Secret-Key Provisioning Queue for QKD Access Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional access networks face challenges in providing sufficient and flexible secret-key provisioning for multiple users, as the volume of secret-keys generated by real-time Quantum Key Distribution (QKD) cannot fully meet the security requirements of final users in QKD-secured access networks.
Innovation Solution
A method and device for secret-key provisioning (SKP) that generates an SKP queue based on key requests, determines the quantity of secret-keys needed, and allocates time slots for key generation and storage in key pools at optical network units (ONUs), ensuring efficient and flexible key distribution by prioritizing high-level requests and matching time slots with security requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If real-time QKD is used to generate secret-keys, then security is improved, but the volume of secret-keys generated is insufficient to meet final user requirements
Solution Approach 1:
The system performs preliminary actions by generating secret-keys in advance and storing them in key pools at ONUs before actual communication occurs. The OLT proactively manages key generation and distribution based on predicted or pre-stated user needs, ensuring sufficient key volume is available when required without waiting for real-time requests alone.
Solution Approach 2:
The OLT acts as an intermediary between the QKD system and final users. It receives key requests from ONUs, manages the SKP queue, coordinates with QKD resources, and distributes appropriate secret-keys to key pools. This intermediary role enables the system to buffer and allocate key resources efficiently, bridging the gap between real-time QKD generation and user demand.
2Device complexity
If traditional access network management is used, then network control is simplified, but security requirements challenge the aggregation and broadcasting processes
Solution Approach 1:
The system segments the key management process into distinct functional components: key request collection at ONUs, queue management at the OLT, key generation based on prioritized requests, and distribution to key pools. This segmentation allows traditional network control mechanisms to coexist with enhanced security functions, as each component handles specific security tasks independently while maintaining overall network manageability.
Solution Approach 2:
The system introduces dynamic key management capabilities where the OLT adjusts key generation and distribution based on real-time requests, user levels, and available resources. The SKP queue dynamically prioritizes requests based on user levels and pairing opportunities, allowing the network to adapt its security provisioning behavior without fundamentally redesigning traditional access network control architectures.
3Adaptability or versatility
If secret-keys are generated without prioritization, then all user requests are treated equally, but high-level requests may not receive sufficient key provisioning
Solution Approach 1:
The system applies local quality by differentiating key provisioning based on user request levels. High-level requests receive prioritized treatment with faster key generation and guaranteed provisioning, while lower-level requests follow standard processing. The SKP queue implements level-based prioritization that allocates resources differently to different request types, ensuring high-level users receive adequate key support without completely ignoring lower-level needs.
Data Source
AI summary
Disclosed is a secret-key provisioning (SKP) method and device based on an optical line terminal (OLT), which can generate an SKP queue according to key requests received; generate at least one secret-key according to the SKP queue; and store the at least one secret-key in key pools (KPs) of corresponding ONUS. A non-transitory computer-readable storage medium is also disclosed.


