Signal Processing System
The signal processing system enhances security and reduces costs by leveraging quantum cryptography to secure optical fiber networks.
Patent Information
- Application Number
- JP2024514173
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-04-04
- Filing Date
- 2023-02-21
- Publication Date
- 2025-12-22
- Estimated Expiration
- 2043-02-21
AI Technical Summary
Existing methods for securing communication systems fail to adequately protect against eavesdropping at the physical layer, particularly in optical fiber networks, and lack cost-effective solutions.
A signal processing system employing Y-00 optical communication quantum cryptography, utilizing extremely multi-valued phase or amplitude modulation to obscure signal points with quantum noise, ensuring encryption is unbreakable by eavesdroppers.
Enhances security against eavesdropping by leveraging quantum noise, and reduces implementation costs, ensuring encryption is unbreakable by eavesdroppers.
Smart Images

Figure 0007789432000002 
Figure 0007789432000003 
Figure 0007789432000004
Abstract
Description
[Technical Field]
[0001] The present invention relates to a signal processing system. [Background technology]
[0002] In recent years, security measures have become increasingly important in information and communications. The network systems that make up the Internet are described by the OSI reference model established by the International Organization for Standardization. The OSI reference model separates layers from layer 1, the physical layer, to layer 7, the application layer, and the interfaces connecting each layer are standardized or de facto. The lowest layer is the physical layer, which is responsible for actually sending and receiving signals via wired and wireless connections. Currently, security measures are implemented at Layer 2 or higher using mathematical encryption in most cases, and no security measures are implemented at the physical layer. However, even at the physical layer, there is a risk of eavesdropping. Specifically, for example, in optical fiber communication, which is a representative form of wired communication, it is theoretically possible to steal a large amount of information at once by introducing a branch into the optical fiber and extracting a portion of the signal power. Therefore, the present applicant is developing a specific protocol, such as that described in Patent Document 1, as an encryption technology in the physical layer. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2012-085028 Summary of the Invention [Problem to be solved by the invention]
[0004] In the prior art including the above-mentioned Patent Document 1, by transmitting transmission information (plaintext data to be transmitted, etc.) as a multi-value optical signal according to a predetermined protocol, it is possible to take measures against eavesdropping at the physical layer using optical fiber. More specifically, as will be described in detail later, by utilizing the properties of the shot noise (noise) of the optical signal, it is possible to transmit unit information (for example, a bit string of a predetermined length) so that signals representing each unit information are indistinguishable from one another. From the viewpoint of security measures, it is desirable to enhance security not only by taking into account the properties of the shot noise (noise) of the optical signal as described above, but also by taking into account various other factors associated with it. Furthermore, if it is sufficient to achieve a certain level of security, it is desirable to adopt elements that require low implementation costs as a configuration for achieving that level of security. As such, there is a demand for improved convenience, such as improved security and reduced costs, in countermeasures against eavesdropping at the physical layer.
[0005] An object of the present invention is to improve the convenience of measures against eavesdropping at the physical layer. [Means for solving the problem]
[0006] In order to achieve the above object, a signal processing system according to one aspect of the present invention comprises: a transmitting means for modulating laser light and transmitting it as a first optical signal at a first intensity, so that N-valued (N is an integer value of 2 or more) transmission information corresponds to M (M is an integer value greater than N) symbol points according to a predetermined protocol, when an optical signal associated with a predetermined symbol point is received, the N-valued transmission information is detected as being at the same position as optical signals associated with other nearby symbol points on the IQ plane, and when an optical signal associated with a predetermined symbol point out of the M symbol points is received, the optical signal is detected as being an optical signal associated with another symbol point on the IQ plane; a receiving means for receiving the first optical signal via the path as a second optical signal; an acquisition means for acquiring a third optical signal obtained by modulating the laser for demodulation according to the predetermined protocol; a demodulation unit that demodulates the second optical signal and the third optical signal into transmission information using a demodulation method in which the second optical signal and the third optical signal are interfered with each other; A signal processing system comprising: The first intensity is less than twice the second intensity that is the lower limit at which the second optical signal can be demodulated. [Effects of the Invention]
[0007] According to the present invention, it is possible to improve the convenience of measures against eavesdropping in the physical layer. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is a block diagram showing an example of the configuration of a signal transmitting and receiving system including a signal transmitting system according to an embodiment of the signal processing system of the present invention. [Figure 2A] FIG. 2 is a diagram illustrating an outline of the principle of Y-00 optical communication quantum cryptography applied to the signal transmission system of FIG. [Figure 2B] FIG. 2 is a diagram illustrating an outline of the principle of Y-00 optical communication quantum cryptography applied to the signal transmission system of FIG. [Figure 2C] FIG. 2 is a diagram illustrating an outline of the principle of Y-00 optical communication quantum cryptography applied to the signal transmission system of FIG. [Figure 3] 2 so that the arrangement of three adjacent symbol points can be seen from the arrangement of N=4096 symbol points in the phase modulation of FIG. [Figure 4A] 1. FIG. 4 is a diagram illustrating an example of a phase modulation method in the encrypted signal decryption unit of the optical receiving device of FIG. [Figure 4B] 1. FIG. 4 is a diagram illustrating an example of a phase modulation method in the encrypted signal decryption unit of the optical receiving device of FIG. [Figure 5] 5 is a diagram illustrating an example of adjustment of output power of an optical transmitting device when decoding in the optical domain shown in FIG. 4 is adopted. [Figure 6] FIG. 10 is a diagram illustrating an example of a configuration for performing homodyne detection in decoding in the optical domain. [Figure 7]FIG. 10 is a diagram showing an example of a more suitable configuration for performing homodyne detection in decoding in the optical domain. [Figure 8] FIG. 1 is a diagram showing an example of a modulation flow for decrypting a quadrature amplitude modulated optical signal (encrypted signal). [Figure 9] FIG. 1 is a diagram illustrating an example of a configuration for performing homodyne detection in decoding a quadrature amplitude modulated optical signal in the optical domain. [Figure 10] 10 is a diagram showing an example of a configuration for performing homodyne detection in decoding a quadrature amplitude modulated optical signal in the optical domain, which is different from that shown in FIG. 9. FIG. [Figure 11] FIG. 10 is a diagram showing the relationship between the number of quantum noise masks and the PSK order after encryption. [Figure 12A] FIG. 10 is a diagram comparing examples of the configurations required for decoding in the optical domain and decoding in the electrical domain. [Figure 12B] FIG. 10 is a diagram comparing examples of the configurations required for decoding in the optical domain and decoding in the electrical domain. [Figure 13] FIG. 1 is a diagram illustrating an example of a man-in-the-middle attack by an eavesdropper. [Figure 14] FIG. 14 is a diagram showing an example of a man-in-the-middle attack by an eavesdropper, which is different from the example shown in FIG. 13. DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, an embodiment of the present invention will be described. FIG. 1 is a block diagram showing an example of the configuration of an embodiment of a signal processing system according to the present invention. The signal processing system of the example in FIG. 1 is configured to include an optical transmitter 1, an optical receiver 2, and a transmission line 3 connecting them.
[0010] The transmission data providing unit 11 generates plaintext data to be transmitted or obtains it from a generator (not shown), and provides it to the encrypted signal generating unit 13 as transmission data. The encryption key providing unit 12 provides the encryption key used for encryption in the encrypted signal generating unit 13 to the encrypted signal generating unit 13. Note that the encryption key is sufficient as long as it can be used for encryption and decryption by the optical transmitting device 1 and the optical receiving device 2, and the source (place of generation or storage), method of providing, and encryption / decryption method of the encryption key are not particularly limited. The encrypted signal generation unit 13 encrypts the transmission data provided by the transmission data provision unit 11 using the encryption key provided by the encryption key provision unit 12, and provides the encrypted data to the encrypted signal transmission unit 14, which will be described later. Note that the optical signal generated by the encrypted signal generation unit 13, i.e., the optical signal on which the encrypted transmission data is superimposed, will be referred to as the "encrypted signal" hereinafter. The encrypted signal transmitting unit 14 amplifies the encrypted signal generated by the encrypted signal generating unit 13 as necessary, and then transmits the signal to the optical receiving device 2 via the transmission path 3 .
[0011] As described above, the encrypted signal (optical signal) is output from the optical transmitting device 1, transmitted through the transmission line 3, and received by the optical receiving device 2. The optical receiving device 2 restores plaintext data (transmission data) by decrypting the received encrypted signal. To this end, the optical receiving device 2 is configured to include an encrypted signal receiving unit 21, an encryption key providing unit 22, an encrypted signal decrypting unit 23, and a received data managing unit 24.
