Information processing device, information processing method, and communication system
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2025-12-23
- Publication Date
- 2026-03-25
AI Technical Summary
Existing encrypted communication systems face security degradation when switching from the Vernam cipher to a block cipher due to key exhaustion, leading to potential interruptions in secure communication.
An information processing device and method that acquires and specifies an encryption method based on the accumulated amount of common keys shared between terminals, using quantum key distribution, to dynamically select between one-time pad and block ciphers, ensuring continuous and secure communication.
This approach allows for more appropriate and secure encrypted communication by optimizing encryption methods based on available key amounts, maintaining security without interrupting communication, even during key replenishment.
Abstract
Description
Information processing device, information processing method, program, and communication system
[0001] The present disclosure relates to an information processing device, an information processing method, a program, and a communication system.
[0002] Patent Document 1 discloses a technique for switching the encryption method from the Vernam cipher to a block cipher such as Camellia (registered trademark) or AES when the keys of the one-time pad cipher (Vernam cipher) are exhausted. The technique described in Patent Document 1 enables encrypted communication to continue even during the period until the Vernam cipher keys are replenished, without causing interruption of the encrypted communication due to a shortage of Vernam cipher keys.
[0003] International Publication No. 2012 / 025988
[0004] However, in the technology described in Patent Document 1, for example, security may be reduced during communication because one-time pad encryption is switched to block encryption during communication to avoid interrupting the encrypted communication.
[0005] In view of the above-mentioned problems, an object of the present disclosure is to provide a technology that enables encrypted communication to be performed more appropriately.
[0006] In a first aspect of the present disclosure, an information processing device is provided that has, when communication between a first terminal and a second terminal is initiated, an acquisition unit that acquires information indicating an accumulated amount of a common key that can be used in the communication, and an identification unit that identifies an encryption method to be used in the communication based on the accumulated amount.
[0007] In addition, a second aspect of the present disclosure provides an information processing method that, when communication between a first terminal and a second terminal is initiated, performs a process of obtaining information indicating an accumulated amount of common keys available for use in the communication, and a process of identifying an encryption method to be used in the communication based on the accumulated amount.
[0008] In addition, in a third aspect of the present disclosure, a program is provided that causes a computer to execute, when communication between a first terminal and a second terminal is initiated, a process of obtaining information indicating an accumulated amount of a common key available for use in the communication, and a process of identifying an encryption method to be used in the communication based on the accumulated amount.
[0009] In addition, a fourth aspect of the present disclosure provides a communication system including a first terminal and a second terminal, and having an acquisition unit that acquires information indicating an accumulated amount of a common key available for communication when communication between the first terminal and the second terminal is initiated, and an identification unit that identifies an encryption method to be used for the communication based on the accumulated amount.
[0010] According to one aspect, encrypted communication can be performed more appropriately.
[0011] It is a figure which shows an example of the configuration of the information processing device based on the embodiment. It is a figure which shows an example of the configuration of the communication system based on the embodiment. It is a figure which shows an example of the hardware configuration of the information processing device based on the embodiment. It is a sequence diagram which shows an example of the process of the information processing device based on the embodiment. It is a figure which shows an example of the key management DB based on the embodiment.
[0012] The principles of the present disclosure will be described with reference to some exemplary embodiments. It should be understood that these embodiments are set forth for illustrative purposes only, to aid those skilled in the art in understanding and practicing the present disclosure, without implying any limitation on the scope of the disclosure. The disclosure described herein may be implemented in various ways other than those described below.
[0013] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.
[0014] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. (Embodiment 1) A configuration of an information processing device 10 according to an embodiment will be described with reference to Fig. 1. <Configuration> Fig. 1 is a diagram showing an example of the configuration of the information processing device 10 according to an embodiment. In the example of Fig. 1, the information processing device 10 has an acquisition unit 11 and an identification unit 12. Each of these units may be realized by cooperation between one or more programs installed in the information processing device 10 and hardware such as a processor and memory of the information processing device 10.
[0015] When communication between a first terminal and a second terminal is initiated, the acquisition unit 11 acquires information indicating the accumulated amount of common keys (secret keys, symmetric keys) available for the communication. The identification unit 12 identifies (determines, selects, determines, or specifies) the encryption method to be used for communication between the first terminal and the second terminal based on the accumulated amount. This enables more appropriate encrypted communication. Note that the common key may be a key shared between the first terminal and the second terminal by, for example, quantum key distribution (QKD).
