Receiver, quantum cryptography system, information adjustment method, and program
Patent Information
- Application Number
- JP2025508001
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-03
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2043-03-22
AI Technical Summary
Existing quantum cryptographic systems require additional hardware for generating random numbers, which is not efficient for information adjustment in key distillation processes.
A receiving device and quantum cryptographic system that generate random numbers using a hash function to compress key information based on noise characteristic values, enabling information reconciliation and confidentiality enhancement without the need for a physical random number source.
This approach allows for efficient generation of random numbers for information adjustment, ensuring information-theoretic security without additional hardware, reducing calculation load, and maintaining overall system performance.
Abstract
Description
Receiver, quantum cryptography system, information adjustment method, and computer-readable medium
[0001] The present disclosure relates to a receiving device, a quantum cryptography system, an information adjustment method, and a computer-readable medium.
[0002] Patent Documents 1 and 2 disclose techniques related to key distillation for generating a final key used in cryptographic communications. Key distillation includes information adjustment (also known as error correction) for generating a correction key from a sifted key, and privacy amplification for increasing the confidentiality of the correction key.
[0003] JP 2018-37904 A JP 2015-99310 A
[0004] Random numbers may be required for information adjustment. When generating such random numbers using a hardware random number generator, there is a problem in that additional hardware is required.
[0005] Therefore, one of the objectives that the embodiments disclosed in this specification aim to achieve is to provide a receiving device, a quantum cryptography system, an information adjustment method, and a computer-readable medium that generate random numbers used for information adjustment based on key information.
[0006] A receiving device according to a first aspect of the present disclosure includes: quantum communication means for receiving key information including information on which a sifted key is based; random number generation means for generating a random number obtained by compressing a part of the key information based on a characteristic value of noise in receiving the key information; and error correction means for performing information reconciliation based on the random number.
[0007] A quantum cryptography system according to a second aspect of the present disclosure is a quantum cryptography system including a transmitting device and a receiving device, wherein the receiving device includes: quantum communication means for receiving key information including information on which a sifted key is based from the transmitting device; random number generation means for generating a random number obtained by compressing a part of the key information based on a characteristic value of noise in receiving the key information; and error correction means for performing information reconciliation based on the random number.
[0008] An information adjustment method according to a third aspect of the present disclosure includes receiving key information including information on which a sifted key is based, generating a random number by compressing a part of the key information based on a characteristic value of noise in receiving the key information, and performing information reconciliation based on the random number.
[0009] A non-transitory computer-readable medium according to a fourth aspect of the present disclosure stores a program for causing a computer to execute the following processes: receiving key information including information on which a sifted key is based; generating a random number by compressing a part of the key information based on a characteristic value of noise in receiving the key information; and performing information reconciliation based on the random number.
[0010] According to the present disclosure, it is possible to provide a receiving device, a quantum cryptography system, an information adjustment method, and a computer-readable medium that generate random numbers used for information adjustment based on key information.
[0011] Fig. 1 is a block diagram showing the configuration of a receiving device according to embodiment 1. Fig. 2 is a block diagram showing the configuration of a quantum cryptography system according to embodiment 2. Fig. 3 is a diagram illustrating a modified example of the receiving device according to embodiment 2.
[0012] 1 is a block diagram showing the configuration of a receiving device 1 according to embodiment 1. The receiving device 1 includes a quantum communication unit 11, a random number generation unit 12, and an error correction unit 13. The receiving device 1 is communicably connected to a transmitting device (not shown) via an optical fiber.
[0013] The quantum communication unit 11 receives key information including information on which the sifted key is based. The quantum communication unit 11 may, for example, measure an optical signal modulated based on the key information in a selected basis and convert the measured signal into digital data.
[0014] The random number generation unit 12 generates a random number by compressing a part of the key information based on a characteristic value of noise when the key information is received. Specifically, the random number generation unit 12 generates a random number by inputting a part of the key information into a hash function. The compression rate of the hash function may be determined based on the amount of eavesdropping calculated from the characteristic value of the noise (e.g., variance).
[0015] The error correction unit 13 performs information reconciliation based on a random number. Specifically, the error correction unit 13 performs a process called reverse adjustment. In this case, the error correction unit 13 performs a process of transmitting error correction information to the transmitting device based on the random number. The error correction information may be generated based on the random number. Furthermore, when a portion of the code of the error correction information is punctured, a random number may be assigned to the portion that is not transmitted.
