Centralized method for pairing quantum cryptographic keys via satellite
A centralized method for quantum key distribution and storage via a ground-based management unit addresses delays in satellite-based key distribution, ensuring immediate key availability and improved integration with terrestrial systems.
Patent Information
- Application Number
- FR2023014794
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2043-12-21
AI Technical Summary
Existing quantum key distribution methods via satellite face challenges in reducing the delay between a pairing request and its execution, particularly due to weather conditions and satellite visibility, which can lead to inefficient and complex key distribution.
A centralized method involving quantum key distribution, centralized key storage, and pairing steps to securely manage cryptographic keys via a central ground key management unit, allowing immediate availability upon request, independent of satellite constraints.
The method reduces pairing delays and adapts key distribution to immediate needs, enhancing responsiveness and integration between terrestrial and satellite systems by ensuring keys are available on demand.
Smart Images

Figure 00000016_0000 
Figure 00000017_0000
Abstract
Description
Title of the invention: Centralized method for pairing quantum cryptographic keys via satellite
[0001] The invention relates to a centralized method for pairing a quantum cryptographic key via satellite for a plurality of ground stations. The invention further relates to a centralized system for pairing a quantum cryptographic key via satellite for a plurality of ground stations, using a method according to the invention.
[0002] There is an interest in enabling the exchange of sensitive information via an open communication channel, such as a wireless communication channel, while preserving its confidentiality. An open communication channel or open link is understood to be a communication channel or link whose content can be intercepted by a third party without the sender or receiver being able to detect it. Such a problem is typically represented by a situation in which two people, Alice and Bob, wish to exchange sensitive information discreetly, through an authenticated open communication channel (e.g., the internet). Cryptographic techniques exist for this purpose, by which Alice and Bob encrypt their messages.We know of symmetric cryptographic techniques that use only a shared private key (also called a "shared secret") and asymmetric cryptographic techniques that rely on a combination of public and private keys. The principle of a symmetric cryptographic technique is briefly detailed below. Let's call Eve the person who wants to intercept these messages. Alice, using a cryptographic function and a private key shared with Bob, encrypts her messages before sending them to Bob through an open channel. When Bob receives the encrypted messages, he decrypts them using the same cryptographic function and the shared private key to access the plaintext. Eve, not possessing the key, will not be able to decrypt the message.
[0003] In the implementation of symmetric cryptographic techniques, a crucial question concerns the preservation of secrecy, in particular the ways of sharing the secret key securely between Alice and Bob, away from prying eyes.
[0004] A new solution was devised at the end of the 20th century, proposing the use of quantum communications to securely share a common key between Alice and Bob. Quantum communication consists of establishing a quantum link between a transmitter and a receiver for the exchange of information. The quantum link notably includes an optical link transmitting a sequence of photons. A qubit (or qubit) is the quantum information carried by a photon. This information is, for example, encoded in the polarization state of the photon.
[0005] Quantum Key Distribution (QKD) refers to a cryptographic protocol for establishing a shared secret key between two participants, Alice and Bob, using quantum communication. Thanks to quantum properties, particularly those arising from the quantum no-cloning theorem, any attempt to attack the communication, such as an attempt to eavesdrop by a third party, Eve, can be reliably detected by Alice and Bob, allowing them to quickly invalidate the key. Therefore, QKD enables the secure establishment of a symmetric cryptographic key.
[0006] The Prepared & Measure (P&M) protocol is an example of a known QKD process. In this P&M protocol, the transmitter Alice encodes a classical bit (0 or 1) in an individual optical signal, such as a photon, before transmitting it as a qubit to the receiver Bob. Bob performs a set of specific measurements on each of the individual optical signals, such as photons, emitted by Alice in order to recover the encoded bits. An example of a P&M protocol is the BB84 protocol, in which the polarization of an individual photon allows the encoding of a bit. The BB84 protocol is notably described in the publication "Quantum cryptography: Public key distribution and coin tossing," by Charles H. Bennett and Gilles Brassard, Theoretical Computer Science, vol. 560, 1984, pp. 7-11 (D01:10.1016 / j.tcs.2014.05.025).
