Quantum Key Distribution Service Platform
The quantum key distribution service platform addresses key generation and sharing limitations by using AI to predict and manage encryption key consumption, ensuring continuous encrypted communication through adaptive key transfer.
Patent Information
- Application Number
- JP2021012971
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-01-29
- Publication Date
- 2025-11-17
- Estimated Expiration
- 2041-01-29
AI Technical Summary
The generation and sharing of encryption keys using quantum key distribution technologies are insufficient to meet the increasing demands of high-speed data communication, leading to potential shortages and the need for adaptive management to ensure continuous encrypted communication.
A quantum key distribution service platform that includes an administration server to monitor, predict, and manage encryption key consumption, transferring keys between communication nodes to prevent shortages by leveraging AI for adaptive key management.
Ensures stable encrypted communication by dynamically managing encryption keys, preventing shortages through intelligent key transfer and allocation, optimizing resource utilization and cost efficiency.
Smart Images

Figure 0007770772000001 
Figure 0007770772000002 
Figure 0007770772000003
Abstract
Description
[Technical Field]
[0001] SUMMARY OF THE INVENTION An embodiment of the present invention relates to a quantum key distribution service platform. [Background technology]
[0002] In recent years, it has become commonplace to encrypt and send data between locations connected via a network. One-time pad (OTP) encryption, which cannot be decrypted using ciphertext alone, is also widely used. OTP consumes an encryption key equivalent to the amount of data. Encrypted communication using OTP requires secure sharing of the large amount of encryption key consumed between locations. For these reasons, quantum key distribution, which shares encryption keys (quantum keys) based on the principles of quantum mechanics, has attracted attention. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 6615718 Summary of the Invention [Problem to be solved by the invention]
[0004] Quantum key distribution is a technology that utilizes the behavior of photons, generating and sharing encryption keys by sending and receiving encryption key information between locations using photons as a medium, such as optical fiber (or vacuum). Generating and sharing encryption keys takes a certain amount of time. With the recent dramatic increase in data communication speeds, there is a possibility that the amount of encryption keys consumed per unit time for encrypted communication will exceed the amount that can be generated and shared per unit time. Therefore, in order to continue encrypted communication stably for a certain period of time, it is necessary to store a certain amount of encryption keys.
[0005] For example, when providing a service that provides users who conduct encrypted communications between locations with encryption keys generated and shared using quantum key distribution, it is necessary to set limits on the encryption key generation and sharing performance and the amount of encryption keys that can be stored, that is, on the encryption key supply capacity, due to cost considerations. Therefore, it is necessary to manage encryption keys adaptively according to the consumption status of each user's encryption keys so that no user experiences a shortage (exhaustion) of encryption keys.
[0006] The problem to be solved by the present invention is to provide a quantum key distribution service platform that can adaptively manage encryption keys. [Means for solving the problem]
[0007] According to an embodiment, a quantum key distribution service platform includes a plurality of quantum key distribution devices and an administration server. The plurality of quantum key distribution devices transmit and receive encryption key information to and from other quantum key distribution devices, and generate encryption keys to be shared with the other quantum key distribution devices based on the encryption key information. The administration server monitors the amount of encryption keys stored for each of the plurality of cryptographic communication devices in the plurality of quantum key distribution devices, records the consumption history of the encryption keys for each of the plurality of cryptographic communication devices, predicts the consumption of the encryption keys for each of the plurality of cryptographic communication devices based on the consumption history of the encryption keys, and detects signs of a shortage of encryption keys that may occur in cryptographic communication between the plurality of cryptographic communication devices based on the accumulated amount of encryption keys and the predicted consumption of encryption keys. Based on the predicted amount of stored encryption keys and the amount of consumed encryption keys, the method selects, from among other encrypted communications in the same section as the encrypted communication in which a sign of a shortage of encryption keys has been detected, other encrypted communications that are expected to have surplus encryption keys and are suitable as a source of encryption keys to supplement the encryption keys, and transfers the encryption keys of the selected other encrypted communications to the encryption keys of the encrypted communication in which a sign of a shortage of encryption keys has been detected. . [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 is a diagram showing an example of the configuration of a quantum key distribution service platform according to an embodiment. [Figure 2] FIG. 1 is a diagram illustrating an example of functional blocks of a quantum key distribution service management server of a quantum key distribution service platform according to an embodiment. [Figure 3] FIG. 1 is a diagram for explaining encryption key transfer control that can be performed in the quantum key distribution service platform of the embodiment. [Figure 4]FIG. 1 is a diagram showing an example of a user management DB used in the quantum key distribution service platform of the embodiment. [Figure 5] FIG. 1 is a diagram showing an example of an encryption key storage amount management DB used in the quantum key distribution service platform of the embodiment; [Figure 6] FIG. 1 is a diagram showing an example of an encryption key consumption record management DB used in the quantum key distribution service platform of the embodiment; [Figure 7] FIG. 1 is a diagram showing an example of an encryption key consumption prediction management DB used in the quantum key distribution service platform of the embodiment; [Figure 8] 1 is a flowchart showing an example of a flow of predicting the consumption of encryption keys by a quantum key distribution service management server of a quantum key distribution service platform according to an embodiment; [Figure 9] 1 is a flowchart showing an example of a flow of determining the allocation amount of encryption keys and detecting a sign of a shortage of encryption keys by a quantum key distribution service management server of a quantum key distribution service platform according to an embodiment. [Figure 10] 1 is a flowchart showing an example of the flow of a cryptographic key lending process performed by a quantum key distribution service management server of a quantum key distribution service platform according to an embodiment; DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, embodiments will be described with reference to the drawings.
