Communication device, cipher communication method, program, and cipher communication system
The communication device enhances quantum cryptography security by using closed network communication to transmit encryption keys and identifiers from a key management device, ensuring secure encrypted communication over wide area networks.
Patent Information
- Application Number
- JP2024051071
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-27
- Publication Date
- 2025-10-09
AI Technical Summary
Quantum cryptography requires a special quantum key distribution device for sending and receiving photons, making it difficult to deliver encryption keys securely to communication devices, and there is a risk of eavesdropping between the quantum key distribution device and the communication device over non-quantum networks.
A communication device that uses closed network communication to receive encryption keys and identifiers from a key management device connected to a quantum key distribution device, allowing secure transmission and use of encryption keys over wide area networks.
Ensures more secure encrypted communication by reducing the risk of eavesdropping and enhancing key delivery security through closed network communication.
Smart Images

Figure 2025150266000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a communication device, an encrypted communication method, a program, and an encrypted communication system. [Background technology]
[0002] Quantum cryptography is attracting attention. Quantum cryptography is a communications technology that guarantees the security of information. It involves transmitting a cryptographic key on photons over optical fiber, notifying the other party of the communication, and then encrypting the data with this cryptographic key before transmitting it over a regular line. Utilizing the quantum mechanical property that photons always change state when they come into contact with something, it is possible to reliably detect eavesdropping on a key by a third party. Therefore, if eavesdropping on an encryption key is detected, that encryption key can be discarded and a cryptographic key that has not been detected as having been eavesdropped can be used, ensuring secure communications.
[0003] Patent Document 1 discloses a transfer device connected to a key management server device that receives information specifying packets to be encrypted from a mobile phone network management server device and generates encryption keys using quantum key distribution. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Publication No. 2022-075398 Summary of the Invention [Problem to be solved by the invention]
[0005] In quantum cryptography, encryption keys are distributed securely over a quantum key distribution (QKD) network using optical fiber. However, quantum cryptography requires a special quantum key distribution device (QKD distribution device) for sending and receiving photons, making it difficult to deliver the encryption key to the communication device that uses it.
[0006] Therefore, since it is assumed that a normal communication network other than the quantum key distribution network will be used from the quantum key distribution device to the terminal that actually uses the encryption key, there is a risk of eavesdropping or other problems occurring between this quantum key distribution device and the communication device.
[0007] The present disclosure has been made in consideration of the above circumstances, and discloses a communication device that can perform more secure encrypted communication. [Means for solving the problem]
[0008] The communication device disclosed herein is a communication device that includes: a communication unit that receives an encryption key and a key identifier of the encryption key from a key management device that receives the encryption key from a quantum key distribution device via closed network communication, which is communication via a closed network without going through a wide area network; and that transmits the key identifier to a counterpart communication device connected to the closed network via the closed network communication; and a control unit that performs encrypted communication with the counterpart communication device using the encryption key via the wide area network.
[0009] The communication device of the present disclosure is a communication device that includes a communication unit that receives a key identifier from a counterpart communication device via closed network communication, which is communication via a closed network without going through a wide area network, and receives the encryption key corresponding to the key identifier via the closed network communication from a key management device that receives an encryption key from a quantum key distribution device, and a control unit that performs encrypted communication with the counterpart communication device using the encryption key via the wide area network.
[0010] The communication device disclosed herein is a communication device that includes a communication unit that transmits its own encryption key, which is an encryption key stored in its own non-volatile memory unit, to a counterpart communication device as a request to start encrypted communication via closed network communication, which is communication via a closed network rather than a wide area network, and receives from the counterpart communication device a counterpart encryption key, which is an encryption key stored in the non-volatile memory unit of the counterpart communication device, as a response to start encrypted communication via the closed network communication, and a control unit that performs encrypted communication with the counterpart communication device using the encryption key via the wide area network.
[0011] The communication device disclosed herein is a communication device that includes a communication unit that receives a counterpart encryption key, which is an encryption key stored in a non-volatile memory unit of the counterpart communication device, as a request to start encrypted communication via closed network communication, which is communication via a closed network rather than a wide area network, from the counterpart communication device, and transmits its own encryption key, which is an encryption key stored in its own non-volatile memory unit, to the counterpart communication device via the closed network communication as a response to start encrypted communication, and a control unit that performs encrypted communication with the counterpart communication device using the encryption key via the wide area network.
[0012] The cryptographic communication method disclosed herein is a cryptographic communication method in which a key management device receives an encryption key from a quantum key distribution device via closed network communication, which is communication via a closed network without going through a wide area network, receives the encryption key and a key identifier of the encryption key, transmits the key identifier via the closed network communication to a counterpart communication device connected to the closed network, and performs cryptographic communication with the counterpart communication device using the encryption key via the wide area network.
[0013] The cryptographic communication method disclosed herein is a cryptographic communication method in which a key identifier is received from a counterpart communication device via closed network communication, which is communication via a closed network without going through a wide area network, and the cryptographic key corresponding to the key identifier is received via the closed network communication from a key management device that receives a cryptographic key from a quantum key distribution device, and cryptographic communication is performed with the counterpart communication device using the cryptographic key via the wide area network.
[0014] The cryptographic communication method disclosed herein is a cryptographic communication method in which a request to start cryptographic communication is sent to a counterpart communication device via closed network communication, which is communication via a closed network rather than a wide area network, along with a self-encryption key, which is an encryption key stored in the counterpart communication device's non-volatile memory unit, and a cryptographic communication start response is received from the counterpart communication device via the closed network communication, along with a counterpart encryption key, which is an encryption key stored in the non-volatile memory unit of the counterpart communication device, and cryptographic communication is performed with the counterpart communication device using the encryption key via the wide area network.
