Authentication and key sharing method using quantum entanglement swapping
The novel protocol using quantum entanglement swapping and a trusted third party addresses authentication and key sharing challenges in quantum networks, ensuring secure communication despite malicious attacks.
Patent Information
- Application Number
- PCT/JP2025/017418
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-22
- Filing Date
- 2025-05-13
- Publication Date
- 2025-11-27
AI Technical Summary
Existing quantum communication networks face challenges in authenticating new users and securely sharing encryption keys, particularly due to vulnerabilities from malicious attackers and the inability to achieve information-theoretically secure position-based cryptography.
A novel protocol using quantum entanglement swapping and a trusted but not highly competent third party (Tom) for authentication and key sharing, employing optical separators and photon detection units to verify user locations and establish secure communication.
Enables reliable authentication and cryptographic key sharing with new users in quantum communication networks, even under potential attacks, by leveraging quantum optical interference measurements and minimizing classical information conversion.
Smart Images

Figure JP2025017418_27112025_PF_FP_ABST
Abstract
Description
Authentication and key sharing method using quantum entanglement swapping
[0001] The present invention relates to an authentication and key sharing method using quantum entanglement swapping.
[0002] The goal of position-based cryptography (PBC) is for honest parties to use their spatiotemporal location as a credential in a cryptographic protocol. In particular, location verification aims to verify that a specific party, known as a prover, possesses a specific location in space and time. PBC has been actively researched in classical settings, and it has been shown that information-theoretic security can never be achieved in the standard model (Non-Patent Document 1). However, the same paper provides a secure structure using a constrained retrieval model, a variant of the constrained storage model. Furthermore, attempts have been made to overcome the no-go theorem using quantum technology. For example, quantum key distribution and the sharing of co-random numbers using quantum entanglement with EPR pairs are features not available in classical systems, and security studies using these are currently underway. Kent et al. published a paper on PBC using quantum technology in 2002, describing an attack against a quantum structure (Non-Patent Document 2). Furthermore, Malaney proposes a verification function in Non-Patent Document 3 below.
[0003] Furthermore, Lau and Lo demonstrated the feasibility of implementing PBC using causality (Non-Patent Document 4), but Buhrman et al. (Non-Patent Document 6) showed that an attacker capable of quantum teleportation could spoof the EPR pair (Non-Patent Document 5) in advance, proving that information-theoretically secure implementation is impossible. Meanwhile, efforts are ongoing to prove the computational security of PBC against currently known attack methods, such as proposing protocols that require exponential EPR pairs, but no progress has been made toward achieving information-theoretically secure PBC.
[0004] Japanese Patent No. 5911097 describes a single-photon detector that detects single photons in a quantum key distribution system. In a quantum communication network such as a quantum key distribution system, it is not easy to properly authenticate a new user (terminal).
[0005] Patent No. 5911097
[0006] N. Chandran, V. Goyal, R. Moriarty, and R. Ostrovsky, in Advances in Cryptology-CRYPTO 2009 (Springer, New York, 2009), pp. 391-407. A. Kent, W. J. Munro, and T. P. Spiller, Phys. Rev. A 84, 012326 (2011). R. A. Malaney, inProceedings of the IEEE Global Telecommunications Conference (GLOBECOM 2010) (IEEE, 2010), pp. 1-6. H. -K. Lau and H. -K. Lo, Phys. Rev. A 83, 012322 (2011). Einstein A, Podolsky B and Rosen N 1935 Can quantum-mechanical description of physical reality be considered Complete? Phys. Rev. 47 777-80H. Buhrman, N. Chandran, S. Fehr, R. Gelles, V. Goyal, R. Ostrovsky, and C. Schaffner, in Advances in Cryptology-CRYPTO 2011 (Springer, New York, 2011), pp. 429-446.
[0007] The object of this invention is to provide a method for authenticating a person who can make an accurate measurement and declare it, and for sharing a key with that person using a novel protocol in a quantum communication network such as a quantum entanglement swapping node.
[0008] This invention is based on the finding that by providing a reliable but not highly capable authentication unit in a quantum communication network and adjusting the photon signals output from two already authenticated users (terminals), authentication of a new user (terminal) and key sharing in the quantum communication network can be performed using a new protocol.
