Quantum distribution method and associated telecommunications devices
By encrypting parity bit values and basis information using a previously generated secret key, the method addresses information leakage in QKD protocols, enhancing the secrecy and security of the shared key.
Patent Information
- Application Number
- FR2022013411
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-12-15
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2042-12-15
AI Technical Summary
Existing quantum key distribution (QKD) protocols suffer from information leakage on the public channel during the reconciliation phase, compromising the secrecy of the shared key due to the transmission of basis choices and parity information, which can be exploited by an eavesdropper.
Implementing a quantum key distribution method where the communication of parity bit values and basis information is encrypted using a previously generated secret key via the quantum channel, ensuring that only the legitimate parties, Alice and Bob, have access to this sensitive information, thereby reducing information leakage.
The proposed solution enhances the secrecy of the shared key by preventing eavesdroppers from accessing the choice of bases and parity information, significantly reducing the risk of information leakage and ensuring unconditional security against computational attacks.
Smart Images

Figure 00000037_0000 
Figure 00000038_0000 
Figure 00000039_0000
Abstract
Description
Title of the invention: Quantum distribution methods and associated telecommunications devices Technical field
[0001] The invention lies in the field of generating and sharing a symmetric secret key between two remote telecommunications devices associated with their respective users, hereinafter called Alice and Bob: the devices of Alice and Bob must use a strictly identical key to be able to encrypt / decrypt their messages. The invention relates more particularly to quantum key distribution (QKD: Quantum Key Distribution) and the underlying communication of information such as parity bits or choice of bases used or selection of the measures retained. Prior art
[0002] Quantum cryptography relies on the transmission of qubits (quantum bits) or randomly generated coherent states, to develop and distribute secret keys usable by classical encryption protocols such as one-time pad encryption. Since the first protocol proposed in 1984 (BB84), multiple QKD protocols have been defined. A distinction is made between protocols with discrete variables (qubits, DV-QKD) and those with continuous variables (CV-QKD). Some protocols (BB84, DV-QKD) rely on random choices of a basis (or quadrature) for generation and measurement, and involve the communication of these basis choices. Other protocols (CV-QKD with heterodyne receiver) do not involve communications on the choice of a measurement basis. Some protocols based on photon entanglement involve a photon source external to Alice and Bob's devices.But all QKD protocols integrate a residual error correction step to develop a shared key between Alice and Bob, implementing the communication of parity bits, for various error detection or correction techniques (FEC (Forward Error Correction code) codes such as LDPC (Low Density Parity Code), interactive and iterative protocols such as Cascade or Winnow, etc.). For illustration purposes, we will subsequently refer to the BB84 protocol.
[0003] During a quantum cryptography protocol, the two remote interlocutors Alice and Bob have: - quantum objects, that is, physical objects that behave according to the laws of quantum physics; in practice, these objects are light pulses in the quantum regime (photons), which can take several forms: single photons, coherent states, pairs of entangled photons, etc.; the photon, allows the encoding of information on observable variables such as the polarization of light, its frequency, its phase etc.; - a quantum channel, which allows the transit of light pulses; - a classic channel (also called a public channel) of communication (typically Internet, radio, optical transmission over fiber or in free space).
[0004] Quantum Key Distribution (QKD) is a technique that exploits quantum properties to guarantee randomness to detect the interception and re-transmission by a malicious third party, let's call it Eve (Eavesdropper), of an initial message generated by Alice to Bob. Since it is impossible to clone unknown quantum information without destroying it, or to measure an unknown quantum state without modifying it, the reading of qubits during their transmission between two interlocutors wishing to encrypt their communications with a secret key derived from these qubits by an intruder can be immediately detected: an interception will be immediately detected by Alice's and Bob's devices, which will give up this key.
[0005] A reference QKD technique is the BB84 protocol published by C. Bennett and G. Brassard in 1984 and using discrete variables: qubits. A qubit takes a value of 0 or 1, and is represented by the polarization of a single photon, on two possible quadratures (bases): H / V or D / A (the capital letter H, V, D, A indicates the type of polarization: H for horizontal, V for vertical, D for diagonal and A for Antidiagonal).
[0006] The main steps of quantum key distribution are as follows: - Alice's device generates a sequence of random bits and encodes each bit on each light pulse, then transmits it to Bob's device through the quantum channel. - This then measures the information carried by the impulse it received. - Alice and Bob's devices evaluate a level of interception of information exchanged on the quantum channel based on the differences between the data transmitted and those measured and if the level is higher than a fixed threshold, the quantum distribution operation is terminated. - If not, the extraction of the secret key from the correlated data is carried out via a so-called data reconciliation step: in this reconciliation step, a bit string shared by Alice and Bob's devices is determined from the correlated data and an error correction algorithm implementing parity bits. - A secrecy amplification step is generally implemented to neutralize the information leak during reconciliation.
[0007] For each qubit (0 / 1) of a series of qubits randomly generated by Alice's device, the latter generates on the quantum channel a photon whose polarization depends on the random choice of a quadrature (H / V or D / A) and the binary value considered (0 / 1).
[0008] At the other end of the quantum channel, on the receiving side, Bob's device randomly selects, for each qubit, a quadrature to perform the detection (either on H / V or on D / A). Any qubit measured on the same quadrature as the quadrature used for transmission is normally correctly transmitted: 100% to within e, (typically the value of e is in the range [0; 10%]. When the Tx / Rx quadratures are not identical, the transmission is false with a probability of 50% to within e.
[0009] After the transmission, Bob's device therefore has a set of measurements which are correlated with the data sent by Alice's device, but whose information could have been spied on by Eve.
[0010] Then the so-called reconciliation phase takes place using only the classic communication channel, where: - a so-called sifting step selects the transmitted qubits for which Alice's and Bob's devices use the same generation and detection quadrature: to do this, Alice's and Bob's devices communicate in clear on the classical channel to broadcast the quadratures used, either symmetrically and explicitly, or asymmetrically with one party broadcasting its used quadratures then the other party determining and broadcasting the selection of the selected qubits (identical Tx / Rx quadratures); this makes it possible to develop two versions of a so-called "sifted key" respectively on the Alice and Bob sides, by discarding on average 50% of the qubits (different Tx / Rx quadratures); - an estimate of the error rate is made, to determine the possible presence of Eve (case of key rejection), and to select an error-correcting code (choice of code and yield) or to configure an interactive and iterative error-correcting protocol by request / response for the rest of the processing; - a step of detection and correction of residual errors comprising exchanges on the classic channel of parity bits calculated by the devices of Alice and / or Bob on their respective "sifted key" then takes place (Cascade or Winnow protocol, FEC LDPC error correcting code, etc.), following which the devices of Alice and Bob share a strictly identical key, for which Eve has certain information.
[0011] Alice and Bob's devices then share a secret key (after an additional secret amplification step). The notion of "shared key" means that the key is common to Alice and Bob.
[0012] The dissemination on the public channel of the information shared between Alice and Bob's devices ("side information") concerning the values of the parity bits and the choices of the bases used (or possibly relating to the selection of the qubits which are kept), during the reconciliation phase, constitutes a harmful leak of information likely to favor Eve in her search for the key. This disclosure goes against the secrecy of the key, and requires a secret amplification process, at the cost of a reduction in the size of the key.
[0013] Indeed, knowing the choice of bases used for each qubit, Eve knows which qubits are reliable (to within 1-e) among those she has measured. From the reliable qubits, and knowing the (reliable) parity values and the residual error correction method, Eve can deduce values of other qubits, either in terms of value or in terms of probability. In all cases, this information broadcast on the public channel makes it possible to reduce the combinatorics of key exploration for Eve. The only known countermeasure is the secret amplification treatment, implementing hash functions to combine the elements of the key, at the cost of a reduction in the key size.
