Hybrid key exchange method robust to quantum attacks

A hybrid secret key generation method combining quantum-resistant and asymmetric technologies creates secure VPN tunnels resistant to quantum attacks, addressing vulnerabilities in existing encryption methods with reduced key consumption and complexity.

FR3153207B1Active Publication Date: 2026-06-05THALES SA

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
THALES SA
Filing Date
2023-09-18
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

Current encryption methods for VPN tunnels are vulnerable to quantum computing attacks, with existing solutions being complex, costly, or lacking maturity, and there is no efficient method to generate symmetric keys robust against such attacks.

Method used

A hybrid secret key generation method that combines a quantum-attack-resistant technology with another encryption method, such as asymmetric key exchange, to create a hybrid key that is robust to both classical and quantum attacks, reducing the need for frequent key renewals and infrastructure.

Benefits of technology

The hybrid method provides secure VPN tunnels resistant to quantum attacks with reduced key consumption, flexibility, and compatibility with existing technologies, while being simpler and less resource-intensive than existing solutions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000015_0000
    Figure 00000015_0000
  • Figure 00000015_0001
    Figure 00000015_0001
  • Figure 00000016_0000
    Figure 00000016_0000
Patent Text Reader

Abstract

The invention relates to a method for obtaining a hybrid secret key comprising: - a first step (201) of obtaining a first secret key, using a technology robust to quantum attacks, - a second step (202) of obtaining a second secret key in a space encrypted by the first secret key, using a technology other than that used in the first step (201), the hybrid secret key corresponding to the second secret key. It also relates to a method for secure data exchange, a system, a computer program product, and a storage medium using the hybrid secret key. Figure for the abstract: Fig. 2
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Hybrid key exchange method robust to quantum attacks. Technical field

[0001] The invention lies in the technical field of cybersecurity, and more specifically relates to a method for obtaining symmetric keys, or secret keys, by hybridizing technologies that provide resistance to quantum computing attacks. Such keys can be used, among other things, for establishing VPN (Virtual Private Network) tunnels between two devices. Previous technique

[0002] VPN tunnels allow secure connections to be established between two devices over an insecure communication channel. The data exchanged over the VPN tunnel is encrypted end-to-end by an encryption key, making it impossible to interpret for any observer who does not have this key.

[0003] There are two types of encryption: symmetric encryption and asymmetric encryption.

[0004] Symmetric encryption, or secret-key encryption, uses the same key to encrypt and decrypt data. This type of encryption is fast, uses few resources, and is particularly efficient. However, it requires the prior and secure sharing of the secret key between the equipment involved in the transmission.

[0005] Asymmetric encryption uses a public key to encrypt data and a private key to decrypt it. The two keys are linked. The public key can be transmitted without any special precautions: the sender uses it to encrypt the data, which can only be decrypted using the private key. Therefore, a secure key exchange is not necessary prior to transmission. However, asymmetric encryption is more complex, and therefore slower and more expensive, than symmetric encryption.

[0006] Thus, VPN tunnels between two devices generally comprise two phases: - a first phase of obtaining a secret key, during which a secret key is established between the two devices through an asymmetric cryptographic exchange based on a public / private key provided by a PKI (Public Key Infrastructure) with authentication, for example IKEv2 (Internet Key Exchange version 2, or internet key exchange) for IPsec (English acronym for Internet Protocol security). This is the Diffie-Hellman principle; - a second phase of data exchange, during which the packets transmitted over the VPN tunnel are encrypted / decrypted using the symmetric key negotiated during the first phase, for example with an AES algorithm (English acronym for Advanced Encryption Standard).

[0007] Subsequently, the term "obtaining a secret key" is used to indicate that two peer entities agree, through exchanges, injections or a negotiation phase, on a common key.

[0008] Today, prior art encryption methods are secure because breaking them would require computing power far exceeding the capabilities of current computers. However, quantum computing is changing the game, as it is estimated that in the near future, quantum computers using algorithms like Shor's will be able to break asymmetric exchanges based on the mathematical exponentiation function. The security of public / private key cryptography currently deployed for establishing VPN tunnels could therefore collapse, since it would be possible for an attacker to intercept the secret key established during the key acquisition phase, thereby compromising all data transmitted over the VPN tunnel thereafter.

