Key delivery system, control method, and control program
The key distribution system facilitates secure cryptographic communication across diverse locations by determining encryption key distribution routes and methods, addressing the limitation of quantum cryptography to fiber-installed areas, thereby establishing a wide-area network.
Patent Information
- Application Number
- JP2025041539
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-14
- Filing Date
- 2025-03-14
- Publication Date
- 2025-12-25
AI Technical Summary
Quantum cryptography communication is limited to areas where optical fiber is installed, preventing the establishment of a wide-area cryptography communication network.
A key distribution system comprising multiple key generation, management, and supply devices, along with a network management device that determines distribution routes and encryption methods for encryption keys, enabling secure cryptographic communication across various locations using quantum and post-quantum cryptography methods.
Enables the construction of an extensive cryptographic communication network by providing users with information on cryptographic security and allowing selection of encryption methods, ensuring secure communication over long distances and through relay points.
Smart Images

Figure 2025187980000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a key distribution system, a control method, and a control program. [Background technology]
[0002] In encrypted communication of messages from a sending server to a receiving server, the message is encrypted at the sending server and decrypted at the receiving server using an encryption key that is shared in advance between the sending server and the receiving server. In particular, a method that uses an encryption key with the same data size as the message and does not reuse an encryption key once it has been used is called one-time pad encryption.
[0003] Furthermore, in recent years, the development of quantum cryptography communication has been progressing. Quantum cryptography communication enables more secure cryptographic communication by transmitting a cryptographic key generated by a transmitter on the sending server side, carried on photons (particles of light), the smallest unit of light, or weak light, from the transmitter to a receiver on the receiving server side. Technology related to quantum cryptography communication is disclosed in Patent Document 1, for example.
[0004] Patent Document 1 discloses a key exchange system including a plurality of QKD (Quantum Key Distribution) devices that execute a quantum key distribution protocol including error correction, and a plurality of base stations that perform encrypted communication with each other. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] International Publication No. 2023 / 218575 [Patent Document 2] International Publication No. 2018 / 047716 Summary of the Invention [Problem to be solved by the invention]
[0006] Related technologies have had the problem that quantum cryptography communication cannot be carried out between bases where optical fiber is not installed, making it impossible to build a wide-area cryptography communication network.
[0007] One of the objects of the present disclosure is to provide a key distribution system, a control method, and a control program that solve the above-mentioned problems. [Means for solving the problem]
[0008] A key distribution system according to one aspect of the present disclosure includes a plurality of key generation devices provided at a plurality of locations, each of which generates an encryption key; a plurality of key management devices provided corresponding to the plurality of key generation devices and which manage the encryption keys generated by each of the plurality of key generation devices; a plurality of key supply devices provided corresponding to the plurality of key management devices and which supply the encryption keys managed by the plurality of key management devices to an application performing encrypted communication; and a network management device. The network management device includes a determination unit that determines a distribution route for the encryption key from a first key management device that is a source of the encryption key to a second key management device that is a destination of the encryption key, and an encryption method for the encryption key along the distribution route; and an output control unit that causes first and second key supply devices provided corresponding to the first and second key management devices among the plurality of key supply devices to supply information regarding the determined encryption method to the application performing encrypted communication.
[0009] A control method for a key distribution system according to one aspect of the present disclosure determines a distribution path for an encryption key from a first key management device that is a source of the encryption key to a second key management device that is a destination of the encryption key, and an encryption method for the encryption key along the distribution path, among a plurality of key management devices that are provided corresponding to a plurality of key generation devices provided at each of a plurality of locations and that manage the encryption keys generated by each of the plurality of key generation devices, and then supplies information about the determined encryption method to an application that performs encrypted communication by a first and a second key supply device that is provided corresponding to the first and second key management devices among a plurality of key supply devices provided corresponding to the plurality of key management devices.
[0010] A control program according to one aspect of the present disclosure causes a computer to execute the following steps: determining a delivery route for an encryption key from a first key management device that is a source of the encryption key to a second key management device that is a destination of the encryption key, and an encryption method for the encryption key along the delivery route, among a plurality of key management devices provided corresponding to a plurality of key generation devices provided at a plurality of locations and managing the encryption keys generated by each of the plurality of key generation devices; and supplying information about the determined encryption method to an application performing encrypted communication by first and second key supply devices provided corresponding to the first and second key management devices among a plurality of key supply devices provided corresponding to the plurality of key management devices. [Effects of the Invention]
[0011] The present disclosure provides a key distribution system, a control method, and a control program that can build an extensive cryptographic communication network by providing users with information regarding the security of cryptographic communications and selecting and using an encryption method from multiple encryption methods when distributing cryptographic keys used in cryptographic communications. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 is a diagram illustrating an example configuration of a key distribution system according to the present disclosure. [Figure 2] FIG. 1 is a diagram showing the relationship between the transmission distance, the key generation probability, and the key generation rate in quantum key distribution. [Figure 3] FIG. 2 is a block diagram illustrating an example configuration of a network management device provided in the key distribution system according to the present disclosure. [Figure 4] 10 is a flowchart illustrating the operation of a network management device provided in the key distribution system according to the present disclosure. [Figure 5] FIG. 1 is a diagram illustrating an example of an encryption key distribution route determined by a network management device provided in a key distribution system according to the present disclosure, and an encryption method for the encryption key distributed along the determined distribution route. [Figure 6] FIG. 10 is a diagram illustrating a modification of the key distribution system according to the present disclosure. [Figure 7] FIG. 10 is a diagram illustrating another example of a distribution route of an encryption key determined by a network management device provided in a key distribution system according to the present disclosure, and an encryption method for the encryption key distributed along the determined distribution route. [Figure 8] FIG. 10 is a diagram illustrating another example of a distribution route of an encryption key determined by a network management device provided in a key distribution system according to the present disclosure, and an encryption method for the encryption key distributed along the determined distribution route. [Figure 9] FIG. 10 is a diagram illustrating an example of the content of a notification sent to an application by a network management device provided in the key distribution system according to the present disclosure. [Figure 10] FIG. 10 is a diagram illustrating an example of the content of a notification sent to an application by a network management device provided in the key distribution system according to the present disclosure. [Figure 11] FIG. 2 is a block diagram illustrating an example of a hardware configuration for implementing a key management function of a network management device according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, embodiments will be described with reference to the drawings. Note that the drawings are simplified, and the technical scope of the embodiments should not be narrowly interpreted based on the description in the drawings. Furthermore, identical elements are given the same reference numerals, and duplicate explanations will be omitted.
