KM device, QKD system, key management start control method, and program
The KM device with authentication processing and start unit improves QKD system security by managing and relaying encryption keys, allowing secure key sharing between any two locations through multiple authentication steps.
Patent Information
- Application Number
- JP2022119666
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-07-27
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-07-27
AI Technical Summary
Existing quantum key distribution (QKD) systems lack robust security measures in key management, limiting secure key sharing to one-to-one communication and requiring improved authentication and connection protocols for secure key distribution across multiple nodes.
Introducing a key management (KM) device with an authentication processing unit and a start unit to manage and relay encryption keys, ensuring legitimate connections and operations between QKD devices and KM devices through multiple authentication steps.
Enhances the security of key management in QKD systems by enabling secure key sharing between any two locations, ensuring legitimate device connections, and maintaining the integrity of cryptographic keys across a network.
Smart Images

Figure 0007714507000001 
Figure 0007714507000002 
Figure 0007714507000003
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to a KM device, a QKD system, a key management start control method, and a program.
Background Art
[0002] Conventionally, there has been known a quantum key distribution (QKD) technique for securely sharing an encryption key by using single photons continuously transmitted between a transmitting device and a receiving device connected by an optical fiber. The encryption key generated and shared by the quantum key distribution technique (QKD) is guaranteed not to have been eavesdropped on based on the principles of quantum mechanics.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Non-Patent Documents
[0004]
Non-Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] The problem to be solved by the present invention is to provide a KM device, a QKD system, a key management start control method, and a program that can further improve the security of key management in a QKD system.
Means for Solving the Problems
[0006] The key management device of the embodiment includes an authentication processing unit and a start unit. The authentication processing unit performs KM device indirect authentication indicating the authentication processing with the opposing KM (Key Manager) device and KM-QKD connection authentication indicating the authentication processing with the opposing QKD (Quantum Key Distribution) device. The start unit enables the KM function when the KM device indirect authentication is successful and the KM-QKD connection authentication is successful.
Brief Description of the Drawings
[0007]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Embodiments for Carrying Out the Invention
[0008] Hereinafter, embodiments of the KM device, QKD system, key management start control method, and program will be described in detail with reference to the accompanying drawings.
[0009] (First Embodiment) Key sharing by QKD is limited in principle in terms of the communication distance, and only one-to-one key sharing can be used. By introducing a key management (KM) device in addition to the QKD device and having the KM device hold and manage keys and relay keys, a QKD network can be configured. As a result, in a network with QKD as a link and KM devices as nodes, secure key sharing between any two locations becomes possible (see Patent Document 1 and Non-Patent Document 1).
[0010] Note that the shared encryption key is provided from the KM device to an external application and used. The QKD device and the KM device may be integrally realized by, for example, one housing.
[0011] [Example of Device Configuration] FIG. 1 is a diagram showing Example 1 of the device configuration of the QKD system 100 according to the embodiment. The QKD system 100 according to the embodiment includes QKD devices 1a to 1c, KM devices 2a to 2c, and a management system 3. When not distinguishing between the QKD devices 1a to 1c, they are simply referred to as the QKD device 1. Similarly, when not distinguishing between the KM devices 2a to 2c, they are simply referred to as the KM device 2.
[0012] The QKD device 1 executes a QKD protocol with the opposing QKD device 1 by QKD as described above to generate an encryption key. The encryption key is provided to the KM device 2.
[0013] The KM device 2 receives an encryption key from at least one QKD device 1. The KM device 2 holds and manages the encryption key and relays the encryption key between the KM devices 2 to realize secure key sharing between any KM devices 2. Details of the relay are described in Patent Document 1, Non-Patent Document 1, etc.
[0014] The management system 3 manages the state and configuration of the QKD network composed of the QKD devices 1 and the KM devices 2.
[0015] Sites A to C are locations where the QKD device 1 and the KM device 2 are installed. The node composed of the QKD device 1 and the KM device 2 may also be called a trusted node. Sites A to C are assumed to be compartments with physical security ensured, thereby guaranteeing the storage of cryptographic keys and the security in relay.
[0016] Note that the application using the cryptographic key connects to the KM device 2, receives the cryptographic key from the KM device 2, and performs encrypted communication using the cryptographic key. The application is also often installed within Sites A to C. Also, the management system 3 is generally installed in an independent site (trusted node) or in one of the sites (for example, in Site C in the example of FIG. 1).
[0017] The QKD device connection, KM device connection, and KM-QKD connection necessary for the correct connection and operation of the QKD system 100 will be described.
[0018] The QKD device connection is the connection between QKD devices 1. The QKD protocol is executed through the QKD device connection, and cryptographic keys are generated. The QKD device 1 generally consists of a transmitter that sends photons and a receiver that receives photons, and operates in a specific pair. It is necessary to operate the correct QKD devices in the correct pair configuration.
