Quantum key distribution apparatus and quantum key distribution method
By transforming and processing data without accessing external memory, the quantum key distribution device addresses inefficiencies in data transfer, enhancing processing performance and key generation rates through reduced memory access.
Patent Information
- Application Number
- JP2024106212
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-01
- Publication Date
- 2026-01-16
AI Technical Summary
Conventional quantum key distribution techniques face challenges in reducing the amount of data transferred to and from external memory during privacy amplification, leading to inefficiencies in processing performance due to insufficient data transfer bandwidth.
The quantum key distribution device employs a processing unit that generates and transforms data using a hash function, storing it in external memory, and performs element multiplication and inverse transformation operations without accessing external memory, thereby reducing data transfer by dividing the processes into partial operations.
This approach significantly reduces the amount of data transferred to and from external memory, improving processing performance by approximately 22-50% and enhancing key generation rates.
Smart Images

Figure 2026006878000001_ABST
Abstract
Description
[Technical Field]
[0001] FIELD Embodiments of the present invention relate to a quantum key distribution device and a quantum key distribution method. [Background technology]
[0002] Quantum cryptography technology is expected to be put into practical use as an encryption technology that cannot be decrypted even with the advancement of computer computing power. In quantum cryptography, secure encryption keys are shared between senders and receivers using quantum key distribution (QKD). [Prior art documents] [Non-patent literature]
[0003] [Non-Patent Document 1] M. Lucamarini, KAPatel, JFDynes, B. Frohlich, AWSharpe, ARDixon, ZLYuan, RVPenty, and AJShields, “Efficient decoy-state quantum key distribution with quantified security”, Opt.Express 21,24550-24565 (2013) [Non-patent document 2] M.Hayashi, “Exponential Decreasing Rate of Leaked Information in Universal Random Privacy”, IEEE Transactions on Information Theory,Vol.57,2011 [Non-patent document 3] DHBailey, “FFTs in External or Hierarchical Memory”, Journal of Supercomputing, Vol. 4, No. 1, 1990. [Non-patent document 4] B.Yan,et al., “An efficient hybrid hash based privacy amplification algorithm for quantum key distribution.”,Quantum Inf Process 21,130 (2022). [Non-patent document 5] W.Li,et al., “High-rate quantum key distribution exceeding 110 Mb s-1”, Nature Photonics,17,416-421 (2023). Summary of the Invention [Problem to be solved by the invention]
[0004] However, with conventional techniques, it has been difficult to reduce the amount of data transferred to and from external memory in Privacy Amplification (PA). [Means for solving the problem]
[0005] A quantum key distribution device according to an embodiment includes a processing unit. The processing unit generates input vector transformation data and random number transformation data by performing a transformation process to transform an input vector based on photons received via a quantum cryptography communication channel and random number data based on a hash function into data in frequency space. The processing unit stores the input vector transformation data and the random number transformation data in an external memory. The processing unit reads a portion of the input vector transformation data and a portion of the random number transformation data from the external memory to a local memory. The processing unit performs an element multiplication operation between a portion of the input vector transformation data and a portion of the random number transformation data, and an inverse transformation process of a result of the element multiplication operation, without accessing the external memory, and writes intermediate results of the inverse transformation process to the external memory. [Brief explanation of the drawings]
[0006] [Figure 1]FIG. 2 is a diagram showing an example of the functional configuration of the quantum key distribution device according to the first embodiment. [Figure 2] FIG. 2 is a diagram for explaining an example of privacy amplification processing using a Toeplitz matrix according to the first embodiment. [Figure 3] FIG. 2 is a diagram for explaining an example of privacy amplification processing using a Toeplitz matrix according to the first embodiment. [Figure 4A] 10 is a flowchart showing the first half of an example of privacy amplification processing according to the first embodiment. [Figure 4B] 10 is a flowchart showing the second half of an example of the privacy amplification processing according to the first embodiment. [Figure 5] FIG. 1 is a diagram for explaining an example of processing by the Six-step method in FFT or NTT. [Figure 6] FIG. 6 is a diagram for explaining the processing order of the Six-step method in FIG. 5; [Figure 7A] FIG. 4 is a diagram showing an example of the first half of processing when the Six-step method is applied in the first embodiment. [Figure 7B] FIG. 4 is a diagram showing an example of the latter half of processing when the Six-step method is applied in the first embodiment. [Figure 8] FIG. 4B is a diagram for explaining a processing example in which the Six-step method is applied to the inverse transformation processing (first half) flow of FIG. 4A. [Figure 9A] FIG. 10 is a diagram for explaining an example of a division calculation method of a Toeplitz matrix according to the second embodiment. [Figure 9B] FIG. 10 is a diagram for explaining an example of a division calculation method of a Toeplitz matrix according to the second embodiment. [Figure 10] 10 is a flowchart showing the first half of an example of privacy amplification processing according to the second embodiment. [Figure 11A] FIG. 11 is a diagram for explaining the details of the processing in the first half of the flowchart in FIG. 10; [Figure 11B] FIG. 11 is a diagram for explaining the details of the processing in the first half of the flowchart in FIG. 10; [Figure 11C] FIG. 11 is a diagram for explaining the details of the processing in the first half of the flowchart in FIG. 10; [Figure 12] FIG. 11 is a diagram for explaining an example of calculation of MMH-MH in the third embodiment. [Figure 13] FIG. 10 is a diagram showing an example of a calculation method for multiple-precision multiplication using NTT according to the third embodiment. [Figure 14A] 11 is a flowchart showing the first half of an example of privacy amplification processing according to the third embodiment. [Figure 14B] 13 is a flowchart showing the second half of an example of the privacy amplification processing according to the third embodiment. [Figure 15] FIG. 1 is a diagram showing an example of the hardware configuration of a quantum key distribution device according to first to third embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0007] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, embodiments of a quantum key distribution device and a quantum key distribution method will be described in detail with reference to the accompanying drawings.