[0014] There is therefore a need for a quantum key distribution solution that can better preserve secrecy and reduce the risk of information leaking onto the public channel. Summary of the invention
[0015] Thus, according to a first aspect, the present invention describes a method for quantum key distribution, named Kqkd N to a first and a second telecommunication device to implement between them a telecommunication encrypted by said key Kqkd_n,
[0016] said first and second telecommunications devices each being connected to a respective first telecommunications link and connected to each other by a second telecommunications link,
[0017] said first link being an optical transmission link and being hereinafter called quantum channel, said second telecommunications link being hereinafter called classical channel;
[0018] said method comprising the following steps of determining KQKd_n, implemented by at least one device considered among the first and second devices: - implementing, on the quantum channel, a communication of a random sequence of bits in the form of a sequence of pulses light in quantum regime such that for each light pulse of the pulse sequence, a physical parameter of each light pulse encodes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by each of the first and second devices; - implementation, on the conventional channel, of a communication, between the first and second devices, of information indicating parity bit values, said parity bit values having been calculated by at least one of said first and second devices as a function of the random sequence of bits that it has memorized, then being transmitted, during said communication, to the other of said first and second devices which then implements, in the sequence of bits memorized by the other of said first and second devices, an error correction, as a function of said transmitted parity bits; - determining said key Kqkdn based on said random sequence of bits, and storing said key KQKd_n, said key being shared between said first and a second device; said method being characterized in that said communication of information indicating parity bit values between the first and second devices is encrypted or decrypted by said device considered according to at least one key Kqkd n_ k previously determined by prior implementation of a quantum key distribution mechanism QKD to said first and second devices.
[0019] The proposed solution greatly reduces information leakage and improves the level of secrecy. There is no transmission in clear (or with public key encryption) of choice of bases used, and / or information relating to parities on the public channel. This sensitive information is previously encrypted from at least one secret key previously generated by QKD via the quantum channel and the classical channel in a previous step.
[0020] The use of a key obtained by QKD guarantees unconditional security relative to the computing power of a third party (Eve).
[0021] Eve cannot access the information on the choice of bases used (jointly by Alice and Bob's devices) and on the selection of the qubits retained, nor the information relating to the parity bits. Because if Alice and Bob's devices share these previously generated secret keys and can therefore encrypt / decrypt the messages carrying the information on the choice of bases, the selection of qubits and on the parities, this is not the case for Eve.
[0022] This makes it possible to greatly reduce the leakage of information on the key.
[0023] Eve has a sequence of qubits without being able to identify which are correct (on average 75% of the sequence) and which are retained to form the key.
[0024] According to a second aspect, the present invention describes a method for quantum key distribution, named Kqkd_n, to a first and a second telecommunication devices to implement between them a telecommunication encrypted by said key KQKd_n,
[0025] said first and second telecommunication devices each being connected to a respective first telecommunication link and connected to each other by a second telecommunication link,
[0026] said first link being an optical transmission link and being hereinafter called quantum channel, said second telecommunications link being hereinafter called classical channel;
[0027] said method comprising the following steps of determining Kqkd_n, implemented by at least one device considered among the first and second devices:
[0028] implementing, on the quantum channel, a communication of a random sequence of bits in the form of a sequence of light pulses in quantum regime such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by each of the first and second devices;
[0029] implementation, on the conventional channel, of a communication, between the first and second devices, of information relating to bases, indicating, for each bit of the stored sequence, the base, among at least two distinct bases of coding between values of said parameter and the values 0 or 1 of a bit of the random sequence of bits, that at least one of the first and second devices has randomly selected to carry out the coding between the bit and the value of said light pulse parameter;
[0030] selection, by said device, of those bits of the random sequence of bits for which the first and second devices have selected the same bases;
[0031] implementing, on the conventional channel, a communication, between the first and second devices, of information indicating parity bit values, said parity bit values having been calculated by at least one of said first and second devices as a function of said selected bits, then being transmitted, during said communication, to the other of said first and second devices which then implements an error correction, as a function of said transmitted parity bits, on the bits selected by the other of said first and second devices;
[0032] determining said key Kqkd N as a function of the selected bits and the error correction, and storing said key KQKd_n, said key being shared between said first and a second device;
[0033] said method being characterized in that said communication of information relating to said bases between the first and the second device is encrypted or decrypted by said device considered as a function of at least one key Kqkd n_ k previously determined by prior implementation of a quantum key distribution mechanism QKD to said first and second devices.
[0034] In embodiments of such a method, said communication of information indicating parity bit values between the first and second devices is further encrypted or decrypted by said device in question based on at least one key KQkd N previously determined by implementing a prior iteration of a quantum key distribution method QKD to said first and second devices.
[0035] In embodiments of a method according to the first aspect or the second aspect of the invention, at least one of the following arrangements is implemented:
[0036] - the encryption or decryption of information is carried out according to a symmetric encryption or decryption key determined by concatenation and permutation type operations and / or logical combination at bit level of at least one key previously determined by quantum key distribution QKD to said first and second devices;
[0037] - said information used for QKD reconciliation encrypted or decrypted in function of at least the key KQKD_Nk, which is determined internally is random and independent information.
[0038] According to a third aspect, the invention describes a computer program intended to be stored in the memory of a telecommunications device and further comprising a microcomputer, said computer program comprising instructions which, when executed on the microcomputer, orchestrate the steps of a method according to the first or second aspect of the invention.
[0039] According to a fourth aspect, the invention describes a telecommunications device adapted to be connected to a first telecommunications link, adapted to be connected to another telecommunications device by a second telecommunications link, and to implement with said other device a telecommunication encrypted by a key KQKd_n,
[0040] said first link being an optical transmission link and being hereinafter called quantum channel, said second telecommunication link being hereinafter called classical channel; said device being adapted to determine Kqkd_n> in:
[0041] by implementing, on the quantum channel, a communication of a random sequence of bits in the form of a sequence of light pulses in quantum regime such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by the device;
[0042] by placing, on the conventional channel, a communication with the other device, of information indicating parity bit values, said parity bit values having been calculated by at least a first device among said device and said other device as a function of the random sequence of bits that it has memorized, then being transmitted, during said communication, to the second among said device and said other device which then implements, in the sequence of bits memorized by the other of said first and second devices, an error correction, as a function of said transmitted parity bits;
[0043] by determining said key KQKD N based on said random sequence of bits, and storing said key KQKd_n, said key being shared between said device and said other device;
[0044] said device being characterized in that said communication of information indicating parity bit values between said device and said other device is encrypted or decrypted by said device according to at least one key Kqkd n_ k previously determined by prior implementation of a quantum key distribution mechanism QKD to said device and to said other device.
[0045] According to a fifth aspect, the invention describes a telecommunications device adapted to be connected to a first telecommunications link, adapted to be connected to another telecommunications device by a second telecommunications link, and to implement with said other device a telecommunication encrypted by a key KQKD_N,
[0046] said first link being an optical transmission link and being hereinafter called quantum channel, said second telecommunication link being hereinafter called classical channel; said device being adapted to determine Kqkd_n> in: - implementing, on the quantum channel, a communication of a random sequence of bits in the form of a sequence of light pulses in quantum mode such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by the device; - by putting, on the conventional channel, a communication with the other device, of information indicating, for each bit of the stored sequence, the base, among at least two distinct bases of coding between values of said parameter and the values 0 or 1 of a bit of the random sequence of bits, that a first device among said device and said other device has randomly selected to carry out the coding between the bit and the value of said light pulse parameter; - by selecting those bits of the random sequence of bits for which said device and said other device have selected the same bases; - by implementing, on the conventional channel, a communication, between said device and said other device, of information indicating parity bit values, said parity bit values having been calculated by a first device among said device or said other device as a function of said selected bits, then being transmitted, during said communication, to the second device among said device and said other device which then implements an error correction, as a function of said transmitted parity bits, on the bits selected by the second device among said device and said other device; - determination of said key KQKDN as a function of the selected bits, and storage of said key KQKd_n, said key being shared between said device and said other device; said device being characterized in that said communication of information relating to said bases between said device and said other device is encrypted or decrypted by said device according to at least one key KQKD_Nk previously determined by prior implementation of a quantum key distribution mechanism QKD to said device and to said other device.
