Quantum cryptography service device and quantum cryptography communication service method

The pre-quantum key generation method addresses latency issues in quantum cryptography services by generating and storing quantum keys in advance, enhancing service performance and resource efficiency.

JP2026057460APending Publication Date: 2026-04-02KOREA INST OF SCI & TECH INFORMATION
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Quantum key relay computations cause significant latency and performance degradation in quantum cryptography services, especially between long-distance service nodes.

Method used

A pre-quantum key generation method is employed to generate and store quantum keys in advance between key management nodes, reducing the need for real-time relay computations during service requests.

Benefits of technology

This approach minimizes quantum key support delay time, leading to low-latency quantum cryptography services and efficient utilization of expensive quantum resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026057460000001_ABST
    Figure 2026057460000001_ABST
Patent Text Reader

Abstract

This invention provides a solution for minimizing quantum key support latency for end-to-end quantum cryptography services at service nodes in a quantum cryptography service. [Solution] The quantum cryptography service device according to the present invention includes: a memory containing instruction words; and a processor that, by executing instruction words, generates adjacent quantum keys for all key management nodes in the quantum key management layer to be shared with other key management nodes directly connected to each key management node, and when a particular pair of key management nodes that are not directly connected to each other is determined from the connection state between the key management nodes, generates a pre-quantum key to be shared between the particular pair of key management nodes through a quantum key relay that consumes the adjacent quantum keys of each key management node connecting the particular pair of key management nodes, before a quantum cryptography service request is made in the service layer.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This application claims priority to Korean Patent Application No. 10-2024-0128094, filed with the Korean Intellectual Property Office on September 23, 2024, and the entire contents of the Korean Patent Application are included in this application by reference.

[0002] The present invention relates to a method for minimizing quantum key support latency for end-to-end quantum cryptography services at service nodes in a quantum cryptography service. [Background technology]

[0003] Quantum cryptography is a method of communication that utilizes quantum keys, which are generated by leveraging the quantum mechanical properties of quanta, for the encryption and decryption of communications.

[0004] The ITU-T (International Telecommunication Standardization Sector) international standard (ITU.T Y.3800) defines a layered structure for quantum cryptography communication networks, consisting of a quantum layer, a quantum key management layer, and a service layer.

[0005] The quantum layer includes a quantum key distribution module (QKD module), and a pair of QKD modules connected by a quantum link generate and share quantum keys through an arbitrary quantum key distribution protocol.

[0006] Subsequently, the quantum key distribution module transmits the quantum key to the key manager (KM) of the quantum key management layer, and the key manager recombines the quantum key and transmits it to the service node of the service layer.

[0007] The service node utilizes the transmitted quantum key to perform an end-to-end quantum cryptography service (quantum-secured service).

[0008] On the other hand, when a quantum cryptography service request occurs between end-to-end service nodes in a quantum cryptography communication network, the service node can request an end-to-end quantum key from the connected key management node.

[0009] In this case, the difference between the time a quantum key is requested and the time the quantum key is actually received can be defined as the key response latency, which is a key performance indicator for users of quantum cryptography services.

[0010] In particular, the ITU-T standardization group defines key solicitation delay as a primary measure of quantum cryptography service performance through its Y.3807 standardization document.

[0011] In this context, quantum key relay is an essential technology for quantum cryptographic services between long-distance service nodes.

[0012] However, the quantum key relay function requires computations such as XOR (exclusive OR) between quantum keys, which causes a delay in the service layer's response to quantum key requests.

[0013] In other words, the greater the distance between end-to-end service nodes, the more relay computations are required between a large number of quantum keys, which can result in very long quantum key support latency and induce performance degradation of quantum cryptography services. [Overview of the project] [Problems that the invention aims to solve]

[0014] This invention was created in consideration of the circumstances described above, and its objective is to minimize the quantum key support delay time for end-to-end quantum cryptography services at service nodes in quantum cryptography services. [Means for solving the problem]

[0015] A quantum cryptography service apparatus according to one embodiment of the present invention for achieving the above objective includes: a memory containing instruction words; and a processor that, by executing the instruction words, generates adjacent quantum keys for all key management nodes in the quantum key management layer to be shared with other key management nodes directly connected to each key management node, and, when a particular pair of key management nodes that are not directly connected to each other is determined from the connection state between the key management nodes, generates a pre-quantum key to be shared between the particular pair of key management nodes through a quantum key relay that consumes adjacent quantum keys for each key management node connecting the particular pair of key management nodes, before a quantum cryptography service request is made in the service layer.

[0016] Specifically, when a quantum cryptography service request occurs, the processor can transmit a pre-quantum key, or a quantum key generated through a quantum key relay that consumes the pre-quantum key, as a service quantum key for the service node's end-to-end quantum cryptography service.

[0017] Specifically, the processor can generate pre-quantum keys for all key management nodes in the quantum key management layer, which are shared with all other key management nodes that are not directly connected to each respective key management node.

[0018] Specifically, the processor can generate pre-quantum keys between pairs of key management nodes that are at a distance (hop) predetermined by the quantum key management layer.

[0019] Specifically, the processor can generate pre-quantum keys between all key management node pairs directly connected to the service nodes of the service layer in the quantum key management layer.

[0020] Specifically, the processor can generate pre-quantum keys between key management nodes that are directly connected to service nodes at a predefined distance (hop) between them in the service layer.

[0021] Specifically, the processor can generate pre-quantum keys for key management node pairs that use pre-quantum keys to reduce the number of quantum key relays between arbitrary key management node pairs to less than a threshold value during quantum key generation between them in the quantum key management layer.

[0022] A quantum cryptography communication service method performed by a quantum cryptography service device according to one embodiment of the present invention for achieving the above objective is characterized by including: an adjacent quantum key generation step for all key management nodes in the quantum key management layer to generate adjacent quantum keys to be shared with other key management nodes directly connected to each key management node; and a pre-quantum key generation step, when a specific pair of key management nodes that are not directly connected to each other is determined from the connection state between the key management nodes, to generate a pre-quantum key to be shared between the specific pair of key management nodes through a quantum key relay that consumes adjacent quantum keys for each key management node connecting the specific pair of key management nodes, before a quantum cryptography service request is made in the service layer.

[0023] Specifically, the method may further include a service quantum key transfer step in which, when a quantum cryptographic service request occurs, a pre-quantum key, or a quantum key generated through a quantum key relay that consumes the pre-quantum key, is transmitted as a service quantum key for the service node's end-to-end quantum cryptographic service.

[0024] Specifically, the pre-quantum key generation step can generate a pre-quantum key for each key management node in the quantum key management layer that is shared with all other key management nodes that are not directly connected to that node.

[0025] Specifically, the pre-quantum key generation step can generate pre-quantum keys between pairs of key management nodes that are at a distance (hop) predetermined by the quantum key management layer.

[0026] Specifically, the pre-quantum key generation step can generate pre-quantum keys between all key management node pairs directly connected to the service nodes of the service layer in the quantum key management layer.

[0027] Specifically, the pre-quantum key generation step can generate pre-quantum keys between key management nodes that are directly connected to service nodes at a predefined distance (hop) between service nodes in the service layer.