[0008] In quantum key distribution, the final encryption key data is generated through privacy amplification processing using a hash function such as a Toeplitz matrix. Due to the finite size effect described in Non-Patent Document 1, privacy amplification processing for large-scale input data is required to achieve high key generation speed.
[0009] In the case of a hash function using a Toeplitz matrix, which is commonly used in privacy amplification processing, the Toeplitz matrix is multiplied by the error-corrected vector data. At this time, a calculation reduction method using a transformation process that converts data into frequency space can be applied. For example, the fast Fourier transform (FFT) or the number theoretic transform (NTT) can be used as the transformation process.
[0010] As mentioned above, privacy amplification processing is performed on large amounts of input data, so the number of FFT or NTT points also becomes large. Hereafter, FFT or NTT will be referred to as FFT / NTT.
[0011] For example, to handle 100 Mbit input data, a 134,217,728-point FFT / NTT is required, and if the conversion process is performed at 32 bits, 4 Gbits of data is required just for the input data. It is not realistic to store all of this large data in local memory close to the processor (for example, cache memory (SRAM: Static Random Access Memory)). Therefore, this data is generally stored in external memory (DRAM: Dynamic Random Access Memory), and data is transferred between the local memory and external memory during calculation.
[0012] As mentioned above, the data required for FFT / NTT is usually stored in external memory, but this requires transferring a huge amount of data between the external memory and local memory. Therefore, in systems where the data transfer bandwidth between the external memory and the processor is insufficient, this data transfer becomes a bottleneck, preventing the processor's arithmetic units from operating efficiently and resulting in a decrease in processing performance.
[0013] (First embodiment) First, an example of the functional configuration of the quantum key distribution device 1 of the first embodiment will be described.
[0014] [Example of functional configuration] 1 is a diagram showing an example of the functional configuration of a quantum key distribution device 1 according to the first embodiment. The quantum key distribution device 1 according to the first embodiment includes a receiving unit 11 and a processing unit 12. The processing unit 12 includes a sifting processing unit 13, an EC (Error Correction) processing unit 14, and a PA (Privacy Amplification) processing unit 15.
[0015] The receiving unit 11 receives photons from a quantum cryptography communication channel and inputs the photons to the processing unit 12 .
[0016] The processing unit 12 is realized by at least one processing unit, and executes the processing of the quantum key distribution device 1. This processing unit includes, for example, a control unit and an arithmetic unit, and is realized by analog or digital circuits, etc. The processing unit may be a central processing unit (CPU), a general-purpose processor, a microprocessor, a digital signal processor (DSP), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a combination thereof.
[0017] The sifting processing unit 13 performs sifting processing to acquire sifted key data by referring to the photon data in units of a predetermined bit string using a reference base randomly selected from a plurality of bases.
[0018] The EC processing unit 14 corrects errors contained in the sifted key data and generates input data to be input to the PA processing unit 16 .
[0019] The PA processing unit 15 performs privacy amplification processing on the input data input from the EC processing unit 14. The privacy amplification processing of the first embodiment employs a Toeplitz matrix as a hash function, and performs an element product operation and an inverse transformation process using the operation result without accessing an external memory.
[0020] 1 illustrates a configuration in which the processing unit 12 includes the sifting processing unit 13, the EC processing unit 14, and the PA processing unit 15, but the processing unit 12 may be configured to implement only the PA processing unit 15. In this case, the processing of the sifting processing unit 13 and the EC processing unit 14 is implemented by, for example, another processing unit outside the processing unit 12.
