WO2023242972A1 - 通信システム、通信装置、方法、及びプログラム - Google Patents

通信システム、通信装置、方法、及びプログラム Download PDF

Info

Publication number
WO2023242972A1
WO2023242972A1 PCT/JP2022/023867 JP2022023867W WO2023242972A1 WO 2023242972 A1 WO2023242972 A1 WO 2023242972A1 JP 2022023867 W JP2022023867 W JP 2022023867W WO 2023242972 A1 WO2023242972 A1 WO 2023242972A1
Authority
WO
WIPO (PCT)
Prior art keywords
key
key sharing
communication
sharing method
shared
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2022/023867
Other languages
English (en)
French (fr)
Inventor
盛 知加良
恆和 齋藤
鉄太郎 小林
優太郎 清村
浩司 千田
勝行 夏川
耕一 高杉
大介 白井
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
NTT Inc
Original Assignee
Nippon Telegraph and Telephone Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nippon Telegraph and Telephone Corp filed Critical Nippon Telegraph and Telephone Corp
Priority to PCT/JP2022/023867 priority Critical patent/WO2023242972A1/ja
Priority to KR1020247042845A priority patent/KR20250013236A/ko
Priority to EP22946792.3A priority patent/EP4542923A4/en
Priority to JP2024527972A priority patent/JP7835288B2/ja
Publication of WO2023242972A1 publication Critical patent/WO2023242972A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/12Transmitting and receiving encryption devices synchronised or initially set up in a particular manner
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0838Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0852Quantum cryptography
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0852Quantum cryptography
    • H04L9/0855Quantum cryptography involving additional nodes, e.g. quantum relays, repeaters, intermediate nodes or remote nodes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • H04L9/16Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms the keys or algorithms being changed during operation

