Key management device, key management method, and program
The key management device and method optimize QKD key utilization by updating and reusing expired encryption keys, addressing the inefficiency in conventional systems and conserving resources.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-20
- Publication Date
- 2026-04-02
AI Technical Summary
Conventional technologies have not effectively utilized encryption keys shared using Quantum Key Distribution (QKD) after their expiration, leading to discarding of valuable resources.
A key management device and method that includes a global key generation unit, management unit, and communication unit to generate, manage, and share encryption keys, updating expired keys with new ones while utilizing expired keys for encryption/decryption, thereby conserving local key consumption.
Enhances the effective utilization of expired encryption keys shared via QKD, conserving resources and optimizing key management by reusing expired keys for new communications.
Smart Images

Figure 2026056821000001_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to a key management device, a key management method, and a program.
Background Art
[0002] By using the quantum mechanical properties of light, Quantum Key Distribution (QKD) is conventionally known, which enables sharing of encryption keys between two remote locations without leaking information to any third party (eavesdropper) having any computational power theoretically. The encryption keys shared using QKD are used for encrypted communication between applications, but encryption keys that have elapsed for a certain period of time or more have not been used for encrypted communication and have been deleted from the perspective of security risk.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Non-Patent Documents
[0004]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] Conventional technologies have not been able to utilize more effectively the encryption keys shared using QKD. [Means for solving the problem]
[0006] The key management device of this embodiment comprises a global key generation unit, a management unit, a communication unit, and a provision unit. The global key generation unit generates a first global key used for encrypting or decrypting communications by an application, and stores the first global key, which has been shared with other key management devices by encrypted transfer using QKD (Quantum Key Distribution), in a storage unit. The management unit checks the expiration date of the first global key stored in the storage unit and updates the expired first global key to an expired global key. When the communication unit shares a second global key newly generated by the global key generation unit with the other key management device, it encrypts the second global key using the expired global key and transmits the encrypted second global key to the other key management device. The provision unit provides the second global key to the application. [Brief explanation of the drawing]
[0007] [Figure 1] Figure 1 shows an example of the configuration of a quantum cryptography communication system according to the first embodiment. [Figure 2] Figure 2 is a diagram illustrating an example of the functional configuration of the key management device according to the first embodiment. [Figure 3] Figure 3 shows the state of the key management device with local key sharing enabled in the first embodiment. [Figure 4] Figure 4 is a diagram illustrating an example of the global key sharing process in the first embodiment. [Figure 5] Figure 5 is a diagram illustrating an example of the global key sharing process in the first embodiment. [Figure 6] Figure 6 is a diagram illustrating an example of the global key sharing process in the first embodiment. [Figure 7] Figure 7 is a diagram illustrating an example of the global key sharing process in the first embodiment. [Figure 8]Figure 8 is a flowchart illustrating an example of the sender's process for updating the global key in the embodiment with an expired global key. [Figure 9] Figure 9 shows an example of the data structure of global key sharing information in the first embodiment. [Figure 10] Figure 10 shows an example of the data structure of a global key (for cryptography) according to the first embodiment. [Figure 11] Figure 11 is a flowchart showing an example of the receiving side's process for updating the global key in the first embodiment to an expired global key. [Figure 12] Figure 12 shows an example of the data structure of the global key (for decryption) in the first embodiment. [Figure 13] Figure 13 shows the state of the key management device after the process of updating the global key in the first embodiment with an expired global key has been performed. [Figure 14] Figure 14 is a flowchart showing an example of the sender's processing for global key sharing using an expired global key in the first embodiment. [Figure 15] Figure 15 is a flowchart showing an example of the processing of the global key sharing (sender side) [1] in the first embodiment. [Figure 16] Figure 16 shows an example of the packet configuration of a global key sharing request in the first embodiment. [Figure 17] Figure 17 is a flowchart showing an example of the processing of the global key sharing (sender side) [2] in the first embodiment. [Figure 18] Figure 18 is a flowchart showing an example of the global key sharing (receiving side) process in the first embodiment. [Figure 19] Figure 19 shows the global key sharing process using the expired global key in the first embodiment. [Figure 20] Figure 20 shows the global key sharing process using the expired global key in the first embodiment. [Figure 21] Figure 21 shows the global key sharing process using the expired global key in the first embodiment. [Figure 22]FIG. 22 is a diagram showing an example of the configuration of the quantum key distribution system according to the second embodiment. [Figure 23] FIG. 23 is a diagram showing the state of the key management device after local key sharing in the second embodiment. [Figure 24] FIG. 24 is a diagram for explaining an example of the global key sharing process in the second embodiment. [Figure 25] FIG. 25 is a diagram for explaining an example of the global key sharing process in the second embodiment. [Figure 26] FIG. 26 is a diagram for explaining an example of the global key sharing process in the second embodiment. [Figure 27] FIG. 27 is a diagram for explaining an example of the global key sharing process in the second embodiment. [Figure 28] FIG. 28 is a diagram for explaining an example of the global key sharing process in the second embodiment. [Figure 29] FIG. 29 is a diagram for explaining an example of the global key sharing process in the second embodiment. [Figure 30] FIG. 30 is a flowchart showing an example of the processing on the transmitting side for updating the global key in the second embodiment to an invalidated global key with relays. [Figure 31] FIG. 31 is a flowchart showing an example of the processing on the relay side for updating the global key in the second embodiment to an invalidated global key with relays. [Figure 32] FIG. 32 is a flowchart showing an example of the processing on the receiving side for updating the global key in the second embodiment to an invalidated global key with relays. [Figure 33] FIG. 33 is a diagram showing the state of the key management device after the process of updating the global key in the second embodiment to an invalidated global key with relays. [Figure 34] FIG. 34 is a flowchart showing an example of the processing on the transmitting side for global key sharing (with relays) using the invalidated global key in the second embodiment. [Figure 35] FIG. 35 is a flowchart showing an example of the processing of [3] on the transmitting side for global key sharing (with relays) in the second embodiment. [Figure 36] Figure 36 is a flowchart showing an example of the processing [4] on the transmitting side of global key sharing (with relay) in the second embodiment. [Figure 37] Figure 37 is a flowchart showing an example of the relay side processing in the second embodiment of global key sharing (with relay). [Figure 38] Figure 38 is a flowchart showing an example of the receiving side processing for global key sharing (with relay) in the second embodiment. [Figure 39] Figure 39 shows the global key sharing process (with relay) using the expired global key in the second embodiment. [Figure 40] Figure 40 shows an example of a global key sharing process (with relay) using an expired global key according to the second embodiment. [Figure 41] Figure 41 shows an example of a global key sharing process (with relay) using an expired global key according to the second embodiment. [Figure 42] Figure 42 shows an example of a global key sharing process (with relay) using an expired global key according to the second embodiment. [Figure 43] Figure 43 is a flowchart showing an example of the sender's process for updating the global key of the third embodiment to an expired global key without any intermediary. [Figure 44] Figure 44 is a flowchart showing an example of the receiving side's processing to update the global key of the third embodiment to an expired global key without relaying. [Figure 45] Figure 45 shows the state of the key management device after the process of updating the global key of the third embodiment to an expired global key without an intermediary has been performed. [Figure 46] Figure 46 is a flowchart showing an example of the sender's processing for global key sharing (without relay) using an expired global key in the third embodiment. [Figure 47] Figure 47 is a flowchart showing an example of the processing of the sender [5] in the global key sharing (without relay) of the third embodiment. [Figure 48]Figure 48 is a flowchart showing an example of the receiving side processing for global key sharing (without relay) in the first embodiment. [Figure 49] Figure 49 shows the global key sharing process (without relay) using the expired global key according to the third embodiment. [Figure 50] Figure 50 shows the global key sharing process (without relay) using the expired global key according to the third embodiment. [Figure 51] Figure 51 shows the global key sharing process (without relay) using the expired global key according to the third embodiment. [Figure 52] Figure 52 shows examples of the hardware configuration of the QKD device according to the first to third embodiments. [Figure 53] Figure 53 shows examples of the hardware configuration of the key management device according to the first to third embodiments. [Modes for carrying out the invention]
[0008] The embodiments of the key management device, key management method, and program will be described in detail below with reference to the attached drawings.
[0009] [Example configuration] Figure 1 shows an example of the configuration of the quantum cryptography communication system 100 according to the first embodiment. The quantum cryptography communication system 100 according to the first embodiment comprises key management devices 1a and 1b, applications 2a and 2b, and QKD devices 3a and 3b.
[0010] The key management device 1a of the first embodiment includes a supply unit 11a, a receiving unit 12a, a management unit 13a, a storage unit 14a, a random number generation unit 15a, a global key generation unit 16a, and a communication unit 17a. Similarly, the key management device 1b includes a supply unit 11b, a receiving unit 12b, a management unit 13b, a storage unit 14b, a random number generation unit 15b, a global key generation unit 16b, and a communication unit 17b.
