Method and device for sharing secret keys in a network including a satellite
The method and device for sharing secure secret keys via satellite networks address long-distance communication challenges in QKD by using satellites orbiting a common station and symmetric encryption, simplifying planning and enhancing security and resilience.
Patent Information
- Application Number
- FR2023009413
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-09-07
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2043-09-07
AI Technical Summary
Existing quantum key distribution (QKD) methods face limitations in long-distance communication and complex planning due to physical constraints such as optical fiber absorption and satellite trajectory rigidity, making them impractical for widespread industrial application.
A method and device for sharing secure secret keys using a network of satellites that orbit a common station, allowing key exchange via quantum channels without requiring direct line-of-sight, and utilizing symmetric encryption methods to distribute keys through authenticated channels, decoupling key generation from distribution.
Simplifies key distribution planning, enhances communication security, and reduces operational complexity by enabling secure key sharing between distant stations without direct satellite overflights, improving network flexibility and resilience to weather conditions.
Smart Images

Figure 00000024_0000 
Figure 00000024_0001 
Figure 00000025_0000
Abstract
Description
Title of the invention: Method and device for sharing secret keys in a network including a satellite. Technical field
[0001] The present invention relates to the field of information technology security and more particularly to the field of sharing encryption keys by satellite via quantum channels. Previous technique
[0002] There has always been a need to exchange sensitive information, which must remain secret, via a public communication channel. Suppose that two people, Alice and Bob, wish to exchange sensitive information, protected from prying eyes, via an authenticated public communication channel (for example, the internet). To do this, they must encrypt their messages. Let's call Eve the person who wants to intercept these messages. Alice must use a published (i.e., non-secret) cryptographic function and a secret key to encrypt her messages before sending them to Bob via a public channel. When Bob receives the encrypted messages, he must use the same cryptographic function and secret key as Alice to decrypt them in order to access the plaintext information.
[0003] The problem now arises of the secret key shared between Alice and Bob: how is it generated, how is it exchanged securely and away from prying eyes?
[0004] During secure internet exchanges, the establishment of a shared secret key is carried out using techniques based on public-key cryptography, which we will not detail here. A new solution was conceived at the end of the 20th century. It proposes using a quantum channel that allows Alice and Bob to establish a common secret key by exchanging quantum particles (e.g., photons) without Eve being able to recover the key by intercepting these particles. However, this technique of key sharing via quantum channels (QKD for Quantum Key Distribution) suffers from some limitations that make it difficult to apply to a large number of users and over very long distances. This could, in the long term, make this technique unattractive and therefore not profitable enough to generate industrial opportunities.
[0005] Figure 1 schematically represents the architecture of a quantum channel that allows two users, Alice (the particle emitter) and Bob (the particle receiver), to establish a common secret key. The key is a sequence of bits, random, therefore able to take the value 0 or 1. For example, within the BB84 protocol, Alice proposes key bits using two photon polarization modes prepared by Alice; the choice of polarization mode is random. Alice records the randomly chosen polarization mode for each bit (i.e., each photon). Using a polarizing filter and a photon detector that can be oriented alternately according to the two randomly chosen polarization modes, Bob records the detection result (the photon exited the filter via the 'parallel' or 'perpendicular' path to its axis), as well as the chosen orientation of the filter.
[0006] In BB84, once the entire sequence has been transmitted, Alice sends Bob the polarization modes used for each detection via an authenticated clear channel. Bob can then deduce the value of the bits for which the polarization orientation was the same. He then knows with certainty NU bits on average for N bits transmitted by Alice; this sequence is called the reconciled key. This step can be accompanied by error correction procedures using check values and LDPC or cascade-type algorithms, which use control parameters exchanged over the authenticated channel.
[0007] Finally, Alice and Bob agree on a subset of bits from the reconciled key. They then compare whether they obtained the same bits in this subset. Each difference is attributed by default to an eavesdropper (even though measurement errors may also have caused them). Indeed, the no-cloning theorem guarantees that in the event of eavesdropping, Eve forces the photon into a polarization mode (which is not necessarily Alice's). So, if Eve correctly guesses Alice's mode with a probability of 50%, then 25% of the bits in the reconciliation key will be in disagreement between Alice and Bob. At this stage, a mathematical security proof allows us to evaluate, based on the number of different bits, the amount of potentially compromised information and to define a one-way hash function which, when applied to the reconciled key, produces a smaller key that no longer contains any compromised information.This is the confidentiality amplification stage, which provides a secure key.
[0008] At the ground network level, key exchange (or more precisely: key establishment) via a quantum channel is straightforward, using an optical communication channel carried by optical fiber. However, the exchange of single polarized photons (or very low-intensity light pulses) through a fiber does not allow Alice and Bob to exchange these photons beyond a few tens of kilometers, which represents the combined asymptote of the probability of 100% absorption of the photons by the material composing the optical fiber and the shortening of the key due to privacy amplification.
[0009] Consequently, the architecture of quantum channel networks is strongly impacted by this physical constraint. Two solutions have been devised to overcome this distance limitation in optical fiber.
