Conversion device, conversion system, conversion method, and conversion program

The conversion device addresses the challenge of converting non-quantum-resistant to quantum-resistant encryption methods by using a determination unit and conversion unit within the device, ensuring secure and continuous communication in mixed environments.

JP2025077805APending Publication Date: 2025-05-19NTT COMM CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023190278
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-07
Publication Date
2025-05-19

AI Technical Summary

Technical Problem

Existing technologies face difficulties in easily converting encryption methods from non-quantum-resistant to quantum-resistant in mixed encryption communication environments.

Method used

A conversion device with a determination unit to identify target communications for conversion and a conversion unit to transform non-quantum-resistant encrypted communications into quantum-resistant encrypted communications using data sandbox technology.

Benefits of technology

Enables seamless conversion of encryption methods, ensuring service continuity and secure communication even in environments with mixed encryption methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025077805000001_ABST
    Figure 2025077805000001_ABST
Patent Text Reader

Abstract

To make it possible to easily convert an encryption method of encrypted communication to be converted in communication in which encryption methods are mixed.SOLUTION: A conversion device 100 determines whether or not encrypted communication is conversion target, which is converted into encrypted communication based on post-quantum cryptography. The conversion device 100 converts the encrypted communication determined to be the conversion target into encrypted communication based on post-quantum cryptography.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a conversion device, a conversion system, a conversion method, and a conversion program.

Background Art

[0002] In recent years, with the development of practical quantum computers, it is expected that current asymmetric encryption methods such as the RSA (Ron Rivest, Adi Shamir, and Leonard Adleman) cipher, which is a traditional asymmetric key cipher (TasC), and elliptic curve ciphers will be endangered. Therefore, a shift from TasC to a post-quantum cryptography (PQC) method is being considered. In that case, it is also necessary to shift the public key infrastructure based on TasC (TasC-PKI) to a public key infrastructure based on PQC (PQC-PKI).

[0003] When the above-described encryption method shift is performed, it is expected that different encryption methods such as TasC and PQC will coexist. Therefore, in order to establish encrypted communication between all entities without causing problems, it is necessary to convert the encryption method of communication. For example, regarding the conversion of the encryption method, there is known a technique for changing the encryption method of data by decrypting each encrypted data using a plurality of encryption / decryption means and then re-encrypting it with another encryption method (see, for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, in the above-described conventional technology, there is a problem that it is difficult to easily convert the encryption method of encrypted communication to be converted in communication where encryption methods are mixed. For example, the above-described conventional technology is a technology in which a device storing a plurality of decryption processes and encryption processes changes to different encryption methods when decrypting and encrypting data, but it is not possible to convert encrypted communication using a non-quantum-resistant encryption method to encrypted communication using a quantum-resistant encryption method.

Means for Solving the Problem

[0006] Therefore, in order to solve the above-described problems and achieve the object, the conversion device of the present invention includes a determination unit that determines whether encrypted communication is a conversion target to encrypted communication based on quantum-resistant encryption, and a conversion unit that converts the encrypted communication determined to be the conversion target by the determination unit to encrypted communication based on the quantum-resistant encryption.

Effect of the Invention

[0007] According to the present invention, in communication where encryption methods are mixed, it is possible to easily convert the encryption method of encrypted communication to be converted.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

[0009] Hereinafter, embodiments for carrying out the present invention (hereinafter referred to as "embodiments") will be described with reference to the drawings. Note that each embodiment is not limited to the content described below.

[0010] <OVERALL OUTLINE> FIG. 1 is a diagram for explaining the overall image of the processing of the conversion device 100 according to the present embodiment. The conversion device 100 shown in FIG. 1 is an example of a computer that provides a technique for converting encrypted communication based on non-quantum-resistant encryption (hereinafter, may be referred to as "non-quantum-resistant encrypted communication") into encrypted communication based on quantum-resistant encryption (hereinafter, may be referred to as "quantum-resistant encrypted communication").

[0011] (BACKGROUND) In recent years, the development towards the practical application of quantum computers has been progressing. Quantum computers that apply the principles of quantum mechanics to computing can perform superparallel processing that is impossible with conventional electronic circuits, etc., and can solve complex problems that are difficult to solve with conventional computers. Therefore, it is expected that quantum computers will endanger TasC such as RSA encryption and elliptic curve encryption, and it is necessary to shift the encryption method from TasC to PQC, which is a quantum-resistant encryption method. Along with this, it is also necessary to shift PKI from the conventional TasC-PKI to PQC-PKI.

[0012] Here, the encryption of communication will be explained. For the encryption of communication, TLS (Transport Layer Security), which is a protocol for encrypting and transmitting and receiving data over TCP (Transmission Control Protocol) / IP (Internet Protocol) networks such as the Internet, is used. In conventional TLS, digital certificates such as SSL (Secure Socket Layer) server certificates signed by a certification authority (CA: Certificate Authority) installed on the server side and the certificate of the same certification authority as the server side or the root certificate of the top-level certification authority installed on the client side are used to encrypt communication.

[0013] On the other hand, in recent years, due to the standardization of NFV (Network Functions Virtualization) by the European Telecommunications Standards Institute (ETSI) and others, the reduction of the attack target area of the network, the prevention of the horizontal movement of threats, and the construction towards the reduction of the risk of data infringement, the progress of ZTA (Zero Trust Architecture), it is required that all communication between VNFCs (Virtual Network Function Components) be mTLS (mutual Transport Layer Security).

[0014] For example, in the case of encrypted communication using TLS, it is possible to specify cryptographic primitives and the like available from the client side during session negotiation (for example, if it is not compatible with PQC-PKI, only specify TasC-PKI, etc.). Therefore, by making the server certificate and the corresponding private key compatible with PQC, it is possible to shift from conventional non-quantum-resistant encryption communication to quantum-resistant encryption communication.

[0015] However, in an environment premised on mutual authentication using certificates such as mTLS, unlike TLS that uses only conventional server certificates, certificates exist for each client such as individual entities and terminal devices. Therefore, when shifting from conventional non-quantum-resistant encryption communication to quantum-resistant encryption communication, both the client and the server need to shift to quantum-resistant encryption communication. That is, in mTLS communication, since the terminal device and the server mutually authenticate, not only is it necessary to make the private key corresponding to the server certificate compatible with PQC, but it is also necessary to make the private key of the terminal device compatible with PQC. Therefore, in order to establish encrypted communication between entities with different encryption methods, it is necessary to convert the communication encryption method for all entities.

[0016] Regarding such conversion of the encryption method, for example, there is a known reference technique for changing the encryption method of data by decrypting each encrypted data using a plurality of encryption / decryption means and then re-encrypting it with another encryption method. However, in the situation where the encryption methods of communication are mixed in the above-described reference technique, it is difficult to easily convert the encryption method of encrypted communication.

[0017] (Conversion processing of encrypted communication by the conversion device) Therefore, the conversion device 100 according to the present embodiment provides a technique for identifying encrypted communication to be converted and performing decryption processing and encryption processing of encrypted communication using data sandbox technology, multifactor security, etc., to convert non-quantum-resistant encrypted communication into quantum-resistant encrypted communication.

[0018] Now, returning to FIG. 1, the conversion process of encrypted communication by the conversion device 100 will be described. As shown in (1) of FIG. 1, the conversion device 100 determines whether the non-quantum-resistant encrypted communication received from a terminal device (source) or the like is a target for conversion to quantum-resistant encrypted communication. For example, the conversion device 100 compares the determination conditions in which the source, destination, transmission content, etc. of the communication are associated with the encryption method to be converted, with the source, destination, etc. of the received non-quantum-resistant encrypted communication, and determines whether there is communication to be converted.

[0019] As shown in (2) of FIG. 1, the conversion device 100 converts the non-quantum-resistant encrypted communication determined to be a conversion target into quantum-resistant encrypted communication. For example, when the conversion device 100 determines that the communication used by the terminal device (source) is "non-quantum-resistant encrypted communication" and thus is a target for conversion of the encryption method, the conversion device 100 decrypts the non-quantum-resistant encrypted communication received from the terminal device (source) into plaintext communication by a predetermined decryption process. Subsequently, the conversion device 100 encrypts the communication decrypted into plaintext communication into quantum-resistant encrypted communication again. Then, the conversion device 100 can output the communication converted into quantum-resistant encrypted communication to the terminal device (destination).

[0020] In this way, the conversion device 100 according to the present embodiment can maintain communication (service) even in communication where encryption methods such as non-quantum-resistant encryption methods and quantum-resistant encryption methods are mixed, by converting encrypted communication such as non-quantum-resistant encrypted communication into quantum-resistant encrypted communication. Therefore, the conversion device 100 has the effect of facilitating the maintenance of service continuity and changing the encryption communication method all at once.

[0021] (Overview of IOWN Technology) Note that the conversion process by the conversion device 100 according to the present embodiment described above may be realized by using technologies related to IOWN (Innovative Optical and Wireless Network) technology. From here, an explanation of IOWN technology will be given.

[0022] First, the overview of the IOWN technology will be described. FIG. 2 is a diagram showing the overview of the IOWN technology. As shown in FIG. 2, the IOWN technology is composed of three major technical fields: "All-Photonics Network (APN)", "Digital Twin Computing (DTC)", and "Cognitive Foundation (CF: Cognitive Foundation (registered trademark))".

