Encrypted communication system, encrypted communication device, and encrypted communication method

The cryptographic communication system addresses the risk of encryption key theft by using secret sharing techniques to distribute the key across multiple nodes, ensuring secure communication even if one node is compromised.

JP7673019B2Active Publication Date: 2025-05-08KK TOSHIBA +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2022066918
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-04-14
Publication Date
2025-05-08
Estimated Expiration
2042-04-14

AI Technical Summary

Technical Problem

The existing cryptographic communication systems face a risk of encryption key theft during transmission between users, particularly due to vulnerabilities in terminal nodes and data transfer between QKD devices.

Method used

The system employs a cryptographic communication method where the encryption key is shared through a network of multiple nodes using secret sharing techniques, distributing the key across multiple nodes to prevent theft even if one node is compromised.

Benefits of technology

This approach effectively prevents the encryption key from being stolen, ensuring secure communication by distributing the key in a way that requires multiple nodes to reconstruct it, thus enhancing the security of the communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007673019000001
    Figure 0007673019000001
  • Figure 0007673019000002
    Figure 0007673019000002
  • Figure 0007673019000003
    Figure 0007673019000003
Patent Text Reader

Abstract

To provide a cryptographic communication system that can prevent cryptographic keys from being stolen even if one of nodes that transmit and receive data about the cryptographic keys to and from users is intruded.SOLUTION: According to an embodiment, in a cryptographic communication system, a first apparatus and a second apparatus that perform cryptographic communication via a first network share an encryption key to be used for cryptographic communication via a second network composed of a plurality of nodes. The first apparatus generates n pieces of first data used to generate an encryption key, allocates the n pieces of first data to n nodes among the plurality of nodes, and sends the data out on the second network to transmit the data to the second apparatus, and generates the encryption key using the n pieces of first data. The second apparatus receives the n pieces of first data from the n nodes among the plurality of nodes, and generates the encryption key using the n pieces of first data.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] An embodiment of the present invention relates to a cryptographic communication system, a cryptographic communication device, and a cryptographic communication method. [Background technology]

[0002] The currently popular public key cryptography relies on computational security, which means that existing computers and algorithms cannot decrypt the cryptography within a valid time. In the future, when quantum computers begin to operate, computational security will no longer be guaranteed, and conventional cryptography will no longer be able to ensure secure communications. Therefore, quantum cryptography is expected to be a cryptography method that has information-theoretic security without relying on computational security. In quantum cryptography, the use of optical cables imposes restrictions on the distance over which keys can be shared directly. Therefore, by relaying the quantum cryptography key using a relay node that can be trusted from a security standpoint, it becomes possible for users in remote locations to share a cryptographic key (random number key) and communicate encrypted using quantum cryptography.

[0003] For example, a cryptographic communication system has been proposed in which, when connecting with a communication partner, multiple independent encryption keys are distributed via multiple different routes, and multiple encryption and decryption are performed using the encryption keys, thereby suppressing degradation of encrypted communication due to a deterioration in the reliability of the relay station. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent No. 5672425 Summary of the Invention [Problem to be solved by the invention]

[0005] However, as shown in Fig. 12, in the above-mentioned cryptographic communication system, although the reliability of the relay nodes A5 and A6 is guaranteed, there is a problem that there is a risk that the cryptographic key may be intercepted over the Internet when it is distributed from the terminal node [1] A3 and terminal node [2] A4 to the user [1] A1, who is the source of the cryptographic communication, and the user [2] A2, who is the destination of the cryptographic communication, by the QKD device (quantum key distribution device) A7 and A8. This problem is known as the last-mile problem.

[0006] As a method for solving the last mile problem, as shown in Fig. 13, in addition to QKD devices B7 and B8 (e.g., BB84) that perform quantum key distribution between the terminal node [1] B3 and the terminal node [2] B4 and the relay node [1] B5 and the relay node [2] B6, it is being considered to place QKD devices (different QKD devices) B15 and B16 (e.g., CVQKD) that perform quantum key distribution between the user [1] B1 and the user [2] B2 at the terminal node [1] B3 and the terminal node [2] B4. In other words, it is being considered to apply quantum cryptography that encrypts information (cryptographic key to be distributed) with a quantum key to communication between the user [1] B1 and the user [2] B2 and the terminal node [1] B3 and the terminal node [2] B4.

[0007] However, even with this method, there remains the risk that an unauthorized person could infiltrate end node [1] B3 or end node [2] B4 and eavesdrop on data transfers between QKD device B7 and QKDB device (a different QKD device) B15, or between QKD device B8 and QKDB device (a different QKD device) B16, thereby stealing information (the quantum key to be distributed).

[0008] One embodiment of the present invention provides a cryptographic communication system, a cryptographic communication device, and a cryptographic communication method that can prevent cryptographic keys from being stolen even if one of the nodes that transmits and receives data related to cryptographic keys to and from a user is intruded into. [Means for solving the problem]

[0009] According to an embodiment, in a cryptographic communication system, a first device and a second device that perform cryptographic communication via a first network share an encryption key used for the cryptographic communication via a second network consisting of a plurality of nodes. The first device generates n pieces of first data to be used for generating the encryption key, transmits the n pieces of first data to the second device by distributing the n pieces of first data to n nodes among the plurality of nodes and sending them onto the second network, and generates an encryption key using the n pieces of first data. The second device receives the n pieces of first data from the n nodes among the plurality of nodes, and generates an encryption key using the n pieces of first data. The first device and the second device generate an encryption key based on second data obtained by a restoration process using a secret sharing scheme in which the n pieces of first data are regarded as shared data. [Brief description of the drawings]

