Network control device

The network control device addresses the exponential key consumption issue in secure communication networks by grouping users and using network coding to share messages efficiently, reducing key usage and maintaining message confidentiality.

JP7802349B2Active Publication Date: 2026-01-20NAT INST OF INFORMATION & COMM TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2022073442
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-04-27
Publication Date
2026-01-20
Estimated Expiration
2042-04-27

AI Technical Summary

Technical Problem

In secure communication networks like quantum cryptography networks, the consumption of secret random number sequences (keys) increases exponentially with the number of users, limiting the capacity to provide secure communication services due to the one-time use and high demand for key consumption in multicast messaging.

Method used

A network control device that divides user nodes into groups, instructs nodes to collect and calculate exclusive ORs of messages using assigned keys, and shares network-coded information to reduce key consumption while maintaining message confidentiality.

Benefits of technology

Efficiently shares messages among multiple users by reducing the number of secret random number sequences consumed, while ensuring that the confidentiality of each message is maintained even if some messages are compromised.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007802349000014
    Figure 0007802349000014
  • Figure 0007802349000015
    Figure 0007802349000015
  • Figure 0007802349000016
    Figure 0007802349000016
Patent Text Reader

Abstract

To allow a plurality of users using a secret communication network to efficiently share messages.SOLUTION: A controller 100 controls a network having a plurality of user nodes and a link connecting two user nodes and assigned with a key, and the controller comprises: a division unit 110 that divides the plurality of user nodes into a plurality of groups; a first instruction unit 120 that instructs the user nodes to collect, by using the key, messages held in a predetermined number of user nodes; a second instruction unit 130 that instructs a specific node in the network to collect, by using the key, messages initially held in the plurality of user nodes belonging to the groups; a third instruction unit 140 that instructs the specific node to calculate the exclusive OR of the plurality of messages and transmits the exclusive OR to the user nodes without using the key; and a fourth instruction unit 150 that instructs the user nodes to obtain messages in the other user nodes that the user nodes have not obtained yet.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a network control device. [Background technology]

[0002] Advances in cloud services and high-speed mobile communications technology are driving a rapid increase in Internet traffic. While network facilities, including high-capacity optical fiber, are being strengthened, the number of devices and new services and applications are expected to continue to increase. Therefore, simply strengthening infrastructure at the current rate will not be enough, and communication methods themselves must be transformed into more efficient ones. Furthermore, with the amount of highly confidential information increasing, there is an increasing demand for information security. In addition to improving communication efficiency, there is also a need for mechanisms to prevent information leaks to third parties other than authorized users and unauthorized data tampering.

[0003] Network coding, which combines multiple pieces of information collected at a relay node, converts (encodes) them into another piece of information, and then transmits them, is known as a method for efficiently performing multicast communication over a network (Non-Patent Documents 1 and 2). Network coding is beginning to be put into practical use as a new technology to support the rapid increase in communication traffic (Non-Patent Document 3). Furthermore, as a method for ensuring the security of communications, research and development of a technology called secure network coding (Non-Patent Documents 4 to 6) that combines network coding with secrecy using random numbers is also progressing. Furthermore, quantum key distribution (QKD) and quantum cryptography, which uses a one-time pad with a key (a pair of symmetric secret random number sequences) generated by QKD, are methods for achieving completely secure communication using the principles of quantum mechanics. In recent years, quantum cryptography communication networks have begun to be put into practical use to provide cryptographic applications such as secure communication between multiple points using quantum cryptography and secret sharing storage (Non-Patent Documents 7 to 9). [Prior art documents]

Non-licensed literature

[0004]

Non-licensed literature 1

Non-licensed Document 2

Non-licensed Document 4

Non-licensed Document 5

Non-licensed Document 6

[0005] In a secure communication network such as a quantum cryptography network, a secret random number sequence is a valuable key resource. When multiple users of the secure communication network share messages by multicast, a large number of keys are consumed for one-time padding of messages and for pre-sharing of group keys. As the number of users increases, the consumption of keys increases rapidly, making it impossible to keep up with the generation of secret random number sequences, which limits the capacity to provide secure communication services.

[0006] The present invention has been made in view of the above circumstances, and has as its object to enable a plurality of users who use a secret communication network to efficiently share messages. [Means for solving the problem]

[0007] To achieve the above object, a control device according to one embodiment controls a network having a plurality of user nodes and a link connecting two of the user nodes, wherein each of the plurality of user nodes holds a message and a key is assigned to the link. The control device includes a division unit that divides the multiple user nodes into multiple groups; a first instruction unit that instructs each of the multiple user nodes to collect messages held by a predetermined number of user nodes excluding the user node in question using the link and a key assigned to the link, the predetermined number being determined according to the number of groups obtained by the division unit; a second instruction unit that instructs a specific node in the network to collect messages initially held by each of the multiple user nodes belonging to the group using the link and a key assigned to the link; a third instruction unit that instructs the specific node to calculate an exclusive OR of the multiple messages collected by the specific node and send the exclusive OR to each of the multiple user nodes using the link without using the key assigned to the link; and a fourth instruction unit that instructs each of the multiple user nodes to obtain messages of other user nodes that the user node has not yet obtained using the messages collected in accordance with the instruction from the first instruction unit and the exclusive OR. [Effects of the Invention]

