Mobile object, encryption key distribution system, encryption key distribution method and program
The use of a mobile object like a drone for encryption key distribution addresses security and distance constraints by securely transmitting and erasing keys upon detection of abnormalities, ensuring robust encryption key distribution between distant installations.
Patent Information
- Application Number
- JP2024522854
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-05-26
- Publication Date
- 2025-11-26
- Estimated Expiration
- 2042-05-26
AI Technical Summary
Existing encryption key distribution methods face security risks during transmission and are constrained by distance and transmission path limitations, particularly when using airborne vehicles that do not secure the encryption key itself.
A method involving a mobile object, such as a drone, that stores and transmits encryption keys securely by detecting abnormalities and erasing the key if issues arise, using wireless communication with laser light and quantum cryptography, ensuring secure distribution without a direct transmission path.
Enables secure encryption key distribution without distance or path constraints, reducing eavesdropping risks and maintaining high security by erasing keys upon detection of abnormalities, particularly suitable for installations like land-based and sea-based devices.
Smart Images

Figure 0007776000000001 
Figure 0007776000000002 
Figure 0007776000000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a technology for distributing encryption keys by mobile devices. [Background technology]
[0002] On the Internet and other networks, there is a risk that information (data) may be intercepted during transmission from a sending device to a receiving device. To prevent this, various encryption technologies are available to conceal the data being transmitted. Many encryption technologies use a key known as an encryption key to encrypt and transmit data, and the receiving device then decrypts the data using the same encryption key. Another method involves decrypting the data using a decryption key that corresponds to the encryption key that the receiving device holds in advance. Hereinafter, keys used to encrypt and / or decrypt data, including decryption keys, will be collectively referred to as encryption keys. Such encryption keys must be shared between the sending and receiving devices before data transmission.
[0003] Generally, an encryption key is generated by one party and then distributed to the other party, so it is important to improve the security of encryption key distribution.
[0004] There are various methods for distributing encryption keys, such as quantum cryptography (quantum cryptography key distribution method) that uses quantum mechanics (see, for example, Patent Document 1).
[0005] Quantum key distribution is a system that uses quantum communication to securely distribute encryption keys. However, the transmission path (transmission medium) is limited to optical fiber and laser light, and there are also distance limitations.
[0006] One technique for distributing encryption keys without the constraints of distance or transmission path is to use a flying object for delivery (see, for example, Patent Document 2). In the technique disclosed in Patent Document 2, only a portion of the information required to generate an encryption key is temporarily stored in the flying object. In other words, the encryption key is shared among multiple base stations without all of the information required to generate the encryption key being stored in the flying object at the same time. [Prior art documents] [Patent documents]
[0007] [Patent Document 1] Japanese Patent Application Publication No. 2017-055335 [Patent Document 2] Japanese Patent Publication No. 2022-002379 Summary of the Invention [Problem to be solved by the invention]
[0008] The following analysis is provided by the present invention.
[0009] The invention described in Cited Document 2 does not transmit the encryption key itself, but rather multiple pieces of key information required to generate the encryption key, sequentially from the airborne vehicle to multiple base stations (sender and receiver). Because the encryption key itself is not transmitted from the airborne vehicle, security during transmission and security on the airborne vehicle are not taken into consideration. Note that the invention described in this cited document is based on the premise that there is a transmission path using optical fiber or the like between the transmitter and receiver. Key information is transmitted from either the transmitter or receiver to the other using that transmission path, and key distillation processing is performed on the receiver.
[0010] The present invention has been made in consideration of the above circumstances, and aims to provide a technology for securely distributing encryption keys without the need for a transmission path between the sending and receiving sides and without the constraints of distance or transmission path. [Means for solving the problem]
[0011] According to a first aspect of the present invention, there is provided a method for transmitting a cryptographic key to a receiving device, the method comprising: a storage control unit that controls storage of the encryption key in a storage unit; a movement control unit that moves the device to the receiving device after receiving the encryption key from the transmitting device, A mobile body is provided in which the storage control unit stores the encryption key in the storage unit when it receives it from the transmitting device, and erases the encryption key stored in the storage unit if an abnormality is detected.
[0012] According to a second aspect of the present invention, there is provided a vehicle comprising: the transmitting device; the receiving device, the transmitting device includes a transmitting device communication unit that transmits the encryption key to the mobile unit; The receiving device includes a receiving device communication unit that receives the encryption key from the mobile object.
[0013] According to a third aspect of the present invention, there is provided a method for transmitting a cryptographic key from a transmitting device, comprising: a storage step of storing the received encryption key in a storage unit; a moving step of moving the device toward the receiving device after storing the encryption key; an erasing step of erasing the encryption key stored in the storage unit when an abnormality in the device itself is detected during movement; Upon arrival at a destination area, the encryption key stored in the storage unit is transmitted to the receiving device.
[0014] According to a fourth aspect of the present invention, there is provided a computer mounted on a mobile body, comprising: a receiving step of receiving an encryption key from the transmitting device; a storage step of storing the received encryption key in a storage unit; a moving step of moving the device toward the receiving device after storing the encryption key; an erasing step of erasing the encryption key stored in the storage unit when an abnormality in the device itself is detected during movement; A program is provided for executing a transmission step of transmitting the encryption key stored in the storage unit to the receiving device upon arrival at the destination area.
[0015] These programs can be recorded on a computer-readable storage medium. The storage medium can be a non-transient medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. The present invention can also be embodied as a computer program product. [Effects of the Invention]
[0016] No transmission path is required between the sender and receiver, and encryption keys can be securely distributed without restrictions on distance or transmission media. [Brief explanation of the drawings]
[0017] [Figure 1] FIG. 1(a) is a schematic diagram showing an example of an encryption key distribution system according to one embodiment of the present invention, and FIG. 1(b) is a functional block diagram of the flying vehicle. [Figure 2] 1A and 1B are a functional block diagram and a hardware configuration diagram, respectively, of an example of a transmitting device according to a first embodiment. [Figure 3] 1A and 1B are a functional block diagram and a hardware configuration diagram, respectively, of an example of a receiving device according to a first embodiment. [Figure 4] 1A and 1B are a functional block diagram and a hardware configuration diagram, respectively, of an example of a flying object according to a first embodiment. [Figure 5] 1 is a flowchart illustrating an example of an encryption key distribution process in the encryption key distribution system according to the first embodiment. [Figure 6] 10 is a flowchart illustrating an example of encryption key distribution processing in the flying object of the first embodiment. [Figure 7] FIG. 10 is a schematic diagram illustrating an example of the configuration of an encryption key distribution system according to a second embodiment. [Figure 8] 10A and 10B are a functional block diagram and a hardware configuration diagram, respectively, of an example of a monitoring device according to a second embodiment. [Figure 9]10A is a functional block diagram of an example of a flying object according to a third embodiment, and FIG. 10B is an explanatory diagram for explaining an example of log information according to the third embodiment. [Figure 10] 13 is a flowchart illustrating an example of encryption key distribution processing in the flying object according to the third embodiment. [Figure 11] FIG. 10 is a schematic diagram illustrating an example of the configuration of an encryption key distribution system according to a fourth embodiment. [Figure 12] FIG. 13 is an explanatory diagram for explaining an encryption key table according to the fourth embodiment; [Figure 13] FIG. 10 is a schematic diagram showing an example of the configuration of an encryption key distribution system according to a modified example of the present invention. [Figure 14] 1A is a schematic diagram showing an example of the configuration of an encryption key distribution system according to a modified example of the present invention, and FIG. 1B is a flowchart showing an example of encryption key distribution processing in the flying object according to the modified example. [Figure 15] FIG. 10 is an explanatory diagram illustrating an example of an encryption key table according to a modified example of the present invention. [Figure 16] FIG. 10 is a schematic diagram showing an example of the configuration of an encryption key distribution system according to a modified example of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0018] Hereinafter, examples of embodiments of the present invention will be described with reference to the drawings. Note that the attached reference numerals are attached to each element for convenience as an example to facilitate understanding, and are not intended to limit the present invention to the illustrated form. Furthermore, connecting lines between blocks in the drawings and the like referred to in the following description include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of main signals (data) and do not exclude bidirectionality.
