Key management method and system for establishing secure communications between a satellite control center and a satellite
A PKI-based key management system using digitally signed certificates and satellite-specific authentication simplifies and secures on-board-ground communication by eliminating initial secret keys, addressing the limitations of symmetric cryptography in space systems.
Patent Information
- Application Number
- FR2023006094
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-06-15
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2043-06-15
AI Technical Summary
Current space communication systems rely on symmetric secret key cryptography, which requires cumbersome manual distribution chains and pre-shared secret keys, failing to comply with key management best practices and persistently exposing keys to security risks during the satellite's lifetime.
Implement a public key infrastructure (PKI) using digitally signed certificates and semi-mutual authentication based on unique satellite physical parameters, eliminating the need for initial secret keys on the satellite and ensuring secure key negotiation.
This approach simplifies key management, reduces security risks, and complies with key management best practices by using non-secret certificates and physical authentication, ensuring secure on-board-ground communication links without persistent secret keys.
Smart Images

Figure 00000023_0000 
Figure 00000024_0000 
Figure 00000025_0000
Abstract
Description
Title of the invention: Method and system for key management for establishing secure communications between a satellite control center and a satellite Technical field
[0001] The present invention relates to the space field of communications between a satellite control center located on Earth and satellites in orbit. The invention is more specifically concerned with the security of such communications. State of the art
[0002] In the general field of communications, it is recognized that the security of communications between two parties is based on three fundamental factors: the availability of a communication channel, the confidentiality of the messages exchanged and the authenticity of the messages exchanged (authentication of the source of the messages and integrity of the messages).
[0003] There are two widespread approaches to securing communications between two parties A and B, generally referred to as Alice and Bob: public / private key cryptography or asymmetric cryptography, and symmetric secret key cryptography.
[0004] In the particular field of space communications, security principles must be respected. For any communication link between a satellite control center (SCC) located on Earth (also referred to as a ground control segment) and a satellite in orbit, the availability of the transmission channel, the confidentiality and the authenticity of the messages exchanged must be guaranteed.
[0005] The present invention is specifically concerned with the authenticity and confidentiality of messages exchanged between a ground control segment and a satellite.
[0006] To date, space systems base the security of their onboard-ground communication on symmetric secret key cryptography.
[0007] As is known, during secure exchanges on the internet, denoted https: / / , symmetric secret key cryptography allows two parties, generally designated by Alice and Bob, to secure their communication. The secret key is negotiated from public elements exchanged between Alice and Bob and private elements that are specific to them and known only to them. These public / private elements are produced at the time, they are therefore "ephemeral". The authentication of Alice and Bob is based on the establishment of certificates, signed by a trusted third-party authority, which respectively contain their public key. These public certificates are issued by a trusted certification authority (CA) which guarantees the validity and authenticity of the certificates. This infrastructure called (PKI) for "Public Key Infrastructure" according to The Anglicism, consecrated, allows the creation of shared secret keys, on demand and at the time they are required by Alice and Bob. However, this type of infrastructure does not free Alice and Bob from having a persistent secret, which is their respective private key, at all times.
[0008] For communications in current space systems, symmetric secret key cryptography is also used to secure exchanges between the control ground segment and the satellite, except that the establishment of the secret key does not rely on a PKI and requires that the control ground segment and the satellite have pre-shared secret keys known only to them.
[0009] An infrastructure for the management of secret key keys, acronym (IGC) or (SKI) for “Secret Key Infrastructure” according to the accepted Anglicism, is shown schematically in [Fig.l].
[0010] The illustrated example of the infrastructure 100 makes it possible to produce on the ground and distribute in ground encryption / decryption equipment 102 and in a satellite 104 before it is put into orbit, secret encryption keys for the exchange of telemetry data TM and remote control data TC.
[0011] The infrastructure makes it possible to distribute secret keys, from key generation equipment (random generators) 106 and key management equipment 108, to the ground cryptographic equipment 102 and to the satellite 104 before it is put into orbit, and this via different media (CD-ROM, USB key, Smart-Card, key injectors, etc.).
[0012] This infrastructure requires the implementation on the ground of a trusted "manual" distribution chain which is cumbersome and which relies on both organizational measures and accredited personnel, such as the OSSI (Information Systems Security Officer). It requires the implementation of restrictive security measures: authorization of individuals, approval of key production and distribution equipment, etc.
[0013] Furthermore, such an infrastructure does not allow compliance with all the rules and best practices in terms of secret key management. Thus, for example, the principle according to which "a secret key must be created at the time when the system needs it so that it is exposed only for the time necessary during its use", is not respected in the case of space systems, because the secret keys are generated at the very beginning of a mission while the satellite is on the ground, and are generated once for the entire lifetime of the satellite in orbit (i.e. between 10 and 20 years).
[0014] Another rule that is little or not respected by this type of infrastructure relates to the fact that "the security of a secret key must not depend on the security of other secret keys previously used during encryption or decryption operations." Here we identify the notion of persistence of confidentiality or PFS for "Prefect Forward Secrecy" in English.
[0015] Finally, this type of infrastructure remains limited to systems with few satellites to operate and little equipment deployed on the ground.
