Source-linked AI summary

Experimental demonstration of phase-remapping attack in a practical quantum key distribution system

Feihu Xu, Bing Qi, Hoi-Kwong Lo

arXiv:1005.2376v1quant-ph

TL;DR

The paper addresses a security loophole in a commercial plug & play QKD system. It experimentally demonstrates a feasible intercept-and-resend attack, achieving full information while introducing a QBER of 19.7%, below the 20.0% BB84 security bound.

  • Problem

    A security loophole in a commercial plug & play QKD system allows Eve to launch a phase-remapping attack.

  • Method

    The paper experimentally demonstrates a technologically feasible intercept-and-resend attack on a commercial bidirectional QKD system.

  • Results

    19.7% QBER allows Eve to get full information, below the proven security bound of 20.0% for BB84.

  • Takeaways & Limitations

    The demonstration shows that a simple photon BB84 QKD system has been compromised by the first successful intercept-and-resend attack on a commercial bidirectional QKD system.

Abstract

from arXiv · show

Unconditional security proofs of various quantum key distribution (QKD) protocols are built on idealized assumptions. One key assumption is: the sender (Alice) can prepare the required quantum states without errors. However, such an assumption may be violated in a practical QKD system. In this paper, we experimentally demonstrate a technically feasible "intercept-and-resend" attack that exploits such a security loophole in a commercial "plug & play" QKD system. The resulting quantum bit error rate is 19.7%, which is below the proven secure bound of 20.0% for the BB84 protocol. The attack we utilize is the phase-remapping attack (C.-H. F. Fung, et al., Phys. Rev. A, 75, 32314, 2007) proposed by our group.

1 Center for Quantum Information and Quantum Control (CQIQC),

This section identifies the Center for Quantum Information and Quantum Control and lists the paper’s PACS classifications.

  • The paper is classified under PACS numbers 03.67.Dd and 03.67.Hk.

I. INTRODUCTION

The introduction frames practical imperfections as security loopholes in QKD and presents an experimental phase-remapping attack against a commercial system. The attack obtains full sifted-key information while producing a QBER below BB84’s proven security bound.

  • A key QKD assumption is that Alice encodes her signals correctly, but practical imperfections may violate it.
  • The paper experimentally investigates phase-remapping attacks in a commercial QKD system.
  • The phase-remapping attack is an intercept-and-resend attack that allows Eve to gain full information of the sifted keys.
  • The practical phase-remapping process is more complicated than the theoretical model, motivating modified type 1 and type 2 attacks.
  • 19.7% QBER is below BB84’s proven security bound of 20.0%, while Eve gains full information.
  • The reported result compromises the security of the commercial QKD system.

II. PHASE-REMAPPING ATTACK

The phase-remapping attack exploits finite phase-modulator response by shifting pulse timing, thereby changing Alice’s encoded phases. Eve uses the remapped states for selective discrimination and resend operations.

  • Finite phase-modulator response allows Eve to change the encoded phase by altering the time difference between reference and signal pulses.
  • A time shift from t0 to t1 changes the signal pulse phase from φ0 to φ1.
  • The original phases {0, π/2, π, 3π/2} are remapped to {0, φ1, φ1 + φ2, φ1 + φ2 + φ3}.
  • Unlike the simplifying theoretical model, the practical attack uses a more general setting in which φi depend on Eve’s time displacement and the actual modulation system.
  • Eve’s practical strategy includes intercepting Bob’s strong pulse, sending a time-shifted pulse to Alice, and selectively distinguishing remapped states.
  • Eve performs interference measurements and resends a standard BB84 state when detector 1 clicks, otherwise discarding the pulse.
  • After the attack, the error probabilities for the four states are {0, 1/2, 1, 1/2}.

“PLUG & PLAY ” QKD SYSTEM

The commercial ID-500 plug-and-play QKD system uses reference-pulse triggering and phase modulation, creating timing and polarization conditions exploitable by practical phase-remapping attacks.

