Quantum distribution methods and associated telecommunications devices

EP4635126A1Pending Publication Date: 2025-10-22THALES SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023806308
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-12-15
Filing Date
2023-11-16
Publication Date
2025-10-22

AI Technical Summary

Technical Problem

Quantum key distribution protocols face challenges in maintaining secrecy and reducing information leakage on public channels, particularly due to the broadcast of parity bits and base choices, which can be exploited by eavesdroppers to deduce key values.

Method used

Implementing a method where information indicating parity bit values and base choices are encrypted using a previously generated secret key via the quantum key distribution mechanism, ensuring that only the communicating parties, Alice and Bob, share the encrypted information, thereby preventing eavesdroppers from accessing this sensitive data.

Benefits of technology

This approach significantly reduces information leakage and enhances secrecy by ensuring that eavesdroppers cannot determine the correct qubits or parity bits, effectively protecting the key from unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

The invention relates to a method for distributing a quantum key, denoted KQKD_N, to two telecommunications devices (D_ALICE, D_BOB), each connected to one quantum channel (30) and connected to each other by a conventional channel (40), comprising: - communicating a random sequence of bits, in the form of a sequence of light pulses, on the quantum channel; - communicating parity bits on the conventional channel; and correcting errors in the random sequence of bits on the basis of the communicated parity bits; - determining said key KQKD_N on the basis of said random sequence of bits, said key being shared between said devices; said method being characterized in that said communication of the parity bits is encrypted or decrypted on the basis of at least one key KQKD_N-k determined beforehand through the prior implementation of a mechanism of quantum key distribution QKD to said devices.
Need to check novelty before this filing date? Find Prior Art

Description

DESCRIPTION Title: Quantum distribution processes and associated telecommunications devices Technical field:

[0001] The invention lies in the field of generating and sharing a symmetric secret key between two remote telecommunications devices associated with their respective users, hereinafter referred to as Alice and Bob: Alice's and Bob's devices must use a strictly identical key to be able to encrypt / decrypt their messages. The invention relates more particularly to quantum key distribution (QKD: Quantum Key Distribution) and the underlying communication of information such as parity bits or choice of bases used or selection of the measures retained. Previous technique:

[0002] Quantum cryptography relies on the transmission of qubits (quantum bits) or randomly generated coherent states to develop and distribute secret keys that can be used by classical encryption protocols such as One Time Pad encryption. Since the first protocol proposed in 1984 (BB84), multiple QKD protocols have been defined. A distinction is made between discrete variable protocols (qubits, DV-QKD) and continuous variable protocols (CV-QKD). Some protocols (BB84, DV-QKD) rely on random choices of a basis (or quadrature) for generation and measurement, and involve the communication of these basis choices. Other protocols (CV-QKD with heterodyne receiver) do not involve communications on the choice of a measurement basis. Some protocols based on photon entanglement involve a photon source external to Alice and Bob's devices.But all QKD protocols integrate a residual error correction step to develop a shared key between Alice and Bob, implementing the communication of parity bits, for various error detection or correction techniques (FEC (Forward Error Correction code) codes such as LDPC (Low Density Parity Code), interactive and iterative protocols such as Cascade or Winnow, etc.). For illustration purposes, we will subsequently refer to the BB84 protocol.

[0003] During a quantum cryptography protocol, the two remote interlocutors Alice and Bob have: quantum objects, that is, physical objects that behave according to the laws of quantum physics; in practice, these objects are light pulses in the quantum regime (photons), which can take several forms: single photons, coherent states, pairs of entangled photons, etc.; the photon allows the encoding of information on observable variables such as the polarization of light, its frequency, its phase, etc.; a quantum channel, which allows the transit of light pulses; a classical channel (also called a public channel) of communication (typically the Internet, hertzian, optical transmission on fiber or in free space).

[0004] Quantum Key Distribution (QKD) is a technique that exploits quantum properties to guarantee randomness to detect the interception and re-transmission by a malicious third party, let's call it Eve (Eavesdropper), of an initial message generated by Alice to Bob. Since it is impossible to clone unknown quantum information without destroying it, or to measure an unknown quantum state without modifying it, the reading of qubits during their transmission between two interlocutors wishing to encrypt their communications with a secret key derived from these qubits by an intruder can be immediately detected: an interception will be immediately detected by Alice's and Bob's devices, which will give up this key.

[0005] A reference QKD technique is the BB84 protocol published by C. Bennett and G. Brassard in 1984 and using discrete variables: qubits. A qubit takes a value of 0 or 1, and is represented by the polarization of a single photon, on two possible quadratures (bases): HA / or D / A (the capital letter H, V, D, A indicates the type of polarization: H for horizontal, V for vertical, D for diagonal and A for Antidiagonal).

[0006] The main steps of quantum key distribution are as follows: Alice's device generates a sequence of random bits and encodes each bit on each light pulse, then transmits it to Bob's device through the quantum channel. This then measures the information carried by the pulse it received. Alice and Bob's devices evaluate a level of interception of the information exchanged on the quantum channel based on the differences between the data emitted and those measured and if the level is higher than a fixed threshold, the quantum distribution operation is terminated. If not, the extraction of the secret key from the correlated data is carried out via a so-called data reconciliation step: in this reconciliation step, a bit string shared by Alice's and Bob's devices is determined from the correlated data and an error correction algorithm implementing parity bits. A secrecy amplification step is usually implemented to neutralize information leakage during reconciliation.

[0007] For each qubit (0 / 1) in a series of qubits randomly generated by Alice's device, the latter generates on the quantum channel a photon whose polarization depends on the random choice of a quadrature (H / V or D / A) and the binary value considered (0 / 1).

[0008] At the other end of the quantum channel, on the receiving side, Bob's device randomly selects, for each qubit, a quadrature to perform the detection (either on H / V or on D / A). Any qubit measured on the same quadrature as the quadrature used for transmission is normally correctly transmitted: 100% to within E, (typically the value of E is in the range [0; 10%]. When the Tx / Rx quadratures are not identical, the transmission is false with a probability of 50% to within E.

[0009] After the transmission, Bob's device therefore has a set of measurements which are correlated with the data sent by Alice's device, but whose information could have been spied on by Eve.

[0010] Then takes place the so-called reconciliation phase using only the classical communication channel, where: a so-called sifting step selects the transmitted qubits for which the devices of Alice and Bob use the same generation and detection quadrature: to do this, the devices of Alice and Bob communicate in clear on the classical channel to broadcast the quadratures used, either symmetrically and explicitly, or asymmetrically with one party broadcasting its used quadratures then the other party determining and broadcasting the selection of the selected qubits (identical Tx / Rx quadratures); this makes it possible to develop two versions of a key called "sifted key" respectively on the side of Alice and Bob, by discarding on average 50% of the qubits (different Tx / Rx quadratures); an estimation of the error rate is carried out, to determine the possible presence of Eve (case of rejection of the key), and to select an error correcting code (choice of the code and performance) or to configure an interactive and iterative error correction protocol by request / response for the rest of the processing; a step of detection and correction of residual errors comprising exchanges on the classic channel of parity bits calculated by the devices of Alice and / or Bob on their respective "sifted key" then takes place (Cascade or Winnow protocol, FEC LDPC error correcting code, etc.), following which the devices of Alice and Bob share a strictly identical key, for which Eve has certain information.

[0011] Alice and Bob's devices then share a secret key (after an additional secret amplification step). The notion of "shared key" means that the key is common to both Alice and Bob.

[0012] The dissemination on the public channel of the information shared between Alice and Bob's devices ("side information") concerning the values ​​of the parity bits and the choices of the bases used (or possibly relating to the selection of the qubits that are kept), during the reconciliation phase, constitutes a harmful information leak likely to favor Eve in her search for the key. This disclosure goes against the secrecy of the key, and requires a secrecy amplification process, at the cost of a reduction in the size of the key.