[0047] In embodiments, a telecommunications device according to the fifth aspect of the invention is adapted to encrypt or decrypt said communication of information indicating parity bit values between said and said other device according to at least one key KQkd_n^previously determined by prior implementation of a quantum key distribution QKD to said device and said other device.
[0048] In embodiments, a telecommunications device according to the fourth or fifth aspect of the invention is adapted to carry out the encryption or decryption of information according to a symmetric encryption or decryption key determined by operations of the concatenation and permutation type and / or logical combination at the bit level of at least one key previously determined by quantum key distribution QKD to said first and second devices (D_ALICE, D_B0B). Brief description of the drawings
[0049] The invention will be better understood and other characteristics, details and advantages will appear more clearly on reading the following description, given without limitation, and thanks to the appended figures, given by way of example.
[0050] [Fig-1] [Fig.l] schematically represents a QKD key generation system in one embodiment of the invention;
[0051] [Fig.2] [Fig.2] represents the steps of a quantum key distribution method in one embodiment of the invention;
[0052] [Fig.3] [Fig.3] illustrates the transmission and detection of a sequence of qubits in one embodiment of the invention;
[0053] [Fig.4] [Fig.4] is a table illustrating the implementation of a method in one embodiment of the invention, at startup;
[0054] [Fig.5] [Fig.5] is a table illustrating the implementation of a method in one embodiment of the invention, in steady state;
[0055] Identical references may be used in different figures when they designate identical or comparable elements. Description of the embodiments
[0056] [Fig.l] represents a system for generating a symmetric key by QKD in one embodiment of the invention, comprising two telecommunication devices 10, 20 connected to each other by a quantum channel 30 and a conventional channel 40. Each or one of the telecommunication devices 10, 20 is for example on the ground, or on board a satellite, an aircraft, etc.
[0057] The quantum channel 30 is a telecommunications channel which allows the transit of information (binary in DV-QKD or continuous in CV-QKD) carried by a physical property of a quantum object (e.g.: polarization of a photon) transmitted on this channel; here the quantum channel 30 is adapted to transmit light pulses (generated by a photon source, the transmission being carried out on an optical link of the optical fiber type or simply by free propagation in the open air, the atmosphere, Space, etc.).
[0058] The classic channel 40 is a communication channel, for example a standard one (e.g. radio frequency link, internet network, optical fiber, etc.), assumed to be accessible in clear by all (including a malicious third party Eve), to allow the telecommunications devices 10 and 20 to converge towards the definition of a secret key on the basis of transmitted qubits, as described below for the BB84 protocol.
[0059] The telecommunications device 10, hereinafter called D_ALICE, of user Alice, comprises a control block 11, a quantum transmission block 12, a radiofrequency (RF) transmission / reception block 13 and a memory 14. The control block 11 comprises a cryptography block 110 and a memory 111 associated with the cryptography block 110 and storing secret keys previously generated by QKD method between D_ALICE 10 and D_BOB 20.
[0060] The telecommunications device 20, hereinafter called D_BOB, of user Bob, comprises a control block 21, a quantum reception block 22, a radio frequency (RF) transmission / reception block 23 and a memory 24. The control block 21 comprises a cryptography block 210 and a memory 211 associated with the cryptography block 210 and storing secret keys previously generated by QKD between D_ALICE 10 and D_BOB 20.
[0061] The radio frequency (RF) transmit / receive blocks 13 and 23 are adapted to communicate together via the conventional channel 40.
[0062] The control block 11, respectively 21, comprises for example a memory and a microprocessor (not shown). In one embodiment, the memory of the control block 11, respectively 21, comprises software instructions, which when executed on the microprocessor of the control block 11, respectively 21, implement the steps incumbent on the control block 11, respectively 21, and described later, in particular with reference to [Fig. 2].
[0063] The radio frequency (RF) transmission / reception block 13, respectively 23, typically comprises a modem and a radio frequency transmission and reception antenna (not shown).
[0064] The quantum emission block 12 comprises a generation block, named GEN 121, and a polarization block, named Pol 122.
[0065] The GEN 121 block is adapted to randomly generate a sequence of bits to be transmitted.
[0066] The Pol 122 block is adapted to randomly choose, for each bit to be transmitted, a base from a set of bases comprising several reference polarization bases (these bases are also called modes or quadratures) and to transmit a light pulse with a polarization corresponding to the value of the bit to be transmitted in the base chosen randomly for this bit.
[0067] The Pol 122 block comprises, for example, a polarization rotator, capable of rotating the polarization of the emitted light signal, selectively by 0° (if the H / V base is chosen by the Pol 132 block) or by 45° (if the D / A base is chosen), the selection between the 0° and 45° angles being carried out randomly. For example, the polarization rotator is produced with a half-wave retardation plate whose rotation is ensured by an actuator. Another embodiment uses an electro-optical polarization modulator, suitable for high rates of polarization change.
[0068] The set of bases, in the present case, includes two bases for example: - a first Horizontal / Vertical (H / V) base in which "1" is coded by a photon with a 0° polarization axis and "0" by a 90° polarization photon; - a second Diagonal / Antidiagonal (D / A) base in which "0" is encoded by a photon with a 45° polarization axis and "1" by a photon with a 135° polarization axis.
[0069] The quantum reception block 22 comprises a polarization block, named Pol 132, and a measurement block 131.
[0070] Before the expected arrival of a photon, the Pol 132 block is adapted to perform a polarization rotation in order to randomly choose a base from the two H / V and D / A bases. The Pol 132 block comprises a polarization rotator, capable of rotating the polarization of the emitted light signal, selectively by 0° (if the H / V base is chosen by the Pol 132 block) or by 45° (if the D / A base is chosen). For example, the polarization rotator is produced with a half-wave delay plate whose rotation is ensured by an actuator.
[0071] The measuring block 131 is adapted to measure two light polarization components in quadrature at the output of the polarization rotator Pol 132, either on the H / V basis if the polarization rotation is 0°, or on the D / A basis if the polarization rotation is 45°. For example, the measuring block is produced with a polarizing beam splitter (PBS) generating a quadrature, and two photon detectors (SPD) for the two components of the quadrature.
[0072] It is recalled here that a photon can be polarized along any axis. A photon polarized along an axis of angle 'a' passing through a polarizing filter along an axis of angle 'b' has a probability equal to cos2(ba) of passing the polarizing filter, according to Malus's law.
[0073] According to the quantum properties used by quantum cryptography: - when the probability of passing the filter is neither 0 nor 1, the passage of an individual photon through the filter is fundamentally unpredictable and indeterministic; - the polarization axis can only be known by using a polarizing filter (or more generally, by making a measurement whose result is YES or NO) and with a large number of measurements to estimate the probability of passage; there is no direct measurement on an individual photon, giving an angle for example, of the polarization axis of the photon.
[0074] The steps of a QKD method according to the invention are now described with reference to [Fig.2].
[0075] The starting context is as follows: Alice wishes to exchange an Nth message, named M_N, with Bob. To do this, a secret key, Kqkd_n, must be generated by QKD, shared between D_ALICE 10 and D_BOB 20, to allow one to encrypt, and the other to decrypt this Nth message which can be transmitted with maximum security. For her part, Eve attempts to intercept the communications to determine the key. In accordance with Kerckhoff's principles (worst case hypothesis), we assume for example that Eve has access to the communication channels used by D_ALICE 10 and D_BOB 20, that she knows the protocol used perfectly and has unlimited computing resources. The security of the encrypted communications between D_ALICE 10 and D_BOB 20 is then ensured solely by the secret key that the method described below results in generating and distributing.
