Source-linked AI summary
Full-field implementation of a perfect eavesdropper on a quantum cryptography system
Ilja Gerhardt, Qin Liu, Antia Lamas-Linares, Johannes Skaar, Christian Kurtsiefer, Vadim Makarov
TL;DR
The paper addresses whether a practical imperfection in QKD can compromise an established connection without detection. It implements a complete faked-state attack and finds that Eve’s sifted key matches Bob’s while monitored rates remain unchanged.
Problem
The paper examines the gap between QKD’s theoretical description and practical systems, where technological imperfections may remain exploitable.
Method
The authors implement a faked-state attack using detector blinding and controlled optical pulses to force Bob’s outcomes, then reconstruct the key from public communication.
Results
Eve’s sifted key was identical to Bob’s in all eavesdropped sessions, while key rates remained unchanged and detector clicks approached 100%.
Takeaways & Limitations
The demonstration shows that a technological imperfection in a QKD system can be fully exploited with off-the-shelf components.
Takeaways & Limitations
The demonstrated weakness can be closed by suitable countermeasures, although monitoring and implementation of those measures may be impractical.
Abstract
from arXiv · showhide
Quantum key distribution (QKD) allows two remote parties to grow a shared secret key. Its security is founded on the principles of quantum mechanics, but in reality it significantly relies on the physical implementation. Technological imperfections of QKD systems have been previously explored, but no attack on an established QKD connection has been realized so far. Here we show the first full-field implementation of a complete attack on a running QKD connection. An installed eavesdropper obtains the entire 'secret' key, while none of the parameters monitored by the legitimate parties indicate a security breach. This confirms that non-idealities in physical implementations of QKD can be fully practically exploitable, and must be given increased scrutiny if quantum cryptography is to become highly secure.
RESULTS · A. The faked-state attack
The experiment implements a faked-state attack in which Eve intercepts Alice’s quantum states and controls Bob’s detections to obtain the same raw and final secret key. The attack exploits detector blindability and controllability under strong illumination, using light to suppress ordinary clicks and create controlled detector responses.
- A. The faked-state attack: Eve intercepts and measures every state with a replica receiver, then uses a faked-state generator to force Bob’s bases and bits to match hers.She also records the unencrypted classical communication and repeats the parties’ post-processing to compute the final secret key.
- A. The faked-state attack: The attack requires full control of Bob’s detection outcomes, enabled here by exploiting single-photon-detector blindability and controllability under strong illumination.The targeted QKD system used passively quenched single-photon avalanche photodiodes.
- A. The faked-state attack: The installed attack spans four campus buildings, with Eve inserted midway along a 290 m fibre linking Alice and Bob.Alice generated polarization-entangled photon pairs, measured one photon locally, and sent the other to Bob.
- A. The faked-state attack: A detected single photon creates an avalanche whose current spike is processed by a comparator and pulse-shaper as a photon-arrival click.This describes the detector’s ordinary operating principle before strong illumination changes its response.
- A. The faked-state attack: A detector deadtime of ∼1 µs results from finite recharge; increased illumination prevents full recharge and progressively reduces avalanche size below the comparator threshold.Under sufficiently high illumination, the detector can no longer identify the event as a click.
- A. The faked-state attack: The custom-built detectors used an APD biased 15 V above breakdown, with avalanche current supplied by approximately 1.2 pF stray capacitance and sensed across a 100 Ω resistor.The detector circuit is driven by a voltage supply of approximately 220 V.
- A. The faked-state attack: High light levels can indefinitely blind Bob’s detectors, converting the APDs into classical photodiodes whose photocurrent is proportional to optical power.A strong pulse above threshold Pth produces a current spike that mimics a legitimate-photon signal.
B. Experimental implementation
The experiment implements a four-detector, four-state polarization-coded QKD attack in which Eve blinds detectors and selectively triggers any target detector. Her control produced clicks in the intended detector with virtually no line loss.
- B. Experimental implementation: The system uses four detectors, a four-state polarization-coded protocol, and passive basis choice.
- B. Experimental implementation: Eve blinds all detectors with continuous-wave circularly polarized light, then adds a linearly polarized pulse at peak power 2Pth to trigger a target detector.Four laser diodes aligned to vertical, horizontal, and ±45° polarizations let Eve target any of Bob’s detectors before executing the faked-state attack.
- B. Experimental implementation: 8,736,719 clicks were received by Eve during a 5 min session, and she resent an equal number of faked states to Bob.The polarizations were manually aligned to match Bob’s detector settings before characterizing control fidelity.
- B. Experimental implementation: 99.75% of resent faked states caused clicks in Bob, and those clicks were always produced in the intended detector.A 4 × 4 detector-click matrix recorded during a 5 min diagnostic session had no off-diagonal elements; the overall click rate was close to 100%.
C. QKD performance and key extraction
Eavesdropping left the monitored QKD rates unchanged, while Eve recovered a sifted key identical to Bob’s and could process it using Bob’s subsequent key-extraction steps.
- QKD performance: Eve’s installation did not alter the raw, sifted, or final secret key rates observed by Alice and Bob.Small average-rate differences reflected normal medium-term alignment fluctuations rather than eavesdropping.
- Key extraction: During eavesdropped sessions, Eve extracted Bob’s sifted key from her detector clicks and Alice–Bob’s recorded public communication.The protocol’s public time-tag exchange lets the parties synchronize detections and identify photon pairs.
