Communication devices, communication systems, communication methods, and programs

The communication device and system address the issue of cryptographic key depletion by incorporating a generation, determination, and selection mechanism to use dummy keys when normal generation fails, maintaining secure communication.

JP2026069298APending Publication Date: 2026-04-23NEC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
NEC CORP
Filing Date
2024-10-11
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

In quantum key distribution systems, the generation of cryptographic keys may not proceed normally due to calibration procedures, recovery from failures, or noise in the communication path, leading to a decrease in the remaining amount of generated cryptographic keys, which are conventionally used despite this abnormality.

Method used

A communication device and system that includes a generation unit for creating encryption keys, a determination unit to assess the correctness of key generation, and a selection unit to choose between a first communication process using an authentication key generated from the encryption key or a second process that does not consume the encryption key, based on the determination result.

Benefits of technology

This configuration suppresses the decrease in the remaining amount of cryptographic keys even when normal generation is not occurring, ensuring secure communication by selectively using dummy keys when generation fails.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026069298000001_ABST
    Figure 2026069298000001_ABST
Patent Text Reader

Abstract

This technology provides a way to suppress the decrease in the remaining number of encryption keys, even if the generation of encryption keys does not proceed normally. [Solution] The communication device includes a generation means for generating an encryption key to be consumed in encrypted communication, a determination means for determining whether the generation of the encryption key by the generation means is performed correctly, and a selection means for selecting either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key, according to the determination result by the determination means.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a communication device, a communication system, a communication method, and a program.

Background Art

[0002] As a technology for ensuring high confidentiality in communication, a technology called Quantum Key Distribution (QKD) is known. In a quantum key distribution system (also called a QKD system) that performs quantum key distribution, by transmitting and receiving quantum states between communication devices via a communication channel capable of transmitting quantum states (also called a quantum communication channel), it is possible to share an encryption key with high confidentiality between communication devices. Various technologies related to quantum key distribution have been proposed. For example, Patent Document 1 discloses a technology aimed at performing one-time pad-based encrypted data communication using a shared application key and reducing the processing delay of the encryption key sharing operation.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In a QKD system, first, an authentication process is executed to authenticate whether each other is the correct communication partner using an authentication key (initial key) between the communication device on the transmission side (also called Alice) and the communication device on the reception side (also called Bob). When this initial authentication is successful, a key generation process is started between Alice and Bob. This authentication process is important for determining whether the key generation process is started between legitimate communication devices. Therefore, it is desirable that the authentication key be discarded once it is used.

[0005] On the other hand, in communication devices that constitute a QKD system, situations may arise where the generation of cryptographic keys used to generate authentication keys does not proceed normally, for example, due to calibration procedures, recovery work from failures, or the occurrence of faults or noise in the communication path. In conventional technologies described in Patent Document 1, etc., even in such cases, the cryptographic keys generated up to that point are used in the authentication process, which leads to a problem in that the remaining amount of generated cryptographic keys decreases.

[0006] This disclosure has been made in view of the above-mentioned problems, and one exemplary purpose thereof is to provide a technology that can suppress the decrease in the remaining amount of cryptographic keys even when cryptographic key generation does not occur normally. [Means for solving the problem]

[0007] A communication device relating to an exemplary aspect of this disclosure includes a generation means for generating an encryption key to be consumed in encrypted communication, a determination means for determining whether the generation of the encryption key by the generation means is performed correctly, and a selection means for selecting either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key, according to the determination result by the determination means.

[0008] An exemplary aspect of the communication system relating to this disclosure is a communication system including a first communication device and a second communication device, The first communication device comprises a first generation means for generating an encryption key to be consumed in encrypted communication, a first determination means for determining whether the generation of the encryption key by the first generation means is performed correctly, and a first selection means for selecting either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, according to the determination result by the first determination means. The second communication device includes a second generation means for generating an encryption key to be consumed in encrypted communication, a second determination means for determining whether the generation of the encryption key by the second generation means is performed correctly, and a second selection means for selecting either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, according to the determination result by the second determination means.

[0009] An exemplary communication method relating to this disclosure includes determining whether the generation of an encryption key by a generation means for generating an encryption key consumed in encrypted communication is being performed correctly, and selecting, according to the result of the determination, either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key.

[0010] An exemplary aspect of the present disclosure is a program that causes a computer to function as a communication control device, and causes the computer to perform a determination process to determine whether the generation of an encryption key by a generation means for generating an encryption key consumed in encrypted communication is being performed normally, and a selection process to select either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key, according to the determination result of the determination process. [Effects of the Invention]

[0011] According to an illustrative aspect of this disclosure, even if the generation of cryptographic keys does not proceed normally, the decrease in the remaining amount of cryptographic keys can be suppressed. [Brief explanation of the drawing]

[0012] [Figure 1] This is a block diagram showing the configuration of the communication device related to this disclosure. [Figure 2] This is a flowchart showing the flow of the communication method related to this disclosure. [Figure 3] This is a block diagram showing the configuration of the communication system related to this disclosure. [Figure 4] This is a block diagram showing the configuration of the communication system related to this disclosure. [Figure 5] This is a flowchart showing the flow of the communication method related to this disclosure. [Figure 6] This diagram illustrates an example of a key generation protocol related to this disclosure. [Figure 7] This block diagram shows the hardware configuration of the communication device related to this disclosure. [Modes for carrying out the invention]

[0013] The following are examples of embodiments of the present invention. However, the present invention is not limited to the exemplary embodiments shown below, and various modifications are possible within the scope of the claims. For example, embodiments obtained by appropriately combining some or all of the technologies (things or methods) employed in each of the exemplary embodiments shown below may also be included in the scope of the present invention. Furthermore, embodiments obtained by appropriately omitting some of the technologies employed in each of the exemplary embodiments shown below may also be included in the scope of the present invention. In addition, the effects mentioned in each of the exemplary embodiments shown below are examples of effects that can be expected in that exemplary embodiment and do not define the scope of the present invention. That is, embodiments that do not produce the effects mentioned in each of the exemplary embodiments shown below may also be included in the scope of the present invention.

