Quantum cryptographic communication system, quantum cryptographic communication method, and program

The quantum cryptography communication system addresses the issue of user confidentiality by generating and managing keys within a cloud system, ensuring secure encryption and storage of confidential information, thereby enhancing user data privacy.

JP2025124298APending Publication Date: 2025-08-26TOPPAN HOLDINGS INC +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024020250
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-14
Publication Date
2025-08-26

AI Technical Summary

Technical Problem

In existing quantum cryptography communication systems, user confidential information managed by a cloud system can be decrypted by the operator, compromising user confidentiality.

Method used

A quantum cryptography communication system that generates a first common key for users via a cloud system with a quantum cryptography network, allowing users to encrypt and store confidential information securely, using a third common key generated between user and operator systems, ensuring confidentiality through quantum cryptography communication.

Benefits of technology

Enhances the confidentiality of users' confidential information managed in a cloud system based on a QKD network, preventing unauthorized access by the cloud system operator.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025124298000001_ABST
    Figure 2025124298000001_ABST
Patent Text Reader

Abstract

To provide a quantum cryptographic communication system, a quantum cryptographic communication method, and a program, capable of enhancing confidentiality of a user's confidential information managed in a cloud system based on a QKD network.SOLUTION: A quantum cryptographic communication system comprises: a quantum cryptographic communication processing unit that using a cloud system having a quantum cryptographic communication network for connecting a plurality of enterprise systems using quantum cryptographic communication, generates a first common key to be provided for a user via a predetermined medium and, in order that the user uses the user's confidential information managed by a first enterprise to utilize a service provided by a second enterprise, receives the confidential information encrypted using a third common key generated on the basis of the first common key provided from a user terminal and a second common key generated between the user terminal and a first enterprise system from the first enterprise system; and a storage unit for storing the received confidential information using the cloud system.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a quantum cryptography communication system, a quantum cryptography communication method, and a program. [Background technology]

[0002] Conventionally, encryption technology has been used to ensure secure communications in communication environments such as the Internet. In communications using IC (Integrated Circuit) cards for online identity authentication and payment, the use of encryption keys stored on the IC cards has enabled secure use.

[0003] However, if quantum computers become practical in the future, there is a risk that the cryptographic technologies that support secure communications will be compromised. Therefore, various cryptographic technologies for quantum computers have been proposed. Examples include post-quantum cryptography (PQC), which applies mathematical problems that are difficult even for quantum computers to solve, quantum key distribution (QKD), which uses photons with quantum mechanical properties to share a cryptographic key between two parties as a countermeasure against data harvesting attacks, and one-time pad (OTP), which encrypts data using a key shared by QKD only once. Communication that combines QKD and OTP is generally called quantum cryptography, and is information-theoretically secure.

[0004] In recent years, quantum cryptography communication services including the provision of quantum keys have been provided by cloud systems. For example, Patent Document 1 below discloses a technology in which a user who is a data sender and a user who is a data receiver receive a quantum key from a cloud system and perform quantum cryptography communication. In this technology, the user who is a sender obtains a quantum key from the cloud system, encrypts data with the obtained quantum key, and transmits the data to the user who is a receiver. The user who is a receiver also obtains a quantum key from the cloud system and decrypts the encrypted data. Among users of a cloud system based on a QKD network such as that disclosed in Patent Document 1 below, there are users who wish to send and receive confidential information to and from other users, and to store, view, update, etc., confidential information over the QKD network. These users wish to exchange confidential information only with other users and to store the confidential information safely without disclosing it to the operator of the cloud system. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Publication No. 2023-40843 Summary of the Invention [Problem to be solved by the invention]

[0006] However, in the technology disclosed in Patent Document 1, the quantum key used by the user to encrypt confidential information is managed by the operator of the cloud system. Therefore, even if the user's confidential information can be managed on the QKD network, the operator of the cloud system can decrypt the user's confidential information at any time using the quantum key managed by the cloud system operator, and the user's confidential information can essentially be viewed.

[0007] In view of the above-mentioned problems, an object of the present invention is to provide a quantum cryptography communication system, a quantum cryptography communication method, and a program that can increase the confidentiality of users' confidential information managed in a cloud system based on a QKD network. [Means for solving the problem]

[0008] In order to solve the above-mentioned problems, one embodiment of the quantum cryptography communication system of the present invention is a quantum cryptography communication system comprising: a quantum cryptography communication processing unit that generates a first common key to be provided to a user via a predetermined medium in a cloud system having a quantum cryptography communication network that connects multiple operator systems via quantum cryptography communication; and receives from the first operator system the confidential information encrypted with a third common key generated based on the first common key provided from the user terminal and a second common key generated between the user terminal and the first operator system, so that the user can use a service provided by a second operator using the user's confidential information managed by the first operator; and a memory unit that stores the received confidential information in the cloud system.

[0009] A quantum cryptography communication method according to one embodiment of the present invention is a quantum cryptography communication method executed by a computer, the method including: a quantum cryptography processing step of generating a first common key to be provided to a user via a predetermined medium in a cloud system having a quantum cryptography communication network connecting multiple operator systems via quantum cryptography communication; receiving, from the first operator system, the confidential information encrypted with a third common key generated based on the first common key provided from the user terminal and a second common key generated between the user terminal and the first operator system, so that the user can use a service provided by a second operator using the user's confidential information managed by the first operator; and a storage step of storing the received confidential information in the cloud system.

[0010] A program according to one embodiment of the present invention is a program for causing a computer to function as a quantum cryptography processing means in a cloud system having a quantum cryptography communication network connecting multiple operator systems via quantum cryptography communication, which generates a first common key to be provided to a user via a predetermined medium, and receives from the first operator system the confidential information encrypted with a third common key generated based on the first common key provided from the user terminal and a second common key generated between the user terminal and the first operator system, so that the user can use a service provided by a second operator using the user's confidential information managed by the first operator, and a storage means for storing the received confidential information in the cloud system. [Effects of the Invention]

[0011] According to the present invention, it is possible to improve the confidentiality of users' confidential information managed in a cloud system based on a QKD network. [Brief explanation of the drawings]

[0012] [Figure 1] 1 is a diagram illustrating an overview of a quantum cryptography communication service according to an embodiment of the present invention. [Figure 2] 1 is a diagram illustrating an example of the configuration of a quantum cryptography communication system according to an embodiment of the present invention. [Figure 3] FIG. 2 is a diagram illustrating an example of a functional configuration of a user terminal according to the present embodiment. [Figure 4] FIG. 2 is a diagram illustrating an example of a functional configuration of a first business operator system according to the present embodiment. [Figure 5] FIG. 2 is a diagram illustrating an example of a functional configuration of a second business operator system according to the present embodiment. [Figure 6] FIG. 1 is a diagram illustrating an example of the functional configuration of a quantum secure cloud system according to an embodiment of the present invention. [Figure 7] FIG. 2 is a diagram illustrating an example of a functional configuration of the card issuing system according to the present embodiment. [Figure 8]FIG. 10 is a sequence diagram showing an example of a processing flow in a registration phase according to the present embodiment. [Figure 9] FIG. 10 is a sequence diagram showing an example of a processing flow in a card issuance phase according to the present embodiment. [Figure 10] FIG. 10 is a sequence diagram showing an example of a processing flow in a card usage phase according to the present embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0013] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.

