Method for guaranteeing context of individual operations in communication method in which plurality of operators performs plurality of operations

The method and system for quantum key distribution ensure the sequence of operations by transmitting unknown information between operators and batch authentication, addressing vulnerabilities in existing systems and reducing costs and resource consumption.

WO2026094890A1PCT designated stage Publication Date: 2026-05-07NAT INST OF INFORMATION & COMM TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
NAT INST OF INFORMATION & COMM TECH
Filing Date
2025-10-28
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Existing quantum key distribution systems fail to guarantee the temporal order of operations, leaving them vulnerable to security breaches due to the assumption that classical information reception time is not tampered with, which is not adequately secured by message authentication alone.

Method used

A method and system that ensure the sequence of operations by having each operator perform their operation and transmit unknown information to the next, followed by a batch authentication of all information after all operations are completed, using a quantum key distribution protocol.

Benefits of technology

Guarantees the temporal sequence of operations in an information-theoretic manner, reducing computational costs and minimizing the consumption of confidential information while enhancing security against malicious delays.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025037724_07052026_PF_FP_ABST
    Figure JP2025037724_07052026_PF_FP_ABST
Patent Text Reader

Abstract

Provided is a method for guaranteeing the context of individual operations in a communication method in which a plurality of operators performs a plurality of operations. The method for guaranteeing the context of individual operations in a communication method in which a plurality of operators performs a plurality of operations, comprises: an operation step of repeating, up to a predetermined number (N) of times, a step in which an n-th (n is an integer greater than or equal to one) operator performs an n-th operation and thereafter transmits n-th unknown information to an (n + 1)-th operator (however, the N-th operator does not need to transmit the N-th unknown information); and an authentication step of authenticating the first unknown information to the N-th unknown information after the operation step.
Need to check novelty before this filing date? Find Prior Art

Description

Method for ensuring the order of operations in a communication method where multiple operators perform multiple operations

[0001] This invention relates to a communication method and a communication system that can ensure the order of operations, for example, in quantum key distribution.

[0002] In normal communication, it is important that the content is not finally tampered with. For this reason, many means for ensuring that the content has not been tampered with, such as message authentication, have been studied. On the other hand, even if the communication timing is maliciously delayed, as long as the information arrives, it does not have a great impact on the purpose of communication itself, which is to send information. Therefore, there has been little research on means for actively detecting whether an act of simply delaying communication is done maliciously.

[0003] In such a situation, quantum communication is attracting attention as next-generation communication. This is because in recent years, quantum computers have been developed, and as a secure cryptographic protocol, a protocol called quantum key distribution that uses quantum communication is being implemented by multiple vendors.

[0004] It is known that in a quantum key distribution device, it is assumed that classical communication is message-authenticated (using an authenticated public channel) (for example, Non-Patent Document 1). Also, in quantum key distribution, usually, the guarantee of chronological order is not considered (for example, Japanese Unexamined Patent Application Publication Nos. 2015-142339, 2015-226277, 2016-100693, 2016-136673, 2016-178381, 2016-181814, and Patent No. 7002713).

[0005] In the quantum key distribution protocol, it is an important prerequisite for ensuring the security of quantum key distribution that the temporal order between locally performed operations and the normal communication performed behind is maintained. Therefore, different from a protocol that only involves simple normal communication, means for strictly ensuring the temporal order of specific operations executed remotely are required.

[0006] The following explains the basic structure of quantum key distribution. In the quantum key distribution protocol, communication is performed on both ordinary information (classical information) and quantum information. In discussions of quantum key distribution, the security of classical information is proven under the assumption that its contents have not been tampered with by any means. In fact, by performing message authentication called Wegman-Carter after the quantum key distribution protocol, it is possible to securely verify, information-theoretically, that the classical information exchanged during the quantum key distribution protocol has not been tampered with. On the other hand, because it is assumed that classical information is not tampered with, the assumption that when classical information is received during the quantum key distribution protocol, the time at which that classical information is received is later than when that classical information was sent was also overlooked when theoretically justifying security. However, if the classical information exchanged is easily guessed by an eavesdropper, this temporal order assumption is not guaranteed by message authentication alone. As a result, currently implemented quantum key distribution devices do not guarantee this temporal order order information-theoretically, which has the potential to become a security vulnerability.