[0016] Also, this type of infrastructure (SKI) imposes heavy operational constraints to guarantee the confidentiality of the keys for the entire lifetime of the system, among others constraints to guarantee the confidentiality and integrity of the keys loaded into the satellite, during the entire phase preceding the firing on the launch site. Indeed, the constraint of an initial secret (a symmetric secret key or even a private key) remains strong for space systems, especially at the level of the satellite when it is located either on an industrial site, or in the transport phase, or on a launch site.
[0017] Thus, in the face of these limitations and drawbacks, there is a need to have an encryption key management solution, which allows, in a simple manner, space solution operators who have to manage one or a plurality of satellites, to secure on-board-ground links between one or more satellites and their control ground segment.
[0018] The present invention meets this need. Summary of the invention
[0019] An object of the present invention is to solve the problem of distributing secret keys for encryption / decryption of remote controls and telemetry exchanged between a control ground segment and a satellite in orbit. Indeed, the initial establishment of secret keys poses the problem of the initial authentication of the control ground segment with respect to the satellite, and the initial authentication of the satellite with respect to the control ground segment.
[0020] Advantageously, the method of the invention makes it possible to avoid the presence of an initial secret in the satellite during the entire preparation phase of the latter until firing.
[0021] Advantageously, the present invention makes it possible to dispense, for a satellite, with the need to carry an initial secret (a symmetric secret key or a private key) before it is put into orbit, and is based on a secret key negotiation protocol with semi-mutual authentication.
[0022] The proposed solution is based on a key management infrastructure based on the implementation of digitally signed public (non-secret) certificates (PKI), the use of public / private key cryptography (i.e. asymmetric cryptography) for signing certificates and for negotiating secret keys, and on authentication of a satellite in orbit which relies solely on unique physical parameters of the latter, such as for example its orbital position.
[0023] The key management infrastructure of the invention is based on the principles of a PKI type infrastructure, but where, in contrast and against all expectations according to the infra classic PKI structures, the satellite concerned only carries with it a self-signed certificate from a certification authority (CA) with a PAC public key, which is not confidential.
[0024] According to the PKI infrastructure of the present invention, ground cryptographic equipment (generally part of the control center) produces a “public key / private key” pair. The public key is transmitted to a CA so that it is inserted into a certificate signed by PAC (i.e. with the PAC private key). At the end of this preparatory phase of setting up certificates, advantageously the satellite is devoid of sensitive elements, because it only has the PAC public key.
[0025] Once the satellite is launched, the ground control center can send it its valid ground certificate. The satellite can verify the authenticity of this ground certificate by countersigning it with the PAC public key that it possesses. The satellite's cryptographic function and the ground cryptographic equipment can then exchange public (non-sensitive) parameters, generated at the time, which allow them to produce a shared secret key.
[0026] The authentication of the messages sent by the ground control center is then carried out by means of the signature on the ground with the private key and the counter-signature (i.e. the authentication verification) on board with the public key of the ground (the one which was present in the certificate sent by the ground).
[0027] Advantageously, the authentication of the satellite by the control center does not involve a cryptographic mechanism, but physical parameters identifying the satellite without any possible doubt.
[0028] In one of the possible embodiments, the authentication of the satellite is based on the ephemerides of the operated satellite, and on the fact that a control center knows them at all times, the latter being unique and specific to any object in orbit around the Earth.
[0029] Other modes of authentication of the satellite can be envisaged, such as, for example, identification by analysis of the RF fingerprint of the TM message modulator or even of a beacon.
[0030] Advantageously, the method of the invention allows key management which does not require positioning an initial secret in a satellite on the ground, before it is put into orbit. Thus, the method of the invention allows a drastic simplification of key management operations over the entire lifetime of a space system.
[0031] The invention applies to space systems for which an end user requires secure on-board-ground communication links. This is the case for all current space systems, whether civil or military.
[0032] Advantageously, the implementation of the invention avoids an end user having to take on the complex management of a secret key infrastructure on the ground. (SKI). This management remains the responsibility of the manufacturer, who will provide the end customer with the elements enabling them to secure the on-board-ground links of their system with ease: certificates from the certification authority, certificates from the ground cryptographic equipment and cryptographic functions for signing and negotiating secret keys.
[0033] The space systems targeted are essentially geostationary telecommunications satellites for civil satellite operators or commercial satellites. However, the method can be extended to other space systems (low orbit constellation) as long as the operations of the system are not unduly affected.
[0034] The invention makes it possible to comply with the basic rules concerning the management of secret keys, i.e. use of a "fresh" key and guarantee of persistent confidentiality in the event of a past key being compromised. It thus makes it possible to reduce the risk of compromise of the secret keys used throughout the lifetime of the space system.
[0035] To obtain the desired results, a key management method is proposed for establishing secure communications between a ground control center and a satellite in orbit, the method comprising steps consisting of:
[0036] - in a phase where the satellite is on the ground, to operate an asy cryptography protocol metric with a certification authority, allowing to deploy:
[0037] - on cryptographic equipment of the ground control center, a ground private key and a certificate signed by the certification authority, containing a ground public key; and
[0038] - on cryptographic equipment of the satellite on the ground, a self-signed certificate by the certification authority, containing a public key CA of the certification authority;
[0039] - in a phase where the satellite is in orbit, to operate an authentication protocol semi-mutual, between the ground control center and the satellite in orbit, consisting of:
[0040] - for the cryptographic equipment of the ground control center: to authenticate the satellite by one or more physical characteristics identifying the satellite; to send to said authenticated satellite, a message signed with the ground private key, said message containing the certificate self-signed by the certification authority and the ground public key; and
[0041] - for the cryptographic equipment of the satellite in orbit: to authenticate the certificate received from the cryptographic equipment of the ground control center, using the public key AC of the certification authority.