[0009] Conversely, symmetric encryption / decryption algorithms are considered resistant to attacks by quantum computers, since it is possible to increase the size of the secret key in proportion to the increase in the computing power of quantum computers.

[0010] Several solutions make it possible to establish a VPN tunnel by securely distributing the secret keys for symmetric data encryption.

[0011] The first and simplest of these solutions relies on the distribution of secret keys via trusted courier. This involves delivering the secret keys to the various devices through a secure, third-party method, for example, by mail. The problem is that symmetric encryption keys must be renewed regularly. They are considered to "wear out," meaning they can only encrypt a limited amount of data without revealing information to a potential attacker. Renewing secret keys via trusted courier is complex to implement, which is why a large number of keys are generally delivered together and used successively as they are renewed. This requires secure storage for unused secret keys and raises the issue of key vulnerability. This is time-consuming and requires extensive planning. An alternative solution is to securely deliver equipment pre-loaded with an initial set of keys sufficient to cover its operational lifespan. This solution is feasible if only a few keys are needed and requires careful attention to the transport and storage of the equipment.

[0012] Another solution is based on PHYSEC / SKG (an acronym for Physical Layer Security / Secret Key Generation). This solution uses the characteristics of the radio transmission channel and a reconciliation phase to negotiate secret keys. The principle of this solution relies on exploiting the physical randomness induced by propagation and reception noise to generate secret keys or apply secret error-correcting coding. However, this solution provides only limited quantifiable security.

[0013] Other solutions, known as post-quantum cryptography (or PQC), were presented in a campaign by NIST (National Institute of Standards and Technology). These solutions include signature algorithms (such as Falcon) and key encapsulation mechanisms (KEM). However, the maturity level of post-quantum algorithms should not be overestimated. Indeed, these techniques lack maturity on several levels: - in terms of sizing: the size of the data and sometimes the processing capacity is increased (the size of the keys needed for key exchange can be up to 16,000 times larger than the size of the final key), - at the level of integrating algorithms into communication protocols, - at the level of designing secure implementations (the processes are recent, with a certain lack of perspective).

[0014] In addition, several post-quantum schemes have suffered from "classical" attacks in recent years.

[0015] Another solution involves exchanging secret keys using QKD (Quantum Key Distribution). QKD relies on photon exchanges performed over an optical channel (free space or optical fiber), and on so-called "reconciliation" exchanges performed over a separate protocol channel, in order to associate the emitted and received photons with a secret key. These techniques use the physical properties of quantum phenomena rather than mathematics to determine keys.

[0016] The problem with this solution is that it is also a recent technology. The keys are not easy to obtain, and are generated over limited distances and with limited data rates. This distance limitation necessitates the insertion of "trusted nodes" for hop-by-hop routing of the secret keys. The level of protection of the trusted nodes must be commensurate with the classification level of the generated keys.

[0017] Figure 1 illustrates the mechanisms to be implemented for a QKD key exchange between an encryptor 101 and an encryptor 102 whose distance is such that they cannot directly perform the QKD key exchange. It is therefore necessary to implement a QKD node network 103 comprising one or more QKDA to QKDD trusted nodes. In the example of Figure 1, the QKDA trusted node is connected to the encryptor 101 by a secure link, and the QKDD trusted node is connected to the encryptor 102 by another secure link. This exchange takes place in several steps: - a first step during which the QKDA node and the QKDB node negotiate a Q1 104 secret key using a quantum mechanism, - a second step during which the QKDB node and the QKDC node negotiate a secret Q2 key 105 via a quantum mechanism, - a third step during which the QKDB node protects (encrypts) the secret key Q1 using the secret key Q2, and transmits the protected key Q1 to the QKDC node, - a fourth step during which the QKDC node and the QKDD node negotiate a secret Q3 key 107 via a quantum mechanism, - a fifth step during which the QKDC node protects the secret key Q1 using the secret key Q3, and transmits the protected key Q1 to the QKDD node, - a sixth step during which the QKDA node distributes the secret key Q1 to the encryptor 101, and the QKDD node distributes the secret key Q1 to the encryptor 102.