[0010] The first solution considered is to propagate the keys via so-called "trusted nodes" placed at regular intervals (every 50 kilometers, for example). Figure 2A schematically illustrates a trusted node key generation device known from the prior art. The trusted node manipulates in plaintext the key established with Alice (Key A) and the key established with Bob (Key B). This trusted node is positioned approximately equidistant between Alice and Bob and allows the key establishment range via quantum channels to be doubled. The trusted node then uses the one-time pad technique to transmit this key A to Bob. To do this, the trusted node performs an XOR operation (bit-by-bit exclusive OR logic gate) between Alice's key and Bob's key. "XOR" here and throughout the rest of this document refers to combining two keys using the exclusive OR operator, symbol ©.The result is transmitted to Bob via an authenticated clear channel. Bob, who holds key B, can then perform another XOR operation between the sequence received from node #2 and his key (Key B) to recover Alice's key (Key A).
[0011] This first solution relies on the property of the XOR function: A © B ® B = A © (B © B)⁰ = A, but also on the one-time pad (OTP) cryptography technique, which guarantees that it is not possible to recover key A and / or key B using only the sequence Key A © Key B. A © B is called the "ciphered key." The one-time pad technique is based on the following principle: any message to be encrypted will be encrypted using a strictly random key, the size of the message, which will be combined with the plaintext to produce the ciphertext. Decryption will be performed by carrying out the inverse operation on the ciphertext using the same secret key. This technique has been demonstrated to be theoretically secure by Claude Shannon, regardless of the attacker's means, provided that three absolutely fundamental rules are respected: A. The key must be as long as the message to be encrypted. B. The key must be strictly random; the elements that constitute the key (bits) (or characters) of the key must all be independent of each other. C. Each key (or mask) must be used only once to encrypt a single message.
[0012] However, this first solution requires that the trusted nodes, which handle the keys in plaintext, be secured with a very high level of security, which entails significant additional costs and operational constraints. Furthermore, this type of solution is difficult, if not impossible, to implement for interconnecting two users separated by an ocean (it is difficult and expensive to implement trusted nodes every 100km in the ocean).
[0013] The second solution is to exchange photons in free space, and from space to reach long distances. In this case, the 100-kilometer limit of optical fiber is no longer applicable, and it is possible to distribute encryption keys to two users located anywhere on Earth via QKD channels from space. This configuration is illustrated in Figure 2B. In this case, the satellite acts as a trusted node since it establishes a key A with Alice (for example, a ground station) and a key B with Bob (for example, another ground station) and then transmits key A © key B (encryption key) to Bob over a clear and authenticated conventional communication channel during the flyby of Bob's station.On the ground, Bob, holder of key B, will be able to extract key A from Alice by performing an XOR operation on key B with the Key A © Key B sequence encryption key that the satellite will have brought back down to him. Here, the satellite, if it is in low Earth orbit, moves relative to Alice and relative to Bob. Therefore, regardless of the distance between Alice and Bob, the satellite acts as a mobile trusted node capable of establishing Key A and Key B and distributing the Key A ® Key B combination that allows Alice and Bob to share a common secret key (Key A).
[0014] In this second solution, the 'pair management' aspect of ground stations and the 'overflight of paired stations' aspect are likely to strongly constrain the planning of quantum optical contacts between station and satellite in the generally considered means. Indeed, the satellite trajectories are extremely rigid, and the optical contact periods between satellites and ground stations, while predictable, are not flexible. Moreover, cloud cover is likely to interrupt the quantum channel linking the satellite and a ground station and thus prevent the establishment of an elementary satellite-station link. In this case, the exchange planning must therefore be able to be updated.
[0015] These constraints make planning contacts between stations and satellites very complex and inefficient. Indeed, the solution in [Fig. 2B] requires a precise sequence of the different contacts, due to the fact that it does not manage point-to-point connections, but rather pairs of connections to share keys between pairs of ground stations. If the sequence is interrupted by an unforeseen weather disturbance, service availability can be jeopardized because the visibility of the station to be connected may not reappear for several days. Consequently, strategies for optimizing contacts between satellites and stations are extremely complex and require solving problems for which the optimum is difficult to determine.