[0019] The program is executed via a computer device, which includes, for example, a processor, a storage device, an input device, a communication interface, and, if necessary, a display device. This computer device is configured to be able to communicate with internal or external devices (including computers) via the communication interface, either wired or wirelessly. Ports or interfaces are present at the input / output connection points of each block in the diagram, but are not shown. In the following description, "A and / or B" means either A or B, or both A and B.
[0020] A first embodiment, which is an example of an embodiment of the present invention, will be described. In this embodiment, an encryption key distribution system is realized using an airborne vehicle as a moving object, which is difficult to eavesdrop on. In this embodiment, an encryption key is carried on an airborne vehicle and transmitted from a device that is a sender (sender) of the encryption key to a device that is a destination (receiver) of the encryption key. At this time, security is ensured using sensor signals from various sensors inside and outside the airborne vehicle. Hereinafter, in this embodiment, the device that sends the encryption key will be called a transmitter, and the device that receives the encryption key will be called a receiver.
[0021] 1(a) shows an example of an encryption key distribution system 910 according to one embodiment of the present invention. As shown in this figure, the encryption key distribution system 910 includes a transmitting device 100, a receiving device 200, and an air vehicle 300.
[0022] In the example shown in the figure, the transmitting device 100 is installed at a base on land (ground). The receiving device 200 is installed at sea, for example, on a ship. The flying object 300 is, for example, a drone, which is an example of an autonomously navigable unmanned aerial vehicle (UAV). Note that the locations where the transmitting device 100 and the receiving device 200 are installed are not limited to this.
[0023] In the encryption key distribution system 910 of this embodiment, the transmitting device 100 sends the encryption key 500 to the airborne object 300, which then flies to the receiving device 200, and the receiving device 200 receives the encryption key 500 from the airborne object 300. If the airborne object 300 detects an abnormality at this time, it erases the encryption key 500 it holds. Not only if there is an abnormality in the equipment, but also if there is a risk that the encryption key 500 will be intercepted or that the encryption key 500 will not be delivered due to an unexpected event such as contact with another airborne object or a malfunction of the airborne object 300 itself, the airborne object 300 determines that an abnormality has occurred and erases the encryption key 500.
[0024] 1(b), the flying object 300 includes an input / output unit 311 that receives the encryption key 500 from the transmitting device 100 and transmits the encryption key 500 to the receiving device, a storage control unit 312 that stores the encryption key 500 in an encryption key storage unit 321 upon receiving the encryption key 500 from the transmitting device 100, and a movement control unit 315 that moves the flying object 300 from the transmitting device 100 to the receiving device 200. If an abnormality is detected during movement, the storage control unit 312 erases the encryption key 500 stored in the encryption key storage unit.
[0025] In this embodiment, it is not assumed that the flying object 300 will actually carry the file (information itself) to be transmitted or received. This is because real-time communication is not possible considering the flight speed of the flying object 300. Note that, since it is sufficient for the encryption key 500 to be shared before communication, the delivery of the encryption key 500 does not require real-time performance as compared to general communication.
[0026] <<First Embodiment>> A first embodiment of the present invention will be described below. In the first embodiment, in a cipher key distribution system 910, a flying object 300 is provided with an anomaly detection means for detecting anomalies that occur during movement. Each device will be described in detail below.
[0027] [Transmitting device] 2(a) is a functional block diagram of the configuration related to this embodiment of the transmitting device 100. As shown in this figure, the transmitting device 100 includes a communication unit 111, a control unit 112, an authentication unit 113, an encryption key storage unit 121, and an authentication information storage unit 122.
[0028] The encryption key storage unit 121 stores an encryption key 500. The encryption key 500 is generated within the transmission device 100 or received from an external device.
[0029] The authentication information storage unit 122 stores authentication information. The authentication information is information for proving that the flying object 300 is authorized to deliver the encryption key 500. The authentication information is set in advance for each flying object 300, and the transmitting device 100, the receiving device 200, and the flying object 300 have the same information. The authentication information is stored in advance.
[0030] The communication unit 111 transmits and receives data to and from external devices. In this embodiment, the communication unit 111 transmits and receives the encryption key 500 and authentication information to and from the flying object 300.
[0031] As described above, the encryption key 500 is transmitted from the transmitting device 100 to the flying object 300 using, for example, a laser beam. Quantum communication can be imparted to communication using a laser beam. Therefore, the communication unit 111 transmits the encryption key 500 to the flying object 300 using, for example, quantum communication or quantum cryptography communication.
[0032] The communication unit 111 may transmit and receive the authentication information by laser light, similarly to the encryption key 500. The authentication information may also be transmitted and received by short-range wireless communication such as Bluetooth (registered trademark) or Wi-Fi (registered trademark).
[0033] The authentication unit 113 authenticates the flying object 300. When the authentication unit 113 receives authentication information via the communication unit 111, it compares the received authentication information with the authentication information stored in the authentication information storage unit 122 in accordance with instructions from the control unit 112. After the comparison, the authentication unit 113 notifies the control unit 112 of the comparison result. If the received authentication information matches the stored authentication information, the authentication unit 113 determines the comparison result as authentication success, and if they do not match, the authentication fails.
[0034] The control unit 112 controls the overall operation of the transmitting device 100 and also controls the transmission and reception of the encryption key 500 via the communication unit 111. Specifically, upon receiving a notification of successful authentication from the authentication unit 113, the control unit 112 reads out the encryption key 500 from the encryption key storage unit 121 and transmits it to the flying object 300 via the communication unit 111.
[0035] 2(b) is a hardware configuration diagram of the configuration related to this embodiment of the transmitting device 100. As shown in this figure, the transmitting device 100 includes a CPU 131, a storage device 132, and a communication device 133.
[0036] The CPU 131 loads a program stored in a non-volatile area of the storage device 132 into a work area and executes the program, thereby realizing the above-mentioned functions and comprehensively controlling the entire transmitting device 100. Note that the CPU 131 may be replaced by one or more processors such as an MPU (Micro Processing Unit).
[0037] The storage device 132 is configured with memories such as a ROM (Read Only Memory) and a RAM (Random Access Memory). The storage device 132 stores programs for executing each function and information such as communication parameters for communication. In this embodiment, each of the above storage units is constructed in the storage device 132.
[0038] The storage device 132 may include, in addition to memories such as ROM and RAM, storage media such as a solid state drive (SSD), a flexible disk, a hard disk, an optical disk, a CD-ROM, a CD-R, a magnetic tape, a nonvolatile memory card, a DVD, etc. The storage device 132 may also include multiple memories.
[0039] The communication device 133 realizes transmission and reception of data. In this embodiment, the communication device 133 includes, for example, an optical wireless communication device having a laser output device (light source) that outputs laser light and a laser receiving device, etc. Note that the light source may be an LD (Laser Diode), an LED (Light Emitting Diode), or the like that outputs visible laser light.
[0040] In addition, data may be transmitted and received using not only visible light but also infrared light, radio waves, sound waves, etc. Specifically, a transmitter / receiver using a communication method conforming to other wireless communication methods such as Bluetooth, Wi-Fi, or NFC (Near Field Communication) may be provided.
[0041] [Receiver] 3(a) is a functional block diagram of a configuration related to this embodiment of the receiving device 200. As shown in this figure, the receiving device 200 includes a communication unit 211, a control unit 212, an authentication unit 213, an encryption key storage unit 221, and an authentication information storage unit 222.
[0042] The control unit 212 controls the overall operation of the receiving device 200 and also controls the transmission and reception of the encryption key 500 via the communication unit 211. Specifically, when the control unit 212 receives a notification of successful authentication from the authentication unit 213, it generates an encryption key transmission request and transmits it to the flying object 300 via the communication unit 211. Furthermore, when the control unit 212 receives the encryption key 500 in response to the encryption key transmission request, it stores it in the encryption key storage unit 221. At this time, it may transmit a signal indicating completion of storage to the flying object 300.
[0043] The other functions of the receiving device 200 are basically the same as the functions of the same name of the transmitting device 100, and therefore description thereof will be omitted here. When it is necessary to distinguish between the functions of the transmitting device 100 and the receiving device 200, they will be referred to as a transmitting device communication unit 111, a receiving device communication unit 211, a transmitting device control unit 112, a receiving device control unit 212, a transmitting device authentication unit 113, and a receiving device authentication unit 213, respectively.
[0044] 3(b) is a hardware configuration diagram of the receiving device 200 related to this embodiment. As shown in this diagram, the receiving device 200 includes a CPU 231, a storage device 232, and a communication device 233. Each component is basically the same as the component of the transmitting device 100 with the same name, and therefore a description thereof will be omitted.
