Transition Node Key Exchange Across Non-QKD Network Links

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for exchanging quantum-safe keys between local area networks, such as metro networks, are limited by the high cost and distance constraints of Quantum Key Distribution (QKD) methods, making secure data transmission between networks beyond 100 kilometers impractical and expensive, especially when satellite-based solutions are even more costly and limited by transmission capacities.

Innovation Solution

A method and network node, known as a transition node, enables the exchange of quantum-safe keys between local networks via a connection not designed for QKD, using symmetric encryption with a bitwise XOR operation and Post-Quantum Cryptography (PQC) methods, ensuring secure transmission through shared quantum keys managed by a key management system and processed in hardware-hardened units.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If QKD methods are used to exchange quantum-safe keys between local networks, then security against quantum computer attacks is improved, but device complexity and cost increase significantly

Engineering Contradiction:
Improvesecurity against quantum computer attacksVSAvoidQKD infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces trusted relay nodes as intermediaries that facilitate secure key exchange between distant networks. These relay nodes use QKD to establish quantum-safe keys with neighboring networks, then act as trusted mediators to enable secure communication across multiple hops, thereby reducing the need for direct QKD infrastructure between all pairs of networks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent divides the large-scale network into smaller segments or domains, each with its own QKD infrastructure. By segmenting the network, the complexity of QKD deployment is reduced to manageable local scales, while inter-segment communication is facilitated through trusted relay nodes that bridge the segments securely

Inventive Principle:
Principle #1Segmentation

2Reliability

If QKD methods are used to transmit quantum-safe keys over long distances, then security is improved, but transmission distance is limited to approximately 100 kilometers via fiber optic cables

Engineering Contradiction:
Improvesecurity of key transmissionVSAvoidtransmission distance
Core Design Contradiction:
ReliabilityVSLength of stationary object

Solution Approach 1:

The patent employs trusted relay nodes as intermediaries to extend the transmission distance of quantum-safe keys. These relay nodes receive quantum-safe keys from one network via QKD, store them securely, and forward them to distant networks through classical encrypted channels, thereby overcoming the 100-kilometer distance limitation of direct QKD transmission

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from a single-dimension approach (direct QKD transmission over fiber optics limited to 100 km) to a multi-dimensional approach by combining QKD for local key generation with classical encrypted communication for long-distance key distribution, effectively adding a temporal and hierarchical dimension to the key exchange process

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Length of stationary object

If satellite-based QKD solutions are used for long-distance key exchange, then transmission distance is improved, but cost and transmission capacity limitations worsen

Engineering Contradiction:
Improvetransmission distanceVSAvoidsatellite infrastructure cost
Core Design Contradiction:
Length of stationary objectVSDevice complexity

Solution Approach 1:

The patent employs terrestrial trusted relay nodes as a more cost-effective alternative to expensive satellite infrastructure. These relay nodes use existing fiber optic infrastructure and standard cryptographic equipment to achieve long-distance key distribution, replacing the need for costly satellite deployment while maintaining security through proven cryptographic methods

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Ease of manufacture

If Post-Quantum Cryptography methods are used for key exchange, then cost is reduced compared to QKD, but absolute security against quantum computer attacks is not proven

Engineering Contradiction:
Improvecost-effectiveness of implementationVSAvoidproven security against quantum attacks
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent merges QKD-based key generation with classical Post-Quantum Cryptography for key distribution. Trusted relay nodes generate quantum-safe keys using QKD with nearby networks, then distribute these keys to distant networks through PQC-encrypted classical channels, combining the proven security of QKD with the cost-effectiveness and ease of deployment of PQC

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary key generation using QKD at trusted relay nodes before distributing keys over long distances. By pre-generating quantum-safe keys locally where QKD infrastructure exists, the system ensures high security at the source, then uses these pre-generated keys for secure long-distance communication through more economical classical channels

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3955508B1Exchange of quantum secure keys between local area networks
Publication Date: 2025.12.31 DEUTSCHE TELEKOM AG
  • EP3955508B1 patent drawingFigure 1
  • EP3955508B1 patent drawingFigure 2

AI summary

The invention relates to a solution for exchanging a quantum-safe key between network nodes (21; 22; 8; 9) of two local networks (11; 12), wherein a quantum-safe key generated by one network node (21; 22; 8; 9) for later use in secure data exchange is transmitted as a user key to a network node (21; 22; 8; 9) of the other network (11; 12) via a connection (10) between transition nodes (21; 22) of the networks (11; 12), which is not configured for the use of a QKD method. This is achieved by a bitwise XOR operation of the user key with a quantum key, which is taken from a common key set locally present in both transition nodes (21; 22), containing at least one quantum key used for encrypting the user key.This at least one common quantum key, stored locally in the transition nodes (21; 22), is generated in one of these transition nodes (21; 22) and transmitted to the other transition nodes (21; 22) encrypted using a quantum key that is previously exchanged between the transition nodes (21; 22) using a PQC procedure.