[0013] Indeed, knowing the choice of bases used for each qubit, Eve knows which qubits are reliable (to within 1-E) among those she has measured. From the reliable qubits, and knowing the (reliable) parity values ​​and the residual error correction method, Eve can deduce values ​​of other qubits, either in terms of value or in terms of probability. In all cases, this information broadcast on the public channel makes it possible to reduce the combinatorics of key exploration for Eve. The only known countermeasure is the secret amplification treatment, implementing hash functions to combine the elements of the key, at the cost of a reduction in the key size.

[0014] There is therefore a need for a quantum key distribution solution that can better preserve secrecy and reduce the risk of information leakage on the public channel. Summary of the invention:

[0015] Thus, according to a first aspect, the present invention describes a method of quantum key distribution, named K QK D_N, to a first and a second telecommunication device for implementing between them a telecommunication encrypted by said key K QK D_N, said first and a second telecommunication devices each being connected to a respective first telecommunication link and connected to each other by a second telecommunication link, said first link being an optical transmission link and being hereinafter called a quantum channel, said second telecommunication link being hereinafter called a classical channel; said method comprising the following steps of determining K QKD_N, implemented by at least one device considered among the first and second devices: implementation, on the quantum channel, of a communication of a random sequence of bits in the form of a sequence of light pulses in quantum regime such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by each of the first and second devices;implementing, on the conventional channel, a communication, between the first and second devices, of information indicating parity bit values, said parity bit values ​​having been calculated by at least one of said first and second devices as a function of the random sequence of bits that it has memorized, then being transmitted, during said communication, to the other of said first and second devices which then implements, in the sequence of bits memorized by the other of said first and second devices, an error correction, as a function of said transmitted parity bits; determining said key K; QK D_N, based on said random sequence of bits, and storing said key K QKD_N, said key being shared between said first and a second device; said method being characterized in that said communication of information indicating parity bit values ​​between the first and the second device is encrypted or decrypted by said device considered according to at least one key KQ K D_N-K previously determined by prior implementation of a quantum key distribution mechanism QKD to said first and second devices.

[0016] The proposed solution significantly reduces information leakage and improves the level of secrecy. There is no clear (or public key encryption) transmission of the choice of bases used, and / or information relating to parities on the public channel. This sensitive information is previously encrypted from at least one secret key previously generated by QKD via the quantum channel and the classical channel in a previous step.

[0017] Using a key obtained by QKD guarantees unconditional security relative to the computing power of a third party (Eve).

[0018] Eve cannot access the information on the choice of bases used (jointly by Alice and Bob's devices) and on the selection of the qubits retained, nor the information relating to the parity bits. Because if Alice and Bob's devices share these previously generated secret keys and can therefore encrypt / decrypt the messages carrying the information on the choice of bases, the selection of qubits and on the parities, this is not the case for Eve.

[0019] This greatly reduces information leakage on the key.

[0020] Eve has a sequence of qubits without being able to identify which are correct (on average 75% of the sequence) and which are retained to form the key.

[0021] According to a second aspect, the present invention describes a method of quantum key distribution, named K QK D_N, to a first and a second telecommunication device for implementing between them a telecommunication encrypted by said key K QK D_N, said first and a second telecommunication devices each being connected to a respective first telecommunication link and connected to each other by a second telecommunication link, said first link being an optical transmission link and being hereinafter called a quantum channel, said second telecommunication link being hereinafter called a classical channel; said method comprising the following steps of determining K QKD_N, implemented by at least one device considered among the first and second devices: implementation, on the quantum channel, of a communication of a random sequence of bits in the form of a sequence of light pulses in quantum regime such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being memorized by each of the first and second devices; implementation, on the conventional channel, of a communication, between the first and second devices, of information relating to bases, indicating, for each bit of the memorized sequence, the base, among at least two distinct bases of coding between values ​​of said parameter and the values ​​0 or 1 of a bit of the random sequence of bits, that one at least of the first and second devices has randomly selected to carry out the coding between the bit and the value of said light pulse parameter; selection, by said device, of those bits of the random sequence of bits for which the first and second devices have selected the same bases; implementation, on the conventional channel, of a communication, between the first and second devices, of information indicating parity bit values, said parity bit values ​​having been calculated by at least one of said first and second devices as a function of said selected bits, then being transmitted, during said communication, to the other of said first and second devices which then implements an error correction, as a function of said transmitted parity bits, on the bits selected by the other of said first and second devices; determination of said key K QKD_N, depending on the selected bits and error correction, and storing said key K QK D_N, said key being shared between said first and a second device; said method being characterized in that said communication of information relating to said bases between the first and the second device is encrypted or decrypted by said device considered according to at least one key K Q KD_N-K previously determined by prior implementation of a quantum key distribution mechanism QKD to said first and second devices.

[0022] In embodiments of such a method, said communication of information indicating parity bit values ​​between the first and second devices is further encrypted or decrypted by said device in question based on at least one key KQ KD_N-K previously determined by implementing a prior iteration of a quantum key distribution method QKD to said first and second devices.

[0023] In embodiments of a method according to the first aspect or the second aspect of the invention, at least one of the following arrangements is implemented: - the encryption or decryption of the information is carried out according to a symmetric encryption or decryption key determined by operations of the concatenation and permutation type and / or logical combination at the bit level of at least one key previously determined by quantum key distribution QKD to said first and second devices; - said information used for QKD reconciliation encrypted or decrypted according to at least the key K Q KD_N-K previously determined are random and independent information.

[0024] According to a third aspect, the invention describes a computer program intended to be stored in the memory of a telecommunications device and further comprising a microcomputer, said computer program comprising instructions which, when executed on the microcomputer, orchestrate the steps of a method according to the first or second aspect of the invention.

[0025] According to a fourth aspect, the invention describes a telecommunication device adapted to be connected to a first telecommunication link, adapted to be connected to another telecommunication device by a second telecommunication link, and to implement with said other device a telecommunication encrypted by a key KQKD_N, said first link being an optical transmission link and being hereinafter called a quantum channel, said second telecommunication link being hereinafter called a classical channel; said device being adapted to determine K QKD_N, in: by implementing, on the quantum channel, a communication of a random sequence of bits in the form of a sequence of light pulses in quantum mode such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being memorized by the device;by putting, on the conventional channel, a communication with the other device, of information indicating parity bit values, said parity bit values ​​having been calculated by at least a first device among said device and said other device according to the random sequence of bits that it has memorized, then being transmitted, during said communication, to the second among said device and said other device which then implements, in the sequence of bits memorized by the other of said first and second devices, an error correction, according to said transmitted parity bits; by determining said key K; QK D_N, based on said random sequence of bits, and storing said key K QK D_N, said key being shared between said device and said other device; said device being characterized in that said communication of information indicating parity bit values ​​between said device and said other device is encrypted or decrypted by said device according to at least one key K Q KD_N-K previously determined by prior implementation of a QKD quantum key distribution mechanism to said device and said other device.

[0026] According to a fifth aspect, the invention describes a telecommunication device adapted to be connected to a first telecommunication link, adapted to be connected to another telecommunication device by a second telecommunication link, and to implement with said other device a telecommunication encrypted by a key KQKD_N, said first link being an optical transmission link and being hereinafter called a quantum channel, said second telecommunication link being hereinafter called a classical channel; said device being adapted to determine K QKD_N, by: implementing, on the quantum channel, a communication of a random sequence of bits in the form of a sequence of light pulses in quantum mode such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by the device; by putting, on the conventional channel, a communication with the other device, of information indicating, for each bit of the stored sequence, the base, among at least two distinct bases of coding between values ​​of said parameter and the values ​​0 or 1 of a bit of the random sequence of bits, that a first device among said device and said other device has randomly selected to carry out the coding between the bit and the value of said light pulse parameter;by selecting those bits of the random sequence of bits for which said device and said other device have selected the same bases; by implementing, on the conventional channel, a communication, between said device and said other device, of information indicating parity bit values, said parity bit values ​​having been calculated by a first device among said device or said other device as a function of said selected bits, then being transmitted, during said communication, to the second device among said device and said other device which then implements error correction, as a function; of said transmitted parity bits, on the bits selected by the second device from among said device and said other device; determination of said key K QK D_N, depending on the selected bits, and storage of said key K QKD_N, said key being shared between said device and said other device; said device being characterized in that said communication of information relating to said bases between said device and said other device is encrypted or decrypted by said device according to at least one key K Q KD_N-K previously determined by prior implementation of a QKD quantum key distribution mechanism to said device and said other device.