[0018] The ciphers 101 and 102 can then exchange data encrypted by the secret key Ql.

[0019] This solution therefore involves the implementation of a communications infrastructure 103 specifically dedicated to the generation of the secret key, which may involve numerous QKD nodes. Furthermore, this solution consumes many QKD keys for the transport of a single secret key, which is costly.

[0020] In order to limit the robustness shortcomings of post-quantum algorithms, a known and recommended solution consists of generating a hybrid secret key from several keys produced by distinct key generation technologies via a technique This is known as the KDF (Key Derivation Function). For example, a secret key can be derived from a QKD key, a post-quantum key, and a key obtained through an asymmetric exchange, or a key from a quantum-resistant technology can be introduced into the classical Diffie-Hellman process. This solution requires obtaining multiple keys from heterogeneous technologies for the generation of each secret key, which has a limited lifespan. It is therefore very resource-intensive.

[0021] There is currently no solution for obtaining a secret key in a simple and robust manner against quantum computer attacks. One of the objectives of the invention is therefore to address this problem with a method based on the hybridization of security solutions, rather than by combining keys obtained through separate security solutions. Hybridization refers to the synergy and cooperation of two techniques for obtaining secret keys. Summary of the invention

[0022] To this end, the present invention describes a method for obtaining a hybrid secret key comprising: - a first step towards obtaining an initial secret key, using a technology robust to quantum attacks, - a second step of obtaining a second secret key in a space encrypted by the first secret key, using a technology other than that used in the first step, the hybrid secret key corresponding to the second secret key.

[0023] Advantageously, the renewal of the secret key is done by executing the second step only again.

[0024] According to various embodiments, the quantum-attack-robust technology used in the first step is chosen from a set of secret key exchange technologies comprising: - key distribution via secure mail, - a key exchange via PHYSec, - a key exchange using a post-quantum method, - a QKD quantum key injection.

[0025] According to various embodiments, the secret key exchange technology used in the second step is chosen from a set of secret key exchange technologies comprising: - an exchange of asymmetric keys, - a PHYSec key exchange.

[0026] The invention also relates to a method for secure data exchange between two devices comprising: - obtaining a hybrid secret key by a method for obtaining a hybrid secret key according to the invention, - a step of implementing an encrypted VPN tunnel between the two devices for secure data exchange, said VPN tunnel being encrypted with said hybrid secret key.

[0027] Advantageously, a plurality of hybrid secret keys are generated by iterating the second step of the hybrid secret key obtaining process to implement respectively a plurality of encrypted VPN tunnels.

[0028] The invention also relates to a system comprising two pieces of equipment connected by a data link, said equipment comprising means configured to implement together a secure data exchange process according to the invention.

[0029] The invention also relates to a computer program product comprising program code instructions, enabling two digital computing means to implement together a method for obtaining a hybrid secret key or a method for secure data exchange according to the invention, and to a computer-readable recording medium on which the computer program product is recorded. Brief description of the drawings

[0030] The invention will be better understood and other features, details and advantages will become clearer from the following description, given by way of non-limiting reason, and from the accompanying figures, given by way of example.

[0031] [Fig-1] Fig. 1 represents the mechanisms implemented for a key exchange secret by QKD according to the state of the art between two remote devices.

[0032] [Fig.2] The [Fig.2] is a synoptic diagram of a method for obtaining a hybrid secret key according to an embodiment of the invention.

[0033] [Fig.3] Fig.3 illustrates the steps of a method for obtaining a hybrid secret key according to an embodiment of the invention.

[0034] [Fig.4] Fig.4 represents an embodiment of a secure data exchange method between two pieces of equipment according to the invention.

[0035] [Fig.5] Fig.5 represents an embodiment of a secure data exchange method between two pieces of equipment according to the invention.

[0036] [Fig.6] Fig.6 represents an embodiment of a secure data exchange method between two pieces of equipment according to the invention.

[0037] [Fig.7] Fig.7 represents an embodiment of a secure data exchange method between two pieces of equipment according to the invention.

