System and method for secure communication based on network coding
The integration of MRD encoding and OTP encryption in a communication network control device addresses limitations in secure network coding and quantum cryptography, enhancing network reliability and confidentiality.
Patent Information
- Application Number
- JP2022010959
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-01-27
- Publication Date
- 2025-12-18
- Estimated Expiration
- 2042-01-27
AI Technical Summary
Existing secure network coding and quantum cryptography communication networks face limitations due to unrealistic eavesdropping assumptions, high encryption costs, and limited key generation speeds, leading to reduced application areas and network reliability.
A control device for a communication network that integrates MRD encoding and OTP encryption to manage eavesdropping, errors, and tampering, using a control device with instruction units for encoding and encryption, ensuring efficient and secure communication.
Maintains high confidentiality and reliability in networks with eavesdropping, errors, and tampering by integrating MRD codes and OTP encryption, ensuring efficient and secure communication.
Smart Images

Figure 0007788104000076 
Figure 0007788104000077 
Figure 0007788104000078
Abstract
Description
[Technical Field]
[0001] The present invention relates to a system and method for secure communications based on network coding. [Background technology]
[0002] Advances in cloud services and high-speed mobile communications technology are driving a rapid increase in Internet traffic. While network facilities, including high-capacity optical fiber, are being strengthened, the number of devices and new services and applications are expected to continue to increase. As a result, strengthening infrastructure at the current rate will no longer be enough, and communication methods themselves must be made more efficient. Furthermore, with the amount of highly confidential information increasing, there is an increasing demand for information security. In addition to improving communication efficiency, there is also a need for mechanisms to prevent information leaks to third parties other than authorized users and unauthorized data tampering.
[0003] Network coding, which combines multiple pieces of information collected at a relay node, converts them into a different form (encodes them), and then transmits them, is a well-known method for efficiently performing multicast communication over a network. Network coding is beginning to be put into practical use as a new technology to support the rapid increase in communication traffic. Furthermore, as a method for ensuring the security of communications, research and development of a technology called secure network coding (Non-Patent Documents 1 and 2) that combines network coding with secrecy using random numbers is also progressing. Furthermore, quantum key distribution (QKD) and quantum cryptography, which uses a QKD key as a one-time pad, are methods for achieving completely secure communication using the principles of quantum mechanics (Non-Patent Documents 3 to 5), and these methods are beginning to be put into practical use. [Prior art documents] [Non-patent literature]
[0004] [Non-Patent Document 1] D. Silva and F. R. Kschischang, “Universal secure network coding via rank-metric codes,” IEEE Trans. Inf. Theory, vol. 57, no.2, pp.1124-1135 (2011). [Non-Patent Document 2] H. Yao, D. Silva, S. Jaggi, and M. Langberg, “Network Codes Resilient to Jamming and Eavesdropping,” IEEE / ACM Trans. Networking, vol. 22, no. 6, pp.1978-1987 (2014). [Non-Patent Document 3] M. Peev, et al., New J. Phys. 11, 075001, 2009. [Non-Patent Document 4] M. Sasaki, et al., Opt. Express 19, pp. 10387-10409, 2011. [Non-Patent Document 5] Y. L. Tang, et al., Phys. Rev. X 6(1) 011024, 2016. [Summary of the Invention] [Problems to be Solved by the Invention]
[0005] Secure Network Coding requires the assumption that the total number of eavesdropped links within the network area from the source node to the terminal node is below a certain threshold. This assumption is reasonable in a multi-point, wide-area network. In fact, assuming that all links are under the control of an eavesdropper is unrealistic and would unnecessarily increase the encryption cost. However, increasing the number of multicast nodes or the degree of decentralization (e.g., the code length n of the MRD code) to enhance error resilience and tamper resistance in Secure Network Coding increases the risk of tapping, which makes the threshold assumption unsatisfied and inevitably narrows the application area.
[0006] In quantum cryptography communication networks, there is a limit to the key generation speed of each individual QKD link system, which means that as the amount of data to be communicated increases, the encryption keys used for OTP encryption tend to run out. Because OTP encryption is used not only for cryptographic applications on the service layer but also for key relay on the key management layer of the quantum key distribution network (QKDN), this problem is a major factor limiting the use of quantum cryptography communication networks. Furthermore, in secure multicast communications between multiple points, group keys must be shared by properly managing true random numbers within each node, replicating them, and relaying them. However, if an error or tampering occurs in any link or node during this process, the impact propagates throughout the network, causing a rapid degradation of reliability.