[0023] (All-Photonics Network) The APN related to the IOWN technology is a technology that enables the construction of a high-speed network by processing all network transfer functions in the optical domain. Specifically, the APN related to the IOWN technology is a technology that is based on optical (photonics-based) technologies such as "optoelectronic fusion technology", "high-capacity optical transmission system device technology", "optical imaging machine", and "optical lattice clock network", and realizes low-power consumption and high-quality, high-capacity, and low-latency communication.

[0024] (Digital Twin Computing) The DTC related to the IOWN technology is a technology that maps individual objects in the real world onto a virtual space using the vast amount of data collected by devices connected to the above-mentioned APN.

[0025] The framework of the conventional digital twin is utilized, for example, by mapping individual objects such as automobiles and robots onto a virtual space, performing analysis and prediction on them, or inversely mapping the results of analysis and prediction, etc. onto the real world.

[0026] On the other hand, the DTC related to IOWN technology develops the concept of the conventional digital twin, and by freely combining digital twins of various industries and things and humans for calculation, for example, it is a technology that can accurately reproduce combinations of multiple objects such as humans and automobiles in a city. Also, in the DTC related to IOWN technology, in order to enable digital expressions not only of the outer surface of a person but also of the inner surface such as consciousness and thinking, technologies such as "speech recognition", "speech synthesis", and "understanding of emotions and intentions" are combined to collect information and construct a digital twin environment.

[0027] In this way, the DTC related to IOWN technology is a technology that enables the generation of digital twins that do not exist in the real space by combining multiple entities that are single in the real world and replicating them as digital twins in the virtual space, or by exchanging or fusing some of the components between multiple digital twins.

[0028] (Cognitive Foundation) The CF related to IOWN technology is a technology that centrally implements the deployment, setting, cooperation, management, and operation of ICT (Information and Communication Technology) resources of different layers such as from the cloud to edge computers, network services, and user facilities. Specifically, the CF related to IOWN technology treats various targets as a group of virtualized ICT resources, and optimally integrates multiple resources of different layers with the multi-orchestration function as the hub.

[0029] Furthermore, as shown in Figure 2, the IOWN technology coordinates the above-mentioned APN, DTC, and network services provided by service providers by service providers to provide high-value-added services.

[0030] For example, as shown in (1) of FIG. 2, the IOWN technology provides a technology for transmitting information collected via an APN to other terminal devices at high speed and with low latency. Also, as shown in (2) of FIG. 2, the IOWN technology provides a technology for transmitting, at high speed and with low latency, the collection of a large amount of information from a terminal device and the output of information such as analysis results from a service provider's service in services such as information analysis provided by the service provider. Further, as shown in (3) of FIG. 2, the IOWN technology provides a technology for constructing a digital twin environment and making future predictions using information obtained from monitoring cameras, vehicle sensors, etc., by transmitting a large volume of information at high speed and with low latency, and outputting the prediction results to the user.

[0031] (Data sandbox technology) Based on the large-capacity, high-speed, and low-latency information transmission infrastructure based on the IOWN technology described above, it is considered that the construction of a digital twin environment and the cooperation between different digital twin environments will progress. And in that case, various types of information that were conventionally used only in a single digital twin environment may be shared among multiple DTCs. Therefore, safer information circulation, data processing, etc. are required.

[0032] Therefore, the IOWN technology provides a group of technologies such as a sandbox technology that realizes data governance related to data processing by performing computational processing in an encrypted state. Here, the data sandbox technology, which is a technology related to the IOWN technology, will be described. FIG. 3 is a diagram showing the data sandbox technology according to the IOWN technology.

[0033] As shown in FIG. 3, in the data sandbox technology related to the IOWN technology, an isolated processing execution environment (DSB: Data Sand Box) is created in a special secure computing area (TEE: Trusted Execution Environment) provided in the CPU (Central Processing Unit) of a computer provided by a platform operator, and data processing is performed within the data sandbox. Note that the data sandbox technology may be provided by a data sandbox providing system 10.

[0034] As an example, the data sandbox providing system 10 first configures a DSB for each policy in a platform that performs data processing in accordance with a data usage policy previously agreed upon by an authenticated data owner and an algorithm owner (FIG. 3(1)). Since communication with the outside is restricted and the memory and disk are encrypted in the DSB, neither the OS (Operating System) nor the platform operator can grasp the data and processing.

[0035] Next, the data sandbox providing system 10 generates and shares a common key between the system operated by the data owner and the DSB, and between the system operated by the algorithm owner and the DSB (FIGS. 3(2-1) and (2-2)). Then, the data sandbox providing system 10 places the data of the data owner and the algorithm of the algorithm owner encrypted with their respective unique common keys in the DSB (FIGS. 3(2-3) and (2-4)).

[0036] The data sandbox providing system 10 decrypts the data of the data owner and the algorithm of the algorithm owner using the common key between the data owner and the algorithm owner, and executes the processing (FIG. 3(3)).

[0037] Next, the data sandbox providing system 10 encrypts the processing result using a common key created and shared with the data user, and provides it to the result data user (step (4) in FIG. 3). After the processing is completed, the data sandbox providing system 10 deletes the data and algorithms for each DSB.

[0038] As described above, the data sandbox technology related to the IOWN technology enables the utilization of data while maintaining the confidentiality of not only the input data and algorithms but also the data in the processing process and processing results. Note that the common key used in the data sandbox technology related to the IOWN technology may be generated using the multi-factor security technology described later.

[0039] (Multi-Factor Security Technology) In addition, the IOWN technology provides an encryption technology for communication based on post-quantum encryption technology. Here, the multi-factor security (MFS) provided by IONW will be described. FIGS. 4 and 5 are diagrams showing the multi-factor security technology related to the IOWN technology.

[0040] Conventional encryption technologies such as RSA encryption (non-post-quantum encryption) are encryption methods based on the fact that it is difficult for a computer to complete calculations such as prime factorization within a realistic time, but there is a risk of being endangered by the emergence of quantum computers. Therefore, by using post-quantum cryptography such as PQC or quantum key distribution (QKD), security can be guaranteed even if conventional encryption technologies are endangered. However, even the above-mentioned post-quantum cryptography may be endangered due to technological progress. In addition, since the IOWN technology is also being considered for use in fields such as finance and medicine, a more robust encryption technology is required.

[0041] Therefore, in the IOWN technology, as a quantum-resistant encryption technology that takes into account "even if one encryption algorithm is compromised, communication is not immediately threatened" and "the ability to flexibly switch from a compromised encryption algorithm to another algorithm or adopt a new encryption algorithm", multi-factor security (MFS) technology is used. Note that the MFS technology may be provided by the MFS providing system 11.

[0042] Specifically, as shown in FIG. 4, the MFS providing system 11 combines a plurality of encryption technologies to synthesize a common key. For example, for encrypted communication between a plurality of communication endpoints, the MFS providing system 11 synthesizes a common key that combines a key exchange method (Type A method) that uses a third-party key exchange service and a key exchange method (Type B method) that can be realized between two parties ((1-1) and (1-2) in FIG. 4). Then, the MFS providing system 11 performs encryption processing and decryption processing of communication using the synthesized common key ((2-1) and (2-2) in FIG. 4).

[0043] By the above-described processing, the MFS providing system 11 provides an encryption technology that combines the information-theoretic security of the Type A method (e.g., QKD, etc.) and the computational security of the Type B method (e.g., PQC, etc.) by combining the Type A method and the Type B method ((1) in FIG. 5). Furthermore, the MFS providing system 11 provides the effect of covering the third-party risk included in the Type A method with the Type B method by combining the Type A method and the Type B method ((2) in FIG. 5).

[0044] The above-mentioned information-theoretic security means security against the most powerful possible attacker, i.e., an attacker with infinite computing power. Also, the above-mentioned computational security means security based on the assumption that the computational amount required for decryption is huge compared to the capabilities of available computers and is infeasible to execute in realistic time. Note that the above-mentioned PQC and QKD are merely examples, and the MFS provision system 11 may appropriately combine and use other encryption methods including current encryption methods such as RSA encryption and elliptic curve encryption.

[0045] In this way, the MFS technology can provide an encryption method according to the required security strength, user needs, etc. by using a common key generated based on multiple encryption technologies to synthesize the common key.

[0046] <First Embodiment> Hereinafter, as a first embodiment, an example of converting non-quantum-resistant encrypted communication to quantum-resistant encrypted communication using the data sandbox technology, which is a technology related to the above-mentioned IOWN technology realized by the conversion device 100 according to this embodiment, will be described. In the following items, the above-mentioned "encrypted communication" will be described as "non-quantum-resistant encrypted communication" meaning that it is not encrypted communication encrypted based on quantum encryption.

[0047] FIG. 6 is a diagram showing an example of the conversion process of encrypted communication according to the first embodiment. FIG. 6 shows a TasC-PKI environment employing the current encryption method (TasC) and a PQC-PKI environment employing the quantum-resistant encryption method (PQC).

