Key management device, quantum cryptography communication system, key management method and program
The key management device facilitates secure and efficient association of QKD devices by using identity verification and module IDs, addressing the challenge of associating multiple QKD devices in quantum key distribution systems.
Patent Information
- Application Number
- JP2023032520
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-03
- Publication Date
- 2025-09-08
- Estimated Expiration
- 2043-03-03
AI Technical Summary
Conventional quantum key distribution systems face difficulties in associating pairs of QKD devices that share a QKD key, particularly when there are multiple devices, leading to high engineering costs and vulnerability to eavesdropping.
A key management device is introduced that connects to local and remote QKD devices via quantum and classical communication channels, using identity verification data and QKD module IDs to automatically associate QKD modules, ensuring secure key sharing without transmitting the QKD key over classical channels.
This solution enables easy and secure association of QKD devices, reducing engineering costs and preventing eavesdropping by ensuring the same QKD key is used for encryption and decryption across multiple devices.
Smart Images

Figure 0007735340000001 
Figure 0007735340000002 
Figure 0007735340000003
Abstract
Description
[Technical Field]
[0001] An embodiment of the present invention relates to a key management device, a quantum cryptography communication system, a key management method, and a program. [Background technology]
[0002] Quantum Key Distribution (QKD) is a technology that securely shares a QKD key (quantum key) between a QKD device that continuously transmits single photons and a QKD device that receives single photons, both connected by optical fiber. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 6599401 [Patent Document 2] Patent No. 6426477 Summary of the Invention [Problem to be solved by the invention]
[0004] However, in the conventional technology, when there are multiple QKD devices, it is not easy to associate pairs of QKD devices that share a QKD key. [Means for solving the problem]
[0005] A key management device according to an embodiment is connected to at least one remote QKD (Quantum Key Distribution) device and at least one local QKD device connected via a quantum communication channel. The key management device includes an acquisition unit and a processing unit. The acquisition unit acquires, from another key management device via a classical communication channel, identity verification data for a remote QKD key generated by the remote QKD device and remote QKD device identification information for identifying the remote QKD device. The processing unit collects the local QKD key generated by the local QKD device and the local QKD device identification information for identifying the local QKD device, generates identity verification data for the local QKD key, and, if the identity verification data for the remote QKD key and the identity verification data for the local QKD key match, associates the remote QKD device identification information with the local QKD device identification information. [Brief explanation of the drawings]
[0006] [Figure 1] FIG. 1 is a diagram showing an example of the device configuration of a quantum cryptography communication system according to a first embodiment. [Figure 2] FIG. 2 is a diagram showing an example of the functional configuration of a key management device according to the first embodiment. [Figure 3] FIG. 2 is a diagram showing an example of the functional configuration of a QKD module according to the first embodiment. [Figure 4] 4 is a flowchart showing an example of the operation of the key management device according to the first embodiment. [Figure 5] FIG. 10 is a diagram showing an example of the functional configuration of a key management device according to a second embodiment. [Figure 6] 10 is a flowchart showing an example of the operation of the key management device according to the second embodiment. [Figure 7] 5A and 5B are diagrams for explaining the effects of the first and second embodiments. [Figure 8] FIG. 2 is a diagram showing an example of the hardware configuration of a key management device according to the first and second embodiments. [Figure 9] FIG. 2 is a diagram showing an example of the hardware configuration of a QKD module according to the first and second embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0007] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, embodiments of a key management device, a quantum cryptography communication system, a key management method, and a program will be described in detail with reference to the accompanying drawings.
[0008] In order to associate a QKD module based on a QKD key, the key management device needs to transmit and receive the QKD key and a hash value that characterizes the QKD key data over a classical communication channel, which creates the possibility of eavesdropping on the QKD key data. For this reason, conventionally, key management devices have not been equipped with a function for transmitting and receiving the QKD key used for encryption. Note that while a function exists in which the key management device encrypts and transmits a key other than the QKD key (e.g., an application key) using the QKD key, this function is not a function for transmitting and receiving the QKD key data used by the key management device for encryption.
[0009] Hereinafter, an embodiment will be described in which the QKD module is associated with a QKD key, thereby making it possible to more easily recognize the QKD module.
[0010] (First embodiment) 1 is a diagram showing an example of the device configuration of a quantum cryptography communication system 100 according to the first embodiment. The quantum cryptography communication system 100 according to the first embodiment includes key management (KM) devices 1a to 1b, QKD modules 2aa to 2az, and QKD modules 2ba to 2bz.
