Communication network control unit
Patent Information
- Application Number
- JP2023048931
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-03-24
- Publication Date
- 2026-03-04
AI Technical Summary
Conventional decentralized relay transmission methods are vulnerable to eavesdropping attacks, as compromising a single relay node can lead to the leakage of secret information due to the lack of secure masking and random number management across multiple relay paths.
A communication network control device that sets multiple relay paths and uses random number masking at each relay node to encrypt and decrypt secret sharing data, ensuring that the masking is updated and canceled only at the terminal node, thereby increasing the difficulty of eavesdropping by requiring specific combinations of attack points.
The solution significantly enhances the security of relay transmission by limiting effective attack patterns, reducing the number of successful eavesdropping combinations from n^m to a smaller subset, thus making it harder for eavesdroppers to recover the secret information.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a control device for a communication network. [Background technology]
[0002] The Vernam cipher has long been known as a method for a sender and a receiver located at a distance to share secret information in an information-theoretically secure manner. According to the Vernam cipher, the sender and the receiver share a random number sequence of the same size as the secret information in question in advance, and the secret information is encrypted using the random number sequence only once (using a One Time Pad (OTP)). By transmitting the encrypted ciphertext as data, the two parties can safely share the secret information. In this case, it is difficult for a third party to obtain information about the secret information from the ciphertext.
[0003] The Vernam cipher requires a secret random number sequence to be shared in advance, but it is difficult to achieve this in an information-theoretically secure manner as long as normal data transmission technology is used. However, by using a key sharing method based on the laws of physics, such as quantum key distribution, it is possible to share a secret random number sequence (i.e., a key) that can be used for the Vernam cipher between a sender and a receiver who are far apart, even though there is a limit to the distance.
[0004] In this way, in recent years, it has become possible to share secret information in an information-theoretically secure manner by combining the sharing of secret random number sequences using quantum key distribution and the transmission of Vernam-encrypted data using OTP.
[0005] However, the above method has a distance limit. This is because there is a physical limit to the distance over which quantum key distribution is possible. This limit is due to the dissipation that the quantum state optical signal experiences while propagating through the optical fiber. In the communication wavelength band, the limit is about 100 km.
[0006] Therefore, in order to expand the distance over which secret information can be shared, a relay transmission method is used. As shown in FIG. 1 as a communication network NW1, a start point (source node SN) where a sender is located and a end point (terminal node TN) where a receiver is located are connected by a single relay path for data transmission via a plurality of reliable relay nodes N1 to N4. As a premise, the relay nodes N1 to N4 are reliable relay points, i.e., trusted nodes. This relay path has five transmission links connecting two adjacent nodes. That is, the first transmission link connecting the source node SN and the first relay node N1, the second transmission link connecting the first relay node N1 and the second relay node N2, the third transmission link connecting the second relay node N2 and the third relay node N3, the fourth transmission link connecting the third relay node N3 and the fourth relay node N4, and the fifth transmission link connecting the fourth relay node N4 and the terminal node TN. The length of each transmission link is a length that allows quantum key distribution.
[0007] Two nodes connected by each transmission link share a secret random number sequence unique to that transmission link by performing quantum key distribution. In this way, secret random number sequences are prepared in all transmission links on the relay route. The source node SN conceals the secret information K with the OTP using the secret random number sequence k1 of the first transmission link, and
number
[0008] The first relay node N1 first uses the secret random number sequence k1 to
number
number
[0009] Each transmission link is secure from eavesdroppers because it is kept secret based on the Vernam cipher. In addition, the secret shared data sent on each transmission link is completely decrypted every time it arrives at a relay node, and all relay nodes are trusted nodes that are isolated by the central office and whose reliability is guaranteed. From the above, it is believed that the secret information K will not be leaked illegally.
[0010] However, there is a possibility that a relay node may be compromised by eavesdropping. For example, there is a non-zero probability that some security functions of a relay node station may be lost due to an unexpected disaster or failure. In addition, as the network becomes wider and the number of relay nodes increases, it becomes practically difficult to operate all relay nodes as ideal trusted nodes.
[0011] In particular, when there is only one relay path connecting the source node and the terminal node, there is a security weakness in that an eavesdropper can obtain the secret information K by simply compromising any one intermediate node on the relay path.
[0012] In order to overcome such weaknesses, Patent Document 1 discloses a method of distributed relay transmission in which a plurality of relay paths are used to relay secret information K. As shown in Fig. 2, in a communication network NW2 in which distributed relay transmission is performed, m relay paths are set between a source node SN and a terminal node TN. Each relay path is provided with n relay nodes. In the example of Fig. 2, m=7 and n=7.
[0013] The first relay route has the first relay node N11 to the seventh relay node N17, the second relay route has the first relay node N21 to the seventh relay node N27, the third relay route has the first relay node N31 to the seventh relay node N37, the fourth relay route has the first relay node N41 to the seventh relay node N47, the fifth relay route has the first relay node N51 to the seventh relay node N57, the sixth relay route has the first relay node N61 to the seventh relay node N67, and the seventh relay route has the first relay node N71 to the seventh relay node N77. The length of the transmission link connecting two adjacent nodes in each relay route in the communication network NW2 is a length that allows quantum key distribution, similar to the case of the communication network NW1.
[0014] The source node SN first generates (m-1) random numbers u1, u2, u3, …, u m-1 Then, the source node SN performs an exclusive OR operation on the secret information K and all the generated random numbers.
number
[0015] In the communication network NW2, an eavesdropper cannot decrypt the secret information K unless he obtains m pieces of secret shared data by attacking any of the intermediate nodes on each of the m relay routes. In this way, in distributed relay transmission, by increasing the number of relay routes, it becomes more difficult for an eavesdropper to launch an attack, thereby improving the security of the system. [Prior art documents] [Patent documents]
[0016] [Patent Document 1] Special Publication No. 2018-502514 Summary of the Invention [Problem to be solved by the invention]
[0017] In conventional distributed relay transmission, there is a problem that if any one relay node is compromised by an eavesdropping attack, the entire relay route including that relay node is compromised.
