Secret data communication system, secret data communication control device, method and program

By selectively encrypting a subset of transmission sections using quantum key distribution, the method addresses the inefficiency in cryptographic key consumption, ensuring secure secret information transmission.

JP2026013462APending Publication Date: 2026-01-29NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024113781
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-17
Publication Date
2026-01-29

AI Technical Summary

Technical Problem

The consumption of cryptographic keys shared by quantum key distribution is excessive when all divided data in a secret sharing scheme are encrypted, leading to inefficiencies in securing secret information transmission.

Method used

A method that selects a subset of transmission sections for encryption using quantum key distribution, ensuring the minimum number of encrypted data segments required to restore the original data, thereby reducing the overall consumption of encryption keys.

Benefits of technology

This approach reduces the consumption of cryptographic keys while maintaining a certain level of security in secret information transmission using a secret sharing scheme.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026013462000001_ABST
    Figure 2026013462000001_ABST
Patent Text Reader

Abstract

To suppress consumption of an encryption key shared by quantum key distribution while securing safety in transmission of secret information by a secret sharing method.SOLUTION: The secret data communication system includes a selection unit configured to select transmission sections of an encryption target number for encrypted communication from among transmission sections of a division number corresponding to each of pieces of divided data obtained by dividing predetermined data by secret sharing processing, and a control unit configured to, for each of a pair of communication devices at both ends of the selected transmission section, and encrypted communication control means for performing communication in which divided data corresponding to the selected transmission section is encrypted, wherein the number of encryption targets is equal to or greater than a minimum number of pieces of divided data for restoration to predetermined data and less than the number of divisions.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a secret data communication system, and a secret data communication control device, method, and program. [Background technology]

[0002] Secret sharing is a technique for transmitting secret information while maintaining its confidentiality. For example, suppose secret information is transmitted from dealer X to dealer Y via multiple participants (share folders). In this case, dealer X on the sending side divides the secret information into n pieces of divided data (n is a natural number greater than or equal to 3) using a (k,n) threshold secret sharing scheme, and sends a different piece of divided data to each of the n participants. Each participant then stores the received divided data. Dealer Y on the receiving side receives the divided data from each participant and restores the secret information from the received multiple divided data.

[0003] In the (k,n) threshold secret sharing scheme, secret information is divided so that the original secret information cannot be restored unless at least k pieces of divided data (k is a natural number greater than or equal to 2 and less than n), which is a threshold value, are used out of n pieces of divided data. Patent Document 1 discloses an example of applying threshold encryption ((k,n) threshold secret sharing scheme) as a secret sharing scheme.

[0004] Quantum cryptography communication has also been attracting attention as a method for encrypting and communicating data. In quantum cryptography communication, a cryptographic key is shared in advance between a transmitting device and a receiving device using quantum key distribution (QKD), and the data is encrypted and communicated using the shared cryptographic key (common key) using a one-time pad (OTP). For example, a common key different for each participant is shared in advance between a transmitting device of dealer X and each of all n receiving devices of each participant using quantum key distribution. Then, between the dealer and each participant, the transmitting device encrypts divided data using a one-time pad using the common key with the specific receiving device and transmits the encrypted data to the receiving device. The receiving device then decrypts the encrypted data received from the transmitting device using the one-time pad using the common key with the transmitting device. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-032521 Summary of the Invention [Problem to be solved by the invention]

[0006] However, when all divided data in a secret sharing scheme are encrypted and communicated using an encryption key (common key) shared by quantum key distribution, a large amount of encryption key is consumed to protect one piece of secret information. This is because the encryption key shared by quantum key distribution is consumed by the one-time pad when encrypting or decrypting each divided data of one piece of secret information.

[0007] In view of the above-mentioned problems, the object of the present disclosure is to provide a secret data communication system, as well as a secret data communication control device, method, and program, that ensure a certain level of security in the transmission of secret information using a secret sharing scheme while suppressing the consumption of a cryptographic key shared by quantum key distribution. [Means for solving the problem]

[0008] The secret data communication system according to the present disclosure comprises: a selection means for selecting a number of transmission sections to be encrypted for encrypted communication from among transmission sections of a number of divisions corresponding to each of the divided data pieces obtained by dividing predetermined data by secret sharing processing; an encrypted communication control means for causing each of a pair of communication devices at both ends of the selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution; Equipped with The number of encryption targets is equal to or greater than the minimum number of divided data items required to restore the predetermined data, and is less than the number of divisions.

[0009] The secret data communication control device according to the present disclosure comprises: a selection means for selecting a number of transmission sections to be encrypted for encrypted communication from among transmission sections of a number of divisions corresponding to each of the divided data pieces obtained by dividing predetermined data by secret sharing processing; an encrypted communication control means for causing each of a pair of communication devices at both ends of the selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution; Equipped with The number of encryption targets is equal to or greater than the minimum number of divided data items required to restore the predetermined data, and is less than the number of divisions.

[0010] The secret data communication control method according to the present disclosure includes: The computer selecting transmission sections, the number of which corresponds to each of the divided data segments obtained by dividing predetermined data through secret sharing processing, as many as the number of transmission sections to be encrypted for the encrypted communication; causing each of a pair of communication devices at both ends of the selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution; The number of encryption targets is equal to or greater than the minimum number of divided data items required to restore the predetermined data, and is less than the number of divisions.

[0011] The secret data communication control program according to the present disclosure is a selection process for selecting a number of transmission sections to be encrypted for encrypted communication from among the transmission sections whose number corresponds to each of the divided data segments obtained by dividing predetermined data through secret sharing processing; an encrypted communication control process for causing each of a pair of communication devices at both ends of the selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution; on the computer, The number of encryption targets is equal to or greater than the minimum number of divided data items required to restore the predetermined data, and is less than the number of divisions. [Effects of the Invention]

[0012] According to the present disclosure, it is possible to reduce consumption of a cryptographic key shared by quantum key distribution while ensuring a certain level of security in the transmission of secret information using a secret sharing scheme. [Brief explanation of the drawings]

[0013] [Figure 1] 1 is a block diagram showing the configuration of a secret data communication system according to the present disclosure. [Figure 2] 1 is a flowchart illustrating the flow of a secret data communication method according to the present disclosure. [Figure 3] 1 is a block diagram showing the overall configuration of a secret data communication system according to the present disclosure. [Figure 4] FIG. 1 is a diagram illustrating the concept of quantum key distribution and key relay according to the present disclosure. [Figure 5] 1 is a diagram for explaining the relationship between a trading device, a distributed management device, and a QKD platform according to the present disclosure. [Figure 6] 1 is a diagram for explaining the relationship between the internal configuration of a transmission line protection unit according to the present disclosure and a QKD platform. [Figure 7] FIG. 2 is a block diagram illustrating a configuration of a key management server according to the present disclosure. [Figure 8] 10 is a flowchart illustrating a flow of a process for selecting an encryption target according to the present disclosure. [Figure 9] FIG. 1 is a diagram illustrating an example of a connection relationship between sites including dealers and participants in a QKDN according to the present disclosure. [Figure 10] FIG. 10 is a diagram illustrating an example of a list of delivery route candidates for the transmission section of a dealer and each participant according to the present disclosure. [Figure 11] FIG. 10 is a diagram illustrating an example of selecting an optimal delivery route for a transmission section of a dealer and each participant according to the present disclosure. [Figure 12] FIG. 10 is a diagram illustrating an example of a transmission section to be encrypted that is selected based on the number of hops according to the present disclosure. [Figure 13] 10 is a flowchart illustrating a processing flow of a transmission path protection unit at a transmitting site according to the present disclosure. [Figure 14] 10 is a flowchart illustrating a processing flow of a transmission path protection unit at a receiving site according to the present disclosure. [Figure 15] 1 is a block diagram showing a hardware configuration of a secret data communication control device according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0014] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In each drawing, the same or corresponding elements are designated by the same reference numerals, and for clarity of explanation, duplicate explanations will be omitted as necessary.

[0015] (Embodiment 1) FIG. 1 is a block diagram showing the configuration of a secret data communication system 1. The secret data communication system 1 includes communication devices 10X, 10Y, 11 to 1N (N is a natural number equal to or greater than 3) and a secret data communication control device 20. The secret data communication system 1 is an information system for communicating predetermined data as secret data between the communication device 10X and the communication device 10Y. Here, the communication device 10X is connected to each of the N communication devices 11, 12, ..., 1N via transmission paths (communication lines). Furthermore, the communication device 10Y is connected to each of the N communication devices 11, 12, ..., 1N via transmission paths. In other words, it can be said that there are N different transmission sections TX1, TX2, ..., TXN between the communication device 10X and each of the communication devices 11 to 1N. For example, both ends of the transmission section TX1 are a pair of the communication device 10X and the communication device 11. Similarly, both ends of the transmission section TX2 are a pair of the communication device 10X and the communication device 12. Furthermore, both ends of the transmission section TXN are a pair of communication devices 10X and 1N. Furthermore, it can be said that there are N different transmission sections T1Y, T2Y, ..., TNY between each of the communication devices 11 to 1N and the communication device 10Y. Note that the transmission paths and communication devices that pass through each transmission section may partially overlap.