[0011] The key management devices 1a and 1b are associated with each other and connected by a classical communication channel. The communication method of the classical communication channel may be a wired method or a wireless method. Furthermore, the classical communication channel may be configured by combining a wired method and a wireless method.
[0012] The key management device 1a is connected to the QKD modules 2aa to 2az by wire or wirelessly. Similarly, the key management device 1b is connected to the QKD modules 2ba to 2bz by wire or wirelessly.
[0013] The QKD modules 2aa to 2az and the QKD modules 2ba to 2bz are connected by a QKD link and perform QKD (quantum key distribution). A pair of QKD modules connected by a QKD link share the same QKD key (quantum key) by performing QKD. For example, the pair of QKD modules 2aa and 2bb can share the same QKD key without being intercepted by performing QKD.
[0014] 1 is an example, and the example of the device configuration of the quantum cryptography communication system 100 is not limited to that shown in Fig. 1. For example, the number of QKD modules 2aa to 2az and QKD modules 2ba to 2bz may be any number, and the number of QKD modules 2aa to 2az and QKD modules 2ba to 2bz is not limited to that shown in Fig. 1.
[0015] A QKD link is a quantum communication channel used to transmit single photons. Typically, QKD links are independent optical fibers, individual channels multiplexed within an optical fiber, individual cores of a multicore fiber, or free-space optical communication channels.
[0016] Hereinafter, when there is no need to distinguish between the QKD modules 2aa to 2az, they will simply be referred to as the QKD module 2a. Similarly, when there is no need to distinguish between the QKD modules 2ba to 2bz, they will simply be referred to as the QKD module 2b.
[0017] Due to the constraints of quantum mechanics, even if a third party eavesdrops on data in a QKD link, the eavesdropping can almost always be detected. Therefore, a pair of QKD modules 2a and 2b (for example, QKD modules 2aa and 2bb) has the characteristic of being able to share a QKD key that is almost never intercepted by anyone.
[0018] Key management device 1a receives a QKD key from QKD module 2a, and key management device 1b receives a QKD key from QKD module 2b. One of key management devices 1a or 1b encrypts data using the QKD key and transmits the encrypted data via a classical communication channel. The other decrypts the encrypted data using the same QKD key as the QKD key used for encryption.
[0019] Here, the QKD keys used for encryption and decryption by the key management devices 1a and 1b must be the same data, because if they were different data, it would be impossible to decrypt the encrypted data.
[0020] Furthermore, the key management devices 1a and 1b do not transmit the QKD key used for encryption and decryption through the classical communication channel between the two devices. If the QKD key used for encryption and decryption were transmitted through the classical communication channel, both the QKD key and the data encrypted with the QKD key would become known to the eavesdropper if the communication through the classical communication channel were eavesdropped on by an eavesdropper. This would enable the eavesdropper to decrypt the encrypted data. Therefore, the key management devices 1a and 1b do not use the QKD key transmitted through the classical communication channel for encryption and decryption.
[0021] As described above, the key management devices 1a and 1b need to use the same QKD key when encrypting or decrypting. When there are multiple pairs of QKD modules 2a and 2b, as shown in FIG. 1, the key management device 1a needs to set which QKD key from which QKD module 2a to use for encryption. Similarly, the key management device 1b needs to set which QKD key from which QKD module 2b to use for decryption. However, when there are many pairs of QKD modules 2a and 2b, one method is to manually set the association between each QKD module 2a and 2b, but the engineering cost is high when there are many QKD modules 2a and 2b.
[0022] Hereinafter, a detailed description will be given of a configuration and method that can more easily (for example, automatically) associate the QKD modules 2a and 2b in order to reduce the labor required for setting.
[0023] Hereinafter, when there is no need to distinguish between the key management devices 1a and 1b, they will simply be referred to as the key management devices 1a and 1. Similarly, when there is no need to distinguish between the QKD modules 2aa to 2az and the QKD modules 2ba to 2bz, they will simply be referred to as the QKD modules 2.
[0024] [Example of functional configuration] 2 is a diagram illustrating an example of the functional configuration of the key management device 1 according to the first embodiment. The key management device 1 according to the first embodiment includes a processing unit 10, an acquisition unit 11, an output unit 12, and a storage unit 13. The processing unit 10 includes a transmission control unit 101, a reception control unit 102, a collection control unit 103, a generation unit 104, and a verification unit 105.