[0014] [First Exemplary Embodiment] A first exemplary embodiment, which is an example of an embodiment of the present invention, will be described in detail with reference to the drawings. This exemplary embodiment is the basic form for each of the exemplary embodiments described later. The scope of application of each technology adopted in this exemplary embodiment is not limited to this exemplary embodiment. That is, each technology adopted in this exemplary embodiment can also be adopted in other exemplary embodiments included in this disclosure, to the extent that no particular technical problems occur. Furthermore, each technology shown in the drawings referenced to explain this exemplary embodiment can also be adopted in other exemplary embodiments included in this disclosure, to the extent that no particular technical problems occur.

[0015] (Configuration of the communication device) The configuration of the communication device 1 according to this exemplary embodiment will be described with reference to FIG. 1. The communication device 1 is, as an example, a communication device that constitutes a quantum key distribution (QKD: Quantum Key Distribution) system that executes quantum key distribution (also referred to as a QKD system). As shown in FIG. 1, it includes a generation unit 11, a determination unit 12, and a selection unit 13. The communication device 1 may also be referred to as a quantum key distribution device or a QKD device.

[0016] (Generation unit 11) The generation unit 11 generates an encryption key consumed in encrypted communication. As an example, the generation unit 11 is connected to the key generation unit of the communication device on the other side via a communication path capable of transmitting a quantum state (also referred to as a quantum communication path), and generates an encryption key shared with the key generation unit on the other side according to a predetermined key generation protocol. The generation unit 11 accumulates the generated encryption key. Further, the encrypted communication that consumes the generated encryption key may include, as an example, an authentication process included in the predetermined key generation protocol by the generation unit 11, or an authentication process separately executed outside the key generation protocol, but this does not limit this exemplary embodiment.

[0017] (Determination unit 12) The determination unit 12 determines whether the generation of the encryption key by the generation unit 11 is being performed normally. As an example, the determination unit 12 may be configured to determine whether the generation of the encryption key by the generation unit 11 is being performed normally by referring to the remaining amount of the generated encryption key accumulated in the generation unit 11. As an example, the determination unit 12 · determines that the generation of the encryption key by the generation unit 11 is being performed normally when the manner of decrease in the remaining amount of the generated encryption key satisfies a predetermined condition, · may determine that the generation of the encryption key by the generation unit 11 is not being performed normally when the manner of decrease in the remaining amount of the generated encryption key does not satisfy a predetermined condition.

[0018] Furthermore, the determination unit 12 can be controlled from the control unit of the communication device or from outside the communication device. • Whether calibration is currently being performed or not Whether or not recovery work is underway from a malfunction, • Presence or absence of interference or noise in the communication channel The configuration may include obtaining information related to the above and, by referring to the obtained information, determining whether the generation of the encryption key by the generation unit 11 has been performed successfully. For example, the determination unit 12 may determine that the obtained information is Calibration is in progress. • Recovery work is underway following a malfunction. • There are interferences or noise in the communication channel. If this is indicated, it may be determined that the generation of the encryption key by the generation unit 11 has not been performed correctly. However, these examples are not limited to the exemplary embodiments described herein.

[0019] (Selection section 13) The selection unit 13 selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, according to the determination result by the determination unit 12. As an example, the selection unit 13 selects: If the determination unit 12 determines that the generation of the encryption key has been performed successfully, it selects the first communication process. If the determination unit 12 determines that the generation of the encryption key has not been performed correctly, it selects the second communication process. The following process is performed. Here, the first communication process is an example of encrypted communication as described above. The second communication process may also be considered an example of encrypted communication as described above. However, in the second communication process, the encryption key generated by the generation unit 11 is not consumed.

[0020] Furthermore, the second communication process may also be a communication process using a second authentication key, which is an authentication key generated without using the encryption key. Here, the second authentication key is also called a dummy key, and as an example, it is an authentication key generated independently of the encryption key. The dummy key may be a fixed key, such as a key composed entirely of zeros, or it may be randomly generated.

[0021] The communication processing selected by the selection unit 13 is, for example, executed in an authentication process included in the key generation protocol executed by the generation unit 11 described above, or in an authentication process associated with said key generation protocol. Furthermore, said authentication process includes, for example, message authentication. More specifically, said authentication process includes sending and receiving a message authentication code (MAC). However, these examples are not limiting to this exemplary embodiment.

[0022] (Effects of communication devices) As described above, the communication device 1 employs a configuration that includes a generation unit 11 that generates an encryption key to be consumed in encrypted communication, a determination unit 12 that determines whether the generation of the encryption key by the generation unit 11 is performed correctly, and a selection unit 13 that, according to the determination result by the determination unit 12, selects either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key.

[0023] According to the above configuration, the determination unit 12 selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, in accordance with the determination result. Therefore, even if the generation unit 11 does not generate the encryption key properly, the decrease in the remaining amount of encryption keys can be suppressed.

[0024] (Communication method flow) The flow of the communication method S1 according to this exemplary embodiment will be explained with reference to Figure 2. Figure 2 is a flowchart showing the flow of the communication method S1. As an example, the communication method S1 is executed by the communication device 1 described above. As shown in Figure 2, the communication method S1 includes a determination process (process, step) S12 and a selection process (process, step) S13.

[0025] (Step S12) In step S12, the determination unit 12 of the communication device 1 determines whether the generation of the encryption key by the generation unit 11, which generates the encryption key consumed in encrypted communication, has been performed correctly. The encryption key generation process by the generation unit 11 and the determination process by the determination unit 12 have been described above, so they will not be explained here.

[0026] (Step S13) Next, in step S13, the selection unit 13 of the communication device 1 selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, according to the determination result in step S12. The specific processing by the selection unit 13 has been described above, so it will not be explained here.

[0027] (Effectiveness of communication methods) As described above, the communication method S1 includes determining whether the generation of an encryption key by the generation means that generates the encryption key consumed in encrypted communication is being performed correctly, and selecting either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, according to the result of the determination. With the above configuration, the same effect as the communication device 1 is achieved.

[0028] (Communication system configuration) Next, the configuration of the communication system 100 according to this exemplary embodiment will be described with reference to Figure 3. As shown in Figure 3, the communication system 100 includes a first communication device 1-1 and a second communication device 1-2. Also, as shown in Figure 3, the first communication device 1-1 and the second communication device 1-2 are connected to each other via communication paths P1 and P2.

[0029] Here, channel P1 is a communication channel capable of transmitting quantum states (a quantum communication channel). On the other hand, channel P2 is a communication channel prepared separately from channel P1, and does not need to be configured to transmit quantum states; it is also called a classical communication channel.