[0010] [Figure 1] FIG. 1 is a diagram illustrating an overall configuration of an encrypted communication system according to a first embodiment. [Diagram 2] FIG. 1 is a block diagram showing an example of the configuration of an encrypted communication system according to a first embodiment. [Diagram 3] 4 is a sequence chart showing the processing steps of a cryptographic communication method executed by the cryptographic communication system according to the first embodiment. [Figure 4] 2 is a block diagram showing an example of a functional configuration of a user (user's communication device) in the encrypted communication system of the first embodiment. [Diagram 5] 2 is a block diagram showing an example of a functional configuration in the case where a node in a quantum cryptography communication network of the cryptographic communication system according to the first embodiment plays the role of a terminal node. FIG. [Figure 6] 2 is a block diagram showing an example of a functional configuration in the case where a node in a quantum cryptography communication network of the cryptographic communication system according to the first embodiment serves as a relay node. FIG. [Figure 7] 2 is a block diagram showing an example of a functional configuration in the case where a node in a quantum cryptography communication network of the cryptographic communication system according to the first embodiment plays the role of an intermediate node. FIG. [Figure 8] FIG. 1 shows an example of a method for generating a random key by ramp secret sharing with a share number of 3 and a threshold value of 3 in the encryption communication system of the first embodiment. [Figure 9]FIG. 2 shows an example of a method for generating a random key by ramp secret sharing with a share number of 3 and a threshold value of 3 in the encryption communication system of the first embodiment. [Figure 10] FIG. 2 is a diagram showing an example of encryption of plaintext data by a user in the encrypted communication system of the first embodiment. [Figure 11] 13 is a diagram showing an example of a method for generating a random number key and encrypting plaintext data in the encrypted communication system according to the second embodiment. [Figure 12] FIG. 1 is a block diagram showing an example of the configuration of an encrypted communication system of a first comparative example. [Figure 13] FIG. 11 is a block diagram showing an example of the configuration of an encrypted communication system of a second comparative example. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0011] Hereinafter, embodiments will be described with reference to the drawings.

[0012] (First embodiment) First, the first embodiment will be described.

[0013] In the cryptographic communication system of the first embodiment, when one of two users performing cryptographic communication via the Internet shares an encryption key with the other user via a quantum cryptographic communication network in which quantum cryptographic communication is performed between nodes, information required for generating the encryption key (hereinafter, the encryption key used in the Internet is also referred to as a random number key) is distributed to multiple nodes and sent to the other user to the quantum cryptographic communication network. The other user receives the information required for generating the encryption key from the multiple nodes. In this way, the cryptographic communication system of the first embodiment can prevent the encryption key from being stolen even if one of the nodes (nodes where data transfer between QKD devices occurs internally) that transmits and receives information required for generating the encryption key to and from the user is intruded into.

[0014] FIG. 1 is a diagram showing a schematic overall view of the cryptographic communication system of the first embodiment. In the cryptographic communication system of the first embodiment, a user [1] 107 (a communication device of the user [1] 107) and a user [2] 115 (a communication device of the user [2] 115) who transmit and receive encrypted data 103 via an Internet network 105 share a random number key 102 for cryptographic communication via a quantum cryptography communication network (a part or all of the section is meshed) 120. In the quantum cryptography communication network 120, a plurality of nodes each having a quantum key distribution function are connected in a mesh shape in a part or all of the section. Although it is called a mesh-shaped connection, it is not necessarily the case that all adjacent nodes are connected. It is also possible that some adjacent nodes are not connected. Quantum key distribution is a technology that utilizes the behavior of quantum such as photons, and for example, a quantum key is generated and shared by transmitting and receiving photons between nodes using optical fiber as a medium. This quantum key is separate from the random number key 102 and is used to execute cryptographic communication (quantum cryptographic communication) between two adjacent nodes on the quantum cryptographic communication network 120. For this cryptographic communication, for example, OTP (One Time Pad cryptography) that cannot be decrypted by the encrypted data alone is used.

[0015] The user [1] 107 encrypts the plaintext data 101 using the random key 102, and transmits the encrypted data 103 generated by this encryption to the user [2] 115 via the Internet 105. The user [2] 115 uses the random key 102 to decrypt the encrypted data 103 received from the user [1] 107 via the Internet 105, and obtains the plaintext data 101.

[0016] When the user [1] 107 shares the random key 102 with the user [2] 115 via the quantum cryptography communication network 120, the user [1] 107 generates a plurality of data (shared data 106) required for generating the random key 102 (108: division). The shared data 106 is, for example, a simple random number. Note that the user [1] 107 has a QKD device for performing quantum key distribution with nodes (terminal node [1] 109, relay node [1] 111) in the quantum cryptography communication network 120, and the encryption key generated by this QKD device may be used as the shared data 106. The encryption key generated by the QKD device is used by the user [1] 107 for cryptographic communication with the nodes in the quantum cryptography communication network 120, and is not the random key 102 used for cryptographic communication with the user [2] 115.

[0017] The QKD device owned by user [1] 107 is, for example, a cheap QKD device with lower specifications than the QKD device for quantum key distribution that each node in the quantum cryptography communication network 120 executes with other nodes. User [2] 115, like user [1] 107, also has a QKD device for quantum key distribution with nodes in the quantum cryptography communication network 120 (terminal node [2] 113, relay node [2] 114).

