Method and device for sharing secret keys in a network including a satellite

The method and device for sharing secure secret keys via a satellite decouples quantum key exchange from distribution, using symmetric encryption to transmit encrypted keys over conventional channels, addressing long-distance and weather limitations in QKD, thereby simplifying network planning and increasing key availability.

FR3152936B1Active Publication Date: 2026-02-20THALES SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023009403
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-09-07
Publication Date
2026-02-20
Estimated Expiration
2043-09-07

AI Technical Summary

Technical Problem

Existing quantum key distribution (QKD) methods face limitations in long-distance communication and require complex planning due to line-of-sight constraints and weather dependencies, making them impractical for widespread use.

Method used

A method and device for sharing secure secret keys via a satellite that decouples the exchange of quantum keys from their distribution, allowing for opportunistic use and flexible planning by using symmetric encryption methods to transmit encrypted keys over conventional channels.

Benefits of technology

This approach simplifies network planning, enhances availability, and increases the number of secure keys available for communication, overcoming distance and weather limitations of traditional QKD methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000019_0000
    Figure 00000019_0000
  • Figure 00000019_0001
    Figure 00000019_0001
  • Figure 00000020_0000
    Figure 00000020_0000
Patent Text Reader

Abstract

Method for distributing pairs of secure secret keys intended to secure communications between a first communication station (S1) and a second communication station (S2), said method comprising the following steps: exchanging, via a quantum channel (CQ1) linking a satellite (Sat) to said first communication station (S1), a first secret key; exchanging, via a quantum channel (CQ2) linking said satellite (Sat) to said second communication station (S2), a second secret key; receiving, in said satellite, a communication request between the first and second communication stations issued by said first or second communication station, referred to as the transmitting station; encrypting, in said satellite, the first secret key (by a symmetric encryption method which uses the second secret key (,in order to generate a first encrypted message ( ) and transmit said first encrypted message to said second communication station (S2) via an authenticated channel ( , called first authenticated channel. [Fig. 3A],
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method and device for sharing secret keys in a network including a satellite. Technical field

[0001] The present invention relates to the field of information technology security and more particularly to the field of sharing encryption keys by satellite via quantum channels. Previous technique

[0002] There has always been a need to exchange sensitive information, which must remain secret, via a public communication channel. Suppose that two people, Alice and Bob, wish to exchange sensitive information, protected from prying eyes, via an authenticated public communication channel (for example, the internet). To do this, they must encrypt their messages. Let's call Eve the person who wants to intercept these messages. Alice must use a published (i.e., non-secret) cryptographic function and a secret key to encrypt her messages before sending them to Bob via a public channel. When Bob receives the encrypted messages, he must use the same cryptographic function and secret key as Alice to decrypt them in order to access the plaintext information.

[0003] The problem now arises of the secret key shared between Alice and Bob: how is it generated, how is it exchanged securely and away from prying eyes?

[0004] During secure internet exchanges, the establishment of a shared secret key is carried out using techniques based on public-key cryptography, which we will not detail here. A new solution was conceived at the end of the 20th century. It proposes using a quantum channel that allows Alice and Bob to establish a common secret key by exchanging quantum particles (e.g., photons) without Eve being able to recover the key by intercepting these particles. However, this technique of key sharing via quantum channels (QKD for Quantum Key Distribution) suffers from some limitations that make it difficult to apply to a large number of users and over very long distances. This could, in the long term, make this technique unattractive and therefore not profitable enough to generate industrial opportunities.

[0005] Figure 1 schematically represents the architecture of a quantum channel that allows two users, Alice (the particle emitter) and Bob (the particle receiver), to establish a common secret key. The key is a sequence of bits, random, therefore able to take the value 0 or 1. For example, within the BB84 protocol, Alice proposes key bits using two photon polarization modes prepared by Alice; the choice of polarization mode is random. Alice records the randomly chosen polarization mode for each bit (i.e., each photon). Using a polarizing filter and a photon detector that can be oriented alternately according to the two randomly chosen polarization modes, Bob records the detection result (the photon exited the filter via the 'parallel' or 'perpendicular' path to its axis), as well as the chosen orientation of the filter.

