Quantum-Secure VPN Tunnel for Last Mile Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for securing data transmission over the last mile of a public wide area network, particularly from and to subscriber-side connection endpoints, are limited by the high costs and limited range of Quantum Key Distribution (QKD) technology, making it impractical for widespread implementation, especially in the 'last mile' segment between subscriber-side access devices and peering points.

Innovation Solution

A method and system that establish a VPN tunnel secured with a quantum-secure key between an Integrated Access Device (IAD) and a peering point using a pre-shared secret and a central entropy source, such as a Quantum Random Number Generator, without requiring expensive QKD equipment, by generating a shared key through a random number and using it to encrypt the tunnel with protocols like AES 256, ensuring secure data transmission over the last mile.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Quantum Key Distribution (QKD) technology is used to secure data transmission, then security against potential attacks is improved, but cost and device complexity increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a central entropy source as an intermediary that generates quantum-secure random numbers and distributes them to multiple IADs and peering points. This mediator approach allows secure key generation without requiring direct QKD connections between all parties, reducing device complexity while maintaining security through the trusted intermediary that provides pre-shared secrets.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses pre-shared secrets that are copied and distributed to multiple IADs and peering points from the central entropy source. Instead of requiring each device to generate its own quantum keys through complex QKD hardware, the same secret material is copied and distributed, enabling secure encryption with simpler devices that lack QKD capabilities.

Inventive Principle:
Principle #26Copying

2Reliability

If Quantum Key Distribution (QKD) technology is deployed, then security is improved, but the range is limited to approximately 100-300 km

Engineering Contradiction:
ImprovesecurityVSAvoidrange
Core Design Contradiction:
ReliabilityVSLength of moving object

Solution Approach 1:

The patent segments the key distribution function by separating the quantum-secure random number generation (performed by the central entropy source) from the local key generation and encryption (performed by IADs and peering points). This segmentation allows the secure key material to be generated centrally and distributed to multiple locations beyond the limited QKD range, enabling secure connections over much longer distances including the last mile.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The central entropy source acts as a mediator that overcomes the range limitation of direct QKD connections. By generating quantum-secure random numbers centrally and distributing them through conventional channels to multiple IADs and peering points, the system extends secure key distribution beyond the 100-300 km physical limit of optical fiber QKD to unlimited geographic ranges.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If QKD equipment is installed at subscriber-side devices, then security is improved, but cost increases making mass market deployment impractical

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The central entropy source serves as a mediator that provides quantum-secure random numbers to IADs without requiring the IADs to have expensive QKD hardware. The intermediary generates the secure material centrally using quantum capabilities and distributes it to cost-effective IADs that can then use standard encryption algorithms, making deployment feasible for mass market applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent copies pre-shared secrets from the central entropy source to multiple IADs and peering points. This copying approach allows inexpensive IADs without QKD capabilities to obtain quantum-secure key material that was generated centrally, enabling cost-effective deployment across mass market subscriber devices while maintaining high security standards.

Inventive Principle:
Principle #26Copying

4Reliability

If symmetric encryption with pre-shared keys is used, then security is improved over asymmetric encryption, but key distribution becomes vulnerable to interception

Engineering Contradiction:
ImprovesecurityVSAvoidinterception risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The central entropy source acts as a trusted intermediary that securely distributes pre-shared secrets to IADs and peering points. By controlling the key distribution through this intermediary, the system eliminates the vulnerability of peer-to-peer key exchange, as the intermediary can authenticate recipients and ensure secure delivery, reducing interception risks while enabling efficient symmetric encryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent copies pre-shared secrets from the central entropy source to authorized IADs and peering points through controlled distribution channels. This copying approach, managed by the intermediary, ensures that key material is delivered securely to authenticated recipients, preventing interception attacks that would plague uncontrolled peer-to-peer key distribution while enabling fast symmetric encryption.

Inventive Principle:
Principle #26Copying

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution enables cost-effective, secure data transmission over the last mile using quantum-secure keys, protecting against potential attacks, without the need for expensive QKD hardware, and ensures continuous key rotation and validation, maintaining high security standards for both control and user data.

Implementation Method 1

generate keys with very high entropy, meaning truly random keys... using a device with quantum mechanical capabilities, such as a quantum random number generator (QRNG)

Methodology Applied
Scientific EffectQuantum mechanical principles:

Data Source

PatentEP4199419A1Securing from and to subscriber-side connection endpoint over public network of transmitted data
Publication Date: 2023.06.21 DEUTSCHE TELEKOM AG
  • EP4199419A1 patent drawing
  • EP4199419A1 patent drawing
  • EP4199419A1 patent drawing

AI summary

The invention relates to the secure transmission of data via a public wide area network between an Integrated Access Device (IAD) as a subscriber-side connection endpoint and a counterpart, wherein the IAD, as the access device, is connected to an access network via a network node configured as a peering point and, via this access network, to the wide area network. On the last mile, a VPN tunnel is established between the IAD and the peering point, which is secured by means of a protocol using a quantum-safe key.According to the proposed solution, the quantum-safe key used for this purpose is formed as a shared key of the IAD and the Peering Point by calculating a random number generated by an entropy source and transmitted to both facilities in the Peering Point and in the IAD in the same way with a pre-shared secret also represented by a number, namely with a shared secret stored at the IAD and at the Peering Point.