[0048] In the TasC-PKI environment, it includes a TasC certification authority that issues certificates related to TasC, and a TasC VNFC that conducts encrypted communication based on TasC TLS1.3 (mTLS), which is TLS communication based on TasC (hereinafter sometimes referred to as "TasC TLS1.3 (mTLS) communication"). On the other hand, in the PQC-PKI environment, it includes a PQC certification authority that issues certificates related to PQC, and a PQC VNFC that conducts encrypted communication based on PQC TLS1.3 (mTLS), which is TLS communication based on PQC (hereinafter sometimes simply referred to as "PQC TLS1.3 (mTLS) communication"). Note that the above-mentioned TLS1.3 means the third version counted from the release of TLS1.0.

[0049] Also, a conversion device 100 exists at the boundary between the TasC-PKI environment and the PQC-PKI environment.

[0050] Since the above-mentioned TasC VNFC is a client that only has TasC certificates in the TasC-PKI environment, it cannot constitute mTLS communication based on PQC VNFC and PQC. Similarly, since the PQC VNFC is a client that only has PQC certificates in the PQC-PKI environment, it cannot constitute mTLS communication based on TasC VNFC and PQC.

[0051] Therefore, for the TasC TLS1.3 (mTLS) communication, which is a non-quantum-resistant encrypted communication received from the TasC VNFC, the conversion device 100 compares the source, destination, content, etc. of the communication with predetermined determination conditions to determine whether it is an encrypted communication to be converted (Figure 6(1)). Since the conversion device 100 has requirements such as a TEE as a Trusted Server, it performs decryption processing and encryption processing of encrypted communication in a secure environment constructed by the data sandbox technology related to the IOWN technology that realizes PEC (Privacy Enhancing Computation). Specifically, the conversion device 100 performs a process of decrypting the TasC TLS1.3 (mTLS) communication determined to be the conversion target into plaintext communication (Figure 6(2)). Next, the conversion device 100 encrypts the communication decrypted into plaintext communication into PQC TLS1.3 (mTLS) communication, which is quantum-resistant encrypted communication, based on the conversion conditions of the encryption method in which the source, destination, and content of the communication are associated with the encryption method (Figure 6(3)).

[0052] That is, the conversion device 100 constitutes TasC TLS1.3 (mTLS) communication with the TasC VNFC and establishes mTLS communication with the TasC VNFC using a certificate based on TasC-PKI commissioned by the PQC VNFC to the conversion device 100. On the other hand, the conversion device 100 constitutes PQC TLS1.3 (mTLS) communication with the PQC VNFC and establishes mTLS communication with the PQC VNFC using a certificate based on PQC-PKI commissioned by the TasC VNFC to the conversion device 100. Then, the conversion device 100 connects the TasC VNFC and the PQC VNFC by converting the TasC TLS1.3 (mTLS) communication into PQC TLS1.3 (mTLS) communication.

[0053] In this way, the conversion device 100 according to the first embodiment performs highly confidential calculations using the data sandbox technology related to the IOWN technology to convert the current non-quantum-resistant encrypted communication into quantum-resistant encrypted communication, thereby establishing a connection between encrypted communications with different encryption methods.

[0054] (Converter 100) Next, the configuration of the converter 100 will be described. FIG. 7 is a diagram showing an example of the configuration of the converter 100 according to the first embodiment. As shown in FIG. 7, the converter 100 includes a communication unit 110, a storage unit 120, and a control unit 130. Although not shown in FIG. 7, the converter 100 can be provided with an input unit such as a keyboard and a mouse for receiving inputs such as operations by a user or the like. Further, the converter 100 can be provided with a display unit such as a display for displaying information such as settings regarding the conversion process of encrypted communication and information regarding the result of the conversion process to a user or the like.

[0055] (Communication Unit 110) The communication unit 110 performs data communication related to the input of information regarding the determination conditions for performing the conversion of the encryption method and the conversion conditions of the encryption method associated with the communication destination, source, content, etc., and the output of communication encrypted based on quantum-resistant encryption. The communication unit 110 is realized by a NIC (Network Interface Card) or the like, and controls communication via a telecommunications line such as a LAN (Local Area Network) or the Internet. Then, the communication unit 110 is connected to the network by wire or wirelessly as necessary, and can transmit and receive information bidirectionally.

[0056] (Storage Unit 120) The storage unit 120 stores data and programs used for various processes by the control unit 130, and various data obtained by the operation of the control unit 130. The storage unit 120 is realized by a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk. Further, as shown in FIG. 7, the storage unit 120 has an encryption method list DB121.

[0057] (Encryption Method List DB121) The encryption method list DB121 is a database that stores an encryption method list in which information about communication included in encrypted communication, determination conditions for whether to perform conversion of the encryption method, and conversion conditions for the encryption method are associated with each other. Specifically, the encryption method list DB121 associates and stores at least any one of the communication source, communication destination, and communication content as information about communication included in encrypted communication, the necessity of converting the encryption method as a determination condition for whether to perform conversion of the encryption method, and the encryption method as a conversion condition for the encryption method.

[0058] Here, an example of the encryption method list stored by the encryption method list DB121 will be described. FIG. 8 is a table diagram showing an example of the encryption method list according to the first embodiment. As shown in FIG. 8, the encryption method list DB121 stores items of the communication source, communication destination, communication content, conversion execution, and encryption method in association with "No", which is identification information of information stored as the encryption method list.

[0059] Here, the communication source is information about the communication source of the encrypted communication received by the conversion device 100, and may be a 5-tuple or the like including the source IP and the source port number. Also, the communication destination is information about the communication destination of the encrypted communication received by the conversion device 100, and may be a 5-tuple or the like including the source IP and the source port number. Also, the communication content is the content of the communication included in the encrypted communication received by the conversion device 100. Also, conversion execution is flag information indicating whether to convert the encrypted communication received by the conversion device 100 to a different encryption method. Also, the encryption method is information indicating to which encryption method to convert when converting the encrypted communication received by the conversion device 100 to a different encryption method.

[0060] For example, as shown in FIG. 8, the encryption method list DB121 can store, as an encryption method list, the sender "A" identified by No. "1", the recipient "B", the transmission content "C", the necessity of conversion "〇", and the encryption method "PQC". The above-described content means that, for example, when the sender is "A", the recipient is "B", and the transmission content is "C", the encryption method is converted to "PQC".

[0061] Also, for example, the encryption method list DB121 can store, as an encryption method list, the sender "D" identified by No. "2", the recipient "E", the transmission content "F", the necessity of conversion "×", and the encryption method "-". The above-described content means that, for example, when the sender is "D", the recipient is "E", and the transmission content is "F", the conversion of the encryption method is not performed.

[0062] Also, for example, the encryption method list DB121 can store, as an encryption method list, the sender "G" identified by No. "3", the recipient "H", the transmission content "I", the necessity of conversion "〇", and the encryption method "TasC". The above-described content means that, for example, when the sender is "G", the recipient is "H", and the transmission content is "I", the encryption method is converted to "TasC".

[0063] (Control Unit 130) Here, returning to FIG. 7, the description will be continued. The control unit 130 has an internal memory for temporarily storing programs and processing data that define various processing procedures of the conversion device 100, and is realized by an electronic circuit such as a CPU or an MPU (Micro Processing Unit), or an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array). As shown in FIG. 7, the control unit 130 includes a reception unit 131, a determination unit 132, a conversion unit 133, and an output unit 134.

[0064] (Reception Unit 131) The reception unit 131 receives encrypted communication transmitted from an external information processing device or the like. For example, the reception unit 131 can receive non-quantum-resistant encrypted communication transmitted from a terminal device or a communication device, which is an external information processing device, via the communication unit 110 described above.

[0065] (Determination unit 132) The determination unit 132 determines whether the received non-quantum-resistant encrypted communication is a target for conversion to quantum-resistant encrypted communication based on the determination conditions for whether to perform conversion of a preset encryption method. Specifically, the determination unit 132 determines the necessity and importance of converting the encryption method from the information related to the communication included in the received encrypted communication, and determines whether to convert the encryption method of the received communication. For example, the determination unit 132 determines that a non-quantum-resistant encrypted communication that satisfies the determination condition (encryption method list) in which the presence or absence of conversion of the encryption method related to the non-quantum-resistant encrypted communication is associated with at least one of the source, destination, and communication content is a target for conversion to quantum-resistant encrypted communication.

[0066] Specifically, the determination unit 132 acquires information about the source and destination included in the received non-quantum-resistant encrypted communication (information related to the communication included in the encrypted communication). Next, the determination unit 132 compares the acquired information about the source and destination (information related to the communication included in the encrypted communication) with the source or / and destination of the communication stored in the encryption method list DB 121. Then, based on the result of the comparison, the determination unit 132 determines whether the received non-quantum-resistant encrypted communication is a target for conversion based on the presence or absence of conversion of the encryption method associated with the source or / and destination of the communication stored in the encryption method list DB 121 that matches the acquired information about the source and destination (information related to the communication included in the encrypted communication).

