User terminal apparatus system, cryptographic communication system, and method for cryptographic communication

The user base device system with CVQKD and BB84QKD devices in a nested configuration addresses the high cost and interception risks of quantum key distribution by distributing encryption keys through multiple paths, enhancing security and reducing interception risks.

JP2025159030APending Publication Date: 2025-10-17KK TOSHIBA +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025131354
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

Existing quantum key distribution systems face challenges in securely distributing encryption keys over long distances due to the high cost of BB84QKD devices and the risk of interception during transmission over the Internet, known as the last-mile problem.

Method used

A user base device system utilizing CVQKD devices and BB84QKD devices in a nested configuration with multiple encryption key transmission paths, ensuring encryption keys are distributed and recovered using quantum key distribution channels to enhance security and prevent complete key restoration.

Benefits of technology

The system provides secure encryption key distribution with improved security performance by using inexpensive CVQKD devices and multiple paths, making it resistant to eavesdropping and reducing the risk of key interception.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025159030000001_ABST
    Figure 2025159030000001_ABST
Patent Text Reader

Abstract

To prevent, by inexpensive means and methods, eavesdropping on an encryption key shared between a first user terminal and a second user terminal, and to provide a user terminal apparatus, a cryptographic communication system and a method for cryptographic communication that improve security.SOLUTION: A user terminal includes: an encryption module for transmitting encrypted data; and a key sharing module having functions of restoring and distributing an encryption key used to generate the encrypted data. The key sharing module includes a plurality of CVQKD devices for distributing a plurality of random keys obtained by distributing the encryption key through different transmission paths, respectively. The plurality of CVQKD devices are quantum-connected to CVQKD devices provided in relay nodes of the respective different transmission paths. Furthermore, the plurality of CVQKD devices are connected to a key distribution / restoration circuit for performing distribution and restoration of the encryption key.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a user base device system, an encrypted communication system, and an encrypted communication method. [Background technology]

[0002] Currently popular public key cryptography relies on computational security, meaning that existing computers and algorithms cannot decrypt the cryptography within a reasonable time. In the future, when quantum computers begin to operate, computational security will no longer be guaranteed, and conventional cryptography will no longer be able to ensure secure communications. Therefore, quantum cryptography is expected to be a cryptography method that has information-theoretic security and does not rely on computational security.

[0003] However, due to the nature of systems using quantum cryptography, which use optical cables, there are limitations on the distance over which remote users can directly share keys. To extend the communication distance, there is a technology that uses intermediate nodes (or relay nodes) to relay quantum cryptography keys. Using this relay technology, users in remote locations can share quantum cryptography keys.

[0004] However, quantum key distribution (hereinafter referred to as BB84QKD) devices using the quantum cryptography protocol BB84 are expensive, and users cannot easily own many of them.

[0005] For this reason, there is an idea to reduce costs by distributing encryption keys (random number keys) from a routing point (key distribution server) to user points over the Internet.

[0006] However, this method poses the risk of the encryption key (random number key) being intercepted during transmission over the Internet. This problem is known as the last-mile problem. [Prior art documents] [Patent documents]

[0007] [Patent Document 1] Patent No. 3263878 [Patent Document 2] Patent No. 4304215 [Patent Document 3] Patent No. 5672425 [Patent Document 4] Patent No. 5685735 [Patent Document 5] Patent No. 6783772 Summary of the Invention [Problem to be solved by the invention]

[0008] As described above, if key distribution from a site that routes encryption keys to a user site is achieved over the Internet, the last-mile problem will occur.

[0009] Therefore, the object of the present invention is to provide a user base device, an encrypted communication system, and an encrypted communication method that improve security by using a user base, a relay node for sending an encryption key (also called a random number key) to be used at this user base, and a relay node for receiving the encryption key from the user base as nodes having a separate, relatively inexpensive QKD device (for example, a CVQKD (Continuous Variable QKD) device).

[0010] Furthermore, the present invention aims to provide a user base device, an encrypted communication system, and an encrypted communication method that distributes an encryption key (random number key), provides multiple routes for transmitting the distributed random number key, and receives the distributed random number key, thereby preventing the encryption key (random number key) from being completely restored along the route. [Means for solving the problem]

[0011] According to one embodiment, there is provided a user base device system including a cryptographic module for transmitting encrypted data and a key sharing module having a function of restoring and distributing a cryptographic key used to generate the encrypted data, wherein the cryptographic module encrypts plaintext data using the cryptographic key and outputs the encrypted data via the Internet, the key sharing module includes first and second CVQKD devices corresponding to the first and second paths; a first relay node having a third CVQKD device to which the first CVQKD device is connected via an optical fiber to form the first path; a second relay node having a fourth CVQKD device to which the second CVQKD device is connected via an optical fiber to form the second path; the first and second CVQKD devices are further connected to an encryption key distribution / recovery circuit for distributing the encryption key and recovering the distributed encryption key; the first relay node further comprises a BB84QKD device on the output side to which an output of the third CVQKD device is optically coupled; the second relay node further comprises a BB84QKD device on the output side to which an output of the fourth CVQKD device is optically coupled; Furthermore, the first and second encryption keys shared by the key sharing module are supplied to the encryption module that encrypts plaintext data; The cryptographic module is provided with means for performing an exclusive-OR operation on the distributed first cryptographic key and the second cryptographic key, and further performing an exclusive-OR operation on the result of this operation with the plaintext data, and transmitting the resulting encrypted data to the Internet. [Brief explanation of the drawings]

[0012] [Figure 1] FIG. 1 is a diagram illustrating the configuration of a quantum cryptography communication system that is the premise of the present invention. [Figure 2] FIG. 2 is a diagram illustrating the configuration of one embodiment of the present invention. [Figure 3]FIG. 3 is a diagram showing an example of the configuration of the key sharing modules 102 and 202 in FIG. [Figure 4] FIG. 4 is an explanatory diagram showing an example of the arrangement of devices within the site A. [Figure 5A] FIG. 5A is an explanatory diagram showing an example of an arrangement of devices in a relay node. [Figure 5B] FIG. 5B is an explanatory diagram showing an example of an arrangement of devices within an intermediate node. [Figure 6] FIG. 6 is a diagram illustrating the configuration of still another embodiment of the present invention. [Figure 7] FIG. 7 is a flowchart illustrating an example of processing when an encryption key is distributed and assigned to a plurality of routes. [Figure 8] FIG. 8 is a flowchart illustrating an example of a process for collecting and restoring keys distributed over multiple routes. [Figure 9] FIG. 9 is an explanatory diagram illustrating a static type in which a plurality of key transmission paths are set. [Figure 10] FIG. 10 is an explanatory diagram showing a dynamic type that sets up the above-mentioned multiple key transmission paths. [Figure 11] FIG. 11 is a diagram showing an example of a combination of CVQKD devices and BB84QKD devices at relay nodes and intermediate nodes. [Figure 12] FIG. 12 is a diagram showing another example of a combination of CVQKD devices and BB84QKD devices in relay nodes and intermediate nodes. [Figure 13] FIG. 13 is a diagram showing yet another example of a combination of CVQKD devices and BB84QKD devices in relay nodes and intermediate nodes. [Figure 14] FIG. 14 is a diagram illustrating an example of a method for generating an encryption key (random number key) 132 in the key sharing module and an example of encryption of plaintext data 131 at site A. In FIG. [Figure 15] FIG. 15 is an explanatory diagram illustrating a method for generating a distributed encryption key. [Figure 16] FIG. 16 is an explanatory diagram illustrating a method for restoring a distributed encryption key. [Figure 17] FIG. 17 is an explanatory diagram showing an example of encryption of plaintext data 131 at site A. In FIG. [Figure 18] FIG. 18 is an explanatory diagram illustrating another example of a method for generating a distributed encryption key. [Figure 19] FIG. 19 is an explanatory diagram illustrating another example of a method for restoring a distributed encryption key. DETAILED DESCRIPTION OF THE INVENTION