[0042] In a phase of establishing or exchanging a secret key between the satellite and the ground control center, the messages sent by the ground control center are signed with the private key of the ground control center and countersigned by the satellite with the public key of the ground control center. The satellite in orbit, the source of the messages sent to the ground control center, is authenticated by one of its physical characteristics, which implicitly authenticates the messages sent by the satellite to the ground control center.
[0043] The invention provides several separate or combined embodiments.
[0044] Thus the step of operating an asymmetric cryptography protocol with a certification authority comprises:
[0045] - a step where the certification authority produces a public / private CA key pair (public key AC, private key AC);
[0046] - a step where the certification authority constitutes a self-signed certificate with said private key AC, and containing said public key AC; and
[0047] - a step where said self-signed certificate is transmitted on the one hand to the crypto equipment ground topography and on the other hand to the cryptographic equipment of the satellite on the ground.
[0048] The method further comprises:
[0049] - a step where the sol cryptographic equipment: produces a sol key pair public / private (sol public key, sol private key); and transmits said sol public key to the certification authority;
[0050] - a step where the certification authority: integrates the received public key into a certificate; signs it with said private key AC; and transmits the signed certificate to the ground cryptographic equipment.
[0051] In one embodiment, the certification authority is capable of operating key registration functions.
[0052] In one embodiment, the step of authenticating the satellite by one or more physical characteristics consists of authenticating said satellite by its ephemerides, by authenticating parameters linked to its orbital position, in particular the azimuth and the elevation.
[0053] In a variant, the step of authenticating the satellite by one or more physical characteristics consists of authenticating said satellite by characteristics of a modulated signal emitted by a telemetry transmitter or by a beacon of the targeted satellite.
[0054] In another variant, the step of authenticating the satellite by one or more physical characteristics, consists of authenticating said satellite by a Doppler of a downlink modulated signal.
[0055] In another variant, the step of authenticating the satellite by one or more physical characteristics consists of authenticating said satellite by a thermal signature of the satellite.
[0056] The method further comprises, after the semi-mutual authentication between the ground control center and the satellite in orbit, steps consisting of the establishment or exchange of secret keys between the ground control center and the authenticated satellite.
[0057] The invention also covers a key management device for establishing secure communications between a ground control center and a satellite in orbit, the device comprising means for implementing the steps of the method of the invention.
[0058] The invention also addresses a computer program comprising code instructions which, when the program is executed by a computer, cause the latter to implement the method of the invention. Brief description of the drawings
[0059] Other characteristics and advantages of the present invention will appear more clearly on reading the description which follows in relation to the following drawings:
[0060] [Fig.l] illustrates a known secret key management infrastructure (SKI) for space system communications;
[0061] [Fig.2] illustrates a known public key management infrastructure (PKI) for internet communications;
[0062] [Fig.3] illustrates a public key management infrastructure (PKI) for space systems communications, according to one embodiment of the invention;
[0063] [Fig.4] schematically illustrates the general principle of an authentication method according to one embodiment of the invention;
[0064] [Fig.5] schematically illustrates the establishment or exchange of secret keys between a satellite in orbit and ground equipment, according to one embodiment of the invention. Detailed description of the invention
[0065] First, some reminders are made on various general and known principles of cryptography.
[0066] In information systems, the security of communications is ensured by means of cryptographic algorithms. A cryptographic algorithm makes it possible to transform initial data into final data which may have different objectives. Cryptography makes it possible to guarantee the confidentiality and authenticity of messages. By cryptographic algorithm is meant any secure function which guarantees that, by any type of computer attack (cryptanalysis, prediction, computing power, etc.) it is not possible to circumvent the security mechanisms put in place.
[0067] Symmetric secret key cryptography:
[0068] To ensure the confidentiality of the messages they will exchange, Alice and Bob must have the following elements:
[0069] - a cryptographic primitive for encrypting messages for Alice called EK;
[0070] - a cryptographic primitive for decrypting messages for Bob called DK
[0071] - a symmetric secret key K known only to Alice and Bob.
[0072] Alice uses the secret key K and the primitive EK to encrypt her initial clear message. The encrypted message can be transmitted to Bob and will not be understandable to anyone. person who does not have the secret key K which would allow the message to be decrypted.
[0073] Bob, when he receives the encrypted message sent by Alice, can decrypt it using the primitive DK and the secret key K to extract the clear message initially constructed by Alice.
[0074] The confidentiality of messages exchanged between Alice and Bob is based on the fact that only Alice and Bob have a shared common secret key.
[0075] A first problem that arises is that of sharing the secret key between Alice and Bob. This need for a shared common secret requires that Alice and Bob meet at least once to exchange, away from prying eyes, the secret key. The problem of distributing / exchanging secret keys remains a major problem in communications security. On the other hand, the fact of meeting allows Alice and Bob to authenticate each other during the initial exchange of the secret key. This at least allows the initial authentication phase to be resolved.
