Network control device

The network control device in secure communication networks uses exclusive OR operations to combine messages at a hub node, reducing key consumption from n^2 to n, addressing the exponential key demand issue and improving network efficiency and security.

JP7787566B2Active Publication Date: 2025-12-17NAT INST OF INFORMATION & COMM TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2022060274
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-31
Publication Date
2025-12-17
Estimated Expiration
2042-03-31

AI Technical Summary

Technical Problem

In secure communication networks like quantum cryptography networks, the consumption of secret random number sequences (keys) increases exponentially with the number of users, limiting the capacity to provide secure communication services due to the one-time use and high demand for key consumption.

Method used

A network control device that instructs user nodes to encrypt messages with assigned keys and transmit ciphertexts to a hub node, which decrypts and combines messages using exclusive OR operations before transmitting back to user nodes, reducing key consumption through network coding.

Benefits of technology

This approach allows multiple users to efficiently share messages while maintaining confidentiality, significantly reducing key consumption from n^2 to n, enhancing the availability and convenience of secure communication networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007787566000027
    Figure 0007787566000027
  • Figure 0007787566000028
    Figure 0007787566000028
  • Figure 0007787566000029
    Figure 0007787566000029
Patent Text Reader

Abstract

To efficiently perform sharing of a message by a plurality of users who uses a secret communication network.SOLUTION: A network control device 100 in a network having: a plurality of user nodes; a hub node; and a plurality of links connecting the plurality of user nodes and the hub node, respectively, comprises: a first instruction part 110; and a second instruction part 120. The first instruction part instructs that a cryptogram formed by encrypting a message held by the user node to each user node is transmitted to the hub node with a key assigned to each link. The second instruction part instructs that the plurality of cryptograms received from the plurality of user nodes is decoded by the key to the hub node, a combination of two or more messages of the plurality of acquired messages is defined, an exclusive disjunction of the message according to the combination is calculated, and the exclusive disjunction is transmitted to each user node.SELECTED DRAWING: Figure 12
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a network control device. [Background technology]

[0002] Advances in cloud services and high-speed mobile communications technology are driving a rapid increase in Internet traffic. While network facilities, including high-capacity optical fiber, are being strengthened, the number of devices and new services and applications are expected to continue to increase. As a result, strengthening infrastructure at the current rate will no longer be enough, and communication methods themselves must be made more efficient. Furthermore, with the amount of highly confidential information increasing, there is an increasing demand for information security. In addition to improving communication efficiency, there is also a need for mechanisms to prevent information leaks to third parties other than authorized users and unauthorized data tampering.

[0003] Network coding, which combines multiple pieces of information collected at a relay node, converts (encodes) them into another piece of information, and then transmits them, is known as a method for efficiently performing multicast communication over a network (Non-Patent Documents 1 and 2). Network coding is beginning to be put into practical use as a new technology to support the rapid increase in communication traffic (Non-Patent Document 3). Furthermore, as a method for ensuring the security of communications, research and development of a technology called secure network coding (Non-Patent Documents 4 to 6) that combines network coding with secrecy using random numbers is also progressing. Furthermore, quantum key distribution (QKD) and quantum cryptography, which uses a one-time pad with a key (a pair of symmetric secret random number sequences) generated by QKD, are methods for achieving completely secure communication using the principles of quantum mechanics. In recent years, quantum cryptography communication networks have begun to be put into practical use to provide cryptographic applications such as secure communication between multiple points using quantum cryptography and secret sharing storage (Non-Patent Documents 7 to 9). [Prior art documents]

Non-licensed literature

[0004]

Non-licensed literature 1

Non-licensed Document 4

Non-licensed Document 5

Non-licensed Document 6

[0005] In a secure communication network such as a quantum cryptography network, a secret random number sequence is a valuable key resource. When multiple users of the secure communication network share messages by multicast, a large number of keys are consumed for one-time padding of messages and for pre-sharing of group keys. As the number of users increases, the consumption of keys increases rapidly, making it impossible to keep up with the generation of secret random number sequences, which limits the capacity to provide secure communication services.

[0006] The present invention has been made in view of the above circumstances, and has as its object to enable a plurality of users who use a secret communication network to efficiently share messages. [Means for solving the problem]

[0007] To achieve the above object, a network control device in a network including a plurality of user nodes, a hub node, and a plurality of links connecting each of the plurality of user nodes to the hub node includes a first instruction unit that issues instructions to the user nodes and a second instruction unit that issues instructions to the hub node. The first instruction unit instructs each of the plurality of user nodes to perform a step of encrypting a message held by the user node using a key assigned to the link connecting the user node to the hub node, and transmitting the resulting ciphertext to the hub node. The second instruction unit instructs the hub node to perform the steps of decrypting the ciphertexts received from the plurality of user nodes using the key to obtain the plurality of messages, determining a combination of two or more of the obtained messages based on a predetermined rule, calculating the exclusive OR of the two or more messages associated with the combination, and transmitting the exclusive OR to each of the plurality of user nodes. The first instruction unit further instructs each of the plurality of user nodes to perform a step of decrypting the exclusive OR using a message held by that user node. [Effects of the Invention]

[0008] According to the present invention, a plurality of users who use a secure communication network can efficiently share messages. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is an explanatory diagram showing a quantum cryptography communication network. [Figure 2A] 1A to 1D are explanatory diagrams each showing an example of multicast distribution in a network having four user nodes. [Figure 2B] FIG. 10 is an explanatory diagram showing keys consumed in the same study example. [Figure 3](A) to (F) are explanatory diagrams showing an example of multicast distribution in a network with six user nodes, and (G) is an explanatory diagram showing keys consumed in the same example. [Figure 4A] 1A to 1D are explanatory diagrams each showing a first example of multicast distribution in a network having four user nodes. [Figure 4B] 1(A) and 1(B) are explanatory views showing the first example. [Figure 4C] FIG. 10 is an explanatory diagram showing keys consumed in the first example. [Figure 5A] 10(A) to 10(D) are explanatory diagrams showing a second example of multicast distribution in a network having four user nodes. [Figure 5B] 10(A) and 10(B) are explanatory views showing the second example. [Figure 5C] FIG. 10 is an explanatory diagram showing keys consumed in the second example. [Figure 6A] 1A and 1B are explanatory diagrams each showing a first example of multicast distribution in a network having six user nodes. [Figure 6B] FIG. 2 is an explanatory diagram showing the first example of the same. [Figure 6C] FIG. 10 is an explanatory diagram showing keys consumed in the first example. [Figure 7A] FIG. 10 is an explanatory diagram showing a second example of multicast distribution in a network having six user nodes. [Figure 7B] FIG. 10 is an explanatory diagram showing a second example of the same. [Figure 7C] FIG. 10 is an explanatory diagram showing keys consumed in the second example. [Figure 8A] FIG. 10 is an explanatory diagram showing a third example of multicast distribution in a network having six user nodes. [Figure 8B] FIG. 10 is an explanatory diagram showing a third example of the same. [Figure 8C] FIG. 10 is an explanatory diagram showing keys consumed in the third example. [Figure 9A] FIG. 10 is an explanatory diagram showing a fourth example of multicast distribution in a network having six user nodes. [Figure 9B] FIG. 10 is an explanatory diagram showing a fourth example of the same. [Figure 9C] FIG. 10 is an explanatory diagram showing keys consumed in the fourth example. [Figure 10] FIG. 10 is an explanatory diagram showing keys consumed in another example of multicast distribution in a network having four user nodes. [Figure 11A] 10(A) to 10(D) are explanatory diagrams showing a third example of multicast distribution in a network having four user nodes. [Figure 11B] 10(A) and 10(B) are explanatory views showing the third example. [Figure 11C] FIG. 10 is an explanatory diagram showing keys consumed in the third example. [Figure 12] FIG. 2 is a block diagram showing the configuration of a network control device. [Figure 13] FIG. 2 is an explanatory diagram illustrating an example of a computer hardware configuration of a node. [Figure 14A] 10A to 10D are explanatory diagrams each showing a third example of multicast distribution in a network having four user nodes. [Figure 14B] FIG. 10 is an explanatory diagram showing keys consumed in the third study example. [Figure 15A] 10(A) to 10(D) are explanatory diagrams showing a fourth example of multicast distribution in a network having four user nodes. [Figure 15B] 10(A) and 10(B) are explanatory views showing the fourth example. [Figure 15C] FIG. 10 is an explanatory diagram showing keys consumed in the fourth study example. [Figure 16] 10(A) to 10(G) are explanatory diagrams showing a fifth example of multicast distribution in a network having six user nodes. DETAILED DESCRIPTION OF THE INVENTION

