Improved key exchange method based on a quantum network and a security service; associated communication infrastructure.
The proposed method for secure key transfer in QKD networks using XOR nodes and security service modules addresses the security and cost challenges of existing QKD networks by ensuring only end nodes know the keys, enhancing security and performance.
Patent Information
- Application Number
- FR2023015410
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-07-04
AI Technical Summary
Existing quantum key distribution (QKD) networks face challenges in securely routing keys over long distances due to the need for trusted relay nodes, which increases costs and vulnerabilities, and existing key transfer methods expose the keys to intermediate nodes, compromising security.
A method involving a security service infrastructure with centralized or non-centralized XOR nodes and security service modules on sender and recipient nodes, using intermediate and composite chains to securely transfer encryption keys over conventional communication links, ensuring only the end nodes have knowledge of the keys.
This method enhances security by preventing intermediate nodes from knowing the transferred keys, reduces resource consumption, and doubles the performance of QKD networks by simultaneous key exchange, while maintaining confidentiality and integrity.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Improved key exchange method based on a quantum network and a security service; associated communication infrastructure.
[0001] The general field of the present invention is that of information technology security in the context of the implementation of quantum communications networks.
[0002] More particularly, the invention applies to key transfer methods based on a network implementing a quantum key distribution mechanism -QKD ("Quantum Key Distribution").
[0003] QKD allows unconditional security of communications, including in the face of the power of future quantum computers, which should make it possible to "break" classical cryptographic processes (notably with the Shor algorithm, for asymmetric cryptography).
[0004] QKD implements two end nodes, each integrating quantum devices, to generate and share a quantum key along a quantum channel established between these two devices. The quantum channel is established over an optical link, which must be continuous (such as an optical fiber or free space).
[0005] However, in the absence of quantum repeaters, QKD is distance limited.
[0006] For longer distances, relay (or transit) nodes are interposed between the end nodes. Since the different nodes are then only a few tens of kilometers apart, it is possible to establish quantum channels between the nodes and thus form a QKD network, also called a quantum secure network - QSN ("Quantum Secured Network"). On the QKD network, two nodes connected by a quantum channel share a so-called "quantum" key.
[0007] The question then arises as to how to route a key from an end node or transmitter node, called Alice in the following, to an end node or destination node, called Mike in the following, using the quantum keys on the various sections (or hops) of a path on the QKD network connecting Alice and Mike, while maximizing the confidentiality of this transfer, in particular in the event of an attack on the nodes of the QKD network.
[0008] The state-of-the-art key transfer method, as presented in the recommendation - ITU-T Y.3803 entitled "Key management for quantum key distribution Networks" ("Key management for QKD networks"), of the study group of the telecommunications standardization sector of the International Telecommunication Union - ITU, performs encryption / decryption hop-by-hop: In a QKD network, a node decrypts the key it receives from an upstream node with the quantum key it shares with that upstream node to retrieve the key to be routed. It then uses the quantum key it shares with a downstream node to encrypt the key to be routed and transmits the encrypted key to the downstream node. Step by step, the key to be routed is transmitted from Alice to Mike.
[0009] However, each node of the QKD network can know the key to be routed, when it passes through it, since it has the keys which allow it to be encrypted / decrypted.
[0010] This is why the nodes of the QKD network must be trusted nodes.
[0011] This strong constraint is a brake on the adoption of QKD networks due to the high cost of the nodes to respect the level of security imposed by the classification of the keys exchanged on the QKD network and the vulnerabilities induced by the presence of relay nodes, whether it is a lack of protection of a relay node or a malicious relay node (for example, in the case of transit through uncontrolled domains of the QKD network).
[0012] ITU-T Y.3803, however, proposes two alternative methods for key transfer, by implementing a specific entity, called "XOR node" in the following. The XOR node is part of a key management system - KMS ("Key Management System") of the QKD network. The XOR node is accessible by each of the nodes of the QKD network, via a conventional communication link, for example of the IP type.
[0013] In the first alternative method, the XOR node is non-centralized. This is an additional feature of the recipient, Mike. In the second alternative method, the XOR node is centralized. It is an entity independent of the QKD network nodes and users.
[0014] According to these alternative methods, each relay node of the QKD network constructs an elementary bit chain by summing (bitwise “XOR” operation) the two quantum keys of the same size that it shares respectively with an upstream node and a downstream node on the path between Alice and Mike. Each relay node transmits this elementary chain to the XOR node.
[0015] The XOR node then calculates a global chain by summing (operator "XOR") the set of elementary chains of all the relay nodes on the path between Alice and Mike. The global chain is finally equal to the sum of the quantum keys of the end nodes, that is to say the sum of the quantum key of the sender, Alice, which is the key that we are trying to transfer to Mike, and the quantum key of the recipient, Mike.
[0016] In the first alternative method, the XOR node being a functionality of the destination node, the latter knows the overall sum. In the second alternative method, the overall sum is transmitted from the XOR node to the destination node, for example over the conventional communication link between the XOR node and the destination node.
[0017] Mike only has to sum his quantum key with this global string to extract Alice's quantum key. He can then store it as an encryption key for future exchanges with Alice.
[0018] It should be noted that it is sometimes considered, as a possible “key to be transferred”, the concatenation of a sequence of random bits (which constitutes a key strictly speaking) with associated metadata such as identifier, creation date, etc.).
[0019] In the remainder of this document, we will refer to "keys", without losing sight of the fact that this covers these various possible implementation cases, i.e. a key as "useful randomness" or a key as "useful randomness augmented with metadata". According to these alternative methods, the relay nodes of the QKD network no longer have the immediate ability to know the key to be routed. Only the access nodes have important knowledge elements: the one to which Alice is connected has direct knowledge of the quantum key of the sender, and the one to which Mike is connected can deduce it if it intercepts the message transmitted to Mike by the XOR node, to the extent that it knows the quantum key of the recipient.