[0016] The receiving device according to the first embodiment can generate random numbers used for information adjustment based on key information.
[0017] The receiving device 1 includes a processor, a memory, and a storage device (not shown). The storage device stores a computer program that implements the processing of the information adjustment method according to this embodiment. The processor then loads the computer program from the storage device into the memory and executes the computer program. This allows the processor to implement the functions of a quantum communication unit 11, a random number generation unit 12, and an error correction unit 13.
[0018] Alternatively, the quantum communication unit 11, the random number generation unit 12, and the error correction unit 13 may each be realized by dedicated hardware. Furthermore, some or all of the components of each device may be realized by general-purpose or dedicated circuits, processors, etc., or a combination of these. These may be configured by a single chip, or by multiple chips connected via a bus. Some or all of the components of each device may be realized by a combination of the above-mentioned circuits, etc., and a program. Furthermore, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an FPGA (Field-Programmable Gate Array), etc. may be used as the processor.
[0019] Furthermore, when some or all of the components of the receiving device 1 are realized by a plurality of information processing devices, circuits, etc., the plurality of information processing devices, circuits, etc. may be centrally or decentralized. For example, the information processing devices, circuits, etc. may be realized as a client-server system, a cloud computing system, etc., in which each device is connected via a communication network.
[0020] 2 is a diagram illustrating the configuration of a quantum cryptography system 1000 according to embodiment 2. The quantum cryptography system 1000 includes a transmitting device 100 and a receiving device 200.
[0021] Specifically, the quantum cryptography system 1000 uses CV (Continuous-Variable)-QKD (Quantum Key Distribution) as a quantum key distribution protocol. CV-QKD transmits, for example, weak light with an average photon count of one or less, and detects the weak light using homodyne detection, as in normal optical communications. Unlike DV (Discrete-Variable)-QKD, which uses single photons, CV-QKD does not require a special detection device to detect single photons. CV-QKD also has the advantage of being able to be multiplexed with normal optical communications over the same optical fiber. The quantum key distribution protocol may be BB84, which uses single photons.
[0022] The transmitting device 100 and the receiving device 200 are communicatively connected via an optical fiber. The optical fiber transmits key information including information on which the sifted key is based. The transmitting device 100 and the receiving device 200 are communicatively connected via a classical channel (also called a public communication channel). The classical channel transmits information on the selected basis and information for error correction.
[0023] The transmitting device 100 includes a quantum communication unit 110, an error correction unit 120, and a privacy amplifier unit 130. The error correction unit 120 and the privacy amplifier unit 130 perform key distillation.
[0024] The quantum communication unit 110 is configured to be able to communicate with the quantum communication unit 210 of the receiving device 200. The quantum communication unit 110 transmits key information to the receiving device 200. The quantum communication unit 110 generates, for example, a random bit string as the key information, and transmits a weak optical signal modulated based on this random bit string through an optical fiber. At this time, a basis may be selected randomly.
[0025] The key information is used to generate a shift key, calculate a characteristic value of noise, and generate a random number for adjusting information. For example, the least significant bits of the key information may be used to generate the random number. Also, bits discarded when generating the shift key may be used to generate the random number.
[0026] The quantum communication unit 110 generates a sifted key based on information (e.g., information about the basis) received from the receiving device 200 through the classical channel. An error exists between the sifted key generated by the quantum communication unit 110 and the sifted key generated by the quantum communication unit 210. In addition, in order for the receiving device 200 to calculate a characteristic value of noise, the quantum communication unit 110 may transmit information about a part (e.g., half) of the key information to the receiving device 200 through the classical channel.
[0027] The error correction unit 120 generates a correction key by correcting the sifted key based on the error correction information received from the receiving device 200. By error correction, a common correction key is shared between the transmitting device 100 and the receiving device 200. In the quantum cryptography system 1000, information adjustment is performed by a method called back-adjustment. In back-adjustment, the error correction information is transmitted from the receiving device 200 to the transmitting device 100. In CV-QKD, back-adjustment is often performed.
