Quantum Key Distribution for Multi-Community Star Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks face challenges in securely managing multiple communities within a single infrastructure, as reliance on switches for routing can lead to unauthorized access and eavesdropping, and traditional key distribution methods are vulnerable to decryption once compromised.

Innovation Solution

A switched optical star network with a hub and endpoints equipped with quantum key distribution devices, using separate key transmitters for each community to securely transmit community keys, ensuring only members of that community can decrypt messages, thereby preventing unauthorized access and ensuring secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a single switched star network infrastructure is used for multiple communities, then cost savings and flexibility are achieved, but security is compromised due to potential switch misrouting and eavesdropping

Engineering Contradiction:
Improvecost savingsVSAvoidnetwork security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The network is segmented into multiple communities, each with its own dedicated key transmitter. This segmentation allows secure key distribution to specific communities while sharing the physical infrastructure, resolving the contradiction between cost savings from shared infrastructure and security from dedicated key management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Quantum key distribution is performed in advance to establish secure keys before any data transmission occurs. This preliminary action ensures that even if the switch misroutes data later, the keys remain secure and can detect eavesdropping attempts, maintaining security while using shared infrastructure.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If separate switches are used for each community, then network security is improved, but device complexity and expense increase

Engineering Contradiction:
Improvenetwork securityVSAvoidnumber of switches
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key distribution function is extracted from the switch and implemented as separate key transmitters. This allows the switch to remain a single shared component while security is provided by dedicated key transmitters for each community, reducing device complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Quantum key distribution acts as an intermediary between the shared infrastructure and security requirements. It provides a mechanism to securely distribute keys to multiple communities through the shared network without requiring separate physical switches for each community.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If traditional encryption is used with shared infrastructure, then cost savings are achieved, but security is vulnerable to decryption once the key is compromised

Engineering Contradiction:
Improvecost savingsVSAvoideavesdropping vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The potential harm of key compromise is converted into a benefit through quantum key distribution's eavesdropping detection capability. Any attempt to intercept the key introduces detectable disturbances, allowing the system to identify and respond to security threats while maintaining cost savings from shared infrastructure.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution enables secure and reliable communication within multiple communities on a single star network, preventing unauthorized access and ensuring that even if the switch misroutes data, only authorized members can decrypt messages, maintaining network security.

Implementation Method 1

using quantum key distribution to establish a shared secret key known only to members of that community

Methodology Applied
Scientific EffectQuantum key distribution:

Data Source

PatentEP2245788B1Multi -community network with quantum key distribution
Publication Date: 2017.06.21 QINETIQ LTD
  • EP2245788B1 patent drawingFigure 1~2
  • EP2245788B1 patent drawingFigure 3

AI summary

This invention relates to an optical star network in which different communities of users, such as different businesses, are provided through use of quantum key distribution (QKD). At least one QKD device (204) is located at the central hub of the star network and communicates with QKD devices (212) at the endpoints to establish a separate quantum key, i.e. a cryptographic key established by QKD, with each endpoint. A separate key manager (206, 208) is provided for each different community and each key manager is arranged to use the appropriate quantum keys for endpoints within that community to deliver the same community key to each endpoint. This community key can be used by for encrypting network traffic between members of the same community with security. Traffic passing through the network switch (102) is encrypted, but the community keys are not delivered via the switch and hence the switch an error in the switch does not compromise security.