[0025] The key management device 1 of the first embodiment associates QKD modules 2 (an example of a QKD device) with each other using a QKD key, thereby enabling automatic recognition of pairs of QKD modules 2.
[0026] The processing unit 10 is realized by at least one processing device and executes the processing of the key management device 1. This processing device includes, for example, a control device and an arithmetic device, and is realized by analog or digital circuits, etc. The processing device may be a central processing unit (CPU), a general-purpose processor, a microprocessor, a digital signal processor (DSP), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a combination thereof.
[0027] The acquisition unit 11 acquires data by wireless or wired communication. For example, the acquisition unit 11 of the key management device 1a acquires identity verification data for a QKD key generated by the QKD module 2b and a QKD module ID (an example of QKD device information) for identifying the QKD module 2b from the key management device 1b via a classical communication channel.
[0028] The output unit 12 outputs data by wireless or wired communication. For example, the output unit 12 of the key management device 1a outputs identity verification data for the QKD key generated by the QKD module 2a and the QKD module ID of the QKD module 2a to the key management device 1b.
[0029] The storage unit 13 stores data such as a QKD key, identity verification data for the QKD key, and a QKD module ID that identifies the QKD module 2 that generated the QKD key. The storage unit 13 is realized by, for example, a non-volatile memory (auxiliary storage device 403 in FIG. 9 described below) or another storage device.
[0030] The transmission control unit 101 controls the output unit 12 to transmit the QKD key identity verification data and the QKD module ID via the classical communication channel to the remote key management device 1 connected via the classical communication channel.
[0031] Hereinafter, the key management device 1b connected to the key management device 1a via a classical communication path and the QKD module 2b connected to the same network as the key management device 1b are referred to as the remote key management device 1b and the remote QKD module 2b, respectively, with respect to the key management device 1a. On the other hand, the QKD module 2a connected to the same network as the key management device 1a is referred to as the local QKD module 2a with respect to the key management device 1a.
[0032] The QKD key identity verification data is data used to verify the identity of the QKD key. The QKD key identity verification data is, for example, the whole or part of a generated QKD key of a predetermined length. Also, for example, the QKD key identity verification data is a hash value generated from the whole or part of a generated QKD key of a predetermined length. Note that, although not essential, it is more preferable for the QKD key identity verification data to further include a QKD key ID that identifies the QKD key.
[0033] The QKD module ID is identification information that identifies a QKD module. The QKD module ID can take various forms. For example, the QKD module ID can be a MAC address, IPv4 address, IPv6 address, DNS (Domain Name System), a host name shared by mDNS (Multicast DNS), an FQDN (Fully Qualified Domain Name), an identifier set for a function running on each QKD module, or a hash value generated from these. Alternatively, the QKD module ID can be a value that combines the MAC address, IPv4 address, IPv6 address, DNS, host name, FQDN, or identifier, or a hash value generated from the combined value.
[0034] The reception control unit 102 controls the acquisition unit 11 to receive QKD key identity verification data and a QKD module ID via the classical communication channel from the remote key management device 1 connected via the classical communication channel.
[0035] Here, the key management devices 1a and 1b may each be equipped with one of the transmission control unit 101 and the reception control unit 102. For example, the key management device 1a may be equipped with the transmission control unit 101, and the key management device 1b may be equipped with the reception control unit 102.
[0036] It is more preferable that each key management device 1 is equipped with both the transmission control unit 101 and the reception control unit 102.
[0037] The collection control unit 103 collects the QKD keys generated by the local QKD modules 2 connected to the key management device 1 and the QKD module IDs of the local QKD modules 2 connected to the key management device 1.
[0038] The generation unit 104 generates QKD key identity verification data from the QKD key. For example, the generation unit 104 generates QKD key identity verification data indicating all or part of the QKD key. Also, for example, the generation unit 104 generates a hash value from all or part of the QKD key, and generates QKD key identity verification data indicating the hash value.
[0039] The verification unit 105 verifies the identity of the QKD key based on the multiple pieces of QKD key identity verification data. Note that the processing unit 10 uses a newly generated QKD key that is different from the QKD key used to generate the QKD key identity verification data for encrypting or decrypting data.
[0040] 3 is a diagram showing an example of the functional configuration of the QKD module 2 of the first embodiment. The QKD module 2 of the first embodiment includes a processing unit 20, a quantum communication unit 21, a classical communication unit 22, and a storage unit 23. The processing unit 20 includes a transmission control unit 201, a reception control unit 202, and a key distillation unit 203.