[0008] According to the present invention, a plurality of users who use a secure communication network can efficiently share messages. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is an explanatory diagram showing a quantum cryptography communication network. [Figure 2] (A) to (F) are explanatory diagrams showing a first study example of multicast distribution in a network having six user nodes. (G) is an explanatory diagram showing keys consumed in the first study example. [Figure 3A]FIG. 10 is an explanatory diagram showing a second example of multicast distribution in a network having six user nodes. [Figure 3B] FIG. 10 is an explanatory diagram showing a second example of multicast distribution in a network having six user nodes. [Figure 3C] FIG. 10 is an explanatory diagram showing a second example of multicast distribution in a network having six user nodes. [Figure 4A] (A) to (F) are explanatory diagrams showing a first example of multicast distribution in a network having six user nodes. (G) is an explanatory diagram showing keys consumed in the first example. [Figure 4B] 1A and 1B are explanatory diagrams showing a first example of multicast distribution in a network having six user nodes. [Figure 4C] 10A and 10B are explanatory diagrams showing a variation of the first example of multicast distribution in a network having six user nodes. [Figure 5A] 1A and 1B are explanatory diagrams showing a first example of multicast distribution in a network having eight user nodes. [Figure 5B] 1A and 1B are explanatory diagrams showing a first example of multicast distribution in a network having eight user nodes. [Figure 6] FIG. 1 is an explanatory diagram showing a network having 10 user nodes. [Figure 7] FIG. 2 is a block diagram showing the configuration of a network control device. [Figure 8] FIG. 2 is an explanatory diagram illustrating an example of a computer hardware configuration of a node. DETAILED DESCRIPTION OF THE INVENTION

[0010] The present invention will be described below based on the illustrated embodiments, but the present invention is not limited to the embodiments described below.

[0011] First, the inventors of the present invention conducted extensive research as described below.

[0012] [1.Secure communication network using quantum key distribution] Currently, the standard methods for ensuring the security of network communications are authentication and key exchange using public key cryptography, and encryption of data communications using symmetric key cryptography. These cryptographic techniques use difficult mathematical problems to create a situation in which a third party who does not know the cryptographic key would be required to perform an enormous amount of calculations to decipher the original information from the ciphertext, effectively preventing eavesdropping and tampering. However, as the risk of deciphering increases with advances in computing technology, it is necessary to periodically extend the length of the cryptographic key and update the cryptographic method. In contrast to this, there are also known methods that guarantee security that cannot be decrypted by any computer (information-theoretic security). Cryptographic methods based on information-theoretic security can, in principle, guarantee security for an extremely long period of time without updating the encryption specifications.

[0013] A typical method for guaranteeing information-theoretic security is quantum cryptography, which encrypts data communications using a one-time pad (OTP) method using a cryptographic key shared by quantum key distribution. Quantum Key Distribution (QKD) is a method in which a common random number sequence (let's say K) with information-theoretic security is shared as a cryptographic key between two distant points connected by optical fiber lines. Encryption is performed by logically ORing the message to be sent (let's say U) with a cryptographic key K of the same size as the message U.

number

number

[0014] The key generation speed of a pair of QKD link systems connecting two points decreases as the transmission distance increases, and with conventional optical fiber installations, it is only a few hundred kbps over 50 km and a few kbps over 100 km. Therefore, by installing multiple "trusted nodes" at intervals of 50 to 60 km and connecting the QKD devices (QKD modules) within each trusted node, a wide-area network called a Quantum Key Distribution Network (QKDN) can be obtained. Each trusted node is equipped with a key management device (Key Manager, KM) separate from the QKD module, which transfers and stores the encryption keys generated by the QKD module to the KM. KMs are connected to each other via classical circuits (KM links), and manage and operate encryption keys, including performing capsule relay (key relay) of encryption keys when necessary. The cryptographic keys shared in this way can be used for various cryptographic applications existing in existing communication networks and cryptographic infrastructures (user networks in Figure 1, which will be described later), such as providing keys to applications such as one-time pad (OTP)-based completely confidential communications, symmetric key cryptography, and secret sharing storage. Functional elements called the QKDN controller and QKDN manager have been introduced to control the route of the capsule relay of cryptographic keys and manage the entire QKDN. A network that includes the QKDN and user networks on which cryptographic applications are executed is called a quantum cryptographic communication network.

[0015] 1 shows the conceptual structure of a quantum cryptography communication network NW1. The quantum cryptography communication network NW1 includes a quantum key distribution network QKDN1 and a user network UN1. The quantum key distribution network QKDN1 includes multiple trusted nodes TN and four functional layers L1 to L4.

