Quantum cryptography communication control device, quantum cryptography communication system, quantum cryptography communication control method and program

The quantum cryptography communication control device optimizes global key transfer paths in a quantum key distribution network by collecting link information, calculating costs, and selecting paths to satisfy security demands, enhancing efficiency and resource utilization.

JP2026119906APending Publication Date: 2026-07-21KK TOSHIBA
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
KK TOSHIBA
Filing Date
2025-01-08
Publication Date
2026-07-21

Smart Images

  • Figure 2026119906000001_ABST
    Figure 2026119906000001_ABST
Patent Text Reader

Abstract

Using local keys shared across each link of a key-sharing network utilizing quantum key distribution, the optimal path for encrypted transmission of the global key is determined. [Solution] In the quantum cryptography communication control device of the embodiment, the collection unit collects link information of the link where a local key is generated by quantum key distribution, and the global key guarantee amount of each of the multiple application pairs that perform encrypted communication using the global key. The calculation unit calculates the link cost used to select the global key transfer path based on the link information. The guarantee amount calculation unit calculates the local key guarantee amount to be allocated to the link for the transfer of the global key of each of the multiple application pairs so as to simultaneously satisfy the global key guarantee amount of each of the multiple application pairs. The selection unit selects the global key transfer path based on the link cost and the local key guarantee amount.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to a quantum cryptographic communication control device, a quantum cryptographic communication system, a quantum cryptographic communication control method, and a program.

Background Art

[0002] There has conventionally been known a quantum cryptographic communication control device that can guarantee the QoS (Quality of Service) originally expected by an application. Also, there has conventionally been known a technique for determining a path for encrypted transfer using a quantum key distribution (QKD) network.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Patent Document 2

Non-Patent Documents

[0004]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, with conventional techniques, it has been difficult to optimally determine a path for encrypted transfer of a global key using local keys shared at each link in a key sharing network using quantum key distribution. [Means for solving the problem]

[0006] The quantum cryptography communication control device of the embodiment comprises an acquisition unit, a calculation unit, a guaranteed amount calculation unit, and a selection unit. The acquisition unit collects link information of links where local keys are generated by quantum key distribution, and the global key guaranteed amount for each of a plurality of application pairs that perform encrypted communication using a global key. The calculation unit calculates the link cost used to select the global key transfer path based on the link information. The guaranteed amount calculation unit calculates the local key guaranteed amount to be allocated to the link for the transfer of the global key for each of the plurality of application pairs so as to simultaneously satisfy the global key guaranteed amount for each of the plurality of application pairs. The selection unit selects the global key transfer path based on the link cost and the local key guaranteed amount. [Brief explanation of the drawing]

[0007] [Figure 1] Figure 1 shows an example of the configuration of a quantum cryptography communication system according to an embodiment. [Figure 2] Figure 2 is a diagram illustrating an example of the global key sharing process in an embodiment. [Figure 3] Figure 3 shows an example of the configuration of the smallest unit of key-sharing network. [Figure 4] Figure 4 shows an example of the functional configuration of a node in the embodiment. [Figure 5] Figure 5 is a flowchart showing an example of a quantum cryptography communication control method according to an embodiment. [Figure 6] Figure 6 shows an example of application pair information in an embodiment. [Figure 7] Figure 7 shows an example of link information in an embodiment. [Figure 8] Figure 8 shows an example of common definitions (variables and constraints) in the guaranteed quantity calculation method of the embodiment. [Figure 9] Figure 9 shows an example of an objective function in the guaranteed quantity calculation method of the embodiment. [Figure 10] FIG. 10 is a diagram showing an example of the path constraint conditions of the embodiment. [Figure 11] FIG. 11 is a diagram showing an example of the common definitions (variables and constraint conditions) in the guaranteed quantity calculation method of the embodiment. [Figure 12] FIG. 12 is a diagram showing an example of the objective function in the guaranteed quantity calculation method of the embodiment. [Figure 13] FIG. 13 is a diagram showing an example of the common definitions (variables and constraint conditions) in the guaranteed quantity calculation method of step S8 of the embodiment. [Figure 14] FIG. 14 is a diagram showing an example of the objective function in the guaranteed quantity calculation method of FIG. 13. [Figure 15] FIG. 15 is a diagram showing an example of the configuration of Modification 1 of the embodiment. [Figure 16] FIG. 16 is a diagram showing an example of the configuration of Modification 2 of the embodiment. [Figure 17] FIG. 17 is a diagram showing an example of the hardware configuration of node 100 of the embodiment.

BEST MODE FOR CARRYING OUT THE INVENTION

[0008] Hereinafter, embodiments of a quantum key distribution control device, a quantum key distribution system, a quantum key distribution control method, and a program will be described in detail with reference to the accompanying drawings.

[0009] First, an example of the configuration of the quantum key distribution system of the embodiment will be described.

[0010] [Example of Configuration] FIG. 1 is a diagram showing an example of the configuration of a quantum key distribution system 1 of the embodiment. The quantum key distribution system 1 of the embodiment includes nodes 100a to 100e, applications 200a to 200b, an application network 501, and a key sharing network 502.

[0011] For example, node 100a is connected to nodes 100b, 100c, and 100d via links. Node 100a shares a local key (quantum key) 301a with node 100b via the link between them. Also, node 100a generates an encryption key, which is a random number, as a global key 401a independently of the generation of the encryption key (quantum key) by QKD, and provides it to application 200a.

[0012] Also for example, node 100e is connected to nodes 100b, 100c, and 100d via links. Node 100e shares a local key 301b with node 100c via the link between them. Also, node 100e generates an encryption key, which is a random number, as a global key 401b independently of the generation of the encryption key by QKD, and provides it to application 200b.

[0013] Hereinafter, when nodes 100a to 100e are not distinguished, they are simply referred to as node 100. When applications 200a to 200b are not distinguished, they are simply referred to as application 200. When local keys 301a to 301b are not distinguished, they are simply referred to as local key 301. When global keys 401a to 401b are not distinguished, they are simply referred to as global key 401.

[0014] Application 200 performs encrypted communication using global key 401 via application network 501.

[0015] Application network 501 is a network through which data encrypted by global key 401 is transmitted and received.

[0016] Key sharing network 502 is a network that shares local key 301 among each node 100 connected by links.

[0017] Note that in the example in Figure 1, the number of nodes 100 is 5, but the number of nodes 100 is not limited to 5. Also, in the example in Figure 1, the number of applications 200 is 2, but the number of applications 200 is not limited to 2.