[0041] The processing unit 20 executes the processing of the QKD module 2. The processing unit 20 can be realized by any of the above-described methods for realizing the processing unit 10.
[0042] The quantum communication unit 21 generates a QKD key by communicating via the above-mentioned QKD link (quantum communication channel).
[0043] The classical communication unit 22 communicates via the classical communication channel described above. For example, the classical communication unit 22 transmits data such as a QKD key and a QKD module ID to the key management device 1.
[0044] The storage unit 23 stores data. For example, the data stored in the storage unit 23 is a QKD key generated by the QKD module 2, a QKD module ID that identifies the QKD module 2, etc. The storage unit 23 can be realized by any of the above-described methods for realizing the storage unit 13.
[0045] The transmission control unit 201 controls the transmission of data via the quantum communication unit 21 or the classical communication unit 22. The reception control unit 202 controls the reception of data via the quantum communication unit 21 or the classical communication unit 22.
[0046] The key distillation unit 203 generates a QKD key by performing key distillation processing on data shared by QKD between the transmitting QKD module 2 and the receiving QKD module 2. The key distillation processing includes, for example, error correction processing and privacy amplification processing.
[0047] 4 is a flowchart showing an example of the operation of the key management device 1 of the first embodiment. First, the collection control unit 103 collects the QKD keys and the QKD module IDs of the local QKD modules 2 from each QKD module 2 (local QKD modules 2) connected to the key management device 1 (step S1).
[0048] Next, the transmission control unit 101 controls the output unit 12 to transmit the QKD key identity verification data and the QKD module ID to the remote key management device 1 (step S2). The QKD key identity verification data is generated by the above-mentioned generation unit 104 from the QKD key collected in step S1.
[0049] Next, the reception control unit 102 controls the acquisition unit 11 to receive the QKD key identity verification data and QKD module ID transmitted from the remote key management device 1 (step S3). In step S3, the remote key management device 1 receives the QKD key identity verification data generated from the QKD key collected from the remote QKD module 2, and the QKD module ID of the remote QKD module 2.
[0050] Here, steps S1 and S2 and step S3 may be executed in parallel at the same time, or may be executed at different times.
[0051] Next, the verification unit 105 identifies the QKD module ID of the local QKD module 2 and the QKD module ID of the remote QKD module 2 whose QKD key identity verification data matches the QKD key identity verification data of the local QKD module 2 (step S4). If the QKD key identity verification data matches, the verification unit 105 associates the QKD module ID of the local QKD module 2 with the QKD module ID of the remote QKD module 2.
[0052] This makes it possible to identify a pair of QKD module IDs that identify the corresponding QKD modules 2 from among a plurality of QKD modules 2 connected to the QKD link.
[0053] As described above, the key management device 1a of the first embodiment is connected to at least one QKD module 2b (an example of a remote QKD device) and at least one QKD module 2a (an example of a local QKD device) connected via a quantum communication channel. The acquisition unit 11 acquires, from the key management device 1b via the classical communication channel, identity verification data for a QKD key (an example of a remote QKD key) generated by the QKD module 2b (an example of a remote QKD device) and a QKD module ID (an example of remote QKD device identification information) that identifies the QKD module 2b. The processing unit 10 collects the QKD key (an example of a local QKD key) generated by the QKD module 2a and the QKD module ID (an example of local QKD device identification information) that identifies the QKD module 2a, generates identity verification data for the local QKD key, and if the identity verification data for the remote QKD key matches the identity verification data for the local QKD key, associates the remote QKD device identification information with the local QKD device identification information.
[0054] As a result, according to the first embodiment, even when there are multiple QKD devices, pairs of QKD devices that share a QKD key can be easily associated with each other.
[0055] (Second embodiment) Next, a second embodiment will be described. In the description of the second embodiment, the same description as in the first embodiment will be omitted, and only the differences from the first embodiment will be described.
[0056] [Example of functional configuration] 5 is a diagram showing an example of the functional configuration of a key management device 1-2 according to the second embodiment. The key management device 1-2 according to the second embodiment includes a processing unit 10, an acquisition unit 11, an output unit 12, and a storage unit 13. The processing unit 10 includes a transmission control unit 101, a reception control unit 102, a collection control unit 103, a generation unit 104, a verification unit 105, a detection unit 106, a local instruction unit 107, and a remote instruction unit 108. In the second embodiment, the detection unit 106, the local instruction unit 107, and the remote instruction unit 108 are further added to the configuration of the first embodiment.
[0057] The detection unit 106 detects that the QKD module 2 to be newly connected to the QKD link has been newly connected to the key management device 1-2.