  • System and implementation: The experiment implemented a phase-remapping attack in a commercial ID-500 plug-and-play QKD system.Eve used a setup based on Bob’s system, including a variable optical delay line and polarization controller.
  • System and implementation: Alice uses the reference pulse as a trigger, while Eve can change the signal-pulse timing because Alice does not monitor its arrival time.The internal reference-to-signal delay is fixed by Alice’s system, but Eve can control another delay without detection.
  • Attack mechanism: The approximately 8 ns modulation rise time and approximately 500 ps laser-pulse width let Eve place a pulse on the rising edge for partial phase modulation.This timing mismatch enables the phase-remapping loophole in the specific QKD design.
  • Attack mechanism: Eve combines variable timing shifts with polarization control to realize two practical attack types that remap phases into a low-QBER range.Type 1 uses the rising edge and aligned polarization; Type 2 uses the plateau region and orthogonal polarization.
  • Attack mechanism: Type 2 remains effective even with a phase modulator having strictly sharp rising and falling edges, whereas Type 1 can become detectable when pulse and rise widths are comparable.Under that condition, Type 1 causes an unreasonably high QBER.

IV. EXPERIMENT RESULTS

The experiment characterizes phase remapping in a commercial QKD system and measures its resulting phase errors and QBER. Combining attack strategies yields QBER below the 20.0% BB84 security bound, compromising the practical system.

  • Experimental setup: The experiment used a commercial ID-500 QKD system with weak coherent pulses, meter-scale transmission, and 10 million measurements per state.Experimental parameters included detector characteristics, optical delay lines, and source settings.
  • Attack implementation: Eve remapped phases by introducing Base0, Base1, or Base2 phase shifts on the reference pulse before measuring each state.The remapped phases were associated with Alice’s BB84 phases and measured detector counts.
  • Phase measurements: 21.1°±1.1°, 16.7°±1.1°, and 14.9°±1.1° were measured for φ1, φ2, and φ3 with Variable Optical Delay Line A.For Delay Line B, the corresponding values were 23.9°±1.2°, 12°±1.2°, and 10.4°±1.2°.
  • Scope and limitation: The observed phase fluctuations are mainly attributed to imperfections in the experimental QKD system.The security proofs’ assumption that Alice prepares states correctly was violated, so they cannot be directly applied to practical QKD systems.
  • Error sources: Imperfect interference produced residual error counts, including about 600–700 counts on Det1 when Eve used Base0 to measure state {01}.The authors attribute these counts mostly to imperfect interference between the signal and reference pulses.
  • Combined attacks: Combining two attack types while balancing Bob’s received bit distribution allows Eve’s overall QBER to remain low.The paper also notes that phase remapping can be combined with a faked-state attack to enhance its power.

V. CONCLUSION

The conclusion shows that practical QKD implementations must experimentally verify state preparation and quantify imperfections, because a technologically feasible attack compromised a commercial single-photon BB84 system. It also identifies implementation-specific scope and recommends testable assumptions and verification throughout the protocol.

  • Conclusion: Alice must experimentally verify that she applies the correct modulations to her states in a practical QKD system.The paper suggests splitting part of each strong modulated signal and checking it locally with a classical detector.
  • Conclusion: A local measurement can directly verify whether Alice performed the correct modulation, supporting unconditional security in practical QKD systems.The proposed check uses a beam splitter and a classical detector such as a power meter.
  • Conclusion: QKD security should use testable assumptions and verify the correctness of each implementation step, rather than rely only on idealized preparation assumptions.The conclusion emphasizes verification of Alice’s encoding and, more generally, every protocol-implementation step.
  • Conclusion: Eve may combine phase-remapping and time-shift attacks to exploit imperfections in Alice’s encoding and Bob’s detection, potentially reducing QBER further.The paper states that imperfections cannot be completely removed, but can be quantified and incorporated into security proofs.
  • Conclusion: The demonstration used a specific implementation, although that implementation is widely used in commercial QKD systems.The conclusion therefore presents the result within an implementation-specific scope while highlighting broader verification concerns.
Loading 1005.2376v1…