[0010] The present invention will be described below based on the illustrated embodiments, but the present invention is not limited to the embodiments described below.

[0011] First, the inventors of the present invention conducted extensive research as described below.

[0012] [1.Secure communication network using quantum key distribution] Currently, the standard methods for ensuring the security of network communications are authentication and key exchange using public key cryptography, and encryption of data communications using symmetric key cryptography. These cryptographic techniques use difficult mathematical problems to create a situation in which a third party who does not know the cryptographic key would be required to perform an enormous amount of calculations to decipher the original information from the ciphertext, effectively preventing eavesdropping and tampering. However, as the risk of deciphering increases with advances in computing technology, it is necessary to periodically extend the length of the cryptographic key and update the cryptographic method. In contrast to this, there are also known methods that guarantee security that cannot be decrypted by any computer (information-theoretic security). Cryptographic methods based on information-theoretic security can, in principle, guarantee security for an extremely long period of time without updating the encryption specifications.

[0013] A typical method for guaranteeing information-theoretic security is quantum cryptography, which encrypts data communications using a one-time pad (OTP) method using a cryptographic key shared by quantum key distribution. Quantum Key Distribution (QKD) is a method in which a common random number sequence (let's say K) with information-theoretic security is shared as a cryptographic key between two distant points connected by optical fiber lines. Encryption is performed by logically ORing the message to be sent (let's say U) with a cryptographic key K of the same size as the message U.

number

number

[0014] The key generation speed of a pair of QKD link systems connecting two points decreases as the transmission distance increases, and with conventional optical fiber installations, it is only a few hundred kbps over 50 km and a few kbps over 100 km. Therefore, by installing multiple "trusted nodes" at intervals of 50 to 60 km and connecting the QKD devices (QKD modules) within each trusted node, a wide-area network called a Quantum Key Distribution Network (QKDN) can be obtained. Each trusted node is equipped with a key management device (Key Manager, KM) separate from the QKD module, which transfers and stores the encryption keys generated by the QKD module to the KM. KMs are connected to each other via classical circuits (KM links), and manage and operate encryption keys, including performing capsule relay (key relay) of encryption keys when necessary. The cryptographic keys shared in this way can be used for various cryptographic applications existing in existing communication networks and cryptographic infrastructures (user networks in Figure 1, which will be described later), such as providing keys to applications such as one-time pad (OTP)-based completely confidential communications, symmetric key cryptography, and secret sharing storage. Functional elements called the QKDN controller and QKDN manager have been introduced to control the route of the capsule relay of cryptographic keys and manage the entire QKDN. A network that includes the QKDN and user networks on which cryptographic applications are executed is called a quantum cryptographic communication network.

[0015] 1 shows the conceptual structure of a quantum cryptography communication network NW1. The quantum cryptography communication network NW1 includes a quantum key distribution network QKDN1 and a user network UN1. The quantum key distribution network QKDN1 includes multiple trusted nodes TN and four functional layers L1 to L4.

[0016] The quantum layer L1 is a set of QKD links connected via QKD modules QM in each trusted node. A QKD link is a one-to-one link. A QKD link connects one QKD module in a trusted node to one QKD module in another trusted node. Each QKD link generates its own encryption key. The generated encryption key is sent to the key manager KM in the trusted node for management and operation.

[0017] The key management layer L2 has a key manager KM in each trusted node and KM links connecting the key managers KM. The key manager KM stores the encryption keys generated in the quantum layer L1 and shares them between the required ends through key capsule relay using OTP encryption. The key manager KM is responsible for overall key management, including supplying encryption keys to cryptographic applications on the user network UN1.

[0018] The QKDN control layer L3 has one or more QKDN controllers CT that control the overall QKDN service. The layer L3 may be a network consisting of multiple QKDN controllers CT. The QKDN management layer L4 has a QKDN manager MG1. The QKDN manager MG has the function of collecting performance information from each of the layers L1 to L3, monitoring whether the service is operating properly, and issuing control commands to the QKDN control layer L3 as necessary.

[0019] The user network UN1 has a service layer L5, which is a functional layer where multiple user terminals UD exist, and a user network management layer L6. The multiple user terminals UD in the service layer L5 perform encrypted communication using keys and cryptographic applications provided by corresponding key managers KM. The service layer L5 may be a multipoint network consisting of three or more user terminals UD. The network manager MG2 in the user network management layer L6 communicates with the QKDN manager MG1 and manages the user terminals UD.

[0020] The key management layer L2 and service layer L5 of the quantum cryptography communication network NW1 are examples of a secret communication network. That is, in the key management layer L2, symmetric encryption keys are shared between two KMs required by key capsule relay using OTP encryption, and group keys are shared among three or more KMs. In addition, in the service layer L5, secret communication between two points and secret multicast communication between multiple points are performed using keys provided from the key management layer L2.

[0021] In such a secure communication network, the secret random number sequence used as the symmetric key for encrypting each link is valid only for one use, and therefore must be discarded after use. Since the use of a secure communication network consumes a large number of secret random number sequences, the network administrator must generate many new secret random number sequences to replenish the symmetric keys. Since the secret random number sequence is a valuable key resource, it is important to consider how to use it efficiently.

