System and method for generating secure private keys - Patents.com

JP2024535356A5Pending Publication Date: 2025-09-02THALES SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024518380
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-09-23
Filing Date
2022-09-15
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

Existing quantum key distribution (QKD) techniques face limitations in extending secure key exchange over long distances and large user networks, particularly due to the 100 km optical fiber limit and challenges in implementing trusted nodes or satellite-based solutions, which are costly and inefficient for widespread user adoption.

Method used

A method utilizing a one-time pad (OTP) technique to generate multiple secure private keys from a single first private key established by QKD, combined with true random number generators, enabling secure key distribution over long distances and large networks without the need for frequent satellite interactions.

Benefits of technology

This approach enhances the availability and security of quantum key distribution systems for a large number of ground users by reducing the reliance on satellite-based key distribution, overcoming distance limitations and weather sensitivity, while maintaining resistance to quantum threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method for generating a secure private key, comprising: A. receiving, at a communication station (SA) called a transmitting station, a first private key (KEK) by a quantum encryption channel (CQAB) via a satellite (Sat), the first private key also being transmitted to at least one other communication station (SB) by the quantum encryption channel; B. generating, at the transmitting station, a second private key (KS) using a true random number generator (TRNG); C. generating an encryption private key (KC) using the first private key (KEK) and the second private key (KS) by a one-time pad method; and D. transmitting the encryption private key (KC) from the transmitting station (SA) to one or more other communication stations (SB).
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to the field of information technology security, and more particularly to the field of satellite-based key distribution over quantum channels. [Background technology]

[0002] There has always been a need to exchange sensitive information over public communication channels that must be kept secret. Suppose two people, Alice and Bob, want to exchange sensitive information protected from prying eyes over an authenticated public communication channel (say the Internet). To do that, Alice and Bob must encrypt their messages. Let's call anyone who tries to intercept these messages Eve. Alice must encrypt her message using a publicly available cryptographic function (i.e., not secret) and her private key, then send it to Bob over the public channel. When Bob receives the encrypted message, he must decrypt it using the same cryptographic function and private key as Alice in order to be able to access the information in plaintext.

[0003] At issue here is the secret key shared between Alice and Bob: how that key is generated, how it is exchanged securely, and how it is protected from prying eyes.

[0004] During secure exchanges over the Internet, a shared secret key is established using techniques based on public key cryptography that will not be described in detail here. At the end of the 20th century, a new solution was devised, which proposes the use of a quantum channel that allows Alice and Bob to establish a common secret key by exchanging quantum particles (e.g. photons) without Eve being able to reveal the key. Nevertheless, this QKD technique (QKD stands for Quantum Key Distribution) has several limitations that make it difficult to apply to a large number of users and over very long distances. Such limitations may eventually make the technique unattractive and therefore not profitable enough to create an industrial opportunity.

[0005] Figure 1 shows a schematic architecture of a quantum channel that allows two users, Alice (sender of the code) and Bob (receiver of the code), to establish a common secret key. The key is a random bit sequence and can therefore take on the value 0 or 1. To transmit this key, Alice encodes each bit of the key in one of two polarization modes of photons prepared by Alice, the choice of polarization mode being random. Alice records the randomly chosen polarization mode for each bit (and therefore for each photon). Bob uses a polarizing filter and a photon detector that can be alternately oriented between the two randomly chosen polarization modes and records the detection result (whether the photon passed through the filter or whether the photon did not pass through the filter) and the chosen orientation of the filter.

[0006] Once the entire sequence of qubits has been transmitted, Alice sends the polarization mode used for each qubit over an authenticated clear channel to Bob. Bob can infer the values ​​of the bits for which the polarization direction was the same. Bob knows with certainty the average N of the 2N bits that Alice sent, and this sequence is called the corrected key.

[0007] Finally, Alice and Bob agree on a subset of the corrected key. They then compare whether they have the same bits in this subset, and if so, use the remaining key to derive the encryption key. If there is a mismatch, the process starts again. Specifically, if Eve eavesdrops, the quantum no-cloning theorem guarantees that she will force the photons into a polarization mode (not necessarily Alice's). Thus, if Eve has a 50% chance of correctly guessing Alice's mode, then 25% of the bits in the correction key will not match. In general, by sacrificing n bits of the correction key, Alice and Bob can

number

[0008] Terrestrial networks can use optical communication channels set up by optical fibers, so key exchange (or more precisely, key establishment) over quantum channels can be easily realized. Nevertheless, Alice and Bob cannot exchange single-polarized photons (or very low-intensity light pulses) over optical fibers if they are more than 100 km apart, which is the asymptote for the probability that the optical fiber material absorbs 100% of the photons.

[0009] Therefore, the architecture of quantum channel networks is heavily influenced by this physical constraint. Two solutions have been devised to overcome this 100 km limit.