[0045] [Flying object] Next, a description will be given of the flying object 300 that delivers the encryption key 500 from the transmitting device 100 to the receiving device 200. In this embodiment, as described above, a case where a drone is used as the flying object 300 will be described as an example.
[0046] 4(a) is a functional block diagram of the configuration related to this embodiment of the flying object 300. The flying object 300 of this embodiment includes an anomaly detection unit 313, an authentication request unit 314, and an authentication information storage unit 322 in addition to the input / output unit 311, the memory control unit 312, the movement control unit 315, and the encryption key storage unit 321 shown in FIG.
[0047] The encryption key storage unit 321 stores the encryption key 500. The encryption key 500 is received from the transmission device 100.
[0048] The authentication information storage unit 322 stores the authentication information of the flying object 300.
[0049] The input / output unit 311 inputs and outputs data to and from an external device, such as the encryption key 500 and authentication information.
[0050] As described above, the input / output unit 311 receives the encryption key 500 from the transmitting device 100 via wireless communication and transmits the encryption key 500 wirelessly to the receiving device 200. The input / output unit 311 also transmits authentication information to the transmitting device 100 and the receiving device 200. The input / output unit 311 may have a function that enables data transmission and reception only under predetermined conditions such as time or location.
[0051] As described above, the encryption key 500 may be transmitted and received between the flying object 300 and the transmitting device 100 or the receiving device 200 by quantum communication using laser light or quantum cryptography communication, for example.
[0052] The authentication information may be transmitted and received using laser light, similar to the encryption key 500. Alternatively, the authentication information may be transmitted and received using short-range wireless communication such as Bluetooth or Wi-Fi.
[0053] The authentication request unit 314 requests authentication from the external device. In this embodiment, the authentication request unit 314 requests authentication from the transmitting device 100 and the receiving device 200. The authentication request unit 314 transmits authentication information stored in the authentication information storage unit 322 to request authentication. Furthermore, when the authentication request unit 314 receives a notification from the movement control unit 315 (described later) that its own device (flying object 300) has entered an area where it can communicate with the external device for which authentication is requested (hereinafter referred to as a communication area), it makes an authentication request.
[0054] The abnormality detection unit 313 monitors the state of the flying object 300, and if an abnormality is detected, transmits an abnormality detection signal to the memory control unit 312.
[0055] The anomaly detection unit 313, for example, collects sensor detection values transmitted from a sensor 334 (described later). If the collected sensor detection values are abnormal (abnormal values), the anomaly detection unit 313 outputs an anomaly detection signal. Whether or not a value is abnormal is determined by whether or not it exceeds a predetermined allowable range for each sensor. The allowable range is predetermined, for example, by a threshold value.
[0056] The abnormality detection unit 313 may also analyze the collected sensor detection values and determine whether or not an abnormality exists. For example, the abnormality detection unit 313 may detect that the flying object 300 is no longer able to fly, has made an emergency landing or crashed, that the battery has run out, or that there is a program problem.
[0057] As described above, the storage control unit 312 controls the storage of the encryption key 500 in the encryption key storage unit 321. In this embodiment, for example, when the encryption key 500 is acquired via the input / output unit 311, it is stored in the encryption key storage unit 321. Furthermore, when an encryption key transmission request is received, the storage control unit 312 reads the encryption key 500 from the encryption key storage unit 321 and transmits the encryption key 500 to the requestor via the input / output unit 311. Furthermore, when an abnormality detection signal is received from the abnormality detection unit 313, the encryption key 500 stored in the encryption key storage unit 321 is erased.
[0058] As described above, the movement control unit 315 causes the flying object 300 to navigate to the destination. In this embodiment, the movement control unit 315 causes the flying object 300 to navigate from the transmitting device 100 to the receiving device 200. In this embodiment, upon receiving the encryption key 500 from the transmitting device 100, the movement control unit 315 controls a navigation device (described later) of the flying object 300 to move the flying object 300 to the receiving device 200.
[0059] The hardware configuration of the flying object 300 will be described. Fig. 4(b) is a hardware configuration diagram of the flying object related to this embodiment. As shown in this figure, the flying object 300 includes a CPU (Central Processing Unit) 331, a storage device 332, a communication device 333, a sensor 334, and a navigation device 335.
[0060] The CPU 331 loads a program stored in a nonvolatile area of the storage device 332 into a work area and executes the program, thereby realizing the above-mentioned functions and comprehensively controlling the entire flying object 300. Note that the CPU 331 may be replaced by one or more processors such as an MPU (Micro Processing Unit).
[0061] The storage device 332 is configured with memories such as a ROM (Read Only Memory) and a RAM (Random Access Memory). The storage device 332 stores programs for executing each function and information such as communication parameters for communication. In this embodiment, each of the above storage units is constructed in the storage device 332.
[0062] The storage device 332 may include, in addition to memories such as ROM and RAM, storage media such as a solid state drive (SSD), a flexible disk, a hard disk, an optical disk, a CD-ROM, a CD-R, a magnetic tape, a nonvolatile memory card, a DVD, etc. The storage device 332 may also include multiple memories.
[0063] The communication device 333 communicates with external devices. In this embodiment, for example, it communicates wirelessly with the transmitting device 100 and the receiving device 200. As described above, the encryption key 500 is transmitted and received using laser light. Therefore, the communication device 333 includes a laser input device and a laser receiving device. It may also include a short-range communication device that transmits and receives authentication information.
[0064] The sensors 334 are provided in various parts of the flying object 300 and detect their states. The sensors 334 are set and arranged so as to be able to detect (observe) all events that affect the flight of the flying object 300, such as vibration, contact, temperature change, voltage, position (latitude, longitude, and height), movement speed (flight speed), movement time, contact with and interference from other devices (other objects), etc. The sensors 334 may also be able to detect whether or not data is being sent or received with other devices. In this embodiment, the sensors 334 include, for example, a gyro sensor, an acceleration sensor, a barometric pressure sensor, an ultrasonic sensor, a geomagnetic sensor (electronic compass), a camera, a GPS device, a battery remaining capacity detection sensor, etc.
[0065] These detected values are output to the abnormality detection unit 313 and the movement control unit 315 and are used to detect abnormalities and control navigation using the navigation device 335.
[0066] The navigation device 335 navigates the flying object 300 under the control of the movement control unit 315. In this embodiment, for example, it is equipped with a propeller and a motor that rotates the propeller. The movement control unit 315 controls the navigation device 335 and navigates the flying object 300 in accordance with a navigation program pre-stored in the storage device 332 and the output from the sensor 334. The movement control unit 315 adjusts the output of the motor and controls the rotation speed of the propeller based on information obtained from the sensor 334, for example.
[0067] [Encryption key distribution method] The following describes an example of the flow of encryption key distribution processing by the encryption key distribution system 910 having the above configuration. Fig. 5 is a flow diagram showing an example of encryption key distribution processing by the encryption key distribution system 910 of this embodiment.
[0068] When the flying object 300 reaches the communication area of the transmitting device 100, the flying object 300 transmits authentication information to the transmitting device 100 (step S1301) and requests authentication.
[0069] When the transmitting device 100 receives authentication information as an authentication request from the flying object 300, it performs authentication (step S1101). Here, the authentication unit 113 compares the received authentication information with the authentication information stored in the authentication information storage unit 122. If the two match, the authentication unit 113 notifies the control unit 112 that the authentication was successful.
[0070] Upon receiving the notification of successful authentication, the control unit 112 reads out the encryption key 500 from the encryption key storage unit 121 and transmits it to the flying object 300 that made the authentication request via the communication unit 111 (step S1102).
[0071] If the authentication is unsuccessful, the transmitting device 100 does not transmit the encryption key 500 to the air vehicle 300 that requested the authentication. At this time, a message indicating the authentication failure may be transmitted to the air vehicle 300 that requested the authentication.
[0072] Upon receiving the encryption key 500, the flying object 300 stores it (step S1302) and starts moving (step S1303).
[0073] If the flying object 300 reaches the communication area of the receiving device 200 without detecting any abnormality (step S1304; No), the flying object 300 stops moving (step S1305). Then, the flying object 300 transmits authentication information to the receiving device 200 (step S1306) and requests authentication.