[0012] The encrypted signal receiving unit 21 receives an encrypted signal (optical signal) and provides it to the encrypted signal decrypting unit 23 . The encryption key providing unit 22 provides the encryption key used to decrypt the encrypted signal to the encrypted signal decrypting unit 23 . The encrypted signal decryption unit 23 decrypts the encrypted signal provided from the encrypted signal reception unit 21 using the encryption key provided from the encryption key provision unit 22, thereby restoring the plaintext data (transmission data). The received data management unit 24 manages the decrypted plaintext data. The plaintext data managed by the received data management unit 24 is provided to, for example, an information processing device (not shown).
[0013] In this embodiment, the explanation will be given assuming that optical fiber communication, which is a representative example of wired communication, is adopted as the transmission path 3. In optical fiber communications, it is theoretically possible for a third party (eavesdropper) to steal a large amount of information (in this case, encrypted signals) at once by introducing a branch or the like into the optical fiber and extracting part or all of the signal power. Therefore, even if an encrypted signal is intercepted, a method is required to prevent an eavesdropper from recognizing the meaning of the encrypted signal, that is, the content of the plaintext (transmitted data). The applicant has developed a method using Y-00 optical communication quantum cryptography as such a method.
[0014] The Y-00 optical communication quantum cryptography is characterized by the fact that "the ciphertext cannot be correctly obtained due to the effect of quantum noise," and was developed by the present applicant. In Y-00 optical communication quantum cryptography, transmitted data (plaintext) is represented by a collection of one or more bit data of "0" or "1". Each bit data constituting this transmitted data is modulated to a predetermined value out of M values (M is an integer value of 2 or more) using a predetermined algorithm. Therefore, hereinafter, this number M will be referred to as the "modulation number M".
[0015] In Y-00 optical communication quantum cryptography, encryption of transmitted data (plain text) is performed by modulating at least one of the phase and amplitude of an optical signal (carrier wave), or a combination thereof, to one of the values of the modulation number M, using a cryptographic key on the encryption side and the decryption side. Here, by making the modulation number M extremely multi-valued, the characteristic that "the cipher text cannot be correctly obtained due to the effect of quantum noise" is realized.
[0016] Furthermore, encryption implemented at layer 2 or higher of the OSI reference model using the mathematical cryptography described above may be deciphered with the development of supercomputers, quantum computers, etc. However, because quantum noise is an unchanging physical phenomenon, encryption at the physical layer using quantum noise has the advantage that its security will not be compromised by future technological advances.
[0017] The following explanation assumes that Y-00 optical communication quantum cryptography is used as the "predetermined protocol" that ensures that "ciphertext cannot be correctly obtained due to the effects of quantum noise." For details of Y-00 optical communication quantum cryptography, please refer to Japanese Patent Application Laid-Open No. 2012-085028. Here, we will briefly explain the outline of the principles of Y-00 optical communication quantum cryptography by using an example in which phase modulation is used as the modulation method, with reference to Figures 2 and 3.
[0018] 2A to 2C are diagrams for explaining an outline of the principle of the Y-00 optical communication quantum cryptography applied to the signal processing system of FIG. FIG. 3 is an enlarged view of FIG. 2 so that the arrangement of three adjacent symbol points can be seen from the arrangement of M=4096 symbol points in the phase modulation of FIG. 2A to 2C, an IQ plane representing the phase and amplitude (intensity) of an optical signal is drawn, with the intersection of the vertical and horizontal axes as the origin. When a point on the IQ plane is determined, the phase and amplitude of the optical signal are uniquely determined. The phase is the angle between the line segment that starts at the origin of the IQ plane and ends at the point representing that optical signal, and the line segment that represents a phase of 0. On the other hand, the amplitude is the distance between the point representing that signal and the origin of the IQ plane.
[0019] FIG. 2A is a diagram for explaining the principle of normal binary modulation to facilitate understanding of Y-00 optical communication quantum cryptography. For example, when plaintext (transmission data) is superimposed on an optical signal (carrier wave) and transmitted as is, the binary modulation shown in FIG. 2A is performed on each bit data (1 or 0) that constitutes the plaintext. 2A, when the bit data is "0," the arrangement of points indicating the optical signal after phase modulation (hereinafter referred to as "symbol points") is the arrangement of symbol point S12 on the right side of the horizontal axis, which is set to 0 (0), i.e., an arrangement with a phase of 0. On the other hand, when the bit data is 1, the arrangement of symbol points after phase modulation is the arrangement of symbol point S11 on the left side of the horizontal axis, which is set to π (1), i.e., an arrangement with a phase of π. Here, the solid-line circle surrounding the symbol point S11 indicates an example of the range of quantum noise fluctuation when an optical signal at the symbol point S11 is received. Similarly, for the symbol point S12, an example of the range of quantum noise fluctuation is shown as a solid circle surrounding the symbol point S12.
[0020] FIG. 2B is a diagram illustrating the principle of phase modulation with a modulation number M=16 when Y-00 optical communication quantum cryptography is employed. In the example of Fig. 2B, for each bit data constituting the plaintext, one of eight random values is generated using an encryption key. Then, the phase of the symbol point (a point with a phase of 0 corresponding to 0 or a point with a phase of π corresponding to 1) of the normal binary modulation shown in Fig. 2A is rotated for each bit in the IQ plane according to the value randomly generated from the eight values using the encryption key, thereby performing phase modulation. Since the bit data can take on two values, "0" or "1," when the phase modulation in the example of Figure 2B is performed, the symbol points are arranged into 16 (modulation number M = 16) with phases that differ by (π / 8).
[0021] However, in the example of Figure 2B, the value of "0" or "1" that the bit data can take is simply modulated to one of the values of the modulation number M = 16. Therefore, if an optical signal (encrypted signal) with an arrangement of 16 symbol points is intercepted, there is a risk that its meaning, i.e., the content of the plaintext (transmitted data), can be recognized (decrypted) by an eavesdropper. In other words, the security of Y-00 optical communication quantum cryptography is not sufficient with a modulation number of about M = 16. Therefore, in practice, as shown in FIG. 2C, an extremely large number of values, for example, 4096, is adopted as the modulation number M, thereby enhancing the security of the Y-00 optical communication quantum cryptography.
[0022] FIG. 2C is a diagram illustrating the principle of phase modulation with a modulation number M=4096 when Y-00 optical communication quantum cryptography is employed. FIG. 3 is an enlarged view of FIG. 2C so that the arrangement of three adjacent symbol points can be seen among the arrangement of M=4096 symbol points in the phase modulation of FIG. 2C. As shown in Fig. 3, at each of the symbol points S21 to S23, fluctuations due to shot noise (quantum noise) occur within a range SN. Specifically, for example, the solid-line circle C surrounding the symbol point S21 shown in Fig. 3 indicates an example of the range SN of quantum noise fluctuations when an optical signal at the symbol point S21 is received.
[0023] Here, shot noise is noise caused by the quantum nature of light, and is characterized by being truly random and unavoidable by the laws of physics. As a result, when extremely multilevel phase modulation with a modulation number M of 4096 or the like is performed, adjacent symbol points become hidden by the shot noise and cannot be distinguished, as shown in Figure 3. In other words, when the distance D between two adjacent symbol points S21 and S22 is sufficiently smaller than the shot noise range SN (when an extremely multi-level phase modulation is performed with the modulation number M to make the distance D so small), it becomes difficult to determine the position of the original symbol point from the phase information measured on the receiving side.
[0024] Specifically, consider a case where the phase measured on the receiving side at a certain time corresponds to the position of symbol point S22 shown in Figure 3. In this case, there is a possibility that the measured phase was transmitted as an optical signal at symbol point S22 and had extremely small shot noise. Alternatively, there is a possibility that the measured phase was transmitted as an optical signal at symbol point S21 and was measured as a phase corresponding to the position of symbol point S22 due to the influence of shot noise. Similarly, there is a possibility that the measured phase was transmitted as an optical signal at symbol point S23 and was measured as a phase corresponding to the position of symbol point S22 due to the influence of shot noise. An eavesdropper cannot distinguish which of these possibilities is correct. As described above, in the Y-00 optical communication quantum cryptography, the modulation number M is extremely large, that is, extremely multi-value modulation is adopted.
