Information processing apparatus, quantum cryptographic communication system, information processing method, and program
The information processing apparatus optimizes key distribution in 5G networks by managing encryption keys based on communication data requirements, addressing the limitations of QKD speed and distance to ensure secure and efficient encryption of specific flows.
Patent Information
- Application Number
- JP2024025252
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-22
- Publication Date
- 2025-09-03
AI Technical Summary
Conventional technologies face challenges in targeting specific communication flows within 5G networks for secure encryption using Quantum Key Distribution (QKD) due to limitations in key generation speed and distance, leading to potential security risks in cloud-based communications.
An information processing apparatus that manages encryption keys by determining the amount of accumulated keys available for each communication destination, ensuring sufficient keys are allocated for secure communication, and instructing key management devices to provide encryption keys when needed, thereby enabling secure communication using QKD.
This approach ensures efficient and secure encryption of specific communication flows within 5G networks by optimizing key distribution, ensuring that the communication data amount is adequately covered by available encryption keys, thus enhancing security and performance.
Smart Images

Figure 2025128537000001_ABST
Abstract
Description
[Technical Field]
[0001] An embodiment of the present invention relates to an information processing device, a quantum cryptography communication system, an information processing method, and a program. [Background technology]
[0002] In cloud-based networks such as 5G networks, security for communications from the 5G network to the cloud is an important issue. For example, while the 5G network is protected by a public encryption method called PQC (Post-Quantum Cryptography), the encryption method for communications from the 5G network to the cloud has not been determined. Furthermore, the data communication throughput of the 5G network is orders of magnitude faster than the key generation speed of QKD. As a result, there is a risk that all data cannot be encrypted using a specific method. In other words, there is hope for the application of quantum cryptography, which cannot be broken even by a quantum computer, to specific communication flows among the massive amounts of data between the 5G core network and the cloud. Therefore, quantum encryption functionality for specific flows is required in the 5G core network for cloud computing. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2022-75398 [Non-patent literature]
[0004] [Non-Patent Document 1] ITU-T,Y.3800,“Overview networks on supporting quantum key distribution,” 2019 [Non-patent document 2] ETSI GS QKD 014,“Quantum Key Distribution (QKD);Protocol and data format of REST-based key delivery API,”2019 [Non-patent document 3] 3GPP,TS 23.501,“System architecture for the 5G System (5GS),” 2016 Summary of the Invention [Problem to be solved by the invention]
[0005] However, with conventional technologies, it has been difficult to target specific flows and perform encrypted communications using QKD networks more safely and efficiently. [Means for solving the problem]
[0006] According to an embodiment, an information processing apparatus includes a processing unit that acquires, from one or more key management devices that share a second encryption key with other key management devices through encryption relay using a first encryption key shared with a counterpart QKD module included in a QKDN (Quantum Key Distribution Network), an accumulated amount of the second encryption key for each shared destination, notifies a control device that controls communication of a user network of a specific rule that identifies a flow to be encrypted using the second encryption key, acquires from the control device flow information including a first communication device and a second communication device that communicate the flow to be encrypted and a communication data amount, determines whether the accumulated amount of the second encryption key used by the first communication device and the second communication device is equal to or greater than the communication data amount, and, if the accumulated amount of the second encryption key is equal to or greater than the communication data amount, instructs a key management device connected to the first communication device to provide the second encryption key to the first communication device. [Brief explanation of the drawings]
[0007] [Figure 1] FIG. 1 is a diagram showing an example of the configuration of a quantum cryptography communication system according to an embodiment. [Figure 2] FIG. 10 is a diagram illustrating an example of implementing a specific flow encryption function according to an embodiment. [Figure 3] FIG. 1 is a diagram showing an example of a sorting function of a 5G core network according to an embodiment. [Figure 4] FIG. 1 is a diagram showing an example of a 5G U-Plane protocol stack according to an embodiment. [Figure 5] FIG. 2 is a diagram illustrating an example of a device configuration that realizes a specific flow encryption function according to an embodiment. [Figure 6] FIG. 2 is a diagram showing an example of the functional configuration of a QCF according to the embodiment. [Figure 7] FIG. 2 is a sequence diagram illustrating an example of an information processing method according to the embodiment. [Figure 8] FIG. 10 is a diagram illustrating an example of a method for encrypting all data packets of a specific flow according to an embodiment. [Figure 9] FIG. 10 is a diagram showing an example of a method for encrypting a payload portion of a specific flow. [Figure 10] FIG. 10 is a diagram for explaining a specific flow encryption function according to the first modification of the embodiment. [Figure 11] FIG. 10 is a diagram for explaining a specific flow encryption function according to a second modification of the embodiment. [Figure 12] FIG. 2 is a diagram showing an example of the hardware configuration of a QKD module according to an embodiment. [Figure 13] FIG. 2 is a diagram illustrating an example of the hardware configuration of a key management device and a QCF according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0008] Hereinafter, embodiments of a key management device, a quantum cryptography communication system, an information processing method, and a program will be described in detail with reference to the accompanying drawings.
[0009] First, a quantum cryptography communication system to be used in the embodiment will be described.
[0010] 1 is a diagram showing an example of the configuration of a quantum cryptography communication system according to an embodiment. Viewed from the side, the QKD network architecture is composed of, from the bottom up, a quantum layer, a key management layer, a QKD network control layer, and a QKD network management layer for managing these three layers. These four layers generate an application key (hereinafter referred to as an "application key") used to encrypt and decrypt data communications by an application 5, and provide it to the service layer in the top-level user network. Viewed vertically, three nodes 1 (QKD nodes / trusted nodes) comprising a QKD network (hereinafter referred to as a "QKDN") and a user network are installed at points A, B, and C, respectively.
[0011] The quantum layer consists of a QKD module 2 and a QKD link 3. The main function of the quantum layer is to exchange photons and classical information (control information transmitted and received over a normal control link, different from the QKD link) with QKD modules 2 at other locations and share a link key (random number sequence). Furthermore, the quantum layer has the function of supplying random number sequences to key managers (KMs) 10 (10a to 10c). The link key (quantum encryption key) shared over the QKD link 3 is guaranteed to be resistant to eavesdropping based on the principles of quantum mechanics. When encrypted data communication is performed using the shared link key with a cryptographic communication method known as a one-time pad, information theory guarantees that the transmitted and received data cannot be decrypted by an eavesdropper, regardless of their knowledge. The QKD modules 2 (2a, 2b-1, 2b-2, and 2c) are connected by QKD links 3, such as optical fibers.
[0012] However, the method of sharing link keys using QKD technology is limited by the distance over which the link key can be shared, due to the use of single photons as a medium. For example, as shown in the example of the quantum layer in Figure 1, the QKD module 2 is basically one-to-one, but in the case of relaying, at least two QKD modules 2b-1 and 2b-2 are required at the relaying point B. In the example in Figure 1, the application key K is shared between points A and C.A AC At site B, the QKD module 2b-1 encrypts the application key encrypted at site A using the same link key K as site A. L AB (i.e., a common key in which the encryption key and the decryption key are the same). Then, the QKD module 2b-2 converts the decrypted application key into a link key K L BC Then encrypt it again with the encrypted application key K A AC Relay to base C.