[0006] In BB84, once the entire sequence has been transmitted, Alice sends Bob the polarization modes used for each detection via an authenticated clear channel. Bob can then deduce the value of the bits for which the polarization orientation was the same. He then knows with certainty NU bits on average for N bits transmitted by Alice; this sequence is called the reconciled key. This step can be accompanied by error correction procedures using check values ​​and LDPC or cascade-type algorithms, which use control parameters exchanged over the authenticated channel.

[0007] Finally, Alice and Bob agree on a subset of bits from the reconciled key. They then compare whether they obtained the same bits in this subset. Each difference is attributed by default to an eavesdropper (even though measurement errors may also have caused them). Indeed, the no-cloning theorem guarantees that in the event of eavesdropping, Eve forces the photon into a polarization mode (which is not necessarily Alice's). So, if Eve correctly guesses Alice's mode with a probability of 50%, then 25% of the bits in the reconciliation key will be in disagreement between Alice and Bob. At this stage, a mathematical security proof allows us to evaluate, based on the number of different bits, the amount of potentially compromised information and to define a one-way hash function which, when applied to the reconciled key, produces a smaller key that no longer contains any compromised information.This is the confidentiality amplification stage, which provides a secure key.

[0008] At the ground network level, key exchange (or more precisely: key establishment) via a quantum channel is straightforward, using an optical communication channel carried by optical fiber. However, the exchange of single polarized photons (or very low-intensity light pulses) through a fiber does not allow Alice and Bob to exchange these photons beyond a few tens of kilometers, which represents the combined asymptote of the probability of 100% absorption of the photons by the material composing the optical fiber and the shortening of the key due to privacy amplification.

[0009] Consequently, the architecture of quantum channel networks is strongly impacted by this physical constraint. Two solutions have been devised to overcome this distance limitation in optical fiber.

[0010] The first solution considered is to propagate the keys via so-called "trusted nodes" placed at regular intervals (every 50 kilometers, for example). Figure 2A schematically illustrates a known prior art trusted node key generation device. The trusted node manipulates in plaintext the key established with Alice (Key A) and the key established with Bob (Key B). This trusted node is positioned approximately equidistant between Alice and Bob and allows the key establishment range via quantum channels to be doubled. The trusted node then uses the one-time pad technique to transmit this key A to Bob. To do this, the trusted node performs an XOR operation (bit-by-bit exclusive OR logic gate) between Alice's key and Bob's key. "XOR" here and throughout the rest of this document refers to combining two keys using the exclusive OR operator, symbol ®.The result is transmitted to Bob via an authenticated clear channel. Bob, who holds key B, can then perform another XOR operation between the sequence received from node #2 and his key (Key B) to recover Alice's key (Key A).

[0011] This first solution relies on the property of the XOR function: A → B → B = A → (B → B)→∞ = A, but also on the one-time pad (OTP) cryptography technique, which guarantees that it is not possible to recover key A and / or key B using only the sequence Key A → Key B. A → B is called the "ciphered key." The one-time pad technique is based on the following principle: any message to be encrypted will be encrypted with a strictly random key, the size of the message, which will be combined with the plaintext to produce the ciphertext. Decryption will be performed by carrying out the inverse operation on the ciphertext using the same secret key. This technique has been demonstrated to be theoretically secure by Claude Shannon, regardless of the attacker's means, provided that three absolutely fundamental rules are respected: A. The key must be as long as the message to be encrypted. B. The key must be strictly random; the elements that constitute the key (bits) (or characters) of the key must all be independent of each other. C. Each key (or mask) must be used only once to encrypt a single message.

[0012] However, this first solution requires that the trusted nodes, which handle the keys in plaintext, be secured with a very high level of security, which entails significant additional costs and operational constraints. Furthermore, this type of solution is difficult, if not impossible, to implement for interconnecting two users separated by an ocean (it is difficult and expensive to implement trusted nodes every 100km in the ocean).