[0025] 2 and 3 show phase modulation, but amplitude (intensity) modulation may be used instead of or in addition to phase modulation. That is, any modulation method such as intensity modulation, amplitude modulation, phase modulation, frequency modulation, or quadrature amplitude modulation may be used to modulate an optical signal using the Y-00 protocol. That is, as mentioned above, with Y-00 optical communication quantum cryptography, it is possible to make the distance D between two symbol points sufficiently smaller than the shot noise range SN in any modulation method, and it is possible to give it the characteristic that "the ciphertext cannot be correctly obtained due to the effect of quantum noise." Furthermore, as will be explained in more detail later, quantum noise ensures security, but in reality, the effects of all other "noise," including quantum noise as well as classical noise such as thermal noise, will prevent an eavesdropper from obtaining the correct ciphertext.
[0026] Next, we will discuss the security of Y-00 quantum cryptography using the mask number Γ, which is an index of security. Q This will be explained using: That is, in Y-00 quantum cryptography, the mask number Γ, which corresponds to "how many adjacent symbols are masked by shot noise," is used as an index of security. Q can be adopted.
[0027] In optical communications, when an optical signal with sufficient intensity for high-speed communication is used, the distribution of the amount of shot noise (range of fluctuation) can be approximated as a Gaussian distribution. Q is the standard deviation of the Gaussian distribution of the shot noise as the distance (radius) corresponding to the range SN of the shot noise described above in FIG. That is, hereinafter, "the number of symbol points that fall within the range of the standard deviation when the noise distribution is approximated as a Gaussian distribution" is defined as the mask number Γ. Q It is defined and explained as follows. In addition, the number of masks Γ Q The concept of is applicable to distributions other than shot noise. Q How to apply this concept will be explained later.
[0028] As described above in FIG. 2, when the distance D between two adjacent symbol points is sufficiently smaller than the shot noise range SN, it becomes difficult to determine the position of the original symbol point from the information measured at the receiving side. In other words, the number of masks Γ Q is the number of other symbol points included in the shot noise range SN. That is, the mask number Γ Q indicates the number of other symbol points whose distance D to a certain symbol point is smaller than the shot noise range SN. That is, the mask number Γ Q is a quantity proportional to the strength of the encryption of the encrypted signal.
[0029] For example, in the Y-00 quantum cryptography, when the phase modulation method is adopted, the mask number Γ Q is expressed by the following equation (1).
[0030]
number
[0031] In equation (1), N is the number of data modulation signals (the number of values of transmission information transmitted per symbol), and the number of encryption bits m is the number of multi-levels increased per data modulation signal for encryption, expressed in bits. Planck's constant h is a physical constant that is a proportional constant relating to the energy and frequency of a photon. The frequency ν0 is the frequency of the signal. The reception band B is the reception band for detection by the receiver. The quantum efficiency η q is the quantum efficiency of the receiver, and the power P0 is a number that represents the power of the signal.
[0032] Here, the number N of data modulated signals and the number m of encryption bits will be explained in association with the explanation of FIG. 2. The number N of data modulated signals, N=2, corresponds to the number of symbol points S11 and S12 in the explanation of FIG. 2A. Furthermore, multi-value encoding of the number m=11 of encryption bits means multi-value encoding of one symbol point into 2 to the power of 11 (=2048) symbol points. In other words, this corresponds to increasing each of the two symbol points S11 and S12 in the explanation of FIG. 2C to 2 to the power of 11 (=2048) and transmitting them as symbol points with a modulation number M=4096.
[0033] Number of masks Γ Q When this value is sufficiently large, shot noise masking works. In other words, Y-00 quantum cryptography works effectively as a cryptosystem. Specifically, for example, when this value is 1 or more, the effect of shot noise masking is exerted, and when it is a sufficiently large value, even higher security is achieved. Here, looking at equation (1), the number of masks Γ Q is inversely proportional to the square root of the power P0. In other words, when the power P0 of the carrier wave is small, the mask number Γ Q In other words, increasing the number of signal levels and reducing the signal power to a level that does not affect communication quality can lead to improved security. As will be described in detail later, the present invention is Q By focusing on the power P0 that affects the transmission speed, it is possible to improve safety and convenience by reducing costs in countermeasures against eavesdropping at the physical layer.
[0034] As mentioned above, the noise of the optical signal varies depending on the characteristics of the transmission path of the optical signal, the surrounding environment, etc. That is, as masking by noise, the above-mentioned mask number Γ Q In addition, any noise may be included, including noise of the optical signal that fluctuates depending on the characteristics of the transmission path of the optical signal, the surrounding environment, and classical noise such as thermal noise. In other words, the mask number Γ related to the shot noise described in the above formula (1) Q The number of masks due to classical noise other than Γ CThen, the number of masks is Γ Q +Γ C This becomes: Specifically, for example, in addition to the noise due to the above-mentioned shot noise, the number of symbol points included in the range of classical noise such as signal fluctuations in the generation of the optical signal (encryption signal) and thermal noise due to the surrounding environment may be used.
[0035] To summarize the above, if the distance between two adjacent symbol points is sufficiently smaller than the range of all noises, including classical noise such as thermal noise, signal secrecy can be achieved by masking. Here, when an optical signal transmitted from the optical transmitter 1 is received, the mask number Γ related to shot noise is Q If is 1 or more, the ciphertext cannot be correctly obtained due to the effect of quantum noise. C The mask number Γ related to the shot noise leaves the possibility that an eavesdropper can reduce it by some means. Q is impossible to reduce in principle and plays an important role in guaranteeing a lower limit of safety.
[0036] Next, the present invention is realized by utilizing the difference in conditions for decrypting an optical signal (encrypted signal) between a legitimate receiver (the person who installed the receiving device 2 in Figure 1) and an eavesdropper (someone who extracts part or all of the signal power from the transmission path 3 in Figure 1 and attempts to decrypt the encryption).
[0037] That is, as described above, encryption is achieved in the optical transmitting device 1 by converting a signal phase-modulated with a modulation factor M=2 shown in FIG. 2A into a signal phase-modulated with a modulation factor M=4096 shown in FIG. 2C. In contrast, decoding is achieved in the optical receiving device 2 by converting a signal phase-modulated with a modulation factor M=4096 shown in FIG. 2C into a signal phase-modulated with a modulation factor M=2 shown in FIG. 2A. More specifically, the optical signal (encrypted signal) is decoded by applying modulation in the opposite direction to the phase modulation amount (magnitude and direction) used for each symbol at each time when increasing the modulation number M from 2 to 4096 in the optical transmitting device 1 in the optical receiving device 2. Thus, the modulation for decoding can be implemented as follows:
[0038] 4A and 4B are diagrams showing examples of a phase modulation method in the encrypted signal decryption unit of the optical receiving device of FIG. FIG. 4A shows an encrypted signal decryption unit 23A that employs a method of performing decryption in the optical domain in the encrypted signal decryption unit 23 of the optical receiving device 2 of FIG. FIG. 4B shows an encrypted signal decryption unit 23B that employs a method of performing decryption in the electrical domain in the encrypted signal decryption unit 23 of the optical receiving device 2 of FIG.
[0039] First, the encrypted signal decryption unit 23A shown in FIG. 4A, which employs a method for performing decryption in the optical domain, will be described. Decoding in the optical domain refers to obtaining decoded data by detecting (receiving) an optical signal decoded by applying phase modulation to the optical signal (encrypted signal). That is, the encrypted signal decryption unit 23A employing a method of performing decryption in the optical domain includes an optical decryption unit 111 and a detection unit 112. The optical decryption unit 111 has a code generation unit that generates a code using a key provided by the encryption key providing unit 22, and an optical phase modulator that performs modulation based on the code generated by the code generation unit.
[0040] The encryption generator will now be described. Although not shown, the encryption generator also includes the encryption signal generator 13 of the optical transmitter 1. The "code" generated by the code generator corresponds to the amount of phase modulation (magnitude and direction) used for each symbol at each time based on a code key in accordance with a predetermined protocol. That is, the encrypted signal generating unit 13 of the optical transmitting device 1 generates an optical signal (encrypted signal) by performing phase modulation based on the cipher generated by the cipher generating unit. In contrast, in the encrypted signal decryption unit 23 (here, the encrypted signal decryption unit 23A) of the optical receiving device 2, the optical signal (encrypted signal) is decrypted by applying phase modulation in the opposite manner to that of the optical transmitting device 1 based on the code generated by the code generation unit.
[0041] In this way, in the optical decoding section 111 of the encrypted signal decoding section 23A, decoding is performed in the optical domain by the optical phase modulator based on the code generated by the code generating section. The detector 112 detects the decoded optical signal and outputs the decoded digital data.
[0042] As described above, when phase modulation, particularly BPSK, is used, the detection unit 112 employs the homodyne method. Furthermore, when IQ data modulation of QPSK or higher is used, methods such as heterodyne detection, phase diversity homodyne detection, or phase diversity intradyne detection are employed.