[0014] <1. Overview of quantum cryptography communication services> An overview of the quantum cryptography communication service according to this embodiment will be described with reference to Fig. 1. Fig. 1 is a diagram showing an overview of the quantum cryptography communication service according to this embodiment. A quantum cryptography communication service is a service for securely sharing information about a user between operators through communication using quantum cryptography technology. Figure 1 shows an example of a quantum cryptography communication service SA in which confidential information of a user is shared between operators. In the example shown in Figure 1, a user US uses the confidential information of the user managed by a first operator J1 to use a service provided by a second operator J2.

[0015] The first business entity J1 is an entity that provides a service for performing identity authentication using a medium such as an IC (Integrated Circuit) card. The first business entity J1 is, for example, a financial institution, a medical institution, or a government agency. The IC card is, for example, a cash card, a credit card, or a personal identification number card (My Number card), and is an example of a predetermined medium.

[0016] Here, the flow when a user US uses the quantum cryptography communication service SA will be explained. First, the user US provides confidential user information to the first business entity J1 through encrypted communication (step S1). The user information includes, for example, the user's basic information (name, date of birth, address, contact information, etc.), identification, biometric information, etc. The encrypted communication in step S1 is performed, for example, by SSL (Secure Sockets Layer) / TLS (Transport Layer Security) using PQC (Post-Quantum Cryptography).

[0017] The first business operator J1 issues the user US an IC card C storing key information K (step S2). The key information K is a common key used to encrypt confidential information.

[0018] The first entity J1 stores the user's confidential information encrypted using the key information K in the quantum secure cloud CS (step S3). The quantum secure cloud CS is a cloud service based on a quantum key distribution (QKD) network. The first entity J1 transmits the user's confidential information to the quantum secure cloud CS by quantum cryptography communication via the QKD network (quantum cryptography communication network), and stores the information in a database of the quantum secure cloud CS.

[0019] The user provides the second service provider J2, which uses the service, with the key information K used to encrypt the confidential information stored in the quantum secure cloud CS (step S4). At this time, the user provides the key information K to the second service provider J2 through encrypted communication over the Internet. Note that the encrypted communication in step S4 is performed, for example, by SSL / TLS using PQC.

[0020] The second entity J2 acquires confidential information necessary for the user US to use the service from the quantum secure cloud CS (step S5). The second entity J2 can decrypt the acquired confidential information using the key information K provided by the user in step S4. Note that the encrypted communication in step S5 is performed, for example, by SSL / TLS using PQC.

[0021] <2. Configuration of quantum cryptography communication system> The outline of the quantum cryptography communication service according to this embodiment has been described above. Next, the configuration of the quantum cryptography communication system according to this embodiment will be described with reference to Fig. 2. Fig. 2 is a diagram showing an example of the configuration of the quantum cryptography communication system according to this embodiment. The quantum cryptography communication system 1 shown in FIG. 2 is a system for operating the quantum cryptography communication service SA the outline of which has been explained with reference to FIG.

[0022] As shown in FIG. 2, the quantum cryptography communication system 1 includes a user terminal 10, a first operator system 20, a second operator system 30, an external operator system 40, a quantum secure cloud system 50, a J-LIS system 60, a credit system 70, a card issuing system 80, and a factory issuing system 90. The network NW may be configured to transmit and receive information using, for example, a LAN (Local Area Network), a WAN (Wide Area Network), a telephone network (mobile phone network, fixed telephone network, etc.), a regional IP (Internet Protocol) network, the Internet, a QKD network, etc.

[0023] (1) User terminal 10 The user terminal 10 is a terminal that a user operates to use the quantum cryptography communication service SA. The user terminal 10 is, for example, a smartphone, a tablet terminal, a PC (Personal Computer), etc. The user terminal 10 is communicably connected to a first operator system 20 and a second operator system 30 via a network NW.

[0024] (2) First operator system 20 The first business operator system 20 is a system used for user services provided by the first business operator. The first business operator system 20 is configured by, for example, a PC, one or more servers (e.g., cloud servers), a combination of a PC and a server, etc. The first business operator system 20 is communicably connected to a user terminal 10, a second business operator system 30, an external business operator system 40, a quantum secure cloud system 50, a card issuing system 80, and a factory issuing system 90 via a network NW.

[0025] (3) Second operator system 30 The second provider system 30 is a system used for user services provided by a second provider. The second provider system 30 is configured by, for example, a PC, one or more servers (e.g., cloud servers), a combination of a PC and a server, etc. The second provider system 30 is communicably connected to the user terminal 10, the first provider system 20, and the quantum secure cloud system 50 via a network NW.

[0026] (4) External business system 40 The external business operator system 40 is a system used for a service for a first business operator provided by an external business operator. The external business operator system 40 is configured, for example, by a PC, one or more servers (e.g., cloud servers), a combination of a PC and a server, etc. The external business operator system 40 is communicatively connected to the first business operator system 20, the quantum secure cloud system 50, the J-LIS system 60, and the credit system 70 via a network NW. The service for the first business is, for example, a service that performs identity verification, credit verification, data verification, etc. of a user who uses a service provided by the first business.

[0027] (5) Quantum Secure Cloud System 50 The quantum secure cloud system 50 is a system that stores confidential information of users and is an example of a cloud system. The quantum secure cloud system 50 is configured, for example, by a PC, one or more servers (e.g., cloud servers), or a combination of a PC and a server. The quantum secure cloud system 50 is communicably connected to a first business operator system 20, a second business operator system 30, and a card issuing system 80 via a network NW.

[0028] (6) J-LIS System 60 The J-LIS system 60 is a system that provides public personal authentication services and is operated by the Japan Agency for Local Authority Information Systems (J-LIS). The J-LIS system 60 is configured by, for example, a PC, one or more servers (for example, cloud servers), a combination of a PC and a server, etc. The J-LIS system 60 is communicably connected to the external business system 40 via a network NW.

[0029] (7) Credit System 70 The credit system 70 is a system that provides a credit examination service. The credit system 70 is configured, for example, by a PC, one or more servers (e.g., cloud servers), or a combination of a PC and a server. The credit system 70 is communicably connected to the external business system 40 via a network NW.

[0030] (8) Card issuing system 80 The card issuing system 80 is a system for managing information required for issuing IC cards. The card issuing system 80 is configured, for example, by a PC, one or more servers (e.g., cloud servers), or a combination of a PC and a server. The card issuing system 80 is communicably connected to the first business operator system 20, the quantum secure cloud system 50, and the factory issuing system 90 via the network NW.

[0031] (9) Factory Issuance System 90 The factory-issuing system 90 is a system for issuing IC cards in a factory. The factory-issuing system 90 is configured, for example, by a PC, one or more servers (e.g., cloud servers), or a combination of a PC and a server. The factory-issuing system 90 is communicably connected to the first business operator system 20 and the card issuing system 80 via a network NW.

[0032] <3. Functional configuration of user terminal> The configuration of the quantum cryptography communication system 1 according to this embodiment has been described above. Next, the functional configuration of the user terminal 10 according to this embodiment will be described with reference to Fig. 3. Fig. 3 is a diagram showing an example of the functional configuration of the user terminal 10 according to this embodiment. As shown in FIG. 3, the user terminal 10 includes a communication unit 110, an input unit 120, a reading unit 130, a storage unit 140, a control unit 150, and an output unit 160.