[0016] The invention aims to overcome some of the aforementioned problems of the prior art. To this end, an object of the invention is a method and a device for sharing secure secret keys intended to secure communications between a first communication station and a second communication station. The invention is implemented in a network comprising at least two satellites that orbit a common station so as to be within line of sight of the latter. In the method and process of the invention, the secure secret key is distributed in a step temporally separate from the step in which these keys are generated by QKD, via the common station. Furthermore, the distribution of the secure key to the first and second stations via the common station is carried out through channels that do not necessarily require line of sight between the satellites and the common station and can be performed much later, depending on the users' needs.The solution of the invention makes it possible to avoid having to implement trajectories of the two satellites which successively fly over the first and second stations that one wishes to connect: the work can be shared between several satellites in groups of stations and not in groups of pairs of stations as is usually envisaged in the prior art. Summary of the invention
[0017] To this end, an object of the invention is a method for sharing a secure secret key intended to secure communications between a first communication station and a second communication station, said method comprising the following steps: A. exchange, via a quantum channel linking a first satellite to the first communication station, a first secret key and exchange, via a quantum channel linking the first satellite to a third communication station, called the common station, a second secret key B. exchange, via a quantum channel linking a second satellite to the common station, a third secret key and exchange, via a quantum channel linking the second satellite to the second communication station, a fourth secret key C. receive, in the first and second satellites, a communication request between the first and second communication stations; D. encrypt, in the first satellite, the first secret key using a symmetric encryption method that utilizes the second secret key, so as to generate a first encrypted message and transmit the first encrypted message to the common station (via a first authenticated channel). E. encrypt, in the second satellite, the fourth secret key using a symmetric encryption method that uses the third secret key, so as to generate a second encrypted message and transmit the second encrypted message to the common station via a second authenticated channel F. In the common station, decrypt the first encrypted message using the second secret key, so as to obtain the first secret key, and decrypt the second encrypted message using the third secret key, so as to obtain the fourth secret key G. encrypt, in the common station, the first secret key by a symmetric encryption method which uses the fourth secret key, so as to generate a third encrypted message and transmit the third encrypted message to the second communication station by a third authenticated channel.
[0018] According to one embodiment, the method of the invention includes a subsequent step H consisting of deciphering, in the second communication station, the third message encrypted using the fourth secret key so as to obtain the first secret key, the first secret key forming the secure secret key.
[0019] Preferably, the symmetric encryption method is the one-time pad method in which the secret keys and the encrypted messages are coded in binary, the encryption steps each being carried out by the XOR logic gate combining the secret keys respectively involved in said encryption step, the decryption steps each being carried out by the XOR logic gate combining the encrypted message with the encrypted secret key which are respectively involved in said decryption step.
[0020] According to one embodiment, the method of the invention comprises two subsequent steps I and J which consist of:
[0021] I. to encrypt, in the first communication station, a non-random message using the first secret key and then to transmit the encrypted non-random message to the second communication station' via a so-called clear channel
[0022] J. decipher, in the second communication station, the said non-random message encrypted using the first secret key.
[0023] According to one embodiment, steps A to H are repeated a plurality of times in order to form a plurality of secure secret keys.
[0024] According to one embodiment, in step A, the exchange of the second secret key requires a reconciliation substep carried out via said first authenticated channel and / or, in step B, the exchange of the third secret key requires a reconciliation substep carried out via said second authenticated channel.
[0025] According to one embodiment, steps A to H are repeated a plurality of times with a pair of communication stations different from the first and second communication stations.
[0026] Another object of the invention is a communication system comprising a first and a second communication station, a third communication station called the common station and a first and a second satellite, said first satellite being adapted to exchange, via a quantum channel linking the first satellite to the first communication station, a first secret key and to exchange, via a quantum channel linking the first satellite to the common station, a second secret key, said second satellite being adapted to exchange, via a quantum channel linking the second satellite to the common station, a third secret key and to exchange, via a quantum channel linking the second satellite to the second communication station, a fourth secret key, the first satellite being further adapted to receive a communication request between the first and second communication stations transmitted via a clear request channel,and after which encrypt the first secret key by a symmetric encryption method that uses the second secret key so as to generate a first encrypted message and transmit the first encrypted message to the common station by a first authenticated channel, the second satellite being further adapted to receive said communication request, and after which encrypt the fourth secret key by a symmetric encryption method that uses the third secret key so as to generate a second encrypted message and transmit the second encrypted message to the common station by a second authenticated channel, the common station being adapted to: - decrypt the first encrypted message using the second secret key so as to obtain the first secret key and decrypt, in the common station, the second encrypted message using the third secret key so as to obtain the fourth secret key, - encrypt the first secret key by a symmetric encryption method which uses the fourth secret key in such a way as to generate a third encrypted message and transmit the third encrypted message to the second communication station by a third authenticated channel.
[0027] According to one embodiment, the second communication station is adapted to decrypt the third encrypted message using the fourth secret key so as to obtain the first secret key, the first secret key forming the secure secret key.
[0028] According to one embodiment, the first authenticated channel and / or the second authenticated channel are each a bidirectional telemetry / remote control link of the first satellite and the second satellite respectively.
[0029] According to one embodiment, the first authenticated channel is relayed by an additional satellite via an optical or RF inter-satellite link connecting the additional satellite and the first satellite and / or the second authenticated channel is relayed by an additional satellite via an optical or RF inter-satellite link connecting the additional satellite and the second satellite.
[0030] According to one embodiment, the first authenticated channel and the second authenticated channel are each an RF or optical anchor link of a telecommunications service carried by the first satellite and the second satellite respectively.
[0031] According to one embodiment, the first authenticated channel station is different from the quantum channel linking the first satellite to said common station (S3) and the second authenticated channel is different from the quantum channel linking the second satellite to said common station.
[0032] According to one embodiment, the clear request channel is relayed by a local station capable of communicating with the first and second satellites via an authenticated local link.