[0016] (Embodiment 2) <System Configuration> Next, the configuration of a communication system 1 according to an embodiment will be described with reference to Fig. 2. Fig. 2 is a diagram showing an example of the configuration of the communication system 1 according to an embodiment. In the example of Fig. 2, the communication system 1 includes an information processing device 10. The communication system 1 also includes a terminal 20A (an example of a "first terminal") and a terminal 20B (an example of a "second terminal") (hereinafter, when there is no need to distinguish between them, they will also be simply referred to as "terminals 20"). The communication system 1 also includes a key management server 30A and a key management server 30B (hereinafter, when there is no need to distinguish between them, they will also be simply referred to as "key management servers 30").
[0017] The communication system 1 also has a QKD server 40A and a QKD server 40B (hereinafter, when there is no need to distinguish between them, they will also be simply referred to as "QKD server 40"). The communication system 1 also has a QKD device 50A and a QKD device 50B (hereinafter, when there is no need to distinguish between them, they will also be simply referred to as "QKD device 50").
[0018] The number of information processing devices 10, terminals 20, key management servers 30, QKD servers 40, and QKD devices 50 is not limited to the example of FIG.
[0019] 2, the information processing device 10, the terminal 20, and the key management server 30 are connected to each other so as to be able to communicate with each other via a network N. Examples of the network N include the Internet, a mobile communication system, a wireless local area network (LAN), a short-range wireless communication such as Bluetooth Low Energy (BLE), a LAN, and a bus. Examples of the mobile communication system include a fifth-generation mobile communication system (5G), a fourth-generation mobile communication system (4G), a third-generation mobile communication system (3G), and the like.
[0020] 2, the terminal 20A, the key management server 30A, the QKD server 40A, and the QKD device 50A are installed at the same base, the first base 60A. The terminal 20A and the key management server 30A, the key management server 30A and the QKD server 40A, and the QKD server 40A and the QKD device 50A may be connected, for example, by a LAN or a bus. At least one of the terminal 20A, the key management server 30A, the QKD server 40A, and the QKD device 50A is also referred to as the "device on the terminal 20A side" as appropriate.
[0021] 2, the terminal 20B, the key management server 30B, the QKD server 40B, and the QKD device 50B are installed at the same base, the second base 60B. The terminal 20B and the key management server 30B, the key management server 30B and the QKD server 40B, and the QKD server 40B and the QKD device 50B may be connected, for example, by an LBN or a bus. At least one of the terminal 20B, the key management server 30B, the QKD server 40B, and the QKD device 50B is also referred to as the "device on the terminal 20B side" as appropriate.
[0022] The key management server 30 manages the accumulated amount of shared keys obtained by quantum key distribution that can be used in communication between the terminals 20A and 20B through communication with other key management servers 30 or the QKD server 40. The key management server 30 may also notify other key management servers 30 of identification information, etc., of the shared keys obtained by quantum key distribution that were used in communication between the terminals 20A and 20B.
[0023] QKD server 40A notifies key management server 30A of the keys that have become available through quantum key distribution between QKD device 50A and QKD device 50B, and the identification information for those keys. QKD server 40B notifies key management server 30B of the keys that have become available through quantum key distribution between QKD device 50A and QKD device 50B, and the identification information for those keys.
[0024] Each QKD server 40 stores (records) key data that has become available through quantum key distribution, and the key data used in encrypted communication between each terminal 20 may be made unreusable by deleting it, etc.
[0025] The QKD device 50 transmits (distributes, distributes) key data (shared keys) to other QKD devices 50 by quantum key distribution. Note that quantum key distribution is, for example, a technology that uses the principles of quantum mechanics to detect eavesdropping when distributing key data. In this case, the QKD device 50 may transmit key data to other QKD devices 50 by, for example, the BB84 method, in which one bit of key information is transmitted per photon, or the CV-QKD method, in which one bit of key information is transmitted on the phase difference between a weak light wave and normal light.
[0026] The information processing device 10 may be, for example, a device such as a server or a cloud server. Furthermore, the information processing device 10 may be included in, for example, at least one of the terminals 20A and 20B. In this case, the information processing device 10 may be realized by, for example, a program running on at least one of the terminals 20A and 20B, or may be realized by an external device externally connected to at least one of the terminals 20A and 20B.
[0027] The terminal 20 may be, for example, a device such as a personal computer or a smartphone. For example, the terminal 20A encrypts and transmits data to the terminal 20B in response to an operation by the user of the terminal 20A. The terminal 20A may transmit data of a pre-recorded file to the other terminal 20. The terminal 20A may also transmit at least one of audio acquired from a microphone and video acquired from a camera to the other terminal 20 in real time.