Definitions

  • QKD Quantum Key Distribution
  • KME Key Management Entity
  • SAE Secure Application Entity
  • QKD has the problem that keys cannot be shared if tapping on the optical fiber cable continues. Therefore, from the viewpoint of service continuity, it is necessary to be able to switch to another key sharing method even if a certain key sharing method becomes unavailable for some reason.
  • a technology is provided that allows switching between multiple key sharing methods.
  • FIG. 1 is a diagram showing an example of the overall configuration of a communication system according to the present embodiment.
  • FIG. 3 is a diagram illustrating an example of a detailed functional configuration of a protocol converter according to the present embodiment.
  • FIG. 3 is a sequence diagram illustrating an example of key acquisition processing according to the present embodiment. It is a sequence diagram which shows an example of the switching process based on this embodiment. It is a figure showing a modification of the whole composition of a communication system concerning this embodiment.
  • 1 is a diagram showing an example of a hardware configuration of a computer.
  • the key sharing system 20A-1 and the key sharing system 20A-2 are capable of mutually generating shared keys using a certain key sharing method (for example, QKD) in which KME and SAE exist on different devices. do.
  • the key sharing system 20B-1 and the key sharing system 20B-2 are able to mutually generate shared keys using a certain key sharing method (for example, PQKD) in which the KME and SAE exist on the same device.
  • the key sharing system 20C-1 and the key sharing system 20C-2 can mutually generate shared keys using a certain key sharing method in which KME and SAE exist on the same device. Therefore, in the example shown in FIG.
  • the key sharing system 20A-1 exists separately from the communication device 10-1, while the key sharing system 20B-1 and the key sharing system 20C-1 are connected to the communication device 10-1. included in. The same applies to the key sharing system 20A-2 to the key sharing system 20C-2.
  • the communication device 10-1 and the key sharing system 20A-1 are communicably connected, for example, via an intra-site network.
  • the communication device 10-2 and the key sharing system 20A-2 are communicably connected via, for example, an intra-site network.
  • the communication device 10-2 uses the key (shared key) shared between the key sharing system 20-2 and the key sharing system 20-1 that use the same key sharing method. Perform encrypted communication with 1.
  • the communication device 10-2 includes an AP 110-2, a protocol conversion section 120-2, and a key output section 130-2 corresponding to each key sharing system 20-2.
  • the key output units 130-2 corresponding to the key sharing systems 20A-2 to 20C-2 are the key output units 130A-2 to 130C-2, respectively.
  • communication device 10 when the communication device 10-1 and the communication device 10-2 are not distinguished, they will be referred to as “communication device 10", and when the key sharing system 20-1 and the key sharing system 20-2 are not distinguishable, they will be referred to as “key sharing system 10".
  • System 20 Other components are similarly expressed as “AP 110,” “protocol conversion unit 120,” “key output unit 130,” etc.
  • key sharing system 20A-1 and the key sharing system 20A-2 are not distinguished, they are referred to as “key sharing system 20A”.
  • Other information will be similarly expressed as “key sharing system 20B”, “key sharing system 20C”, etc.
  • the AP 110 is an application program that performs encrypted communication with the AP 110 of another communication device 10 using a shared key.
  • the protocol converter 120 accepts (a message representing) a key request from the AP 110 and sends (a message representing) a key notification to the AP 110. Further, the protocol conversion unit 120 switches to another key sharing system 20 when an error or the like occurs in the key sharing system 20. Note that a detailed functional configuration example of the protocol converter 120 will be described later.
  • the key output unit 130 has a function of hiding the specific mechanism of the key sharing method executed by the key sharing system 20 corresponding to the key output unit 130, and upon receiving a key request, the key sharing system 20 corresponding to the key output unit 130 The shared key generated in step 20 is returned. That is, upon receiving a key request from the protocol conversion unit 120, the key output unit 130 returns a key output containing the shared key generated by the key sharing system 20 corresponding to itself to the protocol conversion unit 120. Note that the key output unit 130 may also be called a protocol driver or the like.
  • the specific mechanism of the key sharing method is hidden from the AP 110, and the AP 110 can obtain a shared key by simply requesting a key from the protocol conversion unit 120 and receiving a key notification in response to the key request. .
  • the key request reception unit 121 receives a switching notification from the switching unit 124, and sets the key sharing method included in the switching notification as the key sharing method currently in use. Furthermore, the key request reception unit 121 transmits the switching notification to the other communication devices 10.
  • the key notification unit 122 receives the key output from the key output unit 130, extracts the shared key included in the key output, and transmits a key notification including the shared key to the AP 110.
  • the error notification unit 123 receives an error notification from the key output unit 130 and transmits the error notification to the switching unit 124.
  • the switching unit 124 receives the error notification from the key output unit 130, determines a key sharing method to switch to, and sends a switching notification containing information indicating the determined key sharing method to the key request receiving unit. Send to 121.
  • the key storage unit 125 stores the shared key generated by the key sharing method in the storage device.
  • the key (shared key) stored in the storage device will also be referred to as a stored key.
  • the key storage unit 125 is not an essential component, and the protocol conversion unit 120 may not include the key storage unit 125.
  • the overall configuration of the communication system 1 shown in FIG. 1 is an example, and is not limited to this.
  • the communication device 10 can use three key sharing methods, and key sharing systems 20A to 20C corresponding to those key sharing methods are illustrated.
  • key sharing systems 20 there are as many key sharing systems 20 as there are key sharing methods that can be used by the communication device 10.
  • the communication device 10 can use N key sharing schemes, there are N key sharing systems 20 that respectively correspond to the N key sharing schemes.
  • the communication network between the communication devices 10 and the communication network between the key sharing system 20 may be the same, or may be different depending on the key sharing method executed by the key sharing system 20.
  • the key sharing method executed by the key sharing system 20A is QKD
  • the communication network between the communication devices 10 (AP 110) is the Internet, etc.
  • the communication network between the key sharing systems 20A is an optical communication network, etc.
  • the key sharing method executed by the key sharing system 20B is PQKD or the like
  • the communication network between the communication devices 10 (the AP 110 thereof) and the communication network between the key sharing system 20B are both the Internet or the like.
  • AP 110-1 performs encrypted communication with AP 110-2
  • FIG. 3 for key acquisition processing for AP 110-1 and AP 110-2 to acquire a shared key. I will explain while doing so.
  • the AP 110-1 corresponds to an initiator
  • the AP 110-2 corresponds to a responder.
  • the key request receiving unit 121-1 of the protocol conversion unit 120-1 Upon receiving the key request, the key request receiving unit 121-1 of the protocol conversion unit 120-1 sends the key request to the key output unit 130 corresponding to the key sharing method currently set as the key sharing method. (Step S102). For example, when QKD is set as the key sharing method currently in use, the key request receiving unit 121-1 sends a message to the key output unit 130A-1 corresponding to the key sharing system 20A-1 that performs key sharing using QKD. and send the key request. On the other hand, for example, if PQKD is set as the key sharing method currently in use, the key request receiving unit 121-1 sends the key output unit 130B- corresponding to the key sharing system 20B-1 that performs key sharing using PQKD. The key request is sent to 1.
  • the key output unit 130-1 Upon receiving the key request from the key request receiving unit 121-1, the key output unit 130-1 transmits the key request to the key sharing system 20-1 corresponding to itself (step S103). For example, when the key output unit 130A-1 receives a key request, the key output unit 130A-1 transmits the key request to the key sharing system 20A-1. On the other hand, for example, when the key output unit 130B-1 receives a key request, the key output unit 130B-1 transmits the key request to the key sharing system 20B-1.
  • the key sharing system 20-1 executes the key sharing method with the key sharing system 20-2 that executes the same key sharing method as itself, A shared key is generated (step S104). For example, when the key sharing system 20A-1 that executes QKD receives a key request, the key sharing system 20A-1 executes QKD with the key sharing system 20A-2 and generates a shared key. On the other hand, for example, when the key sharing system 20B-1 that executes PQKD receives a key request, this key sharing system 20B-1 executes PQKD with the key sharing system 20B-2 and shares the shared key. generate.
  • the key sharing system 20-1 transmits the key (shared key) generated in step S104 above to the key output unit 130-1 corresponding to itself (step S105).
  • the key notification unit 122-1 of the protocol conversion unit 120-1 Upon receiving the key output from the key output unit 130-1, the key notification unit 122-1 of the protocol conversion unit 120-1 extracts the shared key included in the key output and sends a key notification containing the shared key. is transmitted to the AP 110-1 (step S107).
  • the AP 110-1 Upon receiving the key notification from the protocol converter 120-1, the AP 110-1 acquires the shared key from this key notification (step S108).
  • the key output unit 130-2 Upon receiving the shared key from the key sharing system 20-2, the key output unit 130-2 transmits a key output containing this shared key to the protocol conversion unit 120-2 (step S110).
  • the key notification unit 122-2 of the protocol conversion unit 120-2 Upon receiving the key output from the key output unit 130-2, the key notification unit 122-2 of the protocol conversion unit 120-2 extracts the shared key included in the key output and generates a key notification containing the shared key. is transmitted to the AP 110-2 (step S111).
  • the AP 110-2 Upon receiving the key notification from the protocol converter 120-2, the AP 110-2 acquires the shared key from this key notification (step S112).
  • the key notification unit 122-1 notifies the protocol conversion unit 120-2 of the key ID of the shared key.
  • the protocol conversion unit 120-2 similarly passes the shared key of the key ID from among the stored keys to the key notification unit 122-2, and the shared key is notified to the AP 110-2.
  • Error when requesting a key for example, communication error when sharing a key with the key sharing system 20-2, internal error in the key sharing system 20-1 when sharing a key, etc.
  • Key exhaustion including exhaustion of keys stored by the key storage unit 125
  • Computation capacity depletion (4) System error (5) Tamper abnormality For example, an event in which key sharing becomes impossible due to tapping on an optical fiber cable can be detected as a tamper abnormality.
  • the key output unit 130-1 Upon receiving the error notification from the key sharing system 20-1, the key output unit 130-1 transmits this error notification to the protocol conversion unit 120-1 (step S203).
  • the error notification unit 123-1 of the protocol conversion unit 120-1 Upon receiving the error notification from the key output unit 130-1, the error notification unit 123-1 of the protocol conversion unit 120-1 transmits this error notification to the switching unit 124-1 (step S204).
  • the switching unit 124-1 of the protocol conversion unit 120-1 determines the key sharing method to which to switch (step S205).
  • the switching unit 124 can determine the key sharing method of the switching destination using various methods, and for example, it is conceivable to determine the key sharing method of the switching destination using the following method.
  • One key sharing method is determined randomly or according to a predetermined order (predetermined priority order) from among key sharing methods other than the key sharing method currently in use.
  • the key sharing method may be determined in various other ways. Further, in addition to this, for example, when the key storage unit 125 stores a shared key, it may be determined to switch the acquisition source of the shared key to the stored key. This allows the stored key to be used as a shared key until the stored key is exhausted, and the key sharing method can be switched after the stored key is exhausted. In the following description, it is assumed that the key sharing method to be switched to has been determined.
  • the switching unit 124-2 of the protocol converting unit 120-2 Upon receiving the switching notification from the protocol converting unit 120-2, the switching unit 124-2 of the protocol converting unit 120-2 transmits this switching notification to the key request receiving unit 121-2 (step S209).
  • the key request reception unit 121-2 of the protocol conversion unit 120-2 selects the key sharing method indicated by the information included in this switching notification as the currently used key sharing method. settings (step S210).
  • FIG. 5 shows a modification of the overall configuration of the communication system 1 according to this embodiment.
  • FIG. 1 shows a communication system 1 in which a server 30-1 is further included in base 1 and a server 30-2 is further included in base 2.
  • server 30 when the servers 30-1 and 30-2 are not distinguished from each other, they will be referred to as "server 30.”
  • the server 30 includes a protocol conversion section 120 and a key output section 130.
  • the server 30 also includes a key sharing system 20 that corresponds to the key output unit 130 that the server 30 has, or is communicably connected to the key sharing system 20 that corresponds to the key output unit 130 that the server 30 has.
  • the server 30-1 includes a protocol conversion section 120-11, a key output section 130D-1, and a key output section 130E-1. Furthermore, there are a key sharing system 20D-1 corresponding to the key output section 130D-1 and a key sharing system 20E-1 corresponding to the key output section 130E-1.
  • the server 30-2 includes a protocol conversion section 120-21, a key output section 130D-2, and a key output section 130E-2. Furthermore, there are a key sharing system 20D-2 corresponding to the key output section 130D-2 and a key sharing system 20E-2 corresponding to the key output section 130E-2.
  • which key sharing system 20 is used to generate the shared key (that is, which key sharing method is used to generate the shared key) is shared and coordinated among all communication devices 10 and servers 30. That is, for example, if an error or the like occurs in a certain key sharing system 20 and the key sharing method is switched (or it may be a switch to using a stored key as a shared key),
  • the switching unit 124 that has determined the switching destination also sends a switching notification to the protocol conversion units 120 included in all other communication devices 10 and servers 30. Thereby, the key sharing method used throughout the communication system 1 is shared and linked.
  • the communication device 10 side Operations such as generating a shared key using the key sharing system 20 become possible.
  • the switching unit 124 determines the key sharing method to switch to, the communication device 10 side or the server 30 It is possible to consider which key sharing system 20 (the key sharing method executed by) on the side should be switched to. As a result, for example, if an error occurs in the key sharing system 20 on the server 30 side, the switch is switched to the key sharing system 20 on the communication device 10 side, and conversely, if an error occurs in the key sharing system 20 on the communication device 10 side, This enables operations such as switching to the key sharing system 20 on the server 30 side.
  • the input device 501 is, for example, a keyboard, a mouse, a touch panel, various physical buttons, etc.
  • the display device 502 is, for example, a display, a display panel, or the like. Note that the computer 500 may not include at least one of the input device 501 and the display device 502, for example.
  • the external I/F 503 is an interface with an external device such as a recording medium 503a.
  • Examples of the recording medium 503a include a CD-ROM, a DVD-ROM, an SD memory card, and a USB memory card.
  • the communication I/F 504 is an interface for connecting the computer 500 to a communication network.
  • the processor 505 is, for example, various arithmetic devices such as a CPU (Central Processing Unit).
  • the memory device 506 is, for example, various storage devices such as a HDD (Hard Disk Drive), an SSD (Solid State Drive), a RAM (Random Access Memory), a ROM (Read Only Memory), and a flash memory.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Physics & Mathematics (AREA)
  • Electromagnetism (AREA)
  • Theoretical Computer Science (AREA)
  • Computer And Data Communications (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本開示の一態様による通信システムは、複数の通信装置が含まれる通信システムであって、前記通信装置は、他の通信装置との間で暗号化通信を行うように構成されているアプリケーションプログラムと、前記暗号化通信に用いられる共有鍵を生成する鍵共有方式を切り替えるように構成されている切替部と、を有し、前記切替部は、現在利用中の鍵共有方式によって前記共有鍵を生成できない場合、他の鍵共有方式に切り替えるように構成されている。