[0027] In embodiments, a telecommunications device according to the fifth aspect of the invention is adapted to encrypt or decrypt said communication of information indicating parity bit values ​​between said and said other device according to at least one key KQ K D_N-K previously determined by prior implementation of a quantum key distribution QKD to said device and said other device.

[0028] In embodiments, a telecommunications device according to the fourth or fifth aspect of the invention is adapted to carry out the encryption or decryption of information according to a symmetric encryption or decryption key determined by operations of the concatenation and permutation type and / or logical combination at the bit level of at least one key previously determined by quantum key distribution QKD to said first and second devices (D_ALICE, D_BOB). Brief description of the figures:

[0029] The invention will be better understood and other characteristics, details and advantages will appear more clearly on reading the following description, given without limitation, and thanks to the appended figures, given by way of example.

[0030] [Fig. 1] Figure 1 schematically represents a QKD key generation system in one embodiment of the invention;

[0031] [Fig.2] Figure 2 represents the steps of a quantum key distribution method in one embodiment of the invention;

[0032] [Fig. 3] Figure 3 illustrates the transmission and detection of a sequence of qubits in one embodiment of the invention;

[0033] [Fig. 4] Figure 4 is a table illustrating the implementation of a method in one embodiment of the invention, at startup;

[0034] [Fig. 5] Figure 5 is a table illustrating the implementation of a method in one embodiment of the invention, in steady state;

[0035] Identical references may be used in different figures when they designate the same or comparable elements. Detailed description:

[0036] Figure 1 represents a system for generating a symmetric key by QKD in one embodiment of the invention, comprising two telecommunication devices 10, 20 connected to each other by a quantum channel 30 and a classical channel 40. Each or one of the telecommunication devices 10, 20 is for example on the ground, or on board a satellite, an aircraft, etc.

[0037] The quantum channel 30 is a telecommunications channel which allows the transit of information (binary in DV-QKD or continuous in CV-QKD) carried by a physical property of a quantum object (e.g. polarization of a photon) transmitted on this channel; here the quantum channel 30 is adapted to transmit light pulses (generated by a photon source, the transmission being carried out on an optical link of the optical fiber type or simply by free propagation in the open air, the atmosphere, Space, etc.).

[0038] The classic channel 40 is a communication channel for example standard (e.g. radio frequency link, internet network, optical fiber, etc.), assumed to be accessible in clear by all (including a malicious third party Eve), to allow the telecommunications devices 10 and 20 to converge towards the definition of a secret key on the basis of transmitted qubits, as described below for the BB84 protocol.

[0039] The telecommunications device 10, hereinafter called D_ALICE, of user Alice, comprises a control block 11, a quantum transmission block 12, a radio frequency (RF) transmission / reception block 13 and a memory 14. The control block 11 comprises a cryptography block 110 and a memory 111 associated with the cryptography block 110 and storing secret keys previously generated by QKD method between D_ALICE 10 and D_BOB 20.

[0040] The telecommunications device 20, hereinafter called D_BOB, of user Bob, comprises a control block 21, a quantum reception block 22, a radio frequency (RF) transmission / reception block 23 and a memory 24. The control block 21 comprises a cryptography block 210 and a memory 211 associated with the control block 21. cryptography 210 and storing secret keys previously generated by QKD between D_ALICE 10 and D_BOB 20.

[0041] Radio frequency (RF) transmit / receive blocks 13 and 23 are adapted to communicate together via conventional channel 40.

[0042] The control block 11, respectively 21, comprises for example a memory and a microprocessor (not shown). In one embodiment, the memory of the control block 11, respectively 21, comprises software instructions, which when executed on the microprocessor of the control block 11, respectively 21, implement the steps incumbent on the control block 11, respectively 21, and described later, in particular with reference to FIG. 2.

[0043] The radio frequency (RF) transmission / reception block 13, respectively 23, typically comprises a modem and a radio frequency transmission and reception antenna (not shown).

[0044] Quantum emission block 12 consists of a generation block, named GEN 121, and a polarization block, named Pol 122.

[0045] The GEN 121 block is suitable for randomly generating a sequence of bits to be transmitted.

[0046] The Pol 122 block is adapted to randomly choose, for each bit to be transmitted, a base from a set of bases comprising several reference polarization bases (these bases are also called modes or quadratures) and to transmit a light pulse with a polarization corresponding to the value of the bit to be transmitted in the base chosen randomly for this bit.

[0047] The Pol 122 block comprises, for example, a polarization rotator, capable of rotating the polarization of the emitted light signal, selectively by 0° (if the H / V base is chosen by the Pol 132 block) or by 45° (if the D / A base is chosen), the selection between the 0° and 45° angles being carried out randomly. For example, the polarization rotator is produced with a half-wave delay plate whose rotation is ensured by an actuator. Another embodiment uses an electro-optical polarization modulator, suitable for high polarization change rates.

[0048] The set of bases, in the present case, comprises two bases for example: a first Horizontal / Vertical (H / V) base in which "1" is coded by a photon with a 0° polarization axis and "0" by a 90° polarization photon; a second Diagonal / Antidiagonal (D / A) base in which "0" is coded by a photon with a 45° polarization axis and "1" by a 135° polarization photon.

[0049] The quantum reception block 22 comprises a polarization block, named Pol 132, and a measurement block 131.

[0050] Before the expected arrival of a photon, the Pol 132 block is adapted to perform a polarization rotation in order to randomly choose a base from the two bases H / V and D / A. The Pol 132 block includes a polarization rotator, capable of rotating the polarization of the emitted light signal, selectively by 0° (if the Pol 132 block chooses the H / V base) or by 45° (if the D / A base is chosen). For example, the polarization rotator is made with a half-wave delay plate whose rotation is ensured by an actuator.

[0051] The measuring block 131 is adapted to measure two light polarization components in quadrature at the output of the polarization rotator Pol 132, either on the H / V basis if the polarization rotation is 0°, or on the D / A basis if the polarization rotation is 45°. For example, the measuring block is realized with a polarizing beam splitter (PBS) generating a quadrature, and two photon detectors (SPD) for the two components of the quadrature.

[0052] We recall here that a photon can be polarized along any axis. A photon polarized along an axis of angle 'a' passing through a polarizing filter along an axis of angle 'b' has a probability equal to cos 2 (ba) to pass the polarizing filter, according to Malus's law.

[0053] According to the quantum properties used by quantum cryptography: when the probability of passing the filter is neither 0 nor 1, the passage of an individual photon through the filter is fundamentally unpredictable and indeterministic; the polarization axis can only be known by using a polarizing filter (or more generally, by making a measurement whose result is YES or NO) and with a large number of measurements to estimate the probability of passage; there is no direct measurement on an individual photon, giving an angle for example, of the polarization axis of the photon.

[0054] The steps of a QKD method according to the invention are now described with reference to Figure 2.