[0028] For example, in response to an operation by the user of terminal 20A, terminal 20A encrypts data using an encryption method specified by information processing device 10 and transmits the encrypted data to terminal 20B. For example, in response to an operation by the user of terminal 20B, terminal 20B decrypts the data received from terminal 20A using an encryption method specified by information processing device 10.
[0029] The functional unit that performs encoding for encrypted communication in terminal 20A may be realized by a program that runs on terminal 20A, or may be realized by an external device that is externally connected to terminal 20A. Also, the functional unit that performs decryption for encrypted communication in terminal 20B may be realized by a program that runs on terminal 20B, or may be realized by an external device that is externally connected to terminal 20B.
[0030] <Hardware Configuration> Fig. 3 is a diagram showing an example of the hardware configuration of the information processing device 10 according to the embodiment. In the example of Fig. 3, the information processing device 10 (computer 100) includes a processor 101, a memory 102, and a communication interface 103. These components may be connected via a bus or the like. The memory 102 stores at least a part of a program 104. The communication interface 103 includes an interface required for communication with other network elements.
[0031] When the program 104 is executed by the processor 101, memory 102, and other components in cooperation with each other, the computer 100 performs at least some of the processing of the embodiments of the present disclosure. The memory 102 may be of any type. As a non-limiting example, the memory 102 may be a non-transitory computer-readable storage medium. The memory 102 may also be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory. Although only one memory 102 is shown in the computer 100, several physically different memory modules may be present in the computer 100. The processor 101 may be of any type. The processor 101 may include one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and, as a non-limiting example, a processor based on a multi-core processor architecture. The computer 100 may have multiple processors, such as application-specific integrated circuit chips that are time-slaved to a clock that synchronizes the main processor.
[0032] Embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software that may be executed by a controller, microprocessor, or other computing device.
[0033] The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as instructions included in program modules, that execute on a target real or virtual processor or device to perform the processes or methods of the present disclosure. Program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or divided among program modules as desired in various embodiments. The machine-executable instructions of the program modules may be executed in local or distributed devices. In a distributed device, the program modules may be located in both local and remote storage media.
[0034] The program code for executing the methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus. When the program code is executed by the processor or controller, the functions / acts in the flowcharts and / or implementing block diagrams are performed. The program code may be executed entirely on the machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine, or entirely on a remote machine or server.
[0035] The program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in the embodiments. The program may be stored on a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable media or tangible storage media include random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technologies, CD-ROM, digital versatile disc (DVD), Blu-ray disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable media or communication media include electrical, optical, acoustic, or other forms of propagated signals.
[0036] <Processing> Next, an example of processing of the information processing device 10 according to the embodiment will be described with reference to Fig. 4 and Fig. 5. Fig. 4 is a sequence diagram showing an example of processing of the information processing device 10 according to the embodiment. Fig. 5 is a diagram showing an example of a key management DB (database) 501 according to the embodiment.
[0037] The following processing procedure is an example, and the information processing device 10 of the present disclosure may execute the procedures in a different order as appropriate, provided that there is no contradiction. Hereinafter, the user (user, organization) of terminal 20A will also be referred to as user A, and the user of terminal 20B will also be referred to as user B. The example of FIG. 4 will be used to describe the case where data is sent from user A to user B.
[0038] In step S1, the acquisition unit 11 detects that communication between terminal 20A and terminal 20B has begun. Here, the acquisition unit 11 may receive, for example, a request to begin encrypted communication with terminal 20B from terminal 20A or key management server 30A, which is a device on the terminal 20A side. The acquisition unit 11 may also receive, for example, a data packet from terminal 20A to be transmitted to terminal 20B in a specific communication session. In this case, the specific communication session may be identified by a source ID, a destination ID, and a destination port number. The source ID may be, for example, the Internet Protocol (IP) address of terminal 20A. The destination ID may be, for example, the IP address of terminal 20B. The destination port number may be, for example, a number for identifying a program that processes the received packet.
[0039] Next, the acquiring unit 11 acquires information indicating the amount of shared keys stored by quantum key distribution (QKD) that can be used in communication between the terminals 20A and 20B (step S2). The amount of stored keys is the amount of unused keys among the keys shared by the device on the terminal 20A side and the device on the terminal 20B side by quantum key distribution (QKD).
[0040] Here, the acquiring unit 11 may acquire information indicating the accumulated amount of shared keys obtained by quantum key distribution that can be used for data transmission from terminal 20A to terminal 20B at the time when communication between terminal 20A and terminal 20B is started. Note that the acquiring unit 11 may acquire the information indicating the accumulated amount from terminal 20A, which is a device on the terminal 20A side, or key management server 30A. Also, the acquiring unit 11 may acquire the information indicating the accumulated amount from terminal 20B, which is a device on the terminal 20B side, or key management server 30B.