Description

通信システム、通信装置、方法、及びプログラム
 本開示は、通信システム、通信装置、方法、及びプログラムに関する。
 量子鍵配送(QKD:Quantum Key Distribution)と呼ばれる鍵共有プロトコルが知られている(例えば、非特許文献1及び2参照)。QKDは、2者間の通信を秘匿するための鍵を量子テレポーテーションにより共有し、その鍵(以下、共有鍵ともいう。)を用いて暗号化されたデータの送受信を行う技術である。
 QKDでは、鍵共有を行うエンティティ(KME:Key Management Entity)とデータの送受信を行うエンティティ(SAE:Secure Application Entity)とが別の装置上に存在し、光ファイバーケーブル等で実現される光通信ネットワークを利用してKEM間で鍵を共有する。
ETSI GS QKD 004 V2.1.1 (2020-08) Quantum Key Distribution (QKD); Application Interface ETSI GS QKD 014 V1.1.1 (2019-02) Quantum Key Distribution (QKD); Protocol and data format of REST-based key delivery API
 しかしながら、QKDでは光ファイバーケーブルへのタッピングが続くと鍵の共有ができなくなるという問題がある。このため、サービス継続性の観点から、何等かの理由で或る鍵共有方式が利用できなくなっても、他の鍵共有方式に切り替えることができるようにすることが必要である。
 本開示は、上記の点に鑑みてなされたもので、複数の鍵共有方式を切り替えることができる技術を提供する。
 本開示の一態様による通信システムは、複数の通信装置が含まれる通信システムであって、前記通信装置は、他の通信装置との間で暗号化通信を行うように構成されているアプリケーションプログラムと、前記暗号化通信に用いられる共有鍵を生成する鍵共有方式を切り替えるように構成されている切替部と、を有し、前記切替部は、現在利用中の鍵共有方式によって前記共有鍵を生成できない場合、他の鍵共有方式に切り替えるように構成されている。
 複数の鍵共有方式を切り替えることができる技術が提供される。
本実施形態に係る通信システムの全体構成の一例を示す図である。 本実施形態に係るプロトコル変換部の詳細な機能構成の一例を示す図である。 本実施形態に係る鍵取得処理の一例を示すシーケンス図である。 本実施形態に係る切替処理の一例を示すシーケンス図である。 本実施形態に係る通信システムの全体構成の変形例を示す図である。 コンピュータのハードウェア構成の一例を示す図である。
 以下、本発明の一実施形態について説明する。以下では、QKDを含む複数の鍵共有方式を切り替えることができる通信システム1について説明する。この通信システム1によれば、何等かの理由(例えば、エラー等)で或る鍵共有方式が利用できなくなっても、他の鍵共有方式に切り替えることができるため、暗号化通信が必要なサービスの継続性を担保することができる(言い換えれば、サービスの可用性を高めることができる。)。なお、鍵共有方式は鍵共有プロトコルや鍵交換プロトコル等と呼ばれてもよく、2者間で同一の共有鍵を生成するための技術のことを指す。鍵共有方式としては、QKDの他、例えば、耐量子計算機暗号(PQC:Post-Quantum Cryptograph)を用いた耐量子計算機暗号鍵交換(PQKD:Post-Quantum cryptography-based Key Distribution)等が挙げられる。耐量子計算機暗号鍵交換としては、例えば、KEM(Key Encapsulation Mechanism)に耐量子計算機暗号(例えば、格子暗号等)を適用した鍵交換等が挙げられる。
 なお、本実施形態に係る通信システム1において、SAEとKME間はPQCを用いたTLS等によって通信路が暗号化されており、またSAEとKME間は当該PQCを用いたTLSにおいてPQCに対応した公開鍵証明書を用いた相互認証等が実施されており、SAEとKME間の通信では耐量子計算機を用いた攻撃に耐えうる強度の安全性が確保されていることを前提する。
 <通信システム1の全体構成例>
 本実施形態に係る通信システム1の全体構成例を図1に示す。図1では、一例として、拠点1と拠点2の間で暗号化通信を行う場合の通信システム1を示している。図1に示す通信システム1では、通信装置10-1が拠点1、通信装置10-2が拠点2に存在する場合を示している。また、図1に示す通信システム1では、通信装置10-1が利用可能な鍵共有方式にそれぞれ対応する鍵共有システム20A-1、鍵共有システム20B-1、鍵共有システム20C-1も示されている。同様に、通信装置10-2が利用可能な鍵共有方式にそれぞれ対応する鍵共有システム20A-2、鍵共有システム20B-2、鍵共有システム20C-2も示されている。
 ここで、鍵共有システム20A-1と鍵共有システム20A-2は、KMEとSAEが別の装置上に存在する或る鍵共有方式(例えば、QKD)により互いに共有鍵を生成可能であるものとする。一方で、鍵共有システム20B-1と鍵共有システム20B-2は、KMEとSAEが同一装置上に存在する或る鍵共有方式(例えば、PQKD)により互いに共有鍵を生成可能であるものとする。同様に、鍵共有システム20C-1と鍵共有システム20C-2も、KMEとSAEが同一装置上に存在する或る鍵共有方式により互いに共有鍵を生成可能であるものとする。このため、図1に示す例では、鍵共有システム20A-1は通信装置10-1とは別体で存在する一方、鍵共有システム20B-1及び鍵共有システム20C-1は通信装置10-1に含まれている。鍵共有システム20A-2~鍵共有システム20C-2についても同様である。なお、通信装置10-1と鍵共有システム20A-1は、例えば、拠点内ネットワーク等により通信可能に接続される。同様に、通信装置10-2と鍵共有システム20A-2は、例えば、拠点内ネットワーク等により通信可能に接続される。
 以下、鍵共有システム20A-1~鍵共有システム20C-1を区別しないときは「鍵共有システム20-1」と表記する。同様に、鍵共有システム20A-2~鍵共有システム20C-2を区別しないときは「鍵共有システム20-2」と表記する。
 通信装置10-1は、互いに同一の鍵共有方式を利用する鍵共有システム20-1と鍵共有システム20-2の間で共有された鍵(共有鍵)を用いて通信装置10-2と暗号化通信を行う。ここで、通信装置10-1には、アプリケーションプログラム(以下、APという。)110-1と、プロトコル変換部120-1と、各鍵共有システム20-1にそれぞれ対応する鍵出力部130-1とが含まれる。なお、図1に示す例では、鍵共有システム20A-1に対応する鍵出力部130-1は鍵出力部130A-1である。同様に、鍵共有システム20B-1に対応する鍵出力部130-1は鍵出力部130B-1であり、鍵共有システム20C-1に対応する鍵出力部130-1は鍵出力部130C-1である。
