Key exchange system, QKD device, base device, method, and program
The key exchange system uses a quantum key distribution protocol with private key encryption to secure key exchange in QKD networks, addressing vulnerabilities from untrusted key management devices by ensuring only trusted parties can decrypt the keys.
Patent Information
- Application Number
- JP2024520155
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-05-11
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2042-05-11
AI Technical Summary
Conventional QKD networks face security vulnerabilities due to untrusted key management devices, which can compromise the integrity of key information.
A key exchange system that employs a quantum key distribution protocol to securely share keys between QKD devices and base stations, using a private key shared in advance to encrypt the QKD keys before transmission to untrusted key management devices, ensuring that only the intended recipient can decrypt the original key.
This system maintains secure key exchange even in the presence of untrusted key management devices, enhancing the security of QKD networks.
Smart Images

Figure 0007800669000001 
Figure 0007800669000002 
Figure 0007800669000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a key exchange system, a QKD device, a base device, a method, and a program. [Background technology]
[0002] It is known that the practical application of quantum computers will enable mathematical problems that form the basis of the security of existing cryptography (such as the prime factorization problem and the discrete logarithm problem) to be solved in a realistic amount of time. This raises the risk that existing cryptography, such as RSA and elliptic curve cryptography, may be compromised, making it necessary to transition to cryptographic technologies that cannot be decrypted even by quantum computers.
[0003] Post-Quantum Cryptography (PQC) and Quantum Key Distribution (QKD) are cryptographic technologies that cannot be decrypted even by quantum computers. In addition, there is a QKD network, which is a technology that realizes secure key exchange over a wide area by networking QKD and relaying keys via key management devices (for example, Non-Patent Document 1). [Prior art documents] [Non-patent literature]
[0004] [Non-Patent Document 1] ITU-T Y.3803, Internet<URL:https: / / www.itu.int / rec / T-REC-Y.3803-202012-I / en> Summary of the Invention [Problem to be solved by the invention]
[0005] However, in conventional QKD networks, the key management devices also have key information, so if some of the key management devices are unreliable, security cannot be guaranteed.
[0006] The present disclosure has been made in consideration of the above points, and aims to provide a technology that enables secure key exchange via a QKD network even in the presence of an untrusted key management device. [Means for solving the problem]
[0007] A key exchange system according to one embodiment of the present disclosure is a key exchange system including a QKD network consisting of multiple QKD devices that exchange keys using a quantum key distribution protocol and multiple key management devices that relay the keys, and multiple base stations that perform encrypted communication using the keys received from the key management devices, wherein the QKD devices have a transmission unit that is configured to, when sending the key to an untrusted key management device among the multiple key management devices, transmit the key obtained by exclusive-ORing the private key with the untrusted key management device using a private key that has been shared in advance with the base station device that receives the key via the untrusted key management device, and the base station has a key acquisition unit that is configured to, when receiving the key from an untrusted key management device among the multiple key management devices, use the private key to calculate the exclusive-OR of the private key and the key. [Effects of the Invention]
[0008] A technique is provided that enables secure key exchange over a QKD network even in the presence of an untrusted key management device. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a diagram illustrating an example of key exchange in a QKD network. [Figure 2] 1 is a diagram illustrating an example of the overall configuration of a key exchange system according to a first embodiment. [Figure 3] FIG. 4 is a sequence diagram illustrating an example of a process executed by the key exchange system according to the first embodiment. [Figure 4] FIG. 10 is a diagram illustrating an example of the overall configuration of a key exchange system according to a second embodiment. [Figure 5]It is a sequence diagram showing an example of the process executed by the key exchange system in Example 2. [Figure 6] It is a diagram showing an example of the overall configuration of the key exchange system in Example 3. [Figure 7] It is a sequence diagram showing an example of the process executed by the key exchange system in Example 3. [Figure 8] It is a diagram showing an example of the overall configuration of the key exchange system in Example 4. [Figure 9] It is a sequence diagram showing an example of the process executed by the key exchange system in Example 4. [Figure 10] It is a diagram showing an example of the hardware configuration of a computer.
Modes for Carrying Out the Invention
[0010] Hereinafter, an embodiment of the present invention will be described.
[0011] <Key Exchange by QKD Network> Hereinafter, an example of key exchange by a conventional QKD network will be described with reference to FIG. 1. For details of the QKD network, refer to, for example, Non-Patent Document 1 above.