[0033] Another object of the invention is a communication station called a common station, said station being adapted for: - receive a second secret key exchanged via a quantum channel linking a first satellite and the joint station - receive a third secret key exchanged via a quantum channel linking a second satellite to the joint station - to receive, via a first authenticated channel, a first encrypted message transmitted by the first satellite and generated by a symmetric encryption method which encrypts, with the second secret key, a first secret key exchanged via a quantum channel linking the first satellite to a first communication station, and - to receive, via a second authenticated channel, a second encrypted message transmitted by the second satellite and generated by a symmetric encryption method which encrypts, with the third secret key, a fourth secret key exchanged via a quantum channel linking the second satellite to a second communication station, - decrypt the first encrypted message using the second secret key, in order to obtain the first secret key, and decrypt the second encrypted message using the third secret key, in order to obtain the fourth secret key. Brief description of the drawings
[0034] Other features, details and advantages of the invention will become apparent from the description given with reference to the accompanying drawings provided by way of example, which represent, respectively:
[0035] [Fig-1] a schematic view of a QKD device according to the prior art,
[0036] [Fig.2A], a schematic view of a QKD key generation device by satellite of the previous art,
[0037] [Fig.2B], a schematic view of a node-based key generation device confidence in prior art,
[0038] [Fig. 3A], a schematic view of a secure secret key distribution method according to the invention,
[0039] [Fig.3B], a schematic view of a secret key distribution system according to the invention,
[0040] [Fig. 3C], a schematic view of a secret key distribution system according to a method of embodiment of the invention,
[0041] [Fig.3D], a schematic view of a secret key distribution system according to a method of embodiment of the invention,
[0042] [Fig.4], a schematic view of a method for generating a secure secret key according to a preferred embodiment of the method of the invention
[0043] [Fig. 5A], a schematic view of a method for generating a secure secret key according to an embodiment of the method of the invention
[0044] [Fig. 5B], a schematic view of a secret key distribution system according to a method of embodiment of the invention,
[0045] In the figures, unless otherwise indicated, the elements are not to scale. Description of the implementation methods
[0046] Figure 3A schematically illustrates a method according to the invention for distributing a secure secret key intended to secure communications between a first communication station SI and a second communication station S2. Figure 3B schematically illustrates a communication system 1 according to the invention adapted to implement the method of Figure 3A. In addition to the first and second stations SI, S2, the system 1 comprises a third communication station S3, referred to as the common station, and a first and second satellite ST A, STB.
[0047] In a first step A of the method of the invention, the first STA satellite exchanges a first secret key Ki via a quantum channel CQAi linking the first STA satellite to the first communication station SL. This exchange in step A is carried out when the STA satellite is in position A, during the overflight of the station SI and requires that the STA satellite be within optical line of sight of the station SI in order to transmit and detect qubits.
[0048] Furthermore, when the STA satellite is in a position B in which it is within optical line of sight of the common station S3, the satellite exchanges a second secret key K2 via a quantum channel CQA3 linking the first STA satellite to the common station S3.
[0049] For clarification, in the invention, when describing a key exchange step by quantum channel linking a station and a satellite, the emission of qubits can be from the satellite to the station or vice versa.
[0050] In a step B, the second STB satellite exchanges a third secret key K3 via a CQB3 quantum channel linking a second STB satellite to the common station S3. This exchange takes place when the STB satellite is in position C, during the overflight of the common station S3, and requires that it be within line of sight of station S3. Furthermore, when the STB satellite is in position D, in which it is within line of sight of station S2, the STB satellite exchanges a fourth secret key via a CQB2 quantum channel linking the second STB satellite to the second communication station S2.
[0051] The object of the method of the invention is to transmit the first key Kx to the second station S2 in a perfectly secure manner so that stations S1 and S2 can communicate securely with this key Kh without the need for the STA satellite to fly over station S2 and while considerably simplifying the planning of the respective operations of the STA and STB satellites.
[0052] In the invention, the steps for exchanging secret keys via a quantum channel can be performed using any QKD protocol known to those skilled in the art. It should be noted that cloud cover over a terrestrial communication station blocks any free-space optical link in the visible and near-infrared. Furthermore, the sun generates large quantities of stray photons through atmospheric diffraction (indirect irradiance), which significantly degrade the detection of qubits, potentially leading to link failure. Thus, the current state of the art in satellite QKD allows the transmission of qubits via the near-infrared optical link through the atmosphere under clear skies. Therefore, the availability of the quantum channel between a satellite and a terrestrial communication station is dependent on weather events and conditions above the station.
[0053] It is understood that, in the method of the invention, the relative order of the execution of steps A and B is irrelevant. Therefore, the two steps A and B can be carried out simultaneously or one after the other (i.e., step A then step B or B then A).
[0054] After steps A and B, the method of the invention includes a step C consisting of receiving in the STA and STB satellites a communication request between the station SI and station S2 are emitted by a so-called transmitting station and transmitted via a CR request channel. According to the embodiment illustrated in [Fig. 3B], the request is emitted by station S1, which therefore constitutes the transmitting station. Alternatively, according to another embodiment, the request is emitted by station S2, or even station S3, or another station, for example, a mission control station, different from stations S1-S3 (not shown in [Fig. 3B]).