[0007] The present invention has been made in view of the above circumstances, and has as its object to communicate information efficiently while maintaining high confidentiality over a network where eavesdropping, errors, and tampering occur. [Means for solving the problem]
[0008] To achieve the above object, one embodiment provides a control device for a communication network having a plurality of nodes and links connecting two of the nodes, the control device comprising: a first instruction unit that instructs a source node of the plurality of nodes whether or not the source node should perform MRD encoding when transmitting data from the source node; a random number transmission unit that, when instructed by the first instruction unit to perform MRD encoding, transmits to the source node a random number corresponding to the maximum number of links that may be susceptible to eavesdropping; and a second instruction unit that instructs each of the plurality of nodes whether or not the node should perform OTP encryption when transmitting data to another node. [Effects of the Invention]
[0009] According to the present invention, information can be efficiently communicated while maintaining high confidentiality over a network where eavesdropping, errors, and tampering occur. [Brief explanation of the drawings]
[0010] [Figure 1] FIG. 1 is an explanatory diagram of network coding and secure network coding. [Figure 2] FIG. 1 is an explanatory diagram showing a quantum cryptography communication network. [Figure 3] FIG. 1 is an explanatory diagram showing the basic process of key relay. [Figure 4] 1 is an explanatory diagram showing a quantum cryptography communication network that applies new highly secure network coding that combines MRD codes and OTP encryption. [Figure 5] FIG. 1 is an explanatory diagram showing the storage status of encryption keys on a multipoint network. [Figure 6] FIG. 1 is an explanatory diagram showing a communication channel model of secure network coding using MRD codes and sub-MRD codes. [Figure 7] FIG. 1 is an explanatory diagram showing an example of a network configuration of an advanced distributed key relay system. [Figure 8] FIG. 2 is a block diagram of a control device of a communication network. [Figure 9]FIG. 2 is an explanatory diagram illustrating an example of a computer hardware configuration of a node. DETAILED DESCRIPTION OF THE INVENTION
[0011] The present invention will be described below based on the illustrated embodiments, but the present invention is not limited to the embodiments described below.
[0012] First, the inventors of the present invention have conducted extensive research into network coding, secure network coding, and quantum cryptography communication networks, as described below.
[0013] [1 Network Coding and Secure Network Coding] It has long been known that the amount of information that can be transmitted between any two nodes on a network within a given time is determined by the minimum cut capacity of the network's directed graph model (C.E. Shannon, "A Note on the Maximum Flow Through a Network," 1956). However, the maximum capacity in multicast communication could not be achieved with the store-and-forward method used by conventional relay nodes, which receives information, determines the route to the destination one by one in the order it arrives, and then forwards (routes) it to the next relay node. In 2000, R. Ahlswede et al. proposed the concept of network coding, demonstrating that the maximum capacity of a network can be achieved by combining multiple pieces of information collected at relay nodes, converting them into different information (encoding) and then forwarding them. In 2003, SYRLi et al. demonstrated that the maximum capacity of a network can be achieved. Meanwhile, the currently standard methods for ensuring the security of network communications are authentication and key exchange using public key cryptography, and encryption of data communications using symmetric key cryptography. These cryptographic techniques use difficult mathematical problems to make it necessary for a third party who does not know the cryptographic key to perform an enormous amount of calculation to decipher the original information from the ciphertext, effectively preventing eavesdropping and tampering. However, as the risk of deciphering increases with advances in computing technology, it is necessary to periodically extend the length of the cryptographic key and update the cryptographic method. In contrast, there are known methods that guarantee security that cannot be decrypted by any computer (information-theoretic security). These cryptographic methods based on information-theoretic security can, in principle, guarantee security for an extremely long period of time without updating the cryptographic specifications. One example of a cryptographic method based on information-theoretic security is a technique called secure network coding, which incorporates true random number randomization into network coding. In this method, information is transmitted from one node (sender: source node) on the network to another node (receiver: terminal node) via multiple relay nodes. The source node and relay nodes are equipped with a true random number source and an encoding device, which generate the necessary true random numbers and perform appropriate encoding. The source node generally has multiple output links, and information is distributed and transmitted over these links. In multicast communication, there are multiple terminal nodes. A terminal node has multiple input links, and decryption is performed after the necessary information is collected from the relay nodes. Specific code construction methods for secure network coding, such as a method based on maximum rank distance code (MRD code), are known.
[0014] Figure 1 shows an overview of network coding and secure network coding. Network NW1 is represented by multiple nodes and a set of links (also called edges) connecting two nodes. Here, each node is represented by a unique index, and each link is represented by a pair of two node indexes at its end points. For example, the link connecting source node s and relay node s1 is represented as link (s, s1), and the message flowing through this link (s, s1) is represented as x(s, s1).
[0015] A source node s receives m input messages u0,u1,...,u m-1 Let us consider n output messages x(s,s1), x(s,s2),..., x(s,s n ) and the first relay nodes s1, s2,..., s n A variety of uses are expected, such as sending a message from a source node to one terminal node or multicasting a message to multiple terminal nodes.