[0018] The present invention has been made in view of the above circumstances, and has an object to increase the difficulty of eavesdropping on relay transmission of secret information. [Means for solving the problem]
[0019] According to one embodiment of the present invention, there is provided a control device for a communication network having a plurality of nodes and links connecting two of the nodes. The control device includes a route setting unit for setting a source node which is a source of secret information, a terminal node which is a destination of the secret information, and a plurality of routes connecting the source node and the terminal node via a plurality of relay nodes in the communication network, a transmission instruction unit for instructing the source node to send a plurality of secret sharing data obtained by secret sharing the secret information through the plurality of routes, and a masking instruction unit for instructing the relay node to mask the secret sharing data with the random number and to transmit the random number to a relay node belonging to the route other than the relay node, so that the secret sharing data is masked with different random numbers at a certain link and another link in each route and is sent, and the masked secret sharing data is mathematically canceled and the secret information is restored when the masked secret sharing data are combined at the terminal node. Effect of the Invention
[0020] According to the present invention, it is possible to increase the difficulty of eavesdropping on relay transmission of secret information. [Brief description of the drawings]
[0021] [Figure 1] FIG. 1 is an explanatory diagram illustrating an example of a communication network. [Diagram 2] FIG. 2 is an explanatory diagram showing another example of a communication network. [Diagram 3] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 4] FIG. 1 is an explanatory diagram showing an overview of a first embodiment. [Diagram 5] FIG. 2 is an explanatory diagram showing an example of the first embodiment. [Figure 6] FIG. 4 is an explanatory diagram showing another example of the first embodiment. [Figure 7] 11 is a table showing effects of the first embodiment. [Figure 8A] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 8B] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 8C] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 8D] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 9A] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 9B] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 9C] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 9D] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 10] FIG. 11 is an explanatory diagram showing a second embodiment. [Figure 11] FIG. 11 is an explanatory diagram showing a third embodiment. [Figure 12A] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 12B] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 12C] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 12D] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 12E] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 13] FIG. 13 is an explanatory diagram showing a fourth embodiment. [Figure 14] FIG. 13 is an explanatory diagram showing a fifth embodiment. [Figure 15] FIG. 13 is an explanatory diagram showing a fifth embodiment. [Figure 16] 13 is a table showing the effects of the fifth embodiment. [Figure 17] FIG. 11 is an explanatory diagram showing a specific example of an attack point. [Figure 18] FIG. 13 is an explanatory diagram showing a sixth embodiment. [Figure 19] FIG. 2 is a block diagram of a control device of the communication network. [Figure 20] FIG. 1 is an explanatory diagram showing an example of calculation in a Galois field (51). [Figure 21] FIG. 11 is an explanatory diagram showing another calculation example in the Galois field (51). [Figure 22] FIG. 2 is an explanatory diagram illustrating an example of a computer hardware configuration of a control device. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0022] Hereinafter, the present invention will be described based on the illustrated embodiment, however, the present invention is not limited to the embodiment described below.
[0023] First, the inventors of the present invention have conducted extensive research into conventional distributed relay transmission, as described below.
[0024] 3 shows the communication network NW2 again. For example, suppose that the relay node N14 is compromised in the first relay route, the relay node N26 is compromised in the second relay route, the relay node N35 is compromised in the third relay route, the relay node N42 is compromised in the fourth relay route, the relay node N54 is compromised in the fifth relay route, the relay node N61 is compromised in the sixth relay route, and the relay node N76 is compromised in the seventh relay route. In this case, the secret shared data K1 to K7 are leaked, and as a result, the secret information K is leaked.
[0025] As described above, in the communication network NW2, there is a problem that the secret information K may be leaked due to a combination of the relay nodes N14, N26, N35, N42, N54, N61, and N76 that are merely accidentally compromised in each relay route.
[0026] For example, if there are m relay paths with n relay nodes, the total number of possible combinations of attack points by an eavesdropper is n m The number of eavesdroppers is n m No matter which combination is chosen from the possible combinations, the secret information K can be obtained by compromising the relay node associated with that combination. In this way, it is desirable for legitimate users and operators of the communication network to make eavesdropping even more difficult.
[0027] Therefore, an embodiment will be described below in which it is difficult for an eavesdropper to obtain secret information by simply selecting one of a plurality of relay nodes installed on each relay route as a target of attack and compromising it.
[0028] First Embodiment FIG. 4 shows a communication network NW11. This communication network NW11 has seven relay routes (first to seventh relay routes) connecting a source node SN and a terminal node TN, similar to the communication network NW2, and seven relay nodes are provided on each relay route. In this communication network, if an eavesdropper selects the third relay node N13 as an attack point on the first relay route, the eavesdropper cannot obtain secret information unless he selects the third relay nodes N23, N33, N43, N53, N63, and N73 as attack points on all other relay routes. In other words, unlike the conventional technology, no leakage of secret information occurs unless the combination of attack points selected by the eavesdropper matches a specific combination. This can significantly increase the difficulty of eavesdropping.
[0029] As shown in Fig. 4, the source node SN secretly shares secret information K into secret sharing data K1 to K7. Seven pieces of secret sharing data are sent from the source node SN to the terminal node TN through seven relay routes. At that time, the secret sharing data is masked (encrypted) with a random number every time it is relayed by a relay node.
[0030] Specifically, the relay node N11 does not send the secret shared data K1 as is to the relay node N12, but sends secret shared data K1'' obtained by masking the secret shared data K1 with a random number. The relay node N12 does not send the secret shared data K1'' as is to the relay node N13, but sends secret shared data K1'' obtained by masking the secret shared data K1'' with a random number. The same applies below. The relay node N17 sends the secret shared data K'''''''' received from the relay node N16 to the terminal node TN as is.
[0031] As described above, the secret shared data K1 is masked every time it is relayed, and the secret shared data K2 to K7 are also masked every time it is relayed.
[0032] A specific description will be given with reference to Fig. 5 showing the communication network NW12. The number of relay routes is set to 2, and the number of relay nodes in each relay route is set to 4 (m = 2, n = 4). As will be described later, the basic concept does not change even if the number of relay routes or the number of relay points changes. The communication network NW12 has a first relay route RP1 and a second relay route RP2 connecting a source node SN and a terminal node TN. The first relay route RP1 is provided with a first relay node N11 to a fourth relay node N14, and the second relay route RP2 is provided with a first relay node N21 to a fourth relay node N24. The first relay route RP1 has a transmission link connecting the source node SN and the first relay node N11, a transmission link connecting the first relay node N11 and the second relay node N12, a transmission link connecting the second relay node N12 and the third relay node N13, a transmission link connecting the third relay node N13 and the fourth relay node N14, and a transmission link connecting the fourth relay node N14 and the terminal node TN. The second relay route RP2 has a transmission link connecting the source node SN and the first relay node N21, a transmission link connecting the first relay node N21 and the second relay node N22, a transmission link connecting the second relay node N22 and the third relay node N23, a transmission link connecting the third relay node N23 and the fourth relay node N24, and a transmission link connecting the fourth relay node N24 and the terminal node TN. Two nodes connected by each transmission link can directly share an OTP key using that transmission link.
