Quantum-Resistant Key Generation Using Hardware Noise Entropy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptographic systems, such as those used in the NSA's CSfC program, face challenges in securely distributing and generating Pre-Shared Keys (PSKs) with sufficient cryptographic entropy to resist quantum computer threats, as they are difficult to manage and require specialized, classified equipment.
Innovation Solution
A computer program product and process that identifies hardware noise sources to collect entropy, which is then used by a Deterministic Random Bit Generator (DRBG) to generate quantum computer-resistant algorithm cryptographic keys, allowing for secure key generation, storage, and transfer on commercial devices without the need for Type 1 products or NSA approval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Pre-Shared Keys are used for quantum computer resistant cryptography, then cryptographic strength is improved, but key distribution difficulty increases
Solution Approach 1:
The system enables self-service key generation by allowing each device to independently generate its own cryptographic key pair using local hardware noise sources. The public key can be freely distributed while the private key remains securely stored locally, eliminating the need for secure key distribution channels while maintaining quantum-resistant cryptographic strength
Solution Approach 2:
The cryptographic system is segmented into public and private key components, where the public key can be openly distributed and the private key is kept secure locally. This segmentation allows the public key to serve as a safe distribution artifact while the private key provides the security foundation, resolving the distribution difficulty without compromising cryptographic strength
2Reliability
If Type 1 specialized equipment is used for key generation, then cryptographic entropy quality is improved, but device complexity and cost increase
Solution Approach 1:
The system replaces expensive, specialized Type 1 key generation equipment with commercially available devices that use software-based entropy collection from hardware noise sources. This approach provides sufficient cryptographic entropy quality without requiring classified or specialized equipment, reducing both device complexity and cost while maintaining security requirements
Solution Approach 2:
The system substitutes specialized hardware-based entropy generation with software-based entropy collection from available hardware noise sources in commercial devices. This replacement eliminates the need for specialized Type 1 equipment while maintaining adequate cryptographic entropy quality through careful entropy collection and processing
3Reliability
If Type 1 products are used for key management, then security control is improved, but operational flexibility decreases
Solution Approach 1:
The system uses universal commercial devices that can perform multiple functions including key generation, key storage, and key distribution. These devices comply with NSA CSfC requirements while being compatible with standard commercial cryptographic products, eliminating the restriction that Type 1 products can only connect to other Type 1 products and providing operational flexibility across different platforms
Data Source
AI summary
A system and process provides quantum computer resistant algorithm cryptographic keys. Embodiments utilize a hardware noise source whose entropy is fed to a random bit generator to generate keys which go straight to the advanced encryption standard. The keys avoid the need for mutual authentication and are thus not subject to reverse factoring that can be accomplished through quantum computing.