[0013] Hereinafter, embodiments will be described with reference to the drawings. FIG. 1 shows an example of the configuration of a quantum cryptography communication system that is the premise of this invention. Assume that A is a first point (which may be referred to as user A's device) that is the source of transmission, and B is a second point B (which may be referred to as user B's device) that is the destination of transmission. Note that points A and B can communicate with each other, but in this example, the first point A is the source of transmission and the second point B is the destination of transmission. The first point A and the second point B are connected via an encrypted data transmission system 300. The encrypted data transmission system 300 is configured on the Internet, for example. The first location A includes a processor 100, a cryptographic module 101, and a key sharing module 102. The second location B also includes a processor 200, a cryptographic module 201, and a key sharing module 202.

[0014] Here, it is assumed that the key sharing module 102 at the first point A and the key sharing module 202 at the second point B are each configured by, for example, a CVQKD device (which may also be called a second-type QCD device).

[0015] The key sharing module 102 at the first point A is connected to a relay node C via a quantum key distribution channel 511. The key sharing module 202 at the second point B is connected to a relay node D via a quantum key distribution channel 521.

[0016] The relay node C includes a CVQKD device 411 and a BB84QKD device (a QKD device that uses the quantum cryptography protocol BB84, and may also be referred to as a first-type QKD device) 442, and the two QKD devices can exchange random number keys with each other.

[0017] Terminal node D has a similar configuration to terminal node C, and includes a CVQKD device 444 and a BB84QKD device 443 (first type QKD device), and the two QKD devices can exchange random number keys with each other.

[0018] BB84QKD device 442 of relay node C and BB84QKD device 443 of relay node D are connected by encryption key transmission path 400, which connects intermediate nodes 401 and 402. Intermediate node 401 has BB84QKD device 411 and BB84QKD device 421, and intermediate node 402 also has BB84QKD device 411 and BB84QKD device 422. This encryption key transmission path 400 distributes quantum encryption keys in a so-called nested structure, such as converting key A1 to key A2, then converting key A2 to key A3, and finally distributing the key back to key A1. Distribution in this manner prevents eavesdropping and increases security.

[0019] In the above system, the key sharing module 102 generates an encryption key (random number key) 132. The encryption module 101 encrypts plaintext data 131 using the encryption key (random number key) 132 from the key sharing module 102. The encrypted encrypted data 302 is then transmitted to a second location B via an encrypted data transmission system 300. The plaintext data 131 is read from a storage device (not shown) in the processor 100. The encrypted data 302 is data obtained by, for example, performing an exclusive OR (XOR) operation on the plaintext data 131 and the encryption key 132. The encrypted data transmission system 300 is the Internet.

[0020] Meanwhile, relay node C performs relay processing by receiving the encryption key (random number key) sent from the key sharing module 102 at site A using the CVQKD device 411, then inputting it into the BB84QKD device 442, and outputting it from this BB84QKD device 442 to the external encryption key transmission path 400.

[0021] The BB84QKD device 442 outputs a quantum key (an encryption key for optical communication) to the BB84QKD device 411 at the intermediate node 401 on the encryption key transmission path 400 .

[0022] In the intermediate node 401, the BB84QKD device 412 receives the random key from the BB84QKD device 411. Next, this BB84QKD device 412 transmits the random key to a BB84QKD device 421 in the next intermediate node 402. In this intermediate node 402, the BB84QKD device 422 receives the random key from the BB84QKD device 421.

[0023] As described above, at the intermediate nodes 401 and 402 on the encryption key transmission path 400, random number keys are distributed by quantum key distribution using only the BB84QKD devices.

[0024] The random key distributed as described above is received by the BB84QKD device 443 of the relay node D when it approaches site B. The random key received by the BB84QKD device 443 is sent to the CVQKD device 444. The CVQKD device 444 distributes the random key to the key sharing module 202 in site B via the quantum key distribution path 521.

[0025] The key sharing module 202 supplies the encryption (random number) key 132 to the encryption module 201. The encryption module 201 performs a decryption operation using the encryption data 302 obtained from the encryption data transmission system 300 and the encryption key 132 to obtain the original plaintext data 131. This plaintext data is taken into the processor 200.

[0026] According to the above-described system, the first relay node C and the first key agreement module 102 are connected by a first quantum key distribution channel 511, and use their respective CVQD devices to distribute encryption keys. Similarly, the second relay node D and the second key agreement module 202 are connected by a quantum key distribution channel 521, and use their respective CVQKD devices to distribute encryption keys.

[0027] As a result, according to the present cryptographic communication system and method, the encryption key distribution in the eavesdropping risk area between site A and relay node C is performed using quantum key distribution channel 511, thereby improving security performance. The same can be said for the case between site B and relay node D.

[0028] However, there are further concerns even with the configuration shown in Fig. 1. Therefore, the inventors have focused on further improving the security capabilities of the above-mentioned encrypted communication system.

[0029] 2 shows one embodiment of the present invention. This embodiment is designed to further ensure the security of encryption keys, since there is a possibility of eavesdropping on the connection line Y1 between the BB84QKD device 442 and the CVQKD device 441 of the relay node C, and on the connection line Y2 between the BB84QKD device 443 and the CVQKD device 444 of the relay node D.

[0030] 2, the same components as those in Fig. 1 will be described with the same reference numerals as those in Fig. 1. The system in Fig. 2 further includes a second encryption key transmission path 600 between the site A and the site B.

[0031] Here, the encryption key transmission path 400 will be referred to as the first encryption key transmission path 400, and the encryption key transmission path 600 shown in FIG.

[0032] The second encryption key transmission path 600 connects a relay node 601 and a relay node 602 in series. The relay node 601 has a configuration in which a CVQKD device 611 and a BB84QKD device 612 are connected in series. Similarly, the relay node 602 has a configuration in which a BB84QKD device 621 and a CVQKD device 622 are connected in series. Of course, there may be multiple intermediate nodes between the relay nodes 601 and 602, as in the first encryption key transmission path 400.

[0033] In the above configuration, multiple (two in this example) encryption key transmission paths 400 are provided. For this purpose, two CVQKD devices 102a and 102b are provided inside the key sharing module 102 to connect to the CVQKD devices in the relay nodes of each of the paths 400 and 600.