[0033] Each secret shared data is relayed to the terminal node on each relay route via the same number of relay nodes, and the number of relay nodes on each relay route is called the number of relay stages. Intermediate nodes in the same order from the source node are considered to belong to the same stage. From the perspective of a relay node, the stage on the source node side is the previous stage, and the stage on the terminal node side is the next stage.
[0034] The source node SN secretly shares the secret information K into the secret sharing data K1 and the secret sharing data K2 by using the random number r0 as follows.
number
[0035] A packet including the secret shared data K1 is transmitted from the source node SN to the terminal node TN via the relay nodes N11, N12, N13, and N14 on the first relay route RP1 in this order. Similarly, a packet including the secret shared data K2 is transmitted from the source node SN to the terminal node TN via the relay nodes N21, N22, N23, and N24 on the second relay route RP2 in this order.
[0036] In addition, a public data communication path is provided between two relay nodes that belong to different relay paths, but these data communication paths are not used for transmitting the secret sharing data, but are used to transmit and receive random numbers for masking, which will be described later.
[0037] The basic procedure of distributed relay transmission will be described below with reference to the example of FIG. The source node SN performs the following process. A random number r0 is generated, and secret information K is secretly shared into two pieces of secret sharing data K1 and K2 using the random number r0. The secret shared data K1 is concealed by OTP and transmitted to the relay node N11 on the first relay route RP1. Similarly, the source node SN transmits the secret shared data K2, which has been concealed by the OTP, to the relay node N21 on the second relay route RP2.
[0038] The first relay node N11 on the first relay route performs the following process. Generate a random number r1. The secret shared data K1 is decrypted from the concealed data received from the source node. The secret shared data K1 is masked by the random number r1,
number
[0039] The first relay node N21 on the second relay route performs the following process. Generate a random number r2. The secret shared data K2 is decrypted from the concealed data received from the source node. The secret shared data K2 is masked by the random number r2, and
number
[0040] The second relay node N12 on the first relay route performs the following process. Generate a random number r3. The random number r2 is decrypted from the encrypted data transmitted from the previous intermediate node N21 on the second relay route. From the concealed data transmitted from the previous intermediate node N11 on the same relay route,
number
number
number
[0041] The second intermediate node N22 on the second relay path performs the following process. Generate a random number r4. The random number r1 is decrypted from the encrypted data transmitted from the previous intermediate node N11 on the first relay route. From the concealed data transmitted from the previous intermediate node N21 on the same relay route
number
number
number
[0042] The third relay node N13 on the first relay route performs the following process. Generate a random number r5. The random number r4 is decrypted from the encrypted data transmitted from the previous intermediate node N22 on the second relay route. From the concealed data transmitted from the previous intermediate node N12 on the same relay route,
number
number
number
[0043] The third relay node N23 on the second relay route performs the following process. Generate a random number r6. The random number r3 is decrypted from the encrypted data transmitted from the previous intermediate node N12 on the first relay route. From the concealed data transmitted from the previous intermediate node N22 on the same relay route,
number
number
number
[0044] The fourth relay node N14 on the first relay route does not generate a new random number because the subsequent node is the terminal node TN, but performs the following process. The random number r6 is decrypted from the encrypted data transmitted from the previous intermediate node N23 on the second relay route. From the concealed data transmitted from the previous intermediate node N13 on the same relay route,
number
number
number
[0045] The fourth relay node N24 on the second relay route does not generate a new random number because the subsequent node is the terminal node TN, but performs the following process. The random number r5 is decrypted from the encrypted data transmitted from the previous intermediate node N13 on the first relay route. From the concealed data transmitted from the previous intermediate node N23 on the same relay route,
number
number
number
[0046] The terminal node T performs the following processing. From the concealed data transmitted from the intermediate node N14 on the first relay path,
number
number
number
[0047] <Key Points of the First Embodiment> First point: Automatic removal of random masks at terminal nodes According to the above procedure, the random numbers r1 to r6 for masking generated at a relay node on one relay route are always used on two relay routes by being passed between the relay routes. Therefore, at the terminal node TN that aggregates the relay routes, the effect of the mask is always automatically cancelled by cancelling out the random numbers. Furthermore, the terminal node TN does not need to know the random numbers r1 to R6 for masking. As described above, the restoration of the secret information K at the terminal node TN is guaranteed.
[0048] Second point: Random masking at relay nodes and updating of masks during relaying In conventional distributed relay transmission, random number masking of secret information is performed only at the source node. In contrast, in this embodiment, the relay node also performs random number masking of the secret sharing data. Furthermore, according to the procedure, a new random number is added and the random number mask is updated every time the secret sharing data is relayed to a subsequent intermediate node. As a result, the secret sharing data is masked with a different random number for each relay node. Even if an eavesdropper succeeds in eavesdropping on a certain relay node, he or she can only obtain the secret sharing data masked with a random number generated by another node, but cannot obtain the secret sharing data itself. For example, even if an eavesdropper succeeds in eavesdropping on the relay node N12 (FIG. 5), he or she can only obtain the secret sharing data masked with a random number r1 generated by another node N11, but cannot obtain the secret sharing data K1 itself.
[0049] In the example shown in FIG. 5, the secret shared data K1 is relayed along the first relay path as follows:
number
[0050] As a result, it becomes more difficult to eavesdrop on the secret information K than in the past. In other words, an eavesdropper cannot recover the secret information K by simply selecting and combining one attack point from each relay route, because the random number mask cannot be removed.
[0051] Third point: Scalability to large networks As explained below, the processing performed at a relay node is limited to local processing determined only by the connection relationships with surrounding nodes, and is unrelated to the scale of the entire distributed relay transmission network. Therefore, the basic procedure of the invention described above can be easily expanded to large-scale networks. This is the third point of the invention.