[0013] The second solution is to exchange photons in free space, and from space to reach long distances. In this case, the 100-kilometer limit of optical fiber is no longer applicable, and it is possible to distribute encryption keys to two users located anywhere on Earth via QKD channels from space. This configuration is illustrated in Figure 2B. In this case, the satellite acts as a trusted node since it establishes a key A with Alice (for example, a ground station) and a key B with Bob (for example, another ground station) and then transmits key A → key B (encryption key) to Bob over a clear and authenticated conventional communication channel during the flyby of Bob's station.On the ground, Bob, holder of key B, will be able to extract key A from Alice by performing an XOR operation on key B with the Key A ® Key B sequence encryption key that the satellite will have brought back down to him. Here, the satellite, if it is in low Earth orbit, moves relative to Alice and relative to Bob. Therefore, regardless of the distance between Alice and Bob, the satellite acts as a mobile trusted node capable of establishing Key A and Key B and distributing the Key A ® Key B combination that allows Alice and Bob to share a common secret key (Key A).

[0014] In this second solution, the 'pair management' aspect of ground stations and the 'overflight of paired stations' aspect are likely to strongly constrain the planning of quantum optical contacts between station and satellite in the generally considered means. Indeed, the satellite trajectories are extremely rigid, and the optical contact periods between satellites and ground stations, while predictable, are not flexible. Moreover, cloud cover is likely to interrupt the quantum channel linking the satellite and a ground station and thus prevent the establishment of an elementary satellite-station link. In this case, the exchange planning must therefore be able to be updated.

[0015] These constraints make planning contacts between stations and satellites very complex and inefficient. Indeed, the solution in [Fig. 2B] requires a precise sequence of the different contacts, due to the fact that it does not manage point-to-point connections, but rather pairs of connections to share keys between pairs of ground stations. If the sequence is interrupted by an unforeseen weather disturbance, service availability can be jeopardized because the visibility of the station to be connected may not reappear for several days. Consequently, strategies for optimizing contacts between satellites and stations are extremely complex and require solving problems for which the optimum is difficult to determine.

[0016] The invention aims to overcome certain problems of the prior art. To this end, an object of the invention is a method and a device for distributing secure secret keys intended to secure communications between a first communication station and a second communication station in a network including a satellite. In the method and process of the invention, the secure secret keys are shared by a pair of stations in a step temporally separate from the step in which these keys are generated by QKD. In the invention, the distribution of the secure secret keys to the pair of stations is carried out via a channel that does not necessarily require line of sight between the satellite and the stations and can be done much later depending on user needs. The solution of the invention allows for a more opportunistic use than prior art solutions of pre-established but not pre-allocated keys to a pair of stations. Summary of the invention

[0017] To this end, an object of the invention is a method for sharing secure secret keys intended to secure communications between a first communication station and a second communication station, said method comprising the following steps: A. exchange, via a quantum channel linking a satellite to said first communication station, a first secret key B. exchange, via a quantum channel linking said satellite to said second communication station, a second secret key C. to receive, in said satellite, a communication request between the first and second communication stations D. encrypt, in said satellite, the first secret key by a symmetric encryption method which uses the second secret key, so as to generate a first encrypted message and transmit said first encrypted message to said second communication station by an authenticated channel, said first authenticated channel.

[0018] According to a preferred embodiment, the method of the invention includes a subsequent step E which consists of deciphering, in said second communication station, the first message encrypted using the second secret key, so as to obtain the first secret key, the first secret key forming the secure secret key.

[0019] Preferably, in the preferred embodiment, the symmetric encryption method is the one-time pad method, wherein the first and second secret keys and the first message are binary-encoded, the generation of the first encrypted message being performed by the XOR logic gate combining the first and second secret keys, the decryption of the first encrypted message being achieved by the XOR logic gate combining the first encrypted message with the second secret key.

[0020] Preferably, in the preferred embodiment, the method of the invention comprises two further steps F and G which consist of:

[0021] F- encrypt, in the first communication station, a non-random message using the first secret key and then transmit the encrypted non-random message to the second communication station'

[0022] G- decrypt said non-random message encrypted using the first secret key.

[0023] Preferably, in the preferred embodiment, steps A to E are repeated a plurality of times in order to form a plurality of secure secret keys.

