Receiving device, quantum cryptography system, information coordination method, and program
Patent Information
- Application Number
- JP2025508001
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-22
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2043-03-22
Smart Images

Figure 0007913641000001 
Figure 0007913641000002 
Figure 0007913641000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a receiving device, a quantum cryptography system, an information reconciliation method, and a computer-readable medium. [Background Art]
[0002] Patent Documents 1 and 2 disclose a technology related to key distillation for generating a final key used in cryptographic communication. Key distillation includes information reconciliation (also referred to as error correction) for generating a corrected key from a sifted key, and privacy amplification for enhancing the privacy of the corrected key. [Prior Art Documents] [Patent Documents]
[0003] [Patent Document 1] Japanese Unexamined Patent Publication No. 2018-37904 [Patent Document 2] Japanese Unexamined Patent Publication No. 2015-99310 [Summary of the Invention] [Problem to be Solved by the Invention]
[0004] Random numbers may be required in information reconciliation. When the above random numbers are generated using a hardware random number generator, there is a problem that additional hardware is required.
[0005] Accordingly, one of the objects to be achieved by the embodiments disclosed in the present specification is to provide a receiving device, a quantum cryptography system, an information reconciliation method, and a computer-readable medium that generate random numbers used for information reconciliation based on key information. [Means for Solving the Problem]
[0006] A receiving device according to a first aspect of the present disclosure includes: a quantum communication means that receives key information including information serving as a basis for a sifted key; and Random number generation means that generates a random number obtained by compressing a portion of the key information based on the characteristic value of the noise in the reception of the key information. An error correction means that performs information reconciliation based on the aforementioned random numbers, It is equipped with.
[0007] The quantum cryptography system according to the second aspect of this disclosure is A quantum cryptography system comprising a transmitting device and a receiving device, The receiving device is, A quantum communication means that receives key information, including information that forms the basis of a shift key, from the transmitting device, Random number generation means that generates a random number obtained by compressing a portion of the key information based on the characteristic value of the noise in the reception of the key information. An error correction means that performs information reconciliation based on the aforementioned random numbers, It is equipped with.
[0008] The information coordination method relating to the third aspect of this disclosure is: Receive key information containing the information that forms the basis of the shift key, A random number is generated by compressing a portion of the key information based on the characteristic value of the noise in the reception of the key information. Information reconciliation is performed based on the aforementioned random numbers.
[0009] In the non-temporary computer-readable media relating to the fourth aspect of this disclosure, A process for receiving key information that includes the information that forms the basis of the shift key, A process to generate a random number obtained by compressing a portion of the key information based on the characteristic value of the noise in the reception of the key information, A process that performs information reconciliation based on the aforementioned random numbers. This is where the program that causes the computer to execute it is stored. [Effects of the Invention]
[0010] According to the present disclosure, there can be provided a receiving device that generates random numbers used for information reconciliation based on key information, a quantum cryptography system, an information reconciliation method, and a computer-readable medium. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] [Figure 1] It is a block diagram showing the configuration of the receiving device according to Embodiment 1. [Figure 2] It is a block diagram showing the configuration of the quantum cryptography system according to Embodiment 2. [Figure 3] It is a diagram illustrating a modification of the receiving device according to Embodiment 2. MODES FOR CARRYING OUT THE INVENTION
[0012] <Embodiment 1> Figure 1 is a block diagram showing the configuration of the receiving device 1 according to Embodiment 1. The receiving device 1 includes a quantum communication unit 11, a random number generation unit 12, and an error correction unit 13. The receiving device 1 is communicably connected to a transmitting device (not shown) via an optical fiber.
[0013] The quantum communication unit 11 receives key information including information that serves as a source of shift keys. For example, the quantum communication unit 11 may measure an optical signal modulated based on the key information using a selected basis, and convert the measurement signal into digital data.
[0014] The random number generation unit 12 generates a random number obtained by compressing a part of the key information based on a characteristic value of noise in reception of the key information. Specifically, the random number generation unit 12 generates the random number by inputting a part of the key information into a hash function. A compression ratio of the hash function may be determined based on an eavesdropping amount calculated from a characteristic value of noise (e.g., variance).
[0015] The error correction unit 13 performs information reconciliation based on random numbers. Specifically, the error correction unit 13 performs a process called reverse reconciliation. In this case, the error correction unit 13 executes the process of sending error correction information to the transmitting device based on the random numbers. The error correction information may also be generated based on random numbers. Furthermore, if a part of the code of the error correction information is punctured, random numbers may be assigned to the part that is not transmitted.