[0014] In the following embodiments, when necessary for convenience, the description will be divided into multiple sections or embodiments. However, unless otherwise specified, they are not unrelated to each other, and one is a partial or complete modification, application example, detailed explanation, supplementary explanation, etc. of the other. Furthermore, in the following embodiments, when the number of elements (including the number, numerical value, amount, range, etc.) is mentioned, it is not limited to that specific number, and may be more or less than the specific number, unless otherwise specified or when it is clearly limited to a specific number in principle.
[0015] Furthermore, in the following embodiments, the components (including operational steps, etc.) are not necessarily essential unless otherwise specified or considered to be clearly essential in principle. Similarly, in the following embodiments, when referring to the shape, positional relationship, etc. of components, etc., it is intended to include those that are substantially similar or approximate to the shape, etc., unless otherwise specified or considered to be clearly not essential in principle. The same applies to the above numbers, etc. (including numbers, numerical values, amounts, ranges, etc.).
[0016] <First Embodiment> FIG. 1 is a diagram illustrating an example of the configuration of a key distribution system according to the present disclosure. As illustrated in FIG. 1, the key distribution system 1 is a system for managing and operating encryption keys used in quantum cryptography communication in a QKDN (Quantum Key Distribution Network) platform, and includes at least a plurality of key generation devices 11, a plurality of key management devices 12, a plurality of key supply devices 13, and a network management device 14. However, the key distribution system 1 is configured to manage and operate not only encryption keys used in quantum cryptography communication (encryption keys generated by QKD), but also encryption keys generated by PQC (Post-Quantum Cryptography) and RSA (Rivest Shamir Adleman). PQC is a quantum-computer-resistant cryptography, and unlike quantum cryptography, the amount of calculation required for decryption is so large that it cannot be completed in a practical time frame. Other candidates for PQC include CRYSTALS-Kyber, standardized by the National Institute of Standards and Technology (NIST), as well as HQC, Classic McEliece, and BIKE.
[0017] Each of the multiple key generation devices 11 generates an encryption key. The multiple key generation devices 11 are installed at different locations. Optical fibers 50 are laid between short and medium distance locations, for example, within 50 km of the multiple locations, but are not laid between long distance locations exceeding 50 km or between locations sandwiched between mountainous areas, etc. In the example of Fig. 1, among locations A to E, optical fibers 50 are laid between locations A and B, between locations A and C, between locations B and D, between locations C and D, and between locations C and E, respectively.
[0018] The key distribution system 1 is used for quantum cryptography communication using a continuous variable quantum key distribution method called CV-QKD (Continuous Variable Quantum Key Distribution). In the application layer, in encrypted communication of a message from a sending server to a receiving server, the sending server encrypts the message and the receiving server decrypts the message using an encryption key shared in advance between the sending server and the receiving server. In particular, a method that uses an encryption key with the same data size as the message and does not reuse an encryption key once used is called one-time pad encryption.
[0019] In quantum cryptography communication, the key distribution system 1 transmits an encryption key generated by a key generation device 11 (transmitter 11_1) provided corresponding to a transmission server from the transmitter to a key generation device 11 (receiver 11_2) provided corresponding to a receiving server, using weak light, thereby enabling more secure cryptographic communication. Note that the weak light is light (quantum light) in which quantum mechanical effects appear, for example, with a typical intensity of about one photon.
[0020] The transmitter 11_1 (key generation device 11 on the transmitting side) transmits a plurality of weak lights including randomly assigned transmission bits and information on transmission bases to the receiver 11_2 (key generation device 11 on the receiving side) via the optical fiber 50. In other words, the transmitter 11_1 phase-modulates each of the plurality of weak lights using the randomly assigned transmission bits and transmission bases, and transmits the phase-modulated light to the receiver 11_2 via the optical fiber 50.
[0021] For example, if the bit value of the transmission bit is "0", a phase modulation amount of 0 degrees is assigned, and if the bit value of the transmission bit is "1", a phase modulation amount of 180 degrees is assigned. Also, if the base value of the transmission basis is "X", a phase modulation amount of 0 degrees is assigned, and if the base value of the transmission basis is "Y", a phase modulation amount of 90 degrees is assigned. Each weak light is phase-modulated with a phase modulation amount obtained by adding the phase modulation amount corresponding to the bit value and the phase modulation amount corresponding to the base value. Therefore, weak light phase-modulated using a transmission basis with a base value of "X" ideally appears on the real axis, and weak light phase-modulated using a transmission basis with a base value of "Y" ideally appears on the imaginary axis.
[0022] The receiver 11_2 phase-modulates the reference light using a randomly assigned reception basis corresponding to a transmission basis randomly assigned to each of the plurality of received weak light beams. Thereafter, the receiver 11_2 performs basis matching for the plurality of received weak light beams using, for example, a homodyne detector. Specifically, the receiver 11_2 causes interference between the plurality of weak light beams and the phase-modulated reference light beam, thereby detecting information of a plurality of bit values (bit information) from each of the plurality of weak light beams interfered by the reference light of the reception basis whose basis value matches the transmission basis, among the plurality of weak light beams. Note that the bit information includes a phase component representing the bit value and an amplitude component representing the intensity of the bit value.
[0023] For example, if the basis value of the receiving basis is "X", a phase modulation amount of 0 degrees is assigned, and if the basis value of the receiving basis is "Y", a phase modulation amount of 90 degrees is assigned. Therefore, the desired bit information can be detected only when interference occurs between weak light and reference light whose transmitting basis and receiving basis match each other.
[0024] Thereafter, the transmitter 11_1 and the receiver 11_2 perform error correction processing and privacy amplification processing on the bit string after error correction, and as a result, encryption keys (i.e., shared encryption keys) whose bit strings match each other are individually generated.
[0025] 2 is a diagram showing the relationship between transmission distance and key generation probability and key generation rate in quantum key distribution. As shown in FIG. 2, the longer the transmission distance, the lower the key generation rate and the lower the key generation probability. In particular, when the transmission distance exceeds 50 km, the key generation rate drops sharply. Therefore, the length of each optical fiber 50 connecting multiple key generation devices 11 is, for example, 50 km or less.
[0026] When quantum cryptography communication is performed between two locations separated by a long distance, such as more than 50 km, or when quantum cryptography communication is performed while avoiding transmission routes that may be susceptible to eavesdropping, the quantum cryptography communication (sharing of encryption keys) is performed via a location other than the two locations (a relay location). Key relay technology is used to share encryption keys between two locations via a relay location.