[0012] In FIG. 1, we assume that encrypted communication is performed between a base station device (transmitting node) located at a data transmitting base and a base station device (receiving node) located at a data receiving base. In this case, a key management device (transmitting node) and a QKD device (transmitting node) exist at the data transmitting base, and a key management device (receiving node) and a QKD device (receiving node) exist at the data receiving base. Furthermore, a relay station exists between the data transmitting base and the data receiving base, and this relay station contains a key management device (relay node), a QKD device (relay node 1) connected to the QKD device (transmitting node) via an optical transmission path, and a QKD device (relay node 2) connected to the QKD device (receiving node) via an optical transmission path. A QKD network is comprised of each key management device and the communication paths between them, and each QKD device and the optical transmission paths between them.
[0013] At this time, a key k1 for encrypting communication between the base device (sending node) and the base device (receiving node) is shared (key exchanged) through the following steps S1-1 to S1-4, S2-1 to S2-5, and S3-1.
[0014] The QKD device (sending node) shares k1 with the QKD device (relay node 1) via an optical transmission path using a QKD protocol (for example, the BB84 system) (S1-1). The QKD device (relay node 1) transmits k1 to the key management device (relay node) (S1-2). The QKD device (sending node) transmits k1 to the key management device (sending node) (S1-3). Then, the key management device (sending node) transmits k1 to the base device (sending node) (S1-4).
[0015] Meanwhile, the QKD device (relay node 2) shares k2 with the QKD device (receiving node) via the optical transmission path using a QKD protocol (e.g., the BB84 system) (S2-1). The QKD device (relay node 2) transmits k2 to the key management device (relay node) (S2-2). The QKD device (receiving node) transmits k2 to the key management device (receiving node) (S2-3). The key management device (relay node) transmits the result of an exclusive OR (XOR) of k1 and k2 to the key management device (receiving node) (S2-4). This is called key relay. The key management device (receiving node) then transmits the result of the exclusive OR of k1 and k2 and the result of the exclusive OR with k2 (i.e., k1) to the base device (receiving node) (S2-5).
[0016] As a result, the base device (sending node) and the base device (receiving node) can perform encrypted communication using k1 (S3-1).
[0017] As explained above, in a QKD network, key management devices hold key information. This poses a problem in that security cannot be guaranteed if some key management devices are unreliable. Therefore, we propose a key exchange method that can keep key information secret from unreliable key management devices. An unreliable key management device is, for example, a key management device that is at risk of leaking key information.
[0018] <Proposed method> In this proposed method, in order to keep key information secret from untrusted key management devices, a new secret key sk is introduced and shared between the QKD device that passes the QKD key to the untrusted key management device and the base device that receives the QKD key from the untrusted key management device.The untrusted key management device is then given the result of XORing the secret key sk with the QKD key itself, rather than the QKD key itself.This allows the QKD key to be kept secret from untrusted key management devices.On the other hand, when the base device receives the XOR of the QKD key and the secret key sk from the untrusted key management device, it further XORs it with the secret key sk.This allows the base device to obtain the original QKD key.
[0019] Below, we will explain Examples 1 to 4 of a key exchange system that shares QKD keys using the above proposed method. In each of the following examples, for simplicity, we will explain the case where there is one relay point, but the number of relay points is not limited to one, and the following examples can be similarly applied even if there are multiple relay points.
[0020] [Example 1] In the first embodiment, a case will be described in which the key management device (relay node) and the key management device (receiving node) cannot be trusted.
[0021] Overall configuration of the key exchange system An example of the overall configuration of the key exchange system according to the first embodiment will be described with reference to FIG.
[0022] As shown in Figure 2, the key exchange system in this embodiment includes a plurality of base stations 10, a plurality of key management devices 20, and a plurality of QKD devices 30. Hereinafter, the base station 10 located at the data transmission side base will be referred to as "base station 10A", and the base station 10 located at the data reception side base will be referred to as "base station 10B". Similarly, the key management device 20 and QKD device 30 located at the data transmission side base will be referred to as "key management device 20A" and "QKD device 30A", respectively, and the key management device 20 and QKD device 30 located at the data reception side base will be referred to as "key management device 20B" and "QKD device 30B", respectively. Furthermore, the key management device 20 located at the relay station will be referred to as "key management device 20C", the QKD device 30 connected to the QKD device 30A via an optical transmission path will be referred to as "QKD device 30C-1", and the QKD device 30 connected to the QKD device 30B via an optical transmission path will be referred to as "QKD device 30C-2". In this embodiment, key management device 20B and key management device 20C are untrustworthy key management devices 20. Note that a QKD network is made up of each key management device 20 and the communication paths between them, and each QKD device 30 and the optical transmission paths between them.