[0020] The aim of the invention is then to propose improvements to the known methods of key exchange based on a QKD network.
[0021] For this purpose, the subject of the invention is a method for exchanging encryption keys in a communication infrastructure, the communication infrastructure comprising a network implementing a quantum key distribution mechanism, or QKD network, the QKD network comprising a sender node, a recipient node and a plurality of relay nodes defining a path on the QKD network between the sender node and the recipient node, two successive nodes along the path being adapted to generate and share a quantum key through a quantum channel connecting said two nodes, characterized in that, the communication infrastructure further comprising a security service comprising a security service module on the sender node, associated with a first security key, a security service module on the recipient node, associated with a second security key,and a security service server in communication respectively with the security service modules of the sending and receiving nodes by means of conventional communication links, the method comprises the steps of: exchanging a first encryption key from the sending node to the receiving node and a second encryption key from the receiving node to the sending node; calculation, , by the sending node, of a first intermediate chain by summing the first security key and the second encryption key; transmission of the first intermediate chain to the security service server; calculation, by the receiving node, of a second intermediate chain by summing the second security key and the first encryption key; transmission of the second intermediate chain to the security service server; calculation, by the security service server, of a composite chain resulting from the sum of the first and second intermediate chains received from the sending and receiving nodes; transmission, by the security service server, of the composite chain to the security service module of the receiving node;summing, by the destination node, the composite string, the second intermediate string and the second encryption key, to extract the first security key, and storing the first security key as an encryption key in the encryption key volume of the destination node.;
[0022] According to other advantageous aspects of the invention, the method comprises one or more of the following characteristics, taken in isolation or in all technically possible combinations:
[0023] - the method further comprises: transmission, by the security service server, of the composite chain to the security service module of the sending node; and, summing, by the sending node, the composite chain, the first intermediate key and the first encryption key, to extract the second security key, and storing the second security key as an encryption key in the encryption key volume of the sending node.
[0024] - a first encryption key being shared between the sending node and the server security, the first intermediate string is transmitted encrypted along the conventional link between the security service module of the sending node and the security service server using the first encryption key and the composite string is transmitted encrypted along the conventional link between the security service server and the security service module of the sending node using the first encryption key.
[0025] - a second encryption key being shared between the recipient node and the server security, the second intermediate chain is transmitted encrypted along the conventional communication link between the security service module of the destination node and the security service server using the second encryption key and the composite key is transmitted encrypted along the conventional communication link between the security service server and the security service module of the destination node using the second encryption key.
[0026] - the infrastructure further comprising a centralized computing entity, or “node XOR » , the XOR node being connected to each of the nodes of the QKD network by a conventional communication link, the method comprises the preliminary steps of: calculation, by each relay node, of an elementary chain by summing the two quantum keys of the two quantum channels from said relay node, and transmission of the elementary chain to the XOR node; calculation, by the XOR node, of a global chain by summing the elementary chains received from each of the relay nodes present along the path between the transmitter node and the destination node; transmission, by the XOR node, of the global chain to the destination node; extraction, by the destination node, of the first encryption key of the transmitter node by summing the global chain and the second encryption key of the destination node, and storage of the first encryption key in an encryption key storage volume of the destination node; transmission, by the XOR node, of the global key to the transmitter node;and, extraction, by the sending node, of the second encryption key of the destination node by summing the global chain and the first encryption key of the sending node, and storage of the second encryption key in an encryption key storage volume of the sending node.;
[0027] The invention also relates to a communication infrastructure suitable for implementing the preceding encryption key exchange method, comprising a network implementing a quantum key distribution mechanism, or QKD network, the QKD network comprising a transmitter node, a destination node and a plurality of relay nodes defining a path on the QKD network between the transmitter node and the destination node, two successive nodes along the path being suitable for generating and sharing a quantum key through a quantum channel connecting said two nodes, the infrastructure further comprising a security service comprising a security module on the transmitter node, associated with a first security key, and a security module on the destination node, associated with a second security key,as well as a security service server in communication respectively with the security service modules of the sending and receiving nodes by means of conventional links.
[0028] According to other advantageous aspects of the invention, the method comprises one or more of the following characteristics, taken in isolation or in all technically possible combinations:
[0029] - the security service server is an additional functionality of the node sender and / or recipient node.
[0030] - the infrastructure further comprises a computing entity, or XOR node, the XOR node being connected to each of the nodes of the QKD network by a classic communication link.
[0031] - the XOR node is an additional functionality of the transmitter node and / or the destination node.
[0032] - the communication links being IP links on a communication network In classical mode, the security service server, the security service module of the sending node and the security service module of the receiving node use reserved IP addresses that are different from the IP addresses of the sending and receiving nodes, only the latter being known by the QKD network.
[0033] The invention will appear more clearly on reading the description which follows, given solely by way of non-limiting example, and made with reference to the drawings in which:
[0034] [Fig-1] [Fig.l] is a schematic functional representation of a first embodiment of an infrastructure according to the invention allowing the exchange of keys;
[0035] [Fig.2] [Fig.2] is a block representation of a first mode of implementation of a method according to the invention allowing the exchange of keys, this method being implemented by the infrastructure of [Fig.l];
[0036] [Fig.3] [Fig.3] is a schematic functional representation of a second mode of creating an infrastructure according to the invention allowing the exchange of keys;
[0037] [Fig.4] [Fig.4] is a block representation of a second mode of carrying out a method according to the invention allowing the exchange of keys in the infrastructure of [Fig.3];
[0038] [Fig.5] [Fig.5] is a schematic functional representation of a third embodiment of an infrastructure according to the invention allowing the exchange of keys; and,
[0039] [Fig.6] [Fig.6] is a block representation of a third mode of implementing a method according to the invention allowing the exchange of keys in the infrastructure of [Fig.5].