[0022] [2. Multicast distribution using a secure communication network] In order to explain the problems of the conventional technology, an example of multicast distribution using the above-mentioned secure communication network will be shown. The network NW4A shown in FIG. 2A(A) is typically an example of the above-mentioned service layer L5, and has four user nodes A to D and a hub node H. Alternatively, if these nodes correspond to a key manager KM, the network NW4A becomes an example of a key management layer L2. In the network NW4A, each of the four user nodes A to D and the hub node H are connected by a link. Furthermore, user node A and user node C are connected by a link, user node C and user node B are connected by a link, user node B and user node D are connected by a link, and user node A and user node D are connected by a link. Each of the four user nodes A to D has a user U A ~U D , and the hub node H has no users associated with it. A ~U D A user group is formed by We assume that user nodes A to D and hub node H are implemented and operated as trusted nodes, and that it is extremely difficult for an eavesdropper to access the data stored in the nodes. On the other hand, we assume that the links connecting each node are accessible to an eavesdropper, and that all information flowing on the links falls into the hands of an eavesdropper. User U A Message S A User U B Message SB User U C Message S C User U D Message S D In this example, it is assumed that each user has a message that he or she owns and distributes the message to three other users through multicast.

[0023] A secret random number sequence is prepared as a symmetric key for the link connecting two nodes to conceal the link. For example, the symmetric key (K AC ) i means the i-th secret random number sequence prepared for link AC connecting node A and node C. The symmetric key (K AD ) i , (K BC ) i The same is true for the following. For simplicity, we use the message S instead of the group key R. A ~S D We assume that the message is encrypted using a symmetric key and transmitted via a key relay. For simplicity, we assume that the length of the symmetric key is the same as that of the message. To conserve keys, messages are not delivered to hub nodes H that have no users.

[0024] At this time, as shown in FIG. 2A(A), user node A sends the message S A and the symmetric key (K AC )1 and sends the exclusive OR (ciphertext by Vernam cipher) to the user node C. The user node C receives this exclusive OR and sends the symmetric key (K AC )1 to decrypt the message S A After receiving the message S A and the symmetric key (K BC )1 to user node B. User node B receives this exclusive OR and sends the symmetric key (K BC )1 to decrypt the message S A get. In addition, user node A sends the message S A and the symmetric key (KAD )1. User node D, which receives this exclusive OR, sends the symmetric key (K AD )1 to decrypt the message S A get. In this way, the message S A is distributed by multicast from user node A to user nodes B, C, and D. Similarly, as shown in Figure 2A(B), message S B is multicast from user node B to user nodes A, C, and D. As shown in Figure 2A(C), message S C is multicast from user node C to user nodes A, B, and D. As shown in Figure 2A(D), message S D is distributed by multicast from user node D to user nodes A, B, and C.

[0025] As shown in Figures 2A(A) to 2A(D), three keys (secret random number sequences) are consumed when one user node multicasts a message it holds. Therefore, 12 keys are consumed for multicast distribution by each of four user nodes A to D. This is shown in Figure 2B. While three keys are consumed for each link connecting user nodes, no secret random number sequence is consumed for the link connecting a user node to a hub node.

[0026] The network NW6A shown in FIG. 3(A) has six user nodes A to F and a hub node H. Each of the six user nodes A to F is connected to the hub node H by a link. Furthermore, user node A is connected to user node C by a link, user node C is connected to user node E by a link, and user node E is connected to user node B by a link. Furthermore, user node B is connected to user node D by a link, user node D is connected to user node F by a link, and user node F is connected to user node A by a link. Each of the six user nodes A to F has a user U A ~U F, and the hub node H has no users associated with it. A ~U F A user group is formed by User U A Message S A , user U B Message S B , user U C Message S C , user U D Message S D , user U E Message S E , user U F Message S F In this example, it is assumed that each user has a message that he or she owns and distributes it to five other users through multicast.

[0027] At this time, as shown in FIG. 3(A), user node A sends the message S A and the symmetric key (K AC )1. User node C, which receives this exclusive OR, sends the symmetric key (K AC )1 to decrypt the message S A After receiving the message S A and the symmetric key (K EC )1 to user node E. User node E, which receives this exclusive OR, sends the symmetric key (K EC )1 to decrypt the message S A After receiving the message S A and the symmetric key (K EB )1 to user node B. User node B receives this exclusive OR and sends the symmetric key (K EB )1 to decrypt the message S A get. In addition, user node A sends the message S A and the symmetric key (K AF )1. User node F receives this exclusive OR and sends the symmetric key (KAF )1 to decrypt the message S A After receiving the message S A and the symmetric key (K FD )1 to user node D. User node D receives this exclusive OR and sends the symmetric key (K FD )1 to decrypt the message S A get. In this way, the message S A is distributed by multicast from user node A to user nodes B to F. Similarly, as shown in Figure 3(B), message S B is multicast from user node B to five user nodes excluding the user node B. As shown in Figure 3(C), message S C is multicast from user node C to five user nodes excluding the user node C. As shown in Figure 3(D), message S D is multicast from user node D to five other user nodes. As shown in Figure 3(E), message S E is multicast from user node E to five user nodes excluding the user node E. As shown in Figure 3(F), message S F is multicast from user node F to five user nodes excluding the user node.

[0028] As shown in Figures 3(A) to 3(F), five keys (secret random number sequences) are consumed when one user node multicasts a message it holds. Therefore, 30 keys are consumed for multicast distribution by each of six user nodes A to F. This is shown in Figure 3(G). While five keys are consumed for each link connecting user nodes, no secret random number sequences are consumed for links connecting user nodes with hub nodes.

[0029] As described above, in a network NW4A having four user nodes, 4×(4−1)=12 keys are consumed, and in a network NW6A having six user nodes, 6×(6−1)=30 keys are consumed. In a network with n user nodes, if each user node performs multicast distribution, there are at least n × (n-1) number of nodes, i.e., n 2 This means that a relatively large number of keys (secret random number sequences), on the order of n, are consumed. As such, in the conventional technology, as the number of user nodes n increases, the amount of keys (secret random number sequences) consumed increases exponentially. This large consumption of keys poses a problem in that it significantly impairs the availability of the secure communication network.

[0030] To address these issues, the following two methods are used in the embodiment described below when multicast distribution for information sharing is performed using a secure communication network. Each method may be used alone, or both methods may be used in combination. For simplicity of explanation, the number of user nodes n is set to 4, and the number of messages distributed by multicast is set to 4. The first method is to send four messages (S A , S B , S C , S D ) is shared all at once at the same time, rather than individually at different times. Unlike messages, the time for delivering the group key can be set arbitrarily, making it possible to process it all at once. The second technique is to use the exclusive OR of multiple messages, e.g.

number

number

[0031] By sharing multiple messages simultaneously, the operation between these different messages can be made meaningful. Furthermore, since each of the multiple messages to be XORed mutually conceals the other messages, even if the result of the XOR, such as R or R1, is leaked, each message remains confidential. Therefore, by transmitting the result of the XOR of multiple messages rather than concealing each message using a key, the consumption of keys can be reduced while maintaining the confidentiality of each message.