[0067] Specifically, the determination unit 132 compares the sender "A" and the recipient "B" included in the received non-quantum-resistant encrypted communication with the "recipient" and "sender" in the encryption method list shown in FIG. 8. Here, the determination unit 132 determines that the sender "A" and the recipient "B" included in the received non-quantum-resistant encrypted communication match the "sender" and "recipient" identified by No. "1" in the encryption method list shown in FIG. 8. Then, based on the conversion necessity "〇 (perform conversion)" identified by the No. "1", the determination unit 132 determines that the non-quantum-resistant encrypted communication is a conversion target. Note that the determination unit 132 may determine whether the non-quantum-resistant encrypted communication is a conversion target based on the "transmission content" included in the received non-quantum-resistant encrypted communication, which includes flag information indicating the importance of the communication that can be acquired by the conversion device 100, etc.

[0068] (Conversion unit 133) The conversion unit 133 converts the non-quantum-resistant encrypted communication determined to be a conversion target by the determination unit 132 into a quantum-resistant encrypted communication based on the conversion condition of the encryption method for which conversion is to be performed in advance. Specifically, the conversion unit 133 converts the received non-quantum-resistant encrypted communication into a quantum-resistant encrypted communication corresponding to the communication type, importance, etc. determined based on the communication source, communication destination, communication content, etc. included in the non-quantum-resistant encrypted communication, based on the conversion condition of the encryption method set in advance.

[0069] The conversion unit 133 includes a decryption unit 1331 and an encryption unit 1332 that perform the above-described conversion process. In the following items, the functions of the decryption unit 1331 and the encryption unit 1332 will be described based on the specific conversion process.

[0070] (Decryption unit 1331) The decryption unit 1331 decrypts the non-quantum-resistant encrypted communication determined to be a conversion target by the determination unit 132 into plaintext communication. For example, for a non-quantum-resistant encrypted communication with a sender of "A", a recipient of "B", and a transmission content of "C" determined to be a conversion target by the determination unit 132, the decryption unit 1331 decrypts it into non-encrypted plaintext communication.

[0071] (Encryption Unit 1332) When the information included in the received non-quantum-resistant encrypted communication satisfies the condition for specifying a preset encryption method, the encryption unit 1332 uses a common key shared with the destination terminal device or the like, and encrypts the plaintext communication decrypted using the encryption method associated with the condition for specifying the encryption method into quantum-resistant encrypted communication. Note that the encryption unit 1332 can perform the above-described encryption process using, for example, a common key shared with the destination terminal device or the like.

[0072] In addition, the encryption unit 1332 uses, as a condition for specifying the encryption method, information in which at least one of the source, destination, and communication content included in the non-quantum-resistant encrypted communication is associated with an encryption method based on a quantum-resistant cipher for encryption. To explain with a specific example, the encryption unit 1332 compares the source "A" and the destination "B" included in the received non-quantum-resistant encrypted communication with the "destination" and "source" in the encryption method list shown in FIG. 8. Here, the encryption unit 1332 determines that the source "A" and the destination "B" included in the received non-quantum-resistant encrypted communication match the "source" and "destination" identified by No. "1" in the encryption method list shown in FIG. 8. Then, the encryption unit 1332 converts the non-quantum-resistant encrypted communication into quantum-resistant encrypted communication based on the encryption method "PQC" identified by the No. "1". Note that the encryption unit 1332 may determine which encryption method to convert the non-quantum-resistant encrypted communication into based on the "transmission content" included in the received non-quantum-resistant encrypted communication and including flag information indicating the importance of the communication that can be acquired by the conversion device 100.

[0073] Note that the conversion unit 133 including the above-described decryption unit 1331 and encryption unit 1332 performs conversion processing in an isolated secure calculation processing execution area. For example, the conversion unit 133 uses the data sandbox technology related to the IOWN technology that realizes PEC in order to satisfy the above-described requirements such as TEE, and converts the non-quantum-resistant encrypted communication determined to be a conversion target into quantum-resistant encrypted communication.

[0074] (Output unit 134) The output unit 134 outputs the encrypted communication converted by the conversion unit 133 to an external information processing device or the like. For example, the output unit 134 can output the non-quantum-resistant encrypted communication converted by the conversion unit 133 to a different encryption method via the communication unit 110 described above to a terminal device or a server, which is an external information processing device.

[0075] (Procedure of conversion process) Hereinafter, the procedure of the conversion process of the encryption method of the encrypted communication realized by the conversion device 100 according to the first embodiment will be described. FIG. 9 is a flowchart showing an example of the conversion procedure according to the first embodiment.

[0076] The reception unit 131 receives the non-quantum-resistant encrypted communication (S101). The determination unit 132 makes a predetermined determination as to whether the received non-quantum-resistant encrypted communication is the encrypted communication to be converted (S102).

[0077] Here, when it is determined that the received communication is the non-quantum-resistant encrypted communication to be converted (Yes in S103), the decryption unit 1331 decrypts the non-quantum-resistant encrypted communication into plaintext communication (S104). Next, the encryption unit 1332 encrypts the decrypted plaintext communication into quantum-resistant encrypted communication (S105). Next, the output unit 134 outputs the quantum-resistant encrypted communication with the encryption method converted (S106). Then, the conversion device 100 ends the process.

[0078] On the other hand, when it is determined that the received communication is not the non-quantum-resistant encrypted communication to be converted (No in S103), the conversion device 100 skips the processes from S104 to S106 and ends the process.

[0079] (Effect) Next, the effects of the conversion device 100 according to the first embodiment will be described. The determination unit 132 of the conversion device 100 according to the first embodiment determines whether the received non-quantum-resistant encrypted communication is a target for conversion to quantum-resistant encrypted communication. Then, the conversion unit 133 of the conversion device 100 converts the non-quantum-resistant encrypted communication determined to be a conversion target by the determination unit 132 into quantum-resistant encrypted communication. Therefore, according to the conversion device 100 of the present embodiment, there is an effect that it is possible to convert non-quantum-resistant encryption into quantum-resistant encryption.

[0080] The determination unit 132 determines that a non-quantum-resistant encrypted communication that satisfies the determination condition in which the presence or absence of conversion of the encryption method related to the non-quantum-resistant encrypted communication is associated with the sender, the recipient, the communication content, etc. is a target for conversion to quantum-resistant encrypted communication. In this way, the conversion device 100 can determine whether to perform conversion of the encryption method for the encrypted communication based on information related to the communication included in the encrypted communication such as the sender, the recipient, and the communication content included in the non-quantum-resistant encrypted communication. Therefore, the conversion device 100 can perform the conversion process only after selecting only the encrypted communication for which conversion of the encryption method is required. As a result, the conversion device 100 has an effect that it is possible to perform an efficient conversion of the encryption method by converting only the target encrypted communication.

[0081] The conversion unit 133 decrypts the non-quantum-resistant encrypted communication determined to be the conversion target by the determination unit 132 into plaintext communication. Then, when the information included in the received non-quantum-resistant encrypted communication satisfies the condition for identifying a preset encryption method, the conversion unit 133 encrypts the plaintext communication decrypted using the encryption method associated with the condition into quantum-resistant encrypted communication. Specifically, the conversion unit 133 uses, as the information included in the non-quantum-resistant encrypted communication, the condition for identifying an encryption method in which the source, destination, communication content, etc. are associated with the encryption method based on the quantum-resistant cipher for encryption. In this way, the conversion device 100 can convert the received non-quantum-resistant encrypted communication into an optimal encryption method based on the information related to the communication included in the encrypted communication such as the source, destination, and communication content included in the non-quantum-resistant encrypted communication. Therefore, the conversion device 100 has the effect of enabling the realization of secure encrypted communication and the efficiency improvement of the process of converting the encryption method by selecting an optimal encryption method according to the destination, source, and transmission content of the received encrypted communication and converting the encryption method.

[0082] Also, the conversion unit 133 performs conversion processing in an isolated secure calculation processing execution area constructed by data sandbox technology related to IOWN technology or the like. Therefore, the conversion device 100 can convert non-quantum-resistant encrypted communication into quantum-resistant encrypted communication using the data sandbox technology related to IOWN technology. Therefore, the conversion device 100 has the effect of enabling the conversion processing of the encryption method of encrypted communication to be performed more securely than before.

[0083] That is, the conversion device 100 can smoothly and securely convert encrypted communication even in a communication environment where non-quantum-resistant encrypted communication and quantum-resistant encrypted communication coexist. As a result, the conversion device 100 can migrate the encryption method without stopping the communication and service even in a situation where non-quantum-resistant encrypted communication and quantum-resistant encrypted communication coexist.

[0084] <Second Embodiment> From here, as a second embodiment, an example of a conversion system 1 that converts various types of non-quantum-resistant encrypted communications, such as VPN (Virtual Private Network) communications and optical communications, into quantum-resistant encrypted communications using data sandbox technology and MFS technology, which are technologies related to IOWN technology, will be described. FIG. 10 is a diagram showing an example of the conversion process of encrypted communication according to the second embodiment.

[0085] FIG. 10 shows a TasC-PKI environment that adopts the current encryption method (TasC) and a PQC-PKI environment that adopts the quantum-resistant encryption method (PQC). In the TasC-PKI environment, a TasC certification authority that issues certificates related to TasC, a TasC VNFC that performs TasC TLS1.3 (mTLS) communication, and a communication device 300 that performs encrypted communication such as VPN communication are included. On the other hand, in the PQC-PKI environment, a PQC certification authority that issues certificates related to PQC and a PQC VNFC that performs PQC TLS1.3 (mTLS) communication are included. And a conversion device 100 exists at the boundary between the TasC-PKI environment and the PQC-PKI environment.