[0010] The first solution devised is to propagate the keys via so-called "trusted nodes" placed at regular intervals (e.g. every 100 km). Figure 2A shows a schematic of a prior art device that allows a trusted node to generate keys. The trusted node operates in plaintext on a key established with Alice (key A) and a key established with Bob (key B). This trusted node is placed equidistant between Alice and Bob, allowing the quantum channel key establishment range to be extended to 200 km. The trusted node then transmits key A to Bob using the one-time pad technique. To do this, the trusted node applies an XOR (exclusive-or logic gate) to Alice's key and Bob's key. Here and in the rest of this specification, "XOR" is defined by the symbol

number

[0011] This first solution relies on the following properties of the XOR function:

number

number

[0012] Nevertheless, this first solution requires that trusted nodes operating on keys in the clear be protected at a very high level of security, which implies non-negligible operational constraints and additional costs. Moreover, this kind of solution is difficult, if not impossible, to implement to interconnect two users separated by an ocean (implementing a trusted node every 100 km underwater is difficult and costly).

[0013] The second solution is the free-field exchange of photons, and thus the exchange of photons from space. In this case, the 100 km optical fiber limit no longer applies, and cryptographic keys can be distributed from space over a QKD channel to two users anywhere on Earth. This configuration is shown in Figure 2B. In this case, the satellite establishes key A with Alice and key B with Bob, and transmits key A over a conventional authenticated plaintext communication channel.

number

number

number

[0014] Nevertheless, space-based quantum key distribution techniques have some major drawbacks, namely: - the unavailability of optical channels in case of bad weather (clouds or even the presence of air pollution: aerosols); - the bit rate of the resulting keys is low, at most a few kilobits per second (satellites in low earth orbit with preparation and measurement protocols), - The need to store established keys for a significant period (months) before users actually need them, and the keys are stored in the terrestrial access points used to interface with the satellites It is.

[0015] These drawbacks make it impossible to envisage this type of infrastructure being adopted by a very large number of users on the ground (less than 1000). At the moment, QKD from space is only envisaged for securing interactions between national authorities and systems of great concern, such as energy infrastructure.

[0016] The present invention aims to overcome certain problems of the prior art. To this end, one subject of the invention is a system and method for generating secure private keys using a one-time pad (OTP) technique, so that a larger number of secure private keys can be generated and distributed to terrestrial users. In the present invention, the secure private keys are generated from a first private key that is initially established by QKD by a satellite orbiting the Earth. Thus, a single first private key obtained by QKD is needed to generate multiple secure private keys. As both techniques, QKD and OTP, are resistant to quantum threats, the method of the present invention makes it possible to increase the availability of a global QKD system to a large number of interconnected terrestrial users while guaranteeing security against quantum computer threats. Summary of the Invention [Means for solving the problem]

[0017] To this end, one subject of the present invention is A. receiving, at a communication station, called a transmitting station, a first secret key over a quantum encrypted channel set up with a satellite, said first secret key also being transmitted by said quantum encrypted channel to at least one other communication station; B. generating a second secret key at said transmitting station using a true random number generator; C. generating an encrypted private key from the first private key and the second private key by a one-time pad method; D. transmitting said encrypted private key from the transmitting station to one or more other communication stations; A method for generating a secure private key, comprising:

[0018] According to a preferred embodiment, following step D, the method of the invention comprises a step E of decrypting, in one or more other communication stations, said encrypted private key using the first private key to obtain said second private key forming said secure private key.

[0019] Preferably, in this preferred embodiment, the first private key, the second private key and the encrypted private key are binary coded, the encrypted private key is generated by an XOR logic gate combining the first private key and the second private key, and the encrypted private key is decrypted by an XOR logic gate combining the encrypted private key and the first private key.

[0020] Preferably, in this preferred embodiment, steps B through E are repeated multiple times to form multiple secure private keys, all generated from the first private key.

[0021] Preferably, in this preferred embodiment, the method of the invention comprises a subsequent step F of encrypting a non-random message using said secure private key and then transmitting the encrypted non-random message from one communication station to another, and a subsequent step G of decrypting said encrypted non-random message using said secure private key.

[0022] According to a preferred embodiment, step A is repeated twice before step B in the first communication station in order to receive a first secret key A and a first secret key B different from the first secret key A, the first key and the second key being also transmitted to the second communication station via said quantum channel, steps B to D are executed by the first communication station in order to generate a first encrypted secret key from the first secret key A and from the second secure secret key A generated by the first communication station and to transmit it to said second communication station, said method comprising additional steps D'E, F', G' and H executed by said first communication station, said step D'E comprising: receiving a second encrypted private key generated by the second communication station from the first private key B and from a second secure private key B generated by the second communication station; and decrypting said second encrypted private key with said first private key B to obtain said second secure private key B; and said step F' consists in generating a secret key, called a common secret key, from the second secure secret key A and from the second secure secret key B by the one-time pad technique; The aforementioned step G' is - delivering a secret key, called a first local secret key, to a first local communication station by a first local quantum channel; generating a first encrypted local private key from the first local private key and from the common private key by a one-time pad method; and - transmitting said first encrypted local private key to said first local communication station. and said step H comprises, in said first local communication station, decrypting said first encrypted local private key using the first local private key to obtain said common private key.