[0028] Specifically, the pre-quantum key generation step can generate pre-quantum keys for key management node pairs that use pre-quantum keys to reduce the number of quantum key relays between arbitrary key management node pairs during quantum key generation in the quantum key management layer to less than a threshold. [Effects of the Invention]

[0029] As a result, the quantum cryptography service device and quantum cryptography communication service method of the present invention apply a pre-quantum key generation method in which quantum keys are generated in advance between long-distance nodes in the quantum cryptography service. Compared to existing cryptographic communications, this reduces the quantum key support delay time due to quantum key relay, which is a drawback of quantum cryptography communications, thereby achieving a low-latency quantum cryptography service and efficiently utilizing expensive quantum resources. [Brief explanation of the drawing]

[0030] [Figure 1] This is an illustrative diagram illustrating a quantum key relay system according to one embodiment of the present invention. [Figure 2]This is an illustrative diagram illustrating a conventional quantum cryptography communication network. [Figure 3] This is an illustrative diagram illustrating a conventional quantum cryptography communication network. [Figure 4] This is a diagram illustrating a quantum cryptography service device according to one embodiment of the present invention. [Figure 5] This is an illustrative diagram illustrating the pre-quantum key generation method according to the first embodiment of the present invention. [Figure 6] This is an illustrative diagram illustrating the pre-quantum key generation method according to the first embodiment of the present invention. [Figure 7] This is an illustrative diagram illustrating a pre-quantum key generation method according to a second embodiment of the present invention. [Figure 8] This is an illustrative diagram illustrating a pre-quantum key generation method according to a second embodiment of the present invention. [Figure 9] This is an illustrative diagram illustrating a pre-quantum key generation method according to a third embodiment of the present invention. [Figure 10] This is an illustrative diagram illustrating a pre-quantum key generation method according to a third embodiment of the present invention. [Figure 11] This is an illustrative diagram illustrating a pre-quantum key generation method according to a fourth embodiment of the present invention. [Figure 12] This is an illustrative diagram illustrating a pre-quantum key generation method according to a fourth embodiment of the present invention. [Figure 13] This is an illustrative diagram illustrating a pre-quantum key generation method according to a fifth embodiment of the present invention. [Figure 14] This is an illustrative diagram illustrating a pre-quantum key generation method according to a fifth embodiment of the present invention. [Figure 15] This is a flowchart illustrating a quantum cryptography communication service method according to one embodiment of the present invention. [Modes for carrying out the invention]

[0031] The embodiments disclosed herein will be described in detail below with reference to the accompanying drawings. Regardless of the reference numerals in the drawings, identical or similar components will be assigned the same reference numerals, and redundant explanations will be omitted. The suffixes "module" and "part" used for components in the following description are added or mixed solely for the sake of ease of drafting the specification and do not have any distinguishing meaning or role in themselves. Furthermore, if it is determined that a specific explanation of the relevant prior art would obscure the gist of the embodiments disclosed herein, such detailed explanation will be omitted. In addition, the accompanying drawings are provided solely to facilitate understanding of the embodiments disclosed herein, and the technical ideas of the invention are not limited by the accompanying drawings. It should be understood that they include all modifications, equivalents, or substitutes that fall within the concept and technical scope of the present invention.

[0032] Terms including ordinal numbers, such as "first," "second," etc., can be used to describe a variety of components, but the components are not limited by such terms. The terms are used solely for the purpose of distinguishing one component from another.

[0033] When one component is described as being "linked" or "connected" to another component, it should be understood that this could mean that it is directly linked or connected to the other component, or that another component exists in between. Conversely, when one component is described as being "directly linked" or "directly connected" to another component, it should be understood that there is no other component in between.

[0034] Hereinafter, preferred embodiments of the present invention will be described with reference to the attached drawings.

[0035] One embodiment of the present invention deals with technology relating to quantum cryptography services.

[0036] With current quantum technology, there are distance limitations between adjacent quantum key distribution modules in a quantum layer.

[0037] To overcome this, quantum cryptography networks include trust nodes, which consist of key management nodes and quantum key distribution modules.

[0038] The key management node of a trusted node generates quantum keys that can be shared between long-distance nodes through relays between quantum keys transmitted from the quantum key distribution module.

[0039] In this regard, Figure 1 illustrates a quantum key relay scheme.

[0040] The service layer in Figure 1 includes service nodes a and c. If the physical distance between service nodes a and c is large, it can include a trust node consisting of a key management node b and a quantum key distribution module connected to key management node b.

[0041] In this case, key management node b can be connected to key management nodes a and c.

[0042] Furthermore, the quantum key distribution module connected to key management node b can be connected to the quantum key distribution module connected to key management node a and the quantum key distribution module connected to key management node c, respectively, and each can share a quantum key in its quantum layer.

[0043] In other words, key management node a and key management node b use the same key (k) through the quantum key distribution protocol. ab ) can be shared, and key management node b and key management node c also share the quantum key (k bc ) can be shared.

[0044] Key management node a sends k to service node a ab The key management node b transmits k ab and k bc between

number

[0045] In response to this, key management node c

number

[0046] Therefore, both service nodes a and c have the same quantum key k. ab Since the symmetric key was shared, the corresponding symmetric key can be used to achieve quantum cryptographic services between service nodes a and c.

[0047] On the other hand, when a quantum cryptographic service request occurs between end-to-end service nodes in a quantum cryptographic communication network, the service node can request an end-to-end quantum key from the connected key management node.

[0048] In this case, the difference between the time a quantum key is requested and the time the quantum key is actually received can be defined as the key response latency, which is a key performance indicator for users of quantum cryptography services.

[0049] In particular, the ITU-T standardization group defines key solicitation delay as a primary measure of quantum cryptographic service performance through its Y.3807 standardization document.

[0050] In this context, quantum key relay is an essential technology for quantum cryptographic services between long-distance service nodes.

[0051] However, the quantum key relay function requires computations such as XOR between quantum keys, which introduces a delay in the service layer's response to quantum key requests.

[0052] In other words, the greater the distance between end-to-end service nodes, the more relay computations are required between a large number of quantum keys, which results in very long quantum key support delays and can ultimately induce performance degradation of quantum cryptography services.

[0053] To help understand the explanation, let's look at conventional technology. For example, as shown in Figure 2, a pair of interconnected quantum key distribution modules share a symmetric quantum key (hereinafter referred to as the neighboring "quantum key") through an arbitrary quantum key distribution protocol and transmit it to a key management node. The key management node then stores the corresponding neighboring quantum key in its own key pool.

[0054] In other words, for every key management node in the quantum key management layer of a quantum cryptography communication network, the key management nodes directly connected to each node are searched for and computed. Subsequently, the key pool of each key management node stores the keys that it shares with the key management nodes directly connected to it.

[0055] In this regard, for example, as shown in Figure 3, a quantum cryptographic network structure can be illustrated that includes a service layer consisting of three service nodes (service nodes a, c, and e), a quantum key management layer consisting of five key management nodes (key management nodes a, b, c, d, and e), and a quantum layer consisting of eight quantum key distribution modules.

[0056] For the sake of explanation, Figure 3 illustrates a linear quantum cryptography network topology, but it is not limited to this.

[0057] In the above structure, each service node is connected to one key management node, and each key management node is connected to one or more quantum key distribution modules.

[0058] Key management node b, key management node d, and the quantum key distribution module connected to the key management nodes can be configured as trust nodes to overcome the distance limitations of the quantum key distribution protocol.