[0016] The receiving device according to Embodiment 1 can generate random numbers used for information adjustment based on key information.
[0017] The receiving device 1 includes a processor, memory, and storage device (not shown in the diagram). The storage device stores a computer program that implements the information adjustment method according to this embodiment. The processor loads the computer program from the storage device into the memory and executes the computer program. In this way, the processor realizes the functions of the quantum communication unit 11, the random number generation unit 12, and the error correction unit 13.
[0018] Alternatively, the quantum communication unit 11, the random number generation unit 12, and the error correction unit 13 may each be implemented with dedicated hardware. Furthermore, some or all of the components of each device may be implemented by general-purpose or dedicated circuits, processors, etc., or combinations thereof. These may be configured on a single chip or by multiple chips connected via a bus. Some or all of the components of each device may be implemented by a combination of the aforementioned circuits, etc., and programs. Furthermore, a CPU (Central Processing Unit), GPU (Graphics Processing Unit), FPGA (field-programmable gate array), etc., can be used as the processor.
[0019] Furthermore, if some or all of the components of the receiving device 1 are implemented by multiple information processing devices or circuits, these multiple information processing devices or circuits may be centrally located or distributed. For example, the information processing devices or circuits may be implemented in a form in which each is connected via a communication network, such as a client-server system or a cloud computing system.
[0020] <Embodiment 2> Figure 2 is a diagram illustrating the configuration of the quantum cryptography system 1000 according to Embodiment 2. The quantum cryptography system 1000 includes a transmitter 100 and a receiver 200.
[0021] Specifically, the quantum cryptography system 1000 uses CV (Continuous-Variable)-QKD (Quantum Key Distribution) as its quantum key distribution protocol. CV-QKD transmits, for example, weak light with an average photon count of 1 or less, and detects this weak light using homodyne detection, similar to conventional optical communication. Unlike DV (Discrete-Variable)-QKD, which uses single photons, CV-QKD does not require a special detection device to detect single photons. Furthermore, CV-QKD has the advantage of being multiplexed with conventional optical communication using the same optical fiber. Note that the quantum key distribution protocol may also be BB84, which uses single photons.
[0022] The transmitter 100 and the receiver 200 are communicated together via an optical fiber. The optical fiber transmits key information, including information that forms the basis of the shift key. The transmitter 100 and the receiver 200 are also communicated together via a classical channel (also called a public channel). The classical channel transmits information about the selected base and error correction information.
[0023] The transmitting device 100 includes a quantum communication unit 110, an error correction unit 120, and a security enhancement unit 130. The error correction unit 120 and the security enhancement unit 130 perform key distillation.
[0024] The quantum communication unit 110 is configured to communicate with the quantum communication unit 210 of the receiving device 200. The quantum communication unit 110 transmits key information to the receiving device 200. For example, the quantum communication unit 110 generates a random bit sequence as key information and transmits a weak optical signal modulated based on this random bit sequence through an optical fiber. In this case, the basis may be randomly selected.
[0025] The key information is used for generating shift keys, calculating noise characteristic values, and generating random numbers for information adjustment. For example, the lower bits of the key information may be used to generate the random numbers mentioned above. Alternatively, bits that are discarded during shift key generation may also be used to generate random numbers.
[0026] The quantum communication unit 110 generates a shift key based on information received from the receiver 200 through the classical channel (e.g., information about the basis). An error exists between the shift key generated by the quantum communication unit 110 and the shift key generated by the quantum communication unit 210. In addition, the quantum communication unit 110 may transmit a portion (e.g., half) of the key information to the receiver 200 through the classical channel in order for the receiver 200 to calculate the noise characteristic value.
[0027] The error correction unit 120 generates a corrected key by correcting the shift key based on the error correction information received from the receiving device 200. Error correction allows a common corrected key to be shared between the transmitting device 100 and the receiving device 200. In the quantum cryptography system 1000, information adjustment is performed using a method called reverse adjustment. In reverse adjustment, error correction information is transmitted from the receiving device 200 to the transmitting device 100. Reverse adjustment is often performed in CV-QKD systems.
[0028] The security enhancement unit 130 generates a final key with enhanced security by compressing the correction key based on the amount of eavesdropping. The security enhancement unit 130 may receive the amount of eavesdropping from the receiving device 200 through a classical channel. Alternatively, the security enhancement unit 130 may receive a random number for security enhancement (e.g., a Teplitz matrix) from the receiving device 200 and enhance the security of the correction key based on this random number.