[0033] (1) Communications Unit 110 The communication unit 110 has a function of transmitting and receiving various information. The communication unit 110 transmits and receives various information to and from, for example, the first business operator system 20 and the second business operator system 30. The communication unit 110 communicates with the first business operator system 20 and the second business operator system 30 by SSL / TLS using PQC.

[0034] (2) Input unit 120 The input unit 120 has a function of receiving input. The input unit 120 is configured by, for example, an input device that the user terminal 10 has as hardware, such as a button, a touch panel, a microphone, a mouse, a keyboard, and the like.

[0035] (3) Reading unit 130 The reading unit 130 has a function of acquiring user information stored in an IC card. The user information is written, for example, to an IC chip provided on a credit card. In this case, the reading unit 130 acquires the user information from the IC chip. Note that the method by which the reading unit 130 acquires the user information from the IC chip is not particularly limited. For example, the reading unit 130 acquires the user information read from the IC chip by a reader connected to the user terminal 10. If the user terminal 10 has an NFC (Near Field Communication) function, the reading unit 130 acquires the user information read from the IC chip by NFC.

[0036] (4) Storage section 140 The storage unit 140 has a function of storing various types of information. The function of the storage unit 140 is configured by a storage medium provided as hardware in the user terminal 10, such as a hard disk drive (HDD), a solid state drive (SSD), a flash memory, an electrically erasable programmable read-only memory (EEPROM), a random access read / write memory (RAM), a read-only memory (ROM), or any combination of these storage media.

[0037] (5) Control unit 150 The control unit 150 has a function of controlling the overall operation of the user terminal 10. The function of the control unit 150 is realized, for example, by causing a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit) provided as hardware in the user terminal 10 to execute a program. As shown in FIG. 3, the control unit 150 includes a data acquisition unit 151, a data processing unit 152, a key generation unit 153, an encryption processing unit 154, and an output control unit 155.

[0038] (5-1) Data Acquisition Unit 151 The data acquisition unit 151 has a function of acquiring various types of information. For example, the data acquisition unit 151 acquires information received by the communication unit 110.

[0039] (5-2) Data processing unit 152 The data processing unit 152 has a function of performing processing related to various information. For example, the data processing unit 152 performs processing based on the information acquired by the data acquisition unit 151.

[0040] (5-3) Key generation unit 153 The key generation unit 153 has a function of generating key information. For example, the key generation unit 153 generates a common key used to encrypt confidential information.

[0041] (5-4) Encryption processing unit 154 The encryption processing unit 154 has a function of encrypting various types of information. For example, the encryption processing unit 154 encrypts confidential information of a user and information related to encryption of the confidential information.

[0042] (5-5) Output control unit 155 The output control unit 155 has a function of controlling the output of various information. For example, the output control unit 155 causes the output unit 160 to display information received by the communication unit 110.

[0043] (6) Output unit 160 The output unit 160 has a function of outputting various types of information. The output unit 160 is configured, for example, by an output device provided as hardware in the user terminal 10, such as a display device or a touch screen (touch panel), or an audio output device such as a speaker.

[0044] <4. Functional configuration of the first operator system> The functional configuration of the user terminal 10 according to this embodiment has been described above. Next, the functional configuration of the first business operator system 20 according to this embodiment will be described with reference to Fig. 4. Fig. 4 is a diagram showing an example of the functional configuration of the first business operator system 20 according to this embodiment. As shown in FIG. 4, the first operator system 20 includes a communication unit 210, a quantum cryptography communication processing unit 220, a storage unit 230, a control unit 240, and an output unit 250.

[0045] (1) Communications Unit 210 The communication unit 210 has a function of transmitting and receiving various information. The communication unit 210 transmits and receives various information to and from the user terminal 10, the second operator system 30, the quantum secure cloud system 50, and the factory-issued system 90, for example, by SSL / TLS communication using PQC.

[0046] (2) Quantum cryptography communication processing unit 220 The quantum cryptography communication processing unit 220 has a function of transmitting and receiving various types of information. The quantum cryptography communication processing unit 220 transmits and receives various types of information to and from the external business system 40, the quantum secure cloud system 50, and the card issuing system 80, for example, by quantum cryptography communication via a QKD network.

[0047] (3) Storage section 230 The storage unit 230 has a function of storing various types of information. The function of the storage unit 230 is realized by a storage medium provided as hardware in the first operator system 20, such as an HDD, SSD, flash memory, EEPROM, RAM, ROM, or any combination of these storage media.

[0048] (4) Control unit 240 The control unit 240 has a function of controlling the overall operation of the first operator system 20. The control unit 240 is realized, for example, by causing a CPU or a GPU provided as hardware in the first operator system 20 to execute a program. As shown in FIG. 4, the control unit 240 includes a service processing unit 241, an ID management unit 242, a linking processing unit 243, an encrypted communication processing unit 244, a verification request unit 245, and an output control unit 246.

[0049] (4-1) Service processing unit 241 The service processing unit 241 has a function of performing processing related to a service. For example, the service processing unit 241 performs processing for a user to access a service, processing for a user to register for a service, and the like.

[0050] (4-2) ID management section 242 The ID management unit 242 has a function of performing processes related to ID management. For example, the ID management unit 242 assigns a user ID to a user who has registered for the service.

[0051] (4-3) Linking processing unit 243 The association processing unit 243 has a function of associating various pieces of information. For example, the association processing unit 243 associates various pieces of information about a user with a user ID issued by the ID management unit 242.

[0052] (4-4) Encryption communication processing unit 244 The encrypted communication processing unit 244 has a function of performing processing related to encrypted communication, for example, the encrypted communication processing unit 244 performs processing related to encryption in communication using SSL / TLS.

[0053] (4-5) Verification Request Department 245 The verification request unit 245 has a function of requesting various verifications. For example, the verification request unit 245 requests the external business system 40 to verify the identity of the user, check the creditworthiness, and the like.

[0054] (4-6) Output control unit 246 The output control unit 246 has a function of controlling the output of various information. For example, the output control unit 246 causes the output unit 250 to display information received by the communication unit 210 or the quantum cryptography communication processing unit 220.

[0055] (5) Output section 250 The output unit 250 has a function of outputting various information. The output unit 250 is configured by, for example, an output device provided as hardware in the first business operator system 20, such as a display device or a touch screen (touch panel), or an audio output device such as a speaker.

[0056] <5. Functional configuration of the second operator system> The functional configuration of the first business operator system 20 according to this embodiment has been described above. Next, the functional configuration of the second business operator system 30 according to this embodiment will be described with reference to Fig. 5. Fig. 5 is a diagram showing an example of the functional configuration of the second business operator system 30 according to this embodiment. As shown in FIG. 5, the second operator system 30 includes a communication unit 310, a storage unit 320, a control unit 330, and an output unit 340.

[0057] (1) Communications unit 310 The communication unit 310 has a function of transmitting and receiving various information. The communication unit 310 transmits and receives various information to and from the user terminal 10, the first operator system 20, and the quantum secure cloud system 50, for example, by SSL / TLS communication using PQC.

[0058] (2) Storage section 320 The storage unit 320 has a function of storing various types of information. The function of the storage unit 320 is realized by a storage medium provided as hardware in the second operator system 30, such as an HDD, SSD, flash memory, EEPROM, RAM, ROM, or any combination of these storage media.