[0015] The cryptographic communication method disclosed herein receives a cryptographic communication start request from a counterpart communication device via closed network communication, which is communication via a closed network rather than a wide area network, along with a counterpart encryption key, which is an encryption key stored in a non-volatile memory unit of the counterpart communication device; transmits a cryptographic communication start response to the counterpart communication device via the closed network communication, along with its own encryption key, which is an encryption key stored in its own non-volatile memory unit; and performs cryptographic communication with the counterpart communication device via the wide area network using the encryption key.
[0016] The program disclosed herein causes a computer to execute the following steps: receiving an encryption key and a key identifier of the encryption key from a key management device that receives the encryption key from a quantum key distribution device via closed network communication, which is communication via a closed network without going through a wide area network; transmitting the key identifier to a counterpart communication device connected to the closed network via the closed network communication; and performing encrypted communication with the counterpart communication device using the encryption key via the wide area network.
[0017] The program disclosed herein causes a computer to execute the following steps: receiving a key identifier from a counterpart communication device via closed network communication, which is communication via a closed network without going through a wide area network; receiving an encryption key corresponding to the key identifier via the closed network communication from a key management device that receives the encryption key from a quantum key distribution device; and performing encrypted communication with the counterpart communication device using the encryption key via the wide area network.
[0018] The program disclosed herein causes a computer to execute the following steps: sending a request to start cryptographic communication to a counterpart communication device via closed network communication, which is communication via a closed network rather than a wide area network, along with its own encryption key, which is an encryption key stored in its own non-volatile memory; receiving a cryptographic communication start response from the counterpart communication device via the closed network communication, along with the counterpart encryption key, which is an encryption key stored in the non-volatile memory of the counterpart communication device; and performing cryptographic communication with the counterpart communication device via the wide area network using the encryption key.
[0019] The program disclosed herein causes a computer to execute the following steps: receiving a request to start cryptographic communication from a counterpart communication device, together with a counterpart encryption key, which is an encryption key stored in a non-volatile memory unit of the counterpart communication device, via closed network communication, which is communication via a closed network rather than a wide area network; sending a cryptographic communication start response to the counterpart communication device, together with its own encryption key, which is an encryption key stored in its own non-volatile memory unit, via the closed network communication; and performing cryptographic communication with the counterpart communication device using the encryption key via the wide area network.
[0020] The cryptographic communication system of the present disclosure includes a first communication device and a second communication device, wherein the first communication device receives the cryptographic key and a key identifier of the cryptographic key from a first key management device that receives the cryptographic key from a quantum key distribution device via closed network communication, which is communication via a closed network without going through a wide area network, and transmits the key identifier to the second communication device connected to the closed network via the closed network communication, and the second communication device receives the key identifier from the first communication device via the closed network communication and receives the cryptographic key corresponding to the key identifier via the closed network communication from a second key management device that receives the cryptographic key from the quantum key distribution device, and the first communication device and the second communication device perform cryptographic communication using the cryptographic key via the wide area network.
[0021] The cryptographic communication system of the present disclosure includes a first communication device and a second communication device, wherein the first communication device transmits a cryptographic communication start request to the second communication device, together with a first encryption key, which is an encryption key stored in its own non-volatile memory unit, via closed network communication, which is communication via a closed network without going through a wide area network, and receives a cryptographic communication start response from the second communication device, together with a second encryption key, which is an encryption key stored in the non-volatile memory unit of the second communication device, via the closed network communication; the second communication device receives the cryptographic communication start request from the first communication device, together with the first encryption key, which is an encryption key stored in the non-volatile memory unit of the first communication device, via the closed network communication, and transmits the cryptographic communication start response to the first communication device, together with the second encryption key, which is an encryption key stored in its own non-volatile memory unit, via the closed network communication; and the first communication device and the second communication device perform cryptographic communication using encryption keys via the wide area network. [Effects of the Invention]
[0022] According to the communication device, encrypted communication method, program, and encrypted communication system of the present disclosure, more secure encrypted communication can be performed. [Brief explanation of the drawings]
[0023] [Figure 1] 1 is a diagram illustrating a configuration example of an encrypted communication system according to an embodiment of the present disclosure. [Figure 2] FIG. 2 is a diagram illustrating an example of a hardware configuration of a communication device. [Figure 3] FIG. 1 is a sequence diagram illustrating an example of encrypted communication using the encrypted communication system. [Figure 4] FIG. 10 is a sequence diagram showing another example of encrypted communication using the encrypted communication system. [Figure 5] FIG. 10 is a diagram illustrating an example of a method for generating a combined encryption key. [Figure 6] FIG. 10 is a diagram schematically illustrating another example of a method for generating a combined encryption key. DETAILED DESCRIPTION OF THE INVENTION
[0024] A communication device, a cryptographic communication method, a program, and a cryptographic communication system according to embodiments of the present disclosure will be described with reference to the drawings. In the description, like elements are designated by like reference numerals, and duplicated descriptions will be omitted where appropriate.
[0025] 1 is a diagram illustrating an example configuration of an encrypted communication system 1 according to an embodiment of the present disclosure. As shown in FIG. 1, the encrypted communication system 1 includes a first communication device 111, a second communication device 112, a private network 15, and a wide area network 14. The first communication device 111 and the second communication device 112 can communicate with a base station 152 in the private network 15 via wireless communication. In the following description, when describing matters common to the first communication device 111 and the second communication device 112, they may be simply referred to as "communication device 11."