[0023] The base device 10 is an information processing device (computer) that performs encrypted communication with base devices 10 located at other bases. The base device 10 has an inter-base communication processing unit 101 that performs encrypted communication with base devices 10 located at other bases and various processes for performing the encrypted communication. The inter-base communication processing unit 101 is realized, for example, by processing that one or more programs installed in the base device 10 execute on a processor such as a CPU (Central Processing Unit). Hereinafter, the inter-base communication processing unit 101 included in the base device 10A will be referred to as the "inter-base communication processing unit 101A," and the inter-base communication processing unit 101 included in the base device 10B will be referred to as the "inter-base communication processing unit 101B."
[0024] In this embodiment, the base device 10B also has a secret key sharing unit 102B for sharing the secret key sk with the QKD device 30C-1. The secret key sharing unit 102B is realized, for example, by a process in which one or more programs installed in the base device 10B are executed by a processor such as a CPU.
[0025] The key management device 20 is an information processing device (computer) that manages keys shared between the QKD devices 30 and relays keys to key management devices 20 at other locations. The key management device 20 has a key management processing unit 201 that executes various processes such as managing keys shared between the QKD devices 30 and relaying keys. The key management processing unit 201 is realized, for example, by processing in which one or more programs installed in the key management device 20 are executed by a processor such as a CPU. Hereinafter, the key management processing unit 201 possessed by the key management device 20A will be referred to as the "key management processing unit 201A," the key management processing unit 201 possessed by the key management device 20B will be referred to as the "key management processing unit 201B," and the key management processing unit 201 possessed by the key management device 20C will be referred to as the "key management processing unit 201C."
[0026] The QKD device 30 is an information processing device (computer) that shares QKD keys with QKD devices 30 located at other locations via an optical transmission path using a QKD protocol (for example, the BB84 system) and executes various processes related thereto. The QKD device 30 has a QKD processing unit 301 that shares QKD keys with QKD devices 30 located at other locations via an optical transmission path using the QKD protocol and executes various processes related thereto. The QKD processing unit 301 is realized, for example, by processing that causes a processor such as a CPU to execute one or more programs installed in the QKD device 30. Hereinafter, the QKD processing unit 301 possessed by the QKD device 30A will be referred to as the "QKD processing unit 301A," the QKD processing unit 301 possessed by the QKD device 30B will be referred to as the "QKD processing unit 301B," the QKD processing unit 301 possessed by the QKD device 30C-1 will be referred to as the "QKD processing unit 301C-1," and the QKD processing unit 301 possessed by the QKD device 30C-2 will be referred to as the "QKD processing unit 301C-2."
[0027] Furthermore, in this embodiment, the QKD device 30C-1 has a private key sharing unit 302C-1 for sharing the private key sk with the base device 10B. The private key sharing unit 302C-1 is realized, for example, by a process in which one or more programs installed in the QKD device 30C-1 are executed by a processor such as a CPU.
[0028] The process performed by the key exchange system An example of processing executed by the key exchange system in the first embodiment will be described with reference to Fig. 3. The processing executed by the key exchange system in this embodiment is roughly divided into pre-sharing of a secret key sk (steps S101 to S104), QKD key exchange (steps S105 to S117), and communication between bases (step S118).
[0029] The inter-site communication processing unit 101A of the base device 10A transmits sharing destination information to the key management device 20A (step S101). The sharing destination information is information for sharing the private key sk (for example, designation of the key agreement protocol used to share the private key sk, information on the initiator and responder when executing this key agreement protocol, etc.). In this embodiment, it is assumed that either the QKD device 30C-1 or the base device 10B is the initiator, and the other is the responder.
[0030] The key management processing unit 201A of the key management device 20A transmits the sharing destination information to the key management device 20C (step S102). The key management processing unit 201C of the key management device 20C transmits the sharing destination information to the QKD device 30C-1 (step S103).
[0031] The secret key sharing unit 302C-1 of the QKD device 30C-1 and the secret key sharing unit 102B of the base device 10B share the secret key sk using the key sharing protocol specified in the sharing destination information (step S104).
[0032] QKD processing unit 301A of QKD device 30A and QKD processing unit 301C-1 of QKD device 30C-1 share QKD key k1 via an optical transmission line using a QKD protocol (for example, the BB84 system) (step S105).