[0018] User [1] 107 distributes multiple shared data 106 to multiple nodes (terminal node [1] 109, relay node [1] 111) and sends them to a quantum cryptography communication network 120. The multiple shared data 106 are then branched to multiple nodes (terminal node [2] 113, relay node [2] 114) after passing through an intermediate node 112, and are then transmitted to user [2] 115 from each of the branching destinations.

[0019] Each node in the quantum cryptography communication network 120 can be a terminal node, a relay node, or an intermediate node.

[0020] The user [1] 107, which is the sender of the shared data 106, and the user [2] 115, which is the destination of the shared data 106, respectively regard the multiple shared data 106, which are actually just random numbers, as data generated by a sharing process using a secret sharing method, for example, and perform a recovery process using a secret sharing method using an exclusive OR or the like (108: recovery). The user [1] 107 and the user [2] 115 obtain the data obtained by this recovery process as the random key 102, or generate the random key 102 based on the data. The details of the generation of the random key 102 using the shared data 106 will be described later. The random key 102 generated by the user [1] 107 and the random key 102 generated by the user [2] 115 are the same. In other words, this random key 102 is an encryption key shared between the user [1] 107 and the user [2] 115 via the quantum cryptography communication network 120.

[0021] Next, referring to FIG. 2, a detailed description will be given of the mechanism by which the encrypted communication system of the first embodiment prevents the theft of the random key 102 used in the encrypted communication between user [1] 107 and user [2] 115.

[0022] Here, we assume that an application program on user [1] 107 sends data to an application program on user [2] 115. The data output by the application program on user [1] 107 and the data input by the application program on user [2] 115 are the plaintext data 101 described above.

[0023] Plaintext data 101 output by an application program on user [1] 107 is encrypted into ciphertext data 103 by a cryptographic module and transferred to user [2] 114 via the Internet 105. On the other hand, when user [2] 114 receives the ciphertext data 103, the cryptographic module decrypts the ciphertext data 103 into plaintext data 101, which is then input to the application program.

[0024] The same random key 102 is used for encryption by the cryptographic module of user [1] 107 and for decryption by the cryptographic module of user [2] 115. User [1] 107 and user [2] 114 share this random key 102 via a quantum cryptography communication network 120.

[0025] Each node (terminal node [1] 109, relay node [1] 111, relay node [2] 114, terminal node [2] 113) in the quantum cryptography communication network 120 has a QKD device (207, 209, 210, 211, 212, 208) for performing quantum key distribution with other nodes. In other words, the security of cryptographic communication between two nodes in the quantum cryptography communication network 120 is ensured.

[0026] In addition, the user [1] 107 and the terminal node [1] 109 that performs encrypted communication between the user [1] 107 have QKD devices (different QKD devices) 213 and 215 for quantum key distribution. Therefore, the security of the encrypted communication between the user [1] 107 and the terminal node [1] 109 is also ensured.

[0027] However, since data is exchanged between different QKD devices 215 and 207 in the terminal node [1] 109, if the terminal node [1] 109 is intruded, data may be stolen during data exchange between the different QKD devices 215 and 207. Therefore, if the user [1] 107 sends the random key 102 itself to the quantum cryptography communication network 120 via the terminal node [1] 109 toward the user [2] 115, the random key 102 may be stolen. This problem also exists in the terminal node [2] 113 where data is exchanged between the QKD device 208 and the different QKD device 216.

[0028] Therefore, in the communication system of the first embodiment, the user [1] 107 generates, for example, two pieces of data (shared data 106) necessary for generating the random key 102, distributes them to the terminal node [1] 109 and the relay node [1] 111, and sends them to the quantum cryptography communication network 120 toward the user [2] 115. Alternatively, the user [1] 107 regards the two pieces of shared data 106, which are actually just random numbers, as data obtained by a distribution process using a secret sharing method, distributes them to the terminal node [1] 109 and the relay node [1] 111, and sends them to the quantum cryptography communication network 120 toward the user [2] 115. In this case, the distribution / restoration unit 108 executes a restoration process using the secret sharing method to obtain the random key 102, or generates the random key 102 based on the data obtained by the restoration process.

[0029] It is assumed that some kind of security measures are separately implemented for internal data transfer between QKD devices at each node for quantum key distribution in the quantum cryptography communication network 120, such as data transfer between the QKD device 209 and the QKD device 210 in the relay node [1] 111. Here, the method is not important.

[0030] When user [1] 107 starts sharing the random key 102 with user [2] 115 via the quantum cryptography communication network 120, a route is formed on the quantum cryptography communication network 120 so that the two pieces of shared data 106 are sent separately from two nodes in the quantum cryptography communication network 120 to user [2] 115. Note that a certain node may be present on the route of the two pieces of shared data 106 in a redundant manner (between relay node [1] 111 and relay node [1] 114).

[0031] On the other hand, user [2] 115, who has received two pieces of shared data 106 from user [1] 107 via a quantum cryptography communication network 120, performs a recovery process on the two pieces of shared data 106 using a secret sharing method to obtain a random key 102, or generates a random key 102 based on the data obtained by the recovery process.

[0032] As a result, even if the terminal node [1] 109 is intruded into and the shared data 106 exchanged between the different QKD devices 215 and 207 is stolen, the random key 102 cannot be generated without the shared data 106 transmitted to the relay node [1] 111, so the random key 102 is protected. The same is true for the relay node [2] 114 and terminal node [2] 113 on the user [2] 115 side.