[0040] In the following, when we talk about the sum of two bit strings, we are talking about performing the bit-by-bit sum of these two strings, that is to say applying the XOR operator. The result obtained is a string of the same length.
[0041] A key is a particular string, insofar as it is intended to be used for its random and confidential nature (shared only with identified recipients), in particular to encrypt another key or data. On the other hand, the word "string" is more simply used for the case of a sequence of bits intended to carry information (for example, encrypted data, an "XOR" calculation, etc.).
[0042] We will also speak of "keys", or "encryption keys" for the keys that the QKD network must deliver to its users. We will use the term "security key" to distinguish the case where the key to be transferred has not been generated by QKD devices of the network. On the other hand, to facilitate reading, we will speak of encryption and "encryption keys" for the operations of protecting information transfers by the QKD network or by the proposed processes, even if the term "encryption" is in fact improper: it nevertheless allows us to differentiate the type of keys we are talking about and their use. We will see later that "encryption" here corresponds to the protection of exchanges of chains which are already in fact encrypted keys.
[0043] First embodiment: Symmetrization of exchanges with the XOR node
[0044] A first embodiment of the invention will be presented with reference to Figures 1 and 2.
[0045] The communication infrastructure 1 is based on an underlying QKD network 2.
[0046] The QKD network 2 comprises user nodes, respectively a transmitter node 10, Alice, a destination node 20, Mike, as well as a plurality of relay nodes.
[0047] A path on the QKD network 2 has been established between the sending node 10 and the receiving node 20. The process of establishing this path is in accordance with the state of the art. It is not specified in more detail here, since this process is outside the scope of the present invention.
[0048] This path passes through a succession of relay nodes, which are indexed by the integer i, between 1 and n-1. In [Fig.l], the access relay node on the sender side, 30i, of the intermediate relay nodes, 30i4, 30;, 30i+i, and the access relay node on the recipient side, 30n.i, of the path from Alice to Mike are represented.
[0049] Between two successive nodes of this path, a quantum channel is established. This channel and the quantum devices of the end nodes make it possible to generate and exchange quantum keys. In [Fig.l], the channels 311, 312, 31m, 31;, 3li+1, 3 li+2, 31 ni and 31n of the path between Alice and Mike are represented.
[0050] A quantum key is regularly shared and stored by the end nodes of a quantum channel. The figures show only the keys used during a given key exchange, i.e. at a given time.
[0051] Thus the transmitter node Alice and the first relay node 30; share a quantum key Ki; the first relay node 30i and the second relay node share a quantum key K2; the previous node 30,4 and the current node 30; share a quantum key K; ; the current node 30; and the next node 30i+i share a quantum key Ki+i; and, the relay node 30„ । and the destination node Mike share a quantum key Kn.
[0052] Infrastructure 1 includes an XOR node 40.
[0053] While the XOR node can be non-centralized (i.e., implemented by a node in the network, such as the destination node or the sender node), preferably the XOR node 40 is centralized, as shown in [Fig.l].
[0054] The XOR node 40 is connected to each relay node 30; by a conventional communication link 41;. This link is for example a conventional link, for example, an IP connection via a wide area network (WAN). To increase security, this connection is preferably authenticated according to the rules of the art (for example, by implementing post-quantum or hybrid signature techniques). This aspect is outside the scope of the present invention.
[0055] The XOR node 40 is advantageously co-located with a node of the QKD network, to have keys generated by the QKD network.
[0056] To further increase security, the XOR node 40 is advantageously independent of the QKD network 2, in particular of a key management system - KMS or of a controller of the QKD network. This makes it possible to eliminate, for example, cases of attack by a malicious XOR node collaborating with the KMS of the QKD network.
[0057] Each relay node comprises a unit 32;, adapted to perform the sum of the two quantum keys associated with the two quantum channels coming from this node. The result of this operation is an elementary chain Ke;. For example, the unit 32; of the node 30; determines the elementary chain Ke; result of the sum of the keys K; and Ki+i stored by the relay node 32;: Kq = Kj® Ki+r
[0058] Each relay node, like node 30;, comprises a unit 34;, adapted to transmit the elementary chain Ke; calculated by the unit 32; to the XOR node 40, via the conventional link 41;.
[0059] The XOR node 40 comprises a unit 44, which is adapted to receive the elementary chains Ke; from each of the relay nodes 30; of the path between Alice and Mike.
[0060] The XOR node 40 comprises a unit 42, which is adapted to sum the elementary chains coming from all the relay nodes along the path between Alice and Mike. The result of this operation is a global chain K.
[0061] Knowing that summing the same key twice amounts to performing the identity operation, the global chain K therefore respects the relation:
[0062] K = (K, © K2) © ... © (, © K, ) © ( K{© Ki+, ) © ( Ki+, ©Ki+, ) © ... © (kb, ©Kn)
[0063] K = Kx®Kn
[0064] The XOR node 40 comprises a unit 46M which is adapted to transmit the global string K to the recipient 20, Mike, along a conventional and preferably authenticated communication link 41M, for example a WAN IP link, between the XOR node 40 and the recipient node 20. Alternatively, when the XOR node is a functionality of a user node, such as the recipient node, it is a link in the functional sense (internal to the node).
[0065] Symmetrically, the XOR node 40 comprises a unit 46A which is adapted to transmit the global chain K to the transmitter 10, Alice, along a conventional and preferably authenticated communication link 41A, for example a WAN IP link, between the node 40 and the transmitter node 10.