[0009] The first invention is a method for authenticating a third intra-node user 15 (Charlie) in a network in which a first intra-node user 11 (Alice) and a second intra-node user 13 (Bob) are authenticated. The third intra-node user 15 (Charlie) can receive photon signals (e.g., signals using quantum entangled photons) output from the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) via an optical separator 21. This method includes the following steps: an authentication unit 17 (Tom) controls the optical separator 21 to a first state; a first photon signal and a second photon signal output from the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob), respectively, pass through the optical separator 21 in the first state; and the third intra-node user 15 (Charlie) detects the first photon signal and the second photon signal that have passed through the optical separator 21 to obtain a detection result. The third intra-node user 15 (Charlie) notifies the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) of the detection result (detection result notification step). After the detection result notification step, the authentication unit 17 (Tom) notifies the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) of control information, which is information related to the control of the optical demultiplexer. The first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) authenticate the third intra-node user 15 (Charlie) using the detection result and the control information. This method relates to peer authentication using so-called Bell measurement.
[0010] In a preferred example of the above method, the third intra-node user 15 (Charlie) has a first photon detection unit 31 (e.g., a first arm and detectors a and b) and a second photon detection unit 41 (e.g., a second arm and detectors c and d). The detection result is detection information on the ground state of a single photon by the first photon detection unit 31 and the second single-photon detection unit 41.
[0011] In a preferred example of the above method, the light separating unit 21 has a half-wave plate 23 that changes polarization, and a beam splitter 25 through which light passes after passing through the half-wave plate 23. The authentication unit 17 (Tom) controls the light separating unit 21 by rotating the half-wave plate 23.
[0012] The second invention relates to a method for sharing an encryption key with a third intra-node user 15 (Charlie) in a network in which a first intra-node user 11 (Alice) and a second intra-node user 13 (Bob) are authenticated and share an encryption key.
[0013] This method includes the following steps: Based on the first invention, a user 15 (Charlie) within a third node is authenticated. An authentication unit 17 (Tom) controls the optical separator 21 to make it transparent. A third photon signal and a fourth photon signal output from the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob), respectively, pass through the transparent optical separator 21. The third intra-node user 15 (Charlie) controls the first photon detector 31 (first arm and detectors a, b) and the second single-photon detector 41 (second arm and detectors c, d) to measure different bases, and then detects the third photon signal and the fourth photon signal that have passed through the optical separator 21 to obtain a second detection result. The first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) measure the third photon signal and the fourth photon signal to obtain a self-measurement result. The third intra-node user 15 (Charlie) notifies the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) of the second detection result (second detection result notification process). After the second detection result notification process, the authentication unit 17 (Tom) notifies the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) of transparency information, which is information regarding the transparency of the optical separator 21. Either or both of the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) start sharing an encryption key with the third intra-node user 15 (Charlie) based on the self-measurement result, the second detection result, and the transparency information. This method is related to three-party QKD technology, and by repeating similar processes, the number of users who can share an encryption key can be increased.
[0014] The third invention relates to a system for sharing an encryption key with a third intra-node user 15 (Charlie) in a user node in which a first intra-node user 11 (Alice) and a second intra-node user 13 (Bob) are authenticated and share an encryption key. The third intra-node user 15 (Charlie) can receive photon signals output from the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) via an optical separator 21. An authentication unit 17 (Tom) can control the optical separator 21 to change the basis of the photon signals passing through the optical separator. This system then employs the method according to the second invention to start sharing an encryption key with the third intra-node user 15 (Charlie).
[0015] This invention provides a method for authenticating a person who can make an accurate measurement and declare it, and for key sharing with that person, using a novel protocol in a quantum communication network such as a quantum entanglement swapping node. The novel protocol is, for example, a two-to-one authentication and key sharing protocol using photon-pair quantum entanglement swapping.
[0016] FIG. 1 is a block diagram of a system for performing quantum communication.
[0017] Hereinafter, embodiments of the present invention will be described with reference to the drawings. The present invention is not limited to the embodiments described below, but also includes appropriate modifications of the embodiments below within the scope obvious to those skilled in the art.
[0018] FIG. 1 is a block diagram of a system that performs quantum communication. As shown in FIG. 1, this system manages a network in which a first node user 11 (Alice) and a second node user 13 (Bob) are authenticated. Each user represents a user terminal. The terminal may be a computer or a server, and typically has a processor that can implement various functions and execute each process based on program instructions. This system is capable of performing quantum communication. This system can also authenticate new users and share encryption keys.