[0029] The receiving device 200 comprises a quantum communication unit 210, a random number generation unit 220, an error correction unit 230, and a security enhancement unit 240. The random number generation unit 220, the error correction unit 230, and the security enhancement unit 240 perform key distillation. The receiving device 200 is a specific example of the receiving device 1.
[0030] The quantum communication unit 210 is a specific example of the quantum communication unit 11. The quantum communication unit 210 measures the optical signal representing key information transmitted by the transmitter 100 using a selected basis. The quantum communication unit 210 may convert the measurement result into digital data. The quantum communication unit 210 generates a shift key based on the information received from the transmitter 100 through the classical channel (e.g., information about the basis).
[0031] In some cases, the receiving device 200 may be equipped with a physical random number source for basis selection. However, this physical random number source may be dedicated solely to basis selection, or it may be difficult to use this physical random number source for information adjustment.
[0032] Furthermore, the quantum communication unit 210 measures characteristic values (e.g., variance) of noise in the reception of key information. These characteristic values include, for example, variance, signal-to-noise ratio, and excess noise. The quantum communication unit 210 may also measure the characteristic values of noise by receiving a portion of the key information through a classical channel. Since the accuracy of the characteristic value estimation affects the evaluation of the amount of eavesdropping, typically, information of about half the length of the shift key may be used to estimate the characteristic value.
[0033] The random number generation unit 220 is a specific example of the random number generation unit 12. The random number generation unit 220 generates random numbers used for reverse adjustment. The random number generation unit 220 receives a portion of the key information received by the quantum communication unit 210, and characteristic values measured by the quantum communication unit 210. The random number generation unit 220 calculates the amount of eavesdropping based on the characteristic values (e.g., variance). The random number generation unit 220 also calculates the entropy h of a portion of the key information, i.e., the information used for random number generation. Then, it compresses a portion of the key information with a compression ratio (h-χ) obtained by subtracting the amount of eavesdropping χ from the entropy h. The compression ratio represents, for example, the length of the compressed random numbers.
[0034] The random number generator 220 compresses a portion of the key information using a first hash function. Specifically, the hash function is represented by multiplication using a randomly selected Teplitz matrix. The random number generator 220 may pass the compression ratio and a portion of the key information to the first hash function and receive a random number from the first hash function. The random number generator 220 does not need to have the functionality of the first hash function itself. The functionality of the first hash function may be provided, for example, in the confidentiality enhancement unit 240.
[0035] Information for random number generation may be kept separately from the information that forms the basis of the shift key and the information used to estimate characteristic values. Also, due to constraints imposed by the performance of key distillation, it may be possible to use a portion of the key information for random number generation. For example, information that is discarded by post-selection during shift key generation may be used for random number generation. Alternatively, the lower bits of the soft decision value of the information used to estimate characteristic values may be used for random number generation.
[0036] The random number generation unit 220 can generate truly random numbers or random numbers close to truly random numbers by generating random numbers from a portion of the key information. The key information is generally generated randomly. Furthermore, by compressing the information with a compression ratio corresponding to the amount of eavesdropping, the random number generation unit 220 can generate secure random numbers.
[0037] The error correction unit 230 is a specific example of the error correction unit 13. The error correction unit 230 performs reverse adjustment based on the random numbers mentioned above. The error correction unit 230 may also transmit error correction information based on the random numbers to the transmitting device 100. Furthermore, if a part of the code (e.g., Multi-Edge Type LCPC code) is punctured, that is, if a part of the code is not transmitted, the error correction unit 230 may assign random numbers to the untransmitted part.
[0038] First, let's explain the case where error correction information based on random numbers is transmitted. The error correction unit 230 generates a codeword using random numbers as information and masks the codeword with a shift key. If the shift key is given as hard judgment {0, 1}, the error correction unit 230 transmits the codeword masked with the shift key to the transmitting device 100 as error correction information. In other words, the error correction information Y is Y = Enc(X) + R B It is represented as follows: Enc represents encoding, X represents random numbers, and R B The symbol represents the shift key on the receiving side (Bob's side). The "+" sign represents XOR. In this case, the correction key X generated on the transmitting side (Alice's side) is X = Dec(Y + R). A )=Dec(Enc(X)+(R B +R A It is expressed as )). Dec represents decoding, and R A represents the shift key on the transmitting side (Alice side). Let X be the same length as the code length, (X + R B It is also possible to use the syndromes of ) and X as error correction information.