[0016] In the network NW1, the message is encoded through multiple relay nodes depending on the purpose, and then transmitted to the terminal node t. In general, a relay node v receives multiple messages x(v1, v), x(v2, v), ..., x(v I ,v) is converted into messages x(v,v1´),x(v,v2´),...,x(v,v O ').
number
[0017] However, the matrix R (v) is a linear network code matrix. Equations (1) and (2) can also be expressed as follows:
number
[0018] In this way, messages x(v,v1´),x(v,v2´),...,x(v,v O ′) are linear network code matrices R (v) and multiple messages x(v1,v),x(v2,v),...,x(v I ,v) and is expressed as a linear combination of The relay node v receives the messages x(v,v1´), x(v,v2´),..., x(v,v O ′) to the next nodes v1′, v2′,..., v O Send to ´. The same process as that of relay node v is performed on relay nodes s1, s2,..., s n and relay nodes v1, v2,..., v I and relay nodes v1´,v2´,...,v o ´ and relay nodes t1, t2,..., t l This is also done in the Finally, terminal node t receives l messages x(t1,t), x(t2,t),..., x(t l ,t) and receives m messages u0,u1,...,u from source node s. m-1 Decrypt the
[0019] [2 Quantum cryptography communication network] Another method that guarantees information-theoretic security is quantum cryptography, which uses a shared encryption key via quantum key distribution to encrypt data communications using a one-time pad (OTP) method. Quantum Key Distribution (QKD) is a method in which a common true random number sequence (let's say K) with information-theoretic security is shared as an encryption key between two distant points connected by an optical fiber line. Encryption is performed by logically ORing the message to be sent (let's say U) with an encryption key K of the same size as the message U.
number
number
[0020] The key generation speed of a pair of QKD link systems connecting two points decreases as the transmission distance increases, and with conventional optical fiber installations, it is only a few hundred kbps over 50 km and a few kbps over 100 km. Therefore, by installing multiple "trusted nodes" at intervals of 50 to 60 km and connecting the QKD devices (QKD modules) within each trusted node, a wide-area network called a Quantum Key Distribution Network (QKDN) can be obtained. Each trusted node is equipped with a key management device (Key Manager, KM) separate from the QKD module, which transfers and stores the encryption keys generated by the QKD module to the KM. KMs are connected to each other via classical circuits (KM links), and manage and operate the encryption keys, including performing capsule relay of encryption keys when necessary. The cryptographic keys shared in this way can be used for various cryptographic applications existing in existing communication networks and cryptographic infrastructures (user networks in Figure 2, which will be described later), such as providing keys to applications such as one-time pad (OTP)-based completely confidential communications, symmetric key cryptography, and secret sharing storage. Functional elements called the QKDN controller and QKDN manager have been introduced to control the route of the capsule relay of cryptographic keys and manage the entire QKDN. A network that includes the QKDN and user networks on which cryptographic applications are executed is called a quantum cryptography communication network.
[0021] 2 shows a conceptual structure of a quantum cryptography communication network NW2. The quantum cryptography communication network NW2 includes a quantum key distribution network QKDN2 and a user network UN2. The quantum key distribution network QKDN2 includes multiple trusted nodes TN and four function layers L1 to L4.
[0022] The quantum layer L1 is a set of QKD links connected via QKD modules QM in each trusted node. A QKD link is a one-to-one link. A QKD link connects one QKD module in a trusted node to one QKD module in another trusted node. Each QKD link generates its own encryption key. The generated encryption key is sent to the key manager KM in the trusted node for management and operation.
[0023] The key management layer L2 has a key manager KM in each trusted node and KM links connecting the key managers KM. The key manager KM stores the encryption keys generated in the quantum layer L1 and shares them between the required ends through key capsule relay using OTP encryption. The key manager KM is responsible for overall key management, including supplying encryption keys to cryptographic applications on the user network UN2.
[0024] Figure 3 shows the basic process of key capsule relay using OTP encryption. Key manager A and key manager C are connected, and key manager C and key manager B are connected. Key managers A and C have encryption key K1 (a pair of secret random number sequences shared by both nodes by QKD, so-called symmetric keys) generated by the corresponding QKD module. Key managers C and B have encryption key K2 generated by the corresponding QKD module. Key manager A sends encryption key K1 to key manager C. Key manager C performs an exclusive OR operation on encryption key K1 and encryption key K2 received from key manager A.
number
[0025] The QKDN control layer L3 has one or more QKDN controllers CT that control the overall QKDN services. The QKDN management layer L4 has a QKDN manager MG1. The QKDN manager MG has the function of collecting performance information from each of the layers L1 to L3, monitoring whether the service is operating properly, and issuing control commands to the QKDN control layer L3 as necessary.
[0026] The user network UN2 has a service layer L5, which is a functional layer where multiple user terminals UD exist, and a user network management layer L6. The multiple user terminals UD in the service layer L5 perform encrypted communication using keys and encryption applications provided by corresponding key managers KM. The network manager MG2 in the user network management layer L6 communicates with the QKDN manager MG1 and manages the user terminals UD.
[0027] [3 One embodiment of the present invention] [3.1 New highly secure network coding combining MRD code and OTP encryption] Based on the above considerations, one embodiment of the present invention relates to a new highly secure network coding that combines MRD codes and OTP encryption to compensate for the shortcomings of conventional secure network coding and quantum cryptography communication networks and synergize the advantages of both. This embodiment enables highly efficient information communication without sacrificing reliability and maintaining high confidentiality over a network where eavesdropping, errors, and tampering occur.
