Key management device, quantum cryptography communication system, QKDN control device, information processing device, key management method, QKDN control method, information processing method, and program
The key management device in a QKD network efficiently associates applications with key management devices using link keys, addressing scalability issues and improving processing efficiency in large-scale QKD networks.
Patent Information
- Application Number
- JP2023043319
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-17
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2043-03-17
AI Technical Summary
Conventional quantum key distribution (QKD) networks face challenges in efficiently associating applications with key management devices as the network scale increases, leading to complex address registration and reduced processing efficiency.
A key management device connected to a QKD device, equipped with a communication interface and processing unit, identifies and shares application keys based on request information, using link keys generated by QKD, to facilitate secure communication across a user network.
This solution enables efficient association of applications with key management devices, regardless of the QKD network scale, by managing key sharing and reducing redundancy in mapping information, thus enhancing processing efficiency.
Smart Images

Figure 0007753277000001 
Figure 0007753277000002 
Figure 0007753277000003
Abstract
Description
[Technical Field]
[0001] An embodiment of the present invention relates to a key management device, a quantum cryptography communication system, a QKDN control device, an information processing device, a key management method, a QKDN control method, an information processing method, and a program. [Background technology]
[0002] A technique has been known in the past in which an application obtains a random number shared with another application using quantum key distribution (QKD) from a key management device, and uses this random number as an encryption key to perform encrypted communication with another application. The encrypted communication by this application is performed over a user network, such as the Internet, which is different from the QKD network. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 6426477 [Patent Document 2] Patent No. 5784562 [Non-patent literature]
[0004] [Non-Patent Document 1] ITU-T, Y.3800, “Overview networks on supporting quantum key distribution,” 2019. [Non-patent document 2] ETSI GS QKD 014, “Quantum Key Distribution (QKD); Protocol and data format of REST-based key delivery API,” 2019. Summary of the Invention [Problem to be solved by the invention]
[0005] However, with conventional techniques, the larger the scale of a QKD network, the more difficult it becomes to associate an application with a key management device that transmits an encryption key to the application. [Means for solving the problem]
[0006] According to an embodiment, a key management device is connected to a QKD device that generates link keys by QKD (Quantum Key Distribution), and includes a communication interface and a processing unit. The communication interface receives, from a source application in a user network, request information for an application key, the request information including first identification information that identifies the source application, second identification information that identifies a destination application, and a requested amount of an application key used to encrypt or decrypt communications in the user network. The processing unit identifies a key management device with which the application key is to be shared from the second identification information, determines a shared amount of the application key from the requested amount of the application key, causes the communication interface to transmit the application key encrypted using the link key and satisfying the shared amount to the key management device with which the application key is to be shared, and causes the communication interface to transmit the requested amount of application key to the source application identified by the first identification information. [Brief explanation of the drawings]
[0007] [Figure 1] FIG. 1 is a diagram showing an example of the configuration of a quantum cryptography communication system according to a first embodiment. [Figure 2] FIG. 1 is a diagram showing an example of a quantum cryptography communication network according to a first embodiment. [Figure 3] FIG. 2 is a diagram showing an example of the functional configuration of a key management device according to the first embodiment. [Figure 4] FIG. 2 is a diagram showing an example of the functional configuration of a QKDN control device according to the first embodiment. [Figure 5] FIG. 2 is a diagram showing an example of the functional configuration of the information processing apparatus according to the first embodiment. [Figure 6] FIG. 3 is a sequence diagram showing an example of a secure communication method according to the first embodiment. [Figure 7] FIG. 4 is a diagram showing an example of mapping information according to the first embodiment. [Figure 8A] FIG. 10 is a diagram showing an example 1 of a KSN domain in the second embodiment. [Figure 8B] FIG. 10 is a diagram showing a second example of a KSN domain according to the second embodiment. [Figure 9] FIG. 10 is a diagram showing an example of an ID system for identifying KMs in the second embodiment. [Figure 10] FIG. 10 is a diagram showing an example of a quantum cryptography communication network according to a second embodiment. [Figure 11] FIG. 10 is a sequence diagram showing an example of a secure communication method according to the second embodiment. [Figure 12] FIG. 10 is a diagram showing an example of mapping information according to the second embodiment. [Figure 13] FIG. 10 is a diagram showing an example of state information according to the second embodiment. [Figure 14] FIG. 10 is a diagram showing an example of the format of an inquiry message regarding sharing of mapping information according to the second embodiment. [Figure 15] FIG. 10 is a diagram showing an example of the format of a response message regarding sharing of mapping information according to the second embodiment. [Figure 16] FIG. 10 is a diagram showing an example of a distributed management configuration according to a second embodiment. [Figure 17] FIG. 10 is a diagram showing an example of a centralized management configuration according to a second embodiment. [Figure 18] FIG. 2 is a diagram showing an example of the hardware configuration of a KM, a QKDN control device, and an information processing device according to the first and second embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0008] Hereinafter, with reference to the accompanying drawings, embodiments of a key management device, a quantum cryptography communication system, a QKDN (Quantum Key Distribution Network) control device, an information processing device, a key management method, a QKDN control method, an information processing method, and a program will be described in detail.
[0009] In the past, it was possible to automate the address registration process for using the encryption functions of an encrypted communication network, but this required the installation of a dedicated library in each KM 10. When the QKD network becomes larger, for example, if the number of KMs 10 exceeds 1,000, the address registration library in each KM 10 becomes enormous, reducing processing efficiency. It is also desirable to determine the amount of key sharing based on the key accumulation status between KMs 10, depending on the amount of keys required to use the encryption functions.
[0010] 1 is a diagram showing an example of the configuration of a quantum cryptography communication system according to a first embodiment. Viewed from the side, the QKD network architecture is composed of, from the bottom up, a quantum layer, a key management layer, a QKD network control layer, and a QKD network management layer for managing these three layers. These four layers generate an application key (hereinafter referred to as an "application key") used to encrypt and decrypt data communications of an application 5, and supply it to the service layer in the top-level user network. Viewed vertically, three nodes 1 (QKD nodes / trusted nodes) comprising the QKD network and user network are installed at points A, B, and C, respectively.
[0011] The quantum layer consists of a QKD module 2 and a QKD link 3. The main function of the quantum layer is to exchange photons and classical information (control information transmitted and received over a normal control link, different from the QKD link) with QKD modules 2 at other locations and share a link key (random number sequence). Furthermore, the quantum layer has the function of supplying random number sequences to key managers (KMs) 10 (10a to 10c). The link key (quantum encryption key) shared over the QKD link 3 is guaranteed to be resistant to eavesdropping based on the principles of quantum mechanics. When encrypted data communication is performed using the shared link key with a cryptographic communication method known as a one-time pad, information theory guarantees that the transmitted and received data cannot be decrypted by an eavesdropper, regardless of their knowledge. The QKD modules 2 (2a, 2b-1, 2b-2, and 2c) are connected by QKD links 3, such as optical fibers.