[0041] Here, the acquisition unit 11 may acquire the accumulated amount and the like from the key management DB 501. Note that the key management DB 501 may be recorded in a storage device inside the information processing device 10, or may be recorded in a storage device external to the information processing device 10. The data of the key management DB 501 may be acquired by the acquisition unit 11 from at least one of the device on the terminal 20A side and the device on the terminal 20B side, for example, and recorded.
[0042] 5, the key management DB 501 stores the storage amount, generation rate, and consumption rate in association with a combination of a source ID and a destination ID. The generation rate is the amount of symmetric keys increased by quantum key distribution per unit time (e.g., 1 second). The consumption rate is the amount of symmetric keys used in encrypted communication decreased per unit time (e.g., 1 second).
[0043] Next, the identification unit 12 calculates (determines) a score (index value) for identifying the encryption method used in communication between the terminal 20A and the terminal 20B based on the accumulated amount, etc. (Step S3). Here, the identification unit 12 may calculate the score based on, for example, one or a combination of the following examples:
[0044] (Example of calculation based on accumulated amount) For example, the identification unit 12 may calculate a score value that is larger as the accumulated amount increases. This allows, for example, an encryption method that increases the consumption of keys but improves security as the accumulated amount increases to be used.
[0045] (Example of calculation based on the rate of change of the accumulated amount) The identification unit 12 may calculate the score based on, for example, the rate of change of the accumulated amount. For example, the identification unit 12 may obtain the generation rate and consumption rate recorded in the key management DB 501 and calculate the rate of change by subtracting the consumption rate from the generation rate. In this case, the identification unit 12 may calculate the score to be a larger value, for example, the faster the rate of increase of the accumulated amount. This allows, for example, when the current frequency of use of the shared key via quantum key distribution is relatively low and when the QKD device 50 generates the shared key via quantum key distribution relatively frequently, to use an encryption method that increases key consumption but improves security. Furthermore, for example, when communication between the QKD devices 50 uses a communication path with relatively low communication quality, such as satellite communication, and the frequency of generation of the shared key via quantum key distribution is relatively low, to use an encryption method that reduces key consumption but decreases security.
[0046] (Example of calculation based on the amount of data transmitted, etc.) The identification unit 12 may calculate the score based on, for example, at least one of the amount of data (data size) and the transfer rate transmitted in communication between the terminal 20A and the terminal 20B. In this case, the acquisition unit 11 may acquire, for example, information indicating at least one of the amount of data and the transfer rate from the terminal 20A. Then, the identification unit 12 may calculate a smaller value for the score, for example, as the amount of data transmitted increases. This makes it easier to encourage the use of an encryption method that reduces key consumption but reduces security, for example, in the case of transmission in which the use of a one-time pad increases key consumption.
[0047] Furthermore, the identification unit 12 may calculate the score to be a smaller value as the transfer rate of transmission increases, for example. This makes it easier to use an encryption method that reduces key consumption but lowers security in the case of a video conference or the like where the use of a one-time pad tends to increase key consumption.
[0048] (Example of calculation based on the importance of transmitted data) The identification unit 12 may calculate the score based on, for example, the importance of data transmitted in communication between the terminal 20A and the terminal 20B. This may make it easier to use an encryption method that reduces security but consumes less keys for communication with low importance. In this case, the identification unit 12 may determine the importance based on, for example, information included in a communication packet transmitted from the terminal 20A to the terminal 20B.
[0049] In this case, the identification unit 12 may determine the importance based on, for example, at least one of a source IP address, a destination (transmission destination) IP address, a protocol (IP protocol number), a source port number, and a destination port number included in the header of the communication packet. This allows the identification unit 12 to determine, for example, that communication using a specific protocol from a specific department is highly important, or that communication addressed to a specific application in a specific department is highly important. In this case, an importance value may be set (registered) in advance by an administrator (operator) of the information processing device 10 or the like, in association with at least one of the source IP address, the destination IP address, the protocol, the source port number, and the destination port number.
[0050] The identification unit 12 may also determine the importance level based on, for example, at least one of a DSCP (Differentiated Services Code Point) and an option field included in the header of the communication packet. As a result, for example, a communication designated as having high importance by a user or an application of the terminal 20A can be determined to have high importance. In this case, the importance level value may be set (registered) in advance by an administrator (operator) of the information processing device 10, etc., in association with at least one of the values of the DSCP and the option field.