[0059] In this case, the key pool of each key management node stores only the quantum keys transmitted by the quantum key distribution module connected to that key management node.

[0060] For example, the key pool of the key management node c stores the adjacent quantum keys (k bc , k cd ) transmitted by the quantum key distribution module connected to the corresponding key management node.

[0061] When a quantum cryptography service request occurs between the service nodes a and e in the above example, the end-to-end quantum key (hereinafter referred to as "service quantum key") between the corresponding service nodes is the adjacent quantum key (k ab ) between the key management nodes a and b, the adjacent quantum key (k bc ) between the key management nodes b and c, the adjacent quantum key (k cd ) between the key management nodes c and d, and the adjacent quantum key (k de ) between the key management nodes d and e, and can be generated through a quantum key relay that consumes these keys.

[0062] Ultimately, a large number of quantum key relay calculations required to assist the service quantum key of the service node in the quantum cryptography service may cause a long assistance delay time for the quantum key request, and such a quantum key assistance delay time may inhibit the user experience performance of the quantum cryptography communication service.

[0063] Therefore, in one embodiment of the present invention, it is intended to propose a new solution that can minimize the quantum key assistance delay time through a pre-quantum key generation method. Hereinafter, a quantum cryptography service device (not shown) for realizing this will be described.

[0064] Prior to the explanation, the pre-quantum key generation method can be understood as a method of pre-generating a quantum key between any two long-distance key management nodes through a quantum key relay method and sharing it between the key management nodes even before a quantum cryptography service request using the quantum key occurs, so as to quickly provide a quantum key when a quantum cryptography service request occurs later.

[0065] A pre-quantum key generation method according to one embodiment of the present invention can be performed during idle time when no quantum cryptography service is in operation, can be performed periodically at any user-configurable interval, and can be performed taking into account the current status of quantum key resources shared between each pair of key management nodes.

[0066] On the other hand, a quantum cryptography service device (not shown) according to one embodiment of the present invention can be implemented in the form of a computing device or server equipped with software (e.g., an application) on a quantum cryptography communication network. If implemented in the form of a server, it can be implemented in the form of, for example, a web server, a database server, a proxy server, etc., and one or more of the following can be installed: a network load balancing mechanism or various software that enables the service device to operate on the Internet or other networks, thereby enabling it to be implemented as a computerized system.

[0067] In the following, we will continue the explanation by assigning a new reference number 100 to such a quantum cryptography service device (not shown).

[0068] Figure 4 shows the configuration of a quantum cryptography service device 100 according to one embodiment of the present invention.

[0069] As shown in Figure 4, a quantum cryptography service device 100 according to one embodiment of the present invention can be configured to include a memory containing instruction words and a processor that executes the instruction words in the memory.

[0070] In particular, in the case of a processor according to one embodiment of the present invention, it may have a functional configuration that includes an adjacent key generation unit 110, a pre-key generation unit 120, and a service key generation unit 130, depending on the function to be realized by the execution of an instruction word.

[0071] As described above, the quantum cryptography service device 100 according to one embodiment of the present invention can minimize the quantum key support delay time by applying a pre-quantum key generation method through the configuration described above. Below, we will continue with a more detailed explanation of the functional configuration of the processor that makes this possible.

[0072] The adjacent key generation unit 110 is responsible for generating adjacent quantum keys.

[0073] More specifically, the neighboring key generation unit 110 generates neighboring quantum keys for all key management nodes in the quantum key management layer, which are shared with other key management nodes directly connected to each key management node.

[0074] Referring to Figure 3 shown earlier, if there are five key management nodes (key management nodes a, b, c, d, e) in the quantum key management layer, the adjacent quantum key (k) between key management node a and b is... ab ), adjacent quantum keys (k) between key management nodes b and c bc ), adjacent quantum keys (k) between key management nodes c and d cd ), and the adjacent quantum key (k) between key management nodes d and e. de ) can be generated and stored in the key pool of each key management node.

[0075] The pre-key generation unit 120 is responsible for generating pre-quantum keys.

[0076] More specifically, the pre-key generation unit 120 generates a pre-quantum key to be shared between any two long-range key management nodes through a quantum key relay that consumes adjacent quantum keys.

[0077] At this time, if the pre-key generation unit 120 determines a specific pair of key management nodes that do not have a direct connection to each other based on the connection status between the key management nodes, it can generate a pre-quantum key through a quantum key relay that consumes the adjacent quantum keys of each key management node that connects the relevant pair of key management nodes, before a quantum cryptographic service request is made at the service layer.

[0078] On the other hand, the quantum key resources generated by quantum key distribution modules are extremely limited, requiring efficient use. In particular, in practical quantum cryptography, a lifetime is set for each quantum key, and quantum keys that have exceeded their lifetime are discarded.

[0079] Similarly, methods for generating pre-quantum keys between long-distance key management nodes consume a large number of quantum keys. If these pre-quantum keys are not requested and their lifetime expires, they are discarded, which could reduce the quantum key resource efficiency of quantum cryptography communication.

[0080] Therefore, in one embodiment of the present invention, a first embodiment can be adopted in which a pre-quantum key is generated between all key management node pairs as a way to improve the quantum key resource efficiency of quantum cryptographic communication.

[0081] In other words, the pre-key generation unit 120 generates a pre-quantum key for each key management node of the quantum key management layer, which is shared with all other key management nodes that are not directly connected to that key management node.

[0082] In other words, the pre-key generation unit 120 searches for and computes all key management nodes in the quantum key management layer of the quantum cryptography communication network, as shown in Figure 5, and then stores the pre-quantum key that the key management node shares with all other key management nodes in the key pool of each key management node.

[0083] In this case, a method can be applied that maintains the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0084] Furthermore, the number of pre-generated quantum keys can be differentiated according to the distance between key management nodes. For example, a method can be applied where a large number of quantum keys are pre-generated for key management nodes that are close together, and a small number of quantum keys are pre-generated for key management nodes that are far apart.

[0085] Furthermore, it goes without saying that the number of pre-quantized quantum keys can be varied depending on the number of keys stored in the key pool of each key management node.

[0086] To aid in understanding the explanation, Figure 6 shows the quantum cryptography communication network structure according to the first embodiment.

[0087] The portion of the key pool shown in bold corresponds to the additional key pool compared to before the application of the pre-quantum key generation scheme.

[0088] For example, before applying the pre-quantum key generation scheme at key management node c, the neighboring quantum key (k) is shared with the neighboring key management nodes b and d. bc , k cd ) were managed in the key pool, but in the first embodiment, quantum keys (k ac , k ce These can also be pre-generated through any key relay scheme and stored in a key pool.

[0089] As a result, when a quantum cryptographic service request occurs between service nodes a and e in the first embodiment, the pre-generated quantum key (k) stored in each key pool is used by service nodes a and e. ae This allows for rapid transmission of information, reducing the latency of quantum cryptography services.

[0090] In this case, a method can be applied to maintain the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0091] Furthermore, the number of pre-generated quantum keys can be differentiated according to the distance between key management nodes. For example, a system can be applied in which a large number of quantum keys are pre-generated for key management nodes that are close together, and a small number of quantum keys are pre-generated for key management nodes that are far apart.

[0092] Furthermore, the number of pre-quantized quantum keys can be varied according to the number of keys stored in the key pool of each key management node, for example, k ab The number and k bcIf the number is small, k ab and k bc k generated by relaying ac Only a small number can be pre-generated, on the other hand, k cd The number and k de If the number is sufficiently large, a large number of k ce It can be pre-generated.

