Cryptographic communication system, cryptographic communication device, cryptographic communication method, and cryptographic communication program
View Patent ↗According to one embodiment, a transmitting device includes an encryption key pre-fetching unit and an encryption chunk generation unit. The encryption key pre-fetching unit acquires the encryption key for encrypting plaintext data from a key management system before receiving the plaintext data. The encryption chunk generation unit generates a packet in which first encrypted data acquired by encrypting first plaintext data using a first encryption key and a first key ID of the first encryption key are stored, and a second key ID of a second encryption key used for encrypting second plaintext data transmitted after the first plaintext data, is embedded. A receiving device includes an encryption chunk analysis unit and a decryption key pre-fetching unit. The encryption chunk analysis unit analyzes the packet and reads the second key ID. The decryption key pre-fetching unit acquires the second encryption key corresponding to the second key ID read by the encryption chunk analysis unit from the key management system.
1 . A cryptographic communication system that uses a key management system, which has an interface giving notification of a key ID when providing an encryption key, and returning the encryption key corresponding to the key ID in response to a request for the encryption key for which the key ID is specified, and which shares the encryption key between a first site and a second site by quantum key distribution to execute cryptographic communication between a transmitting device that acquires the encryption key managed by the key management system from the first site and a receiving device that acquires the encryption key managed by the key management system from the second site,
wherein the transmitting device includes a processor programmed to:
use the encryption key acquired from the key management system to encrypt plaintext data,
acquire the encryption key for encrypting the plaintext data from the key management system before receiving the plaintext data,
store the acquired encryption key along with the key ID in an encryption key memory, and
generate a packet in which first encrypted data and a first key ID of the first encryption key are stored, and a second key ID of a second encryption key stored in the encryption key memory, which is used for encrypting second plaintext data transmitted after the first plaintext data, is embedded, and
the receiving device includes a processor programmed to:
use the encryption key acquired from the key management system to decrypt encrypted data,
analyze the packet to read the second key ID,
acquire the second encryption key corresponding to the second key ID from the key management system, and
store the acquired encryption key along with the key ID in a decryption key memory.
2 . The cryptographic communication system according to claim 1 , wherein the processor of the transmitting device is further programmed to:
when generating the packet, embed multiple key IDs of the encryption key in the packet, which are used for encrypting plaintext data transmitted after the plaintext data transmitted in the packet, and
partially duplicate the multiple key IDs embedded in the packet transmitted at a first timing and the multiple key IDs embedded in the packet transmitted at a second timing following the first timing, and
discard the key ID when the corresponding encryption key is stored in the decryption key memory-unit.
3 . The cryptographic communication system according to claim 2 , wherein the interface conforms to an ETSI GS QKD 014 specification.
4 . A cryptographic communication device that acquires an encryption key from a key management system, which has an interface giving notification of a key ID when providing the encryption key, and returning the encryption key corresponding to the key ID in response to a request for the encryption key for which the key ID is specified, and which shares the encryption key between two sites by quantum key distribution to encrypt plaintext data to be transmitted, and that transmits the encrypted data acquired by the encryption, the device comprising a processor programmed to:
use the encryption key acquired from the key management system to encrypt plaintext data;
acquire the encryption key for encrypting the plaintext data from the key management system before receiving the plaintext data;
store the encryption key along with the key ID in an encryption key memory; and
generate a packet in which first data generated using a first encryption key to encrypt first plaintext data and a first key ID of the first encryption key are stored, and a second key ID of a second encryption key stored in the encryption key memory, which is used for encrypting second plaintext data transmitted after the first plaintext data, is embedded.
5 . The cryptographic communication device according to claim 4 ,
wherein the processor is further programmed to:
embed multiple key IDs of the encryption key in the packet, which are used for encrypting plaintext data transmitted after the plaintext data transmitted in the packet, when generating the packet, and
partially duplicate the multiple key IDs embedded in the packet transmitted at a first timing and the multiple key IDs embedded in the packet transmitted at a second timing following the first timing.
6 . A cryptographic communication device that acquires an encryption key from a key management system, which has an interface giving notification of a key ID when providing an encryption key, and returns the encryption key corresponding to the key ID in response to a request for the encryption key for which the key ID is specified, and which shares the encryption key between two sites by quantum key distribution to decrypt received encrypted data, the device comprising a processor programmed to:
use the encryption key acquired from the key management system to decrypt encrypted data;
analyze a packet in which first encrypted data that can be decrypted using a first encryption key and a first key ID of the first encryption key are stored, and a second key ID of a second encryption key that can decrypt second encryption data transmitted after the first encryption data, is embedded, to read the second key ID;
acquire the second encryption key corresponding to the second key ID; and
store the acquired encryption key along with the key ID in a decryption key memory.
7 . The cryptographic communication device according to claim 6 ,
wherein processor is further programmed to discard the first key ID when the encryption key corresponding to the second key ID is stored in the decryption key memory.
8 . The cryptographic communication device according to claim 7 ,
wherein the interface conforms to an ETSI GS QKD 014 specification.
9 . A cryptographic communication method executed in a cryptographic communication system that uses a key management system, which has an interface giving notification of a key ID when providing an encryption key, and returning the encryption key corresponding to the key ID in response to a request for the encryption key for which the key ID is specified, and which shares the encryption key between a first site and a second site by quantum key distribution to execute cryptographic communication between a transmitting device that acquires the encryption key managed by the key management system from the first site and a receiving device that acquires the encryption key managed by the key management system from the second site,
wherein the transmitting device performs a method comprising:
using the encryption key acquired from the key management system to encrypt plaintext data,
acquiring the encryption key for encrypting the plaintext data from the key management system before receiving the plaintext data,
storing the acquired encryption key along with the key ID, and
generating a packet in which first encrypted data acquired by encrypting first plaintext data using a first encryption key and a first key ID of the first encryption key are stored, and a second key ID of second encryption key, which is used for encrypting second plaintext data transmitted after the first plaintext data, is embedded, and
the receiving device performs a method comprising:
using the encryption key acquired from the key management system to decrypt encrypted data,
analyzing the packet to read the second key ID,
acquiring the read second encryption key corresponding to the second key ID from the key management system, and
storing the acquired encryption key along with the key ID.
10 . A cryptographic communication program applied in a cryptographic communication system that uses a key management system, which has an interface giving notification of a key ID when providing an encryption key, and returning the encryption key corresponding to the key ID in response to a request for the encryption key for which the key ID is specified, and which shares the encryption key between a first site and a second site by quantum key distribution to execute cryptographic communication between a transmitting device that acquires the encryption key managed by the key management system from the first site and a receiving device that acquires the encryption key managed by the key management system from the second site,
the program causing the transmitting device to perform a method comprising:
use the encryption key acquired from the key management system to encrypt plaintext data,
acquire the encryption key for encrypting the plaintext data from the key management system before receiving the plaintext data,
store the acquired encryption key along with the key ID in an encryption key memory, and
generate a packet in which first encrypted data that uses a first encryption key to encrypt first plaintext data and a first key ID of the first encryption key are stored, and a second key ID of a second encryption key stored in the encryption key memory, which is used for encrypting second plaintext data transmitted after the first plaintext data, is embedded, and
the program causing the receiving device perform a method comprising:
use the encryption key acquired from the key management system to decrypt encrypted data,
analyze the packet to read the second key ID,
acquire the second encryption key corresponding to the second key ID from the key management system, and
store the acquired encryption key along with the key ID in a decryption key memory.