[0016] The quantum layer L1 is a set of QKD links connected via QKD modules QM in each trusted node. A QKD link is a one-to-one link. A QKD link connects one QKD module in a trusted node to one QKD module in another trusted node. Each QKD link generates its own encryption key. The generated encryption key is sent to the key manager KM in the trusted node for management and operation.

[0017] The key management layer L2 has a key manager KM in each trusted node and KM links connecting the key managers KM. The key manager KM stores the encryption keys generated in the quantum layer L1 and shares them between the required ends through key capsule relay using OTP encryption. The key manager KM is responsible for overall key management, including supplying encryption keys to cryptographic applications on the user network UN1.

[0018] The QKDN control layer L3 has one or more QKDN controllers CT that control the overall QKDN service. The layer L3 may be a network consisting of multiple QKDN controllers CT. The QKDN management layer L4 has a QKDN manager MG1. The QKDN manager MG has the function of collecting performance information from each of the layers L1 to L3, monitoring whether the service is operating properly, and issuing control commands to the QKDN control layer L3 as necessary.

[0019] The user network UN1 has a service layer L5, which is a functional layer where multiple user terminals UD exist, and a user network management layer L6. The multiple user terminals UD in the service layer L5 perform encrypted communication using keys and cryptographic applications provided by corresponding key managers KM. The service layer L5 may be a multipoint network consisting of three or more user terminals UD. The network manager MG2 in the user network management layer L6 communicates with the QKDN manager MG1 and manages the user terminals UD.

[0020] The key management layer L2 and service layer L5 of the quantum cryptography communication network NW1 are examples of a secret communication network. That is, in the key management layer L2, symmetric encryption keys are shared between two KMs required by key capsule relay using OTP encryption, and group keys are shared among three or more KMs. In addition, in the service layer L5, secret communication between two points and secret multicast communication between multiple points are performed using keys provided from the key management layer L2.

[0021] In such a secure communication network, the secret random number sequence used as the symmetric key for encrypting each link is valid only for one use, and therefore must be discarded after use. Since the use of a secure communication network consumes a large number of secret random number sequences, the network administrator must generate many new secret random number sequences to replenish the symmetric keys. Since the secret random number sequence is a valuable key resource, it is important to consider how to use it efficiently.

[0022] [2. Multicast distribution using a secure communication network] To explain the problems of the conventional technology, an example of multicast distribution using the above-mentioned secure communication network will be shown. The network NW6A shown in Fig. 2(A) is typically an example of the above-mentioned service layer L5, and has six user nodes A to F and a hub node H. Alternatively, if these nodes correspond to a key manager KM, the network NW6A becomes an example of a key management layer L2. In the network NW6A, each of the six user nodes A to F is connected to the hub node H by a link. Also, the user node A is connected to the user node C by a link, the user node C is connected to the user node E by a link, and the user node E is connected to the user node B by a link. Furthermore, the user node B is connected to the user node D by a link, the user node D is connected to the user node F by a link, and the user node F is connected to the user node A by a link. Each of the six user nodes A to F is connected to a user U A ~U F , and the hub node H has no users associated with it. A ~U F A user group is formed by We assume that user nodes A to F and hub node H are implemented and operated as trusted nodes, and that it is extremely difficult for an eavesdropper to access the data stored in the nodes. On the other hand, we assume that the links connecting each node are accessible to an eavesdropper, and that all information flowing on the links falls into the hands of an eavesdropper. User U A Message S A User U B Message S B User U C Message S C In addition, user U D Message S D User U E Message S E User U F Message S F In this example, it is assumed that each user multicasts the message they have to the other five users.

[0023] A secret random number sequence is prepared as a symmetric key for the link connecting two nodes to conceal the link. For example, the symmetric key (K AC ) imeans the i-th secret random number sequence prepared for link AC connecting node A and node C. The symmetric key (K FD ) i , (K EB ) i The same is true for the following. For simplicity, the length of the symmetric key is assumed to be the same as the length of the message. To conserve keys, messages are not delivered to hub nodes H that have no users.

[0024] As shown in FIG. 2(A), user node A sends a message S A and the symmetric key (K AC )1 and sends the exclusive OR (ciphertext by Vernam cipher) to the user node C. The user node C receives this exclusive OR and sends the symmetric key (K AC )1 to decrypt the message S A After receiving the message S A and the symmetric key (K EC )1 to user node E. User node E, which receives this exclusive OR, sends the symmetric key (K EC )1 to decrypt the message S A After receiving the message S A and the symmetric key (K EB )1 to user node B. User node B receives this exclusive OR and sends the symmetric key (K EB )1 to decrypt the message S A get. In addition, user node A sends the message S A and the symmetric key (K AF )1. User node F receives this exclusive OR and sends the symmetric key (K AF )1 to decrypt the message S A After receiving the message S A and the symmetric key (K FD )1 to user node D. User node D receives this exclusive OR and sends the symmetric key (K FD )1 to decrypt the message S A get. In this way, the message S A is distributed by multicast from user node A to user nodes B to F. Similarly, as shown in Figure 2(B), message S B is multicast from user node B to five user nodes excluding the user node. As shown in Figure 2(C), message S C is multicast from user node C to five user nodes excluding the user node C. As shown in Figure 2(D), message S D is multicast from user node D to five other user nodes. As shown in Figure 2(E), message S E is multicast from user node E to five user nodes excluding the user node. As shown in Figure 2(F), message S F is multicast from user node F to five user nodes excluding the user node.