[0028] 4 shows a quantum cryptography communication network NW3 in which communication is performed using highly secure network coding according to this embodiment. This quantum cryptography communication network NW3 includes a quantum key distribution network QKDN3 and a user network UN3. The quantum key distribution network QKDN3, like the quantum key distribution network QKDN2, has a plurality of trusted nodes TN, as well as a quantum layer, a key management layer, a QKDN control layer, and a QKDN management layer. Like the user network UN2, the user network UN3 has a service layer, which is a functional layer where multiple user terminals UD exist, and a user network management layer. Note that the user network management layer is not shown in FIG.
[0029] A new highly secure network coding scheme combining MRD code and OTP encryption is introduced to the service layer of the user network UN3 and the key management layer of the quantum key distribution network QKDN3. The combination of MRD code and OTP encryption and the MRD code specifications are appropriately controlled according to the cryptographic key storage status at each node of the quantum key distribution network QKDN3 and the cryptographic key requirements at the service layer of the user network UN3, improving confidentiality and reliability in a balanced manner on the network. Here, OTP encryption is performed using a cryptographic key generated by QKD.
[0030] As an example of a multipoint network pattern to which highly secure network coding is applied, consider the multicast communication shown in Figure 5. In the multipoint network pattern NW4, two source nodes s 11 and s 12 message packets u1 and u2 are sent to the relay node v 11 ~v 14 , v 21 ~v 25 , v 31 ~v 34 , v 41 ~v 45 and v 51 ~v 55through some of the four terminal nodes t 11 , t 12 , t 13 and t 14 The multipoint network pattern in this figure applies to the service layer of the user network UN3 as well as the key management layer of the quantum key distribution network QKDN3. In the latter case, message packets u1 and u2 correspond to encryption keys (group keys). The solid and dotted lines in Figure 5 represent links connecting two nodes. A solid line represents a link where a pair of encryption keys required for OTP encryption can be prepared, while a dotted line represents a link where there are not enough encryption keys. Note that a link is created using a pair of nodes at both ends, for example, (v 11 , v 12 ) is written as follows.
[0031] In such a situation, secure multicast becomes impossible until enough encryption keys are accumulated on the dotted line link, and the QKD link system, which has a relatively slow key generation speed, becomes a major constraint on the communication function of the entire network.In such a case, the following effects can be obtained by performing secure network coding based on the MRD code at each source node. (1) Even if OTP encryption cannot be performed on some links, it is possible to perform secret communication with information-theoretic security over the entire network. (2) The rank error correction capability of the MRD code can be used to improve the error propagation tolerance. (3) By encrypting OTP on many, but not all, links, it becomes easier to guarantee the threshold assumption that MRD codes must satisfy. (4) It is possible to improve confidentiality, reliability, and ultimately availability in a balanced manner while efficiently using cryptographic keys throughout the network.
[0032] In the integrated operation of secure network coding using MRD codes and quantum cryptography communication networks using OTP encryption, the QKDN controller, key manager, and cryptographic application work closely together to appropriately adjust the specifications of secure network coding based on MRD codes according to the consumption of cryptographic keys in the cryptographic application and KM, and the accumulation of cryptographic keys in KM, thereby enabling even more optimal control of confidentiality and reliability.
[0033] [3.1.1 Basic Requirements and Definitions] In this embodiment, new highly secure network coding is realized by integrating the following functions used in secure network coding. (i) The disruptive effect of introducing appropriate randomness into nodes (ii) Ability to correct any unauthorized tampering or errors in messages (iii) The following features of QKDN: - Information-theoretically secure encryption key generation function -Relay delivery function for the above encryption keys - Encryption key storage, management, and operation functions -QKDN control function according to the above circumstances
[0034] Additionally, the following terms are defined: 1) The node that is the starting point of a relay is called the source node, and the node that is the end point is called the terminal node. The source node and the terminal node are generally not connected via a single route, but via a distributed network via multiple nodes and links. 2) Information to be sent from a source node to a terminal node is called a message below. In the key management layer, an encryption key is considered to be a message. 3) The source node adds "random number information to confuse eavesdroppers" and "check information for error correction and tamper detection" to the message and performs secure network coding to distribute and transmit it over multiple links. The message, random number information, and check information are sequences consisting of symbols over a polynomial finite field GF(q) (q is the number of elements and is a power of a prime number greater than or equal to 2). 4) A set of sequences (message, random number information, and inspection information) transmitted on each link is called a packet below. The size of the packet (sequence length) is denoted as N.
[0035] A network topology that is resistant to eavesdropping and tampering should have as large a number of relay nodes as possible, for example, n=4 in Figure 5.
[0036] [3.1.2 Basic parameters and code structure overview] Figure 6 shows a channel model for secure network coding using MRD codes and sub-MRD codes.