[0007] When Alice and Bob are ground users, the quantum link can be implemented via an optical communication channel carried by optical fiber. However, in optical fiber, optical signals are progressively attenuated, which only allows a quantum link below a limiting distance, typically around 100 km. For a quantum key distribution over a longer distance, it is known to propagate the key via one or more so-called "trusted nodes" placed at regular intervals (typically every 100 kilometers). Such a trusted node, positioned between Alice and Bob, makes it possible to extend the range of key establishment by quantum communication. To this end, the trusted node manipulates in plaintext a key KA shared by quantum communication with Alice and a key KB shared by quantum communication with Bob.Therefore, the trusted node must be secured with a very high level of security. Furthermore, the trusted node relies in particular on the one-time pad cryptography (OTP) technique to transmit the KA key, previously shared with Alice, to Bob. To do this, the trusted node applies an XOR function, that is, an "exclusive OR" function. between the KA key shared with Alice and the KB key shared with Bob, to obtain a parity sequence KA®KB. The XOR function between two elements is represented by the # symbol. The parity sequence ka@KB is transmitted to Bob via an authenticated open channel. Bob, who holds the KB key, can then perform another XOR function between the sequence received from the trusted node and his KB key to recover Alice's KA key. This relies on the property of the XOR function that KASKBSKB = KA®{KBSKB) = -RA, but also on the one-time pad encryption technique which guarantees that it is not possible to recover either of the KA or KB keys using only the KA® sequence. <B- Cependant, une connexion via fibre optique entre deux utilisateurs séparés par un océan peut être désavantageuse en termes de garantie de sécurité car nécessitant un grand nombre de nœuds de confiance.
[0008] It is known to carry out the exchange of optical signals in a free field, that is to say, in particular from space, via a satellite and a ground station equipped with a telescope. The quantum link is then implemented by a laser source, notably in the infrared or near-infrared range. By traversing the vacuum of space and the Earth's atmosphere, the laser signal implementing quantum communication undergoes less attenuation, at least over long distances, compared to propagation in an optical fiber. The publication "Progress in satellite Quantum Key Distribution", Robert Bedington, Juan Miguel Arrazola, Alexander Ling, npj Quantum Information 3, Article number: 30 (2017) (DOI:10.1038 / s41534-017-0031-5) describes satellite QKD processes.
[0009] Figure 1 illustrates a classic example of quantum key distribution by satellite. In a first step, the satellite establishes a shared key KA with the ground station Alice via quantum communication. After moving in its orbit, in a second step, the satellite establishes a second shared key KB with the ground station Bob via quantum communication. Then, in a third step, the satellite transmits to Bob the parity sequence KA®KB resulting from an XOR function applied to the keys KA, KB. The transmission of the parity sequence KA®KB takes place over an open communication channel, in particular a non-quantum one, for example via optical or radio frequency (RF) link. In a fourth step, Bob can then extract Alice's key KA by performing an XOR function between its own key Kb and the parity sequence KA®KB that the satellite transmitted to it. Thus, the key KA is finally shared between Alice and Bob.They can then use this KA key to encrypt communications between themselves over an open communication channel. By moving relative to Alice and relative to Bob, the satellite acts as a mobile spatial trust node. Key sharing between Alice and Bob can therefore be achieved. regardless of the distance between them, provided that the same satellite flies over both stations.