[0024] According to one embodiment, step B requires a reconciliation substep carried out via said first authenticated channel.

[0025] Preferably, in the preferred embodiment, steps A to E are repeated a plurality of times with a pair of communication stations different from the first and second communication stations.

[0026] Preferably, in the preferred embodiment, the method of the invention further comprises a step D' and a step E', said step D' consisting of encrypting, in said satellite, the second secret key by a symmetric encryption method which uses the first secret key so as to generate a second encrypted message and transmit said second encrypted message to said first communication station, by an authenticated channel said first authenticated channel, said step E' consisting of decrypting, in said second communication station, the first encrypted message using the second secret key so as to obtain the first secret key.

[0027] Another object of the invention is a satellite for distributing a secure secret key intended to secure communications between a first communication station and a second communication station, said satellite being adapted for - exchange, via a quantum channel linking said satellite to said first communication station, a first secret key - exchange, via a quantum channel linking the satellite to the said second communication station, a second secret key - receive a communication request between the first and second communication stations issued via a clear request channel - encrypt the first secret key by a symmetric encryption method which uses the second secret key, so as to generate a first encrypted message and transmit said first encrypted message to said second communication station by an authenticated channel called first authenticated channel.

[0028] Another object of the invention is a communication system comprising the satellite according to the invention and comprising the first and second communication stations, said second communication station being adapted to decrypt the first encrypted message using the second secret key, so as to obtain the first secret key, the first secret key forming the secure secret key.

[0029] According to a preferred embodiment of the communication system of the invention, the first authenticated channel is different from the quantum channel linking the satellite to said second communication station. Preferably, the first authenticated channel is a bidirectional telemetry / remote control link for said satellite.

[0030] According to one embodiment of the communication system of the invention, the first authenticated channel is relayed by an additional satellite via an optical or RF intersatellite link connecting the satellite and said additional satellite.

[0031] According to one embodiment of the communication system of the invention, the first authenticated channel is an RF or optical anchor link of a telecommunications service carried by the satellite

[0032] According to one embodiment of the communication system of the invention, the clear request channel is relayed by a local station capable of communicating with said satellite via an authenticated local link. Brief description of the drawings

[0033] Other features, details and advantages of the invention will become apparent from the description given with reference to the accompanying drawings provided by way of example, which represent, respectively:

[0034] [Fig. 1] a schematic view of a QKD device according to the prior art,

[0035] [Fig.2A], a schematic view of a QKD key generation device by satellite of the previous art,

[0036] [Fig.2B], a schematic view of a node-based key generation device confidence in prior art,

[0037] [Fig. 3A], a schematic view of a method for distributing secure secret keys according to the invention,

[0038] [Fig. 3B], a schematic view of a secret key distribution system according to the invention,

[0039] [Fig. 3C], a schematic view of a method for generating a secure secret key according to a preferred embodiment of the method of the invention

[0040] [Fig. 3D], a schematic view of a method for generating a secure secret key according to an embodiment of the method of the invention

[0041] [Fig.3E], a schematic view of a secret key distribution system according to a method of embodiment of the invention,

[0042] [Fig.3F], a schematic view of a secret key distribution system according to an embodiment of the invention,

[0043] [Fig.4], a schematic view of a method for generating a secure secret key according to a preferred embodiment of the method of the invention

[0044] [Fig. 5A], a schematic view of a method for generating a secure secret key according to an embodiment of the method of the invention

[0045] [Fig. 5B], a schematic view of a secret key distribution system according to a method of embodiment of the invention,

[0046] In the figures, unless otherwise indicated, the elements are not to scale. Description of the implementation methods

[0047] Figure 3A schematically illustrates a method according to the invention for distributing a secure secret key intended to secure communications between a first communication station S1 and a second communication station S2.

[0048] Figure 3B schematically illustrates a communication system according to the invention comprising the first and second communication stations SI, S2, and a Sat satellite. The Sat satellite is adapted to implement the method of Figure 3A. By way of non-limiting example, Figure 3B illustrates an embodiment in which system 1 comprises two communication stations. Alternatively, according to another embodiment, system 1 comprises more than two communication stations.