[0037] Note that OTP encryption (step ST2 in FIG. 6) is not performed on all links. As mentioned above, OTP encryption is not performed on links (e.g., dotted lines in FIG. 5) that do not have the encryption key (pair of symmetric secret random number sequences) required for OTP encryption. Details are provided below. As mentioned above, the output from a node v is represented by a linear combination of the elements of the linear network coding matrix and the packets on the input links to the node.
number
number
[0038] The attack and compromise models, as well as the basic parameters N, n, μ, τ, ρ, m, l and variables related to secure network coding are described below. 1) Let n be the number of relay nodes through which data must be sent in distributed relay delivery. 2) An eavesdropper can eavesdrop on μ packets (step ST3 in Figure 6) and generate τ error packets.
number
number
number
number
number
number
number
number
number
number
[0039] 5) The source node generates μ random packets (each packet has length N) to confuse eavesdroppers, and sends them to the given m message packets.
number
number
number
number
number
number
number
number
number
number
[0040] The generator matrix is given in the following form:
number
[0041] [Encoding procedure] As shown in step ST1 of FIG. 6, a given message packet
number
number
number
number
number
number
number
[0042] 6) How to achieve confidentiality and integrity
number
[0043] 7) In step ST7 of FIG. 6, the terminal node selects l packets from the links that pass through the relay node.
number
number
number
[0044] 7) An eavesdropper can receive μ packets from any location on the network.
number
number
number
[0045] [3.1.3 Decryption Process] Decryption (step ST7 in FIG. 6) is performed in the following process. 1) The terminal node collects a vector y consisting of l packets and decodes the secure network code to estimate the message x sent from the source node. As shown in equation (11), l packets are
number
number
number
[0046] 2) The estimated x' is decoded using the MRD code to obtain u and v. As can be seen from equation (8), x is a codeword of the MRD code, and the given message packet
number
number
number
[0047] The error vector e can be decomposed as follows:
number
[0048] Step 1: Calculate the syndrome from x' and the check matrix H. Syndrome
number
number
[0049] Step 2: Using the Berlekamp-Massey method, syndrome Sl Calculate the coefficient γ of the Error Locator Polynomial (ELP) and the estimated rank error number τ from the following equation. The ELP is expressed as follows:
number
[0050] Step 3: Use Gaussian elimination to find the root (d) of ELP. Solve the following equation for x to find d.
number
[0051] Step 4: Calculate the error coefficient Θ from d. Θ can be calculated from d using the following relationship:
number
[0052] Step 5: Calculate the error span a from d. a can be calculated from d using the following equation:
number
[0053] Step 6: Estimate the error vector from the error span a and the error coefficient Θ.
number
[0054] Step 7: The estimated codeword is obtained by subtracting the estimated error vector from x'.
number
[0055] Step 8: The message u is obtained from the estimated code word. u and v are separated using the following equation.
number
[0056] The source node performs step ST1 (confidentiality and error correction coding) in Fig. 6. That is, in step ST1, the source node generates a message x using a message packet u, a random number v, and a generator matrix G, and then divides the message x into multiple messages. Next, the source node performs OTP encryption (step ST2) on the multiple messages, and either transmits each OTP-encrypted message to each relay node adjacent to the source node, or transmits the multiple messages as is to each relay node without OTP encryption. The relay node receives messages from each of the multiple nodes connected via input links. If the received message is OTP encrypted, the relay node performs OTP decryption (step ST5). The message after OTP decryption is a linear combination processing message used in the subsequent linear combination processing. If the received message is not OTP encrypted, the received message itself is a linear combination processing message used in the subsequent linear combination processing. The relay node further performs linear combination processing using elements of the linear network code matrix and the above-mentioned linear combination processing message. The terminal node receives messages from each of multiple relay nodes connected via input links. If the received message is OTP encrypted, the terminal node performs OTP decryption (step ST5). The message after OTP decryption is a message for calculation used in the calculation in the subsequent step ST6. If the received message is not OTP encrypted, the received message itself is a message for calculation used in the calculation in the subsequent step ST6. The terminal node then performs the calculation in step ST6 using the message for calculation. The terminal node further performs error correction decoding and decryption (step ST7) on the calculation result obtained in step ST6.
[0057] The above process makes it possible to correct rank errors introduced on the network. Furthermore, due to the effect of the random number packet v, information-theoretic security is maintained even if packets are eavesdropped on links below a threshold (the threshold depends on the number of random number packets v). This means that even if OTP encryption cannot be performed on some links, secret communication can be performed with information-theoretic security maintained throughout the network.
[0058] [4 Usage examples] The field GF(q N ) can be applied to highly distributed key relay subsystems using secure network coding. Assume the packet size is 64 bits. If q=16, then N=16. Also, consider a network configuration in which the transmitted message is distributed into four, as shown in Figure 7. In this case, n=4.
[0059] In the communication network NW5 shown in Fig. 7, relay nodes s0 to s3 are connected to a source node s by links. Furthermore, relay nodes v0 to v3 are connected to each of the relay nodes s0 to s3 by links. In addition, terminal nodes t0 to t3 are connected to each of the relay nodes v0 to v3 by links.
[0060] The "[1]" shown above each of the relay nodes s0 to s3 means that the coefficient of the linear combination is "1." In other words, the relay node s0 transmits the packet x0 received from the source node s to the relay nodes v0 to v3. Similarly, the relay node s1 transmits the packet x1 received from the source node s to the relay nodes v0 to v3, the relay node s2 transmits the packet x2 received from the source node s to the relay nodes v0 to v3, and the relay node s3 transmits the packet x3 received from the source node s to the relay nodes v0 to v3.