[0021] 2 and 3 are diagrams for explaining an example of privacy amplification processing using a Toeplitz matrix according to the first embodiment. In the privacy amplification processing using a Toeplitz matrix, final encryption key data is obtained by multiplying the Toeplitz matrix by an input vector, as shown in FIG.
[0022] The Toeplitz matrix used in privacy amplification processing is a random matrix, and as shown in Figure 3, a Toeplitz matrix has the property that identical values appear in the bottom right corner. By utilizing this property, a Toeplitz matrix element vector containing some of the elements of a Toeplitz matrix can be used as random data. Specifically, the multiplication of a Toeplitz matrix and an input vector can be expressed by convolution of the input vector with a random vector (Toeplitz matrix element vector) that combines the unique values in the first row and first column of the Toeplitz matrix.
[0023] This convolution operation is generally performed using FFT / NTT to reduce the amount of calculation. As a processing method, FFT / NTT is performed on each of the input vector and the Toeplitz matrix element vector, and each of the input vector and the Toeplitz matrix element vector is converted into data in frequency space.
[0024] Hereinafter, data obtained by converting a Toeplitz matrix element vector into data in frequency space will be referred to as "Toeplitz matrix transformed data." Also, data obtained by converting an input vector into data in frequency space will be referred to as "input vector transformed data."
[0025] The Toeplitz matrix transformation data and the input vector transformation data are multiplied element by element (element product), and then the inverse transformation process (IFFT (Inverse Fast Fourier Transform) / INTT (Inverse Number Theoretic Transform)) is performed on the vector after the element product. This allows for an operation equivalent to multiplying the original Toeplitz matrix and the input vector, and the final encryption key data is obtained.
[0026] [Example of Privacy Amplification Processing] Fig. 4A is a first half flowchart showing an example of the privacy amplification processing according to the first embodiment, and Fig. 4B is a second half flowchart showing an example of the privacy amplification processing according to the first embodiment.
[0027] 4A and 4B, the inverse transform process (IFFT / INTT) of FFT / NTT in the privacy amplification process is divided into a first half and a second half. When the first half of the inverse transform process is completed, the processing unit 12 writes the intermediate data to the external memory, and when the second half of the inverse transform process starts, the processing unit 12 reads the intermediate data from the external memory to the local memory.
[0028] First, the processing unit 12 reads out partial data representing a part of the above-mentioned input vector transformation data and partial data representing a part of the above-mentioned Toeplitz matrix transformation data into the local memory (steps S1 and S2).
[0029] Next, the processing unit 12 performs an element product operation and the first half of the inverse transformation process on the partial data read out in steps S1 and S2 (steps S3 and S4), and then writes out the partial data as intermediate data (step S5).
[0030] The processing unit 12 repeats steps S1 to S6, and when all data (input vector transformation data and Toeplitz matrix transformation data) have been calculated (step S6, Yes), in the next step S7, it again partially reads out these intermediate data and partially processes the latter half of the inverse transformation process (steps S8 to S10), thereby completing the element product and inverse transformation process.
[0031] As shown in Figures 4A and 4B, the processing unit 12 generates cryptographic key data from the input vector conversion data and the random number conversion data by repeatedly performing an element product operation between partial data representing a part of the input vector conversion data and partial data representing a part of the random number conversion data, and an inverse conversion process of the result of the element product operation.
[0032] At this time, reading and writing of partial data requires external memory access, but no external memory access is performed between the element product calculation (step S3) and the first half of the IFFT / INTT processing (step S4).
[0033] To improve the key generation rate, it is necessary to increase the size of the FFT / NTT in the privacy amplification process, which reduces memory access efficiency. In this case, a memory access efficiency method such as the Six-step method described in Non-Patent Document 3 can be applied.
[0034] Fig. 5 is a diagram for explaining an example of processing in the Six-step method in FFT or NTT. Fig. 6 is a diagram for explaining the processing order of the Six-step method in Fig. 5.
[0035] In the Six-step method, when the number of FFT / NTT points is N, the vector data is two-dimensionally expanded to N=N1×N2 as shown in Fig. 5. That is, when the Six-step method is applied, the processing unit 12 performs FFT / NTT processing by arranging the above-mentioned input vector and Toeplitz matrix element vector two-dimensionally.
[0036] In the transform process, the two-dimensionally expanded input data is first transposed, as shown in Figure 6. Next, an N1-point FFT / NTT is performed on each row, after which the data is multiplied by twiddle coefficient data that depends on each data position, and then transposed again. By performing an N2-point FFT / NTT on each row before transposing, it is possible to perform calculations equivalent to an N-point FFT / NTT.
[0037] The inverse transform (IFFT / INTT) is also processed in the same manner as the above transform process, except that N1 and N2 are reversed.
[0038] In the privacy amplification process, since it is redundant to transpose the data that was transposed at the end of the transform process again at the beginning of the inverse transform process, these transposition processes may be omitted.