[0013] In order to guarantee unconditional security, QKD inevitably sacrifices some communication performance, such as distance and speed. Generally, the link key generation rate within a 50km radius of installed fiber is approximately 200,000 to 300,000 bits per second (200 to 300kbps). If the QKD key distillation process is implemented and optimized in hardware, the key generation speed for QKD over short distances can reach a maximum of 10Mbps.
[0014] To maintain the key generation speed at Mbps, relay nodes must be installed at intervals that allow the speed to be maintained, and key relay must be performed between relay points. However, encryption and decryption processing takes time at relay points.
[0015] The key management layer is composed of key management devices (KM) 10a to 10c and a KM link. The main functions of the key management layer include supplying application keys to the applications 5a and 5c that actually encrypt data, and relaying keys to other locations via the KM link. The key management devices (KM) 10a to 10c are also responsible for overall key management, such as receiving key requests from the applications 5a and 5c and storing interfaces.
[0016] The QKD network control layer is composed of a QKD network controller 4 and links. The QKD network control layer controls the overall services of the QKD network. A QKD network controller may be provided at each location, or as shown in Figure 1, there may be one (or more) QKD network controllers for the entire quantum cryptography communication system. The QKD network controller 4 and KM 10 may also be implemented as an integrated unit.
[0017] The QKD network management layer includes a QKDN control device 6. The QKD network management layer has the function of collecting performance information from each layer, monitoring whether the service is operating properly, and issuing control commands to the QKD network control layer as necessary. There may be multiple QKDN control devices 6 depending on the configuration of the QKD network. The functions of the QKDN control device 6 may also be realized and performed by the KM 10.
[0018] The service layer's configuration varies depending on the user, but it is composed of applications 5a and 5c for implementing encrypted communications, computer modules, etc. The service layer also has the function of encrypting an application key with a link key and transferring it to an adjacent node. Note that the service layer application 5 may also generate an encryption key (application key) separate from the link key from random number information, etc., independently of QKD.
[0019] In the service layer, application keys are primarily used for encryption using symmetric encryption methods. A symmetric encryption method is an encryption method that uses the same application key shared in advance between the sender and receiver to encrypt and decrypt communication data and messages. Specifically, application keys are used in Advanced Encryption Standard (AES) encryption and One Time PAD (OTP) encryption.
[0020] The user network management layer includes a user network control device 7. The user network management layer collects performance information from the service layer and monitors whether the service is operating properly.
[0021] Note that the architecture shown in FIG. 1 shows basic elements. In reality, the configuration of the architecture may change depending on the situation. For example, the number of bases is not limited to three. Also, for example, the number of applications 5 is not limited to two. Also, for example, the number of QKDN control devices 6 in the QKD network management layer is not limited to one.
[0022] The above-mentioned user network is a public network, and is a network in which encrypted communication is performed by an application 5. The application 5 runs on, for example, a server device 8. The user network is, for example, a data communication network such as the Internet or a cellular communication network. In this embodiment, the user network is a 5G network, which is a representative example of a mobile phone network / mobile communication network. 5G is a fifth-generation mobile communication system.
[0023] On the other hand, the above-mentioned QKD network (quantum cryptography communication network) is a private network, and nodes (QKD nodes / nodes) are installed according to actual needs. The nodes provide encryption keys for encrypted communication to user networks.
[0024] 2 is a diagram illustrating an example of implementing a specific flow encryption function according to an embodiment. The network configuration in FIG. 2 mainly includes four parts: a 5G network, an IP network, a cloud, and a QKDN. The 5G network, the IP network, and the cloud correspond to the user network in FIG. 1.
[0025] A 5G network basically comprises a server device 8, a gNB (5G gNodeB) 9, and user equipment (UE) 11, which constitute a core network.
[0026] The server device 8 that constitutes the 5G core network is the core part of the network owned by the telecommunications carrier. The server device 8 plays various roles related to calls and communications, such as terminal authentication, terminal location management, policy control, packet forwarding control, establishment of communication paths, and data exchange with the data network (DN).
[0027] The gNB9, a base station in the RAN (Radio Access Network), has the functions of an RU (Radio Unit), DU (Distributed Unit), and CU (Central Unit). The RU processes radio frequencies (RF). The DU and CU process functions other than radio frequencies (RF). The DU performs real-time control, etc. The CU implements non-real-time functions, etc. Physically, the gNB9 is equipment such as an antenna, radio equipment, and transmission devices.
[0028] The UE 11 may be a mobile phone, a smartphone, a tablet, a SIM card, or the like.
[0029] To the right of the server device 8 that constitutes the 5G core network is the DN, also called the backbone. A typical example of a DN is the Internet. The communication speed of the backbone is basically 10 Gbps or more. An IP network is a computer network that is interconnected using Internet Protocol Suite technology. An IP network is also called an IP communication network used on the Internet.
[0030] The cloud is a system that provides services to users via a network such as the Internet. Users can use the services provided by a computer (server device 8) connected to a network such as the Internet on their own personal computers, smartphones, tablets, etc. via the network.
[0031] QKDN is a network with nodes 1 that generates encryption keys that cannot be eavesdropped on between nodes 1 and provides encryption keys for encrypted communications to user networks (in the example of Figure 2, the 5G network, IP network, and cloud).
[0032] In this embodiment, a specific flow in communication from a server device 8 of a 5G network to a cloud via an IP network is selected, and end-to-end (E2E) secure communication is performed using an encryption key provided by QKDN. For example, secure communication is performed for a flow of a specified application service from a server device 8 that is a specified starting point to a server device 8 (cloud server) that is a specified destination.
[0033] For example, among communications from UE 11 to cloud server device 8, communication data for a file transfer service (FTP: File Transfer Protocol) is guaranteed E2E secure communication from the core network to the cloud. Specifically, communication data for the file transfer service is encrypted using an encryption key provided from QKDN to the 5G core network, and decrypted using a decryption key (a key common to the encryption key) provided from QKDN to the cloud.
[0034] For example, services other than file transfer services (such as obtaining web information (HTTP: Hyper Text Transfer Protocol)) are securely communicated without encryption or using an encryption method other than quantum cryptography.
[0035] 2 shows an example of implementing the specific flow encryption function. In reality, the configuration may change depending on the situation. For example, the number of UE 11, server device 8, node 1, etc. is not limited to the example in FIG. 2. Also, for example, the destination to which the encryption key (decryption key) is provided from node 1 is not limited to the example in FIG. 2.
[0036] 3 is a diagram illustrating an example of a selection function of a 5G core network according to an embodiment. The 5G network includes a UE 11 used by an end user, a gNB 9 (base station) that wirelessly communicates with the UE 11, and a 5G core network that implements functions for realizing mobile communication.
[0037] The 5G core network in Figure 3 has three main component network functions (NFs): the Access and Mobility Management Function (AMF) 12, which is responsible for access to the 5G core network and mobility management functions, and the Session Management Function (SMF) 13, which is responsible for session management functions.
[0038] The I-UPF Uplink Classifier / Branching Point 14a and the UPF PDU session anchors 14b and 14c are User Plane Functions (UPFs) that perform user plane functions.
[0039] Hereinafter, the I-UPF Uplink Classifier / Branching Point 14a and the UPF PDU session anchors (UPF PSAs) 14b and 14c will be simply referred to as UPFs 14a, 14b, and 14c. When referring to the UPFs 14a, 14b, and 14c collectively, they will be simply referred to as UPFs 14.