[0018] Figure 2 is a diagram illustrating an example of the sharing process of the global key 401 in the embodiment. As described above, node 100 is equipped with QKD functionality. Specifically, node 100 is equipped with the function of generating and sharing random numbers with other nodes 100 connected by a link, and the function of using the generated random numbers as local keys 301 to perform encrypted communication on the key sharing network 502.

[0019] Furthermore, a specific node 100 (nodes 100a and 100e in the example in Figure 2) may be equipped with a function to generate random numbers (global key 401 in the example in Figure 2) independently of the QKD function, and a function to transmit the random numbers generated by this function to the opposing device.

[0020] Each node 100 performs routing to share the global key 401. Then, each node 100 shares (transfers) the global key 401 using the path determined by routing. The global key 401 is encrypted using OTP (One Time Pad) with a local key 301 shared between the linked nodes 100, and securely transferred to the other node 100. Since OTP uses a single key for encryption, a key of the same size as the data to be encrypted is required. In this case, in order to encrypt and transfer the global key 401, a local key 301 of the same size as the global key 401 must be prepared.

[0021] In the example shown in Figure 2, a global key 401 is shared between node 100a and node 100e, and this global key 401 is provided to applications 200a and 200b.

[0022] Figure 3 shows an example of the configuration of the smallest unit key-sharing network 502. The example in Figure 3 shows a case where nodes 100f and 100g are connected by a link, and QKD is performed via this link. As shown in Figure 3, the configuration of the smallest unit key-sharing network 502 consists of a pair of nodes 100f and 100g.

[0023] Figure 4 shows an example of the functional configuration of node 100 in the embodiment. Node 100 in the embodiment (an example of a quantum cryptography communication control device) comprises a control unit 101, a management unit 102, a platform unit 103, a communication unit 104, and a routing processing unit 110.

[0024] The routing processing unit 110 is a processing unit that performs routing (path control) for the global key 401.

[0025] The routing processing unit 110 includes a collection unit 111, a calculation unit 112, a guaranteed amount calculation unit 113, a selection unit 114, a storage unit 115, an adjustment unit 116, a setting unit 117, and a guaranteed amount calculation unit 118.

[0026] The control unit 101 controls the processing performed at node 100. For example, the control unit 101 is responsible for starting each component shown in Figure 4. It also controls the timing of route calculation (route recalculation) performed at the routing processing unit 110.

[0027] The management unit 102 manages key resources such as the local key 301 of the link connected to node 100, the local key generation speed, and the amount of local keys held.

[0028] The platform unit 103 provides management of other components of node 100, computer operating system functions necessary for operation, basic network functions, and security functions, etc.

[0029] The communication unit 104 communicates with other nodes 100 to which node 100 is connected. A communication unit 104 is provided for each link, and each has a quantum communication unit 105 and a classical communication unit 106. In the example in Figure 4, each of the three links is connected to the opposing node 100 by two types of communication interfaces (quantum communication unit 105 and classical communication unit 106).

[0030] The quantum communication unit 105 is connected to another node 100 by a quantum communication channel and performs quantum communication with the other node 100. The quantum communication unit 105 shares a bit sequence of photons (random numbers) with the node 100 connected by the link, using quantum cryptography (QKD) to generate a local key 301 (encryption key).

[0031] The classical communication unit 106 is connected to other nodes 100 via a classical communication channel and performs classical communication with other nodes 100. The data exchanged between nodes 100 via the classical communication unit 106 includes data such as the global key 401. Data such as the global key 401 is usually transmitted via the classical communication unit 106 using encrypted communication with a local key 301 managed by node 100.

[0032] The collection unit 111 collects link information (see Figure 7 below) via the classical communication unit 106. The link information includes the status of the links to which node 100 is connected, the network address of those links, the cost of each link, and network information. The collection unit 111 also collects application pair information (see Figure 6 below) connected to node 100. The collection unit 111 stores the collected link information and application pair information in the storage unit 115.

[0033] The calculation unit 112 reads the amount of local keys generated and the amount of local keys stored for the links connected to node 100 from the storage unit 115. The calculation unit 112 uses the amount of local keys generated and the amount of local keys stored for the links connected to node 100 to calculate the link capacity (the amount of local keys that can be transmitted through the link) and the link cost based on the link capacity. The calculation unit 112 may also use the state and QKD performance to further calculate the link capacity and the link cost based on the link capacity.

[0034] The guaranteed amount calculation unit 113 calculates the local key guaranteed amount to be allocated to each link from the link capacity and link cost calculated by the calculation unit 112 and the global key guaranteed amount obtained from the storage unit 115. The global key guaranteed amount indicates the global key amount requested for each application pair. The local key guaranteed amount indicates the local key amount for each link required to pass the global key guaranteed amount.

[0035] The guarantee amount calculation unit 113 retrieves application pairs stored as application pair information and information on the global key guarantee amount associated with the application pairs. Then, the guarantee amount calculation unit 113 collectively (simultaneously) calculates the local key guarantee amount to be allocated to each path in order to satisfy the global key guarantee amounts of multiple (for example, all) application pairs.

[0036] Specifically, the guarantee amount calculation unit 113 calculates the local key guarantee amount to be assigned to each link in a batch, treating the calculation of the local key guarantee amount as a multi-product flow problem. The guarantee amount calculation unit 113 uses variables to identify application pairs and their global key guarantee amounts to calculate the multi-product flow problem so that the global key guarantee amounts of multiple (e.g., all) application pairs are simultaneously satisfied. Specifically, the guarantee amount calculation unit 113 calculates the local key guarantee amount to be assigned to a link so that the global key guarantee amount is simultaneously satisfied, treating the application pair as a product and the local key guarantee amount as a flow in a multi-product flow problem.

[0037] Furthermore, the guaranteed amount calculation unit 113 may also use the global key storage amount, the global key consumption amount, and the global key generation amount in addition to the global key guaranteed amount for the guaranteed amount calculation. If the global key guaranteed amount cannot be guaranteed, the adjustment unit 116 adjusts the global key guaranteed amount, and then the guaranteed amount calculation unit 113 performs the calculation again based on the adjusted global key guaranteed amount.

[0038] The selection unit 114 selects the optimal path with the best metric from among several candidate optimal paths to reach other nodes 100, based on the metric of each candidate path, and creates an optimal path tree. The metric is determined based on the link cost and the amount of local key guaranteed to be allocated to the link. For example, a path with a lower link cost is selected as the forwarding path, for example, if there is sufficient link capacity. Alternatively, a path with a larger amount of local key guaranteed to be allocated to the link is selected as the forwarding path. The selection unit 114 creates a routing table from the optimal path tree and stores the routing table in the storage unit 115.