[0059] (3) Control unit 330 The control unit 330 has a function of controlling the overall operation of the second operator system 30. The control unit 330 is realized, for example, by causing a CPU or a GPU provided as hardware in the second operator system 30 to execute a program. As shown in FIG. 5, the control unit 330 includes a data acquisition unit 331, an encrypted communication processing unit 332, a decryption processing unit 333, and an output control unit 334.

[0060] (3-1) Data Acquisition Unit 331 The data acquisition unit 331 has a function of acquiring various types of information. For example, the data acquisition unit 331 acquires information received by the communication unit 310.

[0061] (3-2) Encryption communication processing unit 332 The encrypted communication processing unit 332 has a function of performing processing related to encrypted communication, for example, the encrypted communication processing unit 332 performs processing related to encryption in communication using SSL / TLS.

[0062] (3-3) Decryption Processing Unit 333 The decryption processing unit 333 has a function of performing decryption processing. For example, the decryption processing unit 333 decrypts encrypted information received by the communication unit 310 using key information.

[0063] (3-4) Output control unit 334 The output control unit 334 has a function of controlling the output of various information. For example, the output control unit 334 causes the output unit 340 to display information received by the communication unit 310.

[0064] (4) Output unit 340 The output unit 340 has a function of outputting various information. The output unit 340 is configured by, for example, an output device provided as hardware in the second business operator system 30, such as a display device or a touch screen (touch panel), or an audio output device such as a speaker.

[0065] <6. Functional configuration of quantum secure cloud system> The functional configuration of the second operator system 30 according to this embodiment has been described above. Next, the functional configuration of the quantum secure cloud system 50 according to this embodiment will be described with reference to Fig. 6. Fig. 6 is a diagram showing an example of the functional configuration of the quantum secure cloud system 50 according to this embodiment. As shown in FIG. 6, the quantum secure cloud system 50 includes a communication unit 510, a quantum-safe public key authentication unit 520, a quantum cryptography communication processing unit 530, and a secret sharing storage server 540.

[0066] (1) Communications Unit 510 The communication unit 510 has a function of transmitting and receiving various information. The communication unit 510 transmits and receives various information to and from the first business operator system 20 and the second business operator system 30, for example, by SSL / TLS communication using PQC. The communication unit 510 also transmits and receives various information to and from the card issuing system 80, for example, by classical communication. The communication unit 510 also transmits and receives various information to and from the communication unit 550 of the secret sharing storage server 540, which will be described later.

[0067] (2) Quantum-resistant public key authentication unit 520 The quantum-safe public key authentication unit 520 has functions to issue public key certificates, verify public key certificates and signatures, etc. The quantum-safe public key authentication unit 520 is, for example, a private Certificate Authority (CA).

[0068] (3) Quantum cryptography communication processing unit 530 The quantum cryptography communication processing unit 530 has a function of transmitting and receiving various types of information. The quantum cryptography communication processing unit 530 transmits and receives various types of information to and from the first business operator system 20 and the card issuing system 80, for example, by quantum cryptography communication via a QKD network.

[0069] (4) Secret sharing storage server 540 The secret sharing storage server 540 is a server that secretly shares and stores confidential information. As shown in Fig. 6, the secret sharing storage server 540 includes a communication unit 550, a secret sharing processing unit 560, a quantum cryptography communication processing unit 570, and a storage unit 580.

[0070] (4-1) Communications Department 550 The communication unit 550 has a function of transmitting and receiving various types of information. For example, the communication unit 550 transmits and receives various types of information to and from the communication unit 510.

[0071] (4-2) Secret sharing processing unit 560 The secret sharing processing unit 560 has a function of performing processing for secretly sharing and storing various types of information. For example, the secret sharing processing unit 560 performs secret sharing on the confidential information received by the quantum cryptography communication processing unit 530. In addition, when the fragments of the secret shared confidential information are managed in secret sharing DBs at different locations, it is preferable from the viewpoint of security to transmit each fragment to the secret sharing DB at each location by quantum cryptography communication. Therefore, the secret sharing processing unit 560 transmits the fragments of the secret shared confidential information to the secret sharing DB at each location by quantum cryptography communication via the quantum cryptography communication processing unit 570, and stores them in the secret sharing DB at each location.

[0072] (4-3) Quantum cryptography communication processing unit 570 The quantum cryptography communication processing unit 570 has a function of transmitting and receiving various types of information. For example, the quantum cryptography communication processing unit 570 transmits and receives information between the secret sharing processing unit 560 and the secret sharing DB 581 of the storage unit 580 by quantum cryptography communication. This enables the quantum cryptography communication processing unit 570 to safely transmit and receive information (fragments of secretly shared confidential information) between the secret sharing processing unit 560 and the secret sharing DB 581 of the storage unit 580. The number of quantum cryptography communication processing units 570 is not particularly limited, and may be one or more. When there are multiple quantum cryptography communication processing units 570, a quantum cryptography communication processing unit 570 is provided for each secret sharing DB 581, for example.

[0073] (4-4) Storage section 580 The storage unit 580 has a function of storing various information. The function of the storage unit 580 is realized by a storage medium provided as hardware in the secret sharing storage server 540, such as an HDD, SSD, flash memory, EEPROM, RAM, ROM, or any combination of these storage media. The storage unit 580 stores, for example, the confidential information processed by the secret sharing processing unit 560 and received from the quantum cryptography communication processing unit 570 in a plurality of databases (DBs). As shown in Fig. 6, the storage unit 580 includes a plurality of secret sharing DBs 581-1 to 581-N (N is a natural number) as databases for secretly sharing and storing confidential information.

[0074] <7. Functional configuration of the card issuing system> The functional configuration of the quantum secure cloud system 50 according to this embodiment has been described above. Next, the functional configuration of the card issuing system 80 according to this embodiment will be described with reference to Fig. 7. Fig. 7 is a diagram showing an example of the functional configuration of the card issuing system 80 according to this embodiment. As shown in FIG. 7, the card issuing system 80 includes a quantum cryptography communication processing unit 810 and a control unit 820.

[0075] (1) Quantum cryptography communication processing unit 810 The quantum cryptography communication processing unit 810 has a function of transmitting and receiving various types of information. The quantum cryptography communication processing unit 220 transmits and receives various types of information to and from the first operator system 20, the quantum secure cloud system 50, and the factory-issued system 90, for example, by quantum cryptography communication via a QKD network.

[0076] (2) Control unit 820 The control unit 820 has a function of controlling the overall operation of the card issuing system 80. The control unit 820 is realized, for example, by causing a CPU or GPU provided as hardware in the card issuing system 80 to execute a program. As shown in FIG. 7, the control unit 820 includes a key pair generation unit 821, a certificate acquisition unit 822, and a card issuance processing unit 823.

[0077] (2-1) Key pair generation unit 821 The key pair generation unit 821 has a function of generating a key pair. For example, the key pair generation unit 821 generates a pair of a private key and a public key used for identity verification and data tamper prevention. Identity verification is performed using, for example, a digital certificate stored in an IC card. Data tamper prevention is performed using, for example, a private key stored in the IC card.

[0078] (2-2) Certificate Acquisition Unit 822 The certificate acquisition unit 822 has a function of acquiring a certificate, for example, a public key certificate.