[0039] In quantum cryptography communication, the cryptographic key data is random numbers, and the data order does not matter as long as it follows the same rules between the sender and receiver. Therefore, although it is not equivalent to the original operation, the first transposition process in the transformation process and the last transposition process in the inverse transformation process may also be omitted.
[0040] In the above-mentioned Six-step method, the number of FFT / NTT points N is generally a very large value (e.g., 134,217,728), and therefore, due to the data size required for processing, it is not realistic to store all data in local memory. Therefore, in the first embodiment, the transform processing and inverse transform processing when the Six-step method is applied are divided into a first half and a second half, and data is read and processed partially.
[0041] 7A and 7B are diagrams showing examples of the first half and second half processes when the Six-step method is applied in the first embodiment. Taking the Six-step method as an example, due to the dependency of data accessed in each process, the first half is up to the second transposition process, and the subsequent processes are divided into the second half, as shown in FIGS. 7A and 7B. The external memory is accessed at the start and end of the first half process, and at the start and end of the second half process.
[0042] Fig. 8 is a diagram for explaining a processing example when the Six-step algorithm is applied to the inverse transformation processing (first half) flow of Fig. 4A. In the example of Fig. 8, the processing unit 12 partially reads out from the external memory the input vector transformation data and the Toeplitz matrix transformation data in an amount that can be stored in the local memory. Then, the processing unit 12 performs element multiplication and the first half of the inverse transformation processing on the partially read out input vector transformation data and the Toeplitz matrix transformation data, and writes the result (intermediate data) to the external memory.
[0043] In this case, external memory access between the element product result and the inverse transformation process (first half) is not required, so it is possible to reduce the amount of data transferred to and from the external memory.
[0044] Then, in the next step, the processing unit 12 reads the intermediate data partially again and performs the inverse transformation process (the latter half), thereby completing the privacy amplification process.
[0045] As described above, the quantum key distribution device 1 of the first embodiment includes the processing unit 12. The processing unit 12 performs a conversion process to convert an input vector based on photons received via a quantum cryptography communication channel and random number data based on a hash function into data in frequency space, thereby generating input vector conversion data and random number conversion data. The processing unit 12 stores the input vector conversion data and the random number conversion data in an external memory. The processing unit reads a portion of the input vector conversion data and a portion of the random number conversion data from the external memory to the local memory. The processing unit performs an element multiplication operation between a portion of the input vector conversion data and a portion of the random number conversion data, and an inverse conversion process of the calculation result of the element multiplication operation, without accessing the external memory, and writes intermediate results of the inverse conversion process to the external memory.
[0046] According to the first embodiment, the amount of data transferred to and from the external memory can be reduced in the privacy amplification processing. Specifically, in the first embodiment, the amount of data transferred to and from the external memory can be reduced by omitting external memory access between the element product operation and the inverse transform processing (first half).
[0047] The first embodiment can also be applied to the modified Toeplitz matrix of Non-Patent Document 2. The modified Toeplitz matrix is a method of performing privacy amplification processing using a matrix that combines an identity matrix and a Toeplitz matrix, and can be calculated with a smaller FFT / NTT than a normal Toeplitz matrix. Therefore, when the modified Toeplitz matrix is applied, the amount of calculation and the amount of data transfer are generally reduced.
[0048] Even when this modified Toeplitz matrix is used, the processing unit 12 can reduce the amount of data transferred to and from the external memory by partially reading the modified Toeplitz matrix transformation data and omitting external memory access between the element product operation and the inverse transformation process (first half).
[0049] According to the first embodiment, it is possible to reduce the amount of data transferred to and from external memory by approximately 22%. Furthermore, by combining it with the modified Toeplitz matrix of Non-Patent Document 2, it is possible to reduce the amount of data transferred to and from external memory by approximately 45%.
[0050] This makes it possible to improve processing performance in systems where the data transfer bandwidth to and from external memory is a bottleneck, depending on the amount of data transfer reduced. For example, if the amount of data transfer is reduced by about half, performance can be improved by about two times by scaling to that reduction.
[0051] (Second embodiment) Next, a second embodiment will be described. In the description of the second embodiment, the same description as in the first embodiment will be omitted, and only the differences from the first embodiment will be described.
[0052] In the privacy amplification process of the second embodiment, a Toeplitz matrix is adopted as a hash function. In the second embodiment, an element product operation and an inverse transformation operation using the operation result are performed without accessing an external memory, and the Toeplitz matrix transformation data read from the external memory is stored in a local memory and reused.
[0053] In the second embodiment, the Toeplitz matrix is divided for processing, which allows the number of FFT / NTT points to be reduced. However, since increasing the number of divisions reduces the effect of reducing the amount of computation by butterfly operations, it is necessary to limit the number of divisions in order to obtain a certain amount of computation reduction effect, and the data remains relatively large even after division.