[0019] Conventional quantum entanglement repeaters have no role or active function other than performing Bell measurements, regardless of whether the repeater terminal is honest or not. However, Bell measurements cannot be performed correctly anywhere; they must be performed in a location where pulses from Alice and Bob can interfere and a specific measurement can be performed. We propose actively utilizing this fact to authenticate a third user and subsequently lead to key sharing. In this invention, this idea can be implemented by using a measuring device that simultaneously inputs two photon pulses of, for example, 100 ps (2 cm in fiber length) and can observe the interference effect. Conventional quantum optics experiments that do not consider attacks by a malicious user, Eve, require precise control of the transmission distance. However, if Eve's attacks are considered, attacks such as teleportation, tapping, and even quantum memory attacks can be anticipated, so conventional quantum entanglement measurements alone cannot meet the requirements of PBC (position-based cryptography). The authentication and key sharing methods of the present invention propose novel protocols and security requirements for authentication and key sharing by using a trusted but not highly competent third party (Tom). In a system capable of quantum optical interference measurements, the present invention can achieve authentication and cryptographic key sharing with minimal conversion to classical information. In this case, the present invention makes it possible to share cryptographic keys with new users even in an implementation that can only correctly perform Bell measurements.
[0020] The first invention is a method for authenticating a third node user 15 (Charlie) in a network in which a first node user 11 (Alice) and a second node user 13 (Bob) are authenticated. The network may be a quantum key decryption (QKD) network. The encryption key may be distributed via the quantum key decryption (QKD) network. The quantum cryptography communication device includes, for example, a transmitter and a receiver. Quantum cryptography communication is performed between these devices using an optical signal (laser light). The first node, second node, and third node may be the same node or different nodes, as long as they are capable of transmitting and receiving information within the same network.
[0021] The computer has an input unit, an output unit, a control unit, a calculation unit, and a memory unit, and each element is connected by a bus or the like to enable information exchange. For example, a control program or various information may be stored in the memory unit. When predetermined information is input from the input unit, the control unit reads the control program stored in the memory unit. Then, the control unit reads the information stored in the memory unit as appropriate and transmits it to the calculation unit. The control unit also transmits the input information to the calculation unit as appropriate. The calculation unit performs calculation processing using the received various information and stores it in the memory unit. The control unit reads the calculation results stored in the memory unit and outputs them from the output unit. In this manner, various processes and steps are performed. The various units and means execute these various processes. The computer may have a processor, and the processor may realize various functions and steps. The computer may be standalone. Some of the functions of the computer may be distributed between a server and a terminal. In this case, it is preferable that the server and the terminal can exchange information via a network such as the Internet or an intranet. The computer may include a processor and a memory coupled to the processor. The memory may store instructions that, when executed by the processor, cause the computer to perform various processes or function as various elements. The computer may be provided with various training data to construct a learning model and perform various calculations through machine learning. In this case, the computer may perform various analyses using the learning model created through machine learning and deep learning of AI (artificial intelligence).
[0022] In the example shown in FIG. 1 , Alice 11 (first intra-node user) is a terminal capable of outputting single photons. For example, Alice 11 is a terminal located at a node in a quantum keying (QKD) network. In this example, Alice 11 includes a single-photon source 51, a half-wave plate 53, a beam splitter 55, and single-photon detectors 57 and 59. The single photon output from the single-photon source 51 has its polarization plane adjusted (or not adjusted) by the half-wave plate 53 and enters the beam splitter 55. The single photon that enters the beam splitter 55 is then separated according to its polarization plane (basis), and enters the single-photon detectors 57 and 59 for detection. A control unit of Alice 11 may be able to rotate the half-wave plate 53. This allows Alice 11 to adjust the basis detected by the single-photon detectors 57 and 59.
[0023] In the example shown in FIG. 1, Bob 13 (a second intra-node user) has a similar configuration to Alice 11, and each element functions in the same way.
[0024] In the example shown in FIG. 1 , Charlie 15 (a third intra-node user) has an optical separator 21, a first photon detector 31, and a second photon detector 41. Charlie 15 is a terminal located at the same node on the network as Alice 11. In this example, the optical separator 21 has, for example, a half-wave plate (HWP) 23 and a beam splitter (BS) 25. Also in this example, the first photon detector 31 has the same configuration as Alice 11. That is, in this example, the first photon detector 31 has a half-wave plate 33, a beam splitter 35, a single-photon detector a 37, and a single-photon detector b 39. Also in this example, the second photon detector 41 has a half-wave plate 43, a beam splitter 45, a single-photon detector c 47, and a single-photon detector d 49. Charlie 15 is capable of receiving photon signals (for example, signals based on quantum entangled photons) output from Alice 11 and Bob 13 via the optical separation unit 21 .
