Quantum-Secure Data-Path Integration With Multiplexed Service Frames

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern datacenters face vulnerabilities in high-speed data exchange due to unencrypted data, and existing Quantum Key Distribution (QKD) devices are bulky and limited to site-to-site communications, requiring centralized key management and dedicated service channels, which hinder widespread adoption.

Innovation Solution

Integrating QKD functionality with optical transceivers at the datalink and physical coding sublayer, multiplexing QKD service traffic within classical data channels, and implementing scaled key management protocols to enable secure key exchange and quantum channel coordination without dedicated lanes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Volume of moving object

If QKD devices are integrated into network adapters, then device size is reduced and scalability is improved, but device complexity increases due to integration requirements

Engineering Contradiction:
Improvedevice sizeVSAvoidintegration complexity
Core Design Contradiction:
Volume of moving objectVSDevice complexity

Solution Approach 1:

The patent combines QKD functionality with optical transceiver components into an integrated network adapter. The QKD engine is merged with the optical interface, allowing quantum key distribution to coexist with classical data transmission through the same physical medium, thereby reducing device size while managing integration complexity through unified design

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The optical transceiver is designed to perform multiple functions: classical data transmission and quantum key distribution. By making the device universal, it can handle both traditional networking tasks and quantum security protocols simultaneously, reducing the need for separate dedicated QKD hardware

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dedicated service channels are used for QKD, then security is improved, but bandwidth utilization deteriorates due to dedicated lane requirements

Engineering Contradiction:
ImprovesecurityVSAvoidbandwidth utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges quantum service channel traffic with classical data traffic into a single communication medium. By multiplexing QKD control frames with data frames on the same optical channel, the system maintains security through protocol separation while achieving efficient bandwidth utilization through shared physical infrastructure

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent separates quantum and classical traffic at the protocol/frame level rather than requiring separate physical channels. By using different frame types and control mechanisms within the same transmission medium, it adds a logical dimension of separation that maintains security without sacrificing bandwidth efficiency

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If centralized key management is implemented, then security control is improved, but system complexity increases due to centralized architecture requirements

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments key management functionality into distributed network adapter modules, each capable of autonomous key generation and management. This segmentation allows localized security control while reducing the need for complex centralized coordination, as each adapter independently manages its own quantum key distribution

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12413391B2Devices, systems, and methods for integrating encryption service channels with a data path
Publication Date: 2025.09.09 MELLANOX TECHNOLOGIES LTD(IL)
  • US12413391B2 patent drawing
  • US12413391B2 patent drawing
  • US12413391B2 patent drawing

AI summary

A system comprises a transmitter including first circuitry that generates a first frame of a first type for establishing a quantum-secure link with an endpoint according to a security protocol, a data source that generates a second frame of a second type for communicating data to the endpoint, an output that couples to the endpoint via a first communication channel, and second circuitry. The second circuitry selects either the first frame or the second frame, adds information to the selected frame that identifies the selected frame as being of the first type or the second type to form an output frame, and outputs the output frame to the output.