[0040] 5G networks separate user plane (U-Plane) functions from control plane (C-Plane) functions. The U-Plane is the function that enables user communications, and the C-Plane is the function that controls communications. In Figure 3, the U-Plane is shown with a solid line and the C-Plane with a dashed line. The "N numbers" above the U-Plane and C-Plane lines are reference points.
[0041] Reference point Nx indicates the interaction that exists between NF services of a network function described by a point-to-point reference point (N11 between AMF and SMF) between any two components (e.g., AMF and SMF).
[0042] Below the 5G core network is the DN, which represents an external network. Figure 3 shows two types of DN to explain the selection function. One is Mobile Edge Computing (MEC), a local DN that achieves low latency, and the other is the cloud, a central DN that provides third-party services. MEC is a mechanism that creates DNs near terminals and base stations rather than in a central mobile core, providing a low-latency, high-bandwidth computing environment.
[0043] The two DNs are connected to UPF 14b or 14c in the 5G core network. The Uplink Classifier / Branching Point function of the UPF ensures that communications are forwarded to either DN. The Uplink Classifier / Branching Point function is specified as a technology that branches PDU (Protocol Data Unit) sessions based on the destination IP address, etc.
[0044] The basic flow of the sorting function will be explained using Figure 3 as an example. To enable tracking of UE 11 even when it moves, UE 11 (terminal) first registers with AMF 12 via gNB 9 (communication between N1 and N2). Next, AMF 12 requests SMF 13 to establish a PDU session (communication between N11).
[0045] The SMF 13 performs authentication and authorization. The SMF 13 determines parameters such as an IP address to be assigned to the UE 11, and communicates these parameters to the gNB 9 and the UE 11 via the AMF 12. At the same time, the SMF 13 selects the UPF 14a and requests it to perform configuration (communication via N4).
[0046] The UPF 14a sets up a PDU session based on parameters received from the SMF 13. The UPFs 14b and 14c are established by connection with the DN. In FIG. 3, the UPF 14b connected to the MEC and the UPF 14c connected to the Cloud are each established. A communication packet from the UE 11 to a destination is forwarded to the selected UPF 14b or 14c (UPF PSA) via the designated UPF 14a (I-UPF) based on the PDU session setting. The selected UPF 14b or 14c forwards the received communication packet to the designated DN (MEC or Cloud).
[0047] Furthermore, when the UE 11 (terminal) moves (handover), the PDU session must be reestablished. A handover occurs when the UE 11 moves and changes the gNB 9 (base station) to which it connects. Since the IP address of the UE 11 remains the same after handover, connectivity at the Transmission Control Protocol (TCP) / Internet Protocol (IP) level is maintained. If the UPF 14a does not change, the UPF 14b or 14c (UPF PSA) connected to the DN also does not change.
[0048] Figure 4 is a diagram showing an example of a 5G U-Plane protocol stack according to an embodiment. Communication from UE 11 to a specified DN is forwarded to a specified UPF 14 (UPF PSA) via a specified I-UPF according to specific parameters from SMF 13 of the core network. In other words, a dedicated PDU session is established, and communication data from UE 11 to the core network is transmitted via the PDU session. The space from UE 11 to gNB 9 is not described here because it is a different system and is complex.
[0049] The PDU session from gNB9 to the core network (via N3) is implemented using the GPRS Tunneling Protocol for User Plane (GTP-U) protocol. GTP-U is a User Datagram Protocol (UDP)-based protocol. GTP-U encapsulates UE packets and creates a point-to-point overlay network between gNB9 and UPF14c.
[0050] As shown in the PDU layer part of Figure 4, data (payload part and IP header) from UE 11 is encapsulated up to UPF 14c (UPF PSA) in the PDU session and transmitted to the core network. Communication from the core network to DN can be performed either in the case where the IP header of UE 11 (the IP address of UE 11) is used as is, or in the case where the IP header is changed to the IP address of the core network (an IP address dedicated to communication outside the core network).
[0051] The technology in Figures 3 and 4 makes it possible to select only specific flows from a specified starting terminal to a specified destination. Then, by using a quantum cryptographic key, secure communication can be performed from the core network to the specified destination, targeting the specific flow.
[0052] Figure 5 is a diagram showing an example of a device configuration that realizes the specific flow encryption function of an embodiment. Figure 5 is divided into three main parts. The first is a mobile phone network of a 5G network. The 5G network includes a UE 11, a gNB 9, and a 5G core network. The second is a DN, which includes an IP network and a server device 8 (cloud server). The third is a network that provides application keys to the 5G core network and the server device 8 (user network), and includes a QKD module 2, a KM 10, a QKDN control device 6, and a QKD network.
[0053] The function of the QCF 17 (an example of an information processing device) of the embodiment will be described in detail using the configuration example of FIG. 5. For example, secure communication is performed from a specific UE 11 in a user network to a specified server device 8 (cloud server) via an IP network. On land, QKDN is basically an optical fiber-based technology, and wireless communication is performed between the UE 11 and the gNB 9, making it difficult to provide an E2E application key from the QKDN. Therefore, it is assumed that secure communication is achieved using PQC technology from the UE 11 to the core network. That is, in the embodiment, a specific flow from the 5G core network to the specified destination server device 8 is encrypted and communicated using an application key shared using QKD.
[0054] In this embodiment, in addition to the AMF 12, SMF 13, UPF 14a, UPF PSA 14c, UDM 15 (Unified Data Management), and PCF (Policy Control Function) 16, a new QCF (Quantum Cryptograph Function) is installed as NF in the 5G core network.
[0055] The AMF 12 is responsible for managing the registration, connection and movement of the UE 11 (terminal).
[0056] The SMF 13 is responsible for managing the "session." For example, the SMF 13 assigns an IP address to the UE 11, selects the UPF 14 to be connected by the UE 11, and sets the functions executed by the UPF 14.
[0057] The UPF 14 is an anchor point for communication between the UE 11 of the mobile network and the server device 8 of the DN. The UPF 14 is a gateway for connecting the mobile network to a DN such as the Internet. The UPF 14 is responsible for all functions related to user communication, such as buffering when the UE 11 is in the IDLE state, measuring communication volume, and limiting communication speed.
[0058] The UDM 15 manages information such as access authentication, user registration, and data network.
[0059] The PCF 16 is responsible for policy control functions. For example, the PCF 16 sets the quality of the data transfer path to be used, such as the speed and delay time, based on the requirements of each application.
[0060] The QCF17 has external (for QKDN) functions, internal (for 5G networks) functions, and collaboration functions.
[0061] <External Functions> External functions include information collection, information exchange, and application key requests in cooperation with QKDN. For information collection in cooperation with QKDN, for example, information on the application key recipient is obtained from the KM 10 or QKDN control device 6 in the QKDN with which the QCF 17 cooperates. The application key recipient information includes the IP address of the server device 8 in the 5G core network and the IP address of the server device 8 (cloud server) connected to the IP network.
[0062] Furthermore, for example, when collecting information in cooperation with QKDN, information related to application keys is acquired. The information related to application keys includes the accumulated amount of application keys that can be provided from the KM 10 between the 5G core network and the specified destination server device 8 (cloud server).