[0012] However, the method of sharing link keys using QKD technology is limited by the distance over which the link key can be shared, due to the use of single photons as a medium. For example, as shown in the example of the quantum layer in Figure 1, the QKD module 2 is basically one-to-one, but in the case of relaying, at least two QKD modules 2b-1 and 2b-2 are required at the relaying point B. In the example in Figure 1, the application key K is shared between points A and C. A AC At site B, the QKD module 2b-1 encrypts the application key encrypted at site A using the same link key K as site A. L AB (i.e., a common key in which the encryption key and the decryption key are the same). Then, the QKD module 2b-2 converts the decrypted application key into a link key K L BC Then encrypt it again with the encrypted application key K A AC Relay to base C.
[0013] In order to guarantee unconditional security, QKD inevitably sacrifices some communication performance, such as distance and speed. Generally, the link key generation rate within a 50km radius of installed fiber is approximately 200,000 to 300,000 bits per second (200 to 300kbps). If the QKD key distillation process is implemented and optimized in hardware, the key generation speed for QKD over short distances can reach a maximum of 10Mbps.
[0014] To maintain the key generation speed at Mbps, relay nodes must be installed at intervals that allow the speed to be maintained, and key relay must be performed between relay points. However, encryption and decryption processing takes time at relay points.
[0015] The key management layer is composed of key management devices (KM) 10a to 10c and a KM link. The main functions of the key management layer include supplying application keys to the applications 5a and 5c that actually encrypt data, and relaying keys to other locations via the KM link. The key management devices (KM) 10a to 10c are also responsible for overall key management, such as receiving key requests from the applications 5a and 5c and storing interfaces.
[0016] The QKD network control layer is composed of a QKD network controller 4 and links. The QKD network control layer controls the overall services of the QKD network. A QKD network controller may be provided at each location, or as shown in Figure 1, there may be one (or more) QKD network controllers for the entire quantum cryptography communication system. The QKD network controller 4 and KM 10 may also be implemented as an integrated unit.
[0017] The QKD network management layer includes a QKDN control device 6. The QKD network management layer has the function of collecting performance information from each layer, monitoring whether the service is operating properly, and issuing control commands to the QKD network control layer as necessary. There may be multiple QKDN control devices 6 depending on the configuration of the QKD network. The functions of the QKDN control device 6 may also be realized and performed by the KM 10.
[0018] The service layer's configuration varies depending on the user, but it is composed of applications 5a and 5c for implementing encrypted communications, computer modules, etc. The service layer also has the function of encrypting an application key with a link key and transferring it to an adjacent node. Note that the service layer application 5 may also generate an encryption key (application key) separate from the link key from random number information, etc., independently of QKD.
[0019] In the service layer, application keys are primarily used for encryption using symmetric encryption methods. A symmetric encryption method is an encryption method that uses the same application key shared in advance between the sender and receiver to encrypt and decrypt communication data and messages. Specifically, application keys are used in Advanced Encryption Standard (AES) encryption and One Time PAD (OTP) encryption.
[0020] The user network management layer includes a user network control device 7. The user network management layer collects performance information from the service layer and monitors whether the service is operating properly.
[0021] Note that the architecture shown in FIG. 1 shows basic elements. In reality, the configuration of the architecture may change depending on the situation. For example, the number of bases is not limited to three. Also, for example, the number of applications 5 is not limited to two. Also, for example, the number of QKDN control devices 6 in the QKD network management layer is not limited to one.
[0022] The above-mentioned user network is a public network, and is a network in which encrypted communication is performed by an application 5. The application 5 runs on an information processing device 8, such as a personal computer or a smart device. The user network is, for example, a data communication network such as the Internet or a cellular communication network.
[0023] On the other hand, the above-mentioned QKD network (quantum cryptography communication network) is a private network, and nodes (QKD nodes / nodes) are installed according to actual needs. The nodes transmit encryption keys for encrypted communication to user networks.
[0024] The user network and the QKD network are loosely coupled, so the application 5 does not have information about the configuration of the QKD network, such as mapping information that indicates which application 5 is connected to which KM 10.
[0025] Fig. 2 is a diagram showing an example of a quantum cryptography communication network 100 according to the first embodiment. The example in Fig. 2 is an example of a small-scale QKDN, since the number of KMs is as small as eight. Secure communication is performed between applications A and D in the user network via a data communication network 103.
[0026] A key sharing network (KSN) 102 in the key management layer is made up of KMs 10 and links between the KMs 10. In the QKDN management layer, a QKDN control device 6 that communicates with the KMs 10 of the key sharing network 102 is installed.
[0027] In the quantum layer, a network 101 is configured that includes a plurality of QKD modules 2 and a plurality of QKD links 3 between the QKD modules 2. Because the connection between the QKD modules 2 is one-to-one, the QKD modules 2 corresponding to the upper KM 10 are installed according to the number of links connected to the upper KM 10.
[0028] It should be noted that the number of KMs 10, the number of QKD modules 2, and the number of applications are not limited to the example of FIG.
[0029] The mapping information of the KMs 10 and the QKD modules 2 can be managed and shared by each KM 10 in a distributed manner, or managed by a dedicated mechanism (for example, managed by a single authoritative root server device) in a centralized manner. In this embodiment, a case where the mapping information is managed by the QKDN control device 6 will be described.
[0030] [Example of KM function configuration] 3 is a diagram showing an example of the functional configuration of the key management device (KM) 10 of the first embodiment. The key management device (KM) 10 of the first embodiment includes a communication unit 11, a storage unit 12, and a processing unit 13.
[0031] The communication unit 11 is realized by a communication interface that communicates via at least one of a wireless method and a wired method. The communication unit 11 includes a KM communication unit 111, a control communication unit 112, and an application communication unit 113. The KM communication unit 111 communicates with one or more KMs 10 in the key management layer of the QKDN to share encryption keys (application keys). The control communication unit 112 communicates with a QKDN control device 6 in the QKD network management layer to share information such as mapping information. The application communication unit 113 communicates with an application 5 of the user network, which is the highest service layer, to share information such as ID information and application key request information.
[0032] The communication unit 11 may be realized without being divided into the above three functional components.
[0033] The storage unit 12 is realized by a storage medium such as a hard disk drive (HDD), an optical disk, a memory card, or a random access memory (RAM).
[0034] The storage unit 12 stores various types of information and application keys shared between the KMs 10. The information stored in the storage unit 12 includes ID information of the application 5 in the user network, information related to key requests, ID information of the destination KM from the QKDN control device 6, and key accumulation status with the destination KM.
[0035] The processing unit 13 is realized by at least one processing unit and executes the processing of the KM 10. This processing unit includes, for example, a control unit and an arithmetic unit, and is realized by analog or digital circuits, etc. The processing unit may be a central processing unit (CPU), a general-purpose processor, a microprocessor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a combination thereof.
[0036] The processing unit 13 includes an acquisition unit 131 , an execution unit 132 , a key processing unit 133 , a provision unit 134 , a control unit 135 , a management unit 136 , and a platform unit 137 .
[0037] The acquisition unit 131 acquires information from the communication unit 11 .