[0074] When the receiving device 200 receives authentication information as an authentication request from the flying object 300, it performs authentication (step S1201). Here, the authentication unit 213 compares the received authentication information with the authentication information stored in the authentication information storage unit 222. If the two match, the authentication unit 213 notifies the control unit 212 that the authentication was successful.
[0075] Upon receiving the notification of successful authentication, the control unit 212 generates an encryption key transmission request and transmits it to the flying object 300 that made the authentication request via the communication unit 111 (step S1202).
[0076] If the authentication is unsuccessful, the receiving device 200 does not send a request to transmit an encryption key to the flying object 300 that has requested the authentication. At this time, a message indicating the authentication failure may be sent to the flying object 300 that has requested the authentication.
[0077] When receiving the encryption key transmission request from the receiving device 200, the flying object 300 transmits the stored encryption key 500 to the requesting receiving device 200 (step S1307), and then erases the stored encryption key 500 (step S1308).
[0078] On the other hand, if an abnormality is detected during movement (step S1304; Yes), the flying object 300 erases the stored encryption key 500 (step S1308) and ends the process.
[0079] After receiving the encryption key 500 in step S1307, the receiving device 200 notifies the transmitting device 100 via radio waves or the like that the encryption key 500 has been received, and starts using the encryption key 500. The encryption algorithm used after receiving the encryption key 500 is not limited. The encryption key 500 to be transmitted and received may be converted using an algorithm stored in advance in the transmitting device 100 and the receiving device 200, rather than being used for encryption and decryption as is.
[0080] Next, an example of processing within the flying object 300 when distributing an encryption key will be described. Fig. 6 is a flowchart of encryption key distribution processing by the flying object 300 of this embodiment.
[0081] The movement control unit 315 determines whether the transmitting device 100 has arrived within the communication area of the transmitting device 100 (step S1401). Any method of determination may be used, and various existing determination methods may be used. For example, a laser beam for distance measurement is transmitted to the communication unit 111, and if the obtained distance value is equal to or less than a predetermined value, it is determined that the transmitting device 100 has arrived. The determination may also be made using a photographed image acquired by a camera. Furthermore, if the position of the transmitting device 100 is known, the determination may also be made using, for example, a GPS function.
[0082] When the communication area is reached, the authentication request unit 314 makes an authentication request. Here, as described above, the authentication request unit 314 transmits the authentication information stored in the authentication information storage unit 322 to the transmitting device 100 (step S1402).
[0083] In response to the authentication request, when the encryption key 500 is received from the transmission device 100 within a predetermined period of time (step S1403), the storage control unit 312 stores the encryption key 500 in the encryption key storage unit 321 (step S1404).
[0084] If the encryption key 500 is not received within a predetermined period, for example, if an authentication failure message is received, or if no reply is received, the flying object 300 ends the process.
[0085] Next, after storing the encryption key 500, the movement control unit 315 starts movement (step S1405). Here, the movement control unit 315 controls the navigation device 335 to move the flying object 300 to a communication area of the receiving device 200 (step S1407).
[0086] If the abnormality detection unit 313 detects an abnormality during movement (step S1406), it outputs an abnormality detection signal to the memory control unit 312. Upon receiving the abnormality detection signal, the memory control unit 312 erases the encryption key 500 stored in the encryption key memory unit 321 (step S1412) and ends the process.
[0087] On the other hand, if the flying object 300 reaches the communication area without detecting any abnormality (step S1407), the movement control unit 315 ends the movement of the flying object 300 (step S1408). Note that the method for determining whether the receiving device 200 has reached the communication area is the same as the determination method for the transmitting device 100.
[0088] Then, the authentication request unit 314 makes an authentication request to the receiving device 200. Here, the authentication request unit 314 transmits the authentication information stored in the authentication information storage unit 322 to the receiving device 200 (step S1409).
[0089] When an encryption key transmission request is received from the receiving device 200 within a predetermined period in response to the authentication request (step S1410), the storage control unit 312 reads out the encryption key 500 from the encryption key storage unit 321 and transmits it to the receiving device 200 via the input / output unit 311 (step S1411). Thereafter, the storage control unit 312 erases the encryption key 500 from the encryption key storage unit 321 (step S1412) and ends the process.
[0090] If the encryption key transmission request is not received within a predetermined period, for example, if an authentication failure message is received, or if no reply is received, the process proceeds to step S1412.
[0091] As described above, in the encryption key distribution system 910 of this embodiment, the flying object 300 is used to distribute the encryption key 500 between the transmitting device 100 and the receiving device 200. The flying object 300 has an abnormality detection function, and if an abnormality is detected in the flying object 300, the encryption key 500 to be distributed is erased.
[0092] The flying object 300 is an unmanned, autonomously navigable object, such as a drone. As long as the flying object 300 flies at a sufficient altitude, it is unlikely to be physically contacted. In this way, by using the flying object 300 to distribute the encryption key 500, the encryption key distribution system 910 of this embodiment can achieve highly secure key distribution with little risk of eavesdropping, without restrictions on distance or transmission path, even between two points without a transmission path.
[0093] For example, as shown in Figure 1(a), if the transmitting device 100 is installed at a land-based base and the receiving device 200 is installed on a ship sailing at sea, it is difficult to connect the two with a physical cable because the ship is moving. In such a situation where a transmission path cannot be secured, the encryption key distribution system 910 of this embodiment is particularly useful.
[0094] Furthermore, the encryption key distribution system 910 of this embodiment uses wireless communication to transmit and receive the encryption key 500 between the transmitting device 100, the receiving device 200, and the flying object 300. That is, since the encryption key 500 can be transmitted and received without connecting a connector, there is no need to add new hardware to the flying object 300, thereby reducing costs.
[0095] Furthermore, the encryption key distribution system 910 of this embodiment uses laser light for this wireless communication. Laser light has little diffusion, and is focused onto an extremely small area when transmitting and receiving the encryption key 500 between the transmitting device 100, receiving device 200, and flying object 300. This allows the transmission and reception interface areas of the flying object 300, transmitting device 100, and receiving device 200 to be made smaller. Therefore, in the encryption key distribution system 910 of this embodiment, attacks on the transmission and reception interfaces are extremely difficult, and even more secure encryption key distribution can be achieved.
[0096] For example, consider a case where the flying object 300 is eavesdropped on during flight. It is extremely difficult to access the small laser light interface of the flying object 300 and obtain information. Therefore, it is conceivable that an attacker would capture the flying object 300 in order to obtain the encryption key 500.
[0097] However, in the encryption key distribution system 910 of this embodiment, if the flying object 300 comes into contact with an obstacle while flying, the anomaly detection unit 313 detects a change in vibration, radio waves, temperature, etc. and outputs an anomaly detection signal. Then, the memory control unit 312 immediately erases the encryption key 500 stored in the encryption key memory unit 321. Therefore, according to the encryption key distribution system 910 of this embodiment, even if an attacker captures the flying object 300, the encryption key 500 has been erased from the flying object 300, and therefore the attacker cannot obtain the encryption key 500. From this perspective, the encryption key distribution system 910 of this embodiment can also achieve highly secure encryption key distribution.
[0098] Furthermore, by using laser light, the transmission path can be visually confirmed despite the communication being wireless, making it easy to set the area range and allowing for accurate positioning during transmission and reception. This makes it difficult to intercept or eavesdrop, and allows for encryption key distribution with a high probability of success. Furthermore, by using laser light, quantum cryptography can be used for transmission and reception of the encryption key 500 between the transmitting device 100, the receiving device 200, and the flying object 300. This allows for encryption key distribution with the same level of security as when the encryption key 500 is directly distributed between the transmitting device 100 and the receiving device 200 using quantum cryptography.
[0099] In this embodiment, in communication between the flying object 300 and the transmitting device 100 and / or the receiving device 200, laser light may be output from the transmitting device 100 and / or the receiving device 200, or laser light may be output from the flying object 300 to these devices. Different transmission and reception mechanisms may be used between the transmitting device 100 and the flying object 300, and between the receiving device 200 and the flying object 300.
[0100] In this embodiment, the flying object 300 determines whether it has entered the communication area. However, this determination may be made by the transmitting device 100 and the receiving device 200.
[0101] In this case, the transmitting device 100 and the receiving device 200 are provided with sensors or the like for detecting the flying object 300, and these sensors detect that the flying object 300 has entered a communication area. Then, the transmitting device 100 or the receiving device 200 transmits a request to transmit authentication information to the flying object 300.