[0023] Preferably, in this preferred embodiment, step D'E comprises, in the second communication station, decrypting said first encrypted private key using the first private key A to obtain said second secure private key A, and step F' comprises, in the second communication station, generating said common private key from the second secure private key A and from the second secure private key B by a one-time pad technique, and said method comprises the steps of: - delivering the second local private key over a second local quantum channel to a second local communication station; generating a second encrypted local private key from the second local private key and from the common private key by a one-time pad method; and transmitting said second encrypted local private key to said second local communication station. and said step H includes, in a second local communication station, decrypting said second encrypted local private key using the second local private key to obtain said common private key.

[0024] Preferably, the method comprises a step I, after step H and performed by the first local communication station, of encrypting a non-random message using said common secret key and then transmitting the encrypted non-random message to the second local communication station, said method comprising a step J, after step I and performed by the second local communication station, of decrypting said encrypted non-random message using said common secret key.

[0025] Preferably, the first private key and the second private key are the same size.

[0026] Preferably, the non-random message is encrypted by a symmetric encryption method, such as a block cipher or a stream cipher.

[0027] Another subject of the invention is a communication station, called a first communication station, for generating a secure secret key, said first communication station being configured to receive a first secret key over a quantum encryption channel set up with a satellite, said first secret key also being transmitted via said quantum encryption channel to at least one other communication station, said first communication station being: generating a second secret key using a true random number generator; generating an encryption private key from the first private key and the second private key by a one-time pad method; - transmitting said encryption private key to said other communication stations; The cryptographic module is configured to:

[0028] Another subject of the invention is a system including a first communication station and including said other communication stations and said satellite, said other communication stations being configured to decrypt said encrypted private key using the first private key to obtain said second private key forming said secure private key.

[0029] Another subject of the invention is an assembly for generating a secure private key, said assembly comprising said first communication station and comprising a first local communication station, said first communication station comprising: receiving a first private key A and a first private key B different from the first private key A via said quantum encrypted channel, the first key and the second key being also transmitted to a second communication station via said quantum channel; - generating a first encrypted private key from the first private key A and from a second secure private key A generated by the first communication station and transmitting it to said second communication station, receiving a second encrypted private key generated by the second communication station from the first private key B and from a second secure private key B generated by the second communication station; and - decrypting said second encrypted private key with the first private key B to obtain said second secure private key B; - generating a secret key, called a common secret key, from the second secure secret key A and from the second secure secret key B by the one-time pad technique, - delivering a secret key, called a first local secret key, to said first local communication station by a first local quantum channel; generating a first encrypted local private key from the first local private key and from the common private key by a one-time pad method; and - transmitting said first encrypted local private key to said first local communication station. and said first local communication station is configured to decrypt said first encrypted local private key using the first local private key to obtain said common secret key.

[0030] Another subject of the invention is a system including an assembly, a satellite, a second local communication station, and a second communication station including an encryption module, the second communication station comprising: - in a second communication station, decrypting said first encrypted private key with the first private key A to obtain said second secure private key A; - generating a secret key, called a common secret key, from the second secure secret key A and from the second secure secret key B by the one-time pad technique, generating, in a second communication station, said common secret key from a second secure secret key A and from a second secure secret key B by the one-time pad technique, - delivering the second local private key over a second local quantum channel to a second local communication station; generating a second encrypted local private key from the second local private key and from the common private key by a one-time pad method; and transmitting said second encrypted local private key to said second local communication station. and the second local communication station is configured to decrypt said second encrypted local private key using the second local private key to obtain said common private key.

[0031] Preferably, in this system the communication stations are ground based and are greater than 100 km apart.

[0032] Other characteristics, details and advantages of the invention will become apparent on reading the description given with reference to the attached drawings, given as examples and showing respectively the following:

[0033] Other characteristics, details and advantages of the invention will become apparent on reading the description given with reference to the attached drawings, given as examples and showing respectively the following: [Brief description of the drawings]

[0034] [Figure 1] FIG. 1 is a schematic diagram of a prior art QKD device. [Figure 2A] FIG. 1 is a schematic diagram of a prior art satellite-based device for generating keys by QKD. [Figure 2B] FIG. 1 is a schematic diagram of a prior art device that enables a trusted node to generate a key. [Figure 3A] 1 is a schematic diagram of a system for generating a secure private key according to the present invention; [Figure 3B] FIG. 2 is a schematic diagram of a method for generating a secure private key according to the present invention. [Figure 3C] FIG. 2 is a schematic diagram of a method for generating a secure private key according to a preferred embodiment of the method of the present invention. [Figure 4A] FIG. 1 is a schematic diagram of a system for generating a secure private key according to one embodiment of the present invention. [Figure 4B] FIG. 2 is a schematic diagram of a method for generating a secure private key according to a preferred embodiment of the method of the present invention. [Figure 5A] FIG. 1 is a schematic diagram of a system for generating a secure private key according to one embodiment of the present invention. [Figure 5B] FIG. 2 is a schematic diagram of a method for generating a secure private key according to the present invention. [Figure 5C] FIG. 5C is a schematic diagram of a preferred embodiment of the method of FIG. 5B. [Figure 6A] 1 is a schematic diagram of a system according to one embodiment of the present invention. [Figure 6B] FIG. 2 is a schematic diagram of a method for generating a secure private key according to the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0035] Unless otherwise specified, elements in the figures are not drawn to scale.