[0033] In other words, the communication system of the first embodiment can prevent the encryption key from being stolen even if an adjacent node (109, 113) that transmits and receives information essential for generating the random key 102 between the user (107, 115) is intruded into.

[0034] FIG. 3 is a sequence chart showing the processing steps of the encrypted communication method executed by the encrypted communication system of the first embodiment.

[0035] The cryptographic module of the user [1] 107 requests the random key 102 from the distribution / reconstruction unit 108 (301). Upon receiving this request, the distribution / reconstruction unit 108 generates a first random key [1] (distributed data 106) and distributes the quantum key to the terminal node [1] 109 (302). Note that quantum key distribution here refers to transmitting and receiving the distributed data 106 by cryptographic communication using a quantum key shared between a different QKD device 213 and a different QKD device 215. Note that the random key may be generated by generating a quantum key using a quantum key distribution function.

[0036] The terminal node [1] 109 quantum key distributes the random key [1] received from the distribution / recovery unit 108 of the user [1] 107 to the relay node [1] 111 (303). The relay node [1] 111 quantum key distributes the random key [1] to the intermediate node 112 (the intermediate node 112 adjacent to the quantum cryptography communication network 120) (304). The random key [1] is quantum key distributed in the section of the intermediate node 112, passes through the relay node [2] 114 (305), and is quantum key distributed to the terminal node [2] 113 (306). The terminal node [2] 113 quantum key distributes the random key [1] to the distribution / recovery unit 116 of the user [2] 115 (307).

[0037] In addition, the distribution / reconstruction unit 108 of the user [1] 107 generates a second random key [2] (distributed data 106) and distributes it to the relay node [1] 111 (not to the terminal node [1] 109) (308). The relay node [1] 111 distributes the random key [2] to the intermediate node 112 (309). The random key [1] is quantum key distributed in the section of the intermediate node 112 and is quantum key distributed to the relay node [2] 114 (not to the terminal node [2] 113) (310). The relay node [2] 114 distributes this random key [2] to the distribution / reconstruction unit 116 of the user [2] 115 (311).

[0038] The sharing / restoration unit 108 of the user [1] 107 regards the two random keys [1,2] as data obtained by sharing processing using secret sharing, for example, and executes restoration processing using secret sharing using the two random keys [1,2] to obtain a random key, or generates a random key based on the data obtained by the restoration processing (312). This random key is the aforementioned random key 102 that the cryptographic module of the user [1] 107 uses to encrypt the plaintext data 101 into the encrypted data 103.

[0039] Meanwhile, the sharing / restoration unit 116 of the user [2] 115 also obtains a random key by performing a restoration process based on secret sharing for the two random keys [1, 2], or generates a random key based on the data obtained by the restoration process (313). This random key is the aforementioned random key 102 that the cryptographic module of the user [2] 115 uses to decrypt the encrypted data 103 to the plaintext data 101. The random key 102 on the user [1] 107 side and the random key 102 on the user [2] 115 side are the same.

[0040] The distribution / restoration unit 108 of the user [1] 107 delivers the generated or acquired random key 102 to the cryptographic module (314), while the distribution / restoration unit 108 of the user [2] 115 also delivers the generated random key 102 to the cryptographic module (315). The cryptographic module of the user [1] 107 encrypts the plaintext data 101 using the received random key 102, and transmits the encrypted data 103 to the user [2] 115 via the Internet network 105 (316). Meanwhile, the cryptographic module of the user [2] 115 decrypts the encrypted data 103 received from the user [1] 107 via the Internet network 105 to the plaintext data 101 using the random key 102 received from the distribution / restoration unit 108 (317).

[0041] FIG. 4 is a block diagram showing an example of the functional configuration of the users (107, 115) in the encrypted communication system of the first embodiment.

[0042] The user includes data processing function units including an application unit 401, a data encryption unit 402, a data transmission unit 403, a data reception unit 404, a random key distribution unit 405, a random key recovery unit 406, a random number generation unit 407, a quantum key transmission unit 408, and a quantum key reception unit 409, and a storage function unit of a memory unit 410. The data processing function units may be realized by a central processing unit (CPU) executing a program, or may be realized as hardware such as an electric circuit. The storage function units may be various storage devices such as a hard disk drive (HDD) and a solid state drive (SSD).

[0043] The application section 401 is a program that transmits and receives the plaintext data 101 to and from the application section 401 of the opposing user.

[0044] The data encryption unit 402 encrypts the plaintext data 101 received from the application unit 401 using the encryption key generated by the random number key recovery unit 406 to generate encrypted data 103, or decrypts the encrypted data 103 received by the data receiving unit 404 to obtain the plaintext data 101.

[0045] The data transmitting unit 403 transmits the encrypted data 103 generated by the encryption in the data encrypting unit 402 to the opposite user. On the other hand, the data receiving unit 404 receives the encrypted data 103 from the opposite user.

[0046] The random key distribution unit 405 generates a plurality of shared data 106, which is information essential for generating the random key 102. Note that the shared data 106 generated by the random key distribution unit 405 may be simply random numbers, such as a quantum key. Therefore, the role of the random key distribution unit 405 may be played by the random number generation unit 407, the quantum key transmission unit 408, or the quantum key reception unit 409.

[0047] The random key recovery unit 406 recovers the shared data 106 generated by the random key distribution unit 405 using a secret sharing scheme. The random key recovery unit 606 obtains the random key 102 through this recovery process, or generates the random key 102 based on the data obtained through the recovery process.