[0038] In response to a key request from an application 5 of the user network, the execution unit 132 reads information from the storage unit 12 and executes processing. For example, the execution unit 132 calculates the amount of application keys corresponding to the destination KM 10, and executes key sharing processing if there are insufficient application keys. Also, for example, if the storage unit 12 holds enough application keys to satisfy the requested amount, the execution unit 132 executes processing to send the application keys to the application 5.
[0039] In response to a key request from the application 5, the key processing unit 133 passes the application key to the providing unit 134. Specifically, in response to the request from the application 5, the key processing unit 133 determines the requested amount of the application key, the providing time at which the application key is to be transmitted to the application 5, and the destination indicating the destination of the application key.
[0040] Upon receiving the application key from key processing unit 133, providing unit 134 transmits the application key to application 5 of the user network of the service layer. For example, providing unit 134 transmits the requested amount of application keys determined by key processing unit 133 to the destination determined by key processing unit 133 by the delivery time determined by key processing unit 133. Note that the function of providing unit 134 may be included in communication unit 11.
[0041] The control unit 135 controls the processing performed by the KM 10. For example, the control unit 135 is responsible for controlling the activation and operation of each function of the KM 10.
[0042] The management unit 136 manages key resources such as the key generation speed and key holding amount of the links connected to the KM 10 .
[0043] The platform unit 137 provides computer operating system functions, basic network functions, security functions, and the like required for managing and operating functions on the KM 10.
[0044] [Example of functional configuration of QKDN control device] 4 is a diagram showing an example of the functional configuration of the QKDN control device 6 of the first embodiment. The QKDN control device 6 of the first embodiment includes a communication unit 61, a storage unit 62, and a processing unit 63. Note that the communication unit 61, storage unit 62, and processing unit 63 are realized by hardware in the same way as the communication unit 11, storage unit 12, and processing unit 13 of the KM 10.
[0045] The QKDN control device 6 of the first embodiment is connected to a plurality of KMs 10 that transmits to the applications 5 application keys used for encrypting or decrypting communications between the applications 5 in the user network.
[0046] The communication unit 61 includes a KM communication unit 611 and a control communication unit 612 .
[0047] The KM communication unit 611 communicates with one or more of the KMs 10. For example, the KM communication unit 611 communicates to share the ID information of the KM 10, the ID information of the application connected to the KM 10, and the storage status of the application key with the destination KM 10.
[0048] The control communication unit 612 communicates between the QKDN control devices 6 to share the above-mentioned mapping information and information such as the key accumulation status between the KMs 10. In addition, if the above-mentioned mapping information is centrally managed by an authoritative root server device, the control communication unit 612 communicates with the authoritative root server device.
[0049] The communication unit 61 may be realized without being divided into the above two components.
[0050] The storage unit 62 stores mapping information and key accumulation status. The mapping information stores, for example, ID information of a KM 10 and ID information of an application to which an application key is sent by the KM 10 in association with each other. The mapping information can specify, for example, second identification information that identifies the destination application 5 and third identification information that identifies the KM 10 that sends the application key to the destination application 5.
[0051] The key accumulation state indicates the accumulation state of application keys shared between KMs 10. For example, the key accumulation state indicates the amount of application keys already shared between the KM 10 connected to the source application 5 and the KM 10 connected to the destination application 5.
[0052] The processing unit 63 includes an acquisition unit 631 , a control unit 632 , a management unit 633 , and a platform unit 634 .
[0053] The acquisition unit 631 acquires information from the communication unit 61 .
[0054] The control unit 632 controls the processing performed by the QKDN control device 6. For example, the control unit 632 controls the activation and operation of each function. For example, the control unit 632 causes the communication unit 61 (an example of a communication interface) to acquire, from multiple KMs 10, mapping information in which identification information for identifying an application 5 and identification information for identifying a KM 10 that transmits an application key to the application 5 are associated, and state information of the application key, and causes the storage unit 62 to store the mapping information and state information.
[0055] The management unit 633 manages information about the KMs 10 connected to the QKDN control device 6, the number of KMs 10, and so on.
[0056] The platform unit 634 provides computer operating system functions, basic network functions, security functions, etc. required for managing and operating functions on the QKDN control device 6.
[0057] [Example of functional configuration of information processing device] 5 is a diagram showing an example of the functional configuration of the information processing device 8 of the first embodiment. The information processing device 8 of the first embodiment includes a communication unit 81, a storage unit 82, and a processing unit 83. Note that the communication unit 81, the storage unit 82, and the processing unit 83 are realized by hardware in the same way as the communication unit 11, the storage unit 12, and the processing unit 13 of the KM 10.
[0058] The communication unit 81 transmits application key request information, including first identification information for identifying a source application (e.g., application 5a in FIG. 1) of the user network, second identification information for identifying a destination application (e.g., application 5c in FIG. 1), and a requested amount of the application key used for encrypting or decrypting communications in the user network, to a KM 10 connected to a QKD module 2 (an example of a QKD device) that generates a link key by QKD. The communication unit 81 also receives an application key that has been shared with the KM 10 with which the application key is shared, identified from the second identification information, so as to satisfy the requested amount.
[0059] The storage unit 82 stores, for example, an application key for each destination of communication of the application 5.
[0060] The processing unit 83 runs the above-mentioned application 5 to encrypt communications in the user network.
[0061] The configurations of the KM 10, QKDN control device 6, and information processing device 8 in this embodiment are merely examples, and the configurations may be changed as appropriate.
[0062] Fig. 6 is a sequence diagram showing an example of a secure communication method according to the first embodiment. The example of the secure communication method in Fig. 6 includes an ID registration process, an ID conversion process, and an application key sharing and transmission process.
[0063] First, when the application (source) 5a connects to the KM (source) 10a, it notifies the KM 10a of its ID information (e.g., IP address) (step S1). Next, the KM 10a registers the ID information of the application 5a notified in step S1 and its own ID information in the QKDN control device 6 (step S2).
[0064] Similarly, when the application (destination) 5d connects to the KM (destination) 10d, it notifies the KM 10d of the ID information (e.g., IP address) of the application 5d (step S3). Next, the KM 10d registers the ID information of the application 5d notified in step S3 and the ID information of the KM 10d in the QKDN control device 6 (step S4).
[0065] The above-mentioned mapping information is generated from the information registered in steps S2 and S4 by the QKDN control device 6. The mapping information is centrally managed by the QKDN control device 6. Furthermore, the mapping information is periodically updated.
[0066] Before performing secure communication, the application 5a requests an application key from the KM 10a (step S5). At that time, the application 5a notifies the KM 10a of information indicating that the secure communication destination of the application 5a is the application 5d (for example, ID information of the destination application 5d) and the requested amount of the application key.
[0067] Next, since the KM 10a does not have information about the destination KM 10d connected to the destination application 5d, it requests the QKDN control device 6 to convert the ID information of the application 5d into the ID information of the KM 10d (step S6).
[0068] Next, the QKDN control device 6 refers to the mapping information and notifies the KM 10a of the ID information of the KM 10d connected to the application 5d (step S7).