[0052] To perform relay transmission, a source node and a terminal node are first set. The source node secretly shares secret information K into multiple secret shared data. For each piece of secret shared data, the source node specifies the intermediate nodes and terminal nodes to be passed through as relay points in order, and writes this as route information in the header of the packet. A relay route specific to the secret shared data is set on the network using this route information. The intermediate node that receives the packet selects the next intermediate node to which the packet will be forwarded according to the route information. In this way, a number of relay routes equal to the number of secret shared data are configured on the communication network.
[0053] The relay node performs the following process. S1: Receives secret sharing data from a previous source node or a previous intermediate node on the same relay route. S2: Generate the required number of random numbers. The total number of random numbers is equal to the number L1 of other relay routes to which the relay node provides one random number each. S3: Receive one random number from a previous intermediate node on another relay route. The total number of random numbers received here is equal to the number L2 of other relay routes that provide random numbers to the intermediate node. S4: Generate a random number for masking. Here, the sum of the L1 random numbers generated in step S2 and the sum of the L2 random numbers provided in step S3 is added together to obtain the random number for masking. S5: The random number for masking calculated in step S4 is further added to the random number mask for the secret sharing data input in step S1 to update the secret sharing data. S6: The secret sharing data updated in step S5 is output to the subsequent intermediate node or subsequent terminal node on the same relay route. S7: Provide the L1 random numbers generated in step S2 above to subsequent intermediate nodes on other relay routes to which one random number will be provided, one for each relay route. S8: The subsequent intermediate nodes which have received the secret sharing data sequentially repeat the processes of steps S1 to S7, and finally collect the secret sharing data in the terminal node. L1 and L2 are integers greater than or equal to zero.
[0054] The terminal node receives secret sharing data from the last intermediate node on each relay path, aggregates all the secret sharing data, removes the random number mask, and recovers the secret information K.
[0055] According to steps S4 and S5, the random number generated in step S2 is used as part of the random number for masking in the relay route to which the relay node belongs. At the same time, according to steps S7, S3, S4 and S5 in accordance with the actual order, the random number generated in step S2 is also used as part of the random number for masking in one relay route selected as the destination in step S7. In this way, the random number generated at a relay node on a certain relay route is always used on two relay routes. As a result, the effect of the random number is always offset when the relay routes are aggregated at the terminal node. In this way, the first point of the invention is guaranteed.
[0056] In step S7, the number of relay routes to which the generated random number is provided can be an odd number rather than being limited to 1. In this case, the random number is used for an even number of relay routes, including the relay route from which the random number is provided, so that the random numbers are also cancelled out when the relay routes are aggregated at the terminal node.
[0057] According to the above step S5, on each relay route, a new random number is added and the mask is updated every time the secret shared data is relayed to the next relay node, thereby ensuring the second point of the invention.
[0058] The number L1 described in step S2 and the number L2 described in step S3 are determined in advance for each relay node depending on the network and the setting conditions of the relay route. According to the example of Figure 5, at relay nodes N11 and N21 connecting to the source node, (L1, L2) = (1, 0), at relay nodes N12, N13, N22 and N23, (L1, L2) = (1, 1), and at relay nodes N14 and N24 connecting to the terminal node, (L1, L2) = (0, 1).
[0059] How the first and second points of the invention are realized as a result of performing the above steps S1 to S7 will be described with reference to a generalized example. 6 shows a communication network NW13. This communication network NW13 is further provided with a third relay route RP3 connecting a source node SN and a terminal node TN, in addition to the communication network NW12. The third relay route RP3 includes a first relay node N31 to a fourth relay node N34. The third relay route RP3 has a transmission link connecting the source node SN and the first relay node N31, a transmission link connecting the first relay node N31 and the second relay node N32, a transmission link connecting the second relay node N32 and the third relay node N33, a transmission link connecting the third relay node N33 and the fourth relay node N34, and a transmission link connecting the fourth relay node N34 and the terminal node TN.
[0060] In the communication network NW13, random numbers are exchanged between one relay route and the other two relay routes. At the relay nodes N11, N21, and N31 connected to the source node, (L1, L2)=(2, 0), at the relay nodes N14, N24, and N34 connected to the terminal node, (L1, L2)=(0, 2), and at the other relay nodes N12, N13, N22, N23, N32, and N33, (L1, L2)=(2, 2).
[0061] According to the above step S1, the relay node N11 on the first relay route receives an input of the secret shared data K1. The relay node N11 then generates two random numbers r1 and r2 according to the above step S2, and provides the random numbers to the subsequent relay nodes N22 and N32 on the second and third relay routes, respectively, according to the above step S7. According to the above step S4, the relay node N11 generates the random numbers for masking
number
number
[0062] According to step S1, the relay node N12
number
number
number
number
[0063] As shown in FIG. 6, the random numbers {r1, r3, r7, r9, r13, r15} are used in the first and second relay routes and are offset at the terminal node. The random numbers {r2, r5, r8, r11, r14, r17} are used in the first and third relay routes and are offset at the terminal node. The random numbers {r4, r6, r10, r12, r16, r18} are used in the second and third relay route pairs and are offset at the terminal node. In this way, the example of three relay routes shown in FIG. 6 can be understood as a combination of three examples of two relay routes shown in FIG. 5. In this way, even if the number of relay routes is increased, the first point of the invention is guaranteed.
[0064] <Effects> According to this embodiment, it becomes difficult for an eavesdropper to recover secret information by simply choosing a combination of attack points to compromise a network of distributed relay transmission of secret information. On the other hand, if a compromise does occur, a legitimate user or operator of the communication network can identify the pattern of the eavesdropper's attack.
[0065] The effect will be described with reference to the communication network NW12 shown in Fig. 5. According to the second point, the relay node holds the secret shared data masked with different random numbers and several random numbers. The first row of the table shown in Fig. 7 shows the secret shared data and random numbers held by the relay nodes N11 to N14 on the first relay route. Similarly, the first column of the table shows the secret shared data and random numbers held by the relay nodes N21 to N24 on the second relay route.
[0066] Eavesdropper steals secret information
number
[0067] For example, if the attack point is (N13, N23), an eavesdropper first attacks the secret sharing data on relay node N13.
number
number
number
number
number
[0068] If the attack points are any combination other than the four above, the eavesdropper cannot remove the mask applied to the secret information K. In the example of two relay routes shown in Fig. 5, the eavesdropper cannot recover the secret information K unless he selects intermediate nodes belonging to the same stage from all relay routes and sets them as attack points collectively, as shown in Fig. 7. Conversely, a legitimate user or operator can limit the combinations of attack points that are effective for an eavesdropper to the four patterns shown in Fig. 7.