[0010] Since the quantum signals used are inherently very weak in intensity, the use of a low-Earth orbit satellite is preferred to that of a geostationary satellite, which has a higher orbit. As a result, the temporal visibility is more limited for a given station. Furthermore, the laser beam, which carries the quantum communication, remains highly sensitive to meteorological and environmental conditions between the ground station and the satellite. For example, clouds or atmospheric turbulence can disrupt, or even block, the optical signal. For each ground station, the satellite must therefore wait until conditions are favorable for key establishment via quantum communication.Thus, the time required to implement a pairing request between Alice and Bob can be significant, as the satellite must move from one station to another and the weather conditions must be favorable for each of them at the time of the satellite's passage.
[0011] The use of a satellite constellation through which the key is propagated from Alice to Bob is known. However, such a solution is relatively complex and expensive. Furthermore, depending on the geometry of the constellation, it is not always possible to establish an inter-satellite link (or ISL for "Inter Satellite Link") between any two satellites in the constellation. A key could be stored for a long time on board a satellite, waiting for it to have a visibility window with a recipient satellite, before it could be erased. However, the storage capacity of a satellite is limited.
[0012] A solution is therefore sought to reduce the delay between a pairing request between two ground stations and its execution, in a quantum distribution method of cryptographic key by satellite.
[0013] To this end, the invention relates to a centralized method for pairing a quantum cryptographic key via satellite for a plurality of ground stations, a method comprising, in this order: • a quantum key distribution step, in which, for each ground station, at least one respective cryptographic key, called a "ground station linked key", is shared by quantum communication between the ground station and a satellite, called a "key establishment satellite"; • a centralized key storage stage, in which each key linked to a ground station is first transmitted in encrypted form from the key-establishment satellite to a central ground key management unit, and then stored by that central ground key management unit; and • a pairing step between a first and a second of said ground stations, in which, upon receipt of a communication request between the first ground station and second ground station, the central ground key management unit transmits the key linked to the second ground station in encrypted form to the first ground station.
[0014] Thus, a secure repository of cryptographic keys is first created for ground stations, and then these keys are distributed upon request to establish encrypted communication between ground stations. Thanks to these centralized key distribution and storage steps, the keys are available upon a subsequent request to establish a connection between ground stations. Once the repository of cryptographic keys is created, the process of pairing shared cryptographic keys between two ground stations is no longer dependent on the constraints of the satellite system (visibility, mission, atmospheric channel availability, etc.). The pairing time between two ground stations is therefore improved compared to the prior art, and the distribution of key pairs can be adapted to the needs of the moment.
[0015] According to one embodiment, in the pairing step between the first ground station and the second ground station, the central terrestrial key management unit further transmits the key linked to the first ground station to the second ground station in encrypted form.
[0016] According to one embodiment, in the pairing step, the encrypted transmission or transmissions include the transmission of a parity sequence, resulting from an exclusive OR XOR function between the key linked to the first ground station and the key linked to the second ground station.
[0017] According to one embodiment, in the centralized key storage step, each key linked to a ground station is transmitted in encrypted form using a key shared between the key establishment satellite and the terrestrial key management central unit.
[0018] According to one variant, in the centralized key storage step, the encrypted transmission of the key linked to the ground station between the key establishment satellite and the terrestrial key management central unit includes the transmission of a parity sequence, resulting from an exclusive OR XOR function between the key linked to the ground station and the key shared between the key establishment satellite and the terrestrial key management central unit.
[0019] According to one variant, the method includes, before the centralized key storage step, a first preliminary step of quantum distribution of satellite keys, in which the key shared between the key establishment satellite and the terrestrial key management central unit is shared by quantum communication between the key establishment satellite and the terrestrial key management central unit.
[0020] According to one embodiment, the method further comprises, the key establishment satellite belonging to a constellation of satellites, a selection of a satellite among the constellation of satellites as a key establishment satellite from communication conditions with the ground station.
[0021] According to one embodiment, the terrestrial key management central unit is at least partly included in a mission control center of the key establishment satellite or satellite constellation.
[0022] According to one embodiment, for at least one ground station, several keys linked to the ground station shared by quantum communication are stored in the terrestrial central key management unit.