[0030] (First communication device) As shown in Figure 3, the first communication device 1-1 includes a generation unit 11-1, a determination unit 12-1, and a selection unit 13-1. The generation unit 11-1, the determination unit 12-1, and the selection unit 13-1 are sometimes referred to as the first generation unit 11-1, the first determination unit 12-1, and the first selection unit 13-1, respectively.

[0031] (Generation section 11-1) The generation unit 11-1 generates an encryption key to be consumed in encrypted communication. The generation unit 11-1 is connected to the generation unit 11-2 of the second communication device 1-2 via the quantum communication channel P1 described above, and generates an encryption key to be shared with the generation unit 11-2 according to a predetermined key generation protocol. The generation unit 11-1 stores the generated encryption key. The encrypted communication that consumes the generated encryption key may, for example, include an authentication process included in the predetermined key generation protocol by the generation unit 11-1, or an authentication process associated with the key generation protocol, but this does not limit the present exemplary embodiment.

[0032] (Judgment section 12-1) The determination unit 12-1 determines whether the generation of encryption keys by the generation unit 11-1 is being performed correctly. For example, the determination unit 12-1 may be configured to determine whether the generation of encryption keys by the generation unit 11-1 is being performed correctly by referring to the remaining amount of generated encryption keys stored in the generation unit 11-1. For example, the determination unit 12-1, If the rate at which the remaining amount of the generated encryption key decreases satisfies predetermined conditions, it is determined that the generation of encryption keys by the generation unit 11-1 is being performed normally. If the rate at which the remaining amount of the generated encryption key decreases does not meet predetermined conditions, it may be determined that the generation of the encryption key by the generation unit 11-1 has not been performed correctly.

[0033] Furthermore, the determination unit 12-1, similar to the determination unit 12 provided in the communication device 1 described with reference to Figure 1, can be accessed from the control unit provided in the communication device 1-1 or from outside the communication device 1-1. • Whether calibration is currently being performed or not Whether or not recovery work is underway from a malfunction, • Presence or absence of interference or noise in the communication channel The system may also be configured to obtain information related to the above, and then, by referring to the obtained information, determine whether the generation of the encryption key by the generation unit 11-1 has been performed successfully.

[0034] (Selection Section 13-1) The selection unit 13-1 selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, according to the determination result by the determination unit 12-1. As an example, the selection unit 13-1 selects: If the determination unit 12-1 determines that the generation of the encryption key has been performed successfully, it selects the first communication process. If the determination unit 12-1 determines that the generation of the encryption key has not been performed correctly, it selects the second communication process. The following process is performed. Here, the first communication process is an example of encrypted communication as described above. The second communication process may also be considered an example of encrypted communication as described above. However, in the second communication process, the encryption key generated by the generation unit 11-1 is not consumed.

[0035] Furthermore, the second communication process may also be a communication process using a second authentication key, which is an authentication key generated without using the encryption key. Here, the second authentication key is also called a dummy key, and as an example, it is an authentication key that is randomly generated independently of the encryption key.

[0036] The communication process selected by the selection unit 13-1 is, for example, executed in an authentication process included in the key generation protocol executed by the generation unit 11-1 described above, or in an authentication process associated with said key generation protocol. Furthermore, the authentication process includes, for example, message authentication. More specifically, the authentication process includes sending and receiving a message authentication code (MAC). The communication process selected by the selection unit 13-1 is also executed via the classical communication channel P2, for example. However, these examples are not limiting to this exemplary embodiment.

[0037] (Second communication device) As shown in Figure 3, the second communication device 1-2 includes a generation unit 11-2, a determination unit 12-2, and a selection unit 13-2. The generation unit 11-2, the determination unit 12-2, and the selection unit 13-2 are sometimes referred to as the second generation unit 11-2, the second determination unit 12-2, and the second selection unit 13-2, respectively.

[0038] (Generation section 11-2) The generation unit 11-2 generates an encryption key to be consumed in encrypted communication. The generation unit 11-2 is connected to the generation unit 11-1 of the first communication device 1-1 via the quantum communication channel P1 described above, and generates an encryption key to be shared with the generation unit 11-1 according to a predetermined key generation protocol. The generation unit 11-2 stores the generated encryption key. The encrypted communication that consumes the generated encryption key may, for example, include an authentication process included in the predetermined key generation protocol by the generation unit 11-2, or an authentication process associated with the key generation protocol, but this does not limit the present exemplary embodiment.

[0039] (Judgment section 12-2) The determination unit 12-2 determines whether the generation of encryption keys by the generation unit 11-2 is being performed correctly. For example, the determination unit 12-2 may be configured to determine whether the generation of encryption keys by the generation unit 11-2 is being performed correctly by referring to the remaining amount of generated encryption keys stored in the generation unit 11-2. The determination process by the determination unit 12-2 is the same as the determination process by the determination unit 12-1 described above, so redundant explanations will be omitted. It is preferable that the determination logic in the determination unit 12-2 is the same as the determination logic in the determination unit 12-1.

[0040] (Selection section 13-2) The selection unit 13-2 selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, according to the determination result by the determination unit 12-2. As an example, the selection unit 13-2 selects: If the determination unit 12-2 determines that the generation of the encryption key has been performed successfully, it selects the first communication process. If the determination unit 12-2 determines that the generation of the encryption key has not been performed correctly, it selects the second communication process. The following process is performed. The selection process by selection unit 13-2 is the same as the selection process by selection unit 13-1, so redundant explanations are omitted. Preferably, the selection logic in selection unit 13-2 is the same as the selection logic in selection unit 13-1.

[0041] (Effects of communication systems) As described above, the communication system 100 comprises a first communication device 1-1 and a second communication device 1-2, and the first communication device 1-1 is A first generation unit 11-1 generates an encryption key to be used in encrypted communication, A first determination unit 12-1 determines whether the generation of the encryption key by the first generation unit 11-1 is performed correctly, A first selection unit 13-1 selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, in accordance with the determination result by the first determination unit 12-1. The second communication device 1-2 is equipped with, A second generation unit 11-2 generates an encryption key that is consumed in encrypted communication, A second determination unit 12-2 determines whether the generation of the encryption key by the second generation unit 11-2 is performed correctly, A second selection unit 13-2 selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, in accordance with the determination result by the second determination unit 12-2. The configuration adopted includes the following features.