[0032] [Embodiment] An example will be described in which the number of user nodes n is 4 and the number of messages to be shared is 4.

[0033] [First example of four people] FIG. 4A(A) shows a network NW41. This network has the same topology as the network NW4A. Each of the user nodes A, B, C, and D transmits a message (or a group key (a key to be used in the group in the future)) R A , R B , R C , R D The key (secret random number sequence) K assigned to each link HA , K. HB , K. HC , K. HD After concealing it using the message R, it is sent to the hub node H. In addition, user nodes A and C also have their own message R A , R C , key (K AC )1, (K AC )2, and then send the encrypted data to each other, C / A. The same goes for users B and D.

[0034] Specifically, as shown in FIG. 4A(A), a user node A sends a message R A and key (K HA )1 to the hub node H, and sends a message RA and key (K AC )1 and sends the exclusive OR with it to user node C. As shown in FIG. 4A(B), user node B sends a message R B and key (K HB )1 to the hub node H, and sends a message R B and key (K BD )1 and sends the exclusive OR to user node D. As shown in FIG. 4A(C), user node C sends a message R C and key (K HC )1 to the hub node H, and sends a message R C and key (K AC )2 and sends the exclusive OR to user node A. As shown in FIG. 4A(D), user node D sends a message R D and key (K HD )1 to the hub node H, and sends a message R D and key (K BD )2 and sends the exclusive OR to user node B.

[0035] As a result, as shown in FIG. 4B(A), each of user nodes A and C sends a message R A and R C and each of user nodes B and D sends a message R B and R D The hub node H will have four messages R A ~R D will be held.

[0036] Then, the hub node H calculates the following two exclusive ORs (i.e., two pieces of network-coded information) R1 and R2:

number

[0037] User nodes A and C receive R1 from hub node H and the message R they already have. A message R by computing the exclusive OR with B , and compares R2 received from the hub node H with the message R already held. C message R by computing the exclusive OR with D Get. User nodes B and D receive R1 from hub node H and the message R B message R by computing the exclusive OR with A , and compares R2 received from the hub node H with the message R already held. D message R by computing the exclusive OR with C Get.

[0038] In this way, messages R A ~R D In this case, as shown in FIG. 4C, two keys are consumed in link AC, two keys are consumed in link BD, and one key is consumed in each link between the hub node H and each user node. In other words, a total of eight keys are consumed. This is four fewer than the number of keys (12) consumed by the method shown in FIGS. 2A and 2B. In this way, the number of keys consumed can be reduced.

[0039] There is a possibility that the exclusive ORs R1 and R2 are leaked. On the other hand, the message R A and R B One of them conceals the other, and the message R C and R D Therefore, even if the exclusive ORs R1 and R2 are leaked, it is extremely unlikely that a third party will be able to obtain each message.

[0040] If some incident occurs, for example, message R A If the exclusive OR R1 is leaked, a third party can derive the message R from the exclusive OR R1. B However, the message R C and R D Therefore, to prevent such a limited chain of message compromises, the hub node H may use a general block cipher (e.g., AES: Advanced Encryption Standard) or public key cryptography to ensure confidentiality when sending the exclusive ORs R1 and R2.

[0041] [Second example of four people] FIG. 5A(A) shows a network NW42. This network has the same topology as the network NW4A. As shown in FIGS. 5A(A) to 5A(D), each of user nodes A, B, C, and D has a message R A , R B , R C , R D The key K assigned to the link with the hub node H HA , K. HB , K. HC , K. HD At this stage, as shown in Figure 5B(A), the number of messages held by each user node remains the same, but the hub node H receives four messages R A ~R D We possess all of the above.

[0042] The hub node H then calculates the following three exclusive ORs (ie, three pieces of network coded information): R1, R2 and R3.

number

[0043] User node A receives R2 from hub node H and the message R it already has. A message R by computing the exclusive OR with C , and compares R1 received from the hub node H with the message R already held. A message R by computing the exclusive OR with B Furthermore, user node A receives R3 from hub node H and the message R A message R by computing the exclusive OR with D Get. User node C receives R2 from hub node H and the message R it already holds. C message R by computing the exclusive OR with A In addition, user node C receives R1 and R2 from hub node H, and the exclusive OR of R1 and R2, which it already has. C message R by computing the exclusive OR with B Furthermore, user node C obtains the exclusive OR of R2 and R3 received from hub node H and the message R C message R by computing the exclusive OR with DGet. User nodes B and D also perform similar decoding to obtain the remaining three messages.

[0044] In this way, messages R A ~R D In this case, as shown in FIG. 5C, one key is consumed for each link between the hub node H and each user node. In other words, a total of four keys are consumed. This is eight fewer than the number of keys (12) consumed by the method shown in FIGS. 2A and 2B. In this way, the amount of keys consumed can be reduced.

[0045] There is a possibility that the exclusive ORs R1 to R3 may be leaked. On the other hand, one of the two messages that are the subject of each exclusive OR operation conceals the other. Therefore, even if the exclusive OR is leaked, the possibility that the information in each message will be leaked is extremely low.

[0046] If a trusted node is compromised due to some incident, for example, message R A If the exclusive ORs R1 to R3 are leaked, a third party can extract the message R from the exclusive OR R1. B R2 is exclusive-ORed with message R C R3 is exclusive-ORed with message R D You will be able to get the same results. In this way, the scope of the impact of an incident will be wider as the secret random number sequence is further saved compared to the previous example. Therefore, to prevent such a chain of message compromises, when the hub node H sends the exclusive ORs R1, R2, and R3, it may be possible to anonymize them using a common block cipher (e.g., AES: Advanced Encryption Standard) or public key cryptography.

[0047] Either the first or second example can be selected depending on the purpose, taking into consideration the effect of reducing the total consumption of keys and the risk of compromising other messages that may occur if one message is leaked.

[0048] The number of secret random number sequences consumed when sharing messages using a secret communication network can be reduced. The number of secret random number sequences consumed when n user nodes share n messages can be reduced by 2 This can be reduced from about 1 to as few as n, which greatly improves the availability and convenience of secure communication networks for message sharing.

[0049] [First example of six people] Several embodiments will be described using an example where the number of members, n, is 6 and the number of messages is 6. These different embodiments provide different combinations of the benefits of reducing key consumption and the risk of compromising other messages if one of the messages is leaked.

[0050] 6A(A) shows a network NW61, which has the same topology as the network NW6A.