[0016] It is also assumed that each of the pair of communication devices at both ends of each transmission section stores in advance an encryption key that has been shared between the pair of communication devices based on quantum key distribution.

[0017] The secret data communication control device 20 is connected to each of the communication devices 10X, 10Y, and 11 to 1N so as to be able to control encrypted communication. The secret data communication control device 20 controls secret data communication in the transmission sections TX1 to TXN between the communication devices 10X and 11 to 1N, and in the transmission sections T1Y to TNY between the communication devices 11 to 1N and 10Y. The secret data communication control device 20 is realized by one or more computer devices. The secret data communication control device 20 includes a selection unit 21 and an encrypted communication control unit 22.

[0018] The selection unit 21 selects a number of transmission sections to be encrypted for encrypted communication from among the number of transmission sections corresponding to each of the divided data segments obtained by dividing the predetermined data using the secret sharing process. Here, the predetermined data may also be called secret information or secret data. The predetermined data is data to be concealed according to the present disclosure. The "secret sharing process" includes, for example, data division using the (k,n) threshold secret sharing scheme described above. Therefore, n is the "number of divisions" and is a natural number greater than or equal to 3. In the following description, n and N are assumed to have the same value. However, N may be equal to or greater than n. Furthermore, k is a threshold and is a natural number greater than or equal to 2 and less than n. In the (k,n) threshold secret sharing scheme, even if less than k divided data segments are intercepted during transmission, the original data cannot be restored. In other words, the predetermined data can be restored to the original data using k or more divided data segments. The "number of encryption targets" is greater than or equal to the minimum number (k) of divided data segments required to restore the original predetermined data, but less than the number (n) of divisions. It is recommended that the "minimum number of data segments required to restore the original data" (k) is greater than half the number of segments (n / 2). This ensures security by encrypting the minimum number k of data segments in the (k,n) threshold secret sharing scheme.

[0019] For example, the communication device 10X divides predetermined data into N pieces of divided data DX1 to DXN using secret sharing processing. Then, the communication device 10X transmits each piece of divided data to N different communication devices 11 to 1N over different transmission intervals TX1 to TXN. For example, the communication device 10X transmits divided data DX1 to the communication device 11 over the transmission interval TX1. Similarly, the communication device 10X transmits divided data DX2 to the communication device 12 over the transmission interval TX2. The communication device 10X also transmits divided data DXN to the communication device 1N over the transmission interval TXN. The communication device 10Y also receives each piece of divided data from the N communication devices 11 to 1N over different transmission intervals T1Y to TNY. For example, the communication device 10Y receives divided data DX1 from the communication device 11 over the transmission interval T1Y. Similarly, the communication device 10X transmits the divided data DX2 to the communication device 12 in the transmission section TX2. Furthermore, the communication device 10X transmits the divided data DXN to the communication device 1N in the transmission section TXN.

[0020] The encrypted communication control unit 22 causes each of a pair of communication devices at both ends of a selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution. For example, when the selection unit 21 selects the transmission section TX1, the encrypted communication control unit 22 causes each of the communication devices 10X and 11 at both ends of the transmission section TX1 to perform communication in which the divided data DX1 corresponding to the transmission section TX1 is encrypted using an encryption key previously shared between the communication devices 10X and 11 based on quantum key distribution. To this end, under the control of the encrypted communication control unit 22, the communication device 10X encrypts the divided data DX1 using the encryption key shared based on quantum key distribution by one-time pad encryption and transmits the encrypted data to the communication device 11. Further, under the control of the encrypted communication control unit 22, the communication device 11 decrypts the data received from the communication device 10X using the encryption key shared based on quantum key distribution by one-time pad encryption to obtain the divided data DX1.

[0021] 2 is a flowchart showing the flow of the secret data communication method. First, the selection unit 21 selects a number of transmission sections to be encrypted for encrypted communication from among the number of transmission sections corresponding to each of the divided data pieces obtained by dividing predetermined data by secret sharing processing (S1). Here, the number of transmission sections to be encrypted is equal to or greater than the minimum number of divided data pieces required to restore the original predetermined data, but is less than the number of divisions.

[0022] Next, the encrypted communication control unit 22 causes each of the pair of communication devices at both ends of the selected transmission section to communicate encrypted divided data corresponding to the selected transmission section using an encryption key shared between the pair of communication devices based on quantum key distribution (S2).

[0023] As described above, this embodiment can at least reduce the number of encryption keys consumed compared to when all (n) pieces of divided data are encrypted with a one-time pad using an encryption key shared based on quantum key distribution and transmitted. This is because the number of divided data to be encrypted is equal to or greater than the minimum number of divided data required to restore the original predetermined data, but is less than the number of divisions. In other words, encrypted communication is performed with a one-time pad using an encryption key shared based on quantum key distribution, not for all transmission sections, but for the number of transmission sections to be encrypted. This makes it possible to reduce the consumption of the encryption key shared through quantum key distribution while ensuring a certain level of security in the transmission of secret information using the secret sharing scheme.

[0024] The secret data communication control device 20 includes a processor, a memory, and a storage device, which are not shown in the figure. The storage device stores a computer program that implements the processing of the secret data communication control method shown in Fig. 2, for example. The processor then loads the computer program from the storage device into the memory and executes the computer program. This allows the processor to implement the functions of the selection unit 21 and the encrypted communication control unit 22.

[0025] Alternatively, each component of the secret data communication control device 20 may be realized by dedicated hardware. Furthermore, some or all of the components of each device may be realized by general-purpose or dedicated circuits, processors, etc., or a combination of these. These may be configured by a single chip, or by multiple chips connected via a bus. Some or all of the components of each device may be realized by a combination of the above-mentioned circuits, etc., and programs. Furthermore, a CPU (Central Processing Unit), GPU (Graphics Processing Unit), FPGA (Field-Programmable Gate Array), quantum processor (quantum computer control chip), etc., may be used as the processor.

[0026] Furthermore, when some or all of the components of the secret data communication control device 20 are realized by a plurality of information processing devices, circuits, etc., the plurality of information processing devices, circuits, etc. may be centrally or decentralized. For example, the information processing devices, circuits, etc. may be realized as a client-server system, a cloud computing system, etc., in which each device is connected via a communication network. Furthermore, the functions of the secret data communication control device 20 may be provided in the form of SaaS (Software as a Service).

[0027] (Embodiment 2) Here, when a pair of communication devices at opposite ends of a certain transmission section share an encryption key based on quantum key distribution, if the distance of the transmission section is equal to or greater than a certain distance, physical constraints may prevent the encryption key from being shared by quantum key distribution alone. Therefore, key relaying is used to share an encryption key based on quantum key distribution between a pair of communication devices over a transmission section that is equal to or greater than a certain distance. Key relaying is a technology that transmits a shared encryption key through encrypted communication, relaying the key through one or more communication devices (relay devices, sites) between the opposite ends of the transmission section. Here, the communication devices and relay devices are called trusted nodes (sites). In key relaying, when transmitting an encryption key between one end of the transmission section and a relay device, or between relay devices, the encryption key itself is transmitted through encrypted communication using a one-time pad (OTP) with the encryption key previously shared between the devices based on quantum key distribution. Therefore, the encryption key shared (between the relay devices) based on quantum key distribution is consumed even by key relaying. The technology disclosed herein can also solve such problems. An example of this technology is described below.

[0028] 3 is a block diagram showing the overall configuration of a secret data communication system 1000. The secret data communication system 1000 is an example of the above-mentioned secret data communication system 1. The secret data communication system 1000 is an information system that uses secret sharing processing and partial quantum cryptography communication when dealer X transmits predetermined data, that is, secret information, to dealer Y via participants A to N. Participants A to N are entities that participate in the (temporary) storage of divided data (shares) in the secret sharing processing.

