Quantum-Safe Key Distribution for Terminal Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic methods used in telecommunications are vulnerable to quantum computers, which can break existing encryption techniques quickly, and implementing Quantum Key Distribution (QKD) is complex and expensive, limiting its widespread use, especially in terminal devices.

Innovation Solution

A method and terminal device design that obtain quantum-secure keys from a QKD network using XOR links and hash values, allowing for secure encryption and decryption without requiring quantum technology, and store these keys in a tamper-proof memory for later use, enabling secure data transmission even with quantum computers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Quantum Key Distribution (QKD) is implemented to provide quantum-secure keys, then cryptographic security against quantum computers is improved, but device complexity and cost increase due to required quantum technology

Engineering Contradiction:
Improvecryptographic securityVSAvoidquantum technology requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a QKD network as an intermediary service that generates and distributes quantum-secure keys to terminal devices. Instead of requiring terminal devices to have quantum technology capabilities, the QKD network acts as a mediator that provides quantum-secure keys through classical communication channels, thus resolving the contradiction between security improvement and device complexity reduction

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables terminal devices to obtain copies of quantum-secure keys from the QKD network without needing to generate them themselves through quantum processes. The keys are generated once by the QKD network using quantum mechanics and then distributed to multiple terminal devices, allowing these devices to use quantum security without possessing quantum technology

Inventive Principle:
Principle #26Copying

2Reliability

If QKD network is used to generate quantum-secure keys, then security against quantum computer attacks is improved, but implementation cost and complexity increase

Engineering Contradiction:
Improvesecurity against quantum attacksVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The QKD network is designed to serve multiple terminal devices simultaneously, generating quantum-secure keys that can be distributed to various devices for different communication purposes. This multi-functional approach improves cost-effectiveness by consolidating quantum security infrastructure into a single network that serves multiple clients rather than requiring separate quantum systems for each device

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If quantum-secure keys are obtained from QKD network using classical channels, then ease of operation is improved, but security vulnerability to interception increases

Engineering Contradiction:
Improvekey acquisition simplicityVSAvoidinterception vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent employs preliminary actions by first establishing a secure reference key through quantum processes, then using this reference key to encrypt and protect subsequent key distributions and communications. This layered approach allows classical communication for key acquisition while maintaining security through preliminary quantum key establishment

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The QKD network acts as a trusted intermediary that handles quantum key generation and distribution. The network uses quantum-secure reference keys to protect classical communications with terminal devices, effectively mediating between quantum security requirements and classical communication simplicity, thus preventing interception vulnerabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides secure data transmission by using quantum-secure keys generated from a QKD network, ensuring the security of telecommunications, even against quantum computer attacks, without the need for expensive quantum technology, making it feasible for widespread use in terminal devices.

Implementation Method 1

methods based on the use of quantum mechanical effects, such as the method according to the BB84 protocol, enable the secure transmission of data

Methodology Applied
Scientific EffectQuantum mechanical effects:

Data Source

PatentEP4128646B1Use of quantum-safe keys with terminal devices
Publication Date: 2023.10.18 DEUTSCHE TELEKOM AG
  • EP4128646B1 patent drawingFigure 1
  • EP4128646B1 patent drawingFigure 2
  • EP4128646B1 patent drawingFigure 3

AI summary

The invention relates to a solution for using quantum-safe cryptographic keys with telecommunication terminal devices (1) which do not themselves have quantum-engineering-related means for generating said keys. To this end, the terminal device (1) in question obtains the quantum-safe keys by requesting them from a QKD network that continuously generates quantum-safe random numbers and is formed by two network nodes (21, 22) which are connected in a quantum key distribution. In order to achieve this, a plurality of mutually different bitwise XOR concatenations formed from random numbers generated by the QKD network are transmitted from the network nodes (21, 22) on at least two mutually disjoint paths via VPN connections to the terminal device (1) requesting the quantum-safe key, and the terminal device (1) extracts a quantum-safe reference key, that is also present at the network nodes (21, 22), from said XOR concatenations. This reference key is used for symmetric encryption in a subsequent transmission process of data transmitted from one of the network nodes (21, 22) to the terminal device (1), said data comprising a larger number of random numbers which are generated by the QKD network and on the basis of which the terminal device (1) extracts a plurality of keys also present in the network nodes (21, 22) and stores them in a tamper-proof memory.