[0007] Japanese Patent Publication No. 2015-142339, Japanese Patent Publication No. 2015-226277, Japanese Patent Publication No. 2016-100693, Japanese Patent Publication No. 2016-136673, Japanese Patent Publication No. 2016-178381, Japanese Patent Publication No. 2016-181814, Japanese Patent No. 7002713

[0008] Mizutani, A. , Kato, G. , Azuma, K. et al. Quantum key distribution with setting choices-independently correlated light sources. npj Quantum Inf 5, 8 (2019).

[0009] The purpose of this invention is to provide a method for guaranteeing the sequence of operations in a communication method in which multiple operators perform multiple operations.

[0010] This invention is fundamentally based on the following findings: After performing Operation 1, Operator 1 sends information that is difficult for an attacker to deduce at that time but can be made public without issue (Unknown Information) to Operator 2. After receiving this Secret Information, Operator 2 performs Operation 2. After all operations are performed, message authentication of the Unknown Information is performed. In this way, as a result, the temporal sequence is guaranteed when the authentication is successful. Unknown Information is, for example, a random number created by Operator 1.

[0011] The first invention relates to a method for guaranteeing the sequence of operations in a communication method in which multiple operators perform multiple operations. This method includes an operation step and an authentication step. The operation step is a process in which the nth operator performs the nth operation, and then transmits the nth unknown information to the (n+1)th operator (where n is an integer of 1 or more), and this process is repeated up to a predetermined number (N) (however, the nth operator does not have to send the nth unknown information). The communication of unknown information may be carried out on a public channel. An example of each operation is an operation based on a protocol in quantum key distribution. The nth unknown information may include a random number created by the nth operator. This step may also include a step of transmitting information relating to the nth operation or time information, which has been encrypted by the nth operator using the nth unknown information. The authentication step is a step of authenticating the first to the nth unknown information after the operation step. Authentication is, for example, the act of each of the multiple implementers confirming that the intended person is transmitting the intended content.

[0012] The second invention relates to a system for implementing the method described above. This system is a quantum key distribution system that distributes quantum keys based on a predetermined protocol. This system includes a plurality of operators and an authentication unit included in the quantum key distribution system.

[0013] According to this invention, based on the above findings, the sequence of operations in communication (especially quantum cryptography) where multiple operators perform multiple operations can be easily guaranteed. In particular, according to this invention, the sequence of operations in a quantum key distribution method can be easily guaranteed in an information-theoretic manner.

[0014] Figure 1 is a block diagram illustrating an example configuration of a quantum key distribution system. Figure 2 is a conceptual diagram showing an example of a process for guaranteeing the sequence of operations.

[0015] Figure 1 is a block diagram illustrating an example configuration of a quantum key distribution system. Various configurations of quantum key distribution systems are described in the patent documents exemplified earlier. Therefore, a known configuration can be appropriately adopted for the quantum key distribution system. As shown in Figure 1, the quantum key distribution system 1 includes a transmitter 3 (Alice) and a receiver 5 (Bob). In Figure 1, for simplicity, only one transmitter 3 and one receiver 5 are drawn. However, the quantum key distribution system 1 may include multiple devices, and the roles of the transmitter 3 and receiver 5 may change depending on the protocol. Furthermore, the quantum key distribution system 1, the transmitter 3, and the receiver 5 may each have an operation unit 7 and an authentication unit 9. In addition, the quantum key distribution system 1 may have an authentication device having an authentication unit 9, separate from the transmitter 3 and receiver 5.

[0016] The transmitting device 3 and the receiving device 5 may be connected by an optical network 2 or by a communication network 4. An example of the optical network 2 may be free space or an optical fiber network. The optical network 2 is typically a quantum communication channel or quantum communication network used for quantum key distribution. An example of the communication network 4 is an authenticated classical communication channel that allows communication between the transmitting device 3 and the receiving device 5. An example of a classical communication channel is the wireless or wired internet.