[0051] As shown in FIG. 6A(A), each of user nodes C, A, and F has a message R C , R A , R F Let K be the secret random number sequence assigned to each link. HC , K. HA , K. HF After concealing it using User node A sends message R A is encrypted using a key and sent to user nodes C and F. Message R C is sent from user node C to user node A and from hub node H to user node F while being kept secret by the key. Message R F is sent from user node F to user node A and from hub node H to user node C while being kept secret by the key. In this way, one of user nodes A and C receives a message held by the other via a link that directly connects the two user nodes. One of user nodes A and F receives a message held by the other via a link that directly connects the two user nodes. One of user nodes C and F receives a message held by the other via hub node H. At this stage, user nodes A, C, and F and hub node H receive three messages R A , R C and R F The total number of secret random numbers consumed for this sharing is 9.

[0052] As shown in FIG. 6A(B), each of user nodes E, B, and D has a message R E , R B , R D Let K be the secret random number sequence assigned to each link. HE , K. HB , K. HD After concealing it using User node B sends message R B is encrypted using a key and sent to user nodes E and D. Message R E is sent from user node E to user node B and from hub node H to user node D while being kept secret by the key. Message R D is sent from user node D to user node B and from hub node H to user node E while being kept secret by the key. In this way, one of user nodes B and E receives a message held by the other via a link that directly connects both user nodes. One of user nodes B and D receives a message held by the other via a link that directly connects both user nodes. One of user nodes E and D receives a message held by the other via hub node H. At this stage, user nodes B, D, and E and hub node H receive three messages RB , R D and R E The total number of secret random numbers consumed for this sharing is 9.

[0053] As a result of the message distribution shown in Figures 6A(A) and (B), each user node has three messages, and the hub node H has all six messages, resulting in 18 keys being consumed.

[0054] The hub node H then calculates the following three exclusive ORs (ie, three pieces of network coded information): R1, R2 and R3.

number

[0055] User nodes A, C, and F receive R1 and message R A message R by computing the exclusive OR with B and R2 and message R C message R by computing the exclusive OR with D and R3 and message R F message R by computing the exclusive OR with E Get. User nodes B, D, and E receive R1 and message R B message R by computing the exclusive OR with A and R2 and message R D message R by computing the exclusive OR with Cand R3 and message R E message R by computing the exclusive OR with F Get.

[0056] In this way, six messages R A ~R F This means that the information can be shared. As shown in Figure 6C, two keys are consumed for the link between user node C and user node A, two keys are consumed for the link between user node A and user node F, two keys are consumed for the link between user node C and hub node H, two keys are consumed for the link between hub node H and user node F, and one key is consumed for the link between user node A and hub node H. In addition, two keys are consumed in the link between user node E and user node B, two keys are consumed in the link between user node B and user node D, two keys are consumed in the link between user node E and hub node H, two keys are consumed in the link between hub node H and user node D, and one key is consumed in the link between user node B and hub node H. In this way, a total of 18 keys are consumed. This is 60% of the number of keys (30) consumed by the method shown in Figure 3. In this way, the amount of keys consumed can be reduced.

[0057] There is a possibility that the exclusive ORs R1 to R3 may be leaked. On the other hand, one of the two messages that are the subject of each exclusive OR operation conceals the other. Therefore, even if the exclusive OR is leaked, the possibility that the information in each message will be leaked is extremely low.

[0058] If a trusted node is compromised due to some incident, for example, message R A If the exclusive ORs R1 to R3 are leaked, a third party can extract the message R from the exclusive OR R1. B However, the other four messages R C ~RF will not be affected. However, to prevent such limited chain message compromise, the hub node H may anonymize the exclusive ORs R1, R2, and R3 using a common block cipher (e.g., AES: Advanced Encryption Standard) or public key cryptography as a precaution when sending them.

[0059] [Second example of six people] Figure 7A shows network NW62, which has a similar topology to network NW6A.

[0060] As shown in FIG. 7A, all user nodes A to F transmit messages they possess using a key K assigned to each link. HA , K. HC , K. HE , K. HB , K. HD , K. HF After concealing it using Furthermore, user nodes A and C send messages they possess to each other using the key. The same applies to user nodes E and B and user nodes D and F. At this stage, each user node possesses two messages, and the hub node H has all messages R A ~R F The total number of keys consumed so far is 12.

[0061] Next, the hub node H calculates the following four exclusive ORs (four pieces of network-encoded information) R1 to R4.

number

[0062] Here, the exclusive OR of R1 and R3 and the exclusive OR of R2 and R4 in the table are as follows:

number

[0063] User nodes A and C are connected to R4 and R C message R by computing the exclusive OR with E and obtain R1 and R A message R by computing the exclusive OR with B and obtain R2 and R C message R by computing the exclusive OR with D and obtain R3 and R A message R by computing the exclusive OR with F Get. User nodes E and B are connected to R1 and R B message R by computing the exclusive OR with A and obtain R4 and R E message R by computing the exclusive OR with C and R2 and R4 are exclusive ORed with R E message R by computing the exclusive OR with D and R1 and R3 are exclusive ORed with R B message R by computing the exclusive OR with F Get. User nodes D and F are connected to R3 and R F message R by computing the exclusive OR with A and obtain R2 and R D message R by computing the exclusive OR with C and R2 and R4 are exclusive ORed with R D message R by computing the exclusive OR with Eand R1 and R3 are exclusive ORed with R F message R by computing the exclusive OR with B Get.

[0064] In this way, six messages R A ~R F This means that the information can be shared. As shown in Figure 7C, two keys are consumed in the link between user node C and user node A, two keys are consumed in the link between user node E and user node B, and two keys are consumed in the link between user node F and user node D. Furthermore, a total of six keys are consumed in the links between hub node H and six user nodes. In this way, a total of 12 keys are consumed. This is 40% of the number of keys (30) consumed by the method shown in Figure 3. In this way, the amount of keys consumed can be reduced.

[0065] There is a possibility that the exclusive ORs R1 to R4 may be leaked. On the other hand, one of the two messages that are the subject of each exclusive OR operation conceals the other. Therefore, even if the exclusive OR is leaked, the possibility that the information in each message will be leaked is extremely low.

[0066] If a trusted node is compromised due to some incident, for example, message R A If the exclusive ORs R1 to R4 are leaked, a third party can extract the message R B R3 is exclusive-ORed with message R F However, the other four messages are not affected. However, to prevent such limited chain message compromise, the hub node H may use a common block cipher (e.g., AES: Advanced Encryption Standard) or public key cryptography to anonymize the exclusive ORs R1 to R4 when sending them.

[0067] [Third example of six people] Figure 8A shows network NW63, which has a similar topology to network NW6A.

[0068] As shown in FIG. 8A, all user nodes A to F transmit messages they possess using a key K assigned to each link. HA , K. HC , K. HE , K. HB , K. HD , K. HF After concealing it using At this stage, each user node still has one message, as it did initially, but the hub node H now has all six messages. The total number of secret random number sequences consumed so far is 6.