[0034] That is, the key sharing module 102 at site A includes a CVQKD device 102a (connected via optical cable 511a) that connects to the CVQKD device 441 at relay node C, and a CVQKD device 102b (connected via optical cable 511b) that connects to the CVQKD device 611 at the relay node 601 on the second encryption key transmission path 600.

[0035] The key sharing module 202 at site B also has a similar configuration to that at site A, and includes a CVQKD device 202a (connected via optical cable 521a) that connects to the CVQKD device 444 at relay node D, and a CVQKD device 202b (connected via optical cable 521b) that connects to the CVQKD device 622 at the relay node 602 on the second encryption key transmission path 600.

[0036] According to the above-described configuration, the encryption key is distributed between the sender and the destination, and the encryption key is shared using multiple encryption key transmission paths 400, 600. Therefore, even if any node (an intermediate node or a relay node) on the encryption key transmission path is attacked, the attacker can only obtain a portion of the distributed encryption key, and cannot obtain the entire encryption key. Therefore, with this configuration, users can safely share encryption keys and perform encrypted communications.

[0037] CVQKD devices can be implemented more cheaply than BB84QKD devices. BB84QKD devices use quantum detectors that detect light as granular photons, which requires high performance and therefore makes them expensive. In contrast, CVQKD devices use general photodetectors that detect light as wave strengths, which makes them inexpensive to implement. However, the two can be connected via optical fiber cable and can coexist. This system makes good use of this coexistence to improve communication security at low cost.

[0038] Fig. 3 shows a representative example of the configuration of the key sharing module 102 at site A in Fig. 2. In this embodiment, two CVQKD devices 102a and 102b are connected to a distribution / recovery circuit 102c. CVQKD device 102a is connected to relay node C via optical cable 511a, and CVQKD device 102b is connected to relay node 601 via optical cable 511b.

[0039] The key sharing module 202 in FIG. 2 has a similar configuration to that described above, and in the case of the key sharing module 202, each CVQKD device is connected to optical cables 521a and 521b, respectively.

[0040] Therefore, the configuration of the devices at points A and B in this embodiment can be described as follows: That is, device A at a user site is equipped with a cryptographic module 101 for transmitting encrypted data and a key sharing module 102 having the function of restoring or sharing the cryptographic key used to generate the encrypted data. The key sharing module 102 distributes a plurality of encryption keys (a plurality of random number keys) obtained by distributing the encryption key via different routes, and receives the distributed encryption keys sent via the different routes. The user base device is equipped with multiple CVQKD devices 102a, 102b that are quantum-connected to a CVQKD device in a relay node located at the first stage of the different paths, and a cryptographic key distribution / recovery circuit 102c to which the multiple CVQKD devices are connected.

[0041] In the above embodiment, the configuration of the encrypted communication system can be described as follows. That is, the encrypted communication system has a first point A and a second point B connected by a cryptographic data transmission system. A first relay node C and the first point A are quantum-connected by their respective CVQKD devices and relay the distributed encryption key. A second relay node D and the second point B are quantum-connected by their respective CVQKD devices and relay the distributed encryption key. A third relay node 601 and the first point A are quantum-connected by their respective CVQKD devices and relay the distributed encryption key. A fourth relay node 602 and the second point B are quantum-connected by their respective CVQKD devices and relay the distributed encryption key. And, This is an encrypted communication system in which the first relay node C and the second relay node D are connected to each other by their respective BB84QKD devices, and the third relay node 601 and the fourth relay node 602 are also connected to each other by their respective BB84QKD devices.

[0042] Next, the configuration will be described by showing the external appearance of the devices in each of the above-mentioned blocks (base, relay node, intermediate node, etc.).

[0043] 4 is an explanatory diagram showing an example of the arrangement of devices within site A and site B. Site A will be described as a representative. The cryptographic module 101 has an encrypted communication server 101a, and the processor 100 includes, for example, a personal computer. The key sharing module 102 has CVQKD devices 102a and 102b, a control server 102c, and a key management server 102d.

[0044] The above-mentioned encrypted communication server 101a has the function of encrypting plaintext data using an encryption key shared by the key management server 102d in response to an application request from the processor 100, and the function of transmitting the encrypted encrypted data to another location B.

[0045] The control server 102c in the key sharing module 102 controls the entire key sharing module 102. The key management server 102d has a function to share an encryption key with another site B. The key management server 102d also has a function to distribute or restore an encryption key as described in FIG.

[0046] 2 or 3, the CVQKD devices 102a and 102b are connected to the CVQKD device 441 of the relay node C via the optical cable 511a, and the CVQKD device 102b is connected to the CVQKD device 611 of the relay node 601 via the optical cable 511b. Site B has a similar configuration.

[0047] 5A is an explanatory diagram showing an example of an arrangement of devices in relay nodes C and D. The relay node C will be described as a representative. The relay node C includes a key management server 461, a control server 462, a CVQKD device 441, and a BB84QKD device 442.

[0048] Relay node C is a point that connects the last mile between CVQKD equipment and BB84QKD equipment. Relay node C is equipped with an inexpensive CVQKD device 441 for connection to user site A, and a BB84QKD device 442 for connection to BB48QKD equipment 411 in intermediate node 401. Both connections use optical cables.

[0049] The control server 462 has a function of communicating with the user site A through optical fiber using the CVQKD device 441 and sharing a quantum key. The control server 462 also has a function of communicating with the BB84QKD device 411 of the intermediate node 401 through optical fiber using the BB84QKD device 442 and sharing a quantum key.

[0050] The key management server 461 has the function of routing the encryption key (distributed random number key) to be shared between user locations to the next node (user location, relay node, intermediate node) using the quantum key obtained from the control server 462 via a general network.

[0051] 5B is an explanatory diagram showing an example of the device arrangement of intermediate nodes 401 and 402. Intermediate node 401 will be described as a representative. Intermediate node 401 includes a key management server 461, a control server 462, a BB84QKD device 411, and a BB84QKD device 412.

[0052] This intermediate node is a point where the BB84QKD device 411 and the BB84QKD device 412 relay the distributed encryption key (distributed random number key).

[0053] The control server 462 has a function of sharing quantum keys with relay nodes or intermediate nodes through optical fibers using the BB84QKD devices 411 and 412. The key management server 461 has a function of routing the encryption key to be shared between user sites to the next node (user site, relay node, intermediate node) using the quantum key obtained from the control server 462 through a general network.

[0054] Fig. 6 is a diagram showing a further embodiment. This embodiment enables the exchange of encryption keys (distributed encryption keys) between multiple user locations via a mesh-type quantum cryptography distribution network. Parts with the same functions as those in the previous embodiment will be described using the same reference numerals as those in the previous embodiment.

[0055] In this embodiment, since the quantum cryptography distribution network is of a mesh type, the number of encryption key transmission paths can be set arbitrarily, and it is possible to construct a large number of key transmission paths (routes). The setting type of the large number of key transmission paths (routes) may be either static or dynamic.