[0093] Furthermore, in one embodiment of the present invention, a second embodiment can be adopted as a way to improve the quantum key resource efficiency of quantum cryptographic communication, in which computational sample keys are generated between key management nodes at an arbitrary distance.

[0094] In other words, the pre-key generation unit 120 generates pre-quantum keys between pairs of key management nodes that are at a distance (hop) predetermined by the quantum key management layer.

[0095] In other words, the pre-key generation unit 120 calculates the distance between all key management node pairs in the quantum key management layer through an arbitrary path calculation algorithm for a given quantum cryptographic network topology, as shown in Figure 7, and stores the pre-quantum key that the key management node shares with key management nodes at an n-hop distance in its key pool.

[0096] Here, the value of n can be freely selected by the user, may be a large number, and can be chosen based on conditions such as network conditions and topology.

[0097] In this second embodiment, it is necessary to calculate the distance between each key management node in advance, and in this case, the Dijkstra shortest path calculation method or the like can be applied.

[0098] In this case, a method can be applied to maintain the number of pre-quantized keys generated between key management node pairs to be as identical as possible, and differences can be made depending on the number of keys stored in the key pool of each key management node.

[0099] To aid in understanding the explanation, Figure 8 shows the quantum cryptography communication network structure according to the second embodiment.

[0100] This illustrates the case where n is 2, and it goes without saying that it is not limited to this case.

[0101] The portion of the key pool shown in bold corresponds to the additional key pool compared to before the application of the pre-quantum key generation scheme.

[0102] For example, before applying the pre-quantum key generation scheme at key management node b, the neighboring quantum key (k) is shared with the adjacent key management nodes a and c. ab , k bc In the first embodiment, only the first key was managed in the key pool, but in the second embodiment, by applying a pre-quantum key generation scheme between all key management nodes, the quantum key (k) with key management node d at a 2-hop distance was generated. bd These can also be pre-generated through any key relay scheme and stored in a key pool.

[0103] As a result, in the second embodiment, when a quantum cryptographic service request occurs between service nodes a and e, k ab and k bd , and k de Relaying the service quantum key k ae This can be generated and transmitted to the service node.

[0104] Here, k bd Since this is a pre-quantum key, it can reduce the latency of quantum cryptography services compared to when a pre-quantum key generation scheme is not applied.

[0105] In this case, a method can be applied to maintain the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0106] Furthermore, the number of pre-quantized quantum keys can be varied according to the number of keys stored in the key pool of each key management node, for example, k ab The number and k bc If the number is small, k ab and k bc k generated by relaying acOnly a small number can be pre-generated, on the other hand, k cd The number and k de If the number is sufficiently large, a large number of k ce It can be pre-generated.

[0107] Furthermore, in one embodiment of the present invention, a third embodiment can be adopted as a way to improve the quantum key resource efficiency of quantum cryptographic communication, in which a pre-quantum key is generated between all key management nodes directly connected to the service node.

[0108] In other words, the pre-key generation unit 120 generates pre-quantum keys between all pairs of key management nodes that are directly connected to the service nodes of the service layer in the quantum key management layer.

[0109] In other words, the pre-key generation unit 120 searches for and computes the key management nodes of the quantum key management layer connected to each service node of the service layer in the quantum cryptographic communication network topology, for example, as shown in Figure 9. Subsequently, the key pool of the key management nodes connected to the service nodes stores the pre-quantum key that is shared with the key management nodes connected to all other service nodes.

[0110] In this case, a method can be applied that maintains the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0111] Furthermore, the number of pre-generated quantum keys can be differentiated according to the distance between key management nodes. For example, a method can be applied where a large number of quantum keys are pre-generated for key management nodes that are close together, and a small number of quantum keys are pre-generated for key management nodes that are far apart.

[0112] Furthermore, it goes without saying that the number of pre-quantized quantum keys can be varied depending on the number of keys stored in the key pool of each key management node.

[0113] To aid in understanding the explanation, Figure 10 shows the quantum cryptography communication network structure according to the third embodiment.

[0114] In this case, the portion of the key pool shown in bold corresponds to the additional key pool compared to before the application of the pre-quantum key generation scheme.

[0115] For example, before applying the pre-quantum key generation scheme at key management node c, the neighboring quantum key (k) is shared with the neighboring key management nodes b and d. bc , k cd In the third embodiment, where only the key pool was used to manage the quantum keys between the service node and all key management nodes directly connected to the service node, the quantum keys (k ac , k ce These can also be pre-generated through any key relay scheme and stored in a key pool.

[0116] As a result, in the third embodiment, when a quantum cryptographic service request occurs between service nodes a and e, the pre-generated quantum key (k) that has been stored in each key pool by service nodes a and e is used. ae This allows for rapid transmission of information, reducing the latency of quantum cryptography services.

[0117] On the other hand, key management nodes b and d do not store keys through pre-quantum key generation because they are not directly connected to any service nodes.

[0118] In this case, a method can be applied to maintain the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0119] Furthermore, the number of pre-generated quantum keys can be differentiated according to the distance between key management nodes. For example, a system can be applied in which a large number of quantum keys are pre-generated for key management nodes that are close together, and a small number of quantum keys are pre-generated for key management nodes that are far apart.

[0120] Furthermore, the number of pre-quantized quantum keys can be varied according to the number of keys stored in the key pool of each key management node, for example, k ab The number and k bc If the number is small, k ab and k bc k generated by relayingac Only a small number can be pre-generated, on the other hand, k cd The number and k de If the number is sufficiently large, a large number of k ce It can be pre-generated.

[0121] Furthermore, in one embodiment of the present invention, as a way to improve the quantum key resource efficiency of quantum cryptographic communication, a fourth embodiment can be adopted in which a pre-quantum key is generated between a service node and a key management node directly connected at an arbitrary distance.

[0122] In other words, the pre-key generation unit 120 generates pre-quantum keys between key management nodes that are directly connected to service nodes at a predefined distance (hop) between service nodes in the service layer.

[0123] In other words, the pre-key generation unit 120 calculates the distance between service node pairs for the service layer of the quantum cryptography network topology, for example, as shown in Figure 11, through an arbitrary path calculation algorithm. Then, the key pool of the key management node connected to the service node stores the pre-quantum key that is shared with the key management node connected to the service node at a distance of n hops from the relevant service node.

[0124] Here, the value of n can be freely selected by the user, may be a large number, and can be chosen based on conditions such as network conditions and topology.

[0125] In this fourth embodiment, it is necessary to calculate the distance between each key management node in advance, and in this case, the Dijkstra shortest path calculation method or the like can be applied.

[0126] In this case, a method can be applied that maintains the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0127] Furthermore, the number of pre-quantized quantum keys can be varied depending on the distance between key management nodes.

[0128] To aid in understanding the explanation, Figure 12 shows the quantum cryptography communication network structure according to the fourth embodiment.

[0129] This illustrates the case where n is 2, and it goes without saying that it is not limited to this case.

[0130] In this regard, n can be a large number and can be freely selected by the operator.

[0131] The portion of the key pool shown in bold corresponds to the additional key pool compared to before the application of the pre-quantum key generation scheme.