[0069] Next, the hub node H calculates the following five exclusive ORs (five pieces of network-encoded information) R1 to R5.

number

[0070] User node A is connected to each of R1 to R5 and R A message R by computing the exclusive OR with B ~R F are obtained respectively. User node C is connected to R2 and R C message R by computing the exclusive OR with A and R2 and R4 are exclusive ORed with RC message R by computing the exclusive OR with E and R1 and R2 are exclusive ORed with R C message R by computing the exclusive OR with B and R2 and R3 are exclusive ORed with R C message R by computing the exclusive OR with D and R2 and R5 are exclusive ORed with R C message R by computing the exclusive OR with F Get. User nodes E, B, D, and F also perform the calculations shown in Table 5 to obtain five new messages.

[0071] In this way, six messages R A ~R F This means that the information can be shared. As shown in Figure 8C, six keys are consumed. This is 20% of the number of keys (30) consumed by the method shown in Figure 3. In this way, the amount of keys consumed can be reduced.

[0072] There is a possibility that the exclusive ORs R1 to R5 may be leaked. On the other hand, one of the two messages that are the subject of each exclusive OR operation conceals the other. Therefore, even if the exclusive OR is leaked, the possibility that the information in each message will be leaked is extremely low.

[0073] If a trusted node is compromised due to some incident, for example, message R A If the exclusive ORs R1 to R5 are leaked, a third party can obtain the remaining five messages R B ~R F You will be able to get the same results. To prevent such a chain of message compromises, when the hub node H sends the exclusive ORs R1 to R5, it may be possible to anonymize them as a precaution by using a common block cipher (e.g., AES: Advanced Encryption Standard) or public key cryptography.

[0074] As described above, according to the first to third embodiments for a case where there are six user nodes, when the six user nodes share six messages, the amount of key consumption can be reduced using different methods. On the other hand, as the total amount of key consumption decreases, the risk of a chain reaction of compromise of other messages that may occur if one of the messages is leaked increases. An appropriate method can be selected depending on the required level of security.

[0075] [Fourth example of six people] In this example, the size of the group key prepared by each user is different. A , U B , U C and U D exists and user U A and U B holds one message, and user U C and U D holds two units of messages.

[0076] In this case, user U C´ and U D´ It can be considered that six users exist in total, with six users U A , U B , U C , U C´ , U D and U D´ can be associated with user nodes A, B, C, C', D and D', respectively. Each of the six user nodes holds one unit of message. That is, user nodes A, B, C, C', D and D' each hold a message R A , R B , R C , R C´ , R D and R D´ holds the following.

[0077] In network NW64 shown in Fig. 9A, each of six user nodes A, B, C, C', D, and D' is connected to hub node H by a link. User node A and user node C are connected by a link, user node C and user node C' are connected by a link, and user node C' and user node B are connected by a link. Furthermore, user node B and user node D are connected by a link, user node D and user node D' are connected by a link, and user node D' and user node A are connected by a link.

[0078] The network NW64 can be considered as the network NW42 shown in FIG. 5A(A) to which virtual user nodes C' and D' have been added. User node C' is connected to user nodes B and C and hub node H, and user node D' is connected to user nodes A and D and hub node H. The network NW64 can also be considered as the network NW63 shown in FIG. 8A in which user nodes E and F have been replaced with user nodes C' and D', respectively. In this network NW64, messages can be shared in the same manner as in the network NW63.

[0079] Specifically, as shown in FIG. 9A, all user nodes A to F conceal their own messages using a key and then send them to a hub node H. At this stage, each user node still has one message, as it did initially, but the hub node H now has all six messages. The total number of secret random number sequences consumed so far is 6.

[0080] Next, the hub node H calculates the following five exclusive ORs (five pieces of network-encoded information) R1 to R5.

number

[0081] In this way, four users each send one message R A and R B and 2 units of messages (R C , R C´ ) and (R D , R D´ ) can be shared. As shown in Figure 9C, six keys have been consumed.

[0082] When the number of message units held by physical user nodes in a network varies, one or more virtual user nodes can be provided for a physical user node with a relatively large number of message units. At least one message unit initially held by the physical user node can then be assigned to the virtual user node. This reduces the variation in the number of message units among user nodes compared to before the virtual user nodes were provided, enabling subsequent message sharing processing to be performed more efficiently.

[0083] [5th ​​example of 6 people] In this example, the problem of chain compromise pointed out in the third embodiment (i.e., one message, e.g., R AA method is introduced to prevent the problem that if the cipher suite is leaked, a third party can decrypt all other messages from the published exclusive-or of the five cipher suites.

[0084] A specific description will be given below based on the third embodiment. As shown in Table 7, the specific definition method for the network coding information R1, R2, R3, R4, and R5 is different for each of the 120 possible cases. [Table 7]

[0085] It is assumed that user nodes A to F and hub node H share the correspondence table shown in Table 7 as secret information in advance. Hub node H then selects one case number, calculates an exclusive OR (network coded information) according to the selected case number, and sends the exclusive OR together with the case number to the user node. The user node can obtain all group keys based on the received exclusive OR and case number. A third party who does not know the correspondence table in Table 7 may A Even if someone obtains the group key illegally, they cannot know the other five group keys. In this example, randomization of the definitions of the network coding information R1 to R5 in the hub node H can prevent a chain reaction of message compromise caused by network coding.

[0086] [Another example for four people] The network NW4B shown in FIG. 10 has four user nodes A to D and a hub node H. Each of the four user nodes A to D is connected to the hub node H by a link. In addition, there is no link connecting the user nodes together. When user node A sends a message R A and user node B receives message R B and user node C receives message R C and user node D receives message R DIn this example, it is assumed that each user node has a message that it holds, and distributes the message to three other users by multicast.

[0087] In network NW4B, user node A sends message R A Key (K AH )1 and sends the message R A Key (K BH )1 and sends the message R A Key (K CH )1 and sends the message R to user node D. A Key (K DH )1 and send it confidentially. User node B sends message R to hub node H. B Key (K BH )2 and sends the message R B Key (K AH )2 and sends the message R B Key (K CH )2 and sends the message R to user node D. B Key (K DH )2 and send it confidentially. User node C sends message R to hub node H. C Key (K CH )3 and sends the message R C Key (K AH ) 3 and sends the message R C Key (K BH )3 and sends the message R to user node D. C Key (K DH )3 and send it confidentially. User node D sends message R to hub node H. D Key (K DH) 4, the hub node H sends the message R D Key (K AH ) 4 and sends the message R D Key (K BH ) 4 and sends the message R D Key (K CH )4 and send it confidentially.

[0088] In this way, user nodes A to D receive the message R A ~R D In this sharing, four keys are consumed for each of the four links between the hub node H and the user nodes, as shown in Figure 10. Sixteen keys are consumed for the entire network NW4B.

[0089] [Third example of four people] FIG. 11A(A) shows a network NW43. This network has the same topology as the network NW4B. As shown in FIGS. 11A(A) to 11A(D), each of user nodes A, B, C, and D has a message R A , R B , R C , R D is encrypted using a key assigned to each link and then sent to the hub node H.

[0090] As a result, as shown in FIG. 11B(A), the hub node H sends four messages R A ~R D will be held.