[0011] Figure 1 illustrates the overview of the processing of the quantum cryptography communication system 100 according to the first embodiment. Details of the functions of the key management devices 1a and 1b will be described later with reference to Figure 2.
[0012] QKD devices 3a and 3b share a local key via QKD. The local key is transmitted to the receiving unit 12a of key management device 1a and the receiving unit 12b of key management device 1b, and stored in the storage unit 14a of key management device 1a and the storage unit 14b of key management device 1b, respectively.
[0013] The global key generation unit 16a generates a global key using random numbers generated by the random number generation unit 15a. The global key is transmitted from the communication unit 17a in an encrypted state using the local key. The communication unit 17b decrypts the encrypted global key using the local key.
[0014] The global key shared by key management devices 1a and 1b is used, for example, to encrypt communications in application 2a and to decrypt encrypted communications in application 2b. The global key (encryption key / decryption key) shared between key management devices 1a and 1b is stored in storage units 14a and 14b, respectively.
[0015] Application 2a obtains a global key (for encryption) from the provision unit 11a of the key management device 1a. Application 2a uses the global key (for encryption) to encrypt application data using OTP (One Time Pad) or the like and sends it to application 2b. Application 2b accesses the provision unit 11b of the key management device 1b based on the encryption key information such as the key ID sent along with the encrypted data, and obtains a global key (for decryption). Application 2b uses the global key (for decryption) to decrypt the encrypted application data.
[0016] The key management device 1a, application 2a, and QKD device 3a operate at, for example, site A. In the following description, information, devices, and functional blocks related to site A may be denoted by the symbol A. Similarly, the key management device 1b, application 2b, and QKD device 3b operate at, for example, site B. In the following description, information, devices, and functional blocks related to site B may be denoted by the symbol B.
[0017] Furthermore, when key management devices 1a and 1b are not distinguished, they will simply be referred to as key management device 1. Similarly, when applications 2a and 2b are not distinguished, they will simply be referred to as application 2. Similarly, when QKD devices 3a and 3b are not distinguished, they will simply be referred to as QKD device 3.
[0018] Figure 2 is a diagram illustrating an example of the functional configuration of the key management device 1 of the first embodiment. The key management device 1 of the embodiment comprises a supply unit 11, a receiving unit 12, a management unit 13, a storage unit 14, a random number generation unit 15, a global key generation unit 16, and a communication unit 17.
[0019] The provisioning unit 11, in response to a key acquisition request from application 2, acquires a global key (encryption / decryption) from the storage unit 14 and provides the acquired global key.
[0020] The receiving unit 12 receives the local key shared by QKD between QKD device 3a and QKD device 3b. The receiving unit 12 also communicates with the receiving unit 12 of the opposing key management device 1 via the communication unit 17 to determine the purpose of the local key, and stores the local key in the storage unit 14, divided into encryption and decryption keys.
[0021] The management unit 13 manages the key information of the global key. For example, the management unit 13 checks the expiration date of the global key and updates expired global keys with revoked global keys.
[0022] The memory unit 14 stores global key sharing information, local keys (for encryption / decryption), and global keys (for encryption / decryption). The memory unit 14 is implemented by a combination of a main memory device such as RAM (Random Access Memory) and an auxiliary memory device such as an HDD (Hard Disk Drive).
[0023] The random number generation unit 15 generates random numbers to be used as key data for the global key and provides these random numbers to the global key generation unit 16.
[0024] The global key generation unit 16 generates a global key to be provided to application 2 and shares the global key with other key management devices 1.
[0025] The communication unit 17 is used for communication between key management devices 1. Furthermore, when the communication unit 17 communicates to share a global key between key management devices 1, it encrypts / decrypts the global key using a local key or an expired global key.
[0026] The key management device 1 of the first embodiment is characterized by the processing of the management unit 13 and the communication unit 17.
[0027] Figure 3 shows the state of key management devices 1a and 1b with local keys shared according to the first embodiment. The local keys shared by QKD devices 3a and 3b are stored separately in the storage unit 14a of key management device 1a and the storage unit 14b of key management device 1b, respectively, for encryption α and decryption α.
[0028] Figure 4 is a diagram illustrating an example of the global key sharing process in the first embodiment. First, when the global key generation unit 16 of key management device A1a shares a global key with key management device B1b, it first creates a global key AB (for encryption) 14a2 on the memory (main memory) of key management device A1a.
[0029] Next, the communication unit 17a encrypts the global key AB (for encryption) 14a2 using the local key (for encryption α) 14a1 with OTP or the like. The communication unit 17a then transmits the encrypted global key AB (for encryption) 14a2 as the global key AB (for decryption) 14b2 to the key management device B1b, along with the encryption key information used for encryption (see Figure 10 below).
[0030] Figure 5 is a diagram illustrating an example of the global key sharing process in the first embodiment. Next, the communication unit 17b of the key management device 1b decrypts the global key AB (for decryption) 14b2 using the local key (for decryption α) 14b1 based on the received encryption key information and stores it in the storage unit 14b.
[0031] Figure 6 is a diagram illustrating an example of the global key sharing process in the first embodiment. Next, the communication unit 17b of the key management device 1b transmits information to the key management device 1a indicating that the storage process of the global key AB (for decryption) 14b2 was successful. When the communication unit 17a of the key management device 1a receives the processing result (success) from the key management device B1b, the global key generation unit 16a saves the global key AB (for encryption) 14a2, which was stored in memory, to the database (auxiliary storage device such as an HDD) of the storage unit 14a.
[0032] Figure 7 is a diagram illustrating an example of the global key sharing process in the first embodiment. When the global key AB (for encryption) 14a2 and the global key AB (for decryption) 14b2 are shared between key management device 1a and key management device 1b, the state shown in Figure 7 is reached.
[0033] Figure 8 is a flowchart showing an example of the sending side's processing to update the global key of the embodiment to an expired global key. Figure 8 shows an example of the processing on the key management device 1a side. The management unit 13a of the key management device 1a periodically executes the processing shown in Figure 8.
[0034] First, the management unit 13a of the key management device 1a obtains the lifespan from the global key sharing information stored in the storage unit 14a (step S1).
[0035] Figure 9 shows an example of the data structure of global key sharing information in the first embodiment. As shown in Figure 9, the global key sharing information includes a global key identifier, source IP address, destination IP address, source application identifier, destination application identifier, lifespan, and maximum storage amount.
[0036] The global key identifier is a unique string within the system (referring to the quantum cryptography communication system 100; the same applies hereinafter).
[0037] The source IP address is the source IP address of key management device 1, which shares the global key.
[0038] The destination IP address is the destination IP address of key management device 1, which shares the global key.
[0039] The source application identifier is the identifier (a system-unique string) of local application 2 to which the global key (for encryption) is provided.
[0040] The destination application identifier is the identifier (a system-unique string) of the remote application 2 to which the global key (for decryption) that corresponds to the global key (for encryption) is provided.
[0041] The lifetime indicates the lifetime during which the global key remains valid.
[0042] The maximum storage capacity indicates the maximum storage capacity of global keys.
[0043] Returning to Figure 8, the management unit 13a then retrieves a list of key IDs for global keys corresponding to revoked keys (key generation date and time < current date and time - lifespan) from the database of global keys AB (for encryption) 14a2 stored in the storage unit 14a (step S2).
[0044] If the management unit 13a finds at least one key ID in the list of global key AB (encryption) key IDs that will be revoked, obtained in step S2 (step S3, Yes), it proceeds to step S4. If there is no key ID, it terminates the process (step S3, No).
[0045] The management unit 13a transmits to the key management device 1b, via the communication unit 17a, a list of key IDs for the global key AB (for encryption) that will become invalid, and a request to update the invalid key flag (step S4). The list of key IDs for the global key AB (for encryption) that will become invalid may be included in the request to update the invalid key flag, or it may be transmitted separately from the request to update the invalid key flag.
[0046] Next, the management unit 13a receives a response from the key management device 1b to the request to update the expired key flag via the communication unit 17a (step S5). If the response received in step S5 is successful, the management unit 13a proceeds to step S6; otherwise, it terminates the process.
[0047] The management unit 13a retrieves one key ID from the list of key IDs for the global key AB (for encryption) that will become a revoked key (step S6).
[0048] Next, the management unit 13a searches the database of global keys AB (for encryption) 14a2 stored in the storage unit 14a and updates the revoked key flag of the key information that matches the key ID obtained in step S6 to true (step S7).
[0049] Figure 10 shows an example of the data structure of the global key (for cryptography) 14a2 of the first embodiment. The global key (for cryptography) 14a2 of the first embodiment includes key generation date and time, key ID, key data, key size, source application identifier, destination application identifier, and revocation flag.