[0043] Next, the encrypted signal decryption unit 23B shown in FIG. 4B, which employs a method for performing decryption in the electrical domain, will be described. Decryption in the electrical domain refers to detecting (receiving) an optical signal (encrypted signal), and then decoding the detected and digitized information by applying phase modulation using digital signal processing to obtain decrypted data. That is, the encrypted signal decryption unit 23B employing a method of performing decryption in the electrical domain includes a detection unit 121 and an electrical decryption unit 122.
[0044] The detector 121 detects the optical signal (encrypted signal) and converts the position of the optical signal (encrypted signal) on the IQ plane directly into digital data.
[0045] The electrical decryption unit 122 has a code generation unit that generates a code using a key provided by the encryption key providing unit 22, and a digital signal processing circuit that performs modulation based on the code generated by the code generation unit. The function of the code generator is the same as that of the optical decoder 111 described above.
[0046] In Figure 4B, "×exp(jθ)" indicates that the position on the IQ plane of the optical signal (encrypted signal) stored as digital data, which is the result of detecting the optical signal (encrypted signal), is rotated by a phase angle of θ. That is, in the electrical decoding unit 122 of the encrypted signal decoding unit 23B, the position on the IQ plane of the optical signal (encrypted signal), which is the result of detecting the optical signal (encrypted signal), is phase-converted by digital signal processing, thereby decoding in the electrical domain (digital electrical signal domain).
[0047] Thus, when performing detection for demultiplexing in the electrical domain, the position of the optical signal (encrypted signal) on the IQ plane must be directly converted into digital data in the detection unit 121. For this reason, the detection unit 121 employs a method capable of acquiring both I and Q information, such as heterodyne detection, phase diversity homodyne detection, or phase diversity intradyne detection.
[0048] In this way, both approaches to decrypting an optical signal (encrypted signal) are possible: decryption in the optical domain and decryption in the electrical domain. However, by actively adopting decryption in the optical domain, the security of the encryption can be improved by utilizing the difference in reception performance between the authorized receiver and the eavesdropper.
[0049] In other words, since an eavesdropper does not have the key that the legitimate receiver has, he or she must decrypt the data after eavesdropping. Therefore, when eavesdropping, IQ simultaneous detection, typically heterodyne detection, is first performed, and then decryption is attempted using digital signal processing. This is basically the same process as the electrical domain decoding described above.
[0050] In contrast, the authorized receiver has the key and does not need to decrypt the data afterwards. In other words, the data can be decoded in the optical domain before detection. This makes it possible to use a detection method with better reception sensitivity than IQ simultaneous detection, such as heterodyne detection. This is nothing other than the above-mentioned optical domain decoding. Specifically, for example, as the most practical method, when the data modulation is BPSK, the regular receiver can employ homodyne detection as the detection unit after decoding in the optical domain.
[0051] In a system dominated by shot noise, the receiver sensitivity of homodyne detection is about 3 dB better than that of IQ simultaneous detection such as heterodyne detection, meaning that the same error rate can be achieved with roughly half the receive power.
[0052] That is, consider the cipher-decryption unit 23A shown in Fig. 4A, which employs optical domain decoding and homodyne detection, and the cipher-decryption unit 23B shown in Fig. 4B, which employs heterodyne detection and electrical domain decoding. In this case, the receiving power required to achieve the same error rate on the receiving side is approximately 3 dB lower for the cipher-decryption unit 23A employing homodyne detection.
[0053] In other words, consider a case where an optical signal (encrypted signal) is transmitted so that the error rate for the authorized receiver does not change. In this case, in the encryption / decryption unit 23A, the signal power required on the receiving side is half that of the encryption / decryption unit 23B, and therefore the power output on the transmitting side can also be halved.
[0054] As shown in the above equation (1), when the signal power P0 is halved, the number of masks becomes the root of 2. In other words, when the legitimate receiver performs decoding and homodyne detection in the optical domain, the number of masks for an eavesdropper becomes the root of 2.
[0055] In this way, since the authorized receiver already has the key, the optical receiver 2 can employ optical domain decryption and homodyne detection, which has better reception sensitivity than IQ simultaneous detection (heterodyne detection, etc.). This allows the signal power on the transmitting side to be reduced, thereby increasing the security of the encryption.
[0056] Therefore, unless otherwise specified, the following description will be given assuming that the encrypted signal decryption unit 23 of the optical receiving device 2 employs decryption in the optical domain and has a detection unit that employs homodyne detection or the like, which has good reception sensitivity.
[0057] Furthermore, with reference to FIG. 5, it will be explained that a different level of security can be achieved by performing decoding in the optical domain using homodyne detection. FIG. 5 is a diagram showing an example of adjustment of output power of the optical transmitting device when the decoding in the optical domain shown in FIG. 4 is adopted.
[0058] In the example of FIG. 5, only the encrypted signal decryption unit 23 of the optical receiving device 2 in the signal processing system of FIG. 1 is shown. Here, the signal power Pmin is used as the signal power input to the detection unit, which is the minimum signal power required for demodulation using homodyne detection. The signal power output from the optical transmitter 1 is set to less than 2Pmin.
[0059] This provides the following effects. In other words, extremely high security against eavesdropping (security comparable to or superior to information-theoretic security) can be achieved.
[0060] Here, information-theoretically secure means that the decryption result obtained by any key is equally likely, and therefore it is impossible to decrypt the code no matter how much computational power is used. The term "information-theoretic security" is usually used in encryption that uses mathematical bit manipulation, and is not a term commonly used in encryption that protects signals using the physical properties of optical signals, as in this optical signal processing system. By combining this encryption with appropriate encoding, it is expected that information-theoretic security will be achieved. Furthermore, as shown below, it is possible to achieve an excellent feature that is qualitatively different from information-theoretic security: security is guaranteed even if the key is subsequently disclosed.
[0061] As described above, an eavesdropper eavesdrops on an optical signal (encrypted signal) by extracting part or all of the signal power from the transmission line 3. Also, as described above, an eavesdropper attempts to decrypt (attempt to decipher) the signal in the electrical domain, which requires simultaneous IQ detection (heterodyne detection, etc.). As mentioned above, IQ simultaneous detection (heterodyne detection, etc.) has the property that the receiving sensitivity is about 3 dB worse (half as much) than homodyne detection. In other words, to correctly detect with IQ simultaneous detection (heterodyne detection, etc.), a signal power 3 dB greater (twice as much) than with homodyne detection is required. However, even if an eavesdropper extracts all of the signal power from the transmission path 3, the signal power will be less than 2Pmin. In other words, the signal power extracted by the eavesdropper will be below the minimum receiving sensitivity of IQ simultaneous detection (heterodyne detection, etc.).
[0062] This achieves extremely high security against eavesdropping (security comparable to or superior to information-theoretic security). As a result, if an eavesdropper were to obtain the key after IQ simultaneous detection (heterodyne detection, etc.), the eavesdropper would attempt to decrypt the data using digital signal processing with the correct key, but no matter what kind of digital signal processing was performed on the position on the IQ plane of the optical signal (encrypted signal) detected below the minimum receiving sensitivity, the correct data would not be restored. This is a characteristic not found in conventional mathematical cryptography such as AES. Furthermore, even in one-time pad encryption (a cryptography in which a key is used for each bit, which can achieve information-theoretic security), a situation in which the key is obtained after the fact (a situation in which the key cannot be properly discarded) is not anticipated, and this is an advantageous feature that can be realized by this cryptography.
[0063] Here, the conditions that must be met when decoding in the optical domain is actually performed are summarized. First, there is a condition that the optical transmission loss in the transmission line 3, etc. must be kept below 3 dB. This condition is usually met when the transmission line 3 is sufficiently short. Furthermore, research into realizing a transmission line 3 with little signal loss has been ongoing for some time, and further improvements in performance are expected.
[0064] Another condition is that the signal processing system does not use an optical amplifier. This condition is met, as with the above condition, because there is no need to use an optical amplifier when the transmission line 3 is sufficiently short.
[0065] The second condition is that the effect of chromatic dispersion must be suppressed to a level that allows decoding in the optical domain. Here, chromatic dispersion refers to dispersion caused by differences in signal transmission speed within the transmission path 3 due to differences in wavelength. In other words, when an optical signal occupying a certain wavelength band is transmitted, chromatic dispersion causes differences in the arrival time of the optical signal within the transmission path 3, etc. This causes distortion in the time waveform of the optical signal. As described above, when decoding in the optical domain, phase modulation is performed by an optical phase modulator or the like. Consider a case where an optical signal (encrypted signal) is transmitted from the optical transmitter 1, is affected by chromatic dispersion in the transmission path 3, and is then decoded directly in the optical domain by the optical receiver 2. In this case, a portion of the optical signal with a distorted time waveform spans over adjacent time slots, and this portion of the signal is not phase-modulated correctly for decoding. Therefore, it is necessary to suppress the influence of chromatic dispersion to a level that allows decoding in the optical domain.