[0039] The storage unit 115 stores a database of link information (e.g., local key generation amount, local key storage amount, status, and QKD performance), a database of application pair information (e.g., global key guarantee amount, global key storage amount, global key consumption amount, and global key generation amount), and routing tables created by the selection unit 114.

[0040] The adjustment unit 116 adjusts the key guarantee amount for each application pair according to a predetermined policy if the amount of local key guarantees allocated to each link is insufficient and cannot meet the global key guarantee amount requested by at least one application pair.

[0041] For example, the adjustment unit 116 uses the priority of application pairs stored in the storage unit 115 to adjust the global key guarantee amount for each application pair. In this case, for example, a predetermined policy is to reduce the global key guarantee amount of each application pair more for those with lower priority.

[0042] For example, the adjustment unit 116 requests the guaranteed amount calculation unit 118 (described later) to calculate the global key guaranteed amount. The key guaranteed amount for each application pair is adjusted to the global key guaranteed amount for each application pair calculated by the guaranteed amount calculation unit 118.

[0043] Alternatively, for example, the adjustment unit 116 may autonomously reduce the global key guarantee amount by repeatedly adjusting it until the global key guarantee amount can be guaranteed. In this case, for example, a predetermined policy is to uniformly reduce the guarantee amount of the global key 401 for each of the multiple application pairs. Alternatively, for example, a predetermined policy is to reduce the global key guarantee amount more for application pairs that have used the global key 401 less so far, based on the usage history of the global key 401 for each of the multiple application pairs.

[0044] The setting unit 117 uses the path constraint conditions stored in the storage unit 115 to set which paths are available or unavailable for the calculation of the local key guaranteed amount to be assigned to each path by the guaranteed amount calculation unit 113. The setting unit 117 also sets which paths are available or unavailable for the calculation of the guaranteed amount by the guaranteed amount calculation unit 118.

[0045] The guaranteed amount calculation unit 118 calculates the global key guaranteed amount and the local key guaranteed amount to be allocated to each link based on the link capacity and link cost calculated by the calculation unit 112, the global key guaranteed amount obtained from the storage unit 115, and the guaranteed amount calculation flag described later (see Figure 6).

[0046] The global key guaranteeable amount is less than or equal to the requested global key guaranteeable amount, but is the global key amount that can be guaranteed in quantum cryptography communication system 1 (the maximum global key amount that can be guaranteed).

[0047] Specifically, the guaranteed amount calculation unit 118 calculates the global key guaranteed amount and the local key guaranteed amount to be allocated to each link in order to satisfy the global key guaranteed amount, if the guaranteed amount calculation flag indicates that it is an application pair for which a guaranteed amount is to be calculated.

[0048] Furthermore, the guaranteed amount calculation unit 118 may use the global key storage amount, the global key consumption amount, and the global key generation amount to calculate the global key guaranteed amount and the local key guaranteed amount allocated to each path.

[0049] [Example of a quantum cryptography communication control method] Figure 5 is a flowchart showing an example of a quantum cryptographic communication control method according to an embodiment. Figure 5 is a flowchart showing an example of processing by the calculation unit 112, guaranteed amount calculation unit 113, selection unit 114, adjustment unit 116, setting unit 117, and guaranteed amount calculation unit 118 included in the routing processing unit 110.

[0050] First, the calculation unit 112 obtains multiple (for example, all) application pair information (global key guaranteed amount, global key storage amount, global key consumption amount, global key generation amount, guaranteed amount calculation flag, path constraint conditions, and priority) from the storage unit 115 (step S1).

[0051] In addition, during the processing of step S1, instead of obtaining application pair information from the storage unit 115, a request containing application pair information may be received directly from the application 200.

[0052] Figure 6 shows an example of application pair information in the embodiment. The application pair information in the embodiment includes the application pair, domain, sending site (node ​​100), receiving site (node ​​100), global key guarantee amount, key length, key guarantee start date and time, key guarantee end date and time, global key storage amount, global key consumption amount, global key generation amount, guaranteed amount calculation flag, path constraint conditions, priority, and guaranteed required flag.

[0053] The application pair is information that indicates a pair of applications 200 that communicate using encryption.

[0054] The domain is information that identifies the administrator (owner) of the application pair.

[0055] The transmitting node (node ​​100) is information indicating the location (node ​​100) where the transmitting side of the application pair is located. The receiving node (node ​​100) is information indicating the location (node ​​100) where the receiving side of the application pair is located. The transmitting and receiving nodes are used as the start and end points in guaranteed quantity calculation, guaranteed quantity calculation, and route selection.

[0056] The global key guarantee is the guaranteed amount (in bytes) of cryptographic key (global key 401) per unit of time (e.g., a day, an hour, and a minute) that a user of the application pair (e.g., the administrator of the application pair) expects (needs).

[0057] For example, global key guarantees can be accepted by registration from Application 200 or a pair of Application 200s. Alternatively, global key guarantees may also be accepted by registration from users utilizing a pair of Application 200s.

[0058] If the global key guarantee amount is not registered, the actual amount of global keys required to be generated will be estimated based on other global key 401 information (such as global key storage amount, global key consumption amount, or global key generation amount).

[0059] The global key guarantee amount, or global key requirement amount, is used as a parameter for link cost.

[0060] The key length is the length of the encryption key (global key 401). The key guarantee start date and time is the start date and time of the guarantee for the encryption key (global key 401). The key guarantee end date and time is the end date and time of the guarantee for the encryption key (global key 401).

[0061] The global key storage is the amount (in bytes) of cryptographic keys (global key 401) used in the application pair that are stored.

[0062] Global key consumption is the amount of cryptographic key (global key 401) consumed (bytes, bps) per unit of time (e.g., 1 day, 1 hour, and 1 minute) used by the application pair.

[0063] Global key generation rate is the amount of cryptographic keys (global key 401) generated per unit of time (e.g., 1 day, 1 hour, and 1 minute) for an application pair (in bytes, bps).

[0064] The guaranteed amount calculation flag indicates whether or not an application pair is one that calculates guaranteed amounts. Calculating guaranteed amounts means calculating the maximum global key quantity that can be guaranteed for that application pair. For example, a guaranteed amount calculation flag of 1 indicates that the application pair is one that calculates guaranteed amounts, while a guaranteed amount calculation flag of 0 indicates that the application pair is not one that calculates guaranteed amounts. Alternatively, the guaranteed amount calculation flag may not be set, and it may be determined that an application pair is one that calculates guaranteed amounts simply because the global key guaranteed quantity is 0.

[0065] Route constraints specify the constraints on the routes used for the transfer of global key 401. Specifically, they specify which links are used for the transfer of global key 401 and which are not. Route constraints allow each application pair (user) to specify which links they wish to use or do not wish to use for the delivery of global key 401, thus flexibly responding to user preferences.