[0051] (Example of calculation based on accumulated amount of shared keys obtained by quantum key distribution available for communication between bases) At least one of the terminals 20A and 20B may include multiple terminals. The identification unit 12 may calculate the score for communication between a first terminal included in the one or more terminals 20A and a second terminal included in the one or more terminals 20B based on the accumulated amount of shared keys obtained by quantum key distribution available for communication between the one or more terminals 20A and the one or more terminals 20B. This makes it possible to select an encryption method for communication to be newly started between a first terminal and a second terminal based on, for example, the current accumulated amount and the rate of change in the accumulated amount between the first base where the one or more terminals 20A are installed and the second base where the one or more terminals 20B are installed.
[0052] (Example of calculation based on predicted change in storage amount) The identification unit 12 may calculate the score based on predicted change in storage amount. This allows, for example, to more appropriately determine the encryption method. In this case, the identification unit 12 may predict (infer) the change in storage amount using, for example, AI (artificial intelligence).
[0053] In this case, the identifying unit 12 may input, for example, the current value of the accumulated amount, the current date and time, the generation rate (increase rate) of the symmetric key through the current quantum key distribution, and the consumption rate of the symmetric key through the current quantum key distribution to a trained recurrent neural network (RNN).The identifying unit 12 may then output, for example, a predicted transition of the accumulated amount (predicted value of the accumulated amount at each future time point) from the recurrent neural network.The identifying unit 12 may then calculate the score such that, for example, the larger the predicted accumulated amount at each future time point, the larger the value of the score.
[0054] (Example of calculation based on rate of change of accumulated amount) The determination unit 12 may calculate the score based on the rate of change of the accumulated amount, for example. In this case, the determination unit 12 may calculate the score to be a larger value as the rate of increase of the accumulated amount per unit time (for example, one second) increases.
[0055] Next, the identification unit 12 identifies an encryption method to be used for communication between the terminal 20A and the terminal 20B based on the score (step S4). For example, if the stored amount is equal to or greater than a threshold, the identification unit 12 may identify (determine) a first encryption method as the encryption method to be used for communication between the terminal 20A and the terminal 20B. Alternatively, for example, if the stored amount is less than the threshold, the identification unit 12 may identify (determine) a second encryption method, which consumes keys less frequently than the first encryption method, as the encryption method to be used for communication between the terminal 20A and the terminal 20B. This makes it possible to reduce the amount of shared keys used by quantum key distribution, for example, when there is relatively little room for storing shared keys for quantum key distribution.
[0056] In this case, if the accumulated amount is equal to or greater than the threshold, the identification unit 12 may encrypt the plaintext using a combination of each bit of the plaintext and each bit of a key (random number sequence), and may identify that a one-time pad (OTP) (one-time cipher, flip cipher) that is used only once is to be used for communication.
[0057] Furthermore, if the accumulated amount is less than the threshold, the identifying unit 12 may identify an encryption method other than the one-time pad to be used for communication. The encryption method other than the one-time pad may include, for example, the Advanced Encryption Standard (AES) and the Triple DES (Data Encryption Standard), which are block encryption methods that encrypt data in units of fixed-length data (blocks). The encryption method other than the one-time pad may also include, for example, a stream encryption method that encrypts data in units of bits or bytes and uses a relatively short key. The encryption method may not be a method that shares a key of the same length as the plaintext, as in the one-time pad, but may include, for example, a method that shares data and a relatively short key, known as a pseudorandom number generator, and generates a relatively long key from the key using the pseudorandom number generator for encryption.
[0058] Furthermore, when the stored amount is less than the threshold, the specifying unit 12 may specify (determine) the update frequency of the key used in the second encryption method based on the stored amount. In this case, the specifying unit 12 may, for example, determine a shorter expiration date (usable time length) of the key used in the block cipher as the stored amount increases. This makes it possible to further reduce the amount of symmetric keys used in quantum key distribution, for example, when there is relatively little room for storing symmetric keys for quantum key distribution.
[0059] Next, the identification unit 12 outputs information indicating the identified encryption method (step S5). Here, the identification unit 12 may transmit (notify) the information indicating the identified encryption method to terminal 20A. In this case, the information indicating the encryption method is transferred from terminal 20A to terminal 20B. Then, terminal 20A encrypts data using the encryption method and transmits it to terminal 20B, and terminal 20B decrypts the data received from terminal 20A using the encryption method.
[0060] Furthermore, the identification unit 12 may transmit (notify) information indicating the identified encryption method to terminal 20B. In this case, the information indicating the encryption method is transferred from terminal 20B to terminal 20A. Then, terminal 20A encrypts data using the encryption method and transmits it to terminal 20B, and terminal 20B decrypts the data received from terminal 20A using the encryption method.