[0061] Each of the relay nodes v0 to v3 receives packet x0 from relay node s0, packet x1 from relay node s1, packet x2 from relay node s2, and packet x3 from relay node s3.
[0062] Next, the relay node v0 calculates the element A of the linear network code matrix. 00 , A 01 , A 02 and A 03 and the received packets x0 to x3. That is, the relay node v0 performs the following calculation to obtain packet y0. y0=A 00 *x0+A 01 *x1+A 02 *x2+A 03 *x3 The relay node v0 transmits a packet y0 to each of the terminal nodes t0 to t3.
[0063] The relay nodes v1 to v3 also perform linear combination processing using the elements of the linear network code matrix and the received packets x0 to x3. 10 , A 11 , A 12 and A 13 The relay node v2 uses the linear network code matrix element A 20 , A 21 , A 22 and A 23 The relay node v3 uses the linear network code matrix element A 30 , A 31 , A 32 and A 33 The relay nodes v1 to v3 obtain packets y1 to y3 by linear combination processing, respectively. The relay node v1 transmits packet y1 to each of the terminal nodes t0 to t3, the relay node v2 transmits packet y2 to each of the terminal nodes t0 to t3, and the relay node v3 transmits packet y3 to each of the terminal nodes t0 to t3.
[0064] [A 00 A01 A 02 A 03 ] and [A 10 A 11 A 12 A 13 ] and [A 20 A 21 A 22 A 23 ] and [A 30 A 31 A 32 A 33 ] is the linear network code matrix in this example. The elements of the linear network code matrix are often generated so that the matrix is a full-rank matrix, but generally they can be generated randomly.
[0065] Each of the terminal nodes t0 to t3 receives a packet y0 from the relay node v0, a packet y1 from the relay node v1, a packet y2 from the relay node v2, and a packet y3 from the relay node v3. Subsequently, each of the terminal nodes t0 to t3 calculates an inverse matrix A of the linear network coding matrix A. -1 and a vector consisting of received packets y0 to y3 to obtain the original messages x0 to x3.
[0066] As the Gabidulin code to be applied to this network, a code with a code length of 4 and 2 information symbols is considered. Of the 2 information symbols, the number of messages sent from source node s is m=1 and the number of random number packets is μ=1. Parity is added to the 2 information symbols to obtain a codeword with n=4. The codeword consists of four messages x0 to x3, and these four messages are distributed and transmitted to relay nodes s0 to s3, respectively. Then, linear combinations are performed at each relay node, and the message finally reaches terminal nodes t0 to t3. In this way, the message transmitted from source node s is transmitted to terminal nodes t0 to t3 via relay nodes s0 to s3 and relay nodes v0 to v3. In this Gabidulin code, if τ = 1, ρ = 0, the conditions for achieving confidentiality and integrity shown in equation (10) are satisfied. Therefore, even if a packet is eavesdropped on one link, information-theoretic security is maintained (μ = 1). At the same time, one-rank errors can be corrected (τ = 1). Next, we consider the combination of OTP encryption and Gabidulin code. The dotted lines in Figure 7 represent links where OTP encryption cannot be implemented. If a packet is eavesdropped on a link that is not OTP encrypted, information will be leaked. However, by applying Gabidulin code, information-theoretic security is maintained even if packets are eavesdropped on this link. The message sent from the source node s is u=89A1CE37508C00E9, and the random number packet is v=ACDD3AC51A8C5E87. The concatenation of u and v becomes the input to the Gabidulin encoder.
number
[0067] The generator matrix is given by the following equation.
number
[0068] Gabidulin encoding can be performed as follows.
number
[0069] In a distributed key relay system network, x generated by Gabidulin encoding is distributed into four packets and transmitted and relayed to the terminal node. Terminal nodes t0 to t3 collect four packets from the links that pass through the relay nodes. However, suppose that an eavesdropper injects one error packet onto a link in the network. In this example, suppose that an error packet (1918EB1300152F8F) is injected onto the link s1 → v1 in the network. The packet y' collected by the terminal node is as follows: y' is affected by the error packet.
number
[0070] For secure network decryption, x is calculated using the following formula:
number
number
number
number
[0071] Step 1: Calculate syndromes S0 and S1 from x' and the check matrix H. If the check matrix is expressed as follows:
number
number
[0072] Step 2: Using the Berlekamp-Massey method, the coefficients γ0 and γ1 of the Error Locator Polynomial (ELP) and the estimated rank error number τ are calculated from the syndrome.
number
[0073] Step 3: Use Gaussian elimination to find the root (d0) of ELP. Solve the following equation for x to find d0.
number
[0074] Step 4: Calculate the error coefficient Θ0 from d0.
number
[0075] Step 5: Calculate the error span a0 from d0.
number
[0076] Step 6: Estimate the error vector from the error span a0 and the error coefficient Θ0.
number
[0077] Step 7: The estimated codeword is obtained by subtracting the estimated error vector from x'.