[0048] The random number generation unit 407 generates a random number (quantum key) to be used for quantum key distribution between the terminal nodes (109, 113) and the relay nodes (111, 114). Note that the generation of the random number (quantum key) may be performed by the quantum key transmission unit 408 or the quantum key reception unit 409.

[0049] The quantum key transmitting unit 408 transmits the distributed data 106 to the terminal node (109) and the relay node (111). On the other hand, the quantum key receiving unit 409 receives the distributed data 106 from the terminal node (113) and the relay node (114).

[0050] The storage unit 410 stores various data including the plaintext data 101, the random number key 102, the encrypted data 103, the shared data 106, and the random number (quantum key). The various data are deleted from the storage unit 410 as appropriate.

[0051] FIG. 5 is a block diagram showing an example of a functional configuration in the case where nodes in the quantum cryptography communication network 120 of the cryptography communication system according to the first embodiment play the role of terminal nodes (109, 113).

[0052] The terminal node includes data processing function units, ie, a random number generation unit 501 , a split key delivery unit 502 , a quantum key transmission unit 503 and a quantum key reception unit 504 , and a storage function unit, ie, a memory unit 505 .

[0053] The random number generation unit 501 generates a random number (quantum key) to be used for quantum key distribution. In the case of a terminal node, a random number (quantum key) for cryptographic communication with a user and a quantum key for cryptographic communication with a relay node are generated. The generation of the random number (quantum key) may be performed by the quantum key transmission unit 503 or the quantum key reception unit 504.

[0054] The split key transfer unit 502 performs internal transfer of the shared data 106 between QKD devices [different QKD devices] (215, 216) for encrypted communication with the user and QKD devices (207, 208) for encrypted communication with the relay node.

[0055] The quantum key transmission unit 503 transmits the distributed data 106 to the user or the relay node. The transmission of the distributed data 106 to the user is performed by a QKD device [different QKD device] (216), and the transmission of the distributed data 106 to the relay node is performed by a QKD device (207).

[0056] The quantum key receiver 504 receives the distributed data 106 from a user or a relay node. Receiving the distributed data 106 from a user is performed by a QKD device [different QKD device] (215), and receiving the distributed data 106 from a relay node is performed by a QKD device (208).

[0057] The storage unit 505 stores various data including the shared data 106 and the random number (quantum key). The various data are deleted from the storage unit 505 as appropriate.

[0058] FIG. 6 is a block diagram showing an example of a functional configuration in the case where nodes in the quantum cryptography communication network 120 of the cryptography communication system according to the first embodiment play the role of relay nodes (111, 114).

[0059] The relay node comprises data processing function units of a random number generation unit 601 , a split key delivery unit 602 , a quantum key transmission unit 603 and a quantum key reception unit 604 , and a storage function unit of a memory unit 605 .

[0060] The random number generation unit 601 generates random numbers (quantum keys) to be used for quantum key distribution. In the case of a relay node, a random number (quantum key) for cryptographic communication with a user, a random number (quantum key) for cryptographic communication with an end node, and a random number (quantum key) for cryptographic communication with an intermediate node are generated. The generation of random numbers (quantum keys) may be performed by the quantum key transmission unit 603 or the quantum key reception unit 604.

[0061] The split key delivery unit 602 performs internal delivery of the shared data 106 between the QKD devices (219, 220) for cryptographic communication with the users (different QKD devices) and the QKD devices (209, 208) for cryptographic communication with the terminal nodes. The split key delivery unit 602 also performs internal delivery of the shared data 106 between the QKD devices (209, 212) for cryptographic communication with the terminal nodes and the QKD devices (210, 211) for cryptographic communication with the intermediate nodes. For simplification, intermediate nodes between two relay nodes are not shown in FIG. 2.

[0062] The quantum key transmission unit 603 transmits the distributed data 106 to a user, an end node, or an intermediate node. The transmission of the distributed data 106 to the user is performed by a QKD device [different QKD device] (220), and the transmission of the distributed data 106 to the end node or intermediate node is performed by a QKD device (212, 210).

[0063] The quantum key receiver 604 receives the distributed data 106 from a user, an end node or an intermediate node. Receiving the distributed data 106 from a user is performed by a QKD device [different QKD device] (219), and receiving the distributed data 106 from an end node or an intermediate node is performed by a QKD device (209, 211).

[0064] The storage unit 605 stores various data including the shared data 106 and the random number (quantum key). The various data are deleted from the storage unit 605 as appropriate.

[0065] FIG. 7 is a block diagram showing an example of a functional configuration in the case where a node in the quantum cryptography communication network 120 of the cryptography communication system according to the first embodiment plays the role of an intermediate node (112).

[0066] The intermediate node comprises data processing function units of a random number generation unit 701 , a split key delivery unit 702 , a quantum key transmission unit 703 and a quantum key reception unit 704 , and a storage function unit of a memory unit 705 .

[0067] The random number generation unit 701 generates a random number (quantum key) to be used for quantum key distribution. In the case of an intermediate node, a random number (quantum key) for cryptographic communication with a relay node and a random number (quantum key) for cryptographic communication with another intermediate node are generated. Note that the generation of the random number (quantum key) may be performed by the quantum key transmission unit 703 or the quantum key reception unit 704.

[0068] The split key handover unit 702 performs the internal handover of the shared data 106 between the two QKD devices for cryptographic communication with a relay node or other intermediate node.

[0069] The quantum key transmitting unit 703 transmits the shared data 106 to the relay node or another intermediate node, while the quantum key receiving unit 704 receives the shared data 106 from the relay node or another intermediate node.