[0019] The KM device connection is, for example, a connection used by the KM device 2 to verify the cryptographic key obtained from the QKD device 1. Also, for example, the KM device connection is a connection used to perform key relay using the cryptographic key. Since the KM device 2 handles cryptographic key data, the KM device 2 itself must of course be legitimate. Also, it is important that the connection between KM devices 2 is the intended connection.
[0020] The KM-QKD connection is a connection used when providing the encryption key generated by the QKD device 1 to the KM device 2. At the same time, the KM-QKD connection may also be used by the KM device 2 (or other management entities via the KM device 2) to grasp the status of the QKD device 1. The KM device 2 performs functions such as holding, managing, relaying, providing, and erasing the encryption key generated by the QKD device 1. Therefore, it is necessary for both the KM device 2 and the QKD device 1 to be legitimate devices, and it is also important that the QKD device 1 paired with the KM device 2 is the intended QKD device 1.
[0021] In addition to each connection being legitimate, the relationships among the QKD device connection, the KM device connection, and the KM-QKD connection are also important. Usually, for the KM device 2 in the relationship of the KM device connection, a pair of QKD devices 1 connected by the QKD device connection is connected, and it is necessary to operate so as to provide the same encryption key to the KM device 2 in the relationship of the KM device connection.
[0022] For example, in the example of FIG. 1, the QKD device 1a and the QKD device 1b-1 are connected by the QKD device connection. The QKD device 1a and the KM device 2a are connected by the KM-QKD connection. The QKD device 1b-1 and the KM device 2b are connected by the KM-QKD connection. The KM device 2a and the KM device 2b are connected by the KM device connection. In this way, the state where the QKD devices 1a and 1b-1, and the KM devices 2a and 2b are connected in a "quadrilateral relationship" by the QKD device connection, the KM-QKD connection (between the QKD device 1b-1 and the KM device 2b), the KM device connection, and the KM-QKD connection (between the KM device 2a and the QKD device 1a) is the correct connection relationship state.
[0023] In the QKD system 100 of the embodiment shown in FIG. 1 above, ensuring security is important. Therefore, even when introducing (or replacing) the KM device 2, it is required to confirm through proper procedures that it is a legitimate device and has a legitimate setting, ensure that it is connected between appropriate devices, and then operate the KM device 2.
[0024] Next, with reference to FIG. 2, the connection including the management system 3 will be described.
[0025] FIG. 2 is a diagram for explaining the functions of the management system 3 of the embodiment. Generally, the management system 3 of the embodiment monitors and sets the states of the QKD device 1 and the KM device 2, etc. When the QKD device 1 is connected to the management system 3, it is confirmed that the QKD device 1 is legitimate. Similarly, when the KM device 2 is connected to the management system 3, it is also confirmed that the KM device 2 is legitimate. In the management system 3, verifying the legitimacy and setting correctness of the QKD device 1 and the KM device 2, and determining the operation permission of the QKD device 1 and the KM device 2 according to the result, that is, the management system 3 activates the QKD device 1 and the KM device 2.
[0026] Note that the configuration of the QKD system 100 of the embodiment is not limited to the example of FIG. 1. FIG. 3 is a diagram showing Example 2 of the device configuration of the QKD system 100 of the embodiment. In Example 2 of FIG. 3, the base C is not included, and the system form is more simplified.
[0027] To summarize again, the connection relationships included in the system configuration of the QKD system 100 of the embodiment are as follows, and for each, authentication for ensuring security is required. · QKD device connection authentication · KM device connection authentication · KM-QKD connection authentication · QKD device - management system connection authentication · KM device - management system connection authentication
[0028] In the description of the embodiment, the authentication directly related to the KM device 2 (KM device connection authentication, KM-QKD connection authentication, and KM device - management system connection authentication) will be described in detail.
[0029] [Example of functional configuration] FIG. 4 is a diagram showing an example of the functional configuration of the KM device 2 of the embodiment. The KM device 2 of the embodiment includes an authentication processing unit 21, a start unit 22, a reception unit 23, a storage unit 24, a relay unit 25, a communication unit 26, and a provision unit 27.
[0030] The authentication processing unit 21 performs processing for realizing an authentication function directly related to the KM device 2. Details of the processing in the authentication function will be described later.
[0031] The start unit 22 performs control to enable (activate) the KM function (key management function) of the KM device 2 according to the authentication result by the authentication processing unit 21. The key management function includes at least one of a function of executing the KM protocol, a function of storing the cryptographic key received from the opposing QKD device, and a function of executing key relay with the opposing KM device.
[0032] Note that as a method for enabling the function of the KM device 2, for example, there are variations of the following (1) to (3), and any method may be used. (1) The reception unit 23 starts receiving a cryptographic key from the QKD device 1. (2) The storage unit 24 starts an operation of storing the cryptographic key received from the QKD device 1. (3) The relay unit 25 starts an operation of relaying the cryptographic key via a link between the correctly connected KM devices 2.
