Source-linked AI summary

After-gate attack on a quantum cryptosystem

Carlos Wiechers, Lars Lydersen, Christoffer Wittmann, Dominique Elser, Johannes Skaar, Christoph Marquardt, Vadim Makarov, Gerd Leuchs

arXiv:1009.2683v1quant-ph

TL;DR

The paper asks whether practical gated-detector behavior creates a QKD vulnerability. It uses bright faked states timed outside the activation window to control Clavis2 detections, finding that the attack is feasible despite afterpulse-induced QBER under identified conditions.

  • Problem

    Practical deviations in QKD implementations can create side channels that are not covered by idealized security assumptions.

  • Method

    The study experimentally characterizes Clavis2 detector thresholds and models attack-induced afterpulsing and QBER for bright faked states sent outside the gate.

  • Results

    Bright after-gate faked states can generate Bob’s measurement results with only a slight QBER increase, and simulations identify vulnerable Clavis2 parameter regimes.

  • Takeaways & Limitations

    The attack can apply to decoy-state protocols because photon statistics are maintained, while detector timing and dead-time handling provide practical countermeasure targets.

  • Takeaways & Limitations

    Afterpulses from carrier traps can generate uncontrollable clicks that contribute to QBER, and the attack’s feasibility depends on operating conditions such as repetition rate.

Abstract

from arXiv · show

We present a method to control the detection events in quantum key distribution systems that use gated single-photon detectors. We employ bright pulses as faked states, timed to arrive at the avalanche photodiodes outside the activation time. The attack can remain unnoticed, since the faked states do not increase the error rate per se. This allows for an intercept-resend attack, where an eavesdropper transfers her detection events to the legitimate receiver without causing any errors. As a side effect, afterpulses, originating from accumulated charge carriers in the detectors, increase the error rate. We have experimentally tested detectors of the system id3110 (Clavis2) from ID Quantique. We identify the parameter regime in which the attack is feasible despite the side effect. Furthermore, we outline how simple modifications in the implementation can make the device immune to this attack.

1. Introduction

The paper frames practical deviations in QKD implementations as potential side channels and investigates whether bright, timed faked states can control Clavis2 detector events with little QBER increase.

  • Practical deviations from ideal QKD implementations can create side channels that require consideration in security proofs.
  • Commercial QKD systems may be vulnerable to nonconforming light, detector control, time-shifted pulses, or detector blinding.
  • The study targets ID Quantique’s Clavis2 plug-and-play system, which encodes quantum states as relative phases of two pulses.
  • Bright faked states sent outside detector activation time can generate Bob-module measurement results with only a slight QBER increase when side effects are considered.

2. Intercept-resend attack using faked states

Faked-state intercept-resend attacks exploit detector behavior so Bob records events mainly when Eve’s basis matches his, avoiding the errors expected from standard intercept-resend attacks.

  • Eve’s faked states are designed to produce a detection event only when Eve’s and Bob’s bases match.
  • After basis sifting, the retained bits can have identical values and basis choices for Alice, Eve, and Bob, generating no errors.
  • The attack applies to BB84, SARG04, and decoy methods, with an extra 3 dB loss that can be compensated by Eve’s better detector efficiency and loss-free line.

3. Detectors in Clavis2

Clavis2 uses gated Geiger-mode APDs whose behavior outside the gate becomes approximately linear with incident optical power, enabling bright-pulse detector control.

  • The analysis focuses on gated avalanche photodiodes operated in Geiger mode, as used in many QKD systems and commercial realizations.
  • During gates, APDs are biased above breakdown so a photon-triggered avalanche produces a current that can register a click after crossing a threshold.
  • Clavis2 applies detector gates with a 200 ns period using TTL signals superimposed on high-voltage bias.
  • Outside the gate, each APD is below breakdown and its current is approximately proportional to incident optical power, behaving like a photodiode followed by a comparator.

4. Description of loopholes in the system

Clavis2 contains exploitable timing and threshold behavior: after-gate bright pulses can control clicks, while acceptance during dead time can extend or reset detector dead time.

  • 4. Description of loopholes in the system: Bright faked-state pulses produce deterministic clicks for matching bases but remain undetected for mismatched bases because power is split between detectors.
  • 4. Description of loopholes in the system: The standard intercept-resend strategy would cause a 25% QBER, whereas detector-controlled faked states can avoid those mismatched-basis detections.
  • 4.1. Linear mode APDs: A feasible after-gate attack window spans 4.5 ns to 10 ns, with the largest margin at 7.5 ns.
  • 4.1. Linear mode APDs: At 7.5 ns after the gate, 587 µW causes clicks in both detectors while 293.5 µW causes no detector click.
  • 4.2. Faked states applied during the dead time: Bright pulses arriving during dead time are accepted as valid detections and reset the dead time, extending the effective dead time.