[0076] QUANTUM PHASE
[0077] Generally, only this phase uses the quantum channel, the post-processing phase does not use it.
[0078] Step 101
[0079] In this step 101:
[0080] - in response to a corresponding command from control block 11 to block GEN 121, the GEN 121 block randomly generates a sequence of 2T bits therefore taking the value 0 or 1; T is an integer typically greater than 10000;
[0081] - following the reception of a respective command from the control block 11 to the block Pol 122, the Pol 122 block randomly chooses, for each generated bit, a polarization base from among the two polarization bases and emits on the quantum channel 30, photon by photon, a photon whose polarization is a function of the value of the generated bit and the polarization base chosen for this qubit; each photon is emitted at regular intervals. The qubits are thus transmitted.
[0082] The sequence of choices of bases and bits corresponding to the sequence of qubits generated is then stored by the control block 11 in the memory 14 and the value of each bit is stored there, associated with the polarization base chosen for the bit by the Pol block 122 and with the rank of the bit in the sequence and.
[0083] Step 102
[0084] Under the control of the control block 21, before the expected arrival of each photon, the Pol block 132 randomly chooses a base (by modifying the orientation of a rotator or by modifying the control of a polarization modulator). At the expected time of arrival of a photon, under the control of the control block 21, the measurement block 131 performs a measurement of what comes out of the polarizing filter on the selected components. The control block 21 determines the value of the bit corresponding to the photon detected according to the measurement carried out and the basis chosen for the measurement (corresponding to the polarization rotation carried out by the Pol 132 block) and stores in the memory 24, for each photon detected, the value of the bit determined, in association with the basis chosen and the reception rank of the photon (and therefore of the qubit).
[0085] [Fig.3] represents in a table, the rank number of the first 8 bits of a sequence generated in step 101 (first line of the table) and the randomly generated value for these bits (second line). These bits thus take the following values: 0 for the bit of rank 1, 4, 6 and 7 and 1 for the bit of rank 2, 3, 5 and 8.
[0086] The third line indicates the base chosen for the emission of each bit by the D_ALICE 10 device: the “+” sign indicates that the H / V base has been chosen while the “x” sign indicates that the D / A base has been chosen. Thus for bits of rank 1, 2, 4 and 8, the H / V base has been chosen, and the D / A base has been chosen for bits of rank 3, 5 to 7.
[0087] The fourth line indicates the polarization of the emitted photon: vertical for the bit of rank 1, 4, horizontal for the bit of rank 2 and 8, diagonal for the bit of rank 6 and 7, antidiagonal for the bits of rank 3 and 5.
[0088] The fifth line of the table indicates the base chosen by the D_BOB 20 device, in reception: H / V for the photon received at rank 1, 5, 7 and 8 and D / A for the photon of rank 2, 3, 4 and 6.
[0089] Finally, the sixth line illustrates the result of the measurement by the device D_BOB 20: for photons of rank 1, 3, 6, 8 the measurement base corresponds to the emission base and the polarization of the detected photon generally corresponds to the polarization at the emission of the photon; for photons of rank 2, 4, 5, 7 the measurement base is different from the emission base and the polarization of the detected photon is totally random. The value of the determined qubit stored in the memory 24 is 0 for the photon of rank 1 and 6 and is 1 for the photon of rank 3 and 8.
[0090] POST-PROCESSING PHASE
[0091] Step 103
[0092] In a step 103:
[0093] - in the controller 21 of the device D_BOB 20, the binary sequence {bases}Bob, which is stored in the memory 24, successively defining the polarization base chosen to detect each photon of the sequence received in step 102 is provided as input to the cryptography block 210; for example, if the set of bases comprises only the two bases H / V and D / A, in the binary sequence indicating the choice of bases, a “0” (respectively a “1”) at rank n of this sequence {bases}Bob will indicate that the base H / V (respectively D / A) was used to detect the qubit of rank n at the step considered (step 102);
[0094] - the cryptography block 210 encrypts using at least one of the secret keys stored in memory 211 and previously generated by QKD by D_ALICE 10 and D_BOB 20, this binary sequence indicating the chosen bases;
[0095] - the controller 21 of the D_BOB device 20 then transmits to the D_ALICE device 10, via the RF transmission / reception block 23, on the conventional channel 40, the binary sequence thus encrypted indicating the polarization base chosen to detect each photon of the sequence received in step 102;
[0096] - the controller 11 of the D_ALICE device 10 receives, via the transmission / reception block RF 13, the encrypted binary sequence {bases]Bob, which is then processed by the cryptography block 110; the latter decrypts it using the secret key(s) stored in the memory 111 which was (were) used for the encryption of this sequence.
[0097] Step 104 (sifting)
[0098] The controller 11 then compares for each rank in the sequence of qubits, the chosen polarization base received on the conventional channel 40 and the polarization base associated with this rank which is stored in the memory 14 of the device 10; it selectively retains (Sifting step) only the qubits which have been generated (D_ALICE 10) and measured (D_BOB 20) on the same base. Statistically only 50% of the bits are retained.
[0099] The list of indexes of only the retained qubits is then provided as input to the cryptography block 110 which encrypts it, using at least one of the secret keys stored in the memory 111 and previously generated by QKD by D_ALICE 10 and D_BOB 20. The controller 11 of the device D_ALICE 10 then transmits to the device D_BOB 20, via the RF transmission / reception block 13, on the conventional channel 40, the list of retained qubits thus encrypted.
[0100] the controller 21 of the D_BOB device 20 receives, via the RF transmission / reception block 23, the encrypted list of retained indexes and provides it to the cryptography block 210; the latter decrypts it using the secret key(s) stored in the memory 211 which was (were) used for the encryption of this sequence.
[0101] The controller 21 of the device D_BOB 20 selectively retains in turn, among all the qubits received in step 102, only the qubits whose index (i.e. the rank in the sequence emitted by D_ALICE / received by D_BOB) is indicated in the received list, which are the qubits generated (D_ALICE 10) and measured (D_BOB 20) on the same basis.
[0102] The qubits thus retained by D_ALICE 10, D_BOB 20, form their respective “sifted key”.
[0103] All these retained qubits were transmitted to D_BOB 20, with a probability of 1-e, that is to say, to the errors induced by noise, adjustment / synchronization defects and implementation imperfections. Sifting made it possible to eliminate the qubits whose detection was carried out on a basis other than the generation basis, the transmission of these qubits being unreliable (50%: therefore random).
[0104] In the example in [Fig.3], the bits of rank 1, 3, 6 and 8 are thus the only ones retained by D_ALICE 10 and D_BOB 20, among the first eight bits of the sequence, for the rest of the steps (see “sifted key” line)
[0105] (It will be noted that in alternative embodiments of steps 103 and 104, the roles of D_ALICE 10 and D_BOB 11 are reversed or that each of D_ALICE 10 and D_BOB 11 transmits to the other its choices of basis and then compares for each rank in the sequence of qubits, the chosen polarization basis received on the conventional channel 40 and the polarization basis associated with this rank which is stored, in the memory of the device 10, respectively 20; it selectively retains (Sifting step) only the qubits which have been generated (D_ALICE 10) and measured (D_BOB 20) on the same basis.)
[0106] Step 105
[0107] The control blocks 11 and 21 then evaluate the transmission error rate of the qubits (QBER for 'Quantum Bit Error Rate') affecting their respective sets of bits retained in the sifting step 104, in order to detect the possible interception by Eve, to evaluate the quantity of information intercepted by Eve on the quantum channel during the transmission in step 101 and to possibly select, depending on the evaluated error rate, an error correction code (choice of code and rate) or to parameterize an iterative error correction protocol by request / response for the rest of the processing. To do this, a certain number of qubits are "sacrificed" since they are communicated on the conventional channel 40: they are also removed from the bits retained by the control blocks 11 and 21 for the rest of the post-processing. After eliminating the qubits used to estimate the QBER, the Sifted Key consists of t qubits.
