Quantum Key Distribution via Segmented Mesh Network

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing encryption communication systems face challenges in securing the encryption key during quantum encryption, particularly due to the risk of eavesdropping when sharing keys between users via quantum key delivery devices, especially in the 'last-mile' transmission over the Internet, where unauthorized access can occur at terminal nodes.

Innovation Solution

The system distributes and generates encryption keys by dividing data into multiple pieces, which are sent through a mesh network of nodes with quantum key delivery functions, allowing each user to reconstruct the key using secret distribution methods, ensuring that even if one node is compromised, the key cannot be stolen, thereby maintaining secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Length of stationary object

If quantum key delivery devices are used to deliver encryption keys from terminal nodes to users, then encryption communication can be established between distant users, but there is a risk that the encryption key is eavesdropped over the Internet during delivery

Engineering Contradiction:
Improvecommunication distanceVSAvoideavesdropping risk
Core Design Contradiction:
Length of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The encryption key is segmented into multiple pieces (first data, second data, etc.) that are distributed to different nodes. Each node holds only a portion of the key, and no single node can reconstruct the complete key alone. This segmentation prevents eavesdropping at any individual node while still enabling key delivery over long distances through the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Multiple intermediate nodes are introduced between the terminal nodes and the final users. These nodes act as mediators that forward key segments without being able to reconstruct the full key themselves. The use of intermediate nodes with threshold cryptography ensures that the key material passes through multiple points without creating a single vulnerability point for eavesdropping.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If QKD devices are disposed at terminal nodes to perform quantum key delivery, then the last-one mile problem can be solved, but information may still be stolen by unauthorized persons intruding into the terminal node

Engineering Contradiction:
Improvesecurity against relay node degradationVSAvoidterminal node intrusion risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The encryption key is divided into multiple segments distributed across different nodes in the network. Even if an unauthorized person intrudes into a terminal node, they can only access one segment of the key, which is insufficient for decryption. The segmentation ensures that terminal node compromise does not lead to complete key exposure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key distribution system uses a nested structure where multiple layers of encryption and segmentation are applied. The key material is embedded within multiple nodes, each containing only a portion of the complete key. This nested distribution ensures that intrusion at any single level (terminal node or intermediate node) cannot extract the full key.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If encryption keys are distributed through multiple different paths using multiple independent encryption keys, then the reliability of encryption communication is improved, but the device complexity increases

Engineering Contradiction:
Improveencryption communication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses a universal threshold cryptography mechanism that can be applied regardless of the number of nodes or paths involved. The same mathematical framework (threshold schemes) works for any configuration of nodes and paths, simplifying the system architecture compared to managing multiple independent encryption systems. This multi-functional approach handles both key distribution and security requirements through a unified mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Multiple key segments and multiple transmission paths are merged into a unified key reconstruction process at the destination. Instead of managing separate encryption systems for each path, the patent combines all key segments from different nodes through a single threshold decryption operation, reducing overall system complexity while maintaining reliability through path diversity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4280532A1Encryption communication system, encryption communication apparatus, and encryption communication method
Publication Date: 2023.11.22 KK TOSHIBA
  • EP4280532A1 patent drawingFigure 1
  • EP4280532A1 patent drawingFigure 2
  • EP4280532A1 patent drawingFigure 3

AI summary

According to one embodiment, in an encryption communication system, a first device (107) and a second device (115) that execute encryption communication via a first network (105) share an encryption key used for the encryption communication via a second network (120) including a plurality of nodes (109, 111, 113, 114). The first device (107) generates n pieces of first data used for generating the encryption key, transmits the n pieces of first data to the second device by distributing the n pieces of first data to n nodes among the nodes and sending the n pieces of first data to the second network, and generates the encryption key by using the n pieces of first data. The second device (115) receives the n pieces of first data from n nodes among the nodes, and generates the encryption key by using the n pieces of first data.