[0132] For example, before applying the pre-quantum key generation scheme at key management node a, the neighboring quantum key (k) is shared with the adjacent key management node b. ab In the fourth embodiment, only the key management nodes directly connected to the service node were managed in the key pool, but in the fourth embodiment, a pre-quantum key is generated between any pair of key management nodes at an arbitrary (n) hop distance from the service node, thereby generating a quantum key (k) between the service node e and the key management node e connected to the service node e at a 2-hop distance. ae These can also be pre-generated through any key relay scheme and stored in a key pool.

[0133] As a result, when a quantum cryptographic service request occurs between service nodes a and e in the fourth embodiment, the pre-generated quantum key (k) stored in each key pool is used by service nodes a and e. ae This allows for rapid transmission of information, reducing the latency of quantum cryptography services.

[0134] In this case, a method can be applied to maintain the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0135] Furthermore, the number of pre-quantized quantum keys can be varied according to the number of keys stored in the key pool of each key management node, for example, k ab The number, k bc The number, k cd The number, k de If the number is small, k ab, k bc , k cd , k de k generated by relaying ae Only a small number can be pre-generated, on the other hand, k ab , k bc , k cd , k de If the number is large, then a large number of k ae It can be pre-generated.

[0136] Furthermore, in one embodiment of the present invention, a fifth embodiment can be adopted in which an algorithm that takes into account the number of quantum key relays is applied as a way to improve the quantum key resource efficiency of quantum cryptographic communication.

[0137] In other words, the pre-key generation unit 120 generates pre-quantum keys for key management node pairs that make the number of quantum key relays using pre-quantum keys during quantum key generation between arbitrary key management node pairs in the quantum key management layer fall below a threshold.

[0138] In other words, the pre-key generation unit 120 applies an algorithm in the order shown in Figure 13, for example.

[0139] In the algorithm, G is an adjacency matrix representing the current connectivity state between key management nodes. G(a,b)=1 if key management nodes a and b are directly connected to each other, and 0 otherwise.

[0140] In other words, G can represent the key information stored in each key pool, for example, if G(a,b)=1, then the key pool of key management node a is the quantum key (k) between key management node a and key management node b. ab This means that it is saving (something).

[0141] In this case, due to the symmetry of the quantum key, if G(a,b) is 1, then G(b,a) is also 1.

[0142] The algorithm first selects a pair of key management nodes i* and j* from the elements of the key management node set KM that satisfy the following equation [Equation 1].

number

number

[0143] In other words, we select key management node pairs i* and j* that minimize the maximum number of key relays required to generate keys for all key management node pairs s and d, and then perform pre-quantum key generation for the i* and j* thus selected.

[0144] In other words, k is sent to the key pool of key management node i* via the quantum key relay algorithm. i*j* Generate and save it, and similarly, also add k to the key pool of key management node j*. i*j* Save it.

[0145] This updates G with the relevant information in order to perform pre-quantum key generation between key management nodes i* and j*.

[0146] after that,

number

[0147] In other words, the algorithm ensures an upper limit on the key request delay time for quantum cryptography communication by ensuring that the number of key relays between all key management node pairs does not exceed a certain threshold C.

[0148] The algorithm allows the threshold C to be set in various ways depending on the network conditions, user objectives, etc. Furthermore, the algorithm prevents excessive pre-quantum key generation by selecting key management node pairs one by one, thereby achieving more efficient quantum key resource utilization.

[0149] To aid in understanding the explanation, Figure 14 shows the quantum cryptography communication network structure according to the fifth embodiment.

[0150] When the algorithm first runs, G is represented as a directly connected state between key management nodes, that is, it contains information about keys in the key pool that are not in bold.

[0151] Therefore, only G(a,b), G(b,c), G(c,d), and G(d,e) are represented by 1, and the rest are represented by 0.

[0152] Subsequently, in addition to the given G information, one key management node pair is selected at a time, and if the quantum key between the corresponding key management node pair is pre-generated, the number of quantum key relays required for quantum key generation between the remaining key management nodes is calculated.

[0153] As a result, we select the node pair that minimizes the maximum number of quantum key relays.

[0154] In this regard, if a pair of key management nodes b and d is selected, the quantum key k between key management nodes a and e ae is, k ab , k bd , and k de Since it is generated through a quantum key relay, the maximum number of relays is 3.

[0155] Therefore, the algorithm performs pre-quantum key generation between the selected key management node pair b and d, which is represented by the bolded portion of each key pool.

[0156] This assumes that C is 4, so the algorithm terminates after generating a pre-quantum key only between key management nodes b and d.

[0157] Through this method, it is guaranteed that any quantum key generated between any pair of key management nodes can be generated through three or fewer quantum key relays, thus guaranteeing an upper limit on the key request delay time due to quantum key relay computation.

[0158] The service key generation unit 130 is responsible for generating service quantum keys.

[0159] More specifically, the service key generation unit 130 generates a service quantum key for the end-to-end quantum cryptography service of a service node in the service layer when a quantum cryptography service request occurs at that node.

[0160] In this case, the pre-key generation unit 120 can transmit a pre-quantum key, or a quantum key generated through a quantum key relay that consumes the pre-quantum key, in accordance with the quantum cryptography service request, as a service quantum key for the service node's end-to-end quantum cryptography service.

[0161] In this regard, in the first embodiment described earlier with reference to Figure 6, when a quantum cryptographic service request occurs between service nodes a and e, the pre-quantum key (k) that has been generated in advance by service nodes a and e and stored in each key pool is used. ae ) can be quickly transmitted to reduce the quantum cryptography service delay time, and in the second embodiment described earlier with reference to Figure 8, when a quantum cryptography service request occurs between service nodes a and e, k ab and k bd , and k de Relaying the service quantum key k ae This can be generated and transmitted to the service node.

[0162] Furthermore, in the third embodiment described earlier with reference to Figure 10, when a quantum cryptographic service request occurs between service nodes a and e, the pre-generated quantum key (k) stored in each key pool at service nodes a and e is used. ae) can be quickly transmitted to reduce the quantum encryption service delay time. In the fourth embodiment described above with reference to FIG. 12, when a quantum encryption service request occurs between service nodes a and e, the pre-quantum keys (k ae ) generated in advance by service nodes a and e and stored in each key pool can be quickly transmitted to reduce the quantum encryption service delay time.

[0163] Finally, in the fifth embodiment described above with reference to FIG. 14, when a quantum encryption service request occurs between service nodes a and e, k ab and k bd , and k de are relayed to generate a service quantum key k ae , which can be transmitted to the service node.

[0164] As described above, according to the configuration of the quantum encryption service apparatus 100 according to an embodiment of the present invention, by applying a pre-quantum key generation method for pre-generating quantum keys between long-distance nodes in a quantum encryption service, compared with existing encrypted communications, the quantum key assistance delay time due to quantum key relay, which is a drawback of quantum encryption communication, is reduced, and it can be seen that a low-delay quantum encryption service can be achieved and expensive quantum resources can be efficiently utilized.

[0165] Hereinafter, a quantum encryption communication service method according to an embodiment of the present invention will be described with reference to FIG. 15.

[0166] Since the main body of the operation of the quantum encryption communication service method according to an embodiment of the present invention is the quantum encryption service apparatus 100, the description will continue below with reference to the corresponding reference numerals.

