Quantum Key Distribution for Dynamic Storage Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional data storage encryption systems face vulnerabilities due to fixed keys, insecure key distribution processes, and administrative complexities, leading to potential data exposure and decreased efficiency and security.

Innovation Solution

Implementing a quantum key distribution protocol for dynamic key refreshment, where keys are periodically or continuously updated, and corresponding key labels are generated and stored to facilitate secure encryption and decryption, using a quantum engine to generate and synchronize key sequences between a security device and a key-managing device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a fixed key is used for encryption, then the encryption process is simple and efficient, but the stored encrypted data becomes vulnerable to brute force attacks and key discovery

Engineering Contradiction:
Improveencryption efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic key generation where encryption keys are no longer fixed but change over time based on quantum random number generation. The system periodically updates encryption keys using quantum-generated randomness, transforming the static key system into a dynamic one that adapts to security requirements while maintaining encryption efficiency through automated key management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameter of key stability by introducing quantum-generated random keys that are periodically updated. This parameter change from fixed to variable keys, driven by quantum randomness, fundamentally alters the security landscape by making brute force attacks computationally infeasible while maintaining system efficiency through automated key rotation.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If asymmetric encryption algorithm is used for key distribution, then new keys can be selected and transmitted, but the transmission process becomes susceptible to eavesdropping and algorithm hacking

Engineering Contradiction:
Improvekey management flexibilityVSAvoidkey distribution security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces the classical mechanical/crypto system of asymmetric encryption with a quantum-based key distribution system. Instead of relying on mathematical complexity of asymmetric algorithms, the system uses quantum key distribution (QKD) protocols where keys are generated and distributed through quantum channels, providing information-theoretic security that is immune to computational attacks and eavesdropping.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces quantum key distribution protocols as an intermediary mechanism for secure key exchange. Rather than directly transmitting encryption keys through vulnerable classical channels, the system uses quantum-secured communication channels as intermediaries to establish shared secret keys between parties, eliminating the security vulnerabilities of direct key transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If manual key update is performed, then key replacement can be controlled, but the process faces risk of malicious disclosure and requires additional administrative work

Engineering Contradiction:
Improvekey update controlVSAvoidkey update security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements self-service automated key management where the system automatically generates, distributes, and rotates encryption keys using quantum random number generation. This eliminates the need for manual administrative intervention in key updates, reducing human error and malicious disclosure risks while maintaining control through automated policies and scheduling mechanisms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary key generation and distribution through quantum key distribution protocols before actual encryption operations begin. Keys are pre-generated and securely distributed through quantum channels, ensuring that when encryption needs to occur, secure keys are already in place without requiring last-minute manual updates that could be compromised.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If the system retains access to original key and encrypted data upon updating key, then decryption capability is maintained, but administrative users must perform additional computationally complex work

Engineering Contradiction:
Improvedecryption capabilityVSAvoidadministrative work complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms in key management where the system automatically tracks and manages key lifecycle states. When keys are updated through quantum generation, the system automatically maintains appropriate access controls and decryption capabilities through automated key versioning and access policies, eliminating the need for administrators to manually manage complex key relationships.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11658814B2System and method for encryption and decryption based on quantum key distribution
Publication Date: 2023.05.23 CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
  • US11658814B2 patent drawing
  • US11658814B2 patent drawing
  • US11658814B2 patent drawing

AI summary

One embodiment of the present invention provides a system for facilitating storage encryption and decryption. During operation, the system receives a first request to encrypt data which is to be stored on a remote device, wherein the first request indicates the data. The system updates a key based on a dynamic key refreshment protocol. The system determines a key label for the updated key. The system encrypts the data based on the updated key, and transmits the encrypted data and the key label to the remote device, thereby facilitating secure encryption and decryption of data on the remote device.