Quantum Key Distribution Proof via Disjoint Polynomial Paths
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current quantum key distribution systems face challenges in extending link distance, validating secure keys generated by different key management entities, and identifying compromised trusted nodes, leading to resource consumption and increased vulnerability to attacks.
Innovation Solution
A controller device generates polynomials to create disjoint paths through intermediate network devices, assigning secret shares to each device, and verifies cumulative values to ensure secure keys originate from different key management entities and traverse distinct paths, providing proof of origin and transit.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Length of stationary object
If quantum key distribution is used to extend link distance through intermediate trusted nodes, then the communication range is improved, but the security risk increases due to potential compromise of trusted nodes
Solution Approach 1:
The patent segments the quantum key distribution path into multiple disjoint paths through intermediate trusted nodes, where each path is generated using separate polynomials. This segmentation allows the system to extend link distance while maintaining security by ensuring that compromise of one path does not affect other paths, as each path has independent secret shares distributed through Shamir's Secret Sharing scheme.
2Reliability
If multiple paths are used to distribute secure keys, then security is improved, but resource consumption increases
Solution Approach 1:
The patent implements partial verification by checking cumulative values at intermediate nodes rather than verifying every single key transmission. The system generates multiple paths using polynomials but only performs selective verification at trusted nodes, consuming computing resources proportionally to the number of paths rather than exponentially, thus balancing security improvement with resource conservation.
3Reliability
If verification of key provenance is implemented, then security is improved, but system complexity increases
Solution Approach 1:
The patent implements feedback mechanisms where intermediate trusted nodes calculate and return cumulative values to the source device. These cumulative values serve as proof of origin and transit, allowing verification of key provenance without requiring complex centralized verification systems. The feedback loop enables automated validation that reduces system complexity compared to manual verification processes.
4Reliability
If disjoint paths through different intermediate devices are used, then security against attacks is improved, but network complexity increases
Solution Approach 1:
The patent introduces a new dimension to key distribution by creating multiple disjoint paths through different intermediate devices, effectively adding spatial diversity to the network topology. This dimensional approach allows the system to resist attacks by distributing keys across multiple independent routes, where compromise of one path does not affect others, while managing network complexity through structured polynomial-based path generation.
Data Source
AI summary
A device may generate a first polynomial and a second polynomial, and may generate, based on the first polynomial, a primary path from a first network device to a second network device via a first set of intermediate network devices. The device may generate, based on the second polynomial, a secondary path from the first network device to the second network device via a second set of intermediate network devices, and may assign a point of the first and second polynomials to the device, to each of the first set of intermediate network devices and of the second set of intermediate network devices. The device may cause the primary path to be provided from the first network device to the second network device, and may cause the secondary path to be provided from the first network device to the second network device.