[0069] In this way, the effective combination of attack points was previously n m =2 4 = 16 ways, but according to this embodiment, this can be reduced to 4 ways. In other words, it becomes more difficult for an eavesdropper to eavesdrop.
[0070] In the example of three relay routes shown in Figure 6, it can be seen that the combinations of three intermediate nodes that enable the recovery of secret information K are limited to any one of (N11, N21, N31), (N12, N22, N32), (N13, N23, N33), and (N14, N24, N34). These four combinations are shown in Figures 9A to 9D, respectively. In contrast, in conventional distributed relay transmission in which relay nodes simply relay secret shared data as is, the total number of possible combinations of three intermediate nodes is n m =4 3 = 64. According to the above embodiment, the number of attack patterns effective for an eavesdropper can be reduced from 64 to 4.
[0071] <Second embodiment> A communication network NW21 is shown in Fig. 10. In the communication network NW21, similar to the communication network NW13 shown in Fig. 6, three relay routes RP1 to RP3 are provided between a source node SN and a terminal node TN, and each relay route has four relay nodes.
[0072] In the communication network NW21, random numbers {r1, r3, r7, r9, r13, r15} are exchanged between the first and second relay routes, and random numbers {r4, r6, r10, r12, r16, r18} are exchanged between the second and third relay routes. The communication network NW21 differs from the communication network NW13 in FIG. 6 in that the random numbers r2, r5, r8, r11, r14, and r17 are neither used nor generated.
[0073] In the communication network NW21, at the relay nodes N12, N13, N32, and N33 on the first and third relay routes, (L1, L2)=(1, 1). At the relay nodes N22 and N23 on the second relay route, (L1, L2)=(2, 2). At the relay nodes N11, N21, and N31 connected to the source node, (L1, L2)=(1, 0), (L1, L2)=(2, 0), and (L1, L2)=(1, 0), respectively. At the relay nodes N14, N24, and N34 connected to the terminal node, (L1, L2)=(0, 1), (L1, L2)=(0, 2), and (L1, L2)=(0, 1), respectively.
[0074] Compared with the communication network NW13 shown in FIG. 6, the number of pairs of relay routes in the communication network NW21 is reduced from three to two, so that six fewer random numbers are used. The communication network NW21 can be understood as a combination of two examples of two relay routes in the communication network NW12 shown in FIG. 5. The combinations of three relay nodes that enable the recovery of the secret information K are limited to four, namely (N11, N21, N31), (N12, N22, N32), (N13, N23, N33), and (N14, N24, N34). This is the same as the specific combinations shown in FIG. 9A to FIG. 9D related to the communication network NW13 shown in FIG. 6. It is not necessary to use all three possible combinations of relay routes that form pairs as in the communication network NW13 in FIG. 6, and it can be seen that the same result can be obtained by simply using two combinations derived from adjacent relay routes as in the communication network NW21 shown in FIG. 10. Even if the number of relay routes is greater, the same effect can be obtained by simply passing random numbers between only two adjacent relay routes, as in the example of FIG.
[0075] <Third embodiment> A communication network NW31 is shown in Fig. 11. The second relay route RP2 of the communication network NW21 shown in Fig. 10 is replaced with a second relay route RP2a in the communication network NW31 of Fig. 11. This second relay route RP2a has three relay nodes, namely, a first relay node N21, a second relay node N22, and a fourth relay node N24. The second relay route RP2a also has a transmission link connecting the source node SN and the first relay node N21, a transmission link connecting the first relay node N21 and the second relay node N22, a transmission link connecting the second relay node N22 and the fourth relay node N24, and a transmission link connecting the fourth relay node N24 and the terminal node TN.
[0076] In this way, in the communication network NW31 of Fig. 11, the number of relay nodes on the second relay route is one less than that of the communication network NW21 shown in Fig. 10. This is treated as if the third-stage relay node N23 is missing. Also, the random numbers r7, r12, r15, and r16 used in the communication network NW21 of Fig. 10 are not used in the communication network NW31 of Fig. 11.
[0077] As shown in Fig. 12A to Fig. 12E, in this embodiment, the combinations of three intermediate nodes that enable the restoration of the secret information K are limited to five, namely (N11, N21, N31), (N12, N22, N32), (N13, N22, N33), (N13, N24, N33), and (N14, N24, N34). It can be seen that the role played by the relay node N23 in Fig. 10 is instead played by the relay node N22 in the previous stage or the relay node N24 in the subsequent stage on the same relay route in Fig. 11. As described above, the same effect can be obtained even if the number of relay nodes on each relay route is not the same.
[0078] <Fourth embodiment> 13 shows a communication network NW41. The communication network NW41 has a first relay route RP1b and a second relay route RP2b connecting a source node SN and a terminal node TN. Secret shared data K1 is transmitted via the first relay route RP1b, and secret shared data K2 is transmitted via the second relay route RP2b.
[0079] The first relay route RP1b includes a first relay node N11, a second relay node N12, a third relay node N13, a fourth relay node N14, and a fifth relay node N15. The first relay route RP1b also includes a transmission link connecting the source node SN and a first relay node N11; a transmission link connecting the first relay node N11 and the second relay node N12; a transmission link connecting the second relay node N12 and the third relay node N13; a transmission link connecting the third relay node N13 and the fourth relay node N14; a transmission link connecting the fourth relay node N14 and the fifth relay node N15; The fifth relay node N15 has a transmission link connecting the fifth relay node N15 and the terminal node TN.
[0080] The second relay route RP2b includes a first relay node N21, a second relay node N22, a third relay node N23, a fourth relay node N24, and a fifth relay node N25. The second relay route RP2b also includes a transmission link connecting the source node SN and a first relay node N21; a transmission link connecting the first relay node N21 and the second relay node N22; a transmission link connecting the second relay node N22 and the third relay node N23; a transmission link connecting the third relay node N23 and the fourth relay node N24; a transmission link connecting the fourth relay node N24 and the fifth relay node N25; and a transmission link connecting the fifth relay node N25 and the terminal node TN.