[0049] In a first step A of the method of the invention, the satellite Sat establishes a first secret key, denoted Ki, with the first station Si via a quantum channel CQi. This channel CQi connects the satellite Sat to the first communication station Si. This step A is performed when the satellite Sat is in position A, during the overflight of station Si by the satellite Sat, and requires that the satellite Sat be within optical line of sight of station Si in order to transmit and detect qubits. In step A, the transmission of qubits can occur from the satellite Sat to station Si or vice versa.

[0050] In a step B, the satellite Sat is adapted to exchange a second secret key K2 with the second communication station S2 via a quantum channel CQ2 linking the satellite Sat to the second communication station S2. Step B is carried out when the satellite is in position B, during the satellite's flyover of station S2, and requires that the satellite Sat be within line of sight of station S2. In step B, the transmission of qubits can occur from the satellite Sat to station S2 or vice versa.

[0051] Satellite Sat knows and stores all the secret keys K1 and K2 in plain text, these keys forming the secure secret key pair. This satellite is therefore the trusted node of system 1.

[0052] In the invention, the steps for exchanging the secret key via a quantum channel can be performed using any QKD protocol known to those skilled in the art. It should be noted that cloud cover over a terrestrial communication station blocks any free-space optical link in the visible and near-infrared ranges. Furthermore, the sun generates large quantities of stray photons through atmospheric diffraction (indirect irradiance), which significantly degrade the detection of qubits, potentially leading to link failure. Thus, the current state of the art in satellite QKD allows the transmission of qubits via the near-infrared optical link through the atmosphere under clear skies, and especially at night. Therefore, the availability of the quantum channel between a satellite and a terrestrial communication station is dependent on weather events and conditions above the station.

[0053] Following steps A and B, the method of the invention includes a step C consisting of receiving, in the satellite Sat, a communication request between the first and second communication stations SI, S2, via a clear request channel CR. In the embodiment illustrated in [Fig. 3B], by way of example, this request is transmitted by the first communication station Si, referred to as the transmitting station, via a clear request channel CR when the satellite is in position C. Alternatively, according to another embodiment, the transmitting station is the second station S2.

[0054] After receiving the request, in a step D, the satellite Sat encrypts the first secret key using a symmetric encryption method that uses the second secret key Æ2, so as to generate a first encrypted message KCl2. Furthermore, step D includes the transmission of the first encrypted message to the second communication station S2 via an authenticated channel CA2, referred to as the first authenticated channel.

[0055] Following the method shown in Figure 3A, the second communication station S2 is able to decrypt the first encrypted message in order to obtain the first secret key K (see method in Figure 4). Thus, the first and second communication stations Sb and S2 can each possess the first secret key, which forms the secure secret key. Since the steps implemented in the method of the invention (QKD and symmetric encryption) are resistant to quantum threats, the method of the invention therefore makes it possible to provide a secure secret key for encrypting communications between station S1 and station S2.

[0056] It is important to note that in the invention, steps A and B of the exchange of the secret keys K2 by QKD are temporally uncorrelated with the distribution of the encrypted message KC12 to station S2 in step D. Thus, the distribution of the encrypted message KC1n via the CA2 channel does not necessarily require line of sight between the Sat satellite and station S2. The CA2 channel can therefore be any conventional opportunity channel authenticated in the RF or optical domain (see below). In practical terms, this means that the Sat satellite can be significantly further from station S2 when it performs the distribution of the encrypted KCi2 message than when it performs steps A and B. This temporal separation between the exchange of K2 secret keys by QKD and the distribution of the encrypted ÆC12 message is not present in prior art methods. Indeed, in these prior art methods, the distribution of the secure secret key was carried out by the satellite during its flyby of a station almost simultaneously with the establishment of an encryption key by QKD to encrypt the transmission of the secure secret key between the satellite and the station (see [Fig. 2B]).

[0057] The solution of the invention significantly simplifies the planning of operations compared to the prior art method illustrated in Figure 2B. Furthermore, the solution of the invention allows the distribution of the encrypted KCl2 message to be delayed, for example, according to the needs of the users of stations S1 and S2, and thus avoids prolonged storage of the secret keys KY, K2, and the message in station S2, which could potentially be compromised. Therefore, the solution of the invention allows for a more opportunistic use than prior art solutions of the secret keys K2, which are pre-established in steps A and B but not allocated in advance to the pair of stations S1 and S2.

