Symmetric Key Authentication for Quantum-Resistant Application Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing public key authentication standards are vulnerable to attacks from quantum computers, as they can be broken using Shor's algorithm, posing a risk to secure sessions over public or private networks.

Innovation Solution

A method and system for secure authentication between applications using symmetric authentication keys, where a computing device generates unique keys for pairs of applications that can connect, enabling mutual authentication resistant to quantum computer threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public key authentication is used, then authentication can be performed over public networks, but the authentication can be broken by quantum computers using Shor's algorithm

Engineering Contradiction:
Improveauthentication securityVSAvoidquantum computer attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the fundamental parameter of authentication from public key cryptography to symmetric key cryptography. By using pre-shared symmetric keys established before quantum computing threats become practical, the system maintains security against quantum attacks while preserving network communication capabilities

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements preliminary key establishment where symmetric authentication keys are generated and distributed to application pairs before actual communication occurs. This pre-authentication approach ensures that when communication happens, the keys are already in place and resistant to quantum decryption attempts

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If symmetric authentication keys are generated for each application pair, then quantum security is achieved, but key management complexity increases

Engineering Contradiction:
Improvequantum attack resistanceVSAvoidkey management system
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent creates a universal key management system that handles multiple application pairs with a single centralized authority. The key generation server can serve any pair of applications that need secure communication, making the system scalable without proportionally increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the key management into distinct functional components: key generation, key distribution, and key storage. Each component has a specific role, and the segmentation allows for modular implementation and management of the authentication system

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12278894B2Systems and methods for secure authentication between application in quantum computing
Publication Date: 2025.04.15 MORGAN STANLEY SERVICES GROUP INC
  • US12278894B2 patent drawing
  • US12278894B2 patent drawing
  • US12278894B2 patent drawing

AI summary

A system and method for secure authentication between applications that may be attacked with an attack originating from a quantum computer is provided. The systems and methods can involve generating a plurality of keys, wherein each key of the plurality of keys is unique and determining one or more pairs of applications from a plurality of applications, wherein each pair can include applications that can connect. The systems and methods can also involve upon receiving a request from a first application of the plurality of applications to connect to a second application of the plurality of applications finding the pair of the one or more pairs that includes both the first application and the second application and associating one key of the plurality of keys to the pair, and performing by the first application and the second application, mutual authentication using the one key.