[0027] For example, when an encryption key is shared between points A and D via a relay point B, first, the key generation device 11 at point A generates an encryption key Kad to be shared with point D. Then, the key generation device 11 at point A and the key generation device 11 at relay point B generate a common encryption key Kab using the above-mentioned quantum key distribution technology. Then, the key Kad generated at point A is encrypted with the encryption key Kab and transferred from point A to relay point B. At relay point B, the encrypted key Kad is decrypted with the encryption key Kab. Then, the key generation device 11 at relay point B and the key generation device 11 at point D generate a common encryption key Kbd using the above-mentioned quantum key distribution technology. Then, the decrypted key Kab at relay point B is encrypted with the encryption key Kbd and transferred from relay point B to point D. At point D, the encrypted key Kad is decrypted with the encryption key Kbd. In this way, by using the key relay technology, the encryption key is shared between the sites A and D via the site B.
[0028] The multiple key management devices 12 are provided corresponding to the multiple key generation devices 11, and manage the encryption keys generated by each of the multiple key generation devices 11. The encryption keys managed by each key management device 12 include not only encryption keys generated by QKD but also encryption keys generated by PQC. Furthermore, the encryption keys managed by each key management device 12 may also include encryption keys generated by RSA.
[0029] For example, each key management device 12 stores in a storage unit the encryption key generated by the corresponding key generation device 11, and manages the consumption of encryption keys by a key supply device (described later). Each key management device 12 also encrypts and decrypts an encryption key (corresponding to the above-mentioned encryption key Kad) that is distributed from a source base to a destination base via a relay base by key relay.
[0030] The plurality of key supply devices 13 are provided corresponding to the plurality of key management devices 12, and supply encryption keys managed by the plurality of key management devices 12 to applications that perform encrypted communication.
[0031] The network management device 14 acquires the processing status of the encryption keys by each of the multiple key generation devices 11, multiple key management devices 12, and multiple key supply devices 13 as life cycle information, and centrally manages it.
[0032] The network management device 14 also determines a distribution route for the encryption key from a first key management device, which is the encryption key distribution source, among the multiple key management devices 12, to a second key management device, which is the encryption key distribution destination, and determines an encryption method for the encryption key to be distributed along the determined distribution route.The network management device 14 then causes information on the determined encryption method to be supplied to an application performing encrypted communication by first and second key supply devices, which are provided corresponding to the first and second key management devices, among the multiple key supply devices 13.
[0033] Fig. 3 is a block diagram showing an example of the configuration of the network management device 14. Fig. 4 is a timing chart showing the operation of the network management device 14.
[0034] As shown in Fig. 3, the network management device 14 includes at least a determination unit 141 and an output control unit 142. As shown in Fig. 4, the determination unit 141 determines a distribution route for the encryption key from a first key management device, which is a distribution source of the encryption key, among the multiple key management devices 12, to a second key management device, which is a distribution destination of the encryption key, and determines an encryption method for the encryption key along the determined distribution route (step S11). The output control unit 142 causes information on the determined encryption method to be supplied to an application performing encrypted communication by first and second key supply devices, which are provided corresponding to the first and second key management devices, among the multiple key supply devices 13 (step S12).
[0035] FIG. 5 is a diagram showing an example of an encryption key distribution route determined by the network management device 14 and an encryption method for the encryption key distributed over the determined distribution route.
[0036] (First example) 5, network management device 14 determines, as the encryption key distribution route, a route from site A, which is the encryption key distribution source, to site D, which is the encryption key distribution destination, via relay site B. Specifically, network management device 14 determines, as the encryption key distribution route, a route from key management device 12a provided at site A, which is the encryption key distribution source, to key management device 12d provided at site D, which is the encryption key distribution destination, via key management device 12b provided at relay site B.
[0037] Here, a key management device (QKD device) 12 is installed at each of points A, B, and D. The key management devices 12a and 12b at points A and B are connected by a QKD link using optical fiber 50, and the key management devices 12b and 12d at points B and D are also connected by a QKD link using optical fiber 50. In this case, the network management device 14 determines the encryption method for the encryption key on the distribution path between points A and B (i.e., from the key management device 12a to the key management device 12b) to be an encryption method using a key generated by QKD (a key shared between points A and B by QKD). The network management device 14 also determines the encryption method for the encryption key on the distribution path between points B and D (i.e., from the key management device 12b to the key management device 12d) to be an encryption method using a key generated by QKD.
[0038] Then, the network management device 14 causes the key supplying device 13a provided at the site A, which is the source of the encryption key, and the key supplying device 13d provided at the site D, which is the destination of the encryption key, to provide information about the determined encryption method (i.e., information indicating that an encryption method using a key generated by QKD is used on each of the distribution routes between the sites A and B and between the sites B and D) to the application performing the encrypted communication. This allows the network management device 14 to show the user of the application information about the security of the encrypted communication. In this case, the user can know that an encryption method using a key generated by QKD is used as the encryption method when distributing the encryption key used in the encrypted communication. Note that the network management device 14 may also cause the key supplying devices 13a and 13d to provide the application with the security rank of the encrypted communication as information about the security of the encrypted communication.
[0039] (Second example) 5, network management device 14 determines, as the encryption key distribution route, a route from location A, which is the encryption key distribution source, to location D, which is the encryption key distribution destination, via relay locations B and C. Specifically, network management device 14 determines, as the encryption key distribution route, a route from key management device 12a provided at location A, which is the encryption key distribution source, to key management device 12d provided at location D, which is the encryption key distribution destination, via key management device 12b provided at relay location B and key management device 12c provided at relay location C.
[0040] Here, a key management device (QKD device) 12 is installed at each of points A, B, C, and D. The key management devices 12a and 12b at points A and B are connected by a QKD link using optical fiber 50, and the key management devices 12c and 12d at points C and D are connected by a QKD link using optical fiber 50. In contrast, the key management devices 12b and 12c at points B and C are not connected by a QKD link using optical fiber 50. In this case, the network management device 14 determines the encryption method for the encryption key on the distribution route between points A and B (i.e., from the key management device 12a to the key management device 12b) to be an encryption method using a key generated by QKD. The network management device 14 also determines the encryption method for the encryption key on the distribution route between points B and C (i.e., from the key management device 12b to the key management device 12c) to be an encryption method that does not require the optical fiber 50. For example, the network management device 14 determines that the encryption method for the encryption key on the distribution route between points B and C is to be an encryption method using a key generated by PQC (a key shared between points B and C by a wirelessly communicable PQC).Furthermore, the network management device 14 determines that the encryption method for the encryption key on the distribution route between points C and D (i.e., from key management device 12c to key management device 12d) is to be an encryption method using a key generated by QKD.
[0041] Then, the network management device 14 causes the key supply device 13a provided at the point A, which is the source of the encryption key, and the key supply device 13d provided at the point D, which is the destination of the encryption key, to supply information about the determined encryption method (i.e., information indicating that an encryption method using a key generated by PQC is used in part of the distribution route) to the application performing the encrypted communication. This allows the network management device 14 to show information about the security of the encrypted communication to the user of the application. In this case, the user can know that an encryption method using a key generated by PQC is used in part of the distribution route as the encryption method when distributing the encryption key used in the encrypted communication.