[0025] As shown in Figures 2(A) to 2(F), five keys (secret random number sequences) are consumed when one user node multicasts a message it holds. Therefore, 30 keys are consumed for multicast distribution by each of six user nodes A to F. This is shown in Figure 2(G). While five keys are consumed for each link connecting user nodes, no secret random number sequences are consumed for links connecting user nodes with hub nodes.

[0026] As described above, in a network NW6A having six user nodes, 6×(6−1)=30 keys are consumed. In a network with n user nodes, if each user node performs multicast distribution, there are at least n × (n-1) number of nodes, i.e., n 2This means that a relatively large number of keys (secret random number sequences), on the order of n, are consumed. As such, in the conventional technology, as the number of user nodes n increases, the amount of keys (secret random number sequences) consumed increases exponentially. This large consumption of keys poses a problem in that it significantly impairs the availability of the secure communication network.

[0027] If the purpose of message sharing is to conserve secret random number sequences, key relay can be used in the procedure shown in Figures 3A to 3C. Figure 3A shows a network NW6B that has the same topology as the network NW6A. First, in the first step, the messages R held by user nodes A to F are A ~R F Prior to the sharing of the message R, a preliminary group key R is shared among the six user nodes. This is as shown in Figure 3A, where user node A sends a message R A This can be achieved by preparing a pre-group key R0 separately from the users C, E, and B, and F and D, and distributing it to the users C, E, and B, as well as F and D, through a key relay that uses the secret random number sequence as a symmetric key to conceal the transmission link. This key relay ensures the secrecy of the pre-group key R0. When sharing the pre-group key R0, five secret random number sequences (K AC )1, (K CE )1, (K EB )1, (K AF )1 and (K FD )1 is used. At this point, as shown in FIG. 3B, each user node has its own message that it originally possessed and the pre-group key R0.

[0028] In the second step, user nodes A, C, E, B, D, and F each calculate an exclusive OR R1 to R6 between the message held by that user node and the pre-group key R0.

number

[0029] In the third step, as shown in Figure 3C, user nodes A to F each publish their encrypted information R1, R4, R2, R5, R3, and R6. As long as the pre-group key R0 is kept secret, even if R1, R4, R2, R5, R3, and R6 are published, each message remains secret from third parties. Meanwhile, each user node can decrypt the encrypted information by performing an exclusive OR using the pre-group key R0 to obtain the five messages originally held by the other five user nodes.

[0030] By following the procedure described with reference to FIGS. 3A to 3C, six user nodes can share six messages by using only five secret random number sequences. However, as shown in Figure 3C, if you select any two of the six public information R1, R4, R2, R5, R3, and R6 and calculate the exclusive OR, it will match the exclusive OR of two different messages. Therefore, if the six messages R A ~R F If one of the messages is leaked, the value of the exclusive OR between that message and the pre-group key R0 is already known, and therefore all of the other five messages will be compromised. Thus, there is a problem that the trade-off for saving the secret random number sequence is the inevitable reduction in the confidentiality of the message.

[0031] To address these issues, the following two methods are used when multicast distribution for information sharing is performed using a secure communication network. Each method may be used alone, or both methods may be used in combination. For simplicity of explanation, let us assume that the number of user nodes n is 6, and that the number of messages to be multicast distributed is 6. The first method is to use six messages (R A , R B , R C , R D , R E and R F) sharing is performed all at once at the same time, rather than individually at different times. The time for message delivery can be set arbitrarily, making batch processing possible. The second technique is to use the exclusive OR of multiple messages, e.g.

number

[0032] By sharing multiple messages simultaneously, the operation between these different messages can be made meaningful. Furthermore, since each of the multiple messages to be XORed mutually conceals the other messages, even if the result of the XOR, such as R, is leaked, each message remains confidential. Therefore, by transmitting the result of the XOR of multiple messages rather than concealing each message using a key, the consumption of keys can be reduced while maintaining the confidentiality of each message.

[0033] [First embodiment] The first embodiment will be described using an example in which the number of user nodes n is 6 and the number of messages is 6. Fig. 4A(A) shows a network NW61 having the same topology as the network NW6A. In the first stage, each user node uses the key relay method to secretly relay and deliver its message to the next three nodes in a clockwise direction on the page of FIG. 4A. Specifically, as shown in FIG. 4A(A), user node A sends a message R A and key (K AC )1, and user node C decodes this exclusive OR to obtain message R AUser node C sends message R to user node E. A and key (K CE )1, and user node E decodes this exclusive OR to generate message R A User node E receives message R from user node B. A and key (K EB )1, and user node B receives message R A Get. Message R A By distributing the secret random number sequence to user nodes C, E, and B, the number of secret random number sequences consumed is three. Similarly, message R B is sent to user nodes D, F, and A, and a message R C is sent to user nodes E, B, and D, and a message R D is sent to user nodes F, A, and C. Also, as shown in FIG. 4A(E), message R E is sent to user nodes B, D and F, and a message R F is sent to user nodes A, C and E.