[0033] The reception unit 23 receives a cryptographic key from the QKD device 1 via the KM-QKD connection.
[0034] The storage unit 24 stores the cryptographic key. For example, the storage unit 24 stores the cryptographic key received from the opposing QKD device 1 whose validity has been verified by the KM-QKD connection authentication.
[0035] The relay unit 25 relays (transfers) the encryption key via the KM device indirect connection. For example, the relay unit 25 performs relay processing with the opposing KM device 2 verified as legitimate by KM device indirect connection authentication using the encryption key shared by QKD. For example, the relayed encryption key is the G key (global key) used for communication between different bases. The G key is used as a common key (encryption key and decryption key) when an application performs encrypted communication between different bases, for example.
[0036] The communication unit 26 is responsible for the communication function in realizing the KM function. For example, the communication unit 26 receives an encryption key from the QKD device 1 by communicating with the QKD device 1 via the KM-QKD connection. Also, for example, the communication unit 26 relays the encryption key by communicating with the KM device 2 via the KM device indirect connection. Also, for example, the communication unit 26 provides the encryption key to the application by communicating with the application.
[0037] The providing unit 27 uses the communication function of the communication unit 26 to provide the encryption key to the application. For example, the providing unit 27 provides the above-mentioned common key to the application.
[0038] <Basic operation steps of authentication processing> Next, variations A to C of the basic authentication operation steps (authentication (or activation / validation) when the KM device 2 is introduced) in the QKD system 100 of the embodiment will be described.
[0039] A. When QKD device indirect connection authentication and KM-QKD connection authentication are performed and both authentication successes are confirmed, the KM function is activated. That is, in variation A, the authentication processing unit 21 performs KM device indirect connection authentication indicating the authentication processing with the opposing KM device 2 and KM-QKD connection authentication indicating the authentication processing with the opposing QKD device 1. Then, when the KM device indirect connection authentication is successful and the KM-QKD connection authentication is successful, the start unit 22 enables the KM function.
[0040] A-2. When KM-QKD connection authentication is performed and authentication success is confirmed, including the authentication success information, KM device connection authentication is performed. When authentication success is confirmed, the KM function is activated. Variation A-2 corresponds to the activation in the opposing KM device 2, which is also the validation of the KM-QKD connection.
[0041] B. When KM device connection authentication, KM-QKD connection authentication, and KM device - management system connection authentication are performed and all authentication successes are confirmed, the KM function is activated.
[0042] B-2. When KM device connection authentication and KM-QKD connection authentication are performed and both authentication successes are confirmed, including the authentication success information, KM device - management system connection authentication is performed. When authentication success is confirmed, the KM function is activated. That is, in variation B-2, the communication unit 26 sends a request for KM device - management system connection authentication indicating the authentication process with the management system 3 that manages the QKD system 100 to the management system 3. Then, when the KM device - management system connection authentication is successful, the authentication processing unit 21 performs KM device connection authentication and KM-QKD connection authentication. Variation B corresponds to the activation in the management system 3, which is also the validation of the KM device connection and the KM-QKD connection.
[0043] C. When the KM device - management system indirect connection authentication is performed and its successful authentication is confirmed, the KM device indirect connection authentication and the KM - QKD connection authentication are performed with the permission of the management system 3. When both authentication successes are confirmed, the KM function is activated. That is, in Variation C, when the communication unit 26 has a successful KM device indirect connection authentication and a successful KM - QKD connection authentication, it sends a request for KM device - management system connection authentication indicating the authentication process with the management system 3 that manages the QKD system 100 to the management system 3. Then, when the start unit 22 mutually verifies through the KM device - management system connection authentication that the device itself is legitimate and the management system 3 is legitimate, the KM function is enabled. Variation C corresponds to the management system 3 first performing the activation and validation of the introduced KM device 2.
[0044] In addition to the above - mentioned Variations A to C, there are various variations in the order of authentication to be performed, the entity performing the activation, and the connection relationships to be validated, etc., and any combination may be used.
[0045] Hereinafter, examples of the processing steps of each authentication will be explained in detail.
[0046] <KM device - management system connection authentication> FIG. 5 is a sequence diagram showing an example of KM device - management system connection authentication according to the embodiment. The example of FIG. 5 shows the case of an authentication sequence executed between the KM device 2a and the management system 3. Assume that the KM device 2a holds a CA (Certificate Authoritie) certificate, a public - key / secret - key pair of the KM device 2a, and setting information. Assume that the management system 3 holds a CA certificate, a public - key / secret - key pair of the management system 3, and setting information.
[0047] First, the communication unit 26 of the KM device 2a transmits an authentication request to the management system 3 (step S1). At this time, the authentication request may include the setting information of the KM device 2a. The setting information of the KM device 2a includes the KM protocol of the KM device 2a, implementation information, manufacturer information, customer ID (identifier) information, IP address setting, installation location information, key storage capacity, KM setting, connection application information, information on the QKD device 1a (transmitter / receiver) indirectly connected to KM-QKD, authentication information up to now, and certificate information of the KM device 2a, etc.