[0010] Fig. 1 is a diagram showing an example of the configuration of a quantum key distribution service platform 1 according to this embodiment. Fig. 1 also shows an example of cryptographic communication performed by a quantum key user 2 who receives a cryptographic key (quantum key) from the quantum key distribution service platform 1.
[0011] Quantum key distribution service platform 1 provides a quantum key distribution service for users who conduct encrypted communications using OTP. Specifically, quantum key distribution service platform 1 supplies shared encryption keys to each location of users who conduct encrypted communications between locations. By using this quantum key distribution service, users do not need the resources required to generate and share encryption keys between locations.
[0012] The quantum key distribution service platform 1 has a quantum key distribution system 20. The quantum key distribution system 20 is configured as an optical fiber network in which quantum key distribution devices 21A of multiple quantum key distribution centers 21 scattered around various locations are connected via optical fibers. Each of the multiple quantum key distribution centers 21 is equipped with one or more quantum key distribution devices 21A.
[0013] The quantum key distribution device 21A transmits and receives encryption key information to and from other quantum key distribution devices 21A using photons, and the two devices generate a shared encryption key based on the encryption key information. The quantum key distribution device 21A also functions as a relay device that relays encryption key information. That is, encryption keys can be shared not only between quantum key distribution devices 21A directly connected by optical fiber, but also between quantum key distribution devices 21A via one or more quantum key distribution devices 21A. Assuming that there are N quantum key distribution centers 21, there can be (N×(N-1)) / (2×1) possible pairs of two quantum key distribution centers 21 that can generate a shared encryption key.
[0014] The quantum key distribution service platform 1 also has a quantum key distribution layer 30. The quantum key distribution layer 30 is configured as a virtual communication network in which the quantum key distribution centers 21 of the quantum key distribution system 20 are simul- taneously represented as nodes 31 and the nodes 31 are assumed to be connected by communication paths. The quantum key distribution layer 30 may include multiple communication networks. The multiple communication networks of the quantum key distribution layer 30 may be created by region, or may be created to distribute the quantum key users 2 into several groups.
[0015] The nodes 31 in the quantum key distribution layer 30 are positioned as access points of the quantum key distribution service platform 1. The encrypted communication servers 50 of the quantum key users 2 that perform encrypted communication using OTP are each supplied with an encryption key from, for example, the node 31 corresponding to the nearest quantum key distribution center 21. In this case, the encrypted communication server 50 and the node 31 are assumed to be located on the same site or in the same building, and communication between them is assumed to be physically protected.
[0016] As described above, assuming that there are N quantum key distribution centers 21, there can be (N×(N−1)) / (2×1) possible pairs of two quantum key distribution centers 21 that share an encryption key. Therefore, the quantum key distribution service platform 1 can provide a service that supplies encryption keys for (N×(N−1)) / (2×1) possible sections. Also, as described above, one or more quantum key distribution devices 21A are arranged in the quantum key distribution center 21. Encryption keys generated by the one or more quantum key distribution devices 21A are assigned to each cryptographic communication performed in each section that is set with the quantum key distribution center 21 as one end. Also, some of the encryption keys generated by the one or more quantum key distribution devices 21A are assigned as spares for those cryptographic communications.
[0017] In other words, when an encrypted communication server 50 performs encrypted communication with multiple encrypted communication servers 50, an encryption key for each communication partner is supplied to the encrypted communication server 50. For example, in a case where an encrypted communication server [1] 50 at a base in Tokyo performs encrypted communication with an encrypted communication server [2] 50 at a base in Osaka and also performs encrypted communication with an encrypted communication server [3] 50 at a base in Fukuoka, the quantum key distribution service platform 1 supplies the pair of the encrypted communication server [1] 50 and the encrypted communication server [2] 50 with an encryption key generated and shared between the quantum key distribution centers 21 corresponding to the nodes 31 to which they are connected, and supplies the pair of the encrypted communication server [1] 50 and the encrypted communication server [3] 50 with an encryption key generated and shared between the quantum key distribution centers 21 corresponding to the nodes 31 to which they are connected. In other words, in this case, the encrypted communication server [1] 50 is supplied with an encryption key for encrypted communication with the encrypted communication server [2] 50 from the node 31, and also with an encryption key for encrypted communication with the encrypted communication server [3] 50 from the same node 31.