[0091] Then, the hub node H calculates the following two exclusive ORs (i.e., two pieces of network-coded information) R1 and R2:

number

[0092] 11B(B), the hub node H sends the exclusive ORs R1 to R3 to all the user nodes A to D. Each user node decrypts the received exclusive ORs R1 to R3 using the messages it already has.

[0093] Specifically, user node A calculates message R B , R C and R D get.

number

[0094] User node B calculates the message R A , R C and R D get.

number

[0095] User node C calculates the message R A , R B and R D get.

number

[0096] User node D calculates the message R A , R B and R C get.

number

[0097] In this way, messages R A ~R DIn this case, as shown in FIG. 11C, one key is consumed for each of the four links. In other words, a total of four keys are consumed. This is one-fourth of the number of keys (16) consumed by the method shown in FIG. 10. In this way, the amount of keys consumed can be reduced.

[0098] 12 shows a network control device 100 that controls a network according to each of the embodiments described above. The network control device 100 includes a first instruction unit 110 that issues instructions to each user node, and a second instruction unit 120 that issues instructions to the hub node H. In response to instructions from the first instruction unit 110, each user node performs the processing described above, and in response to instructions from the second instruction unit 120, the hub node H performs the processing described above. The network control device 100 may also include a network configuration unit 130. As described above, the network configuration unit 130 performs processing to add a virtual user node to a certain physical user node, assign at least one unit of message to the virtual user node among multiple units of messages that the physical user node originally possesses, and configure the network so that the physical user node and the virtual user node are included in multiple user nodes within the network. The network control device 100 may include a transmission unit 140. The transmission unit 140 transmits a case number (rule number) such as that shown in Table 7 to each user node and hub node.

[0099] 13 shows an example of the computer hardware configuration of the network control device 100. The hub node H includes a CPU 351, an interface device 352, a display device 353, an input device 354, a drive device 355, an auxiliary storage device 356, and a memory device 357, which are interconnected by a bus 358.

[0100] A program that realizes the functions of network control device 100 is provided by a recording medium 359 such as a CD-ROM. When recording medium 359 on which the program is recorded is set in drive device 355, the program is installed from recording medium 359 to auxiliary storage device 356 via drive device 355. Alternatively, the program does not necessarily have to be installed using recording medium 359, but can also be installed via a network. Auxiliary storage device 356 stores the installed program as well as necessary files, data, and the like.

[0101] The memory device 357 reads and stores the program from the auxiliary storage device 356 when an instruction to start the program is received. The CPU 351 realizes the functions of the network control device 100 in accordance with the program stored in the memory device 357. The interface device 352 is used as an interface for connecting to other computers via the network. The display device 353 displays a GUI (Graphical User Interface) or the like according to the program. The input device 354 is a keyboard, a mouse, or the like.

[0102] Each user node and hub node in the communication network also has a computer hardware configuration similar to that of the network control device 100.

[0103] The embodiments described above have aspects not only as an apparatus but also as a method and a computer program.

[0104] In message sharing using a secure communication network, multiple messages may be shared individually at different times, or may be shared collectively at the same time. A user node uses messages it has on hand to decode other messages from the network-coded information (the exclusive OR of multiple messages) received through a public communication channel. Although the network-coded information is made public, confidentiality is maintained because each message is kept secret from the other messages. The network control device 100 instructs the hub node H on combinations of multiple messages to be subjected to the exclusive OR operation so that each user node can decode other messages using messages it already has. The embodiments described above make it possible to reduce the total consumption of keys in a secure communication network by replacing part of the encryption transmission of messages using a key (secret random number sequence) with the disclosure of network-encoded information (the exclusive OR of multiple messages) and the subsequent recovery of the messages.

[0105] [Load balancing] As described with reference to FIG. 2B, the network NW4A has a problem in that the use of the secret random number sequence is biased toward a particular link, causing the load to be concentrated on that link.

[0106] Therefore, we consider distributing the load of consuming the secret random number sequence. Figure 14A(A) shows a network NW4C. This network NW4C has the same topology as the network NW4A shown in Figure 2B.

[0107] As shown in FIG. 14A(A) to (D), each of user nodes A, B, C, and D has a message R A , R B , R C , R D Let K be the secret random number sequence assigned to each link. HA , K. HB , K. HC , K. HD After encrypting the message using the secret random number sequence, the message is sent to the hub node H. In parallel, each user node encrypts the message using the secret random number sequence and sends it to the neighboring user nodes on both sides. As also shown in FIG. 14A(A) to (D), the hub node H sends a message R Ais concealed using a key and sent to user node B, and a message R B is encrypted using a key and sent to user node A, and message R C is encrypted using a key and sent to user node D, and a message R D is anonymized using a key and sent to user node C.

[0108] In this way, the sharing of four messages is completed. At this time, as shown in FIG. 14B, two keys are consumed on each of the eight links, and the consumption load is distributed among the links. However, the total number of keys consumed is 16, which is an increase from the 12 shown in FIG. 2B. In other words, compared to network NW4A shown in FIG. 2B, in network NW4C, the load of consuming secret random number sequences is distributed, but the total number of secret random number sequences consumed is increased.

[0109] Also in the network NW6A shown in FIG. 3, the load of key consumption is concentrated on the links connecting user nodes.

[0110] In consideration of the above problems, an embodiment will be described that aims to distribute the load while suppressing the consumption of keys. Figure 15A(A) shows a network NW44, whose topology is the same as that of the network NW4A shown in Figure 2B. As shown in FIGS. 15A(A) to 15A(D), each of user nodes A to D has a message R A , R B , R C , R D Let K be the secret random number sequence assigned to each link. HA , K. HB , K. HC , K. HD After encrypting the messages using the secret random number sequence, each user node sends the messages to the users on either side of it. At this stage, the number of secret random number sequences consumed is 12, and the messages held by each user node and hub node are shown in Figure 15B(A). In other words, hub node H holds all four messages, and user node A holds only three messages R. A , RC and R D User node B receives three messages R B , R C and R D User node C receives three messages R A , R B and R C User node D receives three messages R A , R B and R D holds the following.

[0111] Next, as shown in FIG. 15B(B), the hub node H sends the four messages (R A , R B , R C , R D ) and calculate the exclusive OR R as follows:

number

[0112] In this way, the load of consuming and replenishing the secret random number sequence used when sharing messages using a secret communication network can be distributed from a specific transmission link to other transmission links without increasing the total consumption of the secret random number sequence, which improves the availability and convenience of the secret communication network for key sharing.

[0113] 16A shows a network NW65. This network NW65 has the same topology as the network NW6A shown in FIG. As shown in FIG. 16(A), user node A sends message R A The user node A sends the message R to the hub node H after encrypting it with a key. A The hub node H sends the message R A In this way, the message R is sent between the five user nodes A, C, F, E, and D. A is securely shared. Five secret random number sequences have been consumed so far.