[0048] Here, the key storage capacity is, for example, the current value of the cryptographic key stored in the storage unit 24, and the maximum storage value, etc. Also, the KM setting includes, for example, settings such as which KM device 2 at which site to share how many G keys (global keys). Also, the information on the QKD device 1 indirectly connected to KM-QKD is the ID, setting, signature, etc. of the QKD device 1a that has already been indirectly connected to KM-QKD, or the QKD device 1a that will be indirectly connected to KM-QKD in the future.
[0049] Also, as authentication information, if the KM device 2a has already been authenticated for connection with the QKD device 1a or the KM device 2b, authentication result information for indicating that authentication may be added to the authentication request.
[0050] Also, signature information indicating that the message of the authentication request is signed by the KM device 2a and has not been tampered with, and is transmitted by a legitimate KM device 2a may be added.
[0051] Next, the management system 3 authenticates the KM device 2a (step S2). For example, in the authentication of step S2, it is verified whether the KM device 2a is a legitimate device with a valid certificate. Also, for example, in the authentication of step S2, it is verified whether the setting of the KM device 2a (for example, network setting, etc.) is an acceptable setting (appropriate setting). Note that the management system 3 may hold in advance the setting information of the acceptable KM device 2a.
[0052] For example, when the KM protocol, implementation information, manufacturer information, or customer ID information in the management system 3 is inappropriate, or when there is a shortage or inappropriateness in the key storage capacity information, the management system 3 may fail the authentication.
[0053] Also, for example, in the authentication of step S2, it is verified whether the authentication that the KM device 2a should have completed in advance (such as KM device indirect connection authentication, etc.) has been completed. Also, for example, in the authentication of step S2, it is verified whether the KM device 2, which is the authentication destination of the connection of the KM device 2a, is the KM device 2b (separately referring to the information held by the management system 3, it may also be verified whether the above-mentioned "quadrilateral relationship" can be confirmed).
[0054] Next, the management system 3 sends an authentication response (authentication processing result of step S2) / authentication request to the KM device 2a (step S3). At this time, the authentication response / authentication request may include the setting information of the management system 3.
[0055] The setting information of the management system 3 includes the management protocol supported by the management system 3, implementation information, manufacturer information, customer ID information, IP address setting, installation location information, network information, and configuration, etc. The network information is, for example, DNS (Domain Name System), NTP (Network Time Protocol), and QKDN (QKD Network) settings, etc.
[0056] Also, the authentication response / authentication request may include the setting information instructed by the management system 3 to the KM device 2a (such as the IP address setting for specifying the device connected to the KM device 2a, etc.).
[0057] Also, signature information indicating that the message of the authentication response / authentication request is signed by the management system 3 and has not been tampered with, and is sent by a legitimate management system 3 may be added.
[0058] Next, the authentication processing unit 21 of the KM device 2a authenticates the management system 3 (step S4). For example, in the authentication of step S4, it is verified whether the management system 3 is a legitimate device with a valid certificate. Also, for example, in the verification of step S4, it is verified whether the settings of the management system 3 (e.g., network settings, etc.) are acceptable settings (appropriate settings). Note that the authentication in step S4 may be performed after verifying whether the setting information instructed from the management system 3 to the KM device 2a is acceptable.
[0059] Next, the communication unit 26 of the KM device 2a transmits an introduction completion notification (an authentication response indicating the authentication processing result of step S4) to the management system 3 (step S5). The message of the introduction completion notification may be appended with signature information indicating that it is signed by the KM device 2a, has not been tampered with, and is transmitted by a legitimate KM device 2a.
[0060] When the KM device - management system connection authentication according to steps S1 to S5 above is successful, the KM device 2a executes any one or more of the following processes (1) to (3). (1) The KM device 2a reflects the settings instructed from the management system 3. (2) The authentication processing unit 21 of the KM device 2a starts the connection authentication (such as KM - QKD connection authentication) that needs to be executed next, whether it is instructed from the management system 3 or not. (3) The start unit 22 of the KM device 2a enables the functions of the KM device 2a.
[0061] When the KM device - management system connection authentication according to steps S1 to S5 above fails, the KM device 2a (temporarily) stops operating and takes measures such as notifying abnormalities through logs or alarms.
[0062] On the other hand, the management system 3 records the authentication result in a log or the like.
[0063] <KM - QKD Connection Authentication> FIG. 6 is a sequence diagram showing an example of KM-QKD connection authentication according to the embodiment. The example of FIG. 6 shows the case of an authentication sequence executed between the KM device 2a and the QKD device 1a. Assume that the KM device 2a holds a CA certificate, a public-private key pair of the KM device 2a, and setting information. Assume that the QKD device 1a holds a CA certificate, a public-private key pair of the QKD device 1a, and setting information.