[0018] The quantum key distribution service platform 1 also supplies the encrypted communication server 50, which performs the encrypted communication, with an encryption key for encrypting data to be sent to the communication partner and an encryption key for decrypting encrypted data received from the communication partner. Therefore, in the above case, the quantum key distribution service platform 1 supplies, for example, six types of encryption keys for different communication partners and communication directions to the encrypted communication server [1] 50 from the node 31.
[0019] The quantum key distribution layer 30 may be configured as a real communication network, rather than as a virtual communication network. The quantum key distribution service platform 1 may lend the communication network of the quantum key distribution layer 30 as an encrypted communication path to a quantum key user 2 that receives a cryptographic key from the node 31 and performs encrypted communication. This communication network does not have to be an optical fiber network (it may be an optical fiber network).
[0020] The quantum key distribution service platform 1 has a quantum key distribution service management server 10 for adaptively managing the supply of encryption keys from the quantum key distribution center 21 (quantum key distribution device 21A) of the quantum key distribution system 20 to the encrypted communication server 50 of the quantum key user 2 as described above, via the node 31 of the quantum key distribution layer 30. In the quantum key distribution service platform 1 of this embodiment, the quantum key distribution service management server 10 detects signs of a shortage (exhaustion) of encryption keys, and enables users to, for example, share encryption keys with each other before the shortage occurs, which will be described in detail below.
[0021] 2 is a diagram showing an example of functional blocks of the quantum key distribution service management server 10. In FIG. 2, an example of functional blocks of the quantum key distribution device 21A and the encrypted communication server 50 is also shown.
[0022] The encrypted communication server 50 has an encrypted communication unit 51. The encrypted communication unit 51 performs encrypted communication with the encrypted communication unit 51 of the encrypted communication server 50 at another base. The encrypted communication server 50 is connected to, for example, a plurality of PCs (personal computers) within the base via a LAN (local area network). The encrypted communication unit 51 receives an encryption key from the quantum key distribution device 21A (recognized as node 31 by the encrypted communication unit 51) and performs encryption and decryption of data transmitted and received between the PC connected to the encrypted communication server 50 and the PC connected to the encrypted communication server 50 at another base.
[0023] The quantum key distribution device 21A has an encryption key generation unit 201, an encryption key provision unit 202, and an encryption key transfer control unit 203. The quantum key distribution device 21A also has an encryption key storage unit 251 provided on a storage medium such as a hard disk drive (HDD). In FIG. 2, a collection of one or more quantum key distribution devices 21A arranged in the quantum key distribution center 21 is shown as a single quantum key distribution device 21A. Therefore, the quantum key distribution device 21A in FIG. 2 can also be read as the quantum key distribution center 21. In addition, for example, some of the units shown as components of the quantum key distribution device 21A in FIG. 2 may be present in the quantum key distribution center 21 rather than in each quantum key distribution device 21A.
[0024] The encryption key generation unit 201 transmits and receives encryption key information to and from the encryption key generation unit 201 of another quantum key distribution device 21A using photons, and generates an encryption key shared between the quantum key distribution device 21A incorporating the encryption key generation unit 201 and the other quantum key distribution device 21A based on the encryption key information. The encryption key information may be transmitted and received unilaterally from one device to the other, or bidirectionally. When the encryption key information is transmitted and received bidirectionally, for example, the encryption key information transferred from one device to the other may be used to generate an encryption key used to encrypt data transferred from one device to the other, and the encryption key information transferred from the other device to one device may be used to generate an encryption key used to encrypt data transferred from the other device to the one device.
[0025] The encryption key generation unit 201 stores the generated encryption keys in the encryption key storage unit 251. As described above, encryption keys need to be prepared for each communication partner and each communication direction. Therefore, the encryption key generation unit 201 stores the generated encryption keys in the encryption key storage unit 251 for each communication partner and each communication direction. The ratio at which the generated encryption keys are allocated to each communication partner and each communication direction and stored in the encryption key storage unit 251 is based on the result of an encryption key consumption prediction by the encryption key lending control unit 103 of the quantum key distribution service management server 10, which will be described later. Note that the encryption key generation unit 201 may allocate a certain amount of the encryption key generation amount per unit time equally to each communication partner and each communication direction, and allocate the remaining amount to each communication partner and each communication direction based on the result of the encryption key consumption prediction by the encryption key lending control unit 103. The encryption key generation unit 201 also reserves a certain amount of encryption keys as spares in the encryption key storage unit 251.
