Quantum Key Generation with Entropy Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current quantum-secure key generation and distribution methods lack validation of individual keys generated at runtime, relying on trust in systems that may not be consistently reliable over time, and existing QKD systems have limitations such as short transmission distances and low key generation rates, making them impractical for widespread secure data exchange.
Innovation Solution
A method using a quantum computer to generate and validate high-entropy quantum-secure keys, which are then transmitted and authenticated using a classical digital computer, allowing for secure data exchange between network nodes without a direct QKD connection, employing a combination of quantum key generation and post-quantum cryptography for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If QKD methods are used to generate quantum-secure keys, then the keys have high entropy and quantum security, but the transmission distance is limited to a few hundred kilometers and the key generation rate is low
Solution Approach 1:
The patent introduces a trusted node as an intermediary that performs QKD with both the first and second network nodes. This mediator generates quantum-secure keys through QKD and then distributes them to the endpoints via classical channels, enabling secure communication between nodes that cannot directly establish QKD connections due to distance limitations.
Solution Approach 2:
The patent divides the secure key distribution task into segments: the trusted node performs QKD with each endpoint separately to generate quantum-secure keys, then distributes these keys through classical channels. This segmentation allows the system to overcome the distance limitation of direct QKD by breaking the direct connection requirement into multiple shorter QKD links through the intermediary.
2Reliability
If QKD systems are deployed for quantum key distribution, then quantum-secure keys can be generated, but the key generation rate is comparatively low
Solution Approach 1:
The patent combines quantum key generation with classical key distribution. The trusted node generates quantum-secure keys using QKD and then distributes multiple keys to endpoints through classical digital channels. This merging allows the system to leverage the security of quantum generation with the higher bandwidth of classical distribution, improving overall key availability.
Solution Approach 2:
The trusted node performs preliminary QKD with each endpoint to generate and store quantum-secure keys before they are needed for actual data transmission. This preliminary key generation allows endpoints to have ready-to-use secure keys when needed, improving the effective key generation rate for actual communications.
3Ease of operation
If quantum keys are generated and distributed without validation, then the system is simpler to operate, but trust in the quantum security of keys cannot be confirmed at runtime
Solution Approach 1:
The patent implements feedback mechanisms where the trusted node provides certificates to endpoints confirming the quantum security of distributed keys. These certificates include information about the QKD process and validation results, allowing endpoints to verify at runtime that the keys they received are genuinely quantum-secure, thereby maintaining trust without complicating the distribution process.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a solution for providing quantum-safe cryptographic keys in a network, according to which a first network node (1) configured for this purpose generates quantum keys and transmits these quantum keys as user keys to a second network node (2). The user keys, which are later to be used for secure data exchange between the two network nodes (1, 2) via one of the layers of the OSI model, are transmitted cryptographically secured via a connection existing between the first and second network nodes (1, 2), which is not configured for the joint generation of quantum-safe keys by these network nodes (1, 2) according to a QKD method.According to the invention, the quantum-safe user keys are generated by means of a quantum computer of the first network node (1) and, before their transmission to the second network node (2), are validated with regard to the existence of a predetermined entropy by means of a classical digital computer of the first network node (1) which is in an operational connection with the quantum computer and together forms a quantum key generator (4).