[0026] The private network 15 can be a mobile communication network that connects so-called mobile phone voice calls and the like. The private network 15 may have, for example, a base station 152, an exchange 151, and a gateway 153. The base station 152 can be connected to the base station 152 to which the communication device 11 of the communication destination is connected via one or more exchanges 151, thereby allowing the communication devices 11 to perform private network communication with each other via the private network 15 without going through the wide area network 14. Here, private network communication means communication that does not go through any wide area network. The base station 152 can also be connected to a wide area network 14 such as the Internet via a gateway 153. This allows the communication devices 11 to communicate with each other via the wide area network 14 via the gateway 153 of the private network 15. The private network 15 is not limited to what is shown here and may have any necessary communication facilities. In addition, the communication device 11 may be capable of connecting to the wide area network 14 by wired or wireless communication directly via a server of a connection provider of the wide area network 14, such as the Internet network, without going through the base station 152.
[0027] The cryptographic communication system 1 may include quantum key distribution devices such as a first quantum key distribution device 121 and a second quantum key distribution device 122, which are terminals of a quantum key distribution network 123. In the quantum key distribution network 123, encryption keys are transmitted and received using quantum encrypted communication. The cryptographic communication system 1 may also include key management devices such as a first key management device 131 and a second key management device 132. The key management device 131 (132) can be directly or indirectly connected to an exchange 151 of the private network 15. Even if the key management device 131 (132) is indirectly connected, it is preferable that the key management device 131 be directly connected to equipment within the private network 15, so that the key management device 131 can be securely connected to the private network 15. Here, the key management device 131 (132) may receive the encryption key from the quantum key distribution device 121 (122) via a communication line that does not go through a wide area network such as a dedicated line or the private network 15. As a result, the encrypted communication system 1 can send the encryption key securely for communication from the quantum key distribution device 121 (122) to the key management device 131 (132). Therefore, even when the encryption key is transmitted from the quantum key distribution device 121 (122) to the communication device 11 without using quantum encrypted communication, more secure encrypted communication can be achieved.
[0028] FIG. 2 is a diagram illustrating an example of the hardware configuration of communication device 11. As shown in this diagram, communication device 11 includes control unit 117, communication unit 118, and storage unit 119. Communication device 11 may be a so-called information processing device, mainly composed of electronic circuits using semiconductor circuit elements. For example, control unit 117 includes a central processing unit (CPU) and a volatile storage unit such as a random access memory (RAM). Communication unit 118 can communicate via base station 152 of private network 15 and can communicate with a server of a service provider via wired or wireless communication to connect to wide area network 14. Storage unit 119 includes a nonvolatile storage unit such as a flash memory or a hard disk, and stores data and programs. Control unit 117, communication unit 118, and storage unit 119 may each include a CPU, a volatile storage unit, or a nonvolatile storage unit. 2 operates in association with programs and data stored in the storage unit 119. The storage unit 119 of the communication device 11 of the encrypted communication system 1 may store programs for configuring the encrypted communication system 1. The communication device 11 may be an information processing device such as a smartphone, a mobile phone, a tablet terminal, or a personal computer.
[0029] 3 is a sequence diagram showing an example of encrypted communication using the encrypted communication system 1. This sequence diagram shows an example in which the first communication device 111 and the second communication device 112 perform encrypted communication using encryption keys distributed by the quantum key distribution devices 121 and 122. As shown in this sequence diagram, first, in step S101, the first communication device 111 transmits a request for issuing a key to be used in the encrypted communication to the first key management device 131 via closed network communication. Upon receiving the key issuance request, the first key management device 131 transmits a key issuance request to the first quantum key distribution device 121 in step S102. Upon receiving the key issuance request, the first quantum key distribution device 121 generates an encryption key in an encryption key generation process S103. In step S104, the generated encryption key is shared with the second quantum key distribution device 122 via quantum encryption communication. In step S105, the second key management device 132 acquires the encryption key and the key identifier distributed together with the encryption key from the second quantum key distribution device 122, and stores them in step S106.
[0030] In step S111, the first key management device 131 acquires an encryption key and a key identifier that is an identifier of the encryption key from the first quantum key distribution device 121, and in step S112 transmits the encryption key and the key identifier to the first communication device 111 via closed network communication. The first communication device 111 stores the received encryption key in step S120, and transmits the key identifier to the second communication device 112 via closed network communication in step S121. The second communication device 112 that has received the key identifier transmits the key identifier to the second key management device 132 via closed network communication in step S122, and acquires the encryption key corresponding to the key identifier from the second key management device 132 in step S123. The second communication device 112 that has acquired the encryption key stores the encryption key in step S131. In step S132, the first communication device 111 and the second communication device 112 perform encrypted communication via the wide area network 14 using the encryption keys that they have each stored.
[0031] As described above, the communication unit 118 of the first communication device 111 receives an encryption key and a key identifier of the encryption key from the key management device 131, which receives the encryption key from the quantum key distribution device 121, via closed network communication, which is communication via the closed network 15 without going through the wide area network 14, and transmits the key identifier to the second communication device 112 connected to the closed network 15, via closed network communication. In addition, the control unit 117 of the first communication device 111 can perform encrypted communication using the encryption key with the second communication device 112 via the wide area network 14. This allows the communication device 11 to receive the encryption key more securely via closed network communication, even if the communication from the quantum key distribution device 121 (122) to the communication device 11 is not quantum encrypted communication. Therefore, even if the encryption key is transmitted from the quantum key distribution device 121 (122) to the communication device 11 without using quantum encrypted communication, more secure encrypted communication can be achieved.
