Cryptographic key sharing system
The cryptographic key sharing system addresses limitations in existing cryptography and quantum key distribution by using differential phase modulation and adaptive intensity adjustment, enabling secure encryption key sharing over long distances and against advanced eavesdropping.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-23
- Publication Date
- 2026-03-31
AI Technical Summary
Conventional physical layer cryptography and quantum key distribution face limitations in eavesdropping models and key generation speed/transmission distance, making it difficult to achieve information-theoretically secure encryption key sharing over long distances and against advanced eavesdropping capabilities.
A cryptographic key sharing system using differential phase modulation quantum key distribution through a line-of-sight communication channel, with channel state monitoring and adaptive intensity adjustment to generate secure encryption keys, enabling universal linkability and improved key generation speed and distance.
The system achieves information-theoretically secure cryptographic key sharing with enhanced speed and distance, capable of generating secure keys even against sophisticated eavesdropping, particularly in satellite-ground station communications.
Smart Images

Figure 0007837537000011 
Figure 0007837537000012 
Figure 0007837537000013
Abstract
Description
[Technical Field]
[0001] This invention relates to an information-theoretically secure cryptographic key sharing system that utilizes optical signals propagating through a line-of-sight communication channel in free space. [Background technology]
[0002] Conventional communication infrastructures use public-key cryptography to share encryption keys that keep communications confidential. However, the security of public-key cryptography is guaranteed under the assumption of the decryptor's computational power, and in principle, it can be cracked through computational processing if one is willing to put in the effort and time.
[0003] In response to this, research is progressing on physical layer cryptography using line-of-sight channels and quantum key distribution (QKD) as technologies for sharing information-theoretically secure cryptographic keys. Information-theoretically secure means that, based on information theory, it has been mathematically proven that the encryption cannot be deciphered even if an eavesdropper has unlimited computing power.
[0004] Physical layer cryptography utilizes light propagating through a line-of-sight communication channel in free space to share information-theoretically secure cryptographic keys (Patent Document 1, Non-Patent Document 1). Compared to quantum key distribution, physical layer cryptography has the advantages of faster key generation speed and the ability to distribute cryptographic keys over long distances. On the other hand, quantum key distribution has the advantage, compared to physical layer cryptography, of being able to share information-theoretically secure cryptographic keys against not only eavesdropping but also various physically permissible attacks. [Prior art documents] [Patent Documents]
[0005] [Patent Document 1] International Publication No. 2019 / 139544 [Non-patent literature]
[0006] [Non-Patent Document 1] Z. Pan et al., “Secret-key distillation across a quantum wiretap channel under restricted eavesdropping,” Phys. Rev. Applied, vol. 14, no. 2, 024044, 2020. [Overview of the Initiative] [Problems that the invention aims to solve]
[0007] Conventional physical layer cryptography requires specifying the channel model for eavesdroppers, thus limiting the eavesdropping models to those within the range of channel model specification. Therefore, with physical layer cryptography, if quantum technology advances in the future and eavesdroppers' capabilities improve, it may become impossible to share information-theoretically secure encryption keys.
[0008] Furthermore, conventional quantum key distribution, while offering strong security, is subject to strict limitations on key generation speed and transmission distance. To extend information-theoretically secure information communication networks on a global scale, it is necessary to achieve high-speed cryptographic key generation between low-Earth orbit satellites and ground stations, and key sharing between high-altitude geostationary orbit satellites and ground stations. However, quantum key distribution struggles to meet these requirements due to its limitations on key generation speed and transmission distance.
[0009] Therefore, the object of the present invention is to provide an encryption key sharing system that can share information-theoretically secure encryption keys while improving key generation speed and transmission distance. [Means for solving the problem]
[0010] To solve the aforementioned problems, the present invention provides an encryption key sharing system that uses an optical signal propagating through a line-of-sight communication channel to share an encryption key between a differential phase modulation quantum key transmitter and a differential phase modulation quantum key receiver, wherein the differential phase modulation quantum key transmitter includes a transmitting optical unit that encodes random bits into the optical signal by differential phase modulation and transmits the encoded optical signal at a preset intensity via the line-of-sight communication channel, and a first key distillation unit that generates an encryption key from the random bit sequence of the transmitting optical unit by key distillation processing via an authenticated public communication channel, and the differential phase modulation quantum key receiver includes a receiving optical unit that receives the optical signal from the transmitting optical unit via the line-of-sight communication channel and decodes the random bits from the received optical signal, and a second key distillation unit that generates an encryption key from the random bit sequence of the receiving optical unit by key distillation processing via the authenticated public communication channel. The differential phase modulation quantum key transmitting device further comprises a first channel state monitoring unit for measuring atmospheric fluctuations in the line-of-sight communication channel, the differential phase modulation quantum key receiving device further comprises a second channel state monitoring unit for measuring atmospheric fluctuations in the line-of-sight communication channel, and a channel state estimation unit for estimating the intensity of leaked light that has leaked outside the line-of-sight communication channel based on the atmospheric fluctuations measured by the first channel state monitoring unit and the second channel state monitoring unit, the transmitting optical unit sets the intensity of the optical signal to be transmitted based on the intensity of leaked light estimated by the channel state estimation unit, the first key distillation unit adjusts the compression ratio when generating an encryption key from the random bit sequence of the transmitting optical unit based on the intensity of the leaked light, and the second key distillation unit adjusts the compression ratio when generating an encryption key from the random bit sequence of the receiving optical unit based on the intensity of the leaked light. This configuration was adopted.
[0011] With this configuration, the cryptographic key sharing system can apply differential phase modulation quantum key distribution to a line-of-sight channel and set the intensity of the optical signal to an appropriate value, thereby improving key generation speed and transmission distance. Furthermore, the cryptographic key sharing system can generate cryptographic keys that satisfy universal linkability without imposing any restrictions on eavesdropping within the assumed range of the line-of-sight channel, thus enabling the sharing of information-theoretically secure cryptographic keys even if the eavesdropper's capabilities improve.
