Trustless Key Provisioning With Quantum-Safe Symmetric Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Classical asymmetric cryptography is vulnerable to quantum computers, and existing methods for symmetric key provisioning are manual, time-consuming, and risk key material loss or compromise.

Innovation Solution

A quantum computing-safe method for symmetric key provisioning that involves providing a shared secret data to a device and a security service, using it to generate a root key, and performing parallel operations to create a sequence of generated keys, ensuring secure and autonomous key distribution without human access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual key distribution is used, then key provisioning can be accomplished, but the process is time-consuming and expensive

Engineering Contradiction:
Improvekey provisioning speedVSAvoidmanual distribution time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables self-service key provisioning where the key management system automatically generates, distributes, and manages cryptographic keys without requiring manual human intervention. The system performs key generation, storage, and distribution operations autonomously, eliminating the need for human operators to physically transport or manually configure key material between systems.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual key distribution is used, then key provisioning can be accomplished, but it relies on the trustworthiness of personnel involved

Engineering Contradiction:
Improvekey securityVSAvoidinternal threat risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system introduces a secure key management system as an intermediary between key generation and key usage. This intermediary automatically manages the entire key lifecycle including generation, storage, distribution, and revocation, eliminating the need for human personnel to handle sensitive key material and thereby removing the internal threat risk associated with trusting human operators.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The key management system performs all key operations autonomously without human intervention, ensuring that no human personnel ever possess or handle the actual key material. This self-service approach eliminates the trust dependency on human personnel while maintaining secure key provisioning.

Inventive Principle:
Principle #25Self-service

3Reliability

If symmetric keys are distributed manually, then quantum computer resistant encryption can be achieved, but the process is slow and expensive

Engineering Contradiction:
Improvequantum resistanceVSAvoidkey distribution efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system automatically performs symmetric key generation and distribution without manual intervention, achieving quantum-resistant security through automated processes. The key management system generates quantum-resistant symmetric keys and distributes them programmatically, eliminating the slowness and high cost associated with manual key distribution while maintaining the security benefits of symmetric encryption.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If key material is held by distributing personnel, then key provisioning can be completed, but the risk of loss or compromise increases

Engineering Contradiction:
Improvekey provisioning capabilityVSAvoidkey material security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The key management system automatically generates and distributes keys without human personnel ever possessing the key material. The system performs all key operations including generation, storage, and distribution autonomously, eliminating the security risk of key material being held by human operators while maintaining the capability to complete key provisioning.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system introduces an automated key management intermediary that handles all key material operations without human involvement. This intermediary securely manages key generation, storage, and distribution, eliminating the risk of key loss or compromise that would occur if human personnel held the key material.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12413398B2System and method for trustless key provisioning
Publication Date: 2025.09.09 ARQIT LTD
  • US12413398B2 patent drawing
  • US12413398B2 patent drawing
  • US12413398B2 patent drawing

AI summary

A method of encryption key provisioning that includes providing, by a quantum computing safe method, a shared secret data to a device and to a security service; using the provided shared secret data to provide a root key; and using the root key for a sequence of stages, wherein each stage includes an operation which converts a start key into a different generated key, and the same stages are carried out in parallel at the device and at the security service; wherein the root key is used as the start key for a first stage, and a generated key produced by each stage, except for the final stage, is used as a start key for a next stage of the sequence; and wherein the generated keys produced by the last stage of the sequence at the device and at the security service are symmetric keys.