[0017] The operation unit 7 of the transmitting device 3 includes, for example, a light source, a random number generator, a quantum transmitter, a control circuit, and a classical transmitter (and classical receiver). The control circuit may include a processor and waveguides, or it may be controlled by a computer or server. The control circuit or processor may also store a program in a memory unit as appropriate and perform various controls based on the program's instructions. The operation unit 7 of the transmitting device 3 performs, for example, the operation of encoding a single photon output from the light source based on an encoding protocol. During this encoding, for example, random numbers generated by a random number generator may be used. However, unknown information other than random numbers may also be used in the encoding operation. An example of an encoding protocol is the BB84 protocol. Any encoding protocol may be used as appropriate. For example, one of two encoding basis sets is randomly selected for each photon, and the photon is randomly encoded with a data value of 1 or 0 using the selected encoding basis set. Then, for example, the encoding rule and data value applied to each photon are passed to the control circuit. A series of encoded single photons are transmitted to the receiver 5 (Bob) via the optical network 2.

[0018] The receiving device 5, for example, randomly selects an encoding basis to measure for a photon, and then determines a data value for the photon using the selected basis. For example, the applied encoding basis and the measured value for each detected photon are passed to the control circuit of the receiving device 5.

[0019] On the other hand, the transmitting device 3 and the receiving device 5 can communicate with each other via classical transmitters and receivers, and for example, establish a common shared key. For example, the transmitting device 3 outputs unknown information, such as random numbers, to the receiving device 5 via the communication network 4.

[0020] In a typical quantum key distribution system, mutual authentication is performed each time unknown information, such as random numbers used for encoding, and the corresponding series of encoded quantum encrypted information are sent and received, in order to eliminate the possibility of a man-in-the-middle attack. This authentication itself is a well-known procedure. The authentication units 9 of the transmitting device 3 and the receiving device 5 only need to perform the authentication procedure. Performing the authentication procedure may involve, for example, applying a digital signature to the messages being exchanged. The digital signature is generated and verified using an encryption key called an ID key for the link. This can be based on symmetric encryption, where the ID key is a secret value known only to both parties.

[0021] On the other hand, the quantum key distribution system of the present invention does not require the authentication procedure to be performed after each operation; it can be performed at a different time from the series of operations (for example, after the series of operations are completed). This authentication process may be performed by the authentication unit 9 of the transmitting device 3 and the receiving device 5, or by an authentication device that has received the information necessary for authentication. The transmitting device 3 and the receiving device 5 in Figure 1 perform various operations, and are therefore also referred to as operators. However, operators usually refer not to people, but to terminals or devices that can perform the quantum key distribution system.

[0022] Figure 2 is a conceptual diagram showing an example of a process for guaranteeing the sequence of operations. This method is implemented, for example, by the system described above, and relates to a method for guaranteeing the sequence of operations in a communication method in which multiple operators perform multiple operations. This method includes an operation step and an authentication step. Examples of communication methods include quantum key distribution methods and quantum cryptographic communication methods involving quantum key distribution. Quantum key distribution methods are publicly known and, for example, are described in the patent documents described earlier. In the case of multiple operators, the operators are usually terminals used for communication.

[0023] The operation process involves the nth operator performing the nth operation, then transmitting the nth unknown piece of information to the (n+1)th operator (where n is an integer greater than or equal to 1), and repeating this process up to a predetermined number of times (N). (However, the nth operator does not have to send the nth unknown piece of information.) Examples of each operation are protocols-based operations in quantum key distribution (e.g., coding operations). The nth unknown piece of information may include a random number generated by the nth operator. The unknown piece of information is typically used for coding, or for creating or verifying cryptographic keys. This process may also include transmitting information relating to the nth operation or time information, which has been encrypted by the nth operator using the nth unknown piece of information. There may be multiple operators, and one operator may perform operations multiple times.