[0066] Chromatic dispersion is a linear phenomenon, so compensation can be achieved by applying a filter with inverse characteristics on the optical transmitter 1 side in accordance with the chromatic dispersion characteristics of the transmission line 3. Specifically, for example, in the optical transmitter 1, this problem can be solved by, in addition to the phase modulation for encryption, performing optical modulation with an electrical signal that has been filtered in an electrical stage according to the chromatic dispersion characteristics of the transmission line 3. Alternatively, for example, this problem can be solved by using a dispersion compensator such as a dispersion compensation fiber to restore the chromatic dispersion that has occurred.
[0067] Furthermore, the loss of signal power during decoding in the optical domain must be sufficiently low, i.e., the sum of the optical transmission loss in the transmission line 3 and the signal power loss during decoding in the optical domain must be less than 3 dB.
[0068] In the following, a method for achieving sufficiently low signal power loss during decoding in the optical domain will be described.
[0069] FIG. 6 is a diagram showing an example of a configuration for performing homodyne detection in decoding in the optical domain. FIG. 6 shows an example of a specific configuration of an optical decoding unit 111 that performs decryption in the optical domain and a detection unit 112 that performs homodyne detection, both of which are included in the encrypted signal decoding unit 23A of FIG. 4A. The optical decoding unit 111 in FIG. 6 includes a code generation unit and an optical phase modulator, as described above in the description of FIG. 4A. That is, the encrypted signal decryption unit 23A in FIG. 6 performs phase modulation on the optical signal (encrypted signal) in the optical decryption unit 111.
[0070] The detection unit 112 in FIG. 6 has a laser 131, a beam splitter 132, and a balanced PD (Photo Diode) 133 as a configuration for performing homodyne detection. That is, the laser 131 in FIG. 6 generates local light of a frequency for homodyne detection. The beam splitter 132 causes the optical signal (decoded signal) that has been phase-modulated in the optical decoding unit 111 to interfere with the local light generated by the laser 131 . The balance PD 133 outputs binary data based on the difference between the two optical signals interfered by the beam splitter 132 .
[0071] This realizes the decoding in the optical domain, as explained using Fig. 4A etc. However, the optical decoding unit 111 in Fig. 6 performs phase modulation on the optical signal (encrypted signal). That is, phase modulation in an optical phase modulator typically causes signal attenuation in the optical signal.
[0072] As described above, the sum of the optical transmission loss in the transmission line 3 and the like and the loss of signal power in decoding in the optical domain must be less than 3 dB. Therefore, there is a disadvantage that the allowable optical transmission loss in the transmission line 3 becomes smaller because a loss of signal power occurs during decoding in the optical domain.
[0073] This disadvantage can be eliminated by adopting the configuration shown in FIG. FIG. 7 is a diagram showing an example of a more suitable configuration for performing homodyne detection in decoding in the optical domain.
[0074] Figure 7 shows an example of a more suitable specific configuration of the encrypted signal decryption unit 23C, which is different from the encrypted signal decryption unit 23 shown in Figures 4A and 4B (encrypted signal decryption units 23A and 23B in Figure 4) and has a configuration for performing decryption in the optical domain and a configuration for performing homodyne detection. The encrypted signal decryption unit 23C of FIG. 7 includes a laser 141, an optical phase modulator 142, a code generation unit 143, a beam splitter 144, and a balanced PD 145.
[0075] That is, the laser 141 in FIG. 7 generates a local frequency light for homodyne detection. The optical phase modulator 142 modulates the local light generated by the laser 141 based on the code generated by the code generator 143 . The function of the cipher generation unit 143 is the same as that of the optical decryption unit 111 in FIG. 4A. The beam splitter 144 causes interference between the optical signal (encrypted signal) and the optical signal obtained by modulating the local light by the optical phase modulator 142 . The balance PD 145 outputs binary data based on the difference between the two optical signals interfered by the beam splitter 144 .
[0076] Here, the output of homodyne detection is the product of the electric fields of the signal light (here, the encryption signal) and the local light. Therefore, by modulating the phase of the local light generated by the laser 141, it is possible to obtain the same effect as by reverse-rotating the phase of the signal light (encryption signal).
[0077] This allows decoding in the optical domain. The configuration shown in FIG. 7 is preferable to the configuration shown in FIG. 6 in the following respects. 7, the optical signal (encrypted signal) is not phase-modulated, and therefore the optical signal (encrypted signal) does not pass through the optical phase modulator, and therefore the optical signal (encrypted signal) is not attenuated. As a result, no loss of signal power occurs during decoding in the optical domain, and therefore the disadvantage of a reduction in the allowable optical transmission loss in the transmission line 3 does not occur.
[0078] In actual operation, the frequency of the local light laser must be the same as that of the signal light. In addition to the configuration shown in Figure 7, it is preferable to employ a feedback mechanism such as a PLL, or a mechanism for synchronizing by sending a carrier light as a clock together with the signal light and injecting it into the local light laser.
[0079] 7, it is possible to reduce the loss of signal power during decoding in the optical domain, which is one of the conditions that must be met when actually performing decoding in the optical domain. As a result, decoding in the optical domain can be achieved even in an environment where the optical transmission loss in the transmission path 3 is large.
[0080] Here, a supplementary explanation will be given of the difference between homodyne detection and heterodyne detection. In FIGS. 6 and 7, the encrypted signal decryption units 23A and 23C have a laser, a beam splitter, and a balanced PD as a configuration for homodyne detection. However, both homodyne detection and heterodyne detection have this configuration. The difference between homodyne detection and heterodyne detection is the frequency of the local light generated by the laser.
[0081] That is, in homodyne detection, the local oscillator frequency and the signal frequency are set to the same frequency, and as a result, in homodyne detection, only one side of the IQ components is acquired as a signal in the band B / 2. In heterodyne detection, the difference between the local oscillator frequency and the signal frequency is set to be greater than half of band B. This allows both the I and Q components to be acquired as signals in band B (I and Q simultaneous detection). In this way, in homodyne detection, the bandwidth is half that of heterodyne detection, and therefore the effect of shot noise is half. As mentioned above, the effect of shot noise is halved, so even if half the signal power of heterodyne detection is used in homodyne detection, the SNR will be the same.
[0082] Up to this point, we have explained an example in which phase modulation is used as a modulation method for optical signals (encrypted signals, etc.), but we will now explain an example in which it is applied to quadrature amplitude modulation (QAM) using Figure 8. FIG. 8 is a diagram showing an example of a modulation flow for decrypting a quadrature amplitude modulated optical signal (encrypted signal).
[0083] In quadrature amplitude modulation, simultaneous I / Q detection is usually performed. However, if the data modulation is BPSK and the signal is multi-valued so that homodyne detection can be performed after decoding in the optical domain, the above-mentioned optical domain decoding process can also be applied to optical signals (encrypted signals) that employ quadrature amplitude modulation.
[0084] The shaded rectangles in Figure 8(A) show how signals are distributed throughout the IQ plane due to the highly multi-level quadrature amplitude modulation. One bit (one or zero) at a given time is represented by two circles and a line connecting them. FIG. 8B shows an example in which the phase of one bit at a certain time shown in FIG. 8A is rotated around the origin. FIG. 8C shows an example in which the amplitude is shifted for the optical signal that has been subjected to phase rotation around the origin shown in FIG. 8B.
[0085] As a result, the position on the IQ plane of the signal shown in Fig. 8(C) is the same as that shown as data (binary) in Fig. 7 etc. In other words, the signal is capable of homodyne detection.
[0086] In the explanations up to Fig. 7, only phase modulation is performed using one phase modulation element in decoding in the optical domain. However, when decoding in the optical domain for a quadrature amplitude modulated optical signal (encrypted signal), it cannot be achieved with one phase modulation element and it is necessary to use the modulators shown in Fig. 9 or 10. FIG. 9 is a diagram showing an example of a configuration for performing homodyne detection in decoding a quadrature amplitude modulated optical signal in the optical domain. The encrypted signal decryption unit 23D of FIG. 9 includes a laser 151, an optical phase modulator 152, a Mach-Zehnder modulator 153, a code generation unit 154, a beam splitter 155, and a balanced PD 156.