[0079] (2-3) Card issuance processing unit 823 The card issuance processing unit 823 has a function of performing processing for issuing an IC card. For example, the card issuance processing unit 823 prepares information necessary for issuing an IC card and information to be stored in the IC card, and transmits this information to the factory issuance system 90 via the quantum cryptography communication processing unit 810.

[0080] <8. Processing flow> The functional configuration of the card issuing system 80 according to this embodiment has been described above. Next, the flow of processing according to this embodiment will be described with reference to Figs.

[0081] (1) Processing flow in the registration phase The flow of processing in the registration phase according to this embodiment will be described with reference to Fig. 8. Fig. 8 is a sequence diagram showing an example of the flow of processing in the registration phase according to this embodiment.

[0082] 8, first, the quantum secure cloud system 50 issues a digital certificate (step S101). Specifically, the quantum-safe public key authentication unit 520 of the quantum secure cloud system 50 issues a digital certificate to the user. The communication unit 510 transmits the digital certificate to the user terminal 10 and the first operator system 20 via SSL / TLS communication using PQC.

[0083] Next, the user terminal 10 applies for a service to the first operator system 20 in response to an operation from the user (step S102). Specifically, the user operates the user terminal 10 to access a uniform resource locator (URL) of the service of the first operator system 20. Upon receiving the access from the user terminal 10, the first operator system 20 establishes a TLS session with the user terminal 10.

[0084] Next, the user terminal 10 performs user registration with the first business operator system 20 in response to an operation from the user (step S103). Specifically, the user performs an operation to input basic information, identification card, biometric information, etc. of the user into the user terminal 10. For basic information, the user enters their name, address, etc. For identification, the user registers an official photo ID. When registering an identification, the user first selects the identification to register (e.g., a driver's license or My Number card), and then photographs the selected identification or reads the IC chip. For identification that requires the IC chip to be read (e.g., My Number card), signature verification and validation of the electronic certificate must be performed using the process described below based on the electronic certificate (e.g., a signature electronic certificate and a user electronic certificate) read from the IC chip. For this reason, when the IC chip is read, the user also enters a PIN (Personal Identification Number) code. For biometric information, the user photographs themselves from the front and checks for movement by rotating their face and blinking. Various pieces of information input by the user (hereinafter also referred to as “user information”) are registered by the service processing unit 241 of the first operator system 20. It should be noted that the user does not necessarily need to input all of the above-mentioned basic information, identification card information, and biometric information as user information, but only needs to input at least the information necessary for the service the user uses.

[0085] Next, the ID management unit 242 of the first business operator system 20 assigns a unique user ID to the user who has registered for the service (step S104). After the issuance, the quantum cryptography communication processing unit 220 of the first operator system 20 transmits the issued user ID to the quantum secure cloud system 50 by quantum cryptography communication (step S105).

[0086] The quantum cryptography communication processing unit 530 of the quantum secure cloud system 50 generates a common key K1 (first common key) linked to the user ID received from the first operator system 20 (step S106). The quantum cryptography communication processing unit 530 transmits the generated common key K1 to the first operator system 20 by quantum cryptography communication (step S107).

[0087] The linking processing unit 243 of the first operator system 20 performs the linking process (step S108). Specifically, the linking processing unit 243 links the common key K1 received by the quantum cryptography communication processing unit 220 from the quantum secure cloud system 50, the user information registered by the user, and the user ID assigned by the ID management unit 242.

[0088] After the linking process, the quantum cryptography communication processing unit 220 encrypts the linked information using a one-time pad (OTP) and transmits it to the external business system 40 (step S109). At this time, the quantum cryptography communication processing unit 220 also transmits a verification request (a request for user identity verification and credit check) from the verification request unit 245. In FIG. 8, the information obtained by encrypting the common key K1, user information, and user ID with OTP is indicated as Enc(K1·user information·ID, OTP).

[0089] The external business system 40 further encrypts Enc(K1·user information·ID, OTP) received from the first business system 20 with OTP, and transmits the resulting Enc(Enc(K1·user information·ID, OTP), OTP) to the quantum secure cloud system 50 by quantum cryptography communication (step S110). Note that the external business system 40 does not necessarily have to perform the process of step S110.

[0090] The secret sharing storage server 540 of the quantum secure cloud system 50 performs secret sharing management for Enc(K1·user information·ID, OTP) (step S111). Specifically, first, the quantum cryptography communication processing unit 530 of the quantum secure cloud system 50 receives Enc(Enc(K1·user information·ID, OTP), OTP) from the external business system 40. Upon reception, Enc(Enc(K1·user information·ID, OTP), OTP) is decrypted to become Enc(K1·user information·ID, OTP). The secret sharing processing unit 560 of the secret sharing storage server 540 secret shares the confidential information Enc(K1·user information·ID, OTP), and stores the pieces of confidential information in the secret sharing DBs 581-1 to 581-N of the storage unit 580 via the quantum cryptography communication processing unit 570.

[0091] The external business system 40 performs processing based on the verification request received from the first business system 20. Specifically, the external business system 40 references the user information stored in the quantum secure cloud system 50, compares the photograph on the identification card with the captured biometric information to confirm consistency, and checks for any deficiencies in the required information. In addition, the external business system 40 requests the J-LIS system 60 to verify the user's signature and confirm validity (step S112), and requests the credit system 70 to perform a credit review of the user (step S113). Note that the processing of step S112 occurs only when the IC chip is read in the processing of step S103. The external business system 40 transmits the examination result to the first business system 20 by quantum cryptography communication (step S114). The communication unit 210 of the first operator system 20 transmits the examination result notification received by the quantum cryptography communication processing unit 220 from the external operator system 40 to the user terminal 10 by SSL / TLS communication using PQC (step S115).

[0092] (2) Processing flow in the card issuance phase The flow of processing in the card issuance phase according to this embodiment will be described with reference to Fig. 9. Fig. 9 is a sequence diagram showing an example of the flow of processing in the card issuance phase according to this embodiment.

[0093] 9, first, the user terminal 10 requests the first business operator system 20 to issue a card in response to an operation from the user (step S201). Specifically, the user operates the user terminal 10 to request the issuance of an IC card related to the service of the first business operator system 20. At this time, the user also specifies a PIN code to be set on the IC card. The quantum cryptography communication processing unit 220 of the first business operator system 20 further transmits the card issuance request received by the communication unit 210 from the user terminal 10 to the card issuing system 80 by quantum cryptography communication (step S202). At this time, the quantum cryptography communication processing unit 220 specifies the user ID of the user who made the card issuance request and transmits the card issuance request.

[0094] When the quantum cryptography communication processing unit 810 receives a card issuance request from the first business operator system 20, the key pair generation unit 821 of the card issuing system 80 generates a key pair (step S203).

[0095] Next, the card issuing system 80 transmits the user ID of the user who has requested the card issuance to the quantum secure cloud system 50 (step S204). The secret sharing processing unit 560 of the quantum secure cloud system 50 obtains Enc(K1·user information·ID, OTP) linked to the user ID received from the card issuing system 80 from the secret sharing DBs 581-1 to 581-N of the memory unit 580 via the quantum cryptography communication processing unit 570 (step S205). The quantum cryptography communication processing unit 530 transmits Enc(K1·user information·ID, OTP) to the card issuing system 80 by quantum cryptography communication (step S206).