[0081] In this embodiment, one relay point is shared by the first relay route RP1b and the second relay route RP2b. This relay point is indicated by the symbol P1 in Fig. 13. The relay point P1 functions as a relay node N13 for the secret shared data K1, and functions as a relay node N23 for the secret shared data K2.
[0082] The second relay node N12 on the first relay route RP1b conceals the random number r3 using OTP and provides it to the fourth relay node N24 on the second relay route RP2b. Similarly, the second relay node N22 on the second relay route RP2b conceals the random number r4 using OTP and provides it to the fourth relay node N14 on the first relay route RP1b.
[0083] The relay nodes N13 and N23 at the relay point P1 do not generate or accept random numbers. The relay nodes N13 and N23 output the input secret sharing data to the next relay node without updating the random number mask.
[0084] If relay point P1 is compromised, the eavesdropper
number
[0085] In the conventional distributed relay transmission method, when all packets containing different secret sharing data join at one relay point, the effect of secret sharing is lost. In contrast, in this embodiment, two packets containing secret sharing data K1 and K2, respectively, arrive at relay point P1, but the secret information cannot be restored by an eavesdropper.
[0086] In this way, it is also effective in the case where multiple relay routes include a common relay point.
[0087] <Fifth embodiment> Fig. 14 shows a communication network NW51. This communication network NW51 has a first relay route RP1 and a second relay route RP2 connecting a source node SN and a terminal node TN, similar to the communication network 12 shown in Fig. 5.
[0088] The source node SN secretly shares the secret information K into the secret sharing data K1 and K2 using the random number r0. A packet including the secret sharing data K1 is sent from the source node SN to the terminal node TN via the relay nodes N11, N12, N13, and N14 in order according to the route information. Similarly, a packet including the secret sharing data K2 is sent from the source node SN to the terminal node TN via the relay nodes N21, N22, N23, and N24.
[0089] In addition, a public data communication path is provided between two relay nodes that belong to different relay paths, but these data communication paths are not used for transmitting the secret sharing data, but are used to transmit and receive random numbers for masking, which will be described later.
[0090] In the first step, a pair of a public key k and a private key k' is prepared in advance as shown in Fig. 14. In the following second step, this pair is used to conceal and transmit a random number used to mask the secret shared data between two nodes belonging to different relay routes.
[0091] In the second stage, as shown in Fig. 15, each relay node on each relay route generates its own random number for masking, and receives a random number for masking from a previous relay node belonging to another relay route. This causes the random number mask for the secret shared data to be updated for each relay section. Finally, at the terminal node, all the random numbers for masking are cancelled out, and the secret information
number
[0092] Further details will be explained with reference to FIG. 14 and FIG. <First Phase> FIG. 14 shows an example of preparation of a public key k and a private key k′ in the first stage of this embodiment. The relay node N22 prepares the public key k′ according to a general procedure of the public key cryptography. 22 and the private key k´ 22 Prepare a pair of public keys k 22 Similarly, the relay node N13 publishes the public key k 13 and the private key k´ 13 Prepare a pair of public keys k 13 The relay node N14 publishes the public key k 14 and the private key k´ 14 Prepare a pair of public keys k 14 The relay node N24 publishes the public key k 24 and the private key k´ 24Prepare a pair of public keys k 24 The terminal node TN publishes the public key k T and the private key k´ T Prepare a pair of public keys k T will be made public. This allows the nodes on the relay route to transmit confidential information to each of the nodes by using the public keys corresponding to each node, without being restricted by the physical distance between the nodes.
[0093] <Second Stage> FIG. 15 shows the second stage of this embodiment. The source node SN performs the following process. Generate a random number R0. Secret information K is secretly shared into two pieces of secret sharing data K1 and K2 using the random number R0.
number
[0094] The first relay node N11 on the first relay route performs the following process. Generate a random number r1 by yourself. · Decrypt the secret shared data K1 from the concealed data received from the source node SN. Mask the secret sharing data K1 with the random number r1.
number
[0095] The first relay node N21 on the second relay route performs the following process. -Generate the random number r2 yourself. The secret shared data K2 is decrypted from the concealed data received from the source node SN. Mask the secret sharing data K2 with the random number r2.
number
[0096] The second relay node N12 on the first relay route performs the following process. Generate the random number r3 yourself. From the concealed data transmitted from the previous relay node N11 on the same relay route
number
number
number
[0097] The second relay node N22 on the second relay route performs the following process. Generate the random number r4 yourself. - The private key k' is obtained from the encrypted data sent from the previous relay node N11 on the first relay route. 22 Decrypt the random number r1 using From the concealed data transmitted from the previous relay node N21 on the same relay route,
number
number
number
[0098] The third relay node N13 on the first relay route performs the following process. -Generate the random number r5 yourself. - The private key k´ is obtained from the concealed data sent from the previous relay node N21 on the second relay path. 13 Decrypt the random number r2 using - The private key k´ is obtained from the concealed data sent from the previous relay node N22 on the second relay path. 13 Decrypt the random number r4 using From the concealed data transmitted from the previous relay node N12 on the same relay route,
number
number
number
[0099] The third relay node N23 on the second relay route performs the following process. -Generate the random number r6 yourself. From the concealed data transmitted from the previous relay node N22 on the same relay route,
number
number
number
[0100] The fourth relay node N14 on the first relay route does not generate a new random number because the subsequent node is the terminal node TN, but performs the following process. - The private key k´ is obtained from the concealed data sent from the previous relay node N23 on the second relay path. 14 Decrypt the random number r6 using From the concealed data transmitted from the previous relay node N13 on the same relay route,
number
number
number
[0101] The fourth relay node N24 on the second relay route does not generate a new random number because the subsequent node is the terminal node TN, but performs the following process. - The private key k´ is obtained from the concealed data sent from the previous relay node N12 on the first relay path. 24 Decrypt the random number r3 using From the concealed data transmitted from the previous intermediate node N23 on the same relay route,
number
number
number
[0102] The terminal node TN performs the following processing. From the concealed data transmitted from the relay node N14 on the first relay route,
number
number
number
[0103] The effect of this embodiment will be described with reference to Fig. 16. According to the above-mentioned second point, different intermediate nodes hold secret shared data masked with different random numbers and several random numbers. The first row of the table shown in Fig. 16 shows the secret shared data and random numbers held in the intermediate nodes N11 to N14 on the first relay route. Similarly, the first column of this table shows the secret shared data and random numbers held in the intermediate nodes N21 to N24 on the second relay route.
