IP Library › Granted Patent US 12,609,820
Granted Patent B2
US 12,609,820 · App. 18/693,934 · Granted Apr 21, 2026

System and method for generating a secure secret key

Inventors: Benoit Tranier (Toulouse, FR); Jean Didier Gayrard (Toulouse, FR)
Assignee: THALES
H04L9/0869H04L9/0822H04L9/0852H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,820
App. No.
18/693,934
Granted
Apr 21, 2026
Kind
B2
Abstract

A method for generating a secure secret key, includes the following steps: A. receiving, in a communication station referred to as the transmitting station, a first secret key by way of a quantum encryption channel via satellite, the first secret key also being transmitted to at least one other communication station by way of the quantum encryption channel; B. generating, in the transmitting station, a second secret key using a trusted random number generator; C. generating an encrypted secret key using the first secret key and the second secret key by the one-time pad method; D. transmitting the encrypted secret key from the transmitting station to the one or more other communication stations.

Claims (57)

1 . A method for generating a secure secret key in stations of a communication system, the stations comprising one or more hardware processors, the method comprising the following steps:

A. receiving, in a communication station (SA) called a sending station, a first secret key (KEK) over a quantum encryption channel (CQ AB ) set up with a satellite (Sat), said first secret key also being transmitted to at least one other communication station (SB) via said quantum encryption channel;

B. generating, in said sending station, a second secret key (KS) using a true random number generator (TRNG);

C. generating an encrypted secret key (KC) from the first secret key (KEK) and second secret key (KS), by means of the one-time-pad method; and

D. transmitting said encrypted secret key (KC) from the sending station (SA) to the one or more other communication stations (SB),

wherein step A is repeated twice before step B, in order to receive, in a first communication station, a first secret key A (KEK A ) and a first secret key B (KEK B ) that is different from the first secret key A, the first secret keys A and B also being transmitted to a second communication station (SB), via said quantum channel,

wherein steps B to D are carried out by the first communication station (SA) to generate a first encrypted secret key (KC A ) from the first secret key A (KEK A ) and from a second secure secret key A (KS A ) generated by the first communication station, and to transmit it to said second communication station (SB),

said method comprising additional steps D′E, F′, G′ and H carried out by said first communication station, said step D′E consisting in:

receiving a second encrypted secret key (KC B ) generated by the second communication station from the first secret key B (KEK B ) and from a second secure secret key B (KS B ) generated by the second communication station, and

decrypting said second encrypted secret key (KC B ) with the first secret key B (KEK B ) so as to obtain said second secure secret key B (KS B ),

said step F′ consisting in generating a secret key (K AB ) called the common secret key, by means of the one-time-pad technique, from the second secure secret key A (KS A ) and from the second secure secret key B (KS B ),

said step G′ consisting in:

i. distributing a secret key (KL A ) called the first local secret key to a first local communication station (SLA), via a first local quantum channel (CLA),

ii. generating, by means of the one-time-pad method, a first encrypted local secret key (KLC A ) from the first local secret key (KL A ) and from the common secret key (K AB ), and

iii. transmitting said first encrypted local secret key (KLC A ) to said first local communication station (SLA),

said step H consisting in decrypting, in said first local communication station, said first encrypted local secret key (KLC A ) using the first local secret key (KL A ), so as to obtain said common secret key (K AB ).

2 . The method as claimed in claim 1 , comprising a step E, subsequent to step D, of decrypting, in the one or more other communication stations, said encrypted secret key (KC) using the first secret key (KEK), so as to obtain said second secret key (KS), which forms said secure secret key.

3 . The method as claimed in claim 2 , wherein the first secret key, the second secret key (KS) and the encrypted secret key (KC) are binary encoded, the encrypted secret key being generated via an XOR logic gate that combines the first secret key and second secret key, the encrypted secret key being decrypted via an XOR logic gate that combines the encrypted secret key and the first secret key.

4 . The method as claimed in claim 2 , wherein steps B to E are repeated a plurality of times, in order to form a plurality of secure secret keys (KS 1 , KS 2 , . . . , KS n ), all generated from the first secret key (KEK).

5 . The method as claimed in claim 2 , comprising a subsequent step F of encrypting a non-random message (M) using said or a said secure secret key then transmitting the encrypted non-random message (MC) from one communication station to another communication station, and comprising a subsequent step G of decrypting said encrypted non-random message using said secure secret key.

6 . The method as claimed in claim 5 , wherein the non-random message is encrypted by means of a symmetric encryption method that comprises block or stream encryption.

7 . The method as claimed in claim 1 , wherein step D′E comprises decrypting, in the second communication station (SB), said first encrypted secret key (KC A ) with the first secret key A (KEK A ) so as to obtain said second secure secret key A (KS A ),

and wherein step F′ comprises generating, in the second communication station, said common secret key (K AB ), by means of the one-time-pad technique, from the second secure secret key A (KS A ) and from the second secure secret key B (KS B ),

said method comprising a step G′, which comprises:

i. distributing a second local secret key (KL B ) to a second local communication station (SLB), via a second local quantum channel (CLB),

ii. generating, by means of the one-time-pad method, a second encrypted local secret key (KLC B ) from the second local secret key (KL B ) and from the common secret key (K AB ), and

iii. transmitting said second encrypted local secret key (KLC B ) to said second local communication station,

and wherein said step H comprises decrypting, in the second local communication station, said second encrypted local secret key (KLC B ) using the second local secret key (KL B ), so as to obtain said common secret key (K AB ).

