Transition Node Key Exchange Across Non-QKD Network Links
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for exchanging quantum-safe keys between local area networks, such as metro networks, are limited by the high cost and distance constraints of Quantum Key Distribution (QKD) methods, making secure data transmission between networks beyond 100 kilometers impractical and expensive, especially when satellite-based solutions are even more costly and limited by transmission capacities.
Innovation Solution
A method and network node, known as a transition node, enables the exchange of quantum-safe keys between local networks via a connection not designed for QKD, using symmetric encryption with a bitwise XOR operation and Post-Quantum Cryptography (PQC) methods, ensuring secure transmission through shared quantum keys managed by a key management system and processed in hardware-hardened units.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If QKD methods are used to exchange quantum-safe keys between local networks, then security against quantum computer attacks is improved, but device complexity and cost increase significantly
Solution Approach 1:
The patent introduces trusted relay nodes as intermediaries that facilitate secure key exchange between distant networks. These relay nodes use QKD to establish quantum-safe keys with neighboring networks, then act as trusted mediators to enable secure communication across multiple hops, thereby reducing the need for direct QKD infrastructure between all pairs of networks
Solution Approach 2:
The patent divides the large-scale network into smaller segments or domains, each with its own QKD infrastructure. By segmenting the network, the complexity of QKD deployment is reduced to manageable local scales, while inter-segment communication is facilitated through trusted relay nodes that bridge the segments securely
2Reliability
If QKD methods are used to transmit quantum-safe keys over long distances, then security is improved, but transmission distance is limited to approximately 100 kilometers via fiber optic cables
Solution Approach 1:
The patent employs trusted relay nodes as intermediaries to extend the transmission distance of quantum-safe keys. These relay nodes receive quantum-safe keys from one network via QKD, store them securely, and forward them to distant networks through classical encrypted channels, thereby overcoming the 100-kilometer distance limitation of direct QKD transmission
Solution Approach 2:
The patent transitions from a single-dimension approach (direct QKD transmission over fiber optics limited to 100 km) to a multi-dimensional approach by combining QKD for local key generation with classical encrypted communication for long-distance key distribution, effectively adding a temporal and hierarchical dimension to the key exchange process
3Length of stationary object
If satellite-based QKD solutions are used for long-distance key exchange, then transmission distance is improved, but cost and transmission capacity limitations worsen
Solution Approach 1:
The patent employs terrestrial trusted relay nodes as a more cost-effective alternative to expensive satellite infrastructure. These relay nodes use existing fiber optic infrastructure and standard cryptographic equipment to achieve long-distance key distribution, replacing the need for costly satellite deployment while maintaining security through proven cryptographic methods
4Ease of manufacture
If Post-Quantum Cryptography methods are used for key exchange, then cost is reduced compared to QKD, but absolute security against quantum computer attacks is not proven
Solution Approach 1:
The patent merges QKD-based key generation with classical Post-Quantum Cryptography for key distribution. Trusted relay nodes generate quantum-safe keys using QKD with nearby networks, then distribute these keys to distant networks through PQC-encrypted classical channels, combining the proven security of QKD with the cost-effectiveness and ease of deployment of PQC
Solution Approach 2:
The patent performs preliminary key generation using QKD at trusted relay nodes before distributing keys over long distances. By pre-generating quantum-safe keys locally where QKD infrastructure exists, the system ensures high security at the source, then uses these pre-generated keys for secure long-distance communication through more economical classical channels
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a solution for exchanging a quantum-safe key between network nodes (21; 22; 8; 9) of two local networks (11; 12), wherein a quantum-safe key generated by one network node (21; 22; 8; 9) for later use in secure data exchange is transmitted as a user key to a network node (21; 22; 8; 9) of the other network (11; 12) via a connection (10) between transition nodes (21; 22) of the networks (11; 12), which is not configured for the use of a QKD method. This is achieved by a bitwise XOR operation of the user key with a quantum key, which is taken from a common key set locally present in both transition nodes (21; 22), containing at least one quantum key used for encrypting the user key.This at least one common quantum key, stored locally in the transition nodes (21; 22), is generated in one of these transition nodes (21; 22) and transmitted to the other transition nodes (21; 22) encrypted using a quantum key that is previously exchanged between the transition nodes (21; 22) using a PQC procedure.