[0108] Depending on the comparison between this error rate evaluation and a given threshold (determining whether a third party has listened to the quantum channel during the transmission of the qubits or whether an unacceptable quantity of information has been intercepted), the present distribution operation is terminated (which can then be re-initiated from step 101); otherwise, step 106 is implemented.
[0109] Due to limitations of photon sources and photon detectors, imperfections in implementation, adjustments or synchronization, the bits of the Sifted Key retained at this stage by D_ALICE and D_BOB are generally not perfectly identical. The set of steps 106-108 below of the reconciliation phase aims to detect / correct the residual errors of the qubits of the “Sifted Key” key determined respectively by D_ALICE and D_BOB, using an error correcting code of the FEC type (Forward Error Correction code), or an interactive and iterative request / response protocol between Alice and Bob, to determine and transmit parity bits associated with subgroups (i.e. packets) of the qubits of the “Sifted Key”, in order to detect / correct residual errors between Alice’s key and Bob’s key and so that they then have a rigorously identical key.
[0110] Redundant parity type information is then generated either by D_ALICE 10, or by D_BOB 20, or by both, and then transmitted by one or the other.
[0111] As described below, these parities are transmitted via the public channel to the other party, so that the latter can identify the residual errors on a sifted key relative to the other (D_ALICE / D_BOB), in accordance with the error detection and correction protocol selected, based on the parities received and its own sifted key.
[0112] Step 106
[0113] In one embodiment, in a step 106, each control block 11, 21, in parallel with one another, calculates parity bits from subgroups of the t bits of the Sifted Key after estimation of the QBER error rate in step 105, according to the error detection and correction protocol selected (here iterative protocol of Cascade or Winnow type).
[0114] The values of the parity bits calculated by each control block 11, respectively 21 are stored in memory 14, 24.
[0115] Step 107
[0116] One of the cryptography blocks 110, respectively 210 encrypts these parity values, using at least one of the secret keys stored in the memory 111, respectively 211 and previously generated by QKD by D_ALICE 10 and D_BOB 20.
[0117] To inform the other device of the values of the calculated parity bits, one of the control blocks 21, respectively 11, transmits the values of these parity bits thus encrypted on the conventional channel 40 via the Em / Rec RF blocks 23, respectively 13. One of the control blocks 11, respectively 21, receives on the conventional channel the values of these parity bits thus encrypted and supplies them to the cryptography block 110, respectively 210, which decrypts them using the secret key(s) stored in the memory 111 respectively 211 which was (were) used for the encryption of these values.
[0118] Step 108
[0119] One of the control blocks 11, respectively 21, then compares the received value of each parity bit, which has been calculated for a given subgroup of bits, with the value that it has calculated for this same subgroup of bits of its own sifted key. With an iterative protocol of the Cascade or Winnow type, the parity comparison makes it possible either to detect / correct an erroneous bit, or to direct the error search process via a new parity calculation request on another subgroup of bits. The residual errors between the Sifted Key held by D_ALICE 10 and D_BOB 20 can thus be detected and corrected based on this comparison made for each parity bit. The detected erroneous bits can either be corrected or rejected. This process makes it possible to obtain, in D_ALICE 10 and D_BOB 20, an ideally rigorously identical secret key, shared between them, of size v.
[0120] An iterative protocol of the Cascade or Winnow type involves a variable number of requests / responses between D_ALICE 10 and D_BOB 20, depending on the number of residual errors; an error-correcting code of the FEC (Forward Error Correction code) type involves a single message sent by only one of the devices 10, 20 to the other of the devices 20, 10 to detect / correct the residual errors. The exchanges take place on the public channel 40.
[0121] Steps 106, 107, 108 above describe by way of example the case of an iterative request / response protocol of Cascade or Winnow type (calculation of the parity bits in the devices 10, 20 transmission by one device to the other, comparison in a device).
[0122] In the case of the use of a FEC code type protocol, for example LDPC, according to the embodiments:
[0123] - the control block D_ALICE 11 calculates for example the parity bits from bits of Alice's sifted key (after sifting, step 104, and after estimation of the QBER error rate, step 105); these parities are transmitted encrypted to control block 21 of D_BOB 20, which decrypts them, then decodes them with its version of the sifted key, to identify errors on its (Bob's) key; then D_BOB 20 corrects its errors; and / or
[0124] - the control block of D_BOB 21 calculates for example the parity bits from the bits of Bob's sifted key; these parities are transmitted encrypted to control block 11 of D_ALICE 10, which decrypts them, then decodes them with its version of the sifted key, to identify errors in its (Alice's) key; then D_ALICE corrects its errors.
[0125] Whatever the error detection and correction protocol chosen, the principle remains the same: transmit encrypted information to the other device on the public channel to access the parity values.
[0126] Step 109
[0127] A secret amplification step, optional and which can in any case be lightened compared to the prior art, implements hash functions to combine the bits of the key obtained at the end of step 108 and thus reduce Eve's information on the final key, at the cost of a reduction in the size of the key. Hash functions are very difficult to invert, and can be used to generate pseudo-random numbers. They often use modular arithmetic.
[0128] Example of a hash function: The proposition was.to P^ 3 pPraep > 771 wS de?ine &«.&(«) œ ((®® 4-$) œ°dp) œod m
[0129] At the end of the implementation of the method according to the invention, D_ALICE 10 and D_BOB 20 have a shared secret key, Kqkd n, which they will then each use as a symmetric encryption key for one to encode and the other to decode the message M_N exchanged between them on the public channel or another channel. Each control block 11, respectively 21, stores the newly generated QKD key, Kqkd n, in the memory 111, 211, for a limited duration.
[0130] The size of KQKd_n is equal to v (i.e. it has v bits, with v < t, v <T).
[0131] To improve the confidentiality of QKD with respect to the transmission of parities, bases used and possibly the selection of qubits retained, QKD is therefore used according to the invention.
[0132] The security of secret key encryption (Vernam) is based on the use of a secret random key of at least the same size as the message to be encrypted, and the obligation not to reuse the key.
[0133] But a key can be reused to encrypt any new random message, without compromising the security of previous transmissions with the same key. It is not common to encrypt perfectly random (because meaningless) information.
[0134] This is used according to the invention for the reconciliation processing in QKD, to encrypt the information on the choice of bases, on the selected qubits and on the parities.
[0135] The random nature of a sequence is associated with statistical characteristics and can be estimated with a set of statistical tests (AIS 31, NIST SP 800-22...). In practice, the mean of a binary sequence must be close to 0.5, the auto-correlation function must be free of peaks, the entropy must be sufficient, etc...
[0136] The choice of bases used for transmission and reception are defined by two independent (uncorrelated) and random binary sequences {bases}Aiice and {bases]Bob: D_ALICE 10 and D_BOB 20 can therefore securely encrypt this information from at least one prior secret key obtained by QKD without compromising the security of prior transmissions with this same key. The same applies when one party (D_BOB) broadcasts its choices of bases and then the other party (D_ALICE) broadcasts the selection of the selected qubits: these sequences are random and independent, D_ALICE 10 and D_BOB 20 can therefore securely encrypt this information from at least one prior secret key obtained by QKD.
[0137] The information on the choice of the bases of D_ALICE (or of D_BOB) or on the selection of the qubits retained on the one hand, and the information on the parities on the other hand are random and independent. Their encryption using at least one secret key therefore does not compromise the security of previous transmissions with this same key.
[0138] For example, the secret key Kqkd n_i used to encrypt the (Nl)th message, named M_N-1, exchanged between D_ALICE 10 and D_BOB 20, can be reused to encrypt the information on the choice of Alice's bases, as well as the parity bits, when constructing the key KQKd_n- The key KQKd_n 2 used to encrypt the (N-2)th message, M_N-2, can be reused to encrypt the information on the choice of Bob's bases to construct the key Kqkd n. ..