[0025] In the example shown in FIG. 1 , Tom 17, an authenticated unit, can rotate a half-wave plate (HWP) 23 (or HWP 33, 43). Tom 17 is also a terminal on the same network as Alice 11. For example, when Tom 17 rotates the HWP 23, the basis of the single photons split by the beam splitter (BS) 25 changes. Tom 17 can also control the HWP 23 to put the BS 25 into a state (transparent state) in which the single photons pass through as they are. Tom 17 is an authenticated terminal on this network. The control units of Alice 11, Bob 13, Charlie 15, and Tom 17 may be control units on a single server, or various information may be output to the server and controlled by the control unit of the server.
[0026] Next, an authentication method using the above system will be described. This method is a method for authenticating a third user, Charlie 15, in a network in which Alice 11 and Bob 13 are authenticated. This method includes the following steps:
[0027] The authentication unit 17 (Tom) controls the light separating unit 21 to put it into a first state. The first state also includes a state in which Tom 17 does not control the half-wave plate 23. The control unit of Tom 17 stores control information for the light separating unit 21 in a storage unit as appropriate. Examples of the control information may be the rotation status of the half-wave plate 23 or information regarding the basis of single photons separated by the light separating unit 21.
[0028] Alice 11 and Bob 13 output a first photon signal and a second photon signal, respectively. In this case, Alice 11 and Bob 13 may independently determine the basis of the first photon signal and the second photon signal. Examples of the basis are H (horizontal), V (vertical), diagonally upper right, and diagonally upper left.
[0029] The first photon signal and the second photon signal output from Alice 11 and Bob 13, respectively, pass through the optical separator 21, which is in the first state.
[0030] Charlie 15 detects the first photon signal and the second photon signal that have passed through the optical separation unit 21 to obtain a detection result. In the example of FIG. 1 , Charlie 15 has a first arm having a first photon detection unit 31 and a second arm having a second photon detection unit 41. Charlie 15 normally controls the first photon detection unit 31 and the second single-photon detection unit 41 so that they measure different bases. Of the photon signals that have passed through the optical separation unit 21, the photon signals directed to the first arm have their polarization plane appropriately adjusted by the half-wave plate 33, and the basis to be separated by the BS 35 is controlled. The photon signals are separated by the basis by the BS 35 and detected by the single-photon detector a 37 or the single-photon detector b 39. In this example, the polarization plane of the photon signal directed to the second arm is appropriately adjusted by the half-wave plate 43, the basis to be separated is controlled by the BS 45, and the photon signal is separated by the basis at the BS 45 and detected by the single-photon detector c 47 or the single-photon detector d 49. Charlie 15 confirms that the first arm or the second arm is firing, and randomly selects and measures a basis in each arm. However, different bases are measured in the first arm or the second arm. The control unit of Charlie 15 stores the detection results of the single-photon detector c 47 or the single-photon detector d 49 in the memory unit. Examples of detection results include receiving a single photon in a certain basis or measuring the entangled state of photons.
[0031] Charlie 15 notifies Alice 11 and Bob 13 of the detection result (detection result notification step). The control unit of Charlie 15 reads the detection result from the storage unit and outputs information about the detection result to Alice 11 and Bob 13 from the output unit.
[0032] Alice 11 and Bob 13 receive information about the detection result from Charlie 15. The input units of Alice 11 and Bob 13 may receive the information about the detection result output by Charlie 15, and the control units of Alice 11 and Bob 13 may store the information about the detection result in their respective storage units.
[0033] After the detection result notification process, the authentication unit 17 (Tom) notifies Alice 11 and Bob 13 of control information, which is information related to the control of the optical separator. The control unit of Tom 17 reads the control information from the storage unit and outputs the read control information from the output unit to Alice 11 and Bob 13.
[0034] Alice 11 and Bob 13 receive the control information output from Tom 17 and store it in their storage units as appropriate.
[0035] Alice 11 and Bob 13 authenticate Charlie 15 using the detection result and the control information. For example, if the detection result and the control information are each information about a basis for a single photon, Charlie 15 may be formally authenticated if they match. Alternatively, Alice 11 and Bob 13 may use the control information to determine a basis for a single photon that Charlie 15 will likely detect, and authenticate Charlie if the determined basis matches the detection result. This authentication is preferably performed simultaneously (in parallel) by Alice 11 and Bob 13. This method relates to peer authentication using so-called Bell measurement.