[0076] The cryptography used here is called symmetric secret key cryptography or incorrectly “symmetric cryptography”.
[0077] To ensure the authenticity of the messages, Alice and Bob must have the following elements:
[0078] - a one-way hash function for Alice and for Bob;
[0079] - a message encryption primitive for Alice called EK;
[0080] - a message decryption primitive for Bob called DK;
[0081] - a symmetric secret key K known only to Alice and Bob.
[0082] Alice uses a one-way hash function that produces a summary of her initial plaintext. Then, Alice uses the secret key K to encrypt the digest of the initial plaintext using the primitive EK. She can then send the plaintext and the encrypted digest to Bob.
[0083] Bob uses the same hash function as Alice to calculate the digest of the received plaintext message. Then, he uses the same secret key K and the primitive DK to decrypt the digest of the original message. Bob thus obtains two message digests that he can compare.
[0084] If the two message digests obtained by Bob are strictly identical, then Bob will have two certainties:
[0085] - the message he has just received is intact (thanks to the hash function),
[0086] - the message he has just received does indeed come from Alice (thanks to the operation of encryption / decryption with the secret key K known to Alice and Bob only).
[0087] Alice and Bob now have secure means to exchange messages while guaranteeing the authenticity of the messages and their confidentiality. They must nevertheless meet to agree or exchange a secret key. municipality which is a mandatory prerequisite.
[0088] Public / private key cryptography:
[0089] Public / private key cryptography is based on the principle that both parties Alice and Bob will have to use different keys for encryption and decryption operations.
[0090] We consider that Bob has, at his disposal, two keys which are complementary:
[0091] - a so-called "public" key which by definition is not sensitive, and which Bob can send to Alice via a non-confidential channel (i.e. clear channel);
[0092] - a so-called "private" key which is sensitive and which must remain known only only him. This key must never be shared, not even with Alice. It is personal to Bob.
[0093] To ensure the confidentiality of the exchanges, Alice encrypts her message with the public key that Bob previously transmitted to her. The encrypted message can then be sent to Bob who can decrypt it with his private key (which is the only key consistent with his public key, the one used by Alice for encryption). A third party "Eve" can try to decrypt the encrypted message with Bob's public key (which she will have intercepted), but she will obtain an unintelligible message since she did not use the private key (known only to Bob) which is the only key that allows the initial clear message to be recovered.
[0094] The advantage of asymmetric cryptography is that Bob was able to transmit his public key to Alice via a non-confidential channel. But the initial authentication phase, which would guarantee Alice that the key sent by Bob is indeed Bob's, has not been resolved.
[0095] It is possible to use asymmetric cryptography to add authenticity to messages. Alice must have her own public / private key pair, also called a key pair. She has previously transmitted her public key to Bob and has kept her own private key secret.
[0096] Alice encrypts the message she wants to send to Bob with Bob's public key. But this time, she also calculates a digest of the original plaintext message using a one-way hash function, and then encrypts this digest with her own private key, known only to her.
[0097] Alice then sends to Bob:
[0098] - the encrypted summary of the initial clear message (encrypted with Alice's private key);
[0099] - the message encrypted with Bob's public key.
[0100] Bob can then perform the following operations:
[0101] - decrypt, with Alice's public key, the encrypted summary of the initial clear message that he received;
[0102] - decrypt, with his private key, the received encrypted message to obtain the message deciphered (which is a priori identical to Alice's initial clear message);
[0103] - calculate, with the same one-way hash function as used by Alice, the summary of the deciphered message.
[0104] If the two message digests obtained by Bob are strictly identical, then Bob will have two certainties:
[0105] - the message he has just received is intact,
[0106] - the message he just received does indeed come from Alice.
[0107] Thus, the authenticity of messages obtained through asymmetric cryptography goes a little further than that obtained through symmetric cryptography. Since Alice has a private key different from Bob's, the integrity of messages sent by Alice is linked to her private key. This makes them special integrity patterns which, in this specific case, are called "digital signature".
[0108] Unlike the authenticity mechanism of symmetric cryptography, which produces a cryptographic integrity pattern attached to the secret key shared by Alice and Bob, the authenticity process of asymmetric cryptography is attached to only one of the two private keys, which justifies speaking of a "digital signature" rather than a cryptographic integrity pattern.
[0109] If Bob keeps the encrypted message and especially the message digest encrypted with Alice's private key, this is valid for him as proof that the message was indeed sent by Alice in the sense that, being the only one to possess her private key, Alice is the only one who can produce a signature that can be cross-verified with the public key that Bob possesses. We are talking here about a non-repudiation mechanism that asymmetric cryptography allows and that symmetric secret key cryptography does not allow.
[0110] Thanks to asymmetric cryptography, Alice and Bob thus have a means which allows them to instantiate the notion of digital signature. However, this scheme remains tainted by a weak point which is the following: how can Alice guarantee to Bob that the public key she sends him is indeed his public key and vice versa? To verify this, Alice and Bob could meet physically to exchange their public key. However, this does not provide more than what symmetric secret key cryptography offers. It then remains to resolve in asymmetric cryptography, the problem of initial authentication which allows Alice to guarantee that she is indeed communicating with Bob and vice versa.
[0111] In the field of information systems security, this initial authentication problem for the initial exchange of public keys is summarized in a very well-known attack called the man-in-the-middle attack. This attack consists of a third party designated "Eve" inserting themselves between Alice and Bob at the level of the communication channel and usurping the identity of Alice and Bob.