[0036] Fig. 3A shows a schematic diagram of a system 1 for generating a secure private key according to the invention, comprising at least two communication stations SA, SB and a satellite Sat. As a non-limiting example, Fig. 3A shows an embodiment in which the system 1 comprises a first communication station SA and a second communication station SB. Alternatively, according to another embodiment, the system of the invention comprises three or more communication stations.

[0037] FIG. 3B illustrates diagrammatically a method for generating a secure private key according to the invention implemented by a first communication station SA of the system 1 .

[0038] In a first step A of the method of the invention, a communication station SA transmits a quantum encrypted channel CQ AB and configured to receive a first secret key KEK from the satellite Sat on the AB and then transmitted to at least one other communication station SB, i.e. station SB in the system shown in Fig. 3A. This step is known to those skilled in the art and consists of conventional QKD by satellite (see Fig. 2B). In the system of the invention, the satellite Sat serves as a reliable node connecting station SA to station SB, so that stations SA and SB may be separated by distances greater than 100 km, which is the limit of QKD channels employing optical fibres.

[0039] In step B of the method of the invention, the first communication station SA is configured to generate the second secret key KS using a true random number generator TRNG. This kind of generator TRNG is known to the person skilled in the art. For example, this generator can be a quantum random number generator (QRNG). In this case, random numbers are created based on unpredictable quantum phenomena.

[0040] In step C, the first communication station SA generates an encryption private key KC from the first private key KEK and from the second private key KS by the One-Time Pad (OTP) method. To ensure the security of the One-Time Pad technique, the first and second private keys are of the same size (i.e. have the same key size) in the present invention. More generally, in the remainder of this specification, all steps of implementing the One-Time Pad technique combine two keys of the same size.

[0041] The method of Fig. 3B comprises a final step D of transmitting the encrypted secret key KC from the first communication station SA to the other communication station, namely the communication station SB in the embodiment of Fig. 3A. This transmission is carried out over a secure and authenticated channel CS linking stations SA and SB. AB This is done above.

[0042] Steps B to D are executed by a module Mod of the first communication station SA.

[0043] The second secret key KS forms a secure secret key. In particular, at the end of the method of Fig. 3B, the user UB of the station SB can decrypt the encrypted secret key KC using the first secret key KEK distributed by QKD via the satellite Sat (see method of Fig. 3C) to obtain the second secret key KS. Now, step B of the method of the invention (i.e. the generation of the second secret key) can be easily repeated and does not suffer from the limitations of the key generation by QKD via satellite (low bit rate, sensitivity to bad weather, etc.). Thus, in the present invention, a single first secret key KEK obtained by QKD allows the generation of several secure private keys by the one-time pad method, by combining these secure private keys with the first private key KEK. The key KEK is here a cryptographic primitive that allows the secure exchange of the second secure private key. The method of the invention therefore allows a significant reduction in the number of private keys distributed by QKD via satellite, providing an elegant solution to the problem caused by the low key rate achievable with this technique. The method of the invention makes it possible to increase the availability of the global QKD system for a large number of interconnected users on the ground, since the techniques implemented in the method of the invention (QKD and OTP) are resistant to quantum threats. However, it is important in the present invention not to reuse the key KEK to encrypt non-random messages that it is desired to exchange between stations SA and SB (see below). In the method of the invention, the second secure secret key KS is actually a random "message", so there is no danger in reusing the same key.

[0044] The following example shows why the method of the invention is secure: Let us assume that a user UA of station SA has created two second keys KS1 and KS2 and has decided to encrypt these keys with the same key KEK in order to transfer them to a user UB of station SB. We assume that these keys are binary coded. The step of encrypting the encrypted private key therefore consists of an XOR of the first private key and the second private key.

[0045] A private key encrypted using KS1 is denoted as KC1.

number

[0046] A private key encrypted using KS2 is denoted as KC2.

number

[0047] A spy named Eve intercepts two messages encrypted with the same KEK distributed by QKD. What information can she extract?

[0048] Eve can XOR these two encrypted messages to remove the influence of the first private key, KEK.

number

[0049] Therefore, Eve has the following information at her disposal:

number

[0050] These three sequences represent the XOR between random messages that have no statistical advantage over any other random message.