 同様に、通信装置10-2は、互いに同一の鍵共有方式を利用する鍵共有システム20-2と鍵共有システム20-1の間で共有された鍵(共有鍵)を用いて通信装置10-1と暗号化通信を行う。ここで、通信装置10-2には、AP110-2と、プロトコル変換部120-2と、各鍵共有システム20-2にそれぞれ対応する鍵出力部130-2とが含まれる。なお、図1に示す例では、鍵共有システム20A-2~鍵共有システム20C-2にそれぞれ対応する鍵出力部130-2は鍵出力部130A-2~鍵出力部130C-2である。
 以下、通信装置10-1と通信装置10-2とを区別しないときは「通信装置10」と表記し、鍵共有システム20-1と鍵共有システム20-2とを区別しないときは「鍵共有システム20」と表記する。その他についても同様に、「AP110」、「プロトコル変換部120」、「鍵出力部130」等と表記する。
 また、鍵共有システム20A-1と鍵共有システム20A-2を区別しないときは「鍵共有システム20A」と表記する。その他についても同様に、「鍵共有システム20B」、「鍵共有システム20C」等と表記する。
 AP110は、共有鍵を利用して他の通信装置10のAP110との間で暗号化通信を行うアプリケーションプログラムである。
 プロトコル変換部120は、AP110からの鍵要求(を表すメッセージ)を受け付けたり、AP110に対して鍵通知(を表すメッセージ)を送信したりする。また、プロトコル変換部120は、鍵共有システム20でエラー等が発生した場合に他の鍵共有システム20に切り替える。なお、プロトコル変換部120の詳細な機能構成例については後述する。
 鍵出力部130は、その鍵出力部130に対応する鍵共有システム20が実行する鍵共有方式の具体的な仕組みを隠蔽する機能を有し、鍵要求を受信すると、自身に対応する鍵共有システム20で生成された共有鍵を返信する。すなわち、鍵出力部130は、プロトコル変換部120から鍵要求を受信すると、自身に対応する鍵共有システム20で生成された共有鍵が含まれる鍵出力を当該プロトコル変換部120に返信する。なお、鍵出力部130はプロトコルドライバ等と呼ばれてもよい。
 これにより、AP110に対して鍵共有方式の具体的な仕組みが隠蔽され、AP110は単にプロトコル変換部120に対して鍵要求を行うだけで、その鍵要求に対する鍵通知により共有鍵を得ることができる。
 また、鍵出力部130は、その鍵出力部130に対応する鍵共有システム20でエラー等が発生した場合、当該鍵共有システム20からエラー通知を受信すると共に、そのエラー通知をプロトコル変換部120に送信する。
 ここで、プロトコル変換部120の詳細な機能構成例を図2に示す。図2に示すように、プロトコル変換部120には、鍵要求受付部121と、鍵通知部122と、エラー通知部123と、切替部124と、鍵蓄積部125とが含まれる。
 鍵要求受付部121は、AP110からの鍵要求を受信すると共に、現在利用中の鍵共有方式(の鍵共有システム20)に対応する鍵出力部130に対して当該鍵要求を送信する。
 また、鍵要求受付部121は、切替部124からの切替通知を受信すると共に、その切替通知に含まれる鍵共有方式を現在利用中の鍵共有方式として設定する。更に、鍵要求受付部121は、その切替通知を他の通信装置10に送信する。
 鍵通知部122は、鍵出力部130から鍵出力を受信すると共に、当該鍵出力に含まれる共有鍵を取り出した上でその共有鍵が含まれる鍵通知をAP110に送信する。
 エラー通知部123は、鍵出力部130からエラー通知を受信すると共に、そのエラー通知を切替部124に送信する。
 切替部124は、鍵出力部130からのエラー通知を受信すると共に、切替先の鍵共有方式を決定した上で、その決定後の鍵共有方式を示す情報が含まれる切替通知を鍵要求受付部121に送信する。
 鍵蓄積部125は、鍵の蓄積が可能な鍵共有方式を利用中である場合、その鍵共有方式により生成された共有鍵を記憶装置に蓄積する。以下、記憶装置に蓄積されている鍵(共有鍵)を蓄積鍵ともいう。なお、鍵蓄積部125は必須の構成要素ではなく、プロトコル変換部120には鍵蓄積部125が含まれていなくてもよい。
 なお、図1に示す通信システム1の全体構成は一例であって、これに限られるものではない。例えば、図1に示す例では、通信装置10が3つの鍵共有方式を利用可能であることを想定し、それらの鍵共有方式にそれぞれ対応する鍵共有システム20A~鍵共有システム20Cが図示されているが、一般に、鍵共有システム20は通信装置10が利用可能な鍵共有方式の数だけ存在する。具体的には、例えば、通信装置10がN個の鍵共有方式を利用可能である場合、それらN個の鍵共有方式にそれぞれ対応するN個の鍵共有システム20が存在する。
 また、通信装置10間の通信ネットワークと鍵共有システム20間の通信ネットワークとが同一のものであってもよいし、鍵共有システム20が実行する鍵共有方式によっては異なるものであってもよい。例えば、鍵共有システム20Aが実行する鍵共有方式がQKDである場合、通信装置10(のAP110)間の通信ネットワークはインターネット等であり、鍵共有システム20A間の通信ネットワークは光通信ネットワーク等である。一方で、例えば、鍵共有システム20Bが実行する鍵共有方式がPQKD等である場合、通信装置10(のAP110)間の通信ネットワークと鍵共有システム20B間の通信ネットワークはいずれもインターネット等である。
 <鍵共有処理>
 以下、一例として、AP110-1がAP110-2との間で暗号化通信を行うことを想定し、AP110-1及びAP110-2が共有鍵を取得するための鍵取得処理について、図3を参照しながら説明する。なお、AP110-1がイニシエータ、AP110-2がレスポンダに相当する。
 まず、AP110-1は、鍵要求をプロトコル変換部120-1に送信する(ステップS101)。
 プロトコル変換部120-1の鍵要求受付部121-1は、鍵要求を受信すると、現在利用中の鍵共有方式として設定されている鍵共有方式に対応する鍵出力部130に対して当該鍵要求を送信する(ステップS102)。例えば、現在利用中の鍵共有方式としてQKDが設定されている場合、鍵要求受付部121-1は、QKDにより鍵共有を行う鍵共有システム20A-1に対応する鍵出力部130A-1に対して当該鍵要求を送信する。一方で、例えば、現在利用中の鍵共有方式としてPQKDが設定されている場合、鍵要求受付部121-1は、PQKDにより鍵共有を行う鍵共有システム20B-1に対応する鍵出力部130B-1に対して当該鍵要求を送信する。
 鍵出力部130-1は、鍵要求受付部121-1からの鍵要求を受信すると、自身に対応する鍵共有システム20-1に対して当該鍵要求を送信する(ステップS103)。例えば、鍵出力部130A-1が鍵要求を受信した場合、この鍵出力部130A-1は、鍵共有システム20A-1に対して当該鍵要求を送信する。一方で、例えば、鍵出力部130B-1が鍵要求を受信した場合、この鍵出力部130B-1は、鍵共有システム20B-1に対して当該鍵要求を送信する。
 鍵共有システム20-1は、鍵出力部130-1からの鍵要求を受信すると、自身と同一の鍵共有方式を実行する鍵共有システム20-2との間で当該鍵共有方式を実行し、共有鍵を生成する(ステップS104)。例えば、QKDを実行する鍵共有システム20A-1が鍵要求を受信した場合、この鍵共有システム20A-1は、鍵共有システム20A-2との間でQKDを実行し、共有鍵を生成する。一方で、例えば、PQKDを実行する鍵共有システム20B-1が鍵要求を受信した場合、この鍵共有システム20B-1は、鍵共有システム20B-2との間でPQKDを実行し、共有鍵を生成する。