[0042] According to the above configuration, the first selection unit 13-1 selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, depending on the determination result by the first determination unit 12-1. Similarly, the second selection unit 13-2 selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, depending on the determination result by the second determination unit 12-2. Therefore, according to the above configuration, even if the generation of the encryption key does not proceed normally, the decrease in the remaining amount of encryption keys can be suppressed.

[0043] [Second exemplary embodiment] A second exemplary embodiment, which is an example of an embodiment of the present invention, will be described in detail with reference to the drawings. Components having the same function as those described in the above-described exemplary embodiment are denoted by the same reference numerals, and their descriptions are omitted as appropriate. The scope of application of each technology adopted in this exemplary embodiment is not limited to this exemplary embodiment. That is, each technology adopted in this exemplary embodiment can also be adopted in other exemplary embodiments included in this disclosure, to the extent that no particular technical problems arise. Furthermore, each technology shown in the drawings referenced to describe this exemplary embodiment can also be adopted in other exemplary embodiments included in this disclosure, to the extent that no particular technical problems arise.

[0044] <Communication System Configuration> The configuration of the communication system 100A according to this exemplary embodiment will be described with reference to Figure 4. Figure 4 is a block diagram showing the configuration of the communication system 100A. As shown in Figure 3, the communication system 100A includes communication device 1A-1 and communication device 1A-2. Communication device 1A-1 and communication device 1A-2 are sometimes referred to as the first communication device 1A-1 and the second communication device 1A-2, respectively.

[0045] As shown in Figure 4, communication devices 1A-1 and 1A-2 are connected to each other via communication channels P1 and P2. Communication channel P1 is a communication channel capable of transmitting quantum states (quantum communication channel). To enable the transmission of photons while maintaining their quantum state, communication channel P1 can be realized, for example, by a dedicated optical fiber. However, this does not limit the present exemplary embodiment. On the other hand, communication channel P2 is a communication channel prepared separately from communication channel P1, and does not need to be configured to transmit quantum states; it is also called a classical communication channel. Communication channel P2 can be realized, for example, by an optical fiber with an amplifier.

[0046] (Communication device 1A-1, communication device 1A-2) As shown in Figure 4, communication device 1A-1, as an example, comprises a generation unit 11-1, a determination unit 12-1, a selection unit 13-1, an execution unit 14-1, a management unit 15-1, an input / output unit 16-1, and a storage unit 20-1. Here, the selection unit 13-1 and the execution unit 14-1 constitute the encrypted communication unit 10-1. Similarly, communication device 1A-2, as an example, comprises a generation unit 11-2, a determination unit 12-2, a selection unit 13-2, an execution unit 14-2, a management unit 15-2, an input / output unit 16-2, and a storage unit 20-2. Here, the selection unit 13-2 and the execution unit 14-2 constitute the encrypted communication unit 10-2.

[0047] In the following explanation, we will use an index i or j (i=1 or 2, j=1 or 2) to indicate the branch number, and refer to the generation unit 11-i, determination unit 12-i, selection unit 13-i, execution unit 14-i, management unit 15-i, input / output unit 16-i, and storage unit 20-i, etc. For example, generation unit 11-i refers to generation unit 11-1 or generation unit 11-2. The same applies to the other blocks.

[0048] (Generation unit 11-i) The generation unit 11-i generates the encryption key EK that is consumed in encrypted communication. The generation unit 11-i is connected to the generation unit 11-j (j≠i) of the j-th communication device 1A-j via the quantum communication channel P1 described above, and generates the encryption key EK to be shared with the generation unit 11-j according to a predetermined key generation protocol. The generation unit 11-i supplies the generated encryption key EK to the storage unit 20-i, where the encryption key EK is stored.

[0049] Furthermore, the encrypted communication that consumes the generated encryption key EK may, for example, include an authentication process included in the predetermined key generation protocol by the generation unit 11-i, or an authentication process associated with the key generation protocol, but this does not limit the present exemplary embodiment. Also, please note that in this exemplary embodiment, the terms "communication processing" and "encrypted communication" refer to authentication of the classical communication channel used for key generation, and not to "encrypted communication (as an application) after key generation."

[0050] Furthermore, the generation unit 11-i generates an authentication key AK from the generated encryption key EK and stores the generated authentication key AK in the storage unit 20-i. Here, the specific example of the authentication key AK generation process by the generation unit 11-i is not limited to this exemplary embodiment, but as an example, the generation unit 11-i can be configured to generate the authentication key AK by extracting a part of the generated encryption key EK. A specific example of the key generation protocol executed between the generation unit 11-i and the generation unit 11-j (j≠i) will be described later with different reference drawings.

[0051] (Judgment part 12-i) The determination unit 12-i determines whether the generation of the encryption key EK by the generation unit 11-i is performed correctly. For example, the determination unit 12-i may be configured to determine whether the generation of the encryption key by the generation unit 11-i is performed correctly by referring to the remaining amount of generated encryption keys EK that have been generated by the generation unit 11-i and stored in the storage unit 20-i. For example, the determination unit 12-i, similar to exemplary embodiment 1, If the rate at which the remaining amount of the generated encryption key decreases satisfies predetermined conditions, it is determined that the generation of the encryption key EK by the generation unit 11-i is being performed normally. If the rate at which the remaining amount of the generated encryption key decreases does not meet predetermined conditions, it may be determined that the generation of the encryption key EK by the generation unit 11-i has not been performed correctly.

[0052] For example, the determination unit 12-i includes a monitor unit 120-i that monitors the remaining amount of generated encryption keys EK stored in the storage unit 20-i at predetermined time intervals. If the change in the remaining amount of encryption key EK monitored by the monitoring unit 120-i is greater than or equal to a predetermined threshold, it is determined that the generation of encryption key EK by the generation unit 11-i is being performed normally. If the change in the remaining amount of encryption key EK monitored by the monitoring unit 120-i is below a predetermined threshold, it may be determined that the generation of encryption key EK by the generation unit 11-i has not been performed correctly.

[0053] Alternatively, the determination unit 12-i compares the amount of encryption key EK generated (supplied) by the generation unit 11-i with the amount of encryption key EK consumed in encrypted communication. • If the above supply of encryption keys EK exceeds the above consumption of encryption keys EK, it is determined that the generation of encryption keys EK is being performed normally. If this is not the case, you may conclude that the generation of the encryption key (EK) has not been performed correctly.