[0167] First, the quantum encryption service apparatus 100 generates adjacent quantum keys to be shared with other key management nodes directly connected to each key management node for all key management nodes in the quantum key management layer (S110).

[0168] Referring to FIG. 3 exemplified above, when there are five key management nodes (key management nodes a, b, c, d, e) in the quantum key management layer, the adjacent quantum key (k ab ) between key management nodes a and b, the adjacent quantum key (k bc ) between key management nodes b and c, the adjacent quantum key (k cd ) between key management nodes c and d, and the adjacent quantum key (k de ) between key management nodes d and e can be generated and stored in the key pool of each key management node.

[0169] After that, the quantum cipher service device 100 generates a pre-quantum key to be shared between any two long-distance key management nodes through a quantum key relay that consumes adjacent quantum keys (S120 - S130).

[0170] At this time, when a specific pair of key management nodes without direct connection between key management nodes is determined from the connection state between key management nodes, before a quantum cipher service request occurs in the service layer, the quantum cipher service device 100 can generate a pre-quantum key through a quantum key relay that consumes an adjacent quantum key of another key management node connecting the corresponding pair of key management nodes.

[0171] In this regard, in one embodiment of the present invention, as a solution for improving the quantum key resource efficiency of quantum cipher communication, a first embodiment of generating pre-quantum keys between all pairs of key management nodes can be adopted.

[0172] That is, the quantum cipher service device 100 generates pre-quantum keys to be shared respectively with all other key management nodes that are not directly connected to each key management node for all key management nodes in the quantum key management layer.

[0173] In other words, the quantum cipher service device 100 searches / calculates all key management nodes in the quantum key management layer of the quantum cipher communication network as exemplified above and as shown in FIG. 5, and then, in the key pool of each key management node, pre-quantum keys to be shared by the corresponding key management node with all other key management nodes will be stored.

[0174] In this case, a method can be applied that maintains the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0175] Furthermore, the number of pre-generated quantum keys can be differentiated according to the distance between key management nodes. For example, a method can be applied where a large number of quantum keys are pre-generated for key management nodes that are close together, and a small number of quantum keys are pre-generated for key management nodes that are far apart.

[0176] Furthermore, it goes without saying that the number of pre-quantized quantum keys can be varied depending on the number of keys stored in the key pool of each key management node.

[0177] To aid in understanding the explanation, Figure 6, shown earlier, illustrates the quantum cryptography communication network structure according to the first embodiment.

[0178] The portion of the key pool shown in bold corresponds to the additional key pool compared to before the application of the pre-quantum key generation scheme.

[0179] For example, before applying the pre-quantum key generation scheme at key management node c, the neighboring quantum key (k) is shared with the neighboring key management nodes b and d. bc , k cd ) were managed in the key pool, but in the first embodiment, quantum keys (k ac , k ce These can also be pre-generated through any key relay scheme and stored in a key pool.

[0180] In this case, a method can be applied to maintain the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0181] Furthermore, the number of pre-generated quantum keys can be differentiated according to the distance between key management nodes. For example, a system can be applied in which a large number of quantum keys are pre-generated for key management nodes that are close together, and a small number of quantum keys are pre-generated for key management nodes that are far apart.

[0182] Furthermore, the number of pre-quantized quantum keys can be varied according to the number of keys stored in the key pool of each key management node, for example, k ab The number and k bc If the number is small, k ab and k bc k generated by relaying ac Only a small number can be pre-generated, on the other hand, k cd The number and k de If the number is sufficiently large, a large number of k ce It can be pre-generated.

[0183] Furthermore, in one embodiment of the present invention, a second embodiment can be adopted as a way to improve the quantum key resource efficiency of quantum cryptography communication, which involves generating computed subkeys between key management nodes at an arbitrary distance.

[0184] In other words, the quantum cryptography service device 100 generates a pre-quantum key between pairs of key management nodes at a distance (hop) predetermined by the quantum key management layer.

[0185] In other words, the pre-key generation unit 120 calculates the distance between all pairs of key management nodes in the quantum key management layer using an arbitrary path calculation algorithm for the given quantum cryptographic network topology as illustrated in Figure 7, and stores the pre-quantum key that the key management node shares with key management nodes at an n-hop distance in its key pool.

[0186] Here, the value of n can be freely selected by the user, may be a large number, and can be selected based on conditions such as network conditions and topology.

[0187] In this second embodiment, it is necessary to calculate the distance between each key management node in advance, and in this case, the Dijkstra shortest path calculation method or the like can be applied.

[0188] In this case, a method can be applied to maintain the number of pre-quantized keys generated between key management node pairs to be as identical as possible, and differences can be made depending on the number of keys stored in the key pool of each key management node.

[0189] To aid in understanding the explanation, Figure 8, shown earlier, illustrates the quantum cryptography communication network structure according to the second embodiment.

[0190] This illustrates the case where n is 2, and it goes without saying that it is not limited to this case.

[0191] The portion of the key pool shown in bold corresponds to the additional key pool compared to before the application of the pre-quantum key generation scheme.

[0192] For example, before applying the pre-quantum key generation scheme at key management node b, the neighboring quantum key (k) is shared with the adjacent key management nodes a and c. ab , k bc In the first embodiment, only the first key was managed in the key pool, but in the second embodiment, by applying a pre-quantum key generation scheme between all key management nodes, the quantum key (k) with key management node d at a 2-hop distance was generated. bd These can also be pre-generated through any key relay scheme and stored in a key pool.

[0193] In this case, a method can be applied to maintain the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0194] Furthermore, the number of pre-quantized quantum keys can be varied according to the number of keys stored in the key pool of each key management node, for example, k ab The number and k bc If the number is small, k ab and k bc k generated by relaying ac Only a small number can be pre-generated, on the other hand, k cd The number and k de If the number is sufficiently large, a large number of k ce It can be pre-generated.

[0195] Furthermore, in one embodiment of the present invention, a third embodiment can be adopted as a way to improve the quantum key resource efficiency of quantum cryptographic communication, in which a pre-quantum key is generated between all key management nodes directly connected to the service node.

[0196] In other words, the quantum cryptography service device 100 generates pre-quantum keys between all pairs of key management nodes that are directly connected to the service nodes of the service layer in the quantum key management layer.

[0197] In other words, the pre-key generation unit 120 searches for and computes the key management nodes of the quantum key management layer connected to each service node of the service layer in the quantum cryptographic communication network topology, as illustrated in Figure 9 above. Subsequently, the key pool of the key management nodes connected to the service nodes stores the pre-quantum key that is shared with the key management nodes connected to all other service nodes.

[0198] In this case, a method can be applied that maintains the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0199] Furthermore, the number of pre-generated quantum keys can be differentiated according to the distance between key management nodes. For example, a method can be applied where a large number of quantum keys are pre-generated for key management nodes that are close together, and a small number of quantum keys are pre-generated for key management nodes that are far apart.

[0200] Furthermore, it goes without saying that the number of pre-quantized quantum keys can be varied depending on the number of keys stored in the key pool of each key management node.

[0201] To aid in understanding the explanation, Figure 10, shown earlier, illustrates the quantum cryptography communication network structure according to the third embodiment.

[0202] In this case, the portion of the key pool shown in bold corresponds to the additional key pool compared to before the application of the pre-quantum key generation scheme.