[0102] In addition, in this embodiment, the flying object 300 immediately deletes the encryption key 500 held therein after transmitting the encryption key 500 to the receiving device 200, but this is not limiting. For example, the flying object 300 may be configured to delete the encryption key 500 after confirming that the receiving device 200 has received it.
[0103] In this case, upon receiving the encryption key 500, the receiving device 200 transmits a receipt notification to the flying object 300. The flying object 300 waits for the receipt notification to be received and then erases the encryption key 500. Note that the flying object 300 may be configured to transmit the encryption key 500 to the receiving device 200 multiple times until the receipt notification is received.
[0104] In addition, when the encryption key 500 is erased in the flying object 300, the flying object 300 may notify the transmitting device 100 and / or the receiving device 200 of this fact. Also, if the authentication is unsuccessful in the above step S1201, a message indicating the authentication failure may also be sent in plain text from the receiving device 200 to the transmitting device 100.
[0105] <<Second embodiment>> Next, a second embodiment of the present invention will be described. In the encryption key distribution system 910 of the first embodiment, an abnormality during distribution is detected by a sensor 334 mounted on the flying object 300. In this embodiment, the flying object 300 is further monitored by an external device, and an abnormality in the flying object 300 is detected.
[0106] Fig. 7 shows an example of an encryption key distribution system 920 of this embodiment. As shown in this figure, the encryption key distribution system 920 of this embodiment basically has the same configuration as the first embodiment. That is, it includes a transmitting device 100, a receiving device 200, and an air vehicle 300. The encryption key distribution system 920 of this embodiment further includes a monitoring device 400. The following description of this embodiment will focus on the monitoring device 400, which has a different configuration from the first embodiment.
[0107] The monitoring device 400 monitors the flying object 300 and its surroundings from the outside. The monitoring device 400 is configured with, for example, a camera and / or a radio wave receiving and transmitting device.
[0108] For example, if the monitoring device 400 is a camera, it is installed so that the flying object 300 is within its field of view. If the monitoring device 400 is a radio wave receiving and transmitting device, it is installed so that the flying object 300 is within the direction of radio wave transmission.
[0109] FIG. 8(a) shows the functional blocks of the monitoring device 400, and FIG. 8(b) shows the hardware configuration of the monitoring device 400.
[0110] As shown in these figures, the monitoring device 400 includes a communication unit 411, an information acquisition unit 412, and an abnormality detection unit 413. The monitoring device 400 also includes a CPU 431, a storage device 432, a communication device 433, and an information collection device 434.
[0111] The information collection device 434 collects information about the flying object 300 and its vicinity. If the information collection device 434 is a camera, it is an imaging unit, and if it is a radio wave receiving and transmitting device, it is a radio wave receiving and transmitting unit.
[0112] The information acquisition unit 412 controls the operation of the information collection device 434 and transfers the information collected by them at predetermined time intervals to the abnormality detection unit 413. In this embodiment, image or reflected wave information is collected.
[0113] The abnormality detection unit 413 analyzes the image or reflected wave acquired by the information acquisition unit 412 and determines whether or not there is an abnormality in the flying object 300. If it determines that there is an abnormality, that is, if it detects an abnormality, it transmits an abnormality detection signal to the flying object 300 via the communication unit 411.
[0114] The communication unit 411, CPU 431, storage device 432, and communication device 433 are similar to the components of the same names in the transmission device 100 in the first embodiment, for example, and therefore will not be described.
[0115] The encryption key delivery process flow of this embodiment is also basically the same as that of the first embodiment. However, in this embodiment, in step S1406, the storage control unit 312 erases the encryption key 500 stored in the encryption key storage unit 321 not only when an abnormality detection signal is received from the abnormality detection unit 313 but also when an abnormality detection signal is received via the input / output unit 311.
[0116] The monitoring device 400 may be installed on the ground or may be a floating object such as a satellite. For example, it may be a flying object that flies alongside the flying object 300. The monitoring device 400 may also be included in the transmitting device 100 or the receiving device 200.
[0117] As described above, this embodiment has the same configuration as the first embodiment, and therefore provides the same effects as the first embodiment. Furthermore, the encryption key distribution system 920 of this embodiment includes a monitoring device 400 that monitors the flying object 300 and its surrounding conditions from the outside. If the monitoring device 400 determines that there is an abnormality in the flying object 300, the flying object 300 also erases the encryption key 500 being distributed. Therefore, abnormalities in the flying object 300 can be detected with higher accuracy, and even more secure distribution of the encryption key 500 can be achieved.
[0118] In this embodiment, the flying object 300 does not necessarily have to include the abnormality detection unit 313.
[0119] Furthermore, in this embodiment, when the monitoring device 400 detects an abnormality, it transmits an abnormality detection signal directly to the flying object 300. However, this is not limited to this. For example, it may be configured to transmit to the transmitting device 100 and / or the receiving device 200. In this case, the abnormality detection signal is transmitted from these devices to the flying object 300.
[0120] <<Third Embodiment>> Next, a third embodiment of this embodiment will be described. In each of the above embodiments, the flying object 300 is monitored in real time while moving, and an abnormality in the flying object 300 is detected. In this embodiment, sensor detection values during movement are accumulated as log information. Then, for example, after the flying object reaches the vicinity of the receiving device 200, this log information is further analyzed to detect whether or not an abnormality exists.
[0121] The configuration of the encryption key distribution system, the configuration of the transmitting device 100, the configuration of the receiving device 200, and the hardware configuration of the flying object 300 of this embodiment are basically the same as those of the first embodiment, so a description thereof will be omitted here.
[0122] An example of a functional block of the flying object 300 of this embodiment is shown in Figure 9(a). As shown in this figure, the flying object 300 of this embodiment includes a log information storage unit 323 in addition to the configuration of the flying object 300 of the first embodiment. The log information storage unit 323 is constructed in a storage device 332.
[0123] In addition to the processing of the first embodiment, the abnormality detection unit 313 of this embodiment stores the collected sensor detection values in the log information storage unit 323 as log information in association with the detection time (or collection time).
[0124] Furthermore, the abnormality detection unit 313 collects and stores not only the sensor detection value of the sensor 334 that detects the state of the flying object 300 but also the access history to the storage device 332 as log information.
[0125] Furthermore, the anomaly detection unit 313 of this embodiment performs a log information verification process after the receiving device 200 has reached the communication range and before making an authentication request. The log information verification process is a process of analyzing log information and verifying whether there are any anomalies. If an invalid log is detected in the log information verification process, the anomaly detection unit 313 determines that there is an anomaly and outputs an anomaly detection signal. As in the first embodiment, when the storage control unit 312 receives the anomaly detection signal, it erases the encryption key 500 from the encryption key storage unit 321.
[0126] For example, if log information 600 as shown in FIG. 9(b) is recorded as an access log to the encryption key storage unit 321, the abnormality detection unit 313 determines that an abnormality has occurred and outputs an abnormality detection signal.
[0127] When the flying object 300 receives the encryption key 500 from the transmitting device 100, it stores it in the encryption key storage unit 321, and there should be no access to it until it is handed over to the receiving device 200. However, the log information 600 records two readouts. Therefore, the abnormality detection unit 313 determines that there has been unauthorized access, i.e., that there is an abnormality.
[0128] An example of the process of delivering an encryption key by the flying object 300 of this embodiment is shown in Fig. 10. The process is the same as in the first embodiment up to the time of arrival at the receiving device 200 (step S1408).
[0129] In this embodiment, the anomaly detection unit 313 then performs a log information verification process (step S3101). If the log information verification process determines that an anomaly has occurred (step S3102; Yes), the anomaly detection unit 313 outputs an anomaly detection signal. In response to this, the storage control unit 312 erases the encryption key 500 from the encryption key storage unit 321 (step S1412).
[0130] On the other hand, if no abnormality is found in the log information verification process (step S3102; No), the process proceeds to step S1409 and continues the same process as in the first embodiment. Note that the log information verification process can be executed at any time between the end of the movement and the transmission of the encryption key.
[0131] As described above, this embodiment has the same configuration as the first embodiment and provides the same effects as the first embodiment. Furthermore, this embodiment also verifies the presence or absence of anomalies using the accumulated information. This allows for more secure delivery of the encryption key 500.