[0087] That is, the functions of the laser 151, the cipher generator 154, the beam splitter 155, and the balance PD 156 in FIG. 9 are similar to those of the laser 141, the cipher generator 143, the beam splitter 144, and the balance PD 145 in FIG. 7, respectively.
[0088] That is, the encrypted signal decryption unit 23D in the example of FIG. 9 differs from the encrypted signal decryption unit 23C shown in FIG. 7 in the following points. Specifically, instead of the optical phase modulator 142 in the above, an optical phase modulator 152 and a Mach-Zehnder modulator 153 are employed.
[0089] The Mach-Zehnder modulator 153 is a modulator with an interferometer structure that splits an input optical signal into two, modulates the phase of each of the split optical signals using an optical phase modulator, and causes the two modulated optical signals to interfere with each other. The Mach-Zehnder modulator 153 can perform amplitude modulation. That is, by using the optical phase modulator 152 and the Mach-Zehnder modulator 153 in combination, both the phase rotation around the origin and the amplitude shift in the description of FIG. 8 can be realized. The white arrows drawn from the code generator 154 to the optical phase modulator 152 and the Mach-Zehnder modulator 153 indicate that they are controlled based on the code generated by the code generator 154. That is, the optical phase modulator 152 and the Mach-Zehnder modulator 153 cooperate to perform modulation based on the code generated by the code generator 154, thereby modulating the local oscillator light generated by the laser 151. The order of the optical phase modulator 152 and the Mach-Zehnder modulator 153 is not limited to the example in FIG. 9, and they may be used in the reverse order.
[0090] FIG. 10 is a diagram showing an example of a configuration for performing homodyne detection in decoding a quadrature amplitude modulated optical signal in the optical domain, which is different from that shown in FIG. The encrypted signal decryption unit 23E of FIG. 10 includes a laser 161, an IQ modulator 162, a code generation unit 163, a beam splitter 164, and a balanced PD 165.
[0091] That is, the functions of the laser 161, the code generator 163, the beam splitter 164, and the balance PD 165 in FIG. 10 are similar to those of the laser 141, the code generator 143, the beam splitter 144, and the balance PD 145 in FIG. 7, respectively.
[0092] That is, the encrypted signal decryption unit 23E in the example of FIG. 10 differs from the encrypted signal decryption unit 23C shown in FIG. 7 in the following points. Specifically, an IQ modulator 162 is employed in place of the optical phase modulator 142 in the first embodiment.
[0093] The IQ modulator 162 is a modulator with an interferometer structure that splits an input optical signal into four, modulates the phase of each of the split optical signals using an optical phase modulator, and causes the four modulated optical signals to interfere with each other. The IQ modulator 162 is capable of performing IQ modulation. That is, by using the IQ modulator 162, IQ modulation including both phase rotation around the origin and amplitude shift in the description of FIG. 8 can be realized by a single IQ modulator. The white arrows drawn from the code generator 163 to each phase modulation element of the IQ modulator 162 indicate that they are controlled based on the code generated by the code generator 163. That is, the optical phase modulation elements of the IQ modulator 162 cooperate to perform modulation based on the code generated by the code generator 163, thereby IQ modulating the local light generated by the laser 161.
[0094] As explained using Figures 9 and 10, by selecting an appropriate modulation element, the decoding and homodyne detection in the optical domain explained using Figure 7 can also be applied to optical signals (encrypted signals) using modulation methods other than phase modulation.
[0095] Here, the merit of modulating the local light for homodyne detection generated from a laser, rather than the optical signal (encrypted signal) as explained with reference to FIGS. 7, 9, 10, etc., will be described.
[0096] That is, when modulating an optical signal (encrypted signal), there are disadvantages such as attenuation of the optical signal (encrypted signal) by a modulation element or the like, and the influence of various noises. In contrast, in this embodiment, as described above, the optical signal (encrypted signal) is not modulated, and therefore is not attenuated by a modulation element or the like. This allows the signal power of the input optical signal (encrypted signal) to be maintained. In other words, the optical receiving device 2 can reduce the influence of other noises, such as thermal noise, on the optical signal (encrypted signal). Furthermore, there is no loss of signal power due to passing through a modulation element for decoding in the optical domain. As a result, decoding in the optical domain can be realized even in an environment where the optical transmission loss in the transmission line 3 is large.
[0097] Furthermore, detectors such as balanced photodiodes have an upper limit on input power. Therefore, it is difficult to increase the signal power of the local light beyond a certain level in order to improve sensitivity. In other words, not attenuating the optical signal (encryption signal) is an important factor in preventing a decrease in sensitivity in homodyne detection.
[0098] Furthermore, when modulating an optical signal (encrypted signal) in the encrypted signal decryption unit 23A shown in Figure 6, the modulator (optical phase modulator, etc.) must be polarization-independent. In contrast, typical coherent receiving optical circuits for homodyne / heterodyne or phase diversity / intradyne detection, which are composed of optical couplers, have a polarization diversity configuration, so when modulating local light, it is sufficient to modulate only one polarization. This makes it possible to use a general-purpose optical modulator that is not polarization-independent, contributing to cost reduction. The above has described the advantages of modulating the local light generated from the laser for homodyne detection.
[0099] Next, in the explanation of equation (1), it was explained that when the signal power P0 is halved, the number of masks becomes the square root of 2. The relaxation of the requirement for the modulation number M in the optical transmitter 1 due to this will be explained. 11 is a diagram showing the relationship between the quantum noise mask number and the PSK order after encryption. That is, the vertical axis represents the mask number Γ in the above explanation. Q The horizontal axis corresponds to the modulation number M. The graph shown in Figure 11 is an example where P0 = 2Pmin in equation (1). Note that the signal power Pmin is calculated as BER = 1 x 10 in homodyne detection. -3 is the signal power that achieves
[0100] From Figure 11, we can see that 7 to 9 bits of encryption phase modulation resolution (approximately 256 to 1024 as the PSK order (modulation number M)) is required to achieve the required number of masks of approximately 10 to 100 to protect the private key. In contrast, although not shown, the PSK order (number of modulations M) required to achieve the same number of masks as in the conventional technique is 14 bits or more. In this way, by limiting the signal power that can be intercepted by an eavesdropper to less than 2Pmin, the requirement for the number of multilevels of the optical signal is relaxed.
[0101] Note that this is not a direct effect of the receiver configuration, which modulates and decodes local light, but rather the effect of limiting the signal power when an eavesdropper eavesdrops to less than 2Pmin (by reducing the optical power on the transmitting side or by introducing a monitor, as described below), that is, the effect of the entire system, including transmission and reception.
[0102] If the signal power of an eavesdropper is limited to less than 2Pmin, the data will be protected even if the PSK order after encryption is low. In an extreme example, the data will be protected even if the PSK order is 4.
[0103] Here, the degree of PSK is increased to some extent in order to protect the shared key. A key (e.g., a common key) is usually used that is shorter than the data length. As mentioned above, even if an eavesdropper somehow obtains the common key after communication is complete, they will not be able to decrypt the data after IQ simultaneous detection. However, if the mask is acquired during communication, it will be possible to perform homodyne reception using the same receiver configuration as the legitimate receiver. Therefore, it is necessary to maintain a mask count of several tens to hundreds.
[0104] Next, the advantages of decoding in the optical domain over decoding in the electrical domain will be described with reference to FIG. FIG. 12 is a diagram comparing examples of the configurations required for decoding in the optical domain and decoding in the electrical domain. FIG. 12A shows an example of the configuration of a typical digital coherent optical receiver. The digital coherent optical receiver (optical receiving device 2) in the example of FIG. 12A includes a laser 171, a coherent receiving optical circuit and balance PD 172, and a signal processing ASIC 173.
[0105] Here, for example, a coherent optical receiving circuit for homodyne detection or heterodyne detection may be adopted as the coherent optical receiving circuit in the coherent optical receiving circuit and balanced PD 172. The coherent optical receiving circuit for homodyne detection or heterodyne detection includes one optical coupler. Alternatively, for example, a coherent optical receiving circuit for phase diversity intradyne detection may be employed, which includes four optical couplers and one polarization rotator. Furthermore, a coherent optical receiving circuit that is independent of the incident polarization may be adopted, in which the signal light and the local light are each separated into orthogonal polarization components using a polarization beam splitter, and the signal light of each polarization component is subjected to homodyne detection, heterodyne detection, or phase diversity intradyne detection using the local light of the same polarization.