[0033] Similarly, QKD processing unit 301B of QKD device 30B and QKD processing unit 301C-2 of QKD device 30C-2 share QKD key k2 via the optical transmission line using a QKD protocol (for example, BB84 system) (step S106).
[0034] The QKD processing unit 301C-1 of the QKD device 30C-1 calculates the exclusive OR of k1 and sk (step S107). The QKD processing unit 301C-1 of the QKD device 30C-1 transmits the calculation result to the key management device 20C (step S108).
[0035] The QKD processing unit 301A of the QKD device 30A transmits k1 to the key management device 20A (step S109).
[0036] The QKD processing unit 301C-2 of the QKD device 30C-2 transmits k2 to the key management device 20C (step S110).
[0037] QKD processing unit 301B of QKD device 30B transmits k2 to key management device 20B (step S111).
[0038] The key management processing unit 201C of the key management device 20C calculates the exclusive OR of k1, sk, and k2 (step S112). The key management processing unit 201C of the key management device 20C transmits the calculation result to the key management device 20B (key relay) (step S113).
[0039] The key management processing unit 201B of the key management device 20B performs an exclusive OR operation on the result of the operation received from the key management device 20C and k2 (i.e., the exclusive OR operation on k1, sk, k2, and k2) (step S114). The key management processing unit 201B of the key management device 20B transmits the result of the operation to the base device 10B (step S115).
[0040] The inter-site communication processing unit 101B of the base device 10B calculates the exclusive OR of the calculation result received from the key management device 20B and sk (i.e., the exclusive OR of k1, sk, and sk) (step S116). As a result, the base device 10B can obtain k1.
[0041] The key management processing unit 201A of the key management device 20A transmits k1 to the base device 10A (step S117), thereby enabling the base device 10A to obtain k1.
[0042] As a result of the above, the inter-site communication processing unit 101A of the base device 10A and the inter-site communication processing unit 101B of the base device 10B can perform encrypted communication using k1 as the encryption key (step S118).
[0043] [Example 2] In the second embodiment, a case where the key management device (transmission node) cannot be trusted will be described. In the second embodiment, differences from the first embodiment will be described, and descriptions of similarities with the other embodiments will be omitted as appropriate.
[0044] Overall configuration of the key exchange system An example of the overall configuration of a key exchange system according to the second embodiment will be described with reference to FIG.
[0045] 4, the key exchange system in this embodiment includes a plurality of base devices 10, a plurality of key management devices 20, and a plurality of QKD devices 30. In this embodiment, the key management device 20A is an untrusted key management device 20.
[0046] The differences from the first embodiment are that the base device 10A has a secret key sharing unit 102A for sharing the secret key sk with the QKD device 30A, and that the QKD device 30A has a secret key sharing unit 302A for sharing the secret key sk with the base device 10A. Also, the base device 10B does not have the secret key sharing unit 102B, and the QKD device 30C-1 does not have the secret key sharing unit 302C-1. The secret key sharing unit 102A is realized, for example, by a process in which one or more programs installed in the base device 10A are executed by a processor such as a CPU. The secret key sharing unit 302A is realized, for example, by a process in which one or more programs installed in the QKD device 30A are executed by a processor such as a CPU.
[0047] The process performed by the key exchange system An example of processing executed by the key exchange system in the second embodiment will be described with reference to FIG.
[0048] The inter-site communication processing unit 101A of the base device 10A transmits sharing destination information to the key management device 20A (step S201). In this embodiment, it is assumed that either the QKD device 30A or the base device 10A is the initiator, and the other is the responder.
[0049] The key management processing unit 201A of the key management device 20A transmits the sharing destination information to the QKD device 30A (step S202).
[0050] The secret key sharing unit 302A of the QKD device 30A and the secret key sharing unit 202A of the base device 10A share the secret key sk using the key sharing protocol specified in the sharing destination information (step S203).
[0051] QKD processing unit 301A of QKD device 30A and QKD processing unit 301C-1 of QKD device 30C-1 share QKD key k1 via an optical transmission line using a QKD protocol (for example, the BB84 system) (step S204).
[0052] Similarly, QKD processing unit 301B of QKD device 30B and QKD processing unit 301C-2 of QKD device 30C-2 share QKD key k2 via the optical transmission line using a QKD protocol (for example, BB84 system) (step S205).
[0053] The QKD processing unit 301A of the QKD device 30A calculates the exclusive OR of k1 and sk (step S206). The QKD processing unit 301A of the QKD device 30A transmits the calculation result to the key management device 20A (step S207).