[0028] The privacy amplifier 130 compresses the correction key based on the amount of eavesdropping to generate a final key with the privacy of the correction key amplified. The privacy amplifier 130 may receive the amount of eavesdropping from the receiving device 200 via a classical channel. The privacy amplifier 130 may also receive a random number for privacy amplification (e.g., a Toeplitz matrix) from the receiving device 200 and amplify the privacy of the correction key based on the random number.
[0029] The receiving device 200 includes a quantum communication unit 210, a random number generation unit 220, an error correction unit 230, and a privacy amplification unit 240. The random number generation unit 220, the error correction unit 230, and the privacy amplification unit 240 perform key distillation. The receiving device 200 is a specific example of the receiving device 1.
[0030] The quantum communication unit 210 is a specific example of the quantum communication unit 11. The quantum communication unit 210 measures the optical signal representing the key information transmitted by the transmitting device 100 in a selected basis. The quantum communication unit 210 may convert the measurement result into digital data. The quantum communication unit 210 generates a sifted key based on information (e.g., information regarding the basis) received from the transmitting device 100 via the classical channel.
[0031] The receiving device 200 may include a physical random number source for basis selection. However, there are cases where this physical random number source is dedicated to basis selection, or where it is difficult to use this physical random number source for information adjustment.
[0032] The quantum communication unit 210 also measures a characteristic value (e.g., variance) of noise in receiving the key information. The characteristic value may be, for example, variance, signal-to-noise ratio, or excess noise. The quantum communication unit 210 may measure the characteristic value of noise by receiving a portion of the key information through a classical channel. Because the accuracy of estimating the characteristic value affects the evaluation of the amount of eavesdropping, information having a length of about half the length of the sifted key may typically be used to estimate the characteristic value.
[0033] The random number generation unit 220 is a specific example of the random number generation unit 12. The random number generation unit 220 generates random numbers used for reverse adjustment. The random number generation unit 220 receives a portion of the key information received by the quantum communication unit 210 and a characteristic value measured by the quantum communication unit 210. The random number generation unit 220 calculates the amount of eavesdropping based on the characteristic value (e.g., variance). The random number generation unit 220 also calculates the entropy h of a portion of the key information, i.e., the information used to generate the random number. Then, the random number generation unit 220 compresses the portion of the key information at a compression rate (h-χ) obtained by subtracting the amount of eavesdropping χ from the entropy h. The compression rate represents, for example, the length of the compressed random number.
[0034] The random number generation unit 220 compresses a portion of the key information using a first hash function. Specifically, the hash function is expressed by a multiplication process using a randomly selected Toeplitz matrix. The random number generation unit 220 may pass the compression rate and a portion of the key information to the first hash function and receive a random number from the first hash function. The random number generation unit 220 does not need to have the functionality of the first hash function. The functionality of the first hash function may be provided in, for example, the privacy amplifier 240.
[0035] Information for generating random numbers may be secured separately from information that is the basis of the sifted key and information used to estimate the characteristic value. Furthermore, due to constraints imposed by the performance of key distillation, it is possible that part of the key information may be used for generating random numbers. For example, information that is discarded by post-selection when generating the sifted key may be used for generating random numbers. Furthermore, the lower bits of the soft decision value of the information for estimating the characteristic value may be used for generating random numbers.
[0036] The random number generation unit 220 can generate true random numbers or numbers close to true random numbers by generating random numbers from part of the key information. Key information is generally generated randomly. Furthermore, by compressing the information at a compression rate according to the amount of eavesdropping, the random number generation unit 220 can generate secure random numbers.
[0037] The error correction unit 230 is a specific example of the error correction unit 13. The error correction unit 230 performs reverse adjustment based on the random number. The error correction unit 230 may transmit error correction information based on the random number to the transmitting device 100. Furthermore, when a part of a code (e.g., a Multi-Edge Type LCPC code) is punctured, that is, when the part is not transmitted, the error correction unit 230 may assign a random number to the part that is not transmitted.
[0038] First, a case where error correction information based on a random number is transmitted will be described. The error correction unit 230 generates a code word using the random number as information and masks the code word with a shift key. When the shift key is given as hard decision {0, 1}, the error correction unit 230 transmits the code word masked with the shift key to the transmitting device 100 as the error correction information. That is, the error correction information Y is expressed as Y=Enc(X)+R B Enc represents the encoding, X represents the random number, and R B represents the sifted key on the receiving side (Bob's side). Also, "+" represents XOR. In this case, the correction key X generated on the transmitting side (Alice's side) is A )=Dec(Enc(X)+(R B +R A )) where Dec stands for decoding and R A represents the sifted key on the transmitting side (Alice's side). X is the same length as the code length, and (X+R B ) and the syndrome of X can be used as error correction information.