[0066] A user node, transmitter 10 or recipient 20, comprises: - a volume for storing its own quantum keys, respectively 11 and 21; - a communication unit with the XOR node 40, respectively 14 and 24; - a computing unit, in particular suitable for deciphering the information received from the XOR node 40, respectively 12 and 22; and, - a volume for storing encryption keys, 15 and 25 respectively, containing keys that can be used for encrypting communications, in particular those between Alice and Mike.
[0067] Referring to [Fig.2], an embodiment of the encryption key exchange method will be presented.
[0068] The method 100 comprises the following successive steps:
[0069] Following a request for keys and the establishment of a path between Alice and Mike on the QKD network 2, in step 110, the calculation unit 32; of each relay node 30; along this path performs the sum of the two quantum keys that it has in memory: Ke; = K,© Ki+i.
[0070] It should be noted that a relay node can in fact store many quantum keys, but the choice of the two keys to be summed from among the set of available keys is outside the scope of the invention and is carried out according to the state of the art.
[0071] The transmission unit 34; of each relay node 30; transmits the elementary chain Ke; obtained, to the XOR node 40.
[0072] In step 120, the unit 44 of the XOR node 40 receives the elementary chains Ke; from the access and intermediate relay nodes present along the path between Alice and Mike and transmits them to the calculation unit 42. The latter performs the sum of the elementary chains. The result of this operation is the global chain K:
[0073] K^© K2) ©... © (Ku© KD © (K;©Ki+1) © ... © (^©KJ = Kt© Kn
[0074] In step 130, the global string K is transmitted to Mike along the link 41M between the unit 46m and the communication unit 24 of Mike.
[0075] In step 140, unit 22 sums the global string K with Mike's quantum key Kn, so as to extract Alice's quantum key Ki.
[0076] Mike stores (step 145) the quantum key Ki as a new encryption key in his encryption key storage volume 25, alongside his quantum key Kn. Thus Alice has successfully conveyed her quantum key Ki to Mike.
[0077] Symmetrically, in step 150, the XOR node 40 transmits the global string K to Alice, along the link 41A between the unit 46A and the communication unit 14 of Alice.
[0078] In step 160, Alice's computing unit 12 sums the global string K with its quantum key Kb so as to extract Mike's quantum key Kn.
[0079] Alice stores (step 165) the quantum key Kn as a new encryption key in her encryption key storage volume 15, alongside her own quantum key Kb. Thus, simultaneously, Mike provided his quantum key Kn to Alice.
[0080] Thus, the method 100 carries out the transmission of the global chain K calculated by the XOR node 40 not only to the destination node, Mike, but also and simultaneously to the transmitter node, Alice.
[0081] Performing the transmission of the global chain to both users simultaneously saves resources by allowing not only Alice to transmit a secret to Mike, but simultaneously Mike to transmit a secret to Alice. In particular, the two users simultaneously exchange two encryption keys Ki and Kn without consuming more transport quantum keys.
[0082] Instead of iterating the key exchange method according to the state of the art by swapping sender and recipient, the method according to the invention allows the sender to obtain, at a marginal cost, an additional encryption key allowing it to encrypt future exchanges with the recipient.
[0083] The method according to the invention therefore makes it possible to double the performance of the QKD network.
[0084] In a first variant of this first embodiment, a first encryption key Kj^ is shared between Alice and the XOR node 40 and / or a second encryption key Krm is shared between Mike and the XOR node 40.
[0085] The manner of sharing the encryption keys Kj^ and KRM between a user node and the XOR node, as well as the manner in which they subsequently update it (by combining it with QKD keys for example) is outside the scope of the present patent application. It is carried out according to techniques known to those skilled in the art or by the method 100 described previously, the XOR node then imperatively being a node of the QKD network and then playing the role of sender / recipient of the secret to be shared.
[0086] Thus, in step 130, it is no longer the global string K which is transmitted between the XOR node 40 and Mike, but the global string K encrypted by the calculation unit 40 of the XOR node with the second encryption key KRM.
[0087] In step 140, Mike's computing unit 22 begins by decrypting the received information using the second encryption key Krm before applying its quantum key Kn in order to recover Alice's quantum key Ki. Thus, additional encryption is implemented on the link 41M
[0088] Similarly, in step 150, it is no longer the global string K which is transmitted from the XOR node 40 to Alice, but the global string K encrypted by the calculation unit 40 of the XOR node with the first encryption key Kra.
[0089] In step 160, Alice's computing unit 12 begins by decrypting the received information using its first encryption key Kra, before applying its quantum key Ki in order to find Mike's quantum key Kn.
[0090] In a second variant of the method, or method 100' in [Fig.2], Alice seeks to transmit to Mike another encryption key than the first quantum key Kl, which is shared with the first relay node of the path of the QKD network 2 which leads to Mike. For example, she wants to transmit a first so-called classical key, KO, whether she has acquired it by an external means (specific application or key injector) or whether it has been generated by a true random number generator ("True Random Number Generator"), preferably quantum. To transmit it, Alice simply has to sum (step 105') the first classical key KO with the first quantum key Kl and send the first additional elementary chain KeO thus obtained to the XOR node 40, as the relay nodes do. The XOR node then calculates a global chain integrating this first additional elementary chain:
[0091] K= (KO © Kl) © (Kl ©K2) © ... © (Ki-1 ©Ki) © (Ki © Ki+1) © (Ki+1 © Ki+2) © ... © (Kn-1 © Kn)
[0092] Which reduces to:
[0093] K= Ko© Kn
[0094] Mike is then able to find the first classical key Ko as the first encryption key by summing (step 140) his quantum key Kn to the global string K that he receives from the XOR node.
[0095] In this variant, the string that Alice seeks to transmit to Mike is not known to the first relay node 30i (unlike the quantum key Ki that Alice shares with this access node 30i).
[0096] This variant therefore makes it possible to improve the security of the proposed solution, since it would be necessary not only to corrupt the access node 30i to know Kh but also to intercept the sending from Alice to the XOR node 40, containing the information Ko© Ki, to find Ko.