[0054] The QKD processing unit 301C-1 of the QKD device 30C-1 transmits k1 to the key management device 20C (step S208).
[0055] The QKD processing unit 301C-2 of the QKD device 30C-2 transmits k2 to the key management device 20C (step S209).
[0056] QKD processing unit 301B of QKD device 30B transmits k2 to key management device 20B (step S210).
[0057] The key management processing unit 201C of the key management device 20C calculates the exclusive OR of k1 and k2 (step S211). The key management processing unit 201C of the key management device 20C transmits the calculation result to the key management device 20B (key relay) (step S212).
[0058] The key management processing unit 201B of the key management device 20B calculates the exclusive OR of the calculation result received from the key management device 20C and k2 (i.e., the exclusive OR of k1, k2, and k2) (step S213). The key management processing unit 201B of the key management device 20B transmits the calculation result (i.e., k1) to the base device 10B (step S214). As a result, the base device 10B can obtain k1.
[0059] The key management processing unit 201A of the key management device 20A transmits the calculation result of the above step S207 (that is, the exclusive OR of k1 and sk) to the base device 10A (step S215).
[0060] The inter-site communication processing unit 101A of the base device 10A calculates the exclusive OR of the calculation result received from the key management device 20A and sk (that is, the exclusive OR of k1, sk, and sk) (step S216). As a result, the base device 10A can obtain k1.
[0061] As a result of the above, the inter-site communication processing unit 101A of the base device 10A and the inter-site communication processing unit 101B of the base device 10B can perform encrypted communication using k1 as the encryption key (step S217).
[0062] [Example 3] In the third embodiment, a case where the key management device (receiving node) cannot be trusted will be described. In the third embodiment, differences from the first embodiment will be described, and descriptions of similarities with the other embodiments will be omitted as appropriate.
[0063] Overall configuration of the key exchange system An example of the overall configuration of a key exchange system according to the third embodiment will be described with reference to FIG.
[0064] 6, the key exchange system in this embodiment includes a plurality of base devices 10, a plurality of key management devices 20, and a plurality of QKD devices 30. In this embodiment, the key management device 20B is an untrusted key management device 20.
[0065] The differences from the first embodiment are that the base device 10B has a secret key sharing unit 102B for sharing the secret key sk with the QKD device 30B, and that the QKD device 30B has a secret key sharing unit 302B for sharing the secret key sk with the base device 10B. Also, the QKD device 30C-1 does not have a secret key sharing unit 302C-1. The secret key sharing unit 302C-1 is realized, for example, by a process in which one or more programs installed in the QKD device 30C-1 are executed by a processor such as a CPU.
[0066] The process performed by the key exchange system An example of processing executed by the key exchange system in the third embodiment will be described with reference to FIG.
[0067] The inter-site communication processing unit 101B of the base device 10B transmits sharing destination information to the key management device 20B (step S301). In this embodiment, it is assumed that either the QKD device 30B or the base device 10B is the initiator, and the other is the responder.
[0068] The key management processing unit 201B of the key management device 20B transmits the sharing destination information to the QKD device 30B (step S302).
[0069] The secret key sharing unit 302B of the QKD device 30B and the secret key sharing unit 202B of the base device 10B share the secret key sk using the key sharing protocol specified in the sharing destination information (step S303).
[0070] QKD processing unit 301A of QKD device 30A and QKD processing unit 301C-1 of QKD device 30C-1 share QKD key k1 via an optical transmission line using a QKD protocol (for example, the BB84 system) (step S304).
[0071] Similarly, QKD processing unit 301B of QKD device 30B and QKD processing unit 301C-2 of QKD device 30C-2 share QKD key k2 via the optical transmission line using a QKD protocol (for example, BB84 system) (step S305).
[0072] QKD processing unit 301B of QKD device 30B calculates the exclusive OR of k2 and sk (step S306). QKD processing unit 301B of QKD device 30B transmits the calculation result to key management device 20B (step S307).
[0073] The QKD processing unit 301C-2 of the QKD device 30C-2 transmits k2 to the key management device 20C (step S308).
[0074] The QKD processing unit 301C-1 of the QKD device 30C-1 transmits k1 to the key management device 20C (step S309).
[0075] The QKD processing unit 301A of the QKD device 30A transmits k1 to the key management device 20A (step S310).
[0076] The key management processing unit 201C of the key management device 20C calculates the exclusive OR of k1 and k2 (step S311). The key management processing unit 201C of the key management device 20C transmits the calculation result to the key management device 20B (key relay) (step S312).