[0012] Universal connectability refers to the property that the security guaranteed for each protocol individually is maintained regardless of how they are connected or the environment in which they are used. The security of a typical quantum key distribution is measured by the trace distance between the quantum states representing the ideal protocol and the protocol actually implemented. A protocol is said to be ε-secure if the trace distance can be reduced to less than or equal to an arbitrarily specified small value ε. For example, if universal connectability is satisfied, combining an ε-secure protocol with an ε'-secure protocol results in an (ε+ε')-secure protocol. Universal connectability of cryptographic key sharing systems will be discussed later. [Effects of the Invention]
[0013] According to the present invention, it is possible to share information-theoretically secure cryptographic keys while improving key generation speed and transmission distance. [Brief explanation of the drawing]
[0014] [Figure 1] This is an explanatory diagram illustrating the communication channel model in an embodiment. [Figure 2] This is a block diagram showing the configuration of the cryptographic key sharing system according to the embodiment. [Figure 3] This is a block diagram showing the configuration of the transmitting optical unit in an embodiment. [Figure 4] This is a block diagram showing the configuration of the receiving optical unit in the embodiment. [Figure 5] This is a sequence diagram showing the key distillation process in the embodiment. [Figure 6] This is an explanatory diagram illustrating the adjustment of the compression ratio of the encryption key in the embodiment. [Figure 7] This is a block diagram showing the configuration of the communication channel condition monitoring unit in an embodiment. [Figure 8] This is a graph showing the key generation rate at asymptotic length in the example. [Figure 9] This graph shows the key generation rate for a finite length in the example. [Modes for carrying out the invention]
[0015] Embodiments will be described below with reference to the drawings. However, the embodiments described below are intended to embody the technical concept of the present invention, and unless otherwise specified, the present invention is not limited to these embodiments. In addition, the same reference numerals are used for the same means, and their descriptions may be omitted.
[0016] [Communication channel model] Referring to Figure 1, the communication channel model that underlies the cryptographic key sharing system 1 (Figure 2) according to this embodiment will be explained. We propose a cryptographic key sharing system 1 (Figure 2) employing line-of-sight quantum key distribution as a physical layer cryptographic technique applicable to line-of-sight communication channels 4 where atmospheric turbulence exists (e.g., between low-Earth orbit satellites and ground stations, and between high-altitude geostationary orbit satellites and ground stations). The security of line-of-sight quantum key distribution can be proven by applying the channel model shown in Figure 1 and the complementarity approach, one of the security proof techniques for quantum key distribution, to that channel model. This complementarity approach can prove security independently of the characteristics of the line-of-sight communication channel 4 between sender A and legitimate receiver B.
[0017] As shown in Figure 1, transmitter A has a laser light source 200 and a phase modulator 202, and encodes random bits. In this case, the modulation method is a differential phase modulation method in which the bit value is determined by the relative phase of the preceding and succeeding light pulses. Also, the average number of photons of the light pulses is μ A This is expressed as follows: The average number of photons is μ. A The method for determining this will be described later.
[0018] Transmitter A transmits a modulated light pulse train 90 to regular receiver B via a phase-insensitive line-of-sight channel 4. Note that any physical phenomenon, not limited to atmospheric turbulence, may affect the light pulse train 90 passing through the line-of-sight channel 4. However, the sole condition is that the line-of-sight channel 4 is independent of the absolute phase of each light pulse and the relative phase between light pulses. This condition is called phase insensitivity. For this phase insensitivity condition to be broken, the line-of-sight channel 4 must have a mechanism such that the dipole moment of particles in the atmosphere resonates with the phase of the light pulse and further affects subsequent photons. Therefore, the relaxation time of the dipole moment must be longer than the interval between light pulses, or the linewidth of the resonance frequency of the moment must correspond to that interval. At the current modulation speed of differential phase modulation (approximately 1 GHz), it is unlikely that molecules in the atmosphere have such sharp linewidths. Therefore, differential phase modulation is considered to satisfy this phase insensitivity condition.
[0019] As shown in Figure 1, regular receiver B has a 1-bit delay interferometer 301 and two photon detectors 302 (3020, 3021) located at its output. Regular receiver B demodulates the optical pulse sent from transmitter A.
[0020] The photon detector 302 is an on-off type photon detector that turns on when it detects the presence of photons, regardless of the number of photons. The regular receiver B assigns the number "0" to the first photon detector 3020 and "1" to the second photon detector 3021, and records the numbers of the photon detectors 3020 and 3021 that are turned on at a certain time. The bit sequence obtained by arranging this bit information in chronological order is called the regular receiver B's raw key. Note that the on-off type photon detector 302 has the property of being a dark count, which means it outputs an electrical pulse even when no photons have arrived. Also, due to the imperfections of the delay interferometer, there is a possibility that photons may leak to the wrong output port. Even if both photon detectors 3020 and 3021 are turned on simultaneously due to these effects, it is treated as a successful detection and assigned either "0" or "1".
[0021] The eavesdropper E's eavesdropping method, similar to physical layer cryptography, is limited to passive eavesdropping scenarios from various non-line-of-sight locations (e.g., the edge of the beam footprint, behind the legitimate receiver B) in order to avoid detection by the sender A and legitimate receiver B. In line-of-sight quantum key distribution, these eavesdropping scenarios are reduced to a model in which eavesdropper E eavesdrops through a beam splitter 91 placed in front of sender A. In this eavesdropping model, eavesdropper E takes a portion of the light pulse intensity transmitted by sender A, based on the reflectivity (tapping rate) η of the beam splitter 91. E It is assumed that the light intensity corresponding to can be stolen. In other words, the tapping rate η E This represents the ratio to which eavesdropper E can tap the optical signal 40 in the line-of-sight communication channel 4. On the other hand, eavesdropper E can eavesdrop using a receiving device that implements an arbitrary demodulation method, similar to quantum cryptography, and can perform arbitrary signal processing on the eavesdropped information. Note that the tapping rate η E The method for determining this will be described later.