[0114] Message R B ~R F The same procedure is followed for sharing, namely: As shown in FIG. 16(B), user node B receives message R B The user node B sends the message R to the hub node H after encrypting it with a key. B The hub node H sends the message R B In this way, the message is shared securely among the five user nodes. As shown in FIG. 16(C), user node C sends message R C The user node C sends the message R to the hub node H after encrypting it with a key. C The hub node H sends the message R C In this way, the message is shared securely among the five user nodes. As shown in FIG. 16(D), user node D sends message R DThe user node D sends the message R to the hub node H after encrypting it with a key. D The hub node H sends the message R D In this way, the message is shared securely among the five user nodes. As shown in FIG. 16(E), user node E sends message R E The user node E sends the message R to the hub node H after encrypting it with a key. E The hub node H sends the message R E In this way, the message is shared securely among the five user nodes. As shown in FIG. 16(F), user node F sends message R F The user node F sends the message R to the hub node H after encrypting it with a key. F The hub node H sends the message R F In this way, the message is shared securely among the five user nodes. In this way, each of the six user nodes A to F receives five messages, and the hub node H receives all six messages.

[0115] The hub node H then computes the exclusive OR R of the six messages as follows:

number

number

[0116] In this way, all user nodes have completed sharing of the six messages. The number of secret random number sequences consumed in the entire network is 30, which is the same as when no load balancing is performed (Fig. 3(G)). On the other hand, as shown in Fig. 16(G), the consumption load is distributed to the links connecting user nodes and the links connecting user nodes and hub nodes.

[0117] The network control device 100 shown in FIG. 12 can also achieve load distribution while suppressing an increase in the amount of key consumption.

[0118] The first instruction unit 110, second instruction unit 120, network configuration unit 130, and transmission unit 140 within the network control device 100 may be located in the same physical node, or may be distributed across multiple physically different nodes.

[0119] The following notes are provided regarding the embodiments described above. [Appendix 1] A network control device in a network including a plurality of user nodes, a hub node, and a plurality of links connecting each of the plurality of user nodes to the hub node, the network control device comprising: a first instruction unit that issues an instruction to the user node; a second instruction unit that issues an instruction to the hub node; Equipped with the first instruction unit instructs each of the plurality of user nodes to perform a step of encrypting a message held by the user node using a key assigned to the link connecting the user node and the hub node, and transmitting the ciphertext to the hub node; The second instruction unit instructs the hub node to: decrypting the ciphertexts received from the user nodes using the key to obtain the messages; determining a combination of two or more of the acquired messages based on a predetermined rule, and calculating an exclusive OR of the two or more messages relating to the combination; transmitting the exclusive OR to each of the plurality of user nodes; Instruct them to do the following: the first instruction unit further instructs each of the plurality of user nodes to perform a step of decrypting the exclusive OR using a message held by the user node; Network control device. [Appendix 2] the network further comprising a link connecting two of the user nodes; the first instruction unit further instructs one of the two user nodes to perform a step of encrypting a message held by the one user node using a key assigned to the link connecting the one user node and the other of the two user nodes, and transmitting the ciphertext to the other user node. 2. The network control device according to claim 1. [Appendix 3] 3. The network control device according to claim 1, further comprising a network configuration unit that adds a virtual user node to a physical user node that has a plurality of units of messages, and assigns at least one unit of message among the plurality of units of messages that the physical user node has to the virtual user node, thereby configuring the network so that the physical user node and the virtual user node are included in the plurality of user nodes. [Appendix 4] a transmitting unit that transmits a plurality of rules including the predetermined rule to each of the plurality of user nodes and the hub node; the second instruction unit instructs each of the plurality of user nodes to transmit a rule number indicating which of the plurality of rules the predetermined rule is and the exclusive OR, 4. The network control device according to claim 1, wherein the network control device is a [Appendix 5] 5. The network control device according to claim 1, wherein the first instruction unit and the second instruction unit are present in physically different nodes. [Appendix 6] A network control device according to any one of Supplementary Notes 1 to 5; the plurality of user nodes; the hub node; a plurality of links respectively connecting each of the plurality of user nodes to the hub node; A network comprising:

[0120] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments, and various modifications and changes can be made based on the technical concept of the present invention. [Explanation of symbols]

[0121] QM QKD module TN Trusted Node KM Key Manager CT QKDN Controller MG1 QKDN Manager MG2 Network Manager UD user terminal A~F User nodes H Hub Node 100 control device 110 1st instruction section 120 2nd instruction section 130 Network Configuration Section 140 Transmitter

Claims

1. A network control device in a network including a plurality of user nodes, a hub node, and a plurality of links connecting each of the plurality of user nodes to the hub node, the network control device comprising: a first instruction unit that issues an instruction to the user node; a second instruction unit that issues an instruction to the hub node; Equipped with the first instruction unit instructs each of the plurality of user nodes to perform a step of encrypting a message held by the user node using a key assigned to the link connecting the user node and the hub node, and transmitting the ciphertext to the hub node; The second instruction unit instructs the hub node to: decrypting the ciphertexts received from the user nodes using the key to obtain the messages; determining a combination of two or more of the acquired messages based on a predetermined rule, and calculating an exclusive OR of the two or more messages relating to the combination; transmitting the exclusive OR to each of the plurality of user nodes; Instruct them to do the following: the first instruction unit further instructs each of the plurality of user nodes to perform a step of decrypting the exclusive OR using a message held by the user node. Network control device.

2. the network further comprising a link connecting two of the user nodes; the first instruction unit further instructs one of the two user nodes to perform a step of encrypting a message held by the one user node using a key assigned to the link connecting the one user node and the other of the two user nodes, and transmitting the ciphertext to the other user node. The network control device according to claim 1 .

3. 3. The network control device according to claim 1, further comprising a network configuration unit that adds a virtual user node to a physical user node that holds a plurality of units of messages, and assigns at least one unit of message from the plurality of units of messages held by the physical user node to the virtual user node, thereby configuring the network so that the physical user node and the virtual user node are included in the plurality of user nodes.

4. a transmitting unit that transmits a plurality of rules including the predetermined rule to each of the plurality of user nodes and the hub node; the second instruction unit instructs each of the plurality of user nodes to transmit a rule number indicating which of the plurality of rules the predetermined rule is and the exclusive OR, The network control device according to any one of claims 1 to 3.

5. 5. The network control device according to claim 1, wherein the first instruction unit and the second instruction unit are present in physically different nodes.

6. A network control device according to any one of claims 1 to 5; the plurality of user nodes; the hub node; a plurality of links respectively connecting each of the plurality of user nodes to the hub node; A network comprising:

Citation Information

Patent Citations

  • Transmission system, transmission method, and transmission program

    JP2015041863A

  • Quantum encryption device, quantum cipher communication charge calculation system, and quantum cipher communication charge calculation method

    JP2021170742A

  • Information sharing system, information sharing method, information sharing device, relay device, and program

    WO2021161386A1