[0034] At this point, each user node has a total of four messages, including the message it initially had. Figure 4A(G) shows a list of messages held by each user node at the end of the first stage. As shown in the figure, at the end of the first stage, three secret random number sequences have been consumed on each of the six links connecting the user nodes, meaning that a total of 18 secret random number sequences have been consumed.

[0035] In the second stage, as shown in FIG. 4B(A), user node A sends message R A and Message R D The exclusive OR with

number

number

[0036] In the third stage, the hub node H decrypts the data sent from the user nodes A, B, E, and F using the secret random number sequence assigned to each link, and then calculates two pieces of network-encoded information P1 and P2.

number

[0037] A group consisting of six user nodes A to F is divided into the following two subgroups. First subgroup: User nodes A, D, and E Second subgroup: User nodes B, C and F In FIGS. 4A(A) to 4A(F), user nodes A, D, and E belonging to the first subgroup are connected to one another by dotted lines, and user nodes B, C, and F belonging to the second subgroup are connected to one another by dotted lines.

[0038] Then, as shown in Figure 4B(B), the hub node H publicly announces the network-coded information P1 and P2 to all user nodes. Each user node can obtain two new messages by calculating the exclusive OR of two of the four messages it already has with the network-coded information P1 or P2. Figure 4B(B) also shows the decoding calculations performed by each user node. In this way, the six user nodes can share the six messages.

[0039] The feature of the network coding according to this embodiment is that the two pieces of network-coded information P1 and P2 to be publicly announced are given by the exclusive OR of three messages, and that even if the exclusive OR of the network-coded information P1 and P2 is calculated, it does not reduce to the exclusive OR of the two messages. One of the two messages does not conceal the other, but the two messages together conceal the other message. Therefore, if a message R A Even if is leaked, that alone does not guarantee that the message R D and R E Furthermore, another subgroup message R B , R C , R F will have no effect whatsoever on

[0040] While the method described with reference to Figures 2(A) to (G) consumes 30 secret random number sequences, this embodiment can reduce this to 22 (=18+4) and solves the problem of reduced confidentiality associated with the method described with reference to Figures 3A to 3C.

[0041] [Modification of the first embodiment] There is also a method for the second step that does not involve the hub node. As shown in Figure 4C(A), user node E sends a message R E secret random number sequence (K CE )2 and sends it to the neighboring user node C. User node F then sends message R F secret random number sequence (KDF )2 and sends it to the adjacent user node D. As shown in Figure 4C(B), user node C calculates exclusive OR P1 and publicly notifies other user nodes of the result. Similarly, user node D calculates exclusive OR P2 and publicly notifies other user nodes of the result. According to this modification, one extra secret random number sequence is consumed in each of the transmission links CE and DF, but the total number of secret random number sequences consumed can be reduced by two more than in the first embodiment.

[0042] In the first embodiment and its modifications, a group consisting of six user nodes A to F is divided into two subgroups of the same size, and network-coded information P1 and P2 are assigned to each subgroup. The number of network-coded information corresponds to the number of messages that a user node can newly acquire in the second stage. From this, it can be seen that the number of messages that need to be collected in the first stage is 4, which is the number of user nodes n=6 minus the number of subgroups 2.

[0043] This relationship also holds in the general case. For example, if n = 15, and 15 user nodes are divided into five subgroups, each with three user nodes, the number of network-coded information given by the exclusive OR of three messages is five. Therefore, in the first stage, before the network-coded information is publicly announced, 10 messages (the number of user nodes, n = 15, minus the number of subgroups, 5) must be collected. The number of secret random number sequences consumed in the first stage is (10 - 1) × 15 = 135. In the second stage, to send information to the hub node H to calculate five network-coded information, twice the number of secret random number sequences as the number of network-coded information, i.e., 5 × 2 = 10 secret random number sequences, is required. The total number of secret random number sequences consumed is 145 (= 135 + 10).

[0044] On the other hand, when network coding is not performed, the number of secret random number sequences consumed is (15-1)×15=210.

[0045] If 15 user nodes are divided into three subgroups, each with five user nodes, the number of network-coded messages given by the exclusive OR of five messages is three. Therefore, in the first stage, 12 messages (n = 15, the number of user nodes minus 3, the number of subgroups) must be collected, and the number of secret random number sequences consumed in the first stage is (12 - 1) × 15 = 165. In the second stage, to send the information needed to calculate three network-coded messages to the hub node H, twice the number of secret random number sequences as the number of network-coded messages, i.e., 3 × 2 = 6 secret random number sequences, are required. The total number of secret random number sequences consumed is 171 (= 165 + 6). In this case, one network-coded message is the exclusive OR of five messages, which further strengthens the confidentiality of the messages.