[0051] The XOR between KC1 and KC2 indeed allows Eve to remove the influence of the KEK. However, since KS1 and KS2 are also keys and therefore strictly random messages, it is impossible for Eve to perform an attack by statistical analysis or even a brute force attack, simply because every message Eve obtains is possibly correct. Eve does not have any information that would allow her to reveal the initial plaintext message. Conversely, such

number

[0052] Thus, in the present invention, the fact that the second secret keys are random messages (i.e., all with equal probability) allows the UA and UB to encrypt their keys using the same first secret key KEK without compromising the security of the encryption.

[0053] It should be pointed out that all steps of the method of FIG. 3B are implemented by the first station SA and are therefore "localized" within the same geographical area, rather than being distributed among various stations hundreds or thousands of kilometers apart.

[0054] Figure 3C shows a preferred embodiment of the method of the invention. This method is implemented by the system 1 of Figure 3A, which also includes the satellite Sat and the station SB. The method of Figure 3C includes a step E, which follows step D and is carried out by the communication station to which the encryption secret key KC has been transmitted, i.e. the station SB in the embodiment of Figure 3A. This step E consists in decrypting the encryption secret key KC using the first secret key KEK to obtain a second secret key KS forming a secure secret key. This step is necessary because it allows the two stations SA and SB to obtain a secure secret key which they will later use to encrypt the non-random messages they wish to exchange.

[0055] Preferably, in the method of the invention, the second private key and the encrypted private key are binary coded. In this embodiment, the encrypted private key KC is generated by an XOR logic gate combining the first private key KEK and the second private key KS. Step C therefore comprises:

number

number

[0056] As explained above, a single first private key KEK is required to generate and exchange a plurality of second secure private keys according to the method of the present invention. Thus, in a preferred embodiment of the method of FIG. 3C, a plurality of secure private keys KS1, KS2, ..., KS3, all generated from the first private key KEK are used. n Steps B through E are repeated multiple times to form

[0057] Figure 4A shows an implementation of the system 1 of the invention, arranged to implement the method of figure 4B. This method is a preferred embodiment of the method of figure 3C and allows to exchange non-random messages M between stations SA and SB. The method of figure 4B comprises two additional steps F and G. Step F, executed within one of the communication stations, for example SA, comprises: - encrypting a non-random message M using a secure private key KS generated by the method of the present invention; and - consists in transmitting an encrypted non-random message MC from a communication station SA to another communication station SB, said message being preferably transmitted over a secure and authenticated channel linking stations SA and SB, for example a channel CS AB will be exchanged above.

[0058] The method of Fig. 3D further comprises a final step G consisting of decrypting the encrypted non-random message MC using the secure private key KS. The method of Fig. 4B is the ultimate goal of the method of the invention. This method involves the decryption of multiple secure private keys KS1, KS2, ..., KS, all generated from a first private key KEK. nMultiple encrypted non-random messages MC1, MC2, ..., MC n This allows for the exchange of

[0059] In order not to compromise the confidentiality of the one or more non-random messages M exchanged in the method of Figure 3D, it is necessary that in step F the non-random messages are not encrypted using the one-time pad method with one of the secure secret keys KS generated by the method of the present invention. In particular, assume that the UA performs this encryption. Thus, the UA:

number

number

[0060] The following encrypted message is denoted as MC1.

number

[0061] The following encrypted message is denoted as MC2.

number

[0062] Eve has free access to the encryption private keys KC1 and KC2. Eve can combine the encryption private keys KC1 and KC2 with MC1 and MC2 to obtain the following:

number

[0063] Now Eve has the equivalent of two encryption sequences of the plaintext non-random message combined with the same first private key, KEK, so she can "xor" the two sequences together as follows:

number

[0064] Eve removes the influence of the first secret key, KEK, and generates a sequence that represents the combination of two non-random messages.

number

[0065] Therefore, to avoid compromising the security of the non-random message M, we encrypt the non-random message with a symmetric encryption method, such as block cipher or stream cipher.

[0066] Fig. 5A shows a system 2 for generating secure keys, which forms a particular embodiment of the inventive device 1 shown in Fig. 3A. In addition to the system 1, the system 2 comprises a first local communication station SLA and a second local communication station SLB. In the system 2, stations SA and SB both comprise a cryptographic module Mod. Fig. 5B shows diagrammatically a method for generating secure private keys according to the invention, implemented by the assembly SA+SLA of the system 2. As will be explained below, the method of Fig. 5B is carried out in such a way that two users UA and UB of the local stations SLA and SLB, respectively, subscribe to a common private key K by the station SA or SB to which the local station SLA or SLB, respectively, is connected. ABThe advantage of this system 2 and the associated method is that it allows the users UA and UB to avoid the need to manage the QKD delivery by the satellite Sat to the stations SA and SB. The communication with the satellite is thus via gateway stations SA, SB to which the end users UA and UB are connected by short-distance quantum channels, e.g. based on fibre.