 鍵共有システム20-1は、自身に対応する鍵出力部130-1に対して、上記のステップS104で生成した鍵(共有鍵)を送信する(ステップS105)。
 鍵出力部130-1は、鍵共有システム20-1からの共有鍵を受信すると、この共有鍵が含まれる鍵出力をプロトコル変換部120-1に送信する(ステップS106)。
 プロトコル変換部120-1の鍵通知部122-1は、鍵出力部130-1からの鍵出力を受信すると、当該鍵出力に含まれる共有鍵を取り出した上でその共有鍵が含まれる鍵通知をAP110-1に送信する(ステップS107)。
 AP110-1は、プロトコル変換部120-1からの鍵通知を受信すると、この鍵通知から共有鍵を取得する(ステップS108)。
 一方で、鍵共有システム20-2は、自身に対応する鍵出力部130-2に対して、上記のステップS104で生成した鍵(共有鍵)を送信する(ステップS109)。
 鍵出力部130-2は、鍵共有システム20-2からの共有鍵を受信すると、この共有鍵が含まれる鍵出力をプロトコル変換部120-2に送信する(ステップS110)。
 プロトコル変換部120-2の鍵通知部122-2は、鍵出力部130-2からの鍵出力を受信すると、当該鍵出力に含まれる共有鍵を取り出した上でその共有鍵が含まれる鍵通知をAP110-2に送信する(ステップS111)。
 AP110-2は、プロトコル変換部120-2からの鍵通知を受信すると、この鍵通知から共有鍵を取得する(ステップS112)。
 以上により、AP110-1とAP110-2との間で同一の鍵(共有鍵)が共有されるため、この共有鍵を暗号化鍵として暗号化通信を行うことができる。
 なお、図3に示す例では共有鍵を新たに生成する場合について説明したが、例えば、鍵蓄積部125が共有鍵を蓄積している場合には、AP110は、蓄積鍵を共有鍵として取得してもよい(特に、エラーの発生等といった何等かの理由により新たに共有鍵を生成できない場合に、鍵蓄積鍵を共有鍵として取得してもよい。)。この場合、上記のステップS101で鍵要求を受信した鍵要求受付部121は、その鍵要求を鍵蓄積部125-1に送信する。これにより、鍵蓄積部125によって蓄積されている共有鍵が鍵通知部122-1に渡され、その共有鍵がAP110-1に通知される。また、この場合、鍵通知部122-1は、その共有鍵の鍵IDをプロトコル変換部120-2に通知する。これにより、プロトコル変換部120-2でも同様に蓄積鍵の中から当該鍵IDの共有鍵が鍵通知部122-2に渡され、その共有鍵がAP110-2に通知される。
 <切替処理>
 以下、一例として、現在利用中の或る鍵共有方式に対応する鍵共有システム20-1で何等かのエラーが発生し、他の鍵共有方式に切り替える場合の切替処理について、図4を参照しながら説明する。
 鍵共有システム20-1は、エラーの発生を検知する(ステップS201)。ここで、鍵共有システム20-1に発生するエラーとしては様々なものが考えられ、本実施形態は任意のエラーを対象とすることができるが、例えば、以下のようなエラーを対象とすることができる。なお、エラーは、例えば、障害や異常等と呼ばれるものであってもよい。
 (1)鍵要求時エラー(例えば、鍵共有システム20-2との間で鍵共有を行う際の通信エラー、鍵共有の際の鍵共有システム20-1の内部エラー等)
 (2)鍵枯渇(鍵蓄積部125によって蓄積されている鍵の枯渇も含む。)
 (3)計算能力枯渇
 (4)システムエラー
 (5)タンパー異常
 なお、例えば、光ファイバーケーブルへのタッピングにより鍵共有ができなくなる事象はタンパー異常として検知され得る。
 鍵共有システム20-1は、自身に対応する鍵出力部130-1に対して、上記のステップS201で検知したエラーに関するエラー通知を送信する(ステップS202)。
 鍵出力部130-1は、鍵共有システム20-1からのエラー通知を受信すると、このエラー通知をプロトコル変換部120-1に送信する(ステップS203)。
 プロトコル変換部120-1のエラー通知部123-1は、鍵出力部130-1からのエラー通知を受信すると、このエラー通知を切替部124-1に送信する(ステップS204)。
 プロトコル変換部120-1の切替部124-1は、エラー通知部123-1からのエラー通知を受信すると、切替先の鍵共有方式を決定する(ステップS205)。ここで、切替部124は、様々な方法により切替先の鍵共有方式を決定することができるが、例えば、以下の方法により切替先の鍵共有方式を決定することが考えられる。
 (a)エラー通知に含まれるエラー内容又はエラー原因に応じて、切替先の鍵共有方式を決定する。これは、例えば、エラー内容又はエラー原因と切替先の鍵共有方式とを予め対応付けておき、その対応関係により切替先の鍵共有方式を決定する方法である。
 (b)現在利用中の鍵共有方式以外の鍵共有方式の中からランダムに又は所定の順番(所定の優先順)に従って1つの鍵共有方式を決定する。
 (c)エラー通知に含まれるエラー内容又はエラー原因をAP110又はユーザに通知し、AP110から指示又はユーザからの指示に従って鍵共有方式を決定する。この場合、AP110又はユーザがエラー内容又はエラー原因を確認することができるため、そのエラー内容又はエラー原因に応じて適切な鍵共有方式を決定することができる。
 なお、上記の決定方法はいずれも一例であって、これ以外にも様々な方法で鍵共有方式が決定されてもよい。また、これ以外にも、例えば、鍵蓄積部125が共有鍵を蓄積している場合には、共有鍵の取得先を蓄積鍵に切り替えると決定してもよい。これにより、蓄積鍵が枯渇するまでは蓄積鍵を共有鍵として利用し、蓄積鍵が枯渇した後に鍵共有方式を切り替えることができる。以下では、切替先の鍵共有方式が決定されたものとして説明する。
 プロトコル変換部120-1の切替部124-1は、上記のステップS205で決定した鍵共有方式(切替先の鍵共有方式)を示す情報が含まれる切替通知を鍵要求受付部121-1に送信する(ステップS206)。
 プロトコル変換部120-1の鍵要求受付部121-1は、切替部124-1からの切替通知を受信すると、この切替通知に含まれる情報が示す鍵共有方式を現在利用中の鍵共有方式として設定する(ステップS207)。
 また、プロトコル変換部120-1の切替部124-1は、上記のステップS205で決定した鍵共有方式(切替先の鍵共有方式)を示す情報が含まれる切替通知をプロトコル変換部120-2に送信する(ステップS208)。
 プロトコル変換部120-2の切替部124-2は、プロトコル変換部120-2からの切替通知を受信すると、この切替通知を鍵要求受付部121-2に送信する(ステップS209)。
 プロトコル変換部120-2の鍵要求受付部121-2は、切替部124-2からの切替通知を受信すると、この切替通知に含まれる情報が示す鍵共有方式を現在利用中の鍵共有方式として設定する(ステップS210)。