[0061] (Example of Starting Communication After Obtaining User Approval for the Identified Encryption Method) The identification unit 12 may start communication between the terminal 20A and the terminal 20B when at least one of the users of the terminal 20A and the terminal 20B approves the communication using the identified encryption method. This allows the user to recognize that communication will be performed using an encryption method with relatively low security due to factors such as the amount of shared keys stored through quantum key distribution, and may reject the communication. In this case, the identification unit 12 may, for example, send information indicating the identified encryption method to the terminal 20A and the terminal 20B and display to each user that encrypted communication will be started using the identified encryption method. Then, for example, when the users of the terminal 20A and the terminal 20B approve the start of encrypted communication, the identification unit 12 may instruct the terminal 20A to start encrypted communication.
[0062] <Modifications> The information processing device 10 may be a device contained in a single housing, but the information processing device 10 of the present disclosure is not limited to this. Each unit of the information processing device 10 may be implemented, for example, by cloud computing configured with one or more computers. At least some of the processing of the information processing device 10 may be executed by, for example, at least one of the terminal 20A, the terminal 20B, the key management server 30A, and the key management server 30B. The information processing device 10 may be built into, for example, the housing of at least one of the terminal 20A, the terminal 20B, the key management server 30A, and the key management server 30B. The information processing device 10 may be integrated with, for example, at least one of the terminal 20A, the terminal 20B, the key management server 30A, and the key management server 30B. Such information processing devices 10 are also included as examples of the "information processing device" of the present disclosure.
[0063] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.
[0064] Each drawing is merely an example for describing one or more embodiments. Each drawing may not relate to only one particular embodiment, but may also relate to one or more other embodiments. As will be understood by those skilled in the art, various features or steps described with reference to any one drawing can be combined with features or steps shown in one or more other drawings to create, for example, an embodiment not explicitly shown or described. Not all features or steps shown in any one drawing are necessary to describe an exemplary embodiment, and some features or steps may be omitted. The order of steps described in any drawing may be changed as appropriate.
[0065] Some or all of the above embodiments can be described as, but are not limited to, the following supplementary notes. (Supplementary Note 1) An information processing device comprising: an acquisition unit that, when communication between a first terminal and a second terminal is initiated, acquires information indicating an accumulated amount of common keys that can be used in the communication; and a specification unit that specifies an encryption method to be used in the communication based on the accumulated amount. (Supplementary Note 2) The information processing device according to Supplementary Note 1, wherein the accumulated amount is the amount of unused keys among keys shared between the first terminal side and the second terminal side by quantum key distribution (QKD). (Supplementary Note 3) The information processing device according to Supplementary Note 1 or 2, wherein the specification unit specifies a first encryption method as the encryption method if the accumulated amount is equal to or greater than a threshold, and specifies a second encryption method that consumes keys less frequently than the first encryption method as the encryption method if the accumulated amount is less than the threshold. (Supplementary Note 4) The information processing device according to Supplementary Note 3, wherein, if the accumulated amount is equal to or greater than the threshold, the specifying unit specifies a one-time pad as the encryption method, which encrypts using a combination of each bit of plaintext and each bit of a key. (Supplementary Note 5) The information processing device according to Supplementary Note 4, wherein, if the accumulated amount is less than the threshold, the specifying unit specifies an update frequency of a key used in the second encryption method based on the accumulated amount. (Supplementary Note 6) The information processing device according to Supplementary Note 1 or 2, wherein the specifying unit specifies the encryption method based on a rate of change of the accumulated amount. (Supplementary Note 7) The information processing device according to Supplementary Note 1 or 2, wherein the specifying unit specifies the encryption method based on at least one of the amount of data transmitted in the communication and a transfer rate. (Supplementary Note 8) The information processing device according to Supplementary Note 1 or 2, wherein at least one of the first terminal and the second terminal includes a plurality of terminals. (Supplementary Note 9) The information processing device according to Supplementary Note 1 or 2, wherein the specifying unit specifies the encryption method based on a predicted transition of the accumulated amount. (Supplementary Note 10) The information processing device according to Supplementary Note 1 or 2, wherein the specifying unit specifies the encryption method based on the importance of the communication. (Supplementary Note 11) The information processing device according to Supplementary Note 10, wherein the specifying unit determines the importance based on information included in a communication packet transmitted from the first terminal to the second terminal.