number
[0078] Step 8: The message u is obtained from the estimated code word. u and v are separated using the following equation.
number
[0079] Even though an eavesdropper injected one error packet onto the network link, the error was corrected and the correct message u was obtained. In this embodiment, when there is one link on the network where OTP encryption cannot be performed, and that link is eavesdropped on by an eavesdropper and an error packet is injected on that link, it is possible to carry out secret communication that maintains information-theoretic security throughout the network, and at the same time, it is possible to correct the injected error. When using only OTP encryption, if there are insufficient encryption keys, it is not possible to perform secret communication that maintains information-theoretic security. It is necessary to wait until a new encryption key is generated, which reduces communication speed. On the other hand, when only Gabidulin codes are used without OTP encryption, eavesdropping on a small number of links can be countered, but if eavesdropping occurs on many links, secret communication with information-theoretic security cannot be achieved. In this embodiment, information-theoretic security was maintained even when a packet was eavesdropped on one link (μ = 1). Increasing μ allows for countermeasures against eavesdropping on more links, but this leads to a reduction in the number of transmitted messages m. This means that communication efficiency deteriorates, making it difficult to counter eavesdropping on many links using Gabidulin codes alone. Furthermore, when the number of links on a network is large, the number of links that are susceptible to eavesdropping tends to increase, making it even more difficult to counter eavesdropping using Gabidulin codes alone. As in this embodiment, by combining OTP encryption and Gabidulin code, it is possible to perform secret communication that maintains information-theoretic security without reducing communication speed, even when there is a possibility of eavesdropping on many links.
[0080] According to the above embodiment, by combining the MRD code, which is one of the secure network coding methods, with OTP encryption, it is possible to perform a new highly secure network coding method that compensates for the shortcomings of conventional secure network coding and quantum cryptography communication networks, and synergizes the advantages of both.
[0081] The present invention is not limited to quantum cryptography communication networks, but can be implemented in any communication network in which source nodes and terminal nodes are connected via relay nodes. Although MRD codes are suitable for correcting rank errors that tend to occur in communication networks that use linear network coding, the present invention can also be applied to communication networks that do not use linear network coding.
[0082] Fig. 8 shows the control device 100 of the communication network NW5 shown in Fig. 7. This control device 100 is configured to be able to communicate with each node in the communication network NW5, and includes a first instruction unit 110, a random number transmission unit 120, and a second instruction unit 130. The communication network NW5 and the control device 100 can be collectively called a communication network system.
[0083] The first instruction unit 110 instructs a source node s among multiple nodes in the communication network NW5 whether or not to perform MRD encoding when the source node s transmits data. For example, the first instruction unit 110 can determine whether there are enough keys for performing OTP encryption on each link of the communication network NW5, and determine that MRD encoding is necessary if there are not enough keys, or determine that MRD encoding is not necessary if there are enough keys. Alternatively, another entity in the communication network system other than the control device 100 may make such a determination and transmit the determination result to the first instruction unit 110. This entity may be, for example, a QKDN manager MG1, a network manager MG2, or a QKDN controller CT.
[0084] When the first instruction unit 110 instructs the source node s to perform MRD encoding, the random number transmission unit 120 transmits to the source node s a random number corresponding to the maximum number of links that may be subject to eavesdropping. The maximum number of links that may be subject to eavesdropping is determined according to the network status of the communication network NW5. This determination can be made by the random number transmission unit 120 itself, or the entity may make the determination and transmit the determination result to the random number transmission unit 120.
[0085] The second instruction unit 130 instructs each node in the communication network NW5 whether or not to perform OTP encryption when the node transmits to another node. The second instruction unit 130 can be configured so that when the first instruction unit 110 determines that MRD encoding is necessary, an instruction is issued to all nodes transmitting on a link for which the encryption key required for OTP encryption is provided to perform OTP encryption. Alternatively, the second instruction unit 130 can be configured to instruct at least one node that transmits data not to perform OTP encryption, in accordance with the security requirements for the information to be communicated, when the first instruction unit 110 determines that MRD encoding is necessary. In this case, consumption of encryption keys can be reduced. The second control unit 130 can be configured so that, when the first instruction unit 110 determines that MRD encoding is unnecessary, an instruction is issued to all nodes that perform transmission to perform OTP encryption.
[0086] Alternatively, MRD encoding and OTP encryption may be always performed at a source node in a communication network having a plurality of nodes and links connecting two of the nodes. That is, in this case, the source node includes an MRD encoding unit that performs MRD encoding of a message using a random number according to the maximum number of the links that may be subject to eavesdropping and generates an MRD-encoded message, an OTP encryption unit that performs OTP encryption of the MRD-encoded message using a key for OTP encryption and generates an OTP-encrypted message, and a transmission unit that transmits the OTP-encrypted message to another node connected to the source node via the link. Furthermore, a communication network can be configured that includes the source node, a terminal node that is the final destination of the message, and a relay node that relays messages between the source node and the terminal node. There may be multiple relay nodes in the communication path between the source node and the terminal node. The random number used for MRD encoding and the number of relay nodes that perform OTP encryption during relay are determined according to the number of links that cannot prepare the encryption key pair required for OTP encryption (i.e., the number of links that may not be able to maintain communication security if eavesdropped).