[0036] Next, a method for sharing an encryption key will be described. This method is a method for sharing an encryption key with a new user terminal, Charlie 15, in a network in which Alice 11 and Bob 13 are authenticated and share an encryption key. This method may use the system described above.
[0037] The method includes the following steps: Authenticate user 15 (Charlie) in the third node according to the method described above.
[0038] Tom 17 (authentication unit) controls the light separating unit 21 to make it transparent. For example, the control unit of Tom 17 may receive a program command to rotate the HWP 23 and control the light separating unit 21 so that the BS 25 transmits light. In the example of FIG. 1 , the light from Alice 11 may be transmitted to the second arm (second single-photon detector 41), and the light from Bob 13 may be transmitted to the first arm (first single-photon detector 31). Tom 17 may store transparency information, which is information relating to the fact that the light separating unit 21 has been made transparent, in a storage unit as appropriate.
[0039] Alice 11 and Bob 13 output the third and fourth photon signals, respectively. Charlie 15 does not know that Tom 17 has taken control of the optical splitter 21.
[0040] The third photon signal and the fourth photon signal output from Alice 11 and Bob 13, respectively, pass through the transparent optical separation unit 21.
[0041] Charlie 15 normally controls the first photon detection unit 31 and the second single photon detection unit 41 to measure different bases. If the first photon detection unit 31 and the second single photon detection unit 41 are configured to measure only the same base, Charlie 15 controls the HWPs 33, 43 to adjust the first photon detection unit 31 and the second single photon detection unit 41 to measure different bases. Then, Charlie 15 detects the third photon signal and the fourth photon signal that have passed through the optical separation unit 21 to obtain a second detection result. The obtained second detection result may be stored in a storage unit as appropriate.
[0042] Alice 11 and Bob 13 measure the third photon signal and the fourth photon signal, respectively, to obtain self-measurement results. Alice 11 and Bob 13 may also measure the photon signals after randomly selecting a basis to measure. For example, the third photon signal, which is a single photon output from the single-photon source 51 of Alice 11, has its polarization plane adjusted (or not adjusted) by the half-wave plate 53 and enters the beam splitter 55. The third photon signal that enters the beam splitter 55 is then separated according to its polarization plane (basis), and enters and is detected by the single-photon detectors 57 and 59. Bob 13 may measure the fourth photon signal in a similar manner. For example, Alice 11 and Bob 13 store the obtained self-measurement results in their respective memories.
[0043] Charlie 15 notifies Alice 11 and Bob 13 of the second detection result (second detection result notification step). For example, the control unit of Charlie 15 may read the second detection result from the storage unit and output it to Alice 11 and Bob 13.
[0044] Alice 11 and Bob 13 receive the second detection result output from Charlie 15. Then, for example, Alice 11 and Bob 13 store the second detection result in a storage unit.
[0045] After the second detection result notification step, Tom 17 notifies Alice 11 and Bob 13 of transparency information, which is information about making the optical separating unit 21 transparent. Tom 17 reads the transparency information from the storage unit and outputs it to Alice 11 and Bob 13.
[0046] Alice 11 and Bob 13 receive the transparency information output from Tom 17 and store it in a storage unit as appropriate.
[0047] Either Alice 11 or Bob 13, or both, perform second-stage authentication of Charlie 15 based on the self-measurement result, the second detection result, and the transparency information, and start sharing an encryption key with Charlie 15 based on the result. For example, if Charlie 15 notifies them that the first arm and the second arm have fired (the second detection result), and Tom 17 notifies them of information regarding the transparency of the optical separator 21, Alice 11 and Bob 13 can independently start sharing an encryption key with Charlie 15. To start sharing an encryption key, for example, quantum cryptography communication using quantum entanglement, such as the BBM92 protocol, can be performed. In this notification, a common key used for encryption is shared using two photons (a photon pair) in a state called quantum entanglement. When the state of one photon is determined by observation, the state of the other photon is also determined. For example, if Charlie 15 is found to be legitimate through the second-stage authentication, Alice 11 and Bob 13 may share the encryption key they share with Charlie. In this case, either or both of Alice 11 and Bob 13 may output the encryption key to Charlie 15. This method is related to three-party QKD technology, and by repeating the same process, the number of users who can share the encryption key can be increased.
[0048] The third invention relates to a system for sharing an encryption key with Charlie 15 at a user node where Alice 11 and Bob 13 have been authenticated and have shared an encryption key. Charlie 15 can receive photon signals output from Alice 11 and Bob 13 via an optical separator 21. Tom 17 can control the optical separator 21 to change the basis of the photon signals passing through the optical separator. This system then employs the method described above to start sharing an encryption key with Charlie 15. In this system, the processor simply executes instructions based on a program to perform the above-mentioned steps.