5. Characterization of afterpulsing side effect

Bright pulses populate detector carrier traps and produce delayed afterpulses, creating random clicks that can raise QBER. Measurements and Monte Carlo modeling quantify this side effect and identify operating conditions where the attack remains feasible.

  • Afterpulses arise because bright pulses populate carrier traps even without registered detections, while no dead time is applied in that case.Released carriers can later trigger uncontrollable clicks that contribute to QBER.
  • 287.5 µW pulses applied to both detectors were used to characterize cumulative afterpulse probability across successive gates.The experiment measured clicks after directly injecting laser pulses into the beamsplitter input.
  • 84 % cumulative probability of a random click was reached after 50 gates, potentially raising QBER enough to jeopardize the attack.The pulse itself did not cause an immediate click, but frequently caused an afterpulse in following gates.
  • Because frames contain 1075 pulses, applying the attack near frame end reduces random-afterpulse risk; requiring only one detection every second frame completely compromises security.Applicability may also depend on system parameters such as Bob’s operating frequency.
  • The afterpulse probability was modeled with a double exponential decay and fitted through Monte Carlo simulation using detector-specific trap parameters.The fitted parameters reproduced the measurement data shown in Figure 5 and agreed with earlier APD data.

6. Simulations of after-gate attack and QBER estimation

The simulations incorporate experimentally determined detector behavior and afterpulsing to estimate when after-gate attacks remain feasible. Attacking during dead time can overcome afterpulse-related QBER under favorable conditions, including realistic eavesdropper performance.

  • Simulation model: The Monte Carlo simulation models BB84 attacks with experimentally determined detector parameters, including afterpulsing, dark counts, transmittance, efficiency, and dead time.The simulated detector parameters include T_B = 0.412, η_B = 0.1, and τ_dead = 10 µs.
  • Afterpulse model: Half-power bright pulses are especially important because they generate carriers without triggering the detector dead time.This carrier generation increases subsequent afterpulse probabilities and contributes to QBER.
  • Strategy with dead time: Attacking only the last χ of N = 1075 gates preserves the raw key rate while concentrating trapped carriers near the frame end.The strategy also uses short burst memory and waits through the detector dead time after the attack.
  • Strategy with dead time: At a 5 MHz gate repetition rate, increased afterpulse probability prevents the attack from compromising Clavis2 when Bob rejects clicks during dead time.The simulation indicates compromise for gate frequencies below about 1 MHz or for a more tolerant security proof applicable to single-photon systems.
  • Strategy without dead time: Without rejecting dead-time clicks, the advanced attack is feasible at high transmittance, including for an implementable eavesdropper, while maintaining photon statistics.During dead time, repeated attack events can prolong the detector dead time and suppress afterpulse effects.

7. Countermeasures

The attacks leave detectable timing fingerprints, and countermeasures exploit these patterns or directly distinguish bright pulses from valid single-photon detections.

  • Timing checks: Bob can search for detection events spaced more closely than the 10 µs detector dead time.Rejecting detections during dead time also restricts the attack to lower frequencies.
  • Timing resolution: Resolving detection times inside versus outside the single-photon-sensitive gate region provides complete protection against the presented attacks.This is difficult because avalanche build-up jitter is about as long as the gate itself.
  • Optical monitoring: A watchdog detector at Bob’s input can detect bright faked states, but it must not itself be an avalanche detector.This countermeasure is effective only against bright faked states.

8. Conclusions

The study demonstrates control of Clavis2 gated detectors with bright after-gate pulses, while identifying afterpulsing and dead-time handling as the conditions determining practical security. Countermeasures were implemented after the loophole was reported.

  • Conclusion: Bright laser pulses arriving after the gate can control the gated detectors of the commercial Clavis2 QKD system.The attack operates during the detectors’ linear mode.
  • Conclusion: Afterpulsing raises QBER and protects against a straightforward faked-state attack, but accepting and resetting dead time enables a successful attack in simulation.The attack can also be combined with detector blinding while using weaker optical power than the blinding attack.
  • Implementation: ID Quantique was notified of the loophole before manuscript submission and implemented countermeasures.
Loading 1009.2683v1…