Quantum-Safe Key Distribution via Disjoint PQC Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current quantum key distribution (QKD) methods for secure key generation and distribution in network systems face limitations such as high costs, limited range, and impracticality in mobile networks, while post-quantum cryptography (PQC) methods lack proven security against quantum computers, leaving room for potential attacks through side-channel vulnerabilities.

Innovation Solution

A method utilizing quantum-secure keys generated by QKD devices and entropy sources, combined with post-quantum cryptography (PQC) and the robust combiner principle, where random numbers are transmitted through multiple disjoint network paths using different PQC methods and key derivation functions to enhance security by ensuring that even if one path is compromised, others can still secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If QKD methods are used for key distribution, then security against quantum attacks is improved, but system cost and device complexity increase significantly

Engineering Contradiction:
Improvesecurity against quantum attacksVSAvoidsystem cost and device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key distribution system into multiple independent paths, each using different PQC methods. Instead of relying on a single complex QKD system, the solution divides the security function across multiple simpler channels, reducing device complexity while maintaining quantum-level security through diversity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a composite security system by combining multiple PQC methods (different algorithms and key derivation functions) into a unified key distribution mechanism. This composite approach leverages the strengths of various cryptographic methods to achieve quantum-resistant security without requiring expensive QKD hardware.

Inventive Principle:
Principle #40Composite materials

2Reliability

If QKD is used for key distribution, then quantum-safe key generation is achieved, but transmission range is limited to approximately 100-1000 km

Engineering Contradiction:
Improvequantum-safe key generationVSAvoidtransmission range
Core Design Contradiction:
ReliabilityVSLength of stationary object

Solution Approach 1:

The patent introduces intermediate nodes that use multiple PQC methods to generate and forward quantum-safe keys. These intermediaries extend the effective range of quantum-safe key distribution by relaying keys through multiple hops, overcoming the physical distance limitations of direct QKD transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of extending the physical transmission distance in a single dimension, the patent adds a dimensional aspect by using multiple independent transmission paths and diverse cryptographic methods. This multi-dimensional approach allows quantum-safe key distribution over extended networks without being constrained by single-path distance limits.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If multiple PQC methods and disjoint paths are used for key distribution, then security against side-channel attacks is improved, but the number of required network paths and algorithms increases

Engineering Contradiction:
Improvesecurity against side-channel attacksVSAvoidnumber of network paths and algorithms
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key distribution into multiple disjoint paths, each employing different PQC methods. This segmentation isolates potential side-channel attacks to individual paths, preventing them from compromising the entire system, while the modular structure manages complexity through clear separation of functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of cryptographic diversity by systematically varying algorithms and key derivation functions across different paths. This parameter variation ensures that attacks successful against one configuration cannot automatically compromise other paths, enhancing security while organizing complexity through controlled parameter diversity.

Inventive Principle:
Principle #35Parameter changes

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach significantly increases security by requiring attackers to breach multiple paths and algorithms, making it more difficult to intercept quantum-safe keys and ensuring secure communication even in the presence of side-channel attacks.

Implementation Method 1

this requires a quantum channel, i.e. a channel for the transmission of quantum mechanical states, between the participants involved or their devices using the keys

Methodology Applied
Scientific EffectQuantum mechanical states transmission:

Implementation Method 2

Quantum Key Distribution (QKD) methods make it possible to provide corresponding keys with high entropy at at least two remote locations simultaneously

Methodology Applied
Scientific EffectQuantum key distribution:

Data Source

PatentEP4221070A1Use of quantum secure key in a network system
Publication Date: 2023.08.02 DEUTSCHE TELEKOM AG
  • EP4221070A1 patent drawingFigure 1
  • EP4221070A1 patent drawingFigure 2
  • EP4221070A1 patent drawingFigure 3

AI summary

The invention relates to a method for using quantum-safe keys in a network system comprising several network elements interconnected via at least one network, as well as at least one QKD device, namely a device for generating quantum keys according to a quantum key distribution method, and/or at least one entropy source for generating high-entropy random numbers for generating quantum-safe keys. By applying the robust combiner concept at several system and process levels, at least two distinct random numbers are exchanged in encrypted form via disjoint network paths by two network elements of the network system, wherein the encryption is performed using various PQC methods.At least one of the network elements processes at least two random numbers received by it, or at least two random numbers coupled with the received random numbers, by applying a processing rule selected from a pool of Key Derivation Functions (KDFs) to generate a quantum-safe key.