[0054] 9A and 9B are diagrams for explaining an example of a division calculation method of a Toeplitz matrix according to the second embodiment.
[0055] Toeplitz matrices have the property that the same value appears in the bottom right element, and the same matrix also appears in the bottom right element of divided matrices. Furthermore, the same property is also true for data transformed by FFT / NTT, so in a divided matrix as shown in Figure 9A, the transformed data of matrices A to I at the left and top edges can be reused.
[0056] When performing privacy amplification processing using a Toeplitz matrix divided as shown in FIG. 9A, the processing unit 12 calculates, for example, divided blocks β of the output vector as shown in FIG. 9B.
[0057] The calculation method for the divided blocks α, γ, and δ of the output vector is the same as the calculation method for the divided block β. That is, the processing unit 12 first performs element product and inverse transform processing on corresponding divided blocks for the divided blocks of the Toeplitz matrix transformation data and the divided blocks of the input vector transformation data. Then, the processing unit 12 calculates the output vector of the divided block by exclusive ORing the vectors (binary data) indicating the results of the element product and inverse transform processing.
[0058] As mentioned above, in a Toeplitz matrix, the same data appears diagonally downward to the right, so if the divided matrix is accessed diagonally downward to the right while processing the input data block, the Toeplitz matrix transformation data can be reused.
[0059] Fig. 10 is a first half flowchart showing an example of privacy amplification processing according to the second embodiment. The first half flowchart in Fig. 10 includes an element product operation and the first half of the inverse transform processing.
[0060] First, the processing unit 12 reads out some of the partial data (divided matrix blocks) of the Toeplitz matrix transformation data from the external memory and stores them in the local memory (step S21).
[0061] Next, the processing unit 12 reads out from the external memory a part of the partial data (divided input block) of the input vector conversion data of the divided region corresponding to the part of the partial data read out in step S21, and stores it in the local memory (step S22).
[0062] Next, the processing unit 12 performs an element multiplication operation between a part of the divided matrix block and a part of the divided input block, and the first half of the inverse transformation process using the result of the operation, without accessing the external memory (steps S23 and S24).
[0063] Next, the processing unit 12 writes the data obtained by the processes of steps S23 and S24 to the external memory as partial data of the intermediate data (step S25).
[0064] Next, the processing unit 12 determines whether or not the reuse of the Toeplitz matrix transformation data has been completed (step S26).
[0065] If the reuse of the Toeplitz matrix transformation data is not complete (step S26, No), that is, if the processing unit 12 can reuse part of the divided matrix block read in step S21 for the processes of steps S23 and S24, the processing returns to the process of step S22.
[0066] When the Toeplitz matrix transformation data is reused, the processes of steps S22 to S25 are performed while part of the divided matrix block read out in step S21 remains held in the local memory.
[0067] When the reuse of the Toeplitz matrix transformation data is completed (Yes at step S26), the processing unit 12 determines whether or not the processing is completed for all the data (all of the Toeplitz matrix transformation data) (step S27).
[0068] If the process has not been completed for all the data (step S27, No), the process returns to step S21, and if the process has been completed for all the data (step S27, Yes), the first half of the inverse conversion process ends.
[0069] As described above, the processing unit 12 repeats the processes of steps S22 to S25 until the partial data of the Toeplitz matrix transformation data read into the local memory can no longer be reused. Then, the processing unit 12 reads the next partial data of the Toeplitz matrix transformation data and repeats the same processes. When the calculation of all data is completed, the first half of the inverse transformation process is completed.
[0070] By performing such processing, each partial data of the Toeplitz matrix transformation data only needs to be read from the external memory to the local memory once, thereby reducing the number of accesses to the external memory. Furthermore, similar to the first embodiment, the external memory access from the element product calculation to the first half of the inverse transformation process (steps S23 to S24) can be omitted.
[0071] The latter half of the flowchart of the privacy amplification process of the second embodiment is the same as that of the first embodiment, and therefore the description will be omitted. However, since the intermediate data is generated as many times as the number of divisions of the Toeplitz matrix, the same processing is performed on each of them.
[0072] 11A to 11C are diagrams for explaining the details of the processing in the first half of the flowchart in FIG.
[0073] 11A shows an example in which partial data (divided matrix block A) of Toeplitz matrix transformation data is further divided into A[0] to A[3], each of which is a vector having multiple elements.
[0074] Although the example of FIG. 11A shows the case of the divided matrix block A, the same applies to the cases of the divided matrix blocks B to I.
[0075] 11B shows an example in which partial data (divided input block a) of the input vector conversion data is further divided into a[0] to a[3], each of which is a vector having multiple elements.