[0096] Next, the certificate acquisition unit 822 of the card issuing system 80 requests the quantum secure cloud system 50 to issue a public key certificate for the public key generated in step S203 (step S207). The quantum-safe public key authentication unit 520 of the quantum secure cloud system 50 issues a public key certificate in response to the request received by the communication unit 510 from the card issuing system 80 (step S208). After issuance, the communication unit 510 transmits the public key certificate to the card issuing system 80 by classical communication (step S209).

[0097] The card issuance processing unit 823 of the card issuing system 80 transmits the common key K1, the user ID, the public key certificate, and the private key to the factory issuance system 90 by quantum cryptography communication via the quantum cryptography communication processing unit 810 (step S210). As a result, the card issuance processing unit 823 requests the factory issuance system 90 to issue an IC card.

[0098] The factory-issuing system 90 issues an IC card based on the information received from the card-issuing system 80 (step S211). Specifically, the factory-issuing system 90 issues an IC card having the common key K1, user ID, public key certificate, and private key received from the card-issuing system 80 stored in an IC chip. After issuing the IC card, the factory issuing system 90 transmits an IC card issuance completion notification to the first business operator system 20 by SSL / TLS communication using PQC (step S212). The first business operator system 20, which has received the IC card issuance completion notification, transmits an IC card delivery notification to the user terminal 10 by SSL / TLS communication using PQC (step S213). The factory issuing system 90 performs processing to send the issued IC card and its notification to the user (step S214). In this way, the IC card is issued to the user with the common key K1 stored therein.

[0099] (3) Processing flow in the card usage phase The flow of processing in the card usage phase according to this embodiment will be described with reference to Fig. 10. Fig. 10 is a sequence diagram showing an example of the flow of processing in the card usage phase according to this embodiment.

[0100] 10, first, the user terminal 10 reads the information stored in the IC chip from the IC card (step S301). Specifically, the user terminal 10 reads the common key K1, the user ID, and the public key certificate stored in the IC chip of the IC card.

[0101] Next, the user terminal 10 accesses the first provider system 20 in response to an operation from the user (step S302). Specifically, the user operates the user terminal 10 to access the URL of a service of the first provider system 20. Upon accepting the access from the user terminal 10, the first provider system 20 sends a request to the user terminal 10 to input a PIN, and the user terminal 10 transmits the PIN input by the user. The first provider system 20 verifies the PIN received from the user terminal 10, and establishes a TLS session with the user terminal 10 only if the PIN is successful.

[0102] By establishing the TLS session, the user terminal 10 and the first operator system 20 share a common key K2 (second common key) (step S303).

[0103] Next, the verification request unit 245 of the first operator system 20 requests the quantum secure cloud system 50 to verify the certificate and the signature via the communication unit 210 (step S304). The quantum-safe public key authentication unit 520 of the quantum secure cloud system 50 performs verification in response to the request from the first operator system 20, and transmits the verification result to the first operator system 20 (step S305). After the verification is completed, the verification request unit 245 of the first business operator system 20 transmits an authentication completion notification to the user terminal 10 (step S306).

[0104] The key generation unit 153 of the user terminal 10 generates a common key K3 (third common key) (step S307). Specifically, the key generation unit 153 generates the common key K3 by combining the common key K1 read from the IC chip of the IC card and the common key K2 shared through the TLS session with the first operator system 20, and stores the common key K3 in the IC card. After generation, the encryption processing unit 154 encrypts the user's confidential information with the common key K3 and transmits it together with the user ID to the first business operator system 20 (step S308). In Fig. 10, the confidential information encrypted with the common key K3 is indicated as Enc(confidential information, K3). The confidential information handled here may vary depending on the service used by the user. In the case of a financial service, confidential information may be, for example, transaction information, loan information, credit information, etc. In this case, the second business providing the service to the user is an institution that wants to access the transaction information, such as a branch of a financial institution or a securities company. In the case of medical services, confidential information is, for example, information indicating medical history, prescription history, genomic data, etc. exchanged through online medical consultations. In this case, the second entity providing the service to the user is, for example, a pharmacy or healthcare company that wants to access that information. In the case of administrative services, confidential information may be, for example, information indicating national tax payment history, defense-related information, or other national secrets. In this case, the second entity providing the service to the user may be, for example, an administrative agency or local government that wishes to access that information.

[0105] The communication from step S302 to step S308 described above is performed by SSL / TLS encrypted communication using PQC.

[0106] The quantum cryptography communication processing unit 220 of the first operator system 20 further encrypts the user ID and Enc (confidential information, K3) received from the user terminal 10 with OTP, and transmits the encrypted information to the quantum secure cloud system 50 by quantum cryptography communication (step S309). Note that in Fig. 10, the information obtained by encrypting the user ID and Enc (confidential information, K3) with OTP is shown as Enc(ID·Enc(confidential information, K3), OTP).

[0107] The quantum secure cloud system 50 performs secret sharing management of Enc(ID·Enc(confidential information, K3), OTP) received from the first operator system 20 at the secret sharing storage server 540 (step S310). Note that Enc(confidential information, K3), in which confidential information is encrypted with the common key K3, is received from the first operator system 20 by the quantum cryptography communication processing unit 530 of the quantum secure cloud system 50.

[0108] From this point onward, the user terminal accesses the second operator system 30 in response to an operation from the user, and the process is carried out. For this purpose, a TLS session is first established between the user terminal 10 and the second operator system 30 by the same processes as those in steps S301 and S302 described above. Note that the second operator system 30 needs to inquire about the user's PIN to the first operator system 20 in advance in order to verify the PIN. By establishing the TLS session, the user terminal 10 and the second operator system 30 generate a common key K4 (fourth common key) (step S311). After generation, the encryption processing unit 154 encrypts the user ID and the common key K3 used to encrypt the confidential information with the common key K4, and transmits the encrypted information to the second business operator system 30 (step S312). In Fig. 10, the information obtained by encrypting the user ID and the common key K3 used to encrypt the confidential information with the common key K4 is indicated as Enc(ID·K3, K4).

[0109] The decryption processing unit 333 of the second operator system 30 decrypts Enc(ID·K3, K4) received by the communication unit 310 from the user terminal 10 with the common key K4, and reads out the user ID and the common key K3 (step S313). Next, the data acquisition unit 331 of the second operator system 30 transmits a request to acquire information (confidential information) linked to the user ID to the quantum secure cloud system 50 via the communication unit 310 (step S314). When the quantum secure cloud system 50 receives a request to obtain confidential information from the second operator system 30, it obtains Enc (confidential information, K3) that is being managed through secret sharing in the secret sharing storage server 540 and transmits it to the second operator system 30 (step S315). The second operator system 30 decrypts Enc(confidential information, K3) received from the quantum secure cloud system 50 with the common key K3 (step S316).

[0110] In the process flow described with reference to Figures 8 to 10, information transmitted and received via Internet communication is transmitted and received in a state encrypted using post-quantum cryptography (PQC). However, communication is not limited to communication using post-quantum cryptography (PQC), and may be communication using existing cryptography.

[0111] As described above, the quantum cryptography communication system 1 of this embodiment is provided with a quantum secure cloud system 50 (cloud system) having a QKD network (quantum cryptography communication network) that connects multiple operator systems via quantum cryptography communication, and includes a quantum cryptography communication processing unit 530 that generates a first common key to be provided to a user via an IC card (predetermined medium) and receives confidential information from the first operator system 20 encrypted with a third common key generated based on the first common key provided from the user terminal 10 and the second common key generated between the user terminal 10 and the first operator system 20, so that the user can use a service provided by a second operator using the user's confidential information managed by the first operator, and a memory unit 580 that stores the received confidential information in the quantum secure cloud system 50.