[0203] For example, before applying the pre-quantum key generation scheme at key management node c, the neighboring quantum key (k) is shared with the neighboring key management nodes b and d. bc , k cdIn the third embodiment, where only the key pool was used to manage the quantum keys between the service node and all key management nodes directly connected to the service node, the quantum keys (k ac , k ce These can also be pre-generated through any key relay scheme and stored in a key pool.

[0204] On the other hand, key management nodes b and d do not store keys through pre-quantum key generation because they are not directly connected to any service nodes.

[0205] In this case, a method can be applied to maintain the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0206] Furthermore, the number of pre-generated quantum keys can be differentiated according to the distance between key management nodes. For example, a system can be applied in which a large number of quantum keys are pre-generated for key management nodes that are close together, and a small number of quantum keys are pre-generated for key management nodes that are far apart.

[0207] Furthermore, the number of pre-quantized quantum keys can be varied according to the number of keys stored in the key pool of each key management node, for example, k ab The number and k bc If the number is small, k ab and k bc k generated by relaying ac Only a small number can be pre-generated, on the other hand, k cd The number and k de If the number is sufficiently large, a large number of k ce It can be pre-generated.

[0208] Furthermore, in one embodiment of the present invention, as a way to improve the quantum key resource efficiency of quantum cryptographic communication, a fourth embodiment can be adopted in which a pre-quantum key is generated between a service node and a key management node directly connected at an arbitrary distance.

[0209] In other words, the quantum cryptography service device 100 generates a pre-quantum key between key management nodes that are directly connected to service nodes at a predefined distance (hop) between them in the service layer.

[0210] In other words, as illustrated in Figure 11 above, the pre-key generation unit 120 calculates the distance between service node pairs in the service layer of the quantum cryptography network topology through an arbitrary path calculation algorithm. Subsequently, the key pool of the key management node connected to the service node stores the pre-quantum key that is shared with the key management node connected to the service node at a distance of n hops from the relevant service node.

[0211] Here, the value of n can be freely selected by the user, may be a large number, and can be selected based on conditions such as network conditions and topology.

[0212] In this fourth embodiment, it is necessary to calculate the distance between each key management node in advance, and in this case, the Dijkstra shortest path calculation method or the like can be applied.

[0213] In this case, a method can be applied that maintains the number of pre-quantum keys generated between key management node pairs to be as identical as possible.

[0214] Furthermore, the number of pre-quantized quantum keys can be varied depending on the distance between key management nodes.

[0215] To aid in understanding the explanation, Figure 12, shown earlier, illustrates the quantum cryptography communication network structure according to the fourth embodiment.

[0216] This illustrates the case where n is 2, and it goes without saying that it is not limited to this case.

[0217] In this regard, n can be a large number and can be freely selected by the operator.

[0218] The bold - displayed part of the key pool corresponds to the additional key pool compared to before applying the pre - quantum key generation method.

[0219] For example, before applying the pre - quantum key generation method at key management node a, only the adjacent quantum key (k ab ) shared with the adjacent key management node b (the adjacent key management node) was managed in the key pool. However, in the fourth embodiment, by generating pre - quantum keys between pairs of key management nodes at an arbitrary (n) - hop distance among the key management nodes directly connected to the service node, the quantum key (k ae ) with the key management node e connected to the service node corresponding to a 2 - hop distance can also be pre - generated through an arbitrary key relay method and saved in the key pool.

[0220] At this time, a method can be applied to maintain the number of pre - quantum keys generated between pairs of key management nodes to be maximally the same.

[0221] Also, the number of pre - quantum keys can be differentiated according to the number of keys stored in the key pool of each key management node. For example, if the number of k ab , the number of k bc , the number of k cd , the number of k de is small, only a small number of k ab , k bc , k cd , k de pre - generated by relaying can be generated in advance. On the other hand, if the number of k ae , k ab , k bc , k cd , k de is large, a large number of k ae can be pre - generated.

[0222] Furthermore, in one embodiment of the present invention, as a solution for enhancing the quantum key resource efficiency of quantum cryptographic communication, a fifth embodiment applying an algorithm considering the number of quantum key relays can be adopted.

[0223] In other words, the quantum cryptography service device 100 generates pre-quantum keys in the quantum key management layer for key management node pairs that reduce the number of quantum key relays using pre-quantum keys to less than a threshold when generating quantum keys between arbitrary key management node pairs.

[0224] In other words, the quantum cryptography service device 100 applies an algorithm in the order shown in Figure 13, as illustrated earlier.

[0225] In the algorithm, G is an adjacency matrix representing the current connectivity state between key management nodes. G(a,b)=1 if key management nodes a and b are directly connected to each other, and 0 otherwise.

[0226] In other words, G can represent the key information stored in each key pool, for example, if G(a,b)=1, then the key pool of key management node a is the quantum key (k) between key management node a and key management node b. ab This means that it is saving (

[0227] In this case, due to the symmetry of the quantum key, if G(a,b) is 1, then G(b,a) is also 1.

[0228] The algorithm first selects key management node pairs i* and j* from the elements of the key management node set KM that satisfy the previously exemplified [Equation 1].

[0229] In other words, we select key management node pairs i* and j* that minimize the maximum number of key relays required to generate keys for all key management node pairs s and d, and then perform pre-quantum key generation for the i* and j* thus selected.

[0230] In other words, through the quantum key relay algorithm, k is added to the key pool of key management node i*. i*j* Generate and save it, and similarly, also add k to the key pool of key management node j*. i*j* Save it.

[0231] This updates G with the relevant information in order to perform pre-quantum key generation between key management nodes i* and j*.

[0232] after that,

number

[0233] In other words, the algorithm ensures an upper limit on the key request delay time for quantum cryptography communication by ensuring that the number of key relays between all key management node pairs does not exceed a certain threshold C.

[0234] The algorithm allows the threshold C to be set in various ways depending on the network conditions, user objectives, etc. Furthermore, the algorithm prevents excessive pre-quantum key generation by selecting key management node pairs one by one, thereby achieving more efficient quantum key resource utilization.

[0235] To aid in understanding the explanation, Figure 14, shown earlier, illustrates the quantum cryptography communication network structure according to the fifth embodiment.

[0236] When the algorithm first runs, G is represented as a directly connected state between key management nodes, that is, it contains information about keys in the key pool that are not in bold.

[0237] Therefore, only G(a,b), G(b,c), G(c,d), and G(d,e) are represented by 1, and the rest are represented by 0.

[0238] Subsequently, in addition to the given G information, one key management node pair is selected at a time, and if the quantum key between the corresponding key management node pair is pre-generated, the number of quantum key relays required for quantum key generation between the remaining key management nodes is calculated.

[0239] As a result, we select the node pair that minimizes the maximum number of quantum key relays.

[0240] In this regard, when key management nodes b and d are selected, the quantum key k between key management nodes a and e ae is k ab , k bd and k de are generated through the quantum key relay between them, so the number of relays is at most 3 times.

[0241] Therefore, the algorithm performs pre-quantum key generation between the selected key management nodes b and d, which is represented by the bold part of each key pool.

[0242] Since it is assumed that C is 4, the algorithm generates a pre-quantum key only between key management nodes b and d and then ends.

[0243] Through such a method, no matter which key management node pair generates a quantum key, it is guaranteed that the quantum key can be generated through no more than 3 quantum key relays, so the upper limit of the key request delay time due to quantum key relay calculation can be guaranteed.