[0046] Thus, there is a trade-off between savings in secret random number sequences and message confidentiality.

[0047] The number of subgroups can be determined according to the confidentiality requirements of the messages. For example, if there are 15 user nodes and the confidentiality requirements of the messages are relatively high, the number of subgroups can be set to a relatively small number of "3" and the number of messages to be subjected to the exclusive OR calculation can be set to a relatively large number of "5". In this case, even if up to three messages are compromised, the compromise of other messages can be prevented. Alternatively, if the above requirements are relatively low, the number of subgroups can be set to a relatively large number (5) and the number of messages to be subjected to the exclusive OR calculation can be set to a relatively small number (3). In this case, even if a maximum of one message is compromised, other messages can be prevented from being compromised.

[0048] [Second embodiment] The second embodiment will be described using an example in which the number of user nodes n is 8 and the number of messages is 8. FIG. 5A(A) shows a network NW81 having eight user nodes A to G and I and a hub node H. In the network NW81, each of the eight user nodes and the hub node H are connected by a link. Also, user node A and user node B are connected by a link, user node B and user node C are connected by a link, user node C and user node D are connected by a link, and user node D and user node E are connected by a link. Furthermore, user node E and user node F are connected by a link, user node F and user node G are connected by a link, user node G and user node I are connected by a link, and user node I and user node A are connected by a link. Each of the eight user nodes A to G and I is connected to a user U. A ~U G , U I , and the hub node H has no users associated with it. A ~U G , U I A user group is formed by the above. Eight user nodes A to G and I each send a message R A ~R G , R I holds the following.

[0049] A group consisting of eight user nodes is divided into a first subgroup to which user nodes A, C, E, and G belong, and a second subgroup to which user nodes B, D, F, and H belong. The number of subgroups is two, and the corresponding network coding information P1 and P2 are as follows:

number

[0050] In the second stage, two messages will be decoded at each user node upon receiving the public notification of the network-encoded information P1 and P2, so the number of messages collected by each user node in the first stage will be a total of six, including the one message that it initially holds.

[0051] In the first stage, as shown in Fig. 5A(A), the message R A is secretly transferred sequentially to the five user nodes B, C, D, E, and F adjacent to the user node in the clockwise direction on the paper by using a key relay that uses a secret random number sequence. Similarly, messages held by the other seven user nodes B to G and I are secretly transferred sequentially to the five user nodes adjacent to the user node in the clockwise direction on the paper by using a key relay that uses a secret random number sequence.

[0052] Figure 5A(B) shows a list of six messages held by each user node at the end of the first stage. Since five keys are used on each of the eight links between user nodes, the number of keys consumed in the first stage is 40.

[0053] In the second stage, as shown in FIG. 5B(A), user node A sends message R F and R I The exclusive OR of the secret random number sequence K AH The user node C conceals the message R A and R C The exclusive OR of the secret random number sequence K CH The user node E conceals the message R B and R D The exclusive OR of the secret random number sequence K EH The user node G conceals the message R E and R G The exclusive OR of the secret random number sequence K GH The data is then encrypted and sent to the hub node H.

[0054] The hub node H calculates two pieces of network coding information P1 and P2 as follows:

number

[0055] Then, as shown in FIG. 5B(B), the hub node H publicly notifies each user node of the network coding information P1 and P2. Each user node can obtain two new messages from the publicly announced network coding information P1 and P2 and the six messages collected in the first stage. For example, user node A receives message R as shown in FIG. 5B(B). D , R F and R I and the network-coded information P2 to obtain the message R B Get the message R A , R E and R G and the network-coded information P1 to obtain the message R C Similarly, other user nodes also receive two new messages.

[0056] According to this embodiment, for example, message R A Even if it is leaked,

number

[0057] [Modification of the second embodiment] Note that there is also a method that does not use the hub node H in the second stage. User node A receives a message R from a neighboring user node I. C Then, user node A receives the transfer of

number

number

[0058] [Third embodiment] FIG. 6 shows a network NW101 having ten user nodes 1 to 10 and a hub node H. Each of the ten user nodes 1 to 10 is connected to the hub node H by a link. User node 1 is connected to user node 2 by a link, user node 2 is connected to user node 3 by a link, and user node 3 is connected to user node 5 by a link. User node 5 is connected to user node 7 by a link, user node 7 is connected to user node 9 by a link, and user node 9 is connected to user node 1 by a link. In addition, user node 4 is connected to user node 6 by a link, user node 6 is connected to user node 8 by a link, user node 8 is connected to user node 10 by a link, and user node 10 is connected to user node 4. User nodes 2 and 3 are each connected to user node 4 by a link. User nodes 7 and 9 are each connected to user node 8 by a link. User node 1 and user node 10 are connected by a link, and user node 5 and user node 6 are connected by a link.