[0066] Priority is information indicating the priority of application pairs that guarantee the requested global key security amount. For example, priority is set according to requests from application pairs (users) and contract types.

[0067] The "Guarantee Required" flag indicates whether an application pair is required to guarantee the global key guarantee amount if, due to the performance limitations of the key-sharing network 502, at least one application pair cannot meet the global key guarantee amount. For example, a "Guarantee Required" flag of 1 indicates that the guarantee is required, while a "Guarantee Required" flag of 0 indicates that the guarantee is not required.

[0068] Note that the application pair information shown in Figure 6 is just an example. Among the application pair information shown in Figure 6, for example, the domain, key length, key guarantee start date and time, key guarantee end date and time, guaranteed amount calculation flag, path constraint conditions, priority, and guaranteed must flag are optional, and the application pair information does not have to include, for example, the domain, key length, key guarantee start date and time, key guarantee end date and time, guaranteed amount calculation flag, path constraint conditions, priority, and guaranteed must flag.

[0069] Returning to Figure 5, the calculation unit 112 then obtains link information (for example, local key generation amount, local key storage amount, status, and QKD performance) from the storage unit 115 (step S2).

[0070] Figure 7 shows an example of link information in the embodiment. The link information in the embodiment includes the link, the starting point (node), the ending point (node), the status, the maximum amount of local keys stored, the amount of local keys stored, the amount of local keys generated, the amount of local keys consumed, the time, and the QKD performance.

[0071] The link indicates the links to which node 100 is connected.

[0072] The starting point (node) is information indicating the location where the starting point of the link is located.

[0073] The endpoint node is information indicating the location where the endpoint of the link is located.

[0074] The status refers to the operational status of the link and the operational status of the node 100 that constitutes the link.

[0075] The maximum local key storage capacity is the maximum amount (in bytes) of the link's encryption key (local key 301) that can be stored, and indicates the storage capacity of the link's encryption key (local key 301).

[0076] The local key storage amount is the amount of stored encryption keys (local keys) for the link (in bytes), and indicates the currently stored amount of encryption keys (local key 301).

[0077] The local key generation amount is the cumulative amount (bytes, bps) of encryption keys (local key 301) generated for the link.

[0078] The maximum local key storage capacity, the local key storage capacity, and the local key generation capacity are used as parameters for link capacity and link cost.

[0079] Local key consumption is the cumulative consumption (bytes, bps) of the link's encryption key (local key 301).

[0080] The time is a timestamp indicating the time the link information was recorded.

[0081] QKD performance refers to the performance of the QKD device (node ​​100 in the example in Figure 1). For example, QKD performance includes the amount of secure keys generated, the secure key rate, and the secure key error rate. The secure key is the key used before generating the local key 301, and differs from the local key 301 in that it is not divided into encryption and decryption keys.

[0082] Note that the link information shown in Figure 7 is just an example. Among the link information shown in Figure 7, for example, the status is arbitrary, and the link information does not necessarily have to include a status.

[0083] Returning to Figure 5, the calculation unit 112 then uses the link information obtained in step S2 to calculate the link capacity and the link cost based on the link capacity (step S3). The link cost is used to calculate the guaranteed amount of global key 401, the guaranteed amount of global key 401, and the transmission path of global key 401.

[0084] The formulas for calculating link capacity and link cost will be described later using Figure 9. Furthermore, in step S3, the amount of global keys actually required for generation may be estimated from the guaranteed global key amount.

[0085] Next, the setting unit 117 determines whether or not a path constraint condition exists in the application pair information data acquired in step S1 (step S4).

[0086] If path constraints exist (Step S4, Yes), the configuration unit 117 sets the path constraints for the application pair subject to the guaranteed amount calculation (Step S5). For example, the configuration unit 117 sets, for each application pair, the links used in the global key 401 transfer path, or links not used in the global key 401 transfer path, as constraints for calculating the global key request amount for multiple application pairs.

[0087] Next, the guaranteed amount calculation unit 113 calculates whether the global key guaranteed amount for multiple application pairs can be guaranteed and the amount of local keys to be allocated to each link as a multi-product flow problem (step S6). Specifically, the guaranteed amount calculation unit 113 calculates the local key guaranteed amount as the amount of local keys required for each link in order to satisfy the global key guaranteed amount for multiple application pairs.

[0088] The following information is used in the calculation in step S6. • The amount of global key guaranteed for multiple application pairs obtained in step S1 (or the amount of global key required as described above) • The amount of local keys available for use in the link, calculated from the link information obtained in step S2 (amount of local keys generated, amount of local keys stored, status, and QKD performance). • Link cost calculated in step S3

[0089] The calculation in step S6 is equivalent to solving a multi-product flow problem, where application pairs are considered product types, and the amount of local key guarantees required by each application pair for encrypted transfer of the global key 401 (the amount of local key used to encrypt the global key 401 at the starting node of the link, send it through the link, and decrypt it at the ending node) is considered a flow. The calculation by the guarantee amount calculation unit 113 is performed by identifying the global key guarantee amount for each application pair using a variable to identify each application pair.

[0090] The process in step S6 calculates the global key guarantee amount for multiple application pairs (users) simultaneously, allowing for efficient use of the resources (local key amount) of the key sharing network 502 regardless of the registration order of each application pair (no advantage is given to application pairs that registered earlier).

[0091] Next, the adjustment unit 116 determines, based on the calculation result of step S6, whether or not it is possible to guarantee a global key guarantee amount for multiple application pairs (step S7).

[0092] If it is possible to guarantee a global key guarantee amount for multiple application pairs (step S7, Yes), the selection unit 114 selects a route and calculates the flow for each route based on the link cost calculated in step S3 and the local key guarantee amount for each link calculated in step S6 (step S9). In route selection, the links used for the route that will transport the global key 401 are selected. In flow calculation, the amount of local keys used by the links included in the route is calculated.

[0093] If it is not possible to guarantee a global key guarantee amount for multiple application pairs (step S7, No), the adjustment unit 116 adjusts the global key guarantee amount for the multiple application pairs according to the adjustment method policy (step S8), and the process returns to step S6.

[0094] If the calculation by the guaranteed amount calculation unit 113 fails to guarantee the global key guaranteed amount, the process cannot proceed to route selection and flow calculation for each route, making it impossible to deliver the global key 401 requested by the application pair. Therefore, the adjustment unit 116 adjusts the application pair's global key guaranteed amount through the process in step S8, and performs the calculation in step S6 again with a key amount that is less than the global key guaranteed amount requested by the application pair (a portion of the requested global key guaranteed amount). In other words, by adjusting the global key guaranteed amount, the global key 401 can be delivered even with a key amount that is only a portion of the global key guaranteed amount requested by the application pair.