[0029] The secret data communication system 1000 includes an application layer L1, a key management layer L2, and a QKD (Quantum Key Distribution) layer L3. The key management layer L2 and the QKD layer L3 are included in a QKD platform L0. The application layer L1 includes a trading device 100X on the dealer X side, a trading device 100Y on the dealer Y side, and distributed management devices 101, 102, ..., 10N on the N side of participants A, B, ..., N. The trading devices 100X, 100Y, and distributed management devices 101, 102, ..., 10N are communicatively connected via an application network APN. Here, the application network APN is a wired or wireless communication network, or a wired and wireless communication network. The application network APN may be, for example, the Internet or a dedicated line network.

[0030] The trading device 100X is an information processing device or information processing system used by the dealer X side to trade confidential information. The trading device 100Y is an information processing device or information processing system used by the dealer Y side to trade confidential information. In the following explanation, a case where the dealer X transmits confidential information to the dealer Y will be described. That is, functions related to the secret sharing process of the confidential information from the trading device 100X to 100Y and communication by partial quantum cryptography communication will be described. However, the configurations of the trading devices 100X and 100Y may have equivalent functions.

[0031] Each of the distributed management devices 101 to 10N is an information processing device or information processing system used by each of the participants A to N. The configuration and processing of the distributed management device 101 will be described later. It is assumed that the trading devices 100X and 100Y and the distributed management devices 101 to 10N are installed at physically separate locations.

[0032] The key management layer L2 includes a key management server 200 and key management agents 20X, 20Y, 201, 202, ..., 20N. The key management server 200 and the key management agents 20X, 20Y, 201, 202, ..., 20N are communicatively connected via a key management network KAN. Here, the key management network KAN is a wired or wireless communication network, or a combination of wired and wireless communication networks. The key management network KAN may be, for example, the Internet or a dedicated line network.

[0033] The key management server 200 is an example of the above-mentioned secret data communication control device 20. The key management server 200 is a computer device that manages encryption keys used in quantum cryptography communication. Specifically, the key management server 200 manages quantum key distribution and key relay, manages the amount of (unused) encryption keys generated in the QKD layer L3, and selects a transmission section to be used for transmitting the number of shares to be encrypted out of the N shares in the application layer L1. The key management server 200 may be realized as a computer system with distributed functions or redundancy using multiple computer devices. The configuration of the key management server 200 will be described in detail later.

[0034] Each of the key management agents 20X, 20Y, 201, 202, ..., 20N stores the encryption key generated and quantum key distributed in the QKD layer L3, performs key relay, which is encrypted communication using a different encryption key to share the encryption key for encrypted communication of divided data as needed, and supplies the encryption key for encrypted communication of divided data to the application layer L1. Each of the key management agents 20X, 20Y, 201, 202, ..., 20N is communicatively connected to each of the transaction devices 100X, 100Y and distributed management devices 101, 102, ..., 10N in the application layer L1. Each of the key management agents 20X, etc. is an information processing device or information processing system installed at a physically separate location. Furthermore, the key management agent 20X, etc. may be a software module operating within the corresponding device in the application layer L1. The configuration of the key management agent 20X, etc. will be described in detail later.

[0035] The QKD layer L3 includes QKD devices 30X, 301, 302, 311, 312, 322, ..., 3N1, 3N2, and 30Y. Each of the QKD devices 30X, etc. is communicatively connected to one of the key management agents 20X, etc. of the key management layer L2. For example, QKD device 30X is connected to key management agent 20X, QKD devices 301 and 311 are connected to key management agent 201, and QKD devices 312 and 322 are connected to key management agent 202. Similarly, QKD devices 3N1 and 3N2 are connected to key management agent 20N, and QKD device 30Y is connected to key management agent 20Y. However, QKD devices 30X, etc. are not limited to hardware, and may be realized by software modules and hardware operating in cooperation with each other. Furthermore, the QKD devices 30X, etc. do not necessarily have to be connected one-to-one to the key management agents 20X, etc. In other words, a key management agent may be connected to three or more QKD devices. The QKD devices 30X, etc. have equivalent functions. The QKD devices 30X, etc. generate a true random number of a predetermined length as an encryption key and supply the encryption key to the connected key management agent 20X, etc. Furthermore, adjacent (opposing) QKD devices within the QKD layer L3 are connected by a dedicated optical fiber. Here, the distance between the opposing QKD devices is assumed to be such that the transmission loss of the optical fiber can be tolerated. Then, one opposing QKD device transmits an encryption key, which serves as a common key between the key management agents corresponding to each QKD device, to the other QKD device via optical fiber using quantum cryptography communication. The common key between the key management agents is used in key relay.

[0036] 4 is a diagram for explaining the concept of quantum key distribution and key relay. Here, the key QKD held by the key management agent 2A is A-BThis section explains the case where the QKD device 31A shares the key with the key management agent 2D via two hops on the distribution route in the key relay of the encryption key to be shared based on quantum key distribution. As a premise, QKD devices 31A and 31B are connected by optical fiber as described above. The same applies to the connection between QKD devices 32B and 32C, and between QKD devices 33C and 33D. In other words, due to physical constraints such as transmission loss, it is not possible to directly transmit the key QKD from QKD device 31A to QKD device 31D using quantum key distribution via optical fiber. A-B shall not be transmitted.

[0037] First, either one of the QKD devices 31A or 31B generates a truly random key QKD A-B and transmits the key to the other QKD device via optical fiber quantum cryptography communication. A-B For example, the QKD device 31A transmits the key QKD A-B When the QKD device 31A generates the key QKD A-B The QKD devices 31A and 31B then share key extraction information via a classical channel. This allows the QKD devices 31A and 31B to accurately and securely transmit the key to the QKD device 31B. A-B It is possible to verify whether a single bit of photon has been transmitted. If an eavesdropper intercepts a single bit of photon on the quantum channel, that photon will not reach the receiving QKD device 31B. Furthermore, if an eavesdropper returns the intercepted single bit of photon to the quantum channel, the state of the photon will change quantum mechanically. Therefore, in either case, QKD devices 31A and 31B can detect eavesdropping using key extraction information, etc., discard the key data transmitted and received by both parties, and attempt to generate and share a new key separately. This allows secure encryption keys to be shared between opposing QKD devices connected by optical fiber over a specified distance.

[0038] Then, the QKD device 31A receives a key QKD shared with the QKD device 31B. A-B to the corresponding key management agent 2A (S112).A-B As a common key shared with the key management agent 2B, the QKD device 31B holds the key QKD A-B to the corresponding key management agent 2B (S113). A-B is held as a common key shared with the key management agent 2A.

[0039] Thereafter, a key QKD is transmitted between the QKD devices 32B and 32C in the same manner. B-C Then, the QKD device 32B shares the key QKD B-C The QKD device 32C supplies the key QKD B-C to the corresponding key management agent 2C (S123). B-C The key management agent 2B holds the key QKD as a common key shared with the key management agent 2C. A-B and Key QKD B-C The key management agent 2C holds the key QKD B-C is held as a common key shared with the key management agent 2B.

[0040] Similarly, a key QKD is transmitted between the QKD devices 33C and 33D. C-D Then, the QKD device 33C shares the key QKD C-D The QKD device 33D supplies the key QKD C-D to the corresponding key management agent 2D (S133). C-D The key management agent 2C holds the key QKD as a common key shared with the key management agent 2D. B-C and Key QKD C-D The key management agent 2D holds the shared key as a key QKD. C-D is held as a common key shared with the key management agent 2C.

[0041] Then, the key management agent 2A receives the key QKD A-B The key management agent 2B shares the key QKD, which is a common key with the key management agent 2A, from the key management server 200. A-B In this case, the key management agent 2B may receive an instruction to relay the key to the key management agent 2C. A-B The key management agent 2C and the shared key QKD B-C The key management agent 2B encrypts the data using the one-time pad (S142) and transmits the encrypted data to the key management agent 2C (S142). B-C Then, the key management agent 2C discards the encrypted data received from the key management agent 2B using the key QKD, which is a common key shared with the key management agent 2B. B-C (S143) and decrypt it using the key QKD A-B At this time, the key management agent 2C acquires the key QKD used in the one-time pad. B-C Discard.

[0042] Next, the key management agent 2C receives the key QKD, which is a common key with the key management agent 2A, from the key management server 200. A-B In this case, the key management agent 2C may receive an instruction to relay the key to the key management agent 2D. A-B The key management agent 2D shares the key with the QKD C-D The key management agent 2C encrypts the data using the one-time pad (S144) and transmits the encrypted data to the key management agent 2D (S145). C-D Then, the key management agent 2D discards the encrypted data received from the key management agent 2C using the key QKD, which is a common key shared with the key management agent 2C. C-D (S146) and decrypt it using the key QKD A-BAt this time, the key management agent 2D obtains the key QKD used in the one-time pad. C-D Discard.