[0070] The storage unit 705 stores various data including the shared data 106 and the random number (quantum key). The various data are deleted from the storage unit 705 as appropriate.

[0071] Here, a method for generating the random key 102 by the user (107, 115) in the encrypted communication system of the first embodiment will be described with reference to FIGS.

[0072] 8 is the first diagram showing an example of a method for generating the random key 102 by the users (107, 115) in the cryptographic communication system of the first embodiment. Here, an example is given of generating the random key 102 by ramp secret sharing with the number of shares being 3 and the threshold being 3 (this example is ramp secret sharing with (thresholds K=3, L=2, number of shares N=3)). In this case, it is preferable that the user 107 sends the three pieces of shared data 106 to the quantum cryptography communication network 120 via different nodes. It is also preferable that the user 115 receives the three pieces of shared data via different nodes.

[0073] In the case of this ramp secret sharing, even if one of the three shared data 106 is intercepted, it cannot be restored. Also, here, it is assumed that the ratio of random numbers (dummy data, i.e., disposable physical random numbers) to plain text (here, the common key, i.e., the physical random numbers used as the random number key 102) is "1:2". The ramp type is a type in which the ratio of random numbers to plain text is changeable, and when the ratio of random numbers to plain text is "(threshold-1):1", it is particularly called perfect secret sharing.

[0074] Assume that user [1] 107 has a certain physical random number. Assume that user [1] 107 considers the physical random number as the original data and performs a sharing process using ramp secret sharing with a threshold value of 3. User [1] 107 regards the randomly generated random numbers (random key [1], random key [2], random key [3]) as being obtained by this sharing. In other words, user [1] 107 does not actually generate shared data 106 using secret sharing here. Therefore, the shared data 106 can be a quantum key generated by a quantum key distribution function, which improves the efficiency of physical random number generation. In this way, the present invention has features not found in data transfer using simple secret sharing. It is also possible to generate distributed data 106 by distributing the randomly generated random numbers (random key [1], random key [2], random key [3]) using a secret sharing method. However, in this case, user [1] 107 must generate additional physical random numbers to serve as the original data in addition to the quantum key (physical random number) generated by the quantum key distribution function, which reduces the efficiency of physical random number generation.

[0075] To explain the sharing process of ramp secret sharing with threshold 3 in more detail, first, the original data is sorted into the threshold number. For example, if the original data is "1 to 15", it is sorted into "1, 4, 7, 10, 13", "2, 5, 8, 11, 14", and "3, 6, 9, 12, 15". In Figure 8, each group after sorting is represented by a row.

[0076] Next, to generate the three shared data, the second row of the shared data (2) is shifted by one column, and the third row of the shared data (3) is shifted by one column, and then, for each of the shared data (1) to (3), a convolution is performed using, for example, exclusive OR. Note that this convolution is not limited to exclusive OR, and may be a calculation using a polynomial, or addition or subtraction.

[0077] When user [1] 107 generates a random number, it regards this random number as shared data obtained by the above procedure (distribution processing by ramp secret sharing with threshold 3). In other words, user [1] 107 generates multiple random number sequences (random key [1], random key [2], random key [3]) and regards each random number sequence as shared data. User [1] 107 distributes the random numbers (shared data 106) to different routes for each random number sequence and transfers them to user [2] 115.

[0078] FIG. 9 is a second diagram showing an example of a method for generating the random key 102 by the user [1] 107 in the encrypted communication system of the first embodiment.

[0079] User [1] 107 uses three pieces of shared data 106 (which are actually just random numbers) to perform a recovery process using ramp secret sharing with three shares and a threshold of three (in this example, ramp secret sharing with thresholds K=3, L=2, and N=3 shares) (see “Calculation” in FIG. 9). This recovery process yields the original data “1 to 15” of the hypothetical physical random numbers mentioned above.

[0080] If the restoration process is performed in this manner without performing the sharing process using the secret sharing method, the data (original data) of some layers (rows) of some of the shared data will be inconsistent (if all the shared data is restored to the original data, the original data will not match for some of the shared data). In order to prevent inconsistency, it is sufficient to consider that some of the shared data is exclusive-ORed with another random number (x1 to x5). This can be considered to have been shared in advance between user [1] 107 and user [2] 115. If user [1] 107 and user [2] 115 decide in advance or dynamically which shared data to use to generate the original data, the original data generated by at least user [1] 107 and user [2] 115 will match, so this inconsistency will not be a problem. Although there is some inconsistency, the restoration process is performed using the secret sharing method by considering the physical random numbers (random key [1], random key [2], random key [3]) as the shared data, so security is sufficiently ensured.

[0081] Here, it is assumed that the ratio of random numbers to plain text is "1:2", so the user [1] 107 removes, for example, "1, 4, 7, 10, 13" (one predetermined row) as dummy data (disposable physical random numbers) from the restored original data "1 to 15", and extracts "2, 3, 5, 6, 8, 9, 11, 12, 14, 15" (two predetermined rows), thereby generating the random number key 102.

[0082] In the case of perfect secret sharing, the ratio of random numbers to plaintext is “threshold-1:1” (”2:1”), so user [1] 107 generates the random key 102 by, for example, removing “1, 2, 4, 5, 7, 8, 10, 11, 13, 14” (predetermined two rows) as dummy data (disposable physical random numbers) and extracting “3, 6, 9, 12, 15” (predetermined one row).

