Quantum-Safe Key Distribution via Hierarchical Entropy Streams
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current quantum key distribution (QKD) technologies are limited by high costs and restricted range, making them unsuitable for widespread use in network elements without quantum mechanical means, particularly in access networks, and there is a need for secure key distribution in mobile and IoT applications.
Innovation Solution
A method and system for generating and distributing quantum-safe keys using high-entropy random numbers, where these keys are generated locally in network elements without quantum mechanical means, using a hierarchical structure with a top-level entropy source and stream multipliers to distribute random numbers and identifiers, allowing for secure communication via symmetrical encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Quantum Key Distribution (QKD) is used to distribute secret keys, then key security and entropy are improved, but system cost and device complexity increase significantly
Solution Approach 1:
The patent extracts the quantum mechanical means from the key distribution process itself, keeping only the entropy generation function. Quantum random number generators are used solely to generate high-entropy seeds, while the actual key distribution is handled by classical cryptographic protocols, separating the quantum component from the distribution infrastructure.
Solution Approach 2:
The patent introduces trusted third-party servers that distribute pre-shared secrets and quantum-generated random numbers to network elements. These intermediaries handle the complex distribution logistics using classical channels, allowing network elements to generate secure keys without direct quantum communication or complex QKD hardware.
2Reliability
If QKD technology is deployed in core networks, then security for critical infrastructure is improved, but adaptability to access networks and mobile devices is reduced
Solution Approach 1:
The patent creates a universal key generation mechanism that works across all network elements regardless of their capabilities. Network elements without quantum hardware can still generate quantum-secure keys by receiving random numbers from trusted servers and combining them with locally-generated randomness, making the solution applicable from core networks to mobile devices.
Solution Approach 2:
The patent allows each network element to contribute local randomness and process distributed entropy according to its own capabilities. Elements with quantum hardware can generate higher entropy locally, while those without can rely more on distributed entropy, with each element's key generation process tailored to its specific resources and requirements.
3Reliability
If quantum channels are used for key distribution, then key entropy and security are improved, but transmission range and loss tolerance deteriorate
Solution Approach 1:
The patent establishes continuous trusted server infrastructure that can distribute quantum-generated random numbers across arbitrary distances using classical channels. This eliminates the transmission distance limitation of quantum channels while maintaining the high entropy benefit, as servers can repeatedly distribute fresh random numbers to any number of elements within their network reach.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables secure communication across a large number of network elements, maintaining security for extended periods with minimal maintenance, as the pre-shared secret can last for over 1000 years with 256-bit AES keys, and the system is scalable and cost-effective for widespread implementation.
Implementation Method 1
at least one entropy source for generating random numbers with high entropy relative to their randomness, due to the use of quantum mechanical means
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a solution for using quantum-safe keys in a network. It enables at least two network elements (31, 32, ... 3n) to secure communication between them over the network using shared quantum-safe keys, without the elements themselves being equipped with quantum mechanical means. The at least two network elements (31, 32, ... 3n) each generate a shared quantum-safe key locally from an identical high-entropy random number by processing it using a pre-shared secret according to the same processing procedure. The network elements (31, 32, ... 3n) receive the random number as an entropy stream consisting of random numbers and associated identifiers, which they obtain via a stream multiplier (211, 212, ... 21n, 221, 222, ... 2mn) of a hierarchical structure formed in the network. This stream multiplier (211, 212, ...21n, 221, 222, ... 2mn) in turn receives at least one entropy stream from at least one stream multiplier (211, 212, ... 21n, 221, 222, ... 2mn) of a higher-level structure or from at least one entropy source (11, 12, ... 1n) of a top-level structure (L0) generating random numbers of high entropy using quantum mechanical means.