[0054] Furthermore, the determination unit 12-i, similar to the exemplary embodiment 1, receives information from the management unit 15-i or input / output unit 16-i of the communication device 1A-i. • Whether calibration is currently being performed or not Whether or not recovery work is underway from a malfunction, • Presence or absence of interference or noise in the communication channel The system may also be configured to obtain information related to the above, and then use that information to determine whether the generation of the encryption key by the generation unit 11-i has been performed correctly.

[0055] Furthermore, the determination unit 12-i may be configured to receive a notification from the other party's communication device 1A-j (j≠i) indicating that the encryption key generation has not been performed correctly, and to determine whether the encryption key generation by the generation unit 11-i has been performed correctly when it receives such a notification. Correspondingly, the determination unit 12-i may be configured to notify the determination unit 12-j of the other party's communication device 1A-j (j≠i) that the encryption key generation has not been performed correctly when it determines that the encryption key generation by the generation unit 11-i has not been performed correctly.

[0056] (Selection section 13-i) The selection unit 13-i selects either a first communication process using a first authentication key, which is an authentication key AK generated from the encryption key EK, or a second communication process that does not consume the encryption key EK, according to the determination result by the determination unit 12-i. As an example, the selection unit 13-i selects: If the determination unit 12-i determines that the generation of the encryption key EK has been performed successfully, it selects the first communication process. If the determination unit 12-i determines that the generation of the encryption key EK has not been performed correctly, it selects the second communication process. The following process is performed. Here, the first communication process is an example of encrypted communication as described above. The second communication process may also be considered an example of encrypted communication as described above. However, in the second communication process, the encryption key generated by the generation unit 11-i is not consumed.

[0057] Furthermore, the second communication process may be a communication process using a second authentication key DAK, which is an authentication key generated without using the encryption key EK. Here, the second authentication key is also called a dummy key DAK, and as an example, it is an authentication key randomly generated by the generation unit 11-i independently of the encryption key EK. Alternatively, an authentication key predetermined as a dummy key DAK may be stored in the storage unit 20-i, and the selection unit 13-i may read and use the dummy key DAK. Alternatively, multiple authentication keys predetermined as candidates for dummy key DAK may be stored in the storage unit 20-i, and the selection unit 13-i may select one of the authentication keys based on a predetermined selection logic, and the selected authentication key may be used as the dummy key DAK. In this configuration, the selection units 13-1 and 13-2 • Multiple candidates for dummy key DAK • The above selection logic It is preferable to use the same type.

[0058] The communication process selected by the selection unit 13-i is, for example, executed in an authentication process included in the key generation protocol executed by the generation unit 11-i between itself and the generation unit 11-j (j≠i), or in an authentication process associated with the key generation protocol. These authentication processes may also be executed via the execution unit 14-i, which will be described later. The authentication process includes, for example, message authentication between the generation unit 11-i and the generation unit 11-j (j≠i). More specifically, the authentication process includes sending and receiving a message authentication code (MAC) between the generation unit 11-i and the generation unit 11-j (j≠i). The communication process selected by the selection unit 13-i is also executed via the classical communication channel P2, for example. However, these examples do not limit this exemplary embodiment.

[0059] (Execution Unit 14-i) The execution unit 14-i executes the communication process (the first communication process or the second communication process) selected by the selection unit 13-i. The execution unit 14-i may be configured as part of the generation unit 11-i described above.

[0060] Furthermore, the execution unit 14-i may be configured to perform a security verification process in the first communication process, or prior to the first communication process, when the determination unit 12-i determines that the generation of the encryption key EK has not been performed normally, and then determines that the generation of the encryption key EK has become normal (i.e., when calibration is completed or recovery from a failure or malfunction has been achieved). As an example, the execution unit 14-i may perform the security verification process as follows: • Process to verify whether calibration was performed correctly. • A process to confirm that the system has recovered properly from a malfunction or failure. The following may be performed. Specifically, the amount of encryption key EK generated (supplied) by the generation unit 11-i may be compared with the amount of encryption key EK consumed in encrypted communication, and a process may be performed to confirm whether the amount of encryption key EK supplied exceeds the amount of encryption key EK consumed. In addition, a process may be performed to confirm that the number of photons detected and the bit error rate on the receiving side are at normal values.

[0061] (Management Department 15-i) The management unit 15-i manages the operation of each component of the communication device 1A-i. The management unit 15-i may also be described as a control unit that controls the operation of each component of the communication device 1A-i. For example, when the management unit 15-i receives an instruction from the input / output unit 16-1 (described later) to start calibration, it changes the operating mode of the communication device 1A-i to calibration mode.

[0062] Furthermore, the management unit 15-i refers to information from the generation unit 11-i or the execution unit 14-i, or refers to information received by the input / output unit 16-i, Whether or not recovery work is underway from a malfunction, • Presence or absence of interference or noise in the communication channel The configuration may be such that it can be identified.

[0063] (I / O section 16-i) The input / output unit 16-i is connected to input / output devices such as a keyboard, mouse, display, printer, and touch panel, as an example. The input / output unit 16-i receives various types of information from the connected input devices to the communication device 1A-1. The input / output unit 16-i also outputs various types of information to the connected output devices under the control of the management unit 15-i. An interface such as USB (Universal Serial Bus) can be used for the input / output unit 16-i.

[0064] (Processing flow in communication device 1A-i) Next, we will explain the processing flow in communication device 1A-i by referring to Figure 5. Figure 5 is a flowchart showing the processing flow in communication device 1A-i.

[0065] (Step S12a) In step S12a, the monitor unit 120-i of the determination unit 12-i acquires monitor information. Here, the monitor information includes: • Remaining amount of generated encryption keys stored in generation unit 11-i • Whether calibration is currently being performed or not • Whether or not recovery work is underway from a malfunction. • Presence or absence of interference or noise in the communication channel It contains at least one of the following pieces of information.

[0066] (Step S12b) Next, in step S12b, the determination unit 12-i refers to the monitor information obtained in step S12a and determines whether the generation unit 11-i has successfully generated the encryption key. The specific determination process by the determination unit 12-i has been described above, so it will not be explained here. If it is determined that the generation unit 11-i has successfully generated the encryption key (YES in step S12b), the process proceeds to step S13a; otherwise (NO in step S12b), the process proceeds to step S13b.

[0067] (Step S13a) If it is determined in step S12b that the cryptographic key generation has been performed successfully, in step S13a, the selection unit 13-i selects the authentication key AK. Here, the authentication key AK is an authentication key generated from the cryptographic key EK generated by the generation unit 11-i according to a predetermined key generation protocol.