[0104] confidential information
number
[0105] Sixth Embodiment A communication network NW61 is shown in Fig. 18. This communication network NW61 has first relay routes RP1 and RP2, similar to the communication network NW51 shown in Fig. 14 and Fig. 15. Furthermore, a public data communication path is provided between two relay nodes belonging to different relay routes, separately from the relay routes. However, these data communication paths are not used for transmitting the secret sharing data, but are used for transmitting and receiving random numbers for masking.
[0106] In this embodiment, in addition to the above-mentioned processing in the communication network NW51, the source node SN generates a random number r0 and masks the secret shared data K2.
number
[0107] Although the public key cryptosystem has been described as an encryption system for transmitting and receiving the random numbers while keeping them secret, the present invention is not limited to this, and other arithmetic encryption systems such as AES (Advanced Encryption Standard) may also be used.
[0108] 19 shows a control device 100 that controls a communication network having a plurality of nodes and a link connecting two of the nodes. The control device 100 is configured to be able to communicate with each node in the communication network, and includes a route setting unit 110, a transmission instruction unit 120, and a masking instruction unit 130. The communication network and the control device 100 can be collectively called a communication network system.
[0109] The route setting unit 110 sets a source node SN which is the transmission source of secret information K, a terminal node TN which is the destination of the secret information, and a plurality of routes which connect the source node and the terminal node via a plurality of relay nodes.
[0110] A transmission instruction unit 120 instructs the source node to transmit a plurality of pieces of secret sharing data obtained by secret sharing of the secret information via the plurality of routes, respectively.
[0111] The masking instruction unit 130 instructs a relay node to mask the secret sharing data with a random number and to transmit the random number to a relay node that belongs to the route other than the relay node. Here, the masking instruction and the random number transmission instruction are performed such that (a) the secret sharing data is masked with different random numbers at a certain link and another link in each route and is transmitted, and (b) when the masked secret sharing data are combined at the terminal node, the masking is mathematically canceled and the secret information is restored. This allows the masking to be mathematically cancelled when the terminal node recovers the secret information, and this cancellation is done automatically without the terminal node knowing the masking random number.
[0112] The control device 100 may further include a restoration instruction unit 140. The restoration instruction unit 140 instructs the terminal node to combine the multiple pieces of secret shared data transmitted through the multiple routes to restore the secret information.
[0113] The random numbers are generated in a Galois field GF(q x ), where q is a prime number and x is a positive integer.
[0114] The illustrated embodiment is in a Galois field GF(2 x) is used. Therefore, when the terminal node decrypts the data, if the number of the same mask random numbers included in all the masked secret sharing data received by the terminal node is a multiple of 2, the above cancellation effect can be obtained. x ) and the same random number, the result of adding the two random numbers and the result of exclusive ORing the two random numbers are the same. This means that in the Galois field GF(q x ) (where q is a prime number).
[0115] x1, x2 are stored in the Galois field GF(2 x ), the calculation of x1+x2 is equivalent to the calculation of the XOR (exclusive OR) of x1 and x2. For example, in the Galois field GF(2 8 ), let x1 = 100 (bit representation: 01100100) and x2 = 246 (bit representation: 11110110). 8 ), addition of x1 + x2 = 146. On the other hand, if you calculate the XOR between each bit of x1 and x2, you get 10010010. This bit representation is expressed in decimal as 146. This shows that addition and exclusive OR are equivalent. Therefore, when the same elements are added together (for example, x1 + x1), the result is 0 because each bit is the exclusive OR of the same bit. In other words, they are cancelled out. Therefore, in the Galois field GF(2 x ) If you add an even number (a multiple of 2) of elements on In general, a Galois field GF(q x ), q identical elements add up to 0. The above are the characteristics of Galois field calculations. The embodiments described so far make good use of these characteristics of Galois field calculations.
[0116] When q=2, addition and subtraction are equivalent. When q>2, addition and subtraction are not equivalent. When q>2, in order to cancel the masking by random numbers, not only addition of q identical elements but also subtraction can be used. In this case, one subtraction (subtraction of two identical elements) results in 0. For example, x1-x1=0. More generally, when q is a prime number, masking can be performed such that the masking is mathematically cancelled out by arithmetic operations on the masking random numbers at the connections at the terminal nodes.
[0117] See Figure 20. Galois field GF(5 1 ), K1 and K2 are secret sharing data, and secret sharing is performed as K=2*K1+3*K2. r1, r2, r3, and r4 are random numbers. Data is exchanged in a manner similar to that described with reference to FIG. Of the two routes from the source node SN to the terminal node TN in the network NW71, the secret shared data K1 is sent via the first route, and the secret shared data K2 is sent via the second route. In the relay nodes N12 to N14 and N22 to N24, masking of the secret sharing data is performed by adding random numbers. Then, the terminal node TN receives the following two masked secret sharing data. K1+r1+r2+r3+r4 K2+r2+r1+r4+r3 The terminal node performs the following calculation based on the secret sharing rules to recover the secret information K. 2*(K1+r1+r2+r3+r4)+3*(K2+r2+r1+r4+r3) =(2*K1+3*K2)+(2*r1+3*r1)+(2*r2+3*r2)+(2*r3+3*r3)+(2*r4+3*r4) =2*K1+3*K2 =K In this way, masking is canceled by adding q identical random numbers at the connections at the terminal nodes.
[0118] See Figure 21. Galois field GF(5 1), K1 and K2 are secret sharing data, and secret sharing is performed as K=2*K1+3*K2. r1, r2, r3, and r4 are random numbers. Data is exchanged in a manner similar to that described with reference to FIG. Of the two routes from the source node SN to the terminal node TN in the network NW72, the secret shared data K1 is sent via the first route, and the secret shared data K2 is sent via the second route. In the relay node N12, masking by subtraction is performed as follows. 2*K1-r1 Subtractive masking is also performed at relay node N22. In the relay node N13, masking is performed by addition and subtraction as shown below. 2*K1-r1+r2-r3 The relay node N23 also performs masking by addition and subtraction. In the relay node N14, masking by addition is performed as shown below. 2*K1-r1+r2-r3+r4 The relay node N24 also performs masking by addition. The terminal node performs the following calculation based on the secret sharing rules to recover the secret information K. (2*K1-r1+r2-r3+r4)+(3*K2-r2+r1-r4+r3) =(2*K1+3*K2)+(r1-r1)+(r2-r2)+(r3-r3)+(r4-r4) =2*K1+3*K2 =K In this way, masking is cancelled by subtracting a random number from the same random number at the connection at the terminal node.