[0055] This CR request channel is an authenticated channel that does not necessarily require line-of-sight between the STA and STB satellites and the transmitting station. It can, for example, be an RF channel or an optical channel. Furthermore, step C is temporally uncorrelated with steps A and B and can therefore be implemented at a time when the STA and STB satellites are not within line-of-sight of the transmitting station, for example, because they are too far from the station or because atmospheric disturbances between the STA and STB satellites and the transmitting station are too significant. It can only be transmitted when the need for secure communication between stations S1 and S2 arises.
[0056] After receiving this request, in a step D, the STA satellite is adapted to encrypt the first secret key Aj using a symmetric encryption method that uses the second secret key K2 to generate a first encrypted message KC12. Furthermore, step D includes the transmission of the first encrypted message to the common station S3 via a first authenticated channel CAb.
[0057] Similarly, after receiving the request, in a step E, the STB satellite is adapted to encrypt the fourth secret key by a symmetric encryption method which uses the third secret key so as to generate a second encrypted KC43 message. The STB satellite then transmits a second encrypted message to the common station S3 via a second authenticated CA2 channel.
[0058] Just like the CR request channel, the authenticated CA}, CA2 channels are not channels that necessarily require optical line of sight between the STA and STB satellites and the S3 station because steps D and E are temporally uncorrelated with steps A and B. The authenticated CA}, CA2 channels can therefore be any classic channels of authenticated opportunities in the RF or optical domain (see below).
[0059] Furthermore, it is understood that the relative order of steps D and E is irrelevant in the method of the invention. Therefore, steps D and E can be carried out simultaneously or one after the other.
[0060] After these steps D and E, the method of the invention comprises two steps F and G implemented in the common station S3. Step F consists of decrypting the first encrypted message KCn using the second secret key K2 so as to obtain the first secret key Aj and decrypting the second encrypted message KC43 using the third secret key K3 so as to obtain the fourth secret key K^,
[0061] After step F, the common station S3 is adapted to implement step G, which consists of encrypting the first secret key by a symmetric encryption method that uses the fourth secret key to generate a third encrypted message, KCl4. Furthermore, step G includes the transmission of the third encrypted message, KCl4, to the second communication station S2 via a third authenticated channel, CAy.
[0062] Following the method shown in Figure 3A, station S2 is able to decrypt the third encrypted message ÆC14 with the fourth secret key ^4 that it had previously exchanged via QKD with the STB satellite. It is therefore able to obtain the first secret key K2, which then forms the secure secret key (see method in Figure 4). Thus, the first and second communication stations SI and S2 are each able to possess the secure secret key Kb. Since the steps implemented in the method of the invention (QKD and symmetric encryption) are resistant to quantum threats, the method of the invention therefore makes it possible to provide a secure secret key for encrypting communications between station SI and station S2.
[0063] As mentioned previously, in the invention, steps A and B of the QKD secret key exchange are temporally decoupled from the distribution of the encrypted messages KCn, KC12 to station S3 in steps D and E, respectively. Thus, the distribution of the encrypted messages KCn, KC43 via the CA and CA2 channels, respectively, does not necessarily require line of sight between the STA and STB satellites and the common station S3. Specifically, this implies that in step D, the STA satellite can be significantly further from station S3 when distributing the encrypted message ÆC12 than when it is in position B to perform the K2 key exchange with station S3. Similarly, in step E, the STB satellite may be significantly further from station S3 when it is distributing the encrypted KC43 message than when it is in position C to perform the exchange of the K3 key with station S3.This temporal separation between the exchange of Kp K2 secret keys by QKD and the distribution of encrypted messages is not present in prior art methods. Indeed, in these prior art methods, the distribution of the secure secret key was carried out by the satellite during the flyby of a station almost simultaneously after the establishment of an encryption key by QKD to encrypt the transmission of the secure secret key between the satellite and the station (see [Fig.2B]).
[0064] The solution of the invention makes it possible to considerably simplify the planning of operations compared to the prior art method illustrated in Figure 2B. Furthermore, the solution of the invention makes it possible to delay the distribution of encrypted messages, for example, according to the needs of the users of stations S1 and S2, and thus avoid prolonged storage of the secret keys Kp K4 and encrypted messages in the common station S3, which could potentially be compromised. Moreover, the solution of The invention makes it possible to avoid having to implement trajectories of the two satellites STA, STB which successively fly over the first and second stations SI, S2 which one wishes to connect: the work can be shared between the satellites STA, STB by packets of stations (SI, S3) and (S3, S2) and not by packets of pairs of stations (SI, S2) as is usually envisaged in the prior art.
[0065] It is understood that temporally decoupling steps A and B from the rest of the steps of the invention implies that the STA and STB satellites can securely store the K2 keys and the Ky Ka keys respectively after their exchange by QKD.
[0066] According to the invention, the symmetric encryption method for steps D, E and G can be any block or stream method known to those skilled in the art, for example the one-time pad method or the AES (Advanced Encryption Standard) method or the Triple DES method.
[0067] In the invention, step G can alternatively consist of generating a third encrypted message ÆC41 generated by encrypting the fourth secret key by a symmetric encryption method which uses the first secret key and transmitting the third encrypted message ÆC14 to the communication station SI by a third authenticated channel CAy. These two formulations are equivalent, the only difference being that, in the first alternative, the key is the secure secret key for encrypting communications between station SI and station S2, whereas, in the second alternative, the key is the secure secret key.