[0064] First, the communication unit 26 of the KM device 2a transmits an authentication request to the QKD device 1a (step S11). At this time, the authentication request may include the setting information of the KM device 2a. The setting information of the KM device 2a is the same as the description of FIG. 5 above.
[0065] Note that if the KM device 2a has already been authenticated for connection with the KM device 2b or the management system 3 as authentication information, authentication result information for indicating the authentication may be added to the authentication request.
[0066] Further, signature information indicating that the message of the authentication request is signed by the KM device 2a and has not been tampered with and is transmitted by a legitimate KM device 2a may be added.
[0067] Next, the QKD device 1a authenticates the KM device 2a (step S12). For example, in the authentication of step S12, it is verified whether the KM device 2a is a legitimate device with a valid certificate. Also, for example, in the authentication of step S12, it is verified whether the settings of the KM device 2a are acceptable. Note that the QKD device 1a may hold in advance the acceptable setting information of the KM device 2a. Also, for example, in the authentication of step S12, it is verified whether the KM device 2a has completed the authentication (such as KM device interconnection authentication, etc.) that should be completed in advance.
[0068] For example, in the authentication of step S12, it is verified whether the KM device 2, which is the authentication destination of the connection of the KM device 2a, is the KM device 2b. Additionally, with reference to the information held by the QKD device 1a, it may also be verified whether the above-mentioned "quadrilateral relationship" can be confirmed separately. When the normal "quadrilateral relationship" is maintained, the KM device 2b, which is the KM device for KM device connection authentication by the KM device 2a, should be performing KM-QKD connection authentication with the QKD device 1b-1, which is the QKD device for QKD device connection authentication by the QKD device 1a.
[0069] In addition, in response to the authentication in step S12, the QKD device 1a may perform authentication by communicating with an external device (for example, the management system 3) as necessary.
[0070] Next, the QKD device 1a transmits an authentication response (the authentication processing result of step S12) / authentication request to the KM device 2a (step S13). At this time, the authentication response / authentication request may include the setting information of the QKD device 1a.
[0071] The setting information of the QKD device 1a includes the QKD protocol of the QKD device 1a, implementation information, manufacturer information, customer ID information, IP address setting, installation location information, operation parameters, performance indicators, and information of the KM device 2a connected by KM-QKD, etc. The information of the KM device 2a connected by KM-QKD is, for example, the ID information, address information, and setting information of the KM device 2a.
[0072] In addition, the authentication response / authentication request may include setting information (for example, KM protocol, implementation information, manufacturer information, or customer ID information, etc.) for instructing settings to the KM device 2a.
[0073] In addition, signature information indicating that the message of the authentication response / authentication request is signed by the QKD device 1a and has not been tampered with, and is transmitted by a legitimate QKD device 1a may be added.
[0074] Next, the authentication processing unit 21 of the KM device 2a authenticates the QKD device 1a (step S14). For example, in the authentication of step S14, it is verified whether the QKD device 1a is a legitimate device with a valid certificate. Also for example, in the authentication of step S14, it is verified whether the settings of the QKD device 1a (e.g., network settings, etc.) are acceptable settings (appropriate settings).
[0075] Note that the authentication processing unit 21 may perform the authentication in step S14 after verifying whether the setting information instructed from the QKD device 1a to the KM device 2a is acceptable. For example, if the KM protocol, implementation information, manufacturer information, or customer ID information instructed from the QKD device 1a to the KM device 2a is different, the authentication processing unit 21 may reject the connection.
[0076] Also for example, at the time of authentication in step S14, the authentication processing unit 21 may re - set the information regarding the amount and frequency of the encryption keys provided by the QKD device 1a to the KM device 2a in light of the key storage capacity information, or may reject the connection in light of the key storage capacity information. Further, at the time of authentication in step S14, the authentication processing unit 21 may verify whether the QKD device 1a has completed the authentication (e.g., QKD device - to - device connection authentication, etc.) that should have been completed in advance.
[0077] Also for example, in the authentication of step S14, it is verified whether the QKD device 1 which is the connection authentication destination of the KM device 2a is the QKD device 1a. Additionally, referring to the information held by the KM device 2a, it may be separately verified whether the above - mentioned "quadrilateral relationship" can be confirmed. For example, it may be verified whether the QKD device 1b - 1 connected to the opposing KM device 2b and the QKD device 1b - 1 QKD - device - connected to the opposing QKD device 1a are the same device. For example, the authentication processing unit 21 verifies whether the QKD device 1 is the same device based on whether the IDs of the QKD device 1 match.
[0078] Note that along with the authentication in step S14, the KM device 2a may perform authentication by communicating with an external device (e.g., the management system 3) as necessary.
[0079] Next, the communication unit 26 of the KM device 2a transmits an authentication completion notification (authentication response / connection start) to the QKD device 1a (step S15). The message of the authentication completion notification (authentication response / connection start) may be appended with signature information indicating that it is signed by the KM device 2a and has not been tampered with, and that it is transmitted by an authentic KM device 2a.