[0077] The key management processing unit 201B of the key management device 20B calculates the exclusive OR of the calculation result received from the key management device 20C and the calculation result received from the QKD device 30B (i.e., the exclusive OR of k1, k2, k2, and sk) (step S313). The key management processing unit 201B of the key management device 20B transmits the calculation result (i.e., the exclusive OR of k1 and sk) to the base device 10B (step S314).
[0078] The key management processing unit 201A of the key management device 20A transmits k1 to the base device 10A (step S315), thereby enabling the base device 10A to obtain k1.
[0079] The inter-site communication processing unit 101B of the base device 10B calculates the exclusive OR of the calculation result received from the key management device 20B and sk (i.e., the exclusive OR of k1, sk, and sk) (step S316). As a result, the base device 10B can obtain k1.
[0080] As a result of the above, the inter-site communication processing unit 101A of the base device 10A and the inter-site communication processing unit 101B of the base device 10B can perform encrypted communication using k1 as the encryption key (step S317).
[0081] [Example 4] In the fourth embodiment, a case where the key management device (sending node) and the key management device (receiving node) cannot be trusted will be described. In the fourth embodiment, differences from the first embodiment will be described, and descriptions of similarities with the other embodiments will be omitted as appropriate.
[0082] Overall configuration of the key exchange system An example of the overall configuration of a key exchange system according to the fourth embodiment will be described with reference to FIG.
[0083] 8, the key exchange system in this embodiment includes a plurality of base stations 10, a plurality of key management devices 20, and a plurality of QKD devices 30. In this embodiment, key management devices 20A and 20B are untrusted key management devices 20.
[0084] The differences from the first embodiment are that the base device 10A has a secret key sharing unit 102A for sharing the secret key sk among the base device 10B, QKD device 30A, and QKD device 30B, and that the QKD device 30A has a secret key sharing unit 302A for sharing the secret key sk among the base device 10A, QKD device 30B, and QKD device 30B. Also, the base device 10B has a secret key sharing unit 102A for sharing the secret key sk among the base device 10A, QKD device 30A, and QKD device 30B, and that the QKD device 30B has a secret key sharing unit 302B for sharing the secret key sk among the base device 10A, base device 10B, and QKD device 30A. Furthermore, the QKD device 30C-1 does not have a secret key sharing unit 302C-1.
[0085] The process performed by the key exchange system An example of processing executed by the key exchange system in the fourth embodiment will be described with reference to FIG.
[0086] The inter-site communication processing unit 101A of the base device 10A transmits the sharing destination information to the key management device 20A (step S401). In this embodiment, it is assumed that one of the base device 10A, the base device 10B, the QKD device 30A, and the QKD device 30B is the initiator, and the rest are responders. In addition, the inter-site communication processing unit 101A of the base device 10A transmits the sharing destination information to the base device 10B (step S402).
[0087] The inter-site communication processing unit 101B of the site device 10B transmits the sharing destination information to the key management device 20B (step S403). The key management processing unit 201B of the key management device 20B transmits the sharing destination information to the QKD device 30B (step S404). The key management processing unit 201A of the key management device 20A transmits the sharing destination information to the QKD device 30A (step S405).
[0088] The private key sharing unit 102A of the base device 10A, the private key sharing unit 102B of the base device 10B, the private key sharing unit 302A of the QKD device 30A, and the private key sharing unit 302B of the QKD device 30B share the private key sk using the key sharing protocol specified in the sharing destination information (step S406).
[0089] QKD processing unit 301A of QKD device 30A and QKD processing unit 301C-1 of QKD device 30C-1 share QKD key k1 via the optical transmission line using a QKD protocol (for example, the BB84 system) (step S407).
[0090] Similarly, QKD processing unit 301B of QKD device 30B and QKD processing unit 301C-2 of QKD device 30C-2 share QKD key k2 via the optical transmission line using a QKD protocol (for example, BB84 system) (step S408).
[0091] QKD processing unit 301A of QKD device 30A calculates the exclusive OR of k1 and sk (step S409).
[0092] Similarly, QKD processing unit 301B of QKD device 30B calculates the exclusive OR of k2 and sk (step S410).
[0093] The QKD processing unit 301C-1 of the QKD device 30C-1 transmits k1 to the key management device 20C (step S411).
[0094] Similarly, the QKD processing unit 301C-2 of the QKD device 30C-2 transmits k2 to the key management device 20C (step S412).