[0068] As mentioned previously, the CA^ and CA2 channels can be any authenticated classical opportunity channels. According to a preferred embodiment of the invention, denoted MR, the CA^ and CA2 channels are different from the quantum channels CQas and CQbs respectively.
[0069] According to an embodiment of the method of the invention, denoted MP, in step A, the reconciliation substep necessary for the exchange of the secret key K2 is performed via the CA channel. Similarly, in step B, the reconciliation substep necessary for the exchange of the secret key K3 is performed via the CA channel. Indeed, these reconciliation substeps, like the encrypted message distribution steps ^Cj2, ^^43, do not require that the STA and STB satellites be within line of sight of the common station S3. Thus, it is possible to simplify the network architecture of system 1 by sharing some of the links necessary for its operation. This embodiment MP is compatible with embodiment MR.
[0070] According to another embodiment, compatible with embodiment MR and embodiment MP, the first authenticated channel and / or the second authenticated channel are each a bidirectional telemetry / remote control link for the first and second satellites respectively. Hereinafter referred to as a "link" The bidirectional satellite telemetry / remote control link allows for both the control, configuration, and programming of the satellite's mission, and the measurement of the satellite's configuration and status. This simplifies the network architecture of System 1 by sharing some of the links necessary for its operation.
[0071] According to another embodiment of the system of the invention, the first authenticated channel and the second authenticated channel are each an RF or optical anchor link of a telecommunications service carried by the first and second satellites, respectively. This embodiment also simplifies the network architecture of system 1.
[0072] System according to any one of claims 7 to 10, wherein the first authenticated channel and the second authenticated channel are each an RF or optical anchor link of a telecommunications service carried by the first satellite and the second satellite respectively.
[0073] Figure 3C schematically illustrates an embodiment of system 1 of Figure 3B, in which the authenticated channel CA2 is relayed by an additional satellite SR via an inter-satellite link LI connecting the satellite STB and the additional satellite SR. This LI link is, for example, an optical or RF link. This embodiment improves the availability of system 1, for example, when the satellite STB is too far from station S3 to communicate with it directly without the intermediary of the additional satellite SR. More generally, according to one embodiment of system 1 of the invention, the first and / or the second authenticated channel CA*.CA2 is / is relayed by the additional satellite SR via an inter-satellite link LI connecting the additional satellite SR and, respectively, the satellites STA and STB.
[0074] Advantageously, according to one embodiment of System 1 in Figure 3C, the additional SR satellite is configured to operate at an altitude higher than that of clouds and atmospheric turbulence, for example, in the stratosphere or in orbit. Furthermore, the portion of the CA2 channel between the S3 station and the additional SR satellite uses a wavelength in the RF, visible, or LWIR range to avoid potential interference from weather conditions (e.g., clouds). Finally, the portion of the CA2 channel between the STB satellite and the additional SR satellite uses a length that maximizes transmission capacity, for example, a wavelength in the SWIR range (for Short Wavelength Infrared, typically between 1 jim and 2.7 µm). This embodiment optimizes the operation of System 1, making it more robust to weather conditions.
[0075] Figure 3D schematically illustrates an embodiment of system 1 of the invention in which the communication request issued by the transmitting station (for example, station SI as illustrated in Figure 3D) is relayed to the satellites ST A and STB are communicated by a local station SL capable of communicating with these satellites via an authenticated local link LL. This embodiment is advantageous in order to take advantage of a possible flyby of the station SL by the satellites STA and STB when they are too far from the transmitting station for the latter to transmit the communication request directly to them.
[0076] Figure 4 illustrates a preferred embodiment of the method of the invention. This method is particularly suitable for implementation by the system 1 of Figure 3B. The method of Figure 4 includes an additional step H which consists of decrypting, in the second communication station S2, the third encrypted message Af 14 using the fourth secret key K4. Thus, station S2 obtains the first secret key K^.
[0077] This step H is necessary so that stations SI and S2 both possess the secure secret key K, which they can subsequently use to encrypt non-random messages they wish to exchange (see Figures 5A and 5B). Indeed, given that the encryption of the secure secret key Kx in step G is performed using a symmetric encryption method, the decryption of the first encrypted message Æ'14 is carried out with the same key used for encryption, i.e., the fourth secret key K4. Thus, the method in Figure 4 makes it easy to distribute, securely and unbreakably—even against quantum attacks—a secure secret key K1 for encrypting communications between station SI and station S2, relaxing the key distribution constraints compared to other prior art methods.
[0078] According to one embodiment of the method in [Fig.4], steps A to H are repeated a plurality of times in order to form a plurality of secure secret keys, each intended to secure communications between station SI and station S2.