[0086] Also, the conversion system 1 according to the second embodiment includes a generation device 200 (200a and 200b) that generates and supplies a common key used for the conversion of encrypted communication by the conversion device 100. The conversion system 1 also includes a communication device 300 that encrypts TasC TLS1.3 (mTLS) communication from the TasC VNFC into PQC VPN communication.

[0087] Since the above-mentioned TasC VNFC is a client that only has a TasC certificate in the TasC-PKI environment, it cannot configure PQC VNFC and mTLS communication based on PQC. Similarly, since the PQC VNFC is a client that only has a PQC certificate in the PQC-PKI environment, it cannot configure mTLS communication based on TasC VNFC and PQC. Note that since TasC VNFC, PQC VNFC, TasC TLS1.3 (mTLS) communication, PQC TLS1.3 (mTLS) communication, etc. are the same as the content described in FIG. 6, detailed description is omitted in this item.

[0088] As shown in FIG. 10, for the PQC VPN communication encrypted by the communication device 300 using the common key (the first common key) supplied by the generation device 200, in a secure environment constructed using the data sandbox technology, the conversion device 100 uses the common key (the second common key) supplied by the generation device 200 to convert the encryption method to PQC TLS1.3 (mTLS) communication. Then, the conversion device 100 establishes communication between the TasC VNFC and the PQC VNFC.

[0089] Hereinafter, an example of a series of processes for the conversion process of encrypted communication according to the second embodiment will be described. First, the communication device 300 configures TasC TLS1.3 (mTLS) communication with the TasC VNFC (step (1) in FIG. 10). Then, the communication device 300 outputs a request for supplying a common key for encrypting the TasC TLS1.3 (mTLS) communication into PQC VPN communication to the generation device 200 (step (2) in FIG. 10).

[0090] The generation device 200 receives the request for supplying the common key output from the communication device 300. Then, the generation device 200a supplies the generated first common key to the communication device 300 (step (3) in FIG. 10). Note that the generation device 200 can generate and store the first common key and the second common key in advance using the MFS technology described above.

[0091] The communication device 300 superimposes and encrypts the PQC VPN communication (encryption communication based on the first quantum-resistant cryptography) without decrypting the TasC TLS1.3 (mTLS) communication with the TasC VNFC using the first common key supplied by the generation device 200a and the common key for encrypting the PQC VPN communication stored in advance (item (4) in FIG. 10).

[0092] The conversion device 100 receives the PQC VPN communication output from the communication device 300. The conversion device 100 determines whether the received PQC VPN communication is a conversion target for PQC TLS1.3 (mTLS) communication (encryption communication based on the second quantum-resistant cryptography) (item (5) in FIG. 10). Then, when the conversion device 100 determines that the received PQC VPN communication is a conversion target, the conversion device 100 outputs a supply request for a second common key for decrypting the received PQC VPN communication to the generation device 200b (item (6) in FIG. 10).

[0093] The generation device 200b receives the supply request for the second common key output from the conversion device 100. Then, the generation device 200b supplies the generated second common key to the conversion device 100 (item (7) in FIG. 10).

[0094] The conversion device 100 performs conversion processing in a secure environment constructed by data sandbox technology. Specifically, the conversion device 100 decrypts the PQC VPN communication output by the communication device 300 into plaintext communication using the second common key supplied by the generation device 200b and the common key for decrypting the PQC VPN communication stored in advance (item (8) in FIG. 10). Next, the conversion device 100 encrypts the communication decrypted into plaintext communication into PQC TLS1.3 (mTLS) communication, which is quantum-resistant encrypted communication, using the method described in the first embodiment (item (9) in FIG. 10). Then, the conversion device 100 configures PQC TLS1.3 (mTLS) communication with the PQC VNFC.

[0095] In this way, the conversion system 1 according to the second embodiment encrypts non-quantum-resistant encrypted communication into quantum-resistant encrypted communication related to VPN communication (encrypted communication based on the first quantum-resistant cipher) by generating a common key using the MFS technology described above, and further converts the quantum-resistant encrypted communication related to VPN communication (encrypted communication based on the first quantum-resistant cipher) into quantum-resistant encrypted communication (encrypted communication based on the second quantum-resistant cipher).

[0096] (Conversion system 1) Next, the configuration of the conversion system 1 will be described. FIG. 11 is a diagram showing an example of the configuration of the conversion system 1 according to the second embodiment. The conversion system 1 includes a conversion device 100 that converts encrypted communication, a generation device 200 that generates a common key, and a communication device 300 that controls predetermined communication. The conversion device 100, the generation device 200, and the communication device 300 are connected bidirectionally via communication units provided in each device.

[0097] (Conversion device 100) Next, the configuration of the conversion device 100 according to the second embodiment will be described. As shown in FIG. 11, the conversion device 100 includes a communication unit 110, a storage unit 120, and a control unit 130. Note that descriptions of portions where the functions of the conversion device 100 according to the second embodiment and the conversion device 100 according to the first embodiment overlap will be omitted as appropriate.

[0098] (Determination unit 132) The determination unit 132 determines whether the encrypted communication based on the first quantum-resistant cipher output by the communication device 300 (hereinafter, may be referred to as "first quantum-resistant encrypted communication") is a conversion target into encrypted communication based on the second quantum-resistant cipher (hereinafter, may be referred to as "second quantum-resistant encrypted communication"). For example, for the PQC VPN communication (first quantum-resistant encrypted communication) output by the communication device 300 where the transmission source is "A", the transmission destination is "B", and the transmission content is "C", the determination unit 132 determines that the conversion necessity corresponding to No. "1" in the encryption method list shown in FIG. 8 is "〇 (convert to second quantum-resistant encrypted communication)".

[0099] (Conversion Unit 133) The conversion unit 133 performs a conversion process on the first quantum-resistant encrypted communication determined to be a conversion target by the determination unit 132 into a second quantum-resistant encrypted communication using a second common key and a common key for decrypting the first quantum-resistant encrypted communication. As described above, the conversion unit 133 according to the second embodiment can execute the conversion process in a secure environment constructed using the data sandbox technology, which is a technology related to the IOWN technology, similar to the first embodiment.

[0100] Specifically, the decryption unit 1331 included in the conversion unit 133 uses the second common key supplied by the generation device 200 and a common key for decrypting the first encrypted communication encrypted by superposition by the communication device 300 to decrypt the encrypted communication determined to be a conversion target into plaintext communication. Then, the encryption unit 1332 included in the conversion unit 133 encrypts the plaintext communication into a second quantum-resistant encrypted communication using the same method as the encryption unit 1332 according to the first embodiment.

[0101] As described above, the conversion unit 133 according to the second embodiment has a decryption unit 1331 and an encryption unit 1332, similar to the conversion unit 133 according to the first embodiment. And since the conversion unit 133 according to the second embodiment performs the decryption process and the encryption process of the encrypted communication in the same method as the conversion unit 133 according to the first embodiment described above, detailed description is omitted here.

[0102] (An Example of Decryption and Encryption Processing Using the Generated Common Key) Here, an example of the conversion process of encrypted communication according to the second embodiment will be described. FIG. 12 is a diagram showing an example of encryption and encrypted conversion processing according to the second embodiment. In FIG. 12, the flow of conversion of the encryption method related to the encrypted communication between the TasC VNFC and the communication device 300, between the communication device 300 and the conversion device 100, and between the conversion device 100 and the PQC VNFC is shown as a diagram. Further, the conversion device 100 shown in FIG. 12 has a TasC-PKI certificate commissioned by the PQC VNFC and a PQC-PKI certificate commissioned by the TasC VNFC, and secret keys associated therewith, respectively. Also, the common keys 20a and 20b shown in FIG. 12 are session keys shared by mTLS using TasC-PKI. Further, the common keys 30a (first common key) and 30b (second common key) shown in FIG. 12 are pre-shared keys supplied by the generation devices 200a and 200b, and are session keys of the PQC-VPN. Also, the common keys 40a and 40b are session keys shared by mTLS using TasC-PKI.

[0103] First, the TasC VNFC converts plain communication (Plain) into mTLS communication (TasC-PKI) using the common key 20a (step (1) in FIG. 12). Next, the communication device 300 performs an encryption process by superimposing the mTLS communication (TasC-PKI) encrypted by the TasC VNFC using the common key 30a, and converts it into PQC VPN communication (step (2) in FIG. 12).

[0104] The conversion device 100 receives PQC VPN communication from the communication device 300. The conversion device 100 decrypts the PQC VPN communication received from the communication device 300 into plain communication (Plain) using the common key 20b corresponding to the common key 20a and the common key 30b corresponding to the common key 30a (step (3) in FIG. 12). Then, the conversion device 100 encrypts the plain communication (Plain) into mTLS communication (PQC-PKI) using the common key 40a (step (4) in FIG. 12).