 以上により、或る鍵共有システム20でエラー等が発生し、その鍵共有システム20で共有鍵が生成できなくなった場合に、他の鍵共有システム20で共有鍵を生成するように切り替えることができる。また、蓄積鍵が存在する場合には、蓄積鍵を共有鍵として利用するように切り替えることもできる。このため、鍵共有システム20が利用できなくなった場合であっても、暗号化通信が必要なAP110によって提供されるサービスを継続することが可能となる。
 <変形例>
 本実施形態に係る通信システム1の全体構成の変形例を図5に示す。図1では、サーバ30-1が拠点1に更に含まれると共に、サーバ30-2が拠点2に更に含まれる通信システム1を示している。以下、サーバ30-1とサーバ30-2とを区別しないときは「サーバ30」と表記する。
 サーバ30には、プロトコル変換部120と、鍵出力部130とが含まれる。また、サーバ30は、自身が有する鍵出力部130に対応する鍵共有システム20を備えたり、自身が有する鍵出力部130に対応する鍵共有システム20と通信可能に接続されたりしている。
 図5に示す例では、サーバ30-1には、プロトコル変換部120-11と、鍵出力部130D-1と、鍵出力部130E-1とが含まれている。また、鍵出力部130D-1に対応する鍵共有システム20D-1と、鍵出力部130E-1に対応する鍵共有システム20E-1とが存在している。
 同様に、サーバ30-2には、プロトコル変換部120-21と、鍵出力部130D-2と、鍵出力部130E-2とが含まれている。また、鍵出力部130D-2に対応する鍵共有システム20D-2と、鍵出力部130E-2に対応する鍵共有システム20E-2とが存在している。
 変形例に係る通信システム1は、図5に示すような構成を有することにより、サーバ30は通信装置10に対して共有鍵を提供することができる。すなわち、例えば、サーバ30-1は、鍵共有システム20D-1又は鍵共有システム20E-1で生成された共有鍵を通信装置10-1のAP110-1に提供することができる。同様に、例えば、サーバ30-2は、鍵共有システム20D-2又は鍵共有システム20E-2で生成された共有鍵を通信装置10-2のAP110-2に提供することができる。
 このとき、どの鍵共有システム20で共有鍵を生成するか(つまり、どの鍵共有方式で共有鍵を生成するか)は、すべての通信装置10及びサーバ30間で共有及び連携される。すなわち、例えば、或る鍵共有システム20でエラー等が発生し、鍵共有方式の切り替えが発生した場合(又は、蓄積鍵を共有鍵として利用することへの切り替えであってもよい。)、その切替先を決定した切替部124は、他のすべての通信装置10及びサーバ30が備えるプロトコル変換部120に対しても切替通知を送信する。これにより、通信システム1全体で利用される鍵共有方式が共有及び連携される。
 なお、本変形例では、切替部124が切替先の鍵共有方式を決定する際に、通信装置10側の鍵共有システム20とサーバ30側の鍵共有システム20とのいずれを優先するかを考慮することができる。すなわち、例えば、上記の(b)により切替先の鍵共有方式を決定する際の優先順位として、通信装置10側の鍵共有システム20(が実行する鍵共有方式)とサーバ30側の鍵共有システム20(が実行する鍵共有方式)とのいずれを優先するかを設定することができる。これにより、例えば、サーバ30側の鍵共有システム20で優先的に共有鍵を生成し、サーバ30側の鍵共有システム20で共有鍵を生成することができなくなった場合に、通信装置10側の鍵共有システム20で共有鍵を生成する、といった運用が可能となる。
 また、本変形例では、切替部124が切替先の鍵共有方式を決定する際に、サービスの品質レベルやエラーの発生内容、発生原因、発生箇所等に応じて、通信装置10側又はサーバ30側のいずれの鍵共有システム20(が実行する鍵共有方式)に切り替えるかを考慮することができる。これにより、例えば、サーバ30側の鍵共有システム20でエラーが発生した場合は通信装置10側の鍵共有システム20に切り替え、逆に、通信装置10側の鍵共有システム20でエラーが発生した場合はサーバ30側の鍵共有システム20に切り替える、といった運用が可能となる。
 <ハードウェア構成例>
 本実施形態に係る通信システム1に含まれる通信装置10、鍵共有システム20、及びサーバ30は、例えば、図6に示すコンピュータ500のハードウェア構成により実現することができる。図6に示すコンピュータ500は、入力装置501と、表示装置502と、外部I/F503と、通信I/F504と、プロセッサ505と、メモリ装置506とを有する。これらの各ハードウェアは、それぞれがバス507を介して通信可能に接続される。
 入力装置501は、例えば、キーボード、マウス、タッチパネル、各種物理ボタン等である。表示装置502は、例えば、ディスプレイ、表示パネル等である。なお、コンピュータ500は、例えば、入力装置501及び表示装置502のうちの少なくとも一方を有していなくてもよい。
 外部I/F503は、記録媒体503a等の外部装置とのインタフェースである。記録媒体503aとしては、例えば、CD-ROM、DVD-ROM、SDメモリカード、USBメモリカード等が挙げられる。
 通信I/F504は、コンピュータ500を通信ネットワークに接続するためのインタフェースである。プロセッサ505は、例えば、CPU(Central Processing Unit)等の各種演算装置である。メモリ装置506は、例えば、HDD(Hard Disk Drive)、SSD(Solid State Drive)、RAM(Random Access Memory)、ROM(Read Only Memory)、フラッシュメモリ等の各種記憶装置である。
 ただし、図6に示すコンピュータ500のハードウェア構成は一例であって、これに限られるものではない。例えば、コンピュータ500は、複数のプロセッサ505や複数のメモリ装置506を有していてもよいし、図示したハードウェア以外の種々のハードウェアを有していてもよい。
 なお、図1に示したAP110、プロトコル変換部120及び鍵出力部130を実現する1以上のプログラムはメモリ装置506に格納され、それら1以上のプログラムによってプロセッサ505が種々の処理を実行することで種々の機能が実現される。
 <まとめ>
 以上のように、本実施形態に係る通信システム1では、何等かの理由で或る鍵共有方式が利用できなくなった場合、他の鍵共有方式に切り替えることができる。このため、暗号化通信を利用するアプリケーションプログラムによって提供されるサービスの可用性を高めることが可能となり、サービス品質の向上が実現できる。
 本発明は、具体的に開示された上記の実施形態に限定されるものではなく、請求の範囲の記載から逸脱することなく、種々の変形や変更、既知の技術との組み合わせ等が可能である。
 1    通信システム
 10   通信装置
 20   鍵共有システム
 30   サーバ
 110  AP
 120  プロトコル変換部
 121  鍵要求受付部
 122  鍵通知部
 123  エラー通知部
 124  切替部
 125  鍵蓄積部
 130  鍵出力部
 500  コンピュータ
 501  入力装置
 502  表示装置
 503  外部I/F
 503a 記録媒体
 504  通信I/F
 505  プロセッサ
 506  メモリ装置
 507  バス