[0022] The bit sequences of the sender A and the legitimate receiver B, that is, the raw keys, are different from each other and may partially leak to the eavesdropper E. In order to generate a bit sequence of equal security, that is, the final key, from this raw key, a signal processing called key distillation processing is performed while exchanging information on the authenticated public communication channel 5.
[0023] The security of this prospective communication quantum key distribution, similar to general quantum key distribution, can be calculated by the trace distance d Tr (ρ,σ) between two quantum states ρ and σ as shown in the following formula (1). Here, Tr represents the trace operator.
[0024]
Equation
[0025] The state of the final key of the sender A at the end of the key distillation process |κ fin A >>κ fin A | and the quantum state ρ E (κ fin A ) held by the eavesdropper E in the quantum memory are represented by the following formula (2). Here, the bit sequence of the final key of the sender A is represented by κ fin A .
[0026]
Equation
[0027] Also, the quantum state corresponding to the ideal key is represented by the following formula (3). Here, |·| represents the length of the sequence, and Tr A (·) represents the partial trace focusing on the system of the sender A. The trace distance between these two quantum states is defined by the following formula (4).
[0028]
Equation
Equation
[0029] The value defined by equation (4) is called the quantum universal security criterion. In line-of-sight quantum key distribution, security can be evaluated using this quantum universal security criterion, so security can be evaluated even if an eavesdropper E can perform general eavesdropping using quantum mechanics. Furthermore, since the quantum universal security criterion is a security criterion that satisfies so-called universal couplingability, it is possible to perform security evaluations that are compatible with other security technologies that satisfy universal couplingability. Note that the calculation result of equation (4) is a pre-set value ε. X If it is smaller than ε, this line-of-sight communication quantum key distribution protocol is ε X -Assume it is safe.
[0030] In line-of-sight communication, highly directional laser light is used, making it virtually impossible for eavesdropper E to carry out an active attack such as placing an eavesdropping device at the center of the light beam and then processing and retransmitting all the optical signals without being detected by sender A and legitimate receiver B. Therefore, eavesdropper E has no choice but to utilize light leaking from the line-of-sight communication channel 4 due to atmospheric fluctuations, etc., while staying out of the line of sight of sender A and legitimate receiver B. However, it is clear that disturbances in the natural environment, including atmospheric fluctuations, cannot be secretly and intentionally controlled by eavesdropper E. For these reasons, it is considered reasonable to assume a channel model in line-of-sight communication using laser light in which eavesdropper E can only tap information from the leaking optical signals. Furthermore, the state of the line-of-sight communication channel 4 and its surroundings can be directly observed by various means, making it possible to judge the validity of the eavesdropping model.
[0031] As described above, assuming a line-of-sight communication channel 4, the leaked light that leaks outside the line-of-sight communication channel 4 is tapping rate η EThis can be expressed as and can be easily modeled using the beam splitter 91. In this case, the eavesdropping activity by eavesdropper E is limited to performing some operation, including measuring the leaked light. Under this assumption, if a differential phase modulation scheme is adopted as the quantum key distribution scheme, a cryptographic key with general coupling capability can be generated.
[0032] [Configuration of the cryptographic key sharing system] Referring to Figure 2, the configuration of the cryptographic key sharing system 1 according to this embodiment will be described. The cryptographic key sharing system 1 uses an optical signal 40 propagating through a line-of-sight communication channel 4 to share cryptographic keys between a sender system (differential phase modulation quantum key transmitter) 2 and a legitimate receiver system (differential phase modulation quantum key receiver) 3. As shown in Figure 2, the cryptographic key sharing system 1 comprises a sender system 2, a legitimate receiver system 3, a line-of-sight communication channel 4, and an authenticated public communication channel 5. In Figure 2, the optical signal 40, probe light 41, and atmospheric fluctuations 42 in the line-of-sight communication channel 4 are illustrated.
[0033] The transmitter system 2 transmits an optical signal 40 to the regular receiver system 3 via a line-of-sight communication channel 4, and comprises a transmitting optical unit 20, a key distillation unit (first key distillation unit) 21, and a communication channel state monitoring unit (first communication channel state monitoring unit) 22.
[0034] The transmitting optical unit 20 encodes random bits into an optical signal 40 by differential phase modulation and transmits the encoded optical signal 40 at a preset intensity via the line-of-sight communication channel 4. The key distillation unit 21 generates an encryption key from the random bit sequence of the transmitting optical unit 20 by key distillation processing via the authenticated public communication channel 5.
[0035] The communication channel condition monitoring unit 22 measures the state of the line-of-sight communication channel 4 (atmospheric fluctuations 42). Here, the communication channel condition monitoring unit 22 uses a sufficiently strong laser beam (probe light 41) irradiated by the communication channel condition monitoring unit 32, which will be described later. BThe state of the line-of-sight communication channel 4 is measured by observing the probe light 41. A The light is directed at the communication channel condition monitoring unit 32.
[0036] The regular receiver system 3 receives optical signals 40 from the transmitter system 2 via a line-of-sight communication channel 4, and comprises a receiving optical unit 30, a key distillation unit (second key distillation unit) 31, and a communication channel state monitoring unit (second communication channel state monitoring unit) 32.
[0037] The receiving optical unit 30 receives an optical signal 40 from the transmitting optical unit 20 via the line-of-sight communication channel 4 and decodes random bits from the received optical signal 40. The key distillation unit 31 generates an encryption key from the random bit sequence of the receiving optical unit 30 by key distillation processing via the authenticated public communication channel 5.