[0069] The KMs 10a and 10d then share the application key (step S8). Specifically, the KM 10a determines the amount of application key to be shared from the requested amount of application key, and shares the application key to satisfy this amount by sending the application key encrypted using the link key to the KM 10d.
[0070] Next, the KMs 10a and 10d provide (transmit) the application key shared in step S8 to the applications 5a and 5d (steps S9 and S10).
[0071] Application 5a encrypts communication data using the application key provided in step S9, and transmits the encrypted communication data to application 5d via data communication network 103. Then, application 5d decrypts the encrypted communication data received in step S11 with the application key provided in step S10 (the same application key as the application key provided in step S9), thereby performing secure communication (step S11).
[0072] In the application key sharing process performed in step S8, for example, KM 10a stores the link key generated by QKD module 2a. KM 10a then encrypts the application key using the link key and relays the encrypted application key to adjacent KM 10b. Similarly, KM 10b relays the encrypted application key to adjacent KM 10c, and KM 10c relays the encrypted application key to adjacent KM 10d.
[0073] Each KM 10 consumes a link key when encrypting and exchanging an application key with the link key. Each KM 10 uses the link key in a one-time pad and discards the link key once it has been used. Each KM 10 also determines a key relay path for sharing the application key with any KM 10. Each KM 10 then shares (transfers) the application key to the destination KM 10, following the determined path and repeating encryption and decryption using the link key on each link.
[0074] As described above, the node 1 at each site has the function of generating and sharing random numbers with the opposing QKD module 2 (QKD module 2 function), and the function of using the generated random number as a link key to perform encrypted communication on the key sharing network 102 (KM10 function). The KM10 may also have the function of generating random numbers independently of the link key, and the function of transmitting the random number generated independently of the link key to another node 1 (KM10).
[0075] 7 is a diagram showing an example of mapping information in the first embodiment. The mapping information indicates the correspondence between the ID information of an application and the ID information of the KM 10 to which the application connects. When converting the ID information of the application 5 into its own ID information, the KM 10 refers to the mapping information shown in FIG.
[0076] 7 is an example of a case where the mapping information is managed using an IP-based table. This table includes a pair index number, an application ID, and a KM ID.
[0077] The pair index number is a number that identifies data in a table, and is automatically assigned when data is added to a table, for example.
[0078] For example, in the case of an IP address, the application ID is 192.168.11.36 (IPv4) or 2001:db8:20:3:10:1c:11:8 (IPv6) for application D. For example, the ID of the KM is 16.10.11.7 (IPv4) for KM 10d.
[0079] The IP address of KM 10 can be converted or generated according to certain rules in accordance with the IP address of the application connected to KM 10. The IP address of KM 10 can also be specified by the QKDN control device 6. Generally, when adding node 1 to the QKDN (when adding a new KM 10 to the key sharing network 102), the ID of KM 10 is often specified by the QKDN control device 6. Furthermore, the QKDN is a private network and is not connected to a public network. Therefore, it is possible for the IP address of KM 10 in the QKDN to match the IP address of the application 5 connected to KM 10.
[0080] When connecting with application 5, KM 10 notifies the QKDN control device 6 of the ID information of KM 10 and the ID information of application 5. When the QKDN control device 6 receives the information notified from KM 10, it adds it to the mapping information. Furthermore, there are cases where the mapping information is updated only when there is a change, and cases where it is updated periodically.
[0081] It should be noted that ID information such as an IP address assigned to an application 5 may change, for example, when the information processing device 8 on which the application 5 runs moves. In this case, the application 5 may notify the newly connected KM 10 of the changed ID information, and the newly connected KM 10 may notify the QKDN control device 6 to change the mapping information. Also, when the application 5 stops a service, it may notify the KM 10 connected to the application 5 that the service will be stopped, and the KM 10 may notify the QKDN control device 6 to delete the mapping information of the application 5 whose service is being stopped.
[0082] Furthermore, by installing the QKDN control device 6, mapping information is managed in a unified manner and updated periodically. One advantage of managing mapping information in a unified manner is that even if the number of KMs 10 increases, the storage area for saving the mapping information of each KM 10 can be saved compared to when it is stored in each KM 10. It also alleviates the problem of redundancy and duplication of mapping information of each KM 10. Furthermore, by installing the QKDN control device 6, responses to inquiries regarding mapping information can be made efficiently.
[0083] As described above, the KM 10 of the first embodiment is a key management device connected to a QKD module 2 (an example of a QKD device) that generates a link key by QKD. The communication unit 11 (an example of a communication interface) receives application key request information from a source application in a user network, the application key request information including first identification information that identifies the source application, second identification information that identifies the destination application, and a requested amount of the application key used to encrypt or decrypt communications in the user network. The processing unit 13 then identifies a key management device with which the application key will be shared, based on the second identification information, and determines the shared amount of the application key from the requested amount of the application key. The processing unit 13 causes the communication unit 11 to transmit an application key that is encrypted using the link key and satisfies the shared amount to the key management device with which the application key will be shared. The processing unit 13 causes the communication unit 11 to transmit the requested amount of application key to the source application identified by the first identification information.
[0084] As a result, according to the first embodiment, it is possible to easily associate an application 5 with a key management device that transmits an encryption key to the application 5, regardless of the scale of the QKDN.
[0085] (Second embodiment) Next, a second embodiment will be described. In the description of the second embodiment, the same description as in the first embodiment will be omitted, and only the differences from the first embodiment will be described.
[0086] As the QDKN scales up and the number of KMs 10 increases, it is common for the key sharing network (KSN) 102 to be divided into multiple KSN domains in order to efficiently and easily manage the KSN 102. In a KSN domain, for example, the number of KMs 10 or the number of links between KMs 10 is limited to a certain value (e.g., 1000).
[0087] Fig. 8A is a diagram showing Example 1 of KSN domains in the second embodiment. Fig. 8A shows a case where there are five key sharing networks 102a to 102e (five KSN domains of the same type) of the same type (IP-based in the example of Fig. 8A). Note that the number of key sharing networks 102 and the number of QKDN control devices 6 may be any number and are not limited to the example of Fig. 8A.
[0088] The five KSN domains shown in Fig. 8A have an IP-based ID system. A dedicated QKDN control device 6a to 6e in the QKD network management layer is installed for each key sharing network 102a to 102e in the key management layer.
[0089] Each QKDN control device 6 collects information such as mapping information from the KM 10 of each key sharing network 102 and manages the collected information.
[0090] Key sharing networks 102 are connected by KMs 10 (hereinafter referred to as BKMs (Boarder KMs)) installed at the boundaries between domains. BKMs at the boundaries between domains are physically located in the same place (node). Furthermore, information sharing between BKMs does not depend on the QKD link 3 used to share link keys.
[0091] When secure communication is performed from an application 5a (source) connected to a KM 10a in the key sharing network 102a to an application 5d (destination) connected to a KM 10d in the key sharing network 102d, the mapping information of the KM 10d does not exist in the QKDN control device 6a. Therefore, it is desirable that the mapping information of the KM 10d be shared from the QKDN control device 6d to the QKDN control device 6a.
