Trojan-horse attacks threaten the security of practical quantum cryptography

Trojan-horse attacks threaten the security of practical quantum cryptography
复制标题

DOI:
10.1088/1367-2630/16/12/123030
复制
发表时间:
2014-12-10
影响因子:
3.3
通讯作者:
Leuchs, Gerd
Leuchs, Gerd
中科院分区:
物理与天体物理2区
文献类型:
--
作者:
Jain, Nitin;Anisimova, Elena;Leuchs, Gerd

文献摘要

被引文献

相似文献

通过在量子通道的明亮光线发送并分析背面反射,可以通过窃听前夕探测量子键分布(QKD)系统。我们提出并在实验上展示了用于安装这种特洛伊木马攻击的设置。我们以ID Quontique的量子密码系统Clavis2的形式显示了它作为原理证明。 Eve只有几个反射光子的光子,可以辨别鲍勃(Secret)的基础选择,因此在Scarani-Acin-ribordy-Gisin 2004协议中的原始密钥位,其概率高于90%。这显然会违反密码系统的安全性。不幸的是,夏娃的明亮脉冲具有导致鲍勃的单光子探测器的高水平的副作用,从而导致较大的量子错误率,从而有效地保护了该系统免受攻击。但是,在配备有较不命中但现实特征的探测器的类似Clavis2的系统中,将存在一种键泄漏的攻击策略。我们通过数值模拟来确认这一点。窃听的设置和策略都可以推广到攻击当前大多数QKD系统,尤其是如果它们缺乏适当的保障措施。我们还提出了对策以防止这种攻击。
A quantum key distribution (QKD) system may be probed by an eavesdropper Eve by sending in bright light from the quantum channel and analyzing the back-reflections. We propose and experimentally demonstrate a setup for mounting such a Trojan-horse attack. We show it in operation against the quantum cryptosystem Clavis2 from ID Quantique, as a proof-of-principle. With just a few back-reflected photons, Eve discerns Bob's (secret) basis choice, and thus the raw key bit in the Scarani-Acin-Ribordy-Gisin 2004 protocol, with higher than 90% probability. This would clearly breach the security of the cryptosystem. Unfortunately, Eve's bright pulses have a side effect of causing a high level of afterpulsing in Bob's single-photon detectors, resulting in a large quantum bit error rate that effectively protects this system from our attack. However, in a Clavis2-like system equipped with detectors with less-noisy but realistic characteristics, an attack strategy with positive leakage of the key would exist. We confirm this by a numerical simulation. Both the eavesdropping setup and strategy can be generalized to attack most of the current QKD systems, especially if they lack proper safeguards. We also propose countermeasures to prevent such attacks.