[0050] The key generation date and time indicates the date and time the global key was generated.
[0051] The key ID is a system-unique string in the format of a UUID (Universally Unique Identifier).
[0052] The key data is a byte sequence of random numbers encoded in Base64.
[0053] The key size indicates the size of the key data.
[0054] The source application identifier is the identifier (a system-unique string) of the local application to which the global key (for encryption) is provided.
[0055] The destination application identifier is the identifier (a system-unique string) of the remote application to which the global key (for decryption) that corresponds to the global key (for encryption) is provided.
[0056] The revocation flag is a flag used to identify a key as revoked (true: revoked key, false: valid key).
[0057] Returning to Figure 8, in step S8, if the management unit 13a succeeds in updating the expired key flag, it proceeds to step S9; otherwise, it terminates the process.
[0058] The management unit 13a repeats the processes in steps S6 to S8 until there is no more key ID information left in the key ID list for the global key AB (for encryption) that will become a revoked key (step S9, Yes), and terminates the process when there is no more key ID information left (step S9, No).
[0059] Figure 11 is a flowchart showing an example of the receiving side's processing to update the global key to an expired global key in the first embodiment. Figure 11 shows an example of the processing on the key management device 1b side.
[0060] First, the management unit 13b of the key management device 1b receives from the key management device 1a via the communication unit 17b a list of key IDs for the global key AB (for encryption) that will become invalid, and an invalid key flag update request (step S10).
[0061] Next, the management unit 13b retrieves one key ID from the list of key IDs for the global key AB (for encryption) that will become a revoked key (step S11).
[0062] Next, the management unit 13b searches the database of global keys AB (for decryption) 14b2 stored in the storage unit 14b and updates the expired key flag of the key information that matches the key ID obtained in step S11 to true (step S12).
[0063] Figure 12 shows an example of the data structure of the global key (for decryption) 14b2 of the first embodiment. The global key (for decryption) 14b2 of the first embodiment includes key generation date and time, key ID, key data, key size, source application identifier, destination application identifier, and revocation flag.
[0064] The key generation date and time indicates the date and time the global key was generated.
[0065] The key ID is a system-specific string, such as a UUID.
[0066] The key data is a byte sequence of random numbers encoded in Base64.
[0067] The key size indicates the size of the key data.
[0068] The source application identifier is the identifier (a system-unique string) of the remote application to which the global key (for cryptography) is provided.
[0069] The destination application identifier is the identifier (a system-unique string) of the local application to which the global key (for decryption) that corresponds to the global key (for encryption) is provided.
[0070] The revocation flag is a flag used to identify a key as revoked (true: revoked key, false: valid key).
[0071] Returning to Figure 11, in step S13, if the management unit 13b succeeds in updating the expired key flag, it proceeds to step S15. If it fails to update the expired key flag, it returns a failure response to the key management device 1a via the communication unit 17b and terminates the process (step S14).
[0072] The management unit 13b repeats the processes in steps S11 to S14 until there is no more key ID information left in the list of key IDs for the global key AB (for encryption) that will become a revoked key (step S15, Yes). Once there is no more key ID information left (step S15, No), it proceeds to step S16.
[0073] The management unit 13b returns a success response to the key management device 1a via the communication unit 17b and terminates the process (step S16).
[0074] Figure 13 shows the state of key management devices 1a and 1b after the process of updating the global key in the first embodiment with a revoked global key has been performed. In the first embodiment, a new global key sharing is performed using the revoked global key AB (for encryption) 14a3 and the revoked global key AB (for decryption) 14b3.
[0075] Figure 14 is a flowchart showing an example of the sending side processing for global key sharing using an expired global key in the first embodiment. Figure 14 shows an example of processing on the key management device 1a side. The global key generation unit 16a of the key management device 1a periodically executes the processing shown in Figure 14.
[0076] First, the global key generation unit 16a of the key management device 1a obtains the maximum amount of global key AB (for cryptography) stored from the global key sharing information stored in the storage unit 14a (step S17). The data structure of the global key sharing information is as shown in Figure 9 above.
[0077] Next, the global key generation unit 16a obtains the amount of global key AB (for encryption) 14a2 stored in the memory unit 14a (number of global keys stored × key size) (step S18).
[0078] Next, the global key generation unit 16a checks whether the amount of global key AB (for encryption) 14a2 acquired in step S18 is less than the maximum amount of global key AB (for encryption) acquired in step S17. If it is less than the maximum amount (step S19, Yes), the process proceeds to step S20. If it is greater than or equal to the maximum amount (step S19, No), the process ends.
[0079] The global key generation unit 16a obtains the IP address of the key management device 1b that shares global key AB (for decryption) from the global key sharing information stored in the storage unit 14a (step S20). The data structure of the global key sharing information is as shown in Figure 9 above.
[0080] Next, the global key generation unit 16a obtains a random number from the random number generation unit 15a (step S21).
[0081] Next, the global key generation unit 16a generates global key AB (encryption / decryption) data from the random number obtained in step S21 (step S22). The data structure of the global key (encryption / decryption) is as shown in Figures 10 and 12 above.
[0082] Next, the global key generation unit 16a passes the IP address of the key management device 1b and the data of the global key AB (for decryption) 14b2 to the communication unit 17a (step S23).
[0083] Next, the communication unit 17a obtains from the storage unit 14a the amount of revoked global keys AB (for encryption) for which the revoked key flag is true (number of revoked global keys × key size) (step S24).
[0084] Next, in step S25, if the amount of shared global key AB (for decryption) 14b2 (the amount of stored global key AB (for encryption) 14a2 in the key management device 1a) is less than or equal to the amount of stored expired global key AB (for encryption) (step S25, Yes), proceed to [1] (step S26); if it exceeds the stored amount (step S25, No), proceed to [2] (step S27). Details of the process in [1] will be described later using Figure 15, and details of the process in [2] will be described later using Figure 17.
[0085] After processing in step S26 or S27, the communication unit 17a checks the processing result passed to the global key generation unit 16a (step S28). If the processing result is successful, it stores the data of the global key AB (for encryption) 14a2 in the storage unit 14a (step S29). The revoked key flag in the data of the global key AB (for encryption) 14a2 is set to false.
[0086] On the other hand, if the processing result is a failure, the communication unit 17a discards the global key AB (for encryption) 14a2 (step S30).
[0087] Figure 15 is a flowchart showing an example of the processing of [1] for global key sharing (sender side) in the first embodiment. Figure 15 shows an example of the processing on the key management device 1a side.
[0088] The communication unit 17a obtains the expired global key AB (for encryption) 14a3 from the storage unit 14a (step S26-1).
[0089] Next, the communication unit 17a encrypts the global key AB (for decryption) 14b2 using the revoked global key AB (for encryption) 14a3 with OTP or the like (step S26-2).
[0090] Next, the communication unit 17a deletes the expired global key AB (for encryption) 14a3 used for encryption from the storage unit 14a (step S26-3).
[0091] Next, the communication unit 17a sends a global key sharing request to the key management device 1b (step S26-4).
[0092] Figure 16 shows an example of the packet structure of a global key sharing request in the first embodiment. The global key sharing request in the first embodiment includes the encryption key type, destination IP address, encryption key information, and encryption payload.
[0093] The encryption key type indicates the type of encryption key used for encryption. This information helps distinguish whether a local key or a revoked global key was used for encryption.
[0094] The destination IP address is the destination IP address of key management device 1, which shares the global key.
[0095] Cryptographic key information refers to the information of the local key or revoked global key used to encrypt the global key. For example, if a local key was used to encrypt the global key, the cryptographic key information includes the identification information of the local key. Also, if a revoked global key was used to encrypt the global key, the information includes the identification information that identifies the revoked global key (see Figure 10 above).
[0096] The encrypted payload is global key information encrypted with either a local key or a revoked global key.
[0097] Returning to Figure 15, the global key sharing request in step S26-4 includes the following: Cryptographic key type: Expired global key Destination IP address: IP address of key management device 1b Cryptographic key information: Data of the expired global key AB (encryption) used when encrypting global key AB (decryption). Encryption payload: Encrypted global key AB (for decryption) data
[0098] Next, the communication unit 17a checks the response to the global key sharing request from the key management device 1b (step S26-5). If the response is a processing result (success), the communication unit 17a passes the processing result (success) to the global key generation unit 16a (step S26-6), and if the response is a processing result (failure), it passes the processing result (failure) to the global key generation unit 16a (step S26-7).
[0099] Figure 17 is a flowchart showing an example of the processing of the global key sharing (transmitter side) of the first embodiment [2]. Figure 17 shows an example of the processing on the key management device 1a side.
[0100] The communication unit 17a obtains the amount of the local key (for encryption α) 14a1 stored from the storage unit 14a (step S27-1).