[0026] The encryption key generation unit 201 continuously generates encryption keys. When the amount of encryption keys stored in the encryption key storage unit 251 reaches an upper limit, such as when encrypted communication is not being performed, the encryption key generation unit 201 discards the encryption keys in chronological order and replaces them with newly generated encryption keys.
[0027] In response to a request from the cryptographic communication unit 51, the encryption key supplying unit 202 reads out an encryption key stored in the encryption key storage unit 251 and transmits it to the cryptographic communication unit 51. Here, it is assumed that a quantum key distribution device 21A is associated with the cryptographic communication server 50 for each cryptographic communication performed by the cryptographic communication unit 51. In other words, multiple quantum key distribution devices 21A can be associated with the cryptographic communication server 50. It is also assumed that the amount of encryption keys consumed by the cryptographic communication unit 51 per unit time exceeds the amount of encryption keys that the encryption key generation unit 201 can generate per unit time. Therefore, while the cryptographic communication of the cryptographic communication unit 51 continues, the amount of encryption keys stored in the encryption key storage unit 251 for that cryptographic communication decreases. The encryption key supplying unit 202 notifies the quantum key distribution service management server 10 of the amount of encryption keys consumed and the amount of encryption keys stored in the encryption key storage unit 251 at predetermined intervals, for example, every time a certain amount of encryption keys is supplied.
[0028] Based on instructions from the quantum key distribution service management server 10, the encryption key transfer control unit 203 performs encryption key transfer control, such as sharing the encryption keys stored in the encryption key storage unit 251 with other quantum key distribution devices 21A located in the same quantum key distribution center 21, for example.
[0029] Here, with reference to FIG. 3, the encryption key transfer control that can be performed by the encryption key transfer control unit 203 under the control of the quantum key distribution service management server 10 will be described.
[0030] For example, assume that quantum key user [1] 2 and quantum key user [2] 2 exist as users using the section connecting node [A] 31 and node [B] 31 of the quantum key distribution layer 30. Quantum key user [1] 2 performs encrypted communication between the encrypted communication server [1] 50 and the encrypted communication server [2] 50, with the encrypted communication server [1] 50 receiving an encryption key from node [A] 31 and the encrypted communication server [2] 50 receiving an encryption key from node [B] 31.
[0031] On the other hand, the quantum key user [2] 2 performs encrypted communication between the encrypted communication server [3] 50 and the encrypted communication server [4] 50, with the encrypted communication server [3] 50 receiving an encryption key from the node [A] 31 and the encrypted communication server [4] 50 receiving an encryption key from the node [B] 31.
[0032] In the quantum key distribution system 20, an encryption key is generated and shared between the quantum key distribution device [A1] 21 and the quantum key distribution device [B1], and an encryption key is generated and shared between the quantum key distribution device [A2] 21 and the quantum key distribution device [B2]. For ease of understanding, it is assumed that an encryption key generated by the quantum key distribution device [A1] 21 is supplied to the encrypted communication server [1] 50 via the node [A] 31, and that an encryption key generated by the quantum key distribution device [B1] 21 is supplied to the encrypted communication server [2] 50 via the node [B] 31. It is also assumed that an encryption key generated by the quantum key distribution device [A2] 21 is supplied to the encrypted communication server [3] 50 via the node [A] 31, and that an encryption key generated by the quantum key distribution device [B2] 21 is supplied to the encrypted communication server [4] 50 via the node [B] 31.
[0033] The quantum key distribution device [A1] 21 stores, in the encryption key storage unit 251, an encryption key a1 for encrypting data that the encrypted communication server [1] 50 transmits to the encrypted communication server [2] 50, and an encryption key a2 for decrypting (encrypted) data that the encrypted communication server [1] 50 receives from the encrypted communication server [2] 50.
[0034] The quantum key distribution device [B1] 21 also stores the encryption key a1 and the encryption key a2 in the encryption key storage unit 251. In the quantum key distribution device [B1] 21, the encryption key a1 is used by the encrypted communication server [2] 50 to decrypt (encrypted) data received from the encrypted communication server [1] 50, and the encryption key a2 is used by the encrypted communication server [2] 50 to encrypt data to be transmitted to the encrypted communication server [1] 50.
[0035] The quantum key distribution device [A2] 21 stores, in the encryption key storage unit 251, an encryption key a3 for encrypting data that the encrypted communication server [3] 50 transmits to the encrypted communication server [4] 50, and an encryption key a4 for decrypting (encrypted) data that the encrypted communication server [3] 50 receives from the encrypted communication server [4] 50.
[0036] The quantum key distribution device [B2] 21 also stores the encryption key a3 and the encryption key a4 in the encryption key storage unit 251. In the quantum key distribution device [B2] 21, the encryption key a3 is used by the encrypted communication server [4] 50 to decrypt (encrypted) data received from the encrypted communication server [3] 50, and the encryption key a4 is used by the encrypted communication server [4] 50 to encrypt data to be transmitted from the encrypted communication server [3] 50.
