Secret-Key Provisioning Queue for QKD Access Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional access networks face challenges in providing sufficient and flexible secret-key provisioning for multiple users, as the volume of secret-keys generated by real-time Quantum Key Distribution (QKD) cannot fully meet the security requirements of final users in QKD-secured access networks.

Innovation Solution

A method and device for secret-key provisioning (SKP) that generates an SKP queue based on key requests, determines the quantity of secret-keys needed, and allocates time slots for key generation and storage in key pools at optical network units (ONUs), ensuring efficient and flexible key distribution by prioritizing high-level requests and matching time slots with security requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time QKD is used to generate secret-keys, then security is improved, but the volume of secret-keys generated is insufficient to meet final user requirements

Engineering Contradiction:
ImprovesecurityVSAvoidvolume of secret-keys
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system performs preliminary actions by generating secret-keys in advance and storing them in key pools at ONUs before actual communication occurs. The OLT proactively manages key generation and distribution based on predicted or pre-stated user needs, ensuring sufficient key volume is available when required without waiting for real-time requests alone.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The OLT acts as an intermediary between the QKD system and final users. It receives key requests from ONUs, manages the SKP queue, coordinates with QKD resources, and distributes appropriate secret-keys to key pools. This intermediary role enables the system to buffer and allocate key resources efficiently, bridging the gap between real-time QKD generation and user demand.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional access network management is used, then network control is simplified, but security requirements challenge the aggregation and broadcasting processes

Engineering Contradiction:
Improvenetwork controlVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system segments the key management process into distinct functional components: key request collection at ONUs, queue management at the OLT, key generation based on prioritized requests, and distribution to key pools. This segmentation allows traditional network control mechanisms to coexist with enhanced security functions, as each component handles specific security tasks independently while maintaining overall network manageability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces dynamic key management capabilities where the OLT adjusts key generation and distribution based on real-time requests, user levels, and available resources. The SKP queue dynamically prioritizes requests based on user levels and pairing opportunities, allowing the network to adapt its security provisioning behavior without fundamentally redesigning traditional access network control architectures.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If secret-keys are generated without prioritization, then all user requests are treated equally, but high-level requests may not receive sufficient key provisioning

Engineering Contradiction:
ImproveflexibilityVSAvoidkey provisioning for high-level requests
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system applies local quality by differentiating key provisioning based on user request levels. High-level requests receive prioritized treatment with faster key generation and guaranteed provisioning, while lower-level requests follow standard processing. The SKP queue implements level-based prioritization that allocates resources differently to different request types, ensuring high-level users receive adequate key support without completely ignoring lower-level needs.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11936777B2Method, device of secret-key provisioning and computer-readable storage medium thereof
Publication Date: 2024.03.19 BEIJING UNIV OF POSTS & TELECOMM
  • US11936777B2 patent drawing
  • US11936777B2 patent drawing
  • US11936777B2 patent drawing

AI summary

Disclosed is a secret-key provisioning (SKP) method and device based on an optical line terminal (OLT), which can generate an SKP queue according to key requests received; generate at least one secret-key according to the SKP queue; and store the at least one secret-key in key pools (KPs) of corresponding ONUS. A non-transitory computer-readable storage medium is also disclosed.