[0101] Next, the communication unit 17a checks whether the amount of shared global key AB (for decryption) is less than or equal to the amount of stored local key (for encryption α) 14a1 (step S27-2). If it is less than or equal to the stored amount (step S27-2, Yes), the communication unit 17a obtains local key (for encryption α) 14a1 (step S27-3) and proceeds to step S27-5. On the other hand, if the amount of shared global key AB (for decryption) exceeds the amount of stored local key (for encryption α) 14a1 (step S27-2, No), the communication unit 17a passes the processing result (failure) to the global key generation unit 16a (step S27-4).
[0102] The communication unit 17a encrypts the data of global key AB (for decryption) 14b2 using local key (for encryption α) 14a1 with OTP or the like (step S27-5).
[0103] Next, the communication unit 17a deletes the local key (for encryption α) 14a1 used for encryption from the storage unit 14a (step S27-6).
[0104] Next, the communication unit 17a sends a global key sharing request to the key management device 1b (step S27-7). The packet structure of the global key sharing request is as shown in Figure 16 above.
[0105] The global key sharing request in step S27-7 includes the following: Encryption key type: Local key Destination IP address: IP address of key management device 1b Encryption key information: Data of the local key (for encryption α) used when encrypting the global key AB (for decryption). Encryption payload: Encrypted global key AB (for decryption) data
[0106] Next, the communication unit 17a checks the response to the global key sharing request from the key management device 1b (step S27-8). If the response is a processing result (success), the communication unit 17a passes the processing result (success) to the global key generation unit 16a (step S27-9), and if the response is a processing result (failure), it passes the processing result (failure) to the global key generation unit 16a (step S27-10).
[0107] Figure 18 is a flowchart showing an example of the global key sharing (receiving side) process in the first embodiment. Figure 18 shows an example of the process on the key management device 1b side.
[0108] First, the communications unit 17b receives a global key sharing request from the key management device 1a (step S31).
[0109] Next, the communication unit 17b obtains the destination IP address from the packet received in step S31 (step S32).
[0110] Next, the communication unit 17b confirms that the destination IP address obtained in step S32 matches the IP address of the key management device 1b, and obtains the encryption key type, encryption key information, and encrypted payload from the received packet (step S33).
[0111] Next, the communication unit 17b confirms the type of encryption key obtained in step S33 (step S34).
[0112] If the encryption key type is an expired global key, the communication unit 17b retrieves the expired global key AB (for decryption) 14b3 from the storage unit 14b based on the encryption key information (step S35). The communication unit 17b uses the expired global key AB (for decryption) 14b3 retrieved in step S35 to decrypt the encrypted payload (data of global key AB (for decryption) 14b2) (step S36). The communication unit 17b deletes the expired global key AB (for decryption) 14b3 used for decryption from the storage unit 14b (step S37).
[0113] If the encryption key type is a local key, the communication unit 17b retrieves the local key (for decryption α) 14b1 from the storage unit 14b based on the encryption key information (step S38). The communication unit 17b uses the local key (for decryption α) 14b1 retrieved in step S38 to decrypt the encrypted payload (data of global key AB (for decryption) 14b2) (step S39). The communication unit 17b deletes the local key (for decryption α) 14b1 used for decryption from the storage unit 14b (step S40).
[0114] Next, the communication unit 17b passes the decrypted global key AB (for decryption) 14b2 data to the global key generation unit 16b (step S41).
[0115] The global key generation unit 16b stores the data of the global key AB (for decryption) 14b2 in the storage unit 14b (step S42).
[0116] The global key generation unit 16b checks the data storage result of the global key AB (for decryption) 14b2 (step S43). If successful, the global key generation unit 16b passes the processing result (success) to the communication unit 17b (step S44), and if unsuccessful, passes the processing result (failure) to the communication unit 17b (step S45).
[0117] The communication unit 17b transmits the processing result (success / failure) received from the global key generation unit 16b as a response to the global key sharing request to the key management device 1a (step S46).
[0118] Figure 19 shows the global key sharing process using the expired global key of the first embodiment. Figure 19 shows the state of key management devices 1a and 1b when the processes from steps S17 to S26 in Figure 14 and steps S26-1 to S26-4 in Figure 15 are carried out.
[0119] Figure 20 shows the global key sharing process using the expired global key of the first embodiment. Figure 20 shows the state of the key management devices 1a and 1b when steps S31 to S37 and S41 to S42 of Figure 18 described above are performed.
[0120] Figure 21 is a diagram showing the global key sharing process using the expired global key of the first embodiment. Figure 21 shows the state of key management devices 1a and 1b when the processes described above, from steps S43 to S44 and S46 in Figure 18, from steps S26-5 to S26-6 in Figure 15, and from steps S28 to S29 in Figure 14, are carried out.
[0121] As described above, in the key management device 1a of the first embodiment, the global key generation unit 16a generates a first global key used for encrypting or decrypting communications by application 2a, and stores the first global key, which has been shared with the key management device 1b by encrypted transfer using QKD, in the storage unit 14a. The management unit 13a checks the expiration date of the first global key stored in the storage unit 14a and updates the expired first global key with an expired global key. When the communication unit 17a shares the second global key newly generated by the global key generation unit 16a with the key management device 1b, it encrypts the second global key using the expired global key and transmits the encrypted second global key to the key management device 1b. The provisioning unit 11a provides the second global key to application 2a.
[0122] As a result, according to the first embodiment, encryption keys (global keys in this embodiment) shared using QKD can be utilized more effectively. Global keys, which are transmitted and shared over a QKD network with limited transmission capacity, are valuable resources, but conventionally they were discarded after their expiration date. As explained in the first embodiment, in order to effectively utilize expired global keys that have been inactive for a certain period of time, it is also possible to conserve local key consumption by using expired global keys as encryption / decryption keys when sharing new global keys, instead of using local keys.
[0123] In the first embodiment, OTP was used for encryption during global key sharing, but other encryption methods may be used. For example, AES (Advanced Encryption Standard) may be used for encryption during global key sharing. That is, the communication unit 17a may encrypt the second global key using AES with the revoked global key.
[0124] (Second Embodiment) Next, a second embodiment will be described. In the description of the second embodiment, explanations similar to those of the first embodiment will be omitted, and the differences from the first embodiment will be described. In the second embodiment, a method for performing global key sharing with a destination key management device via an adjacent key management device will be described in a quantum cryptography communication system configuration that further includes relay key management devices.
[0125] [Example configuration] Figure 22 shows an example of the configuration of the quantum cryptography communication system 100-2 of the second embodiment. The quantum cryptography communication system 100-2 of the second embodiment comprises key management devices 1a to 1c, applications 2a and 2c, and QKD devices 3a, 3ab, 3bc and 3c. As with the first embodiment (Figure 1), application 2b may be connected to key management device 1b.
[0126] The global key shared by key management devices 1a and 1c is used, for example, to encrypt communications in application 2a and to decrypt encrypted communications in application 2c. The global key (encryption key / decryption key) shared between key management devices 1a and 1c is stored in storage units 14a and 14c, respectively.
[0127] Application 2a obtains a global key (for encryption) from the provision unit 11a of the key management device 1a. Application 2a encrypts the application data using the global key (for encryption) with OTP or the like and sends it to application 2c. Application 2c accesses the provision unit 11c of the key management device 1c based on the encryption key information such as the key ID sent along with the encrypted data, and obtains a global key (for decryption). Application 2c decrypts the encrypted application data using the global key (for decryption).
[0128] The key management device 1a, application 2a, and QKD device 3a operate at, for example, site A. In the following description, information, devices, and functional blocks related to site A may be denoted by the symbol A. Similarly, the key management device 1b and QKD device 3b operate at, for example, site B. In the following description, information, devices, and functional blocks related to site B may be denoted by the symbol B. Similarly, the key management device 1c, application 2c, and QKD device 3c operate at, for example, site C. In the following description, information, devices, and functional blocks related to site C may be denoted by the symbol C.
[0129] For example, if key management device 1a and QKD device 3a are physically separated from key management device 1c and QKD device 3c, and they cannot share local keys (encryption / decryption), then key management devices 1a and 1c cannot communicate directly to share global keys because they lack the local keys (encryption / decryption) necessary for encrypted communication between them.
[0130] As a solution, a key management device 1b, QKD devices 3ab and 3bc are installed as shown in Figure 22. Local keys (encryption / decryption) are shared between QKD devices 3a and 3ab, and between QKD devices 3bc and 3c. As a result, key management devices 1a and 1c cannot communicate directly to share global keys, but global key sharing becomes possible via key management device 1b.