[0058] It is understood that temporally decoupling the distribution of the encrypted KCn message to station S2 from the exchange of the Kv K2 secret keys by QKD to stations SI and S2 implies that the satellite can securely store the K2 keys after their exchange by QKD, at least until the distribution step D.

[0059] According to an embodiment illustrated in Figure 3C, the method of the invention further comprises a step D', in which the satellite encrypts the second secret key K2 by a symmetric encryption method that uses the first secret key to generate a second encrypted message KC2i. Furthermore, step D' comprises the transmission of the second encrypted message to the first communication station SI via an authenticated channel CAb, referred to as the second authenticated channel. As explained above, step E is temporally uncorrelated with step A, which involves exchanging the secret keys K1 by QKD. Figure 3D schematically illustrates a device adapted to implement the method of Figure 3C.Following the method shown in Figure 3C, the first and second communication stations SI, S2 are able to decrypt respectively the second and first encrypted messages in order to obtain respectively the second and first secret keys K2. Thus, the first and second communication stations SI, S2 have the ability to each obtain the first and second secret keys K2, which form a pair of secure secret keys allowing secure communication between stations SI and S2.

[0060] According to the invention, the symmetric encryption method for steps D and D' can be any block or stream method known to those skilled in the art, for example the one-time pad method or the AES (Advanced Encryption Standard) method or the Triple DES method.

[0061] As mentioned previously, the CA channel and the CA2 channel (when present) can be any conventional authenticated opportunity channels. According to a preferred embodiment of the invention, denoted MR, the first and second communication stations are ground-based terrestrial stations.

[0062] According to an embodiment of the method of the invention, denoted MP, in step A, the reconciliation substep necessary for the exchange of the first secret key Kx is performed via the second authenticated channel. Similarly, in step B, the reconciliation substep necessary for the exchange of the second secret key K2 is performed via the first authenticated channel. These reconciliation substeps, as well as the encrypted message distribution steps KC2Y EC?, do not require the Sat satellite to be within line of sight of stations SI and S2. Thus, it is possible to simplify the network architecture of system 1 by sharing some of the links necessary for its operation. This embodiment MP is compatible with embodiment MR.

[0063] According to another embodiment, compatible with embodiment MR and embodiment MP, the first authenticated channel and the second authenticated channel are each a bidirectional satellite telemetry / remote control link. Herein, a "bidirectional satellite telemetry / remote control link" is defined as a link enabling, on the one hand, the control, configuration, and programming of the satellite's mission, and on the other hand, the measurement of the satellite's configuration and status. Thus, it is possible to simplify the network architecture of system 1 by sharing some of the links necessary for its operation.

[0064] According to another embodiment of the system of the invention, the first authenticated channel and the second authenticated channel are each an RF or optical anchor link of a telecommunications service carried by the satellite.

[0065] Figure 3E schematically illustrates an embodiment of system 1 of Figure 3D, in which the authenticated channel CAY is relayed by an additional satellite SR via an inter-satellite link LI connecting the Sat satellite and the additional satellite SR. This LI link is, for example, an optical or RF link. This embodiment improves the availability of system 1, for example, when the Sat satellite is too far from the SI station to communicate with it directly without the intermediary of the additional satellite SR. More generally, according to one embodiment of system 1 of the invention, the first and / or the second authenticated channel is / are relayed by the additional satellite SR via the inter-satellite link LL

[0066] Advantageously, according to one embodiment of system 1 of [Fig. 3E], the additional SR satellite is configured to operate in geostationary orbit to maximize its availability. Alternatively, the additional SR satellite is in low Earth orbit (LEO) or medium Earth orbit (MEO).

[0067] Figure 3F schematically illustrates an embodiment of system 1 of the invention in which the communication request issued by the transmitting station is relayed to the satellite by a local station SL capable of communicating with the satellite via an authenticated local link LL. This embodiment is advantageous in order to take advantage of a possible overflight of the station SL by the satellite when the satellite Sat is too far from the transmitting station for the latter to transmit the communication request directly to it.