- Key extraction: Eve’s sifted key was identical to Bob’s in all eavesdropped QKD sessions analyzed with the processing script.The script was run on recorded experimental data, with the script and sample available in Methods Section C.
- Key extraction: Because Eve had Bob’s sifted key, she could apply Bob’s error-correction and privacy-amplification processing to produce the secret key.Under realistic conditions, these steps reconcile differing sifted keys and complete the public Alice–Bob exchange.
DISCUSSION
The study demonstrates a complete, undetected attack on an established QKD system, showing that implementation imperfections can be fully exploited with off-the-shelf components. It also identifies countermeasures for the exploited weakness, including detecting blinding light and testing detector sensitivity.
- Countermeasures: The exploited weakness can be addressed by detecting incoming blinding light through watchdog detectors or APD electrical and thermal monitoring.These are proposed countermeasures for identifying the blinding light used in the attack.
- Countermeasures: Bob’s APD single-photon sensitivity can be tested randomly with a calibrated light source placed inside Bob.The passage presents this internal calibrated-source test as an additional countermeasure.
- Conclusion: The authors demonstrated a complete and undetected eavesdropping attack against an established QKD system.The conclusion states that the attack succeeded without detection by the legitimate parties.
- Conclusion: The demonstration shows that a technological imperfection in QKD can be fully exploited using off-the-shelf components.The authors note that potentially exploitable loopholes exist in both research and commercial QKD systems.
METHODS · A. Complete Eve’s setup
Eve’s setup used tailored optical pulses to force Bob’s target detector to click while suppressing clicks in the other detectors. A polarized pre-pulse improved detector selectivity, enabling 100% target-detector click probability without wrong-detector clicks during calibration.
- A. Complete Eve’s setup: A pulse with peak power Pth at Bob’s target detector caused it to click with 100% probability.Eve’s FSG was designed to keep the other detectors silent.
- A. Complete Eve’s setup: The intended condition was that a pulse of power Pth/2 never cause the two conjugate-basis detectors to click.This condition was not met by Bob’s actual polarization analyser.
- A. Complete Eve’s setup: One detector in Bob’s polarization analyser had significantly higher click thresholds than the other three.This detector imbalance prevented the initial control condition from holding.
- A. Complete Eve’s setup: For blinding power >1 µW, the click thresholds of all four detectors rose uniformly.The threshold behavior was observed while characterizing Bob’s detector response.
- A. Complete Eve’s setup: Eve’s improved control method added a polarized pre-pulse 100 ns before the main trigger pulse to dynamically increase blinding power at orthogonal-basis detectors.The pre-pulses were emitted by four additional laser diodes.
- A. Complete Eve’s setup: With the improved setup, clicks never occurred in a wrong detector, while calibration yielded 100% click probability in any target detector.Calibration used the same faked state sent at a fixed rate.
B. Jitter and insertion delay introduced by Eve
Eve’s insertion delays were equalized so Alice and Bob’s coincidence-time distributions remained indistinguishable from those without eavesdropping. The attack introduced a 212 ns overall delay, but photon-coincidence clock synchronization made it inconsequential; independently synchronized systems could require delay cancellation.
- Delay equalization: Eve’s four detection and Bob control channels initially differed in insertion delay by ≲1 ns, so the delays were equalized using time-delay circuits.This adjustment was necessary because Alice and Bob used a tight coincidence window to identify photon pairs.
- Delay equalization: Eve’s equalized insertion delays produced relative coincidence-time distributions indistinguishable from those without eavesdropping.The comparison is shown in Fig. 6.
- Overall insertion delay: 212 ns overall insertion delay had no consequence because Alice and Bob synchronized their clocks by photon coincidences, and propagation delay is not authenticated or part of QKD security.This synchronization method is common in QKD systems of this type.
- Overall insertion delay: If Alice and Bob synchronized independently, Eve could cancel the delay by shortening or bypassing fibre, including a radio-frequency link where signals travel ∼1.5 times faster than in fibre.These countermeasures would not apply to free-space line-of-sight QKD systems.
C. Raw experimental data and Eve’s key extraction software
The paper provides raw data and MATLAB software for reproducing Eve’s sifted-key extraction under realistic classical-channel access. Across four eavesdropped sessions, Eve’s extracted keys matched Bob’s with zero discrepancies.
- Experimental data: Four eavesdropped QKD sessions were conducted over 2 h, including a 5-min session yielding 393,323-bit sifted keys identical between Bob and Eve.The raw data and extraction script are provided in a 74 MiB archive, with 125 MiB minimum disk space including generated files.
- Extraction software: Eve’s extraction uses the MATLAB script eve key.m and supporting functions in scripts-matlab, tested under both Windows and Linux.Running the script generates the proclog.txt log file.
- Extraction conditions: Under realistic eavesdropping conditions, Eve accesses the public classical channel and her own computer, but not Bob’s or Alice’s computers.The script uses timing, basis-choice, and sifting-response data exchanged through the specified receive-file directories.
- Key verification: Zero discrepancies were reported when the script compared Eve’s and Bob’s sifted keys for all eavesdropped QKD sessions.Both sifted keys are also saved as ASCII files in the output directory data-produced-by-scripts.