[0068] (Step S13b) On the other hand, if it is determined in step S12b that the generation of the encryption key has not been performed correctly, in step S13b, the selection unit 13-i selects a dummy authentication key DAK. Here, the dummy key DAK is, as an example, an authentication key that is randomly generated independently of the encryption key EK, as described above.

[0069] (Step S14) In step S14, the generation unit 11-i (or 14-i) performs message authentication with the other communication device 1A-j (j≠i) using the authentication key (authentication key AK or dummy authentication key DAK) selected in step S13a or step S13b.

[0070] (Effects of communication system 100A) As explained above, the communication device 1A-i provided in the communication system 100A is A generation unit 11-i generates encryption keys that are consumed in encrypted communication, A determination unit 12-i determines whether the generation of the encryption key by the generation unit 11-i is performed correctly, A selection unit 13-i selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, in accordance with the determination result by the determination unit 12-i. It is equipped with this feature. Therefore, with the above configuration, even if the generation of the encryption key does not proceed normally, the decrease in the remaining amount of encryption keys can be suppressed.

[0071] (Example of a key generation protocol) The following describes an example of a key generation protocol executed by generation units 11-1 and 11-2, with reference to Figure 6. In the following example, generation unit 11-1 is the transmitter (Alice) and generation unit 11-2 is the receiver (Bob), and a representative protocol called the BB84 protocol is used as an example. The quantum cryptography key distribution algorithm will be used as an example. However, this example is not intended to limit the scope of this exemplary embodiment.

[0072] As shown in Figure 6, in QKD, a generator (key generator) 11-1 (Alice) and a generator (key generator) 11-2 (Bob), connected by a quantum communication channel P1, constitute an optical interferometer, and Alice and Bob randomly apply phase modulation to each photon. An output of 0 or 1 is obtained by the difference in the modulation phase depth, and then by comparing a part of the conditions when the output data was measured between Alice and Bob, it is finally possible to share the same bit sequence between Alice and Bob. Here, four quantum states are used, and the key generator 11-1 (Alice) has two random number sources (R1 and R2), • On the other hand, the random number R1 represents the encryption key data, either 0 or 1. • The other random number R2 is used to determine how to code the information from the random number R1. It shall be considered as such.

[0073] More specifically, in a quantum cryptography key distribution method that uses the phase difference between two coherent pulses to code four states, A coding set (hereinafter also referred to as the "X basis") where phase 0 represents the encryption key "0" and phase π represents the encryption key "1", A coding set (hereinafter also referred to as the "Y basis") where phase π / 2 represents the encryption key "0" and phase 3π / 2 represents the encryption key "1", Two sets of basis vectors are selected using a random number R2. In other words, the key generation unit 11-1 (Alice) randomly applies one photon to four different modulations: 0, π / 2, π, and 3π / 2, and transmits the modulated photon to the key generation unit 11-2 (Bob).

[0074] In the lower left of Figure 6, Table T1 is shown as an example of such transmission, illustrating the data (random number R1), basis (random number R2), and phase associated with each photon from No. 1 to No. 8. For example, as shown in Table T1, the No. 1 photon is given a phase π using the basis X, and the encryption key data 1 is transmitted to the key generation unit 11-2 (Bob) by this photon.

[0075] Meanwhile, the key generation unit 11-2 (Bob) has a random number source (random number R3) corresponding to the basis and decodes the photons sent from the key generation unit 11-1 (Alice). If the value of random number R3 is "0", the photon is modulated with phase 0 (X basis), and if it is "1", it is modulated with phase π / 2 (Y basis). The random number obtained as the output of the optical interferometer is called random number R4.

[0076] If the modulation bases applied by both key generation unit 11-1 (Alice) and key generation unit 11-2 (Bob) are the same (random number R2 = random number R3), key generation unit 11-2 (Bob) can correctly detect the value of random number R1 (i.e., random number R1 = random number R4). On the other hand, if the modulation bases applied by the two are different (random number R2 ≠ random number R3), key generation unit 11-2 (Bob) will randomly obtain a value of 0 or 1 as random number R4, regardless of the value of random number R1.

[0077] In the lower right of Figure 6, Table T2 is shown as an example of such reception, displaying the selected basis (R3), phase, and output (R4) for each photon from No. 1 to No. 8 shown in Table T1 above. For example, as shown in Table T2, for photon No. 1 transmitted from key generation unit 11-1 (Alice), basis X and phase 0 are selected, and the encryption key data 1 is decoded as the output (R4).

[0078] Since the random numbers R1, R2, and R3 are all random numbers that change bit by bit, the probability of the bases matching and the probability of them not matching are both 50%. However, in subsequent processing, for example, by performing basis reconciliation via classical channel P2, bits that do not match the bases are removed, so key generation units 11-1 (Alice) and 11-2 (Bob) can share the 0 / 1 bit sequence corresponding to the random number R1.

[0079] In this way, the random numbers shared between the key generation unit 11-1 (Alice) and the key generation unit 11-2 (Bob) are stored as the encryption key EK in their respective memory units 20-1 and 20-2, and used to generate the authentication key AK.

[0080] [Examples of implementation using software] Some or all of the functions of communication devices 1, 1-1, 1-2, 1A-1, and 1A-2 (hereinafter also referred to as "each of the above devices") may be implemented by hardware such as integrated circuits (IC chips) or by software.

[0081] In the latter case, each of the above devices is implemented by a computer that executes instructions for a program, which is software that realizes each function. An example of such a communication device 1, 1-1, 1-2, 1A-1, 1A-2 (hereinafter referred to as device A with computer C) is shown in Figure 7. Figure 7 is a block diagram showing the hardware configuration including computer C that functions as each of the above devices.

[0082] Computer C functions as a communication control device. More specifically, computer C functions, for example, as a determination unit 12, 12-1, a selection unit 13, 13-1, and a management unit 15-1. Computer C may also perform some of the functions of the execution unit 14-1 described above. Furthermore, an optical processing device D is connected to computer C, for example, via bus B, and the optical processing device D functions, for example, as the generation unit 11, 11-1 described above.

[0083] Computer C comprises at least one processor C1 and at least one memory C2. Memory C2 stores a program P that causes computer C to operate as each of the above-mentioned devices. In computer C, processor C1 reads program P from memory C2 and executes it, thereby realizing each of the above-mentioned devices.