[0244] After that, when a quantum encryption service request occurs at the service node of the service layer in the quantum encryption service device 100, the quantum encryption service device 100 generates / transmits a service quantum key for the end-to-end quantum encryption service of the service node (S140 - S160).

[0245] At this time, the quantum encryption service device 100 can transmit the pre-quantum key or the quantum key generated through the quantum key relay that consumes the pre-quantum key as the service quantum key for the end-to-end quantum encryption service of the service node according to the quantum encryption service request.

[0246] In this regard, in the first embodiment described above with reference to FIG. 6, when a quantum encryption service request occurs between service nodes a and e, the pre-quantum key (k ae) can be quickly transmitted to reduce the quantum cryptography service delay time, and in the second embodiment described earlier with reference to Figure 8, when a quantum cryptography service request occurs between service nodes a and e, k ab and k bd , and k de Relaying the service quantum key k ae This can be generated and transmitted to the service node.

[0247] Furthermore, in the third embodiment described earlier with reference to Figure 10, when a quantum cryptographic service request occurs between service nodes a and e, the pre-generated quantum key (k) stored in each key pool at service nodes a and e is used. ae ) can be quickly transmitted to reduce the delay time of quantum cryptography services, and in the fourth embodiment described earlier with reference to Figure 12, when a quantum cryptography service request occurs between service nodes a and e, the pre-quantum key (k) that has been generated in advance by service nodes a and e and stored in each key pool can be transmitted. ae This allows for rapid transmission of information, reducing the latency of quantum cryptography services.

[0248] Finally, in the fifth embodiment described earlier with reference to Figure 14, when a quantum cryptographic service request occurs between service nodes a and e, k ab and k bd , and k de Relaying the service quantum key k ae This can be generated and transmitted to the service node.

[0249] As discussed above, according to one embodiment of the present invention, a quantum cryptographic communication service method can be applied to the quantum cryptographic service, which applies a pre-quantum key generation method that pre-generates quantum keys between long-distance nodes. This reduces the quantum key support delay time due to quantum key relay, which is a drawback of quantum cryptographic communication compared to existing cryptographic communication, thereby achieving a low-latency quantum cryptographic service and enabling efficient utilization of expensive quantum resources.

[0250] In the specification of this disclosure (in particular the claims), the use of the term “the foregoing” and similar directive terms may be singular or plural. Furthermore, where a range is described in this disclosure, it includes inventions to which the individual values ​​belonging to that range are applied (unless otherwise stated), and is equivalent to describing each individual value constituting that range in the detailed description of the invention.

[0251] Unless otherwise stated, the steps constituting the method described herein may be performed in any order that is appropriate. The order in which the steps are described does not necessarily limit the scope of this disclosure. The use of all examples or exemplary terms (e.g., etc.) in this disclosure is simply for the purpose of detailing the disclosure and does not limit the scope of this disclosure unless it is limited by the claims. Furthermore, a person of ordinary skill will see that design conditions and factors can be constructed within the scope of the claims or their equivalents with various modifications, combinations, and changes.

[0252] Therefore, the concept of this disclosure should not be limited to the embodiments described above, and not only the claims described below, but also any scope equivalent to or equivalently modified from these claims, falls within the scope of the concept of this disclosure.

Claims

1. Memory containing instruction words; and A quantum cryptography service device comprising: a processor that, by executing the aforementioned instruction, generates adjacent quantum keys for all key management nodes in the quantum key management layer to be shared with other key management nodes directly connected to each key management node; and, when a particular pair of key management nodes that are not directly connected to each other is determined from the connection state between the key management nodes, generates a pre-quantum key to be shared between the particular pair of key management nodes through a quantum key relay that consumes the adjacent quantum keys of each key management node connecting the particular pair of key management nodes, before a quantum cryptography service request is made in the service layer;

2. The aforementioned processor, The quantum cryptography service device according to claim 1, characterized in that, when a quantum cryptography service request occurs, a pre-quantum key, or a quantum key generated through a quantum key relay that consumes the pre-quantum key, is transmitted as a service quantum key for the service node's end-to-end quantum cryptography service.

3. The aforementioned processor, The quantum cryptography service device according to claim 1, characterized in that all key management nodes in the quantum key management layer generate a pre-quantum key that is shared with all other key management nodes that are not directly connected to each key management node.

4. The aforementioned processor, The quantum cryptography service device according to claim 1, characterized in that a quantum key management layer generates a pre-quantum key between pairs of key management nodes at a predefined distance (hop).

5. The aforementioned processor, The quantum cryptography service device according to claim 1, characterized in that the quantum key management layer generates pre-quantum keys between all pairs of key management nodes directly connected to the service nodes of the service layer.

6. The aforementioned processor, The quantum cryptography service device according to claim 1, characterized in that it generates a pre-quantum key between a pair of key management nodes that are directly connected to a predefined distance (hop) between service nodes in the service layer.

7. The aforementioned processor, The quantum cryptography service device according to claim 1, characterized in that the quantum key management layer generates a pre-quantum key for a pair of key management nodes that reduces the number of quantum key relays using the pre-quantum key to less than a threshold when generating a quantum key between any pair of key management nodes.

8. In a quantum cryptographic communication service method performed by a quantum cryptographic service device, A neighboring quantum key generation step in the quantum key management layer that generates neighboring quantum keys to be shared with other key management nodes directly connected to each key management node; and A quantum cryptographic communication service method characterized by including a pre-quantum key generation step, which generates a pre-quantum key to be shared between a specific pair of key management nodes that do not have a direct connection to each other, through a quantum key relay that consumes the adjacent quantum keys of the key management nodes that connect the specific pair of key management nodes, before a quantum cryptographic service request is made at the service layer.

9. The aforementioned method, The quantum cryptographic communication service method according to claim 8, further comprising a service quantum key transfer step of transferring a pre-quantum key, or a quantum key generated through a quantum key relay that consumes the pre-quantum key, as a service quantum key for the service node's end-to-end quantum cryptographic service when a quantum cryptographic service request occurs.

10. The aforementioned pre-quantum key generation step is, The quantum cryptography communication service method according to claim 8, characterized in that all key management nodes in the quantum key management layer generate a pre-quantum key that is shared with all other key management nodes that are not directly connected to each key management node.

11. The aforementioned pre-quantum key generation step is, The quantum cryptography communication service method according to claim 8, characterized in that a pre-quantum key is generated between pairs of key management nodes at a predefined distance (hop) in the quantum key management layer.

12. The aforementioned pre-quantum key generation step is, The quantum cryptographic communication service method according to claim 8, characterized in that the quantum key management layer generates pre-quantum keys between all pairs of key management nodes directly connected to the service nodes of the service layer.

13. The aforementioned pre-quantum key generation step is, The quantum cryptography communication service method according to claim 8, characterized in that a pre-quantum key is generated between a pair of key management nodes that are directly connected to a service node at a predefined distance (hop) between the service nodes in the service layer.

14. The aforementioned pre-quantum key generation step is, The quantum cryptography communication service method according to claim 8, characterized in that the quantum key management layer generates a pre-quantum key for a pair of key management nodes that reduces the number of quantum key relays using the pre-quantum key to less than a threshold when generating a quantum key between any pair of key management nodes.

15. A computer program coupled with hardware and stored on a medium for performing the method of any one of claims 8 to 14.