[0131] Figure 23 shows the state of key management devices 1a to 1c with shared local keys in the second embodiment. Key management device 1b relays the local keys. The local keys shared by QKD devices 3a and 3ab are distinguished into encryption α and decryption α, and are stored in the storage unit 14a of key management device 1a and the storage unit 14b of key management device 1b. Similarly, the local keys shared by QKD devices 3bc and 3c are distinguished into encryption β and decryption β, and are stored in the storage unit 14b of key management device 1b and the storage unit 14c of key management device 1c.
[0132] Figure 24 is a diagram illustrating an example of global key sharing processing in the second embodiment. When key management device 1a performs global key sharing with key management device 1c, a global key AC (for encryption) 14a4 is created in the memory (main memory) of key management device 1a. Next, communication unit 17a encrypts the global key AC (for encryption) 14a4 as the global key AC (for decryption) 14c2 in key management device 1c using local key (for encryption α) 14a1 with OTP or the like. Communication unit 17a transmits the encrypted global key AC (for decryption) 14c2 and the encryption key information used for encryption to key management device 1c.
[0133] However, since key management device 1a is configured not to communicate directly with key management device 1c, communication is routed (relayed) through key management device 1b.
[0134] Figure 25 is a diagram illustrating an example of the global key sharing process in the second embodiment. Next, the communication unit 17b of the key management device 1b decrypts the global key AC (for decryption) 14c2 using the local key (for decryption α) 14b1 based on the encryption key information received from the key management device 1a. Then, the communication unit 17b encrypts the global key AC (for decryption) 14c2 using the local key (for encryption β) 14b4 with OTP or the like.
[0135] Figure 26 is a diagram illustrating an example of the global key sharing process in the second embodiment. Next, the communication unit 17b of the key management device B1b transmits the encrypted global key AC (for decryption) 14c2 and the encryption key information used for encryption to the key management device 1c.
[0136] Figure 27 is a diagram illustrating an example of the global key sharing process in the second embodiment. Next, the communication unit 17c of the key management device 1c decrypts the global key AC (for decryption) 14c2 using the local key (for decryption β) 14c1 based on the encryption key information received from the key management device 1b. The communication unit 17c stores the decrypted global key AC (for decryption) 14c2 in the storage unit 14c.
[0137] Figure 28 is a diagram illustrating an example of the global key sharing process in the second embodiment. Next, the communication unit 17c of the key management device 1c transmits to the key management device 1a via the key management device 1b that the saving process of the global key AC (for decryption) 14c2 was successful. Upon receiving the processing result (success) from the key management device 1c, the key management device 1a saves the global key AC (for encryption) 14a4, which was stored in memory, to the database (auxiliary storage device such as an HDD) of the storage unit 14a.
[0138] Figure 29 is a diagram illustrating an example of the global key sharing process in the second embodiment. When the global key AC (for encryption) 14a4 and the global key AC (for decryption) 14c2 are shared between key management device 1a and key management device 1c, the state shown in Figure 29 is reached.
[0139] As shown in Figures 24 to 29, when a local key is used for encrypted communication in global key sharing, it is always necessary to relay it to the key management device 1c at the destination site via the adjacent key management device 1b.
[0140] However, in a global key sharing scheme using an expired global key, it is not necessary to go through the adjacent key management device 1b, and communication can be made directly with the key management device 1c at destination site C.
[0141] First, regarding the global key sharing method using expired global keys, a method of sharing global keys with the key management device at the destination site via an adjacent key management device will be described as the second embodiment. A method of directly sharing global keys with the key management device at the destination site will be described in the third embodiment below.
[0142] Figure 30 is a flowchart showing an example of the sending side's processing to update the global key of the second embodiment to an expired global key with an intermediary. Figure 30 shows an example of processing on the key management device 1a side. The management unit 13a of the key management device 1a periodically executes the processing shown in Figure 30.
[0143] First, the management unit 13a of the key management device 1a obtains the lifespan from the global key sharing information stored in the storage unit 14a (step S47). The data structure of the global key sharing information is as shown in Figure 9 above.
[0144] Next, the management unit 13a retrieves a list of key IDs for global keys corresponding to revoked keys (key generation date and time < current date and time - lifespan) from the database of global keys AC (for cryptography) 14a4 stored in the storage unit 14a (step S48).
[0145] If the management unit 13a finds one or more key IDs in the list of global key AC (encryption) key IDs that will be revoked, obtained in step S48 (step S49, Yes), it proceeds to step S50. If there are no or fewer key IDs (step S49, No), it terminates the process.
[0146] The management unit 13a transmits to the key management device 1c, via the communication unit 17a, a list of key IDs for the global key AC (for encryption) that will become invalid, and a request to update the invalid key flag (step S50). Since the key management devices 1a and 1c cannot communicate directly, they transmit the list of key IDs for the global key AC (for encryption) that will become invalid and the request to update the invalid key flag via the key management device 1b (as an intermediary).
[0147] Next, the management unit 13a receives a response from the key management device 1c to the request to update the expired key flag via the communication unit 17a (step S51). Note that since the key management devices 1a and 1c cannot communicate directly, the response is received via the key management device 1b.
[0148] If the response received in step S51 is successful, the management unit 13a proceeds to step S52; otherwise, it terminates the process.
[0149] The management unit 13a retrieves one key ID from the list of key IDs for the global key AC (for encryption) that will become a revoked key (step S52).
[0150] Next, the management unit 13a searches the database of global keys AC (for encryption) 14a4 stored in the storage unit 14a and updates the revoked key flag of the key information that matches the key ID obtained in step S52 to true (step S53). The data structure of the global key (for encryption) is as shown in Figure 10 above.
[0151] In step S54, if the management unit 13a succeeds in updating the expired key flag, it proceeds to step S55; otherwise, it terminates the process.
[0152] The management unit 13a repeats the process in steps S52 to S54 until there is no more key ID information left in the key ID list of the global key AC (for encryption) that will become a revoked key (step S55, Yes). Once there is no more key ID information left (step S55, No), the process terminates.
[0153] Figure 31 is a flowchart showing an example of the relay-side processing for updating the global key of the second embodiment to an expired global key with the help of an intermediary. Figure 31 shows an example of the processing on the key management device 1b side.
[0154] The communication unit 17b of the key management device 1b transmits the key ID list information of the global key AC (for encryption) that will become a revoked key, along with the revoked key flag update request, received from the key management device 1a, to the key management device 1c as is (step S56).
[0155] The communication unit 17b of the key management device 1b transmits the response to the expired key flag update request received from the key management device 1c to the key management device 1a as is (step S57).
[0156] Figure 32 is a flowchart showing an example of the receiving side's processing to update the global key of the second embodiment to an expired global key with an intermediary. Figure 32 shows an example of the processing on the key management device 1c side.
[0157] First, the management unit 13c of the key management device 1c receives from the key management device 1b via the communication unit 17c a list of key IDs of the global key AC (for encryption) that will become a revoked key, and a request to update the revoked key flag (step S58).
[0158] Next, the management unit 13c retrieves one key ID from the list of key IDs for the global key AC (for encryption) that will become a revoked key (step S59).
[0159] Next, the management unit 13c searches the database of global keys AC (for decryption) 14c2 stored in the storage unit 14c and updates the expired key flag of the key information that matches the key ID obtained in step S59 to true (step S60). The data structure of the global key (for decryption) is as shown in Figure 12 above.
[0160] In step S61, if the management unit 13c successfully updates the expired key flag, it proceeds to step S63. If it fails to update the expired key flag, it returns a failure response to the key management device 1a via the communication unit 17c and terminates the process (step S62). Since the key management devices 1c and 1a cannot communicate directly, the response is sent via the key management device 1b.
[0161] The management unit 13c repeats the process in steps S59 to S61 until there is no more key ID information left in the list of key IDs for the global key AC (for encryption) that will become a revoked key (step S63, Yes). Once there is no more key ID information left (step S63, No), it proceeds to step S64.
[0162] The management unit 13c returns a success response to the key management device 1a via the communication unit 17c and terminates the process (step S64). Note that since the key management devices 1c and 1a cannot communicate directly, the response is sent via the key management device 1b.
[0163] Figure 33 shows the state of key management devices 1a and 1c after the process of updating the global key of the second embodiment with an expired global key via an intermediary has been performed. In the second embodiment, a new global key sharing is performed using this expired global key AC (for encryption) 14a5 and expired global key AC (for decryption) 14c3.
[0164] Figure 34 is a flowchart showing an example of the sending side processing for global key sharing (with relay) using an expired global key in the second embodiment. Figure 34 shows an example of processing on the key management device 1a side. The global key generation unit 16a of the key management device 1a periodically executes the processing shown in Figure 34.
[0165] First, the global key generation unit 16a of the key management device 1a obtains the maximum amount of global key AC (for cryptography) 14a4 stored from the global key sharing information stored in the storage unit 14a (step S65). The data structure of the global key sharing information is as shown in Figure 9 above.
