Satellite Constellation Secret Key Distribution via Trusted Node

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing quantum key distribution (QKD) methods face limitations in scalability and distance, particularly in establishing secure secret keys for satellite constellations, where key exchange over long distances and multiple users is hindered by physical constraints and vulnerability to interception.

Innovation Solution

A method and system for distributing secure secret keys among a constellation of satellites using a single communication station, where secret keys are exchanged via a quantum channel and encrypted using a secret encryption key, allowing each satellite to decipher and use the keys for secure communication, employing a disposable mask method for encryption and decryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If quantum key distribution is used to exchange secret keys between satellites, then security is improved, but the distance and scalability are limited due to photon absorption in optical fibers

Engineering Contradiction:
ImprovesecurityVSAvoiddistance
Core Design Contradiction:
ReliabilityVSLength of stationary object

Solution Approach 1:

A trusted node satellite is introduced as an intermediary to facilitate key distribution between ground stations and other satellites. The trusted node receives quantum keys from ground stations via quantum channels, stores them securely, and then distributes them to other satellites through classical encrypted channels, thereby extending the reach of quantum key distribution beyond direct line-of-sight constraints.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trusted node satellite performs self-service by autonomously managing its own key storage and distribution operations. It maintains local key repositories, automatically encrypts keys using pre-shared secrets with target satellites, and schedules key distribution operations without requiring continuous human intervention, thus enabling scalable key management across the constellation.

Inventive Principle:
Principle #25Self-service

2Length of stationary object

If trusted nodes are deployed to extend quantum key distribution range, then distance limitation is overcome, but device complexity and operational costs increase

Engineering Contradiction:
ImprovedistanceVSAvoidsystem complexity
Core Design Contradiction:
Length of stationary objectVSDevice complexity

Solution Approach 1:

The trusted node satellite is designed to perform multiple functions: it acts as a quantum key receiver from ground stations, a secure key repository, an encryption device using pre-shared secrets, and a distribution hub to other satellites. This multi-functionality consolidates what would otherwise require multiple separate components into a single integrated system, reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements key lifecycle management where quantum keys are generated, stored temporarily in the trusted node, distributed to satellites, and then discarded after use. This ephemeral key approach ensures that sensitive quantum keys do not persist longer than necessary, reducing security risks and simplifying key management by automatically retiring unused keys.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If quantum channels are used for key exchange, then unconditional security is achieved, but scalability to multiple users is hindered

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The key distribution process is segmented into distinct phases: quantum key generation between ground stations and the trusted node, classical encryption of keys using pre-shared secrets, and distributed delivery to multiple satellites. This segmentation allows the quantum channel to be used only where absolutely necessary (ground-to-trusted-node), while classical channels handle the bulk of key distribution to multiple users, thereby scaling the system to serve many satellites without requiring quantum channels for every pair.

Inventive Principle:
Principle #1Segmentation

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach enables secure and efficient distribution of secret keys across a satellite constellation, enhancing security and reducing operational costs by eliminating the need for trusted nodes and overcoming distance limitations, thus ensuring unconditional security for satellite communication.

Implementation Method 1

exchange a secret encryption key CAKEj via a quantum channel between the communication station and a satellite Sj

Methodology Applied
Scientific EffectQuantum key distribution:

Data Source

PatentEP4243336A1Method and apparatus for distributing secret keys in a satellite constellation
Publication Date: 2023.09.13 THALES SA
  • EP4243336A1 patent drawingFigure 1~2A
  • EP4243336A1 patent drawingFigure 2B~2C
  • EP4243336A1 patent drawingFigure 3A~3B

AI summary

Method for distributing secure secret keys for a constellation (C) of N > 1 satellites Sp, p = [1; N] using a communication station (SC), said method comprising the following steps: A. exchanging at least one secret key Kij, i, j ∈ [1; N], i ≠ j, between the communication station (SC) and a satellite Si via a quantum channel (CQSI), each secret key Kij being intended for secure communication of the satellite Si with a respective satellite Sj of the constellation, said at least one secret key Kij,j ∈ [1; N], i ≠ j forming said secure secret keys; B.for each j B1- exchange a secret encryption key KEKj, between the communication station (SC) and the satellite Sj via a quantum channel (CQSJ); B2- encrypt the secret key Kij by an encryption method which uses the secret encryption key KEKj, so as to produce an encrypted message KCij and transmit via an authenticated channel CAj from the communication station (SC) to the satellite Sj, said encrypted message KCij.