[0055] The starting context is as follows: Alice wants to exchange an Nth message, named M_N, with Bob. For this, a secret key, K QKD_N, must be generated by QKD, in a shared manner between D_ALICE 10 and D_BOB 20, to allow one to encrypt, and the other to decrypt this Nth message which can be transmitted with maximum security. For its part, Eve tries to intercept the communications to determine the key. In accordance with Kerckhoff's principles (worst case hypothesis), we assume for example that Eve has access to the communication channels used by D_ALICE 10 and D_BOB 20, that she knows the protocol used perfectly and has unlimited computing resources. The security of encrypted communications between D_ALICE 10 and D_BOB 20 is then ensured solely by the secret key that the process described below results in generating and distributing.

[0056] QUANTUM PHASE

[0057] Typically, only this phase uses the quantum channel, the post-processing phase does not.

[0058] Step 101

[0059] In this step 101: - in response to a corresponding command from control block 11 to block GEN 121, block GEN 121 randomly generates a sequence of 2T bits therefore taking the value 0 or 1; T is an integer typically greater than 10000; - following receipt of a respective command from the control block 11 to the Pol block 122, the Pol block 122 randomly chooses, for each bit generated, a polarization base from among the two polarization bases and emits on the quantum channel 30, photon by photon, a photon whose polarization is a function of the value of the bit generated and the polarization base chosen for this qubit; each photon is emitted at regular intervals. The qubits are thus transmitted.

[0060] The sequence of choices of bases and bits corresponding to the generated sequence of qubits is then stored by the control block 11 in the memory 14 and the value of each bit is stored there, associated with the polarization base chosen for the bit by the Pol block 122 and with the rank of the bit in the sequence and.

[0061] Step 102

[0062] Under the control of the control block 21, before the expected arrival of each photon, the Pol block 132 randomly chooses a base (by modifying the orientation of a rotator or by modifying the control of a polarization modulator). At the expected time of arrival of a photon, under the control of the control block 21, the measurement block 131 carries out a measurement of what comes out of the polarizing filter on the selected components. The control block 21 determines the value of the bit corresponding to the detected photon according to the measurement carried out and the base chosen for the measurement (corresponding to the polarization rotation carried out by the Pol block 132) and stores in the memory 24, for each photon detected, the value of the bit determined, in association with the chosen base and the reception rank of the photon (and therefore of the qubit).

[0063] Figure 3 represents in a table, the rank number of the first 8 bits of a sequence generated in step 101 (first line of the table) and the randomly generated value for these bits (second line). These bits thus take the following values: 0 for the bit of rank 1, 4, 6 and 7 and 1 for the bit of rank 2, 3, 5 and 8.

[0064] The third line indicates the base chosen for the emission of each bit by the D_ALICE 10 device: the "+" sign indicates that the H / V base was chosen while the "x" sign indicates that the D / A base was chosen. Thus for bits of rank 1, 2, 4 and 8, the HA / base was chosen, and the D / A base was chosen for bits of rank 3, 5 to 7.

[0065] The fourth line indicates the polarization of the emitted photon: vertical for the bit of rank 1, 4, horizontal for the bit of rank 2 and 8, diagonal for the bit of rank 6 and 7, antidiagonal for the bits of rank 3 and 5.

[0066] The fifth line of the table indicates the base chosen by the D_BOB 20 device, in reception: H / V for the photon received at rank 1, 5, 7 and 8 and D / A for the photon of rank 2, 3, 4 and 6.

[0067] Finally, the sixth line illustrates the result of the measurement by the D_BOB 20 device: for photons of rank 1, 3, 6, 8 the measurement base corresponds to the emission base and the polarization of the detected photon generally corresponds to the polarization at the emission of the photon; for photons of rank 2, 4, 5, 7 the measurement base is different from the emission base and the polarization of the detected photon is totally random. The determined qubit value stored in the memory 24 is 0 for the photon of rank 1 and 6 and is 1 for the photon of rank 3 and 8.

[0068] POST-PROCESSING PHASE

[0069] Step 103

[0070] In step 103: - in the controller 21 of the D_BOB device 20, the binary sequence {bases}BO b, which is stored in the memory 24, successively defining the polarization base chosen to detect each photon of the sequence received in step 102 is provided as input to the cryptography block 210; for example, if the set of bases comprises only the two bases H / V and D / A, in the binary sequence indicating the choice of bases, a “0” (respectively a “1”) at rank n of this sequence {bases} BO b will indicate that the H / V (respectively D / A) basis was used to detect the qubit of rank n at the step considered (step 102); - the cryptography block 210 encrypts using at least one of the secret keys stored in the memory 211 and previously generated by QKD by D_ALICE 10 and D_BOB 20, this binary sequence indicating the chosen bases; - the controller 21 of the D_BOB device 20 then transmits to the D_ALICE device 10, via the RF transmission / reception block 23, on the conventional channel 40, the binary sequence thus encrypted indicating the polarization base chosen to detect each photon of the sequence received in step 102; - the controller 11 of the D_ALICE device 10 receives, via the RF transmission / reception block 13, the binary sequence {bases} BO b encrypted, which is then processed by the cryptography block 110; the latter decrypts it using the secret key(s) stored in the memory 111 which was (were) used for the encryption of this sequence.

[0071] Step 104 (sifting)

[0072] The controller 11 then compares for each rank in the sequence of qubits, the chosen polarization base received on the conventional channel 40 and the polarization base associated with this rank which is stored in the memory 14 of the device 10; it selectively retains (Sifting step) only the qubits which have been generated (D_ALICE 10) and measured (D_BOB 20) on the same base. Statistically only 50% of the bits are retained.

[0073] The list of indexes of only the retained qubits is then provided as input to the cryptography block 110 which encrypts it, using at least one of the secret keys stored in the memory 111 and previously generated by QKD by D_ALICE 10 and D_BOB 20. The controller 11 of the device D_ALICE 10 then transmits to the device D_BOB 20, via the RF transmission / reception block 13, on the conventional channel 40, the list of retained qubits thus encrypted.

[0074] the controller 21 of the D_BOB device 20 receives, via the RF transmission / reception block 23, the encrypted list of retained indexes and provides it to the cryptography block 210; the latter decrypts it using the secret key(s) stored in the memory 211 which was (were) used for the encryption of this sequence.

[0075] The controller 21 of the device D_BOB 20 selectively retains in turn, from among all the qubits received in step 102, only the qubits whose index (i.e. the rank in the sequence emitted by D_ALICE / received by D_BOB) is indicated in the received list, which are the qubits generated (D_ALICE 10) and measured (D_BOB 20) on the same basis.

[0076] The qubits thus retained by D_ALICE 10, D_BOB 20, form their respective “sifted key”.

[0077] All these retained qubits were transmitted to D_BOB 20, with a probability of 1-E, that is to say, to the errors induced by noise, adjustment / synchronization defects and implementation imperfections. Sifting made it possible to discard the qubits whose detection was carried out on a basis other than the generation basis, the transmission of these qubits being unreliable (50%: therefore random).

[0078] In the example in figure 3, the bits of rank 1, 3, 6 and 8 are thus the only ones retained by D_ALICE 10 and D_BOB 20, among the first eight bits of the sequence, for the rest of the steps (see “sifted key” line)

[0079] (It will be noted that in alternative embodiments of steps 103 and 104, the roles of D_ALICE 10 and D_BOB 11 are reversed or that each of D_ALICE 10 and D_BOB 11 transmits to the other its base choices and then compares for each rank in the sequence of qubits, the chosen polarization base received on the conventional channel 40 and the polarization base associated with this rank which is stored, in the memory of the device 10, respectively 20; it selectively retains (Sifting step) only the qubits which have been generated (D_ALICE 10) and measured (D_BOB 20) on the same base.)

[0080] Step 105

[0081] The control blocks 11 and 21 then evaluate the transmission error rate of the qubits (QBER for 'Quantum Bit Error Rate') affecting their respective sets of bits retained in the sifting step 104, in order to detect the possible interception by Eve, to evaluate the quantity of information intercepted by Eve on the quantum channel during the transmission in step 101 and to possibly select, depending on the evaluated error rate, an error-correcting code (choice of code and throughput) or to parameterize an iterative error-correcting protocol by request / response for the rest of the processing. To do this, a certain number of qubits are "sacrificed" since they are communicated on the conventional channel 40: they are also removed from the bits retained by the control blocks 11 and 21 for the rest of the post-processing. After eliminating the qubits used to estimate the QBER, the Sifted Key consists of t qubits.