[0042] (Third example) 5, network management device 14 determines, as the encryption key distribution route, a route from site A, which is the encryption key distribution source, to site D, which is the encryption key distribution destination, via relay site B. Specifically, network management device 14 determines, as the encryption key distribution route, a route from key management device 12a provided at site A, which is the encryption key distribution source, to key management device 12d provided at site D, which is the encryption key distribution destination, via key management device 12b provided at relay site B.
[0043] Here, a key management device (QKD device) 12 is installed at each of points A, B, and D. The key management devices 12a and 12b at points A and B are connected by a QKD link using optical fiber 50, and the key management devices 12b and 12d at points B and D are connected by a QKD link using optical fiber 50.
[0044] In this case, for example, a sufficient number of keys generated by QKD are stored in the key management devices 12a and 12b at points A and B. Therefore, the network management device 14 determines that the encryption method for the encryption key on the distribution route between points A and B is an encryption method using a key generated by QKD. On the other hand, a sufficient number of keys generated by QKD are not stored in the key management devices 12b and 12d at points B and D. Therefore, the network management device 14 determines that the encryption method for the encryption key on the distribution route between points B and D is an encryption method using a key generated by PQC (other than QKD). More specifically, in this example, the amount of key required to be used to encrypt the encryption key distributed via the distribution route from point B to point D is greater than the amount of key generated by QKD stored in each key management device 12b, 12d at points B and D, so the network management device 14 determines that the encryption method for the encryption key on the distribution route between points B and D will be an encryption method using a key generated by PQC (other than QKD).
[0045] In addition, if the amount of key required to be used for encrypting the encryption key distributed via the distribution route from point B to point D is equal to or less than the amount of key generated by QKD stored in each key management device 12b, 12d at points B and D, i.e., if a sufficient amount of key generated by QKD is stored, the network management device 14 may determine that the encryption method for the encryption key on the distribution route between points B and D is an encryption method using a key generated by QKD.
[0046] Then, the network management device 14 causes the key supply device 13a provided at the point A, which is the source of the encryption key, and the key supply device 13d provided at the point D, which is the destination of the encryption key, to supply information about the determined encryption method (i.e., information indicating that an encryption method using a key generated by PQC is used in part of the distribution route) to the application performing the encrypted communication. This allows the network management device 14 to show information about the security of the encrypted communication to the user of the application. In this case, the user can know that an encryption method using a key generated by PQC is used in part of the distribution route as the encryption method when distributing the encryption key used in the encrypted communication.
[0047] In the third example, the network management device 14 determines the encryption method for the encryption key on the distribution route between the locations B and D based on whether the key size required to be used for encrypting the encryption key distributed via the wiring route from the location B to the location D is equal to or less than the key size generated by QKD and stored in the key management devices 12b and 12d at the locations B and D, respectively, but this is not limited to this.
[0048] For example, the network management device 14 may determine the encryption method for the encryption key on the distribution route between the locations B and D based on whether the key size required to be used for encrypting the encryption key distributed via the wiring route from the location B to the location D is less than or equal to a predetermined first threshold and less than or equal to the key size generated by QKD stored in each of the key management devices 12b and 12d at the locations B and D.
[0049] In this case, if the key amount requested to be used to encrypt the encryption key distributed via the wiring route from point B to point D is less than a predetermined first threshold and less than the key amount generated by QKD stored in each key management device 12b, 12d at points B, D, the network management device 14 determines that the encryption method for the encryption key on the distribution route between points B, D will be an encryption method using a key generated by QKD; otherwise, it determines that the encryption method will be an encryption method using a key generated by PQC (other than QKD).
[0050] Alternatively, the network management device 14 may determine the encryption method for the encryption key on the delivery route between the locations B and D based on whether the amount of keys generated by QKD stored in the key management devices 12b and 12d at the locations B and D is greater than or equal to a predetermined second threshold.
[0051] In this case, if the amount of keys generated by QKD stored in each key management device 12b, 12d at points B, D is equal to or greater than a predetermined second threshold, the network management device 14 determines that the encryption method for the encryption key on the distribution route between points B, D will be an encryption method using a key generated by QKD; otherwise, it determines that the encryption method will be an encryption method using a key generated by PQC (other than QKD).
[0052] The network management device 14 may determine the encryption method for the encryption key for a wiring route other than between sites B and D, such as the wiring route between sites A and B, in the same manner as the encryption method for the encryption key for the wiring route between sites B and D. Furthermore, when an encryption method using a key generated by PQC is adopted as the encryption method for delivering the encryption key, the network management device 14 may specifically specify the type of PQC. Furthermore, the network management device 14 may adopt an encryption method using a key generated by RSA as the encryption method for the encryption key if security as high as that of QKD or PQC is not required.
[0053] In this way, the key distribution system 1 according to the present disclosure can provide users with information regarding the security of cryptographic communications, while allowing them to select and use an encryption method from multiple encryption methods when distributing cryptographic keys used in cryptographic communications, thereby enabling the construction of an extensive cryptographic communication network.
[0054] In the key distribution system 1 according to the present disclosure, the network management device 14 may determine the encryption method for the encryption key along the distribution path in accordance with conditions specified by an application that performs encrypted communication. In the following, the conditions specified by the application are represented by a parameter ε.
[0055] For example, if the parameter ε=0, the network management device 14 determines that there is no condition specified by the application. In this case, the network management device 14 determines the encryption key distribution route and the encryption method for the encryption key on the distribution route, for example, using the method described with reference to FIG.
[0056] Furthermore, when the parameter ε=1, the network management device 14 determines that the condition specified by the application is "to use only encryption methods using keys generated by QKD." In this case, the network management device 14 determines a delivery route that can adopt an encryption method using a key generated by QKD, and determines the encryption method of the encryption key for the determined delivery route to be an encryption method using a key generated by QKD. If no such delivery route exists, the network management device 14 returns an error to the application.
[0057] Furthermore, when the parameter ε=2, the network management device 14 determines that the condition specified by the application is "allowing the use of an encryption method using a key generated by PQC." In this case, the network management device 14 determines a distribution route for the encryption key, and determines the encryption method for the encryption key on the determined distribution route to be an encryption method using a key generated by QKD or PQC. Note that the parameter ε may specify a specific type of PQC or RSA.
[0058] Although the present disclosure has been described with reference to an example in which the network management device 14 determines the encryption key delivery route and the encryption method for the encryption key on that delivery route after receiving the parameter ε specified by the application, the present disclosure is not limited to this. For example, the network management device 14 may acquire multiple encryption keys generated under multiple conditions before receiving the parameter ε from the application, and then, immediately after receiving the parameter ε, provide the application with an encryption key that satisfies the conditions represented by the parameter ε.