[0039] In the case of soft decision where the shift key is given as a plus or minus sign representing 0 or 1 of the bit and an absolute value representing the reliability, the sign is represented as 0 or 1, and Enc(X) is masked to generate Y in the same way as in the case of hard decision, and this is combined with the reliability to generate error correction information. In this case, the transmitting side (Alice's side) processes the sign part in the same way as in the case of hard decision, and performs decoding by combining the reliability information.
[0040] When performing multidimensional adjustment in Gaussian modulation CV-QKD, the error correction unit 230 generates a vector of random signal points from Enc(X), and uses a matrix that converts the vector of soft-decision received values to that signal point as error correction information. The transmitting side (Alice's side) obtains the sign and reliability of each bit from the vector obtained by applying the same conversion to the transmitted signal point vector, and uses this as input for decoding.
[0041] Next, a case where a random number is assigned to a portion of the code included in the error correction information that is not transmitted will be described. Depending on the code configuration, the efficiency of the code may be improved by puncturing a portion of the code. The punctured portion is not transmitted. In this case, in the information adjustment of QKD, efficiency can be improved by assigning a random number to this punctured portion in the error correction unit 230. When a syndrome is used for error correction, the syndrome is generated from a data block consisting of the random number of the punctured portion and the shift key (its code portion in the case of soft decision). On the receiving side (Alice's side), the punctured portion is treated as an erasure and decoding is performed using the syndrome.
[0042] The privacy amplifier 240 generates a final key by compressing the correction key using a second hash function. The correction key is compressed to a length obtained by subtracting the amount of information used for error correction and the amount of information presumed to have leaked in quantum communication from the amount of mutual information in quantum communication. More specifically, the compression ratio r is calculated as r = β * I - χ. I is the amount of mutual information between the transmitting device 100 and the receiving device 200. β is the efficiency of the error correction code. χ is the amount of information that may have been eavesdropped in quantum communication (also known as the amount of eavesdropping). I is determined according to the magnitude of the total noise. β is determined according to the magnitude and code of the total noise. χ is calculated according to the magnitude of the total noise, the transmittance, and the magnitude of noise other than quantum noise (also known as excess noise).
[0043] Each hash function is a universal hash function. In a universal hash function, more specifically, an ε-universal 2 hash function, if the family of hash functions H={h} and the size of the hash value space is m, then for different hash values x and y, |{h∈H:h(x)=h(y)}|≦ε|H| / m holds. A universal hash function has the property that the number of original data corresponding to a hash value, i.e., the number of corresponding functions, is constant. Therefore, if functions are uniformly selected, it is guaranteed that no further information about the original data will be leaked from the hash value. A universal hash function is typically expressed as multiplication by a randomly generated Toeplitz matrix. The Toeplitz matrix representing the hash function used for random number generation (the first hash function) and the Toeplitz matrix defining the hash function used for privacy amplification (the second hash function) may be independent of each other. Independence may mean, for example, that the two Toeplitz matrices are selected from different hash function families.
[0044] The quantum cryptography system according to the second embodiment does not need to include a physical random number source for generating the random numbers. True random numbers are necessary for information-theoretic security, and so related quantum cryptography systems have included a physical random number source. In the second embodiment, true random numbers can be obtained by using received key information, so there is no need to include a physical random number source. Furthermore, the random numbers are compressed to a length according to the amount of eavesdropping, ensuring the security of the random numbers.
[0045] There is no need to generate random numbers quickly, as is the case when generating key information or selecting a basis. Also, generating random numbers using a hash function is considered to be a relatively light process. Therefore, the increase in computational load is small.
[0046] When the error correction information is generated based on a random number, only the information portion is generated using the random number, not the entire codeword, so the length of the required random number is small. Also, when a random number is assigned to the portion that is not transmitted, the length of the portion that is not transmitted is at most about 10% of the length of the sifted key. Also, the length of the information that is the basis of the sifted key and the length of the information used to generate the random number can be adjusted. In this way, since the length of the required random number is short, the random number for adjusting the information does not need to be generated quickly.