[0068] Figure 4 illustrates a preferred embodiment of the method of the invention. This method is particularly suitable for implementation by the system 1 of Figure 3B. The method of Figure 4 includes an additional step E which consists of decrypting, in the second communication station S2, the first encrypted message ÆC12 using the second secret key K2. Thus, station S2 obtains the first secret key

[0069] This step E is necessary so that stations SI and S2 both possess the secure secret key that they can subsequently use to encrypt non-random messages they wish to exchange (see Figures 5A and 5B). Indeed, given that the encryption of the secure secret key K is performed using a symmetric encryption method, the decryption of the first encrypted message KCn is carried out with the same key used for encryption, i.e., the second secure secret key K2. Thus, the method in [Fig. 4] makes it easy to distribute, securely and unbreakably—even against quantum attacks—a secure secret key for encrypting communications between station SI and station S2, by relaxing the key distribution constraints and doubling the volume of available secure secret keys compared to other prior art methods.

[0070] According to one embodiment of the method in [Fig.4], steps A to E are repeated a plurality of times in order to form a plurality of secure secret keys, each intended to secure communications between station SI and station S2.

[0071] When the method of Figure 4 is combined with the embodiment of Figure 3C, in addition to step E, the method includes a step E' which consists of deciphering, in the first communication station SI, the second encrypted message KC2l using the first secret key Kb. Thus, station SI obtains the second secret key K2.

[0072] In a preferred embodiment of the invention, the symmetric encryption method is the one-time pad method.

[0073] In this embodiment, the first and second secret keys K2, and the first encrypted message &C]2 (and KC2\ if applicable) are encoded in binary. Thus, the generation of the first encrypted message KCn (and ÆC2i if applicable) is performed by the XOR logic gate (of symbol ®) combining the first and second secret keys K2. More precisely, the first and second encrypted messages are identical and are obtained by the following logical operation &C]2 = ^21 = K-fa. Similarly, the decryption of the first and second encrypted messages KCn, KC2i is performed by the XOR logic gate combining, respectively, the first encrypted message with the second secret key and the second encrypted message with the first secret key. More precisely, the decryption of the second encrypted message KC2i in the first station SI corresponds to the logical operation: KC2fa = KjK2K}- K2.Similarly, decrypting the first encrypted message &Cl2 in the second station S2 corresponds to the logical operation: KCl2K2 = KXK2K2 = K v This embodiment is the one that allows the implementation of the least complex invention.

[0074] To ensure the security of the disposable mask technique, the first and second secret keys are of the same length (key size). More generally, in the invention, all steps implementing the disposable mask technique combine two keys that are of the same length.

[0075] Figure 5A illustrates a preferred embodiment of the method in Figure 4, enabling the secure exchange of a non-random message M between station S1 and station S2. Figure 5B schematically illustrates an embodiment of the system of the invention adapted to implement the method in Figure 5A. In addition to the steps detailed above, the method in Figure 5A includes two further steps F and G, which consist of:

[0076] F- encrypt, in the first communication station SI, a non-random message M using one of the first secret keys and transmit the encrypted non-random message MC to the second communication station S2'

[0077] G- decrypt the non-random message encrypted using the first secret key fa in step F. Thus, station S2 obtains the non-random message M in a perfectly secure manner.

[0078] According to an embodiment different from that illustrated in [Fig. 5B], the message M is exchanged from station S2 to station SL

[0079] According to a preferred embodiment of the method in Figure 5A, steps F and G are repeated a plurality n of times in order to encrypt a plurality of communications between station S1 and station S2. The number n of repetitions of steps F and G is less than a so-called critical number calculated from a cryptoperiod of the key used for encrypting message M and decrypting message MC. This feature prevents the compromise of the exchanged messages. We call Here, "crypto-period" is the number of uses of a key in an encryption algorithm that must not be exceeded in order to guarantee the security of the message encrypted by that key.