[0097] Symmetrically, to improve security against corruption of the access node 30n on the recipient side, which would give access to the second quantum key Kn, Mike may also prefer to transfer to Alice a second classical key, Kn +i. He sums it (step 115') with the second quantum key Kn and transmits a second additional elementary string Ken thus obtained to the XOR node 40 so that the latter takes it into account in the calculation of the global string K.
[0098] When Alice receives the global string K, she is then able to find the second classical key Kn+[ as a second encryption key by summing (step 160) its quantum key Ki to the global chain K received from the XOR node.
[0099] The combination of these last two variants is conceivable. It corresponds to the use of a first classical key Ko not only on Alice's side but also of a second classical key Kn+1 on Mike's side is conceivable. Alice must then use (step 160') her classical key Ko to extract Mike's classical key Kn+1 from the global key K and memorize the latter (step 165'), and Mike, on his side, must use (step 140') his classical key Kn+1 to extract Alice's classical key Ko from the global key K and memorize the latter (step 145').
[0100] It should be noted that, in these variants, the encryption of the exchanges with the first encryption key and / or the second encryption key also makes it possible to encrypt the additional elementary chains sent by Alice and / or Mike to the XOR node. This prevents the interception of the outgoing flow of a user (corresponding to Ko® Kipour Alice), as well as the corruption of the node allowing this user to access the QKD network (giving access to Ko) from making it possible to discover the user's classic key (here Ko).
[0101] This first embodiment also presents a security gain due to the partitioning of the information, the XOR node being advantageously a separate entity (advantageously provided by a different operator) from the entities associated with the QKD network (such as the key management system - KMS or the QKD network controller).
[0102] Second embodiment: additional privacy-enhancing security service
[0103] A second embodiment of the invention will be presented with reference to Figures 3 and 4.
[0104] [Fig.3] is a schematic representation of a second embodiment of the communication infrastructure.
[0105] An element of the second embodiment identical to an element of the first embodiment is identified in [Fig.3] by a reference numeral equal to that used in [Fig.l] to designate this identical element.
[0106] An element of the second embodiment similar to an element of the first embodiment is identified in [Fig.3] by a reference numeral corresponding to that used in [Fig.l] to designate this element, increased by two hundreds.
[0107] The infrastructure 201 is based on a QKD network 2 including all of the components of the QKD network 2 of the infrastructure 1, with the possible exception of the XOR node 40 which may not be present for the implementation of this second embodiment.
[0108] The infrastructure 201 implements a security service 202.
[0109] The security service 202 comprises, on each user node seeking to share an encryption key, an additional security service module. Thus Alice implements a security service module 216 and Mike implements a security service module 226.
[0110] A security service module, 216, respectively 226, comprises a computing unit, 218, 228, and a communication unit 219, 229 for communication with a security service server.
[0111] In addition, the security service 202 comprises a security service server 260, on which the service 202 relies. In the embodiment shown in [Fig. 3], the server 260 is a physical entity separate from the user nodes. But, alternatively, this security service server can be a feature of both user nodes, leading to direct exchanges between Alice and Mike.
[0112] The server 260 comprises a computing unit 262 and a communication unit 264a dedicated to communication with Alice and a communication unit 264M dedicated to communication with Mike.
[0113] The security service module of a user node communicates with the server 260 via a conventional and advantageously authenticated communication link, 62A for Alice and 62M for Mike. This is for example a conventional link, for example again an IP link on a conventional network of the WAN type. This link is only functional in the variant where the security service server is provided by one of the user nodes.
[0114] Advantageously, the server 260 is hidden (“phantom service”), for example by using a set of reserved IP addresses, different from those of the nodes associated with the QKD network 2, and unknown to the QKD network.
[0115] Advantageously, this set of reserved IP addresses is specific to an operator of the security service 202. This operator controls the subscription of users to the security service and the access rights of these subscribed users.
[0116] Furthermore, Alice has a conventional encryption key, called the first security key, KA, preferably locally generated, which she wishes to share with Mike. And advantageously, Mike has an encryption key, called the second security key, KM, preferably locally generated, which he wishes to share with Alice at the same time as he receives Alice's first security key KA.
[0117] The method of exchanging the encryption keys, KA and KM, implemented in this second infrastructure 201 will now be presented with reference to [Fig.4].
[0118] The method 300 begins once a first exchange of encryption keys has been carried out between Alice and Mike such that Alice and Mike share first and second encryption keys.
[0119] In the following, the first encryption key is a first quantum key Kb but could alternatively be a first classical key Ko.
[0120] In the following the second encryption key is a second quantum key Kn, but could alternatively be a second classical key Kn+i.
[0121] This means, for example, that method 100 of [Fig. 2] was implemented prior to method 300 (the infrastructure then necessarily includes an XOR node 40). Alternatively, it is a method in accordance with the state of the art which was implemented once from Alice to Mike to share the first encryption key, then another time from Mike to Alice to share the second encryption key.
[0122] In a step 310, the security service module 216 of the transmitter node 210, Alice, calculates a first intermediate chain KiA by summing the second encryption key Kn and the first security key KA.
[0123] The first intermediate chain KiA thus calculated is transmitted, during step 320, to the security server 260.
[0124] Preferably, symmetrically and simultaneously, in step 330, the security service module 226 of the destination node 220, Mike, calculates a second intermediate chain KiMen summing the first encryption key Ki with the second security key KM.
[0125] In step 340, this second KiM string is transmitted to the security server 260.
[0126] In step 350, the security server 260 calculates a composite chain K' resulting from the sum of the first and second intermediate chains KiA and KiM received from Alice on the one hand and from Mike on the other hand.