[0105] The conversion device 100 outputs the encrypted communication converted into mTLS communication (PQC-PKI) to the PQC VNFC. Then, the PQC VNFC decrypts the mTLS communication (PQC-PKI) received from the conversion device 100 into plaintext communication (Plain) using the common key 40b corresponding to the common key 40a (item (5) in FIG. 12).

[0106] That is, the conversion device 100 has a function (TasC VNFC’) that substitutes for the PQC VNFC, which is the communication partner of the TasC VNFC, and establishes mTLS communication with the TasC-VNFC’. Also, the conversion device 100 has a function (PQC VNFC’) that substitutes for the TasC VNFC, which is the communication partner of the PQC VNFC, and establishes mTLS communication between the PQC VNFC and the PQC VNFC’.

[0107] Through the above-described series of conversion processes, the conversion system 1 can establish encrypted communication even when the encryption methods are different by converting the encrypted communication between the TasC VNFC and the PQC VNFC.

[0108] (Generator device 200) Next, the configuration of the generator device 200 will be described. The generator device 200 generates a common key using the MFS technology, which is a technology related to the IOWN technology. Then, the generator device 200 receives a supply request for the common key from an external information processing device or the like, and supplies the common key to the information processing device or the like that is the output source of the request.

[0109] For example, the generator device 200 receives a supply request for the common key from the communication device 300 and supplies the generated first common key to the communication device 300. Also, the generator device 200 receives a supply request for the common key from the conversion device 100, generates a second common key, and supplies the generated second common key to the conversion device 100. Here, the first common key and the second common key are the same common key for decrypting the encrypted communication, but the common key used by the communication device 300 is referred to as the first common key, and the common key used by the conversion device 100 is referred to as the second common key.

[0110] As shown in FIG. 11, the generation device 200 includes a communication unit 210, a storage unit 220, and a control unit 230. Although not shown in FIG. 11, the generation device 200 can be provided with an input unit such as a keyboard or a mouse for receiving inputs such as operations by a user or the like. Further, the generation device 200 can be provided with a display unit such as a display for displaying the generated common key or the like to the user or the like.

[0111] (Communication Unit 210) The communication unit 210 performs data communication related to the input of a supply instruction of a common key or the like used for encryption processing and the output of the generated common key or the like. The communication unit 210 is realized by a NIC or the like and controls communication via an electric communication line such as a LAN or the Internet. Then, the communication unit 210 is connected to the network by wire or wirelessly as necessary and can perform bidirectional transmission and reception of information.

[0112] (Storage Unit 220) The storage unit 220 stores data and programs used for various processes by the control unit 230, and various data acquired by the operation of the control unit 230. Then, the storage unit 220 is realized by a semiconductor memory element such as a RAM or a flash memory, or a storage device such as a hard disk or an optical disk. Further, as shown in FIG. 11, the storage unit 220 has a generation key information DB 221 and a generation list DB 222.

[0113] (Generation Key Information DB 221) The generation key information DB 221 is a database that stores a common key generated by a generation unit 232 described later. Specifically, the generation key information DB 221 stores a first common key generated based on a predetermined condition and a second common key corresponding to the first common key.

[0114] (Generation List DB 222) The generation list DB222 is a database that stores a generation list in which information related to encrypted communication related to the communication device 300 is associated with a common key type. Specifically, the generation list DB222 stores, in association with each other, at least one of the source, destination, and transmission content of the encrypted communication related to the communication device 300 and the common key type.

[0115] Here, an example of the generation list stored by the generation list DB222 will be described. FIG. 13 is a table diagram showing an example of a generation method list according to the second embodiment. As shown in FIG. 13, the generation list DB222 stores the source, destination, transmission content, and common key type in association with "No", which is the identification information of the information stored in the generation list.

[0116] Here, the source related to the generation list is information about the source that transmitted the encrypted communication received by the communication device 300, and may be a 5-tuple including the source IP and the source port number. Also, the destination related to the generation list is information about the destination of the encrypted communication received by the communication device 300, and may be a 5-tuple including the source IP and the source port number. Further, the transmission content related to the generation list is the content of the communication included in the encrypted communication received by the communication device 300. Also, the common key type related to the generation list is information indicating the type of the common key when supplying the common key in response to a common key supply request.

[0117] For example, as shown in FIG. 13, the generation list DB222 can store the source "a", destination "b", transmission content "c", and common key type "PQC+QKD" identified by No "1" as the generation list. The above-described content means, for example, that when the source is "a", the destination is "b", and the transmission content is "c", the common key is generated by combining "PQC and QKD" as the common key type.

[0118] Also, for example, the generation list DB 222 can store, as a generation list, the source "d" identified by No. "2", the destination "e", the transmission content "f", and the common key type "PQC". The above-described content means, for example, when the source is "d", the destination is "e", and the transmission content is "f", that a common key is generated based on PQC as the common key type.

[0119] Also, for example, the generation list DB 222 can store, as a generation list, the source "g" identified by No. "3", the destination "h", the transmission content "i", and the common key type "QKD". The above-described content means, for example, when the source is "g", the destination is "h", and the transmission content is "i", that a common key is generated based on QKD as the common key type.

[0120] (Control unit 230) The control unit 230 has an internal memory for temporarily storing a program and processing data that define various processing procedures and the like of the generation device 200, and is realized by an electronic circuit such as a CPU or MPU, or an integrated circuit such as an ASIC or FPGA. And as shown in FIG. 11, the control unit 230 includes a reception unit 231, a generation unit 232, and an output unit 233.

[0121] (Reception unit 231) The reception unit 231 receives a common key supply request from the communication device 300 and the conversion device 100 via the above-described communication unit 210. Note that the supply request from the communication device 300 includes trigger information for requesting the generation device 200 to supply a common key (first common key), and information related to the communication of the communication device 300 such as the source, destination, and transmission content of the communication. Further, the supply request from the conversion device 100 includes trigger information for requesting the generation device 200 to supply a common key (second common key), and information for identifying the first common key.

[0122] (Generation unit 232) The generation unit 232 generates a common key based on preset conditions. Note that the generation unit 232 can generate multiple types of common keys using the MFS technology, which is a technology related to the IOWN technology.

[0123] For example, the generation unit 232 combines one or more encryption methods associated with at least any one of the transmission destination of a predetermined communication such as communication based on an electrical line or communication based on an optical line, the transmission source of the predetermined communication, and the communication content of the predetermined communication to generate a common key (a first common key and a second common key). Specifically, the generation unit 232 generates a first common key supplied to the communication device 300 and a second common key supplied to the conversion device 100 based on predetermined conditions. Note that the predetermined conditions mentioned here may be, for example, periodic conditions such as every 1 second, every 1 minute, every 1 hour, etc., or conditions such as generating a specified number of common keys when the effective number of common keys falls below a predetermined number.

[0124] To explain with a specific example, the generation unit 232 compares the transmission source "a" and the transmission destination "b" output by the communication device 300 with the "transmission destination" and "transmission source" in the generation list shown in FIG. 13. Here, the generation unit 232 determines that the transmission source "a" and the transmission destination "b" output by the communication device 300 match the "transmission source" and "transmission destination" identified by No. "1" in the generation list shown in FIG. 13. Then, the generation unit 232 generates a common key by combining PQC and QKD as the common key type based on the common key type "PQC+QKD" identified by the No. "1". Note that the generation unit 232 may determine the common key type to be generated based on the "transmission content" including flag information indicating the importance of the communication that can be acquired by the communication device 300 and included in the information output by the communication device 300.

[0125] (Output unit 233) The output unit 233 outputs the common key generated by the generation unit 232 to an external information processing device or the like that has output the supply request for the common key in response to the supply request for the common key received from the external information processing device or the like.

[0126] Specifically, based on the common key supply request output by the communication device 300, the output unit 233 outputs to the communication device 300 a common key (first common key) corresponding to the common key type identified by matching the communication-related information output from the communication device 300 with the information of the generation list stored in the generation list DB222. For example, when the output unit 233 receives from the communication device 300 a common key supply request for encrypting an encrypted communication where the source is "a", the destination is "b", and the content is "c", it outputs to the communication device 300 the "common key (first common key) generated by combining PQC and QKD" corresponding to No. "1" in the encryption method list shown in FIG. 13.

[0127] Also, based on the common key supply request output by the conversion device 100, the output unit 233 outputs to the conversion device 100 a second common key corresponding to the first common key identified by the information for identifying the first common key.

[0128] (Communication device 300) Next, the configuration of the communication device 300 will be described. The communication device 300 is an information processing device that mediates communication between a terminal device or the like and the conversion device 100, and encrypts a predetermined communication such as communication through an electrical line or communication through an optical line into an encrypted communication such as VPN communication according to set conditions. For example, the communication device 300 encrypts a predetermined communication (non-quantum-resistant encrypted communication) using the first common key supplied from the generation device 200 into a first quantum-resistant encrypted communication such as PQC VPN communication. Then, the communication device 300 outputs the first quantum-resistant encrypted communication to the conversion device 100.

[0129] As shown in FIG. 11, the communication device 300 includes a communication unit 310, a storage unit 320, and a control unit 330. Although not shown in FIG. 11, the communication device 300 can be provided with an input unit such as a keyboard or a mouse for receiving inputs such as operations by a user or the like. Also, the communication device 300 can be provided with a display unit such as a display for displaying information regarding the communication status to a user or the like.

