IP Library Granted Patent US 12665754
Granted Patent B2
US 12665754 · App. 18/457,598 · Granted Jun 23, 2026

Key management device, quantum cryptography communication system, key management method, and computer program product

Inventors: Keisuke Mera (Tokyo, JP); Koji Kanazawa (Tokyo, JP); Katsuyuki Kimura (Kamakura Kanagawa, JP); Yoshimichi Tanizawa (Yokohama Kanagawa, JP)
Assignee: Kabushiki Kaisha Toshiba
H04L9/0858H04L9/0819
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12665754
App. No.
18/457,598
Granted
Jun 23, 2026
Kind
B2
Abstract

According to one embodiment, a key management device includes an acquiring circuitry and a processor. The acquiring circuitry is configured to: acquire identity verification data of a remote QKD key generated by a remote QKD device, and remote QKD device identification information identifying the remote QKD device, from another key management device via a classical communication channel. The processor is configured to: collect a local QKD key generated by a local QKD device and local QKD device identification information identifying the local QKD device; generate identity verification data of the local QKD key; and map, when the identity verification data of the remote QKD key matches the identity verification data of the local QKD key, the remote QKD device identification information to the local QKD device identification information.

Claims (64)

1 . A key management device that is connected to at least one local quantum key distribution (QKD) device connected to at least one remote QKD device via a quantum communication channel, the device comprising:

an acquiring circuitry configured to acquire identity verification data indicative of a remote QKD key generated by the remote QKD device, and remote QKD device identification information identifying the remote QKD device, from another key management device via a classical communication channel; and

a processor configured to:

collect a local QKD key generated by the local QKD device, and local QKD device identification information identifying the local QKD device;

generate identity verification data indicative of the local QKD key; and

map, when the identity verification data indicative of the remote QKD key matches the identity verification data indicative of the local QKD key, the remote QKD device identification information to the local QKD device identification information.

2 . The device according to claim 1 , further comprising an output circuitry configured to output the identity verification data of the local QKD key and the local QKD device identification information to the other key management device.

3 . The device according to claim 1 , wherein the identity verification data of the local QKD key includes whole or a part of the generated local QKD key having a predetermined length, and the identity verification data of the remote QKD key includes whole or a part of the generated remote QKD key having a predetermined length.

4 . The device according to claim 1 , wherein the identity verification data of the local QKD key includes a hash value generated from whole or a part of the generated local QKD key having a predetermined length, and the identity verification data of the remote QKD key includes a hash value generated from whole or a part of the generated remote QKD key having a predetermined length.

5 . The device according to claim 1 , wherein the processor is configured to instruct the local QKD device to start generating the local QKD key, and, when generation of the local QKD key fails, instruct the other key management device to start generating the remote QKD key.

6 . The device according to claim 1 , wherein the processor is configured to encrypt or decrypt data using a newly generated local QKD key that is different from the local QKD key used in generating the identity verification data of the local QKD key.

7 . The device according to claim 1 , wherein the processor is configured to:

when detecting a new local QKD device connected to the quantum communication channel, instruct the new local QKD device to generate a new local QKD key;

collect the new local QKD key and local QKD device identification information identifying the new local QKD device;

generate identity verification data of the new local QKD key; and

map, when the identity verification data of the remote QKD key matches the identity verification data of the new local QKD key, the remote QKD device identification information to the local QKD device identification information identifying the new local QKD device.

8 . The device according to claim 1 , wherein the processor is configured to instruct the local QKD device to generate the local QKD key when an instruction for generating the local QKD key is received from the other key management device.

9 . A quantum cryptography communication system comprising:

the key management device according to claim 1 ;

the other key management device;

the at least one local QKD device; and

the at least one remote QKD device,

the local QKD device comprising:

a quantum communication unit configured to generate the local QKD key via the quantum communication channel; and

a classical communication unit configured to transmit the local QKD key and the local QKD device identification information via the classical communication channel, and the remote QKD device comprising:

a quantum communication unit configured to generate the remote QKD key via the quantum communication channel; and

a classical communication unit configured to transmit the remote QKD key and the remote QKD device identification information via the classical communication channel.

10 . A key management method for a key management device that is connected to at least one local quantum key distribution (QKD) device connected to at least one remote QKD device via a quantum communication channel, the method comprising:

causing an acquiring circuitry to acquire identity verification data indicative of a remote QKD key generated by the remote QKD device, and remote QKD device identification information identifying the remote QKD device, from another key management device via a classical communication channel; and

causing a processor to

collect a local QKD key generated by a local QKD device, and local QKD device identification information identifying the local QKD device;

generate identity verification data indicative of the local QKD key; and

map, when the identity verification data indicative of the remote QKD key matches the identity verification data indicative of the local QKD key, the remote QKD device identification information to the local QKD device identification information.

11 . A computer program product comprising a non-transitory computer-readable medium including programmed instructions, the instructions causing a computer, which is connected to at least one local quantum key distribution (QKD) device connected to at least one remote QKD device via a quantum communication channel, to execute:

causing an acquiring circuitry to acquire identity verification data indicative of a remote QKD key generated by the remote QKD device, and remote QKD device identification information identifying the remote QKD device, from another key management device via a classical communication channel; and

causing a processor to

collect a local QKD key generated by a local QKD device, and local QKD device identification information identifying the local QKD device;

generate identity verification data indicative of the local QKD key, and

map, when the identity verification data indicative of the remote QKD key matches the identity verification data indicative of the local QKD key, the remote QKD device identification information to the local QKD device identification information.

12 . A quantum cryptography communication system comprising:

the key management device according to claim 2 ;

the other key management device;

the at least one local QKD device; and

the at least one remote QKD device,

the local QKD device comprising:

a quantum communication unit configured to generate the local QKD key via the quantum communication channel; and

a classical communication unit configured to transmit the local QKD key and the local QKD device identification information via the classical communication channel, and the remote QKD device comprising:

a quantum communication unit configured to generate the remote QKD key via the quantum communication channel; and

a classical communication unit configured to transmit the remote QKD key and the remote QKD device identification information via the classical communication channel.

13 . The device according to claim 1 , wherein the processor is configured to:

when detecting a new local QKD device connected to the quantum communication channel, instruct the new local QKD device to generate a new local QKD key;

collect the new local QKD key and local QKD device identification information identifying the new local QKD device; and

generate identity verification data of the new local QKD key.

14 . The method according to claim 10 , further comprising:

when detecting a new local QKD device connected to the quantum communication channel,

causing the processor to:

instruct the new local QKD device to generate a new local QKD key;

collect the new local QKD key and local QKD device identification information identifying the new local QKD device; and

generate identity verification data of the new local QKD key.

15 . The computer program product according to claim 11 , wherein the instructions cause the computer to further execute:

causing the processor to:

instruct the new local QKD device to generate a new local QKD key;

collect the new local QKD key and local QKD device identification information identifying the new local QKD device; and

generate identity verification data of the new local QKD key.