[0127] The composite chain K' can be written:
[0128] K'= KiA © KiM = (Kn©KA) © (K1®Km) = K©Ka©Km
[0129] It therefore corresponds to the sum of the encryption keys to be exchanged with the global chain K, as defined in the first embodiment.
[0130] In step 360, the composite string K' is transmitted by the server 260 to the module 226 of the destination node 220.
[0131] In step 370, the module 226 of the destination node 220 adds the received composite string K', the second intermediate string KiM and the second encryption key Kn. The result of this operation is equal to the first security key KA. Thus Alice has successfully transmitted the key KA to Mike. This is stored (step 375) by Mike as a new encryption key in Volume 25 of Backup Encryption Keys.
[0132] Symmetrically, in step 380, the composite key K' is transmitted by the server 260 to the module 216 of the transmitter node 210.
[0133] In step 390, the module 216 of the transmitter node 210 adds the received composite string K', the first intermediate string KiA and the first encryption key Ki. The result of this operation is equal to the second security key KM. Thus Mike has successfully transmitted the key KM to Alice. This is stored (step 395) by Alice as a new encryption key in the encryption key backup volume 15.
[0134] The method 300, by splitting the operations between the XOR node 40 (exchange of the global chain K for sharing the first pair of encryption keys Ki and Kn) and the security service server 260 (exchange of the composite chain K' for sharing the second pair of encryption keys KA and KM), allows the exchanges linked to the sharing of the second pair of encryption keys not to be easily identifiable as relating to the known users of the underlying QKD network 2, in particular of the XOR node 40 when there is one.
[0135] In a first variant of this second embodiment, a first security encryption key Ks A is shared between Alice and the server 260 and a second security encryption key Ks M is shared between Mike and the server 260. These two keys may be identical, in particular during the installation of the service before being differentiated from one another by independent updates.
[0136] How these first and second encryption keys, Ks A and Ks M, are exchanged, as well as how they subsequently update it (for example, by combining it with quantum keys) is outside the scope of the present patent application. It involves the implementation of known techniques, such as, for example, manual key distribution (“trusted courier”).
[0137] The first encryption key Ks A makes it possible to secure the exchanges between Alice and the service server 260. The second encryption key Ks M makes it possible to secure the exchanges between Mike and the security service server 260.
[0138] Thus, for step 320, the first intermediate string KiA is encrypted by the transmitter with the key KsA, then transmitted encrypted to the server 260, which decrypts it also using the key KSA.
[0139] Similarly, for step 340, the second intermediate string KiM is encrypted by the recipient with the key Ks M, then transmitted encrypted to the server 260, which decrypts it also using the key Ks M.
[0140] The security server 260 therefore calculates the composite string K' after having decrypted the messages sent by Alice and Mike.
[0141] Advantageously, for step 380, the server 260 encrypts the composite key K' using the key Ks A .then the composite key is transmitted encrypted to Alice, who decrypts it also using the key KSA- Similarly, for step 360, the server 260 encrypts the composite key K' using the key Ks M>then the composite key is transmitted encrypted to Mike, who decrypts it also using the key Ks M-
[0142] The other steps of the process remain unchanged.
[0143] This second embodiment presents enhanced security based on the generation outside the QKD network of the encryption keys KA and KM. For an attacker to obtain this information, he must at least attack an access node of the QKD network (to obtain Ki and Kn), the service server, of which he does not know the addresses a priori, (to identify the IP addresses of Alice and Mike in particular and known only to the security service) and decrypt the exchanges between Alice and Mike, on the one hand, and the service server, on the other hand.
[0144] Third embodiment: additional service for creating keys with guaranteed integrity.
[0145] A third embodiment of the invention will be presented with reference to Figures 5 and 6.
[0146] At the end of the implementation of a method in accordance with the embodiments presented above, Alice and Mike can (and must) carry out an integrity check on an encryption key that they have exchanged. This may involve, for example, the transmission of a hash value of the exchanged encryption key in order to verify that they both have the same key. When this integrity check fails, the received encryption key being tainted with an error compared to the initial encryption key, this key cannot be used for the encryption of exchanges between these two users. The encryption key exchange method has therefore failed.
[0147] Guarding against possible problems with the integrity of the exchanged keys is essential to avoid very simple attacks by malicious QKD network nodes that would lead to a denial of service without it being possible to determine the disruptive element. This would be the case, for example, of a path on the QKD network including nodes belonging to uncontrolled domains, inducing errors, either voluntarily or involuntarily, in their contribution to the calculations.
[0148] In a particularly advantageous manner, this third embodiment allows an exchange of keys, the integrity of which is guaranteed. Indeed, this method makes it possible to carry out compensation for any errors introduced during the exchange.
[0149] This compensation is made possible by sharing the security encryption keys KA and KM by means of the security service which is considered to be provided sincerely and honestly and carried out without using the QKD network.
[0150] The infrastructure 501 of [Fig.5] for implementing this third embodiment is similar to the infrastructure 201 of [Fig.3]. It is possibly differentiated by additional software codes and information stored by the transmitter 210 and recipient 220 nodes.
[0151] When implementing the method 100 according to the embodiment, the XOR node 40 transmits to Alice and Mike a bit string, denoted Keir, which should correspond to the global string K, but which is potentially the global string K tainted with an error, err. This may be a relay node, faulty or malicious, injecting an error. It may also be the XOR node, faulty or malicious, injecting an error during the calculation of the sum of the elementary keys, or injecting different errors between the transmission to Alice and the transmission to Mike.
[0152] In this case, it is necessary to estimate the impact of these errors on the keys held by Alice and Mike. Indeed, users actually only have access to estimates of the initial keys or strings. An estimated key or string is noted by adding a "hat" to the notation of the corresponding initial key or string (i.e., the true key or string without errors). For example, if KA is the value of the security encryption key generated by Alice, Alice knows KA but Mike estimates a possibly different value, k .