[0037] As described above, during the duration of a certain cryptographic communication, the demand (consumption) of encryption keys for that cryptographic communication exceeds the supply (generation) of encryption keys. Therefore, the amount of encryption keys stored for that cryptographic communication decreases. To avoid a shortage (depletion) of encryption keys, in the quantum key distribution service platform 1 of this embodiment, under the control of the quantum key distribution service management server 10, the encryption key transfer control unit 203 transfers encryption keys among the encryption keys a1 to a4. For example, when the amount of encryption keys stored for data transfer in a first direction of a certain cryptographic communication is about to be depleted, if there is still some encryption keys stored for data transfer in a second direction opposite to the first direction, encryption keys may be transferred between the two directions of the cryptographic communication (a11, a12). Furthermore, when the amount of encryption keys stored for one of two cryptographic communications in the same section is about to be depleted, if there is still some encryption keys stored for the other cryptographic communication (a13 to a16), encryption keys may be transferred between the two cryptographic communications. The transfer of encryption keys between two encrypted communications can be performed for encryption keys used for data transfer in the same direction (a13, a14), or for encryption keys used for data transfer in opposite directions (a15, a16). The transfer of encryption keys between two directions of a certain encrypted communication (a11, a12) and the transfer of encryption keys between two encrypted communications (a13 to a16) can be performed in combination.
[0038] Returning to FIG. 2, the quantum key distribution service management server 10 will be described.
[0039] The quantum key distribution service management server 10 has a user management unit 101, an encryption key supply and demand management unit 102, and an encryption key lending control unit 103. The quantum key distribution service management server 10 also has a user management DB (database) 151, an encryption key storage amount management DB 152, an encryption key consumption history management DB 153, and an encryption key consumption prediction management DB 154, which are provided on a storage medium such as a HDD.
[0040] The user management unit 101 accepts applications for use of the quantum key distribution service platform 1, for example, via the Internet, and manages information about the quantum key users 2 obtained at the time of the application using a user management DB 151. The user management unit 101 also accepts applications for changes in the mode of use of the quantum key distribution service platform 1 or applications for suspension of use. Fig. 4 is a diagram showing an example of the user management DB 151.
[0041] The user management DB 151 stores a user ID and one or more pieces of interval information. The user ID is information for identifying the quantum key user 2. The interval information is information indicating the interval used by the quantum key user 2. The interval information is expressed, for example, as a set of two nodes 31. For example, in the case of a quantum key user 2 that is supplied with encryption keys for three intervals, three pieces of interval information are stored.
[0042] The encryption key supply and demand management unit 102 updates the encryption key storage amount management DB 152 and the encryption key consumption record management DB 153 based on the encryption key consumption amount and the encryption key storage amount notified from the quantum key distribution device 21A.
[0043] 5 is a diagram showing an example of the encryption key storage capacity management DB 152. The encryption key storage capacity management DB 152 stores a user ID, a storage capacity of encryption keys in a first direction, and a storage capacity of encryption keys in a second direction (opposite to the first direction) for each section that is a pair of two nodes 31 in the quantum key distribution layer 30. The encryption key storage capacity management DB 152 also stores the storage capacity of spare encryption keys.
[0044] The user ID, like the user management DB 151, is information for identifying the quantum key user 2. The accumulated amount of first-direction encryption keys is the accumulated amount of first-direction encryption keys for the encrypted communication performed by the quantum key user 2 identified by the user ID. The accumulated amount of second-direction encryption keys is the accumulated amount of second-direction encryption keys for the encrypted communication. The accumulated amount of encryption keys decreases while encrypted communication is being performed, and increases or is maintained at an upper limit value while encrypted communication is not being performed.
[0045] 6 is a diagram showing an example of the encryption key consumption history management DB 153. The encryption key consumption history management DB 153 stores the consumption amount of encryption keys in the first direction and the consumption amount of encryption keys in the second direction for each section and user in units of a certain time period, such as 10 minutes or 1 hour. This information is accumulated in the encryption key consumption history management DB 153 for a preset period, such as 3 years.
[0046] Returning to FIG. 2, the description of the quantum key distribution service management server 10 will be continued.
[0047] The encryption key lending control unit 103 periodically predicts the amount of encryption key consumption for a certain period of time in the future for all cryptographic communications that may be performed using the quantum key distribution service platform 1, using information from the encryption key consumption record management DB 153, and stores the results in the encryption key consumption prediction management DB 154. If the prediction period overlaps between the previous prediction and the current prediction, the encryption key lending control unit 103 updates the amount of encryption key consumption for the overlapping period to the current prediction result. The encryption key lending control unit 103 performs this prediction using, for example, AI (artificial intelligence) 110.