[0038] The communication channel condition monitoring unit 32 measures the state of the line-of-sight communication channel 4 (atmospheric fluctuations 42). Here, the communication channel condition monitoring unit 32 uses a sufficiently strong laser beam (probe light 41) irradiated by the communication channel condition monitoring unit 22. A The state of the line-of-sight communication channel 4 is measured by observing the probe light 41. B The light is directed at the communication channel condition monitoring unit 22.
[0039] Line-of-sight communication channel 4 is a communication channel for line-of-sight communication. Here, line-of-sight communication is a state of communication where there are no obstructions between the sender and receiver, and they can see each other clearly. Examples of line-of-sight communication include optical communication between low-Earth orbit satellites and ground stations, and optical communication between high-altitude geostationary orbit satellites and ground stations. Authenticated public channel 5 is an authenticated public channel. For example, authenticated public channel 5 is used to send and receive information about key distillation and the state of line-of-sight channel 4.
[0040] [Configuration of the transmitting optical unit] Referring to Figure 3, the configuration of the transmitting optical unit 20 will be explained. As shown in Figure 3, the transmitting optical unit 20 includes a laser light source 200, a physical random number source 201, a phase modulator 202, a light intensity adjuster 203, and a transmitting optical system 204.
[0041] The laser light source 200 is a laser light source that generates a train of light pulses. The physical random number source 201 generates random bit sequences. The phase modulator 202 phase-modulates the optical pulse train generated by the laser light source 200 based on the random bit sequence generated by the physical random number source 201.
[0042] The optical intensity adjuster 203 adjusts the intensity of the optical pulse train modulated by the phase modulator 202 to an appropriate level. In this embodiment, the optical intensity adjuster 203 adjusts the tapping rate η estimated by the channel state estimation unit 324, which will be described later. E Based on this, the intensity of the light pulse train is adjusted. Here, the light intensity adjuster 203 controls the tapping rate η E When the tapping rate η is large (i.e., when the intensity of leaked light is large), the light signal intensity is set to be reduced. On the other hand, the light intensity adjuster 203 controls the tapping rate η E When the value is small (i.e., when the intensity of leaked light is small), the intensity of the optical signal is set to increase.
[0043] The transmitting optical system 204 is an optical system that transmits a train of light pulses (optical signals 40) whose intensity has been adjusted by the light intensity adjuster 203 via the line-of-sight communication channel 4. For example, the transmitting optical system 204 consists of a transmitting telescope for focusing light, a coarse tracking system that changes the attitude of the transmitting telescope in accordance with the relative positional changes between the transmitter system 2 and the regular receiver system 3, and a fine tracking system for correcting fine changes in beam position caused by atmospheric turbulence 42, etc.
[0044] The operation of the transmitting optical unit 20 will be described below. Length (N) output from laser light source 200 totThe optical pulse train (x0, x1, ..., x) is input to the phase modulator 202. This optical pulse train is the transmission sequence (x0, x1, ..., x) output from the physical random number source 201. Ntot Based on this, phase modulation (for any index i, x i If =0 then 0, x i If = 1, then π) is applied. Note that N tot This represents the total number of light pulses transmitted.
[0045] The phase-modulated light pulse train is input to the light intensity tuner 203, and its intensity is measured by the average number of photons μ A The light is adjusted (dimmed) until it reaches this value. Here, the average number of photons is μ. A This is the tapping rate η input from the communication channel state estimation unit 324. E Based on this, the settings are configured to maximize the key generation speed. The dimmed light pulse train is input to the transmitting optical system 204 and then to the line-of-sight communication channel 4.
[0046] Furthermore, for a transmission sequence, a certain bit x i and the previous bit x i―1 By performing a differential exclusive OR operation to calculate the exclusive OR of the raw key sequence (a1, ..., a Ntot This generates the raw key sequence (a1, ..., a Ntot ) is input to the key distillation unit 21.
[0047] [Configuration of the receiving optical unit] Referring to Figure 4, the configuration of the receiving optical unit 30 will be explained. As shown in Figure 4, the receiving optical unit 30 comprises a receiving optical system 300, a 1-bit delay interferometer 301, and a photon detector 302.
[0048] The receiving optical system 300 is an optical system that receives a train of light pulses (optical signals 40) from the transmitting optical unit 20 via the line-of-sight communication channel 4. For example, the receiving optical system 300 consists of a receiving telescope for receiving light, a coarse tracking system that changes the attitude of the receiving telescope in accordance with the relative positional changes between the transmitting system 2 and the regular receiver system 3, and a fine tracking system for correcting fine changes in beam position caused by atmospheric turbulence 42, etc.
[0049] The 1-bit delay interferometer 301 interferes with the optical pulse train received by the receiving optical system 300 by delaying the optical pulses by 1 bit. The photon detector 302 is an on-off type photon detector and consists of two photon detectors 3020 and 3021. Note that photon detector 3020 may be referred to as D0 and photon detector 3021 as D1.
[0050] The operation of the receiving optical unit 30 will be described below. The light pulse train received by the receiving optical system 300 is input to the 1-bit delay interferometer 301 for demodulation using differential phase modulation. The light pulses output from the 1-bit delay interferometer 301 are input to either of the two photon detectors 3020 or 3021, depending on the output port. Specifically, light pulses with a relative phase of 0 to the previous light pulse are input to photon detector 3020, and light pulses with a relative phase of π are input to photon detector 3021.
[0051] Then, by arranging the outputs of the photon detector 302 that are turned on in each time slot in a time series, the raw key sequence (b1, ..., b Ntot This generates the raw key sequence (b1, ..., b Ntot ) is input to the key distillation unit 31.