[0059] Furthermore, the key distribution system 1 according to the present disclosure may be configured to enable encrypted communication between a mobile location P, such as an airplane, and fixed locations A to E, as shown in FIG. 6.
[0060] FIG. 7 is a diagram showing a fourth example of an encryption key distribution route determined by the network management device 14 and an encryption method for the encryption key distributed over the determined distribution route.
[0061] (Example 4) In the fourth example shown in FIG. 7, the network management device 14 determines the route from the point P, which is the source of the encryption key, via the relay points A and B to the point D, which is the destination of the encryption key, as the encryption key distribution route.
[0062] Here, a key management device (QKD device) 12 is installed at each of points A, B, and D. Furthermore, the key management devices 12a and 12b at points A and B are connected by a QKD link using optical fiber 50, and the key management devices 12b and 12d at points B and D are connected by a QKD link using optical fiber 50. In contrast, no key management device (QKD device) 12 is installed at point P. Furthermore, points P and A are not connected by a QKD link using optical fiber 50.
[0063] Therefore, the network management device 14 determines that the encryption method for the encryption key on the distribution route between the points P and A is to be an encryption method using a key generated by PQC (a key shared between the points P and A by a wirelessly communicable PQC).The network management device 14 also determines that the encryption method for the encryption key on the distribution route between the points A and B (i.e., from the key management device 12a to the key management device 12b) is to be an encryption method using a key generated by QKD.The network management device 14 also determines that the encryption method for the encryption key on the distribution route between the points B and D (i.e., from the key management device 12b to the key management device 12d) is to be an encryption method using a key generated by QKD.
[0064] Then, the network management device 14 causes the key supply device 13p provided at the point P, which is the source of the encryption key, and the key supply device 13d provided at the point D, which is the destination of the encryption key, to supply information about the determined encryption method (i.e., information indicating that an encryption method using a key generated by PQC is used in part of the distribution route) to the application performing the encrypted communication. This allows the network management device 14 to show the user of the application information about the security of the encrypted communication. In this case, the user can know that an encryption method using a key generated by PQC is used in part of the distribution route as the encryption method when distributing the encryption key used in the encrypted communication.
[0065] <Embodiment 2> In the first embodiment, the case has been described where information about the least secure encryption method among the encryption methods for encryption keys between nodes on the key distribution route determined by the network management device 14 is notified to the application, but the present invention is not limited to this. All information about the encryption methods for encryption keys between nodes on the key distribution route determined by the network management device 14 may be notified to the application. Furthermore, more specific information about the encryption method, such as the protocol and implementation method of the encryption method, may be notified to the application. This allows the user of the application to know in more detail the security level of the encryption method for encryption keys between nodes on the key distribution route, and thus allows the user to appropriately decide whether or not to officially adopt the key distribution route.
[0066] Fig. 8 is a diagram showing another example of an encryption key distribution route determined by the network management device 14 and an encryption method for the encryption key distributed over the determined distribution route. Figs. 9 and 10 are diagrams showing examples of the content of a notification to an application by the network management device 14. Hereinafter, QKD1 represents the quantum key distribution technology of the BB84 protocol, and QKD2 represents the quantum key distribution technology of the CV-QKD protocol. However, the quantum key distribution technology is not limited to BB84 or CV-QKD, and may be another protocol.
[0067] (Fifth Example) 8, network management device 14 determines, as the encryption key distribution route, a route from site A, which is the encryption key distribution source, to site D, which is the encryption key distribution destination, via relay site B. Specifically, network management device 14 determines, as the encryption key distribution route, a route from key management device 12a provided at site A, which is the encryption key distribution source, to key management device 12d provided at site D, which is the encryption key distribution destination, via key management device 12b provided at relay site B.
[0068] Here, the network management device 14 determines that the encryption method for the encryption key between points A and B is an encryption method using a key generated by QKD1 (quantum key distribution technology of the BB84 protocol).The network management device 14 also determines that the encryption method for the encryption key between points B and D is an encryption method using a key similarly generated by QKD1.
[0069] At this time, the network management device 14 causes information regarding the encryption method of the encryption key between each point on the determined key distribution route (i.e., the encryption method of the encryption key between points A and B, and the encryption method of the encryption key between points B and D) to be supplied to the application performing the encrypted communication by the key supply device 13a installed at point A, which is the source of the encryption key, and the key supply device 13d installed at point D, which is the destination of the encryption key.
[0070] The upper diagram of Figure 9 shows an example of the notification content to an application in the fifth example. As shown in the upper diagram of Figure 9, the application is notified of, for example, the encryption method of the encryption key between each point and the security level of the encryption method. This allows the user of the application to know in detail the security level of the encryption method of the encryption key between each point of the key distribution route, and therefore can appropriately decide whether or not to officially adopt the key distribution route.
[0071] Here, the quantum key distribution technology (QKD1) of the BB84 protocol may employ an implementation method called the decoy method, in which a decoy pulse with a different intensity from the optical pulse is mixed in with the optical pulse transmitted from the transmitter. When the decoy method is applied, the waveform of the applied voltage for modulating the optical intensity may be distorted due to the response speed of the electrical circuit, which may result in distortion of the waveforms of adjacent pulses. This phenomenon is called the pattern effect. If measures are taken to prevent this pattern effect, the safety level will be higher. Technology related to the pattern effect is also disclosed in Patent Document 2, for example.
[0072] Therefore, as shown in the upper diagram of Fig. 10, the application may be notified of information on whether or not QKD1 has been implemented with countermeasures against the pattern effect, as an example of how the encryption method is implemented. This allows the application user to know in more detail the security level of the encryption method for the encryption key between each node in the key distribution path, and thus to more appropriately decide whether or not to officially adopt the key distribution path.
[0073] (Example 6) 8, the network management device 14 determines, as the encryption key distribution route, a route from the site A, which is the source of the encryption key, to the site D, which is the destination of the encryption key, via the relay point C. Specifically, the network management device 14 determines, as the encryption key distribution route, a route from the key management device 12a provided at the site A, which is the source of the encryption key, via the key management device 12c provided at the relay point C, to the key management device 12d provided at the site D, which is the destination of the encryption key.
[0074] Here, the network management device 14 determines that the encryption method for the encryption key between points A and C is to be an encryption method using a key generated by QKD1. Also, the network management device 14 determines that the encryption method for the encryption key between points C and D is to be an encryption method using a key generated by QKD2 (a quantum key distribution technology of the CV-QKD protocol).