[0058] The local instruction unit 107 instructs the local QKD module 2 connected to the key management device 1-2 to generate a QKD key. For example, when the detection unit 106 detects a newly connected QKD module 2, the local instruction unit 107 instructs the new QKD module 2 to generate a QKD key. Also, for example, when the local instruction unit 107 is instructed by another key management device 1-2 to generate a QKD key, the local instruction unit 107 instructs the local QKD module 2 connected to the key management device 1-2 to generate a QKD key.
[0059] The remote instruction unit 108 instructs the remote key management device 1-2, which is connected via a classical communication channel, to generate a QKD key by the remote QKD module 2.
[0060] Fig. 6 is a flowchart showing an example of the operation of the key management device 1-2 of the second embodiment. The example in Fig. 6 shows a case where the key management device 1a-2 instructs the local QKD module 2a connected to the key management device 1a-2 to start key generation, and the key management device 1b-2 instructs the QKD module 2b connected to the key management device 1b-2 to start key generation based on the instruction from the key management device 1a-2.
[0061] First, the local instruction unit 107 of the key management device 1a-2 instructs the local QKD module 2a connected to the key management device 1a-2 to start key generation (step S11).
[0062] Furthermore, if the detection unit 106 detects a newly connected QKD module 2a, it is more preferable for the local instruction unit 107 to instruct only that QKD module 2a to start key generation in step S11, as this will prevent existing QKD modules 2a that have already been associated from being associated again.
[0063] The explanation of steps S12 and S13 is omitted because they are the same as steps S1 and S2 in the first embodiment.
[0064] Next, local instruction unit 107 determines whether there is any QKD module 2a that has instructed the start of key generation in step S11 but failed to start key generation (step S14).
[0065] If there is a QKD module 2a that failed to start key generation (step S14, Yes), the remote instruction unit 108 instructs the remote key management device 1b-2 connected via the classical communication channel to generate a QKD key (step S15), and the process proceeds to step S16. By starting key generation in the remote QKD module 2b in step S15, key generation (key sharing) with the QKD module 2a that failed to start key generation (key sharing) can be performed normally. There are various possible reasons why the QKD module 2a fails to start key generation (key sharing), but for example, a function to accept instructions such as a command to start key generation (key sharing) may not be implemented in the QKD module 2a, or the settings of the QKD module 2a or QKD module 2b may be configured so that the QKD module 2a cannot start key generation (key sharing).
[0066] If there is no QKD module 2a that has failed to start key generation (step S14, No), the process proceeds to step S16.
[0067] The explanation of steps S16 and S17 is omitted because they are similar to steps S3 and S4 in the first embodiment.
[0068] On the other hand, when the reception control unit 102 of the key management device 1b-2 receives the instruction sent by the key management device 1a-2 in step S11 via the acquisition unit 11 (step S21), the local instruction unit 107 of the key management device 1b-2 instructs the QKD module 2b, which has been instructed to start key generation, to start key generation (step S22).
[0069] The explanation of steps S22 to S26 of the key management device 1b-2 is omitted because they are similar to steps S12, S13, S16 and S17 of the key management device 1a-2.
[0070] Here, various variations are possible for the method of implementing step S15 of the key management device 1a-2 and step S21 of the key management device 1b-2. For example, the key management device 1a-2 may instruct the key management device 1b-2 to start key generation for all of the QKD modules 2a connected to the key management device 1b-2.
[0071] Also, for example, the key management device 1a-2 may instruct the key management device 1b-2 to start key generation for the QKD modules 2b that have not yet started key generation, among the QKD modules 2b connected to the key management device 1b-2.
[0072] Also, for example, the key management device 1a-2 may instruct the key management device 1b-2 to start key generation for the QKD module 2b that is newly connected to the key management device 1b-2.
[0073] Furthermore, the message from key management device 1a-2 instructing QKD module 2b connected to key management device 1b-2 to start key generation may be modified by key management device 1b-2, or may be forwarded directly to QKD module 2b by key management device 1b-2. When the message is modified, for example, local instruction unit 107 of key management device 1b-2 modifies the destination address included in the message from the address of key management device 1b-2 to the address of QKD module 2b for which key generation is to be started.
[0074] In this method, the key management device 1b-2 effectively acts as a relay, or a tunnel, between the key management device 1a-2 and the QKD module 2b.