[0063] In information exchange in cooperation with QKDN, for example, QCF17 obtains the amount of data in secure communications and compares that data amount with the number of stored application keys that can be provided by KM10. Then, QCF17 selects the optimal encryption method based on communication requirements (e.g., processing time limitations due to low-latency communications). After that, QCF17 notifies KM10 of the amount of application keys, their destination, and other information, and requests an application key. Examples of encryption methods include OTP and AES. OTP is an encryption method that uses a random number sequence at most once. AES is a symmetric key encryption algorithm established by the United States as a standard encryption method in 2001. AES is a block cipher with a substitution permutation network structure (SPN).
[0064] <Internal functions> The internal functions include determining flow specification elements and selection rules, and exchanging information between NFs to realize flow selection. Flow specification elements include, for example, specification of the source, destination, and application type, or a combination of these specifications.
[0065] Flow selection rules based on specific elements include, for example, the location of the UE 11, the destination name (Data Network Name: DNN), the type of slicing, 3Tuples, and 5Tuples, or a combination of these. DNN is proprietary information within the 5G network. Conversion of the destination IP address and DNN is one of the functions of UDM 15. When using the IP protocol, 3Tuples refers to the source and destination IP addresses and protocol in the IP header. When using the TCP / UDP protocol, 5Tuples refers to the source (source) port number and destination (destination) port number in the TCP / UDP header.
[0066] The specific elements or selection rules can be specified from the UE 11 or the administrator terminal of the 5G core network. The selection rules can be specified from the UE 11, for example, by inputting and editing them via a dedicated application homepage. The selection rules can also be specified from the administrator terminal of the 5G core network by directly inputting and editing them from the NF dedicated to the administrator. The flow selection rules are stored in the QCF 17, but may also be stored in the PCF 16 and UDM 15.
[0067] <Linkage function> The linking functions include storing information related to a specific flow (e.g., the amount of secure communication data using an encryption key), application key provision information (e.g., the amount of application key provision), etc., and sharing the information with other NFs (e.g., a billing management device operating as an NF with a billing function), as well as managing other encryption keys.
[0068] The linking function, for example, shares information with other NFs that have billing functionality. The QCF 17 collects related information, such as the amount of secure communication data using the application key in the UPF 14, via the SMF 13. The QCF 17 stores the collected related information and periodically notifies the NFs that have billing functionality of the related information. Specifically, the QCF 17 notifies the billing management device (NFs that have billing functionality) of the total amount of communication data encrypted and communicated using the application key via the communication IF. The NFs that have billing functionality calculate the fee based on the total amount of communication data encrypted and communicated using the application key (the amount of secure communication data used).
[0069] Furthermore, for example, the QCF 17 stores related information such as the amount of application keys provided collected from the KM 10, and periodically exchanges the related information with an NF with a billing function. The NF with a billing function calculates the fee based on the amount of application keys provided.
[0070] Furthermore, for example, the QCF 17 may also manage encryption keys other than the application keys provided by the QKDN (encryption keys such as PQC), generate hybrid keys by combining them with the application keys, and provide even more diverse secure communications.
[0071] In order to control the encryption of a specific flow, not only is the QCF 17 installed in the embodiment, but functions are also added to the SMF 13 and UPF 14 .
[0072] A function for acquiring specific rules for flows encrypted with an application key is added to SMF 13. For example, the specific rules for a flow include a combination of a cloud (specific DNN) specification, a communication type specification (e.g., TCP communication data (protocol number 6)), and an application specification (e.g., FTP, a file transfer application that uses port number 20).
[0073] The SMF 13 controls communications by exchanging information with the UDM 15 and the PCF 16. For example, the SMF 13 converts a DNN into an IP address of a destination cloud. Also, for example, the SMF 13 controls communications-related policies in the 5G core network.
[0074] The SMF 13 selects an appropriate UPF 14a according to specific rules and establishes a UPF 14c (UPF PSA). A function is also added for the SMF 13 to share related information with the QCF 17. For example, the related information may include the IP address of the UE 11, information about the selected UPF 14a, information about the UPF 14c (UPF PSA), and communication data of a specific flow.
[0075] The SMF 13 also determines the routing from the UE 11 to the UPF 14c (UPF PSA) and establishes a dedicated PDU session.
[0076] Before requesting an application key, the selected UPF 14a obtains relevant information about the KM 10 from the QCF 17 via the SMF 13 and performs authentication and authorization with the KM 10. The UPF 14a receives data from the dedicated PDU session and inspects the packets. At that time, the UPF 14a requests an application key based on the data size from the KM 10 via the QCF 17. The UPF 14a receives the application key from the KM 10 and encrypts the data of the specific flow. The UPF 14a then forwards the encrypted data packets of the specific flow to the DN via the established UPF 14c (UPF PSA).
[0077] Note that, using Figure 5, the configuration of the 5G core network and the functions of QCF17 in this embodiment have been explained, but the above configuration is an example, and the configuration of the 5G core network and the functions of QCF17 are not limited to the example of Figure 5.
[0078] 6 is a diagram showing an example of the functional configuration of the QCF 17 of the embodiment. The QCF 17 of the embodiment includes a communication unit 171, a storage unit 172, and a processing unit 173.
[0079] The communication unit 171 transmits and receives communication data to and from other devices and is realized by a wireless IF or a wired IF.
[0080] The storage unit 172 stores information such as the accumulated amount of application keys collected from one or more KMs 10 for each sharing destination, and the total amount of communication data encrypted and communicated using the application keys. The storage unit 22 is realized by, for example, a combination of main storage devices such as a ROM (Read Only Memory) and a RAM (Random Access Memory), and auxiliary storage devices such as a HDD (Hard Disk Drive) and a memory card.
[0081] The processing unit 173 performs various processes to realize the functions of the QCF 17. The processing unit 173 is realized by at least one processing unit. This processing unit includes, for example, a control unit and an arithmetic unit, and is realized by analog or digital circuits, etc. The processing unit may be a central processing unit (CPU), a general-purpose processor, a microprocessor, a digital signal processor (DSP), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a combination thereof.
[0082] 7 is a sequence diagram showing an example of an information processing method according to an embodiment. In FIG. 7, all NFs except for UE 11 and KM 10 are 5G core network NFs. In order to select a specific flow and implement encryption functions using an application key that utilizes QKDN, additional operations are performed in addition to QCF 17, including SMF 13, UPF 14, and KM 10.
[0083] By registering the UE 11 with the network, it becomes possible for the user to receive services, for the UE 11 to be able to communicate, and for the UE 11 to be tracked when it moves. Details of the process of registering the UE 11 with the network are omitted because they are outside the scope of the embodiment. Note that the method of registering the UE 11 is defined in ITU-T TS 23.502. Similarly, the method of deregistering the UE 11 is outside the scope of the embodiment.
[0084] The following explanation will be mainly based on the phase of establishing a PDU session.
[0085] First, UE 11 sends a message to AMF 12 for a PDU session establishment request (step S1). The message includes a DNN, a request type, an old PDU session ID (the ID of the PDU session used in the previous communication), slice-related information, and PDU session establishment request information. The message also includes location information and access type information obtained by gNB 9 (base station).
[0086] Next, the AMF 12 selects the SMF 13 based on the request type (step S2).