[0079] In a preferred embodiment of the invention, the symmetric encryption method is the one-time pad method. In this embodiment, the secret keys K^, and the encrypted messages KCn, KC43> KC4l are encoded in binary. Thus, the encryption steps are each performed by the XOR logic gate by combining the secret keys respectively involved in that encryption step. For example, in step D, the encryption step is obtained by combining the first and second secret keys K and K2, using the following logical operation: KC12 = K^K2. Similarly, the decryption steps are each performed by the XOR logic gate by combining the encrypted message with the encrypted secret key respectively involved in that decryption step. For example, in step F, the decryption step of the first encrypted message XC12 is performed by the following logical operation: KC12®K2=K\®K2®K2 = which allows the station S3 to obtain the Kb key. This embodiment is the one that allows the implementation of the least complex invention.
[0080] In order to ensure the security of the disposable mask technique in the invention, all steps implementing the disposable mask technique combine two secret keys or a secret key and a key and an encrypted message which are of the same length (key size).
[0081] Figure 5A illustrates a preferred embodiment of the method in Figure 4, enabling the secure exchange of a non-random message M between station S1 and station S2. Figure 5B schematically illustrates an embodiment of the system of the invention adapted to implement the method in Figure 5A. In addition to the steps detailed above, the method in Figure 5A comprises two further steps I and J, which consist of:
[0082] I - encrypt, in the first communication station SI, a non-random message M using a first secret key KY and transmit the encrypted non-random message MC to the second communication station S2'
[0083] J- decrypt the non-random message encrypted using the first secret key Ki in step F. Thus, station S2 obtains the non-random message M in a perfectly secure manner.
[0084] According to an embodiment different from that illustrated in [Fig. 5B], the message M is exchanged from station S2 to station SL
[0085] According to a preferred embodiment of the method in Figure 5A, steps I and J are repeated a plurality n of times to encrypt a plurality of communications between station SI and station S2. The number n of repetitions of steps I and J is less than a so-called critical number calculated from a crypto-period of the key used for encrypting message M and decrypting message MC. This feature prevents the compromise of exchanged messages and is relevant when encoding a non-random message M (for example, human language). Here, the "crypto-period" refers to the number of times a key is used in an encryption algorithm that must not be exceeded to guarantee the security of the message encrypted by that key.
[0086] Finally, another object of the invention is the common station S3 of system 1 described above. Station S3 is therefore adapted for: - receive the second K2 secret key exchanged via the CQA3 quantum channel - receive the third secret key K3 exchanged via the CQB3 quantum channel - receive, via the CA^ channel, the first encrypted KCi2 message transmitted by the first STA satellite - receive, via channel CA2, the second encrypted KC43 message transmitted by the second STB satellite - decrypt the first encrypted message KCl2 using the second secret key K2 to obtain the first secret key, and decrypt the second encrypted message using the third secret key K3 to obtain the fourth secret key - encrypt the first secret key A^ by a symmetric encryption method which uses the fourth secret key so as to generate the third encrypted message ^C14 and transmit the third encrypted message to the second communication station S2 by a third authenticated channel CA-i.
[0087] The common station S3 of system 1 is therefore adapted to implement a method in which the steps are "localized" in the same geographical area (i.e. station S3), instead of being distributed over different stations and satellites spaced several hundred or thousands of kilometers apart.
Claims
Demands
1. A secure secret key sharing method for securing communications between a first communication station (S1) and a second communication station (S2), said method comprising the following steps: A. exchange, via a quantum channel (CQAi) linking a first satellite (STA) to the first communication station (SI), a first secret key j and exchange, via a quantum channel (CQA3) linking the first satellite (STA) to a third communication station called the common station B. C. E. (S3), a second secret key j exchange, via a quantum channel (CQB3) linking a second satellite (STB) to the common station (S3), a third secret key) and exchange, via a quantum channel (CQB2) linking the second satellite (STB) to the second communication station (S2), a fourth secret key to receive, in the first and second satellites (STA, STB), a communication request between the first and second communication stations, encrypt, in the first satellite, the first secret key ( J uses a symmetric encryption method that employs the second secret key (K2) to generate a first encrypted message (KC) and transmit the first encrypted message to the common station (S3) via a first authenticated channel (CAj). The fourth secret key is then encrypted in the second satellite. P31 is a symmetric encryption method that uses the third secret key to generate a second encrypted message (KC43) and transmit the second encrypted message to the common station (S3) via a second authenticated channel (CA?). At the common station (S3), the first encrypted message (KCi2) is decrypted using the second secret key. (K2), so as to obtain the first secret key and decrypt the second encrypted message (KC43) using the third secret key (^3), so as to obtain the fourth secret key f G. encrypt, in the common station (S3), the first secret key (x J) by a symmetric encryption method which uses the fourth secret key so as to generate a third encrypted message (KCu) and transmit the third encrypted message to the second communication station (S2) by a third authenticated channel ( CA,}
2. Method according to the preceding claim, comprising a further step H of deciphering, in the second communication station, the third encrypted message (X'Ci4) using the fourth secret key (K4), so as to obtain the first secret key (X^'a first secret key forming the secure secret key.
3. Method according to the preceding claim, said symmetric encryption method is the one-time pad method and in which the secret keys (Kb K2, K3, K4\ and the encrypted messages (.XC^ KC43 are coded in binary, the encryption steps each being carried out by the XOR logic gate combining the secret keys respectively involved in said encryption step, the decryption steps each being carried out by the XOR logic gate combining the encrypted message with the encrypted secret key which are respectively involved in said decryption step.