Claims

Demands

1. A method for sharing secure secret keys intended to secure communications between a first communication station (SI) and a second communication station (S2), said method comprising the following successive steps: A. exchange, via a quantum channel (QC) linking a satellite (Sat) to said first communication station (SI), a first secret key B. exchange, via a quantum channel (CQ2) linking said satellite (Sat) to said second communication station (S2), a second secret key j C. to receive, in said satellite, a communication request between the first and second communication stations D. encrypt, in response to the receipt of said request, in said satellite, the first secret key (g by a symmetric encryption method which uses the second secret key so as to generate a first encrypted message (ÆCl2) and transmit said first encrypted message to said second communication station (S2) by an authenticated channel (CA2)' said first authenticated channel.

2. A method according to the preceding claim, comprising a subsequent step consisting of: A. decipher, in said second communication station (S2), the first encrypted message (^Cl2) using the second secret key (^2), so as to obtain the first secret key, the first secret key forming the secure secret key.

3. A method according to claim 2, wherein said symmetric encryption method is the one-time pad method and wherein the first and second secret keys (^j, K2), and the first encrypted message (^fp) are encoded in binary, the generation of the first encrypted message being carried out by the XOR logic gate combining the first and second secret keys (K^K2y), the decryption of the first encrypted message ^(7) being carried out by the XOR logic gate combining the first encrypted message with the second secret key.

4. A method according to any one of claims 2 to 3, comprising two further steps F and G consisting of: A. encrypting, in the first communication station, a non-random message (M) using the first secret key and then transmitting the encrypted non-random message (MC) to the second communication station B. decrypting said encrypted non-random message using the first secret key.

5. A method according to any one of claims 2 to 4, wherein steps A to E are repeated a plurality of times in order to form a plurality of secure secret keys.

6. A method according to any one of the preceding claims, wherein step B requires a reconciliation substep performed via said first authenticated channel.

7. Method according to any one of claims 2 to 5, wherein steps A to E are repeated a plurality of times with a pair of communication stations different from the first and second communication stations.

8. A method according to any one of claims 2 to 7, further comprising a step D' and a step E', said step D' consisting of encrypting, in said satellite, the second secret key by a symmetric encryption method which uses the first secret key so as to generate a second encrypted message (AfCAj) and transmitting said second encrypted message to said first communication station (S1), by an authenticated channel (CA^), said first authenticated channel, said step E' consisting of decrypting, in said second communication station (S2), the first encrypted message (^Cl2) using the second secret key (K2), so as to obtain the first secret key (^J).

9. Satellite (Sat) for distributing a secure secret key intended to secure communications between a first communication station (SI) and a second communication station (S2), said satellite being adapted for: - exchange, via a quantum channel (CQ1) linking said satellite (Sat) to said first communication station (SI), a first secret key - exchange, via a quantum channel (CQ2) linking the satellite (Sat) to said second communication station (S2), a second secret key - receive a communication request between the first and second communication stations issued via a clear request channel (CR) - encrypt, in response to the reception of said request, the first secret key J by a symmetric encryption method which uses the second secret key (K^ in order to generate a first encrypted message (KC l2) and transmit said first encrypted message to said second communication station (S2) via an authenticated channel (CA2) first authenticated channel.

10. Communication system comprising the satellite according to the preceding claim and comprising said first and second communication stations, said second communication station being adapted to decrypt the first encrypted message (KC i2) ​​using the second secret key (A3), so as to obtain the first secret key, the first secret key forming the secure secret key.

11. System according to the preceding claim, wherein the first authenticated channel is different from the quantum channel linking the satellite (Sat) to said second communication station (S2).

12. System according to the preceding claim, wherein the first authenticated channel is a bidirectional telemetry / remote control link of said satellite.

13. System according to any one of claims 10 to 12, wherein the first authenticated channel is relayed by an additional satellite (SR) via an optical or RF inter-satellite link (LI) linking the satellite and said additional satellite.

14. A system according to any one of claims 10 to 13 wherein the first authenticated channel is an RF or optical anchor link of a satellite-borne telecommunications service 18

15. System according to any one of claims 10 to 14, wherein the clear request channel is relayed by a local station (SL) capable of communicating with said satellite via an authenticated local link (LL).