[0106] In a typical digital coherent optical receiver, the data on the position on the IQ plane output by the balanced PD 172 is input to the signal processing ASIC 173. As a result, the signal processing ASIC 173 needs to be equipped with a circuit for decoding encryption in addition to compensating for waveform distortion caused by digital signal processing. In other words, it is necessary to develop a signal processing ASIC 173 that is equipped with a circuit for performing decoding using digital signal processing (i.e., a complex function using digital signal processing), which requires a very large cost.
[0107] FIG. 12B shows an example of a configuration for decoding in the optical domain. The optical receiving device 2 in the example of FIG. 12B includes a laser 181, an optical modulation phase and / or intensity modulator 182, a code generation unit 183, a coherent receiving optical circuit and balance PD 184, and a signal processing ASIC 185. Here, the optical modulation phase and / or intensity modulator 182 refers to a modulator that performs at least one of optical phase modulation and intensity modulation. Specifically, for example, any configuration such as a single optical phase modulator, a combination of an optical phase modulator and a Mach-Zehnder modulator, or an IQ modulator can be adopted as the and / or intensity modulator 182.
[0108] Furthermore, for example, a coherent optical receiving circuit for homodyne detection or heterodyne detection may be adopted as the coherent optical receiving circuit in the coherent optical receiving circuit and balanced PD 184. The coherent optical receiving circuit for homodyne detection or heterodyne detection includes one optical coupler. Alternatively, for example, a coherent optical receiving circuit for phase diversity intradyne detection may be employed, which includes four optical couplers and one polarization rotator. Furthermore, a coherent optical receiving circuit that is independent of the incident polarization may be adopted, in which the signal light and the local light are each separated into orthogonal polarization components using a polarization beam splitter, and the signal light of each polarization component is subjected to homodyne detection, heterodyne detection, or phase diversity intradyne detection using the local light of the same polarization.
[0109] 12B only processes the decrypted signal, so an existing optical communication signal processing ASIC can be used. By feeding back a control signal such as a clock from the existing optical communication signal processing ASIC to drive the cipher generation unit 183, decryption synchronized with the optical signal (encrypted signal) becomes possible. That is, by adding the rectangular portion surrounding the optical modulation phase and / or intensity modulator 182 and the cipher generation unit 183 to a normal optical communication circuit including an existing optical communication signal processing ASIC, an optical receiving device 2 that performs decryption in the optical domain can be realized. This allows the optical receiving device 2 to be realized at low cost.
[0110] Next, we will explain a signal processing system that takes advantage of the property described above in Figure 5 that even if an eavesdropper eavesdrops on a signal with a signal power of less than 2Pmin, the reception sensitivity will be below the minimum reception sensitivity of IQ simultaneous detection (heterodyne detection, etc.), thereby achieving extremely high security against eavesdropping (security comparable to or surpassing information-theoretic security). 5, the signal power output from the optical transmitter 1 is assumed to be less than 2Pmin. However, consider the case where a signal is transmitted with a signal power much greater than 2Pmin. In this case, an eavesdropper branches off a signal with a power of 2Pmin or more as part of the signal power and eavesdrops on it. The eavesdropper performs IQ simultaneous detection on the eavesdropped optical signal (encrypted signal) and subsequently decrypts it.
[0111] Therefore, when installing the signal processing system shown in Figure 1, it is advisable to introduce a monitor that can detect eavesdropping if an eavesdropper branches off a signal of 2Pmin or more. If the monitor detects eavesdropping, some kind of response will be taken, such as cutting off communication. This will ensure the security of the signal.
[0112] In this way, assuming that measures against eavesdropping using a signal of 2 Pmin or more are implemented by a monitor, the signal power output from the optical transmitter 1 can be made greater than 2 Pmin, which makes it possible to transmit an optical signal (encrypted signal) via a transmission line 3 having an optical transmission loss of 3 dB or more.
[0113] Here, the following can be used as the monitor. That is, simply, it is sufficient to detect a decrease in signal power or signal quality (which changes depending on optical power) on the side of the optical receiving device 2. This method is vulnerable to a so-called man-in-the-middle attack, in which an optical signal is eavesdropped on along the way and an optical signal is returned that does not detect a decrease in power. An example of a man-in-the-middle attack is shown in FIGS. FIG. 13 is a diagram illustrating an example of a man-in-the-middle attack by an eavesdropper. FIG. 14 is a diagram showing an example of a man-in-the-middle attack by an eavesdropper, which is different from the example shown in FIG.
[0114] 13, the eavesdropper receives (detects) and analyzes all optical signals (encrypted signals) transmitted from the optical transmitting device 1, and transmits optical signals according to the reception (detection) results, thereby conducting a man-in-the-middle attack. At this time, the eavesdropper transmits signals with a signal power equivalent to that in the absence of a man-in-the-middle attack. As a result, the signal power received by the optical receiving device 2 becomes approximately Pmin, which is the same as the initial signal strength described using Figure 5 etc. Therefore, simply monitoring the signal strength at the optical receiving device 2 makes it impossible to determine whether a man-in-the-middle attack has occurred.
[0115] 14, the eavesdropper performs a man-in-the-middle attack (tap attack) by splitting the optical signal (encrypted signal) transmitted from the optical transmitter 1, receiving (detecting) and analyzing a portion of it, and then superimposing and transmitting an optical signal corresponding to the reception (detection) result from the splitter. In this case, the eavesdropper transmits with a signal power equivalent to that when no man-in-the-middle attack is performed. As a result, the signal power received by the optical receiving device 2 becomes approximately Pmin, which is the same as the initial signal strength described using Figure 5 etc. Therefore, simply monitoring the signal strength at the optical receiving device 2 makes it impossible to determine whether a man-in-the-middle attack has occurred.
[0116] Therefore, man-in-the-middle attacks can be detected by monitoring the distribution of optical power in the transmission path. Also, the insertion of optical branches in tap attacks shown in Fig. 14 can be detected. Such a monitor requires high performance (dynamic range and resolution). However, in reality, it is not possible to split light with zero loss. Therefore, detection itself is possible. As a (classical) monitor, the following methods can be adopted. That is, a method can be adopted in which a probe light is inserted from the optical receiving device 2 side. Also, for example, a method can be adopted in which the signal power distribution in the transmission path 3 is monitored by digital signal processing of the optical signal itself. This method does not require any additional mechanism, so it is suitable when combined with encrypted communication.
[0117] Furthermore, while conventional (classical) monitors require high performance (dynamic range and resolution), it is preferable to employ the quantum monitor described below. That is, a quantum monitor is a device that inputs weak light with pronounced quantum properties (an optical signal with low signal power and, as a result, large shot noise relative to the signal power) from an optical transmitter 1 or an optical receiver 2 together with signal light. That is, when weak light with pronounced quantum properties is received (detected), large shot noise is generated relative to the signal power. An eavesdropper cannot reproduce the weak light without the shot noise. Therefore, an optical signal with shot noise generated will be transmitted. As a result, when the weak light is received, the signal intensity of the weak light will differ from what is expected. This makes it possible to reliably detect man-in-the-middle attacks (tapping attacks). Furthermore, as described above, this signal processing system is an encryption method that improves encryption strength by lowering the strength of the optical signal (encrypted signal) transmitted from the optical transmitter 1. Therefore, a method of multiplexing and transmitting the optical signal (encrypted signal) and weak light from the quantum monitor is preferable.
[0118] Here, the configurations of the optical receiving device 2 described above and the advantages of each configuration will be summarized. First, it is preferable that the optical receiving device 2 is configured to perform decoding in the optical domain. By performing decryption in the optical domain, the optical signal (encrypted signal) is not detected as it is, but the decrypted optical signal is detected, so that existing optical communication elements and electronic circuits can be used, which makes it easier to manufacture the optical receiving device 2 and reduces costs.
[0119] Next, in the optical receiving device 2, it is preferable to employ a detection method for decoding in the optical domain, in which local light from a laser is modulated and interferes with the optical signal (encryption signal). Specifically, for example, it is preferable to employ a coherent detection method such as homodyne detection, heterodyne detection, or phase diversity intradyne detection in the optical receiving device 2, and to employ a configuration in which at least one of phase modulation and intensity modulation is performed on the local light. This prevents the optical signal (encryption signal) from being attenuated by a modulation element or the like. As a result, the optical signal (encryption signal) is not attenuated anywhere other than the transmission line 3, and therefore, better detection results can be obtained.
[0120] Furthermore, it is preferable that the optical receiving device 2 employs homodyne detection. That is, a legitimate receiver capable of demodulation in the optical domain can use homodyne detection, but an eavesdropper cannot use homodyne detection because they must perform simultaneous IQ detection. Homodyne detection also has a 3 dB better reception sensitivity than other detection methods. This allows a legitimate receiver to obtain better detection results than an eavesdropper.