[0038] [Fig.8] Fig.8 represents an embodiment of a secure data exchange method between two pieces of equipment according to the invention. Description of the implementation methods

[0039] The invention described below relates to a method for obtaining a hybrid secret key, usable for symmetric encryption of data in a transmission carried out through a VPN tunnel, according to a mechanism robust to quantum attacks. The method is applicable in the case of constructing a VPN tunnel, but also more generally for any use implementing a secret key.

[0040] Fig. 2 is a synoptic diagram of a method for generating a secret key according to an embodiment of the invention.

[0041] The process includes a first step 201 of obtaining a first secret key, using a technology robust to quantum attacks. As previously mentioned, there are several quantum-robust technologies for obtaining a secret key, including key injection by QKD, the result of a key exchange by a post-quantum cryptographic algorithm (PQC), by PHYSEC, or by trusted courier distribution. This step can be implemented using any type of quantum-robust technology.

[0042] The process then includes a second step 202 of obtaining a second secret key in a protected space encrypted by the first secret key. This step is performed using a different technology than that used in the first step. There are no constraints on the technology used in the second step for obtaining the second secret key, which will therefore be chosen from among technologies that are low in time and computing power, such as, for example, a classic asymmetric key exchange (Diffie-Hellman) or a key exchange using PHYSec. The term "encrypted space" refers to a space in which data exchanges are protected by systematic symmetric encryption using the first secret key.

[0043] The second generated key is therefore a hybrid key obtained using two key injection, distribution, and / or exchange technologies. This hybridization protects the acquisition of the hybrid key in a space protected by a key robust to quantum attacks. The proposed hybridization is robust to both classical and quantum attacks. Thus, in the event of a failure of one of the two technologies, the overall process remains robust to at least one of the two types of attacks. The resulting hybrid key offers a level of security equivalent to hybrid keys obtained by KDF derivation of a secret key from secret keys obtained by different technologies, while being much less expensive to produce. implement. This hybrid key can be used to implement a VPN 203 tunnel that is robust against attacks from quantum computers.

[0044] Renewal of the secret key used to encrypt VPN tunnel 203 is done by repeating step 202 of the process, without it being necessary (up to a certain point) to renew the first secret key.

[0045] The first step 201 of the process may seem complex and / or costly to implement, but ultimately, this complexity and cost are limited because the first generated secret key wears out very slowly. Its need for renewal is low, and it can be used to generate a multitude of second secret keys. The process therefore makes very little use of step 201.

[0046] The hybrid secret key, used to encrypt traffic in the VPN tunnel, wears out more quickly and its need for renewal is greater, which is why it can advantageously (but not necessarily) be implemented by a technology that consumes little time and computing power, such as a classic asymmetric Diffie-Helman or PHYsec key exchange.

[0047] Figure 3 illustrates the steps of a method for generating a secret key according to an embodiment of the invention. The first step 201 consists of obtaining a first secret key 302 using a technology 301 robust to quantum attacks.

[0048] This key 302 is used to create an encrypted space 303 under cover of which a second secret key 305 is negotiated, using a technology 304 different from the technology 301.

[0049] Secure data exchange takes place through a 306 VPN tunnel encrypted by the second secret key, or hybrid key, 305.

[0050] The secret key generation method according to the invention has many advantages: - it enables the implementation of encrypted transmissions that are robust against attacks carried out by classical and / or quantum computers; - It enables the implementation of a VPN tunnel with reduced key consumption. Indeed, only one encrypted key obtained using a technology robust to quantum attacks (the first key) is needed to transmit a very large amount of secure data. Unlike secret key generation by QKD as illustrated in [Fig. 1] or key generation by KDF, it is not necessary, for each secret key, to negotiate multiple keys, the transmission of which can be lengthy and costly. This can be considered eco-design; - Secret keys can be generated on demand. The transmission system implementing the method according to the invention is therefore flexible and dynamic; - it is simple to implement, since it involves encapsulating known encryption systems in a space protected by a symmetric key obtained through a mechanism robust to quantum attacks; - It is compatible with all existing encryption technologies.