[0112] When Alice sends her public key to Bob, Eve retrieves it and sends Bob her own public key; Bob thinks he is receiving Alice's public key when he is actually receiving Eve's. Then, when Bob sends his public key to Alice, Eve retrieves it and sends Alice her own public key; Alice thinks she is receiving Bob's public key when she is actually receiving Eve's.
[0113] This attack is possible because Alice and Bob do not yet have a reliable way to perform the initial authentication phase. This phase is crucial in any communication.
[0114] Subsequently, each time Alice encrypts a message, she will unknowingly use Eve's public key, which will allow her to easily decrypt it with her private key. Eve will then be able to modify and "re-encrypt" the new message using Bob's public key, before sending it to Bob, who will decrypt it with his own private key, thinking that Alice encrypted it with Bob's public key.
[0115] For the signature, Alice will "digitally sign" her message with her private key. But Eve will replace Alice's signature with her own (made with her own private key). Bob, when he receives the signed message, will countersign it with Eve's public key, thinking he is using Alice's. Eve will also be able to intercept messages sent in the other direction (those sent by Bob to Alice) to pass herself off as Bob in Alice's eyes.
[0116] This attack, feared by information systems security specialists, is unstoppable as long as Alice and Bob do not have a secure means of carrying out the initial authentication which would then allow them to thwart a man-in-the-middle attack.
[0117] To avoid the threat of a man-in-the-middle attack, one solution is for Alice and Bob to rely on a public key infrastructure (PKI).
[0118] A PKI is based on the digital signature mechanisms enabled by asymmetric cryptography and on the implementation of certificates digitally signed by a third-party entity (external to Alice, Bob and Eve) called a “trusted” entity or third party.
[0119] [Fig.2] illustrates in a simplified manner the operational mechanism of an infra PKI structure for an example where Alice (A) wants to develop a business by offering an online sales service on the internet. To do this, she must deploy a 202 server which must provide guarantees of authenticity (in the sense of authenticity of the source) to all her future online customers, in the example Bob (B). When a customer connects to Alice's server, he must be certain that it is indeed Alice's server that he is connecting to and not a fraudulent server that would have been set up by Eve (E) to retrieve sensitive information (for example, bank card numbers).
[0120] In order to guarantee the authenticity of her server to her clients, Alice asks her server to produce a public / private key pair 204 (a key pair). Then, she creates a file to request a certificate that will authorize her to connect her server to the web. She sends 206 to a Certification Authority (CA) her public key with all the information related to her commercial activity: her company's Siret number, proof of legal deposit and other official documents.
[0121] The CA will propagate 208 Alice's request to a Registration Authority (RA) which will contact Alice through another channel 210 to verify that she is indeed the person (or business entity) she claims to be. Once this verification is done, the RA gives the green light to the CA so that the latter can create the certificate containing Alice's public key and sign it with her private CA key known only to her. Once Alice has received her certificate signed by the CA 212 and which contains her public key, she can connect her server to the internet.
[0122] Bob (B) can then connect to Alice's server with complete confidence. To ensure that, when he connects to Alice's server, he will be connected to it and not to a fraudulent server, Bob knows that his internet browser, which was installed at the same time as his operating system OS, already contains a panel of several certificates from various certification authorities, but all recognized as being trusted. He will find, among others, the self-signed 214 certificate from the CA that also signed Alice's certificate.
[0123] When Bob connects to Alice's server, the latter will send him a 216 message signed with Alice's private key and which contains Alice's certificate (with her public key) signed by the CA. Bob's computer will perform some checks to authenticate the message and also the certificate it contains: it will countersign the certificate received with the public key of the CA that it has to verify that the certificate is authentically Alice's and not a certificate forged by Eve; it will countersign the message received with Alice's public key to verify that it was indeed Alice's server (the only one with the private key) that sent the message containing the certificate.
[0124] Thus, at this point in the exchange:
[0125] - Bob, the client, is certain to be connected to Alice's server;
[0126] - Alice's server doesn't know much about the connected client, but that's not serious in the sense that the server is ready to chat with already registered customers or even with new customers.
[0127] The rest of the exchange will allow Bob's computer to exchange or establish (depending on the asymmetric cryptography mechanism chosen but not detailed here) with Alice's server a symmetric secret key 218. Once the symmetric secret key is in the possession of Bob's computer and Alice's server, they will be able to exchange data that will be encrypted and authenticated using symmetric cryptography mechanisms. Bob can then, in complete confidentiality, enter his identifiers 220 - his login and password - to authenticate himself to the server as an already registered client, and access his personal client account.
[0128] In this configuration:
[0129] - Bob is certain to be connected to Alice's server;
[0130] - Alice's server is certain to be connected to Bob's computer;
[0131] - Alice's server and Bob's computer have a common secret key which allows them to exchange confidential and authenticated information without Alice having to physically meet Bob to share the secret key.
[0132] The initial mutual authentication was thus carried out by:
[0133] - sending to Bob, Alice's certificate signed by the CA at the very beginning of the communication communication;
[0134] - sending Bob's connection identifiers, once the secure channel is established with the shared secret key.