[0084] As an example, program P is a program that causes a computer to function as a communication control device, and the computer, A determination process to determine whether the generation of encryption keys used in encrypted communication by the generation means is being performed correctly, Depending on the determination result from the aforementioned determination process, a selection process is performed to select either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key. This is a program that executes [the command / action].

[0085] For processor C1, for example, a CPU (Central Processing Unit), GPU (Graphic Processing Unit), DSP (Digital Signal Processor), MPU (Micro Processing Unit), FPU (Floating Point Number Processing Unit), PPU (Physics Processing Unit), TPU (Tensor Processing Unit), quantum processor, microcontroller, or a combination thereof can be used. For memory C2, for example, flash memory, HDD (Hard Disk Drive), SSD (Solid State Drive), or a combination thereof can be used.

[0086] Computer C may also be equipped with RAM (Random Access Memory) for loading program P at runtime and for temporarily storing various data. Furthermore, computer C may be equipped with communication interfaces for sending and receiving data with other devices. Additionally, computer C may be equipped with input / output interfaces for connecting input / output devices such as keyboards, mice, displays, and printers.

[0087] Furthermore, program P can be recorded on a non-temporary, tangible recording medium M that is readable by computer C. Such a recording medium M could be, for example, tape, disk, card, semiconductor memory, or programmable logic circuitry. Computer C can acquire program P via such a recording medium M. Program P can also be transmitted via a transmission medium. Such a transmission medium could be, for example, a communication network or broadcast waves. Computer C can also acquire program P via such a transmission medium.

[0088] Furthermore, each of the above functions of each of the above devices may be implemented by a single processor in a single computer, by multiple processors in a single computer working together, or by multiple processors in each of multiple computers working together. In addition, the programs for implementing each of the above functions in each of the above devices may be stored in a single memory in a single computer, distributed and stored in multiple memories in a single computer, or distributed and stored in multiple memories in each of multiple computers.

[0089] [Additional Note A] This disclosure includes the technologies described in the following appendices. However, the present invention is not limited to the technologies described in the following appendices, and various modifications are possible within the scope of the claims.

[0090] (Note A1) A generation means for generating encryption keys consumed in encrypted communication, A determination means for determining whether the generation of the encryption key by the generation means has been performed successfully, A selection means that, in accordance with the determination result by the determination means, selects either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key. A communication device equipped with the following features.

[0091] (Appendix A2) The aforementioned selection means is, If the determination means determines that the generation of the encryption key has been performed successfully, it selects the first communication process, If the determination means determines that the generation of the encryption key has not been performed correctly, it selects the second communication process. The communication device described in Appendix A1.

[0092] (Note A3) The aforementioned selection means is, If the determination means determines that the generation of the encryption key has not been performed correctly, it selects the second communication process using the second authentication key, which is an authentication key generated without using the encryption key. The communication device described in Appendix A2.

[0093] (Note A4) The first and second communication processes include message authentication. A communication device as described in any one of the appendices A1 to A3.

[0094] (Note A5) The determination means refers to the remaining amount of encryption keys generated by the generation means and determines whether the generation of encryption keys by the generation means is being performed correctly. A communication device as described in any one of the items A1 to A4 in the appendix.

[0095] (Note A6) If the determination means determines that the generation of the encryption key has been performed normally, and then determines that the generation of the encryption key has become normal, The system further includes an execution means for performing a safety verification process in the first communication process, or prior to the first communication process. A communication device as described in any one of the appendices A1 to A5.

[0096] (Note A7) A communication system including a first communication device and a second communication device, The first communication device is, A first generation means for generating an encryption key consumed in encrypted communication, A first determination means for determining whether the generation of the encryption key by the first generation means has been performed successfully, A first selection means selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, in accordance with the determination result by the first determination means. It is equipped with, The second communication device is A second generation means for generating an encryption key consumed in encrypted communication, A second determination means for determining whether the generation of the encryption key by the second generation means is performed correctly, A second selection means selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, in accordance with the determination result by the second determination means. A communication system equipped with these features.

[0097] [Additional Note B] This disclosure includes the technologies described in the following appendices. However, the present invention is not limited to the technologies described in the following appendices, and various modifications are possible within the scope of the claims.

[0098] (Note B1) At least one processor determines whether the generation of encryption keys by the generation means that generates encryption keys consumed in encrypted communication is being performed correctly, At least one processor selects, depending on the result of the determination, either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key. A communication method that includes this.

[0099] (Note B2) In making the above selection, the processor If the determination means determines that the generation of the encryption key has been performed successfully, it selects the first communication process, If the determination means determines that the generation of the encryption key has not been performed correctly, it selects the second communication process. The communication method described in Appendix B1.

[0100] (Note B3) In making the above selection, the processor If, in the above determination, it is determined that the generation of the encryption key has not been performed correctly, the second communication process is selected, which uses a second authentication key that is an authentication key generated without using the encryption key. The communication method described in Appendix B2.

[0101] (Note B4) The first and second communication processes include message authentication. The communication method described in any one of the appendices B1 to B3.

[0102] (Note B5) In making the above determination, the remaining amount of cryptographic keys generated by the generation means is referenced to determine whether the generation of cryptographic keys by the generation means is being performed correctly. The communication method described in any one of the appendices B1 to B4.

[0103] (Note B6) In making the above determination, if it is determined that the generation of the encryption key has been performed normally, and then it is determined that the generation of the encryption key has become normal, The first communication process further includes, or precedes to, performing a safety verification process. The communication method described in any one of the appendices B1 to B5.

[0104] [Additional Note C] This disclosure includes the technologies described in the following appendices. However, the present invention is not limited to the technologies described in the following appendices, and various modifications are possible within the scope of the claims.

[0105] (Note C1) A program that causes a computer to function as a communication control device, wherein the computer, A determination process to determine whether the generation of encryption keys used in encrypted communication by the generation means is being performed correctly, Depending on the determination result from the aforementioned determination process, a selection process is performed to select either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key. A program that executes the command.

[0106] (Note C2) The aforementioned selection process is, In the determination process, if it is determined that the generation of the encryption key has been performed successfully, the first communication process is selected. If the determination process determines that the generation of the encryption key has not been performed correctly, the second communication process is selected. The program described in Appendix C1.