[0032] Furthermore, the communication unit 118 of the second communication device 112 receives a key identifier from the first communication device 111 via closed network communication, which is communication via the closed network 15 without via the wide area network 14, and receives an encryption key corresponding to the key identifier via closed network communication from the key management device 132, which receives an encryption key from the quantum key distribution device 122. Furthermore, the control unit 117 of the second communication device 112 can perform encrypted communication with the first communication device 111 using the encryption key via the wide area network 14. This allows the communication device 11 to receive the encryption key more securely via closed network communication, even if the communication from the quantum key distribution device 121 (122) to the communication device 11 is not quantum encrypted communication. Therefore, more secure encrypted communication can be achieved when transmitting and receiving keys via the quantum key distribution device 121 (122).
[0033] FIG. 4 is a sequence diagram illustrating another example of encrypted communication using the encrypted communication system 1. This sequence diagram illustrates an example in which the first communication device 111 and the second communication device 112 perform encrypted communication using encryption keys stored in each other's nonvolatile storage unit. As shown in this sequence diagram, first, in step S201 before the request to start encrypted communication, the communication unit 118 of the first communication device 111 may transmit a communication inquiry request to the key management device 131 via closed network communication, together with a first device key identifier that is the key identifier of its own encryption key and a second device identifier that is identification information of the second communication device 112. In this case, in step S202, the first key management device 131 may transmit a communication inquiry response to the first communication device 111 together with the second device key identifier that is the key identifier of the second communication device 112. In this case, the first communication device 111 receives the second device key identifier and the communication inquiry response. Here, the first device key identifier, which is the key identifier of the encryption key itself, may be stored in the nonvolatile storage unit together with the encryption key itself.
[0034] Here, if a communication inquiry response is received along with the key identifier of the second communication device 112, it can be interpreted as meaning that the key of the second communication device 112, which is the counterpart communication device, is valid and communication is possible. In this way, the key management device 131 (132) stores the encryption key stored in the non-volatile storage unit of each communication device 11 and can determine whether the encryption key is usable based on the key identifier. Furthermore, the first key management device 131 can transmit a key identifier corresponding to the device identifier by receiving a device identifier that is the identifier of the communication device 11. Here, the key identifier of each communication device can be authentication information such as login information for the key management device 131 (132). This allows the communication device 11 to confirm whether the counterpart communication device is secure based on the information related to the encryption key stored in the key management device 131 (132). Note that the key management device 131 (132) may store a unique management number such as the IMEI (International Mobile Equipment Identity) of each communication device in addition to the key identifier of each communication device, and determine whether a request is from each communication device. Furthermore, when keys of each communication device are managed by an application installed in each communication device, the key management device 131 (132) may determine whether a request is from a legitimate user based on user registration information of the application. Furthermore, the key management device 131 (132) may store the IP address of each communication device and determine whether a request is from each communication device. Furthermore, when each communication device stores an encryption key received from the quantum key distribution device 121 (122) in a non-volatile storage unit, the key management device 131 (132) may determine whether the encryption key or key identifier is received from the quantum key distribution device 121 (122).
[0035] Next, steps S205, S208, and S210 will be described. In step S205, communication unit 118 of first communication device 111 can transmit an encrypted communication start request together with the first device encryption key, which is an encryption key stored in its own nonvolatile storage unit, to second communication device 112 via closed network communication. Meanwhile, in step S205, communication unit 118 of second communication device 112 can receive the encrypted communication start request together with the first device encryption key, which is an encryption key stored in the nonvolatile storage unit of first communication device 111, from first communication device 111 via closed network communication.
[0036] Subsequently, in step S208, the communication unit 118 of the second communication device 112 can transmit an encrypted communication start response together with its own encryption key, which is the encryption key stored in its own nonvolatile storage unit, to the first communication device 111 via closed network communication. Meanwhile, in step S208, the communication unit 118 of the first communication device 111 can receive an encrypted communication start response together with the second device encryption key, which is the encryption key stored in the nonvolatile storage unit of the second communication device 112, from the second communication device 112 via closed network communication.
[0037] The first communication device 111 and the second communication device 112 (their respective control units 117) can use both the first device encryption key and the second device encryption key to perform encrypted communication S210 using the encryption keys via the wide area network 14. As a result, the encryption key stored in advance in the nonvolatile storage unit is delivered to the counterpart communication device via closed network communication, reducing the risk of the key being stolen by eavesdropping or the like, thereby enabling more secure encrypted communication. Here, the encryption key stored in the nonvolatile storage unit may be stored in advance within the device when the communication device 11 is manufactured. Alternatively, the encryption key stored in the nonvolatile storage unit may be stored by a retailer or a delivery store when the communication device 11 is sold or repaired. When the encryption key is stored in advance at the time of manufacture, it may be stored in a nonvolatile storage unit (secure area) whose contents cannot be confirmed by the user of the communication device 11, or in a ROM (Read Only Memory) area that cannot be rewritten. This allows the encryption key to be safely stored in the nonvolatile storage unit.
[0038] Here, the encrypted communication S210 can be performed based on a combination encryption key 25 created by combining the own encryption key 21 and the destination encryption key 22 using a predetermined algorithm. Fig. 5 is a diagram schematically illustrating an example of how the combination encryption key 25 is generated. As shown in this diagram, the combination encryption key 25 used in actual encrypted communication can be generated by combining the own encryption key 21 and the destination encryption key 22, which is obtained through closed network communication and stored in a non-volatile memory unit of the destination communication device, using a predetermined algorithm. The predetermined algorithm may be one in which key character strings are simply concatenated, or one in which predetermined parts of each key are combined, one in which hash values are calculated and combined, or one in which a hash value is calculated for the concatenated character string.