[0076] Although the example in FIG. 11B shows the case of divided input block a, the same applies to the cases of divided matrix blocks b to f.
[0077] 11C, first, the processing unit 12 reads A[0] from the external memory into the local memory, then reads a[0] from the external memory into the local memory, and performs an element multiplication operation. Next, the processing unit 12 performs the first half of the inverse transformation process, and writes a part of the intermediate data (temp(A, a)[0]) to the external memory.
[0078] Since the divided matrix block A cannot be reused, the processing unit 12 subsequently reads out a part B[0] of the divided matrix block B and reads out the corresponding a[0]. Then, the processing unit 12 performs an element-by-element multiplication operation between B[0] and a[0] and the first half of an inverse transformation operation of the operation result, and then writes out a part of the intermediate data (temp(B, a)[0]) to the external memory.
[0079] In the next step, since B[0] can be reused, the processing unit 12 reads b[0] corresponding to B[0], and similarly performs element product operation and inverse transformation processing to write a part of the intermediate data (temp(B, b)[0]).
[0080] The processing unit 12 repeats these processes until it has accessed the entire region of the Toeplitz matrix transformation data to obtain intermediate data. This method requires the external memory to have a capacity large enough to store the intermediate data for the number of divisions of the Toeplitz matrix.
[0081] The processing unit 12 then reads the intermediate data stored in the external memory into the local memory, performs the second half of the inverse transformation process on each piece of data, and then performs an exclusive OR operation on the results of the inverse transformation on the corresponding pieces of data. This makes it possible to reduce the amount of data transferred to and from the external memory while taking advantage of the characteristics of the divided Toeplitz matrix.
[0082] In the example of Figures 11A to 11C, the Toeplitz matrix transformation data is read in the order A[0] → B[0] → C[0] → ... → A[1] → B[1] → C[1] → ..., but the same effect can be obtained by reading it in the order A[0] → A[1] → A[2] → ... → B[0] → B[1] → B[2] → ....
[0083] As described above, in the second embodiment, the processing unit 12 divides the input vector transformation data into a plurality of divided input blocks and divides the Toeplitz matrix transformation data into a plurality of divided matrix blocks. Then, the processing unit 12 reads the divided input blocks from the external memory as part of the input vector transformation data into the local memory, and reads the divided matrix blocks as part of the Toeplitz matrix transformation data into the local memory.
[0084] According to the second embodiment, the amount of data transferred to and from the external memory can be reduced by reusing Toeplitz matrix transformation data and omitting external memory access during the element product and inverse transformation process (first half).
[0085] As in the first embodiment, the second embodiment can be applied to the modified Toeplitz matrix of Non-Patent Document 2, thereby further reducing the amount of data transferred to and from an external memory.
[0086] According to the second embodiment, it is possible to reduce the amount of data transferred to and from external memory by approximately 30%. Furthermore, by combining it with the modified Toeplitz matrix of Non-Patent Document 2, it is possible to reduce the amount of data transferred to and from external memory by approximately 50%.
[0087] (Third embodiment) Next, a third embodiment will be described. In the description of the third embodiment, the same description as in the first embodiment will be omitted, and only the differences from the first embodiment will be described.
[0088] In the privacy amplification process of the third embodiment, a hash function other than a Toeplitz matrix is used. In the third embodiment, an example will be described in which a hash calculation method called MMH-MH, which is shown in Non-Patent Document 4, is used. MMH-MH is a hybrid hash function that combines two hash functions, MMH (Multi-linear Modular Hashing) and MH (Modular Arithmetic Hashing).
[0089] Fig. 12 is a diagram for explaining an example of an MMH-MH calculation according to the third embodiment. As shown in Fig. 12, first, the processing unit 12 performs MMH processing. Specifically, the processing unit 12 divides the input vector and random number vector into pieces of size (γ), multiplies the divided input vector and random number vector, and adds the multiplication results in a remainder ring modulo prime number p. Since the size (γ) takes a large value, this multiplication is usually multiple-precision multiplication. Through the MMH processing, the processing unit 12 outputs a hash value y of fixed length γ.
[0090] Thereafter, the processing unit 12 generates the output vector z by calculating variable length data from the fixed length γ data in the calculation of MH.
[0091] To efficiently perform MMH multiple-precision multiplication, FFT / NTT can be used. When N-digit multiple-precision data is expressed in B-ary notation (B is any integer greater than or equal to 2), it can be expressed as a polynomial as shown in the following equation (1).
[0092]
number
[0093] It is known that polynomial multiplication becomes a convolution operation between coefficient vectors when the coefficients are organized as vectors. The convolution operation can be performed using FFT / NTT, reducing the computational complexity to O(N 2 ) to O(N log(N)), making it an efficient computation.
