Key exchange system, hub apparatus, QKD apparatus, method, and program
A key exchange system according to an aspect of the present disclosure includes: a plurality of quantum key distribution (QKD) apparatuses that executes a quantum key distribution protocol including at least error correction; and a plurality of hub apparatuses that performs encrypted communication with each other, in which each of the hub apparatuses includes a key generation unit configured to generate an encryption key for performing the encrypted communication with another hub apparatus based on information received from a corresponding one of the QKD apparatuses, and each of the QKD apparatuses includes a QKD processing unit configured to execute the quantum key distribution protocol with another QKD apparatus and generate a correction key from a ciphertext of random number information, and a first transmission unit configured to transmit information representing a result of basis reconciliation in the quantum key distribution protocol to a corresponding one of the hub apparatuses.
1 . A key exchange system comprising:
a plurality of quantum key distribution (QKD) apparatuses that executes a quantum key distribution protocol including at least error correction; and
a plurality of hub apparatuses that performs encrypted communication with each other, wherein
each of the hub apparatuses includes
a first processor, and
a first memory storing first program instructions that cause the first processor to
generate an encryption key for performing the encrypted communication with another hub apparatus based on information received from a corresponding one of the QKD apparatuses, and
each of the QKD apparatuses includes
a second processor, and
a second memory storing second program instructions that cause the second processor to
execute the quantum key distribution protocol with another QKD apparatus and generate a correction key from a ciphertext of random number information, and
transmit information representing a result of basis reconciliation in the quantum key distribution protocol to a corresponding one of the hub apparatuses,
wherein for a hub apparatus configured as a hub on a data transmission side among the plurality of hub apparatuses, the first program instructions further cause the first processor to:
share a secret key with a hub apparatus existing in a hub on a data reception side;
generate the random number information that is a random bit string having a predetermined length;
generate the ciphertext by encrypting the random number information by using the secret key; and
transmit the ciphertext to a QKD apparatus existing in the hub on the data transmission side; and
wherein the first processor of the hub apparatus existing in the hub on the data transmission side generates the encryption key based on the result of the basis reconciliation and the random number information.
2 . The key exchange system according to claim 1 , wherein
in the QKD apparatus existing in the hub on the data reception side among the plurality of QKD apparatuses, the second program instructions cause the second processor to transmit the information representing the result of the basis reconciliation and the correction key to the hub apparatus existing in the hub on the data reception side, and
in the hub apparatus existing in the hub on the data reception side, the first program instructions cause the first processor to generate the encryption key based on the result of the basis reconciliation, the correction key, and the secret key.
3 . The key exchange system according to claim 1 , wherein
the secret key is a key of a stream encryption scheme, and
the first program instructions cause the first processor to share the secret key with the hub apparatus existing in the hub on the data reception side by using a key encapsulation mechanism based on post-quantum cryptography.
4 . A hub apparatus in a key exchange system, the key exchange system including: a plurality of QKD apparatuses that executes a quantum key distribution protocol including at least error correction; and a plurality of hub apparatuses that performs encrypted communication with each other, the hub apparatus comprising:
a processor; and
a memory storing program instructions that cause the processor, when the hub apparatus is configured as a hub on a data transmission side, to:
share a secret key with another hub apparatus existing in a hub on a data reception side;
generate random number information that is a random bit string having a predetermined length;
generate a ciphertext by encrypting the random number information using the secret key;
transmit the ciphertext to a QKD apparatus existing in the hub on the data transmission side; and
receive information representing a result of basis reconciliation in the quantum key distribution protocol from the QKD apparatus; and
generate an encryption key for performing the encrypted communication with said another hub apparatus based on the result of the basis reconciliation and the random number information.
5 . A non-transitory computer-readable recording medium storing a program for causing a computer to function as the hub apparatus of claim 4 .
6 . A quantum key distribution (QKD) apparatus in a key exchange system, the key exchange system including: a plurality of QKD apparatuses that executes a quantum key distribution protocol including at least error correction; and a plurality of hub apparatuses that performs encrypted communication with each other, the QKD apparatus comprising:
a processor; and
a memory storing program instructions that cause the processor to:
execute the quantum key distribution protocol with another QKD apparatus;
receive a ciphertext corresponding to random number information generated by a hub apparatus configured as a hub on a data transmission side;
generate a correction key based on the ciphertext; and
transmit information representing a result of basis reconciliation in the quantum key distribution protocol to a hub apparatus existing in a hub on a data transmission side,
wherein
the correction key corresponds to the ciphertext corresponding to the random number information, and
the result of basis reconciliation is transmitted to the hub apparatus configured as the hub on the data transmission side, the hub apparatus being configured to generate an encryption key based on the result of the basis reconciliation and the random number information.
7 . A non-transitory computer-readable recording medium storing a program for causing a computer to function as the QKD apparatus of claim 6 .