(Supplementary Note 12) The information processing device according to Supplementary Note 1 or 2, wherein the specification unit starts the communication when at least one of a user of the first terminal and a user of the second terminal agrees to perform the communication using the specified encryption method. (Supplementary Note 13) An information processing method, when communication between a first terminal and a second terminal is started, performing the following processes: acquiring information indicating an accumulated amount of common keys that can be used in the communication; and specifying the encryption method to be used in the communication based on the accumulated amount. (Supplementary Note 14) The information processing method according to Supplementary Note 13, wherein the accumulated amount is the amount of unused keys among keys shared between the first terminal side and the second terminal side by quantum key distribution (QKD). (Supplementary Note 15) The information processing method according to Supplementary Note 13 or 14, wherein the specifying process specifies a first encryption method as the encryption method if the accumulated amount is equal to or greater than a threshold, and specifies a second encryption method, which has a lower key consumption frequency than the first encryption method, as the encryption method if the accumulated amount is less than the threshold. (Supplementary Note 16) The information processing method according to Supplementary Note 15, wherein the specifying process specifies a one-time pad, which encrypts using a combination of each bit of plaintext and each bit of a key, as the encryption method if the accumulated amount is equal to or greater than the threshold. (Supplementary Note 17) The information processing method according to Supplementary Note 16, wherein the specifying process specifies an update frequency of the key used in the second encryption method based on the accumulated amount if the accumulated amount is less than the threshold. (Supplementary Note 18) The information processing method according to Supplementary Note 13 or 14, wherein the specifying process specifies the encryption method based on a rate of change of the accumulated amount. (Supplementary Note 19) The information processing method according to Supplementary Note 13 or 14, wherein the specifying process specifies the encryption method based on at least one of an amount of data transmitted in the communication and a transfer rate. (Supplementary Note 20) The information processing method according to Supplementary Note 13 or 14, wherein at least one of the first terminal and the second terminal includes a plurality of terminals. (Supplementary Note 21) The information processing method according to Supplementary Note 13 or 14, wherein the specifying process specifies the encryption method based on a predicted transition of the storage amount.(Supplementary note 22) The information processing method according to Supplementary note 13 or 14, wherein the specifying process specifies the encryption method based on the importance of the communication. (Supplementary note 23) The information processing method according to Supplementary note 22, wherein the specifying process determines the importance based on information included in a communication packet transmitted from the first terminal to the second terminal. (Supplementary note 24) The information processing method according to Supplementary note 13 or 14, wherein the specifying process starts the communication when at least one of a user of the first terminal and a user of the second terminal agrees to perform the communication using the specified encryption method. (Supplementary note 25) A program that causes a computer to execute, when communication between a first terminal and a second terminal is started, a process of acquiring information indicating an accumulated amount of a common key that can be used in the communication, and a process of specifying the encryption method to be used for the communication based on the accumulated amount. (Supplementary Note 26) The program according to Supplementary Note 25, wherein the stored amount is the amount of unused keys among keys shared between the first terminal side and the second terminal side by quantum key distribution (QKD). (Supplementary Note 27) The program according to Supplementary Note 25 or 26, wherein the specifying process specifies a first encryption method as the encryption method if the stored amount is equal to or greater than a threshold, and specifies a second encryption method, which consumes keys less frequently than the first encryption method, as the encryption method if the stored amount is less than the threshold. (Supplementary Note 28) The program according to Supplementary Note 27, wherein the specifying process specifies a one-time pad, which encrypts using a combination of each bit of plaintext and each bit of a key, as the encryption method if the stored amount is equal to or greater than the threshold. (Supplementary Note 29) The program according to Supplementary Note 28, wherein, in the specifying process, if the accumulated amount is less than the threshold, an update frequency of a key used in the second encryption method is specified based on the accumulated amount. (Supplementary Note 30) The program according to Supplementary Note 25 or 26, wherein, in the specifying process, the encryption method is specified based on a rate of change of the accumulated amount. (Supplementary Note 31) The program according to Supplementary Note 25 or 26, wherein, in the specifying process, the encryption method is specified based on at least one of the amount of data transmitted in the communication and a transfer rate.(Supplementary Note 32) The program according to Supplementary Note 25 or 26, wherein at least one of the first terminal and the second terminal includes a plurality of terminals. (Supplementary Note 33) The program according to Supplementary Note 25 or 26, wherein, in the specifying process, the encryption method is specified based on a predicted transition of the storage amount. (Supplementary Note 34) The program according to Supplementary Note 25 or 26, wherein, in the specifying process, the encryption method is specified based on the importance of the communication. (Supplementary Note 35) The program according to Supplementary Note 34, wherein, in the specifying process, the importance is determined based on information included in a communication packet transmitted from the first terminal to the second terminal. (Supplementary Note 36) The program according to Supplementary Note 25 or 26, wherein, in the specifying process, the communication is started when at least one of a user of the first terminal and a user of the second terminal agrees to perform the communication using