[0056] 6 shows an example in which three key transmission paths are established. A case in which encrypted data is transmitted from point A to point B will be described.

[0057] The first key transmission path RU1 is established between a relay node RU11 at point A and a relay node RU1N at point B, and is made up of intermediate nodes RU12, RU13, . . . RU1(N-1). The second key transmission path RU2 is established between a relay node RU21 at point A and a relay node RU2N at point B, and is made up of intermediate nodes RU22, RU23, . . . RU2(N-1). The third key transmission path RU3 is established between a relay node RU31 at point A and a relay node RU3N at point B, and is composed of intermediate nodes RU32, RU33, ... RU3(N-1).

[0058] In this embodiment, the encryption key 132 is divided into three divided encryption keys 132a, 132b, and 132c, which are transmitted from site A to site B via key transmission paths RU1, RU2, and RU3, respectively. The encryption module 101 at site A transmits the encryption key to the encryption module 201 at site B via the encrypted data transmission system 300.

[0059] For ease of understanding, the figure shows the key simply split into three parts. However, there are various encryption methods, and "splitting" and "distribution" are different things, and we will explain how to generate these encryption keys later.

[0060] Meanwhile, distributed encryption keys (which may also be referred to as distributed random number keys) 132a, 132b, and 132c are sent from the key sharing module 102 to the relay nodes RU1, RU2, and RU3 that form the respective routes. The configurations of the respective relay nodes RU1, RU2, and RU3 are the same as those described with reference to Figures 2 and 5A. The key sharing module 102 at site A is equipped with three CVQKD devices for sending the encryption keys 132a, 132b, and 132c to the respective relay nodes RU1, RU2, and RU3.

[0061] The intermediate nodes RU12, RU13, . . . RU1(N-1), the intermediate nodes RU22, RU23, . . . RU2(N-1), and the intermediate nodes RU32, RU33, . . . RU3(N-1) have the same configurations as those described in Figures 2 and 5B. The key sharing module 202 at site B has three CVQKD devices for receiving encryption keys 132a, 132b, and 132c from the respective relay nodes RU1, RU2, and RU3.

[0062] The number of intermediate nodes can be adjusted as desired depending on the distance between site A and site B. Therefore, there are cases where intermediate nodes are not required, and the relay node on site A's side and the relay node on site B's side are directly connected. In addition, in this embodiment, a mesh-type quantum cryptography distribution network is used, so the number of routes can also be changed.

[0063] 7 is a flowchart illustrating an example of processing for distributing an encryption key and allocating the distributed encryption key to multiple routes. This processing function is provided in each of the key sharing modules 102 and 202.

[0064] This processing function is roughly divided into a quantum key sharing processing block 710, an encryption key generation block 720, and an encryption key distribution processing block 730.

[0065] The quantum key sharing processing block 710 receives a command from the input unit 71. In response to the command, the quantum key sharing processing block 710 prepares in advance any number of routes for sharing a quantum key. For example, routes 1 to n are prepared. The information for each route is, for example, the arrangement information for the relay nodes and intermediate nodes between site A and site B as explained above. These routes 1 to n are not all used at the same time, but the quantum key sharing processing block 710 selects and identifies routes that have not been used as much as possible from route 1, route 2, route 3, ..., route n. Therefore, the profile information for each route also includes information on the number of times it has been used.

[0066] Next, the encryption key generation block 720 generates an encryption key for distribution from one location to another after multiple routes have been identified.

[0067] Next, the encryption key distribution processor 730 processes the encryption key as follows: First, the encryption key is distributed (step 731). In this case, the number of shares is set to the same number as the number of routes set earlier, and distributed encryption keys are generated and stored in memory. Note that, as for the distribution of the encryption key, the generated random numbers may also be regarded as the result of distributing the encryption key, as will be described later.

[0068] Next, a check is made to see if any distributed encryption keys remain in the memory (step 732). If any remain, a transmission path for the distributed encryption keys is selected, for example, from a path that has been used least frequently (step 733). Next, the distributed keys (shared quantum keys) are transmitted to the selected path, and the process returns to step 732 (step 734). The routine from step 732 to step 734 is repeated, and if no distributed keys remain, an end notification is output to the output unit 72.

[0069] 8 is a flowchart showing an example of a process for collecting encryption keys distributed over multiple routes and restoring the original encryption key at the receiving site B. This process is provided in the key sharing modules 102 and 202.

[0070] This processing block is roughly divided into a quantum key sharing processing block 810 and a shared encryption key recovery processing unit 830 .

[0071] The quantum key sharing processing block 810 receives a command from the input unit 81. In response to the command, the quantum key sharing processing block 810 establishes multiple paths (multiple paths prepared in advance) for sharing the quantum key (these are the same as paths 1 to n shown in FIG. 7). Note that information about the multiple paths that will actually be used has been mutually confirmed in advance between site A and site B.

[0072] The shared encryption keys received from multiple routes are input to a shared encryption key restoration processor 830. The restoration processor 830 first determines whether all the shared encryption keys have been received (step 831). If all the shared encryption keys have been received, it executes restoration processing of the original encryption key using the shared encryption keys (step 833). If collection of the shared encryption keys has not been completed in step 831, it waits for reception of the shared encryption keys and returns to step 831 (steps 831, 832).

[0073] In step 833, when all of the distributed encryption keys are collected and the original encryption key is restored, this encryption key is provided to encryption module 201, which decrypts the encrypted data. That is, encrypted communication between the users begins (step 834). Information that encrypted communication has begun is output from output unit 82.

[0074] Fig. 9 is an explanatory diagram explaining how to construct the above-mentioned multiple routes (multiple route construction method: static type). Fig. 7 was explained on the assumption that multiple routes from site A to site B have already been determined, but Fig. 9 explains how to construct each route.

[0075] First, the premise is that the route management server 1000 is deployed on a cloud and has node information on the route in its database. In other words, the route management server 1000 manages a large number of nodes that make up the quantum cryptography distribution network and has location (address) information for each node on the distribution network (which may also be referred to as intersection information for a three-dimensional matrix network). Each node also has a selector that can connect or disconnect with any of multiple other nearby nodes, and a control circuit for this selector. The control circuit of the node addressed by the route management server 1000 can also be in a standby state to select an input node and an output node and construct part of the route in response to a command from the server 1000.

[0076] 9, an example will be described in which a plurality of routes are constructed from site A to site B. The following is a description of the operation based on a command from the route management server 1000.

[0077] For example, upon receiving a notification from point A, the relay node RU11 sends link request information to the route management server 1000. The link request information includes information indicating that point B is the communication partner and the number of routes for communication.

[0078] The route management server 1000 designates the intermediate node RU12 adjacent to the relay node RU11, and indicates the adjacent relay node RU11 as the link destination. As a result, the intermediate node RU12 is linked to the relay node RU11. Next, the route management server 1000 designates the intermediate node RU13, and indicates the intermediate node RU12 as the link destination. As a result, the intermediate nodes RU12 and RU13 are linked. In this way, routes are constructed one after another, and a route to the intermediate node RU1(N-1) (not shown), which is immediately before the relay node RU1N adjacent to site B, is formed.