[0043] In this way, key QKD is performed between the key management agents 2A and 2D by quantum key distribution and key relay. A-B In this example, the two keys generated by the QKD device can be shared by two hops in the key relay distribution route. B-C and key QKD C-D is consumed.

[0044] FIG. 5 is a diagram for explaining the relationship between the trading devices 100X and 100Y, the distributed management devices 101 to 10N, and the QKD platform L0. The trading device 100X includes at least a division unit 111 and transmission path protection units 121, 122, . . . 12N. The trading device 100Y includes at least transmission path protection units 131, 132, . . . 13N and a restoration unit 141. The distributed management device 101 includes at least transmission path protection units 151 and 161 and a storage unit (not shown) for the share D1. The distributed management device 102 includes at least transmission path protection units 152 and 162 and a storage unit (not shown) for the share D2. Similarly, the distributed management device 10N includes at least transmission path protection units 15N and 16N and a storage unit (not shown) for the share DN. The above-mentioned "division unit," "transmission path protection unit," and "restoration unit" are functional blocks, and may be realized by software modules.

[0045] Here, the transmission path protection unit 121 and the transmission path protection unit 151 are connected by a transmission path P1. Therefore, the trading device 100X including the transmission path protection unit 121 and the distributed management device 101 including the transmission path protection unit 151 can be said to be a pair of communication devices at both ends of the transmission section corresponding to the share D1. Similarly, the transmission path protection unit 161 and the transmission path protection unit 131 are connected by a transmission path T1. Therefore, the distribution management device 101 including the transmission path protection unit 161 and the trading device 100Y including the transmission path protection unit 131 can be said to be a pair of communication devices at both ends of the transmission section corresponding to the share D1.

[0046] Furthermore, the transmission path protection unit 122 and the transmission path protection unit 152 are connected by a transmission path P2. The transmission path protection unit 162 and the transmission path protection unit 132 are connected by a transmission path T2. Therefore, the pair of communication devices at both ends of the transmission section corresponding to share D2 is the pair of the trading device 100X and the distributed management device 102, and also the pair of the distributed management device 102 and the trading device 100Y.

[0047] Similarly, the transmission path protection unit 12N and the transmission path protection unit 15N are connected by a transmission path PN. The transmission path protection unit 16N and the transmission path protection unit 13N are connected by a transmission path TN. Therefore, the pair of communication devices at both ends of the transmission section corresponding to the share DN is the pair of the trading device 100X and the distributed management device 10N, and also the pair of the distributed management device 10N and the trading device 100Y.

[0048] The QKD platform L0 is equivalent to that shown in Fig. 3. Fig. 5 shows an example in which key management agents 20X, 201, 202, 20N, 2YN, 2Y2, 2Y1, and 20Y are connected in series. However, as described above in Fig. 3, each key management agent and key management server 200 are connected to be able to communicate with each other via an application network APN.

[0049] It is assumed that key management agent 20X is supplied with N encryption keys corresponding to encryption of each transmission section from transmission paths P1 to PN from QKD layer L3. Then, key management agent 20X shares encryption key KP1 corresponding to transmission path P1 with key management agent 201 through key relay. Similarly, key management agent 20X shares encryption key KP2 corresponding to transmission path P2 with key management agent 202 through key relay. Furthermore, key management agent 20X shares encryption key KPN corresponding to transmission path PN with key management agent 20N through key relay. In these cases, as described above, encryption keys are consumed according to the number of hops on the key relay delivery route. Then, key management agent 20X supplies encryption key KP1 to transmission path protection unit 121, encryption key KP2 to transmission path protection unit 122, and encryption key KPN to transmission path protection unit 12N. Furthermore, the key management agent 201 supplies the encryption key KP1 to the transmission line protection unit 151. Furthermore, the key management agent 202 supplies the encryption key KP2 to the transmission line protection unit 152. Thereafter, in a similar manner, the key management agent 20N supplies the encryption key KPN to the transmission line protection unit 15N.

[0050] Similarly, it is assumed that the key management agent 20Y is supplied with N encryption keys corresponding to encryption of each transmission section from the transmission paths T1 to TN from the QKD layer L3. The key management agent 20Y then shares the encryption key KT1 corresponding to the transmission path T1 with the key management agent 2Y1 through key relay. Similarly, the key management agent 20Y also shares the encryption key KT2 corresponding to the transmission path T2 with the key management agent 2Y2 through key relay. Furthermore, the key management agent 20Y also shares the encryption key KTN corresponding to the transmission path TN with the key management agent 2YN through key relay. In these cases, as described above, encryption keys are consumed according to the number of hops in the key relay delivery path. The key management agent 20Y then supplies the encryption key KT1 to the transmission path protection unit 131, the encryption key KT2 to the transmission path protection unit 132, and the encryption key KTN to the transmission path protection unit 13N. Furthermore, the key management agent 2Y1 supplies the encryption key KT1 to the transmission line protection unit 161. Furthermore, the key management agent 2Y2 supplies the encryption key KT2 to the transmission line protection unit 162. Thereafter, in a similar manner, the key management agent 2YN supplies the encryption key KTN to the transmission line protection unit 16N.

[0051] Since the distributed management device 101 and the like are provided with transmission path protection units on both the transaction device 100X side and the transaction device 100Y side, the encryption key may be supplied from the same key management agent. For example, the key management agents 201 and 2Y1 may be the same. Similarly, the key management agents 202 and 2Y2, and the key management agents 20N and 2YN may be the same.

[0052] Next, the configurations of the trading devices 100X and 100Y and the distributed management devices 101 to 10N will be described. The dividing unit 111 of the trading device 100X acquires data D to be traded from an external device and divides it into N shares D1, D2, ..., DN using secret sharing processing. If the selection result by the key management server 200 indicates that the data is to be encrypted, the transmission path protection unit 121 encrypts the share D1 using the encryption key KP1 and transmits the encrypted data to the transmission path protection unit 151 via the transmission path P1. If the selection result indicates that the share D1 is not to be encrypted, the transmission path protection unit 121 transmits the share D1 as is to the transmission path protection unit 151 via the transmission path P1. The transmission path protection unit 122 similarly determines whether to use the encryption key KP2 depending on the selection result, and transmits the share D2 or the encrypted data of the share D2 to the transmission path protection unit 152 via the transmission path P2. Similarly, the transmission path protection unit 122 determines whether to use the encryption key KPN depending on the selection result, and transmits the shared DN or encrypted data of the shared DN to the transmission path protection unit 15N via the transmission path PN. In these cases, since the selection result is the target of encrypted communication, an encryption key is used, and each transmission path protection unit consumes, that is, discards, the encryption key that was used.

[0053] Furthermore, the transmission path protection unit 151 of the distributed management device 101 determines whether to use encryption key KP1 for data received from the transmission path protection unit 121 via transmission path P1, depending on whether the selection result by the key management server 200 indicates that the data is subject to encrypted communication. If the data is subject to encrypted communication, the transmission path protection unit 151 decrypts the received data using encryption key KP1 and obtains share D1. Similarly, transmission path protection units 152 to 15N subsequently determine whether to use encryption keys KP2 to KPN depending on the selection result, and if the data is subject to encrypted communication, the corresponding transmission path protection unit decrypts the received data using the encryption key and obtains the DN from share D2.

[0054] Similarly to the transmission path protection units 121 and the like, each of the transmission path protection units 161 to 16N of the distributed management devices 101 to 10N determines whether to use encryption keys KT1 to KTN depending on the selection result. If the encrypted communication is to be performed, the corresponding transmission path protection unit encrypts the shares held therein using the encryption key and transmits the encrypted data to the corresponding transmission path protection unit via the corresponding transmission path. On the other hand, if the encrypted communication is not to be performed, the corresponding transmission path protection unit transmits the shares held therein as is to the corresponding transmission path protection unit via the corresponding transmission path. Similarly to the transmission path protection units 151 and the like, each of the transmission path protection units 131 to 13N of the trading device 100Y determines whether to use encryption keys KT1 to KTN depending on the selection result. If the encrypted communication is to be performed, the corresponding transmission path protection unit decrypts the received data using the encryption key to acquire the shares. On the other hand, if the encrypted communication is not to be performed, the corresponding transmission path protection unit acquires the received data as shares. Thereafter, the restoration unit 141 of the trading device 100Y restores the data D using the shares D1 to DN acquired from the transmission path protection units 131 to 13N. The restoration unit 141 may output the restored data D for subsequent processing.