[0112] With this configuration, the user's confidential information is managed in the cloud system in a state encrypted based on a common key generated within the cloud system and a common key generated outside the cloud system, and the common key generated outside the cloud system is not shared with the cloud system. As a result, the cloud system operator cannot obtain all of the common keys used to encrypt the user's confidential information, and cannot decrypt the user's confidential information, so the user's confidential information cannot be viewed. Therefore, the user can manage confidential information on the cloud system without disclosing the confidential information to the cloud system operator. Therefore, the quantum cryptography communication system 1 according to this embodiment makes it possible to improve the confidentiality of users' confidential information managed in a cloud system based on a QKD network.

[0113] Furthermore, according to the present invention, in institutions such as financial institutions, medical institutions, and government agencies that perform identity authentication using IC cards or the like and provide services to users while handling relatively highly confidential data, when sending and receiving confidential data generated between users and businesses, or between users and service providers that use platforms provided by businesses, and storing the received data, it is possible to provide a highly confidential data transmission method and system that can withstand threats such as the compromise of existing encryption by quantum computers and data harvesting attacks, without sacrificing convenience.

[0114] <9. Variations> The processing flow according to this embodiment has been described above. Next, a modified example of this embodiment will be described. Note that the modified examples described below may be applied to the embodiment alone or in combination with the embodiment. Furthermore, the modified examples may be applied in place of the configuration described in the embodiment, or may be applied in addition to the configuration described in the embodiment.

[0115] In the above-described embodiment, an example in which the predetermined medium is an IC card has been described, but the present invention is not limited to such an example. The predetermined medium may be, for example, a SIM (Subscriber Identity Module) card. In this case, the first business entity is not limited to a business that provides a service for identity authentication using a medium such as an IC card. In other words, the first business entity is not limited to a business that issues IC cards. For example, the first business entity may be a business that provides services that can be used using a SIM-card compatible device, such as a smartphone, tablet device, or PC. Examples of such services include administrative procedures, Fintech, medical care, employment / temporary staffing, qualification / license certification, tourism (such as accommodation), electronic approval, education / examination, data access control, MaaS (Mobility as a Service), airport (boarding procedures), and entrance / exit procedures.

[0116] Furthermore, in the above-described embodiment, in the card issuance phase described with reference to Figure 9, an example was described in which a card issuance request is sent from the first business operator system 20 to the card issuance system 80, thereby issuing an IC card at the factory issuance system 90, and an IC card issuance completion notification is sent from the factory issuance system 90 to the first business operator system 20, but this example is not limited to this. For example, in the card issuance phase, a card issuance request may be sent from the external business system 40 to the card issuance system 80, which may result in the issuance of an IC card at the factory issuance system 90, and a notification of completion of IC card issuance may be sent from the factory issuance system 90 to the external business system 40. In other words, the issuance of the user's IC card may be controlled by the external business system 40, rather than by the first business system 20.

[0117] Here, we will explain the configuration of each system when the issuance of a user's IC card is controlled by the external business system 40. Note that we will only explain the configuration that is different from the above-mentioned embodiment, and will omit explanations of the configuration that is the same. External business system 40 is communicably connected via network NW to card issuing system 80 and factory issuing system 90. The first business service provided by external business system 40 is a service that further controls card issuance based on the results of user identity verification, credit verification, data verification, etc. Card issuing system 80 is also connected to external business system 40 via network NW so as to be able to communicate with it. In this case, card issuing system 80 further includes a communication unit in the functional configuration shown in Fig. 7. The communication unit transmits and receives various information to and from external business system 40 via network NW. The factory issuing system 90 is also connected to an external business system 40 via a network NW so as to be able to communicate with the external business system 40 . The external business system 40 may be configured to include the card issuing system 80 or the factory issuing system 90. In other words, the card issuing system 80 or the factory issuing system 90 is under the control of an external business, and the external business system 40 is configured to be able to cooperate with the card issuing system 80 or the factory issuing system 90.

[0118] Here, we will explain an example of the processing flow when the issuance of a user's IC card is controlled by the external business system 40. Note that we will only explain the processing that differs from the above-mentioned embodiment, and will omit explanations of the processing that is the same. For example, in the registration phase described with reference to Fig. 8, assume that the processing up to the credit check in step S113 is completed in the same manner as in the above-described embodiment, and the credit check results are satisfactory. In this case, the external business system 40 performs processing to send a card issuance request to the card issuing system 80. This processing corresponds to the processing of step S202 in the card issuance phase described with reference to Fig. 9. After the card issuance request is sent, the processes from step S203 to step S211 in the card issuance phase described with reference to Fig. 9 are performed in the same manner as in the above-described embodiment. When the IC card is issued in step S211, the factory-issuing system 90 performs a process of sending an IC card issuance completion notification to the external business system 40. This process corresponds to the process of step S212 in Fig. 9. This configuration allows the external business to centralize the management of card issuance requests and card issuance completion notifications, which eliminates the need for businesses that provide services to users to perform tasks such as requesting the issuance of IC cards from card issuance system 80 and receiving completion notifications directly from factory issuance system 90, thereby reducing the burden on the businesses.

[0119] Note that the external business system 40 may transmit a card issuance request to the card issuing system 80 upon receiving the card issuance request from the first business system 20. In this case, when the first business system 20 receives the card issuance request from the first business system 20, it transmits the card issuance request to the external business system 40 instead of the card issuing system 80, as in the processing of step S201 in the card issuance phase described with reference to FIG.

[0120] In addition, in the above-described embodiment, in the processing of step S110 of the registration phase described with reference to FIG. 8, an example was described in which Enc(Enc(K1·user information·ID, OTP), OTP) is transmitted from the external business system 40 to the quantum secure cloud system 50 by quantum cryptography communication, but the present invention is not limited to such an example. In the registration phase, the user ID is transmitted from the first operator system 20 to the quantum secure cloud system 50 in the processing of step S105, and the quantum secure cloud system 50 generates the common key K1 in the processing of step S106. That is, the quantum secure cloud system 50 knows the user ID and the common key K1 at the time when the processing of step S106 is completed. Therefore, in the registration phase, the processing of step S110 does not necessarily have to be performed. In this case, the quantum secure cloud system 50 secretly shares the user ID received from the first operator system 20 in the process of step S105 and the common key K1 generated in step S106, and manages them in the secret sharing DBs 581-1 to 581-N. Furthermore, in the processing of step S109, the first business operator system 20 only needs to transmit information necessary for the examination to the external business operator system 40, and for example, does not transmit the user ID and the common key K1, but transmits only the user information. That is, in step S109, the first business operator system 20 transmits Enc (user information, OTP) to the external business operator system 40 by quantum cryptography communication. This reduces the number of OTP keys that need to be managed by the external business operator system 40, thereby enabling a reduction in the management costs of the external business operator and a reduction in security risks in management by the external business operator.

[0121] However, if the processing of step S110 is not performed, the external business system 40 must responsibly store the user information received in step S109 from the first business system 20. When it becomes unnecessary to store the user information, the external business system 40 must destroy the stored user information and certify that it has been destroyed.