[0052] Table 1 shows the raw key sequence (b1, ..., b Ntot The rules for determining b are shown below. As shown in Table 1, if only the photon detector 3020 is turned on, then b i If we set = 0 and only the photon detector 3021 is turned on, then b iLet = 1. Also, if both photon detectors 3020 and 3021 are turned on, b i = 0 or b i =1 is randomly determined. Also, if both photon detectors 3020 and 3021 are turned off, it is assumed that the photons have been dissipated, and a symbol representing detection failure is set (b i =×).
[0053] [Table 1]
[0054] [Key distillation process] Referring to Figure 5, the key distillation process performed by the key distillation units 21 and 31 will be explained. As shown in Figure 5, the key distillation process is performed via an authenticated public communication channel 5 and consists of four processes: shifting S1, qubit error rate estimation S2, information matching S3, and confidentiality enhancement S4.
[0055] <Shifting> In shifting S1, the key distillation unit 31 of the regular receiver system 3 publishes the index information of successful photon reception to the sender system 2. This index information is b i This represents the index i such that ≠ ×.
[0056] The key distillation unit 21 of the sender system 2 is the raw key sequence (a1, ..., a Ntot From this, the key distillation unit 21 extracts bits corresponding to the index information it has released and arranges them in chronological order to construct a shifted bit sequence, i.e., a shifted key sequence. In other words, the key distillation unit 21 extracts bits that the regular receiver system 3 has not received from the raw key sequence (a1, ..., a Ntot Remove from ). The key distillation unit 31, like the key distillation unit 21, is the raw key sequence (b1, ..., b) of the regular receiver system 3. Ntot Construct a shift key sequence from ).
[0057] <Estimation of Quantum Bit Error Rate> In the qubit error rate estimation S2, the key distillation unit 31 of the regular receiver system 3 calculates probability p for each bit of the shifted key sequence. test Bernoulli sampling is performed. Then, the key distillation unit 31 extracts a bit sequence based on the sampling result, thereby obtaining a test bit sequence of length N from the regular receiver system 3. test It consists of the following. Furthermore, the key distillation unit 31 exposes its test bit sequence and the index information in its shift key sequence to the sender system 2.
[0058] The key distillation unit 21 of the sender system 2 constructs the test bit sequence of the sender system 2 by extracting bits from the shift key sequence of the sender system 2 based on the index information published by the regular receiver system 3. Then, the key distillation unit 21 estimates the qubit error rate by comparing the test bit sequences of the sender system 2 and the regular receiver system 3. The length of the shift key sequence after extracting the test bit sequence is N. sift Let's assume that the shift key sequence of sender system 2 is (a1,...,a Nsift ) and the shift key sequence of regular receiver system 3 is (b1, ..., b Nsift )
[0059] <Information matching> In information matching S3, the key distillation unit 21 of the sender system 2 calculates the error correction information necessary for error correction based on the estimated qubit error rate. The length of this error correction information is N. IR The key distillation unit 21 then encrypts this error correction information using a key that has already been shared, i.e., a one-time pad, only once, and then publishes it to the regular recipient system 3. Note that the correction key sequence of the sender system 2 is (a1,...,a Nsift ) is identical to the shift key sequence.
[0060] The key distillation unit 31 of the regular receiver system 3 uses the error correction information released by the sender system 2 to extract a corrected key sequence (a'1,...,a') from the shift key sequence of the regular receiver system 3 that matches the shift key sequence of the sender system 2 with a very high probability. Nsift ) constitutes.
[0061] <Enhanced Confidentiality> In the security enhancement S4, the channel state estimation unit 324 of the regular receiver system 3 calculates the tapping rate η based on the measured atmospheric turbulence of the line-of-sight communication channel 4. E The channel state estimation unit 324 then estimates the tapping rate η. E This will be made public to sender system 2. Note that the tapping rate η E The estimation method will be described in detail later.
[0062] The key distillation unit 21 of the sender system 2, as described below, uses the tapping rate η disclosed by the regular receiver system 3. E Based on this, the compression ratio is adjusted when generating the encryption key from the random bit sequence of the transmitting optical unit 20. Similarly, the key distillation unit 31 of the regular receiver system 3 adjusts the tapping ratio η E Based on this, the compression ratio is adjusted when generating an encryption key from the random bit sequence of the receiving optical unit 30. The encryption key compression ratio represents the ratio of the sequence sizes when the final key sequence is generated from the corrected key sequence in the confidentiality enhancement S4.
[0063] Refer to Figure 6 to explain how to adjust the compression ratio of the encryption key. In Figure 6, slots 60-62, indicated by dots, represent slots (raw key sequences) that the regular receiver system 3 successfully received. Also, slot 60, marked with a circle, represents N sift This represents a sequence of shift keys. Also, slot 61, marked with a triangle, represents N test This represents a sequence of test bits. Also, slot 62, which is marked with both a triangle and a square, represents the test bit (N) located immediately before the shift key. sif-tes This represents the number of slots (N) that failed to receive data, located immediately before the shift key. cand It represents an individual.
[0064] The key distillation unit 31 of the regular receiver system 3 has a test bit sequence number N. test And the number of test bits (slot 62) located immediately before the shift key, N. sif-tes And, among the slots that failed to receive data, the number of bits (slot 63) in the slot immediately following it that were adopted as the shift key sequence is N.cand This will be made public to sender system 2.
[0065] The key distillation unit 21 of the sender system 2 receives N from the regular receiver system 3. test , N sif-tes and N cand Based on the information, the secret key length N can be calculated using the following formulas. fin The key distillation unit 21 is N sift ×N fin A two-dimensional compression matrix of size is generated and sent to the regular receiver system 3. Furthermore, the key distillation unit 21 corrects the compression matrix into a correct key sequence (a1, ..., a Nsift By multiplying by ), the final key (k1, ..., k G Similarly, the key distillation unit 31 of the regular receiver system 3 generates a corrected key sequence (a'1,...,a') from its compressed matrix. Nsift By multiplying by ), the final key (k'1,...,k' G ) generates.