[0132] For example, even if an attacker attempts to eavesdrop by disabling the anomaly detection function, such as by accessing the laser light interface without touching the flying object 300, the eavesdropping can be confirmed by checking the transmission and reception log of the encryption key 500.
[0133] In this embodiment, the flying object 300 accumulates log information and performs the log information verification process, but this is not limited to this. While the flying object 300 is moving, the log information of the flying object 300 may be transmitted to the transmitting device 100 or the receiving device 200, and these devices may accumulate the log information and perform the log information verification process. In this case, if an abnormality is detected, these devices may transmit an abnormality detection signal to the flying object 300.
[0134] Furthermore, this embodiment may include a monitoring device 400, as in the second embodiment. In this case, the monitoring device 400 may also store collected information as log information and perform log information verification processing. The log information stored by the monitoring device 400 may also be transmitted to the transmitting device 100 or the receiving device 200, and these devices may perform log information verification processing. In this case as well, if an abnormality is detected, these devices transmit an abnormality detection signal to the flying object 300.
[0135] Furthermore, the receiving device 200 may combine the monitoring results of the monitoring device 400 with log information to more precisely determine whether or not there is an abnormality. For example, tracking investigations are performed using satellite cameras, radio waves, etc., until the flying object 300 passes data to the receiving device 200. As a method of detecting an abnormality at this time, if an unexpected object approaches and contacts the flying object 300, the receiving device 200 is notified. If an abnormality is confirmed after comparing the information with the log information (flight log and contact log) of the flying object 300, the receiving device 200 may determine that the flying object 300 is being used fraudulently. Furthermore, if an unexpected object contacts the flying object 300, it may be assumed that eavesdropping has occurred, and an abnormality detection signal may be transmitted to the flying object 300, causing the encryption key 500 in the flying object 300 to be erased.
[0136] Furthermore, the receiving device 200 may determine whether an unexpected event has occurred by inquiring of the transmitting device 100 and / or the monitoring device 400 about the flight log, sensor detection value log, transmission and reception log, etc. of the flying object 300. If an unexpected event has occurred, the receiving device 200 may erase the encryption key 500 in the flying object 300 as there is a risk of eavesdropping.
[0137] Furthermore, the reception device 200 may determine whether the flight time is appropriate. In this case, the reception device 200 may erase the encryption key 500 in the flying object 300 if the flying object 300 does not arrive within a predetermined time.
[0138] In this case, for example, when the transmitting device 100 transmits the encryption key 500 to the flying object 300, it simultaneously transmits a message to the receiving device 200 indicating that the encryption key 500 has been transmitted. If the flying object 300 does not arrive within a predetermined time from the reception of the message, the receiving device 200 generates an abnormality detection signal. At this time, the receiving device 200 may search for the flying object 300 and transmit the abnormality detection signal at the timing when the abnormality detection signal is generated. Furthermore, when authentication information is transmitted from the flying object 300, the abnormality detection signal may be returned without performing authentication.
[0139] Upon receiving the abnormality detection signal, the storage control unit 312 of the flying object 300 erases the encryption key 500 without transmitting it to the receiving device 200.
[0140] The flight time may also be determined by the flying object 300. That is, when a predetermined time has elapsed since the encryption key 500 was received, the storage control unit 312 erases the encryption key 500 from the encryption key storage unit 321.
[0141] The period until deletion can be specified at the time of individual delivery. For example, the transmission device 100 may be configured to receive a specification of the period until deletion from the transmission device 100 at the same time as receiving the encryption key 500. The storage control unit 312 deletes the encryption key 500 when this period has elapsed.
[0142] <<Fourth Embodiment>> Next, a fourth embodiment of the present invention will be described. In each of the above embodiments, one flying object 300 is caused to fly from the transmitting device 100 to the receiving device 200. In contrast, in this embodiment, multiple flying objects 300 are caused to fly from the transmitting device 100 to the receiving device 200, and multiple encryption keys 500 are delivered.
[0143] An example of an encryption key distribution system 940 of this embodiment is shown in Fig. 11. As shown in this figure, the encryption key distribution system 940, like the first embodiment, includes a transmitting device 100 and a receiving device 200. Furthermore, in this embodiment, it includes a plurality of flying objects 300.
[0144] The configurations of the transmitting device 100, the receiving device 200, and the flying object 300 are basically the same as those of the first embodiment. Hereinafter, this embodiment will be described, focusing on the configurations that are different from those of the first embodiment.
[0145] Each flying object 300 has its own unique authentication information. The transmitting device 100 of this embodiment stores an encryption key 500 associated with the authentication information in the encryption key storage unit 121 as an encryption key table 140. In this embodiment, the authentication information storage unit 122 may not be provided.
[0146] The encryption key table 140 registers the encryption key 500 to be distributed in association with the authentication information of each flying object 300. An example of the encryption key table 140 of this embodiment is shown in FIG.
[0147] As shown in this figure, each record in the encryption key table 140 includes an authentication information storage section 141 and an encryption key storage section 142. The authentication information storage section 141 stores authentication information for each flying object 300 that is permitted to deliver an encryption key 500. The encryption key storage section 142 stores the encryption key 500 to be delivered by the flying object 300 identified by the corresponding authentication information.
[0148] Similarly, the receiving device 200 may also have an encryption key table consisting of records having the same items. The authentication information storage unit stores in advance the authentication information of all flying objects 300 that are permitted to deliver the encryption key 500.
[0149] In the authentication process of step S1101 in Figure 5, the authentication unit 113 compares the authentication information with all authentication information stored in the authentication information storage unit 141, and if there is any matching authentication information, it transmits the encryption key 500 registered in correspondence with that authentication information to the flying object 300.
[0150] If there is no matching authentication information stored in the authentication information storage unit 141, the authentication unit 113 determines that the authentication has failed.
[0151] 5, the receiving device 200 compares the received authentication information with all authentication information stored in the authentication information storage unit. If there is matching authentication information, the receiving device 200 transmits an encryption key transmission request to the flying object 300. The receiving device 200 then stores the encryption key 500 transmitted from the flying object 300 in the encryption key storage unit associated with the matching authentication information.
[0152] As a result, according to this embodiment, it is possible to increase the supply of encryption keys 500 within the same time period.
[0153] The same encryption key 500 may also be loaded and delivered to multiple flying objects 300. In this case, the reliability of delivery of the encryption key 500 is increased.
[0154] Furthermore, in this embodiment, the encryption key 500 to be transmitted may include a dummy. A part of the encryption key 500 to be transmitted may be a dummy, or the entire encryption key 500 delivered by a specific flying object 300 may be a dummy. The dummy key (bit) is not used as an encryption key. In this case, the encryption key 500 to be transmitted and received may also be converted using an algorithm stored in advance in the transmitting device 100 and the receiving device 200. Furthermore, whether or not the key is a dummy may be determined using an algorithm stored in advance in the transmitting device 100 and the receiving device 200. These techniques can reduce the risk of eavesdropping, capture, etc.
[0155] This embodiment may be combined with the second embodiment.
[0156] <Variation 1> In the above-described embodiments and modifications, when the encryption key 500 is transmitted and received between the transmitting device 100, the receiving device 200, and the flying object 300, the flying object 300 is in a gliding state, and the encryption key 500 is transmitted and received via wireless communication. However, this is not limiting. For example, this communication may be wired communication, as shown in Fig. 13. Fig. 13 illustrates an encryption key distribution system 910 similar to that of the first embodiment.
[0157] In this case, the flying object 300 lands near the transmitting device 100 or the receiving device 200 when transmitting or receiving the encryption key 500. Then, as shown in the figure, the two are connected by a physical cable to transmit and receive the encryption key 500.
[0158] In this case, the communication device 133 of the transmitting device 100, the communication device 233 of the receiving device 200, and the communication device 333 of the flying object 300 are provided with connectors for wired communication. Furthermore, instead of the communication devices 133, 233, and 333, each device may be provided with an interface for inputting and outputting data via a medium, and the encryption key 500 may be transmitted and received via the medium.
[0159] As described above, when the transmitting device 100, the receiving device 200, and the flying object 300 are equipped with multiple data communication and input / output interfaces, the exchange of the encryption key 500 between the transmitting device 100 and the flying object 300, and the exchange of the encryption key 500 between the receiving device 200 and the flying object 300 may each use a different communication method.