[0087] Meanwhile, the QCF 17 collects QKDN information from the KM 10 or QKDN control device 6 in the associated QKDN (step S3). For example, the QKDN information includes information on application key recipients and application key storage information. The process of step S3 is performed periodically.
[0088] Next, the AMF 12 sends an SM context request to the SMF 13 (step S4). There are two types of SM context requests: a "create request" and an "update request." The "create request" and the "update request" each contain different information.
[0089] Next, if the request type of the SM context request sent in step S4 is not an "emergency request" or an "existing emergency PDU session", and if the PDU session ID has not yet been registered by SMF13, SMF13 requests UDM15 to register the session management (step S5).
[0090] Next, the SMF 13 sends an SM context response (a response to the create request or a response to the update request) to the AMF 12 in response to the SM request received in step S4 (step S6). There are two types of responses to the create request: "SM context ID" and "PDU session reject." In the former case, if the SMF 13 receives the request and can process the PDU session establishment request, it creates an SM context and determines an SM context identifier (e.g., SM context ID).
[0091] Note that the creation request may be rejected based on the local configuration, etc., according to the integrity protection settings in the U-Plane security policy of the PDU session. If the creation request is rejected, the PDU session establishment process is stopped.
[0092] Meanwhile, the QCF 17 determines a specific rule for identifying the flow to be encrypted according to the identification element (step S7). For example, the QCF 17 receives the specific rule from a UE 11 (an example of a user terminal of a user network) of the 5G network or an administrator terminal via a communication IF. Step S7 can be executed after the UE 11 is registered. Note that step S7 may be executed at any timing between steps S1 to S6. Alternatively, the administrator of the 5G core network may input the specific rule to the QCF 17 in advance.
[0093] Next, the QCF 17 transmits the QKDN information collected in step S3 and the flow identification rule to the SMF 13 (step S8).
[0094] Next, the SMF 13 selects the PCF 16 and establishes or modifies an SM policy association (step S9).
[0095] Next, the SMF 13 selects a UPF 14a (step S10). Specifically, if the request type of the SM context request sent in step S4 is an initial request, the SMF 13 starts an N4 session establishment process using the selected UPF 14a. If the request type is not an initial request, the SMF 13 starts an N4 session modification process using the selected UPF 14a.
[0096] Next, the UPF 14a establishes a dedicated UPF PSA 14c connected to the designated DN in accordance with the specific rules of the flow from the SMF 13 (step S11).
[0097] Next, the SMF 13 notifies the QCF 17 of related information about the UPFs 14a and 14c, and shares the related information with the QCF 17 (step S12). For example, the related information about the UPFs 14a and 14c includes the IP addresses of the UPFs 14a and 14c, the size of communication data, and the like.
[0098] Next, the QCF 17 shares related information such as the UPFs 14a and 14c and the application key with the KM 10 (step S13). Specifically, first, the QCF 17 notifies the KM 10 of the related information of the UPFs 14a and 14c, and feeds back the related information to the QKDN. For example, the QCF 17 feeds back the related information to the KM 10 that is directly connected to the 5G core network. Also, for example, the QCF 17 feeds back the related information to the QKDN control device 6, and feeds back the related information to the KM 10 that can provide the application key to the 5G core network via the QKDN control device. For example, the related information of the UPFs 14a and 14c includes the IP address of the UPF PSA 14c and the amount of the application key according to the size of the communication data.
[0099] Next, the QCF 17 secures a communication path from the KM 10 to the UPF 14a. For example, the process of securing the communication path includes determining a routing path (path) between the UPF 14a and the KM 10, and notifying the KM 10 connected to the UPF 14a of the routing path via the communication IF.
[0100] Next, the KM 10 compares the size of the communication data included in the fed-back related information with the accumulated amount of application keys between the KM 10 connected to the destination. Note that this comparison process may be performed by the QCF 17 based on the QKDN information collected in step S3, or the QCF 17 may request the KM 10 to perform the comparison process.
[0101] If the application key is equal to or larger than the size of the communication data, the KM 10 notifies the QCF 17 that it can provide the application key. If the application key is smaller than the size of the communication data, the KM 10 notifies the QCF 17 of the current storage amount and the time for which the application key can be provided, and begins sharing the application key with the destination KM 10.
[0102] The QCF 17 receives a notification from the KM 10 and selects an appropriate encryption method. For example, the QCF 17 selects either the first encryption method or the second encryption method depending on the amount of application key stored. The first encryption method is an encryption method that uses a larger amount of application key for encryption than the second encryption method. The second encryption method is an encryption method that uses a smaller amount of application key for encryption than the first encryption method. Specifically, if the application key is equal to or larger than the size of the communication data, the KM 10 selects the OTP encryption method (an example of the first encryption method). If the application key is smaller than the size of the communication data, the KM 10 selects the AES encryption method (an example of the second encryption method) and calculates the application key update interval.
[0103] Thereafter, the QCF 17 notifies the UPF 14a of the encryption method and instructs the UPF 14a to provide the application key.
[0104] Next, the SMF 13 starts the session establishment process or the session modification process. For example, the SMF 13 sets packet routing and forwarding in the UPF 14a (step S14).
[0105] Next, when the UPF 14a performs authentication and authorization with the KM 10 connected to the 5G core network (step S15), the KM 10 can provide the application key to the UPF 14a.
[0106] Next, the SMF 13 sends the above-mentioned messages regarding N1 and N2 to the AMF 12 (step S16). The message in step S16 includes the PDU session ID, the SM information of N2, and the PDU session establishment request of N1.
[0107] Next, the AMF 12 transmits a PDU session establishment response to the UE 11 (step S17).
[0108] Next, the UE 11 completes PDU session establishment to the UPF 14a and the UPF PSA 14c in the 5G core network (steps S18-1 and S18-2).
[0109] Next, when the UPF 14a receives communication data of a specific flow encrypted by PQC from the UE 11 to the UPF 14a, the UPF 14a requests an application key for encrypting the specific flow from the KM 10 and receives an encryption key from the KM 10 (step S19).
[0110] The KM 10 compares the requested amount of application keys with the amount of application keys it has stored, and if the amount of stored application keys is sufficient, it notifies the UPF 14a of the encryption method and provides the application key. The UPF 14a uses the application key provided by the KM 10 to encrypt the communication data using the encryption method communicated from the KM 10 (step S20).
[0111] If the amount of stored application keys is less than the requested amount, the KM 10 shares the application key with the KM 10 connected to the destination of the communication data. If the amount of stored application keys is insufficient, the KM 10 returns a response to the UPF 14a rejecting the application key request. When responding, the KM 10 also notifies the UPF 14a of related information regarding the provision of the requested application keys (for example, the time when the requested amount of application keys will be available).
[0112] Through the above sequence, secure communication using PQC is performed from the UE 11 to the UPF 14a of the 5G core network. Then, communication data of a specific flow from the UPF 14a to a specified DN is encrypted with an application key using QKD and transferred to the specified DN via the UPF PSA 14c.
[0113] 7 is an example, and the order of processing may be adjusted and optimized depending on the actual situation and needs.
[0114] 8 is a diagram illustrating an example of a method for encrypting data packets of a specific flow as a whole according to an embodiment. The method for encrypting data packets as a whole is a method in which data packets of a specific flow are selected and encrypted as a whole, including the IP header and IP payload at the network layer.