[0139] The sequence of bases used by D_ALICE, {bases}Aiice, is encrypted by D_ALICE 10 in a different and independent way, for each bit, from the encryption of the sequence {bases]Bob by D_BOB 20: thus Eve cannot know which qubits will be discarded or retained during sifting.
[0140] By doing this, Eve cannot know: - which (index) qubits will be discarded / retained during sifting - the choice of bases for the retained qubits - the parity values.
[0141] Eve only has the raw sequence of qubits that she has randomly observed (according to the choice of bases), of which 75% of the content is statistically correct, and 50% will be discarded during sifting. She cannot perform sifting, not knowing which qubits are retained. No information on parities allows her to restrict the search space of candidate keys. Another example in the case of asymmetric diffusion of information on the choices of bases: the secret key Kqkd n_i used to encrypt the (Nl)th message, named M_N-1, exchanged between D_ALICE 10 and D_BOB 20, can be reused to encrypt the information on the choice of bases by D_BOB, then to encrypt the parity bits, during the construction of the key KQKd_n- The key Kqkd n-2 used to encrypt the (N-2)th message, M_N-2, can be reused by D_ALICE to encrypt the information on the selection of the qubits retained to construct the key Kqkd_ n ■ • •
[0142] Size of information (selected bases, parity bits) to be encrypted, use of secret keys
[0143] The 2 sequences of qubits, respectively generated (step 101, that of D_ALICE) and received (step 102, that of D_BOB), i.e. considered before sifting, have a size 2T. Each of the two binary sequences defining the choices of the bases used, {bases}Aiice and {bases}Bob have the same size. This size is equal to 2T when only two bases appear in the set of bases. The size is greater than 2T when more than one bit is necessary to identify the chosen base (i.e. in cases where D_ALICE 10 and D_BOB 20 choose their base from a set of bases comprising a number of bases strictly greater than two).
[0144] The 2 sequences after sifting have a variable size t close to T, the sifting discarding on average 50% of the qubits emitted by D_ALICE. The 2 sequences after estimation of the QBER error rate (step 105) have a size u less than t.
[0145] The parity sequence has a possibly variable size, which for example can be considered less than 2T, the invention also being suitable for sequences to be encrypted of a size greater than 2T.
[0146] Finally, after amplification of the secret (step 109), each secret key has a size v strictly less than u, t and T.
[0147] Symmetric key encryption of these different sequences (choice of bases, selection of the retained qubits, parity bits) therefore requires keys of size 2T. However, secret keys of size less than T can be used.
[0148] A classic approach consists of using an encryption algorithm using a key of size independent of that of the message, which is conditioned on the availability / distribution of keys for D_ALICE and D_BOB.
[0149] But for better protection, another solution consists of using Vernam's One Time Pad cipher, reusing secret keys obtained by QKD, in particular by combining them by concatenation, permutation and / or logical combination operations (XOR or exclusive operator) at the bit level, to form larger keys to encrypt information on the choices of Alice's and / or Bob's bases, on the selection of the qubits retained as well as on the parities.
[0150] Encrypting the choice of bases of D_BOB and D_ALICE differently and independently for each qubit has the effect that Eve cannot determine which qubits are retained / rejected during sifting. Permutations between or within the secret keys used can meet this need. The 2 bits of symmetric encryption keys used to encrypt the choice of base relating to each qubit by D_ALICE and by D_BOB must therefore be independent (uncorrelated).
[0151] The parity information being independent of the choice of bases (random) and of the selection of the qubits retained and being relative to random information (random sequence to form a key), the same secret encryption key can be used to encrypt this information (choice of base of a single part, i.e. either D_ALICE or D_BOB, selection of the qubits retained and parity information), without compromising the security of this key.
[0152] This applies to the transient regime, after having generated at least one secret key by QKD, and to the established regime, which corresponds to the generation of at least k secret keys (i.e. k=3 to encrypt binary sequences of size 2T) by QKD.
[0153] Process initialization
[0154] When starting a QKD session between D_ALICE 10 and D_BOB 20, they do not always store previously shared secret keys generated by QKD in their respective memory 111,211.
[0155] To initiate the mechanism according to the invention, several options can be used, for example those described below.
[0156] Option A (we wait until we have the required number of previous keys to encrypt on the classic channel)
[0157] It is sufficient to generate by QKD, according to classical methods, the required number of keys, for example three (or more) keys, for example Kqkd_i, KqKD_2, Kqkd 3, without encrypting the information on the choice of bases, selection of the qubits retained, and parities transmitted on the classical channel. Each key KQKd_i, respectively KQKD_2, KQKD_3 makes it possible to encrypt a useful message M_l, respectively M_2, M_3 (a priori carrying meaning, i.e. no random sequence). Then during the phase of developing the QKD key KQKD_n, for example for n>3 when, in accordance with the method of the invention, at least three previously generated keys, for example KQKD_n_i, KQKD_n_2, KQKD_n 3 are used to generate, by combination (permutation / concatenation / logical combination at the bit level) the encryption keys of the sequences of choice of bases, selection of the retained qubits, and parity of steps 103, 104, 107.
[0158] Option B (the required number of prior keys are produced before starting to encrypt useful messages and on the classical channel)
[0159] Same as option A, but without using the keys to encrypt useful messages (carrying meaning), for greater security, as long as the transmissions of the base and parity sequences are not encrypted in accordance with the invention.
[0160] Option AB, intermediate (at least one previous key is reused to form the 2T size keys to encrypt the classic channel)
[0161] According to this intermediate option, by using one of the previous options to generate a first secret key, it can be reused (secret key) several times to encrypt the information on the choice of bases, the selection of the retained qubits and the parities, until a sufficient number of secret keys is generated to implement the general method described with reference to [Fig.2] (the method can however be implemented from a secret key obtained by QKD; the required / optimal number of keys to encrypt the side information corresponds to an additional level of confidentiality). When the selection of the retained qubits is not communicated, it is then desirable to perform at least one permutation of the secret key to encrypt in a different and independent way each bit of the choice of bases for D_ALICE 10 and D_BOB 20, so that Eve cannot determine which qubits are retained / rejected.In a final intermediate step, different secret keys can be used. to encrypt information on the choice of bases, the selection of the retained qubits and the parities, one of which is reused during this encryption.
[0162] Thus, accessibility to information on the choice of bases, the selection of the qubits retained and the parities evolves rapidly with the production of new keys, until it becomes inaccessible for Eve.
[0163] As described, D_ALICE 10 and D_BOB 20 keep a record, in memories 111, 211, of the last secret keys used during the session. This allows them to secretly generate (by encrypting sensitive information) new secret keys.
[0164] The table in [Fig.4] illustrates the transient regime at startup, in one embodiment of the invention, with the use of prior QKD secret key(s) to encrypt the base selection information used by D_ALICE 10 and D_BOB 20 and the parity information.
[0165] The table in [Fig.5] illustrates, in an embodiment of the invention, in steady state, this time the use of prior secret keys to form secret keys of size 2T to encrypt the information on the choice of bases used by D_ALICE 10 and D_BOB 20, as well as to encrypt the parity information.
[0166] Each line in these tables corresponds to the step of construction of a QKD key, of size u less than T and indicated in the left column. The box in the second column indicates how, during this construction, the sequence {bases}Aiice of size 2T is encrypted (or not) and the box in the third column indicates how, during this construction, the sequence {bases}Bob of size 2T is encrypted (or not). The box in the fourth column indicates how, during this construction, the sequence of parity bits of size less than 2T is encrypted (or not) (in the error detection protocol considered here, only D_ALICE 10 transmits the parity bits to D_BOB 20, the latter not sending them). Finally, in the rightmost column of the table, the useful message that will be transmitted encrypted by the key once constructed is indicated: the message M_i is thus encrypted by the key KQKD iji = 1, 2, 3, .. .Nl, N ...The size of message M_i is less than or equal to the size of KQKD_i- .