[0082] Depending on the comparison between this error rate evaluation and a given threshold (determining whether a third party has listened to the quantum channel during the transmission of the qubits or whether an unacceptable quantity of information has been intercepted), the present distribution operation is terminated (which can then be re-initiated from step 101); otherwise, step 106 is implemented.

[0083] Due to limitations of photon sources and photon detectors, imperfections in implementation, settings or synchronization, the bits of the Sifted Key retained at this stage by D_ALICE and D_BOB are generally not perfectly identical. The set of steps 106-108 below of the reconciliation phase aims to detect / correct residual errors of the qubits of the "Sifted Key" key determined respectively by D_ALICE and D_BOB, by using an error correcting code of the FEC type (Forward Error Correction code), or an interactive and iterative request / response protocol between Alice and Bob, to determine and transmit parity bits associated with subgroups (i.e. packets) of the qubits of the "Sifted Key", in order to detect / correct residual errors between Alice's key and Bob's key and so that they then have a rigorously identical key.

[0084] Redundant parity information is then generated by either D_ALICE 10, D_BOB 20, or both, and then emitted by one or the other.

[0085] As described below, these parities are transmitted via the public channel to the other party, so that the latter can identify residual errors on one sifted key relative to the other (D_ALICE / D_BOB), in accordance with the error detection and correction protocol chosen, based on the parities received and its own sifted key.

[0086] Step 106

[0087] In one embodiment, in a step 106, each control block 11, 21, in parallel with one another, calculates parity bits from subgroups of the t bits of the Sifted Key after estimation of the QBER error rate in step 105, according to the error detection and correction protocol selected (here iterative protocol of Cascade or Winnow type).

[0088] The values ​​of the parity bits calculated by each control block 11, respectively 21 are stored in memory 14, 24.

[0089] Step 107

[0090] One of the cryptography blocks 110, respectively 210 encrypts these parity values, using at least one of the secret keys stored in the memory 111, respectively 211 and previously generated by QKD by D_ALICE 10 and D_BOB 20.

[0091] To inform the other device of the values ​​of the calculated parity bits, one of the control blocks 21, respectively 11, transmits the values ​​of these parity bits as well encrypted on the conventional channel 40 via the Em / Rec RF blocks 23, respectively 13. One of the control blocks 11, respectively 21, receives on the conventional channel the values ​​of these parity bits thus encrypted and supplies them to the cryptography block 110, respectively 210, which decrypts them using the secret key(s) stored in the memory 111 respectively 211 which was (were) used for the encryption of these values.

[0092] Step 108

[0093] One of the control blocks 11, respectively 21, then compares the received value of each parity bit, which was calculated for a given subgroup of bits, with the value that it itself calculated for this same subgroup of bits of its own sifted key. With an iterative protocol of the Cascade or Winnow type, the parity comparison makes it possible either to detect / correct an erroneous bit, or to orient the error search process via a new parity calculation request on another subgroup of bits. The residual errors between the Sifted Key held by D_ALICE 10 and D_BOB 20 can thus be detected and corrected according to this comparison carried out for each parity bit. The detected erroneous bits can be either corrected or rejected. This process makes it possible to obtain, in D_ALICE 10 and D_BOB 20, an ideally rigorously identical secret key, shared between them, of size v.

[0094] An iterative protocol of the Cascade or Winnow type involves a variable number of requests / responses between D_ALICE 10 and D_BOB 20, depending on the number of residual errors; an error-correcting code of the FEC (Forward Error Correction code) type involves a single message sent by only one of the devices 10, 20 to the other of the devices 20, 10 to detect / correct the residual errors. The exchanges take place on the public channel 40.

[0095] Steps 106, 107, 108 above describe by way of example the case of an iterative request / response protocol of the Cascade or Winnow type (calculation of the parity bits in the devices 10, 20 transmission by one device to another, comparison in a device).

[0096] In the case of using a FEC code type protocol, for example LDPC, depending on the embodiments: - the control block D_ALICE 11 calculates for example the parity bits from the bits of Alice's sifted key (after sifting, step 104, and after estimation of the QBER error rate, step 105); these parities are transmitted encrypted to the control block 21 of D_BOB 20, which decrypts them, then decodes them with its version of the sifted key, to identify the errors on its key (Bob); then D_BOB 20 corrects its errors; and / or - the control block of D_BOB 21 calculates for example the parity bits from the bits of Bob's sifted key; these parities are transmitted encrypted to the control block 11 of D_ALICE 10, which decrypts them, then decodes them with its version of the sifted key, to identify the errors on its key (Alice); then D_ALICE corrects its errors.

[0097] Regardless of the error detection and correction protocol chosen, the principle remains the same: transmit encrypted information to the other device on the public channel to access the parity values.

[0098] Step 109

[0099] A secret amplification step, optional and which can in any case be lightened compared to the prior art, implements hash functions to combine the bits of the key obtained at the end of step 108 and thus reduce Eve's information on the final key, at the cost of a reduction in the size of the key. Hash functions are very difficult to invert, and can be used to generate pseudo-random numbers. They often use modular arithmetic.

[0100] Example of a hash function:

[0101] At the end of the implementation of the method according to the invention, D_ALICE 10 and D_BOB 20 have a shared secret key, KQK D_N, which they will then each use as a symmetric encryption key to encode and decode the message M_N exchanged between them on the public channel or another channel. Each control block 11, respectively 21, stores the newly generated QKD key, K QK D_N, in memory 111, 211, for a limited time.

[0102] K's size QK D_N is equal to v (i.e. it has v bits, with v < t, v <T).

[0103] To improve the confidentiality of QKD with respect to the transmission of parities, bases used and possibly the selection of qubits retained, QKD is therefore used according to the invention.

[0104] The security of secret key encryption (Vernam) is based on the use of a secret random key of at least the same size as the message to be encrypted, and the obligation not to reuse the key.

[0105] But a key can be reused to encrypt any new random message, without compromising the security of previous transmissions with the same key. It is not common to encrypt perfectly random (because meaningless) information.

[0106] This is used according to the invention for reconciliation processing in QKD, to encrypt information on the choice of bases, on the selected qubits and on the parities.

[0107] The random nature of a sequence is associated with statistical characteristics and can be estimated with a set of statistical tests (AIS 31, NIST SP 800-22...). In practice, the mean of a binary sequence must be close to 0.5, the autocorrelation function must be free of peaks, the entropy must be sufficient, etc...

[0108] The choice of bases used for transmission and reception are defined by two binary sequences {bases} A | iceand {bases} BO b independent (uncorrelated) and random in nature: D_ALICE 10 and D_BOB 20 can therefore securely encrypt this information from at least one prior secret key obtained by QKD without compromising the security of prior transmissions with this same key. The same is true when one party (D_BOB) broadcasts its choices of bases and then the other party (D_ALICE) broadcasts the selection of the chosen qubits: these sequences are random and independent, D_ALICE 10 and D_BOB 20 can therefore securely encrypt this information from at least one prior secret key obtained by QKD.

[0109] The information on the choice of the bases of D_ALICE (or D_BOB) or on the selection of the qubits retained on the one hand, and the information on the parities on the other hand are random and independent. Their encryption from at least one secret key therefore does not compromise the security of previous transmissions with this same key.