[0055] FIG. 6 is a diagram illustrating the relationship between the internal configuration of the transmission path protection unit and the QKD platform. The relationship between a transmitting site 41 and a receiving site 42 is also shown. A "site" refers to the same physical location, and each component within the site is implemented by the same computer or multiple securely connected computers, even if they are in different layers. The transmitting site 41 is an example of a site that includes a transmission path protection unit 51 in the application layer L1, a key management agent 221 in the key management layer L2, and a QKD device 31 in the QKD layer L3. The receiving site 42 is an example of a site that includes a transmission path protection unit 52 in the application layer L1, a key management agent 222 in the key management layer L2, and a QKD device 32 in the QKD layer L3. The key relay distribution route between the transmitting site 41 and the receiving site 42 requires the passage of multiple communication devices (sites).

[0056] First, the QKD devices 31, 30, 22, and 32 in the QKD layer L3 in the QKD platform L0 have the same functions as the above-mentioned QKD devices. In this example, the QKD devices 31 and 30 are opposed to each other and connected by a dedicated optical fiber. Furthermore, the QKD device 33 is connected to an opposed QKD device (not shown) by a dedicated optical fiber. Similarly, the QKD device 32 is connected to an opposed QKD device (not shown) by a dedicated optical fiber. It is assumed that the QKD devices 30 and 33 are connected to the same key management unit 2202. Furthermore, the number of QKD devices and their connection relationships are not limited to this.

[0057] The key management layer L2 in the QKD platform L0 comprises a key management server 200, a key management agent 221, and a key management agent 222. The key management unit 2202 is a component within a key management agent (not shown) on the key relay distribution path between the key management agent 221 and the key management agent 222. In other words, the key management unit 2202 does not belong to at least either the sending site 41 or the receiving site 42. However, the key management unit 2202 is supplied with an encryption key shared with the QKD device 31 (key management unit 2212) from the QKD device 30, and similarly, is supplied with an encryption key shared with the opposing QKD device from the QKD device 33, and stores each encryption key in an internal memory unit (not shown). The site to which the key management server 200 belongs is not limited.

[0058] The key management agent 221 of the transmitting site 41 includes a key supply unit 2211 and a key management unit 2212. The key management unit 2212 acquires the encryption key shared with the opposing QKD device 30 from the QKD device 31 and stores it in an internal storage unit (not shown). In response to a key relay instruction from the key management server 200, the key management unit 2212 encrypts the encryption key to be distributed from among the stored encryption keys using a one-time pad with a key shared with the key management unit 2202 of the distribution destination, and transmits the encrypted data to the key management unit 2202. The key management unit 2212 then discards the encryption key used for the one-time pad. The key management unit 2212 then supplies the encryption key to be distributed to the key supply unit 2211.

[0059] The key supply unit 2211 supplies the encryption key supplied from the key management unit 2212 to the transmission path protection unit 51 belonging to the transmitting site 41. Furthermore, when the key supply unit 2211 receives a selection result from the key management server 200, it may transmit the selection result to the transmission path protection unit 51.

[0060] The key management agent 222 of the receiving site 42 includes a key supply unit 2221 and a key management unit 2222. Each component of the key management agent 222 is the same as that of the key management agent 221 described above. The key management unit 2222 acquires the encryption key shared with the opposing QKD device (not shown) from the QKD device 32 and stores it in an internal storage unit (not shown). The key management unit 2222 decrypts encrypted data received from an adjacent key management unit via key relay using the shared key with the opposing QKD device and stores the decrypted data in the storage unit. The key management unit 2222 then discards the encryption key used for the one-time pad. The key management unit 2222 and then the key management unit 2212 supply the encryption key acquired via key relay to the key supply unit 2221. The key supply unit 2221 supplies the encryption key supplied from the key management unit 2222 to the transmission path protection unit 52 belonging to the receiving site 42. Furthermore, when the key provision unit 2221 receives the selection result from the key management server 200 , the key provision unit 2221 may transmit the selection result to the transmission path protection unit 52 .

[0061] The transmission path protection unit 51 of the transmitting site 41 includes an encryption / decryption unit 511, a one-time key storage unit 512, and a one-time key information management unit 513. The one-time key storage unit 512 is a memory area that stores the encryption key supplied from the key supply unit 2211 as a one-time key to be used in the one-time pad. The one-time key information management unit 513 manages the one-time keys stored in the one-time key storage unit 512. Specifically, the one-time key information management unit 513 holds information on the amount of one-time keys stored (e.g., the number of keys). Therefore, when an encryption key supplied from the key supply unit 2211 is stored in the one-time key storage unit 512, the one-time key information management unit 513 adds 1 to the amount of one-time keys stored. On the other hand, when the encryption / decryption unit 511 uses an encryption key that is a one-time key in the one-time pad, the one-time key information management unit 513 deletes the used one-time key from the one-time key storage unit 512 and subtracts 1 from the amount of one-time keys stored. Furthermore, the one-time key information management unit 513 may transmit and receive binding information DC to and from the one-time key information management unit 523 in the transmission path protection unit 52 of the receiving site 42. The binding information DC may be used to synchronize the amount of one-time keys stored between the sending site 41 and the receiving site 42.

[0062] When the encryption / decryption unit 511 acquires the share DK, it acquires the selection result of the target of encrypted communication from the key management server 200, for example, via the key provision unit 2211. Then, the encryption / decryption unit 511 determines whether or not the target of encrypted communication is determined based on the selection result. If the target of encrypted communication is determined to be the one-time key, the encryption / decryption unit 511 acquires a one-time key from the one-time key storage unit 512 and encrypts the share DK with the one-time key to generate share information DK2. Then, the encryption / decryption unit 511 transmits the share information DK2 to the transmission path protection unit 52 via the transmission path to the transmission path protection unit 52. On the other hand, if the target of encrypted communication is not determined to be the one-time key, the encryption / decryption unit 511 transmits the share information DK2 from the share DK as share information DK2 to the transmission path protection unit 52 via the transmission path to the transmission path protection unit 52.

[0063] The transmission path protection unit 52 of the receiving site 42 includes an encryption / decryption unit 521, a one-time key storage unit 522, and a one-time key information management unit 523. The one-time key storage unit 522 and the one-time key information management unit 523 are similar to the one-time key storage unit 512 and the one-time key information management unit 513 described above, and therefore a description thereof will be omitted.

[0064] When the encryption / decryption unit 521 receives the share information DK2 from the transmission path protection unit 51 via the transmission path, it acquires the selection result of the target of encrypted communication from the key management server 200, for example, via the key provision unit 2221. Then, the encryption / decryption unit 521 determines whether or not the target of encrypted communication is selected based on the selection result. If the target of encrypted communication is selected, the encryption / decryption unit 521 acquires a one-time key from the one-time key storage unit 522 and decrypts the share information DK2 with the one-time key to obtain the share DK. At this time, the one-time key information management unit 523 deletes the one-time key used for decryption from the one-time key storage unit 522 and subtracts 1 from the accumulated amount. On the other hand, if the target of encrypted communication is not selected, the encryption / decryption unit 521 sets the share information DK2 as the share DK. Then, the encryption / decryption unit 521 outputs the share DK for subsequent processing.

[0065] A communication device equipped with the transmission path protection unit 51 or 52 determines whether the transmission section, of which the device is one end, is subject to encrypted communication based on the selection result notified from the key management server 200. If the communication device determines that the transmission section is subject to encrypted communication, it performs communication by encrypting the divided data corresponding to the transmission section using an encryption key. In other words, if the communication device determines that the transmission section is subject to encrypted communication, it encrypts and transmits the divided data or decrypts the received data using an encryption key shared between a pair of communication devices in the transmission section based on quantum key distribution. If the communication device determines that the transmission section is not subject to encrypted communication, it performs communication of the divided data corresponding to the transmission section. In other words, if the communication device determines that the transmission section is not subject to encrypted communication, it transmits and receives the divided data without using an encryption key.

[0066] Furthermore, if a transmitting device, which is a communication device on the sending side of a transmission section, determines that the transmission section is subject to encrypted communication, it encrypts the divided data corresponding to the transmission section using an encryption key and transmits the encrypted data to a receiving device, which is a communication device on the receiving side of the transmission section.On the other hand, if the transmitting device determines that the transmission section is not subject to encrypted communication, it transmits the divided data corresponding to the transmission section to the receiving device.Then, if the receiving device determines that the transmission section is subject to encrypted communication, it obtains the divided data by decrypting the data received from the transmitting device using the encryption key.On the other hand, if the receiving device determines that the transmission section is not subject to encrypted communication, it obtains the data received from the transmitting device as divided data.

[0067] 7 is a block diagram showing the configuration of the key management server 200. The key management server 200 includes a storage unit 210, an IF (Interface) unit 220, and a control unit 230. The storage unit 210 includes, for example, a non-volatile storage device such as a flash memory and a memory such as a RAM (Random Access Memory), i.e., a volatile storage device. The storage unit 210 stores a delivery route candidate list 211, an optimum delivery route list 212, and encryption target information 213.