Claims (8)

  1.  複数の通信装置が含まれる通信システムであって、
     前記通信装置は、
     他の通信装置との間で暗号化通信を行うように構成されているアプリケーションプログラムと、
     前記暗号化通信に用いられる共有鍵を生成する鍵共有方式を切り替えるように構成されている切替部と、を有し、
     前記切替部は、
     現在利用中の鍵共有方式によって前記共有鍵を生成できない場合、他の鍵共有方式に切り替えるように構成されている、通信システム。
  2.  前記切替部は、
     現在利用中の鍵共有方式によって前記共有鍵を生成する鍵共有システムにエラーが発生した場合、前記他の鍵共有方式に切り替えるように構成されている、請求項1に記載の通信システム。
  3.  前記エラーには、
     前記共有鍵を生成するときの通信エラー若しくは内部エラー、前記共有鍵の鍵枯渇、前記鍵共有システムの計算能力枯渇、前記鍵共有システムのシステムエラー、及び前記鍵共有システムの通信路に関するタンパー異常の少なくとも1つが含まれる、請求項2に記載の通信システム。
  4.  前記切替部は、
     前記エラーの内容、前記エラーの原因、及び前記エラーの発生箇所の少なくとも1つに応じて、複数の鍵共有方式の中から切替先となる前記他の鍵共有方式又は鍵蓄積機能を決定し、決定した前記他の鍵共有方式又は鍵蓄積機能に切り替えるように構成されている、請求項2又は3に記載の通信システム。
  5.  前記複数の鍵共有方式には、量子鍵配送と耐量子計算機鍵交換とが少なくとも含まれる、請求項4に記載の通信システム。
  6.  他の通信装置との間で暗号化通信を行うように構成されているアプリケーションプログラムと、
     前記暗号化通信に用いられる共有鍵を生成する鍵共有方式を切り替えるように構成されている切替部と、を有し、
     前記切替部は、
     現在利用中の鍵共有方式によって前記共有鍵を生成できない場合、他の鍵共有方式に切り替えるように構成されている、通信装置。
  7.  通信装置に用いられる方法であって、
     アプリケーションプログラムが、他の通信装置との間で暗号化通信を行うステップと、
     切替部が、前記暗号化通信に用いられる共有鍵を生成する鍵共有方式を切り替えるステップと、を実行し、
     前記切替部は、現在利用中の鍵共有方式によって前記共有鍵を生成できない場合、他の鍵共有方式に切り替えるステップを実行する、方法。
  8.  コンピュータを、請求項1に記載の通信システムに含まれる通信装置として機能させるプログラム。
PCT/JP2022/023867 2022-06-14 2022-06-14 通信システム、通信装置、方法、及びプログラム Ceased WO2023242972A1 (ja)