[0110] For example, the secret key K QK D_ NI used to encrypt the (N-1)th message, named , M_N-1, exchanged between D_ALICE 10 and D_BOB 20, can be reused to encrypt the information on the choice of Alice's bases, as well as the parity bits, during the construction of the key K QK D_N- The K key QK D_ N-2 used to encrypt the (N-2)th message, M_N-2, can be reused to encrypt the information about Bob's choice of bases to construct the key KQKD_ N- - -

[0111] The sequence of bases used by D_ALICE, {bases} A | ice is encrypted by D_ALICE 10 in a different and independent way, for each bit, of the encryption of the sequence {bases} BO b by D_BOB 20: thus Eve cannot know which qubits will be discarded or retained during sifting.

[0112] By doing this, Eve cannot know: which (index) qubits will be discarded / retained during sifting the choice of bases for the retained qubits the parity values.

[0113] Eve only has the raw sequence of qubits that she has randomly observed (according to the choice of bases), 75% of the content of which is statistically correct, and 50% will be discarded during sifting. She cannot perform sifting, not knowing which qubits are retained. No information on parities allows her to restrict the search space of candidate keys. Another example in the case of asymmetric diffusion of information on the choice of bases: the secret key K QK D_ NI used to encrypt the (N-1)th message, named , M_N-1, exchanged between D_ALICE 10 and D_BOB 20, can be reused to encrypt the information on the choice of bases by D_BOB, then to encrypt the parity bits, during the construction of the key K QK D_N- The K key QKD_ N-2 used to encrypt the (N-2)th message, M_N-2, can be reused by D_ALICE to encrypt the information on the selection of qubits retained to construct the key KQ K D_ N- - -

[0114] Size of information (selected bases, parity bits) to be encrypted, use of secret keys

[0115] The 2 qubit sequences, respectively generated (step 101, that of D_ALICE) and received (step 102, that of D_BOB), i.e. considered before sifting, have a size 2T. Each of the two binary sequences defining the choices of the bases used, {bases} A ii Ce and {bases} BOb have the same size. This size is equal to 2T when only two bases appear in the set of bases. The size is greater than 2T when more than one bit is necessary to identify the chosen base (i.e. in cases where D_ALICE 10 and D_BOB 20 choose their base from a set of bases containing a number of bases strictly greater than two).

[0116] The 2 sequences after sifting have a variable size t close to T, the sifting discarding on average 50% of the qubits emitted by D_ALICE. The 2 sequences after estimation of the QBER error rate (step 105) have a size u less than t.

[0117] The parity sequence has a possibly variable size, which for example can be considered less than 2T, the invention also being suitable for sequences to be encrypted of a size greater than 2T.

[0118] Finally, after amplification of the secret (step 109), each secret key has a size v strictly less than u, t and T.

[0119] Symmetric key encryption of these different sequences (choice of bases, selection of retained qubits, parity bits) therefore requires keys of size 2T. However, secret keys of size less than T can be used.

[0120] A classic approach is to use an encryption algorithm using a key of size independent of that of the message, which is conditioned on the availability / distribution of keys for D_ALICE and D_BOB.

[0121] But for better protection, another solution is to use Vernam's One Time Pad cipher, to reuse secret keys obtained by QKD in particular by combining them by concatenation, permutation and / or logical combination operations (XOR or exclusive operator) at the bit level, to form larger keys to encrypt information on the choices of Alice's and / or Bob's bases, on the selection of the qubits retained as well as on the parities.

[0122] Encrypting the basis choices of D_BOB and D_ALICE differently and independently for each qubit means that Eve cannot determine which qubits are retained / rejected during sifting. Permutations between or within the secret keys used can address this need. The 2 bits of symmetric encryption keys used to encrypt the basis choice for each qubit by D_ALICE and D_BOB must therefore be independent (uncorrelated).

[0123] Since the parity information is independent of the choice of bases (random) and the selection of the retained qubits and is relative to random information (random sequence to form a key), the same secret encryption key can be used to encrypt this information (choice of base of a single part, i.e. either D_ALICE or D_BOB, selection of the retained qubits and parity information), without compromising the security of this key.

[0124] This applies to the transient regime, after generating at least one secret key by QKD, and to the established regime, which corresponds to the generation of at least k secret keys (i.e. k=3 to encrypt binary sequences of size 2T) by QKD.

[0125] Process initialization

[0126] When starting a QKD session between D_ALICE 10 and D_BOB 20, they do not always store previously shared secret keys generated by QKD in their respective memory 111, 211.

[0127] To initiate the mechanism according to the invention, several options can be used, for example those described below.

[0128] Option A (we wait until we have the required number of previous keys to encrypt on the classic channel)

[0129] It is sufficient to generate by QKD, according to classical methods, the required number of keys, for example three (or more) keys, for example K QK D_I, K QK D_2, K QK D_3, without encrypting the information on the choice of bases, the selection of the retained qubits, and the parities transmitted on the classical channel. Each key K QK D_I, respectively K QK D_2, K QKD_3 allows to encrypt a useful message M_1, respectively M_2, M_3 (a priori carrying meaning, i.e. no random sequence). Then during the phase of development of the QKD key K QK D_n, for example for n>3 when, in accordance with the method of the invention, at least three previously generated keys, for example K QK D_n-i, K QK D_n-2, K QK D_n-3 are used to generate, by combination (permutation / concatenation / logical combination at the bit level) the encryption keys of the sequences of choice of bases, selection of the retained qubits, and parity of steps 103, 104, 107.

[0130] Option B (we produce the required number of prior keys before starting to encrypt useful messages and on the classical channel)

[0131] Same as option A, but without using the keys to encrypt useful messages (carrying meaning), for greater security, as long as the transmissions of the base and parity sequences are not encrypted in accordance with the invention.

[0132] Option AB, intermediate (at least one previous key is reused to form the 2T size keys to encrypt the classic channel)

[0133] According to this intermediate option, by using one of the previous options to generate a first secret key, it can be reused (secret key) several times to encrypt the information on the choice of bases, the selection of the retained qubits and the parities, until a sufficient number of secret keys is generated to implement the general method described with reference to Figure 2 (the method can however be implemented from a secret key obtained by QKD; the required / optimal number of keys to encrypt the side information corresponds to an additional level of confidentiality). When the selection of the retained qubits is not communicated, it is then desirable to perform at least one permutation of the secret key to encrypt in a different and independent way each bit of the choice of bases for D_ALICE 10 and D_BOB 20, so that Eve cannot determine which qubits are retained / rejected.In a final intermediate step, different secret keys can be used to encrypt information about the choice of bases, the selection of the retained qubits and the parities, one of which is reused during this encryption.

[0134] Thus, accessibility to information on the choice of bases, the selection of the retained qubits and the parities evolves rapidly with the production of new keys, until it becomes inaccessible to Eve.

[0135] As described, D_ALICE 10 and D_BOB 20 keep a record, in memories 111, 211, of the last secret keys used during the session. This allows them to secretly generate (by encrypting sensitive information) new secret keys.

[0136] The table in Figure 4 illustrates the transient regime at startup, in one embodiment of the invention, with the use of prior QKD secret key(s) to encrypt the base selection information used by D_ALICE 10 and D_BOB 20 and the parity information.

[0137] The table in Figure 5 illustrates, in one embodiment of the invention, in steady state, this time the use of prior secret keys to form secret keys of size 2T to encrypt the information on the choice of bases used by D_ALICE 10 and D_BOB 20, as well as to encrypt the parity information.

[0138] Each row in these tables corresponds to the step of constructing a QKD key, of size u less than T and indicated in the left column. The box in the second column indicates how, during this construction, the sequence {bases} A | iceof size 2T is encrypted (or not) and the box in the third column indicates how, during this construction, the sequence {bases} BO b of size 2T is encrypted (or not). The box in the fourth column indicates how, during this construction, the sequence of parity bits of size less than 2T is encrypted (or not) (in the error detection protocol considered here, only D_ALICE 10 transmits the parity bits to D_BOB 20, the latter not sending them). Finally, in the rightmost column of the table, the useful message that will be transmitted encrypted by the key once constructed is indicated: the message MJ is thus encrypted by the key K QK D_ i, i = 1 , 2, 3, ... N-1 , N ... The size of the message MJ is less than or equal to the size of KQKD_ r

[0139] Referring to Figure 4:

[0140] During the QKD protocol elaboration of the first session key, K QKD_ I, the sequences of chosen bases and parity values ​​are transmitted in clear. At the end of this construction, the key K QK D_ I is used to encrypt a first useful message, M_1 , exchanged between D_ALICE 10 and D_BOB 20.