[0166] Next, the global key generation unit 16a obtains the amount of global keys AC (for cryptography) 14a4 stored in the memory unit 14a (number of global keys stored × key size) (step S66).
[0167] Next, the global key generation unit 16a checks whether the amount of global key AC (for encryption) 14a4 acquired in step S66 is less than the maximum amount of global key AC (for encryption) 14a4 acquired in step S65. If it is less than the maximum amount (step S67, Yes), the process proceeds to step S68. If it is greater than or equal to the maximum amount (step S67, No), the process terminates.
[0168] The global key generation unit 16a obtains the IP address of the key management device 1c that shares the global key AC (for decryption) from the global key sharing information stored in the storage unit 14a (step S68). The data structure of the global key sharing information is as shown in Figure 9 above.
[0169] Next, the global key generation unit 16a obtains a random number from the random number generation unit 15a (step S69).
[0170] Next, the global key generation unit 16a generates global key AC (encryption / decryption) data from the random number obtained in step S70 (step S70). The data structure of the global key (encryption / decryption) is as shown in Figures 10 and 12 above.
[0171] Next, the global key generation unit 16a passes the IP address of the key management device 1c and the data of the global key AC (for decryption) 14c2 to the communication unit 17a (step S71).
[0172] Next, the communication unit 17a obtains from the storage unit 14a the amount of expired global keys AC (for cryptography) for which the expired key flag is true (number of expired global keys × key size) (step S72).
[0173] Next, in step S73, if the amount of shared global key AC (for decryption) 14c2 (the amount of stored global key AC (for encryption) 14a4 in the key management device 1a) is less than or equal to the amount of stored expired global key AC (for encryption) (step S73, Yes), proceed to [3] (step S74); if it exceeds the stored amount (step S73, No), proceed to [4] (step S75). Details of the process in [3] will be described later using Figure 35, and details of the process in [4] will be described later using Figure 36.
[0174] After processing in step S74 or S75, the communication unit 17a checks the processing result passed to the global key generation unit 16a (step S76). If the processing result is successful, it stores the data of the global key AC (for encryption) 14a4 in the storage unit 14a (step S77). The revoked key flag in the data of the global key AC (for encryption) 14a4 is set to false.
[0175] On the other hand, if the processing result is a failure, the communication unit 17a discards the global key AC (for encryption) 14a4 (step S78).
[0176] Figure 35 is a flowchart showing an example of the processing on the transmitting side [3] of the global key sharing (with relay) in the second embodiment. Figure 35 shows an example of the processing on the key management device 1a side.
[0177] The communication unit 17a obtains the expired global key AC (for encryption) 14a5 from the storage unit 14a (step S74-1).
[0178] Next, the communication unit 17a encrypts the global key AC (for decryption) 14c2 using the revoked global key AC (for encryption) 14a5 with OTP or the like (step S74-2).
[0179] Next, the communication unit 17a deletes the expired global key AC (for encryption) 14a5 used for encryption from the storage unit 14a (step S74-3).
[0180] Next, the communication unit 17a sends a global key sharing request to the key management device 1b, which is the forwarding destination for the destination IP address (key management device 1c), based on the routing information (step S74-4). The packet structure of the global key sharing request is as shown in Figure 16 above.
[0181] The global key sharing request in step S74-4 includes the following: Cryptographic key type: Expired global key Destination IP address: IP address of key management device 1c Encryption key information: Data of the expired global key AC (encryption) used when encrypting the global key AC (decryption). Encryption payload: Encrypted global key AC (for decryption) data
[0182] Next, the communication unit 17a checks the response to the global key sharing request from the key management device 1b (step S74-5). If the response is a processing result (success), the communication unit 17a passes the processing result (success) to the global key generation unit 16a (step S74-6), and if the response is a processing result (failure), it passes the processing result (failure) to the global key generation unit 16a (step S74-7).
[0183] Figure 36 is a flowchart showing an example of the processing on the transmitting side [4] of the global key sharing (with relay) in the second embodiment. Figure 36 shows an example of the processing on the key management device 1a side.
[0184] The communication unit 17a obtains the amount of local key (for encryption α) 14a1 stored from the storage unit 14a (step S75-1).
[0185] Next, the communication unit 17a checks whether the amount of shared global key AC (for decryption) is less than or equal to the amount of stored local key (for encryption α) 14a1 (step S75-2). If it is less than or equal to the stored amount (step S75-2, Yes), the communication unit 17a obtains local key (for encryption α) 14a1 (step S75-3) and proceeds to step S75-5. On the other hand, if the amount of shared global key AC (for decryption) exceeds the amount of stored local key (for encryption α) 14a1 (step S75-2, No), the communication unit 17a passes the processing result (failure) to the global key generation unit 16a (step S75-4).
[0186] The communication unit 17a encrypts the data of the global key AC (for decryption) 14c2 using the local key (for encryption α) 14a1 with OTP or the like (step S75-5).
[0187] Next, the communication unit 17a deletes the local key (for encryption α) 14a1 used for encryption from the storage unit 14a (step S75-6).
[0188] Next, the communication unit 17a sends a global key sharing request to the key management device 1b, which is the forwarding destination for the destination IP address (key management device 1c), based on the routing information (step S75-7). The packet structure of the global key sharing request is as shown in Figure 16 above.
[0189] The global key sharing request in step S75-7 includes the following: Encryption key type: Local key Destination IP address: IP address of key management device 1c Encryption key information: Data of the local key (for encryption α) used when encrypting the global key AC (for decryption). Encryption payload: Encrypted global key AC (for decryption) data
[0190] Next, the communication unit 17a checks the response to the global key sharing request from the key management device 1b (step S75-8). If the response is a processing result (success), the communication unit 17a passes the processing result (success) to the global key generation unit 16a (step S75-9), and if the response is a processing result (failure), it passes the processing result (failure) to the global key generation unit 16a (step S75-10).
[0191] Figure 37 is a flowchart showing an example of processing on the relay side of global key sharing (with relay) in the second embodiment. Figure 37 shows an example of processing on the key management device 1b side.
[0192] First, the communications unit 17b receives a global key sharing request from the key management device 1a (step S79).
[0193] Next, the communication unit 17b obtains the destination IP address from the packet received in step S79 (step S80).
[0194] Next, the communication unit 17b confirms that the destination IP address obtained in step S80 does not match the IP address of the key management device 1b, and obtains the encryption key type, encryption key information, and encrypted payload from the received packet (step S81).
[0195] Next, the communication unit 17b confirms the type of encryption key obtained in step S81 (step S82).
[0196] If the encryption key type is an expired global key, the communication unit 17b transmits the global key sharing request received from the key management device 1a to the key management device 1c as is (step S83). The packet structure of the global key sharing request is as shown in Figure 16 above.
[0197] If the encryption key type is a local key, the communication unit 17b retrieves the local key (for decryption α) 14b1 from the storage unit 14b based on the encryption key information (step S84). The communication unit 17b uses the local key (for decryption α) 14b1 retrieved in step S84 to decrypt the encrypted payload (data of the global key AC (for decryption) 14c2) (step S85). The communication unit 17b deletes the local key (for decryption α) 14b1 used for decryption from the storage unit 14b (step S86).
[0198] Next, the communication unit 17b obtains the local key (for encryption β) 14b4 from the storage unit 14b (step S87).
[0199] Next, the communication unit 17b encrypts the data of the global key AC (for decryption) 14c2, which was decrypted in step S85, using the local key (for encryption β) 14b4 with OTP or the like (step S88).
[0200] Next, the communication unit 17b deletes the local key (for encryption β) 14b4 used for encryption from the storage unit 14b (step S89).
[0201] Next, the communication unit 17b sends a global key sharing request to the key management device 1c (step S90). The packet structure of the global key sharing request is as shown in Figure 16 above.
[0202] Next, the communication unit 17b checks the response to the global key sharing request from the key management device 1c (step S91). If the response is a processing result (success), the communication unit 17b sends the processing result (success) to the key management device 1a as a response to the global key sharing request (step S92). If the response is a processing result (failure), the communication unit 17b sends the processing result (failure) to the key management device 1a as a response to the global key sharing request (step S93).
[0203] Figure 38 is a flowchart showing an example of the receiving side processing for global key sharing (with relay) in the second embodiment. Figure 38 shows an example of the processing on the key management device 1c side.
[0204] First, the communication unit 17c receives a global key sharing request from the key management device 1b (step S94).
[0205] Next, the communication unit 17c obtains the destination IP address from the packet received in step S94 (step S95).
[0206] Next, the communication unit 17c confirms that the destination IP address obtained in step S95 matches the IP address of the key management device 1c, and obtains the encryption key type, encryption key information, and encrypted payload from the received packet (step S96).
[0207] Next, the communication unit 17c confirms the type of encryption key obtained in step S96 (step S97).