[0023] The invention further relates to a centralized satellite quantum cryptographic key pairing system for a plurality of ground stations, a system comprising at least one satellite, referred to as a "key establishment satellite", and at least one terrestrial key management central unit, configured to implement a method according to the invention.
[0024] Other features and advantages of the present invention will become more apparent upon reading the following description in relation to the following accompanying figures:
[0025] [Fig. 1] The [Fig. 1], already described, representing a method of quantum distribution of cryptographic key by satellite according to the prior art;
[0026] [Fig.2] Fig.2 represents an example of a centralized key pairing method quantum cryptography via satellite according to the invention.
[0027] The steps of an example of a method according to the invention will be described with reference to [Fig. 2]. The method enables quantum key pairing between two ground stations A, B. The method can be applied to more than two ground stations. The ground stations A, B include, in particular, means of communication with one or more satellites.
[0028] In a quantum key distribution step 1, for each ground station A, B, at least one cryptographic key KA, KB, referred to as the "ground station-linked key," is shared by quantum communication between the ground station A, B and a satellite SAT A, SAT B, referred to as the "key-establishment satellite." Thus, quantum communication is established between a first ground station A and a first key-establishment satellite SAT A. A key KA linked to the first ground station A is shared between the first ground station A and the first key-establishment satellite SAT A following this quantum communication. Also in this quantum key distribution step 1, in a similar manner, quantum communication is established between a second ground station B and a second key-establishment satellite SAT B.A key KB linked to the second ground station B is shared between the second ground station B and the second key-establishing satellite SAT B via this quantum communication.
[0029] At the end of step 2 of the quantum key distribution step, the key KA linked to the first ground station A is shared between the first ground station A and the first key establishment satellite SAT A; the key KB linked to the second ground station B is shared between the second ground station B and the second key establishment satellite SAT B. In other words, each key KA, KB linked to a ground station A, B is stored in the respective ground station A, B and in the respective key establishment satellite SAT A, SAT B.
[0030] Next, in a centralized key storage step 3, each key KA, KB, linked to a ground station A, B is transmitted in encrypted form from the key-establishment satellite SAT A, SAT B to a central key management unit UC. The central key management unit UC stores, in particular securely, the keys KA, KB linked to the ground stations A, B. In other words, the first key-establishment satellite SAT A sends the encrypted key KA linked to the first ground station A to the central key management unit UC; and the second key-establishment satellite SAT B sends the encrypted key KB linked to the second ground station B to the central key management unit UC. Thus, the central key management unit UC centralizes all KA, KB keys linked to ground stations A, B, previously shared between ground stations A, B and key establishment satellites SAT A, SAT B during key distribution step 1.The central key management unit (CU) is terrestrial, i.e., located on the ground, which makes it less complex to implement and more easily accessible compared to a satellite.
[0031] At the end of step 4 of the centralized key storage step 3, the keys KA, KB are therefore all recorded and available in the central key management unit UC, for pairing between two ground stations A, B. The key establishment satellite SAT A, SAT B can delete the key KA, KB linked to the ground station A, B in order in particular to free up memory space on board.
[0032] A service request 5 to the central unit UC initiates a pairing step 6 between the first ground station A and the second ground station B. Such a service request 5 requests the pairing of the first ground station A with the second ground station B, namely the provision of one of the keys KA, KB linked to the ground stations to communicate with each other.
[0033] In the pairing step 6, the central key management unit UC then transmits in encrypted form the key KB linked to the second ground station B to the first ground station A.
[0034] At the end of step 7 of pairing step 6, the KB key linked to the second ground station B is available in the first ground station A.
[0035] Then, in a communication step 8, the first ground station A can send an encrypted message to the second ground station B using the key KB associated with the second ground station B. However, the first ground station A and the second ground station B may not be the users of the keys KA, KB. They then provide their respective keys KA, KB to their respective users, notably via a terrestrial link. The users can connect to the ground stations A, B via a local or remote communication network. Preferably, the link between the ground station A, B and the user is encrypted using a key shared by quantum communication. However, the key could be shared by other means. For example, the key could be defined during the design of the ground station A, B and the user. For example, the users could be satellites.