Priority Applications (4)

Application Number Priority Date Filing Date Title
PCT/JP2022/023867 WO2023242972A1 (ja) 2022-06-14 2022-06-14 通信システム、通信装置、方法、及びプログラム
KR1020247042845A KR20250013236A (ko) 2022-06-14 2022-06-14 통신 시스템, 통신 장치, 방법, 및 프로그램
EP22946792.3A EP4542923A4 (en) 2022-06-14 2022-06-14 COMMUNICATION SYSTEM, DEVICE, METHOD AND PROGRAM
JP2024527972A JP7835288B2 (ja) 2022-06-14 2022-06-14 通信システム、通信装置、方法、及びプログラム

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2022/023867 WO2023242972A1 (ja) 2022-06-14 2022-06-14 通信システム、通信装置、方法、及びプログラム

Publications (1)

Publication Number Publication Date
WO2023242972A1 true WO2023242972A1 (ja) 2023-12-21

Family

ID=89192658

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2022/023867 Ceased WO2023242972A1 (ja) 2022-06-14 2022-06-14 通信システム、通信装置、方法、及びプログラム

Country Status (4)

Country Link
EP (1) EP4542923A4 (ja)
JP (1) JP7835288B2 (ja)
KR (1) KR20250013236A (ja)
WO (1) WO2023242972A1 (ja)

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2018037888A (ja) * 2016-08-31 2018-03-08 株式会社東芝 通信装置、通信方法および通信システム
JP2018207348A (ja) * 2017-06-06 2018-12-27 株式会社東芝 通信装置、通信システム、鍵共有方法及びプログラム

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR102595369B1 (ko) * 2019-09-16 2023-10-30 주식회사 케이티 양자 암호키 분배 방법, 장치 및 시스템

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2018037888A (ja) * 2016-08-31 2018-03-08 株式会社東芝 通信装置、通信方法および通信システム
JP2018207348A (ja) * 2017-06-06 2018-12-27 株式会社東芝 通信装置、通信システム、鍵共有方法及びプログラム

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP4542923A4 *

Also Published As

Publication number Publication date
KR20250013236A (ko) 2025-01-31
EP4542923A4 (en) 2026-04-22
JP7835288B2 (ja) 2026-03-25
JPWO2023242972A1 (ja) 2023-12-21
EP4542923A1 (en) 2025-04-23

Similar Documents

Publication Publication Date Title
JP6856772B2 (ja) 信頼できる実行環境において実行されるスマートコントラクト動作に基づくブロックチェーンデータの処理
EP3417569B1 (en) System and method for quantum key distribution
JP2024010123A (ja) ブロックチェーンコンセンサス方法、装置及びシステム
JP6951649B2 (ja) ブロック検証装置、ブロック検証方法、及びプログラム
MX2008013324A (es) Solicitud y respuesta de contacto par a par.
US20250016522A1 (en) Geofence tracking with device location privacy
US20210297397A1 (en) Computer-implemented system and methods for off-chain exchange of transactions pertaining to a distributed ledger
US12081675B2 (en) Content use system, permission terminal, browsing terminal, distribution terminal, and content use program
JP2012504287A (ja) データ転送記憶における測定
US7398388B2 (en) Increasing peer privacy
JP2012504284A (ja) データ転送記憶における分解/再構築
JP2014038637A (ja) クラスタデータ処理のための方法及び装置
US10630589B2 (en) Resource management system
US7600253B1 (en) Entity correlation service
Naghizadeh et al. Structural‐based tunneling: preserving mutual anonymity for circular P2P networks
US12032713B1 (en) Systems and methods for sending and receiving encrypted submessages
CN106571968A (zh) 一种业务切换方法和系统
US20230004356A1 (en) Secure random number generation system, secure computation apparatus, secure random number generation method, and program
JP7835288B2 (ja) 通信システム、通信装置、方法、及びプログラム
WO2024185146A1 (ja) 鍵提供システム、方法、及びプログラム
WO2024095451A1 (ja) 通信システム、通信装置、方法、及びプログラム
CN112529402A (zh) 任务委派方法、系统、装置、设备和存储介质
JP2020038506A (ja) 情報処理システム、情報処理方法、及び、プログラム
CN118074901A (zh) 基于代理重加密的数据查询方法、装置、存储介质及设备
US20140280787A1 (en) Auditable distribution of a data file

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22946792

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2024527972

Country of ref document: JP

ENP Entry into the national phase

Ref document number: 20247042845

Country of ref document: KR

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 1020247042845

Country of ref document: KR

WWE Wipo information: entry into national phase

Ref document number: 2022946792

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2022946792

Country of ref document: EP

Effective date: 20250114

WWP Wipo information: published in national office

Ref document number: 2022946792

Country of ref document: EP