[0059] Unlike the first and second embodiments, in this embodiment, the user nodes 1 to 10 are connected in a net shape rather than in a ring shape.

[0060] Ten user nodes 1 to 10 have users U1 to U 10 are associated with each node, and no users are associated with the hub node H. There are 10 users U1 to U 10 A user group is formed by We assume that user nodes 1 to 10 and hub node H are implemented and operated as trusted nodes, and that it is extremely difficult for an eavesdropper to access the data stored in the nodes. On the other hand, we assume that the links connecting each node are accessible to an eavesdropper, and that all information flowing on the links falls into the hands of an eavesdropper. Users U1~U 10 are messages R1 to R10 In this example, it is assumed that each user multicasts the messages they hold to the other nine users.

[0061] A group of 10 user nodes is divided into two subgroups as follows: First subgroup: User nodes 1, 3, 5, 7 and 9 Second subgroup: User nodes 2, 4, 6, 8 and 10

[0062] Each user node collects messages from the other seven user nodes using the OTP method. The number "7" is obtained by subtracting "2" (the number of subgroups) and "1" (the number of messages initially held by the user node) from "10" (the number of user nodes). In this collection, communication between user nodes that are not directly connected goes through other user nodes. For example, communication between user node 9 and user node 10 goes through user node 1 or 8.

[0063] Hub node H or any of user nodes 1 to 10 collects any uncollected messages among messages R1, R3, R5, and R7, and then calculates the following exclusive OR P1. Also, hub node H or any of user nodes 1 to 10 collects any uncollected messages among messages R2, R4, R6, and R8, and then calculates the following exclusive OR P2.

number

[0064] The node that calculated the exclusive OR P1 sends the exclusive OR P1 to each of the user nodes 1 to 10. In addition, the node that calculated the exclusive OR P2 sends the exclusive OR P2 to each of the user nodes 1 to 10.

[0065] Each of the user nodes 1 to 10 uses the received exclusive ORs P1 and P2 and the message that the user node already has to decrypt the remaining two messages.

[0066] In this way, all user nodes 1 to 10 in the network NW101 receive 10 messages R1 to R 10 can be shared.

[0067] According to the above embodiment, the total amount of secret random number sequences consumed for message sharing can be reduced, and even if one of multiple shared messages is leaked, other messages will not be compromised in a chain reaction, thereby improving confidentiality.

[0068] 7 shows a network control device 100 that controls a network according to each of the embodiments described above. The network control device 100 includes a dividing unit 110, a first instruction unit 120, a second instruction unit 130, a third instruction unit 140, and a fourth instruction unit 150. The dividing unit 110 divides a group made up of a plurality of user nodes included in a target network into a plurality of subgroups. A first instruction unit 120 instructs each of the plurality of user nodes to collect messages held by a predetermined number of user nodes excluding the user node, using the link and the key assigned to the link, where the predetermined number is determined according to the number of the subgroups obtained by the dividing unit. The second instruction unit 130 instructs a specific node in the network (one of the multiple user nodes or the hub node H) to collect messages that each of the multiple user nodes belonging to the subgroup originally possesses, using the link and the key assigned to the link. The third instruction unit 140 instructs the specific node to calculate the exclusive OR of multiple messages collected by the specific node and send the exclusive OR to each of the multiple user nodes using the link without using the key assigned to the link. The fourth instruction unit 150 instructs each of the multiple user nodes to obtain messages from other user nodes that the user node has not yet obtained, using the messages collected by instruction from the first instruction unit and the exclusive OR.

[0069] 8 shows an example of the computer hardware configuration of the network control device 100. The hub node H includes a CPU 351, an interface device 352, a display device 353, an input device 354, a drive device 355, an auxiliary storage device 356, and a memory device 357, which are interconnected by a bus 358.

[0070] A program that realizes the functions of network control device 100 is provided by a recording medium 359 such as a CD-ROM. When recording medium 359 on which the program is recorded is set in drive device 355, the program is installed from recording medium 359 to auxiliary storage device 356 via drive device 355. Alternatively, the program does not necessarily have to be installed using recording medium 359, but can also be installed via a network. Auxiliary storage device 356 stores the installed program as well as necessary files, data, and the like.

[0071] The memory device 357 reads and stores the program from the auxiliary storage device 356 when an instruction to start the program is received. The CPU 351 realizes the functions of the network control device 100 in accordance with the program stored in the memory device 357. The interface device 352 is used as an interface for connecting to other computers via the network. The display device 353 displays a GUI (Graphical User Interface) or the like according to the program. The input device 354 is a keyboard, a mouse, or the like.

[0072] Each user node and hub node in the communication network also has a computer hardware configuration similar to that of the network control device 100.

[0073] The embodiments described above have aspects not only as an apparatus but also as a method and a computer program.

