Quantum-Safe Key Distribution via Disjoint PQC Paths
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current quantum key distribution (QKD) methods for secure key generation and distribution in network systems face limitations such as high costs, limited range, and impracticality in mobile networks, while post-quantum cryptography (PQC) methods lack proven security against quantum computers, leaving room for potential attacks through side-channel vulnerabilities.
Innovation Solution
A method utilizing quantum-secure keys generated by QKD devices and entropy sources, combined with post-quantum cryptography (PQC) and the robust combiner principle, where random numbers are transmitted through multiple disjoint network paths using different PQC methods and key derivation functions to enhance security by ensuring that even if one path is compromised, others can still secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If QKD methods are used for key distribution, then security against quantum attacks is improved, but system cost and device complexity increase significantly
Solution Approach 1:
The patent segments the key distribution system into multiple independent paths, each using different PQC methods. Instead of relying on a single complex QKD system, the solution divides the security function across multiple simpler channels, reducing device complexity while maintaining quantum-level security through diversity.
Solution Approach 2:
The patent creates a composite security system by combining multiple PQC methods (different algorithms and key derivation functions) into a unified key distribution mechanism. This composite approach leverages the strengths of various cryptographic methods to achieve quantum-resistant security without requiring expensive QKD hardware.
2Reliability
If QKD is used for key distribution, then quantum-safe key generation is achieved, but transmission range is limited to approximately 100-1000 km
Solution Approach 1:
The patent introduces intermediate nodes that use multiple PQC methods to generate and forward quantum-safe keys. These intermediaries extend the effective range of quantum-safe key distribution by relaying keys through multiple hops, overcoming the physical distance limitations of direct QKD transmission.
Solution Approach 2:
Instead of extending the physical transmission distance in a single dimension, the patent adds a dimensional aspect by using multiple independent transmission paths and diverse cryptographic methods. This multi-dimensional approach allows quantum-safe key distribution over extended networks without being constrained by single-path distance limits.
3Reliability
If multiple PQC methods and disjoint paths are used for key distribution, then security against side-channel attacks is improved, but the number of required network paths and algorithms increases
Solution Approach 1:
The patent segments the key distribution into multiple disjoint paths, each employing different PQC methods. This segmentation isolates potential side-channel attacks to individual paths, preventing them from compromising the entire system, while the modular structure manages complexity through clear separation of functions.
Solution Approach 2:
The patent changes the parameter of cryptographic diversity by systematically varying algorithms and key derivation functions across different paths. This parameter variation ensures that attacks successful against one configuration cannot automatically compromise other paths, enhancing security while organizing complexity through controlled parameter diversity.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach significantly increases security by requiring attackers to breach multiple paths and algorithms, making it more difficult to intercept quantum-safe keys and ensuring secure communication even in the presence of side-channel attacks.
Implementation Method 1
this requires a quantum channel, i.e. a channel for the transmission of quantum mechanical states, between the participants involved or their devices using the keys
Implementation Method 2
Quantum Key Distribution (QKD) methods make it possible to provide corresponding keys with high entropy at at least two remote locations simultaneously
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for using quantum-safe keys in a network system comprising several network elements interconnected via at least one network, as well as at least one QKD device, namely a device for generating quantum keys according to a quantum key distribution method, and/or at least one entropy source for generating high-entropy random numbers for generating quantum-safe keys. By applying the robust combiner concept at several system and process levels, at least two distinct random numbers are exchanged in encrypted form via disjoint network paths by two network elements of the network system, wherein the encryption is performed using various PQC methods.At least one of the network elements processes at least two random numbers received by it, or at least two random numbers coupled with the received random numbers, by applying a processing rule selected from a pool of Key Derivation Functions (KDFs) to generate a quantum-safe key.