[0079] Next, the route management server 1000 designates the relay node RU1N and indicates the intermediate node RU1(N-1) as the link destination. The relay node RU1N then links to the intermediate node RU1(N-1). The route management server 1000 also notifies the relay node RU11, site A, and site B that the first route has been established (912, 913).

[0080] Next, the system begins constructing a second route. The management server 1000 designates relay node RU21 and indicates site A as the link destination. This links site A to relay node RU21, the first relay node on the second route. Next, the route management server 1000 designates intermediate node RU22 and designates relay node RU21 as the link destination. This links intermediate node RU22 to relay node RU21. In this way, second routes are constructed one after another, and a route to intermediate node RU2(N-1), which is immediately before relay node RU2N, next to site B, is formed.

[0081] The route management server 1000 then designates the relay node RU2N and specifies intermediate node RU2(N-1) (not shown) as the link destination. The relay node RU2N then links to the intermediate node RU2(N-1). The route management server 1000 also notifies the relay node RU21, site A, and site B that the first route has been established (912, 913).

[0082] Similarly, a third route, a fourth route, etc. are constructed, and when the specified number of routes is reached, the route construction process stops.

[0083] The key transmission route setting type described above is a static type, but may also be a dynamic type. Furthermore, it is not limited to the above procedure, and many other setting types are possible.

[0084] 10 is an explanatory diagram showing a dynamic type of key transmission route setup method. This key transmission route setup method is based on the premise that each node holds route information.

[0085] First, the route information is, for example, link data for specifying the next node to be selected in order to approach the desired relay node (desired base) from the current location. Multiple relay nodes are set, and the addresses (link data) of adjacent nodes for approaching each relay node are stored in advance in memory. Therefore, link formation command data (link request data) includes identification data of the base that is the source of transmission, addresses (identification data) of relay nodes around that base, identification data of the base that is the destination of transmission, and addresses (identification data) of relay nodes around that base, and is transferred one after another through each node that constructs the route. This allows the node that constructed the route to recognize from which base to which base the route is being constructed.

[0086] Returning to FIG. 10, the explanation will be given below. Point A requests the nearest relay node RU11 to form a link for the first route (route 1) (by providing link request data) (step R1S0). In response, relay node RU11 selects, for example, intermediate node RU12, forms a link, and provides link request data to this intermediate node RU12 (step R1S1). Then, intermediate node RU12 selects the next intermediate node, forms a link, and provides link request data to the next intermediate node (step R1S2). In this way, links are formed one after another, and when the route is completed up to relay node RU1N, relay node RU1N notifies relay node RU11 that construction of the first route is complete (step R1S3). At this time, a notification is also sent to point A. Furthermore, relay node RU1N notifies point B that construction of the first route is complete (step R1SN). Next, construction of the second route begins.

[0087] Point A requests the nearest relay node RU21 to form a link for the second route (route 2) (by providing link request data) (step R2S0). Relay node RU21 then selects, for example, intermediate node RU22, forms a link, and provides link request data to this intermediate node RU22 (step R2S1). In turn, intermediate node RU22 selects the next intermediate node, forms a link, and provides link request data to the next intermediate node (step R2S2). Links are formed one after another in this manner, and when the route is completed up to relay node RU2N, relay node RU2N notifies relay node RU21 that construction of the second route is complete (step R3S3). At this time, a notification is also sent to point A. Furthermore, relay node RU1N notifies point B that construction of the second route is complete (step R2SN). Subsequently, the third and fourth routes are constructed in a similar manner.

[0088] Figures 11, 12, and 13 show various examples of combinations of CVQKD and BB84QKD devices at relay nodes and intermediate nodes, respectively. Each example shows an example in which three paths are constructed, but the number of paths is not limited.

[0089] 11 is an example in which relay nodes C, E, and G connected to CVQKD devices 102a, 102b, and 102c in site A are configured with a CVQKD device and a BB84QKD device, respectively. The CVQKD devices in relay nodes C, E, and G are connected to the CVQKD devices 102a, 102b, and 102c in site A, respectively.

[0090] Meanwhile, relay nodes D, F, and H connected to CVQKD devices 202a, 202b, and 202c in point B are also configured with a CVQKD device and a BB84QKD device, respectively. In this case, the CVQKD devices in relay nodes D, F, and H are also connected to the CVQKD devices 202a, 202b, and 202c in point B. Intermediate nodes X, Y, and Z connecting relay nodes C, E, and G with relay nodes D, F, and H, respectively, are each configured with a BB84QKD device.

[0091] The embodiment of Figure 12 is an example in which nodes (CVQKD nodes) J, K, and L connected to CVQKD devices 102a, 102b, and 102c in site A are each configured with the same type of CVQKD device and CVQKD device. Meanwhile, relay nodes D, F, and H connected to CVQKD devices 202a, 202b, and 202c in site B are also each configured with a CVQKD device and a BB84QKD device (the same as the case of Figure 11). Furthermore, relay nodes C, E, and G between nodes J, K, and L and corresponding relay nodes D, F, and H are configured with CVQKD devices on the site A side and BB84QKD devices on the site B side.

[0092] The embodiment of FIG. 13 is an example in which CVQKD nodes J, K, and L connected to CVQKD devices 102a, 102b, and 102c in site A are configured with CVQKD devices and CVQKD devices of the same type, respectively.

[0093] On the other hand, point B does not have a CVQKD device, but has BB84QKD devices 202d, 202e, and 202f. Therefore, in this example, the three closest route nodes (BB84QKD nodes) X, Y, and Z to point B are each configured with BB84QKD devices.

[0094] The relay nodes C, E, and G between nodes J, K, and L and nodes X, Y, and Z are respectively composed of a CVQKD device (located on the side of point A) and a BB84QKD device (located on the side of point B).

[0095] As mentioned above, various combinations of CVQKD and BB84QKD equipment are possible in relay nodes and intermediate nodes. Looking at the above-mentioned configuration and this embodiment as a whole, the combination of the CVQKD device and the BB84QKD device can be said to be a first quantum cryptography communication device suitable for the front-end, and the BB84QKD device can be said to be a second quantum cryptography communication device suitable for the back-end.

[0096] In this system, the encryption key is generated by the key sharing module. There are various methods for generating the encryption key, and some of the most common methods will be explained below.

[0097] 14 is a diagram illustrating a method for generating an encryption key (hereinafter referred to as a random number key) 132 in the key sharing module 102, and an example of encryption of plaintext data 131 at site A. Note that the following description will be given assuming the encrypted communication system shown in FIG.

[0098] Now, the three generated split random number keys (the split encryption keys described above) are called random number key "1," random number key "2," and random number key "3," respectively. In the key sharing module 102 at site A, Random key "1" XOR random key "2" XOR random key "3" By calculating the above, a random number key (encryption key) 132 is obtained.

[0099] On the other hand, in the cryptographic module 101, Random key 132 XOR plaintext data 131 By calculating the above, the encrypted data 302 is obtained.

