Encryption communication system, encryption communication apparatus, and encryption communication method
According to one embodiment, in an encryption communication system, a first device and a second device that execute encryption communication via a first network share an encryption key used for the encryption communication via a second network including a plurality of nodes. The first device generates n pieces of first data used for generating the encryption key, transmits the n pieces of first data to the second device by distributing the n pieces of first data to n nodes among the nodes and sending the n pieces of first data to the second network, and generates the encryption key by using the n pieces of first data. The second device receives the n pieces of first data from n nodes among the nodes, and generates the encryption key by using the n pieces of first data.
1 . An encryption communication system comprising:
a first device and second device that execute encryption communication via a first network, the first device and the second device sharing an encryption key used for the encryption communication via a second network including a plurality of nodes, wherein
the first device is configured to
generate n pieces of first data used for generating the encryption key, the n pieces of first data being random numbers,
transmit the n pieces of first data to the second device by distributing the n pieces of first data to n nodes among the nodes and sending the n pieces of first data to the second network, and
obtain second data using the generated n pieces of first data by restoration processing by a secret distribution method, and generate the encryption key based on the second data, the generated n pieces of first data, which are random numbers, being regarded as distributed data,
the second device is configured to
receive the n pieces of first data from n nodes among the nodes, and
obtain the second data using the generated n pieces of first data by restoration processing by the secret distribution method, and generate the encryption key based on the obtained second data, the generated n pieces of first data, which are random numbers, being regarded as distributed data.
2 . The encryption communication system of claim 1 , wherein:
transmission and reception of the first data between the nodes are executed via a first communication device included in each of the nodes;
transmission and reception of the first data between the first device or the second device and a node coupled to the first device or the second device among the nodes are executed via a second communication device included in each of the first device, the second device, and the node coupled to the first device or the second device; and
the node coupled to the first device or the second device is configured to internally execute exchange of the first data between the first communication device and the second communication device.
3 . The encryption communication system of claim 1 , wherein the secret distribution method is a ramp-type secret distribution method.
4 . The encryption communication system of claim 1 , wherein the first device and the second device are configured to generate the encryption key by superimposing the n pieces of first data.
5 . The encryption communication system of claim 4 , wherein the superimposition of the n pieces of first data is to calculate an exclusive OR of the n pieces of first data.
6 . The encryption communication system of claim 1 , wherein:
the second network has a configuration in which the nodes are coupled by an optical fiber; and
each of the nodes are configured to transmit and receive data to and from an adjacent node over the second network by photons using the optical fiber as a medium.
7 . An encryption communication apparatus that executes encryption communication with another encryption communication apparatus via a first network, the encryption communication apparatus sharing an encryption key used for the encryption communication with the another encryption communication apparatus via a second network including a plurality of nodes, the apparatus comprising:
a first device configured to generate n pieces of first data used for generating the encryption key, the n pieces of first data being random numbers;
a second device configured to transmit the n pieces of first data to the another encryption communication apparatus by distributing the n pieces of first data to n nodes among the nodes and sending the n pieces of first data to the second network; and
a third device configured to obtain second data using the generated n pieces of first data by restoration processing by a secret distribution method, and generate the encryption key based on the second data, the generated n pieces of first data, which are random numbers, being regarded as distributed data.
8 . An encryption communication method in which a first device and a second device that execute encryption communication via a first network share an encryption key used for the encryption communication via a second network including a plurality of nodes, the method comprising:
by the first device,
generating n pieces of first data used for generating the encryption key, the n pieces of first data being random numbers,
transmitting the n pieces of first data to the second device by distributing the n pieces of first data to n nodes among the nodes and sending the n pieces of first data to the second network, and
obtaining second data using the generated n pieces of first data by restoration processing by a secret distribution method, and generating the encryption key based on the second data, the generated n pieces of first data, which are random numbers, being regarded as distributed data; and
by the second device,
receiving the n pieces of first data from the n nodes among the nodes, and
obtaining the second data using the generated n pieces of first data by restoration processing by the secret distribution method, and generating the encryption key based on the obtained second data, the generated n pieces of first data, which are random number, being regarded as distributed data.