Source-linked AI summary

Side-channel-free quantum key distribution

Samuel L. Braunstein, Stefano Pirandola

arXiv:1109.2330v3quant-ph

TL;DR

The paper addresses side-channel vulnerabilities arising from imperfect implementations and open quantum communication ports. It replaces real channels with virtual channels, uses quantum memories, and keeps detectors inside inaccessible private spaces. The resulting construction supports a lower bound on secret-key rate given by the entanglement-distillation rate over the distributed states.

  • Problem

    Quantum-security proofs assume inaccessible private spaces and perfect implementations, but implementation redundancies and open quantum communication ports can expose state-preparation or measurement information to side-channel attacks.

  • Method

    The scheme uses virtual channels, quantum memories, and an untrusted entanglement-swapper measurement so detectors remain inaccessible while private systems become correlated.

  • Results

    The construction makes port reflections reveal only reduced public-system states, containing no useful information about private systems or detector settings and outputs.

  • Takeaways & Limitations

    The scheme makes the notion of absolutely private spaces feasible by overcoming side-channel exposure at open quantum communication ports.

  • Takeaways & Limitations

    The security argument assumes that Alice’s measurement is a rank one POVM and relies on an idealized isolation technology for private spaces.

Abstract

from arXiv · show

Quantum key distribution (QKD) offers the promise of absolutely secure communications. However, proofs of absolute security often assume perfect implementation from theory to experiment. Thus, existing systems may be prone to insidious side-channel attacks that rely on flaws in experimental implementation. Here we replace all real channels with virtual channels in a QKD protocol, making the relevant detectors and settings inside private spaces inaccessible while simultaneously acting as a Hilbert space filter to eliminate side-channel attacks. By using a quantum memory we find that we are able to bound the secret-key rate below by the entanglement-distillation rate computed over the distributed states.

IN DEFENSE OF PRIVATE SPACES

The paper identifies open quantum communication ports as a remaining side-channel vulnerability and proposes virtual channels that keep private detectors inaccessible. The scheme uses quantum memories and untrusted measurements to create correlations while filtering information available through the ports.

  • Motivation: Side-channel attacks can exploit redundant implementation degrees of freedom and remain possible through quantum communication ports even when transmitted channels are protected.Attackers may send trojan systems through ports and infer state-preparation or measurement settings from reflections.
  • Proposed scheme: The proposed scheme replaces exposed detector alignments with a configuration in which detectors are not in line with the quantum communication ports.This is intended to prevent external parties from probing detector settings or readouts through parasite systems.
  • Protocol: Alice and Bob distribute public systems to an untrusted party, which measures them and communicates processed outcomes to activate correlations between their private systems.They can then measure the private systems to obtain correlated variables X and Y for secret-key extraction.
  • Security mechanism: In the scheme, Eve can retrieve only reduced states ρA′ and ρB′ from port reflections, which contain no useful information about private systems or detector settings and outputs.The private systems A and B remain inaccessible while public systems A′ and B′ are sent to the untrusted party.
  • Isolation procedure: A possible isolation procedure stores private system A in a quantum memory while sending A′ through a delay line, then opens the port only after separating the delay line.After repeated rounds, Alice performs a collective measurement on the stored systems, optionally preceded by entanglement distillation.

NOTATION AND BASIC FORMULAS

The notation embeds classical variables into quantum systems and defines the entropy and information quantities used throughout the analysis. These definitions connect quantum mutual information to Holevo and classical mutual information in the relevant classical-quantum cases.

  • Classical-quantum representation: A stochastic variable X={x,p(x)} encoded into states of system A can be represented as a classical-quantum state using an orthonormal basis for a dummy system X.The conditional state ρA|X denotes ρA(x) without specifying x.
  • Entropy and information: For a quantum system A, H(A) denotes its von Neumann entropy, while the entropy of an embedded stochastic variable X equals its Shannon entropy.The notation also introduces quantum mutual information and conditional quantum entropy.
  • Information identities: When computed on the corresponding classical-quantum state, I(A:X) equals the Holevo information of the ensemble, while I(X:Y) becomes classical mutual information.Conditional quantum mutual information is nonnegative by strong subadditivity.
  • Basic formulas: The chain rule decomposes I(A:BC) into I(A:B)+I(A:C|B), and information decreases along a Markov chain under data processing.The listed identities also cover invariance of Holevo information under added classical channels and conditional-information behavior.
  • Basic formulas: Interaction information I(X:Y:Z) can be positive, negative, or zero because conditional mutual information may be greater than, less than, or equal to mutual information.This quantity is defined as I(X:Y|Z)−I(X:