[0208] If the encryption key type is an expired global key, the communication unit 17c obtains the expired global key AC (for decryption) 14c3 from the storage unit 14c based on the encryption key information (step S98). The communication unit 17c uses the expired global key AC (for decryption) 14c3 obtained in step S98 to decrypt the encrypted payload (data of global key AC (for decryption) 14c2) (step S99). The communication unit 17c deletes the expired global key AC (for decryption) 14c3 used for decryption from the storage unit 14c (step S100).
[0209] If the encryption key type is a local key, the communication unit 17c obtains the local key (for decryption β) 14c1 from the storage unit 14c based on the encryption key information (step S101). The communication unit 17c uses the local key (for decryption β) 14c1 obtained in step S101 to decrypt the encrypted payload (data of the global key AC (for decryption) 14c2) (step S102). The communication unit 17c deletes the local key (for decryption β) 14c1 used for decryption from the storage unit 14c (step S103).
[0210] Next, the communication unit 17c passes the decrypted global key AC (for decryption) 14c2 data to the global key generation unit 16c (step S104).
[0211] The global key generation unit 16c stores the data of the global key AC (for decryption) 14c2 in the storage unit 14c (step S105).
[0212] The global key generation unit 16c checks the data storage result of the global key AC (for decryption) 14c2 (step S106). If successful, the global key generation unit 16c passes the processing result (success) to the communication unit 17c (step S107), and if unsuccessful, passes the processing result (failure) to the communication unit 17c (step S108).
[0213] The communication unit 17c transmits the processing result (success / failure) received from the global key generation unit 16c as a response to the global key sharing request to the key management device 1b (step S109).
[0214] Figure 39 shows the global key sharing process (with relay) using the expired global key of the second embodiment. Figure 39 shows the state of the key management devices 1a to 1c when the processes from steps S65 to S74 in Figure 34 and S74-1 to S74-4 in Figure 35 are performed.
[0215] Figure 40 shows an example of global key sharing processing (with relay) using an expired global key according to the second embodiment. Figure 40 shows the state of key management devices 1a to 1c when the processing from steps S79 to S73 of Figure 37 described above is performed.
[0216] Figure 41 shows an example of a global key sharing process (with relay) using an expired global key according to the second embodiment. Figure 41 shows the state of key management devices 1a to 1c when steps S94 to S100 and S104 to S105 of Figure 38 described above are performed.
[0217] Figure 42 shows an example of a global key sharing process (with relay) using an expired global key according to the second embodiment. Figure 42 shows the state of key management devices 1a to 1c when the processes described above, from steps S106 to S107 and S109 in Figure 38, steps S91 to S92 in Figure 37, steps S74-5 to S74-6 in Figure 35, and steps S76 to S77 in Figure 34, are carried out.
[0218] (Third embodiment) Next, a third embodiment will be described. In the description of the third embodiment, explanations similar to those of the second embodiment will be omitted, and the differences from the second embodiment will be explained. In the third embodiment, a method for performing global key sharing with the key management device of a direct destination location will be described in a quantum cryptography communication system configuration that further includes a relay key management device (the same configuration as the second embodiment in Figure 22 above).
[0219] Figure 43 is a flowchart showing an example of the sending side's processing to update the global key of the third embodiment to an expired global key without relaying. Figure 43 shows an example of processing on the key management device 1a side. The management unit 13a of the key management device 1a periodically executes the processing shown in Figure 43.
[0220] Steps S110 to S112 are the same as steps S47 to S49 (Figure 30) of the second embodiment described above, so their explanation will be omitted.
[0221] The management unit 13a transmits to the key management device 1c, via the communication unit 17a, a list of key IDs for the global key AC (for encryption) that will become invalid, and a request to update the invalid key flag (step S113). In the third embodiment, the key management device 1a transmits the list of key IDs for the global key AC (for encryption) that will become invalid, and the request to update the invalid key flag directly to the key management device 1c, without going through (relaying) the key management device 1b.
[0222] Next, the management unit 13a receives a response from the key management device 1c to the expired key flag update request via the communication unit 17a (step S114). In the third embodiment, the key management device 1a receives the response from the key management device 1c to the expired key flag update request directly, without going through (relaying) the key management device 1b.
[0223] Steps S115 to S118 are the same as steps S52 to S55 (Figure 30) of the second embodiment described above, so their explanation will be omitted.
[0224] Figure 44 is a flowchart showing an example of the receiving side's processing to update the global key of the third embodiment to an expired global key without relaying. Figure 44 shows an example of the processing on the key management device 1c side.
[0225] Steps S119 to S122 are the same as steps S58 to S61 (Figure 32) of the second embodiment described above, so their explanation will be omitted.
[0226] If the management unit 13c fails to update the expired key flag, it returns a failure response to the key management device 1a via the communication unit 17c and terminates the process (step S123). In the third embodiment, the key management device 1c sends the response directly to the key management device 1b without going through (relaying) the key management device 1b.
[0227] Step S124 is the same as step S63 (Figure 32) of the second embodiment described above, so its explanation will be omitted.
[0228] The management unit 13c returns a success response to the key management device 1a via the communication unit 17c and terminates the process (step S125). In the third embodiment, the key management device 1c transmits the response directly to the key management device 1b without going through (relaying) the key management device 1b.
[0229] Figure 45 shows the state of key management devices 1a and 1c after the process of updating the global key of the third embodiment with an expired global key without an intermediary has been performed. In the third embodiment, a new global key sharing is performed using this expired global key AC (for encryption) 14a5 and expired global key AC (for decryption) 14c3.
[0230] Figure 46 is a flowchart showing an example of the sending side processing for global key sharing (without relay) using an expired global key in the third embodiment. Figure 46 shows an example of processing on the key management device 1a side. The global key generation unit 16a of the key management device 1a periodically executes the processing shown in Figure 46.
[0231] Steps S126 to S133 are the same as steps S65 to S72 (Figure 34) of the second embodiment described above, so their explanation will be omitted.
[0232] In step S134, if the amount of shared global key AC (for decryption) 14c2 (the amount of stored global key AC (for encryption) 14a4 in the key management device 1a) is less than or equal to the amount of stored expired global key AC (for encryption) (step S134, Yes), the process proceeds to [5] (step S135). If the amount exceeds the stored amount (step S134, No), the communication unit 17a passes the processing result (failure) to the global key generation unit 16a (step S136). Details of the process in [5] will be described later using Figure 50.
[0233] Steps S137 to S139 are the same as steps S76 to S78 (Figure 34) of the second embodiment described above, so their explanation will be omitted.
[0234] Figure 47 is a flowchart showing an example of the processing on the transmitting side [5] of the global key sharing (without relay) in the third embodiment. Figure 47 shows an example of the processing on the key management device 1a side.
[0235] Steps S135-1 to S135-3 are the same as steps S74-1 to S74-3 (Figure 35) of the second embodiment described above, so their explanation will be omitted.
[0236] Next, the communication unit 17a sends a global key sharing request directly to the key management device 1c without relaying it through the key management device 1b (step S135-4). The packet structure of the global key sharing request is as shown in Figure 16 above.
[0237] The global key sharing request in step S135-4 includes the following: Cryptographic key type: Expired global key Destination IP address: IP address of key management device 1c Encryption key information: Data of the expired global key AC (encryption) used when encrypting the global key AC (decryption). Encryption payload: Encrypted global key AC (for decryption) data
[0238] Steps S135-5 to S135-7 are the same as steps S74-5 to S74-7 (Figure 35) of the second embodiment described above, so their explanation will be omitted.
[0239] Figure 48 is a flowchart showing an example of the receiving side processing for global key sharing (without relay) in the first embodiment. Figure 48 shows an example of the processing on the key management device 1c side.
[0240] First, the communication unit 17c receives a global key sharing request from the key management device 1a (step S140).
[0241] Steps S141 to S142 are the same as steps S95 to S96 (Figure 38) of the second embodiment described above, so their explanation will be omitted.
[0242] The communication unit 17c confirms that the encryption key type obtained in step S142 is an expired global key, and obtains the expired global key AC (for decryption) 14c3 from the storage unit 14c based on the encryption key information (step S143).
[0243] Steps S144 to S150 are the same as steps S99 to S100 and S104 to S108 (Figure 38) of the second embodiment described above, so their explanation will be omitted.
[0244] The communication unit 17c directly transmits, without going through the key management device 1b, the processing result (success / failure) passed from the global key generation unit 16c as a response to the global key sharing request to the key management device 1a (step S151).
[0245] FIG. 49 is a diagram showing the global key sharing process (without relay) using the invalid global key in the third embodiment. FIG. 49 shows the states of the key management devices 1a to 1c when the processes of steps S126 to S135 in FIG. 46 and steps S135-1 to S135-4 in FIG. 47 described above are performed.