[0083] On the other hand, user [2] 115 who received the shared data 106 from user [1] 107 also performs the same calculation as user [1] 107 to generate a random key 102. The random key 102 generated by user [1] 107 is the same as the random key 102 generated by user [2] 115. In other words, this random key 102 is the random key 102 shared between user [1] 107 and user [2] 115.

[0084] FIG. 10 is a diagram showing an example of encryption of plaintext data 101 by user [1] 107.

[0085] User[1]107, Random key 102 XOR plaintext data 101 By calculating the above, the encrypted data 103 is obtained.

[0086] In this way, the cryptographic communication system of the first embodiment distributes multiple pieces of shared data 106 (which are actually just random numbers) considered to have been shared by the ramp secret sharing scheme, so that even if an unauthorized eavesdropper intrudes into one of the nodes that transmits and receives the shared data 106 to and from the users and steals a part of the shared data 106, the information of the random key 102 will not be leaked. Therefore, even a part of the encrypted data 103 communicated between user [1] 107 and user [2] 115 on the Internet 105 cannot be decrypted.

[0087] As described above, in the cryptographic communication system of the first embodiment, assuming the restoration process by the secret sharing method between users, the multiple shared data 106 essential for generating the random key 102 are distributed to multiple nodes and sent to the quantum cryptography communication network 120, and the multiple shared data 106 are received from multiple nodes of the quantum cryptography communication network 120 to share the random key 102 (common key). Even if an unauthorized eavesdropper intrudes into one node that transmits and receives the shared data 106 to and from users and steals some of the multiple shared data 106 essential for generating the random key 102, the unauthorized eavesdropper will not be able to decrypt the random key 102, and the security of the user's communications can be maintained.

[0088] In the above description, it is assumed that there exists some original data, and the restoration is performed by ramp secret sharing with a share number of 3 and a threshold value of 3. If the ratio of random numbers to plaintext is "1:2", one line (out of three lines) from the data obtained by the restoration is removed as random numbers (dummy data), and two lines of data are used as the random key 102. If information-theoretic security is given up here, all of the data obtained by the restoration can be used as plaintext (random key 102), or only a part of the line can be used as random numbers, rather than the entire line. Even in this case, although information-theoretic security cannot be ensured, the combination of operators for obtaining the original data is enormous, and the security of the user's encrypted communication can be sufficiently ensured. In this case, the consumption of random numbers can be significantly reduced. Therefore, the transfer rate is also improved accordingly.

[0089] When the threshold value is set to 2, the ratio of random numbers to plaintext must be set to "1:1" to ensure information-theoretic security. However, as mentioned above, if information-theoretic security is abandoned, all the data obtained by the restoration can be used as plaintext, or only a part of one line (out of two lines) can be used as random numbers, instead of the entire line. Even in this case, information-theoretic security cannot be ensured, but the combination of operators to obtain the original data is enormous, and the security of the user's encrypted communication can be sufficiently ensured. Therefore, the consumption of random numbers can be significantly reduced. Note that, for the sake of simplicity, the secret sharing schemes shown in Figs. 8 and 9 have been described here, but the secret sharing schemes that can be used are not limited to these, and other secret sharing schemes using exclusive OR or secret sharing schemes using polynomials can also be used.

[0090] Second embodiment Next, a second embodiment will be described.

[0091] In the cryptographic communication system of the first embodiment, one of two users performing cryptographic communication generates multiple random numbers as shared data 106, regards the data as data generated by distributing them using a secret sharing scheme, performs a restoration process using the secret sharing scheme, and obtains a random key 102. In addition, one of the two users distributes the multiple shared data 106 to multiple nodes and sends it to the other of the two users over a quantum cryptography communication network 120. Meanwhile, the other of the two users receives the multiple shared data 106 from the multiple nodes, performs a restoration process using the secret sharing scheme, and obtains a random key 102.

[0092] In contrast, in the cryptographic communication system of the second embodiment, one of two users performing cryptographic communication generates multiple random numbers as shared data 106, and then considers the data as data generated by distributing them using a secret sharing scheme, and instead of performing a restoration process using the secret sharing scheme, superimposes the data using an exclusive OR or the like to generate a random key 102. Meanwhile, the other user also superimposes multiple shared data 106 received from multiple nodes of the quantum cryptography communication network 120 using an exclusive OR or the like to generate a random key 102. Note that the superposition may be performed using any of the many other techniques available, such as addition or subtraction, instead of or in addition to the exclusive OR.

[0093] Even in this case, there is no communication redundancy (the number of shares is made larger than a threshold value) compared to the cryptographic communication system of the first embodiment, but based on the assumption of overlapping between users, such as exclusive OR, multiple shared data 106 essential for generating the random key 102 are distributed to multiple nodes and sent to the quantum cryptography communication network 120, and the multiple shared data 106 are received from multiple nodes of the quantum cryptography communication network 120 to share the random key 102 (common key). Even if an unauthorized eavesdropper intrudes into one node that transmits and receives the shared data 106 to and from a user and steals some of the multiple shared data 106 essential for generating the random key 102, the unauthorized eavesdropper will not be able to decrypt the random key 102, and the security of user communications can be maintained.

[0094] FIG. 11 is a diagram showing an example of a method for generating a random number key 102 and encrypting plaintext data 101 in the encrypted communication system according to the second embodiment.

[0095] Here, the two generated random keys (distributed data 106) are called random key [1] and random key [2], respectively. The sending user (user [1] 107) Random key[1] XOR random key[2] By calculating the above, the random key 102 is obtained.