[0080] When the KM-QKD connection authentication in steps S11 to S15 is successful, the QKD device 1a executes any one or more of the following processes (1) to (3). (1) The QKD device 1a reflects the settings instructed by the KM device 2a. (2) The authentication processing unit 21 of the QKD device 1a starts the connection authentication (QKD device interconnection authentication, etc.) that needs to be executed next, whether it is instructed by the KM device 2a or not. (3) The start unit 22 of the QKD device 1a enables the functions of the QKD device 1a.
[0081] When the KM-QKD connection in steps S11 to S15 fails, the QKD device 1a (temporarily) stops operating and takes measures such as notifying the abnormality through logs and alarms.
[0082] On the other hand, when the authentication is successful as a result of the authentication, the KM device 2a executes any one or more of the following processes (1) to (3). (1) The KM device 2a reflects the settings instructed by the QKD device 1a. (2) The KM device 2a starts the connection authentication (KM device interconnection authentication, etc.) that needs to be executed next, whether it is instructed by the QKD device 1a or not. (3) The KM device 2a enables the functions of the KM device 2a.
[0083] When the authentication fails, the KM device 2a (temporarily) stops operating and takes measures such as notifying the abnormality through logs and alarms.
[0084] Note that the start trigger for connection authentication may be from the KM device 2 or from the QKD device 1.
[0085] <KM Device Interconnection Authentication> FIG. 7 is a sequence diagram showing Example 1 of the KM device interconnection authentication according to the embodiment. Example 1 in FIG. 7 shows the case of an authentication sequence executed between the KM device 2a and the KM device 2b. It is assumed that the KM device 2a holds a CA certificate, a public key / private key pair of the KM device 2a, and setting information. It is assumed that the KM device 2b holds a CA certificate, a public key / private key pair of the KM device 2b, and setting information.
[0086] First, the communication unit 26 of the KM device 2a transmits an authentication request (connection request) to the KM device 2b (step S21). At this time, the authentication request may include the setting information of the KM device 2b. The setting information of the KM device 2a is the same as the description of FIG. 5 above.
[0087] Note that if the KM device 2a has already been authenticated for connection with the QKD device 1a or the management system 3 as authentication information, authentication result information for indicating that authentication may be added to the authentication request.
[0088] Also, signature information indicating that the message of the authentication request is signed by the KM device 2a and has not been tampered with, and is transmitted by an authentic KM device 2a may be added.
[0089] Next, the KM device 2b authenticates the KM device 2a (step S22). For example, in the authentication of step S22, it is verified whether the KM device 2a is a legitimate device with a valid certificate. Also for example, in the authentication of step S22, it is verified whether the settings of the KM device 2a are acceptable. Note that the KM device 2b may hold in advance the setting information of the acceptable KM device 2a. Also for example, in the authentication of step S22, it is verified whether the KM device 2a has completed the authentication (such as KM-QKD connection authentication, etc.) that should be completed in advance.
[0090] Also for example, in the authentication of step S22, it is verified whether the QKD device 1, which is the connection authentication destination of the KM device 2a, is the QKD device 1a (it may be verified whether the above-mentioned "quadrilateral relationship" can be separately confirmed with reference to the information held by the KM device 2b). When the normal "quadrilateral relationship" is maintained, the QKD device 1a with which the KM device 2a performs KM-QKD connection authentication should be performing QKD device connection authentication with the QKD device 1b-1 with which the KM device 2b performs KM-QKD connection authentication.
[0091] Also for example, when the performance index is included in the setting information of the KM device 2a, the authentication approval in step S22 may be determined based on the sufficiency of the capabilities of the KM device 2a.
[0092] Note that along with the authentication in step S22, the KM device 2b may perform the authentication by communicating with an external device (such as the management system 3) as necessary. An example of the sequence in this case will be described later with reference to FIG. 8. For a method in which an external device (the management system 3 in FIG. 8) collectively manages the network configuration or the authentication information between components, there is an advantage that the above-mentioned "quadrilateral relationship" and the like are easier to grasp.
[0093] Next, the KM device 2b transmits a connection response (the authentication processing result in step S22) to the KM device 2a (step S23). At this time, the connection response may include the setting information of the KM device 2b. The description of the setting information of the KM device 2b is the same as that of the KM device 2a, so it is omitted. Also, the connection response may include the setting information of the KM device 2a instructed by the KM device 2b.
[0094] In addition, signature information indicating that the connection response message is signed by the KM device 2b, not tampered with, and transmitted by an authentic KM device 2b may be added.
[0095] Next, the authentication processing unit 21 of the KM device 2a authenticates the KM device 2b (step S24). The description of step S24 is the same as the processing for the KM device 2b to authenticate the KM device 2a (step S22), so it is omitted.