[0067] In the method of Figure 5B, KEK A A first private key A, denoted as A, and a KEK different from the first private key A. B Step A of the method of the invention is repeated twice before step B in order to receive in the first communication station SA first secret keys B, denoted as KEK A and KEK B Channel QC AB The first secret key KEK is distributed by QVK via the satellite Sat on the left and is transmitted to the second communication station SB in the same manner. A and KEK B The two stations SA and SB need to be able to store the above.

[0068] In the method of FIG. 5B, a first encryption private key KC A Steps B to D of the method of the invention are carried out by the first communication station SA to generate this key KC A is the first private key, KEK A and K.S. A It is generated from a second secure private key A, which we denote as A. So the steps are:

number

[0069] The method further comprises additional steps D'E, F', G' and H executed by the first communication station SA, step D'E comprising: -First private key KEK B and KS generated by the second communication station SB B A second encrypted private key KC generated by a second communication station from a second secure private key B, denoted as B , i.e.

number

number

[0070] Step F' is the process of generating a secret key K AB , and convert it to a second secure private key, K.S., by the one-time pad technique. A and a second secure private key K B In other words,

number

[0071] Step G' of the method of FIG. 5B comprises the following: A first secret key KL, called the local secret key Ato a first local communication station SLA on a first local quantum channel CLA, which is a simple QKD quantum channel connecting stations SA and SLA by optical fiber, the distance between these stations SA and SLA therefore being less than 100 km. - A first local secret key KL A and the common secret key K AB First encrypted local secret key KLC A , i.e.

number

[0072] Step H of the method of FIG. 5B comprises, in the first local communication station SLA, generating a common secret key K AB First, we use a local secret key KL A First encrypted using the local private key KLC A This step therefore consists of decoding

number

[0073] As with the method of FIG. 3B, the various steps of the method of FIG. 5B are implemented by the assembly SA+SLA and are therefore "localized" within the same geographic area, rather than being distributed across various stations hundreds or thousands of kilometers apart.

[0074] At the end of the method of FIG. 5B and subject to certain steps being implemented by stations SB and SLB (see method of FIG. 5C), users UA and UB obtain a common secret key K, known only to them and which can be used to secure their communications. AB Now, this operation can be repeated as many times as UA and UB need to communicate with each other. A and KEKB The method can be repeated with pairs of KEK, KEK+1, KEK+2, KEK+3, KEK+4, KEK+5, KEK+6, KEK+7, KEK+8, KEK+9, KEK+10, KEK+11, KEK+12, KEK+13, KEK+14, KEK+15, KEK+16, KEK+17, KEK+18, KEK+19, KEK+20, KEK+21, KEK+22, KEK+23, KEK+24, KEK+25, KEK+26, KEK+27, KEK+28, KEK+29, KEK+21, KEK+21, KEK+21, KEK+21, KEK+22, KEK+23, KEK+24, KEK+25, KEK+26, KEK+27, KEK+28, KEK+29, KEK+30, KEK+31, KEK+32, KEK+33, KEK+34, KEK+35, KEK+36, KEK+37, KEK+38, KEK+39, KEK+40, KEK+41, KEK+42, KEK+43, KEK+44, KEK+45, KEK+46, KEK+47, KEK+48, KEK+49, KEK+50, KEK+51, KEK+52, KEK+53, KEK+54, KEK+55, KEK+56, KEK+57, KEK+58, KEK+59, KEK+59, KEK+ A and KEK B Therefore, the first secret key KEK A and KEK B The pair remains safe and secret.

[0075] The advantages of the method of Fig. 5B will become clear from the following description of Fig. 5C, which shows a preferred embodiment of the method of Fig. 5B, which is implemented by the system 2 of Fig. 5A, as well as by the assembly SA+SLA, as in the method of Fig. 5B.

[0076] In the method of FIG. 5C, a step D′E comprises the step of: A To obtain the first encryption secret key KC A The first private key, KEK A This step therefore further comprises:

number

[0077] Step F' of the method of FIG. 5C comprises generating, in a second communication station SB, a second secure secret key KS by the one-time pad technique. A and a second secure private key B K B from the common secret key K AB The method includes generating

[0078] In the method of FIG. 5C, step G′ further includes: i. A second local secret key KL Bto a second local communication station SLB by a second local quantum channel CLB. Like the first local quantum channel CLA, CLB is a QKD quantum channel connecting stations SB and SLB by optical fiber. The distance between these stations SB and SLB is therefore less than 100 km. ii. A second local secret key KL is obtained by the one-time pad method. B and the common secret key K AB from the second encrypted local private key KLC B To generate. iii. the second encrypted local private key KLC as described above; B to the second local communication station SLB.

[0079] Finally, step H of the method of FIG. 5C involves the transfer, in the second local communication station SLB, of the aforementioned common secret key K AB To obtain the second local secret key KL B A second encrypted local private key, KLC B If the key is binary encoded, this step involves:

number

[0080] As explained above, at the end of the method of FIG. 5C, the users UA and UB of the local communication stations SLA and SLB have a common secret key K that only they know and can use to secure their communications. AB Essentially, operators UA and UB hold a first secret key KEK distributed by stations SA and SB and used to generate common secret keys for other users. A and KEK B Therefore, the key KEK A and KEK B The pair can be used for all users and as many times as they wish, without compromising the security of the common secret key that is generated.