[0135] In summary, three steps are required to set up a fully secure communication between a client (B) and a server (A) on the internet. A first step of initial mutual authentication by exchange of signed certificates which are countersigned via the public key of a recognized CA. The exchanges are themselves signed / countersigned with the public / private keys of A and B. A second step of exchange of the secret key with mutual authentication by signature / countersignature with the authenticated private / public keys of A and B. A third step of secure communication with mutual authentication by symmetric encryption / decryption of the message digests based on a one-way hash function.
[0136] It appears that all the steps involve a mutual authentication mechanism. Authentication of the source is thus essential and must be guaranteed from the very first contact (i.e. initial mutual authentication) until the last exchange, in any secure communication. During the exchanges, which are all secured with the shared symmetric secret key, the authenticity of the messages (authentication of the source and integrity) is ensured by symmetric secret key cryptography coupled with a one-way hash function which takes over until the end of the communication.
[0137] This example shows that a PKI infrastructure is not in itself much simpler than a SKI infrastructure. However, for the end user, a PKI is much simpler to manage. In the example of Bob's computer connecting to Alice's server, Bob simply has to manage his login and password. Everything else in the process is managed, without his knowledge, by the infrastructure of certificates deployed in upstream in Alice's server and in Bob's computer's Internet browser. Each time Bob connects to a server on the Internet, he unknowingly uses cryptographic mechanisms of rare complexity whose sole purpose is to secure his connection and simplify his task.
[0138] The present invention, applicable to the space domain, aims to enable space solution operators to manage, in a simple manner, the securing of on-board-ground links between their ground control segment and their satellite(s).
[0139] Generally speaking, the device of the invention is based on a public key management infrastructure, e.g. PKI type, with an intermediary of digitally signed certificates.
[0140] [Fig. 3] is a schematic illustration of a public key key management infrastructure 300 for space system communications, according to one embodiment of the invention, which makes it possible to "key" a control ground segment 302 and a satellite 304.
[0141] The expression "to put the key" refers to the fact of getting the two parties involved in a communication to share the same symmetric secret key which will allow them to ensure the security of their communications.
[0142] The space system is said to be "closed" and "private" in the sense that the recipients (the ground control segment and the satellite) of the certificates containing the public keys are identified in advance and do not change over time. The space system considered is "static" and does not change over time, unlike an open system such as the Internet.
[0143] In the example, for reasons of simplification of the illustration, a key registration authority is confused with a certification authority 306, the functions of the key registration authority being supported by the certification authority AC (i.e. on a device implementing the functions of a certification authority).
[0144] The implementation of the public key key management infrastructure according to the invention makes it possible to deploy certificates in the ground cryptographic equipment 302 and in the ground satellite 304, advantageously without any of the deployed elements being confidential.
[0145] The process implemented to deploy the certificates consists of a succession of the following steps:
[0146] - a step where the AC 306 produces its own public / private key pair (key public AC / private AC key);
[0147] - a step where the AC 306 constitutes a certificate 308 containing its public key, self-signed certificate with its private key which is known only to it;
[0148] - a step where the self-signed certificate 308 of the CA 306 is transmitted on the one hand to the ground cryptographic equipment 302 and on the other hand to the cryptographic function present in the satellite 304 on the ground;
[0149] - a step where the ground cryptographic equipment 302 produces its own torque of public / private keys (public key sol / private key sol);
[0150] - a step where the public key sol of the cryptographic equipment sol is transmitted to the CA which integrates it into a certificate which is signed with the CA's private key;
[0151] - a step where the signed certificate 310 containing the public key of the crypto equipment ground topographic is transmitted by the AC to the ground cryptographic equipment.
[0152] Those skilled in the art understand that the implementation of each step can be carried out by known techniques such as described previously for a PKI type infrastructure.
[0153] This preliminary phase of deployment of the PKI infrastructure, which takes place before the launch of the satellite, allows the ground cryptographic equipment to have (a) a ground private key which is specific to it and which must remain confidential, and (b) its certificate which contains its ground public key and which is signed by PAC.
[0154] This preliminary phase of deployment of the PKI infrastructure, which takes place before the launch of the satellite, also allows the satellite cryptographic equipment to have the self-signed certificate of the CA which contains the CA public key of the CA. This will allow it to countersign (i.e. to authenticate) the messages received from the ground segment (those signed with the ground private key).
[0155] Thus, through this preliminary phase, the only two sensitive elements which must remain confidential are the private key AC of the certification authority (which is located at the PAC level), and the private ground key of the ground equipment (which is located at the ground equipment level).
[0156] Advantageously, none of the sensitive elements are, at any time, transported from one piece of equipment to another. This makes it possible to minimize the risks of compromise linked to the handling of sensitive and confidential elements.
[0157] The satellite therefore did not carry, before the launch, a sensitive secret element which would need to be guaranteed confidentiality during the entire sequence of preparation for the launch on the ground.
[0158] The initial deployment of certificates in the satellite and at the level of the control ground segment according to the method described, guarantees that a third party (i.e. Eve) will never be able to pass itself off as the control center and therefore take control of the satellite.
[0159] Once the PKI infrastructure is fully deployed, the satellite is devoid of any sensitive element. The satellite therefore did not carry any initial secret before being put into orbit.
[0160] After the preliminary phase, the satellite is put into orbit. Another object of the invention relates to the authentication between a control ground segment and a orbiting satellite whose respective certificates were initially deployed according to the method of the invention described for the preliminary phase.