[0066] The length G of the final key generated by the above key distillation process is expressed by the following equation (5). Of the right-hand side of equation (5), the length N of the error correction information... IR This is determined by the error correction technology adopted in information integrity S3. Also, the final key length N fin This can be expressed by the following equation (6).
[0067]
number
number
[0068] Here, the function h²(p) is called the two-dimensional entropy and is defined by the following equation (7). Also, k ph N satisfies either equation (8) or equation (9) below. L rec The following are positive integers. Also, function D KL(p||q) is called the Kullback-Leibler information quantity and is defined by the following formula (10). For arbitrarily given parameters ε, s, this protocol is {2(ε - 2 -s )} 1 / 2 -secure.
[0069] [Number]
[0070] p ph (μ) is related to the amount of information leaked to eavesdropper E, called the phase error rate, and is expressed by the following formula (11).
[0071] [Number]
[0072] N L rec is the length of the bit sequence excluding the bits related to the test bit sequence published by the quantum bit error rate estimator S2, and is expressed by the following formula (12). Here, k test is N that satisfies either of the following formulas (13) and (14) cand and is the following positive integer (note that the definitions of N cand and p test are as described above).
[0073] [Number]
[0074] [Configuration of Channel State Monitoring Unit] Referring to FIG. 7, the configurations of the channel state monitoring units 22 and 32 will be described. Note that FIG. 7 extracts the configurations related to the channel state monitoring units 22 and 32 from the encryption key sharing system 1 of FIG. 2. As shown in FIG. 7, the communication path state monitoring unit 22 of the transmitter system 2 includes a probe light irradiation unit 220, a reception intensity measurement unit 221, a DIMM unit 222, and a weather sensor 223.
[0075] The communication path state monitoring unit 32 of the legitimate receiver system 3 includes a probe light irradiation unit 320, a reception intensity measurement unit 321, a DIMM unit 322, a weather sensor 323, a communication path state estimation unit 324, and a storage unit 325. Note that the communication path state monitoring unit 32 will be mainly described focusing on the differences from the communication path state monitoring unit 22.
[0076] The probe light irradiation units 220 and 320 are laser beam light sources that irradiate probe light 41 through the line-of-sight communication path 4. In the present embodiment, the probe light irradiation unit 220 of the transmitter system 2 irradiates the probe light 41 toward the legitimate receiver system 3 from a position coaxial with or very close to the transmission optical system 204. A Also, the probe light irradiation unit 320 of the legitimate receiver system 3 irradiates the probe light 41 toward the transmitter system 2 from a position coaxial with or very close to the reception optical system 300. B At this time, it is preferable that the probe light irradiation units 220 and 320 have different wavelengths and polarization directions of the probe light 41 with respect to the optical signal 40 to prevent crosstalk between the optical signal 40 and the probe light 41.
[0077] The reception intensity measurement units 221 and 321 receive the probe light 41 through the line-of-sight communication path 4, and measure the scintillation index and beam acquisition error from the probe light 41 as the state (atmospheric turbulence 42) of the line-of-sight communication path 4. In the present embodiment, the reception intensity measurement unit 221 of the transmitter system 2 measures the scintillation index and beam acquisition error from the probe light 41 irradiated by the probe light irradiation unit 320 of the legitimate receiver system 3. B Also, the reception intensity measurement unit 321 of the legitimate receiver system 3 measures the scintillation index and beam acquisition error from the probe light 41 irradiated by the probe light irradiation unit 220 of the transmitter system 2. A From.
[0078] The DIMM units 222 and 322 measure the Fried parameters related to the refractive index of the atmosphere present in the line-of-sight communication channel 4 as the state of the line-of-sight communication channel 4 (atmospheric fluctuation 42). DIMM stands for Differential Image Motion Monitor. These DIMM units 222 and 322 measure the relative centroid fluctuations of the image formed on the camera sensor by probe light 41 that has passed through an aperture at a distance. In this embodiment, the DIMM unit 222 measures the Fried parameters on the transmitter system 2 side, and the DIMM unit 322 measures the Fried parameters on the regular receiver system 3 side.
[0079] Weather sensors 223 and 323 measure atmospheric wind pressure, humidity, temperature, and atmospheric pressure as conditions of the line-of-sight communication channel. Weather sensor 223 measures weather parameters on the transmitter system 2 side, and weather sensor 323 measures weather parameters on the regular receiver system 3 side.
[0080] Furthermore, the transmission channel status monitoring unit 22 of the transmission system 2 transmits the status of the line-of-sight transmission channel on the transmission side to the transmission channel status estimation unit 324 of the regular receiver system 3 via the authenticated public transmission channel 5.
[0081] The channel state estimation unit 324 calculates the intensity of leaked light (tapping rate η) that has leaked outside the line-of-sight channel 4 based on atmospheric fluctuations measured by the channel state monitoring units 22 and 32. E This estimates the tapping rate η (however, this does not apply when the transmitting side, such as a satellite, is in outer space). Here, the channel state estimation unit 324 estimates the tapping rate η E When estimating this, the history data in the memory unit 325 may be referred to. The memory unit 325 is a storage device such as a memory or HDD (Hard Disk Drive) that stores historical data of the state of the line-of-sight communication channel 4.
[0082] The following is tapping η E An example of an estimation method will be explained. If the atmosphere is sufficiently stable (for example, if the siciency index is 10 -2In the following cases, the contribution of light leakage to the outside of the line-of-sight communication channel 4 is small, and the accuracy of the equipment used to monitor the line-of-sight communication channel 4 is also high, so the possibility of eavesdropping on the line-of-sight communication channel 4 is considered low. In such cases, the communication channel state estimation unit 324 determines the tapping rate η E Set a low value (for example, 10) -6 We estimate it using ).