[0051] The reduced key consumption for implementing a VPN tunnel based on a secret key generation method according to the invention can be illustrated by taking the example of an encryptor configured to encrypt a data stream with a secret key at a rate of 10 Mbit / second. Arbitrarily, we assume that the symmetric key must be renewed every 4 hours, or every 180 billion encrypted bytes.

[0052] In a system robust to quantum attacks according to the prior art, such as a QKD key exchange system, it would be necessary to carry out a quantum key negotiation as illustrated in [Fig.1] every four hours.

[0053] An asymmetric key exchange (IKEv2) requires approximately 20 KB for each renewal. A VPN tunnel implemented using a secret key generation method according to the invention requires the generation of a key robust to quantum attacks (first key 302) to encrypt more than 9 million secret keys (second key 305). The use of quantum-attack-resistant technologies, which is costly and time-consuming, is therefore significantly reduced by using the key generation method according to the invention, without compromising the robustness of the encryption.

[0054] Figures 4 to 7 illustrate different embodiments of a secure data exchange method according to the invention.

[0055] In [Fig.4], equipment 401 and 402 obtain a first secret key 403 by a mechanism robust to quantum attacks through a QKD key exchange network 404 as illustrated in [Fig.1].

[0056] The first secret key 403 is used to set up an encrypted space 405 in which the equipment 401 and 402 obtain a second secret key 406 using an asymmetric key exchange technology (IKEv2 for example).

[0057] A VPN tunnel 407 encrypted with the second secret key 406 is then implemented for secure data exchange between equipment 401 and equipment 402.

[0058] The renewal of the second secret key 406 takes place in the space 401 encrypted by the first secret key 403, until the wear and tear of this key.

[0059] Note that the 405 space encrypted by the first secret key can be used to obtain several second secret keys respectively intended for the implementation of several VPN tunnels.

[0060] In [Fig.5], equipment 501 and 502 obtain a first secret key 503 by a mechanism robust to quantum attacks using a post-quantum key exchange (PQC) technology.

[0061] The first secret key 503 is used to set up an encrypted space 504 in which the equipment 501 and 502 obtain a second secret key 505 using an asymmetric key exchange technology (IKEv2 for example).

[0062] A VPN tunnel 506 encrypted with the second secret key 505 is then implemented for secure data exchange between equipment 501 and equipment 502.

[0063] The renewal of the second secret key 505 takes place in the space 504 encrypted by the first secret key 503, until the wear and tear of this key.

[0064] In [Fig. 6], devices 601 and 602 obtain a first secret key 603 through a mechanism robust to quantum attacks by using a trusted courier 604 and 605 that injects the key 603 into the two devices. The trusted courier could, for example, be a DTC (Depository Trust Company), diplomatic pouch delivery, or any other method guaranteeing the security of the keys during their transmission and injection.

[0065] The first secret key 603 is used to set up an encrypted space 606 in which the equipment 601 and 602 obtain a second secret key 607 using an asymmetric key exchange technology (IKEv2 for example).

[0066] A VPN tunnel 608 encrypted with the second secret key 607 is then implemented for secure data exchange between equipment 601 and equipment 602.

[0067] The renewal of the second secret key 607 takes place in the space 606 encrypted by the first secret key 603, until the wear and tear of this key.

[0068] In [Fig.7], equipment 701 and 702 obtain a first secret key 703 by a mechanism robust to quantum attacks using a PHYSEC-type technology.

[0069] The first secret key 703 is used to set up an encrypted space 704 in which the equipment 701 and 702 obtain a second secret key 705 using an asymmetric key exchange technology (IKEv2 for example).

[0070] A VPN tunnel 706 encrypted with the second secret key 705 is then implemented for secure data exchange between equipment 701 and equipment 702.

[0071] The renewal of the second secret key 705 takes place in the space 704 encrypted by the first secret key 703, until the wear and tear of this key.

[0072] In [Fig.8], equipment 801 and 802 obtain a first secret key 803 by a quantum-attack robust mechanism using any quantum-attack robust technology.

[0073] The first secret key 803 is used to set up an encrypted space 804 in which the equipment 801 and 802 obtain a second secret key 805 using PHYSEC-type technology.

[0074] An 806 VPN tunnel encrypted with the second secret key 805 is then implemented for secure data exchange between equipment 801 and equipment 802.