the specified encryption method. (Supplementary Note 37) A communication system including a first terminal and a second terminal, comprising: an acquisition unit that acquires information indicating an accumulated amount of common keys that can be used in communication when communication between the first terminal and the second terminal is started; and an identification unit that identifies an encryption method to be used in the communication based on the accumulated amount. (Supplementary Note 38) The communication system according to Supplementary Note 37, wherein the accumulated amount is the amount of unused keys among keys shared between the first terminal side and the second terminal side by quantum key distribution (QKD). (Supplementary Note 39) The communication system according to Supplementary Note 37 or 38, wherein the identification unit identifies a first encryption method as the encryption method if the accumulated amount is equal to or greater than a threshold, and identifies a second encryption method that consumes keys less frequently than the first encryption method as the encryption method if the accumulated amount is less than the threshold. (Supplementary Note 40) The communication system according to Supplementary Note 39, wherein the specifying unit specifies, as the encryption method, a one-time pad that encrypts using a combination of each bit of plaintext and each bit of a key when the accumulated amount is equal to or greater than the threshold. (Supplementary Note 41) The communication system according to Supplementary Note 40, wherein, when the accumulated amount is less than the threshold, the specifying unit specifies an update frequency of a key used in the second encryption method based on the accumulated amount.(Supplementary Note 42) The communications system according to Supplementary Note 37 or 38, wherein the specifying unit specifies the encryption method based on a rate of change in the accumulated amount. (Supplementary Note 43) The communications system according to Supplementary Note 37 or 38, wherein the specifying unit specifies the encryption method based on at least one of the amount of data transmitted in the communication and a transfer rate. (Supplementary Note 44) The communications system according to Supplementary Note 37 or 38, wherein at least one of the first terminal and the second terminal includes a plurality of terminals. (Supplementary Note 45) The communications system according to Supplementary Note 37 or 38, wherein the specifying unit specifies the encryption method based on a predicted change in the accumulated amount. (Supplementary Note 46) The communications system according to Supplementary Note 37 or 38, wherein the specifying unit specifies the encryption method based on the importance of the communication. (Supplementary Note 47) The communications system according to Supplementary Note 46, wherein the specifying unit determines the importance based on information included in a communication packet transmitted from the first terminal to the second terminal. (Supplementary Note 48) The communication system according to Supplementary Note 37 or 38, wherein the specification unit starts the communication when at least one of a user of the first terminal and a user of the second terminal agrees to perform the communication using the specified encryption method.
[0066] REFERENCE SIGNS LIST 1 Communication system 10 Information processing device 11 Acquisition unit 12 Identification unit 20A, 20B Terminal 30A, 30B Key management server 40A, 40B QKD server 50A, 50B QKD device
Claims
1. When communication between the first terminal and the second terminal is initiated, an acquisition unit acquires information indicating the amount of shared keys available for use in the communication. A specification unit that identifies the encryption method used for the communication based on the amount of stored data, An information processing device having
2. The aforementioned accumulated amount is the amount of unused keys among the keys shared between the first terminal and the second terminal by quantum key distribution (QKD). The information processing apparatus according to claim 1.
3. The identifying unit identifies the first encryption method as the encryption method if the accumulated amount is equal to or greater than a threshold, and identifies a second encryption method as the encryption method if the accumulated amount is less than the threshold, which has a lower key consumption frequency than the first encryption method. The information processing apparatus according to claim 1.
4. The identification unit identifies a one-time pad, which is encrypted using a combination of each bit of the plaintext and each bit of the key, as the encryption method if the accumulated amount is equal to or greater than the threshold. The information processing apparatus according to claim 3.
5. If the accumulated amount is less than the threshold, the specified unit determines the update frequency of the key used in the second cryptographic scheme based on the accumulated amount. The information processing apparatus according to claim 4.
6. The specified unit identifies the encryption method based on the rate of change of the stored amount. The information processing apparatus according to claim 1.
7. The identifying unit identifies the encryption method based on at least one of the amount of data transmitted in the communication and the transfer rate. The information processing apparatus according to claim 1.
8. At least one of the first terminal and the second terminal includes a plurality of terminals. The information processing apparatus according to claim 1.
9. When communication between the first terminal and the second terminal is initiated, the process involves obtaining information indicating the amount of shared keys available for use in the communication. A process to identify the encryption method used for the communication based on the amount of storage, An information processing method that performs the following.
10. Including the first terminal and the second terminal, When communication between the first terminal and the second terminal is initiated, an acquisition unit acquires information indicating the amount of shared keys available for use in the communication, A specification unit that identifies the encryption method used for the communication based on the amount of stored data, A communication system having