[0095] Next, we will describe in detail an example of an adjustment method using the adjustment unit 116 or the guaranteed amount calculation unit 118 of the embodiment.

[0096] (Adjustment Method 1: Calculation of Guaranteed Amount) If the adjustment unit 116 indicates that the guaranteed amount calculation flag is an application pair for which guaranteed amounts are to be calculated, it requests the guaranteed amount calculation unit 118 to calculate the global key guaranteed amount.

[0097] The guaranteed amount calculation unit 118 calculates the global key guaranteed amount as the maximum global key guaranteed amount that can be simultaneously guaranteed for multiple (for example, all) application pairs, and calculates the amount of local keys to allocate to each link according to the global key guaranteed amount. That is, the guaranteed amount calculation unit 118 calculates the amount of local keys to allocate to the links for the transfer of the global key 401 of each of the multiple application pairs so as to simultaneously satisfy the guaranteed amount of the global key 401 of each of the multiple application pairs.

[0098] The guaranteed amount calculation unit 118 calculates the local key guaranteed amount to be allocated to the link so as to simultaneously satisfy the guaranteed amount of the global key 401, and calculates this as a multi-product flow problem where the application pair is considered a product and the local key guaranteed amount is considered a flow.

[0099] In adjustment method 1, by using the calculation results from the guaranteed amount calculation unit 118, the calculation by the guaranteed amount calculation unit 113 in step S6 of the next loop and the determination by the adjustment unit 116 in step S7 become unnecessary, and the next loop can proceed to step S9.

[0100] However, there may be differences in the amount of global key guarantees adjusted for each application pair, which could be unfair.

[0101] (Adjustment method 2: uniform reduction) The adjustment unit 116 uniformly reduces the global key guarantee amount requested by each of the multiple (for example, all) application pairs. Then, the guarantee amount calculation unit 113 repeats the calculation of the guarantee amount until the global key guarantee amounts for the multiple application pairs can be guaranteed.

[0102] Adjustment method 2 allows for a fair reduction in the amount of global key security required by each application pair. However, the loop from steps S6 to S8 must be repeated until the amount of global key security required by multiple application pairs can be guaranteed simultaneously.

[0103] (Adjustment method 3: Priority) The adjustment unit 116, based on the application pair information data (priority) in the storage unit 115, assigns weights to the global key guarantee amount and then modifies the global key guarantee amount of the application pair provided to the guarantee amount calculation unit 113.

[0104] For example, priority may be determined by settings from application pairs. Alternatively, priority may be determined based on information held by quantum cryptography communication system 1. The information held by quantum cryptography communication system 1 may include, for example, the global key guarantee amount before adjustment, the remaining time of the unit guarantee period for application pairs, the number of application pairs included in the domain, the total amount of local keys 301 consumed on the transit links in the entire key sharing network 502, and the number of transit links (hops).

[0105] The guaranteed amount calculation unit 113 repeats the calculation of the guaranteed amount until the global key guaranteed amounts for multiple application pairs can be guaranteed.

[0106] Adjustment method 3 allows you to adjust the global key guarantee amount according to the priority of the application pair. However, it is necessary to repeat the loop from steps S6 to S8 until a guarantee is achieved.

[0107] (Adjustment method 4: Use the history of the most recent global key 401) The adjustment unit 116 adjusts the guaranteed amount for each application pair based on the history of the amount of global key used by the application pair during the most recent period N (the unit of the period is arbitrary).

[0108] In adjustment method 4, the amount of global key is adjusted according to the recent usage history of global key 401, so that application pairs that are more likely to use global key 401 in the future will have a larger amount of global key.

[0109] (Adjustment method 5: Use the history of previous global key 401) The adjustment unit 116 adjusts the global key guarantee amount for each application pair based on the usage history of the global keys 401 used so far during the unit guarantee period.

[0110] In adjustment method 5, the amount of global key guaranteed is adjusted according to the history of global key 401 usage so that application pairs that are more likely to use global key 401 in the future will receive a larger amount of global key guaranteed.

[0111] (Adjustment method 6: Use the remaining guaranteed key amount) The adjustment unit 116 determines the adjustment amount based on the global key guarantee amount (the amount of global keys that will be used in the future) relative to the remaining period of the unit guarantee period (for example, one day). For example, the adjustment unit 116 reduces the global key guarantee amount more for application pairs with a short remaining period of the unit guarantee period for the global key 401.

[0112] Adjustment method 6 adjusts the global key guarantee amount according to the amount of global keys that are expected to be used in the future, so that application pairs that are more likely to use global key 401 in the future will have a larger global key guarantee amount.

[0113] (Adjustment method 7: Warranty required or not) The adjustment unit 116 changes the global key guarantee amount based on the application pair information data (guarantee required flag) in the storage unit 115, depending on whether the guarantee of the global key 401 is required. The adjustment unit 116 does not change the global key guarantee amount for application pairs where the guarantee of the global key 401 is required, but adjusts (reduces) the global key guarantee amount for application pairs where the guarantee is not required. If the adjustment unit 116 cannot guarantee the global key guarantee amount for application pairs where the guarantee is required, it sets a higher priority and adjusts using the priority method of adjustment method 3 (in combination with adjustment method 3).

[0114] Adjustment method 7 allows you to adjust the amount of global key guarantees by deciding, for example, whether or not to make global key guarantees mandatory by contract.

[0115] The above adjustment methods 1 to 7 may be applied independently or in combination. For example, the guaranteed amount may be allocated according to the priority of the application pair (adjustment method 3) (adjustment method 1). Alternatively, for example, a guaranteed amount to be uniformly reduced may be set according to the priority of the application pair (adjustment method 3) (adjustment method 2).

[0116] Next, we will describe in detail an example of the method for calculating guaranteed quantities by the guaranteed quantity calculation unit 113 of the embodiment. An example of an equation for the guaranteed quantity calculation unit 113 to calculate the multi-product flow problem is shown below. In the following example, a variable is introduced to identify the application pair and the global key guaranteed quantity associated with the application pair, and the calculation of the global key guaranteed quantity is performed by treating it as a multi-product flow problem.

[0117] The multi-product flow problem described below aims to determine the optimal global key distribution path that does not monopolize the link's local key 301 by the previously registered application pair, by calculating the distribution paths of the global key 401 for both the registered application pair and the newly registered application pair together.

[0118] Figure 8 shows an example of variables and constraints in the guaranteed quantity calculation method of the embodiment.

[0119] The variables in equation (1) represent the local key guarantees for each link required to pass the global key guarantee amount requested for each application pair.

