches increases

Engineering Contradiction:
Improvestorage accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security protection mechanism by implementing encryption at the data segment level rather than relying on physical security of entire storage locations. Each data piece is encrypted with quantum keys before distribution across multiple cloud storage nodes, allowing widespread accessibility while maintaining security through cryptographic segmentation rather than physical consolidation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces quantum key distribution as an intermediary security layer between the data and storage locations. Instead of relying on physical security of storage facilities, quantum-encrypted keys act as mediators that control access to distributed data, enabling secure retrieval through cryptographic verification rather than physical presence at storage locations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If conventional encryption methods are used for cloud storage, then ease of implementation is maintained, but security against quantum computing attacks and unauthorized access is insufficient

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent changes the fundamental parameter of cryptographic security from classical to quantum-level encryption. By implementing quantum key distribution and quantum-resistant algorithms, the system transitions from conventional encryption parameters that are vulnerable to quantum attacks to quantum-grade security parameters that provide future-proof protection while maintaining cloud storage functionality.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent performs preliminary quantum key distribution and key establishment before actual data storage operations. By pre-establishing quantum-secure key pairs and distributing quantum-encrypted keys to cloud storage nodes beforehand, the system prepares security infrastructure in advance, making quantum-secure encryption as integrated and straightforward as conventional encryption while providing superior security guarantees.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If quantum data keys are used for encryption, then security against unauthorized access is enhanced, but key management complexity and computational overhead increase

Engineering Contradiction:
Improvesecurity strengthVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the quantum key distribution system automatically generates, distributes, and manages quantum-encrypted keys between cloud storage nodes and client devices. The system performs automated key rotation, renewal, and verification without requiring manual cryptographic management, reducing the complexity burden on users while maintaining quantum-grade security through automated key lifecycle management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal quantum key management infrastructure that serves multiple functions: encryption key generation, authentication verification, data integrity checking, and secure communication establishment. This multi-functional quantum key system consolidates what would otherwise be separate security mechanisms into a single unified key management framework, reducing overall system complexity while providing comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10574446B2Method and system for secure data storage and retrieval
Publication Date: 2020.02.25 CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
  • US10574446B2 patent drawing
  • US10574446B2 patent drawing
  • US10574446B2 patent drawing

AI summary

One embodiment described herein provides a system and method for secure data storage. During operation, a client device selects a quantum data key from a plurality of quantum data keys shared between the client device and a storage server, encrypts to-be-stored data using the selected quantum data key, and transmits a data-storage request to the storage server. The data-storage request comprises a key-identifier of the selected quantum data key and the encrypted data.