Quantum Key Distribution System Decentralized Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Classical cryptography used in cloud computing environments is vulnerable to cracking due to advancements in computing technologies, and existing key management systems face issues with centralization, leading to potential misuse of user data and difficulties in recovering keys in case of damage or loss.

Innovation Solution

A quantum key distribution system that splits an identity-based system private key into sub-private keys using a threshold secret sharing mechanism, distributing them to multiple devices for decentralized management, allowing any number of devices meeting a threshold to reconstruct the private key, thus reducing the risk of centralization abuse and enabling key recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If classical cryptography is used for key management in cloud computing, then key generation and management can be achieved, but the system becomes vulnerable to cracking due to advancements in computing technologies

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to cracking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces classical cryptographic mechanisms with quantum key distribution mechanisms. Instead of relying on computational complexity for security, the system uses quantum mechanical principles (such as quantum entanglement and no-cloning theorem) to generate and distribute encryption keys, making the system fundamentally resistant to computational attacks including those from quantum computers.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If key management is centralized in a key management server, then key generation and distribution can be achieved, but administrators with higher operation permissions can access user data and keys, potentially giving away confidential information

Engineering Contradiction:
Improvekey managementVSAvoidadministrator misuse
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent segments the key management functionality by distributing quantum key distribution capabilities to multiple terminal devices rather than centralizing it in a server. Each terminal device can independently generate and manage its own encryption keys through quantum key distribution, eliminating the single point of control that enables administrator misuse while maintaining ease of operation through automated quantum key exchange protocols.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If encryption keys are stored centrally, then key management can be achieved, but once lost or damaged, the key or data cannot be recovered

Engineering Contradiction:
Improvekey storageVSAvoidkey recovery
Core Design Contradiction:
Ease of operationVSEase of repair

Solution Approach 1:

The patent enables terminal devices to self-generate encryption keys through quantum key distribution without relying on centralized key storage. Each device independently produces its own quantum-generated keys, eliminating the risk of key loss associated with centralized storage. The system provides automatic key generation and management services to each terminal, ensuring that keys are never stored in a vulnerable centralized location and can be regenerated if needed.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3248310B1Method, apparatus, and system for quantum key distribution
Publication Date: 2022.07.20 ALIBABA GROUP HOLDING LTD
  • EP3248310B1 patent drawingFigure 1
  • EP3248310B1 patent drawingFigure 2
  • EP3248310B1 patent drawingFigure 3

AI summary

A quantum key distribution system includes a quantum security key management (QSKM) device, a plurality of quantum security key distribution (QSKD) devices, and a quantum security key service (QSKS) device. The QSKD device splits an identity-based system private key into a plurality of system sub-private keys, and distributes the plurality of system sub-private keys to a corresponding number of the QSKD devices. The QSKS device forwards a request for acquiring an authorized private key from a first QSKD device to a predetermined number of second QSKD devices. The predetermined number of second QSKD devices each generate an identity-based authorized sub-private key from the system sub-private key. The first QSKD device acquires, from the predetermined number of second QSKD devices, the identity-based authorized sub-private keys, and reconstructs an identity-based authorized private key based on the identity-based authorized sub-private keys.