[0075] According to the key management method of the second embodiment shown in the flowchart of Figure 6 above, it is possible to identify corresponding pairs of QKD modules 2 connected to a QKD link even if all or some of the multiple QKD modules 2 have not yet started key generation.
[0076] Fig. 7 is a diagram for explaining the effects of the first and second embodiments. Data 111a and 111b used to verify the identity of the QKD keys, and verification result data 112a and 112b are obtained by the flowchart of the first embodiment (Fig. 4) and the flowchart of the second embodiment (Fig. 6).
[0077] The data 111a used to verify the identity of the QKD key of the key management device 1a (1a-2) includes, for example, a set of identity verification data for the QKD key A1 and a QKD module ID-AA that identifies the QKD module 2aa that generates the QKD key A1.
[0078] The data 111b used to verify the identity of the QKD key of the key management device 1b (1b-2) is the same as the data 111a used to verify the identity of the QKD key.
[0079] The verification result data 112a of the key management device 1a (1a-2) is data identified in step S4 of the flowchart of the first embodiment (FIG. 4) and in step S17 of the flowchart of the second embodiment (FIG. 6). The example of FIG. 7 shows a case where the identity verification data of QKD key A1 matches the identity verification data of QKD key B2, thereby identifying that QKD keys A1 and B2 are the same, and associating QKD module ID-AA with QKD module ID-BB.
[0080] The verification result data 112b of the key management device 1b (1b-2) is data identified in step S4 of the flowchart of the first embodiment (FIG. 4) and in step S26 of the flowchart of the second embodiment (FIG. 6). The verification result data 112b of the key management device 1b (1b-2) is the same as the verification result data 112a.
[0081] In the examples of the first and second embodiments described above, a method has been shown in which a pair of QKD key identity verification data and a QKD module ID is shared between the key management device 1a (1a-2) and the key management device 1b (1b-2). However, as described above, the data 111a and 111b used to verify the identity of the QKD keys match, and the verification result data 112a and 112b also match. Therefore, for example, the key management device 1a (1a-2) may collect and acquire the data 111a used to verify the identity of the QKD keys and perform the verification. In this case, for example, the key management device 1b (1b-2) receives the verification result data 112a from the key management device 1a (1a-2). For example, the key management device 1b (1b-2) receives not only the verification result data 112a but also all or part of the data 111a used to verify the identity of the QKD key (for example, the QKD key identity verification data and QKD module ID of the remote QKD module 2a connected to the key management device 1a (1a-2)) from the key management device 1a (1a-2).
[0082] In addition, if either of the key management devices 1 (1-2) performs the collection / acquisition and verification of data 111 used to verify the identity of the QKD key, this may be performed by the key management device 1b (1-2) rather than the key management device 1a (1a-2).
[0083] Finally, an example of the hardware configuration of the key management device 1 (1-2) and the QKD module 2 (2-2) in the first and second embodiments will be described.
[0084] [Example of hardware configuration] 8 is a diagram showing an example of the hardware configuration of the key management device 1 (1-2) according to the first and second embodiments. The key management device 1 (1-2) according to the first and second embodiments includes a processor 301, a main storage device 302, an auxiliary storage device 303, a display device 304, an input device 305, and a communication IF 306. The processor 301, the main storage device 302, the auxiliary storage device 303, the display device 304, the input device 305, and the communication IF 306 are connected via a bus 310.
[0085] The processor 301 executes a program read from the auxiliary storage device 303 to the main storage device 302. Instead of the processor 301 executing the program, an FPGA circuit may be configured in RTL (Register Transfer Level) and the FPGA circuit may execute the processing. The main storage device 302 is memory such as a ROM (Read Only Memory) and a RAM (Random Access Memory). The auxiliary storage device 303 is a HDD (Hard Disk Drive), a memory card, etc.
[0086] The display device 304 displays the status of the key management device 1 (1-2), etc. The input device 305 accepts input from a user. Note that the key management device 1 (1-2) of the first and second embodiments does not necessarily have to include the display device 304 and the input device 305.
[0087] The communication IF 306 is an interface for connecting to the key management device 1 (1-2), the QKD module 2 (2-2), etc. If the key management device 1 (1-2) does not have the display device 304 and the input device 305, the display function and input function of an external terminal connected via the communication IF 306 may be used, for example.
[0088] 9 is a diagram showing an example of the hardware configuration of the QKD module 2 (2-2) of the first and second embodiments. The QKD module 2 (2-2) includes a processor 401, a main memory device 402, an auxiliary memory device 403, a display device 404, an input device 405, a quantum communication IF 406, and a classical communication IF 407. The processor 401, the main memory device 402, the auxiliary memory device 403, the display device 404, the input device 405, the quantum communication IF 406, and the classical communication IF 407 are connected via a bus 410.