[0096] Next, the communication unit 26 of the KM device 2a transmits a key relay permission notice (authentication completion notice) to the KM device 2b (step S25). Signature information indicating that the key relay permission notice message is signed by the KM device 2a, not tampered with, and transmitted by an authentic KM device 2a may be added.
[0097] When the KM device - to - KM device connection authentication by the above steps S21 to S25 is successful, the KM device 2a executes any one or more of the following processes (1) to (3). (1) The KM device 2a reflects the settings instructed by the KM device 2b. (2) The authentication processing unit 21 of the KM device 2a starts the connection authentication (such as KM - QKD, etc.) that needs to be executed next, whether it is instructed by the KM device 2a or not. (3) The start unit 22 of the KM device 2a enables the functions of the KM device 2a.
[0098] If the KM device indirect connection authentication according to the above steps S21 to S25 fails, the KM device 2a stops its operation (temporarily) and takes measures such as notifying abnormalities through logs and alarms.
[0099] Note that the operations of the KM device 2b after successful authentication and after failed authentication are the same as those of the KM device 2a.
[0100] In the authentication in step S22 above, the setting information of the KM device 2a includes performance indicators of the KM function such as, for example, the storage capacity (maximum storage value) of the encryption key assumed in the KM device 2a. Therefore, it is also possible to determine whether authentication is possible based on the sufficiency of the performance of the KM device 2a. When determining whether authentication is possible based on the sufficiency of performance, specifically, in step S21, the communication unit 26 transmits a connection request including the performance indicators of the KM function to the opposing KM device 2b. The authentication processing unit 21 performs a process of verifying whether the KM device 2a is legitimate and satisfies the performance indicators of the KM function in the authentication in step S22. Next, in the authentication in step S24, a process of verifying the legitimacy of the opposing KM device 2b is performed. Then, the authentication processing unit 21 determines that the KM device indirect connection authentication has succeeded (step S25) when the legitimacy is mutually verified and the performance indicators of the KM function are satisfied. Note that the process of verifying whether the performance indicators of the KM function are satisfied may be performed on the KM device 2a side in the authentication in step S24. In this case, the KM device 2a receives the performance indicators of the KM device 2b from the opposing KM device 2b.
[0101] FIG. 8 is a sequence diagram showing Example 2 of the KM device indirect connection authentication according to the embodiment. Example 2 in FIG. 8 shows the case where the authentication of the KM devices 2a and 2b is performed by the management system 3 in step S33. The detailed description of the processing of each step S31 to S36 is the same as that in FIG. 7 and is therefore omitted.
[0102] As described above, in the KM device 2 of the embodiment, the authentication processing unit 21 performs KM device connection authentication indicating authentication processing with the opposing KM device and KM-QKD connection authentication indicating authentication processing with the opposing QKD device. The start unit 22 enables the KM function when the KM device connection authentication is successful and the KM-QKD connection authentication is successful.
[0103] According to the QKD device 1 of the embodiment, the security of key management in the QKD system 100 can be further improved.
[0104] Finally, an example of the hardware configuration of the KM device 2 of the embodiment will be described.
[0105] [Example of Hardware Configuration] FIG. 9 is a diagram showing an example of the hardware configuration of the KM device 2 of the embodiment. The KM device 2 of the embodiment includes a processor 301, a main storage device 302, an auxiliary storage device 303, a display device 304, an input device 305, and a communication IF 306. The processor 301, the main storage device 302, the auxiliary storage device 303, the display device 304, the input device 305, and the communication IF 306 are connected via a bus 310.
[0106] The processor 301 executes a program read from the auxiliary storage device 303 to the main storage device 302. The main storage device 302 is a memory such as a ROM and a RAM. The auxiliary storage device 303 is an HDD, a memory card, or the like.
[0107] The display device 304 displays the state of the KM device 2 and the like. The input device 305 receives input from the user. Note that the KM device 2 may not include the display device 304 and the input device 305.
[0108] The communication IF 306 is an interface for communicating with the QKD device 1, the KM device 2, the management system 3, and applications. When the KM device 2 does not include the display device 304 and the input device 305, for example, the display function and the input function of an external terminal connected via the communication IF 306 may be used.
[0109] The program executed by the KM device 2 is stored in a computer-readable storage medium such as a CD-ROM, a memory card, a CD-R, and a DVD (Digital Versatile Disc) in a file in an installable format or an executable format, and is provided as a computer program product.
[0110] Alternatively, the program executed by the KM device 2 may be stored on a computer connected to a network such as the Internet and provided by being downloaded via the network.
[0111] Alternatively, the program executed by the KM device 2 may be provided via a network such as the Internet without being downloaded.
[0112] Alternatively, the program executed by the KM device 2 may be provided by being pre-embedded in a ROM or the like.
[0113] The program executed by the KM device 2 has a module configuration including functions that can be realized by the program among the functional configurations of the above-described KM device 2. The functions realized by the program are loaded into the main storage device 302 when the processor 301 reads the program from a storage medium such as the auxiliary storage device 303 and executes it. That is, the functions realized by the program are generated on the main storage device 302.
