Quantum-Safe Key Generation for Mobile Terminals via Network Entropy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile radio terminals lack secure data transmission capabilities against quantum computer attacks due to limitations in quantum key distribution technology, particularly in range and cost, which restricts the use of quantum-secure encryption methods, and there is a need for a solution to enable symmetric encryption using quantum-safe keys without relying on quantum channels or expensive QKD technology.
Innovation Solution
A method and system that enables mobile radio terminals equipped with a Subscriber Identity Module (SIM) to use a shared secret for local generation of a quantum-safe application key for symmetric encryption with a remote station, using an entropy source to generate random numbers, which are then converted into application keys independently on both sides without transmission over public networks, employing key derivation functions like XOR or block ciphers like AES, and storing these keys temporarily for secure data exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Quantum Key Distribution (QKD) methods are used to generate and distribute high-entropy keys, then key security against quantum attacks is improved, but the range is limited to around 100-300 km and infrastructure cost increases significantly
Solution Approach 1:
The patent extracts the quantum random number generation functionality from the mobile terminal itself and places it on the network side (entropy source). The mobile terminal only needs to receive and process classical random numbers, not generate or transmit quantum states, thereby removing the complex quantum hardware requirements from the terminal while maintaining quantum-level entropy quality.
Solution Approach 2:
The patent introduces an intermediary entropy source on the network side that generates high-entropy random numbers using quantum methods and distributes them to mobile terminals via classical channels. This intermediary handles the complex quantum operations centrally, allowing multiple terminals to benefit from quantum-secure entropy without each terminal needing quantum capabilities.
2Reliability
If symmetric encryption with shared secret keys is used, then encryption strength is improved, but the challenge of securely distributing secret keys to authorized users without interception increases
Solution Approach 1:
The patent performs preliminary key derivation by the mobile terminal itself using a key derivation function (KDF) applied to received random numbers and stored secret information. This preliminary action creates the actual encryption key locally, so the sensitive key material never needs to be distributed over the network - only the non-sensitive random numbers and KDF parameters are transmitted, simplifying secure key distribution.
Solution Approach 2:
The mobile terminal performs self-service by locally generating its encryption keys through key derivation from received random numbers and its own stored secret information. Each terminal independently creates its keys without relying on external key distribution infrastructure, reducing the complexity of key management while maintaining strong encryption.
3Reliability
If quantum random number generators are used in mobile terminals, then key entropy is improved, but device cost and complexity increase
Solution Approach 1:
The patent extracts the quantum random number generation hardware from the mobile terminal and relocates it to the network infrastructure. The terminal only requires standard communication capabilities to receive and process classical random numbers, eliminating the need for expensive quantum hardware in consumer devices while still achieving quantum-level entropy quality through network-side generation.
Data Source
AI summary
The invention relates to the secure transmission of data exchanged between a mobile communication terminal equipped with a Subscriber Identity Module (SIM) and a counterpart via at least one mobile network. The data is symmetrically encrypted using a shared application key with quantum safety. According to the proposed solution, the shared, i.e., identical, application key is generated locally by both the mobile communication terminal and the counterpart. For this purpose, the mobile communication terminal and the counterpart are first equipped with a shared secret represented by a bit sequence, which is stored in the SIM of the mobile communication terminal.The mobile communication terminal and the counterpart generate the shared application key independently of each other by locally calculating the same random number received from an entropy source via the at least one mobile communication network in an identical manner, i.e. according to the same rule, with the shared secret and thus converting this random number into the quantum-safe shared application key.