[0122] When performing the processing of step S110, the external business system 40 may decrypt Enc(K1·user information·ID, OTP) received from the first business system 20 with an OTP key, and transmit it again as Enc(K1·user information·ID, OTP) with another OTP key to the quantum secure cloud system 50. This reduces the number of OTP keys that need to be managed by the external business system 40, thereby reducing the management costs of the external business and the security risks involved in management by the external business.

[0123] In addition, in the above-described embodiment, an example was described in which the quantum cryptography communication processing unit 570 transmits and receives information between the secret sharing processing unit 560 and the secret sharing DB 581 of the memory unit 580 using quantum cryptography communication, but the present invention is not limited to such an example. For example, the communication between the secret sharing processing section 560 and the secret sharing DB 581 may be SSL / TLS communication using PQC instead of quantum cryptography communication.

[0124] In addition, in the above-described embodiment, an example was described in which Enc(Enc(K1·user information·ID, OTP), OTP) is transmitted from the external business system 40 to the quantum secure cloud system 50 in the processing of step S110 of the registration phase described with reference to Figure 8, but this example is not limited to this. For example, the information transmitted from the external provider system 40 to the quantum secure cloud system 50 may be Enc(K1·user information·ID, OTP). In this way, the number of times the information transmitted to the quantum secure cloud system 50 is encrypted with OTP may vary depending on the service level.

[0125] In the above-described embodiment, in the processing of step S202 of the card issuance phase described with reference to Fig. 9, only the ID is transmitted from the first business operator system 20 to the card issuance system 80, but this is not limiting. For example, a PIN may be transmitted to the card issuance system 80 together with the ID. In this case, in step S210, the card issuance system 80 also transmits the PIN to the factory issuance system 90. In step S211, the factory issuance system 90 issues an IC card in which the PIN is also stored in the IC chip.

[0126] The above describes an embodiment of the present invention. Note that some or all of the functions of the quantum cryptography communication system 1, user terminal 10, first operator system 20, second operator system 30, quantum secure cloud system 50, and card issuing system 80 in the above-described embodiment may be implemented by a computer. In this case, a program for implementing the functions may be recorded on a computer-readable recording medium, and the program may be loaded and executed by a computer system. Note that the term "computer system" as used herein includes hardware such as an operating system and peripheral devices. Furthermore, the term "computer-readable recording medium" refers to portable media such as flexible disks, optical magnetic disks, ROMs, and CD-ROMs, as well as storage devices such as hard disks built into a computer system. Furthermore, the term "computer-readable recording medium" may also include media that dynamically store programs for a short period of time, such as communication lines used when transmitting programs via networks such as the Internet or telephone lines, and media that store programs for a fixed period of time, such as volatile memory within the computer systems that serve as servers or clients in such cases. Furthermore, the above program may be one that realizes part of the above-mentioned functions, or may be one that can realize the above-mentioned functions in combination with a program already recorded in a computer system, or may be one that is realized using a programmable logic device such as an FPGA (Field Programmable Gate Array).

[0127] The embodiments of the present invention have been described in detail above with reference to the drawings, but the specific configuration is not limited to that described above, and various design changes and the like are possible within the scope that does not deviate from the gist of the present invention. [Explanation of symbols]

[0128] 1...quantum cryptography communication system, 10...user terminal, 20...first operator system, 30...second operator system, 40...external operator system, 50...quantum secure cloud system, 60...J-LIS system, 70...credit system, 80...card issuing system, 90...factory issuing system, 110...communication unit, 120...input unit, 130...reading unit, 140...storage unit, 150...control unit, 151...data acquisition unit, 152...data processing unit, 153...key generation unit, 154...encryption processing unit, 155...output control unit, 160...output unit, 210...communication unit, 220...quantum cryptography communication processing unit, 230...storage unit, 240...control unit, 241...service processing unit, 242...ID management unit, 243...linking processing unit, 244...Encryption communication processing unit, 245...Verification request unit, 246...Output control unit, 250...Output unit, 310...Communication unit, 320...Memory unit, 330...Control unit, 331...Data acquisition unit, 332...Encryption communication processing unit, 333...Decryption processing unit, 334...Output control unit, 340...Output unit, 510...Communication unit, 520...Quantum-resistant public key authentication unit, 530...Quantum cryptography communication processing unit, 540...Secret sharing storage server, 550...Communication unit, 560...Secret sharing processing unit, 570...Quantum cryptography communication processing unit, 580...Memory unit, 581 (581-1 to 581-N)...Secret sharing DB, 810...Quantum cryptography communication processing unit, 820...Control unit, 821...Key pair generation unit, 822...Certificate acquisition unit, 823...Card issuance processing unit, NW...Network

Claims

1. a quantum cryptography communication processing unit that generates a first common key to be provided to a user via a predetermined medium in a cloud system having a quantum cryptography communication network that connects a plurality of provider systems by quantum cryptography communication, and receives, from a first provider system, confidential information encrypted with a third common key generated based on the first common key provided from the user terminal and a second common key generated between the user terminal and the first provider system, so that the user can use a service provided by a second provider using the user's confidential information managed by the first provider; a storage unit that stores the received confidential information in the cloud system; A quantum cryptography communication system comprising:

2. a communication unit that, when receiving a request to acquire the confidential information corresponding to the user from a second provider system to which the third common key has been provided from the user terminal, transmits the confidential information stored in the storage unit from the cloud system to the second provider system when the user uses a service provided by the second provider; The quantum cryptography communication system according to claim 1 , further comprising:

3. the third common key is encrypted with a fourth common key generated between the user terminal and the second operator system, and the encrypted third common key is provided from the user terminal to the second operator system; The quantum cryptography communication system according to claim 2 .

4. Information sent and received via internet communications is encrypted using quantum-resistant cryptography. The quantum cryptography communication system according to claim 1 .

5. the confidential information is encrypted with the third common key and further encrypted with a one-time pad and then transmitted from the first business operator system to the cloud system; The quantum cryptography communication system according to claim 1 .

6. the predetermined medium is an IC card, the IC card is issued to the user in a state in which the first common key is stored; The quantum cryptography communication system according to claim 1 .

7. a quantum cryptography processing step in a cloud system having a quantum cryptography communication network connecting a plurality of provider systems by quantum cryptography communication, generating a first symmetric key to be provided to a user via a predetermined medium, and receiving, from a first provider system, confidential information encrypted with a third symmetric key generated based on the first symmetric key provided from a user terminal and a second symmetric key generated between the user terminal and the first provider system, so that the user can use a service provided by a second provider using the user's confidential information managed by the first provider; a storage step of storing the received confidential information in the cloud system; A quantum cryptography communication method implemented by a computer, comprising:

8. Computer, a quantum cryptography processing means for generating a first common key to be provided to a user via a predetermined medium in a cloud system having a quantum cryptography communication network connecting a plurality of provider systems by quantum cryptography communication, and receiving, from a first provider system, confidential information encrypted with a third common key generated based on the first common key provided from a user terminal and a second common key generated between the user terminal and the first provider system, so that the user can use a service provided by a second provider using the user's confidential information managed by the first provider; a storage means for storing the received confidential information in the cloud system; A program to function as a

Citation Information

Patent Citations

  • Cloud key management service platform system

    JP2023040843A