[0036] Thanks to the quantum key distribution and centralized storage steps in the central key management unit (CU), the keys are immediately available upon a subsequent pairing request, particularly within the limits of the performance of the terrestrial links through which the pairing request and the key Kb associated with the second ground station B are transmitted. Thus, an urgent pairing request can be fulfilled, which was not the case in the prior art. Its fulfillment is no longer likely to be delayed due to adverse weather conditions and / or overflights at the ground stations. Indeed, the method shifts these uncertainties to the prior key distribution step. Advantageously, the requested pairing between ground stations can be achieved at the latest, particularly when communication between ground stations A and B is required.There is no need to plan pairing far in advance, with the risk that it will be unnecessary. The advantages of the process reduce the differences between the operation of terrestrial QKD infrastructures and satellite QKD infrastructures, thus facilitating integration between terrestrial and satellite systems.
[0037] In particular, the key distribution steps 1 and centralized key storage steps 3 are carried out for all ground stations A, B, before any pairing step 6 between ground stations A, B.
[0038] In particular, in the centralized key storage step 3, for the transmission of the key KA, KB linked to the ground station A, B to the central unit UC, the key establishment satellite SAT A, SAT B uses a respective key KMA, KMB shared between the key establishment satellite SAT A, SAT B and the central key management unit UC.
[0039] In particular, the key establishment satellite SAT A, SAT B performs an exclusive OR function between the key KA, KB linked to the ground station A, B and the key KMA, KMB shared between the key establishment satellite SAT A, SAT B and the central management unit of UC keys. The resulting parity sequence KA®KMA, KBSKMB is then transmitted to the UC key management unit. For this purpose, the UC key management unit can implement one-time pad cryptography (OTP). Thus, the link between the key generation satellites SAT A and SAT B and the UC key management unit can be established via an open, non-quantum link, such as optical or radio frequency (RF) communication.
[0040] In particular, at the end of step 4 of the centralized key storage step 3, the central key management unit CU extracts the key KA, KB linked to the ground station A, B from the parity sequence KA@KMA, KBSKMB emitted by the key establishment satellite SAT A, SAT B. In particular, if the level of security is thereby increased, this decryption of the key KA, KB linked to the ground station A, B can be carried out upon receipt of the communication request 5 between the first ground station A and the second ground station B.
[0041] In particular, the KMA, KMB key shared between the key-establishment satellite SAT A, SAT B and the central key management unit UC is shared quantum-wise in a first preliminary step of quantum satellite key distribution. This first preliminary step of quantum satellite key distribution is implemented before the centralized key storage step 3, to enable secure encrypted transmission of the KA, KB keys associated with the ground stations A, B to the central key management unit UC. Thus, a first KMA key is shared by quantum communication between the first key-establishment satellite SAT A and the central key management unit UC; and a second KMB key is shared by quantum communication between the second key-establishment satellite SAT B and the central key management unit UC.Preferably, the first preliminary quantum key distribution step is implemented before the quantum key distribution step 1 of the keys linked to ground stations A, B, to allow transmission of the keys KA, KB linked to ground stations A, B immediately after their sharing between ground station A, B and the key establishment satellite SAT A, SAT B.
[0042] However, the KMA, KMB key shared between the key establishment satellite SAT A, SAT B and the central key management unit UC could be obtained by other means, if the security level permits. For example, it could be defined during the design of the key establishment satellite SAT A, SAT B and carried on board before its launch.
[0043] In particular, the first key-establishment satellite SAT A and the second key-establishment satellite SAT B can correspond to the same satellite traveling a distance for a quantum-like sharing of the key KA linked to the The first ground station A, then the key KB linked to the second ground station B, or vice versa. Alternatively, the first key establishment satellite SAT A and the second key establishment satellite SAT B can correspond to two different satellites, including those belonging to a satellite constellation.
