Quantum Secure Key Distribution via XOR Linking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current quantum key distribution (QKD) networks are complex and expensive to implement, especially in fully meshed networks with long transmission paths, as they require numerous connections and optical amplifiers that can destroy quantum mechanical states, limiting their distance to around 100 km.

Innovation Solution

A method that uses quantum-secure keys (QSKs) distributed through a network with at least three nodes, where two nodes are connected via a QKD connection, generating shared symmetrical keys for data encryption, and extending QSKs to non-QKD-supported nodes via disjoint network paths, using XOR linking and Quantum Random Number Generators to increase key generation rate and reduce costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Length of stationary object

If QKD connections are established over long distances using optical amplifiers, then transmission distance is extended, but quantum mechanical states are destroyed and QKD key generation becomes impossible

Engineering Contradiction:
Improvetransmission distanceVSAvoidQKD key generation capability
Core Design Contradiction:
Length of stationary objectVSReliability

Solution Approach 1:

The network is segmented into QKD-supported nodes (with direct QKD connections) and non-QKD-supported nodes (without direct QKD connections). This segmentation allows long-distance communication without requiring QKD infrastructure at every node, thereby extending transmission distance while preserving QKD key generation capability where needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

QKD-supported nodes act as intermediaries that generate quantum-secure keys using QKD connections and then distribute these keys to non-QKD-supported nodes through classical encrypted channels. This intermediary approach enables long-distance secure communication without requiring optical amplifiers in the quantum channel, avoiding destruction of quantum states.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a fully meshed QKD network is implemented to secure all connections, then network security is improved, but implementation complexity and cost increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidQKD connection infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is divided into QKD-supported and non-QKD-supported nodes. Only critical connections between QKD-supported nodes require direct QKD infrastructure, while other connections use classical encrypted channels with keys distributed by QKD nodes. This segmentation maintains network security while dramatically reducing the number of required QKD connections from N×(N-1)/2 to far fewer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

QKD-supported nodes perform multiple functions: they generate quantum-secure keys through QKD connections, store these keys, and distribute them to non-QKD-supported nodes via classical encrypted channels. This multi-functionality allows a small subset of nodes to provide security services to the entire network, reducing overall infrastructure complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If symmetric encryption is used to improve security, then encryption strength increases, but key distribution difficulty increases between sender and receiver

Engineering Contradiction:
Improveencryption strengthVSAvoidkey distribution
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

QKD-supported nodes act as key distribution intermediaries. They generate symmetric encryption keys using quantum-secure QKD connections and then distribute these keys to non-QKD-supported nodes through classical channels protected by the same QSKs. This approach maintains strong symmetric encryption while solving the key distribution problem through centralized key management at QKD nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables secure and cost-effective encryption of data across the entire network, including long transmission paths, by distributing QSKs efficiently and securely, reducing the need for extensive QKD connections and optical amplifiers, thus enhancing network security and scalability.

Implementation Method 1

at least two network nodes are connected to one another via a QKD connection, via which shared symmetrical keys are generated using quantum mechanical effects

Methodology Applied
Scientific EffectQuantum mechanical effects:

Implementation Method 2

which use quantum mechanical principles for key generation and distribute quantum-secure keys via quantum-secure connections

Methodology Applied
Scientific EffectQuantum mechanical principles:

Data Source

PatentEP3761557B1Distribution and utilisation of quantum secure keys in a network
Publication Date: 2022.04.27 DEUTSCHE TELEKOM AG
  • EP3761557B1 patent drawingFigure 1
  • EP3761557B1 patent drawingFigure 2
  • EP3761557B1 patent drawingFigure 3

AI summary

The invention relates to a technical solution for using quantum-safe keys (QSKs) for data transmission in a network (communication network) with at least three network nodes. In the network, at least two network nodes forming a QKD alliance are interconnected via a QKD connection. At least one network node, however, is a non-QKD-supported node, i.e., a network node that does not belong to a QKD alliance. According to the invention, a completely disjoint connection is established to all non-QKD-supported nodes, unless one already exists.A QKD network generates a number of initial QSKs. These QSKs are then sequentially distributed to non-QKD-supported nodes by repeatedly XORing them with each other and with one of several further QSKs D[1,n] generated by the QKD network. This distribution enables the establishment of quantum-secured connections and encrypted data transmission via different network paths of their disjoint connection to the QKD network. The generation and distribution of the QSKs are controlled by a central key management system and a local key management system present at each network node.