[0161] [Fig.4] schematically illustrates the general principle of the authentication method according to one embodiment of the invention. The inventors designate the principle by the acronym KARMAH for “Key negotiAtion pRotocol with semi-Mutual AutHentication” in English, or key negotiation protocol with semi-mutual authentication.
[0162] A control ground segment 402 which has (a) a ground private key and (b) its certificate signed by a certification authority and which contains its ground public key (by the implementation in a preliminary phase of the PKI infrastructure according to the invention), wishes to authenticate a satellite 404 in orbit, which has a self-signed certificate from the same certification authority and which contains the public key AC of the certification authority (still by the implementation in a preliminary phase of the PKI infrastructure according to the invention).
[0163] Advantageously, instead of using an initial secret to authenticate the satellite as in the solutions of the prior art, the ground control segment relies on non-confidential public parameters linked to the satellite itself.
[0164] Different types of public parameters can be taken into account by the ground control segment. The following examples can be named:
[0165] - satellite ephemerides, i.e. parameters linked to its orbital position, as are azimuth and elevation in the case of a geostationary satellite, and as illustrated in [Fig.4];
[0166] - characteristics of a modulated signal emitted by a telemetry transmitter or by a beacon of the targeted satellite. These modulation characteristics are designated by the term (RFF) for “Radio Frequency Fingerprint” in English or RF fingerprint;
[0167] - a Doppler of a descending modulated signal, in the case of moving satellites (in low Earth orbit (LEO)
[0168] - a thermal signature of the satellite (provided that the ground station has a infrared detector sufficiently precise to carry out this type of measurement).
[0169] The physical parameters allow the ground control segment 402 to authenticate with certainty the satellite 404 with which it wishes to establish secure communication.
[0170] Indeed, concerning ephemerides, national and international organizations, such as space agencies or the North American Aerospace Defense Command (NORAD), are responsible for mapping the sky with respect to objects in orbit. It is therefore impossible to position a satellite in orbit without it being listed and characterized from the point of view of its ephemerides.
[0171] The authentication according to the invention is said to be semi-mutual, in that on the communication channel, only the control ground segment authenticates itself by cryptographic means with respect to the satellite.
[0172] The ground control segment 402, after having authenticated the satellite by one or more physical parameters, sends it a ground message (406) signed with its ground private key which contains its ground certificate signed by the AC, and its ground public key.
[0173] The satellite, when receiving the certificate sent by the control ground segment, can authenticate it using the AC public key of the AC that it already possesses. This allows the initial authentication of the ground by the satellite to be resolved, and allows the satellite to formally authenticate the source of the message that contains the certificate.
[0174] Once the satellite 404 has the public key of the ground segment, communication for exchanges or for establishing a secret key can begin.
[0175] Uplink messages are authenticated on board the satellite via signature with the ground private key and countersignature with the on-board public key.
[0176] For downlink messages, it is the orbital position of the satellite (or any other physical means linked to the satellite) which authenticates the source.
[0177] [Fig.5] schematically illustrates the establishment or exchange of secret keys between a control ground segment 502 and a satellite 504, according to one embodiment of the invention.
[0178] In this phase of establishing or exchanging a secret key between the satellite and the ground control center, the messages sent by the ground control center are signed with the private key of the ground control center and countersigned by the satellite with the public key of the ground control center. The satellite in orbit, the source of the messages sent to the ground control center, is authenticated by one of its physical characteristics, which implicitly authenticates the messages sent by the satellite to the ground control center.
[0179] Advantageously, different key exchange protocols of the key encapsulation mechanism (KEM) type can be used to securely transmit a session key using an unsecured channel.
[0180] More generally, all asymmetric signature, key exchange or key establishment mechanisms used can be based on pre-quantum asymmetric algorithms (RSA, DSA, Diffie-Hellman, elliptic curves, etc.) or on post-quantum asymmetric algorithms (CRYSTAL-KYBER, CRYSTAL DILITHIUM, FALCON, SPHINCS+, etc.).
[0181] In one embodiment, the key exchange mechanism consists of:
[0182] - satellite 504 generates symmetric secret keys (which will then be used to secure the TM / TC edge-to-ground links);
[0183] - satellite 504 encrypts the symmetric secret keys with the public key of the ground ground control segment 502;
[0184] - satellite 504 sends the encrypted secret keys to the control ground segment 502;
[0185] - the control ground segment 502 receives the encrypted secret keys and authenticates the origin of this key via the orbital position of satellite 504 transmitting the encrypted keys;
[0186] - the control ground segment 502 decrypts the secret keys with its private ground key;
[0187] - the control ground segment 502 and the satellite 504 share the same set of keys secret keys which then allow them to carry out TM / TC exchanges which are secure (confidentiality and authenticity of messages) thanks to the shared secret keys.
[0188] According to other embodiments, key establishment protocols of the “Key Agreement” or “Key Negotiation” type may be used.
[0189] Thus, in a particular embodiment:
[0190] - the satellite generates a pair of public and private elements (according to the protocols key establishment based on asymmetric Diffie-Hellman type mechanisms which are not detailed here);
[0191] - the control ground segment generates a pair of public and private elements;
[0192] - the satellite sends its public element to the control ground segment;
[0193] - the ground control segment sends its public element to the satellite;
[0194] - the control ground segment (ground) and the satellite (edge) apply a function 'F' identical on the elements they have (public and private) to arrive at the same common secret 'K'.