[0081] Consider all the information available to users UA and UB, and Eve, of stations SLA and SLB.

number

number

number

number

[0082] Eve can attempt the following actions:

number

[0083] Eve

number

[0084] Similarly, Eve

number

[0085] In addition to the combinations that Eve may try, UA and UB share a common secret key K AB Since we hold the same value, we can try other combinations.

[0086] Therefore, UA and UB are

number

number

[0087] In the method of FIG. 5C, station SA transmits two first secret keys KEK , which are distributed by QKD in common with station SB, in order to be able to establish at any time a common secret key, which can be distributed to users who need it. A , KEK B The satellites no longer need to pre-establish a large number of secret keys. A common secret key can be generated very quickly on demand by stations SA and SB, which makes it possible to increase the number of users on the ground and therefore the overall availability of system 2.

[0088] Fig. 6A shows an implementation of the system 2 of the invention configured to implement the method of Fig. 6B, which is a preferred embodiment of the method of Fig. 5C. The method of Fig. 6B is carried out after step H and by the first local communication station SLA, using the aforementioned common secret key K ABand then transmitting the encrypted non-random message MC to a second local communication station SLB. This message is preferably transmitted over a secure and authenticated channel CS AB The method of FIG. 6B is carried out after step I and by the second local communication station by exchanging a common secret key K AB and step J of decrypting said encrypted non-random message using

[0089] The method of Fig. 6B is the ultimate goal of the method of Fig. 5C. This method involves the generation of a first secret key KEK by stations SA and SB. A , KEK B Multiple shared secret keys K, all generated locally from a single pair of AB This enables stations SLA and SLB to exchange multiple non-random messages encrypted using the .

[0090] Preferably, the first encryption secret key KC A and the second encryption private key KC B uses a message authentication code (MAC) calculated based on a common authentication key, and transmits the AB The information is transmitted over a secure and authenticated channel such as

[0091] In a preferred embodiment of the system 1 or 2 of the present invention, the communication stations SA and SB are on the ground and are more than 100 km apart. In particular, if the stations SA and SB are closer than this distance, a simple QKD channel linking the two stations by optical fiber is sufficient to exchange a secure secret key.

Claims

1. 1. A method for generating a secure private key, comprising: A. A communication station (SA), called a transmitting station, sets up a quantum encryption channel (CQ AB receiving a first secret key (KEK) on said station (SB), said first secret key also being transmitted to at least one other station (SB) by said quantum encrypted channel; B. At the transmitting station, generating a second secret key (KS) using a true random number generator (TRNG); C. generating an encryption private key (KC) from the first private key (KEK) and the second private key (KS) by a one-time pad method; D. transmitting said encryption secret key (KC) from said sending station (SA) to said one or more other communication stations (SB); A method comprising:

2. 2. The method of claim 1, further comprising, following step D, a step E at the one or more other communication stations of decrypting the encrypted private key (KC) using the first private key (KEK) to obtain the second private key (KS) forming the secure private key.

3. 3. The method of claim 2, wherein the first private key, the second private key (KS), and the encrypted private key (KC) are binary coded, the encrypted private key is generated by an XOR logic gate combining the first private key and the second private key, and the encrypted private key is decrypted by an XOR logic gate combining the encrypted private key and the first private key.

4. A plurality of secure private keys (KS) all generated from the first private key (KEK). 1 , K.S. 2 ,... ,KS n 4. The method of claim 2 or 3, wherein steps B through E are repeated multiple times to form a

5. 4. A method according to claim 2 or 3, comprising a subsequent step F of encrypting a non-random message (M) using said secure private key and then transmitting said encrypted non-random message (MC) from one communication station to another, and a subsequent step G of decrypting said encrypted non-random message using said secure private key.

6. In the first communication station, a first secret key A (KEK A ), and a first private key B (KEK B Step A is repeated twice before step B to receive the first secret keys A and B, and said first secret keys A and B are also transmitted to a second communication station (SB) via said quantum channel; The first private key A (KEK A ) and a second secure private key A(KS) generated by said first communication station. A ) to the first encryption private key (KC A Steps B to D are performed by the first communication station (SA) to generate a .times. ... The method comprises additional steps D'E, F', G', and H, performed by the first communication station, said step D'E comprising: - the first private key B (KEK B ) and a second secure private key B(KS) generated by the second communication station. B ) to generate a second encryption secret key (KC B ) and - said second secure private key B(KS B ) to obtain the second encryption secret key (KC B ) into the first private key B (KEK B ) to decrypt it. It consists of The step F' derives the second secure secret key A(KS A ) and the second secure private key B(KS B ) to the secret key (K AB ) and Step G' comprises: i. The first local private key (KL A ) to a first local communication station (SLA) over a first local quantum channel (CLA); ii. The first local secret key (KL A ) and the common secret key (K AB ) to the first encrypted local secret key (KLC A ), and iii. The first encrypted local secret key (KLC A ) to the first local station (SLA). It consists of The step H includes, in the first local communication station, AB ) to obtain the first local secret key (KL A ) to generate the first encrypted local secret key (KLC A ) The method according to any one of claims 1 to 3.