[0089] The processor 401 executes a program read from the auxiliary storage device 403 to the main storage device 402. Instead of the processor 401 executing the program, an FPGA circuit may be configured using RTL, and the processing may be executed by the FPGA circuit. The main storage device 402 is memory such as ROM and RAM. The auxiliary storage device 403 is a HDD, memory card, etc.
[0090] The display device 404 displays the status of the QKD module 2 (2-2), etc. The input device 405 accepts input from the user. Note that the QKD module 2 (2-2) does not necessarily have to include the display device 404 and the input device 405.
[0091] The quantum communication IF 406 is an interface for connecting to a quantum cryptography communication channel (QKD link). The classical communication IF 207 is an interface for connecting to a classical communication channel and the key management device 1 (1-2), etc. If the QKD module 2 (2-2) does not have a display device 404 and an input device 405, the display function and input function of an external terminal connected via the classical communication IF 407 may be used, for example.
[0092] The programs executed by the key management device 1 (1-2) and the QKD module 2 (2-2) are provided as computer program products stored in the form of installable or executable files on computer-readable storage media such as CD-ROMs, memory cards, CD-Rs, and DVDs (Digital Versatile Discs).
[0093] Furthermore, the programs executed by the key management device 1 (1-2) and the QKD module 2 (2-2) may be stored on a computer connected to a network such as the Internet and provided by being downloaded via the network.
[0094] Furthermore, the programs executed by the key management device 1 (1-2) and the QKD module 2 (2-2) may be configured to be provided via a network such as the Internet without being downloaded.
[0095] Furthermore, the programs executed by the key management device 1 (1-2) and the QKD module 2 (2-2) may be provided in advance by being stored in a ROM or the like.
[0096] The program executed by the key management device 1 (1-2) has a modular configuration including functions that can be realized by the program among the functional configuration of the key management device 1 (1-2) described above. The functions realized by the program are loaded into the main memory device 302 by the processor 301 reading and executing the program from a storage medium such as the auxiliary storage device 303. In other words, the functions realized by the program are generated on the main memory device 302.
[0097] Similarly, the program executed by the QKD module 2 (2-2) has a modular configuration that includes functions that can be realized by the program, among the functional configuration of the QKD module 2 (2-2) described above. The functions realized by the program are loaded into the main memory device 402 by the processor 401 reading and executing the program from a storage medium such as the auxiliary storage device 403. In other words, the functions realized by the program are generated on the main memory device 402.
[0098] Furthermore, when an FPGA circuit is configured with RTL instead of the processor 301 that executes a program, the RTL executed by the key management device 1 (1-2) has a modular configuration that includes functions that can be realized by RTL from among the functional configuration of the key management device 1 (1-2) described above. In this case, the functions realized by RTL are generated on the FPGA circuit.
[0099] Similarly, when an FPGA circuit is configured with RTL instead of the processor 401 that executes a program, the RTL executed in the QKD module 2 (2-2) is a modular configuration that includes functions that can be realized by RTL from among the functional configuration of the QKD module 2 (2-2) described above. In this case, the functions realized by RTL are generated on the FPGA circuit.
[0100] Some or all of the functions of the key management device 1 (1-2) and the QKD module 2 (2-2) may be realized by hardware such as an integrated circuit (IC). The IC is, for example, a processor that executes dedicated processing, an FPGA circuit, or the like.
[0101] Furthermore, when each function is realized using a plurality of processors, each processor may realize one of the functions, or may realize two or more of the functions.
