Quantum Key Distribution and Trusted Computing for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data security approaches in cloud computing are inadequate to meet the unique security requirements, particularly due to the potential vulnerabilities from advanced quantum computing and the need for dynamic monitoring and authentication of user behaviors and platform integrity.

Innovation Solution

A system and method that combines quantum key distribution (QKD) and trusted computing technologies to establish secure communication channels by negotiating secret keys between clients and servers, using Trusted Platform Modules (TPMs) for authentication and integrity verification, and implementing a trusted authorization center with secret-sharing schemes for secure key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional data security approaches are used in cloud computing, then ease of operation is maintained, but security reliability is insufficient against quantum computing threats

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments security functions into distinct modules: quantum key distribution for key generation, trusted computing modules for key storage and protection, and classical communication for data transmission. This segmentation allows each component to specialize in specific security tasks, improving overall reliability while managing complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces quantum key distribution as an intermediary mechanism between communicating parties, enabling secure key exchange without direct exposure of cryptographic keys. The trusted computing module acts as an intermediary that verifies platform integrity and protects sensitive operations, thereby enhancing security reliability without requiring complete system redesign

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If quantum key distribution and trusted computing are implemented, then security against quantum threats is improved, but device complexity increases

Engineering Contradiction:
Improvequantum security resistanceVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically negotiates quantum keys for each communication session, allowing security parameters to adapt to current threats and requirements. The trusted computing module dynamically verifies platform integrity and adjusts security operations based on runtime conditions, providing quantum-level security without static rigid architecture

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces classical cryptographic key exchange mechanisms with quantum key distribution, substituting mathematical problem-solving with quantum physical principles. This substitution provides provable security against quantum attacks while the trusted computing module handles the complex key management operations, separating security concerns from application logic

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If dynamic monitoring and authentication of user behaviors is implemented, then security detection capability is improved, but processing time increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The trusted computing module performs preliminary measurements of platform configuration registers and generates trustworthiness information during system initialization and boot-up. This preliminary action allows authentication to proceed quickly during runtime, as the foundation of trust has already been established without requiring extensive real-time analysis

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors platform integrity and user behaviors, providing feedback to the trusted computing module. This feedback mechanism enables dynamic adjustment of security operations, allowing the system to maintain high authentication capability while minimizing processing time through intelligent resource allocation based on current security needs

Inventive Principle:
Principle #23Feedback

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances data and computation security in cloud computing by ensuring the secrecy of keys, authenticating entities, and dynamically monitoring the integrity of platforms and user behaviors, thereby strengthening security against potential quantum computing threats.

Implementation Method 1

the server negotiates, via a quantum-key-distribution process, a secret key shared between the client and the server

Methodology Applied
Scientific EffectQuantum key distribution:

Data Source

PatentUS10855452B2Method and system for data security based on quantum communication and trusted computing
Publication Date: 2020.12.01 CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
  • US10855452B2 patent drawing
  • US10855452B2 patent drawing
  • US10855452B2 patent drawing

AI summary

One embodiment described herein provides a system and method for ensuring data and computation security. During operation, a server receives a key-negotiation request from a client and authenticates the client. In response to the client authenticating the server, the server negotiates, via a quantum-key-distribution process, a secret key shared between the client and the server; and stores the secret key in a trusted-computing module.