[0121] Furthermore, if the minimum receiving sensitivity in homodyne detection of the optical receiving device 2 is the signal power Pmin, it is preferable that the signal power during transmission in the optical transmitting device 1 is less than 2Pmin. This ensures extremely high security (security comparable to or superior to information-theoretic security) against eavesdroppers using detection methods other than homodyne detection. In other words, an eavesdropper will not be able to restore the correct data, no matter what kind of digital signal processing they perform to decrypt the data after IQ simultaneous detection.
[0122] Furthermore, if an eavesdropper branches a signal of 2Pmin or more between the optical transmitting device 1 and the optical receiving device 2 and eavesdrops on it, it is preferable to introduce a monitor that can detect this. This allows the signal power during transmission to be 2Pmin or more in the optical transmitter 1. This makes it possible to exchange optical signals (encrypted signals) while ensuring security, even if the optical transmission loss in the transmission path 3 is 3dB or more.
[0123] Furthermore, it is preferable to adopt a monitor system that monitors the signal power distribution in the transmission line 3 by digital signal processing of the optical signal itself. Furthermore, it is preferable to adopt a method for the monitor in which weak light from the quantum monitor is multiplexed and transmitted.
[0124] Various embodiments of the signal processing system to which the present invention is applied have been described above. However, it is sufficient for the signal processing system to which the present invention is applied to be one that realizes "the inability to correctly obtain ciphertext due to the effect of quantum noise," that is, performs encryption at the physical layer and improves the convenience of measures against eavesdropping at the physical layer, and the configuration is not limited to the various embodiments described above, and may be, for example, as follows:
[0125] For example, in the above embodiment, for convenience of explanation, the transmission path 3 is used as the transmission path for the optical signal transmitted from the optical transmitter 1 and received by the optical receiver 2, but this is not particularly limited. That is, although an optical communication cable has been used as an example of the transmission path 3 in the description, it is not particularly limited to this. That is, the transmission path 3 is not limited to one using optical fiber, but includes a communication path that propagates through space, such as so-called optical wireless. Specifically, for example, the atmosphere, water, or a vacuum space including outer space may be used as the optical transmission path. That is, any communication channel may be used between the optical communication cable 3 and the optical transmitter 1 or the optical receiver 2.
[0126] Furthermore, for example, the transmission data providing unit 11 is built into the optical transmitting device 1, but may also include a transmission data receiving unit (not shown) and receive data from outside the optical transmitting device via a predetermined receiving means such as wired or wireless. Furthermore, the transmission data may be provided using a storage device or removable media (not shown). In other words, the transmission data providing unit may have any transmission data obtaining means.
[0127] For example, the encryption key providing units 12 and 22 may provide a key sufficient for the encryption signal generating unit to generate multi-valued data related to encryption. That is, the encryption key may be a shared key or a key using other algorithms such as a secret key and a public key.
[0128] Furthermore, for example, the laser does not need to be built in the optical receiving device 2. That is, the optical transmitting device 2 may function as an optical signal decoding device, receiving local light for detection and decoding the encrypted signal.
[0129] For example, in the above-described embodiments, for convenience of explanation, modulation is performed using one optical phase modulator, a combination of an optical phase modulator and a Mach-Zehnder modulator, or an IQ modulator, but this is not a limitation. Modulation may be performed on any path of an interferometer configuration that branches into any number of paths, and the modulated signal may undergo interference at any location any number of times. Furthermore, other interferometer structures may be used after the interferometer configuration, such as multiple cascaded Mach-Zehnder modulators or multiple cascaded IQ modulators.
[0130] For example, in the above-described embodiment, the predetermined data to be transmitted is multi-valued information based on the Y-00 optical communication quantum cryptography protocol as the predetermined protocol, but this is not particularly limited to this. That is, in the above-described embodiment, when performing modulation with an extremely large number of values, the symbol points are uniformly distributed, as explained with reference to Figures 2 and 3. However, the symbol points do not need to be uniformly distributed. It is sufficient that the modulation is performed so that the distance between at least one symbol point in a pair of adjacent symbol points is sufficiently smaller than the range of various noises including shot noise. In other words, when optical signals are transmitted in association with any two symbol points among a plurality of symbol points, a predetermined protocol is sufficient as long as the optical signals associated with the two symbol points are detected as being at the same position on the IQ plane.
[0131] In summary, the signal processing system to which the present invention is applied is sufficient as long as it is as follows, and various embodiments can be adopted. That is, a signal processing system to which the present invention is applied (for example, the signal processing systems of FIGS. 7, 9, and 10) is a transmitting means (e.g., the optical transmitting device 1 of FIGS. 7, 9, and 10) for modulating laser light to transmit N-value (N is an integer value of 2 or more) transmission information as a first optical signal at a first intensity so that the information corresponds to M (M is an integer value greater than N) symbol points according to a predetermined protocol, and so that when an optical signal associated with a predetermined symbol point is received, the modulated laser light is detected as being at the same position as optical signals associated with other symbol points on an IQ plane; a receiving means (for example, the encrypted signal receiving unit 21 in FIG. 1) for receiving the first optical signal via the path as a second optical signal; an acquisition means (for example, the input portion of the beam splitter in FIGS. 7, 9, and 10) for acquiring a third optical signal obtained by modulating the laser in accordance with the predetermined protocol for demodulation; a demodulator (for example, a demodulator including a beam splitter and a balance PD shown in FIGS. 7, 9, and 10) that demodulates the second optical signal and the third optical signal into transmission information using a demodulation method that causes interference between the second optical signal and the third optical signal; A signal processing system comprising: The first intensity needs only to be less than twice the second intensity, which is the lower limit at which the second optical signal can be demodulated. This ensures safety in that even if an eavesdropper intercepts an optical signal between the transmitting means and the receiving means, the eavesdropper cannot decipher the signal by any means.
[0132] Furthermore, the predetermined protocol determines the modulation amount based on a key, The third optical signal can be generated by being modulated by a modulation element that modulates a local light laser by the modulation amount. As a result, modulation of the second optical signal is not performed, so that the second optical signal is not attenuated and more satisfactory demodulation is achieved. [Explanation of symbols]
[0133] 1 optical transmitter, 2 optical receiver, 3 transmission path, 11 transmission data provider, 12 encryption key provider, 13 encrypted signal generator, 14 encrypted signal transmitter, 21 encrypted signal receiver, 22 encryption key provider, 23 encrypted signal decryption unit, 24, 24A to 24E encrypted signal decryption unit, 25 received data manager, 101 electrical decryption unit, 111 optical decryption unit, 112 detection unit, 121 detection unit, 122 electrical decryption unit, 131 laser, 132 beam splitter, 141 laser, 142 optical phase modulator, 143 Encryption generator, 144, beam splitter, 151, laser, 152, optical phase modulator, 153, Mach-Zehnder modulator, 154, encryption generator, 155, beam splitter, 161, laser, 162, modulator, 163, encryption generator, 164, beam splitter, 171, laser, 172, optical circuit for coherent reception and balanced PD, 173, signal processing ASIC, 181, laser, 182, intensity modulator, 183, encryption generator, 184, optical circuit for coherent reception and balanced PD, 185, signal processing ASIC
Claims
1. a transmitting means for modulating laser light by at least one of phase modulation and intensity modulation to transmit as a first optical signal with a first intensity N-ary (N is an integer value of 2 or more) transmission information as a first optical signal, so that the N-ary (N is an integer value greater than N) transmission information corresponds to M symbol points according to a predetermined protocol, and so that when an optical signal corresponding to a predetermined symbol point among the M symbol points is received, the optical signal is detected as an optical signal corresponding to another symbol point in an IQ plane; a receiving means for receiving as a second optical signal the first optical signal via a path; an acquiring means for acquiring as a third optical signal the laser light modulated for demodulation according to the predetermined protocol; and a demodulating unit for demodulating the second optical signal and the third optical signal as transmission information using a method of demodulating by causing interference between the second optical signal and the third optical signal, the first intensity is less than twice the second intensity that is a lower limit at which the second optical signal can be demodulated; Signal processing system.
2. The predetermined protocol determines a modulation amount based on a key, the third optical signal is generated by being modulated by a modulation element that modulates a local light laser by the modulation amount; 2. The signal processing system of claim 1.
Citation Information
Patent Citations
Secure communication system
JP2007336409A
Yuen encryption optical transmitter and receiver, yuen encryption optical transmission method and reception method, and encryption communication system
JP2012085028A
Optical Cryptography for High Speed Coherent Systems
US20170005789A1
Signal processing device
WO2019216025A1