[0153] For example, when implementing the method 100, the XOR node 40 transmits to Alice the information:
[0154] K^K^Kn^ô
[0155] where ô is a first error.
[0156] Alice then estimates a second encryption chain:
[0157] = kô $ Ki = Kn 0 g
[0158] Alice therefore makes an error equal to ô on the value of the second encryption key Kn.
[0159] At the same time, the XOR node 40 transmits the information to Mike:
[0160]
[0161] where 9 is a second error.
[0162] Mike then estimates a first encryption chain: [°163] 0 Kn = K, ® t]
[0164] So Mike makes an error equal to 0 on the value of the first encryption key Kb
[0165] According to method 500, in a step 510, Alice calculates a first string intermediate KiA:
[0166] ïz _ iz Æ) iz t8-L\ — rvn m7 A. — Ikn vI7 O mz A.
[0167] There is a summation of potentially erroneous information coming from the recipient, with true information held by the sender.
[0168] In a step 520, the security service module 216 of Alice transmits (in encrypted form if this variant is implemented) to the security service server 260 the first intermediate string KiA.
[0169] For his part, in step 530 Mike calculates a second intermediate chain KiM:
[0170] iz -K n K K1m - K| Km - KJ kP 1] 'd? Km
[0171] There is a summation of potentially erroneous information coming from the sender, with true information held by the recipient.
[0172] In a step 540, the security service module 226 of Mike transmits (in encrypted form if this variant is implemented) to the security service server 260 the second intermediate KiM chain.
[0173] At the same time, in a step 550, Alice retransmits to Mike, preferably directly to reinforce security, the first global string that she herself had received from the XOR node 40 in step 150 of the method 100 (or that she calculates in the variant where the method 100 has not been implemented and the exchange of the first pair of encryption keys Ki and Kn has been carried out in another way). This first global string is the sum of the encryption keys potentially affected by the first error:
[0174] K6=Kiekn=
[0175] Symmetrically, but optionally, in a step 560, Mike informs Alice by transmitting to her the second global string that he himself had received from the XOR node 40 in step 130 of the method 100. This second global string is the sum of the encryption keys potentially affected by the second error:
[0176] = K^Kn^q
[0177] In step 570, the security server 260 calculates a composite chain K' by summing the first and second intermediate chains: K'= KiA © KiM
[0178] Either:
[0179] K =(K„®S ®KA)®(K,®n®KM)
[0180] The server 260 is trusted and does not introduce any error (i.e. the link between Alice and Mike through the security server 260 is intact and authenticated).
[0181] In step 580, the composite string K' is transmitted to Mike and in step 590 the composite string K' is transmitted to Alice.
[0182]
[0183]
[0184]
[0185]
[0186]
[0187]
[0188]
[0189]
[0190]
[0191]
[0192]
[0193]
[0194]
[0195]
[0196]
[0197]
[0198]
[0199]
[0200]
[0201]
[0202]
[0203] At step 700, Mike calculates the sum of the composite string K', the second intermediate string KiM and the second encryption key Kn: K ® KiM © Kn = (KiA © KiM) © KiM © Kn = KiA © Kn = KA © ô So Mike estimated the security encryption key KA but tainted by the first error ô. He thus obtains an estimate of the first security encryption key: At step 710, Mike calculates an exact encryption string KAi by summing the estimate of the first security encryption key A 5 , the second key of ka Kn encryption and the first global string Kô received from Alice at step 550: The 6 errors balance out and Mike gets: KAi = KA© K! For her part, at step 720, Alice adds the first security encryption key Ka and the first encryption key K b of which she holds by definition the correct values, to obtain KAb KA1 = KA© K! So Alice gets the same result as Mike. KAi is therefore a first security encryption chain shared between Alice and Mike. At step 600, from the composite key K' received from the server 260, Alice calculates Km^K©^©!^ (KiA©KiM) ©^©K^ K|®KM©Kj = KM©q So Alice estimated the security encryption key KM but tainted with the second error 0. In step 610, Alice sums the estimate of the second security encryption key A11 and the estimate of the second encryption key to obtain KMn. Kn At the same time, in step 620, Mike calculates the sum of the second intermediate string KiM and the first global string Kô received from Alice in step 550: KiM© Kô Which reduces to: KM® q® K © ô That is, KMn. So Mike gets the same result as Alice.
[0204] KMn is therefore a second shared security encryption chain with no differences between Alice and Mike.
[0205] The corrected cipher strings KAi and KMn are recorded as cipher strings usable between Alice and Mike. These are integrity-enhanced strings.
[0206] In what has just been presented, it is Mike who applies a correction (Kô) to obtain the two shared security encryption chains. Alternatively, it is Alice who applies the corrections. In this case, step 560 is mandatory while step 550 becomes optional. In yet another variant, Alice and Mike share the correction tasks. Steps 550 and 560 are mandatory.
[0207] In another variant of this third embodiment, there is no separate security service server 260, and the operations that are performed by this entity are performed by the security service modules, 226, 216, of Mike or Alice.
[0208] Obviously, communications between Alice (respectively Mike) with the security service server can be encrypted with KSA and Ksm- encryption keys.
[0209] This third embodiment has the advantage of leading to keys with enhanced security, KA[ and KMn having an integrity guarantee. This solution is resistant to attacks by nodes of the QKD network or the XOR node.
[0210] Thus, a person skilled in the art will note that an error introduced at the XOR node can be systematically eliminated by using the security service and by combining several pieces of information tainted with errors that can compensate for each other.