[0095] QKD processing unit 301A of QKD device 30A transmits the calculation result of step S409 above (that is, the exclusive OR of k1 and sk) to key management device 20A (step S413).
[0096] Similarly, QKD processing unit 301B of QKD device 30B transmits the calculation result of step S410 above (that is, the exclusive OR of k2 and sk) to key management device 20B (step S414).
[0097] The key management processing unit 201C of the key management device 20C calculates the exclusive OR of k1 and k2 (step S415), and transmits the calculation result to the key management device 20B (key relay) (step S416).
[0098] The key management processing unit 201B of the key management device 20B calculates the exclusive OR of the calculation result received from the key management device 20C and the calculation result received from the QKD device 30B (i.e., the exclusive OR of k1, k2, k2, and sk) (step S417). The key management processing unit 201B of the key management device 20B transmits the calculation result (i.e., the exclusive OR of k1 and sk) to the base device 10B (step S418).
[0099] Meanwhile, the key management processing unit 201A of the key management device 20A transmits the calculation result received from the QKD device 30A (that is, the exclusive OR of k1 and sk) to the base device 10A (step S419).
[0100] The inter-site communication processing unit 101B of the base device 10B calculates the exclusive OR of the calculation result received from the key management device 20B and sk (i.e., the exclusive OR of k1, sk, and sk) (step S420). As a result, the base device 10B can obtain k1.
[0101] Similarly, the inter-site communication processing unit 101A of the base device 10A calculates the exclusive OR of the calculation result received from the key management device 20A and sk (i.e., the exclusive OR of k1, sk, and sk) (step S421). As a result, the base device 10A can obtain k1.
[0102] As a result of the above, the inter-site communication processing unit 101A of the base device 10A and the inter-site communication processing unit 101B of the base device 10B can perform encrypted communication using k1 as the encryption key (step S422).
[0103] [Hardware configuration of each device] The base device 10, the key management device 20, and the QKD device 30 can be realized, for example, by the hardware configuration of a computer 500 shown in FIG.
[0104] 10 includes an input device 501, a display device 502, an external I / F 503, a communication I / F 504, a RAM (Random Access Memory) 505, a ROM (Read Only Memory) 506, an auxiliary storage device 507, and a processor 508. Each of these pieces of hardware is connected to each other via a bus 509 so as to be able to communicate with each other.
[0105] The input device 501 is, for example, a keyboard, a mouse, a touch panel, a physical button, etc. The display device 502 is, for example, a display, a display panel, etc. Note that the computer 500 does not necessarily have to have at least one of the input device 501 and the display device 502, for example.
[0106] The external I / F 503 is an interface with an external device such as a recording medium 503a. The computer 500 can read from and write to the recording medium 503a via the external I / F 503. Examples of the recording medium 503a include a flexible disk, a CD (Compact Disc), a DVD (Digital Versatile Disk), an SD memory card (Secure Digital memory card), and a USB (Universal Serial Bus) memory card.
[0107] The communication I / F 504 is an interface for connecting the computer 500 to a communication network. The RAM 505 is a volatile semiconductor memory (storage device) that temporarily stores programs and data. The ROM 506 is a non-volatile semiconductor memory (storage device) that can store programs and data even when the power is turned off. The auxiliary storage device 507 is a storage device (storage device) such as an HDD (Hard Disk Drive), an SSD (Solid State Drive), or a flash memory. The processor 508 is an arithmetic device such as a CPU.
[0108] The base device 10, key management device 20, and QKD device 30 according to this embodiment can realize the various processes described above by having, for example, the hardware configuration of a computer 500 shown in Fig. 10. Note that the hardware configuration of the computer 500 shown in Fig. 10 is an example, and the hardware configuration of the computer 500 is not limited to this. For example, the computer 500 may have multiple auxiliary storage devices 507 or multiple processors 508, may not have some of the hardware shown in the figure, or may have various hardware other than the hardware shown in the figure.
[0109] [summary] As described above, in the key exchange system of each of the above embodiments, a private key sk is shared between a QKD device that delivers a QKD key to an unreliable key management device and a base device that receives a QKD key from the unreliable key management device, and a key obtained by exclusive-ORing the private key sk with the base device is exchanged between the unreliable key management device and the QKD device. This keeps the key information secret from the unreliable key management device, and ensures the security of key exchange via the QKD network.