[0039] As a result, even if either the own encryption key 21 or the destination encryption key 22 is stolen or eavesdropped on, it is not possible to generate an encryption key to be used, thereby enabling more secure communication. Furthermore, even if the own encryption key 21 stored in the non-volatile storage unit is removed due to repair, disassembly, etc., the destination encryption key 22 is designed to be used temporarily during encrypted communication and to be stored only in the volatile storage unit, so that the destination encryption key 22 can be erased by turning off the power or ending communication, etc., and the encryption key used in the encrypted communication cannot be reproduced, thereby enabling more secure communication.
[0040] The additional information 23 can also be included in the encrypted communication start response in step S208. In this case, the combined encryption key 25 may be generated by combining the additional information 23 with the local encryption key 21 and the destination encryption key 22. Here, the additional information 23 may be generated by the second communication device 112, for example, as a random character string or a random number. FIG. 6 is a schematic diagram showing another example of how the combined encryption key 25 is generated. As shown in this diagram, the combined encryption key 25 used in actual encrypted communication can be generated by combining the local encryption key 21, the destination encryption key 22, and the additional information 23 transmitted and received in the encrypted communication start response using a predetermined algorithm. The predetermined algorithm may be simply concatenating the character strings of the local encryption key 21, the destination encryption key 22, and the additional information 23, combining predetermined portions of each, calculating hash values of each, or calculating a hash value for the concatenated character string. The additional information 23 may also determine the type of algorithm.
[0041] As a result, even if both the own encryption key 21 and the destination encryption key 22 are stolen or eavesdropped, the encryption key used in the encrypted communication cannot be reproduced because the encryption key is generated by adding the additional information 23 that is temporarily used in communication, thereby enabling more secure communication. Furthermore, even if the own encryption key 21 stored in the non-volatile storage unit is removed due to repair, disassembly, etc., the destination encryption key 22 and the additional information 23 are designed to be used temporarily during the encrypted communication and are stored only in the volatile storage unit, so that the destination encryption key 22 and the additional information 23 can be erased by turning off the power or terminating the communication, etc., and therefore the encryption key used in the encrypted communication cannot be reproduced, enabling more secure communication.
[0042] Returning to FIG. 4, when receiving the encrypted communication start request in step S205, the communication unit 118 of the second communication device 112 may further receive a first device key identifier, which is the key identifier of the first communication device 111. In this case, after receiving the encrypted communication start request, in step S206, a communication inquiry request can be transmitted to the key management device 132 via closed network communication together with the second device key identifier, which is the key identifier of the encryption key of the second communication device 112, and the first device key identifier. In this case, in step S207, a communication inquiry response, which is a response to the communication inquiry request, can be received via closed network communication together with the first device key identifier. Here, if a communication inquiry response is received together with the key identifier of the counterpart communication device, it can be interpreted as meaning that the key of the counterpart communication device is valid and communication is possible (positive response). Furthermore, the second communication device 112 may perform the same processing as the determination processing performed by the first key management device 131 between steps S201 and S202 described above.
[0043] If the communication inquiry response is affirmative, an encrypted communication start response may be transmitted as an affirmative response to the first communication device 111 in step S208. In this way, the key management device 131 (132) may be a device that determines whether an encryption key is available for use based on the key identifier. This allows the communication device 11 to confirm whether the destination communication device is secure based on information about the encryption key stored in the key management device 131 (132). Furthermore, the key management device 131 (132) may be a device that receives an encryption key from the quantum key distribution device 121 (122). As described above, the sequence of encrypted communication using the encrypted communication system 1 shown in FIGS. 4 to 6 enables more secure encrypted communication.
[0044] The encryption key transmitted and received in the above-described embodiment may be a common key or a public key paired with a private key.
[0045] The operational flows and operational examples in the above-described embodiments do not necessarily have to be executed in chronological order according to the order depicted in the flow diagrams or sequence diagrams. For example, steps in the operations may be executed in an order different from that depicted in the flow diagrams or sequence diagrams, or may be executed in parallel. Some steps in the operations may be deleted, or additional steps may be added to the processing. The operational flows and operational examples in the above-described embodiments may be executed independently, or two or more operational flows and operational examples may be combined and executed. For example, some steps in one operational flow may be added to another operational flow, or some steps in one operational flow may be replaced with some steps in another operational flow.
[0046] A program may be provided that causes a computer to execute the operations according to the above-described embodiments. The program may be recorded on a computer-readable medium. The computer-readable medium can be used to install the program on a computer. Here, the computer-readable medium on which the program is recorded may be a non-transitory recording medium. The non-transitory recording medium is not particularly limited, and may be, for example, a recording medium such as a CD-ROM or a DVD-ROM.
[0047] As used in this disclosure, the terms "based on" and "depending on" do not mean "based only on" or "depending only on," unless expressly stated otherwise. The term "based on" means both "based only on" and "based at least in part on." Similarly, the term "depending on" means both "depending only on" and "depending at least in part on." Furthermore, the terms "include," "comprise," and variations thereof do not mean including only the listed items, but may include only the listed items, or may include additional items in addition to the listed items. Furthermore, the term "or" as used in this disclosure is not intended to mean an exclusive or. In this disclosure, when articles are added by translation, such as a, an, and the in English, these articles are intended to include the plural unless the context clearly indicates otherwise.
[0048] The above describes the embodiments in detail with reference to the drawings, but the specific configuration is not limited to that described above, and various design changes can be made within the scope that does not deviate from the gist of the invention.
[0049] The following additional notes are about the features of the above-described embodiment.
[0050] (Appendix 1) a communication unit that receives an encryption key and a key identifier of the encryption key from a key management device that receives the encryption key from a quantum key distribution device by closed network communication, which is communication via a closed network without going through a wide area network, and that transmits the key identifier to a counterpart communication device connected to the closed network by the closed network communication; A communication device comprising: the counterpart communication device; and a control unit that performs encrypted communication using the encryption key via the wide area network.
