Quantum-Safe Key Generation for Mobile Terminals via Network Entropy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile radio terminals lack secure data transmission capabilities against quantum computer attacks due to limitations in quantum key distribution technology, particularly in range and cost, which restricts the use of quantum-secure encryption methods, and there is a need for a solution to enable symmetric encryption using quantum-safe keys without relying on quantum channels or expensive QKD technology.

Innovation Solution

A method and system that enables mobile radio terminals equipped with a Subscriber Identity Module (SIM) to use a shared secret for local generation of a quantum-safe application key for symmetric encryption with a remote station, using an entropy source to generate random numbers, which are then converted into application keys independently on both sides without transmission over public networks, employing key derivation functions like XOR or block ciphers like AES, and storing these keys temporarily for secure data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Quantum Key Distribution (QKD) methods are used to generate and distribute high-entropy keys, then key security against quantum attacks is improved, but the range is limited to around 100-300 km and infrastructure cost increases significantly

Engineering Contradiction:
Improvekey securityVSAvoidinfrastructure requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the quantum random number generation functionality from the mobile terminal itself and places it on the network side (entropy source). The mobile terminal only needs to receive and process classical random numbers, not generate or transmit quantum states, thereby removing the complex quantum hardware requirements from the terminal while maintaining quantum-level entropy quality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary entropy source on the network side that generates high-entropy random numbers using quantum methods and distributes them to mobile terminals via classical channels. This intermediary handles the complex quantum operations centrally, allowing multiple terminals to benefit from quantum-secure entropy without each terminal needing quantum capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If symmetric encryption with shared secret keys is used, then encryption strength is improved, but the challenge of securely distributing secret keys to authorized users without interception increases

Engineering Contradiction:
Improveencryption strengthVSAvoidkey distribution
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary key derivation by the mobile terminal itself using a key derivation function (KDF) applied to received random numbers and stored secret information. This preliminary action creates the actual encryption key locally, so the sensitive key material never needs to be distributed over the network - only the non-sensitive random numbers and KDF parameters are transmitted, simplifying secure key distribution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile terminal performs self-service by locally generating its encryption keys through key derivation from received random numbers and its own stored secret information. Each terminal independently creates its keys without relying on external key distribution infrastructure, reducing the complexity of key management while maintaining strong encryption.

Inventive Principle:
Principle #25Self-service

3Reliability

If quantum random number generators are used in mobile terminals, then key entropy is improved, but device cost and complexity increase

Engineering Contradiction:
Improvekey entropyVSAvoidterminal hardware
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the quantum random number generation hardware from the mobile terminal and relocates it to the network infrastructure. The terminal only requires standard communication capabilities to receive and process classical random numbers, eliminating the need for expensive quantum hardware in consumer devices while still achieving quantum-level entropy quality through network-side generation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4199564A1Quantum-secure transmission of data over mobile radio network
Publication Date: 2023.06.21 DEUTSCHE TELEKOM AG
  • EP4199564A1 patent drawing
  • EP4199564A1 patent drawing
  • EP4199564A1 patent drawing

AI summary

The invention relates to the secure transmission of data exchanged between a mobile communication terminal equipped with a Subscriber Identity Module (SIM) and a counterpart via at least one mobile network. The data is symmetrically encrypted using a shared application key with quantum safety. According to the proposed solution, the shared, i.e., identical, application key is generated locally by both the mobile communication terminal and the counterpart. For this purpose, the mobile communication terminal and the counterpart are first equipped with a shared secret represented by a bit sequence, which is stored in the SIM of the mobile communication terminal.The mobile communication terminal and the counterpart generate the shared application key independently of each other by locally calculating the same random number received from an entropy source via the at least one mobile communication network in an identical manner, i.e. according to the same rule, with the shared secret and thus converting this random number into the quantum-safe shared application key.