8 . The method as claimed in claim 7 , comprising a step I, subsequent to step H, and performed by the first local communication station, of encrypting a non-random message (M) using said common secret key (K AB ) then transmitting the encrypted non-random message (MC) to the second local communication station,

said method comprising a step J, subsequent to step I, and performed by the second local communication station, of decrypting said encrypted non-random message using said common secret key (K AB ).

9 . The method as claimed in claim 1 , wherein the first secret key and the second secret key are of the same size.

10 . An assembly (SA+SLA) for generating a secure secret key, said assembly comprising:

a communication station (SA) configured and/or operable to be implemented as part of a system, the communication station (SA) implemented as a first communication station comprising one or more hardware processors, the first communication station, for generating a secure secret key, said first communication station being configured to receive a first secret key (KEK) over a quantum encryption channel (CQ AB ) set up with a satellite (Sat), said first secret key also being transmitted to at least one other communication station (SB) via said quantum encryption channel, said first communication station comprising an encrypting module (Mod) configured to:

generate a second secret key (KS) using a true random number generator (TRNG);

generate an encrypted secret key (KC) from the first secret key (KEK) and second secret key (KS) by means of the one-time-pad method; and

transmit said encrypted secret key (KC) to said other communication stations (SB); and

said assembly further comprising a first local communication station (SLA), said first communication station (SA) being configured to:

receive a first secret key A (KEK A ) and a first secret key B (KEK B ) that is different from the first secret key A via said quantum encryption channel, the first key and the second key also being transmitted to a second communication station (SB) via said quantum channel,

generate a first encrypted secret key (KC A ) from the first secret key A (KEK A ) and from a second secure secret key A (KS A ) generated by the first communication station, and to transmit it to said second communication station (SB),

receive a second encrypted secret key (KC B ) generated by the second communication station from the first secret key B (KEK B ) and from a second secure secret key B (KS B ) generated by the second communication station, and

decrypt said second encrypted secret key (KC B ) with the first secret key B (KEK B ) so as to obtain said second secure secret key B (KS B ),

generate a secret key (K AB ) called the common secret key, by means of the one-time-pad technique, from the second secure secret key A (KS A ) and from the second secure secret key B (KS B ),

distribute a secret key (KL A ) called the first local secret key to said first local communication station (SLA), via a first local quantum channel (CLA),

generate, by means of the one-time-pad method, a first encrypted local secret key (KLC A ) from the first local secret key (KL A ) and from the common secret key (K AB ), and

transmit said first encrypted local secret key (KLC A ) to said first local communication station (SLA), and

said first local communication station being configured to decrypt said first encrypted local secret key (KLC A ) using the first local secret key (KL A ), so as to obtain said common secret key (K AB ).

11 . A system for generating a secure secret key, comprising said first communication station (SA) as claimed in claim 10 , and comprising said other communication stations (SB) and said satellite (Sat), said other communication stations (SB) being configured to decrypt said encrypted secret key (KC) using the first secret key (KEK), so as to obtain said second secret key (KS), which forms said secure secret key.

12 . The system as claimed in claim 11 , wherein the communication stations are on the ground and spaced apart by more than 100 km.

13 . A system comprising the assembly (SA+SLA) according to claim 10 , the satellite (Sat), a second local communication station (SLB), and comprising a second communication station (SB) comprising an encrypting module (Mod),

the second communication station being configured to:

decrypt, in the second communication station (SB), said first encrypted secret key (KC A ) with the first secret key A (KEK A ) so as to obtain said second secure secret key A (KS A ),

generate a secret key (K AB ) called the common secret key, by means of the one-time-pad technique, from the second secure secret key A (KS A ) and from the second secure secret key B (KS B ),

generate, in the second communication station, said common secret key (K AB ), by means of the one-time-pad technique, from the second secure secret key A (KS A ) and from the second secure secret key B (KS B ),

distribute a second local secret key (KL B ) to the second local communication station (SLB), via a second local quantum channel (CLB),

generate, by means of the one-time-pad method, a second encrypted local secret key (KLC B ) from the second local secret key (KL B ) and from the common secret key (K AB ), and

transmit said second encrypted local secret key (KLC B ) to said second local communication station,

the second local communication station being configured to decrypt said second encrypted local secret key (KLC B ) using the second local secret key (KL B ), so as to obtain said common secret key (K AB ).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2024
From: TRANIER, BENOIT; GAYRARD, JEAN DIDIER
To: THALES
Reel/Frame 067100/0622 →
Priority Claims (1)
FR 2110024 · Sep 23, 2021 · national
Continuity (1)
Related Publication 20240388430A1 · Nov 21, 2024
References Cited (6)
US 7073073B1 · Nonaka · 2006 [cited by examiner]
US 11411722B2 · Walenta · 2022 [cited by examiner]
US 20200351087A1 · Mccandlish et al. · 2020 [cited by applicant]
WO WO2021090026A1 · 2021 [cited by examiner]
Cui, et al., “A new scheme for quantum key distribution in free-space”, 2009 15th Asia-Pacific Conference on Communications, pp. 637-640, 2009. [cited by applicant]
Menezes, et al., “Chapter 12: Key Establishment Protocols ED”, Handbook of Applied Cryptography; [CRC Press Series on Discrete Mathematices and Its Applications], pp. 489-541, 1996. http://www.cacr.math.uwaterloo.ca/hac… [cited by applicant]