4. A method according to any one of claims 2 to 3, comprising two further steps I and J which consist of: I. encrypting, in the first communication station, a non-random message (M) using the first secret key and then transmitting the encrypted non-random message (MC) to the second communication station' by a so-called plain channel J. decrypting, in the second communication station, said non-random message encrypted using the first secret key.
5. A method according to any one of claims 2 to 4, wherein steps A to H are repeated a plurality of times in order to form a plurality of secure secret keys.
6. A method according to any one of the preceding claims, wherein in step A, the exchange of the second secret key requires a reconciliation substep carried out via said first authenticated channel and / or, in step B, the exchange of the third secret key requires a reconciliation substep carried out via said second authenticated channel.
7. Method according to any one of claims 2 to 6, wherein steps A to H are repeated a plurality of times with a pair of communication stations different from the first and second communication stations.
8. Communication system comprising a first and a second communication station (SI, S2), a third communication station called the common station (S3) and a first and a second satellite (STA, STB), said first satellite (STA) being adapted to exchange, via a quantum channel (CQAi) linking the first satellite (STA) to the first communication station (SI), a first secret key j and to exchange, via a quantum channel (CQAi) linking the first satellite (STA) to the common station (S3), said second satellite (STB) being adapted to exchange, via a quantum channel (CQbs) linking the second satellite (STB) to the common station (S3), a third secret key j and to exchange, via a quantum channel (CQB2) linking the second satellite (STB) to the second communication station,a fourth secret key j the first satellite being further adapted to receive a communication request between the first and second communication stations transmitted via a clear request channel (CR), and after which encrypt the first secret key (^ ^ by a symmetric encryption method which uses the second secret key (^), so as to generate a first encrypted message (KC12) and transmit the first encrypted message to the common station (S3) via a first authenticated channel (CAj', the second satellite being further adapted to receive said communication request, and after which encrypt the fourth secret key () by a symmetric encryption method which uses the third secret key so as to generate a second encrypted message (^C43) and transmit the second encrypted message to the common station (S3) by a second authenticated channel (CA^ the common station being adapted to: • decrypt the first encrypted message (KC^) using the second secret key (^2), so as to obtain the first secret key J, and decrypt, in the common station (S3), the second encrypted message (^C43) using the third secret key (^3),in order to obtain the fourth secret key (g4) • encrypt the first secret key (^J) by a symmetric encryption method which uses the fourth secret key in order to generate a third encrypted message (KCl4) and transmit the third encrypted message to the second communication station (S2) by a third authenticated channel (CA3),
9. System according to the preceding claim, wherein the second communication station is adapted to decrypt the third encrypted message (ÆCj4) using the fourth secret key (^4), so as to obtain the first secret key, the first secret key forming the secure secret key.
10. System according to claim 8 or 9, wherein the first authenticated channel and / or the second authenticated channel are each a bidirectional telemetry / remote control link of the first satellite and the second satellite respectively.
11. System according to any one of claims 8 to 10, wherein the first authenticated channel is relayed by an additional satellite (SR) via an optical or RF inter-satellite link (LI) connecting the additional satellite and the first satellite and / or the second authenticated channel is relayed by an additional satellite (SR) via an optical or RF inter-satellite link (LI) connecting the additional satellite and the second satellite.
12. A system according to any one of claims 8 to 9 or 11, wherein the first authenticated channel and the second authenticated channel are each an RF or optical anchor link of a telecommunications service carried by the first satellite and the second satellite respectively.
13. System according to any one of claims 8 to 11, the first authenticated channel is different from the quantum channel linking the first satellite to said common station (S3) and the second authenticated channel is different from the quantum channel linking the second satellite to said common station (S3) ..
14. System according to any one of claims 8 to 12, wherein the clear request channel is relayed by a local station (SL) capable of communicating with the first and second satellites via an authenticated local link (LL).
15. Communication station referred to as common station (S3), said station being adapted to: - receive a second secret key exchanged via a quantum channel (CQAI) linking a first satellite (STA) and the common station (S3), - receive a third secret key exchanged via a quantum channel (CQBS) linking a second satellite (STB) to the common station (S3), - receive, via a first authenticated channel, a first encrypted message (KC12) transmitted by the first satellite and generated by a symmetric encryption method which encrypts, with the second secret key, a first secret key exchanged via a quantum channel (CQAI) linking the first satellite (STA) to a first communication station (SI), and - receive, via a second authenticated channel, a second encrypted message (KC43) transmitted by the second satellite and generated by a symmetric encryption method which encrypts, with the third secret key,a fourth secret key exchanged via a quantum channel (CQB2) linking the second satellite (STB) to a second communication station (S2), decrypt the first encrypted message (AC12) using the second secret key (AV) to obtain the first secret key, and decrypt the second encrypted message (AC43) using the third secret key (A3) to obtain the fourth secret key. encrypt the first secret key J using a symmetric encryption method that uses the fourth secret key to generate a third encrypted message (ACi4) and transmit the third encrypted message to the second communication station (S2) via a third authenticated channel.