[0115] For example, IPsec (Internet Protocol Security) technology is a method for comprehensive encryption. IPsec is a set of protocols for protecting IP communications at the network layer. IPsec is used to protect connections between devices and to keep data transmitted over public networks safe. IPsec is a mechanism for encrypting IP packets, making their contents unreadable to others, thereby creating a secure connection. IPsec supports a variety of encryption methods, including AES and Triple DES. IPsec can also be used for both asymmetric encryption (e.g., PQC technology) and symmetric encryption (e.g., QKD technology).
[0116] Another example of a method for full encryption is the TUNnel (TUN) / Terminal Access Point (TAP) technology of Open Virtual Private Network (VPN). TUN / TAP allows network communication in the same way as a device driver corresponding to a real hardware network card, but data is sent to and processed by a software process that virtualizes network communication, rather than by hardware. TAP simulates an Ethernet device and can manipulate the data link layer (MAC layer). TUN simulates the network layer (IP layer) and can manipulate IP packets, etc. Examples of uses include TAP being used for bridging and TUN being used for routing.
[0117] With the above technology, a dedicated tunnel is set up from the UPF PSA 14c to the server device 8 (cloud server), and encapsulation is realized in which the entire packet is embedded in protocol data (payload) of another layer or the same layer for communication.
[0118] Note that the application key is shared by QKDN, but the key ID of the application key (an identifier indicating which application key is being used) and the like are shared by a separate tunnel between the UPF PSA 14c and the server device 8. The tunnel may also run from the UPF 14a to the server device 8.
[0119] Figure 9 is a diagram showing an example of a method for encrypting the payload portion of a specific flow. A TCP segment is used as an example in Figure 9. Figure 9 shows a method in which an application key ID is stored in the Option field of the TCP header, and the payload portion is encrypted using the corresponding application key.
[0120] Figure 9 shows the TCP header and payload. First, we will explain the structure of the header.
[0121] Source port: A 16-bit field indicating the port number of the sender. Destination port: A 16-bit field that indicates the port number of the receiving side. Sequence number: A 32-bit field indicating the sequence number. Acknowledgment number: A 32-bit field indicating the acknowledgment number. Data offset: A 4-bit field that indicates the size of the TCP header in 32-bit words. This field is used to determine whether or not an option is being used. Reserved: A reserved field, 3 bits. This bit string is reserved for future use and is always set to 0. Flags: A 9-bit field indicating flags or control bit strings. There are nine 1-bit flags. Window size: A 16-bit field indicating the size of the receiving window. Checksum: A 16-bit field indicating a 16-bit checksum for detecting errors in the header and data. Urgent pointer: A 16-bit field indicating the urgent pointer. If the urgent pointer flag is set, it indicates the offset from the sequence number of the most recent urgent data byte. The Options: Header Length field determines the length of this field, which can vary from 0 to 320 bits in 32-bit increments. Type: 8-bit field indicating the option type. Length: 8-bit field indicating the option length. QKD identification code: A 12-bit field indicating the identifier used in the Option field in the QKD key ID. NK: A 2-bit field indicating the number of QKD keys. For example, "01" indicates that one 128-bit key ID is stored. "10" indicates that two 128-bit key IDs are stored. EM: A 2-bit field indicating the encryption method. For example, "00" indicates encryption using the OTP method. "01" indicates encryption using the AES method. Key ID: A field indicating the key ID, which can vary from 128 to 256 bits and changes in 128-bit increments. Unused / Padding: 32-bit field indicating unused or padding.
[0122] The length of the TCP header (160-bit fixed length + length indicated by the data offset) is subtracted from the length indicated in the "Length" field of the IP header, and the remaining part is the length of the TCP payload. The TCP payload part is encrypted with the application key corresponding to the key ID stored in the header.
[0123] As described above, in the QCF 7 (an example of an information processing device) of the embodiment, the processing unit 173 acquires the accumulated amount of the application key for each shared destination from one or more key management devices 10 that share an application key (second encryption key) with other key management devices 10 through encryption relay using a link key (first encryption key) shared with the counterpart QKD module 2 included in the QKDN. The processing unit 173 notifies the SMF 13 (an example of a control device) that controls communication in the user network of a specific rule that identifies a flow to be encrypted using the application key. The processing unit 173 acquires from the SMF 13 flow information including the UPF 14a (an example of a first communication device) and server device 8 (an example of a second communication device) that communicate the flow to be encrypted and the communication data amount, and determines whether the accumulated amount of the application key used by the UPF PSA 14c and server device 8 is equal to or greater than the communication data amount. If the accumulated amount of application keys is equal to or greater than the amount of communication data, the processing unit 173 instructs the key management device 10 connected to the UPF 14a to provide the application keys to the UPF 14a.
[0124] According to the QCF7 of the embodiment, encrypted communication using a QKD network can be performed more safely and efficiently for a specific flow.
[0125] As described above, the communication system according to this embodiment cooperates with the 5G core network and QKDN, and can realize encryption functionality using application keys from the QKDN only for specific flows between the 5G core network and the cloud. This reduces the need for the 5G core network to request QKDN to generate application keys. Furthermore, encryption methods related to security can be selected based on data volume and communication requirements. Furthermore, when other encryption methods are also managed by QCF17, management can be made more efficient and diverse.
[0126] (Modification 1 of the embodiment) Next, a variation of the above-described embodiment will be described. In the description of Variation 1, the same description as in the embodiment will be omitted, and only the differences from the embodiment will be described.
[0127] FIG. 10 is a diagram illustrating a specific flow encryption function according to a first modification of the embodiment. The difference between the first modification of FIG. 10 and the example of FIG. 5 is that the destination of the application key provided from the QKDN to the 5G core network is the QCF 17, not the UPF 14a. The advantage of the first modification is that the application key can be provided to a fixed destination (the IP address of the QCF 17), regardless of the selection of the UPF 14a and the establishment of the UPF PSA 14c. Furthermore, in the case of the first modification, authentication and authorization between the QCF 17 and the KM 10 only needs to be performed once.
[0128] It is also possible to encrypt data packets of a specific flow not only in the UPF 14a but also in the UPF PSA 14c. The QCF 17 transfers the application key to the UPF 14a or the UPF PSA 14c for encryption. For example, the application key is transferred to the UPF 14a or the UPF PSA 14c via the SMF 13 using an existing reference point. Alternatively, for example, the application key may be transferred directly from the QCF 17 to the UPF 14a or the UPF PSA 14c by defining a new reference point.
[0129] For example, an application key may be provided to the QCF 17 each time an application key is requested. Alternatively, for example, an area (buffer) for storing application keys may be provided in the QCF 17, so that application keys can be stored in advance even when no application key is requested. This reduces the time required to provide an application key from the KM 10 to the UPF 14a or UPF PSA 14c via the QCF 17.
[0130] (Modification 2 of the embodiment) Next, a variation of the above-described embodiment will be described. In the description of the second variation, the same description as in the embodiment will be omitted, and only the differences from the embodiment will be described.
