Source-linked AI summary

Device calibration impacts security of quantum key distribution

Nitin Jain, Christoffer Wittmann, Lars Lydersen, Carlos Wiechers, Dominique Elser, Christoph Marquardt, Vadim Makarov, Gerd Leuchs

arXiv:1103.2327v4quant-ph

TL;DR

The paper asks whether channel characterization and hardware calibration, largely absent from QKD security assumptions, can create exploitable vulnerabilities. It deceives a commercial system’s line-length calibration to induce detector-efficiency mismatch, then evaluates an optimized faked-state attack that keeps detection behavior and QBER within acceptance conditions. The experiment and analysis show that this strategy can compromise security over a broad range of expected channel transmissions.

  • Problem

    QKD security analyses have not incorporated channel characterization and hardware calibration, although careless calibration can strengthen or create eavesdropping opportunities.

  • Method

    The paper deceives Clavis2’s line-length measurement to induce temporal detector-efficiency mismatch, then models an optimized faked-state attack using coherent states, dark counts, and double clicks.

  • Results

    For T > 0.25, Eve keeps detection rates within 5% of expected values and QBER below 7%, breaking the system’s security.

  • Takeaways & Limitations

    Calibration and channel-characterization routines in practical gated-APD QKD systems require careful implementation to avoid inadvertent backdoors.

  • Takeaways & Limitations

    The time-shift attack applies only when a naturally occurring mismatch exceeds a threshold, observed in 4% of instances, and Eve cannot control or learn its value.

Abstract

from arXiv · show

Characterizing the physical channel and calibrating the cryptosystem hardware are prerequisites for establishing a quantum channel for quantum key distribution (QKD). Moreover, an inappropriately implemented calibration routine can open a fatal security loophole. We propose and experimentally demonstrate a method to induce a large temporal detector efficiency mismatch in a commercial QKD system by deceiving a channel length calibration routine. We then devise an optimal and realistic strategy using faked states to break the security of the cryptosystem. A fix for this loophole is also suggested.

Device calibration impacts security of quantum key distribution: Technical appendix

The appendix describes a proof-of-principle implementation that deceives Clavis2’s line-length calibration by modifying Alice’s module and synchronizing phase modulation with the optical pulses. It also explains how detector-efficiency curves are measured and clarifies the implementation’s scope.

  • Implementation: The phase modulator is placed before the 23.5 km delay loops, while the original onboard pulser is disconnected.The trigger conditioner permits triggering from short-arm pulses but prevents triggering from long-arm pulses.
  • Implementation: Eve’s manipulated Alice module, mAlice, uses an electronic tap and conditioned trigger circuit to drive a pulse-and-delay generator during line-length measurement.The generator drives the phase modulator in mAlice.
  • Calibration deception: During calibration, Bob’s phase setting is changed to ϕBob = 0, allowing Eve’s pulse-centered modulation to switch from 0 to Vπ.This firmware change relaxes the required modulation waveform compared with the Letter’s original scheme.
  • Calibration deception: Eve scans the pulse-generator delay in 5 ps steps until interference visibility reaches zero, then uses that delay to induce the detector mismatch.The modulation edge is synchronized to the optical-pulse center.
  • Scope: The mAlice apparatus demonstrates mismatch induction during line-length measurement only and is distinct from the intercept and resend modules used for the later faked-state attack.Eve can modify or replace Bob’s pulses to control the induced mismatch.
  • Efficiency measurement: Detection efficiencies are estimated by scanning detector gates in 20 ps steps with an external laser and subtracting dark-count rates from averaged click probabilities.The external optical pulses have an approximate 200 ps width.
Loading 1103.2327v4…