[0107] (Note C3) The aforementioned selection process is, If the determination process determines that the generation of the encryption key has not been performed correctly, the second communication process is selected, which uses a second authentication key that was generated without using the encryption key. The program described in Appendix C2.

[0108] (Note C4) The first and second communication processes include message authentication. The program described in any one of the appendices C1 to C3.

[0109] (Note C5) The determination process refers to the remaining amount of cryptographic keys generated by the generation means and determines whether the generation of cryptographic keys by the generation means is being performed correctly. The program described in any one of the appendices C1 through C4.

[0110] (Appendix C6) In the determination process described above, if it is determined that the generation of the encryption key has been performed successfully, and then it is determined that the generation of the encryption key has been performed successfully, the computer In the first communication process described above, or prior to the first communication process, an execution process is further executed to perform a safety verification process. The program described in any one of the appendices C1 through C5.

[0111] [Additional Note D] This disclosure includes the technologies described in the following appendices. However, the present invention is not limited to the technologies described in the following appendices, and various modifications are possible within the scope of the claims.

[0112] (Note D1) The system comprises a generation means for generating encryption keys consumed in encrypted communication, and one or more processors, the processors being: A determination process to determine whether the generation of the encryption key by the generation means is performed correctly, A selection process is performed to select either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, depending on the result of the determination process. A communication device that performs [this action].

[0113] (Note D2) In the selection process, the processor If the determination means determines that the generation of the encryption key has been performed successfully, it selects the first communication process, If the determination means determines that the generation of the encryption key has not been performed correctly, it selects the second communication process. The communication device described in Appendix D1.

[0114] (Note D3) In the selection process described above, the processor, If the determination means determines that the generation of the encryption key has not been performed correctly, it selects the second communication process using the second authentication key, which is an authentication key generated without using the encryption key. The communication device described in Appendix D2.

[0115] (Note D4) The first and second communication processes include message authentication. A communication device as described in any one of the appendices D1 to D3.

[0116] (Note D5) In the determination process, the processor refers to the remaining amount of encryption keys generated by the generation means to determine whether the generation of encryption keys by the generation means is being performed correctly. A communication device as described in any one of the appendices D1 to D4.

[0117] (Note D6) In the determination process, if the processor determines that the generation of the encryption key has been performed successfully, and then determines that the generation of the encryption key has become successful, The aforementioned processor, In the first communication process, or prior to the first communication process, a safety verification process is performed. A communication device as described in any one of the items D1 through D.

[0118] (Note D7) A communication system including a first communication device and a second communication device, The first communication device is, The system comprises a first generation means for generating an encryption key consumed in encrypted communication, and one or more first processors, the first processors being A first determination process for determining whether the generation of the encryption key by the first generation means is performed correctly, A first selection process selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, depending on the result of the first determination process. Execute The second communication device is The system comprises a second generation means for generating encryption keys consumed in encrypted communication, and one or more second processors, the second processors being A second determination process for determining whether the generation of the encryption key by the second generation means is performed correctly, A second selection process selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, depending on the result of the second determination process. A communication system that performs this task. [Additional Note E] This disclosure includes the technologies described in the following appendices. However, the present invention is not limited to the technologies described in the following appendices, and various modifications are possible within the scope of the claims.

[0119] (Note E1) A program that causes a computer to function as a communication control device, wherein the computer, A determination process to determine whether the generation of encryption keys used in encrypted communication by the generation means is being performed correctly, Depending on the determination result from the aforementioned determination process, a selection process is performed to select either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key. A non-temporary recording medium that contains a program that executes [the specified action]. [Explanation of symbols]

[0120] 100, 100A ··· Communication System 1,1-1,1-2,1A-1,1A-2 ···Communication equipment 11,11-1,11-2...Generation unit (key generation unit) 12,12-1,12-2...Judgment section 13, 13-1, 13-2 ···Selection section 14-1, 14-2 ···Execution Department 15-1, 15-2 ... Management Department

Claims

1. A generation means for generating encryption keys consumed in encrypted communication, A determination means for determining whether the generation of the encryption key by the generation means has been performed successfully, A selection means selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, depending on the determination result by the determination means. A communication device equipped with the following features.

2. The aforementioned selection means is, If the determination means determines that the generation of the encryption key has been performed successfully, it selects the first communication process, If the determination means determines that the generation of the encryption key has not been performed correctly, it selects the second communication process. The communication device according to claim 1.

3. The aforementioned selection means is, If the determination means determines that the generation of the encryption key has not been performed correctly, it selects the second communication process using the second authentication key, which is an authentication key generated without using the encryption key. The communication device according to claim 2.

4. The first and second communication processes include message authentication. A communication device according to any one of claims 1 to 3.

5. The determination means refers to the remaining amount of cryptographic keys generated by the generation means and determines whether the generation of cryptographic keys by the generation means is being performed correctly. A communication device according to any one of claims 1 to 3.

6. If the determination means determines that the generation of the encryption key has been performed normally, and then determines that the generation of the encryption key has become normal, The system further includes an execution means for performing a safety verification process in the first communication process, or prior to the first communication process. A communication device according to any one of claims 1 to 3.

7. A communication system including a first communication device and a second communication device, The first communication device is A first generation means for generating an encryption key consumed in encrypted communication, A first determination means for determining whether the generation of the encryption key by the first generation means is performed correctly, A first selection means selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, in accordance with the determination result by the first determination means. It is equipped with, The second communication device is A second generation means for generating an encryption key consumed in encrypted communication, A second determination means for determining whether the generation of the encryption key by the second generation means is performed correctly, A second selection means selects either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key, in accordance with the determination result by the second determination means. A communication system equipped with these features.

8. To determine whether the generation of encryption keys used in encrypted communication by the generation means is being performed correctly, Depending on the result of the determination, either a first communication process using a first authentication key, which is an authentication key generated from the encryption key, or a second communication process that does not consume the encryption key is selected. A communication method that includes this.

9. A program that causes a computer to function as a communication control device, wherein the computer, A determination process to determine whether the generation of encryption keys used in encrypted communication by the generation means is being performed correctly, Depending on the determination result from the determination process, a selection process is performed to select either a first communication process using a first authentication key which is an authentication key generated from the encryption key, or a second communication process which does not consume the encryption key. A program that executes the command.

Citation Information

Patent Citations

  • Quantum key delivery device, quantum key delivery system and quantum key delivery method

    JP2016181814A