[0075] At this time, the network management device 14 causes information regarding the encryption method of the encryption key between each point on the determined key distribution route (i.e., the encryption method of the encryption key between points A and C, and the encryption method of the encryption key between points C and D) to be supplied to the application performing the encrypted communication by the key supply device 13a installed at point A, which is the source of the encryption key, and the key supply device 13d installed at point D, which is the destination of the encryption key.
[0076] The middle diagram in Figure 9 shows an example of the content of notification to an application in the sixth example. As shown in the middle diagram in Figure 9, the application is notified, for example, of the encryption method of the encryption key between each point and the security level of the encryption method. Furthermore, as shown in the middle diagram in Figure 10, the application may also be notified of information on whether or not QKD1 has been implemented with countermeasures against the pattern effect, as an example of how the encryption method is implemented. This allows the user of the application to know in more detail the security level of the encryption method of the encryption key between each point in the key distribution route, and therefore allows the user to appropriately decide whether or not to officially adopt the key distribution route.
[0077] (Example 7) 8, the network management device 14 determines, as the encryption key distribution route, a route from the site A, which is the source of the encryption key, to the site D, which is the destination of the encryption key, via the relay points B and C. Specifically, the network management device 14 determines, as the encryption key distribution route, a route from the key management device 12a provided at the site A, which is the source of the encryption key, to the key management device 12d provided at the site D, which is the destination of the encryption key, via the key management device 12b provided at the relay point B and the key management device 12c provided at the relay point C.
[0078] Here, the network management device 14 determines that the encryption method for the encryption key between points A and B will be an encryption method using a key generated by QKD1. The network management device 14 also determines that the encryption method for the encryption key between points B and C will be an encryption method using a key generated by PQC. Furthermore, the network management device 14 determines that the encryption method for the encryption key between points C and D will be an encryption method using a key generated by QKD2.
[0079] At this time, the network management device 14 causes information regarding the encryption method of the encryption key between each point on the determined key distribution route (i.e., the encryption method of the encryption key between points A and B, the encryption method of the encryption key between points B and C, and the encryption method of the encryption key between points C and D) to be supplied to the application performing the encrypted communication by the key supply device 13a installed at point A, which is the source of the encryption key, and the key supply device 13d installed at point D, which is the destination of the encryption key.
[0080] The bottom diagram of Figure 9 shows an example of the content of notification to an application in the seventh example. As shown in the bottom diagram of Figure 9, the application is notified, for example, of the encryption method of the encryption key between each point and the security level of the encryption method. Furthermore, as shown in the bottom diagram of Figure 10, the application may also be notified of information on whether or not QKD1 has been implemented with countermeasures against the pattern effect, as an example of how the encryption method is implemented. This allows the user of the application to know in more detail the security level of the encryption method of the encryption key between each point in the key distribution route, and therefore allows the user to appropriately decide whether or not to officially adopt the key distribution route.
[0081] In the present disclosure, as an example of a method for implementing an encryption method using QKD1, a case has been described in which information about whether or not countermeasures against the pattern effect have been implemented for QKD1 is notified to an application, but the present disclosure is not limited to this. For example, as another example of a method for implementing an encryption method using QKD1, information about whether or not countermeasures against a bright illumination attack have been implemented for a receiver may be notified to an application. A bright illumination attack is an attempt to disrupt the operation of a single photon detector provided in a receiver by inputting light of extremely high intensity into the receiver.
[0082] Furthermore, for example, in the quantum key distribution technology (QKD2) of the CV-QKD protocol, the LO light used for homodyne detection may be installed on the transmitter side. In this case, the LO light may be subject to eavesdropping attacks on the communication path from the transmitter to the receiver. To prevent such eavesdropping attacks, the LO light must be generated at the receiver. Therefore, as an example of a method for implementing an encryption method using QKD2, information on whether or not measures to generate LO light have been taken at the receiver may be notified to an application.
[0083] In this way, the key distribution system 1 according to the present disclosure can provide users with more detailed information regarding the security of cryptographic communications, while allowing them to select and use an encryption method from multiple encryption methods when distributing cryptographic keys used in cryptographic communications, thereby enabling the construction of an extensive cryptographic communication network.
[0084] The network management device 14 may determine the encryption method for the encryption key between each node on the determined key distribution route in accordance with the conditions specified by the application for the encrypted communication. In the following, the conditions specified by the application are represented by the parameter ε2.
[0085] For example, if the parameter ε2=0, the network management device 14 determines that there is no condition specified by the application. In this case, the network management device 14 determines the encryption key distribution route and the encryption method for the encryption key on the distribution route, for example, using the method described with reference to FIG.
[0086] Furthermore, when parameter ε2=1, the network management device 14 determines that the condition specified by the application is "to use only encryption methods using keys generated by QKD1." In this case, the network management device 14 determines a delivery route that can employ an encryption method using a key generated by QKD1, and determines the encryption method for the encryption key on the determined delivery route to be the encryption method using a key generated by QKD1. If no such delivery route exists, the network management device 14 returns an error to the application.
[0087] Furthermore, when the parameter ε2=2, the network management device 14 determines that the condition specified by the application is "to use only encryption methods using keys generated by QKD2." In this case, the network management device 14 determines a delivery route that can adopt an encryption method using a key generated by QKD2, and determines the encryption method for the encryption key on the determined delivery route to be the encryption method using a key generated by QKD2. If no such delivery route exists, the network management device 14 returns an error to the application.
[0088] Furthermore, when the parameter ε2=3, the network management device 14 determines that the condition specified by the application is "allowing the use of an encryption method using a key generated by PQC." In this case, the network management device 14 determines the distribution route of the encryption key, and determines the encryption method of the encryption key on the determined distribution route to be QKD1, QKD2, or an encryption method using a key generated by PQC. Note that the parameter ε2 may specify a specific type of PQC or RSA.
[0089] In the present disclosure, the network management device 14 determines the encryption key delivery route and the encryption method for the encryption key on the delivery route after receiving the parameter ε2 specified by the application, but the present disclosure is not limited to this. For example, the network management device 14 may acquire multiple encryption keys generated under multiple conditions before receiving the parameter ε2 from the application, and immediately supply the encryption key satisfying the conditions represented by the parameter ε2 to the application after receiving the parameter ε2.
[0090] (Hardware configuration for realizing the key management function of the key management device 12) The key management process performed by the key management device 12 can be realized by a general-purpose computer system, which will be briefly explained below with reference to FIG.
[0091] 11 is a block diagram showing an example of a hardware configuration that realizes the key management function of the key management device 12. The computer 300 includes, for example, a central processing unit (CPU) 301, which is a control device, a random access memory (RAM) 302, and a read only memory (ROM) 303. The computer 300 further includes an interface (IF) 304, which is an interface with the outside, and a hard disk drive (HDD) 305, which is an example of a non-volatile storage device. The computer 300 may also include input devices such as a keyboard and a mouse, and a display device such as a display, as other components not shown.