[0044] In particular, when a satellite constellation is available, the quantum key distribution step of KA, KB linked to ground stations A, B, includes, for each ground station A, B, a selection of a satellite from the constellation as the key establishment satellite SAT A, SAT B, depending on the communication conditions with the ground station A, B. The key establishment satellite SAT A, SAT B is in particular the one in the satellite constellation having the most favorable communication conditions with the ground station A, B, for example the one closest to the ground station A, B and / or benefiting from weather conditions characterized by the lowest cloud cover and / or the one benefiting from night transmission rather than day transmission.The use of a satellite constellation makes it possible, among other things, to multiply the opportunities to establish quantum communications with ground stations A, B when conditions are favorable.
[0045] In the centralized key storage step 3, the encrypted transmission of the KA, Kb keys associated with the ground stations A, B utilizes, in particular, the satellite constellation infrastructure. For example, the key-establishing satellite SAT A, SAT B transmits the Ka, Kb key in encrypted form via an open link to a telemetry, telecommand and control (TT&C) station, although another path is possible. The TT&C station is, in particular, a relay antenna for the known satellite constellation. The TT&C station then relays the encrypted transmission of the KA, Kb key associated with the ground station A, B to a mission control center (MCC). The MCC's function is, in a known manner, to manage the satellite constellation.In particular, the encrypted transmission of the KA, KB key linked to the ground station A, B is carried out via a TM / TC link, i.e. a telemetry-remote control link, in particular in the form of a radio frequency link.
[0046] The encrypted transmission of the KA, KB keys linked to ground stations A, B can also use inter-satellite links. One or more satellites in the constellation can act as a relay between the key-establishing satellite SAT A, SAT B and the TT&C station. The transmission can then be end-to-end encrypted and / or hop-by-hop encrypted. The use of one or more keys shared by quantum communication is preferred.
[0047] In particular, the central key management unit (CU) is included in the mission control center. This is particularly advantageous because, by virtue of its function As the manager of the satellite constellation, the mission control center is highly secure, both digitally to prevent any computer infiltration, and physically through security guards, differentiated access authorizations, and vaults, for example. The security level of the mission control center is notably compatible with a trusted node function. The central key management unit (CMU) can then benefit from these security measures. The CMU is preferably fully integrated within the mission control center. Alternatively, the CMU is partially integrated within the mission control center or entirely located outside of it.Communication between the mission control center and the central key management unit (CU) is then preferably highly secure, for example by a key shared via quantum communication.
[0048] The central key management unit UC can be on a single site.
[0049] Alternatively, the central key management unit (CU) can be distributed across multiple sites. In this case, during the centralized key storage step 3, each key Ka, Kb associated with a ground station A, B is transmitted to a site of the central key management unit (UC). In particular, a synchronization mechanism is implemented between the sites of the central key management unit (UC) to manage the distribution of keys associated with ground stations A, B.
[0050] Preferably, the method then includes a second preliminary step of quantum key distribution, in which keys are shared by quantum communication between the sites of the central key management unit (CU). This second preliminary step of quantum key distribution is implemented before the key storage step 3, to allow secure encrypted transmission of the key Ka, Kb associated with the ground station A, B to the respective site of the central key management unit (CU). Preferably, this second preliminary step of quantum key distribution is implemented before the quantum key distribution step 1 of the keys associated with the ground stations A, B, to allow transmission of the keys Ka, Kb associated with the ground stations A, B immediately after their sharing between the ground station A, B and the key establishment satellite SAT A, SAT B.
[0051] In particular, the first preliminary step of quantum distribution of satellite keys and / or the second preliminary step of quantum distribution of site keys are implemented during an initial configuration of the system implementing the method, in particular before any quantum distribution step 1 of keys linked to ground stations A, B. Such an initial configuration may take place during a first commissioning of the system or after an update of the system.
