Secure Key Agreement with Untrusted Quantum Stations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems face challenges in generating secure keys in noisy networks with untrusted components, particularly due to vulnerabilities in key distribution methods that can be exploited by eavesdroppers through memory attacks and covert channels.

Innovation Solution

The method involves generating correlated raw data using quantum key distribution (QKD) between cryptographic stations, followed by information reconciliation and privacy amplification to ensure secure key generation, even in the presence of untrusted key generation and post-processing units, using techniques like secret sharing and verifiable secret sharing schemes to distribute and verify key shares.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If quantum key distribution is used to generate cryptographic keys in noisy networks, then security against eavesdropping is improved, but vulnerability to memory attacks and covert channels by untrusted components increases

Engineering Contradiction:
Improvesecurity against eavesdroppingVSAvoidvulnerability to memory attacks and covert channels
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the key generation system into multiple independent components: multiple key generation units (KGUs) and multiple classical post-processing units (CLPUs). Each KGU generates independent raw keys, and each CLPU independently processes these keys. This segmentation ensures that a compromise in one component does not affect the entire system, as honest components can still generate secure keys. The segmented architecture specifically addresses memory attacks by isolating potential memory vulnerabilities to individual units rather than the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces verifiable secret sharing (VSS) as an intermediary mechanism between key generation units and classical post-processing units. VSS allows KGUs to distribute key shares to CLPUs in a verifiable manner, ensuring that untrusted components cannot manipulate the key generation process. The VSS protocol acts as a mediator that provides information-theoretic security guarantees, preventing covert channels and memory attacks by ensuring that only authorized participants can access the final key material.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple key generation units and post-processing units are used to ensure security against untrusted components, then information-theoretic security is improved, but device complexity increases

Engineering Contradiction:
Improveinformation-theoretic securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs key generation units and classical post-processing units with universal functionality. Each KGU can generate raw keys for multiple CLPUs, and each CLPU can process keys from multiple KGUs. This multi-functionality allows the system to achieve information-theoretic security through modular components that can be independently deployed and configured. The universal design reduces overall system complexity by avoiding specialized hardware for each security function, as the same units perform multiple security-related tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If raw data is generated and processed through information reconciliation and privacy amplification, then secure key generation is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvesecure key generationVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary key generation and verification actions before final key distribution. Multiple KGUs generate raw keys in advance, and VSS protocols verify the integrity of these keys beforehand. This preliminary action allows the system to identify and eliminate compromised keys early in the process, reducing the time needed for subsequent reconciliation and amplification operations. By preparing and verifying key material in advance, the system minimizes processing time during critical key distribution phases.

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach provides information-theoretic security for the generated key, ensuring unconditional security against eavesdroppers and foil covert channels, thereby enhancing the reliability of secure communication and authentication.

Implementation Method 1

generating correlated raw data using quantum key distribution (QKD) between cryptographic stations

Methodology Applied
Scientific EffectQuantum key distribution:

Data Source

PatentUS11336442B2Secure key agreement with untrusted parties
Publication Date: 2022.05.17 UNIVE DE VIGO
  • US11336442B2 patent drawing
  • US11336442B2 patent drawing
  • US11336442B2 patent drawing

AI summary

Traditional key generation methods in a noisy network often assume trusted devices and are thus vulnerable to many attacks including covert channels. The present invention differs from previous key generation schemes in that it presents a mechanism which allows secure key generation with untrusted devices in a noisy network with a prescribed access structure.