[0092] The HDD 305 stores an OS (Operating System) (not shown) and a control program 306. The control program 306 is a computer program in which the key management process of the key management device 12 is implemented.
[0093] The CPU 301 controls various processes in the computer 300, and access to the RAM 302, ROM 303, IF 304, and HDD 305. In the computer 300, the CPU 301 reads and executes the OS and control program 306 stored in the HDD 305. In this way, the computer 300 realizes the key management function of the key management device 12.
[0094] The above-mentioned program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in this disclosure. The program may be stored on a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable medium or tangible storage medium includes RAM, ROM, flash memory, solid-state drive (SSD) or other memory technology, CD-ROM, digital versatile disc (DVD), Blu-ray disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable medium or communication medium includes electrical, optical, acoustic, or other forms of propagated signals.
[0095] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.
[0096] Each drawing is merely an example for describing one or more embodiments. Each drawing may relate not only to one particular embodiment, but also to one or more other embodiments. As will be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings to create, for example, an embodiment not explicitly shown or described. Not all features or steps shown in any one drawing are necessary to describe an exemplary embodiment, and some features or steps may be omitted. The order of steps described in any drawing may be changed as appropriate.
[0097] Furthermore, some or all of the above-described embodiments can be described as, but are not limited to, the following supplementary notes.
[0098] (Appendix 1) a plurality of key generation devices provided at a plurality of locations, each of which generates an encryption key; a plurality of key management devices provided corresponding to the plurality of key generation devices and managing the encryption keys generated by the plurality of key generation devices; a plurality of key supply devices provided corresponding to the plurality of key management devices and supplying encryption keys managed by the plurality of key management devices to applications performing encrypted communication; a network management device; Equipped with the network management device, a determination unit that determines a distribution route of the encryption key from a first key management device that is a distribution source of the encryption key among the plurality of key management devices to a second key management device that is a distribution destination of the encryption key, and an encryption method of the encryption key along the distribution route; an output control unit that causes first and second key supplying devices, which are provided corresponding to the first and second key management devices among the plurality of key supplying devices, to supply information about the determined encryption method to an application that performs encrypted communication; A key distribution system comprising:
[0099] (Appendix 2) The encryption method of the encryption key includes at least an encryption method using a key generated by QKD (Quantum Key Distribution) and an encryption method using a key generated by PQC (Post-Quantum Cryptography). 1. A key distribution system as described in Appendix 1.
[0100] (Appendix 3) When the delivery route includes a first delivery route that passes through a key generation device among the plurality of key generation devices that is connected by a QKD (Quantum Key Distribution) link, the determination unit determines that the encryption method of the encryption key in the first delivery route is an encryption method that uses a key generated by QKD. 1. A key distribution system as described in Appendix 1.
[0101] (Appendix 4) When the distribution route includes a first distribution route that passes through a key generation device among the plurality of key generation devices that is connected by a QKD (Quantum Key Distribution) link, and when the amount of key required for encryption of the encryption key distributed via the first distribution route is equal to or less than the amount of key generated by QKD and stored in a key management device provided on the first distribution route, the determination unit determines the encryption method of the encryption key on the first distribution route to be an encryption method that uses a key generated by QKD. 1. A key distribution system as described in Appendix 1.
[0102] (Appendix 5) When the delivery route includes a first delivery route that passes through a key generation device among the plurality of key generation devices that is connected by a QKD (Quantum Key Distribution) link, and when the key size required for encryption of the encryption key delivered via the first delivery route is equal to or less than a preset first threshold and equal to or less than the key size generated by QKD and stored in a key management device provided on the first delivery route, the determination unit determines the encryption method of the encryption key on the first delivery route to be an encryption method that uses a key generated by QKD. 1. A key distribution system as described in Appendix 1.
[0103] (Appendix 6) When the delivery route includes a first delivery route that passes through a key generation device connected by a QKD (Quantum Key Distribution) link among the plurality of key generation devices, and when the amount of keys generated by QKD and stored in a key management device provided on the first delivery route is equal to or greater than a second preset threshold, the determination unit determines that the encryption method of the encryption key on the first delivery route is an encryption method that uses a key generated by QKD. 1. A key distribution system as described in Appendix 1.
[0104] (Appendix 7) When the delivery route includes a first delivery route that passes through a key generation device among the plurality of key generation devices that is not connected by a QKD (Quantum Key Distribution) link, the determination unit determines an encryption method for the encryption key in the first delivery route to be an encryption method different from an encryption method using a key generated by QKD. 1. A key distribution system as described in Appendix 1.
[0105] (Appendix 8) When the delivery route includes a first delivery route that passes through a key generation device among the plurality of key generation devices that is not connected by a QKD (Quantum Key Distribution) link, the determination unit determines that the encryption method of the encryption key in the first delivery route is an encryption method that uses a key generated by PQC (Post-Quantum Cryptography). 1. A key distribution system as described in Appendix 1.
[0106] (Appendix 9) the network management device determines an encryption method for the encryption key along the delivery path in accordance with conditions specified by an application for performing encrypted communication; 1. A key distribution system as described in Appendix 1.
[0107] (Appendix 10) the network management device causes the first and second key supply devices to supply the encryption method of the encryption key between each of the determined nodes on the delivery route as information on the encryption method to an application that performs encrypted communication. 1. A key distribution system as described in Appendix 1.
[0108] (Appendix 11) the network management device further provides, via the first and second key provision devices, an implementation method of the encryption method for the encryption key between each of the determined points on the delivery route as information on the encryption method to an application that performs encrypted communication. 11. The key distribution system of claim 10.
[0109] (Appendix 12) the network management device determines an encryption method for the encryption key along the delivery path in accordance with conditions specified by an application for performing encrypted communication; 11. The key distribution system of claim 10.
[0110] (Appendix 13) determining a delivery route of an encryption key from a first key management device that is a delivery source of the encryption key to a second key management device that is a delivery destination of the encryption key, and an encryption method of the encryption key along the delivery route, among a plurality of key management devices that are provided corresponding to a plurality of key generation devices provided at a plurality of locations and that manage the encryption keys generated by the plurality of key generation devices, respectively; providing information about the determined encryption method to an application performing encrypted communication by first and second key supply devices provided corresponding to the first and second key management devices among a plurality of key supply devices provided corresponding to the plurality of key management devices; Control method by key distribution system.