[0052] In particular, in the pairing step 6, the encrypted transmission of the key KB associated with the second ground station B to the first ground station A includes the transmission of a parity sequence KA@KB resulting from the exclusive OR function between the key Ka associated with the first ground station A and the key KB associated with the second ground station B. For this purpose, the central key management unit CU can implement the one-time pad cryptography (OTP) technique. Therefore, it is not necessary to define a shared key between each ground station A, B, and the central key management unit CU.
[0053] In particular, at the end of step 7 of pairing step 6, the first ground station A extracts the key Kb linked to the second ground station B from the parity sequence KAë KB issued by the central key management unit UC.
[0054] Then, in the communication step 8, the first ground station A can then send a parity sequence KÀ^KB resulting from the exclusive OR function between the key Ka linked to the first ground station A and the key KB linked to the second ground station B, so that the second ground station B also has the key KA of the first ground station A.
[0055] The KA key of the first ground station A can also be transmitted in encrypted form to the second ground station B during the pairing step 6. For this purpose, the central key management unit UC also sends the parity sequence KÀSKB to the second ground station B, so that the latter extracts the KA key linked to the first ground station A, as described in relation to the first ground station A.
[0056] In particular, the links between the ground stations A, B and the central key management unit UC are terrestrial, or even exclusively terrestrial, i.e. implemented by ground infrastructure, such as for example communication cables, optical fibers or mobile telecommunication systems.
[0057] The key establishment satellite(s) S ATA, S ATA B and the central key management unit UC are therefore part of a centralized quantum cryptographic key pairing system for a plurality of ground stations A, B.
[0058] The key establishment satellite(s) SAT A, SAT B and / or the central key management unit CU, as trusted nodes in the key exchange between the ground stations A, B, are preferably highly secured against digital and physical attacks by appropriate protection means, in accordance with best practices for critical infrastructure. Thus, the central key management unit CU securely stores the keys KA, KB associated with the ground stations A, B. The key establishment satellite(s) SAT A, SAT B may temporarily securely store the keys KA, KB associated with the ground stations A, B.
[0059] To carry out step 1 of quantum key distribution linked to ground stations A, B, the key-establishing satellite(s) SAT A, SAT B and the ground stations A, B are preferably each equipped with quantum optical terminals. For example, the quantum optical terminal of the key-establishing satellite SAT A, SAT B includes a photon source; and the quantum optical terminal of the ground station A, B includes, among other things, a qubit analyzer and single-photon detectors. The central key management unit (CU) may also be equipped with a quantum optical terminal, in order to implement the first preliminary step of quantum key distribution from the satellites.
[0060] A ground station A, B can be fixed or mobile, such as a boat or a submarine.
[0061] For at least one of the ground stations A, B, or even all of them, several keys associated with the ground station can be shared via quantum communication between the ground station and the key-establishing satellite, and stored in parallel in the central key management unit (CU). These keys are shared between the ground station and the key-establishing satellite, either in the same key distribution step 1 or in separate key distribution steps 1. Thus, several keys associated with ground station A, B can be available in advance, which improves the responsiveness of the process upon receiving a pairing request. This is particularly advantageous for a ground station that is heavily used.
[0062] It is preferable that for each ground station A, B at least a minimum quantity of key Ka, Kb be available in the central unit UC at all times, so that a pairing request concerning any of the ground stations A, B can be satisfied immediately.
[0063] For example, quantum communication between ground station A, B and key establishment satellite SAT A, SAT B or between key establishment satellite SAT A, SAT B and key management central unit UC, or any other quantum communication described in relation to the invention, implements a QKD process known per se, for example with a Prepared and Measure protocol, such as the BB84 protocol.