[0130] (Communication unit 310) The communication unit 310 performs data communication related to the input of communication from a terminal device or the like and the output of encrypted communication encrypted based on VPN technology. The communication unit 310 is realized by a NIC or the like and controls communication via a telecommunications line such as a LAN or the Internet. Then, the communication unit 310 is connected to a network by wire or wirelessly as necessary and can transmit and receive information bidirectionally.

[0131] (Storage unit 320) The storage unit 320 stores data and programs used for various processes by the control unit 330 and various data obtained by the operation of the control unit 330. Then, the storage unit 320 is realized by a semiconductor memory element such as a RAM or a flash memory, or a storage device such as a hard disk or an optical disk.

[0132] (Control unit 330) The control unit 330 has an internal memory for temporarily storing programs and processing data that define various processing procedures of the communication device 300, and is realized by an electronic circuit such as a CPU or an MPU, or an integrated circuit such as an ASIC or an FPGA. Then, as shown in FIG. 11, the control unit 330 includes a reception unit 331, a conversion unit 332, and an output unit 333.

[0133] (Reception unit 331) The reception unit 331 receives encrypted communication transmitted from an external information processing device or the like. For example, the reception unit 331 can receive non-quantum-resistant encrypted communication or quantum-resistant encrypted communication transmitted from a terminal device or the like via the communication unit 310 described above.

[0134] (Conversion unit 332) The conversion unit 332 performs encryption processing on the received predetermined communication using the first common key supplied in response to the supply request of the common key to the generation device 200.

[0135] Specifically, the conversion unit 332 encrypts the encryption communication in a superimposed manner using the first common key, thereby converting the non-quantum-resistant encrypted communication to be converted into the first quantum-resistant encrypted communication. For example, when the received non-quantum-resistant encrypted communication is a target for conversion to VPN communication, the conversion unit 332 superimposes and performs the encryption process related to VPN without decrypting the encrypted communication, and converts it into a quantum-resistant encrypted communication such as PQC VPN communication.

[0136] In addition, the conversion unit 332 can superimpose and perform the encryption process based on the first quantum-resistant cipher on the communication based on an electric line or the communication based on an optical line. For example, when the received encrypted communication is optical communication, the conversion unit 332 superimposes and performs the encryption process related to optical communication without decrypting the encrypted communication, and converts it into the encrypted communication related to optical communication.

[0137] (Output unit 333) The output unit 333 outputs the encrypted communication to an external information processing device or the like. For example, the output unit 333 can output the first quantum-resistant encrypted communication to the conversion device 100 via the communication unit 310 described above. In addition, the output unit 333 can output the information for identifying the first common key supplied from the generation device 200 to the conversion device 100.

[0138] (Procedure of conversion process) Hereinafter, the procedure of the conversion process of the encryption method of the encrypted communication realized by the conversion system 1 according to the second embodiment will be described. FIG. 14 is a flowchart showing an example of the conversion procedure according to the second embodiment.

[0139] The communication device 300 receives the non-quantum-resistant encrypted communication by the communication device 300 (S201). The communication device 300 outputs a supply request for the common key to the generation device 200 (S202).

[0140] The generation device 200 supplies the generated first common key to the communication device 300 in response to the supply request for the common key from the communication device 300 (S203).

[0141] The communication device 300 converts non-quantum-resistant encrypted communication into first quantum-resistant encrypted communication using the first common key supplied from the generation device 200 (S204). Then, the communication device 300 outputs the encrypted first encrypted communication and information for identifying the first common key supplied from the generation device 200 to the conversion device 100 (S205).

[0142] The determination unit 132 of the conversion device 100 makes a predetermined determination as to whether the received first quantum-resistant encrypted communication is a target for conversion into a second quantum-resistant encrypted communication (S206).

[0143] Here, when it is determined that it is a conversion target (Yes in S207), the conversion device 100 outputs a common key supply request to the generation device 200 (S208).

[0144] The generation device 200 supplies the conversion device 100 with a second common key associated with the first common key in response to the common key supply request from the conversion device 100 (S209).

[0145] The decryption unit 1331 of the conversion device 100 decrypts the first quantum-resistant encrypted communication using the supplied second common key and the common key for decrypting the first quantum-resistant encrypted communication (S210). Next, the encryption unit 1332 encrypts the decrypted encrypted communication into a second quantum-resistant encrypted communication (S211). Then, the output unit 134 outputs the second quantum-resistant encrypted communication with the encryption method converted (S212). Then, the conversion device 100 ends the process.

[0146] On the other hand, when it is determined that it is not a conversion target (No in S207), the conversion device 100 skips the processes from S208 to S212 and ends the process.

[0147] (Effect) From here, the effects of the conversion system 1 according to the second embodiment will be described. The generation device 200 included in the conversion system 1 according to the second embodiment supplies a first common key to the communication device 300 and supplies a second common key to the conversion device 100. The communication device 300 included in the conversion system 1 according to the second embodiment encrypts a predetermined communication into a first quantum-resistant encrypted communication using the first common key supplied from the generation device 200, and outputs the first quantum-resistant encrypted communication to the conversion device 100. The determination unit 132 of the conversion device 100 included in the conversion system 1 according to the second embodiment determines whether the first quantum-resistant encrypted communication output by the communication device 300 is a target for conversion into a second quantum-resistant encrypted communication. Then, the conversion unit 133 of the conversion device 100 performs a conversion process on the first quantum-resistant encrypted communication determined to be a conversion target by the determination unit 132 into a second quantum-resistant encrypted communication using the second common key.

[0148] Therefore, according to the conversion system 1 of the present embodiment, regarding the communication between the terminal device and the conversion device 100, even in a situation where communications using different encryption methods such as VPN communication are mixed, it is possible to convert a non-quantum-resistant encrypted communication into a quantum-resistant encrypted communication. That is, in addition to a simple configuration such as terminal device (source) - conversion device 100 - terminal device (destination), the conversion system 1 includes a communication device or the like in the middle of the path, and even when communication encrypted by a different encryption method is performed, the communication can be appropriately converted into a quantum-resistant encrypted communication.

[0149] The communication device 300 performs an encryption process based on the first quantum-resistant encryption on communication based on an electrical line or communication based on an optical line in a superimposed manner. In this way, the communication device 300 can perform an encryption process in a superimposed manner on the already encrypted communication without decrypting the encrypted communication. Therefore, the communication device 300 has the effect of efficiently enabling the first quantum-resistant encrypted communication.

[0150] The generation device 200 combines an encryption method associated with a predetermined communication such as encrypted communication received by the communication device 300, including the source, destination, communication content, etc., using the MFS technology, which is a technology related to the IOWN technology, to generate a first common key and a second common key. In this way, based on information related to the communication such as the destination, source, and communication content included in the predetermined communication, the generation device 200 can flexibly combine encryption methods to generate a common key. Therefore, the generation device 200 can support encryption methods for a wide range of encrypted communications.

[0151] <Modification Example> A modification example realized by the conversion system 1 according to the present embodiment is described below.

[0152] (Data, etc.) The encrypted communication, quantum-resistant encrypted communication, non-quantum-resistant encrypted communication, destination, source, transmission content, conversion execution, encryption method, common key type, determination conditions for whether to perform conversion of the encryption method, conversion conditions for the encryption method, information related to the communication included in the encrypted communication, names of the functional parts of the conversion device 100, the generation device 200, and the communication device 300, steps, processes, names of steps or processes, etc. used in the description of the above embodiment are merely examples and can be arbitrarily changed.

[0153] In addition, the conversion device 100 and the communication device 300 can obtain information that can be obtained by known technologies such as packet capture as the "communication content" included in the above-described encrypted communication. Note that the conversion device 100 and the communication device 300 can use methods for obtaining information from communication without limitation, other than the above-described packet capture.

[0154] In addition, the above-described encrypted communication may include other forms of communication such as unencrypted communication in addition to non-quantum-resistant encrypted communication.

[0155] Also, in the description of the encryption list stored in the encryption method list DB121 using FIG. 8, the sender, recipient, and transmission content were described using the letters from "A" to "I". However, this alphabet is merely a simplified notation for the item content, and the actually stored content is not limited to this. Also, in the description of the encryption list stored in the generation list DB222 using FIG. 13, the sender, recipient, and transmission content were described using the letters from "a" to "i". However, this alphabet is merely a simplified notation for the item content, and the actually stored content is not limited to this.

[0156] (Data governance technology, etc.) The conversion device 100 according to this embodiment was described as performing decryption and re-encryption processing of encrypted communication using the data sandbox technology as a data governance technology. However, the data governance technology used by the conversion device 100 is not limited to the data sandbox technology, and for example, secure computing technology may be used.

[0157] Specifically, the conversion device 100 can use multi-party computing based on secret sharing compliant with ISO (International Organization for Standardization) standards as an encryption mechanism. Here, the multi-party computing refers to a technology that realizes data processing while keeping the data encrypted as fragments called shares of secret sharing by performing operations and exchanges of encrypted data by multiple servers according to a predetermined procedure.