[0102] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, and are also included in the scope of the invention and its equivalents as defined in the claims. [Explanation of symbols]
[0103] 1 Key management device 2 QKD modules 10 Processing section 11 Acquisition Department 12 Output section 13 Storage section 20 Processing section 21 Quantum Communications Department 22 Classical Communication Club 23 Memory section 100 Quantum cryptography communication system 101 Transmission control section 102 Reception control section 103 Collection control section 104 Generation part 105 Verification Department 106 Detector 107 Local Instructions 108 Remote instruction unit 201 Transmission control section 202 Reception control section 203 Key Distillation Department 301 processor 302 Main storage 303 Auxiliary storage device 304 Display device 305 Input Device 306 Communication Interface 310 Bus 401 processor 402 Main storage 403 Auxiliary storage 404 Display device 405 Input Device 406 Quantum Communication Interface 407 Classical Communication IF 410 Bus
Claims
1. A key management device connected to at least one remote QKD (Quantum Key Distribution) device and at least one local QKD device connected via a quantum communication channel, An acquisition unit that acquires identity verification data of the remote QKD key generated by the remote QKD device and remote QKD device identification information that identifies the remote QKD device from another key management device via a classical communication channel; A processing unit that collects a local QKD key generated by the local QKD device and local QKD device identification information that identifies the local QKD device, generates identity verification data for the local QKD key, and if the identity verification data for the remote QKD key matches the identity verification data for the local QKD key, associates the remote QKD device identification information with the local QKD device identification information; A key management device comprising:
2. an output unit that outputs identity verification data of the local QKD key and the local QKD device identification information to the other key management device; The key management device of claim 1 further comprising:
3. The identity verification data of the local QKD key is all or a part of the local QKD key of a predetermined length to be generated, The remote QKD key identity verification data is all or a part of the remote QKD key of a predetermined length to be generated. The key management device according to claim 1 or 2.
4. The identity verification data of the local QKD key is a hash value generated from all or part of the local QKD key of a predetermined length, The identity verification data of the remote QKD key is a hash value generated from all or part of the remote QKD key of a predetermined length. The key management device according to claim 1 or 2.
5. The processing unit instructs the local QKD device to start generating the local QKD key, and if the generation of the local QKD key fails, instructs the other key management device to start generating the remote QKD key. The key management device according to claim 1 or 2.
6. The processing unit uses a newly generated local QKD key that is different from the local QKD key used to generate the identity verification data of the local QKD key for encrypting or decrypting data. The key management device according to claim 1 or 2.
7. When the processing unit detects a new local QKD device connected to the quantum communication channel, it instructs the new local QKD device to start generating a new local QKD key, collects the new local QKD key and local QKD device identification information that identifies the new local QKD device, generates identity verification data for the new local QKD key, and if the identity verification data for the remote QKD key matches the identity verification data for the new local QKD key, it associates the remote QKD device identification information with the local QKD device identification information that identifies the new local QKD device. The key management device according to claim 1 or 2.
8. When the processing unit is instructed by the other key management device to generate the local QKD key, the processing unit instructs the local QKD device to generate the local QKD key. The key management device according to claim 1 or 2.
9. The key management device according to claim 1 or 2; the other key management device; the at least one local QKD device; the at least one remote QKD device; The local QKD device a quantum communication unit that generates the local QKD key via the quantum communication channel; a classical communication unit that transmits the local QKD key and the local QKD device identification information via the classical communication channel; the remote QKD device a quantum communication unit that generates the remote QKD key via the quantum communication channel; A classical communication unit that transmits the remote QKD key and the remote QKD device identification information via the classical communication channel; A quantum cryptography communication system comprising:
10. A key management method for a key management device connected to at least one remote QKD (Quantum Key Distribution) device and at least one local QKD device connected via a quantum communication channel, comprising: An acquisition unit acquires identity verification data for the remote QKD key generated by the remote QKD device and remote QKD device identification information that identifies the remote QKD device from another key management device via a classical communication channel; A processing unit collects a local QKD key generated by the local QKD device and local QKD device identification information that identifies the local QKD device, generates identity verification data for the local QKD key, and if the identity verification data for the remote QKD key matches the identity verification data for the local QKD key, associates the remote QKD device identification information with the local QKD device identification information; A key management method comprising:
11. A computer connected to at least one remote Quantum Key Distribution (QKD) device and at least one local QKD device connected via a quantum communication channel, An acquisition unit that acquires identity verification data of the remote QKD key generated by the remote QKD device and remote QKD device identification information that identifies the remote QKD device from another key management device via a classical communication channel; a processing unit that collects a local QKD key generated by the local QKD device and local QKD device identification information that identifies the local QKD device, generates identity verification data for the local QKD key, and, if the identity verification data for the remote QKD key matches the identity verification data for the local QKD key, associates the remote QKD device identification information with the local QKD device identification information; A program to function as a
Citation Information
Patent Citations
Character wheel positioning device in printer
JP1989026477A
Method and apparatus for managing encryption key in private communication network
JP2008306633A
Communication system, communication device, communication method, and program
JP2015179989A
Data utilization device, encrypted data distribution system, data utilization method, and program
JP6599401B2
Terminal device, management device, communication system, communication method, management method, and non-transitory computer-readable medium
WO2022264373A1