[0092] Note that each KSN domain does not necessarily have the same standard, scale, or quantum protocol. Furthermore, the KSN domain (key sharing network 102) is not limited to an IP-based ID system. For example, there may be a mixture of IP-based and non-IP-based key sharing networks 102.
[0093] Fig. 8B is a diagram showing Example 2 of the KSN domain of the second embodiment. Fig. 8B shows an example in which different types of key sharing networks 102 coexist. In the example of Fig. 8B, there are five key sharing networks 102a to 102e. The key sharing networks 102a, 102c, and 102d are IP-based key sharing networks 102, and the key sharing networks 102b and 102e are non-IP-based key sharing networks 102. Note that the number of key sharing networks 102 and the number of QKDN control devices 6 may be any number and are not limited to the example of Fig. 8B.
[0094] When different types of key sharing networks 102 coexist, it is desirable that destination mapping information be shared efficiently.
[0095] Fig. 9 is a diagram showing an example of an ID system for identifying the KM 10 of the second embodiment. As shown in Fig. 9, the ID system of the KM 10 generally includes a QKD identifier, a KSN identification number, and a KM identification number.
[0096] The QKD identifier is an identifier that identifies the QKDN. The QKD identifier may also include an identifier that identifies the type of QKDN.
[0097] The KSN identification number indicates an ID that identifies the key sharing network 102 .
[0098] The KM identification number indicates an ID that identifies the KM 10 .
[0099] The ID system of the KM10 can follow, for example, an existing ID system. For example, an IP (Internet Protocol)-based ID system is used, with the network portion (including subnetworks) representing the QKD identifier and KSN identification number, and the host portion representing the KM identification number. Either IPv4 (32 bits) or IPv6 (128 bits) may be used. The advantage of using an IP-based ID system is that the IP network protocol can be used as is, and it is easy to implement routing for key relay between KM10.
[0100] Note that although the KSN identification number is different, the KM identification number may be the same. Therefore, the system of identifying a KM10 by combining the KSN identification number and the KM identification number is also called the Tree type.
[0101] For example, the KM10 ID system may also follow a UUID (Universally Unique IDentifier)-based ID system (128 bits). When following UUID, it is possible to use only a MAC (Media Access Control address)-based ID system (48 bits) without using a timestamp (60 bits) or clock sequence (14 bits). The OUI (Organizationally Unique IDentifier) (24 bits) portion of the ID system (48 bits) is assigned as a QKD identifier and KSN identification number, and is uniquely assigned so that they do not overlap. The remaining OUI (24 bits) portion is assigned as a KM identification number. Because KM identification numbers do not overlap, this type of system is also called a decentralized system.
[0102] On the other hand, other original ID systems may also be used as the ID system for the KM 10. The original ID system should include at least a KSN identification number and a KM identification number, and should be able to realize key relay based on the original ID system within the key sharing network 102.
[0103] Fig. 10 is a diagram showing an example of a quantum cryptography communication network according to the second embodiment. The example in Fig. 10 shows the case of a QKDN including different types of key sharing networks 102a and 102b. Secure communication is performed between application A and application B via a data communication network 103. Application A connects to KM 10a-1 in key sharing network 102a. Application B connects to KM 10b-1 in key sharing network 102b.
[0104] The key sharing networks 102a and 102b are connected by Link #1 between the physically co-located BKMs 10a-2 and 10b-2. Link #1 is independent of the QKD link 3 networks 101a and 101b.
[0105] Furthermore, QKDN control devices 6a and 6b are installed in the key sharing networks 102a and 102b, respectively, and the QKDN control devices 6a and 6b are connected by another link (Link#2).
[0106] Link #2 may utilize networks 101a and 101b of QKD link 3, or may be an ordinary link secured by a method other than QKD. Note that Link #2 may not exist. If Link #2 does not exist, it may be possible to share information via Link #1 between BKMs 10a-2 and 10b-2.
[0107] In the example of FIG. 10, for simplicity, the KM 10 in the key sharing network 102 and the QKD modules 2 in the networks 101a and 101b of the QKD link 3 are omitted.
[0108] Fig. 11 is a sequence diagram showing an example of a secure communication method according to the second embodiment. The example in Fig. 11 shows a sequence of relaying and transmitting an application key based on the mapping information and key storage status in the configuration in Fig. 10. Application 5a (source) corresponds to application A in Fig. 10. Application 5b (destination) corresponds to application B in Fig. 10.
[0109] First, when the application 5a connects to the KM 10a-1, it notifies the KM 10a-1 of the ID information of the application 5a (step S21). Next, the KM 10a-1 registers the ID information of the application 5a notified in step S21 and the ID information of the KM 10a-1 in a mapping information table stored in the QKDN control device 6a (step S22).
[0110] Similarly, when application 5b connects to KM 10b-1, it notifies KM 10b-1 of the ID information of application 5b (step S23), and registers the ID information of application 5b and the ID information of KM 10b-1 in the mapping information table of QKDN control device 6b (step S24).
[0111] Before performing secure communication, the application 5a requests an application key from the KM 10a-1 (step S25). At that time, the application 5a notifies the KM 10a-1 of information indicating that the secure communication destination of the application 5a is the application 5b (for example, ID information of the destination application 5b), as well as the requested amount of the application key.
[0112] Next, the KM 10a-1 requests the QKDN control device 6a to convert the ID of the application 5b into the ID of the KM 10 connected to the application 5b (step S26).
[0113] Next, the QKDN control device 6a refers to the mapping information table to search for the KM 10 to which the application 5b is connected. If the QKDN control device 6a cannot find information about the KM 10 to which the application 5b is connected, it queries the QKDN control device 6b for ID information about the KM 10 to which the application 5b is connected (step S27). The QKDN control device 6b refers to the mapping information table and identifies that the KM 10 to which the application 5b is connected is KM 10b-1 and the ID information of KM 10b-1.
[0114] When the QKDN control device 6a receives mapping information indicating that the KM 10 to which the application 5b is connected is KM 10b-1 from the QKDN control device 6b (step S28), it returns the ID information of KM 10b-1 to KM 10a-1 (step S29).
[0115] Furthermore, the QKDN control device 6b inquires of the KM 10b-1 about the application key storage status shared with the KM 10a-1, and upon receiving the application key storage status (step S30), notifies the QKDN control device 6a of the application key storage status (step S31).
[0116] Next, the QKDN control device 6a updates the mapping information and key accumulation status stored in the storage unit 62 of the QKDN control device 6a based on the mapping information notified in step S27 and the application key accumulation information notified in step S30. The QKDN control device 6a calculates the required amount of additional application keys (shared amount) from the requested amount of application keys and the accumulation status of application keys shared between KM 10a-1 and KM 10b-1, and notifies KM 10a-1 of the required amount of application keys (step S32).
[0117] Next, if the required amount of additional application keys is not 0 (if the accumulated amount of application keys is less than the requested amount of application keys), the KM 10a-1 shares the application keys by relaying the application keys from the KM 10a-1 to the KM 10b-1 (step S33).