[0100] In this way, the encrypted communication system here generates encrypted data 302 by superimposing a random number key and the Vernam cipher of multiple divided data obtained by dividing plaintext data 131. Therefore, even if an unauthorized eavesdropper infiltrates an intermediate node within a certain route and steals part of the divided data, he or she will not be able to decrypt even part of the encrypted data 302 communicated between points A and B over the Internet network (encrypted data transmission system 300).

[0101] Furthermore, as described above, in an encrypted communication system, for example, assuming the overlapping of the Vernam cipher, data essential for generating the entire random key is sent and received along multiple routes between points A and B, and the random key (encryption key) is shared. Even if an unauthorized eavesdropper infiltrates an intermediate node on a route and steals part of the data essential for generating the random key, the unauthorized eavesdropper will not be able to decrypt the random key, and the security of user communications can be maintained.

[0102] 15 and 16 are explanatory diagrams illustrating a method for generating and restoring a further shared encryption key. FIG. 15 is a diagram illustrating an example of a method for generating a random key 132 in the key sharing modules 102 and 202 in an encryption communication system. Here, we take as an example a case where the random key 131 (=131a, 131b, 131c) is generated by ramp secret sharing with a share number of 3 and a threshold of 3 (in this example, ramp secret sharing with thresholds K=3, L=2, and N=3). With this ramp secret sharing, even if one of the three shared data (shared encryption keys) 132a, 132b, and 132c is intercepted, it cannot be restored. Also, we assume that the ratio of random numbers (dummy data, i.e., disposable physical random numbers) to plaintext (here, the common key, i.e., the physical random numbers used as the random key 132) is 1:2. The ramp type allows the ratio of random numbers to plaintext to be changed, and when the ratio of random numbers to plaintext is "(threshold-1):1", it is particularly called perfect secret sharing.

[0103] It is assumed that the key sharing module 102 first has a physical random number 2000. It is also assumed that the key sharing module 102 considers this physical random number as original data 2001 and performs a sharing process using ramp secret sharing with a threshold of 3. The key sharing module 102 then considers the randomly generated random numbers (random key "1", random key "2", random key "3") to have been obtained through this sharing. In other words, it can be said that the random key "1", random key "2", and random key "3" are deemed to be shared encryption keys (random keys).

[0104] In other words, the key sharing module 102 does not actually generate the shared data (shared encryption keys) 132a, 132b, and 132c by secret sharing here. Therefore, quantum keys generated by a quantum key distribution function can be used as the shared data 132a, 132b, and 132c, which improves the efficiency of physical random number generation.

[0105] As described above, this system has features not found in data transfers that use simple secret sharing. It is also possible to generate distributed data 132a, 132b, and 132c by sharing the randomly generated random numbers (random key "1," random key "2," and random key "3") using a secret sharing method. However, in this case, the key sharing module 102 must generate additional physical random numbers to serve as the original data, in addition to the quantum keys (physical random numbers) generated by the quantum key distribution function, which reduces the efficiency of physical random number generation.

[0106] To explain the sharing process of ramp secret sharing with a threshold of 3 in more detail, first, the original data is sorted according to the threshold number. For example, if the original data 2001 is "1 to 15," it is sorted into "1, 4, 7, 10, 13," "2, 5, 8, 11, 14," and "3, 6, 9, 12, 15." In Figure 15, each group after sorting is represented by a row.

[0107] Next, to generate the three shared data, the second row of shared (2) is shifted by one column, and the third row of shared (3) is shifted by one column, and then convolution is performed, for example, using exclusive OR, on each of shared (1) to shared (3). Note that this convolution is not limited to exclusive OR, and may be a calculation using a polynomial, or addition or subtraction, etc.

[0108] When the key sharing module 102 at site A generates a random number, it regards this random number as shared data obtained by the above procedure (shared processing using ramp secret sharing with threshold 3). In other words, the key sharing module 102 generates multiple random number sequences (random key "1", random key "2", random key "3") and regards each random number sequence as shared data. The key sharing module 102 transfers these random numbers (shared data 19) to site B by assigning each random number sequence to a different route.

[0109] FIG. 16 is a diagram showing an example of a method for obtaining, that is, a restoration method of, the random number key 132 by the key sharing modules 102 and 202 in the encrypted communication system that distributes the encryption key (random number key) as described above.

[0110] The key sharing modules 102 and 202 use three pieces of shared data (actually, they are simply random numbers) to perform a recovery process using ramp secret sharing with three shares and a threshold of three (in this example, ramp secret sharing with thresholds K=3, L=2, and N=3 shares) ("Calculation 2010" in FIG. 16). This recovery yields "1 to 15" as the original data 2001 of the hypothetical physical random numbers mentioned above.

[0111] Note that if the restoration process is performed in this manner without performing the sharing process using the secret sharing scheme, the data (original data) of some layers (rows) of some of the shared data will be inconsistent (if all of the shared data is restored to the original data, the original data will not match for some of the shared data). To prevent this inconsistency, it is sufficient to consider some of the shared data as having been exclusive-ORed with other random numbers (x1 to x5). This can be considered to have been shared in advance between the key sharing module 102 and the key sharing module 202. Note that if the key sharing module 102 and the key sharing module 202 determine in advance or dynamically which shared data to use to generate the original data, the original data generated by at least the key sharing module 102 and the key sharing module 202 will match, so this inconsistency will not be a problem. Note that although there is some inconsistency, the restoration process is performed using the secret sharing scheme by considering the physical random numbers (random key "1", random key "2", random key "3") as shared data, so security is sufficiently ensured.

[0112] Here, it is assumed that the ratio of random numbers to plain text is 1:2, so the key sharing module 202 removes, for example, "1, 4, 7, 10, 13" (one predetermined line) from the restored original data "1 to 15" as dummy data (disposable physical random numbers), and extracts "2, 3, 5, 6, 8, 9, 11, 12, 14, 15" (two predetermined lines), thereby generating the random number key 132 to be delivered to site B.

[0113] In the case of perfect secret sharing, the ratio of random numbers to plain text is "threshold - 1:1" ("2:1"), so the key sharing module 102 generates the random number key 132 to be distributed to site B by removing, for example, "1, 2, 4, 5, 7, 8, 10, 11, 13, 14" (two predetermined rows) as dummy data (disposable physical random numbers) and extracting "3, 6, 9, 12, 15" (one predetermined row).

[0114] Meanwhile, the key sharing module 202, which receives the shared data 132a, 132b, and 132c from the leaf node C 131, also performs the same calculation as the key sharing module 102 to generate the random key 132 to be used at site B. The random key 132 generated by the key sharing module 102 is the same as the random key 132 generated by the key sharing module 202. In other words, the random key (encryption key) at sites A and B is the shared random key 132.

[0115] FIG. 17 is an explanatory diagram showing an example of encryption of plaintext data 131 at site A. In FIG.

[0116] At base A, Random key 132 XOR plaintext data 131 By calculating the above, the encrypted data 302 is obtained.