[0111] (Appendix 14) a process of determining a delivery route of an encryption key from a first key management device that is a delivery source of the encryption key to a second key management device that is a delivery destination of the encryption key, and an encryption method of the encryption key along the delivery route, among a plurality of key management devices that are provided corresponding to a plurality of key generation devices provided at a plurality of bases and that manage the encryption keys generated by the plurality of key generation devices, respectively; a process of causing a first key supply device and a second key supply device, which are provided corresponding to the first and second key management devices among a plurality of key supply devices provided corresponding to the plurality of key management devices, to supply information about the determined encryption method to an application that performs encrypted communication; A control program that causes a computer to execute the above.
[0112] Some or all of the elements (e.g., configurations and functions) described in Supplementary Notes 2 to 12 that are dependent on Supplementary Notes 1 may also be dependent on Supplementary Notes 13 and 14 in the same dependency relationship as Supplementary Notes 2 to 12. Some or all of the elements described in any Supplementary Note may be applied to various hardware, software, recording means for recording software, systems, and methods. [Explanation of symbols]
[0113] 1. Key Distribution System 11 Key generation device 12 Key management device 12a~12d Key management device 13 Key supply device 13a,13d,13p Key supply device 14 Network Management Device 50 Optical Fiber 141 Decision Section 142 Output control section 300 Computers 301 CPU 302 RAM 303 ROM 304 IF 305 HDD 306 Control Program
Claims
1. a plurality of key generation devices provided at a plurality of locations, each of which generates an encryption key; a plurality of key management devices provided corresponding to the plurality of key generation devices and managing the encryption keys generated by the plurality of key generation devices; a plurality of key supply devices provided corresponding to the plurality of key management devices and supplying encryption keys managed by the plurality of key management devices to applications performing encrypted communication; a network management device; Equipped with the network management device, a determination unit that determines a distribution route of the encryption key from a first key management device that is a distribution source of the encryption key among the plurality of key management devices to a second key management device that is a distribution destination of the encryption key, and an encryption method of the encryption key along the distribution route; an output control unit that causes first and second key supplying devices, which are provided corresponding to the first and second key management devices among the plurality of key supplying devices, to supply information about the determined encryption method to an application that performs encrypted communication; A key distribution system comprising:
2. The encryption method of the encryption key includes at least an encryption method using a key generated by QKD (Quantum Key Distribution) and an encryption method using a key generated by PQC (Post-Quantum Cryptography). The key distribution system according to claim 1 .
3. When the delivery route includes a first delivery route that passes through a key generation device among the plurality of key generation devices that is connected by a QKD (Quantum Key Distribution) link, the determination unit determines that the encryption method of the encryption key in the first delivery route is an encryption method that uses a key generated by QKD. The key distribution system according to claim 1 .
4. When the distribution route includes a first distribution route that passes through a key generation device among the plurality of key generation devices that is connected by a QKD (Quantum Key Distribution) link, and when the amount of key required for encryption of the encryption key distributed via the first distribution route is equal to or less than the amount of key generated by QKD and stored in a key management device provided on the first distribution route, the determination unit determines the encryption method of the encryption key on the first distribution route to be an encryption method using a key generated by QKD. The key distribution system according to claim 1 .
5. When the distribution route includes a first distribution route that passes through a key generation device among the plurality of key generation devices that is connected by a QKD (Quantum Key Distribution) link, and when a key amount required for encryption of the encryption key distributed via the first distribution route is equal to or less than a preset first threshold and equal to or less than a key amount generated by QKD and stored in a key management device provided on the first distribution route, the determination unit determines that the encryption method of the encryption key on the first distribution route is an encryption method using a key generated by QKD. The key distribution system according to claim 1 .
6. When the delivery route includes a first delivery route that passes through a key generation device connected by a QKD (Quantum Key Distribution) link among the plurality of key generation devices, and when the amount of keys generated by QKD and stored in a key management device provided on the first delivery route is equal to or greater than a second preset threshold, the determination unit determines that the encryption method of the encryption key on the first delivery route is an encryption method using a key generated by QKD. The key distribution system according to claim 1 .
7. When the delivery route includes a first delivery route that passes through a key generation device among the plurality of key generation devices that is not connected by a QKD (Quantum Key Distribution) link, the determination unit determines an encryption method for the encryption key in the first delivery route to be an encryption method different from an encryption method using a key generated by QKD. The key distribution system according to claim 1 .
8. When the delivery route includes a first delivery route that passes through a key generation device among the plurality of key generation devices that is not connected by a QKD (Quantum Key Distribution) link, the determination unit determines that the encryption method of the encryption key in the first delivery route is an encryption method that uses a key generated by PQC (Post-Quantum Cryptography). The key distribution system according to claim 1 .
9. the network management device determines an encryption method for the encryption key along the delivery path in accordance with conditions specified by an application for performing encrypted communication; The key distribution system according to claim 1 .
10. the network management device causes the first and second key supply devices to supply the encryption method of the encryption key between the determined nodes of the delivery route as information on the encryption method to an application that performs encrypted communication; The key distribution system according to claim 1 .
11. the network management device further provides, via the first and second key provision devices, an implementation method of the encryption method for the encryption key between each of the determined nodes on the delivery route as information on the encryption method to an application that performs encrypted communication. The key distribution system according to claim 10.
12. the network management device determines an encryption method for the encryption key along the delivery path in accordance with conditions specified by an application for performing encrypted communication; The key distribution system according to claim 10.
13. determining a delivery route of an encryption key from a first key management device that is a delivery source of the encryption key to a second key management device that is a delivery destination of the encryption key, and an encryption method of the encryption key along the delivery route, among a plurality of key management devices that are provided corresponding to a plurality of key generation devices provided at a plurality of bases and that manage the encryption keys generated by the plurality of key generation devices, respectively; providing information about the determined encryption method to an application performing encrypted communication by first and second key supply devices provided corresponding to the first and second key management devices among a plurality of key supply devices provided corresponding to the plurality of key management devices; Control method by key distribution system.
14. a process of determining a delivery route of an encryption key from a first key management device that is a delivery source of the encryption key to a second key management device that is a delivery destination of the encryption key, and an encryption method of the encryption key along the delivery route, among a plurality of key management devices that are provided corresponding to a plurality of key generation devices provided at a plurality of bases and that manage the encryption keys generated by the plurality of key generation devices, respectively; a process of causing a first key supplying device and a second key supplying device, which are provided corresponding to the first and second key management devices among a plurality of key supplying devices provided corresponding to the plurality of key management devices, to supply information about the determined encryption method to an application that performs encrypted communication; A control program that causes a computer to execute the above.
Citation Information
Patent Citations
Transmitting device, receiving device, quantum key distribution method, and quantum key distribution program for quantum key distribution system
WO2018047716A1
Key exchange system, hub device, QKD device, method, and program
WO2023218575A1