[0048] The AI 110 has an encryption key consumption prediction model 111 for predicting future encryption key consumption from past encryption key consumption trends. The encryption key consumption prediction model 111 is a model constructed to predict, for example, encryption key consumption for the next day by inputting, for example, trends in encryption key consumption over the past hour, encryption key consumption in the same time slot over the past week, encryption key consumption on the same day and time slot over the past month, and encryption key consumption on the same date and time slot over the past three years. The method for constructing various models of the AI 110, including the encryption key consumption prediction model 111, is not limited to a specific method, and various known methods may be employed.
[0049] 7 is a diagram showing an example of the encryption key consumption prediction management DB 154. The encryption key consumption prediction management DB 154 stores the predicted consumption amount of the encryption key in the first direction and the predicted consumption amount of the encryption key in the second direction for each section and user in units of time periods with a certain width. The width of the time periods preferably matches the width of the time periods in the encryption key consumption record management DB 153 shown in FIG. 6.
[0050] Furthermore, the encryption key lending control unit 103 uses information from the encryption key storage amount management DB 152 and information from the encryption key consumption prediction management DB 154 to detect signs of a shortage of encryption keys for encrypted communications currently being performed using the quantum key distribution service platform 1. Information from the encryption key consumption record management DB 153 may also be used to detect signs of a shortage of encryption keys. The encryption key lending control unit 103 performs this detection using, for example, the AI 110.
[0051] The AI 110 has an encryption key shortage prediction model 112 for detecting signs of a shortage of encryption keys based on the current amount of accumulated encryption keys and the amount of encryption key consumption predicted by the encryption key consumption prediction model 111. The encryption key shortage prediction model 112 may further take into account past trends in encryption key consumption, for example, over the past hour. The encryption key shortage prediction model 112 is a model constructed to detect signs of a shortage of encryption keys that may occur, for example, due to a sudden consumption of encryption keys that far exceeds the amount of encryption key consumption predicted by the encryption key consumption prediction model 111. The encryption key shortage prediction model 112 detects signs of a shortage of encryption keys in ongoing encrypted communication and outputs the amount of encryption keys required to avoid a shortage of encryption keys in that encrypted communication.
[0052] Furthermore, when a sign of a shortage of encryption keys is detected and the encryption keys stored as spares are not enough to make up for the shortage, the encryption key lending control unit 103 uses information from the encryption key storage amount management DB 152 and information from the encryption key consumption prediction management DB 154 to determine from where to allocate the encryption keys necessary to avoid the shortage, output in response to the detection of the sign of a shortage of encryption keys. While Fig. 3 shows the encryption key replenishment route (a11 to a16) between two quantum key users 2, in reality, when many quantum key users perform encrypted communications in the same section, there are many candidates for encryption key replenishment sources. The encryption key lending control unit 103 performs this determination using, for example, the AI 110.
[0053] The AI 110 includes an encryption key replenishment route selection model 113 for selecting an encrypted communication that is expected to have a surplus of encryption keys and is suitable as a source of encryption key replenishment, based on the current amount of stored encryption keys and the predicted future amount of encryption key consumption. The encryption key replenishment route selection model 113 may also take into account past trends in encryption key consumption, such as the past hour. The encryption key replenishment route selection model 113 may select multiple encrypted communications. The encryption key replenishment route selection model 113 outputs the amount of encryption key replenishment from each of the one or more selected encrypted communications.
[0054] The encryption key lending control unit 103 notifies the encryption key lending amount to the encryption key transfer control unit 203 of the quantum key distribution device 21A related to the encrypted communication for which a sign of a shortage of encryption keys has been detected, and to the quantum key distribution device 21A related to the encrypted communication selected as the encryption key replenishment source. If the shortage of encryption keys can be resolved by transferring encryption keys between the two directions of the encrypted communication, only the quantum key distribution device 21A related to that encrypted communication is notified.
[0055] Based on instructions from the quantum key distribution service management server 10, the encryption key transfer control unit 203 of the quantum key distribution device 21A performs transfer of the encryption key stored in the encryption key storage unit 251, for example, between the encryption key transfer control unit 203 of another quantum key distribution device 21A.
[0056] In this way, the quantum key distribution service platform 1 of this embodiment uses AI to predict encryption key consumption, detect signs of a shortage of encryption keys, and select a replenishment route to avoid the shortage. This allows the quantum key distribution service platform 1 of this embodiment to manage encryption keys adaptively.
[0057] As described above, a certain amount of encryption keys generated by the encryption key generation unit 201 of the quantum key distribution device 21A may be allocated equally to each communication partner and communication direction, and the remainder may be allocated separately to each communication partner and communication direction based on the result of the encryption key consumption prediction by the encryption key lending control unit 103 of the quantum key distribution service management server 10. Therefore, for example, when the equally allocated amount of encryption keys is lent, the quantum key distribution service management server 10 may manage the amount and reflect it in the amount charged to the quantum key user 2. More specifically, a fee system may be established in which the amount charged increases or decreases depending on the amount of lent of the equally allocated amount of encryption keys.