[0064] Sharing a key in a quantum manner or by quantum communication refers in particular to the establishment, by quantum communication between two entities, of a cryptographic key created by exploiting effects of quantum physics, the quantum cryptographic key being shared between the two entities as a result of this quantum communication. In particular, the cryptographic key is a random sequence of logical bits 0 and 1; and it is said to be "quantum" only because it is established through quantum communication.
Claims
Demands
1. Centralized method for quantum cryptographic key pairing by satellite for a plurality of ground stations (A, B), method comprising in this order: a quantum key distribution step (1), in which, for each ground station (A, B), at least one respective cryptographic key (KA, KB), called the "ground station linked key", is shared by quantum communication between the ground station (A, B) and a satellite (SAT A, SAT B), called the "key establishment satellite"; - a centralized key storage step (3), in which each key (Ka, Kb) linked to a ground station (A, B) is first transmitted in encrypted form from the key establishment satellite (SAT A, SAT B) to a terrestrial central key management unit (CU), and then stored by this terrestrial central key management unit (CU);and - a pairing step (6) between a first (A) and a second (B) of said ground stations, in which, upon receipt of a communication request (5) between the first ground station (A) and the second ground station (B), the terrestrial central key management unit (CU) transmits in encrypted form the key (KB) linked to the second ground station (B) to the first ground station (A).
2. A method according to the preceding claim, wherein: in the pairing step (6) between the first ground station (A) and the second ground station (B), the terrestrial central key management unit (CU) further transmits in encrypted form the key (KA) linked to the first ground station (A) to the second ground station (B).
3. A method according to claim 1 or 2, wherein, in the pairing step (6), the encrypted transmission or transmissions comprise the transmission of a parity sequence KA^KB resulting from an exclusive OR XOR function between the key (KA) linked to the first ground station (A) and the key (KB) linked to the second ground station (B).
4. A method according to any one of the preceding claims, wherein, in the centralized key storage step (3), each key (KA, KB) linked to a ground station (A, B) is transmitted in encrypted form by means of a key (KMA, KMB) shared between the key establishment satellite (SAT A, SAT B) and the terrestrial central key management unit (UC).
5. A method according to the preceding claim, wherein, in the centralized key storage step (3), the encrypted transmission of the key (KA, KB) linked to the ground station (A, B) between the key-establishing satellite (SAT A, SAT B) and the terrestrial key management central unit (CU) comprises the transmission of a parity sequence (KA®KMÀ, Result of an exclusive OR XOR function between the key (KA, KB) linked to the ground station (A, B) and the shared key (KMA, KMB) between the key-establishing satellite (SAT A, SAT B) and the terrestrial key management central unit (CU).
6. A method according to claim 4 or 5, comprising, prior to the centralized key storage step (3), a first preliminary step of quantum satellite key distribution, wherein the key (KMA, Kmb) shared between the key establishment satellite (SAT A, SAT B) and the terrestrial key management central unit (CU) is shared by quantum communication between the key establishment satellite (SAT A, SAT B) and the terrestrial key management central unit (CU).
7. A method according to any one of the preceding claims further comprising, the key-establishing satellite (SAT A, SAT B) belonging to a constellation of satellites, a selection of a satellite from the constellation of satellites as the key-establishing satellite (SAT A, SAT B) from communication conditions with the ground station (A, B).
8. A method according to any one of the preceding claims, wherein the terrestrial key management central unit (CU) is at least partly included in a mission control center (MCC) of the key establishment satellite (SAT A, SAT B) or satellite constellation.
9. A method according to any one of the preceding claims, wherein, for at least one ground station (A, B), several keys (KA, KB) linked to the ground station (A, B) shared by quantum communication are stored in the ground central key management unit (CU).
10. Centralized satellite quantum cryptographic key pairing system for a plurality of ground stations (A, B), system comprising at least one satellite (SAT A, SAT B), referred to as the "key establishment satellite", and at least one ground-based central key management unit (CU), configured to implement a method according to one of the preceding claims.