[0119] Alternatively, although not shown, secret sharing may be performed in the source node as follows. K=2K1+5K2-3K3 Then, three paths are set to connect the source node and the terminal node. Secret shared data K1 is sent through the first path, secret shared data K2 is sent through the second path, and secret shared data K3 is sent through the third path. Masking by random numbers is performed on each path. The terminal node adds the result of multiplying the masked secret sharing data received through the first route by 2, the result of multiplying the masked secret sharing data received through the second route by 5, and the result of multiplying the masked secret sharing data received through the third route by 3, according to the secret sharing rules at the source node. Masking by random numbers is performed on each route so that the masking is canceled by this addition.
[0120] The control device 100 may include an encryption instruction unit (not shown) that instructs the source node, the terminal node, and the relay node to perform encryption on each link of the communication network. Any encryption method such as OTP or AES can be used on each link. By performing encryption on each link, it is possible to increase the difficulty of eavesdropping compared to a case where such encryption is not performed.
[0121] 22 shows an example of a computer hardware configuration of the control device 100. The control device 100 includes a CPU 351, an interface device 352, a display device 353, an input device 354, a drive device 355, an auxiliary storage device 356, and a memory device 357, which are interconnected by a bus 358.
[0122] A program for realizing the functions of the control device 100 is provided by a recording medium 359 such as a CD-ROM. When the recording medium 359 on which the program is recorded is set in the drive device 355, the program is installed from the recording medium 359 into the auxiliary storage device 356 via the drive device 355. Alternatively, the program does not necessarily have to be installed by the recording medium 359, but can also be installed via a network. The auxiliary storage device 356 stores the installed program as well as necessary files, data, and the like.
[0123] The memory device 357 reads out and stores the program from the auxiliary storage device 356 when an instruction to start the program is received. The CPU 351 realizes the functions of the control device 100 according to the program stored in the memory device 357. The interface device 352 is used as an interface for connecting to other computers via a network. The display device 353 displays a GUI (Graphical User Interface) or the like according to a program. The input device 354 is a keyboard, a mouse, or the like.
[0124] Each node in the communication network also has a computer hardware configuration similar to that of the control device 100.
[0125] The embodiments described above have aspects not only as an apparatus, but also as a method and a computer program.
[0126] Regarding the embodiments described above, the following supplementary notes are disclosed. [Appendix 1] A control device for a communication network having a plurality of nodes and a link connecting two of the nodes, a route setting unit that sets, in the communication network, a source node that is a transmission source of secret information, a terminal node that is a destination of the secret information, and a plurality of routes that connect the source node and the terminal node via a plurality of relay nodes; a transmission instruction unit that instructs the source node to transmit a plurality of secret sharing data obtained by secret sharing of the secret information through the plurality of routes, respectively; a masking instruction unit that instructs the relay node to mask the secret sharing data with the random number and to transmit the random number to a relay node that belongs to the route other than the relay node, so that the secret sharing data is masked with different random numbers at a certain link and another link in each route and is transmitted, and so that when the masked secret sharing data are combined at the terminal node, the masking is mathematically canceled and the secret information is restored; A control device for a communication network comprising: [Appendix 2] 2. The control device of a communication network according to claim 1, further comprising a restoration instruction unit that instructs the terminal node to restore the secret information by combining the multiple secret sharing data sent through the multiple routes. [Appendix 3] 3. The control device of a communication network according to claim 1 or 2, wherein the random number is an element in a Galois field GF(qx), where q is a prime number, and x is a positive integer. [Appendix 4] The control device for a communication network described in Appendix 3, wherein the masking instruction unit instructs masking so that masking is canceled by arithmetic operations of the random numbers in combining the multiple secret sharing data that have been masked at the terminal node. [Appendix 5] 3. The control device of a communication network according to claim 1 or 2, further comprising an encryption instruction unit that instructs the source node, the terminal node, and the relay node to perform encryption in each link of the communication network. [Appendix 6] A control device according to claim 1 or 2; the plurality of nodes; said link connecting two said nodes; A communication network system having the above configuration.
[0127] Although the embodiment of the present invention has been described above, the present invention is not limited to the above-described embodiment, and various modifications and changes can be made based on the technical concept of the present invention. [Explanation of symbols]
[0128] NW1, NW2 communication network SN Source Node TN Terminal Node N11~N17 relay nodes RP1, RP2, RP3 pathway K Confidential information 100 Control device 110 Route setting section 120 Transmission instruction section 130 Masking Instructions 140 Restoration Instructions
Claims
1. A control device for a communication network having a plurality of nodes and a link connecting two of the nodes, comprising: a route setting unit that sets, in the communication network, a source node that is a transmission source of secret information, a terminal node that is a destination of the secret information, and a plurality of routes that connect the source node and the terminal node via a plurality of relay nodes; a transmission instruction unit that instructs the source node to transmit a plurality of secret sharing data obtained by secret sharing of the secret information through the plurality of routes, respectively; a masking instruction unit that instructs the relay node to mask the secret sharing data with the random number and to transmit the random number to a relay node that belongs to the route other than the relay node, so that the secret sharing data is masked with different random numbers at a certain link and another link in each route and is transmitted, and so that when the masked secret sharing data are combined at the terminal node, the masking is mathematically canceled and the secret information is restored; A control device for a communication network comprising:
2. 2. The control device for a communication network according to claim 1, further comprising a restoration instruction unit that instructs the terminal node to restore the secret information by combining the plurality of secret sharing data transmitted through the plurality of routes.
3. 3. The control device for a communication network according to claim 1, wherein the random number is an element in a Galois field GF(qx), where q is a prime number, and x is a positive integer.
4. 4. The control device for a communication network according to claim 3, wherein the masking instruction unit instructs masking so that masking is canceled by arithmetic operations of the random numbers in combining the plurality of masked secret sharing data at the terminal node.
5. 3. The communication network control device according to claim 1, further comprising an encryption instruction unit that instructs the source node, the terminal node, and the relay node to perform encryption in each link of the communication network.
6. A control device according to claim 1 or 2; the plurality of nodes; said link connecting two of said nodes; A communication network system having the above configuration.