[0058] 8 is a flowchart showing an example of the flow of predicting the consumption of encryption keys by the quantum key distribution service management server 10 of the quantum key distribution service platform 1 of this embodiment. The quantum key distribution service management server 10 periodically predicts the consumption of encryption keys, for example, for each time period in the encryption key consumption record management DB 153 shown in FIG. 6 or each time period in the encryption key consumption prediction management DB 154 shown in FIG. 7. As described above, the quantum key distribution layer 30 may include multiple communication networks. The quantum key distribution service management server 10 may predict the consumption of encryption keys for each communication network included in the quantum key distribution layer 30.
[0059] The quantum key distribution service management server 10 acquires the amount of encryption keys consumed from the encryption key consumption record management DB 153 (S101). The quantum key distribution service management server 10 calculates the predicted amount of encryption keys consumed from the acquired amount of encryption keys consumed (S102). The quantum key distribution service management server 10 stores the calculated predicted amount of encryption keys consumed in the encryption key consumption prediction management DB 154 (S103).
[0060] 9 is a flowchart showing an example of the flow of determining the allocation amount of encryption keys and detecting signs of a shortage of encryption keys by the quantum key distribution service management server 10 of the quantum key distribution service platform 1 of this embodiment. The quantum key distribution service management server 10 continuously determines the allocation amount of encryption keys and detects signs of a shortage of encryption keys. The determination of the allocation amount of encryption keys and the detection of signs of a shortage of encryption keys may also be performed for each communication network included in the quantum key distribution layer 30.
[0061] The quantum key distribution service management server 10 acquires the storage amount of encryption keys from the encryption key storage amount management DB 152 (S201). The quantum key distribution service management server 10 also acquires the predicted consumption amount of encryption keys from the encryption key consumption prediction management DB 154 (S202). The quantum key distribution service management server 10 determines the allocation amount of encryption keys generated by the quantum key distribution device 21A based on the acquired storage amount of encryption keys and the predicted consumption amount of encryption keys (S203). At this time, the quantum key distribution service management server 10 may also use information from the encryption key consumption record management DB 153. At this time, the quantum key distribution service management server 10 may also divide the amount of encryption keys generated by the quantum key distribution device 21A in half at a predetermined ratio, allocate one half equally, and dynamically determine the allocation amount of the other half.
[0062] Next, the quantum key distribution service management server 10 determines whether any ongoing encrypted communication shows signs of a shortage of encryption keys, for example, due to a sudden consumption of encryption keys that far exceeds the predicted consumption amount, based on the accumulated amount of encryption keys and the predicted consumption amount of encryption keys (S204). At this time, the quantum key distribution service management server 10 may also use information from the encryption key consumption history management DB 153. If a sign of a shortage of encryption keys is detected (S204: YES), the quantum key distribution service management server 10 executes an encryption key lending process (S206), an example of the detailed flow of which is shown in FIG. 10. If no sign of a shortage of encryption keys is detected (S204: NO), the quantum key distribution service management server 10 skips the process of S206.
[0063] FIG. 10 is a flowchart showing an example of the detailed flow of the encryption key lending process in S206 of FIG. 9, which is executed when a sign of a shortage of encryption keys is detected.
[0064] The quantum key distribution service management server 10 first replenishes the encryption keys stored as spares (S301). If the shortage of encryption keys is resolved by the spare replenishment (S301: YES), the quantum key distribution service management server 10 terminates the encryption key lending process for the encrypted communication.
[0065] If the shortage of encryption keys is not resolved (S302: NO), the quantum key distribution service management server 10 acquires the accumulated amount of encryption keys from the encryption key accumulation amount management DB 152 (S303). The quantum key distribution service management server 10 also acquires the consumption amount of encryption keys from the encryption key consumption record management DB 153 (S304). Furthermore, the quantum key distribution service management server 10 acquires the predicted consumption amount of encryption keys from the encryption key consumption prediction management DB 154 (S305).
[0066] The quantum key distribution service management server 10 first determines whether there are any surplus encryption keys stored in the encrypted communication in the opposite direction to the direction in which the sign of a shortage of encryption keys was detected for the encrypted communication in which the sign of a shortage was detected (S306). If there are any surplus encryption keys (S306: YES), the quantum key distribution service management server 10 first executes the exchange of encryption keys between the two directions of the encrypted communication (S307). The quantum key distribution service management server 10 determines whether the exchange of encryption keys between the two directions will resolve the shortage of encryption keys (S308). If the shortage will be resolved (S308: YES), the quantum key distribution service management server 10 terminates the exchange of encryption keys for the encrypted communication.