[0094] Fig. 13 is a diagram showing an example of a calculation method for multiple-precision multiplication using NTT according to the third embodiment. When polynomial multiplication according to the third embodiment is calculated using NTT, the calculation method is as shown in Fig. 13. First, the processing unit 12 transforms each coefficient vector into frequency space using NTT and performs element multiplication of each transformed data. The processing unit 12 then performs an inverse transform (INTT) on the calculation result to execute an operation equivalent to the original convolution operation.
[0095] Although FIG. 13 shows the case of NTT, the same applies to the case of FFT.
[0096] To extract more cryptographic key data after privacy amplification (i.e., to improve the cryptographic key generation rate), the data size (γ) must be increased. However, the number of FFT / NTT points increases according to the data size (γ). Therefore, it is not realistic to store all the data required for calculation in local memory.
[0097] For example, in Non-Patent Document 5, γ = 57,885,161, and FFT / NTT must be performed with a number of points greater than this size (67,108,864 in this example, as it must be a power of 2), resulting in a huge amount of data required for FFT / NTT. Therefore, it is practical to store the data required for calculation in external memory and perform processing while reading data of a size that can be loaded into local memory.
[0098] In the third embodiment, as in the first embodiment, element product operations and inverse transformation processing using the operation results are performed without accessing an external memory.
[0099] [Example of Privacy Amplification Processing] Fig. 14A is a first half flowchart showing an example of the privacy amplification processing of the third embodiment, and Fig. 14B is a second half flowchart showing an example of the privacy amplification processing of the third embodiment.
[0100] 14A and 14B show an example of processing when multiple-precision multiplication in MMH processing is calculated using FFT / NTT. As in the first and second embodiments, the inverse transform processing is divided into a first half and a second half.
[0101] First, the processing unit 12 reads partial data representing a part of the input vector conversion data and partial data representing a part of the random number vector conversion data into the local memory (steps S31 and S32). Here, the part of the input vector conversion data is data obtained by converting the input vector divided by size γ using FFT / NTT. Also, the part of the random number vector conversion data is data obtained by converting the random number vector divided by size γ using FFT / NTT.
[0102] The processing in steps S33 to S35 is the same as the processing in steps S3 to S5 in the first embodiment, and therefore a description thereof will be omitted.
[0103] The processing unit 12 repeats steps S31 to S36, and when calculations have been performed on all of the transformation data of size γ (step S36, Yes), in the next step S37, it again partially reads out these intermediate data and performs the second half of the inverse transformation process (steps S38 to S40), thereby completing the element product and inverse transformation process.
[0104] 14A and 14B, in the third embodiment, partial data is used to perform an element product operation, and the result of this operation is then used to perform the first half of the inverse transform process. The result is then written to external memory as intermediate data, thereby reducing the number of external memory accesses from the element product operation (step S33) to the first half of the IFFT / INTT process (step S34).
[0105] In this way, even when using a hash function called MMH-MH, which is different from the Toeplitz matrix, the amount of data transferred to and from external memory can be reduced by omitting external memory access during the element product and inverse transform process (first half).
[0106] Finally, an example of the hardware configuration of the quantum key distribution device 1 according to the first to third embodiments will be described.
[0107] [Example of hardware configuration] 15 is a diagram showing an example of the hardware configuration of the quantum key distribution device 1 according to the first to third embodiments. The quantum key distribution device 1 according to the first to third embodiments includes a control device 301, a main memory device 302, an auxiliary memory device 303, a display device 304, an input device 305, a quantum communication IF (Interface) 306, and a classical communication IF 307.
[0108] The control device 301 , the main memory device 302 , the auxiliary memory device 303 , the display device 304 , the input device 305 , the quantum communication IF 306 and the classical communication IF 307 are connected via a bus 310 .
[0109] The control device 301 (processor) executes a program read from the auxiliary storage device 303 to the main storage device 302. The control device 301 also includes a local memory (for example, a cache memory such as an SRAM).
[0110] The main storage device 302 is an external memory such as a DRAM, etc. The auxiliary storage device 303 is a hard disk drive (HDD), a memory card, etc.
[0111] The display device 304 displays the status of the quantum key distribution device 1, etc. The input device 305 accepts input from a user. The display device 304 and the input device 305 may be realized by a touch panel or the like having a display function and an input function. Furthermore, the display device 304 and the input device 305 do not have to be provided in the quantum key distribution device 1. In this case, for example, the display function and the input function of an external terminal connected to the quantum key distribution device 1 are used.
[0112] The quantum communication IF 306 is an interface for connecting to a quantum cryptography communication channel through which photons are transmitted, and the classical communication IF 307 is an interface for connecting to a transmission channel through which control signals and the like are transmitted.