[0160] In this case, the transmission and reception of information related to authentication between the flying object 300 and the transmitting device 100 and the receiving device 200 may also be performed using a wired cable. Note that in each embodiment and each modified example, the transmission and reception of information related to authentication may be performed using a wired cable only.
[0161] <Variation 2> In the above-described embodiments and modifications, an example has been described in which an encryption key 500 is delivered from one transmitting device 100 to one receiving device 200. However, the present invention is not limited to this. For example, as shown in FIG. 14(a), the same encryption key 500 may be delivered to multiple receiving devices 200 in sequence using the same flying object 300.
[0162] In this modification, the movement control unit 315 of the flying object 300 flies in a predetermined order toward each receiving device 200. The flight route may be pre-programmed.
[0163] In this modification, when receiving the encryption key 500, the storage control unit 312 receives the number of receiving devices 200 at the delivery destination from the transmitting device 100.
[0164] 14(b) shows the flow of processing when delivering an encryption key by the flying object 300 in this case. Note that here, the number of receiving devices 200 at the delivery destination is assumed to be N (N is an integer equal to or greater than 2), where n is a counter.
[0165] The flying object 300 sets the counter n to an initial value of 1 (step S4501). Then, the flying object 300 executes the processes of steps S1401 to S1411 in FIG. 6, and executes the process of delivering the encryption key 500 to the receiving device 200 that is scheduled to be delivered nth (step S4502).
[0166] Thereafter, it is determined whether or not encryption key 500 has been deleted (step S4503). For example, if an abnormality is detected during the delivery process in step S4502, encryption key 500 has already been deleted. In this case, further delivery is not possible, and the process is terminated.
[0167] On the other hand, if the encryption key 500 has not been erased, the counter is incremented by 1 and the delivery process is repeated up to the last (Nth) receiving device 200 (steps S4504, S4505).
[0168] Then, when the delivery process is completed up to the last receiving device 200, the storage control unit 312 erases the encryption key 500 stored in the encryption key storage unit 321 (step S4506), and the process ends.
[0169] There may also be multiple transmitting devices 100. In this case, the flying object 300 travels around the multiple transmitting devices 100 in a predetermined order, and receives different encryption keys 500 from each transmitting device 100. Then, the flying object 300 delivers these encryption keys to one receiving device 200.
[0170] Furthermore, there may be a plurality of transmitting devices 100 and a plurality of receiving devices 200. A plurality of encryption keys 500 may be received from a single transmitting device 100, and a plurality of encryption keys 500 may be transmitted to a single receiving device 200.
[0171] In this case, the flying object 300 receives, along with the encryption key 500, for example, information (receiving device ID) that identifies the receiving device 200 to which the encryption key 500 is to be sent. The receiving device ID is then stored in the encryption key storage unit 321 as the second encryption key table 150. The receiving device 200 also holds the receiving device ID in advance.
[0172] An example of the second encryption key table 150 is shown in Fig. 15. The second encryption key table 150 includes an encryption key storage unit 151 and a receiving device ID storage unit 152. The encryption key storage unit 151 stores an encryption key 500. The receiving device ID storage unit 152 stores a receiving device ID. When one encryption key 500 is distributed to multiple receiving devices 200, records having the same encryption key 500 are registered as many times as the number of distribution destinations.
[0173] Every time the flying object 300 arrives at the receiving device 200, it receives a request to transmit an encryption key from the receiving device 200 along with a receiving device ID during authentication, and transmits all encryption keys 500 stored in association with the received receiving device ID to the receiving device 200. Then, it erases the delivered records from the second encryption key table 150.
[0174] For example, in the example of FIG. 15, when the flying object 300 arrives at a receiving device 200 whose receiving device ID is RCV001, it transmits encryption keys AAA and BBB to the receiving device 200. It then erases these records. When it arrives at a receiving device 200 whose receiving device ID is RCV002, it transmits encryption keys AAA and CCC and erases these records. When it arrives at a receiving device 200 whose receiving device ID is RCV003, it transmits encryption key CCC and erases the record. When it arrives at a receiving device 200 whose receiving device ID is RCV0004, it transmits encryption key AAA and erases the record.
[0175] <Variation 3> In the above embodiments, the flying object 300 has been described as an example of a flying object such as a drone that navigates according to a pre-stored program, but the flying object 300 is not limited to this. Any flying object capable of unmanned movement between two points (from the transmitting device 100 to the receiving device 200) may be used. For example, the flying object may be a remotely controlled flying object. Furthermore, the flying object may be, like a bullet or artillery shell, a flying object that is not self-propelled but moves only by initial thrust and whose arrival position can be controlled. Furthermore, the flying object may be a manned flying device such as an airplane, helicopter, or glider. In this case, it is desirable that the storage unit storing the encryption key 500 is configured to be inaccessible to the operator.
[0176] Furthermore, the device that delivers the encryption key 500 from the transmitting device 100 to the receiving device 200 is not limited to an airborne object. Anything that can move between the two devices where a transmission path cannot be established and that is difficult for other objects to access may be used, such as a vehicle that travels on the ground, such as an autonomous vehicle, or a moving object such as a ship.
[0177] <Variation 4> Furthermore, the encryption key distribution system according to each of the above embodiments and modifications may be configured to generate revenue.
[0178] In this case, as shown in Fig. 16, an encryption key distribution system 970 further includes a billing device 700 in addition to the configuration of each of the above embodiments. Note that the following example shows a case where the billing device 700 is added to the configuration of the first embodiment. The encryption key distribution system used as the base may be an encryption key distribution system of any of the other embodiments or modified examples.
[0179] Each time an encryption key delivery process is performed by the flying object 300, the billing processing device 700 acquires predetermined billing parameters such as the number of routes, delivery distance, number of deliveries, data volume, and non-delivery information.
[0180] The number of routes is the number of combinations of the transmitting device 100 and the receiving device 200. The number of routes may be received from any of the transmitting device 100, the receiving device 200, and the flying object 300.
[0181] The delivery distance is the distance between the transmitting device 100 and the receiving device 200 for each delivery. The distance may be calculated, for example, from GPS data between the two, or may be the flight distance obtained from the flight log of the flying object 300. For example, when the transmitting device 100 and / or the receiving device 200 is moving, the distance may be the distance at the time of departure or the distance at the time of arrival.
[0182] The number of deliveries is the number of delivered encryption keys 500. The billing processing device 700 collects, for example, the number of encryption keys 500 transmitted by the transmitting device 100, the number of encryption keys 500 received by the receiving device 200, etc.
[0183] The data amount is the amount of data of the distributed encryption key 500. The billing processing device 700 collects, for example, the amount of data transmitted by the transmitting device 100, the amount of data received by the receiving device 200, and the like.
[0184] The non-delivery information is information that indicates that the data has not been delivered. For example, if the flying object 300 erases the encryption key 500 before delivering it to the receiving device 200, the non-delivery information is also transmitted to the billing processing device 700. Alternatively, the non-delivery information may be transmitted via the transmitting device 100 or the receiving device 200.
[0185] The billing processing device 700 collects these billing parameters, tallying them up every predetermined period, calculating the amount according to predetermined calculation conditions, and charging the predetermined billing destination. The calculation conditions may be, for example, a calculation method such as multiplying the delivery distance and data volume of successful deliveries during a predetermined period by a predetermined coefficient. Alternatively, for deliveries that occurred regardless of whether they were successful during a predetermined period, the calculation method may be a calculation method such as multiplying the delivery distance and data volume by a predetermined coefficient, and subtracting a penalty for the number of undelivered deliveries from the result. The calculation conditions are not limited to these and can be set arbitrarily.
[0186] The billing processing device 700 is realized by a general-purpose information processing device equipped with a CPU, a memory, and a communication interface.
[0187] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments, and further modifications, substitutions, and adjustments can be made without departing from the basic technical concept of the present invention. For example, the network configurations and configurations of each element shown in the drawings are examples to aid in understanding the present invention, and the present invention is not limited to the configurations shown in these drawings.
