Untrusted Quantum Nodes for Extended QKD Distance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Quantum Key Distribution (QKD) systems face limitations in range due to the exponential decrease of surviving photons with distance, requiring trusted nodes that compromise security by storing secret keys in plain text, making it unsuitable for external users.

Innovation Solution

Implementing untrusted quantum nodes with mechanical robust containment and a security code system, where customers generate and control access to cryptographic key material, ensuring only authorized access to QKD modules and key management systems, eliminating the need for trust in intermediate nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Length of stationary object

If trusted nodes are used to extend QKD distance, then the transmission distance is improved, but the security is worsened because secret keys are stored in plain text at intermediate nodes

Engineering Contradiction:
Improvetransmission distanceVSAvoidsecurity
Core Design Contradiction:
Length of stationary objectVSReliability

Solution Approach 1:

The quantum connection is segmented into multiple hops between intermediate quantum nodes, where each node performs quantum operations on flying qubits without needing to store secret keys in plain text. This segmentation allows extended transmission distance while maintaining security at each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Intermediate quantum nodes act as mediators that perform quantum operations (such as quantum teleportation or entanglement swapping) on flying qubits to extend the quantum connection distance. These nodes do not require plain text key storage because they operate quantum mechanically rather than classically encrypting and storing keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If mechanical robust containment with security codes is implemented, then access security is improved, but device complexity is worsened

Engineering Contradiction:
Improveaccess securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Mechanical robust containment with security code input units is applied locally at each intermediate quantum node to protect quantum modules and key management systems. This localized security approach protects critical components without requiring system-wide complexity increases.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Security codes are generated in advance using cryptographic key material and stored securely. The mechanical containment structures are prepared with input units before deployment, allowing immediate security protection when the quantum key distribution system is activated without requiring complex runtime security management.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3905094B1System and method for distributing quantum-safe keys over longer distances
Publication Date: 2022.05.04 DEUTSCHE TELEKOM AG
  • EP3905094B1 patent drawingFigure 1
  • EP3905094B1 patent drawingFigure 2
  • EP3905094B1 patent drawing

AI summary

The present invention refers to a method for controlling a quantum key distribution between a first quantum node (110) and a second quantum node (120) over longer distances of a quantum connection including at least one intermediate untrusted quantum node (150), each quantum node (110, 120, 150) comprising at least one quantum key distribution module (112, 122, 152) and at least one key management system (113, 123, 153), the method comprising at least: a) providing, at each of the at least one intermediate untrusted quantum node (150), a mechanical robust containment (151) for the at least one quantum key distribution module (152) and the at least one key management system (153), the mechanical robust containment (151) being configured to prevent an instant physical access to the at least one quantum key distribution module (152) and the at least one key management system (153), b) supplying, at each of the at least one intermediate untrusted quantum node (150), the mechanical robust containment (151) with an input unit (154) for keying in a respective security code to access the at least one quantum key distribution module (152) and the at least one key management system of the respective intermediate untrusted quantum node (150), c) generating the respective security code using cryptographic key material which is to be made available exclusively to at least one of the first quantum node (110) and the second quantum node (120), and the respective one of the at least one intermediate untrusted quantum node (150). The present invention further refers to a respective system.