[0024] The authentication process is a process that takes place after the operation process and authenticates the first to the nth unknown pieces of information. Authentication is, for example, the act of multiple implementers confirming that the intended person is transmitting the intended content. As described above, authentication itself is publicly known. The authentication process may be performed by each operator who has the information (and authentication unit) for performing authentication, or it may be performed by an authentication device (which has an authentication unit). [Example]

[0025] The present invention will be described below with reference to examples. The present invention is not limited to the examples described below. In the examples, operators will be denoted as [Operator 1] and [Operator 2]. Preferably, each operator is located remotely. Furthermore, the operation performed by [Operator m] will be denoted as [Operation m]. Below, without losing generality, we will describe the case where it is guaranteed that [Operation 1] is executed chronologically before [Operation 2]. It should be assumed that [Operator 1] and [Operator 2] are honest, and that the attacker is located in a different place from [Operator 1] and [Operator 2] and can only attack the communication path between them. Examples of attacks include tampering and delay. To explain the effects of the examples, several reference examples will be considered below.

[0026] [Reference Example 1] In Reference Example 1, [Operator 1] and [Operator 2] each possess accurate timekeeping devices. Furthermore, they pre-arrange for [Operator 1] to perform [Operation 1] before a certain time T, and for [Operator 2] to perform [Operation 2] after a certain time T. Then, [Operator 1] and [Operator 2] perform [Operation 1] and [Operation 2] according to their pre-arranged plan. Reference Example 1 thus guarantees the temporal sequence of events.

[0027] [Reference Example 2] Reference Example 2 is almost the same as Reference Example 1. However, in Reference Example 2, it is not necessary to set the time T in advance. In Reference Example 2, after performing [operation m], [operator 1] and [operator 2] exchange information regarding the time of execution to confirm that there is a time T after [operator 1] performs [operation 1] and before [operator 2] performs [operation 2]. In this way, Reference Example 2 guarantees the temporal sequence of operations.

[0028] Reference Examples 1 and 2 have the following problems: These methods require both Operator 1 and Operator 2 to have a common, accurate clock (share the exact time). Furthermore, these methods have the problem of requiring a complex implementation of a series of protocols. Additionally, if the time difference between Operation 1 and Operation 2 is to be minimized, the accuracy of the clocks must be increased accordingly. To guarantee temporal order in a way that is resistant to attackers, the accuracy of the synchronization between the two clocks held by Operator 1 and Operator 2 must be ensured in situations where attacks on the normal communication channel are possible. In the first place, accurately synchronizing remote clocks using normal communication is a technical challenge. Therefore, these reference examples have the problem of difficulty in satisfying the premise of having two accurate remote clocks in situations where communication may be under attack.

[0029] [Reference Example 3] In Reference Example 3, after [Operator 1] performs [Operation 1], [Operator 1] creates information notifying [Operator 2] that the operation has been performed, along with a certificate for message authentication of that information, and sends it to [Operator 2]. [Operator 2] receives the information notifying [Operator 2] that the operation has been performed and the certificate, and after successful message authentication, performs [Operation 2]. Only [Operator 1] can create a certificate that will successfully authenticate the message, and this certificate must be created after [Operation 1] has been performed.

[0030] The problem with Reference Example 3 is that authentication must be performed each time a temporal sequence is guaranteed. This requires significant computing resources. Furthermore, to guarantee the temporal sequence in Reference Example 3 in an information-theoretically secure manner (although this is necessary when used in quantum key distribution), it is necessary to use secret information that is commonly known by [Operator 1] and [Operator 2] but unknown to the attacker, each time a message is authenticated. Once secret information has been used, it is no longer secret, so attempting to handle this information-theoretically securely using Reference Example 3 means that secret information, a crucial resource in communication, is consumed each time the temporal sequence is guaranteed.

[0031] The following examples relate to methods and systems that avoid the problems described in the above-mentioned reference examples.

[0032] In Example 1, after the nth operator performs the nth operation, the nth unknown piece of information is transmitted to the (n+1)th operator (where n is an integer greater than or equal to 1). This process is repeated up to a predetermined number (N). The nth operators do not all need to be different operators; some may be the same operator. Also, if the mth operator and the (m+1)th operator are the same person, the mth unknown piece of information does not need to be transmitted to the (m+1)th operator.