[0188] Finally, the preferred embodiments of the present invention will be summarized. Note that some or all of the above-described embodiments and modifications may be described as follows, but are not limited to the following. [First form] (See first perspective moving object above) [Second Form] It is preferable that the above-mentioned mobile body further comprises an abnormality detection unit that detects the abnormality and notifies the storage control unit. [Third Form] In the above mobile object, it is preferable that the input / output unit receives from an external device that the abnormality has been detected and notifies the storage control unit. [Fourth Form] In the mobile body, it is preferable that the transmitting device and the receiving device further comprise an authentication requesting unit that requests authentication of the mobile body prior to transmission and reception of the encryption key. [Fifth Form] In the above mobile object, it is preferable that the input / output unit communicates the encryption key with the transmitting device and the receiving device using laser light. [Sixth Form] In the mobile object, it is preferable that the input / output unit communicates the encryption key with the transmitting device and the receiving device by quantum cryptography communication. [Seventh Form] In the above-mentioned moving body, it is preferable that the abnormality includes at least one of abnormal values of at least one of the vibration, temperature, voltage, position, movement speed, and movement time of the moving body, interference with the moving body by other objects, transmission and reception of data between the moving body and other devices, and an abnormality obtained as a result of analyzing the log information of the moving body. [Eighth Form] The moving body is preferably a flying object. [Ninth Form] (See the second aspect of the encryption key distribution system above.) [Form 10] In the encryption key distribution system, the transmitting device further includes a transmitting device authentication unit that authenticates the mobile object; the receiving device further includes a receiving device authentication unit that authenticates the mobile object; the transmitting device communication unit transmits the encryption key to the mobile unit if the transmitting device authentication unit has succeeded in authentication; It is preferable that the receiving device communication unit receives the encryption key from the mobile unit if the receiving device authentication unit has succeeded in authentication. [First form] The encryption key distribution system further includes the mobile entity as a second mobile entity, It is preferable that the second mobile unit receives from the transmitting device the same encryption key as the encryption key distributed by the mobile unit. [12th form] The encryption key distribution system further includes the mobile entity as a second mobile entity, It is preferable that the second mobile entity receives from the transmitting device an encryption key different from the encryption key distributed by the mobile entity. [13th Form] The encryption key distribution system preferably further comprises a billing processor that collects parameters related to billing incurred in the encryption key distribution system and performs billing. [Fourth Form] (See the third aspect of encryption key distribution method above.) [Fifteenth Form] (See the fourth perspective program above) The fourteenth and fifteenth embodiments can be expanded to the second to eighth embodiments in the same manner as the first embodiment.
[0189] The disclosures of the above-mentioned patent documents and other documents are incorporated herein by reference. Modifications and adjustments of the embodiments and examples are possible within the scope of the entire disclosure of the present invention (including the scope of the claims), and further based on the basic technical concept thereof. Furthermore, various combinations and selections of the various disclosed elements (including each element of each claim, each element of each embodiment or example, each element of each drawing, etc.) are possible within the scope of the disclosure of the present invention. In other words, the present invention naturally includes various modifications and alterations that would be possible by a person skilled in the art in accordance with the entire disclosure and technical concept, including the scope of the claims. In particular, with regard to the numerical ranges described herein, any numerical value or subrange included within the range should be construed as being specifically described, even if not otherwise specified. [Explanation of symbols]
[0190] 100: transmitting device, 111: (transmitting device) communication unit, 112: (transmitting device) control unit, 113: (transmitting device) authentication unit, 121: encryption key storage unit, 122: authentication information storage unit, 131: CPU, 132: storage device, 133: communication device, 140: encryption key table, 141: authentication information storage unit, 142: encryption key storage unit, 150: second encryption key table, 151: encryption key storage unit, 152: receiving device ID storage unit, 200: Receiving device, 211: (receiving device) communication unit, 212: (receiving device) control unit, 213: (receiving device) authentication unit, 221: encryption key storage unit, 222: authentication information storage unit, 231: CPU, 232: storage device, 233: communication device, 300: flying object, 311: input / output unit, 312: memory control unit, 313: abnormality detection unit, 314: authentication request unit, 315: movement control unit, 321: encryption key storage unit, 322: authentication information storage unit, 323: log information storage unit, 331: CPU, 332: storage device, 333: communication device, 334: sensor, 335: navigation device, 400: monitoring device, 411: communication unit, 412: information acquisition unit, 413: abnormality detection unit, 431: CPU, 432: storage device, 433: communication device, 434: information collection device, 500: encryption key, 600: Log information, 700: Charging processing device 910: encryption key distribution system, 920: encryption key distribution system, 940: encryption key distribution system, 960: encryption key distribution system, 970: encryption key distribution system
Claims
1. an input / output unit that receives an encryption key from a transmitting device and transmits the encryption key to a receiving device; a storage control unit that controls storage of the encryption key in a storage unit; a movement control unit that moves the device to the receiving device after receiving the encryption key from the transmitting device; a notification unit, the storage control unit stores the encryption key in the storage unit when receiving the encryption key from the transmission device, and erases the encryption key stored in the storage unit when an abnormality is detected; The mobile body, when the storage control unit erases the encryption key stored in the storage unit, notifies the transmission device that the encryption key has been erased.
2. 2. The moving body according to claim 1, The mobile body further comprises an abnormality detection unit that detects the abnormality and notifies the storage control unit.
3. 2. The moving body according to claim 1, The input / output unit receives the detection of the abnormality from an external device and notifies the storage control unit.
4. 2. The moving body according to claim 1, The mobile body further comprises an authentication request unit that requests authentication of the mobile body in the transmitting device and the receiving device prior to transmission and reception of the encryption key.
5. 2. The moving body according to claim 1, The input / output unit communicates the encryption key with the transmitting device and the receiving device using laser light.
6. 2. The moving body according to claim 1, The input / output unit communicates the encryption key with the transmitting device and the receiving device using quantum cryptography communication.
7. 2. The moving body according to claim 1, A mobile body, wherein the abnormality includes at least one of abnormal values of the mobile body's vibration, temperature, voltage, position, movement speed, and movement time, interference with the mobile body by another object, transmission and reception of data between the mobile body and another device, and an abnormality obtained as a result of analyzing the log information of the mobile body.
8. 2. The moving body according to claim 1, The moving body is a flying object.
9. A moving body according to any one of claims 1 to 8; the transmitting device; the receiving device, the transmitting device includes a transmitting device communication unit that transmits the encryption key to the mobile unit; The receiving device includes a receiving device communication unit that receives the encryption key from the mobile object.
10. 10. The encryption key distribution system according to claim 9, the transmitting device further includes a transmitting device authentication unit that authenticates the mobile object; the receiving device further includes a receiving device authentication unit that authenticates the mobile object; the transmitting device communication unit transmits the encryption key to the mobile unit if the transmitting device authentication unit has succeeded in authentication; The receiving device communication unit receives the encryption key from the mobile unit if the receiving device authentication unit has succeeded in authentication.
11. 10. The encryption key distribution system according to claim 9, The moving body according to claim 1 is further provided as a second moving body, An encryption key distribution system in which the second mobile entity receives from the transmitting device an encryption key that is the same as the encryption key distributed by the mobile entity.
12. 10. The encryption key distribution system according to claim 9, The moving body according to claim 1 is further provided as a second moving body, An encryption key distribution system in which the second mobile entity receives from the transmitting device an encryption key different from the encryption key distributed by the mobile entity.
13. 10. The encryption key distribution system according to claim 9, The encryption key distribution system further comprises a billing processing device that collects parameters related to billing incurred in the encryption key distribution system and performs billing.
14. a receiving step of receiving an encryption key from a transmitting device; a storage step of storing the received encryption key in a storage unit; a moving step of moving the device toward the receiving device after storing the encryption key; an erasing step of erasing the encryption key stored in the storage unit and notifying the transmitting device that the encryption key has been erased when an abnormality in the device itself is detected during movement; a transmitting step of transmitting the encryption key stored in the storage unit to the receiving device upon arrival at the destination area.
15. The computer installed in the vehicle a receiving step of receiving an encryption key from the transmitting device; a storage step of storing the received encryption key in a storage unit; a moving step of moving the device toward the receiving device after storing the encryption key; an erasing step of erasing the encryption key stored in the storage unit and notifying the transmitting device that the encryption key has been erased when an abnormality in the device itself is detected during movement; a transmission step of transmitting the encryption key stored in the storage unit to the receiving device upon arrival at the destination area.
Citation Information
Patent Citations
Quantum secrete key distribution method and system based on low-altitude aircraft, communication network, and communication method
CN105357000A
Portable information storage medium
JP2000076139A
Portable terminal and portable terminal system
JP2008011218A
Moving body control system
JP2017055335A
Security control device, security control system, security control method, and program
JP2017062669A