[0246] FIG. 50 is a diagram showing the global key sharing process (without relay) using the invalid global key in the third embodiment. FIG. 50 shows the states of the key management devices 1a to 1c when the processes of steps S140 to S147 in FIG. 48 described above are performed.
[0247] FIG. 51 is a diagram showing the global key sharing process (without relay) using the invalid global key in the third embodiment. FIG. 51 shows the states of the key management devices 1a to 1c when the processes of S148 to S149, S151 in FIG. 51, S135-5 to S135-6 in FIG. 47, and S137 to S138 in FIG. 46 described above are performed.
[0248] As described above, in the third embodiment, since it is possible to communicate directly with the key management device 1 of the direct destination site, there is an advantage that the number of times of encryption / decryption during global key sharing can be reduced. In the method using the conventional local key, it was necessary to perform encrypted transfer via the adjacent key management device 1.
[0249] Finally, an example of the hardware configuration of the QKD device 3 and the key management device 1 in the first to third embodiments will be described.
[0250] [Example of Hardware Configuration] FIG. 52 is a diagram showing an example of the hardware configuration of the QKD apparatus 3 according to the first to third embodiments. The QKD apparatus 3 according to the first to third embodiments includes a control device 301, a main memory device 302, an auxiliary storage device 303, a display device 304, an input device 305, a quantum communication IF 306, and a classical communication IF 307.
[0251] The control device 301, the main memory device 302, the auxiliary storage device 303, the display device 304, the input device 305, the quantum communication IF 306, and the classical communication IF 307 are connected via a bus 310.
[0252] The control device 301 executes a program read from the auxiliary storage device 303 into the main memory device 302. The main memory device 302 is a memory such as a ROM and a RAM. The auxiliary storage device 303 is an HDD, a memory card, or the like.
[0253] The display device 304 displays the state of the QKD apparatus 3 and the like. The input device 305 receives an input from the user. Note that the display device 304 and the input device 305 may be realized by a touch panel or the like having a display function and an input function. Further, the display device 304 and the input device 305 may not be provided in the QKD apparatus 3. In this case, for example, the display function and the input function of an external terminal connected to the QKD apparatus 3 are used.
[0254] The quantum communication IF 306 is an interface for connecting to a QKD link through which photons are transmitted. The classical communication IF 307 is an interface for connecting to a transmission path through which a control signal is transmitted to the opposing QKD apparatus 3, a transmission path for communicating with the key management apparatus 1, and the like.
[0255] FIG. 53 is a diagram showing an example of the hardware configuration of the key management apparatus 1 according to the first to third embodiments. The key management apparatus 1 includes a control device 401, a main memory device 402, an auxiliary storage device 403, a display device 404, an input device 405, and a communication IF 406.
[0256] The control device 401, main memory 402, auxiliary memory 403, display device 404, input device 405, and communication IF 406 are connected via bus 410.
[0257] The control device 401 executes the program read from the auxiliary storage device 403 into the main storage device 402. The main storage device 402 is memory such as ROM and RAM. The auxiliary storage device 403 is such as an HDD and memory card.
[0258] The display device 404 displays the status of the key management device 1, etc. The input device 405 accepts input from the user. The display device 404 and the input device 405 may be implemented as touch panels or the like that have display and input functions. Furthermore, the display device 404 and the input device 405 do not have to be provided in the key management device 1. In this case, for example, the display and input functions of an external terminal connected to the key management device 1 may be used.
[0259] The communication IF406 is an interface for connecting to the transmission line.
[0260] The programs executed by the QKD device 3 and key management device 1 of the first to third embodiments are stored in installable or executable file format on computer-readable storage media such as CD-ROMs, memory cards, CD-Rs, and DVDs (Digital Versatile Discs) and provided as computer program products.
[0261] Furthermore, the programs executed by the QKD device 3 and key management device 1 of the first to third embodiments may be stored on a computer connected to a network such as the Internet and provided by being downloaded via the network.
[0262] Furthermore, the programs executed by the QKD device 3 and key management device 1 of the first to third embodiments may be configured to be provided via a network such as the Internet without requiring downloads.
[0263] Further, the programs executed by the QKD apparatus 3 and the key management apparatus 1 according to the first to third embodiments may be configured to be provided by being pre-incorporated into a ROM or the like.
[0264] Note that a part or all of the functions of the QKD apparatus 3 and the key management apparatus 1 according to the first to third embodiments may be realized by hardware such as an IC (Integrated Circuit). The IC is, for example, a processor that executes dedicated processing.
[0265] Also, when realizing each function using a plurality of processors, each processor may realize one of each function or may realize two or more of each function.
[0266] Although some embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be implemented in various other forms, and various omissions, replacements, and changes can be made without departing from the gist of the invention. These embodiments and their modifications are included in the scope and gist of the invention, and are included in the invention described in the claims and the equivalent scope thereof.
Description of Reference Numerals
[0267] 1 Key management apparatus 2 Application 3 QKD apparatus 11 Providing unit 12 Receiving unit 13 Management unit 14 Storage unit 15 Random number generation unit 16 Global key generation unit 17 Communication unit 100, 100-2 Quantum cryptographic communication system 301 Control apparatus 302 Main storage device 303 Auxiliary storage device 304 Display device 305 Input device 306 Quantum Communication IF 307 Classical Communication IF 310 Bus 401 Control Unit 402 Main storage 403 Auxiliary storage 404 Display device 405 Input device 406 Communication IF 410 Bus
Claims
1. A global key generation unit generates a first global key used for encrypting or decrypting communications by an application, and stores the first global key, which has been shared with other key management devices through encrypted transfer using QKD (Quantum Key Distribution), in a storage unit. A management unit checks the expiration date of the first global key stored in the memory unit and updates the first global key that has expired to an expired global key. A communication unit that, when sharing the second global key newly generated by the global key generation unit with the other key management device, encrypts the second global key using the expired global key and transmits the encrypted second global key to the other key management device, A providing unit that provides the second global key to the application, A key management device equipped with the following features.
2. When the communication unit updates the expired first global key to the revoked global key, it sends an update request to the other key management device that includes identification information identifying the revoked global key used for encryption or decryption. The key management device according to claim 1.
3. The communication unit, if the amount of stored first global keys that have not expired is less than or equal to the amount of stored expired global keys, encrypts the second global key using the expired global keys and transmits the encrypted second global key to the other key management device. The key management device according to claim 1 or 2.
4. The system further includes a receiving unit that receives the local key from a QKD device that shares the local key via QKD with a counterpart QKD device, If the amount of stored first global keys that have not expired is not less than or equal to the amount of stored expired global keys, the communication unit encrypts the second global key using the local key and transmits the encrypted second global key to the other key management device. The key management device according to claim 1 or 2.
5. When the communication unit transmits the encrypted second global key to the other key management device, it transmits identification information to the other key management device that identifies the revoked global key used for encryption. The key management device according to claim 1 or 2.
6. When the communication unit receives the encrypted second global key and identification information identifying the revoked global key used for encryption from the other key management device, it identifies the revoked global key to decrypt the encrypted second global key from the identification information, and decrypts the encrypted second global key using the identified revoked global key. The key management device according to claim 1 or 2.
7. A random number generation unit that generates random numbers used for the first and second global keys, The key management device according to claim 1 or 2, further comprising:
8. The communication unit encrypts the second global key using OTP (One Time Pad) with the expired global key. The key management device according to claim 1 or 2.
9. The communication unit encrypts the second global key using AES (Advanced Encryption Standard) with the expired global key. The key management device according to claim 1 or 2.
10. The key management device generates a first global key used to encrypt or decrypt communications by the application, The key management device stores the first global key, which has been shared with other key management devices by encrypted transfer using QKD (Quantum Key Distribution), in its storage unit. The key management device checks the expiration date of the first global key stored in the storage unit, and updates the expired first global key to an expired global key. When the key management device shares the second global key newly generated by the generation step with the other key management device, it encrypts the second global key using the revoked global key and transmits the encrypted second global key to the other key management device. The key management device provides the second global key to the application, A key management method that includes this.
11. Computers, A global key generation unit generates a first global key used for encrypting or decrypting communications by an application, and stores the first global key, which has been shared with other key management devices through encrypted transfer using QKD (Quantum Key Distribution), in a storage unit. A management unit checks the expiration date of the first global key stored in the memory unit and updates the first global key that has expired to an expired global key. A communication unit that, when sharing the second global key newly generated by the global key generation unit with the other key management device, encrypts the second global key using the expired global key and transmits the encrypted second global key to the other key management device, A providing unit that provides the second global key to the application, A program designed to function as such.
Citation Information
Patent Citations
Quantum cryptographic communication system, quantum cryptographic communication device, key management device and program
JP2023043789A