[0118] After sharing the application key, the KMs 10a-1 and 10b-1 provide (transmit) the application key to the applications 5a and 5b (steps S34 and S35).
[0119] The secure communication in step S36 is the same as the secure communication in step S11 in the first embodiment (FIG. 6), and therefore a description thereof will be omitted.
[0120] If the required amount of additional application keys is 0 in step S31 (if the accumulated application key amount is equal to or greater than the requested application key amount), the KM 10a-1 immediately provides the application key to the application 5a. The KM 10a-1 also sends an instruction to the KM 10b-1 to immediately provide the application key to the application 5b.
[0121] Furthermore, the required amount (shared amount) of additional application keys may be calculated by the processing unit 13 of the KM 10. In this case, the communication unit 11 of the KM 10 receives the state information of the application keys from the QKDN control device 6a, and the processing unit 13 determines the shared amount of the application keys from the requested amount of application keys and the state information.
[0122] Fig. 12 is a diagram showing an example of mapping information in the second embodiment. Fig. 12 is an example of a table of mapping information shared between the QKDN control devices 6a and 6b. The table in Fig. 12 shows a table stored in the QKDN control device 6a. Compared to Fig. 7 of the first embodiment, type and KSN ID have been added.
[0123] There are two types: "i" and "o". "i" indicates that it is inside information, and indicates that it is ID information collected from KM10 within each KSN domain. "o" indicates that it is outside information, and indicates that it is ID information shared from other QKDN control devices 6 (ID information of KM10 belonging to other KSN domains).
[0124] The KSN ID is, for example, the identification number of the KSN. The KM ID may be the identification number of the KM 10 alone, or may be an ID that combines the identification number of the KSN and the identification number of the KM.
[0125] In the example of Figure 12, KM 10a-1 has an IP-based ID system, and KM 10b-1 has a non-IP-based ID system. The application ID (e.g., IP address) is assigned by the data communication network 103 to which the application 5 belongs. Multiple applications 5 may connect to the same KM 10. Conversely, one application 5 will not connect to multiple KMs 10.
[0126] In the mapping information table of Figure 12, information from each KM 10 in the KSN domain is updated periodically. The period is set according to the actual situation. In addition, when a new application connects to the KM 10, when the KM 10 terminates the connection with the application 5, or when an application 5 requests an application key, data stored in the mapping information table is added, deleted, or updated.
[0127] Fig. 13 is a diagram showing an example of state information in the second embodiment. Fig. 13 is an example of a table of state information shared between the QKDN control devices 6a and 6b. The table in Fig. 13 shows a table stored in the QKDN control device 6a. The table in Fig. 13 includes a type, a sequence number, a source KM ID, a destination KM ID, an encryption application key, and a decryption application key.
[0128] The explanation of the types is the same as that of FIG. 12 and will be omitted.
[0129] Sequence information is identification information that is assigned in the order in which data is stored. Sequence numbers are numbers that are assigned, for example, in chronological order. Source KM ID is identification information that identifies the source KM 10. Destination KM ID is identification information that identifies the destination KM 10. The encryption application key and decryption application key information indicate the remaining amount of application keys currently stored.
[0130] 13 show a case where the sequence numbers match because the application key accumulation status is shared. In this case, the remaining encryption application key amount in KM 10a-1 matches the remaining decryption application key amount in KM 10b-1. The remaining decryption application key amount in KM 10a-1 also matches the remaining encryption application key amount in KM 10b-1.
[0131] The data examples on the second and fourth lines in Figure 13 show a case where the sequence numbers do not match because the application key storage status has not been shared for a while. The application key storage status of KM 10a-1, which belongs to the KSN domain managed by QKDN control device 6a, is new, while the application key storage status shared by another QKDN control device 6 that manages the KSN domain to which KM 10b-x belongs, is old. As a result, the encryption application key of KM 10a-1 and the decryption application key of KM 10b-x do not match.
[0132] In the application key status information table, the storage status of the application keys in the KM 10 within the KSN domain managed by the QKDN control device 6 may or may not be updated periodically (periodically). The period is set according to the actual situation. Furthermore, the storage status of an application key may be updated when an application 5 requests that application key.
[0133] Since node 1 (QKD module 2 and KM 10) was added to the QKDN, link keys between QKD modules 2 have been generated continuously at a certain speed without interruption. The generated link keys are stored in KM 10 and are used as encryption and decryption keys when application keys are shared. Secure communication between applications 5 occurs as needed, and application keys are shared between KMs 10 in response to application key requests from applications 5.
[0134] In addition, stored application keys may be used in advance. In other words, each KM 10 may share a certain amount of application keys in advance, regardless of whether an application key is requested. This allows the source KM 10 and destination KM 10 to send an application key to the application 5 without performing a new application key sharing process if the amount of the requested application key is equal to or less than the amount of application keys that have been shared in advance (the current amount).
[0135] Furthermore, if the requested amount of application keys is greater than the accumulated amount of application keys that have been shared in advance, the QKDN control device 6, or the KM 10 that has received notification of the application key accumulation status from the QKDN control device 6, calculates the amount of additional application keys required and performs application key sharing processing as necessary. As shown in Fig. 13, by sharing the application key accumulation status among multiple QKDN control devices 6, application keys can be sent to applications 5 flexibly and efficiently.
[0136] 14 is a diagram showing an example of the format of an inquiry message regarding sharing of mapping information in the second embodiment. The header portion of the inquiry message includes six fields.
[0137] The Version of Application is a field that indicates the version of the application 5. For example, in the case of IPv4, 0x04 is stored in the Version of Application. Also, for example, in the case of IPv6, 0x06 is stored in the Version of Application. Also, for example, in the case of non-IP, 0x10 is stored in the Version of Application.
[0138] The Version of KM is a field that indicates the version of KM 10. For example, in the case of IPv4, 0x04 is stored in the Version of KM. For example, in the case of IPv6, 0x06 is stored in the Version of KM. For example, in the case of non-IP, 0x10 is stored in the Version of KM.
[0139] Type is a field that indicates the type of message. For example, in the case of an inquiry, 0x00 is stored in Type. For example, in the case of a response, 0x10 is stored in Type. For example, in the case of an error, 0x20 is stored in Type.
[0140] Code is a field that indicates the purpose of the message. For example, if Type = 0x00 (in the case of an inquiry), if the inquiry is for the KSN domain ID, 0x01 is stored in Code. For example, if the inquiry is for the KM10 ID, 0x02 is stored in Code. For example, if the inquiry is for the sequence number, 0x03 is stored in Code. For example, if the inquiry is for the application key, 0x04 is stored in Code.
[0141] Similarly, for example, if Type = 0x10 (response), if the response is for a KSN domain ID, 0x11 is stored in Code. For example, if the response is for a KM10 ID, 0x12 is stored in Code. For example, if the response is for a sequence number, 0x13 is stored in Code. For example, if the response is for an application key, 0x14 is stored in Code.
[0142] For example, if Type=0x20 (error), and the KSN domain ID is unknown, 0x21 is stored in Code. For example, if the KM10 ID is unknown, 0x22 is stored in Code. For example, if there is an error in the sequence number, 0x23 is stored in Code. For example, if there is an error in the application key, 0x24 is stored in Code.