[0117] In this way, the plurality of shared data 132a, which are regarded as being shared by the ramp secret sharing scheme, By distributing 132b and 132c (which are actually just random numbers), even if an unauthorized eavesdropper infiltrates an intermediate node in a certain route and steals part of the shared data, the random number key information will not be leaked. Therefore, even a part of the encrypted data 302 communicated between site A and site B over the Internet cannot be decrypted.

[0118] As described above, between site A and site B (the source node and the destination node), assuming the recovery process using the secret sharing scheme, the data necessary for generating the random key 132 is sent and received via multiple routes, and the random key 132 (common key) can be shared. Even if an unauthorized eavesdropper infiltrates an intermediate node on a route and steals some of the data necessary for generating the encryption key, the unauthorized eavesdropper cannot decrypt the encryption key, thereby maintaining the security of user communications. Here, the number of shares is the same as the threshold (3). However, if the number of shares is set to (number of shares) = threshold + α (α = 1, 2, 3, etc.), the random key 16 can be generated even if (number of shares - threshold) pieces of data are lost. Therefore, even if some intermediate nodes malfunction, the end node C 131, site A, and site B can share the random key 132 without any problems.

[0119] In the above explanation, assuming the existence of some original data, recovery is performed using ramp secret sharing with a share count of 3 and a threshold of 3. If the ratio of random numbers to plaintext is 1:2, one row (out of three rows) of the recovered data is removed as random numbers (dummy data), and two rows of data are used as the random key 16. If information-theoretic security is not ensured, all of the recovered data can be used as plaintext (random key 132), or only part of one row can be used as random numbers. Even in this case, information-theoretic security cannot be ensured, but the number of combinations of operators required to obtain the original data is enormous, and the security of the user's encrypted communications can be sufficiently ensured. Furthermore, in this case, the consumption of random numbers can be significantly reduced. Therefore, the transfer rate also improves accordingly.

[0120] When the threshold is set to 2, the only way to ensure information-theoretic security is to set the ratio of random numbers to plaintext at 1:1. However, as mentioned above, if information-theoretic security is abandoned, all of the data obtained by reconstruction can be used as plaintext, or only part of one line (out of two lines) can be used as random numbers, rather than the entire line. Even in this case, information-theoretic security cannot be ensured, but the number of combinations of operators required to obtain the original data is enormous, and the security of the user's encrypted communications can be sufficiently ensured. Therefore, the consumption of random numbers can be significantly reduced. Note that the secret sharing schemes that can be used are not limited to those mentioned above; other secret sharing schemes, such as exclusive-OR secret sharing schemes and polynomial secret sharing schemes, can also be used.

[0121] 18 and 19, a method for generating the random number key 132 by secret sharing with a threshold value of 2 will be described. Fig. 18 is a diagram showing an example of a method for generating the random number key 132 by secret sharing with a threshold value of 2 and a share number of 3.

[0122] It is assumed that the key sharing module 102 first has a certain physical random number. It is also assumed that the key sharing module 102 considers this as original data and performs sharing processing using a secret sharing scheme with a threshold value of 2. The key sharing module 102 considers the randomly generated random numbers (random key "1", random key "2", random key "3") to be obtained by this sharing processing. In other words, the key sharing module 102 does not actually generate the shared data 132 using secret sharing. In this way, this system has features not found in data transfer using simple secret sharing. As mentioned above, it is possible to actually perform secret sharing processing here, but in that case, the efficiency of physical random number generation will decrease.

[0123] To explain secret sharing with threshold 2 in more detail, first, the original data is sorted into the threshold number. For example, if the original data is "1 to 14," it is sorted into "1, 3, 5, 7, 9, 11, 13" and "2, 4, 6, 8, 10, 12, 14." In Figure 18, each group after sorting is represented by a row.

[0124] Next, to generate the three shared data, the second row of share (2) is shifted by one column, and the second row of share (3) is shifted by two columns, and then convolution is performed, for example, using exclusive OR, on each of share (1) to share (3). Note that this convolution is not limited to exclusive OR, and may be a calculation using a polynomial, or addition or subtraction, etc.

[0125] When the key sharing module 102 generates a random number, it regards this random number as the shared data obtained by the above procedure (secret sharing with threshold 2). The key sharing module 102 distributes this random number (shared data 132) to different routes for each random number sequence (random key "1", random key "2", random key "3") and transfers it to the key sharing module 202.

[0126] FIG. 19 is a diagram showing an example of a method for generating (restoring) the random number key 132 by secret sharing with a threshold value of 2. In FIG.

[0127] The key sharing module 202 uses two pieces of shared data A and C (which are actually just random numbers) to perform recovery by secret sharing with a share number of 3 and a threshold value of 2 ("Calculation 2020" in FIG. 19). This recovery yields the original data "1 to 14" of the hypothetical physical random numbers mentioned above.

[0128] In the case of ramp secret sharing with a threshold of 2 and a number of shares of 2, no inconsistency occurs during recovery. However, in the case of secret sharing with a threshold of 2 and a number of shares of 2+α (α=1, 2, 3, ...), data in some layers of some shared data will be inconsistent upon recovery, just as in the case of ramp secret sharing with a number of shares of 3 and a threshold of 3 mentioned above. Therefore, just as in the case of ramp secret sharing with a number of shares of 3 and a threshold of 3 mentioned above, we consider that another pre-shared random number is superimposed.

[0129] Even when the random key 16 is generated using secret sharing with a threshold value of 2, the encrypted communication system of the second embodiment distributes multiple shares (actually, simply random numbers) that are considered to have been shared using secret sharing. Even if an unauthorized eavesdropper infiltrates an intermediate node in a certain route and steals part of the shares 19, he or she cannot decrypt even a part of the encrypted data 303 communicated between sites A and B over the Internet 300. Furthermore, since the threshold value is 2 and the number of shares is 3 in this example, even if one share (number of shares minus threshold) is lost, the random key 132 can still be generated. Therefore, even if a malfunction occurs in an intermediate node on a route, the key sharing module 102 and the key sharing module 202 can share the random key 132 without any problems. Note that, for simplicity's sake, the secret sharing schemes shown in FIGS. 18 and 19 have been used for the explanation. However, the secret sharing schemes that can be used are not limited to these. For example, other secret sharing schemes using exclusive OR or polynomials can also be used.

[0130] The technical features of the above embodiment will be described below. First, the features of the configurations of sites A and B will be described.

[0131] A1) According to one embodiment, device A at a user site comprises a cryptographic module 101 for transmitting encrypted data, and a key agreement module 102 having the function of recovering and distributing the cryptographic key used to generate the encrypted data. The key agreement module 102 comprises a plurality of CVQKD devices 102a, 102b for delivering a plurality of random number keys obtained by distributing the cryptographic key via different routes, and for receiving the distributed cryptographic keys sent from the different routes, and the plurality of CVQKD devices 102a, 102b are quantum-connected to CVQKD devices in relay nodes provided on each of the different routes.

[0132] Furthermore, the plurality of CVQKD devices 102a, 102b are connected to an encryption key distribution / recovery circuit 102c for distributing the encryption key and recovering the distributed encryption key.