[0120] Equation (2) shows that the local key guarantee amount cannot exceed the link capacity (constraint (1)). Note that the unit of the local key guarantee amount is arbitrary and can be expressed as bits or bytes, for example.

[0121] Equation (3) shows that the sum of the local key guarantees for all input links for every 100 nodes is equal to the sum of the local key guarantees for all output links (constraint (2)).

[0122] Equation (4) shows the agreement between the sum of the local key guarantees for all output links from the source node 100 and the requested global key guarantee, as well as the agreement between the sum of the local key guarantees for all input links to the destination node 100 and the requested global key guarantee (constraint (3)).

[0123] Furthermore, when the guaranteed quantity calculation unit 113 calculates the global key guaranteed quantity, it sets an objective function, for example, as shown in Figure 9.

[0124] Figure 9 shows an example of an objective function in the guaranteed quantity calculation method of the embodiment.

[0125] Objective function A (Equation (5)) reduces the amount of local keys 301 used to transfer the global key 401 across the entire key-sharing network 502, thus avoiding the unnecessary consumption of local keys 301.

[0126] In objective function B (equation (6)), the depletion of local keys 301 on a link is avoided by prioritizing the selection of links with large link capacity, thereby leveling out the remaining local keys 301.

[0127] The objective function C (equation (7)) aims to equalize and maximize the amount of local keys stored in each link.

[0128] The objective function D (equation (8)) aims to equalize the amount of local keys used by each link as much as possible.

[0129] Next, we will describe in detail an example of how to set path constraint conditions using the setting unit 117 of the embodiment.

[0130] Figure 10 shows an example of path constraint conditions in an embodiment. The setting unit 117 adds path constraints (1) and (2) according to equations (9) and (10) to each application pair information obtained from the storage unit 115 if path constraint conditions (constraints on links used in the path and links not used in the path) exist. The addition of path constraints (1) and (2) is performed before the guarantee amount calculation unit 113 calculates the local key guarantee amount required for each link to satisfy the global key guarantee amount for multiple (e.g., all) application pairs.

[0131] The configuration unit 117 uses route constraints (1) and (2) to set which links to include in the route and which links to exclude from the route. If (the local key guarantee amount for the specified link) == (the requested global key guarantee amount), then only paths passing through that link will be selected. Multiple (for example, all) local key guarantee amounts impose a strict constraint on the use of that link. Note that this does not mean that multiple paths cannot be selected to satisfy the global key guarantee amount from the sending site to the receiving site of the application pair. If (the local key guarantee amount for the specified link) <= (a value less than the requested global key guarantee amount), a path through that link will be selected, but a path that does not include that link will also always be selected. In other words, as a path from the sending site to the receiving site of the application pair to satisfy the global key guarantee amount, either multiple paths will be selected, or there will be no solution as no path that satisfies the global key guarantee amount can be found. If (the amount of local key guarantees for the specified link) >= 1, then the path passing through that link is selected, and a path that does not include that link may also be selected. For example, if the minimum value set in path constraint (2) is 1 or greater, then the constraint becomes loose, requiring at least 1 or more local key guarantees to use that link.

[0132] The configuration process performed by the configuration unit 117 described above enables flexible route selection for each application pair. Specifically, it is possible to specify which links to include in the route and which links to exclude. The guaranteed amount calculation unit 113 calculates the local key guaranteed amount to be allocated to the link for the transfer of the global key 401 for each of the multiple application pairs, based on the link constraints.

[0133] Next, we will describe in detail an example of the method for calculating the guaranteed amount by the guaranteed amount calculation unit 118 of the embodiment.

[0134] Figure 11 shows an example of variables and constraints in the guaranteed quantity calculation method of the embodiment. Figure 11 shows an example of an equation for calculating the maximum global key guaranteed quantity that the guaranteed quantity calculation unit 118 can guarantee for an application pair.

[0135] Constraints (1) to (3) are the same as in the example in Figure 8.

[0136] Equation (11) is a constraint on node pairs (where the requirement for global key guarantees is not specified) (condition (4)). Specifically, it states that the sum of the local key guarantees for all output links from the source node 100 is 0 or greater, and that the sum of the local key guarantees for all input links to the destination node 100 is 0 or greater.

[0137] The path constraint (1) and path constraint (2) by equation (12) are the same as in the example in Figure 10. Path constraint (2) adds the condition that the amount of local key guarantees used by the specified link is less than the sum of the amount of local key guarantees for all output links from the source node 100.

[0138] The formula in Figure 11 calculates the maximum global key 401 distribution path that can be guaranteed for both registered application pairs and newly registered application pairs. This allows for the determination of an optimal global key distribution path that prevents the previously registered application pair from monopolizing the link's local key 301.

[0139] Furthermore, when the guaranteed amount calculation unit 118 calculates the maximum global key guaranteed amount that can be guaranteed for an application pair, it sets an objective function, for example, as shown in Figure 12.

[0140] Figure 12 shows an example of an objective function in the guaranteed quantity calculation method of the embodiment.

[0141] The objective function E (Equation (13)) maximizes the total amount of local key guarantees output from the source node 100 of the application pair (node ​​pair). In other words, the objective function E maximizes the amount of global key 401 transmitted across the entire key sharing network 502.

[0142] The objective function F (Equation (14)) aims to maximize the minimum and average values ​​of the total amount of local key guarantees output from the source node 100 for each application pair (node ​​pair). The importance of the minimum and average values ​​is selected by how the weights are chosen. In other words, the objective function F aims to equalize the amount of local key used by each link as much as possible.

[0143] Next, we will explain how to calculate the guaranteed amount using adjustment method 3 of the adjustment unit 116 in step S8 if it is not possible to guarantee the global key guaranteed amount for multiple application pairs in step S7 described above. The guaranteed amount calculation unit 118 calculates the formula shown in Figure 13.

[0144] Figure 13 shows an example of variables and constraints in the method for calculating the guaranteed quantity in step S8 of the embodiment.

[0145] The variables and constraints (1) and (2) are the same as in the example in Figure 8.

[0146] Equation (15) is a constraint on the node pair (Constraint (3)). Specifically, it states that the sum of the local key guarantees for all output links from the source node 100 is less than or equal to the requested global key guarantee, and that the sum of the local key guarantees for all input links to the destination node 100 is less than or equal to the requested global key guarantee.

[0147] Path constraints (1) and (2) are the same as in the example in Figure 10.

[0148] Furthermore, when the guaranteed amount calculation unit 118 performs the calculation shown in Figure 13, it sets, for example, the objective function shown in Figure 14.