[0051] (Appendix 2) a communication unit that receives a key identifier from a counterpart communication device through closed network communication, which is communication via a closed network without going through a wide area network, and receives the encryption key corresponding to the key identifier from a key management device that receives an encryption key from a quantum key distribution device through the closed network communication; A communication device comprising: the counterpart communication device; and a control unit that performs encrypted communication using the encryption key via the wide area network.
[0052] (Appendix 3) 3. The communication device according to claim 1, wherein the key management device receives an encryption key from the quantum key distribution device via a dedicated line or the closed network communication.
[0053] (Appendix 4) a communication unit that transmits a cryptographic communication start request to a counterpart communication device, the cryptographic key being a cryptographic key stored in a nonvolatile storage unit of the counterpart communication device, by closed network communication that is communication via a closed network without going through a wide area network, and receives a cryptographic communication start response from the counterpart communication device, the cryptographic key being a counterpart communication device stored in a nonvolatile storage unit of the counterpart communication device, by the closed network communication; A communication device comprising the destination communication device and a control unit that performs encrypted communication using the encryption key via a wide area network.
[0054] (Appendix 5) a communication unit that receives a counterpart encryption key, which is an encryption key stored in a nonvolatile storage unit of the counterpart communication device, as a request to start encrypted communication by closed network communication, which is communication via a closed network without going through a wide area network, and that transmits its own encryption key, which is an encryption key stored in its own nonvolatile storage unit, to the counterpart communication device by the closed network communication as a response to start encrypted communication; A communication device comprising the destination communication device and a control unit that performs encrypted communication using the encryption key via a wide area network.
[0055] (Appendix 6) 6. The communication device according to claim 4, wherein the encrypted communication is performed based on a combined encryption key created by combining the local encryption key and the destination encryption key using a predetermined algorithm.
[0056] (Appendix 7) The encrypted communication start response further includes additional information, 7. The communication device according to claim 6, wherein the combined encryption key is generated by combining the additional information with the local encryption key and the destination encryption key.
[0057] (Appendix 8) The communication unit further before the request to start the encrypted communication, transmitting a key identifier, which is a key identifier of the encryption key, and destination identification information, which is identification information of the destination communication device, as a communication inquiry request to a key management device via the closed network communication; 8. The communication device according to claim 4, wherein the communication device receives a counterpart key identifier that is a key identifier of the counterpart communication device as a communication inquiry response.
[0058] (Appendix 9) The communication unit further When receiving the request to start encrypted communication, a destination key identifier that is a key identifier of the destination communication device is received; After receiving the request to start the encrypted communication, the key management device transmits a communication inquiry request including a key identifier of the encryption key and the destination key identifier via the closed network; receiving the counterpart key identifier as a communication inquiry response that is a response to the communication inquiry request via the closed network communication; The communication device according to any one of appendices 5 to 7, wherein the encrypted communication start response is transmitted to the counterpart communication device as a positive response if the communication inquiry response is positive.
[0059] (Appendix 10) 10. The communication device according to claim 8, wherein the key management device receives an encryption key from a quantum key distribution device.
[0060] (Appendix 11) receiving the encryption key and a key identifier of the encryption key from a key management device that receives the encryption key from the quantum key distribution device through closed network communication, which is communication via a closed network without going through a wide area network; transmitting the key identifier to a destination communication device connected to the closed network via the closed network communication; a cryptographic communication method for performing cryptographic communication with the destination communication device via the wide area network using the cryptographic key;
[0061] (Appendix 12) receiving a key identifier from a counterpart communication device through closed network communication, which is communication via a closed network without going through a wide area network; receiving, via the closed network communication, the encryption key corresponding to the key identifier from a key management device that receives the encryption key from the quantum key distribution device; a cryptographic communication method for performing cryptographic communication with the destination communication device via the wide area network using the cryptographic key;
[0062] (Appendix 13) transmitting a request to start encrypted communication to the other communication device via closed network communication, which is communication via a closed network without going through a wide area network, together with the own encryption key, which is the encryption key stored in the nonvolatile storage unit of the own communication device; receiving, via the closed network communication, from the counterpart communication device, a cryptographic communication start response together with a counterpart encryption key, which is an encryption key stored in a non-volatile storage unit of the counterpart communication device; a cryptographic communication method for performing cryptographic communication with the destination communication device via the wide area network using the cryptographic key;
[0063] (Appendix 14) receiving, from a counterpart communication device, a request to start encrypted communication together with a counterpart encryption key, which is an encryption key stored in a non-volatile storage unit of the counterpart communication device, by closed network communication, which is communication via a closed network without going through a wide area network; transmitting a response to start encrypted communication to the destination communication device via the closed network communication together with its own encryption key, which is the encryption key stored in its own nonvolatile storage unit; a cryptographic communication method for performing cryptographic communication with the destination communication device via the wide area network using the cryptographic key;
[0064] (Appendix 15) receiving an encryption key and a key identifier of the encryption key from a key management device that receives the encryption key from a quantum key distribution device via closed network communication, which is communication via a closed network without going through a wide area network; transmitting the key identifier to a destination communication device connected to the closed network through the closed network communication; a program that causes a computer to execute a step of performing encrypted communication with the destination communication device using the encryption key via the wide area network;
[0065] (Appendix 16) receiving a key identifier from a counterpart communication device through closed network communication, which is communication via a closed network without going through a wide area network; receiving, via the closed network communication, the encryption key corresponding to the key identifier from a key management device that receives the encryption key from the quantum key distribution device; a program that causes a computer to execute a step of performing encrypted communication with the destination communication device using the encryption key via the wide area network;
[0066] (Appendix 17) transmitting a request to start encrypted communication to a counterpart communication device via closed network communication, which is communication via a closed network without via a wide area network, together with the communication device's own encryption key, which is the encryption key stored in the communication device's own nonvolatile storage unit; receiving, from the counterpart communication device via the closed network communication, a response to start encrypted communication together with a counterpart encryption key, which is an encryption key stored in a non-volatile storage unit of the counterpart communication device; a program that causes a computer to execute a step of performing encrypted communication with the destination communication device using the encryption key via the wide area network.