[0083] When the atmosphere is unstable (for example, when the scintillation index is 10 -1 In the above case, the contribution of light leakage to the outside of the line-of-sight communication channel 4 is large, and the accuracy of the equipment used to monitor the line-of-sight communication channel 4 is also low, so it is considered that there is a high possibility of eavesdropping on the line-of-sight communication channel 4. Furthermore, in the worst case, it is also possible that all the photons that leak to the outside of the line-of-sight communication channel 4 are eavesdropped on. In such a case, the communication channel state estimation unit 324 calculates the tapping rate η E This is estimated using a high setting (for example, 1 - (loss rate between sender and legitimate recipient)).
[0084] In this embodiment, the scintillation index is measured in both the sender system 2 and the regular receiver system 3. Therefore, the scintillation index measured in the sender system 2 may be applied to the sender system 2 side of the line-of-sight communication channel 4, and the scintillation index measured in the regular receiver system 3 may be applied to the regular receiver system 3 side of the line-of-sight communication channel 4. Alternatively, a statistical value (e.g., the mean value) may be obtained from the scintillation indices of the sender system 2 and the regular receiver system 3, and that statistical value may be used. Also, the tapping rate η E When estimating this, other indicators besides the scintillation index (such as beam capture error, Fried parameters, and atmospheric wind pressure) may also be used.
[0085] [Effects / Effects] As described above, the cryptographic key sharing system 1 according to the embodiment applies differential phase modulation quantum key distribution to the line-of-sight communication channel 4 and can set the intensity of the optical signal to an appropriate value, thereby improving key generation speed and transmission distance. Furthermore, the cryptographic key sharing system 1 can generate cryptographic keys that satisfy general linkability without imposing any restrictions on eavesdropping within the assumed range of the line-of-sight communication channel 4, so it can share information-theoretically secure cryptographic keys even if the capabilities of eavesdroppers improve.
[0086] In other words, the cryptographic key sharing system 1 can efficiently generate secure cryptographic keys even when physical constraints on optical signals are relaxed, by applying a quantum key distribution scheme based on differential phase modulation to a line-of-sight communication channel 4 in free space. Furthermore, the cryptographic key sharing system 1 can generate secure cryptographic keys regardless of changes in the state of the line-of-sight communication channel 4, and maximize the amount of cryptographic keys generated, by observing the state of the line-of-sight communication channel 4 and adaptively adjusting the intensity of the transmitted optical signal and the compression ratio of the cryptographic key according to the measurement results.
[0087] Furthermore, the cryptographic key sharing system 1 can efficiently share information-theoretically secure cryptographic keys between low-Earth orbit satellites and ground stations, keys that cannot be broken even by sophisticated eavesdropping using quantum technology. Moreover, the cryptographic key sharing system 1 can achieve information-theoretically secure cryptographic key sharing between high-altitude geostationary orbit satellites and ground stations, even over extremely long distances, keys that cannot be broken even by sophisticated eavesdropping using quantum technology. As a result, the cryptographic key sharing system 1 can extend information-theoretically secure information communication networks to a global scale.
[0088] (modified version) Although embodiments have been described in detail above, the present invention is not limited to the embodiments described above, and includes design changes and the like that do not depart from the spirit of the present invention.
[0089] In the above embodiment, the light intensity adjuster adjusts the tapping rate η estimated by the channel state estimation unit. EBased on this, the explanation described involves adjusting the intensity of the optical signal, but it is not limited to this. For example, the administrator of the cryptographic key sharing system may pre-set the intensity of the optical signal. [Examples]
[0090] As an example, to demonstrate the effectiveness of the cryptographic key sharing system according to the embodiment, we will describe the results of a performance comparison with conventional physical layer cryptography and quantum key distribution.
[0091] Generally, the performance of each key sharing technology is determined by the total number of optical pulses N transmitted. tot The key generation rate can be evaluated by the ratio of the key length G to the key length. In Figure 8, the key generation rate of a cryptographic key sharing system is shown by a solid line, the key generation rate of conventional physical layer cryptography is shown by a dashed line, and the key generation rate of conventional quantum key distribution is shown by a dashed line.
[0092] Figure 8 shows the total number of light pulses N, called the asymptotic length. tot In an ideal environment where can be set to infinity, the key generation rate of each key sharing technology is calculated in relation to the loss between the sender and the legitimate receiver. Here, the repetition rate of the optical pulse is 1 GHz, the dark count rate of the detector is 1 kHz, and the efficiency of the error correction code from the Shannon limit is 1.1. Also, the line-of-sight channel has a transmittance of (1-η). B We are considering a linear loss channel model that can be modeled with a beam splitter. The transmittance between the sender and the regular receiver is (1-η). E )(1-η B It is represented as η. B This represents the loss in line-of-sight communication channels.
[0093] The modulation scheme and channel model for physical layer cryptography are assumed to be the same as those for the cryptographic key sharing system. A comparison of the key generation rates between the cryptographic key sharing system and physical layer cryptography is shown below (code 92). L ), medium (code 92 M ), small (code 92 S ) and three types of tapping rates η E This is being done. In each case, the average number of photons in the light pulse is μA It is being numerically optimized.
[0094] As shown in Figure 8, the key generation rate of conventional quantum key distribution (dash-dot line) is the lowest among the three key sharing technologies, and decreases sharply when the loss between the sender and legitimate receiver exceeds 50 dB. Since this loss value is equivalent to the link budget α of low-Earth orbit satellite-to-ground optical communication, physical layer cryptography is inevitably required for communication between satellites in medium orbit and beyond and ground stations.
[0095] The key generation rate (solid line) of a cryptographic key sharing system decreases sharply as the loss between the sender and legitimate receiver decreases, similar to conventional quantum key distribution. However, the tapping rate η of an eavesdropper E As the tapping rate η decreases, key generation becomes possible even with greater losses. In cryptographic key sharing systems, the tapping rate η E If the tapping rate η is sufficiently small, a key can be generated even with a loss equivalent to the link budget β of geostationary satellite-to-ground optical communication. Therefore, in cryptographic key sharing systems, the tapping rate η E Under conditions where this can be estimated with a certain degree of accuracy, it becomes possible to realize a globally secure communication network, which is difficult with conventional quantum key distribution.