[0096] Also, user [1] A11, Random key 102 XOR plaintext data 101 By calculating the above, the encrypted data 103 is obtained.

[0097] In addition, the receiving user (user [2] 115) Random key[1] XOR random key[2] By calculating the above, the random key 102 is obtained.

[0098] And user [2]115, Random key 102 XOR encrypted data 103 By calculating the above, the plaintext data 101 is obtained.

[0099] In this way, since the encrypted communication system of the second embodiment generates the random key 102 by superimposing the Vernam cipher of multiple shared data 106, even if an unauthorized eavesdropper intrudes into one node that transmits and receives the shared data 106 between users and steals a portion of the shared data 106, he or she will not be able to decrypt even a portion of the encrypted data 103 communicated by two users over the Internet network 105.

[0100] As described above, in the cryptographic communication system of the second embodiment, multiple pieces of shared data 106 required for generating the random key 102 are distributed to multiple nodes and sent to the quantum cryptography communication network 120, assuming superposition such as exclusive OR between users, and the multiple pieces of shared data 106 are received from multiple nodes of the quantum cryptography communication network 120 to share the random key 102 (common key). Even if an unauthorized eavesdropper intrudes into one node that transmits and receives the shared data 106 to and from a user and steals part of the multiple pieces of shared data 106 required for generating the random key 102, the unauthorized eavesdropper will not be able to decrypt the random key 102, and the security of user communications can be maintained.

[0101] Although some embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be implemented in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included in the scope and spirit of the invention, and are included in the scope of the invention and its equivalents described in the claims. [Explanation of symbols]

[0102] 101...plaintext data, 102...random key, 103...encrypted data, 105...Internet network, 106...distributed data, 107, 115...user (user's communication device), 109, 113...terminal node, 112...intermediate node, 120...quantum cryptography communication network, 213-220...QKD device (different QKD device), 207-212...QKD device, 401...application unit, 402...data encryption unit, 403...data transmission unit, 404...data reception unit, 405...random key distribution unit, 406...random key recovery unit , 407...random number generation unit, 408...quantum key transmission unit, 409...quantum key receiving unit, 410...memory unit, 501...random number generation unit, 502...distributed data delivery unit, 503...quantum key transmission unit, 504...quantum key receiving unit, 505...memory unit, 601...random number generation unit, 602...distributed data delivery unit, 603...quantum key transmission unit, 604...quantum key receiving unit, 605...memory unit, 606...random number key recovery unit, 701...random number generation unit, 702...distributed data delivery unit, 703...quantum key transmission unit, 704...quantum key receiving unit, 705...memory unit.

Claims

1. A cryptographic communication system in which a first device and a second device, which perform cryptographic communication via a first network, share a cryptographic key used in the cryptographic communication via a second network consisting of a plurality of nodes, The first device is generating n pieces of first data to be used for generating the encryption key; Transmitting the n pieces of first data to the second device by distributing the n pieces of first data to n nodes among the plurality of nodes and transmitting the data onto the second network; generating the encryption key using the n pieces of first data; The second device is receiving the n pieces of first data from n pieces of nodes among the plurality of nodes; generating the encryption key using the n pieces of first data; the first device and the second device generate the encryption key based on second data obtained by a restoration process using a secret sharing scheme in which the n pieces of first data are regarded as shared data. Cryptographic communication system.

2. 2. The cryptographic communication system according to claim 1, wherein the secret sharing scheme is a ramp secret sharing scheme including a perfect secret sharing scheme.

3. An encryption communication device that performs encryption communication with another encryption communication device via a first network, and shares an encryption key used in the encryption communication with the other encryption communication device via a second network configured with a plurality of nodes, comprising: means for generating n pieces of first data to be used in generating the encryption key; a means for distributing the n number of first data items to n number of nodes among the plurality of nodes and transmitting the data items onto the second network, thereby transmitting the data items to the other encryption communication device; means for generating the encryption key using the n first data; Equipped with the means for generating the encryption key generates the encryption key based on second data obtained by a restoration process using a secret sharing scheme in which the n pieces of first data are regarded as shared data. Cryptographic communication device.

4. A cryptographic communication device as described in Claim 3, wherein the secret sharing scheme is a ramp secret sharing scheme including a perfect secret sharing scheme.

5. 1. A cryptographic communication method in which a first device and a second device, which perform cryptographic communication via a first network, share a cryptographic key used in the cryptographic communication via a second network consisting of a plurality of nodes, comprising: The first device is generating n pieces of first data to be used for generating the encryption key; Transmitting the n pieces of first data to the second device by distributing the n pieces of first data to n nodes among the plurality of nodes and transmitting the data onto the second network; generating the encryption key using the n pieces of first data; The second device is receiving the n pieces of first data from n pieces of nodes among the plurality of nodes; generating the encryption key using the n pieces of first data; the first device and the second device generate the encryption key based on second data obtained by a restoration process using a secret sharing scheme in which the n pieces of first data are regarded as shared data. Encryption communication method.

6. A cryptographic communication method as described in Claim 5, wherein the secret sharing scheme is a ramp secret sharing scheme including a perfect secret sharing scheme.

Citation Information

Patent Citations

  • Camera with dataaboard simultaneous photographing device

    JP1981072425A

  • Encryption communication system and encryption communication method

    JP2011082832A

  • Quantum Key Distribution System, Method and Apparatus Based on Trusted Relay

    JP2018502514A

  • Encryption communication system, encryption communication apparatus, and encryption communication method

    JP2023145914A