[0167] With reference to [Fig.4]:
[0168] During the QKD protocol elaboration of the first session key, Kqkd b the sequences of chosen bases and parity values are transmitted in clear. At the end of this construction, the key Kqkd_ i is used to encrypt a first useful message, M_l, exchanged between D_ALICE 10 and D_BOB 20.
[0169] The second key KQKd_2 is generated by encrypting transmissions on the conventional channel, using sequences derived from the first secret key (concatenation, logical combination, permutations of bits). For example, during the QKD protocol elaboration of the second session key, Kqkd_2:
[0170] - the sequence of bases, {bases}Aiice is encrypted according to the key KQKD_i; by example, a concatenation function q>' is applied to the key Kqkd_ i to generate an encryption key of the sequence of choice of bases of size greater than or equal to 2T; for example, it performs the concatenation of 3 times the key KQKd_ i: KQKd_ i I KQKd_ i I KqKD_ ! ;
[0171] - the sequence of bases, {bases}Bob is encrypted according to the key KQKD_ b but distinctly and independently (at the level of each bit) with respect to{bases]AiiCe; for example, a function rp' combining permutation and concatenation is applied to the key Kqkd_ i to generate an encryption key of size greater than or equal to 2T; for example, it performs a permutation (P) of the bits in KQKd_ i then a concatenation of 3 times the permuted key: P(Kqkd_ i) IP(Kqkd_ i) IP(Kqkd_ i);
[0172] - the sequence of parities is for example encrypted with the same encryption key than for the sequence {bases}Aiice.
[0173] At the end of the construction of KQKd_2, the key KQKd_2 is used to encrypt a second useful message, M_2, exchanged between D_ALICE 10 and D_BOB 20.
[0174] We proceed similarly to generate the third secret key Kqkd 3, this time using concatenations of the first secret QKD keys KQKD_i and KQKd_2 to carry out the encryption of the choices of bases and the parity values.
[0175] After the generation of Kqkd_3, we move to steady state.
[0176] Referring now to [Fig.5], we are interested in the generation of the key Kqkd n in an embodiment of the invention, with N greater than or equal to 4, the previously generated QKD keys being stored by D_ALICE 10 and D_BOB 20.
[0177] During the method of generating KQKd_n in one embodiment of the invention, sequentially: - a set of the last secret keys shared by D_ALICE 10 and D_BOB 20 (here the last 3 Kqkd_n 3, Kqkd_n 2, and KQKD_N i) is for example used to construct, by concatenation, encryption keys of sufficient size to (de-)crypt the binary information sequences relating to the bases used by D_ALICE, by D_BOB, and to encrypt the parities; - a permutation on the keys concatenated by D_BOB with respect to D_ALICE is performed in order to hide from Eve which qubits are retained / discarded during sifting: for example, in the present case, the symmetric encryption key used to (de-)crypt {bases}Aiice (and the parity bits) is Kqkd_n JKqkdn-2I Kqkd x3 while the symmetric encryption key used to (de-)crypt {bases}Bob is Kqkd-n-JKqkdnJ Kqkd_n-i
[0178] Then the KQKD Nest key used to encrypt an Nth useful message, M_N, exchanged between D_ALICE 10 and D_BOB 20.
[0179] We iterate to generate successive secret keys.
[0180] Only the useful message is meaningful. The other sequences are independent and random at the level of each bit.
[0181] The protection of the information exchanged during reconciliation (choice of bases used, selection of qubits retained, parities) is improved by using a larger number of prior secret keys. Figures 4 and 5 show the use of up to 3 prior keys to develop any new QKD key. The principle is naturally transposable to the use of any number of prior keys in order to encrypt the different sequences during reconciliation.
[0182] Considering, in an exemplary implementation of the invention, on the one hand a random sequence of bits to be encrypted indicating the basic choice information or the selection of the qubits retained, or even the parity bits and on the other hand an encryption key of size (in number of bits) greater than the sequence to be encrypted, an example of encryption by the cryptography block 110, 210 of the sequence with the encryption key is to perform an EXCLUSIVE OR operation between the bit of the sequence of rank n and the bit of rank n of the encryption key, for all n ranging from 1 to the size of the sequence.
[0183] Generally speaking, all QKD protocols have in common the fact of implementing reconciliation and error correction processing to generate two identical keys from raw keys (qubits transmitted on the quantum channel). The invention proposed here is applicable to all QKD protocols, regardless of the coding mode (e.g.: by polarization / phase / ...) and the variants of these protocols.
[0184] In particular, the invention has been described above with reference to the implementation of the transmission of random binary information by the polarization of photons, for example in the context of the BB84 protocol; the invention is however applicable to any protocol (e.g.: E91, B92...) and system for generating symmetric key of QKD type, among others QKD protocols with discrete variables, with other physical parameters used to encode the bits on qubits, for example the frequency or the phase of a photon, optionally in a differential manner (frequency-coded QKD or phase-coded QKD or Differential Phase-coded QKD; in the case of the use of the phase, the coding is based on a phase modulator instead of a polarization rotator / modulator) instead of or in addition to the polarization of the photons, protocols using continuous variables (GG02), and / or using the transmission of several photons per light pulse...
[0185] Similarly, even if an example of coding a single bit per photon has been considered above, the invention also applies in the case where a parameter of the photon transmitted on the quantum channel codes several bits, based for example on protocols making it possible to code several bits per light pulse such as the GG02, GMCS Gaussian Modulated Coherent-States protocols.
[0186] In the exemplary embodiment described above, the encryption is implemented on the sequences for choosing the bases, on the sequences for selecting the retained qubits and the sequences of parity values; in embodiments, only the sequences for choosing the bases or for selecting the retained qubits or only the sequences of parity values are encrypted.
[0187] Furthermore, the invention can also be implemented in embodiments without random choice of base used in reception and / or transmission, such as for example in a Differential Phase-coded QKD protocol; the step of correcting residual errors is then nevertheless always necessary.
[0188] The invention can also be implemented in embodiments where the QKD protocol employed uses the polarization of the photons to code the bits, but with a number of states considered different from the four states considered in BB84: for example BB92 uses 2 polarizations, SSP uses 6.
[0189] The steps incumbent on the control block 11, 21 described above may be implemented by the execution of software instructions on a processor. Alternatively, they may be implemented by dedicated hardware, typically a digital integrated circuit, either specific (ASIC) or based on programmable logic (for example FPGA / Field Programmable Gate Array).
[0190] The term “bit” designates the binary information itself (“0” or “1”), the term “qubit” designates more specifically this binary information when it is carried by a quantum state of an elementary particle, in particular of a photon (i.e. generation and polarization in the device 10, propagation in the quantum channel and measurement in the device 20); however, in the preceding description, one or the other of the two terms may have been used indistinctly to designate the corresponding binary information.
[0191] It will be noted that the random choice of the polarization base, both in transmission and in reception, can be achieved in different ways: as described below, with a polarization modulator or by mechanical switching of a polarization rotator controlled by a quantum randomness generator, a beam splitter such as a semi-reflecting plate, a fixed polarization rotator such as a half-wave plate, etc. according to known techniques.
[0192] Furthermore, in embodiments, the implemented QKD protocol is based on entanglement (for example E91 protocol) for which the photons are generated by a source that may be external to D_ALICE and D_BOB. In this case, D_ALICE does not generate the binary sequence: D_ALICE and D_BOB receive this sequence and are like 2 receivers that agree on the decoding of the received qubit sequence, with random base choices (A and B) (or not), in accordance with steps 102 and following described above.