[0047] It is known that the amount of processing required for random number generation using a hash function is approximately 1 / 10 of the amount of processing required for error correction decoding. Furthermore, in reverse adjustment, the amount of processing required on the receiving side (Bob's side) is smaller than the amount of processing required on the transmitting side (Alice's side). Therefore, even if the processing required for random number generation on the receiving side (Bob's side) is added, the processing performance of the quantum cryptography system 1000 as a whole is not affected.
[0048] The quantum key distribution protocol may be BB84. To explain the BB84 protocol, first, the sending side randomly selects two types of bases and transmits key information. Next, the receiving side also randomly selects a base and receives the key information. If the bases match between the sending side and the receiving side, communication is possible; if not, an error occurs with a 1 / 2 probability. Next, the bases selected by the sending side and the bases selected by the receiving side are compared, and a shift key is generated from only the bits whose bases match. Bits whose bases do not match are discarded. When BB84 is used in embodiment 2, a random number may be generated from information on the bits whose bases do not match.
[0049] Referring to Fig. 3, there is shown a block diagram illustrating the configuration of a receiving device 200a according to a modified example of the second embodiment. Compared to the receiving device 200 of Fig. 2, the receiving device 200a further includes a random number storage unit 250. The random number storage unit 250 is a storage device such as a hard disk or a flash memory. The random number generation unit 220 stores the generated random numbers in the random number storage unit 250. The error correction unit 230 can use the random numbers stored in the random number storage unit 250 at the required timing.
[0050] The above-described program includes a set of instructions (or software code) that, when loaded into a computer, causes the computer to perform one or more functions described in the embodiments. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable media or tangible storage media include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, CD-ROM, digital versatile disc (DVD), Blu-ray (registered trademark) disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable media or communication media include electrical, optical, acoustic, or other forms of propagated signals.
[0051] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the invention.
[0052] 1, 200, 200a Receiving device 11, 110, 210 Quantum communication unit 12, 220 Random number generation unit 13, 120, 230 Error correction unit 100 Transmitting device 130, 240 Privacy amplification unit 250 Random number storage unit 1000 Quantum cryptography system
Claims
1. a quantum communication means for receiving key information including information on which a sifted key is based; a random number generating means for generating a random number obtained by compressing a part of the key information based on a characteristic value of noise in receiving the key information; an error correction means for performing information reconciliation based on the random number; A receiving device comprising:
2. the random number is generated by inputting a part of the key information into a first hash function; The compression rate of the first hash function is determined based on the amount of eavesdropping calculated from the characteristic value of the noise.
2. The receiving device according to claim 1.
3. In the information adjustment, error correction information is transmitted to the transmitting device that transmitted the key information, The error correction information includes information obtained by masking the random number with the shift key.
3. The receiving device according to claim 1.
4. In the information adjustment, error correction information is transmitted to the transmitting device that transmitted the key information, When a part of the code of the error correction information is punctured, the random number is assigned to the part that is not transmitted.
3. The receiving device according to claim 1.
5. The method further includes a privacy amplification means for compressing the confidentiality of the correction key shared in the information adjustment by a second hash function, The Toeplitz matrix representing the first hash function and the Toeplitz matrix representing the second hash function are independent of each other.
3. The receiving device according to claim 2.
6. The random number storage unit further includes:
3. The receiving device according to claim 1.
7. A quantum cryptography system including a transmitting device and a receiving device, The receiving device quantum communication means for receiving key information including information on which a sifted key is based from the transmitting device; a random number generating means for generating a random number obtained by compressing a part of the key information based on a characteristic value of noise in receiving the key information; an error correction means for performing information reconciliation based on the random number; Equipped with Quantum cryptography system.
8. the random number is generated by inputting a part of the key information into a first hash function; The compression rate of the first hash function is determined based on the amount of eavesdropping calculated from the characteristic value of the noise. The quantum cryptography system according to claim 7.
9. receiving key information including information on which the sifted key is based; generating a random number by compressing a part of the key information based on a characteristic value of noise in receiving the key information; Perform information reconciliation based on the random number. Information adjustment method.
10. On the computer, receiving key information including information on which a sifted key is based; generating a random number by compressing a part of the key information based on a characteristic value of noise in receiving the key information; performing information reconciliation based on the random number; A program that executes the following.