[0133] A2) The key sharing module 102 sends shared encryption keys (random number keys) according to a secret sharing scheme to the different paths.

[0134] A3) The different paths are quantum cryptography distribution networks in which multiple nodes are arranged in a mesh configuration.

[0135] A4) The different routes are a quantum cryptography distribution network in which multiple nodes are arranged in a mesh configuration, and the key sharing module 102 has processing means for designating any of the nodes in the quantum cryptography distribution network and constructing quantum cryptography key routes for distributing each of the distributed cryptographic keys.

[0136] B1) According to another embodiment, the cryptographic communication system has a first location A and a second location B connected by a cryptographic data transmission system, and the first location A has multiple CVQKD devices within the location to distribute multiple distributed cryptographic keys to the second location B, and the multiple CVQKD devices are connected to multiple cryptographic key distribution paths. Each of the multiple encryption key distribution paths has a relay node that integrates a CVQKD device within the distribution path and a BB84QKD device that processes the output of this CVQK device using the BB84 protocol and outputs it toward site B.

[0137] B2) There is provided an encryption communication method for distributing distributed encryption keys using the encryption communication system, a plurality of CVQKD devices in the bases, and the relay node.

[0138] B3) The first location A has first and second CVQKD devices 102a, 102b within the location to distribute multiple distributed encryption keys to the second location B, and these first and second CVQKD devices 102a, 102b are connected to third and fourth CVQKD devices 441, 611 within first and second relay nodes located on the first and second encryption key distribution paths.

[0139] B4) The first and second relay nodes include BB48QKD devices 412, 612 that receive the outputs of the third and fourth CVQKD devices 441, 611.

[0140] B5) The plurality of encryption key distribution paths are a quantum cryptography distribution network in which a plurality of nodes are arranged in a mesh configuration.

[0141] B6) The means for distributing a plurality of random number keys obtained by distributing the encryption key through different routes and for receiving the distributed encryption keys sent through the different routes is a key sharing module 102, and the plurality of encryption key distribution paths are a quantum cryptography distribution network in which a plurality of nodes are arranged in a mesh configuration; The key sharing module sends shared encryption keys (random number keys) to the plurality of encryption key distribution paths according to a secret sharing scheme.

[0142] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are within the scope and spirit of the invention, and are also included in the scope of the invention and its equivalents as set forth in the claims. Furthermore, the scope of the present invention also includes cases in which each component of the claims is expressed separately, as a combination of multiple components, or as a combination of these components. Furthermore, multiple embodiments may be combined, and examples composed of such combinations are also within the scope of the invention.

[0143] In addition, to clarify the description, the drawings may show the width, thickness, shape, etc. of each part more schematically than in the actual embodiment. Furthermore, the device of the present invention is applied even when the claims are expressed as control logic, as a program including instructions for causing a computer to execute, or as a computer-readable recording medium containing the instructions. Furthermore, the names and terms used are not limited, and other expressions that have substantially the same content and intent are also included in the present invention. [Explanation of symbols]

[0144] A: Location, B: Location, C, D, 601, 602: Relay nodes, 100, 200...processor, 101, 201...encryption module, 102, 202...key sharing module, 131...plaintext data, 132...encryption key, 300...internet network, 302...encrypted data, 400, 600···Encryption key transmission path, 401, 402···Intermediate nodes, 102a, 102b, 202a, 202b, 441, 444, 611, 622···CVQKD device, 411, 422, 442, 443···BB84QKD device.

Claims

1. A user base device system comprising: a cryptographic module for transmitting encrypted data; and a key sharing module having a function of restoring and distributing a cryptographic key used to generate the encrypted data, wherein the cryptographic module encrypts plaintext data using the cryptographic key and outputs the encrypted data via the Internet, the key sharing module includes first and second CVQKD devices corresponding to the first and second paths; a first relay node having a third CVQKD device to which the first CVQKD device is connected via an optical fiber to form the first path; a second relay node having a fourth CVQKD device to which the second CVQKD device is connected via an optical fiber to form the second path; Furthermore, the first and second CVQKD devices are connected to a cryptographic key distribution / recovery circuit for distributing the cryptographic key and recovering the distributed cryptographic key; The first relay node further includes a BB84 QKD device on the output side to which the output of the third CVQKD device is optically coupled, The second relay node further includes a BB84 QKD device on the output side to which the output of the fourth CVQKD device is optically coupled, Furthermore, the first and second encryption keys shared by the key sharing module are supplied to the encryption module that encrypts plaintext data; The cryptographic module is provided with means for performing an exclusive-OR operation on the distributed first cryptographic key and the second cryptographic key, and further performing an exclusive-OR operation on the result of this operation with the plaintext data, and transmitting the resulting encrypted data to the Internet.

2. 2. The user base equipment system according to claim 1, wherein the key sharing module transmits a shared encryption key (random number key) to the first route and the second route using a secret sharing scheme.

3. 2. The user base equipment system according to claim 1, wherein the preceding route further comprises a plurality of routes, and the preceding route is a quantum cryptography distribution network in which a plurality of nodes are arranged in a mesh configuration.

4. The previous route has multiple routes, and is a quantum cryptography distribution network with multiple nodes arranged in a mesh configuration, The user base device system according to claim 1 , wherein the key sharing module comprises a processing means for designating any of the nodes in the quantum cryptography distribution network and constructing a path for distributing each of the distributed cryptographic keys.

5. 10. An encrypted communication system using the user base equipment system according to claim 1 to communicate with another user base equipment system having a symmetrical configuration to the user base equipment system.

6. 6. The cryptographic communication system according to claim 5, wherein the key sharing module transmits a shared encryption key (random number key) to the first path and the second path using a secret sharing scheme.

7. 6. The cryptographic communication system according to claim 5, wherein the preceding route further comprises a plurality of routes, and the system is a quantum cryptography distribution network in which a plurality of nodes are arranged in a mesh configuration.

8. 6. The cryptographic communication system according to claim 5, wherein the preceding route further comprises a plurality of routes, and the system is a quantum cryptography distribution network in which a plurality of nodes are arranged in a mesh configuration.

9. 10. An encrypted communication method for communicating between the user base equipment system according to claim 1 and another user base system having a symmetrical configuration similar to that of the user base equipment system.

10. 10. The cryptographic communication method according to claim 9, wherein the key sharing module transmits a shared encryption key (random number key) to the first route and the second route using a secret sharing scheme.

11. 10. The cryptographic communication method according to claim 9, wherein the preceding route further comprises a plurality of routes, and the preceding route is a quantum cryptography distribution network in which a plurality of nodes are arranged in a mesh configuration.

Citation Information

Patent Citations

  • Camera with dataaboard simultaneous photographing device

    JP1981072425A

  • Electrochromic display body

    JP1981085735A

  • cryptographic communication system

    JP3263878B2

  • Secret sharing device, method and program

    JP4304215B2

  • Trusted relay-based quantum key distribution system, method, and apparatus

    JP6783772B2