Memory Attacks on Device-Independent Quantum Cryptography

Memory Attacks on Device-Independent Quantum Cryptography
复制标题

DOI:
10.1103/physrevlett.110.010503
复制
发表时间:
2013-01-02
影响因子:
8.6
通讯作者:
Kent, Adrian
Kent, Adrian
中科院分区:
物理与天体物理1区
文献类型:
--
作者:
Barrett, Jonathan;Colbeck, Roger;Kent, Adrian

文献摘要

被引文献

相似文献

设备无关的量子密码方案旨在仅基于所使用的任何组件的输出统计来保证用户的安全性,而无需验证其内部功能。由于这将保护用户免受不可信或不称职的制造商,破坏或设备退化,这个想法引起了很大的兴趣,并且已经提出了许多与设备无关的方案。在这里,我们发现了依赖安全实验室之间公共通信的设备独立协议的一个关键弱点。不受信任的设备可能会记录它们的输入和输出,并在以后的运行期间通过公开讨论的输出来泄露有关它们的信息。因此,重用设备会危及协议的安全性,并有泄露秘密数据的风险。可能的防御措施包括安全地销毁或隔离使用过的设备。然而,这些都是昂贵的,往往是不切实际的。我们提出了其他更实用的部分防御,以及一个新的协议结构,用于设备无关的量子密钥分发,旨在实现组合安全的情况下,双方使用少量的设备,以重复地相互共享密钥(和没有其他方)。DOI:10.1103/PhysRevLett.110.010503
Device-independent quantum cryptographic schemes aim to guarantee security to users based only on the output statistics of any components used, and without the need to verify their internal functionality. Since this would protect users against untrustworthy or incompetent manufacturers, sabotage, or device degradation, this idea has excited much interest, and many device-independent schemes have been proposed. Here we identify a critical weakness of device-independent protocols that rely on public communication between secure laboratories. Untrusted devices may record their inputs and outputs and reveal information about them via publicly discussed outputs during later runs. Reusing devices thus compromises the security of a protocol and risks leaking secret data. Possible defenses include securely destroying or isolating used devices. However, these are costly and often impractical. We propose other more practical partial defenses as well as a new protocol structure for device-independent quantum key distribution that aims to achieve composable security in the case of two parties using a small number of devices to repeatedly share keys with each other (and no other party). DOI: 10.1103/PhysRevLett.110.010503