Source-linked AI summary
Device calibration impacts security of quantum key distribution
Nitin Jain, Christoffer Wittmann, Lars Lydersen, Carlos Wiechers, Dominique Elser, Christoph Marquardt, Vadim Makarov, Gerd Leuchs
TL;DR
The paper asks whether channel characterization and hardware calibration, largely absent from QKD security assumptions, can create exploitable vulnerabilities. It deceives a commercial system’s line-length calibration to induce detector-efficiency mismatch, then evaluates an optimized faked-state attack that keeps detection behavior and QBER within acceptance conditions. The experiment and analysis show that this strategy can compromise security over a broad range of expected channel transmissions.
Problem
QKD security analyses have not incorporated channel characterization and hardware calibration, although careless calibration can strengthen or create eavesdropping opportunities.
Method
The paper deceives Clavis2’s line-length measurement to induce temporal detector-efficiency mismatch, then models an optimized faked-state attack using coherent states, dark counts, and double clicks.
Results
For T > 0.25, Eve keeps detection rates within 5% of expected values and QBER below 7%, breaking the system’s security.
Takeaways & Limitations
Calibration and channel-characterization routines in practical gated-APD QKD systems require careful implementation to avoid inadvertent backdoors.
Takeaways & Limitations
The time-shift attack applies only when a naturally occurring mismatch exceeds a threshold, observed in 4% of instances, and Eve cannot control or learn its value.
Abstract
from arXiv · showhide
Characterizing the physical channel and calibrating the cryptosystem hardware are prerequisites for establishing a quantum channel for quantum key distribution (QKD). Moreover, an inappropriately implemented calibration routine can open a fatal security loophole. We propose and experimentally demonstrate a method to induce a large temporal detector efficiency mismatch in a commercial QKD system by deceiving a channel length calibration routine. We then devise an optimal and realistic strategy using faked states to break the security of the cryptosystem. A fix for this loophole is also suggested.
Device calibration impacts security of quantum key distribution: Technical appendix
The appendix describes a proof-of-principle implementation that deceives Clavis2’s line-length calibration by modifying Alice’s module and synchronizing phase modulation with the optical pulses. It also explains how detector-efficiency curves are measured and clarifies the implementation’s scope.
- Implementation: The phase modulator is placed before the 23.5 km delay loops, while the original onboard pulser is disconnected.The trigger conditioner permits triggering from short-arm pulses but prevents triggering from long-arm pulses.
- Implementation: Eve’s manipulated Alice module, mAlice, uses an electronic tap and conditioned trigger circuit to drive a pulse-and-delay generator during line-length measurement.The generator drives the phase modulator in mAlice.
- Calibration deception: During calibration, Bob’s phase setting is changed to ϕBob = 0, allowing Eve’s pulse-centered modulation to switch from 0 to Vπ.This firmware change relaxes the required modulation waveform compared with the Letter’s original scheme.
- Calibration deception: Eve scans the pulse-generator delay in 5 ps steps until interference visibility reaches zero, then uses that delay to induce the detector mismatch.The modulation edge is synchronized to the optical-pulse center.
- Scope: The mAlice apparatus demonstrates mismatch induction during line-length measurement only and is distinct from the intercept and resend modules used for the later faked-state attack.Eve can modify or replace Bob’s pulses to control the induced mismatch.
- Efficiency measurement: Detection efficiencies are estimated by scanning detector gates in 20 ps steps with an external laser and subtracting dark-count rates from averaged click probabilities.The external optical pulses have an approximate 200 ps width.