[0039] In the case of soft determination, where the shift key is given by a sign (positive or negative) representing 0 or 1 bits and an absolute value representing confidence, the sign is represented as 0 or 1, and Enc(X) is masked in the same way as in hard determination to generate Y, which is then combined with the confidence value to create error correction information. At this time, the transmitting side (Alice side) processes the sign part in the same way as in hard determination, and performs decoding by combining it with the confidence value information.
[0040] When performing multidimensional adjustment in Gaussian modulation CV-QKD, the error correction unit 230 generates a vector of random signal points from Enc(X), and uses a matrix that transforms the vector of soft-decision received values to these signal points as error correction information. The transmitting side (Alice side) applies the same transformation to the transmitted signal point vector to obtain a vector from which it determines the sign and confidence of each bit, and uses this as input for decoding.
[0041] Next, we will explain the case where random numbers are assigned to the untransmitted portion of the code included in the error correction information. Depending on the code configuration, the efficiency of the code can be improved by puncturing a part of the code. The punctured portion is not transmitted. In this case, in QKD information adjustment, the efficiency can be increased by assigning random numbers to this punctured portion in the error correction unit 230. When using a syndrome for error correction, the syndrome is generated from a data block consisting of the random numbers in the punctured portion and the shift key (or its coded portion in the case of soft decision). On the receiving side (Alice side), the punctured portion is treated as lost and decoding is performed using the syndrome.
[0042] The security enhancement unit 240 generates the final key by compressing the correction key using a second hash function. The correction key is compressed to a length obtained by subtracting the amount of information used for error correction and the amount of information suspected to have leaked during quantum communication from the mutual information amount of quantum communication. More specifically, the compression ratio r is calculated by r = β*I - χ. I is the mutual information amount between the transmitter 100 and the receiver 200. β is the efficiency of the error correction code. χ is the amount of information that may have been intercepted during quantum communication (also called the amount of intercepted information). I is determined according to the overall noise level. β is determined according to the overall noise level and code. χ is calculated according to the overall noise level, transmittance, and the level of noise other than quantum noise (also called excess noise).
[0043] Each hash function is a universal hash function. In a universal hash function, more specifically an ε-universal 2 hash function, the family of hash functions H={h}, and if the size of the hash value space is m, then if the hash values x and y are different, then |{h∈H:h(x)=h(y)}|≦ε|H| / m. A universal hash function has the property that the number of original data corresponding to a hash value, i.e., the number of corresponding functions, is constant. Therefore, if the functions are uniformly selected, it is guaranteed that no further information from the original data will leak from the hash value. A universal hash function is typically represented as multiplication by a randomly generated Teplitz matrix. The Teplitz matrix representing the hash function used for random number generation (the first hash function) and the Teplitz matrix defining the hash function used for privacy enhancement (the second hash function) may be independent of each other. Independence may mean, for example, that the two Teplitz matrices are selected from different families of hash functions.
[0044] The quantum cryptography system according to Embodiment 2 does not need to have a physical random number source for generating the above-mentioned random numbers. Since true random numbers are necessary for information-theoretic security, related quantum cryptography systems have had a physical random number source. In Embodiment 2, true random numbers can be obtained using the received key information, so there is no need to have a physical random number source. In addition, the security of the random numbers is ensured because the random numbers are compressed to a length corresponding to the amount of eavesdropping.
[0045] There is no need to generate random numbers quickly, as is the case when generating key information or selecting a basis. Furthermore, random number generation using a hash function is considered a relatively lightweight process. Therefore, the increase in computational load is small.
[0046] When error correction information is generated based on random numbers, only the information portion, not the entire codeword, is generated randomly, resulting in a smaller required random number length. Furthermore, if random numbers are assigned to the portion that is not transmitted, the length of that portion is at most about 10% of the shift key length. It is also possible to adjust the length of the information that forms the basis of the shift key and the length of the information used for random number generation. Thus, because the required random number length is short, the random numbers used for information adjustment do not need to be generated quickly.
[0047] Furthermore, it is known that the processing load for random number generation using a hash function is about 1 / 10 of the processing load for error correction and decryption. Also, in reverse adjustment, the processing load on the receiving side (Bob side) is smaller than that on the sending side (Alice side). Therefore, even if the processing load for random number generation on the receiving side (Bob side) is added, it will not affect the overall processing performance of the quantum cryptography system 1000.
[0048] The quantum key distribution protocol may be BB84. The BB84 protocol works as follows: First, the sender randomly selects two bases and transmits key information. Next, the receiver also randomly selects bases and receives key information. Communication is possible if the bases match between the sender and receiver; otherwise, an error occurs with a 1 / 2 probability. Next, the bases selected by the sender and receiver are compared, and a shift key is generated only from the bits where the bases match. Bits where the bases do not match are discarded. In Embodiment 2, when using BB84, a random number may be generated from the information of the bits where the bases did not match.