[0033] A first operator ([Operator 1]) performs the first operation ([Operation 1]). The first operator ([Operator 1]) obtains the first unknown information (first unknown information) and transmits the first unknown information to the second operator ([Operator 2]). [Operator 1] uses a random number generator to obtain a random number [first secret information]. [Operator 1] performs an encoding operation [Operation 1] to adjust the polarization plane of a single photon using the random number, for example, according to a quantum cryptography protocol. Then, [Operator 1] outputs the random number [first secret information] to a public communication channel (for example, the internet) so that the second operator can receive it. Meanwhile, [Operator 1] outputs the encoded photon to an optical network so that the second operator can receive it.

[0034] From the second operator ([Operator 2]) up to the Nth operator (Operator [N]), each operator performs the same operations and transmission tasks as described above. However, the Nth operator does not need to send the Nth unknown information.

[0035] The authentication process is a process that takes place after the operation process and authenticates the first to the nth unknown pieces of information. Authentication is, for example, the act of each of the multiple implementers confirming that the intended person is transmitting the intended content. Each operator may perform the authentication. Alternatively, an authentication device with an authentication unit may receive the information necessary for authentication (for example, the first to the nth unknown pieces of information) from each operator and perform the authentication.

[0036] Example 1 does not require the introduction of other devices or the imposition of conditions on those devices, as in Reference Examples 1 and 2. This reduces the possibility of security vulnerabilities and lowers the manufacturing cost of the device.

[0037] Example 1 is expected to significantly reduce computational costs and the amount of confidential information consumed compared to Reference Example 3. This is because, in Reference Example 3, the creation of the message authentication certificate is required to be completed before Operation 2 is performed. Therefore, the computational costs and the amount of confidential information consumed are proportional to the number of times the temporal sequence is guaranteed. On the other hand, in Example 1 of the present invention, message authentication can be performed at any time after Operation 1 or Operation 2, regardless of when those operations are performed. In other words, when many temporal sequence guarantees are performed using the same protocol, it is sufficient to perform message authentication on all the transmitted Unknown Information at once. Message authentication has the property that performing it in batches rather than in fragments can significantly reduce the total computational costs and the amount of confidential information consumed. For this reason, the present invention is expected to significantly reduce computational costs and the amount of confidential information consumed.

[0038] This invention can be used in the information and communication-related industries.

[0039] 1. Quantum key distribution system 2. Optical network 3. Transmitter 4. Communication network 5. Receiver 7. Operation unit 9. Authentication unit

Claims

1. A method for guaranteeing the sequence of operations in a communication method in which multiple operators perform multiple operations, comprising: an operation step, in which the nth operator performs the nth operation and then transmits the nth unknown information to the (n+1)th operator (where n is an integer of 1 or more), and repeats this process up to a predetermined number (N) (however, the nth operator does not have to send the nth unknown information); and an authentication step, in which the first to nth unknown information are authenticated after the operation step.

2. The method according to claim 1, wherein each operation is a protocol-based operation in quantum key distribution.

3. The method according to claim 2, wherein the nth unknown piece of information includes a random number generated by the nth operator.

4. A method according to claim 2 or 3, wherein the operation step includes transmitting information relating to an nth operation or time information, which has been encrypted by the nth operator using an nth unknown piece of information.

5. A quantum key distribution system that distributes quantum keys based on a predetermined protocol, the quantum key distribution system includes a plurality of operators, wherein, based on the protocol for quantum key distribution, the nth operator transmits the nth unknown information to the (n+1)th operator after performing the nth operation (where n is an integer between 1 and N, and the nth operator does not have to send the nth unknown information), and the quantum key distribution system further includes an authentication unit that authenticates the first to the nth unknown information after the nth operator performs the nth operation, thereby guaranteeing the sequence of events of the nth operation.

6. A quantum key distribution system according to claim 5, wherein the nth unknown piece of information includes a random number created by the nth operator.