[0096] When compared at the same tapping rate, the key generation rate of conventional physical layer cryptography (dashed line) is always a certain percentage higher than that of cryptographic key sharing systems, and does not decrease sharply even if the loss between the sender and legitimate receiver becomes large. Therefore, physical layer cryptography is more suitable for high-speed or long-distance communication than line-of-sight quantum key distribution. However, if there is concern that eavesdroppers may use eavesdropping methods that apply quantum mechanical techniques, then from a security standpoint, it becomes necessary to use cryptographic key sharing systems based on line-of-sight quantum key distribution.
[0097] From the perspective of device implementation, the total number of optical pulses N tot Even when the total number of optical pulses N is finite in length, it is preferable to achieve performance close to the theoretical limit at the asymptotic length. Therefore, Figure 9 shows the total number of optical pulses N. totThe key generation rate of a cryptographic key sharing system is illustrated in an environment where the key is set to a finite length.
[0098] As shown in Figure 9, each tapping ratio (indicated by 92 L ,92 M ,92 S ) in which the total number of light pulses N tot 10 9 When there are a certain number of pulses, it can be seen that the performance is very close to the asymptotic length. When the transmission rate is 1 GHz, the total number of these optical pulses N tot The value corresponds to one second, meaning that a sufficient amount of keys can be stored not only for geostationary satellites but also within the limited communication time window of ground-to-ground optical communication between low-Earth orbit satellites that orbit the Earth at relatively high speeds. Furthermore, the burden on the computer during key distillation must also be considered, but considering the dissipation of photons in the communication channel, it is thought that only a small amount of shifted keys will remain that can be adequately processed by currently available key distillation hardware. Therefore, it can be realized with hardware at the current level of technology. [Explanation of Symbols]
[0099] 1. Cryptographic key sharing system 2. Transmitter System (Differential Phase Modulation Quantum Key Transmitter) 3. Standard Receiver System (Differential Phase Modulation Quantum Key Receiver) 4. Line of sight communication channel 5. Authenticated public communication channels 20 Transmitting Optical Unit 21 Key Distillation Section (First Key Distillation Section) 22. Communication channel status monitoring unit (First communication channel status monitoring unit) 30 Receiving Optical Section 31 Key distillation section (second key distillation section) 32. Communication channel status monitoring unit (second communication channel status monitoring unit) 324 Communication channel state estimation unit
Claims
1. A cryptographic key sharing system that uses optical signals propagating through a line-of-sight communication channel to share cryptographic keys between a differential phase modulation quantum key transmitter and a differential phase modulation quantum key receiver, The differential phase modulation quantum key transmitter is A transmitting optical unit that encodes random bits into an optical signal by differential phase modulation and transmits the encoded optical signal at a preset intensity via the line-of-sight communication channel, The system comprises a first key distillation unit that generates an encryption key from a random bit sequence of the transmitting optical unit by key distillation processing via an authenticated public communication channel, The differential phase modulation quantum key receiver is A receiving optical unit receives the optical signal from the transmitting optical unit via the line-of-sight communication channel and decodes the random number bits from the received optical signal, A second key distillation unit generates an encryption key from a random bit sequence of the receiving optical unit through key distillation processing via the aforementioned authenticated public communication channel, Equipped with, The differential phase modulation quantum key transmitter is The system further comprises a first communication channel condition monitoring unit for measuring atmospheric fluctuations in the line-of-sight communication channel, The differential phase modulation quantum key receiver is A second communication channel condition monitoring unit for measuring atmospheric fluctuations in the aforementioned line-of-sight communication channel, The system further includes a communication channel state estimation unit that estimates the intensity of leaked light that has leaked outside the line-of-sight communication channel based on atmospheric fluctuations measured by the first communication channel state monitoring unit and the second communication channel state monitoring unit, The transmitting optical unit sets the intensity of the optical signal to be transmitted based on the intensity of the leaked light estimated by the communication channel state estimation unit. The first key distillation unit adjusts the compression ratio when generating an encryption key from the random bit sequence of the transmitting optical unit based on the intensity of the leaked light. The cryptographic key sharing system is characterized in that the second key distillation unit adjusts the compression ratio when generating an encryption key from the random bit sequence of the receiving optical unit based on the intensity of the leaked light.
2. The encryption key sharing system according to claim 1, characterized in that the transmitting optical unit is set to weaken the intensity of the transmitted optical signal when the intensity of the leaked light is high, and to strengthen the intensity of the optical signal when the intensity of the leaked light is low.
3. The first key distillation unit adjusts itself so that when the intensity of the leaked light is high, the compression ratio of the encryption key generated from the random bit sequence of the transmitting optical unit is high, and when the intensity of the leaked light is low, the compression ratio of the encryption key is low. The cryptographic key sharing system according to claim 1 or 2, characterized in that the second key distillation unit is adjusted so that when the intensity of the leaked light is high, the compression ratio when generating the cryptographic key from the random bit sequence of the receiving optical unit is high, and when the intensity of the leaked light is low, the compression ratio of the cryptographic key is low.
4. The encryption key sharing system according to any one of claims 1 to 3, characterized in that the communication channel state estimation unit estimates the tapping rate, which is the ratio at which an eavesdropper can tap the optical signal in the line-of-sight communication channel, as the intensity of the leaked light.
Citation Information
Patent Citations
Quantum communication system and quantum communication method
JP2016154324A
Quantum communication network
JP2019216413A
Secure communication network
JP2020145672A
Single photons source and key distribution
WO2019139544A1