[0149] Figure 14 shows an example of the objective function in the guaranteed quantity calculation method shown in Figure 13. The explanation for Figure 14 is the same as for Figure 12, so it will be omitted.

[0150] As described above, in the node 100 of the embodiment (an example of a quantum cryptography communication control device), the collection unit 111 collects link information of the link where the local key 301 is generated by quantum key distribution, and the global key guarantee amount for each of the multiple application pairs that perform encrypted communication using the global key 401. The calculation unit 112 calculates the link cost used to select the transfer path of the global key 401 based on the link information. The guarantee amount calculation unit 113 calculates the local key guarantee amount to be allocated to the link for the transfer of the global key 401 for each of the multiple application pairs so as to simultaneously satisfy the global key guarantee amount for each of the multiple application pairs. Then, the selection unit selects the transfer path of the global key 401 based on the link cost and the local key guarantee amount.

[0151] As a result, according to node 100 of the embodiment, the path for the encrypted transfer of the global key 401 can be optimally determined using the local key 301 shared on each link of the key sharing network 502 utilizing quantum key distribution.

[0152] Specifically, according to node 100 of the embodiment, the local key guarantee amount is calculated so as to simultaneously satisfy the global guarantee amount of multiple (e.g., all) application pairs. This makes it possible to optimally determine the path for encrypted transmission of the global key 401 across the entire key sharing network 502, without depending on, for example, the global key guarantee amount and routing settings of application pairs that have already been registered.

[0153] (Modification of Embodiment 1) Next, a modified example 1 of the embodiment will be described. In the description of modified example 1, explanations similar to those of the embodiment will be omitted, and only the differences from the embodiment will be described.

[0154] [Example configuration] Figure 15 shows an example of the configuration of Modification 1 of the embodiment. In Modification 1, node 100 of the above-described embodiment is separated into node 100-2 and central management node 600.

[0155] Node 100-2 comprises a control unit 101, a management unit 102, a platform unit 103, a communication unit 104, and a routing processing unit 110-2. The routing processing unit 110-2 comprises a data collection unit 111 and a storage unit 115.

[0156] The central management node 600 (an example of a quantum cryptography communication control device) comprises a collection unit 601, a storage unit 602, and a routing processing unit 110-3. The routing processing unit 110-3 comprises a calculation unit 112, a guaranteed amount calculation unit 113, a selection unit 114, an adjustment unit 116, a setting unit 117, and a guaranteed amount calculation unit 118.

[0157] As shown in Figure 15, the route calculation process, performed by the calculation unit 112, the guaranteed amount calculation unit 113, the selection unit 114, the adjustment unit 116, the setting unit 117, and the guaranteed amount calculation unit 118, may be carried out by the central management node 600.

[0158] The quantum cryptography communication system 1 of the modified example 1 comprises a plurality of nodes 100-2 and a central management node 600. The plurality of nodes 100-2 are equipped with a collection unit 111 (first collection unit) that collects link information of links where local keys 301 are generated by quantum key distribution and the global key guarantee amount of each of the plurality of application pairs that perform encrypted communication using the global key 401.

[0159] In addition, in the central management node 600 of the modified example 1, the collection unit 601 (second collection unit) collects link information and global key guarantee amounts collected by multiple nodes 100-2. The calculation unit 112 calculates the link cost used to select the transfer path for the global key 401 based on the link information. The guarantee amount calculation unit 113 calculates the local key guarantee amount to be allocated to the link for the transfer of the global key 401 for each of the multiple application pairs so as to simultaneously satisfy the global key guarantee amount for each of the multiple application pairs. Then, the selection unit 114 selects the transfer path for the global key 401 based on the link cost and the local key guarantee amount.

[0160] (Modified embodiment 2) Next, a modified example 2 of the embodiment will be described. In the description of modified example 2, explanations similar to those of the embodiment will be omitted, and only the differences from the embodiment will be described.

[0161] [Example configuration] Figure 16 shows an example of the configuration of Modification 2 of the embodiment. In Modification 2, the node 100 of the above-described embodiment is separated into node 100 and a central management node 600-2.

[0162] The configuration of node 100 (an example of a quantum cryptography communication control device) in Modification 2 is the same as in the embodiment. The central management node 600-2 includes a collection unit 601 and a storage unit 602.

[0163] As shown in Figure 16, route calculation may be distributed by having each node 100 perform route calculation processing, and the route calculation results performed by each node 100 may be stored in the storage unit 602 of the central management node 600.

[0164] Finally, an example of the hardware configuration of node 100 and the central management node 600 in the embodiment will be described. Since the hardware configurations of node 100 and the central management node 600 are similar, the case of node 100 will be used as an example.

[0165] [Example hardware configuration] Figure 17 shows an example of the hardware configuration of node 100 in the embodiment. Node 100 includes a CPU (Central Processing Unit) 51, ROM (Read Only Memory) 52, RAM (Random Access Memory) 53, a communication interface 54, and an auxiliary storage device 55. The CPU 51, ROM 52, RAM 53, communication interface 54, and auxiliary storage device 55 are connected via a bus 56.

[0166] The CPU 51 (an example of a processor) executes programs read into the RAM 53 from the ROM 52 (an example of main memory) and auxiliary storage devices 55. The auxiliary storage devices 55 include HDDs (Hard Disk Drives) and memory cards.

[0167] Furthermore, node 100 may also include a display device for showing the status of node 100, and an input device for receiving input from the user.

[0168] Communication I / F54 includes both a quantum communication IF and a classical communication IF. The quantum communication IF is an interface for connecting to a quantum communication channel (optical fiber link). The classical communication IF is an interface for connecting to a classical communication channel.

[0169] The programs executed on node 100 are provided as computer program products, stored in installable or executable file formats on computer-readable storage media such as CD-ROMs, memory cards, CD-Rs, and DVDs (Digital Versatile Discs).

[0170] Alternatively, the program executed on node 100 may be stored on a computer connected to a network such as the Internet, and provided by allowing users to download it via the network.

[0171] Alternatively, the program executed by node 100 may be configured to be provided via a network such as the Internet without requiring a download.

[0172] Alternatively, the program to be executed on node 100 may be pre-installed and provided in ROM or the like.

[0173] The program executed on node 100 has a modular configuration that includes functions that can be implemented by the program, as described above for node 100. The functions implemented by the program are loaded into RAM 53 by the CPU 51 reading the program from a storage medium such as auxiliary storage device 55 and executing it. In other words, the functions implemented by the program are generated on RAM 53.

[0174] Furthermore, some or all of the functions of node 100 may be implemented by hardware such as an IC (Integrated Circuit). An IC is, for example, a processor that performs dedicated processing.

[0175] Furthermore, when multiple processors are used to implement each function, each processor may implement one of the functions, or it may implement two or more of the functions.

