Quantum Network Authentication via Trusted Third Node

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing quantum key distribution (QKD) systems face challenges in scaling secure classical communication channels within quantum networks, particularly in installing and managing pre-shared symmetric keys (PSKs) across multiple nodes, which is not scalable and requires manual intervention.

Innovation Solution

A method for installing PSKs in user nodes using quantum key distribution (QKD), where a trusted third node generates and securely distributes PSKs to other nodes, enabling peer-to-peer authentication and secure communication without the need for manual key installation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If manual PSK installation is used in QKD systems, then security is maintained, but scalability is limited and manual intervention is required

Engineering Contradiction:
ImprovePSK installation easeVSAvoidNetwork scaling speed
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The system enables automated PSK distribution where the QKD network itself performs the key installation without external manual intervention. The automated PSK distribution server and client work together to generate, secure, and distribute pre-shared keys automatically, allowing the network to service itself and eliminating the need for manual key installation while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

An automated PSK distribution server acts as an intermediary between QKD nodes, facilitating secure key exchange. This intermediary component manages the PSK distribution process, securing keys during transmission and enabling automated authentication between nodes without requiring direct manual configuration, thus improving both ease of manufacture and network scaling productivity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If PSKs are distributed across multiple nodes, then authentication capability is improved, but key management complexity increases

Engineering Contradiction:
ImproveAuthentication capabilityVSAvoidKey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The automated PSK distribution server provides multiple functions in a single system: it generates PSKs, secures them during transmission, manages distribution to multiple nodes, and coordinates authentication processes. This multi-functional approach consolidates key management tasks, improving authentication capability across the network while preventing key management complexity from becoming unmanageable through centralized automation

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12267422B2Quantum network and authentication method
Publication Date: 2025.04.01 KK TOSHIBA
  • US12267422B2 patent drawing
  • US12267422B2 patent drawing
  • US12267422B2 patent drawing

AI summary

A method for use in a quantum communication network comprising a first node, a second node and a third node, the method performed by the third node, the method comprising:receiving, from the first node, a request for authentication key data for authenticating communication with the second node;in response to the request:generating the first authentication key data;sending, to the first node, a first message comprising first authentication key data for authenticating communication between the first node and the second node, wherein the first message is authenticated using second authentication key data stored on the first node and the third node, and wherein the first message is encrypted using a first cryptographic key exchanged with the first node on the quantum communication network; andsending, to the second node, a second message comprising the first authentication key data, wherein the second message is authenticated using third authentication key data stored on the second node and the third node, and wherein the second message is encrypted using a second cryptographic key exchanged with the second node on the quantum communication network.