[0087] 9 shows an example of the computer hardware configuration of the control device 100. The control device 100 includes a CPU 351, an interface device 352, a display device 353, an input device 354, a drive device 355, an auxiliary storage device 356, and a memory device 357, which are interconnected by a bus 358.
[0088] A program that realizes the functions of the control device 100 is provided by a recording medium 359 such as a CD-ROM. When the recording medium 359 on which the program is recorded is set in the drive device 355, the program is installed from the recording medium 359 into the auxiliary storage device 356 via the drive device 355. Alternatively, the program does not necessarily have to be installed from the recording medium 359, but can also be installed via a network. The auxiliary storage device 356 stores the installed program as well as necessary files, data, and the like.
[0089] The memory device 357 reads and stores the program from the auxiliary storage device 356 when an instruction to start the program is received. The CPU 351 realizes the functions of the control device 100 in accordance with the program stored in the memory device 357. The interface device 352 is used as an interface for connecting to other computers via a network. The display device 353 displays a GUI (Graphical User Interface) or the like according to the program. The input device 354 is a keyboard, a mouse, or the like.
[0090] Each node in the communication network also has a computer hardware configuration similar to that of the control device 100.
[0091] The embodiments described above have aspects not only as an apparatus but also as a method and a computer program.
[0092] The following notes are provided regarding the embodiments described above. [Appendix 1] A control device for a communication network having a plurality of nodes and a link connecting two of the nodes, a first instruction unit that instructs a source node among the plurality of nodes whether or not to perform MRD encoding when the source node performs transmission; a random number transmitting unit that transmits to the source node a random number corresponding to a maximum number of the links that may be subject to eavesdropping when the first instructing unit instructs the source node to perform MRD encoding; a second instruction unit that instructs each of the plurality of nodes whether or not to perform OTP encryption when the node transmits to another node; A control device comprising: [Appendix 2] 2. The control device according to claim 1, wherein the communication network is a key management network in a quantum key distribution network. [Appendix 3] The control device according to claim 1, wherein the communication network is a service layer of a user network in a quantum cryptography communication network. [Appendix 4] A control device according to any one of Supplementary Notes 1 to 3; the plurality of nodes; said link connecting two said nodes; A communication network system having: [Appendix 5] A source node in a communication network having a plurality of nodes and a link connecting two of said nodes, an MRD encoding unit that performs MRD encoding of a message using a random number corresponding to the maximum number of links that may be eavesdropped, and generates an MRD-encoded message; an OTP encryption unit that performs OTP encryption on the MRD-encoded message using a key for OTP encryption to generate an OTP-encrypted message; a transmitter for transmitting the OTP encrypted message to another node connected to the source node via the link; A source node comprising: [Appendix 6] A source node as described in Appendix 5; and a terminal node that is the final destination of the message; a relay node that relays between the source node and the terminal node; A communications network having:
[0093] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments, and various modifications and changes can be made based on the technical concept of the present invention. [Explanation of symbols]
[0094] NW1~NW5 communication network QM QKD module TN Trusted Node KM Key Manager CT QKDN Controller MG1 QKDN Manager MG2 Network Manager UD user terminal 100 control device 110 1st instruction section 120 Random number transmitter 130 2nd instruction section
Claims
1. A control device for a communication network having a plurality of nodes and a link connecting two of the nodes, comprising: a first indicator that indicates to a source node among the plurality of nodes whether or not the source node should perform MRD encoding when transmitting; a random number transmitting unit that transmits to the source node a random number corresponding to a maximum number of links that may be subject to eavesdropping when the first instructing unit instructs the source node to perform MRD encoding; a second instruction unit that instructs each of the plurality of nodes whether or not to perform OTP encryption when the node transmits to another node; A control device comprising:
2. The control device according to claim 1 , wherein the communication network is a key management network in a quantum key distribution network.
3. The control device according to claim 1 , wherein the communication network is a service layer of a user network in a quantum cryptography communication network.
4. The control device according to any one of claims 1 to 3; the plurality of nodes; said link connecting two of said nodes; A communication network system having:
5. 1. A source node in a communication network having a plurality of nodes and a link connecting two of said nodes, an MRD encoding unit that performs MRD encoding on a message using a random number corresponding to the maximum number of links that may be eavesdropped, and generates an MRD-encoded message; an OTP encryption unit that performs OTP encryption on the MRD-encoded message using a key for OTP encryption to generate an OTP-encrypted message; a transmitter for transmitting the OTP encrypted message to another node connected to the source node via the link; A source node comprising:
6. a source node according to claim 5; a terminal node that is the final destination of the message; a relay node that relays between the source node and the terminal node; A communications network having:
Citation Information
Patent Citations
Transmission apparatus, reception apparatus, system for transferring network code, method for transmitting network code, method for receiving network code, method for transferring network code, and program
JP2013150187A
One-Time Pad Encryption Hub
JP2022516352A