7. Step D'E comprises, in said second communication station (SB), A ) to obtain the first private key A (KEK A ) to generate the first encryption secret key (KC A ) Step F', at the second communication station, generates the second secure secret key A(KS) by the one-time pad technique. A ) and the second secure private key B(KS B ) to the common secret key (K AB ), The method comprises: iv. A second local private key (KL B ) to a second local communication station (SLB) via a second local quantum channel (CLB); v. The second local private key (KL B ) and the common secret key (K AB ) to the second encrypted local secret key (KLC B ), and vi. The second encrypted local secret key (KLC B ) to the second local communication station. a step G' comprising: The step H includes, in the second local communication station, AB ) to obtain the second local private key (KL B ) to generate the second encrypted local secret key (KLC B ) The method of claim 6.

8. After step H and executed by the first local communication station, AB ) and then transmitting said encrypted non-random message (MC) to said second local communication station; After step I and executed by the second local communication station, AB ) and a step J of decrypting the encrypted non-random message using The method of claim 7.

9. The method according to any one of claims 1 to 3, wherein the first private key and the second private key are of the same size.

10. The method of claim 5, wherein the non-random message is encrypted by a symmetric encryption method, such as a block cipher or a stream cipher.

11. A station (SA) called a first station for generating a secure secret key, said first station having a quantum encryption channel (CQ) set up with a satellite (Sat). AB ) on the quantum encryption channel, said first secret key being also transmitted to at least one other communication station (SB), said first communication station being configured to: - generating a second secret key (KS) using a true random number generator (TRNG); generating an encryption private key (KC) from said first private key (KEK) and said second private key (KS) by a one-time pad method; - transmitting said encryption secret key (KC) to said other communication station (SB); a communication station (SA) including a cryptographic module (Mod) configured to:

12. 12. A system (1) for generating a secure private key comprising a first communication station (SA) as claimed in claim 11 and comprising other communication stations (SB) and satellites (Sat), wherein the other communication stations (SB) are configured to decrypt an encrypted private key (KC) using a first private key (KEK) to obtain a second private key (KS) forming the secure private key.

13. Assembly (SA+SLA) for generating a secure private key, said assembly comprising a first communication station (SA) according to claim 11 and a first local communication station (SLA), said first communication station (SA) comprising: - a first secret key A (KEK A ) and a first private key B (KEK B ), wherein the first key and the second key are also transmitted to a second communication station (SB) via the quantum channel; - the first private key A (KEK A ) and a second secure private key A(KS) generated by said first communication station. A ) to the first encryption private key (KC A ) and transmitting it to said second communication station (SB); - the first private key B (KEK B ) and a second secure private key B(KS) generated by the second communication station. B ) to generate a second encryption secret key (KC B ) and - said second secure private key B(KS B ) to obtain the second encryption secret key (KC B ) into the first private key B (KEK B ) and decrypting it with - The second secure secret key A(KS) is generated by the one-time pad technique. A ) and the second secure private key B(KS B ) to a secret key (K AB ) generating - a first private key called local private key (KL A ) over a first local quantum channel to said first local communication station (SLA); - The first local secret key (KL A ) and the common secret key (K AB ) to the first encrypted local secret key (KLC A ), and - the first encrypted local private key (KLC A ) to the first local station (SLA). and the first local communication station is configured to AB ) to obtain the first local secret key (KL A ) to generate the first encrypted local secret key (KLC A ) Assembly (SA+SLA).

14. A system (2) comprising an assembly (SA+SLA) according to claim 13, a satellite (Sat), a second local communication station (SLB) and a second communication station (SB) comprising an encryption module (Mod), The second communication station In said second communication station (SB), a second secure private key A(KS A ) by using a first encryption secret key (KC A ) into a first secret key A (KEK A ) and decrypting it with - The second secure secret key A(KS) is generated by the one-time pad technique. A ) and a second secure private key B(K B ) to a secret key (K AB ) generating - at the second communication station, the second secure secret key A(KS) is generated by the one-time pad technique; A ) and the second secure private key B(KS B ) to the common secret key (K AB ) generating - a second local private key (KL B ) to said second local communication station (SLB) by a second local quantum channel (CLB); - The second local secret key (KL B ) and the common secret key (K AB ) to the second encrypted local secret key (KLC B ), and - the second encrypted local private key (KLC B ) to the second local communication station. configured to: The second local communication station uses the common secret key (K AB ) to obtain the second local private key (KL B ) to generate the second encrypted local secret key (KLC B ) System (2).

15. 15. A system according to claim 12 or 14, wherein the communication stations are on land and are more than 100 km apart.