[0176] While several embodiments of the present invention have been described, these embodiments are presented as examples only and are not intended to limit the scope of the invention. These novel embodiments can be carried out in a variety of other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their variations are included in the scope and spirit of the invention, as well as in the claims of the invention and its equivalents. [Explanation of Symbols]

[0177] 1. Quantum cryptography communication system 51 CPU 52 ROM 53 RAM 54 Communication I / F 55 Auxiliary storage device 56 Bus 100 nodes 101 Control Unit 102 Management Department 103 Platform Department 104 Communications Department 105 Quantum Communications Department 106 Classical Literature Correspondence Department 110 Routing Processing Unit 111 Collection Department 112 Calculation Section 113 Guaranteed Quantity Calculation Unit 114 Selection Section 115 Storage section 116 Adjustment section 117 Settings Section 118 Guaranteed Amount Calculation Unit 200 applications 501 Application Network 502 Key Sharing Network 600 central management nodes 601 Collection Department 602 Memory Department

Claims

1. A collection unit that collects link information of links where local keys are generated by quantum key distribution, and the global key guarantee amount of each of multiple application pairs that perform encrypted communication using the global key, A calculation unit calculates the link cost used to select the transfer path of the global key based on the link information, A guarantee amount calculation unit calculates the local key guarantee amount to be allocated to the link for the transfer of the global key of each of the multiple application pairs so as to simultaneously satisfy the global key guarantee amount of each of the multiple application pairs, A selection unit that selects the global key transfer path based on the link cost and the local key guarantee amount, A quantum cryptography communication control device equipped with the following features.

2. The guaranteed amount calculation unit calculates the local key guaranteed amount to be allocated to the link so as to simultaneously satisfy the global key guaranteed amount, performing the calculation as a multi-product flow problem where the application pair is considered a product type and the local key guaranteed amount is considered a flow. The quantum cryptography communication control device according to claim 1.

3. The collection unit further collects information indicating whether or not to calculate the guaranteed amount of global keys for each of the multiple application pairs if it is not possible to satisfy the guaranteed amount of global keys for at least one application pair. When calculating the guaranteed amount of global keys for each of the multiple application pairs, a guaranteed amount calculation unit calculates the local key guaranteed amount to be allocated to the link for the transfer of the global keys for each of the multiple application pairs so as to simultaneously satisfy the guaranteed amount of global keys for each of the multiple application pairs. A quantum cryptography communication control device according to claim 1 or 2, further comprising the above.

4. The guaranteed amount calculation unit calculates the local key guaranteed amount to be allocated to the link so as to simultaneously satisfy the guaranteed amount of the global key, calculating this as a multi-product flow problem where the application pair is considered a product type and the local key guaranteed amount is considered a flow. The quantum cryptography communication control device according to claim 3.

5. The system further includes an adjustment unit that adjusts the global key guarantee amount according to a predetermined policy if it is not possible to meet the global key guarantee amount for at least one application pair. The guarantee amount calculation unit calculates the local key guarantee amount to be allocated to the link for the transfer of the global key of each of the multiple application pairs so as to simultaneously satisfy the adjusted global key guarantee amount. A quantum cryptography communication control device according to claim 1 or 2.

6. The collection unit further collects information indicating the priority of global key guarantee amounts for each of the multiple application pairs, The aforementioned predetermined policy is to reduce the amount of global key guarantees for each of the multiple application pairs by the amount with a lower priority. The quantum cryptography communication control device according to claim 5.

7. The aforementioned policy is to uniformly reduce the global key guarantee amount for each of the multiple application pairs. The quantum cryptography communication control device according to claim 5.

8. The aforementioned policy is to reduce the amount of global key security granted for application pairs that have used the global key less than the application pair that has used the global key less so far, based on the usage history of the global key for each of the multiple application pairs. The quantum cryptography communication control device according to claim 5.

9. The aforementioned policy is to reduce the global key guarantee amount more for application pairs with a shorter remaining unit guarantee period for the global key. The quantum cryptography communication control device according to claim 5.

10. The collection unit further collects information indicating whether or not the guarantee of the global key guarantee amount for each of the multiple application pairs is essential. The aforementioned policy is to reduce the global key guarantee amount for application pairs where the guarantee of the global key guarantee amount is not essential. The quantum cryptography communication control device according to claim 5.

11. The collection unit further collects information indicating the constraints of the links used for the transfer paths of the global keys of each of the plurality of application pairs. The guarantee amount calculation unit calculates the local key guarantee amount to be allocated to the link for the transfer of the global keys of each of the multiple application pairs, based on the constraints of the link. A quantum cryptography communication control device according to claim 1 or 2.

12. Multiple nodes, It includes a central management node, The aforementioned multiple nodes are It includes a first collection unit that collects link information of links where local keys are generated by quantum key distribution, and the global key guarantee amount of each of multiple application pairs that perform encrypted communication using the global key. The aforementioned central management node is A second collection unit collects the link information collected by the plurality of nodes and the global key guarantee amount, A calculation unit calculates the link cost used to select the transfer path of the global key based on the link information, A guarantee amount calculation unit calculates the local key guarantee amount to be allocated to the link for the transfer of the global key of each of the multiple application pairs so as to simultaneously satisfy the global key guarantee amount of each of the multiple application pairs, A selection unit that selects the global key transfer path based on the link cost and the local key guarantee amount, A quantum cryptography communication system equipped with [the necessary components].

13. The quantum cryptography communication control device collects link information of the link where a local key is generated by quantum key distribution, and the global key guarantee amount for each of the multiple application pairs that perform encrypted communication using the global key. The quantum cryptography communication control device performs the steps of calculating the link cost used for selecting the transfer path of the global key based on the link information, The quantum cryptography communication control device calculates the local key guarantee amount to be allocated to the link for the transfer of the global key of each of the multiple application pairs, such that the global key guarantee amount for each of the multiple application pairs is simultaneously satisfied. The quantum cryptography communication control device selects a transfer path for the global key based on the link cost and the local key guarantee amount. A quantum cryptography communication control method including...

14. Computers, A collection unit that collects link information of links where local keys are generated by quantum key distribution, and the global key guarantee amount of each of multiple application pairs that perform encrypted communication using the global key, A calculation unit calculates the link cost used to select the transfer path of the global key based on the link information, A guarantee amount calculation unit calculates the local key guarantee amount to be allocated to the link for the transfer of the global key of each of the multiple application pairs so as to simultaneously satisfy the global key guarantee amount of each of the multiple application pairs, A selection unit selects the global key transfer path based on the link cost and the local key guarantee amount. A program designed to function as such.