[0195] The function 'F' for the ground is of type:
[0196] F[public element ground, public element edge, private element ground] = Secret key K shared ground-edge.
[0197] The function 'F' for the edge is of type:
[0198] F[public element ground, public element edge, private element edge] = Secret key K shared ground-edge.
[0199] The ground control segment and the satellite then share the same secret key K which allows them to carry out TM / TC exchanges which are secure (confidentiality and authenticity of messages) thanks to the shared secret key.
[0200] Key establishment (or key negotiation) protocols base the generation of the secret key on the exchange of public ephemeral elements which are renewed each time a new secret key must be established.
[0201] Key exchange protocols (or KEM key encapsulation) require the use of the private key / public key pair of the ground segment to encrypt / decrypt the secret key exchanged between the edge and the ground. The key pair of the ground segment being a persistent element, it does not guarantee the independence of the secret keys whose Security depends on the private key present at the ground segment level. Therefore, key establishment protocols are preferred over key exchange protocols.
[0202] Thus, a method has been described where the integrity of the certificate of the certification authority is ensured by a one-way hash function without a key. When the CA produces its self-signed certificate, it passes it through a secure hash function to produce a reference summary. This reference summary makes it possible to verify at key moments in the life of the satellite (just before the launch, just after the positioning, before the transmission of the certificate from the ground to the satellite, etc.) that the certificate of the CA, on board the satellite, is still intact. The edge calculates, on request, the certificate summary with the same one-way hash function without a key as that which was used when calculating the reference summary by the CA. The ground can compare the summary calculated by the edge with the reference summary to verify that the certificate of the CA which is on board is indeed intact and that it is not corrupted.
Claims
1.
2.
3. Claims A method of managing keys for establishing secure communications between a ground control center (402) and an orbiting satellite (404), the method comprising steps consisting of: - in a phase where the satellite is on the ground, to operate an asymmetric cryptography protocol with a certification authority (306), making it possible to deploy: - on cryptographic equipment (302) of the ground control center, a ground private key and a certificate (310) signed by the certification authority, containing a ground public key; and - on cryptographic equipment (304) of the ground satellite, a certificate (308) self-signed by the certification authority, containing a public key AC of the certification authority, such that no initial secret element needs to be on board the ground satellite; - in a phase where the satellite is in orbit, to operate a semi-mutual authentication protocol, between the ground control center and the satellite in orbit, consisting of: - for the cryptographic equipment of the ground control center: to authenticate the satellite by one or more physical characteristics identifying the satellite; to send to said authenticated satellite, a message (406) signed with the ground private key, said message containing the certificate self-signed by the certification authority and the ground public key; and - for the cryptographic equipment of the satellite in orbit: to authenticate the certificate received from the cryptographic equipment of the ground control center, using the public key AC of the certification authority. Method according to claim 1 wherein the step of operating an asymmetric cryptography protocol with a certification authority (306), comprises: - a step where the certification authority produces a public / private AC key pair (AC public key, AC private key); - a step where the certification authority constitutes a self-signed certificate with said private key AC, and containing said public key AC; and - a step where said self-signed certificate (308) is transmitted on the one hand to the ground cryptographic equipment (302) and on the other hand to the cryptographic equipment (304) of the satellite on the ground. The method of claim 2 further comprising: - a step where the ground cryptographic equipment (302): produces a public / private ground key pair (ground public key, ground private key); and transmits said ground public key to the certification authority (306); - a step where the certification authority (306): integrates the received ground public key into a certificate; signs it with said private key AC; and transmits the signed certificate (310) to the ground cryptographic equipment.
4. A method according to any preceding claim wherein the certification authority is capable of performing key registration functions.
5. Method according to any one of the preceding claims in which the step of authenticating the satellite by one or more physical characteristics, consists of authenticating said satellite by its ephemerides, by authenticating parameters linked to its orbital position, in particular the azimuth and the elevation.
6. Method according to any one of the preceding claims in which the step of authenticating the satellite by one or more physical characteristics, consists of authenticating said satellite by characteristics of a modulated signal emitted by a telemetry transmitter or by a beacon of the targeted satellite.
7. A method according to any one of the preceding claims wherein the step of authenticating the satellite by one or more physical characteristics, comprises authenticating said satellite by a Doppler of a downlink modulated signal.
8. A method according to any one of the preceding claims wherein the step of authenticating the satellite by one or more physical characteristics, consists of authenticating said satellite by a thermal signature of the satellite.
9. A method according to any preceding claim further comprising, after the semi-mutual authentication between the ground control center and the orbiting satellite, steps consisting of establishing or exchanging secret keys between the ground control center (502) and the authenticated satellite (504).
10. A computer program comprising code instructions for carrying out the steps of the method according to any one of the preceding claims, when said program is executed on a system comprising a ground control center (302) and a satellite (304).
11. A system comprising a key management device, a ground control center (402) and a satellite (404), said key management device enabling the establishment of secure communications between a control center and a satellite in orbit, such that no initial secret element needs to be carried on the ground satellite, the system comprising means for implementing the steps of the method according to any one of the preceding method claims.