[0067] (Appendix 18) receiving, from a counterpart communication device, a request to start encrypted communication together with a counterpart encryption key, which is an encryption key stored in a non-volatile storage unit of the counterpart communication device, via closed network communication, which is communication via a closed network without going through a wide area network; transmitting a response to start encrypted communication to the destination communication device via the closed network communication together with its own encryption key, which is the encryption key stored in its own nonvolatile storage unit; a program that causes a computer to execute a step of performing encrypted communication with the destination communication device using the encryption key via the wide area network;
[0068] (Appendix 19) A first communication device and a second communication device are provided, The first communication device receiving the encryption key and a key identifier of the encryption key from a first key management device that receives the encryption key from the quantum key distribution device through closed network communication, which is communication via a closed network without going through a wide area network; transmitting the key identifier to the second communication device connected to the closed network via the closed network communication; The second communication device receiving the key identifier from the first communication device through the closed network communication; receiving the encryption key corresponding to the key identifier from a second key management device that receives the encryption key from the quantum key distribution device via the closed network communication; The first communication device and the second communication device perform encrypted communication using the encryption key via the wide area network.
[0069] (Appendix 20) A first communication device and a second communication device are provided, The first communication device transmitting a request to start encrypted communication to the second communication device together with a first encryption key, which is an encryption key stored in the nonvolatile storage unit of the second communication device, via closed network communication, which is communication via a closed network without going through a wide area network; receiving, via the closed network communication, from the second communication device, a response to start encrypted communication together with a second encryption key, which is an encryption key stored in a nonvolatile storage unit of the second communication device; The second communication device receiving, via the closed network communication, from the first communication device, the request to start encrypted communication together with the first encryption key, which is an encryption key stored in a non-volatile storage unit of the first communication device; transmitting the encrypted communication start response to the first communication device via the closed network communication together with the second encryption key, which is an encryption key stored in the nonvolatile storage unit of the first communication device; The first communication device and the second communication device perform encrypted communication using an encryption key via the wide area network. [Explanation of symbols]
[0070] 1. Encrypted communication system 11. Communications equipment 117 Control Unit 118 Communications Department 119 Memory section 111 First communication device (communication device) 112 Second communication device (communication device) 121 First quantum key distribution device (quantum key distribution device) 122 Second quantum key distribution device (quantum key distribution device) 131 1st key management device (key management device) 132 2nd key management device (key management device) 14 Wide area network (Internet network) 15 Closed network (mobile communication network) 151 Exchange 152 Base Station 153 Gateway
Claims
1. a communication unit that receives an encryption key and a key identifier of the encryption key from a key management device that receives the encryption key from a quantum key distribution device by closed network communication, which is communication via a closed network without going through a wide area network, and that transmits the key identifier to a counterpart communication device connected to the closed network by the closed network communication; A communication device comprising: the counterpart communication device; and a control unit that performs encrypted communication using the encryption key via the wide area network.
2. a communication unit that receives a key identifier from a counterpart communication device through closed network communication, which is communication via a closed network without going through a wide area network, and receives the encryption key corresponding to the key identifier from a key management device that receives an encryption key from a quantum key distribution device through the closed network communication; A communication device comprising: the counterpart communication device; and a control unit that performs encrypted communication using the encryption key via the wide area network.
3. The communication device according to claim 1 , wherein the key management device receives the encryption key from the quantum key distribution device via a dedicated line or the closed network communication.
4. a communication unit that transmits a cryptographic communication start request to a counterpart communication device, the cryptographic key being a cryptographic key stored in a nonvolatile storage unit of the counterpart communication device, by closed network communication that is communication via a closed network without going through a wide area network, and receives a cryptographic communication start response from the counterpart communication device, the cryptographic key being a counterpart communication device stored in a nonvolatile storage unit of the counterpart communication device, by the closed network communication; A communication device comprising the destination communication device and a control unit that performs encrypted communication using the encryption key via a wide area network.
5. a communication unit that receives a counterpart encryption key, which is an encryption key stored in a nonvolatile storage unit of the counterpart communication device, as a request to start encrypted communication by closed network communication, which is communication via a closed network without going through a wide area network, and that transmits its own encryption key, which is an encryption key stored in its own nonvolatile storage unit, to the counterpart communication device by the closed network communication as a response to start encrypted communication; A communication device comprising the destination communication device and a control unit that performs encrypted communication using the encryption key via a wide area network.
6. 6. The communication device according to claim 4, wherein the encrypted communication is performed based on a combined encryption key created by combining the local encryption key and the destination encryption key using a predetermined algorithm.
7. The encrypted communication start response further includes additional information, 7. The communication device according to claim 6, wherein the combination encryption key is generated by combining the additional information in addition to the local encryption key and the destination encryption key.
8. The communication unit further before the request to start the encrypted communication, transmitting a key identifier, which is a key identifier of the encryption key, and destination identification information, which is identification information of the destination communication device, as a communication inquiry request to a key management device via the closed network communication; The communication device according to claim 4 , wherein the communication device receives a destination key identifier that is a key identifier of the destination communication device as a communication inquiry response.