[0049] This method can be used in fields such as quantum secure communications.
[0050] 11 Alice (user in first node) 13 Bob (user in second node) 15 Charlie (user in third node) 17 Tom (authentication unit) 21 Optical separation unit 23 Half-wave plate 25 Beam splitter 31 First photon detection unit 33 Half-wave plate 35 Beam splitter 37 Single-photon detector a 39 Single-photon detector b 41 Second photon detection unit 43 Half-wave plate 45 Beam splitter 47 Single-photon detector c 49 Single-photon detector d 51 Single-photon source 53 Half wavelength 55 Beam splitter 57, 59 Single-photon detector
Claims
1. A method for authenticating a third intra-node user (15) in a network in which a first intra-node user (11) and a second intra-node user (13) are authenticated, wherein the third intra-node user (15) can receive photon signals output from the first intra-node user (11) and the second intra-node user (13) via an optical separation unit (21), the method comprising: a step in which an authentication unit (17) controls the optical separation unit (21) to set it to a first state; a step in which a first photon signal and a second photon signal output from the first intra-node user (11) and the second intra-node user (13), respectively, pass through the optical separation unit (21) in the first state; and a step in which the third intra-node user (15) detects the first photon signal and the second photon signal that have passed through the optical separation unit (21) to obtain a detection result. The method includes: a detection result notification step in which a third intra-node user (15) notifies a first intra-node user (11) and a second intra-node user (13) of the detection result; a step in which the authentication unit (17), after the detection result notification step, notifies the first intra-node user (11) and the second intra-node user (13) of control information, which is information related to the control of the optical separation unit (21); and a step in which the first intra-node user (11) and the second intra-node user (13) authenticate the third intra-node user (15) using the detection result and the control information.
2. The method according to claim 1, wherein the third intra-node user (15) has a first photon detection unit (31) and a second photon detection unit (41), and the detection result is detection information regarding the ground state of a single photon by the first photon detection unit (31) and the second single-photon detection unit (41).
3. A method according to claim 1, wherein the light separating section (21) has a half-wave plate (23) that changes polarization and a beam splitter (25) through which light that has passed through the half-wave plate passes, and the authentication unit (17) controls the light separating section (21) by rotating the half-wave plate (23).
4. A method for sharing an encryption key with a third intra-node user (15) in a network in which a first intra-node user (11) and a second intra-node user (13) are authenticated and share the encryption key, comprising: a step of authenticating the third intra-node user (15) based on the method described in claim 2; a step of the authentication unit (17) controlling the optical separation unit (21) to make the optical separation unit (21) transparent; a step of allowing a third photon signal and a fourth photon signal output from the first intra-node user (11) and the second intra-node user (13), respectively, to pass through the transparent optical separation unit (21); and a step of the third intra-node user (15) controlling the first photon detection unit (31) and the second single-photon detection unit (41) to measure different bases, and then detecting the third photon signal and the fourth photon signal that have passed through the optical separation unit (21) to obtain a second detection result. a step in which a first intra-node user (11) and a second intra-node user (13) measure a third photon signal and a fourth photon signal to obtain a self-measurement result; a second detection result notification step in which the third intra-node user (15) notifies the first intra-node user (11) and the second intra-node user (13) of the second detection result; a step in which, after the second detection result notification step, the authentication unit (17) notifies the first intra-node user (11) and the second intra-node user (13) of transparency information, which is information regarding the optical separation unit (21) being made transparent; and a step in which either or both of the first intra-node user (11) and the second intra-node user (13) start sharing an encryption key with the third intra-node user (15) based on the self-measurement result, the second detection result, and the transparency information.
5. A system for sharing an encryption key with a third intra-node user (15) in a user node where a first intra-node user (11) and a second intra-node user (13) are authenticated and share the encryption key, wherein the third intra-node user (15) can receive quantum entangled photon signals output from the first intra-node user (11) and the second intra-node user (13) via an optical separator (21), an authentication unit (17) can control the optical separator (21) to change the basis of the photon signal passing through the optical separator (21), and the system starts sharing the encryption key with the third intra-node user (15) by the method described in claim 3.
Citation Information
Patent Citations
Communication system and method
JP2017130932A
Authentication side device, authentication system, and authentication method
JP2021027394A
Location verification in quantum communications
WO2011044629A1