[0075] The renewal of the second secret key 805 takes place in the space 804 encrypted by the first secret key 803, until the wear and tear of this key.

[0076] It should be noted that in this case, both technologies used are robust to quantum attacks. The first technology enhances the security of the second.

[0077] The invention presented here relates to: - a method for obtaining hybrid secret keys, comprising the hybridization of two key generation technologies in order to protect the key exchange carried out according to one technology in a space using a secret key obtained by another technology robust to quantum attacks, and - a method of data exchange between two devices, comprising the establishment of a VPN tunnel encrypted using a secret key obtained by a process according to the invention hybridizing two key generation technologies, at least the first of which is robust to quantum attacks.

[0078] The invention also relates to a system comprising two pieces of equipment configured to implement together a method for obtaining hybrid secret keys according to the invention and / or a method for exchanging data according to the invention.

[0079] This equipment includes digital computing means, such as, for example, a microprocessor, a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), an ASIC (Application-Specific Integrated Circuit), or any combination thereof, configured to implement encryption and to perform the key injections / exchanges / negotiations necessary for the implementation of the invention. Where appropriate, the equipment may include or be connected to specific means for implementing a given key exchange technology.For example, when quantum-attack-resistant technology relies on quantum key distribution (QKD), these means might include a device for transmitting / receiving a signal over an optical channel and a secondary channel (optical or non-optical), for exchanging photons and reconciling the optical signal. When quantum-attack-resistant technology relies on a trusted courier, the means might include a secret key loading interface. When the technology relies on PHYSec, they might include means for estimating a propagation channel.

[0080] The invention also relates to a computer program product comprising program code instructions readable by a digital computing means (microprocessor, DSP, FPGA, etc.), enabling two digital computing means to jointly execute a method for obtaining a hybrid secret key or a method for secure data exchange according to an embodiment of the invention. Finally, the invention relates to a computer-readable storage medium comprising the computer program product.

Claims

Demands

1. A method for obtaining a hybrid secret key characterized in that it comprises: - a first step (201) of obtaining a first secret key (302), using a secret key exchange technology (301) robust to quantum attacks, - a second step (202) of obtaining a second secret key (305) in a space encrypted by the first secret key, using a secret key exchange technology (304) other than that used in the first step (201), the hybrid secret key corresponding to the second secret key.

2. A method for obtaining a hybrid secret key according to claim 1, wherein the renewal of the secret key is done by executing the second step (202) only again.

3. A method for obtaining a hybrid secret key according to any one of the preceding claims, wherein the quantum-attack-robust technology used in the first step (201) is selected from a set of secret key exchange technologies including: - key distribution (603) by secure mail, - key exchange (703) by PHYSec, - key exchange (503) by a post-quantum method, - quantum QKD key injection (403).

4. A method for obtaining a hybrid secret key according to any one of the preceding claims, wherein the secret key exchange technology used in the second step (202) is selected from a set of secret key exchange technologies comprising: - an asymmetric (406, 505, 607, 705) key exchange, - a PHYSec (805) key exchange.

5. A secure data exchange method between two devices, said secure data exchange method being characterized in that it comprises: - obtaining a hybrid secret key (305) by a method of obtaining a hybrid secret key according to any one of claims 1 to 4, - a step (103) of implementing an encrypted VPN tunnel (306) between the two devices for secure data exchange, said VPN tunnel being encrypted with said hybrid secret key (305).

6. A method for secure data exchange between two devices according to claim 5, wherein a plurality of hybrid secret keys are generated by iterating the second step (202) of the method for obtaining a hybrid secret key to implement respectively a plurality of encrypted VPN tunnels.

7. System comprising two pieces of equipment (401, 402) connected by a data link, said equipment comprising means configured to implement together a secure data exchange method according to any one of claims 5 to 6.

8. Product computer program comprising program code instructions, enabling two digital computing means to implement together a method for obtaining a hybrid secret key according to any one of claims 1 to 4 or a method for secure data exchange according to any one of claims 5 to 6.

9. Computer-readable recording medium on which a computer program product according to claim 8 is recorded.