[0110] [Key agreement protocol for secret key sk] In the above embodiments, the key agreement protocol for sharing the private key sk is not particularly limited, and for example, the private key sk may be shared using public key cryptography and a key encapsulation mechanism (KEM). In this case, for example, by using quantum-resistant cryptography such as NTRU, which is a type of lattice cryptography, it becomes possible to exchange keys securely even against quantum computers, thereby achieving higher security.
[0111] The present invention is not limited to the above-described specifically disclosed embodiments, and various modifications, changes, and combinations with known technologies are possible without departing from the scope of the claims. [Explanation of symbols]
[0112] 10 Base Device 20 Key management device 30 QKD equipment 101 Inter-site communication processing unit 102 Secret key sharing part 201 Key Management Processing Unit 301 QKD processing section 302 Secret key sharing part 500 computers 501 Input Device 502 Display device 503 External I / F 503a Recording media 504 Communication I / F 505 RAM 506 ROM 507 Auxiliary storage 508 processor 509 Bus
Claims
1. A key exchange system including a QKD network consisting of a plurality of QKD devices that exchange keys using a quantum key distribution protocol and a plurality of key management devices that relay keys, and a plurality of base stations that perform encrypted communication using keys received from the key management devices, The QKD device a transmitter configured, when transmitting a first key to be relayed to an unreliable key management device among the plurality of key management devices, to the unreliable key management device, using a private key previously shared with a base device that receives the key by the relay via the unreliable key management device, to transmit a second key obtained by exclusive-ORing the private key and the first key to the unreliable key management device; The base device a key acquisition unit configured, when the third key is received by the relay via an unreliable key management device among the plurality of key management devices, to use the private key to acquire a fourth key obtained by exclusive-ORing the private key and the third key as a key to be used for the encrypted communication; A key exchange system, wherein the unreliable key management device is a key management device from which key information may be leaked.
2. The key exchange system according to claim 1 , wherein the private key is a quantum-safe cryptography key.
3. A QKD network is configured with a plurality of QKD devices that exchange keys using a quantum key distribution protocol and a plurality of key management devices that relay keys, and the QKD device is in a key exchange system that includes a plurality of base devices that perform encrypted communication using keys received from the key management devices, a transmitter configured, when transmitting a first key to be relayed to an unreliable key management device among the plurality of key management devices, to the unreliable key management device, by using a private key previously shared with a base device that receives the key by the relay via the unreliable key management device, to transmit the first key obtained by exclusive-ORing the private key and the first key to the unreliable key management device; A QKD device, wherein the untrusted key management device is a key management device from which key information may be leaked.
4. A base station in a key exchange system including a QKD network consisting of a plurality of QKD devices exchanging keys by a quantum key distribution protocol and a plurality of key management devices relaying keys, and a plurality of base stations performing encrypted communication using keys received from the key management devices, a key acquisition unit configured, when a third key is received by the relay via an unreliable key management device among the plurality of key management devices, to acquire a fourth key obtained by exclusive-ORing the private key and the third key using a private key previously shared with a QKD device that transmits the first key to be relayed to the unreliable key management device, as a key to be used for the encrypted communication; the unreliable key management device is a key management device from which key information may be leaked, A base station device in which a QKD device that transmits a first key to be relayed to the untrusted key management device transmits a second key that is the exclusive OR of the private key and the first key to the untrusted key management device.
5. A method for a key exchange system including a QKD network consisting of a plurality of QKD devices that exchange keys using a quantum key distribution protocol and a plurality of key management devices that relay keys, and a plurality of base stations that perform encrypted communication using keys received from the key management devices, The QKD device: a transmission step of transmitting, to the unreliable key management device among the plurality of key management devices, a second key obtained by exclusive-ORing the private key and the first key using a private key previously shared with a base device that receives the key by the relay via the unreliable key management device, to the unreliable key management device; The base device, a key acquisition step of acquiring, when the third key is received by the relay via an unreliable key management device among the plurality of key management devices, a fourth key obtained by exclusive-ORing the private key and the third key using the private key, as a key to be used for the encrypted communication; The method, wherein the untrusted key management device is a key management device from which key information may be leaked.
6. A program that causes a computer to function as a QKD device or a base device included in the key exchange system described in claim 1 or 2.
Citation Information
Patent Citations
Method for regularly pushing quantum key by edge gateway of Internet of Things
CN113708929A
Method for delivering common key of vernum cipher
JP2002217893A
Encryption communication system and encryption communication method
JP2011082832A
Mobile Secure Communication Method Based on Quantum Key Distribution Network
JP2016521935A
Communication device, communication method and communication system
JP2018037888A