Quantum Key Distribution for Cloud Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data security measures in cloud storage are inadequate for ensuring the secure storage and retrieval of sensitive data due to risks of unauthorized access and data breaches, as they fail to meet the unique security requirements of cloud storage environments.
Innovation Solution
A system and method utilizing quantum data keys and trusted computing to securely store and retrieve data, where client devices and storage servers negotiate and share quantum data keys, perform mutual authentication, and encrypt data using these keys, ensuring secure storage and retrieval through trusted measurement reports and hash validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is distributed to multiple storage locations in cloud storage, then storage capacity and accessibility are improved, but the risk of unauthorized physical access and data breaches increases
Solution Approach 1:
The patent segments the security protection mechanism by implementing encryption at the data segment level rather than relying on physical security of entire storage locations. Each data piece is encrypted with quantum keys before distribution across multiple cloud storage nodes, allowing widespread accessibility while maintaining security through cryptographic segmentation rather than physical consolidation.
Solution Approach 2:
The patent introduces quantum key distribution as an intermediary security layer between the data and storage locations. Instead of relying on physical security of storage facilities, quantum-encrypted keys act as mediators that control access to distributed data, enabling secure retrieval through cryptographic verification rather than physical presence at storage locations.
2Ease of manufacture
If conventional encryption methods are used for cloud storage, then ease of implementation is maintained, but security against quantum computing attacks and unauthorized access is insufficient
Solution Approach 1:
The patent changes the fundamental parameter of cryptographic security from classical to quantum-level encryption. By implementing quantum key distribution and quantum-resistant algorithms, the system transitions from conventional encryption parameters that are vulnerable to quantum attacks to quantum-grade security parameters that provide future-proof protection while maintaining cloud storage functionality.
Solution Approach 2:
The patent performs preliminary quantum key distribution and key establishment before actual data storage operations. By pre-establishing quantum-secure key pairs and distributing quantum-encrypted keys to cloud storage nodes beforehand, the system prepares security infrastructure in advance, making quantum-secure encryption as integrated and straightforward as conventional encryption while providing superior security guarantees.
3Reliability
If quantum data keys are used for encryption, then security against unauthorized access is enhanced, but key management complexity and computational overhead increase
Solution Approach 1:
The patent implements self-service mechanisms where the quantum key distribution system automatically generates, distributes, and manages quantum-encrypted keys between cloud storage nodes and client devices. The system performs automated key rotation, renewal, and verification without requiring manual cryptographic management, reducing the complexity burden on users while maintaining quantum-grade security through automated key lifecycle management.
Solution Approach 2:
The patent creates a universal quantum key management infrastructure that serves multiple functions: encryption key generation, authentication verification, data integrity checking, and secure communication establishment. This multi-functional quantum key system consolidates what would otherwise be separate security mechanisms into a single unified key management framework, reducing overall system complexity while providing comprehensive security.
Data Source
AI summary
One embodiment described herein provides a system and method for secure data storage. During operation, a client device selects a quantum data key from a plurality of quantum data keys shared between the client device and a storage server, encrypts to-be-stored data using the selected quantum data key, and transmits a data-storage request to the storage server. The data-storage request comprises a key-identifier of the selected quantum data key and the encrypted data.