Claims
1. Claims Method for quantum key distribution, named KQKD_N, to a first and a second telecommunication devices (D_ALICE, D_BOB) to implement between them a telecommunication encrypted by said key KQKD_N, said first and a second telecommunication devices (D_ALICE, D_BOB) each being connected to a respective first telecommunication link (30) and connected to each other by a second telecommunication link (40), said first link (30) being an optical transmission link and being hereinafter called quantum channel, said second telecommunication link (40) being hereinafter called classical channel; said method comprising the following steps of determining KQKD_N, implemented by at least one device considered among the first and second devices:
2. - implementing, on the quantum channel (30), a communication of a random sequence of bits in the form of a sequence of light pulses in quantum mode such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by each of the first and second devices; - implementing, on the conventional channel (40), a communication, between the first and second devices, of information indicating parity bit values, said parity bit values having been calculated by at least one of said first and second devices as a function of the random sequence of bits that it has memorized, then being transmitted, during said communication, to the other of said first and second devices which then implements, in the sequence of bits memorized by the other of said first and second devices, an error correction, as a function of said transmitted parity bits; - determining said key KQKD_N, based on said random sequence of bits, and storing said key KQKD_N, said key being shared between said first and a second device; said method being characterized in that said communication of information indicating parity bit values between the first and second devices is encrypted or decrypted by said device considered according to at least one key KQKD_N-k previously determined by prior implementation of a quantum key distribution mechanism QKD to said first and second devices. Method for quantum key distribution, named KQKD_N, to a first and a second telecommunication devices (D_ALICE, D_BOB) to implement between them a telecommunication encrypted by said key KQKD_N, said first and second telecommunication devices (D_ALICE, D_BOB) each being connected to a respective first telecommunication link (30) and connected to each other by a second telecommunication link (40), said first link (30) being an optical transmission link and being hereinafter called quantum channel, said second telecommunication link (40) being hereinafter called classical channel; said method comprising the following steps of determining KQKD_N, implemented by at least one device considered among the first and second devices: implementing, on the quantum channel (30), a communication of a random sequence of bits in the form of a sequence of light pulses in quantum regime such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by each of the first and second devices; implementing, on the conventional channel (40), a communication, between the first and second devices, of information relating to bases, indicating, for each bit of the stored sequence, the base, among at least two distinct bases of coding between values of said parameter and the values 0 or 1 of a bit of the random sequence of bits, that at least one of the first and second devices has randomly selected to carry out the coding between the bit and the value of said light pulse parameter; selection, by said device, of those bits of the random sequence of bits for which the first and second devices have selected the same bases; implementation, on the conventional channel (40), of a communication, between the first and second devices, of information indicating parity bit values, said parity bit values having been calculated by at least one of said first and second devices as a function of said selected bits, then being transmitted, during said communication, to the other of said first and second devices which then implements an error correction, as a function of said transmitted parity bits, on the bits selected by the other of said first and second devices; determining said key KQKD_N, based on the selected bits and the error correction, and storing said key KQKD_N, said key being shared between said first and a second device; said method being characterized in that said communication of information relating to said bases between the first and second devices (D_ALICE, D_BOB) is encrypted or decrypted by said device considered according to at least one key KQKD_N-k previously determined by prior implementation of a quantum key distribution mechanism QKD to said first and second devices.
3. A quantum key distribution method according to claim 2 wherein said communication of information indicating parity bit values between the first and second devices (D_ALICE, D_BOB) is further encrypted or decrypted by said device in question based on at least one key KQKD_N-k previously determined by implementing a prior iteration of a quantum key distribution method QKD to said first and second devices.
4. Quantum key distribution method, according to one of the preceding claims, according to which the encryption or decryption of the information is carried out according to a symmetric encryption or decryption key determined by operations of the concatenation and permutation type and / or logical combination at the bit level of at least one key previously determined by quantum key distribution QKD to said first and second devices (D_ALICE, D_BOB).
5. Quantum key distribution method, according to one of the preceding claims, wherein said information encrypted or decrypted according to at least the previously determined key KQKD_N-k is random and independent information.
6. Computer program, intended to be stored in the memory of a telecommunications device (D_ALICE, D_BOB) further comprising a microcomputer, said computer program comprising instructions which, when executed on the microcomputer, orchestrate the steps of a method according to one of the preceding claims.
7. Telecommunication device (D_ALICE, D_BOB), adapted to be connected to a first telecommunication link (30), adapted to be connected to another telecommunication device ((D_ALICE, D_BOB) by a second telecommunication link telecommunication (40), and to implement with said other device a telecommunication encrypted by a key KQKD_N, said first link (30) being an optical transmission link and being hereinafter called quantum channel, said second telecommunication link (40) being hereinafter called classical channel; said device being adapted to determine KQKD_N: - by implementing, on the quantum channel (30), a communication of a random sequence of bits in the form of a sequence of light pulses in quantum regime such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by the device; - by putting, on the conventional channel (40), a communication with the other device, of information indicating parity bit values, said parity bit values having been calculated by at least a first device among said device and said other device according to the random sequence of bits that it has memorized, then being transmitted, during said communication, to the second among said device and said other device which then implements, in the sequence of bits memorized by the other of said first and second devices, an error correction, according to said transmitted parity bits; - by determining said key KQKD_N, based on said random sequence of bits, and storing said key KQKD_N, said key being shared between said device and said other device; said device (D_ALICE, D_BOB) being characterized in that said communication of information indicating parity bit values between said device and said other device is encrypted or decrypted by said device according to at least one key KQKD_N-k previously determined by prior implementation of a quantum key distribution mechanism QKD to said device and to said other device (D_ALICE, D_BOB).
8. Telecommunication device (D_ALICE, D_BOB) adapted to be connected to a first telecommunication link (30), adapted to be connected to another telecommunication device (D_ALICE, D_BOB) by a second telecommunication link (40), and to implement with said other device a telecommunication encrypted by a key KQKD_N, said first link (30) being an optical transmission link and being hereinafter called quantum channel, said second telecommunication link (40) being hereinafter called classical channel; said device being adapted to determine KQKD_N: by implementing, on the quantum channel (30), a communication of a random sequence of bits in the form of a sequence of light pulses in quantum regime such that for each light pulse of the sequence of pulses, a physical parameter of each light pulse codes the value of at least one of said bits of the random sequence of bits; said sequence of bits being stored by the device; by putting, on the conventional channel (40), a communication with the other device, of information indicating, for each bit of the stored sequence, the base, among at least two distinct bases of coding between values of said parameter and the values 0 or 1 of a bit of the random sequence of bits, that a first device among said device and said other device has randomly selected to carry out the coding between the bit and the value of said light pulse parameter; by selecting those bits from the random sequence of bits for which said device and said other device have selected the same bases; by implementing, on the conventional channel (40), a communication, between said device and said other device, of information indicating parity bit values, said parity bit values having been calculated by a first device among said device or said other device as a function of said selected bits, then being transmitted, during said communication, to the second device among said device and said other device which then implements an error correction, as a function of said transmitted parity bits, on the bits selected by the second device among said device and said other device; determining said key KQKD_N, as a function of the selected bits, and storing said key KQKD_N, said key being shared between said device and said other device; said device being characterized in that said communication of information relating to said bases between said device and said other device (D_ALICE, D_BOB) is encrypted or decrypted by said device according to at least one key KQKD_N-k previously determined by prior implementation of a quantum key distribution mechanism QKD to said device and to said other device.
9. A telecommunications device (D_ALICE, D_BOB) according to claim 8 wherein said communication of information indicating parity bit values between said device and said other device (D_ALICE, D_BOB) is further encrypted or decrypted by said device based on at least one key KQKD_N-k previously determined by prior implementation of a quantum key distribution QKD to said device and said other device (D_ALICE, D_BOB).
10. Telecommunication device (D_ALICE, D_BOB) according to one of claims 7 to 9, in which the encryption or decryption of the information is carried out according to a symmetric encryption or decryption key determined by operations of the concatenation and permutation type and / or logical combination at the bit level of at least one key previously determined by quantum key distribution QKD to said device and to said other device (D_ALICE, D_BOB).