[0114] Note that part or all of the functions of the KM device 2 may be realized by hardware such as an IC (Integrated Circuit). The IC is, for example, a processor that executes dedicated processing.
[0115] When realizing each function using a plurality of processors, each processor may realize one of the functions or may realize two or more of the functions.
[0116] Although some embodiments of the present invention have been described, these embodiments are presented by way of example and are not intended to limit the scope of the invention. These novel embodiments can be implemented in various other forms, and various omissions, replacements, and changes can be made without departing from the gist of the invention. These embodiments and their modifications are included in the scope and gist of the invention, and are included in the invention described in the claims and the equivalent scope thereof.
Explanation of Signs
[0117] 1 QKD device 2 KM device 3 Management system 21 Authentication processing unit 22 Start unit 23 Reception unit 24 Storage unit 25 Relay unit 26 Communication unit 27 Provision unit 100 QKD system 301 Processor 302 Main memory device 303 Auxiliary storage device 304 Display device 305 Input device 306 Communication IF 310 Bus
Claims
1. An authentication processing unit that performs KM device indirect connection authentication indicating authentication processing with an opposing KM (Key Manager) device and KM-QKD connection authentication indicating authentication processing with an opposing QKD (Quantum Key Distribution) device; A start unit that enables the KM function when the KM device indirect connection authentication is successful and the KM-QKD connection authentication is successful; A KM device comprising the above.
2. The KM device further comprises a communication unit that transmits a request for KM device - management system connection authentication indicating authentication processing with a management system that manages the QKD system to the management system when the KM device indirect connection authentication is successful and the KM-QKD connection authentication is successful, The start unit enables the KM function when it is mutually verified by the KM device - management system connection authentication that the device itself is legitimate and the management system is legitimate. The KM device according to Claim 1.
3. The KM device further comprises a communication unit that transmits a request for KM device - management system connection authentication indicating authentication processing with a management system that manages the QKD system to the management system, When the KM device - management system connection authentication is successful, the authentication processing unit performs the KM device indirect connection authentication and the KM-QKD connection authentication. The KM device according to Claim 1.
4. The KM-QKD connection authentication includes a process of verifying whether the QKD device connected to the opposing KM device and the QKD device indirectly connected between the opposing QKD devices are the same device. The KM device according to any one of Claims 1 to 3.
5. The KM function includes at least one of a function of executing the KM protocol, a function of storing the encryption key received from the opposing QKD device, and a function of executing key relay with the opposing KM device. The KM device according to any one of Claims 1 to 3.
6. The KM device further comprises a communication unit that transmits a connection request indicating the start of the KM device indirect connection authentication to the opposing KM device, The connection request includes the performance index of the KM function, The KM device indirect connection authentication includes a process of mutually verifying the legitimacy of the device itself and the opposing KM device and a process of verifying whether the performance index of the KM function is satisfied, When the legitimacy is mutually verified and the performance index of the KM function is satisfied, the authentication processing unit determines that the KM device indirect connection authentication is successful. The KM device according to any one of claims 1 to 3.
7. A storage unit that stores a cryptographic key received from a counterparty QKD device verified to be legitimate by the KM-QKD connection authentication; A relay unit that executes relay processing of a common key shared between different bases with a counterparty KM device verified to be legitimate by the KM device connection authentication, using the cryptographic key shared by QKD; A providing unit that provides the common key to an application; The KM device according to any one of claims 1 to 3, further comprising:
8. A QKD (Quantum Key Distribution) system including a plurality of QKD devices and a plurality of KM (Key Manager) devices, Each of the plurality of KM devices includes an authentication processing unit that performs KM device connection authentication indicating an authentication process with a counterparty KM device and KM-QKD connection authentication indicating an authentication process with a counterparty QKD device; and a start unit that enables the KM function when the KM device connection authentication is successful and the KM-QKD connection authentication is successful. The QKD system comprising:
9. Steps for a KM (Key Manager) device to perform KM device connection authentication indicating an authentication process with a counterparty KM device and KM-QKD connection authentication indicating an authentication process with a counterparty QKD (Quantum Key Distribution) device; Steps for the KM device to enable the KM function when the KM device connection authentication is successful and the KM-QKD connection authentication is successful; A key management start control method including:
10. A program for causing a KM (Key Manager) device to function as an authentication processing unit that performs KM device connection authentication indicating an authentication process with a counterparty KM device and KM-QKD connection authentication indicating an authentication process with a counterparty QKD (Quantum Key Distribution) device; and a start unit that enables the KM function when the KM device connection authentication is successful and the KM-QKD connection authentication is successful.
Citation Information
Patent Citations
ITTY.3800
JP171530A
Communication device, communication method, program and communication system
JP2014036322A
Application key management system, application key management device, application key management method, and program
JP2022006778A
Quantum key distribution-based key exchange orchestration service
US20220209943A1