[0113] The programs executed by the quantum key distribution device 1 of the first to third embodiments are provided as computer program products stored in the form of installable or executable files on computer-readable storage media such as CD-ROMs, memory cards, CD-Rs, and DVDs (Digital Versatile Discs).
[0114] Furthermore, the programs executed by the quantum key distribution devices 1 of the first to third embodiments may be stored on a computer connected to a network such as the Internet, and may be provided by being downloaded via the network.
[0115] Furthermore, the programs executed by the quantum key distribution devices 1 of the first to third embodiments may be configured to be provided via a network such as the Internet without being downloaded.
[0116] Furthermore, the programs executed by the quantum key distribution devices 1 of the first to third embodiments may be provided by being pre-installed in a ROM or the like.
[0117] The programs executed by the quantum key distribution devices 1 of the first to third embodiments have a modular configuration including functions that can be realized by the programs, among the functional configuration of the quantum key distribution device 1. The functions realized by the programs are loaded into the main storage device 302 by the control device 301 reading the programs from a storage medium such as the auxiliary storage device 303 and executing them. In other words, the functions realized by the programs are generated on the main storage device 302.
[0118] Note that some or all of the functions of the quantum key distribution device 1 according to the first to third embodiments may be realized by hardware such as an IC (Integrated Circuit), etc. The IC is, for example, a processor that executes dedicated processing.
[0119] Furthermore, when each function is realized using a plurality of processors, each processor may realize one of the functions, or may realize two or more of the functions.
[0120] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, and are also included in the scope of the invention and its equivalents as defined in the claims. [Explanation of symbols]
[0121] 1 Quantum key distribution device 11 Receiving unit 12 Processing section 13 Sifting processing section 14 EC (Error Correction) processing section 15 PA (Privacy Amplification) processing unit 301 Control device 302 Main storage 303 Auxiliary storage device 304 Display device 305 Input Device 306 Quantum Communication Interface 307 Classical Communication IF 310 Bus
Claims
1. generating input vector conversion data and random number conversion data by performing a conversion process of converting an input vector based on photons received via a quantum cryptography communication channel and random number data based on a hash function into data in a frequency space; storing the input vector transformation data and the random number transformation data in an external memory; reading a portion of the input vector transformation data and a portion of the random number transformation data from the external memory into a local memory; a processing unit that performs an element product operation between a portion of the input vector transformation data and a portion of the random number transformation data, and an inverse transformation process of the calculation result of the element product operation without accessing the external memory, and writes an intermediate result of the inverse transformation process to the external memory; A quantum key distribution device comprising:
2. The transformation process is a fast Fourier transform or a number theoretic transform. The quantum key distribution device according to claim 1 .
3. generating encryption key data from the input vector transformation data and the random number transformation data by repeating an element product operation between a portion of the input vector transformation data and a portion of the random number transformation data and an inverse transformation process of the operation result of the element product operation; The quantum key distribution device according to claim 1 or 2.
4. The inverse transformation process is divided into a first half and a second half, the processing unit writes the intermediate result to the external memory when the first half of the inverse transformation process is completed, and reads the intermediate result from the external memory to the local memory when the second half of the inverse transformation process starts. The quantum key distribution device according to claim 1 or 2.
5. the hash function is a Toeplitz matrix, The random number data is a Toeplitz matrix element vector including some of the elements of the Toeplitz matrix. The quantum key distribution device according to claim 1 or 2.
6. the hash function is a Toeplitz matrix, the processing unit generates a Toeplitz matrix element vector including a part of the elements of the Toeplitz matrix, and generates the random number data by two-dimensionally arranging the Toeplitz matrix element vector. The quantum key distribution device according to claim 1 or 2.
7. the hash function is a Toeplitz matrix, The processing unit Dividing the input vector transformation data into a plurality of divided input blocks, and dividing the random number transformation data into a plurality of divided matrix blocks; reading the divided input block from the external memory into the local memory as part of the input vector transformation data, and reading the divided matrix block into the local memory as part of the random number transformation data; The quantum key distribution device according to claim 1 or 2.
8. The processing unit is realized by a processor, the local memory is a cache memory of the processor; The quantum key distribution device according to claim 1 or 2.
9. a step in which the quantum key distribution device performs a conversion process of converting an input vector based on photons received via a quantum cryptography communication channel and random number data based on a hash function into data in a frequency space, thereby generating input vector conversion data and random number conversion data; the quantum key distribution device storing the input vector transformation data and the random number transformation data in an external memory; a step in which the quantum key distribution device reads a part of the input vector transformation data and a part of the random number transformation data from the external memory into a local memory; the quantum key distribution device performs an element multiplication operation between a portion of the input vector transformation data and a portion of the random number transformation data, and an inverse transformation process of the result of the element multiplication operation, without accessing the external memory, and writes an intermediate result of the inverse transformation process to the external memory; A quantum key distribution method comprising: