QKD device, QKD system, QKD start control method and program
By implementing authentication processing and initiation units in QKD devices, the QKD system ensures secure device-to-device and key manager connections, enhancing security and reliability through legitimate connection verification.
Patent Information
- Application Number
- JP2022119667
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-07-27
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2042-07-27
AI Technical Summary
Existing QKD systems lack robust authentication mechanisms to ensure secure device-to-device and key management connections, limiting their security and reliability.
Incorporating an authentication processing unit and initiation unit in QKD devices to perform device-to-device and key manager authentication, ensuring legitimate connections before enabling QKD functions, and integrating QKD devices with key managers to facilitate secure key sharing across a network.
Enhances the security of QKD systems by verifying the legitimacy of devices and connections, thereby preventing unauthorized access and ensuring secure key distribution.
Smart Images

Figure 0007728232000001 
Figure 0007728232000002 
Figure 0007728232000003
Abstract
Description
[Technical Field]
[0001] Embodiments of the present invention relate to a QKD device, a QKD system, a QKD initiation control method, and a program. [Background technology]
[0002] Quantum Key Distribution (QKD) technology has been known for some time, which uses single photons continuously transmitted between a transmitter and receiver connected by optical fiber to securely share encryption keys. Based on the principles of quantum mechanics, encryption keys generated and shared by QKD technology are guaranteed to be resistant to eavesdropping. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-171530 [Non-patent literature]
[0004] [Non-Patent Document 1] ITU-T Y.3800, [online], [searched on May 20, 2020], Internet <URL: https: / / www.itu.int / rec / T-REC-Y.3800 / en> Summary of the Invention [Problem to be solved by the invention]
[0005] The problem to be solved by the present invention is to provide a QKD device, a QKD system, a QKD initiation control method and a program that can further improve the security of the QKD system. [Means for solving the problem]
[0006] The QKD device of the embodiment includes an authentication processing unit and an initiation unit. The authentication processing unit performs QKD device-to-device connection authentication, which indicates authentication processing with a counterpart QKD (Quantum Key Distribution) device, and KM-QKD connection authentication, which indicates authentication processing with a counterpart KM (Key Manager) device. If the QKD device-to-device connection authentication and the KM-QKD connection authentication are successful, the initiation unit enables the QKD function. [Brief explanation of the drawings]
[0007] [Figure 1] FIG. 1 is a diagram showing a first example of the device configuration of a QKD system according to an embodiment. [Figure 2] FIG. 2 is a diagram for explaining functions of a management system according to an embodiment. [Figure 3] FIG. 10 is a diagram showing a second example of the device configuration of the QKD system according to the embodiment. [Figure 4] FIG. 2 is a diagram showing an example of the functional configuration of a QKD device according to an embodiment. [Figure 5] FIG. 2 is a sequence diagram showing an example of QKD device-management system connection authentication in an embodiment. [Figure 6] FIG. 10 is a sequence diagram illustrating an example of KM-QKD connection authentication according to an embodiment. [Figure 7] FIG. 10 is a sequence diagram showing Example 1 of QKD device-to-device connection authentication according to an embodiment. [Figure 8] FIG. 10 is a sequence diagram showing a second example of QKD device-to-device connection authentication according to the embodiment. [Figure 9] FIG. 1 is a diagram showing an example of the hardware configuration of a QKD device according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0008] Hereinafter, embodiments of a QKD device, a QKD system, a QKD initiation control method and a program will be described in detail with reference to the accompanying drawings.
[0009] (First embodiment) In principle, key sharing using QKD has a limited communication distance and can only be used for one-to-one key sharing. A QKD network can be configured by introducing a key management (KM: Key Manager) device in addition to a QKD device, and configuring the KM device to hold and manage keys and relay them. This makes it possible to share encryption keys between any two locations in a network with QKD as the link and KM devices as the nodes (see Patent Document 1 and Non-Patent Document 1).
[0010] The shared encryption key is provided from the KM device to an external application for use. The QKD device and the KM device may be integrated into a single housing, for example.
[0011] [Example of equipment configuration] 1 is a diagram showing Example 1 of the device configuration of a QKD system 100 of an embodiment. The QKD system 100 of the embodiment includes QKD devices 1a to 1c, KM devices 2a to 2c, and a management system 3. When there is no need to distinguish between the QKD devices 1a to 1c, they will simply be referred to as QKD device 1. Similarly, when there is no need to distinguish between the KM devices 2a to 2c, they will simply be referred to as KM device 2.
[0012] As described above, the QKD device 1 executes the QKD protocol with the opposing QKD device 1 via QKD to generate an encryption key. The encryption key is provided to the KM device 2.
[0013] The KM device 2 receives an encryption key from at least one QKD device 1. The KM device 2 holds and manages the encryption key, and by relaying the encryption key between KM devices 2, encryption key sharing is realized between any KM devices 2. Details of relaying are described in Patent Document 1 and Non-Patent Document 1, etc.
[0014] The management system 3 manages the status and configuration of the QKD network configured by the QKD device 1 and the KM device 2.
[0015] Points A to C are locations where QKD device 1 and KM device 2 are installed. A node consisting of QKD device 1 and KM device 2 is sometimes called a trusted node. Points A to C are assumed to be areas where physical security is ensured, which guarantees the security of the storage and relay of cryptographic keys.
[0016] An application that uses an encryption key connects to the KM device 2, receives the encryption key from the KM device 2, and performs encrypted communication using that encryption key. In many cases, the application is also installed within one of the bases A to C. Furthermore, the management system 3 is generally installed at an independent base (trusted node), or at one of the bases (for example, base C in the example of Figure 1).
[0017] The following describes the connections between QKD devices, the connections between KM devices, and the KM-QKD connections required for the QKD system 100 to be properly connected and operate.
[0018] A QKD inter-device connection is a connection between QKD devices 1, and the QKD protocol is executed through the QKD inter-device connection to generate encryption keys. A QKD device 1 generally consists of a transmitter that transmits photons and a receiver that receives photons, and operates in a specific pair. It is necessary to operate the correct QKD device in the correct pair configuration.
[0019] A connection between KM devices is, for example, a connection used by KM device 2 to verify an encryption key obtained from QKD device 1. A connection between KM devices 2 is also, for example, a connection used to perform key relay using an encryption key. Since KM device 2 handles encryption key data, it goes without saying that KM device 2 itself must be authentic. It is also important that the connection between KM devices 2 is the intended one.
[0020] The KM-QKD connection is a connection used when providing an encryption key generated by QKD device 1 to KM device 2. At the same time, the KM-QKD connection may also be used by KM device 2 (or other management entity via KM device 2) to understand the status of QKD device 1. KM device 2 stores, manages, relays, provides, and deletes the encryption key generated by QKD device 1. For this reason, it is necessary that KM device 2 and QKD device 1 are each legitimate devices, and it is also important that the QKD device 1 paired with KM device 2 is the intended QKD device 1.
[0021] In addition to the need for each QKD device-to-device connection, KM device-to-device connection, and KM-QKD connection to be authentic, the relationships between them are also important. Normally, one pair of QKD devices connected to another KM device in a KM device-to-device connection relationship must be connected, and they must operate to provide the same encryption key to the KM device in the KM device-to-device connection relationship.
[0022] For example, in the example of Figure 1, QKD device 1a and QKD device 1b-1 are connected between QKD devices. QKD device 1a and KM device 2a are connected between KM-QKD devices. QKD device 1b-1 and KM device 2b are connected between KM-QKD devices. KM device 2a and KM device 2b are connected between KM devices. In this way, the correct connection state is when QKD devices 1a and 1b-1, and KM devices 2a and 2b are connected in a "square relationship" consisting of a QKD device-to-device connection, a KM-QKD connection (between QKD device 1b-1 and KM device 2b), a KM device-to-device connection, and a KM-QKD connection (between KM device 2a and QKD device 1a).
[0023] Ensuring security is important in the QKD system 100 of the embodiment shown in Fig. 1. Therefore, even when the QKD device 1 is introduced (or replaced), it is required to go through a proper procedure to confirm that it is a legitimate device and has a proper setting, and to guarantee that connections between appropriate devices are established before the QKD device 1 can be operated.
[0024] Next, the connection including the management system 3 will be described with reference to FIG.
[0025] 2 is a diagram for explaining the functions of the management system 3 of the embodiment. The management system 3 of the embodiment generally monitors the status and configures the QKD device 1 and the KM device 2. When the QKD device 1 is connected to the management system 3, it confirms that the QKD device 1 is authentic. Similarly, when the KM device 2 is connected to the management system 3, it confirms that the KM device 2 is authentic. Note that the management system 3 verifies the authenticity and correctness of the settings of the QKD device 1 and the KM device 2, and based on the results, decides whether to allow the QKD device 1 and the KM device 2 to operate, which is equivalent to the management system 3 activating the QKD device 1 and the KM device 2.
[0026] It should be noted that the configuration of the QKD system 100 of the embodiment is not limited to the example shown in Fig. 1. Fig. 3 is a diagram showing Example 2 of the device configuration of the QKD system 100 of the embodiment. In Example 2 shown in Fig. 3, site C is not included, and the system configuration is simplified.
[0027] To summarize again, the connections included in the system configuration of the QKD system 100 of the embodiment are as follows, and each requires authentication to ensure security. QKD device inter-device connection authentication ·KM device connection authentication KM-QKD connection authentication QKD device-management system connection authentication KM equipment-management system connection authentication
[0028] In the description of the embodiment, authentication directly related to the QKD device 1 (QKD device-to-device connection authentication, KM-QKD connection authentication, and QKD device-management system connection authentication) will be described in detail.
[0029] [Example of functional configuration] 4 is a diagram showing an example of the functional configuration of the QKD device 1 of the embodiment. The QKD device 1 of the embodiment includes an authentication processing unit 11, an initiation unit 12, a generation unit 13, a communication unit 14, and a provision unit 15.
[0030] The authentication processing unit 11 performs processing to realize an authentication function directly related to the QKD device 1. Details of the processing in the authentication function will be described later.
[0031] The initiation unit 12 controls enabling of the QKD function of the QKD device 1 according to the authentication result by the authentication processing unit 11. The QKD function includes at least one of a function to generate an encryption key by QKD and a function to provide the encryption key to the KM device 2.
[0032] Note that there are variations of the method of enabling the functions of the QKD device 1, such as the following methods (1) to (4), and any of these methods may be used. (1) Synchronous operation between the QKD devices 1 (for example, between the QKD devices 1a and 1b-1) required for the QKD devices 1 to operate is initiated. (2) The quantum channel begins to operate, i.e., the transmission and reception of photons. (3) In the key distillation process, the key compression rate is changed to non-zero, thereby outputting a non-zero-sized key (i.e., before authentication, the QKD key distillation process is executed, but the key compression rate is set to zero, so that no key generation is performed). (4) The key provision function to the KM device 2 is started.
[0033] The generation unit 13 generates an encryption key (quantum key) by quantum key distribution, and realizes a so-called QKD protocol function. The generation unit 13 generates an encryption key by QKD between the opposing QKD device 1 whose legitimacy has been verified by QKD device-to-device connection authentication.
[0034] The communication unit 14 is responsible for the communication function in realizing the QKD function. For example, the communication unit 14 transmits and receives photons used for quantum key distribution and control information in the key distillation process between the opposing QKD device 1. For example, the communication unit 14 also performs communication to provide an encryption key (quantum key) to the KM device 2. For example, the communication unit 14 also performs communication to transmit the status of the QKD network to the management system 3.
[0035] The providing unit 15 provides the encryption key generated by QKD to the KM device 2. The providing unit 15 is realized by using part of the functions of the communication unit 14. The providing unit 15 provides the encryption key to the opposing KM device 2 whose legitimacy has been verified by KM-QKD connection authentication.
[0036] <Basic steps of authentication process> Next, variations A to C of the basic authentication operation steps (authentication (or activation / validation) when the QKD device 1 is introduced) in the QKD system 100 of the embodiment will be described.
[0037] A. QKD device-to-device connection authentication and KM-QKD connection authentication are performed, and if both authentications are confirmed to be successful, the QKD function is activated. That is, in variation A, the authentication processing unit 11 performs QKD device-to-device connection authentication, which indicates authentication processing with the opposing QKD device 1, and KM-QKD connection authentication, which indicates authentication processing with the opposing KM device 2. Then, if the QKD device-to-device connection authentication and the KM-QKD connection authentication are successful, the initiation unit 12 enables the QKD function.
[0038] A-2. QKD device-to-device connection authentication is performed, and if the authentication is confirmed to be successful, KM-QKD connection authentication is performed, including the authentication success information, and if the authentication is confirmed to be successful, the QKD function is activated. Variation A-2 corresponds to the activation of QKD device 1 in KM device 2, which is also validation of the QKD device-to-device connection and the KM-QKD connection.
[0039] A-3. KM-QKD connection authentication is performed, and if the authentication is confirmed to be successful, the QKD device-to-device connection authentication is performed, including the authentication success information, and if the authentication is confirmed to be successful, the QKD function is activated. Variation A-3 corresponds to activation in the opposing QKD device 1, which is also validation of the KM-QKD connection.
[0040] B. QKD device-to-device connection authentication, KM-QKD connection authentication, and QKD device-management system connection authentication are performed, and if all authentications are confirmed to be successful, the QKD function is activated.
[0041] B-2. When QKD device-to-device connection authentication and KM-QKD connection authentication are performed and both authentication successes are confirmed, QKD device-management system connection authentication is performed including the authentication success information, and when authentication success is confirmed, the QKD function is activated. That is, in variation B-2, when the QKD device-to-device connection authentication and the KM-QKD connection authentication are successful, the communication unit 14 transmits a QKD device-management system connection authentication request indicating authentication processing with the management system 3 that manages the QKD system 100 to the management system 3. Then, when the QKD device-management system connection authentication mutually verifies that the device itself and the management system 3 are legitimate, the initiation unit 12 enables the QKD function. Variation B-2 corresponds to activation in the management system 3 and also validation of the QKD device-to-device connection and the KM device-QKD device connection.
[0042] C. When the QKD device - management system connection authentication is performed and the success of the authentication is confirmed, the QKD device - to - device connection authentication and the KM - QKD connection authentication are performed because the management system 3 has permitted their execution. When both the QKD device - to - device connection authentication and the KM - QKD connection authentication are confirmed to be successful, the QKD function is activated. That is, in Variation C, the communication unit 14 transmits a request for QKD device - management system connection authentication to the management system 3. Then, when the QKD device - management system connection authentication is successful, the authentication processing unit 11 performs the QKD device - to - device connection authentication and the KM - QKD connection authentication. Variation C corresponds to the management system 3 first performing the activation and validation of the introduced QKD device 1.
[0043] In addition to the above - mentioned Variations A to C, there are various variations in the order of authentication to be performed, the entity that performs the activation, and the connection relationships to be validated, etc., and any combination may be used.
[0044] Hereinafter, examples of the processing steps of each authentication will be explained in detail.
[0045] <QKD device - management system connection authentication> FIG. 5 is a sequence diagram showing an example of QKD device - management system connection authentication according to the embodiment. The example of FIG. 5 shows the case of an authentication sequence executed between the QKD device 1a and the management system 3. Assume that the QKD device 1a holds a CA (Certificate Authority) certificate, a public - key / secret - key pair of the QKD device 1a, and setting information. Assume that the management system 3 holds a CA certificate, a public - key / secret - key pair of the management system 3, and setting information.
[0046] First, the communication unit 14 of the QKD device 1a transmits an authentication request to the management system 3 (step S1). At this time, the authentication request may include setting information of the QKD device 1a. The setting information of the QKD device 1a includes the QKD protocol of the QKD device 1a, implementation information, manufacturer information, customer ID (identifier) information, IP address settings, installation location information, operating parameters, performance indicators, IP address settings of the KM device 2 that provides the encryption key, authentication information up to now, certificate information of the QKD device 1a, etc.
[0047] The performance index may be, for example, an expected key distribution speed (key generation speed). Alternatively, if QKD is already in operation, the performance index may be the actual key distribution speed.
[0048] Furthermore, if the QKD device 1a has already been authenticated for connection with the QKD device 1b-1 or the KM device 2a, authentication result information indicating this authentication may be added to the authentication request as authentication information.
[0049] In addition, the authentication request message may be signed by the QKD device 1a and may include signature information to ensure that the message has not been tampered with and that it has been sent by a legitimate QKD device 1a.
[0050] Next, the management system 3 authenticates the QKD device 1a (step S2). For example, in the authentication of step S2, it is verified whether the QKD device 1a is a legitimate device that has a valid certificate. Also, for example, in the authentication of step S2, it is verified whether the settings of the QKD device 1a are acceptable. Note that the management system 3 may previously store setting information for the acceptable QKD device 1a. Also, for example, in the authentication of step S2, it is verified whether the QKD device 1a has completed authentication that should have been completed in advance (for example, KM-QKD connection authentication, etc.). Also, for example, in the authentication of step S2, it is verified whether the KM device 2 that is the connection authentication destination of the QKD device 1a is the KM device 2a (it may also be verified separately by referring to information stored by the management system 3 whether the above-mentioned "quadrilateral relationship" can be confirmed). Also, for example, in the authentication of step S2, since the setting information for the QKD device 1a also includes a performance index, it may be determined whether authentication is acceptable based on the sufficiency of performance.
[0051] Next, the management system 3 transmits an authentication response (the authentication processing result of step S2) / authentication request to the QKD device 1a (step S3). At this time, the authentication response / authentication request may include setting information of the management system 3.
[0052] The setting information of the management system 3 includes the management protocols supported by the management system 3, implementation information, manufacturer information, customer ID information, IP address settings, installation location information, network information, and configuration, etc. The network information includes, for example, DNS (Domain Name System), NTP (Network Time Protocol), and QKDN (QKD Network) settings, etc.
[0053] The authentication response / authentication request may also include setting information that instructs the QKD device 1a to set settings. The setting information that instructs the QKD device 1a to set settings is, for example, setting information that the QKD device 1a should set (for example, IP address settings, operating parameters, and IP address settings of the KM device 2a that provides the encryption key).
[0054] Furthermore, if the authentication in step S2 does not verify that the QKD device 1a is connected to the KM device 2a, the authentication response / authentication request may include information instructing connection to the KM device 2a or connection authentication to the KM device 2a.
[0055] In addition, the authentication response / authentication request message may be signed by the management system 3 and may include signature information to guarantee that it has not been tampered with and that it has been sent by a legitimate management system 3.
[0056] Next, the authentication processing unit 11 of the QKD device 1a authenticates the management system 3 (step S4). For example, the authentication in step S4 verifies whether the management system 3 is a legitimate device that has a valid certificate. Also, for example, the verification in step S4 verifies whether the settings of the management system 3 are acceptable (whether the network information (settings) of the management system 3 are appropriate). Note that the authentication processing unit 11 may perform the authentication in step S4 after verifying whether the setting information instructed by the management system 3 to the QKD device 1a is acceptable.
[0057] Next, the communication unit 14 transmits an authentication response (the authentication processing result of step S4) to the management system 3 (step S5). The authentication response message may be signed by the QKD device 1a and may include sign information that guarantees that the message has not been tampered with and that it has been sent by the authentic QKD device 1a.
[0058] If the QKD device-management system connection authentication in the above steps S1 to S5 is successful, the QKD device 1a executes one or more of the following processes (1) to (3). (1) The QKD device 1 a reflects the settings instructed by the management system 3 . (2) The authentication processing unit 11 of the QKD device 1a starts the connection authentication (KM-QKD connection authentication, etc.) that needs to be performed next, whether or not instructed by the management system 3. (3) The start part 12 of the QKD device 1a enables the functions of the QKD device 1a.
[0059] If the QKD device - management system connection authentication according to the above steps S1 to S5 fails, the QKD device 1a temporarily stops its operation and takes measures such as notifying abnormalities through logs and alarms.
[0060] On the other hand, the management system 3 records the authentication result in logs and the like.
[0061] <KM - QKD Connection Authentication> FIG. 6 is a sequence diagram showing an example of KM - QKD connection authentication in the embodiment. The example of FIG. 6 shows the case of an authentication sequence executed between the QKD device 1a and the KM device 2a. Assume that the QKD device 1a holds a CA certificate, a public - key / secret - key pair of the QKD device 1a, and setting information. Assume that the KM device 2a holds a CA certificate, a public - key / secret - key pair of the KM device 2a, and setting information.
[0062] First, the communication part 14 of the QKD device 1a sends an authentication request to the KM device 2a (step S11). At this time, the authentication request may include the setting information of the QKD device 1a.
[0063] The setting information of the QKD device 1a includes the QKD protocol of the QKD device 1a, implementation information, manufacturer information, customer ID information, IP address setting, installation location information, operation parameters, performance indicators, and information of the opposite QKD device 1b - 1 to which the QKD device is connected. The information of the opposite QKD device 1b - 1 to which the QKD device is connected is, for example, ID information, address information, and setting information of the opposite QKD device 1b - 1.
[0064] Note that the QKD device connection with the opposite QKD device 1b - 1 may be completed at the time of step S11 or may not be completed.
[0065] Furthermore, if the QKD device 1a has already been authenticated for connection with the QKD device 1b-1 or the management system 3, authentication result information indicating this authentication may be added to the authentication request as authentication information.
[0066] In addition, the authentication request message may be signed by the QKD device 1a and may include signature information to ensure that the message has not been tampered with and that it has been sent by a legitimate QKD device 1a.
[0067] Next, the KM device 2a authenticates the QKD device 1a (step S12). For example, the authentication in step S12 verifies whether the QKD device 1a is a legitimate device that holds a valid certificate. Also, for example, the authentication in step S12 verifies whether the settings of the QKD device 1a are acceptable. Note that the KM device 2a may previously store setting information for the acceptable QKD device 1a. Also, for example, the authentication in step S12 verifies whether the QKD device 1a has completed authentication that should have been completed in advance (for example, QKD device-to-device connection authentication, etc.).
[0068] Also, for example, in the authentication of step S12, it is verified whether the QKD device 1 that is the connection authentication destination of QKD device 1a is QKD device 1b-1. Note that it may also be verified separately by referring to information held by KM device 2a whether the above-mentioned "quadrilateral relationship" can be confirmed. If a normal "quadrilateral relationship" is maintained, QKD device 1b-1, with which QKD device 1a performs QKD device-to-device connection authentication, should have performed KM-QKD connection authentication with KM device 2b, with which KM device 2a performs KM device-to-KM device connection authentication.
[0069] Furthermore, for example, in the authentication in step S12, since the setting information of the QKD device 1a also includes a performance index, it may be possible to determine whether or not to authenticate based on the sufficiency of the performance of the QKD device 1a.
[0070] In addition, in conjunction with the authentication in step S12, the KM device 2a may also perform authentication by communicating with an external device (for example, the management system 3) as necessary.
[0071] Next, the KM device 2a transmits an authentication response (the authentication processing result of step S12) / authentication request to the QKD device 1a (step S13). At this time, the authentication response / authentication request may include setting information of the KM device 2a.
[0072] The setting information of the KM device 2a includes the KM protocol, implementation information, manufacturer information, customer ID information, IP address settings, installation location information, key storage capacity (e.g., current value and maximum storage value, etc.), KM settings, connection application information, information on the QKD devices (transmitters and receivers) connected between the KM and QKD (e.g., ID, settings, and signature, etc.), and information on the KM device 2b connected between the KM devices (e.g., ID, settings, and signature, etc.).
[0073] The authentication response / authentication request may also include setting information that instructs the QKD device 1a to make settings. The setting information that instructs the QKD device 1a to make settings will not be described here as it is the same as in FIG.
[0074] In addition, the authentication response / authentication request message may be signed by the KM device 2a and may include signature information to guarantee that it has not been tampered with and that it has been sent by a legitimate KM device 2a.
[0075] Next, the authentication processing unit 11 of the QKD device 1a authenticates the KM device 2a (step S14). For example, the authentication in step S14 verifies whether the KM device 2a is a legitimate device that holds a valid certificate. Also, for example, the authentication in step S14 verifies whether the settings of the KM device 2a are acceptable (whether the network information (settings) of the KM device 2a is appropriate).
[0076] The authentication processing unit 11 may perform authentication in step S14 after verifying whether the setting information instructed from the KM device 2a to the QKD device 1a is acceptable. For example, the authentication processing unit 11 may refuse connection if the KM protocol, implementation information, manufacturer information, or customer ID information instructed from the KM device 2a to the QKD device 1a is different.
[0077] Also, for example, during authentication in step S14, the authentication processing unit 11 may reset information regarding the amount and frequency of encryption keys that the QKD device 1a provides to the KM device 2a in light of the information on key storage capacity, or may refuse connection in light of the information on key storage capacity.Furthermore, during authentication in step S14, the authentication processing unit 11 may verify whether the KM device 2a has completed authentication that should have been completed in advance (for example, KM device-to-KM device connection authentication, etc.).
[0078] Also, for example, in the authentication of step S14, it is verified whether the KM device 2 to which QKD device 1a is connected and authenticated is KM device 2a. Note that it may also be verified separately by referring to information held by QKD device 1a whether the above-mentioned "quadrilateral relationship" can be confirmed. For example, it may be verified whether the KM device 2b connected to the opposing QKD device 1b-1 and the KM device 2b connected to the opposing KM device 2a are the same device. For example, the authentication processing unit 11 verifies whether the KM devices 2 are the same device by whether the IDs of the KM devices 2 match.
[0079] In addition, in conjunction with the authentication in step S14, the QKD device 1a may perform authentication by communicating with an external device (for example, the management system 3) as necessary.
[0080] Next, the communication unit 14 of the QKD device 1a transmits an authentication completion notification (authentication response / connection start) to the KM device 2a (step S15). The authentication completion notification (authentication response / connection start) message may be signed by the QKD device 1a and may include sign information to guarantee that it has not been tampered with and that it has been sent by the authentic QKD device 1a.
[0081] If the KM-QKD connection authentication in steps S11 to S15 above is successful, the QKD device 1a executes one or more of the following processes (1) to (3). (1) The QKD device 1a reflects the settings instructed by the KM device 2a. (2) The authentication processing unit 11 of the QKD device 1a starts the connection authentication (such as QKD device - to - QKD device connection authentication) that needs to be executed next, whether it is instructed by the KM device 2a or not. (3) The start - up unit 12 of the QKD device 1a enables the functions of the QKD device 1a.
[0082] If the KM - QKD connection by the above steps S11 - S15 fails, the QKD device 1a temporarily stops its operation and takes measures such as notifying the abnormality through logs and alarms.
[0083] On the other hand, if the authentication is successful as a result of the authentication, the KM device 2a executes any one or more of the following (1) - (3) processes. (1) The KM device 2a reflects the settings instructed by the QKD device 1a. (2) The KM device 2a starts the connection authentication (such as KM device - to - KM device connection authentication) that needs to be executed next, whether it is instructed by the QKD device 1a or not. (3) The KM device 2a enables the functions of the KM device 2a.
[0084] If the authentication fails, the KM device 2a temporarily stops its operation and takes measures such as notifying the abnormality through logs and alarms.
[0085] <QKD device - to - QKD device connection authentication> Figure 7 is a sequence diagram showing Example 1 of the QKD device - to - QKD device connection authentication of the embodiment. Example 1 in Figure 7 shows the case of the authentication sequence executed between the QKD device 1a and the QKD device 1b - 1. Assume that the QKD device 1a holds a CA certificate, a public - key / secret - key pair of the QKD device 1a, and setting information. Assume that the QKD device 1b - 1 holds a CA certificate, a public - key / secret - key pair of the QKD device 1b - 1, and setting information.
[0086] First, the communication unit 14 of the QKD device 1a transmits an authentication request (QKD start request) to the QKD device 1b-1 (step S21). At this time, the authentication request may include setting information for the QKD device 1a.
[0087] The setting information of the QKD device 1a includes the QKD protocol, implementation information, manufacturer information, customer ID information, IP address settings, installation location information, operating parameters, performance indicators, and information on the KM device 2a connected to the QKD device 1a, etc. The information on the KM device 2a connected to the KM-QKD device includes, for example, the ID information, address information, and setting information of the KM device 2a.
[0088] It should be noted that the KM-QKD connection with the KM device 2a may or may not be completed at the time of step S21.
[0089] Furthermore, if the QKD device 1a has already been authenticated for connection with the KM device 2a or the management system 3, authentication result information indicating this authentication may be added to the authentication request as authentication information.
[0090] In addition, the authentication request message may be signed by the QKD device 1a and may include signature information to ensure that the message has not been tampered with and that it has been sent by a legitimate QKD device 1a.
[0091] Next, the QKD device 1b-1 authenticates the QKD device 1a (step S22). For example, the authentication in step S22 verifies whether the QKD device 1a is a legitimate device that holds a valid certificate. Also, for example, the authentication in step S22 verifies whether the settings of the QKD device 1a are acceptable. Note that the QKD device 1b-1 may previously store setting information for the acceptable QKD device 1a. Also, for example, the authentication in step S22 verifies whether the QKD device 1a has completed authentication that should have been completed in advance (for example, KM-QKD connection authentication, etc.).
[0092] Also, for example, in the authentication of step S22, it is verified whether the KM device 2 to which QKD device 1a is connected is KM device 2a (information held by QKD device 1b-1 may be referenced to separately verify whether the above-mentioned "quadrilateral relationship" can be confirmed). If a normal "quadrilateral relationship" is maintained, the KM device 2a to which QKD device 1a performs KM-QKD connection authentication should have performed KM device-to-device connection authentication with KM device 2b to which QKD device 1b-1 performs KM device-to-KM device connection authentication.
[0093] In addition, in conjunction with the authentication in step S22, the QKD device 1b-1 may also perform authentication by communicating with an external device (for example, the management system 3) as necessary. An example of the sequence in this case will be described later with reference to Fig. 8. A method in which an external device (the management system 3 in Fig. 8) collectively manages the network configuration or authentication information between components has the advantage of making it easier to grasp the above-mentioned "quadrilateral relationships," etc.
[0094] Next, the QKD device 1b-1 transmits a QKD initiation response (the authentication process result / authentication request of step S22) to the QKD device 1a (step S23). At this time, the QKD initiation response may include setting information for the QKD device 1b-1. Explanation of the setting information for the QKD device 1b-1 is omitted as it is similar to the setting information for the QKD device 1a. The QKD initiation response message may be signed by the QKD device 1b-1 and may include sign information indicating that it has not been tampered with and that it has been sent by the legitimate QKD device 1b-1.
[0095] Next, the authentication processing unit 11 of the QKD device 1a authenticates the QKD device 1b-1 (step S24). Explanation of step S24 is omitted because it is the same as the process in which the QKD device 1b-1 authenticates the QKD device 1a (step S22).
[0096] Next, the communication unit 14 of the QKD device 1a transmits a QKD start notification (authentication completion notification) to the QKD device 1b-1 (step S25). The QKD start notification message may be signed by the QKD device 1a and may include signature information that indicates that the message has not been tampered with and that it has been sent by the authentic QKD device 1a.
[0097] If the inter-QKD device connection authentication in the above steps S21 to S25 is successful, the QKD device 1a executes one or more of the following processes (1) to (3). (1) The QKD device 1a reflects the settings instructed by the QKD device 1b-1. (2) The authentication processing unit 11 of the QKD device 1a starts the connection authentication (KM-QKD, etc.) that needs to be performed next, whether or not instructed to do so by the QKD device 1b-1. (3) The initiator 12 of the QKD device 1a enables the function of the QKD device 1a.
[0098] If the QKD device inter-device connection authentication in steps S21 to S25 fails, the QKD device 1a (temporarily) stops operation and takes measures such as notifying the abnormality by issuing a log or an alarm.
[0099] The operation of the QKD device 1b-1 after successful authentication and after unsuccessful authentication is the same as that of the QKD device 1a.
[0100] In the authentication of step S22 described above, since the setting information of the QKD device 1a includes a performance index such as the key distribution speed (key generation speed) assumed by the QKD device 1a, whether or not authentication is possible may be determined based on the sufficiency of the performance of the QKD device 1a. When determining whether or not authentication is possible based on the sufficiency of performance, specifically, in step S21, the communication unit 14 transmits a QKD start request including the QKD performance index to the counterpart QKD device 1b-1. In the authentication of step S22, the authentication processing unit 11 performs a process of verifying the legitimacy of the QKD device 1a and whether the QKD performance index is satisfied. Next, in the authentication of step S24, the authentication processing unit 11 performs a process of verifying the legitimacy of the counterpart QKD device 1b-1. Then, if the legitimacy is mutually verified and the QKD performance index is satisfied, the authentication processing unit 11 determines that the QKD device-to-device connection authentication has been successful (step S25). The process of verifying whether the QKD performance index is satisfied may be performed on the QKD device 1a side in the authentication of step S24. In this case, the QKD device 1a receives the performance index of the QKD device 1b-1 from the opposing QKD device 1b-1.
[0101] Fig. 8 is a sequence diagram showing Example 2 of QKD device-to-device connection authentication of the embodiment. Example 2 of Fig. 8 shows a case where authentication of QKD devices 1a and 1b-1 is performed by the management system 3 in step S33. Detailed explanation of the processing of each step S31 to S36 is omitted as it is the same as Fig. 7.
[0102] As described above, in the QKD device 1 of the embodiment, the authentication processing unit 11 performs QKD device-to-device connection authentication, which indicates authentication processing with the opposing QKD device 1, and KM-QKD connection authentication, which indicates authentication processing with the opposing KM device 2. Then, if the QKD device-to-device connection authentication and the KM-QKD connection authentication are successful, the initiation unit 12 enables the QKD function.
[0103] As a result, according to the QKD device 1 of the embodiment, the security of the QKD system 100 can be further improved.
[0104] Finally, an example of the hardware configuration of the QKD device 1 of the embodiment will be described.
[0105] [Example of hardware configuration] 9 is a diagram showing an example of the hardware configuration of the QKD device 1 of the embodiment. The QKD device 1 of the embodiment includes a processor 201, a main memory device 202, an auxiliary memory device 203, a display device 204, an input device 205, a quantum communication IF 206, and a classical communication IF 207. The processor 201, the main memory device 202, the auxiliary memory device 203, the display device 204, the input device 205, the quantum communication IF 206, and the classical communication IF 207 are connected via a bus 210.
[0106] The processor 201 executes a program read from the auxiliary storage device 203 to the main storage device 202. The main storage device 202 is memory such as a ROM (Read Only Memory) and a RAM (Random Access Memory). The auxiliary storage device 203 is a hard disk drive (HDD), a memory card, or the like.
[0107] The display device 204 displays the status of the QKD device 1. The input device 205 accepts input from the user. It should be noted that the QKD device 1 does not necessarily have to be equipped with the display device 204 and the input device 205.
[0108] The quantum communication IF 206 is an interface for connecting to a quantum cryptography communication channel (optical fiber link). The classical communication IF 207 is an interface for connecting to a QKD control signal communication channel and the KM device 2, etc. If the QKD device 1 does not have a display device 204 and an input device 205, the display function and input function of an external terminal connected via the classical communication IF 207, for example, may be used.
[0109] The program executed by the QKD device 1 is provided as a computer program product stored in an installable or executable file format on a computer-readable storage medium such as a CD-ROM, memory card, CD-R, or DVD (Digital Versatile Disc).
[0110] Furthermore, the program executed by the QKD device 1 may be stored on a computer connected to a network such as the Internet, and may be provided by being downloaded via the network.
[0111] Furthermore, the program executed by the QKD device 1 may be configured to be provided via a network such as the Internet without being downloaded.
[0112] Furthermore, the program executed by the QKD device 1 may be configured to be provided in advance by being stored in a ROM or the like.
[0113] The program executed by the QKD device 1 has a modular configuration that includes functions that can be realized by the program, among the functional configuration of the above-mentioned QKD device 1. The functions realized by the program are loaded into the main memory device 202 by the processor 201 reading and executing the program from a storage medium such as the auxiliary memory device 203. In other words, the functions realized by the program are generated on the main memory device 202.
[0114] It should be noted that some or all of the functions of the QKD device 1 may be realized by hardware such as an IC (Integrated Circuit). The IC is, for example, a processor that executes dedicated processing.
[0115] Furthermore, when each function is realized using a plurality of processors, each processor may realize one of the functions, or may realize two or more of the functions.
[0116] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, and are also included in the scope of the invention and its equivalents as defined in the claims. [Explanation of symbols]
[0117] 1 QKD device 2 KM equipment 3 Management System 11 Authentication processing section 12 Start part 13 Generation part 14 Communications Department 15 Providing Department 100 QKD Systems 201 processor 202 Main storage 203 Auxiliary storage device 204 Display device 205 Input Device 206 Quantum Communication Interface 207 Classical Communication IF 210 Bus
Claims
1. an authentication processing unit that performs QKD device-to-QKD device connection authentication, which indicates authentication processing with a counterpart QKD (Quantum Key Distribution) device, and KM-QKD connection authentication, which indicates authentication processing with a counterpart KM (Key Manager) device; an initiation unit that enables a QKD function when the QKD device-to-device connection authentication is successful and the KM-QKD connection authentication is successful; A QKD device comprising:
2. If the QKD device-to-device connection authentication is successful and the KM-QKD connection authentication is successful, a communication unit is further provided which transmits a QKD device-management system connection authentication request indicating authentication processing with a management system that manages the QKD system to the management system; The initiation unit enables the QKD function when the authenticity of the device itself and the authenticity of the management system are mutually verified by the QKD device-management system connection authentication. The QKD device of claim 1.
3. A communication unit is further provided for transmitting a request for QKD device-management system connection authentication to the management system, which request indicates an authentication process with the management system that manages the QKD system; When the QKD device-management system connection authentication is successful, the authentication processing unit performs the QKD device-to-QKD device connection authentication and the KM-QKD connection authentication. The QKD device of claim 1.
4. The KM-QKD connection authentication includes a process of verifying whether the KM device connected to the opposing QKD device and the KM device connected between the opposing KM device and the KM device are the same device. A QKD device as claimed in any one of claims 1 to 3.
5. The QKD function includes at least one of a function to generate an encryption key by QKD and a function to provide the encryption key to the KM device. A QKD device as claimed in any one of claims 1 to 3.
6. A communication unit is further provided to transmit a QKD start request indicating a request for connection authentication between the QKD devices to the opposing QKD device, The QKD initiation request includes a QKD performance indicator; The QKD device inter-connection authentication includes a process of mutually verifying the authenticity of the device itself and the authenticity of the opposing QKD device, and a process of verifying whether the QKD performance index is satisfied; The authentication processing unit determines that the QKD device inter-connection authentication has been successful if the authenticity is mutually verified and the QKD performance index is satisfied. A QKD device as claimed in any one of claims 1 to 3.
7. A generation unit that generates an encryption key by QKD between the opposing QKD device whose authenticity has been verified by the QKD device connection authentication; a providing unit that provides the encryption key to a counterpart KM device whose authenticity has been verified by the KM-QKD connection authentication; A QKD device as claimed in any one of claims 1 to 3, further comprising:
8. A system including a plurality of QKD (Quantum Key Distribution) devices and a plurality of KM (Key Manager) devices, Each of the plurality of QKD devices An authentication processing unit that performs QKD device-to-QKD device connection authentication, which indicates authentication processing with a counterpart QKD device, and KM-QKD connection authentication, which indicates authentication processing with a counterpart KM device; an initiation unit that enables a QKD function when the QKD device-to-device connection authentication is successful and the KM-QKD connection authentication is successful; A QKD system comprising:
9. A step in which a QKD (Quantum Key Distribution) device performs QKD device-to-QKD device connection authentication, which indicates authentication processing with a counterpart QKD device, and KM-QKD connection authentication, which indicates authentication processing with a counterpart KM (Key Manager) device; The QKD device enables a QKD function if the QKD device-to-QKD device connection authentication is successful and the KM-QKD connection authentication is successful; A QKD initiation control method including:
10. A QKD (Quantum Key Distribution) device an authentication processing unit that performs QKD device-to-QKD device connection authentication, which indicates authentication processing with a counterpart QKD device, and KM-QKD connection authentication, which indicates authentication processing with a counterpart KM (Key Manager) device; an initiation unit that enables a QKD function if the QKD device-to-device connection authentication is successful and the KM-QKD connection authentication is successful; A program to function as a
Citation Information
Patent Citations
Quantum key transmission control method and system
CN104660602A
ITTY.3800
JP171530A
Quantum cryptographic communication system and method
JP2006203559A
Quantum authentication method and system
JP2007116216A