[0068] The delivery route candidate list 211 is a list of delivery route candidates that are candidates for delivery routes in the key relay for a specific transmission section. The delivery route candidate list 211 is a list for each transmission section. The delivery route candidate list 211 includes, for example, a route ID, delivery route candidates that are the order of communication devices (sites) to be passed through in the key relay, the number of hops that are the number of communication devices to be passed through on the delivery route candidate, and a (priority) ranking based on a predetermined criterion of the delivery route candidates within the transmission section. However, the delivery route candidate list 211 is not limited to these.

[0069] The optimum delivery route list 212 is a list of optimum delivery routes selected based on predetermined criteria for each of all transmission sections. The optimum delivery route list 212 includes the route ID, optimum delivery route, and number of hops selected for each transmission section. However, the optimum delivery route list 212 is not limited to these.

[0070] The encryption target information 213 is information indicating transmission sections selected as targets of encrypted communication based on the optimum delivery route list 212. The encryption target information 213 is information equivalent to the selection result of the number of transmission sections to be encrypted. The encryption target information 213 may be expressed as an encryption target flag in the optimum delivery route list 212.

[0071] The IF unit 220 is an interface circuit that communicates between the key management server 200 and the outside world. Specifically, the IF unit 220 communicates with a key management agent and the like via an application network APN.

[0072] The control unit 230 is a control device that controls each component of the key management server 200. The control unit 230 includes a QKDN (QKD Network) management unit 231 and an encryption target selection unit 232. The QKDN management unit 231 and the encryption target selection unit 232 may be used as means for managing and selecting information or data, respectively.

[0073] The QKDN management unit 231 manages the QKD platform L0. In particular, the QKDN management unit 231 manages the amount of encryption keys stored in the key management layer L2, issues instructions for key relay, etc. The QKDN management unit 231 also generates a delivery route candidate list 211 for key relay for each transmission section. The QKDN management unit 231 is an example of the above-mentioned encrypted communication control unit 22. The QKDN management unit 231 notifies each transmission path protection unit of the selection result by the encryption target selection unit 232. Note that the QKDN management unit 231 may notify the selection result at least to the pair of transmission path protection units selected as targets for encrypted communication.

[0074] The encryption target selection unit 232 is an example of the selection unit 21 described above. The encryption target selection unit 232 selects transmission sections to be encrypted in the application layer L1. Specifically, the encryption target selection unit 232 selects p transmission sections to be encrypted based on the key relay distribution route in each of the N divided transmission sections. In this way, by taking the key relay distribution route into consideration, the number of encryption keys consumed can be further reduced.

[0075] Here, the number of encryption objects p is equal to or greater than the minimum number (k) of divided data pieces required to restore the original specified data, and is less than the number of divisions (n), as in the first embodiment. Furthermore, the number of encryption objects p is preferably the minimum number (k) of divided data pieces required to restore the original specified data. However, the number of encryption objects p is greater than half the number of divisions (n / 2). This ensures security while minimizing the consumption of encryption keys in quantum cryptography communications.

[0076] In particular, it is desirable that the encryption target selection unit 232 selects the transmission section of the encryption target number p based on the number of hops in the delivery route. As a result, since an encryption key is consumed by the one-time pad for each hop in the key relay, by taking the number of hops into consideration, the number of encryption keys consumed can be further reduced.

[0077] The encryption target selection unit 232 includes an optimum route selection unit 2321, a transmission section sorting unit 2322, and a target selection unit 2323. The optimum route selection unit 2321, the transmission section sorting unit 2322, and the target selection unit 2323 may be used as means for selecting and sorting information or data, respectively.

[0078] The optimum route selection unit 2321 may select one delivery route as the optimum delivery route based on a predetermined criterion from among a plurality of delivery route candidates in the key relay for each of the divided transmission sections N. Specifically, the optimum route selection unit 2321 selects the optimum delivery route from the delivery route candidate list 211 for each transmission section based on a predetermined criterion.

[0079] Furthermore, the optimal route selection unit 2321 may select the optimal delivery route from among multiple delivery route candidates based on at least one of the following predetermined criteria: the number of encryption keys stored in the communication device, the number of hops in the delivery route candidate, and the communication status between the pair of communication devices.

[0080] The transmission segment sorting unit 2322 sorts the selected delivery routes in ascending order of the number of hops for the division number N. Specifically, the transmission segment sorting unit 2322 sorts the transmission segments in the optimum delivery route list 212 by the number of hops.

[0081] The target selection unit 2323 selects the transmission sections for the number of encryption targets based on the number of hops of the selected delivery route for the division number N. This improves the accuracy of selecting appropriate transmission sections. Specifically, the target selection unit 2323 may select delivery routes corresponding to the order of the number of encryption targets from the highest in the number of hops in ascending order, and select transmission sections corresponding to each of the selected delivery routes for the number of encryption targets p.

[0082] FIG. 8 is a flowchart showing the flow of the encryption target selection process. First, the QKDN management unit 231 of the key management server 200 generates a delivery route candidate list for each transmission section (S201). Here, the connection relationship of sites when generating the delivery route candidate list will be explained. FIG. 9 is a diagram for explaining an example of the connection relationship of each site including dealers and participants in the QKDN. Site 6X corresponds to the base where dealer X's communication device 10X is located. Site 6A corresponds to the base where participant A's distributed management device 101 is located. Site 6B corresponds to the base where participant B's distributed management device 102 is located. Site 6C corresponds to the base where participant C's distributed management device 103 (not shown) is located. Similarly, site 6N corresponds to the base where participant N's distributed management device 10N is located. Furthermore, sites 61 to 69, 610, and 61Z each correspond to the base where a communication device that can be passed through when relaying a key on the quantum key distribution distribution route is located. These sites may hereinafter be referred to as sites 1, 2, . . . 9, 10, and Z. In addition, sites 6X, 6A, 6B, 6C, and 6N can also be bases where communication devices exist that can be used to relay keys along the quantum key distribution route. Figure 9 shows an example of a QKD network, with lines connecting sites that can communicate via key relay.

[0083] Next, the optimal route selection unit 2321 selects an optimal delivery route from the candidate delivery route list 211 for each transmission section (S202). FIG. 10 is a diagram showing an example of a candidate delivery route list for the transmission section of dealer X and each participant. The candidate delivery route list 71 is an example of a candidate delivery route list for the transmission section of dealer X and participant A. The candidate delivery route list 71 lists route IDs RA1 to RA4, etc., which are identification information for the candidate delivery routes. For each route ID, the candidate delivery route list 71 indicates candidate delivery routes indicating the specific order of sites to be passed through, the number of hops for each candidate delivery route, and the priority within the transmission section. The optimal route selection unit 2321 determines the priority of candidate delivery routes based on the above-mentioned predetermined criteria. In other words, the priority of candidate delivery routes is determined taking into account factors other than the number of hops. The candidate delivery route list 71 indicates that the route ID "RA4," which has four hops, has the highest priority.

[0084] Furthermore, delivery route candidate list 72 is an example of a list of delivery route candidates for the transmission section between dealer X and participant B. Delivery route candidate list 72 indicates that route ID "RB3" has the highest priority. Delivery route candidate list 73 is an example of a list of delivery route candidates for the transmission section between dealer X and participant C. Delivery route candidate list 73 indicates that route ID "RC2" has the highest priority.

[0085] Next, the optimum route selection unit 2321 generates an optimum delivery route list 212 for all transmission sections (S203). Specifically, the optimum route selection unit 2321 selects the delivery route with the highest priority from the delivery route candidate list for each transmission section as the optimum delivery route for that transmission section, and generates them as the optimum delivery route list 212. FIG. 11 is a diagram showing an example of selection of optimum delivery routes for the transmission sections of a dealer and each participant. The optimum delivery route list 74 indicates that for the transmission section between dealer X and participant A, route ID "RA4" was selected, and thereafter, one optimum delivery route was selected for each transmission section based on a predetermined criterion.

[0086] Thereafter, the transmission segment sorting unit 2322 sorts all the transmission segments in the optimum delivery route list 212 in ascending order of the number of hops (S204). For example, the transmission segment sorting unit 2322 sorts the transmission segments in the optimum delivery route list 74 in Fig. 11 in ascending order of the number of hops.

[0087] Then, the target selection unit 2323 selects the pth transmission sections from the top of the sorted result as information to be encrypted (S205). FIG. 12 is a diagram showing an example of transmission sections to be encrypted selected based on the number of hops. Specifically, the target selection unit 2323 selects p pieces of route IDs "RB3", "RA4", ..., "RN1" as targets for encrypted communication. For example, the target selection unit 2323 sets the encryption target flag 751 in the sorted result 75 for the selected route ID to "ON". On the other hand, the target selection unit 2323 may set the encryption target flag 751 in the sorted result 75 for route IDs that are not targets for encrypted communication to "OFF".

[0088] Thereafter, the QKDN management unit 231 notifies each transmission line protection unit of the selection result of step S205 (S206).

[0089] 13 is a flowchart showing the flow of processing by the transmission path protection unit 51 at the sending site 41. First, the transmission path protection unit 51 acquires shares (S211). Then, the transmission path protection unit 51 receives a selection result from the key management server 200 (S212). For example, the key management server 200 may execute the encryption target selection process of FIG. 8 and transmit the selection result to the transmission path protection unit 51 in step S206. Note that step S212 may be executed before step S211.

[0090] Next, the encryption / decryption unit 511 determines, based on the received selection result, whether or not the transmission section, of which the device is one end, is subject to encrypted communication (S213). If it is determined that the transmission section is subject to encrypted communication, the encryption / decryption unit 511 acquires one encryption key from the one-time key storage unit 512 (S214). Then, the encryption / decryption unit 511 encrypts the shares (converts them into share information) using the acquired encryption key by the one-time pad method (S215). Then, the encryption / decryption unit 511 transmits the share information to the receiving site 42 via the transmission path (S218). After step S215, the one-time key information management unit 513 deletes the used encryption key from the one-time key storage unit 512 (S216). Then, the one-time key information management unit 513 subtracts 1 from the accumulated amount of one-time pad keys (S217). On the other hand, if it is determined in step S213 that the share is not subject to encrypted communication, the encryption / decryption unit 511 transmits the acquired share as share information to the receiving site 42 via the transmission path (S219).

[0091] 14 is a flowchart showing the processing flow of the transmission path protection unit 52 at the receiving site 42. First, the transmission path protection unit 52 receives share information from the sending site 41 via the transmission path (S231). For example, the transmission path protection unit 52 receives the share information from the transmission path protection unit 51 in accordance with step S219 in FIG. 13. Then, the transmission path protection unit 52 receives a selection result from the key management server 200 (S232). Note that step S232 may be executed before step S231. It is assumed that at least the selection result received in step S232 has the same content as the selection result received in step S212 in FIG. 13 described above.

[0092] Next, the encryption / decryption unit 521 determines whether the transmission section, of which the device is one end, is a target of encrypted communication based on the received selection result (S233). If it is determined that the transmission section is a target of encrypted communication, the encryption / decryption unit 521 acquires one encryption key from the one-time key storage unit 522 (S234). Then, the encryption / decryption unit 521 decrypts (restores) the share information by the one-time pad method using the acquired encryption key (S235). Then, the encryption / decryption unit 521 outputs the decrypted shares to the storage unit (S238). After step S235, the one-time key information management unit 533 deletes the used encryption key from the one-time key storage unit 522 (S236). Then, the one-time key information management unit 533 subtracts 1 from the accumulated amount of one-time pad keys (S237). On the other hand, if it is determined in step S233 that the share information is not subject to encrypted communication, the encryption / decryption unit 521 outputs the received share information to the storage unit as a share (S239).

[0093] As described above, according to this embodiment, instead of encrypting all shares, only the minimum number of shares necessary are encrypted by one-time pad encryption using the encryption key shared based on quantum key distribution, thereby reducing consumption of the encryption key shared based on quantum key distribution. Furthermore, by selecting the number of transmission sections to be encrypted, it is possible to reduce the number of encryption keys consumed by the one-time pad when sharing encryption keys in advance by key relay between a pair of communication devices at both ends of each transmission section. Furthermore, in this embodiment, the amount of encryption key consumed by key relay can be reduced by selecting the transmission sections to be encrypted taking into account the number of hops of the distribution route in key relay. In particular, by narrowing down multiple candidate delivery routes in each transmission section to the optimal delivery route, the accuracy of selecting the transmission section can be further improved.

[0094] (Other embodiments) 15 is a block diagram showing the hardware configuration of the secret data communication control device 2000. The secret data communication control device 2000 corresponds to the above-mentioned secret data communication control device 20 and key management server 200. The secret data communication control device 2000 includes a memory 2001, a processor 2002, and a network interface 2003.

[0095] The memory 2001 is configured by a combination of volatile memory and nonvolatile memory. The volatile memory is, for example, a volatile storage device such as RAM, and is a storage area for temporarily storing information when the processor 2002 is operating. The nonvolatile memory is, for example, a nonvolatile storage device such as a hard disk or flash memory. The memory 2001 stores at least a computer program that implements the processing of the secret data communication control method in the secret data communication control device 2000 according to the present disclosure. Note that the memory 2001 may include storage located away from the processor 2002. In this case, the processor 2002 may access the memory 2001 via an I / O (Input / Output) interface, not shown.

[0096] The processor 2002 is a control device that controls each component of the secret data communication control device 2000. The processor 2002 reads and executes software (computer programs) from the memory 2001. As a result, the processor 2002 realizes the functions of the selection unit 21 and the encrypted communication control unit 22, or the QKDN management unit 231 and the encryption target selection unit 232 (optimal route selection unit 2321, transmission section sorting unit 2322, and target selection unit 2323). In other words, the processor 2002 performs processing of the secret data communication control method in the secret data communication control device 2000 according to the present disclosure. The processor 2002 may be, for example, a microprocessor, an MPU (Multi Processing Unit), or a CPU (Central Processing Unit). The processor 2002 may also include multiple processors.

[0097] The network interface 2003 may be used to communicate with a network node. The network interface 2003 may include, for example, a network interface card (NIC) conforming to the IEEE 802.3 series. IEEE stands for Institute of Electrical and Electronics Engineers. The network interface 2003 may also include a wireless local area network (LAN), a wired LAN, Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.

[0098] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.

[0099] Each drawing is merely an example for describing one or more embodiments. Each drawing may relate not only to one particular embodiment, but also to one or more other embodiments. As will be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings to create, for example, an embodiment not explicitly shown or described. Not all features or steps shown in any one drawing are necessary to describe an exemplary embodiment, and some features or steps may be omitted. The order of steps described in any drawing may be changed as appropriate.

[0100] A part or all of the above-described embodiments can be described as, but not limited to, the following supplementary notes. (Appendix A1) a selection means for selecting a number of transmission sections to be encrypted for encrypted communication from among transmission sections of a number of divisions corresponding to each of the divided data pieces obtained by dividing predetermined data by secret sharing processing; an encrypted communication control means for causing each of a pair of communication devices at both ends of the selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution; Equipped with The number of encryption targets is equal to or greater than the minimum number of divided data items required to restore the predetermined data, and is less than the number of divisions. Secret data communication system. (Appendix A2) The selection means The number of transmission sections to be encrypted is selected based on a distribution route in a key relay of the encryption key to be shared based on the quantum key distribution in each transmission section. A secret data communication system as described in Appendix A1. (Appendix A3) The selection means Selecting the number of transmission sections to be encrypted based on the number of hops in the delivery route. A secret data communication system as described in Appendix A2. (Appendix A4) The selection means Select the delivery route corresponding to the number of hops in ascending order from the highest to the lowest of the number of encryption targets, Selecting transmission sections corresponding to the selected number of delivery routes to be encrypted A secret data communication system as described in Appendix A3. (Appendix A5) The selection means selecting one delivery route from a plurality of candidate delivery routes in the key relay for each of the divided transmission sections based on a predetermined criterion; Selecting the number of transmission sections to be encrypted based on the number of hops of the selected number of divided delivery routes. A secret data communication system as described in Appendix A3 or A4. (Appendix A6) The selection means From the plurality of delivery route candidates, the delivery route is selected for each transmission section using at least one of the number of encryption keys stored in the communication device, the number of hops in the delivery route candidate, and the communication status between the pair of communication devices as the predetermined criterion. A secret data communication system as described in Appendix A5. (Appendix A7) The encrypted communication control means notifying each of the communication devices of a selection result by the selection means; The communication device Based on the notified selection result, it is determined whether the transmission section, of which the device is one end, is a target of the encrypted communication; If it is determined that the encrypted communication is to be performed, the divided data corresponding to the transmission section is encrypted using the encryption key and then communicated. If it is determined that the encrypted communication is not performed, the divided data corresponding to the transmission section is communicated. 10. A secret data communication system according to any one of Appendix A1 to Appendix A6. (Appendix A8) A transmitting device which is the communication device on the transmitting side of the transmission section, If it is determined that the data is to be encrypted, the encrypted data is encrypted using the encryption key for the divided data corresponding to the transmission section, and the encrypted data is transmitted to a receiving device that is the communication device on the receiving side of the transmission section; If it is determined that the encrypted communication is not performed, the divided data corresponding to the transmission section is transmitted to the receiving device; The receiving device If it is determined that the data is to be encrypted, the data is decrypted using the encryption key to obtain the divided data. If it is determined that the data is not a target of the encrypted communication, the data received from the transmitting device is acquired as the divided data. A secret data communication system as described in Appendix A7. (Appendix A9) the minimum number is greater than half of the number of divisions; 10. A secret data communication system according to any one of Appendix A1 to Appendix A8. (Appendix A10) The number of encryption targets is the minimum number of divided data items required to restore the predetermined data. 10. A secret data communication system according to any one of Appendix A1 to Appendix A9. (Appendix A11) The encrypted communication control means controls communication of the divided data corresponding to the selected transmission section, encrypted by a one-time pad using the encryption key shared based on the quantum key distribution. 10. A secret data communication system according to any one of Appendix A1 to Appendix A10. (Appendix B1) a selection means for selecting a number of transmission sections to be encrypted for encrypted communication from among transmission sections of a number of divisions corresponding to each of the divided data pieces obtained by dividing predetermined data by secret sharing processing; an encrypted communication control means for causing each of a pair of communication devices at both ends of the selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution; Equipped with The number of encryption targets is equal to or greater than the minimum number of divided data items required to restore the predetermined data, and is less than the number of divisions. Secret data communication control device. (Appendix C1) The computer selecting transmission sections, the number of which corresponds to each of the divided data segments obtained by dividing predetermined data through secret sharing processing, as many as the number of transmission sections to be encrypted for the encrypted communication; causing each of a pair of communication devices at both ends of the selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution; The number of encryption targets is equal to or greater than the minimum number of divided data items required to restore the predetermined data, and is less than the number of divisions. A method for controlling confidential data communications. (Appendix D1) a selection process for selecting a number of transmission sections to be encrypted for encrypted communication from among the transmission sections whose number corresponds to each of the divided data segments obtained by dividing predetermined data through secret sharing processing; an encrypted communication control process for causing each of a pair of communication devices at both ends of the selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution; on the computer, The number of encryption targets is equal to or greater than the minimum number of divided data items required to restore the predetermined data, and is less than the number of divisions. Secret data communication control program.

[0101] Some or all of the elements (e.g., configurations and functions) described in Appendix A2 to Appendix A11 that are dependent on Appendix A1 {e.g., system} may also be dependent on Appendix B1 {e.g., device}, Appendix C1 {e.g., method}, and Appendix D1 {e.g., program} in the same dependency relationship as Appendix A2 to Appendix A11. Some or all of the elements described in any appendix may be applied to various hardware, software, recording means for recording software, systems, and methods. [Explanation of symbols]

[0102] 1 Secret data communication system, 20 Secret data communication control device, 21 Selection unit, 22 Encrypted communication control unit, 10X, 10Y, 11, 12, 1N Communication device, 1000 Secret data communication system, L1 Application layer, L0 QKD platform, L2 Key management layer, L3 QKD layer, APN Application network, 100X, 100Y Trading device, 101, 102, 10N Distributed management device, X, Y Dealer, A, B, N Participant, KAN Key management network, 200 Key management server, 20X, 20Y, 201, 202, 20N, 2Y1, 2Y2, 2YN Key management agent, 30X, 301, 302, 311, 312, 322, ... 3N1, 3N2, 30Y QKD device, 210 storage unit, 211 delivery route candidate list, 212 optimum delivery route list, 213 encryption target information, 220 IF unit, 230 control unit, 231 QKDN management unit, 232 encryption target selection unit, 2321 optimum route selection unit, 2322 transmission section sorting unit, 2323 target selection unit, D data, D1, D2, DN share, 111 division unit, 121, 122, 12N, 131, 132, 13N transmission path protection unit, 141 restoration unit, 151, 152, 15N, 161, 162, 16N transmission path protection unit, P1, P2, PN, T1, T2, TN transmission path, 41 transmission site, 42 reception site, 51, 52 Transmission path protection unit, 511, 521 Encryption / decryption unit, 512, 522 One-time key storage unit, 513, 523 One-time key information management unit, DK share, DK2 share information, DC linkage information, 221, 222 Key management agent, 2211, 2221 Key supply unit, 2212, 2222, 2202 Key management unit, 31, 30, 32, 33, 31A, 31B, 32B, 32C, 33C, 33D QKD device, 2A, 2B, 2C, 2D Key management agent, QKD A-B , QKD B-C , QKD C-DKey, 61-69, 610, 61Z, 6X, 6A, 6B, 6C, 6N Site, 71-73 Delivery route candidate list, 74 Optimal delivery route list, 75 Sorting result, 751 Encryption target flag, 2000 Secret data communication control device, 2001 Memory, 2002 Processor, 2003 Network interface, TX1, TX2, TXN, T1Y, T2Y, TNY Transmission section

Claims

1. a selection means for selecting a number of transmission sections to be encrypted for encrypted communication from among transmission sections of a number of divisions corresponding to each of the divided data pieces obtained by dividing predetermined data by secret sharing processing; an encrypted communication control means for causing each of a pair of communication devices at both ends of the selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution; Equipped with The number of encryption targets is equal to or greater than the minimum number of divided data items required to restore the predetermined data, and is less than the number of divisions. Secret data communication system.

2. The selection means The number of transmission sections to be encrypted is selected based on a distribution route in a key relay of the encryption key to be shared based on the quantum key distribution in each transmission section.

10. The secure data communication system of claim 1.

3. The selection means Selecting the number of transmission sections to be encrypted based on the number of hops in the delivery route.

3. The secure data communication system of claim 2.

4. The selection means Select the delivery route corresponding to the number of hops in ascending order from the highest to the lowest of the number of encryption targets, Selecting transmission sections corresponding to the selected number of delivery routes to be encrypted 4. A secure data communication system according to claim 3.

5. The selection means selecting one delivery route from a plurality of delivery route candidates in the key relay for each of the divided transmission sections based on a predetermined criterion; Selecting the number of transmission sections to be encrypted based on the number of hops of the selected number of divided delivery routes.

5. A secret data communication system according to claim 3 or 4.

6. The selection means From the plurality of delivery route candidates, the delivery route is selected for each transmission section using at least one of the number of encryption keys stored in the communication device, the number of hops in the delivery route candidate, and the communication status between the pair of communication devices as the predetermined criterion.

6. A secure data communication system according to claim 5.

7. The encrypted communication control means notifying each of the communication devices of a selection result by the selection means; The communication device Based on the notified selection result, it is determined whether the transmission section, of which the device is one end, is a target of the encrypted communication; If it is determined that the encrypted communication is to be performed, the divided data corresponding to the transmission section is encrypted using the encryption key and then communicated. If it is determined that the encrypted communication is not performed, the divided data corresponding to the transmission section is communicated.

3. A secret data communication system according to claim 1 or 2.

8. a selection means for selecting a number of transmission sections to be encrypted for encrypted communication from among transmission sections of a number of divisions corresponding to each of the divided data pieces obtained by dividing predetermined data by secret sharing processing; an encrypted communication control means for causing each of a pair of communication devices at both ends of the selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution; Equipped with The number of encryption targets is equal to or greater than the minimum number of divided data items required to restore the predetermined data, and is less than the number of divisions. Secret data communication control device.

9. The computer selecting transmission sections, the number of which corresponds to each of the divided data segments obtained by dividing predetermined data through secret sharing processing, as many as the number of transmission sections to be encrypted for the encrypted communication; causing each of a pair of communication devices at both ends of the selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution; The number of encryption targets is equal to or greater than the minimum number of divided data items required to restore the predetermined data, and is less than the number of divisions. A method for controlling confidential data communications.

10. a selection process for selecting a number of transmission sections to be encrypted for encrypted communication from among the transmission sections whose number corresponds to each of the divided data segments obtained by dividing predetermined data through secret sharing processing; an encrypted communication control process for causing each of a pair of communication devices at both ends of the selected transmission section to perform communication in which the divided data corresponding to the selected transmission section is encrypted using an encryption key shared between the pair of communication devices based on quantum key distribution; on the computer, The number of encryption targets is equal to or greater than the minimum number of divided data items required to restore the predetermined data, and is less than the number of divisions. Secret data communication control program.

Citation Information

Patent Citations

  • Quantum information distribution verification method, its apparatus, and program

    JP2004032521A