[0143] The Length field indicates the length of the message.
[0144] Checksum is a field for error checking of the message.
[0145] The data portion of the query message contains four fields.
[0146] The Source Application ID is a field that indicates information about the source application 5. For example, in the case of IPv4, the Source Application ID is 32 bits long, and in the case of IPv6, the Source Application ID is 128 bits long.
[0147] The Destination Application ID is a field that indicates information about the destination application 5. For example, in the case of IPv4, the length of the Destination Application ID is 32 bits, and in the case of IPv6, the length of the Destination Application ID is 128 bits.
[0148] The Source KM ID is a field that indicates information about the source KM 10.
[0149] The Source KSN ID is a field that indicates information about the KSN domain to which the source KM 10 belongs.
[0150] 15 is a diagram showing an example of the format of a response message related to sharing of mapping information in the second embodiment. The header portion of the response message includes six fields. The header portion of the response message is the same as the header portion of the inquiry format.
[0151] The data part of the response message contains eight fields. The first four fields are the same as the data part of the query message. The data part of the response message adds two fields for mapping information and two fields for the application key storage status.
[0152] The Destination KM ID is a field that indicates the ID information of the destination KM 10 .
[0153] Destination KSN ID is a field that indicates the ID information of the destination KSN domain.
[0154] The Sequence Number field indicates the sequence number.
[0155] The Available Amount of Application Key is a field that indicates the accumulation status of application keys that have already been shared between the source KM 10 and the destination KM 10.
[0156] The message field length is defined according to actual requirements, and the message field length shown in Figures 12 and 13 above is an example.
[0157] In the configuration examples of Figures 8A and 7B, for example, when an application 5 connecting to KM 10a in key sharing network 102a requests an application key, and secure communication is performed with an application connecting to KM 10d in key sharing network 102d, the operation is basically the same as in Figure 10. However, because information sharing between QKDN control devices 6a to 6d is not connected by a single link, it becomes a little more complicated.
[0158] There are two ways to share information among the QKDN control devices 6a to 6d: sharing by distributed management and sharing by centralized management. In distributed management, a dedicated network of QKDN control devices 6 is constructed. In centralized management, an authoritative root server device is installed, and all QKDN control devices 6 connect to the authoritative root server device.
[0159] Fig. 16 is a diagram showing an example of a distributed management configuration according to the second embodiment. In the example of Fig. 16, the QKDN control devices 6 construct a dedicated network, and each QKDN control device 6 stores mapping information and application key status information. Furthermore, each QKDN control device 6 creates, updates, and deletes mapping information and application key status information.
[0160] When an application key is requested from an application 5 in a user network, related information (for example, mapping information and key state information of the application key) is shared between each QKDN control device 6.
[0161] Each QKDN control device 6 simultaneously forwards the same inquiry message to other QKDN control devices 6 in the dedicated network, for example, in a broadcast manner, to find out the destination information.
[0162] The other QKDN control device 6 receives the inquiry message, refers to the Destination Application ID field, checks the mapping information, and returns a response message.
[0163] The QKDN control device 6 that sent the inquiry message checks the Type and Code fields when it receives a response message from another QKDN control device 6. If the QKDN control device 6 finds an error in the Type and Code fields, it determines that there is no relevant information for the destination application 5 and therefore secure communication between the applications 5 is not possible. If the QKDN control device 6 finds no error in the Type and Code fields, it performs key transmission and key relay processing based on the four field information from the Destination KM ID field.
[0164] 16, for distributed management, sequence numbers (e.g., chronological order) are assigned to related information, and the latest information is always used. Note that the link between the QKDN control devices 6 may be a QKD link 3, or may be an ordinary link secured by a method other than QKD.
[0165] Fig. 17 is a diagram showing an example of the centralized management configuration of the second embodiment. In the example of Fig. 17, the QKDN control device 6 is connected to the authoritative root server device 9. Mapping information and related information such as application key status information are centrally managed by the authoritative root server device 9. When an application 5 in the user network requests an application key, the QKDN control device 6 queries the authoritative root server device 9 for related information. If the result of checking the Type and Code fields included in the response message received from the authoritative root server device 9 shows no error, the QKDN control device 6 performs key transmission and key relay processing based on the mapping information and application key status information.
[0166] The QKDN control device 6 checks the Type and Code fields contained in the response message received from the authoritative root server device 9, and if an error is found, it feeds back to the KM 10 that secure communication between the applications 5 is not possible because there is no related information for the destination application 5.
[0167] Regarding information updates of the authoritative root server device 9, if the information is constantly updated, the authoritative root server device 9 and the QKDN control device 6 assign the same sequence number. If the information of the authoritative root server device 9 is updated only when the mapping information and the application key status information are queried, the related QKDN control device 6 notifies the authoritative root server device 9 of the latest information when queried.
[0168] The link between the authoritative root server device 9 and the QKDN control device 6 may be a QKD link 3, or may be an ordinary link secured by a method other than QKD.
[0169] Finally, an example of the hardware configuration of the KM 10, the QKDN control device 6, and the information processing device 8 according to this embodiment will be described. [Example of hardware configuration] 18 is a diagram showing an example of the hardware configuration of the KM 10, QKDN control device 6, and information processing device 8 of the first and second embodiments. The KM 10, QKDN control device 6, and information processing device 8 each include a control device such as a CPU 201, storage devices such as a ROM (Read Only Memory) 202 and RAM 203, and a communication I / F 204 that connects to a network and performs communication. The CPU 201, ROM 202, RAM 203, and communication I / F 204 are connected by a bus 205.
[0170] For example, the programs executed by the KM 10, the QKDN control device 6, and the information processing device 8 are provided in a state that they are pre-installed in the ROM 202 or the like.
[0171] Furthermore, for example, the programs executed by KM10, QKDN control device 6, and information processing device 8 may be configured to be provided as a computer program product by being recorded in an installable or executable format on a computer-readable recording medium such as a CD-ROM (Compact Disk Read Only Memory), a flexible disk (FD), a CD-R (Compact Disk Recordable), or a DVD (Digital Versatile Disk).
[0172] Furthermore, the programs executed by the KM 10, the QKDN control device 6, and the information processing device 8 may be stored on a computer connected to a network such as the Internet and provided by being downloaded via the network. Also, the programs executed by the KM 10, the QKDN control device 6, and the information processing device 8 may be provided or distributed via a network such as the Internet.
[0173] The programs executed by the KM 10, the QKDN control device 6, and the information processing device 8 can cause the computer to function as each of the above-mentioned parts of the KM 10, the QKDN control device 6, and the information processing device 8. In this computer, the CPU 201 can read the programs from a computer-readable storage medium onto a main storage device such as the RAM 203 and execute them.