Claims
1. Claims Method (300) for exchanging encryption keys in a communication infrastructure (201), the communication infrastructure comprising a network implementing a quantum key distribution mechanism, or QKD network (2), the QKD network (2) comprising a sender node (10), a recipient node (20) and a plurality of relay nodes (30;) defining a path on the QKD network (2) between the transmitter node (210) and the destination node (220), two successive nodes along the path being adapted to generate and share a quantum key through a quantum channel connecting said two nodes, characterized in that, the communication infrastructure further comprising a security service (202) comprising a security service module (216) on the transmitter node (210), associated with a first security key (KA), a security service module (226) on the destination node (220), associated with a second security key (Km), and a security service server (260) in communication respectively with the security service modules of the transmitter and destination nodes by means of conventional communication links, the method comprises the steps of:; - exchange (100) of a first encryption key (KJ) from the sending node to the receiving node and of a second encryption key (Kn) from the receiving node to the sending node; - calculation (310), by the transmitter node (210), of a first intermediate chain (KiA) by summing the first security key (KA) and the second encryption key (Kn); - transmission (320) of the first intermediate chain (KiA) to the security service server (260); - calculation (330), by the destination node (210), of a second intermediate chain (KiM) by summing the second security key (KM) and the first encryption key (Ki); - transmission (340) of the second intermediate chain (KiM) to the security service server (260); - calculation (350), by the security service server (260), of a composite chain (K') resulting from the sum of the first and second intermediate chains received from the sending and receiving nodes; - transmission (360), by the security service server (260), of the composite chain (K') to the security service module (226) of the receiving node; - summation (370), by the receiving node (220), of the composite chain (K'), the second intermediate chain (KiM) and the second encryption key (Kn), to extract the first security key (KA), and storage (375) of the first security key (KA) as an encryption key in the encryption key volume of the receiving node.
2. Method according to claim 1, further comprising: - transmission (380), by the security service server (260), of the composite string (K') to the security service module (216) of the sending node (210); and, - summation (390), by the sending node (210), of the composite string (K'), of the first intermediate key (KiA) and of the first encryption key (Ki), to extract the second security key (KM), and storage (395) of the second security key (KM) as an encryption key in the encryption key volume of the sending node.
3. Method according to claim 1 or claim 2, wherein, a first encryption key (Ks A) being shared between the sending node (210) and the security server (260), the first intermediate string (KiA) is transmitted encrypted along the conventional link between the security service module of the sending node and the security service server using the first encryption key (KSA) and the composite string (K') is transmitted encrypted along the conventional link between the security service server and the security service module of the sending node using the first encryption key (KSA).
4. Method according to any one of claims 1 to 3, in which, a second encryption key (KSM) being shared between the destination node (220) and the security server (260), the second intermediate chain (KiM) is transmitted encrypted along the conventional communication link between the security service module of the recipient node and the security service server using the second encryption key (KSM) and the composite key (K') is transmitted encrypted along the conventional communication link between the security service server and the security service module of the recipient node using the second encryption key (KSM)-
5. Method according to any one of the preceding claims, in which, the infrastructure (201) further comprising a centralized computing entity, or "XOR node" (40), the XOR node being connected to each of the nodes of the QKD network (2) by a conventional communication link, the method comprises the prior steps of: - calculation (110), by each relay node (30i), of an elementary chain (Kei) by summing the two quantum keys of the two quantum channels from said relay node, and transmission of the elementary chain to the XOR node (40); - calculation (120), by the XOR node (40), of a global chain (K) by summing the elementary chains (Kei) received from each of the relay nodes present along the path between the sending node (210) and the receiving node (220); - transmission (130), by the XOR node (40), of the global chain (K) to the destination node (220);- extraction (140), by the destination node (220), of the first encryption key (Kl) from the sending node by summing the global chain (K) and the second encryption key (Kn) of the destination node, and storage of the first encryption key in a volume (25) for storing encryption keys of the destination node; - transmission (150), by the XOR node (40), of the global key (K) to the sending node (210); and, - extraction (160), by the sending node (210), of the second encryption key (Kn) from the receiving node (20) by summing the global chain (K) and the first encryption key (Kl) of the sending node, and storage of the second encryption key in a volume (15) for storing encryption keys of the sending node.;
6. Communication infrastructure (201) adapted for implementing a method of exchanging encryption keys according to one of any of claims 1 to 5, comprising a network implementing a quantum key distribution mechanism, or QKD network (2), the QKD network (2) comprising a transmitter node (210), a destination node (220) and a plurality of relay nodes (30;) defining a path on the QKD network (2) between the transmitter node (210) and the destination node (220), two successive nodes along the path being adapted to generate and share a quantum key through a quantum channel connecting said two nodes, the infrastructure further comprising a security service comprising a security module (216) on the transmitter node (210), associated with a first security key (KA), and a security module (226) on the destination node (220), associated with a second security key (KM), as well as a security service server (260) in communication respectively with the security service modules of the transmitter and destination nodes by means of conventional links.
7. Infrastructure (201) according to claim 6, wherein the security service server (260) is an additional functionality of the sending node and / or the receiving node.
8. Infrastructure (201) according to claim 6 or claim 7, for implementing the method according to claim 5, the infrastructure further comprising a computing entity, or XOR node (40), the XOR node being connected to each of the nodes of the QKD network (2) by a conventional communication link.
9. Infrastructure (201) according to claim 8, wherein the XOR node (260) is an additional functionality of the sending node and / or the receiving node.
10. Infrastructure according to any one of claims 6 to 9, wherein, the communication links being IP links on a conventional communication network, the security service server (260), the security service module (216) of the sending node (210) and the security service module (226) of the receiving node (220) use reserved IP addresses which are different from the IP addresses of the sending and receiving nodes, only the latter being known by the QKD network (2).
Citation Information
Patent Citations
Low-latency quantum key mobile service method
CN109995513A
Method and system for performing a secure key relay of an encryption key
US20230018829A1