[0131] FIG. 11 is a diagram illustrating the specific flow encryption function of a second modification of the embodiment. The difference between the second modification of FIG. 11 and the example of FIG. 7 is that the QCF 17 provides the application key to the interface of the UPF PSA 14c (the N6 described above) rather than to the UPF 14a or the UPF PSA 14c. For example, there is a mechanism called the N6 Local Area Network (LAN). The N6 LAN is a component that carries data from the UPF 14 to the DN (see FIG. 4). The N6 LAN plays the same role as the SGi-LAN in a 4G network. For example, the N6 LAN includes a local domain name system (LDNS), carrier-grade network address translation (CGNAT), a firewall, TCP optimization, and security services. To provide security services, for example, an encrypted interface and an unencrypted interface are installed, and the QCF 17 provides the application key only to the encrypted interface, thereby performing encryption.
[0132] The encryption keys in the above-described embodiment (FIG. 5) and variants 1 and 2 (FIGS. 10 and 11) may be used as hybrid keys by combining them with not only the application keys provided from the QKDN via QCF17 but also other encryption keys (for example, PQC encryption keys).
[0133] Finally, an example of the hardware configuration of the QKD module 2, key management device (KM) 10, and QCF 17 of the embodiment will be described.
[0134] [Example of hardware configuration] 12 is a diagram showing an example of the hardware configuration of the QKD module 2 of the embodiment. The QKD module 2 of the embodiment includes a control device 301, a main memory device 302, an auxiliary memory device 303, a display device 304, an input device 305, a quantum communication IF 306, and a classical communication IF 307.
[0135] The control device 301 , the main memory device 302 , the auxiliary memory device 303 , the display device 304 , the input device 305 , the quantum communication IF 306 and the classical communication IF 307 are connected via a bus 310 .
[0136] The control device 301 executes a program read from the auxiliary storage device 303 to the main storage device 302. The main storage device 302 is a memory such as a ROM and a RAM. The auxiliary storage device 303 is a HDD, a memory card, or the like.
[0137] The display device 304 displays the status of the QKD module 2, etc. The input device 305 accepts input from the user. The display device 304 and the input device 305 may be realized by a touch panel or the like having a display function and an input function. The display device 304 and the input device 305 may not be provided in the QKD module 2. In this case, for example, the display function and input function of an external terminal connected to the QKD module 2 are used.
[0138] The quantum communication IF 306 is an interface for connecting to a QKD link through which photons are transmitted. The classical communication IF 307 is an interface for connecting to a transmission path through which control signals are transmitted between the opposing QKD module 2 and a transmission path for communication with the key management device 10.
[0139] 13 is a diagram showing an example of the hardware configuration of the key management device 10 and the QCF 17 according to the embodiment. The key management device 10 and the QCF 17 include a control device 401, a main memory device 402, an auxiliary memory device 403, a display device 404, an input device 405, and a communication IF 406.
[0140] The hardware configurations of the QKDN control device 6, server device 8, UE 11, AMF 12, SMF 13, UPF 14, UDM 15, and PCF 16 are also the same as those in FIG.
[0141] The control device 401 , the main memory device 402 , the auxiliary memory device 403 , the display device 404 , the input device 405 and the communication IF 406 are connected via a bus 410 .
[0142] The control device 401 executes a program read from the auxiliary storage device 403 to the main storage device 402. The main storage device 402 is a memory such as a ROM and a RAM. The auxiliary storage device 403 is a HDD, a memory card, or the like.
[0143] The display device 404 displays the status of the key management device 10 and the QCF 17, etc. The input device 405 accepts input from the user. The display device 404 and the input device 405 may be realized by a touch panel or the like having a display function and an input function. Furthermore, the display device 404 and the input device 405 do not have to be provided in the key management device 10 and the QCF 17. In this case, for example, the display function and the input function of an external terminal connected to the key management device 10 and the QCF 17 are used.
[0144] The communication IF 406 is an interface for connecting to a transmission line.
[0145] The programs executed by the QKD module 2, key management device 10 and QCF 17 of the embodiment are provided as a computer program product stored in an installable or executable format on a computer-readable storage medium such as a CD-ROM, memory card, CD-R, or DVD (Digital Versatile Disc).
[0146] Furthermore, the programs executed by the QKD module 2, key management device 10, and QCF 17 may be stored on a computer connected to a network such as the Internet, and may be provided by being downloaded via the network.
[0147] Furthermore, the programs executed by the QKD module 2, the key management device 10, and the QCF 17 may be configured to be provided via a network such as the Internet without being downloaded.
[0148] Furthermore, the programs executed by the QKD module 2, the key management device 10, and the QCF 17 may be provided in advance by being stored in a ROM or the like.
[0149] It should be noted that some or all of the functions of the QKD module 2, the key management device 10, and the QCF 17 may be realized by hardware such as an IC (Integrated Circuit). The IC is, for example, a processor that executes dedicated processing.
[0150] Furthermore, when each function is realized using a plurality of processors, each processor may realize one of the functions, or may realize two or more of the functions.
[0151] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, and are also included in the scope of the invention and its equivalents as defined in the claims.
[0152] (Addendum) The above-described embodiments can be summarized as the following technical proposals.
[0153] Technical proposal 1 Acquires, from one or more key management devices that share a second encryption key with other key management devices by an encryption relay using a first encryption key shared with a QKD module included in a QKDN (Quantum Key Distribution Network), an accumulated amount of the second encryption key for each shared destination; notifying a control device that controls communication in the user network of a specific rule that identifies a flow to be encrypted with the second encryption key; acquires, from the control device, flow information including a first communication device and a second communication device that communicate with the flow to be encrypted and a communication data amount; determining whether an accumulated amount of the second encryption key used by the first communication device and the second communication device is equal to or greater than the communication data amount; a processing unit that instructs a key management device connected to the first communication device to provide the second encryption key to the first communication device when the accumulated amount of the second encryption key is equal to or greater than the amount of communication data; An information processing device comprising: Technical proposal 2 The user network includes a 5G core network and an IP network, The control device is a device that controls communication of the 5G core network, The first communication device is a device that controls communication of a user of the 5G core network, the second communication device is a server device connected to the IP network; An information processing device according to Technical Proposal 1. Technical proposal 3 the control device is a Session Management Function (SMF), The first communication device is a UPF (User Plane Function). An information processing device according to Technical Proposal 2. Technical proposal 4 a storage device that stores the accumulated amount of the second encryption key for each shared destination and the total amount of the communication data encrypted and communicated using the second encryption key; The information processing device according to any one of technical proposals 1 to 3, further comprising: Technical proposal 5 the processing unit notifies a billing management device of the user network of the total amount of communication data encrypted and communicated using the second encryption key. An information processing device according to any one of technical proposals 1 to 4. Technical plan 6 the processing unit acquires the specific rule from a user terminal or an administrator terminal of the user network. An information processing device according to any one of technical proposals 1 to 5. Technical proposal 7 the processing unit determines a routing path between the first communication device and the key management device, and notifies the key management device connected to the first communication device of the routing path; An information processing device according to any one of technical proposals 1 to 6. Technical proposal 8 the processing unit determines the encryption method using the second encryption key to be the first encryption method when the accumulated amount of the second encryption key is equal to or greater than the communication data amount, and determines the encryption method using the second encryption key to be the second encryption method when the accumulated amount of the second encryption key is less than the communication data amount, and notifies a key management device connected to the first communication device of the determined encryption method. An information processing device according to any one of technical proposals 1 to 7. Technical proposal 9 the first encryption method is an encryption method in which the amount of the second encryption key used for encryption is greater than that of the second encryption method, the second encryption method is an encryption method in which the amount of the second encryption key used for encryption is smaller than that of the first encryption method; An information processing device according to Technical Proposal 8. Technical proposal 10 the first encryption method is an OTP (One Time PAD) encryption method, The second encryption method is an AES (Advanced Encryption Standard) encryption method. An information processing device according to Technical Proposal 9. Technical proposal 11 An information processing device according