[0074] In message sharing using a secure communication network, multiple messages may be shared individually at different times, or may be shared collectively at the same time. A user node uses messages it has on hand to decode other messages from the network-coded information (the exclusive OR of multiple messages) received through a public communication channel. Although the network-coded information is made public, confidentiality is maintained because each message is kept secret from the other messages. The network control device 100 instructs the hub node H on combinations of multiple messages to be subjected to the exclusive OR operation so that each user node can decode other messages using messages it already has. The embodiments described so far make it possible to reduce the total consumption of keys in a secure communication network by replacing part of the encryption transmission of messages using a key (secret random number sequence) with the disclosure of network-encoded information (the exclusive OR of multiple messages) and the subsequent recovery of the messages.

[0075] The first instruction unit 110, second instruction unit 120, network configuration unit 130, and transmission unit 140 within the network control device 100 may be located in the same physical node, or may be distributed across multiple physically different nodes.

[0076] Dividing a group consisting of a plurality of user nodes into a plurality of subgroups is equivalent to dividing the plurality of user nodes into a plurality of groups.

[0077] The following notes are provided regarding the embodiments described above. [Appendix 1] A control device for a network having a plurality of user nodes and a link connecting two of the user nodes, comprising: Each of the plurality of user nodes has a message, and a key is assigned to the link; a division unit that divides the plurality of user nodes into a plurality of groups; a first instruction unit that instructs each of the plurality of user nodes to collect messages held by a predetermined number of user nodes excluding the user node, using the link and a key assigned to the link, wherein the predetermined number is determined according to the number of the groups obtained by the division unit; and a second instruction unit that instructs a specific node in the network to collect messages that are initially held by each of a plurality of user nodes that belong to the group, using the link and the key assigned to the link; a third instruction unit that instructs the specific node to calculate an exclusive OR of a plurality of messages collected by the specific node and to send the exclusive OR to each of the plurality of user nodes using the link without using a key assigned to the link; a fourth instruction unit that instructs each of the plurality of user nodes to acquire messages of other user nodes that the user node has not yet acquired, by using the messages collected in response to an instruction from the first instruction unit and the exclusive OR; A control device comprising: [Appendix 2] 2. The control device of claim 1, wherein the number of groups is determined according to confidentiality requirements of the messages. [Appendix 3] 3. The control device according to claim 1, wherein the predetermined number is a number obtained by subtracting the number of groups and 1 from the number of user nodes in the network. [Appendix 4] A control device as described in Appendix 1 or 2, wherein the specific node is one of the plurality of user nodes or a hub node connected to each of the plurality of user nodes in the network by the link. [Appendix 5] 3. The control device according to claim 1, wherein the dividing unit, the first instruction unit, the second instruction unit, the third instruction unit, and the fourth instruction unit are present in physically different nodes. [Appendix 6] A control device according to appendix 1 or 2; the plurality of user nodes; a link connecting two of said user nodes; A network comprising:

[0078] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments, and various modifications and changes can be made based on the technical concept of the present invention. [Explanation of symbols]

[0079] QM QKD module TN Trusted Node KM Key Manager CT QKDN Controller MG1 QKDN Manager MG2 Network Manager UD user terminal A~F User nodes H Hub Node 100 control device 110 1st instruction section 120 2nd instruction section 130 Network Configuration Section 140 Transmitter

Claims

1. A control device for a network having a plurality of user nodes and a link connecting two of the user nodes, comprising: Each of the plurality of user nodes has a message, and a key is assigned to the link; a division unit that divides the plurality of user nodes into a plurality of groups; a first instruction unit that instructs each of the plurality of user nodes to collect messages held by a predetermined number of user nodes excluding the user node, using the link and a key assigned to the link, wherein the predetermined number is determined according to the number of groups obtained by the division unit; and a second instruction unit that instructs a specific node in the network to collect messages that are initially held by each of a plurality of user nodes that belong to the group, using the link and a key assigned to the link; a third instruction unit that instructs the specific node to calculate an exclusive OR of a plurality of messages collected by the specific node and to send the exclusive OR to each of the plurality of user nodes using the link without using a key assigned to the link; a fourth instruction unit that instructs each of the plurality of user nodes to acquire messages of other user nodes that the user node has not yet acquired, by using the messages collected in response to an instruction from the first instruction unit and the exclusive OR; A control device comprising:

2. The control device according to claim 1 , wherein the number of groups is determined according to a requirement of confidentiality of the message.

3. The control device according to claim 1 or 2, wherein the predetermined number is a number obtained by subtracting the number of groups and 1 from the number of user nodes in the network.

4. 3. The control device according to claim 1, wherein the specific node is one of the plurality of user nodes or a hub node connected to each of the plurality of user nodes in the network by the link.

5. The control device according to claim 1 , wherein the dividing unit, the first instruction unit, the second instruction unit, the third instruction unit, and the fourth instruction unit are present in physically different nodes.

6. The control device according to claim 1 or 2; the plurality of user nodes; a link connecting two of said user nodes; A network comprising:

Citation Information

Patent Citations

  • Encryption communication system and encryption communication method

    JP2011082832A

  • Method for controlling quantum cryptography communication network and system thereof

    KR1020200041021A