[0049] Referring to Figure 3, this is a block diagram illustrating the configuration of a receiving device 200a according to a modified example of Embodiment 2. Compared to the receiving device 200 in Figure 2, the receiving device 200a further includes a random number storage unit 250. The random number storage unit 250 is a storage device such as a hard disk or flash memory. The random number generation unit 220 stores the generated random numbers in the random number storage unit 250. The error correction unit 230 can use the random numbers stored in the random number storage unit 250 at the necessary timing.
[0050] The program described above includes, when loaded into a computer, a set of instructions (or software code) for causing the computer to perform one or more of the functions described in the embodiments. The program may be stored in a non-temporary computer-readable medium or a physical storage medium. Examples, but not limited to, include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, CD-ROM, digital versatile disc (DVD), Blu-ray® disc or other optical disc storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices. The program may be transmitted over a temporary computer-readable medium or a communication medium. Examples, but not limited to, include temporary computer-readable medium or a communication medium that includes electrically, optically, acoustically, or otherwise propagating signals.
[0051] Although the present invention has been described above with reference to embodiments, the present invention is not limited thereto. Various modifications to the structure and details of the present invention can be made that are understandable to those skilled in the art within the scope of the invention. [Explanation of Symbols]
[0052] 1, 200, 200a Receiving device 11, 110, 210 Quantum Communications Department 12,220 Random number generation unit 13, 120, 230 Error correction section 100 Transmitter 130, 240 Enhanced Confidentiality Section 250 Random number storage unit 1000 Quantum Cryptography Systems
Claims
1. A quantum communication means that receives key information containing information that forms the basis of a shift key, Random number generation means that generates a random number obtained by compressing a portion of the key information based on the characteristic value of the noise in the reception of the key information. Error correction means that performs information reconciliation based on the aforementioned random numbers, A receiving device equipped with it.
2. The aforementioned random number is generated by inputting a portion of the key information into the first hash function. The compression ratio of the first hash function is determined based on the amount of eavesdropping calculated from the characteristic value of the noise. The receiving device according to claim 1.
3. In the aforementioned information adjustment, error correction information is sent to the transmitting device that transmitted the key information. The error correction information includes information obtained by masking the random number with the shift key. A receiving device according to either claim 1 or 2.
4. In the aforementioned information adjustment, error correction information is sent to the transmitting device that transmitted the key information. If a portion of the error correction information code becomes corrupted, the random number is assigned to the portion that is not transmitted. A receiving device according to either claim 1 or 2.
5. The system further includes a confidentiality enhancement means for compressing the confidentiality of the correction key shared in the aforementioned information coordination using a second hash function, The Teplitz matrix representing the first hash function and the Teplitz matrix representing the second hash function are independent of each other. The receiving device according to claim 2.
6. The system further comprises a random number storage unit for storing the aforementioned random numbers. A receiving device according to either claim 1 or 2.
7. A quantum cryptography system comprising a transmitting device and a receiving device, The receiving device is, A quantum communication means that receives key information, including information that forms the basis of a shift key, from the transmitting device, Random number generation means that generates a random number obtained by compressing a portion of the key information based on the characteristic value of the noise in the reception of the key information. Error correction means that performs information reconciliation based on the aforementioned random numbers, Equipped with Quantum cryptography system.
8. The aforementioned random number is generated by inputting a portion of the key information into the first hash function. The compression ratio of the first hash function is determined based on the amount of eavesdropping calculated from the characteristic value of the noise. The quantum cryptography system according to claim 7.
9. Receive key information containing the information that forms the basis of the shift key, A random number is generated by compressing a portion of the key information based on the characteristic value of the noise in the reception of the key information. Information reconciliation is performed based on the aforementioned random numbers. Information adjustment method.
10. On the computer, A process for receiving key information that includes the information that forms the basis of the shift key, A process to generate a random number obtained by compressing a portion of the key information based on the characteristic value of the noise in the reception of the key information, A process to perform information reconciliation based on the aforementioned random numbers, and A program that executes the command.
Citation Information
Patent Citations
Secrecy enhancement device, and secrecy enhancement data processing method
JP2015099310A
Quantum key delivery device, quantum key delivery system and quantum key delivery method
JP2016181814A
Communication device, quantum key distribution system, quantum key distribution method, and program
JP2017168928A
Quantum key delivery system
JP2018037904A
Efficient random number generation for communication systems
US6993542B1