[0158] (Processing for encrypted communication determined not to be a conversion target) In this embodiment, it has been described that the determination unit 132 of the conversion device 100 determines whether the received encrypted communication is a target for conversion to post-quantum encrypted communication. Here, when it is determined by the determination unit 132 that it is "not a target for conversion to post-quantum encrypted communication", the conversion device 100 may output the received encrypted communication to the output target information processing device or the like without converting the encryption method. In addition, when it is determined that it is "not a target for conversion to post-quantum encrypted communication", the conversion device 100 may reject the encrypted communication and output to the transmission source of the encrypted communication that the encryption method is not an outputtable encryption method to the output target information processing device or the like. In this way, the conversion device 100 can realize the efficiency of processing by performing conversion processing only on the encrypted communication that is a conversion target such as being convertible based on the determination result by the determination unit 132.

[0159] (Configuration of the generation device 200) In the second embodiment, the generation device 200 that supplies the first common key to the communication device 300 and the generation device 200 that supplies the second common key to the conversion device 100 have been described as different devices, but it is not limited to this. For example, the generation device 200a and the generation device 200b may function as an integrated generation device 200 by cloud computing or the like.

[0160] (Generation of the common key by the generation device 200) In the second embodiment, it has been described that the generation device 200 supplies the pre-generated and stored common key based on the supply requests of the common keys by the conversion device 100 and the communication device 300. However, without being limited to this, the generation device 200 can generate a common key. For example, the generation device 200 can generate a common key (the first common key and the second common key) in response to a common key generation request by the communication device 300 and supply it to the conversion device 100 and the communication device 300.

[0161] (Flowchart, etc.) Each step in a flowchart or the like may be implemented by being swapped within a range without contradiction, or there may be steps that are not implemented. Also, connectives such as "next", "subsequently", "furthermore", "at this time", and "at this moment" in the description of the flowchart do not limit the order or timing of the execution of the processes in the flowchart.

[0162] (System) Regarding the processing procedures, control procedures, specific names, and information including various data and parameters shown in the above documents and drawings, they can be arbitrarily changed except when specifically noted.

[0163] Also, each component of each illustrated device is a functional concept and does not necessarily have to be physically configured as shown in the figure. That is, the specific form of the distribution and integration of each device is not limited to that shown in the figure. In other words, all or part of it can be functionally or physically distributed and integrated in any unit according to various loads, usage situations, etc., such as cloud computing.

[0164] <Hardware Configuration> Each component of each illustrated device is a functional concept and does not necessarily have to be physically configured as shown in the figure. That is, the specific form of the distribution and integration of each device is not limited to that shown in the figure, and all or part of it can be functionally or physically distributed and integrated in any unit according to various loads, usage situations, etc. Furthermore, each processing function performed by each device can be realized in whole or in any part by a CPU and a program analyzed and executed by the CPU, or can be realized as hardware by wired logic.

[0165] Also, among the processes described in this embodiment, all or part of the processes described as being automatically performed can be manually performed by a known method. In addition, regarding the processing procedures, control procedures, specific names, and information including various data and parameters shown in the drawings, they can be arbitrarily changed except when specifically noted.

[0166] <Program> As one embodiment, various devices constituting the conversion system 1 can be implemented by installing a conversion program as package software or online software on a desired computer. For example, by causing the above-described conversion program to be executed on an information processing device, it can function as various devices constituting the conversion system 1. The information processing device mentioned here includes desktop or notebook personal computers. In addition, other information processing devices include mobile communication terminals such as smartphones and mobile phones, and further slate terminals such as PDAs (Personal Digital Assistants) are included in this category.

[0167] FIG. 15 is a diagram showing an example of a computer that executes the conversion process according to this embodiment. The computer 1000 has, for example, a memory 1010 and a CPU 1020. The computer 1000 also has a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0168] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System), for example. The hard disk drive interface 1030 is connected to the hard disk drive 1090. The disk drive interface 1040 is connected to the disk drive 1100. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100, for example. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.

[0169] The hard disk drive 1090 stores, for example, an OS (Operating System) 1091, application programs 1092, program modules 1093, and program data 1094. That is, the programs that define the respective processes of the various devices constituting the conversion system 1 are implemented as program modules 1093 in which computer-executable code is described. The program modules 1093 are stored, for example, in the hard disk drive 1090. For example, program modules 1093 for executing the same processes as the functional configurations in the various devices constituting the conversion system 1 are stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced by an SSD (Solid State Drive).

[0170] Also, the setting data used in the processes of the above-described embodiments is stored as program data 1094, for example, in the memory 1010 or the hard disk drive 1090. Then, the CPU 1020 reads out the program modules 1093 and program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as needed, and executes the processes of the above-described embodiments.

[0171] Note that the program modules 1093 and program data 1094 are not limited to being stored in the hard disk drive 1090, and may be stored, for example, in a removable storage medium and read by the CPU 1020 via a disk drive 1100 or the like. Alternatively, the program modules 1093 and program data 1094 may be stored in another computer connected via a network (LAN, WAN (Wide Area Network), etc.). Then, the program modules 1093 and program data 1094 may be read by the CPU 1020 from the other computer via the network interface 1070.

[0172] <Others> Although the present embodiment has been described above, the present embodiment is not limited by the description and drawings that form a part of the disclosure. That is, all other embodiments, examples, operation techniques, etc. made by those skilled in the art based on the present embodiment are included in the scope of the present embodiment.

Explanation of Reference Numerals

[0173] 1 Conversion system 10 Data sandbox providing system 11 MFS providing system 100 Converter 110, 210, 310 Communication unit 120, 220, 320 Storage unit 121 Encryption method list DB 130, 230, 330 Control unit 131, 231, 331 Reception unit 132 Judgment unit 133 Conversion unit 1331 Decryption unit 1332 Encryption unit 134, 233, 333 Output unit 200, 200a, 200b Generation device 221 Generation key information DB 222 Generation list DB 232 Generation unit 300 Communication device 332 Conversion unit

Claims

1. a determination unit that determines whether or not encrypted communication is to be converted into encrypted communication based on post-quantum cryptography; a conversion unit that converts the encrypted communication determined by the determination unit to be the conversion target into encrypted communication based on the post-quantum cryptography; A conversion device comprising:

2. The determination unit is determining that the encrypted communication satisfies a determination condition in which the presence or absence of conversion of the encryption method related to the encrypted communication is associated with at least one of a source, a destination, and a communication content, as a target for conversion to encrypted communication based on the post-quantum cryptography; 2. The conversion device according to claim 1 .

3. The conversion unit is decrypting the encrypted communication determined to be the conversion target by the determination unit into plaintext communication; when information included in the accepted encrypted communication satisfies a condition specifying a preset encryption method, encrypting the plaintext communication decrypted using the encryption method associated with the condition into encrypted communication based on the post-quantum cryptography; 2. The conversion device according to claim 1 .

4. The conversion unit is performing encryption using information in which at least one of a source, a destination, and a communication content, which is included in the encrypted communication, is associated with an encryption method based on the post-quantum cryptography, as a condition for specifying the encryption method; 4. The conversion device according to claim 1 or 3.

5. The conversion unit is performing the transformation in an isolated and secure computational domain; 3. The conversion device according to claim 1 or 2.

6. A conversion system including a generating device that generates a common key, a communication device that controls a predetermined communication, and a conversion device that converts encrypted communication, The generating device comprises: providing the generated first common key to the communication device; providing the generated second common key to the conversion device; The communication device includes: encrypting the predetermined communication into encrypted communication based on a first post-quantum cryptography using the first common key supplied from the generating device; outputting encrypted communication based on the first post-quantum cryptography to the conversion device; The conversion device comprises: a determination unit that determines whether or not the encrypted communication based on the first post-quantum cipher output by the communication device is to be converted into encrypted communication based on a second post-quantum cipher; a conversion unit that performs a conversion process, using the second common key, on the encrypted communication based on the first quantum-postive cipher, which has been determined by the determination unit to be the conversion target, into encrypted communication based on the second quantum-postive cipher; A conversion system comprising:

7. The communication device includes: performing encryption processing based on the first post-quantum cryptography in a superimposed manner on communication based on an electric line or communication based on an optical line; 7. The conversion system according to claim 6.

8. The generating device comprises: generating the first common key and the second common key by combining one or more encryption methods associated with at least one of a source of the predetermined communication, a destination of the predetermined communication, and a communication content of the predetermined communication; 7. The conversion system according to claim 6.

9. A conversion method to be executed by a conversion device, a determination step of determining whether or not the encrypted communication is to be converted into encrypted communication based on post-quantum cryptography; a conversion step of converting the encrypted communication determined to be the conversion target in the determination step into encrypted communication based on the post-quantum cryptography; A method for converting, comprising:

10. a determination step of determining whether or not the encrypted communication is to be converted into encrypted communication based on post-quantum cryptography; a conversion step of converting the encrypted communication determined to be the conversion target in the determination step into encrypted communication based on the post-quantum cryptography; A conversion program characterized by causing a computer to execute the above.

Citation Information

Patent Citations

  • Enciphering / deciphering device and cipher system changing method

    JP2002281016A