9. The communication unit further When receiving the request to start encrypted communication, a destination key identifier that is a key identifier of the destination communication device is received; After receiving the request to start the encrypted communication, the key management device transmits a communication inquiry request including a key identifier of the encryption key and the destination key identifier via the closed network; receiving the counterpart key identifier as a communication inquiry response that is a response to the communication inquiry request via the closed network communication; The communication device according to claim 5 , wherein the encrypted communication start response is transmitted to the counterpart communication device as an affirmative response when the communication inquiry response is affirmative.
10. The communication device according to claim 8 , wherein the key management device receives an encryption key from a quantum key distribution device.
11. receiving the encryption key and a key identifier of the encryption key from a key management device that receives the encryption key from the quantum key distribution device through closed network communication, which is communication via a closed network without going through a wide area network; transmitting the key identifier to a destination communication device connected to the closed network via the closed network communication; a cryptographic communication method for performing cryptographic communication with the destination communication device via the wide area network using the cryptographic key;
12. receiving a key identifier from a counterpart communication device through closed network communication, which is communication via a closed network without going through a wide area network; receiving, via the closed network communication, the encryption key corresponding to the key identifier from a key management device that receives the encryption key from the quantum key distribution device; a cryptographic communication method for performing cryptographic communication with the destination communication device via the wide area network using the cryptographic key;
13. transmitting a request to start encrypted communication to the other communication device via closed network communication, which is communication via a closed network without going through a wide area network, together with the own encryption key, which is the encryption key stored in the nonvolatile storage unit of the own communication device; receiving, via the closed network communication, from the counterpart communication device, a cryptographic communication start response together with a counterpart encryption key, which is an encryption key stored in a non-volatile storage unit of the counterpart communication device; a cryptographic communication method for performing cryptographic communication with the destination communication device via the wide area network using the cryptographic key;
14. receiving, from a counterpart communication device, a request to start encrypted communication together with a counterpart encryption key, which is an encryption key stored in a non-volatile storage unit of the counterpart communication device, by closed network communication, which is communication via a closed network without going through a wide area network; transmitting a response to start encrypted communication to the destination communication device via the closed network communication together with its own encryption key, which is the encryption key stored in its own nonvolatile storage unit; a cryptographic communication method for performing cryptographic communication with the destination communication device via the wide area network using the cryptographic key;
15. receiving an encryption key and a key identifier of the encryption key from a key management device that receives the encryption key from a quantum key distribution device via closed network communication, which is communication via a closed network without going through a wide area network; transmitting the key identifier to a destination communication device connected to the closed network through the closed network communication; a program that causes a computer to execute a step of performing encrypted communication with the destination communication device using the encryption key via the wide area network;
16. receiving a key identifier from a counterpart communication device through closed network communication, which is communication via a closed network without going through a wide area network; receiving, via the closed network communication, the encryption key corresponding to the key identifier from a key management device that receives the encryption key from the quantum key distribution device; a program that causes a computer to execute a step of performing encrypted communication with the destination communication device using the encryption key via the wide area network;
17. transmitting a request to start encrypted communication to a counterpart communication device via closed network communication, which is communication via a closed network without via a wide area network, together with the counterpart communication device's own encryption key, which is the encryption key stored in the counterpart communication device's own nonvolatile storage unit; receiving, from the counterpart communication device via the closed network communication, a response to start encrypted communication together with a counterpart encryption key, which is an encryption key stored in a non-volatile storage unit of the counterpart communication device; a program that causes a computer to execute a step of performing encrypted communication with the destination communication device using the encryption key via the wide area network.
18. receiving, from a counterpart communication device, a request to start encrypted communication together with a counterpart encryption key, which is an encryption key stored in a non-volatile storage unit of the counterpart communication device, via closed network communication, which is communication via a closed network without going through a wide area network; transmitting a response to start encrypted communication to the destination communication device via the closed network communication together with its own encryption key, which is the encryption key stored in its own nonvolatile storage unit; a program that causes a computer to execute a step of performing encrypted communication with the destination communication device using the encryption key via the wide area network;
19. a first communication device and a second communication device; The first communication device receiving the encryption key and a key identifier of the encryption key from a first key management device that receives the encryption key from the quantum key distribution device through closed network communication, which is communication via a closed network without going through a wide area network; transmitting the key identifier to the second communication device connected to the closed network through the closed network communication; the second communication device, receiving the key identifier from the first communication device through the closed network communication; receiving the encryption key corresponding to the key identifier from a second key management device that receives the encryption key from the quantum key distribution device via the closed network communication; The first communication device and the second communication device perform encrypted communication using the encryption key via the wide area network.
20. a first communication device and a second communication device; The first communication device transmitting a request to start encrypted communication to the second communication device together with a first encryption key, which is an encryption key stored in the nonvolatile storage unit of the second communication device, via closed network communication, which is communication via a closed network without going through a wide area network; receiving, via the closed network communication, from the second communication device, a response to start encrypted communication together with a second encryption key, which is an encryption key stored in a nonvolatile storage unit of the second communication device; the second communication device, receiving, from the first communication device via the closed network communication, the request to start encrypted communication together with the first encryption key, which is an encryption key stored in a non-volatile storage unit of the first communication device; transmitting the encrypted communication start response to the first communication device via the closed network communication together with the second encryption key, which is an encryption key stored in the nonvolatile storage unit of the first communication device; The first communication device and the second communication device perform encrypted communication using an encryption key via the wide area network.
Citation Information
Patent Citations
Transfer device, key management server device, communication system, transfer method, and program
JP2022075398A