[0067] If there is no surplus encryption key stored in the encrypted communication in the opposite direction to the direction in which the sign of shortage was detected (S306: NO), or if the shortage of encryption keys cannot be resolved by the exchange of encryption keys between the two directions (S308: NO), the quantum key distribution service management server 10 detects the surplus encryption key stored in the encrypted communication of another quantum key user 2 performing encrypted communication in the same section (S309). The quantum key distribution service management server 10 executes the exchange of encryption keys between users, with the other quantum key user 2 for whom the surplus encryption key stored amount was detected as the exchange source (S310), and terminates the encryption key exchange process for the encrypted communication.
[0068] As described above, the quantum key distribution service platform 1 of this embodiment predicts the consumption of encryption keys, detects signs of a shortage of encryption keys, and selects a replenishment route to avoid the shortage. This allows the quantum key distribution service platform 1 of this embodiment to manage encryption keys adaptively.
[0069] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be embodied in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, and are also included in the scope of the invention and its equivalents as defined in the claims. [Explanation of symbols]
[0070] 1...Quantum key distribution service platform, 2...Quantum key user, 10...Quantum key distribution service management server, 20...Quantum key distribution system, 21...Quantum key distribution center, 21A...Quantum key distribution device, 30...Quantum key distribution layer, 31...Node, 50...Encrypted communication server, 51...Encrypted communication unit, 101...User management unit, 102...Encryption key supply and demand management unit, 103...Encryption key lending control unit, 110...AI, 111...Encryption key consumption prediction model, 112...Encryption key shortage prediction model, 113...Encryption key replenishment route selection model, 151...User management DB, 152...Encryption key accumulation management DB, 153...Encryption key consumption record management DB, 154...Encryption key consumption prediction management DB, 201...Encryption key generation unit, 202...Encryption key supply unit, 203...Encryption key transfer control unit, 251...Encryption key accumulation unit.
Claims
1. a plurality of quantum key distribution devices that transmit and receive encryption key information to and from other quantum key distribution devices and generate encryption keys to be shared with the other quantum key distribution devices based on the encryption key information; a management server that manages supply of the encryption key from the plurality of quantum key distribution devices to a plurality of encryption communication devices that perform encryption communication using the encryption key; Equipped with The management server monitoring the amount of the encryption keys stored for each of the plurality of encryption communication devices in the plurality of quantum key distribution devices; recording the consumption record of the encryption key of each of the plurality of encryption communication devices; predicting the amount of encryption key consumption of each of the plurality of encryption communication devices based on the actual consumption of the encryption keys; detecting a sign of a shortage of the encryption keys that may occur in the encrypted communication between the plurality of encryption communication devices based on the accumulated amount of the encryption keys and the predicted amount of consumption of the encryption keys; selecting, based on the accumulated amount of encryption keys and the predicted amount of consumption of the encryption keys, from among other encrypted communications in the same section as the encrypted communication in which the sign of a shortage of encryption keys has been detected, other encrypted communications that are expected to have a surplus of encryption keys and are suitable as a source of encryption keys to be used as a supplementary source of encryption keys; switching the encryption key of the selected other encrypted communication to the encryption key of the encrypted communication for which a sign of a shortage of encryption keys has been detected; Quantum key distribution service platform.
2. The quantum key distribution service platform according to claim 1 , wherein the management server further selects the other cryptographic communication based on a consumption record of the cryptographic key.
3. 3. The quantum key distribution service platform according to claim 1, wherein the management server further detects a sign of a shortage of the encryption keys based on a consumption record of the encryption keys.
4. 3. The quantum key distribution service platform according to claim 1, wherein the management server controls allocation of the encryption keys generated by the quantum key distribution devices to the plurality of cryptographic communication devices based on a predicted amount of the encryption keys stored and a predicted amount of the encryption keys consumed.
5. The quantum key distribution service platform according to claim 4 , wherein the management server further controls allocation of the encryption keys based on a consumption record of the encryption keys.
6. 3. The quantum key distribution service platform of claim 1, wherein the management server reserves some of the encryption keys generated by the plurality of quantum key distribution devices as spares, and when a sign of a shortage of encryption keys is detected for any of the plurality of encrypted communications being conducted between the plurality of encrypted communication devices, the management server assigns the encryption key reserved as a spare to the encrypted communication for which a sign of a shortage of encryption keys has been detected.
Citation Information
Patent Citations
Method and apparatus for managing encryption key in private communication network
JP2008306633A
Communication device, communication method, program and communication system
JP2014241464A
Communication device, communication system, and communication method
JP2018029283A
Quantum Key Distribution System, Method and Apparatus Based on Trusted Relay
JP2018502514A
Communication device, communication system, and communication method
JP6615718B2