[0141] The second key K QK D_2 is generated by encrypting transmissions over the classical channel, using sequences derived from the first secret key (concatenation, logical combination, permutations of bits). For example, during the QKD protocol elaboration of the second session key, K QK D_2: - the sequence of bases, {bases} A ii Ce is encrypted according to the key K QK D_ I ; for example, a function <p’ de concaténation est appliquée à la clé K QK D_i To generate an encryption key from the sequence of choice of bases of size greater than or equal to 2T; for example it performs the concatenation of 3 times the key K QK D_ I : KQK D_ IIK QK D_ IIK QK D_ I ; - the sequence of bases, {bases} BO b is encrypted according to the key K QK D_ I, but distinctly and independently (at the level of each bit) with respect to {bases} A | ice ; for example, a function i ' combining permutation and concatenation is applied to the key K QK D_ I to generate an encryption key of size greater than or equal to 2T; for example it performs a permutation (P) of the bits in K QK D_ I then a concatenation of 3 times the permuted key: P(KQKD_ I) IP(KQKD_ I) IP(KQKD_ I); - the sequence of parities is for example encrypted with the same encryption key as for the sequence {bases} A | ice .

[0142] After the construction of K QK D_ 2, the K key QK D_2 is used to encrypt a second useful message, M_2, exchanged between D_ALICE 10 and D_BOB 20.

[0143] We proceed similarly to generate the third secret key K QK D_ 3, this time using concatenations of the first secret QKD keys K QK D_ I and K QK D_2 to perform the encryption of the base choices and parity values.

[0144] After the generation of K QK D_3, we move to steady state.

[0145] Referring now to Figure 5, we are interested in the generation of the key K QK D_ N in one embodiment of the invention, with N greater than or equal to 4, the previously generated QKD keys being stored by D_ALICE 10 and D_BOB 20.

[0146] During the K generation process QK D_ N in an embodiment of the invention, sequentially: a set of the last secret keys shared by D_ALICE 10 and D_BOB 20 (here the last 3 K QK D_ N-3, K QK D_ N-2, and K QKD_ NI) is for example used to construct, by concatenation, encryption keys of sufficient size to (decrypt the binary information sequences relating to the bases used by D_ALICE, by D_BOB, and to encrypt the parities; a permutation on the keys concatenated by D_BOB with respect to D_ALICE is carried out in order to hide from Eve which qubits are retained / discarded during sifting: thus for example in this case, the symmetric encryption key used to decrypt Alice's {bases} (and the parity bits) is K QK D_N-I IK QK D_N-2 | K QK D_ N-3 while the symmetric encryption key used to (de-)encrypt {bases} BO b is KQKD_N-2 | KQKD_N-3 | KQKD_N-1

[0147] Then the K key QK D_N is used to encrypt an Nth useful message, M_N, exchanged between D_ALICE 10 and D_BOB 20.

[0148] We iterate to generate successive secret keys.

[0149] Only the useful message carries meaning. The other sequences are independent and random at the bit level.

[0150] The protection of information exchanged during reconciliation (choice of bases used, selection of qubits retained, parities) is improved by using a larger number of prior secret keys. Figures 4 and 5 show the use of up to 3 prior keys to develop any new QKD key. The principle is naturally transposable to the use of any number of prior keys to encrypt the different sequences during reconciliation.

[0151] Considering, in an exemplary implementation of the invention, on the one hand a random sequence of bits to be encrypted indicating the basic choice information or the selection of the qubits retained, or even the parity bits and on the other hand an encryption key of size (in number of bits) greater than the sequence to be encrypted, an example of encryption by the cryptography block 110, 210 of the sequence with the encryption key is to perform an EXCLUSIVE OR operation between the bit of the sequence of rank n and the bit of rank n of the encryption key, for all n ranging from 1 to the size of the sequence.

[0152] Generally speaking, all QKD protocols have in common the fact of implementing reconciliation and error correction processes to generate two identical keys from raw keys (qubits transmitted on the quantum channel). The invention proposed here is applicable to all QKD protocols, regardless of the coding mode (e.g. by polarization / phase / ...) and the variants of these protocols.

[0153] In particular, the invention has been described above with reference to the implementation of the transmission of random binary information by the polarization of photons, for example in the context of the BB84 protocol; the invention is however applicable to any protocol (e.g.: E91, B92, etc.) and system for generating symmetric keys of the QKD type, among others QKD protocols with discrete variables, with other physical parameters used for encoding bits on qubits, for example the frequency or phase of a photon, optionally differentially (frequency-coded QKD or phase-coded QKD or Differential Phase-coded QKD; in the case of using phase, the coding relies on a phase modulator instead of a rotator / polarization modulator) instead of or in addition to the polarization of the photons, protocols using continuous variables (GG02), and / or using the transmission of several photons per light pulse...

[0154] Similarly, even if an example of coding a single bit per photon has been considered above, the invention also applies in the case where a parameter of the photon transmitted on the quantum channel codes several bits, based for example on protocols making it possible to code several bits per light pulse such as the GG02, GMCS Gaussian Modulated Coherent-States protocols.

[0155] In the exemplary embodiment described above, the encryption is implemented on the sequences for choosing the bases, on the sequences for selecting the retained qubits and the sequences of parity values; in embodiments, only the sequences for choosing the bases or for selecting the retained qubits or only the sequences of parity values ​​are encrypted.

[0156] Furthermore, the invention can also be implemented in embodiments without random choice of base used in reception and / or transmission, such as for example in a Differential Phase-coded QKD protocol; the step of correcting residual errors is then nevertheless still necessary.

[0157] The invention can also be implemented in embodiments where the QKD protocol employed uses the polarization of the photons to encode the bits, but with a number of states considered different from the four states considered in BB84: for example BB92 uses 2 polarizations, SSP uses 6.

[0158] The steps incumbent on the control block 11, 21 described above may be implemented by executing software instructions on a processor. Alternatively, they may be implemented by dedicated hardware, typically a digital integrated circuit, either specific (ASIC) or based on programmable logic (e.g. FPGA / Field Programmable Gate Array).

[0159] The term “bit” designates the binary information itself (“0” or “1”), the term “qubit” designates more specifically this binary information when it is carried by a quantum state of an elementary particle, in particular of a photon (i.e. generation and polarization in the device 10, propagation in the quantum channel and measurement in the device 20); however, in the preceding description, one or other of the two terms may have been used indistinctly to designate the corresponding binary information.

[0160] It should be noted that the random choice of the polarization base, both in transmission and in reception, can be achieved in different ways: as described below, with a polarization modulator or by mechanical switching of a polarization rotator controlled by a quantum randomness generator, a beam splitter such as a semi-reflecting plate, a fixed polarization rotator such as a half-wave plate, etc. according to known techniques.

[0161] Furthermore, in embodiments, the implemented QKD protocol is based on entanglement (e.g. E91 protocol) for which the photons are generated by a source that may be external to D_ALICE and D_BOB. In this case, D_ALICE does not generate the binary sequence: D_ALICE and D_BOB receive this sequence and are like 2 receivers that agree with each other on the decoding of the received qubit sequence, with random base choices (A and B) (or not), in accordance with steps 102 and following described above.