[0174] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, and are also included in the scope of the invention and its equivalents as defined in the claims. [Explanation of symbols]
[0175] 1 node 2 QKD modules 3 QKD Link 4 QKD Network Controller 5. Applications 6 QKDN control device 7 User network control device 8. Information processing equipment 9 Authoritative root server devices 10 Key management device (KM) 11 Communications Department 12 Storage section 13 Processing section 61 Communications Department 62 Memory section 63 Processing section 100 Quantum cryptography communication network A network of 101 QKD links 102 Key Sharing Network 103 Data Communication Network 111 KM Communications Department 112 Control and communication unit 113 App Communication Department 131 Acquisition Department 132 Executive Department 133 Key Processing Unit 134 Provision Department 135 Control Unit 136 Management Department 137 Platform Section 611 KM Communications Department 612 Control and communication unit 631 Acquisition Department 632 Control Unit 633 Management Department 634 Platform Section
Claims
1. A key management device connected to a QKD device that generates a link key by QKD (Quantum Key Distribution), a communication interface for receiving, from a source application of a user network, request information for an application key, the request information including first identification information for identifying the source application, second identification information for identifying a destination application, and a requested amount of an application key to be used for encrypting or decrypting communications in the user network; identifying a key management device with which the application key is shared from the second identification information; determining a shared amount of the application key from the requested amount of the application key; transmitting the application key, which is encrypted using the link key and satisfies the sharing amount, to the key management device of the sharing destination via the communication interface; a processing unit that causes the communication interface to transmit the requested amount of application keys to a source application identified by the first identification information; A key management device comprising:
2. the application key request information further includes a provision time for transmitting the application key; the communication interface transmits the requested amount of application keys to the source application by the provision time; The key management device according to claim 1 .
3. the communication interface communicates with a QKDN (Quantum Key Distribution Network) control device that stores mapping information in which second identification information that identifies the destination application and third identification information that identifies a key management device that transmits an application key to the destination application are associated with each other; The communication interface obtains the mapping information from the QKDN control device; the processing unit identifies a key management device with which the application key is to be shared from the mapping information. The key management device according to claim 1 or 2.
4. the QKDN control device further stores state information indicating the amount of application keys already shared between a key management device connected to the source application and a key management device connected to a destination application; the processing unit determines the shared amount of the application key based on the requested amount of the application key and the state information. The key management device according to claim 3 .
5. a first key management device and a second key management device, each of which is the key management device according to claim 3; a key sharing network configured by the first and second key management devices; the QKDN control device in communication with the first and second key management devices; a plurality of applications including the source application and the destination application; the user network in which the plurality of applications perform encrypted communication using the application key; A quantum cryptography communication system comprising:
6. The QKD device further includes a first QKD device and a second QKD device that generate the link key by QKD; the first QKD device transmits the link key to the first key management device; the second QKD device transmits the link key to the second key management device; The quantum cryptography communication system according to claim 5 .
7. A QKDN (Quantum Key Distribution Network) control device connected to a plurality of key management devices that transmit application keys used for encrypting or decrypting communications between applications in a user network to the applications, the QKDN control device comprising: a processing unit that causes the communication interface to acquire, from the plurality of key management devices, mapping information in which identification information for identifying the application and identification information for identifying a key management device that transmits an application key to the application are associated with each other, and status information of the application key, and stores the mapping information and the status information in a storage device; A QKDN control device comprising:
8. the state information indicates the amount of application keys already shared between a first key management device connected to a source application and a second key management device connected to a destination application; The QKDN control device of claim 7.
9. the application key already shared between the first key management device and the second key management device is shared by encrypted communication using a link key generated by QKD in a QKDN between a source QKD (Quantum Key Distribution) device connected to the first key management device and a destination QKD device connected to the first key management device; The QKDN control device of claim 8.
10. a communication interface that transmits application key request information, including first identification information for identifying a source application of a user network, second identification information for identifying a destination application, and a requested amount of an application key used for encrypting or decrypting communications in the user network, to a key management device connected to a QKD device that generates a link key by QKD (Quantum Key Distribution), and receives an application key shared to satisfy the requested amount between the key management device with which the application key is shared and the key management device identified from the second identification information; a processing unit that operates the source application to encrypt communications in the user network; An information processing device comprising:
11. A key management method for a key management device connected to a QKD device that generates a link key by QKD (Quantum Key Distribution), comprising: receiving, by the communication interface, from a source application of a user network, request information for an application key, the request information including first identification information identifying the source application, second identification information identifying a destination application, and a requested amount of an application key to be used for encrypting or decrypting communications in the user network; a processing unit specifying, from the second identification information, a key management device with which the application key is to be shared; the processing unit determining a shared amount of the application key from the requested amount of the application key; a step of causing the processing unit to transmit the application key, which is encrypted using the link key and satisfies the sharing amount, to the communication interface to the key management device of the sharing destination; the processing unit causes the communication interface to transmit the requested amount of application keys to a source application identified by the first identification information; A key management method comprising:
12. A QKDN (Quantum Key Distribution Network) control method for a QKDN control device connected to a plurality of key management devices that transmit application keys used for encrypting or decrypting communications between applications in a user network to the applications, the method comprising: a processing unit causing a communication interface to acquire, from the plurality of key management devices, mapping information in which identification information for identifying the application and identification information for identifying a key management device that transmits an application key to the application are associated with each other, and status information of the application key; the processing unit storing the mapping information and the state information in a storage device; A QKDN control method including:
13. a step in which a communication interface transmits, to a key management device connected to a QKD device that generates a link key by QKD (Quantum Key Distribution), application key request information including first identification information that identifies a source application of a user network, second identification information that identifies a destination application, and a requested amount of application key used for encryption or decryption of communications in the user network; receiving, via the communication interface, an application key shared between the communication interface and a key management device with which the application key is shared, the application key being specified based on the second identification information, so as to satisfy the requested amount; a processing unit running the source application to encrypt communications in the user network; An information processing method comprising:
14. A key management device connected to a QKD device that generates a link key by QKD (Quantum Key Distribution) is a communication interface for receiving, from a source application of a user network, request information for an application key, the request information including first identification information for identifying the source application, second identification information for identifying a destination application, and a requested amount of an application key to be used for encrypting or decrypting communications in the user network; identifying a key management device with which the application key is shared from the second identification information; determining a shared amount of the application key from the requested amount of the application key; transmitting the application key, which is encrypted using the link key and satisfies the sharing amount, to the key management device of the sharing destination via the communication interface; a processing unit that causes the communication interface to transmit the requested amount of application keys to a source application identified by the first identification information; A program to function as a
15. A QKDN (Quantum Key Distribution Network) control device connected to a plurality of key management devices that transmit application keys used for encrypting or decrypting communications between applications in a user network to the applications, a processing unit that causes the communication interface to acquire, from the plurality of key management devices, mapping information in which identification information for identifying the application and identification information for identifying a key management device that transmits an application key to the application are associated with each other, and status information of the application key, and stores the mapping information and the status information in a storage device; A program to function as a
Citation Information
Patent Citations
Small sealed battery
JP1982084562A
Character wheel positioning device in printer
JP1989026477A
Method and apparatus for managing encryption key in private communication network
JP2008306633A
Communication device, communication method, program and communication system
JP2014241463A
Communication apparatus, communication method, program and communication system
JP2016171530A