to any one of technical proposals 1 to 10; the control device that controls communication of the flow to be encrypted between the first communication device and the second communication device; the first communication device; a key management device connected to the first communication device; A quantum cryptography communication system comprising: Technical proposal 12 an information processing device acquires, from one or more key management devices that share a second encryption key with other key management devices by an encryption relay using a first encryption key shared with a QKD module of a QKDN (Quantum Key Distribution Network), an accumulated amount of the second encryption key for each shared destination; the information processing device notifies a control device that controls communication in a user network of a specific rule that identifies a flow to be encrypted with the second encryption key; the information processing device acquires, from the control device, flow information including a first communication device and a second communication device that communicate with the flow to be encrypted and a communication data amount; determining whether an accumulated amount of the second encryption key used by the first communication device and the second communication device is equal to or greater than the communication data amount; When the accumulated amount of the second encryption key is equal to or greater than the communication data amount, the information processing device instructs a key management device connected to the first communication device to provide the second encryption key to the first communication device. Information processing methods. Technical proposal 13 In the information processing device, acquires, from one or more key management devices that share a second encryption key with other key management devices by an encryption relay using a first encryption key shared with a QKD module of a QKDN (Quantum Key Distribution Network), an accumulated amount of the second encryption key for each shared destination; notifying a control device that controls communication in a user network of a specific rule that identifies a flow to be encrypted using the second encryption key; acquires, from the control device, flow information including a first communication device and a second communication device that communicate with the flow to be encrypted and a communication data amount; determining whether or not an accumulated amount of the second encryption key used by the first communication device and the second communication device is equal to or greater than the communication data amount; when the accumulated amount of the second encryption key is equal to or greater than the amount of communication data, causing a key management device connected to the first communication device to instruct the first communication device to provide the second encryption key to the first communication device; program. [Explanation of symbols]
[0154] 1 node 2 QKD modules 3 QKD Link 4 QKD Network Controller 5. Applications 6 QKDN control device 7 User network control device 8 Server equipment 9 gNB (base station) 10 KM (key management device) 11 UE (terminal) 12 AMF 13 SMF 14 UPF 15 UDM 16 PCF 17 QCF 171 Communications Department 172 Memory section 173 Processing Section 301 Control device 302 Main storage 303 Auxiliary storage device 304 Display device 305 Input Device 306 Quantum Communication Interface 307 Classical Communication IF 310 Bus 401 Control device 402 Main storage 403 Auxiliary storage 404 Display device 405 Input Device 406 Communication Interface 410 Bus
Claims
1. acquiring, from one or more key management devices that share a second encryption key with other key management devices by an encryption relay using a first encryption key shared between opposing QKD modules included in a QKDN (Quantum Key Distribution Network), an accumulated amount of the second encryption key for each of the shared devices; notifying a control device that controls communication in a user network of a specific rule that identifies a flow to be encrypted using the second encryption key; acquires, from the control device, flow information including a first communication device and a second communication device that communicate with the flow to be encrypted and a communication data amount; determining whether an accumulated amount of the second encryption key used by the first communication device and the second communication device is equal to or greater than the communication data amount; a processing unit that instructs a key management device connected to the first communication device to provide the second encryption key to the first communication device when the accumulated amount of the second encryption key is equal to or greater than the amount of communication data; An information processing device comprising:
2. The user network includes a 5G core network and an IP network, The control device is a device that controls communication of the 5G core network, The first communication device is a device that controls communication of a user of the 5G core network, the second communication device is a server device connected to the IP network; The information processing device according to claim 1 .
3. the control device is a Session Management Function (SMF), The first communication device is a UPF (User Plane Function), The information processing device according to claim 2 .
4. a storage device that stores the accumulated amount of the second encryption key for each shared destination and the total amount of the communication data encrypted and communicated using the second encryption key; The information processing device according to claim 1 , further comprising:
5. the processing unit notifies a billing management device of the user network of the total amount of communication data encrypted and communicated using the second encryption key. The information processing device according to claim 1 .
6. the processing unit acquires the specific rule from a user terminal or an administrator terminal of the user network. The information processing device according to claim 1 .
7. the processing unit determines a routing path between the first communication device and the key management device, and notifies the key management device connected to the first communication device of the routing path; The information processing device according to claim 1 .
8. the processing unit determines the encryption method using the second encryption key to be the first encryption method when the accumulated amount of the second encryption key is equal to or greater than the communication data amount, and determines the encryption method using the second encryption key to be the second encryption method when the accumulated amount of the second encryption key is less than the communication data amount, and notifies a key management device connected to the first communication device of the determined encryption method. The information processing device according to claim 1 .
9. the first encryption method is an encryption method in which the amount of the second encryption key used for encryption is greater than that of the second encryption method, the second encryption method is an encryption method in which the amount of the second encryption key used for encryption is smaller than that of the first encryption method; The information processing device according to claim 8 .
10. the first encryption method is an OTP (One Time PAD) encryption method, The second encryption method is an AES (Advanced Encryption Standard) encryption method. The information processing device according to claim 9 .
11. An information processing device according to any one of claims 1 to 3; the control device that controls communication of the flow to be encrypted between the first communication device and the second communication device; the first communication device; a key management device connected to the first communication device; A quantum cryptography communication system comprising:
12. The information processing device acquires, from one or more key management devices that share a second encryption key with other key management devices by an encryption relay using a first encryption key shared between the information processing device and a QKD module included in a QKDN (Quantum Key Distribution Network), an accumulated amount of the second encryption key for each of the shared devices; the information processing device notifies a control device that controls communication in a user network of a specific rule that identifies a flow to be encrypted with the second encryption key; the information processing device acquires, from the control device, flow information including a first communication device and a second communication device that communicate with the flow to be encrypted and a communication data amount; determining whether an accumulated amount of the second encryption key used by the first communication device and the second communication device is equal to or greater than the communication data amount; when the accumulated amount of the second encryption key is equal to or greater than the communication data amount, the information processing device instructs a key management device connected to the first communication device to provide the second encryption key to the first communication device. Information processing methods.
13. In the information processing device, acquires, from one or more key management devices that share a second encryption key with other key management devices by an encryption relay using a first encryption key shared between opposing QKD modules included in a QKDN (Quantum Key Distribution Network), an accumulated amount of the second encryption key for each of the shared devices; notifying a control device that controls communication in a user network of a specific rule that identifies a flow to be encrypted using the second encryption key; acquires, from the control device, flow information including a first communication device and a second communication device that communicate with the flow to be encrypted and a communication data amount; determining whether or not an accumulated amount of the second encryption key used by the first communication device and the second communication device is equal to or greater than the communication data amount; when the accumulated amount of the second encryption key is equal to or greater than the communication data amount, causing a key management device connected to the first communication device to instruct the first communication device to provide the second encryption key to the first communication device; program.
Citation Information
Patent Citations
Transfer device, key management server device, communication system, transfer method, and program
JP2022075398A