Claims

CLAIMS Quantum key distribution method, named K QK D_N, to a first and a second telecommunication device (D_ALICE, D_BOB) to implement between them a telecommunication encrypted by said key K QK D_N, said first and a second telecommunication devices (D_ALICE, D_BOB) each being connected to a respective first telecommunication link (30) and connected to each other by a second telecommunication link (40), said first link (30) being an optical transmission link and being hereinafter called quantum channel, said second telecommunication link (40) being hereinafter called classical channel; said method comprising the following steps of determining K QKD_N, implemented by at least one device considered among the first and second devices: implementation, on the quantum channel (30), of a communication of a random sequence of bits in the form of a sequence of light pulses in quantum regime such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by each of the first and second devices;implementing, on the conventional channel (40), a communication, between the first and second devices, of information indicating parity bit values, said parity bit values ​​having been calculated by at least one of said first and second devices as a function of the random sequence of bits that it has memorized, then being transmitted, during said communication, to the other of said first and second devices which then implements, in the sequence of bits memorized by the other of said first and second devices, an error correction, as a function of said transmitted parity bits; determining said key K; QK D_N, based on said random sequence of bits, and storing said key K QKD_N, said key being shared between said first and a second device; said method being characterized in that said communication of information indicating parity bit values ​​between the first and the second device is encrypted or decrypted by said device considered according to at least one key KQ K D_N-K previously determined by prior implementation of a quantum key distribution mechanism QKD to said first and second devices. Quantum key distribution method, named K QK D_N, to a first and a second telecommunication device (D_ALICE, D_BOB) to implement between them a telecommunication encrypted by said key K QKD_N, said first and a second telecommunication devices (D_ALICE, D_BOB) each being connected to a respective first telecommunication link (30) and connected to each other by a second telecommunication link (40), said first link (30) being an optical transmission link and being hereinafter called quantum channel, said second telecommunication link (40) being hereinafter called classical channel; said method comprising the following steps of determining K QKD_N, implemented by at least one device considered among the first and second devices: implementation, on the quantum channel (30), of a communication of a random sequence of bits in the form of a sequence of light pulses in quantum regime such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by each of the first and second devices;implementing, on the conventional channel (40), a communication, between the first and second devices, of information relating to bases, indicating, for each bit of the stored sequence, the base, among at least two distinct bases of coding between values ​​of said parameter and the values ​​0 or 1 of a bit of the random sequence of bits, that at least one of the first and second devices has randomly selected to carry out the coding between the bit and the value of said light pulse parameter; selection, by said device, of those bits of the random sequence of bits for which the first and second devices have selected the same bases;implementing, on the conventional channel (40), a communication, between the first and second devices, of information indicating parity bit values, said parity bit values ​​having been calculated by at least one of said first and second devices as a function of said selected bits, then being transmitted, during said communication, to the other of said first and second; devices which then implement error correction, based on said transmitted parity bits, on the bits selected by the other of said first and second devices; determination of said key K QK D_N, depending on the selected bits and error correction, and storing said key K QKD_N, said key being shared between said first and a second device; said method being characterized in that said communication of information relating to said bases between the first and the second device (D_ALICE, D_BOB) is encrypted or decrypted by said device considered according to at least one key K Q KD_N-K previously determined by prior implementation of a quantum key distribution mechanism QKD to said first and second devices. Quantum key distribution method, according to claim 2, wherein said communication of information indicating parity bit values ​​between the first and second devices (D_ALICE, D_BOB) is further encrypted or decrypted by said device in question according to at least one key KQ KD_N-K previously determined by implementing a previous iteration of a QKD quantum key distribution method to said first and second devices. Quantum key distribution method, according to one of the preceding claims, wherein the encryption or decryption of the information is carried out according to a symmetric encryption or decryption key determined by operations of the concatenation and permutation type and / or logical combination at the bit level of at least one key previously determined by QKD quantum key distribution to said first and second devices (D_ALICE, D_BOB). Quantum key distribution method, according to one of the preceding claims, wherein said information used for QKD reconciliation is encrypted or decrypted according to at least the key KQ KD_N-K previously determined are random and independent information. Computer program, intended to be stored in the memory of a telecommunications device (D_ALICE, D_BOB) further comprising a microcomputer, said computer program comprising instructions which, when executed on the microcomputer, orchestrate the steps of a method according to one of the preceding claims. Telecommunication device (D_ALICE, D_BOB), adapted to be connected to a first telecommunication link (30), adapted to be connected to another telecommunication device ((D_ALICE, D_BOB) by a second telecommunication link (40), and to implement with said other device a telecommunication encrypted by a Key KQKD_N, said first link (30) being an optical transmission link and being hereinafter called quantum channel, said second telecommunication link (40) being hereinafter called classical channel; said device being adapted to determine K QKD_N, by: implementing, on the quantum channel (30), a communication of a random sequence of bits in the form of a sequence of light pulses in quantum mode such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by the device;by putting, on the conventional channel (40), a communication with the other device, of information indicating parity bit values, said parity bit values ​​having been calculated by at least a first device among said device and said other device according to the random sequence of bits that it has memorized, then being transmitted, during said communication, to the second among said device and said other device which then implements, in the sequence of bits memorized by the other of said first and second devices, an error correction, according to said transmitted parity bits; by determining said key K; QK D_N, based on said random sequence of bits, and storing said key K QKD_N, said key being shared between said device and said other device; said device (D_ALICE, D_BOB) being characterized in that said communication of information indicating parity bit values ​​between said device and said other device is encrypted or decrypted by said device according to at least one key KQKD_N-K previously determined by prior implementation of a QKD quantum key distribution mechanism to said device and said other device (D_ALICE, D_BOB). Telecommunication device (D_ALICE, D_BOB) adapted to be connected to a first telecommunication link (30), adapted to be connected to another telecommunication device (D_ALICE, D_BOB) by a second telecommunication link (40), and to implement with said other device a telecommunication encrypted by a Key KQKD_N, said first link (30) being an optical transmission link and being hereinafter called quantum channel, said second telecommunication link (40) being hereinafter called classical channel; said device being adapted to determine K QKD_N, by: implementing, on the quantum channel (30), a communication of a random sequence of bits in the form of a sequence of light pulses in quantum regime such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being memorized by the device; by putting, on the conventional channel (40), a communication with the other device, of information indicating, for each bit of the memorized sequence, the base, among at least two distinct bases of coding between values ​​of said parameter and the values ​​0 or 1 of a bit of the random sequence of bits, that a first device among said device and said other device has randomly selected to carry out the coding between the bit and the value of said light pulse parameter;by selecting those bits of the random sequence of bits for which said device and said other device have selected the same bases; by implementing, on the conventional channel (40), a communication, between said device and said other device, of information indicating parity bit values, said parity bit values ​​having been calculated by a first device among said device or said other device as a function of said selected bits, then being transmitted, during said communication, to the second device among said device and said other device which then implements an error correction, as a function of said transmitted parity bits, on the bits selected by the second device among said device and said other device; determining said key K; QK D_N, depending on the selected bits, and storage of said key K QKD_N, said key being shared between said device and said other device; said device being characterized in that said communication of information relating to said bases between said device and said other device (D_ALICE, D_BOB) is encrypted or decrypted by said device based on at least one key K Q KD_N-K previously determined by prior implementation of a quantum key distribution mechanism QKD to said device and said other device. Telecommunication device (D_ALICE, D_BOB) according to claim 8 wherein said communication of information indicating parity bit values ​​between said and said other device (D_ALICE, D_BOB) is further encrypted or decrypted by said device based on at least one key KQ KD_N-K previously determined by prior implementation of a quantum key distribution QKD to said device and to said other device (D_ALICE, D_BOB). Telecommunication device (D_ALICE, D_BOB) according to one of claims 7 to 9, wherein the encryption or decryption of the information is carried out according to a symmetric encryption or decryption key determined by operations of the concatenation and permutation type and / or logical combination at the bit level of at least one key previously determined by quantum key distribution QKD to said device and to said other device (D_ALICE, D_BOB).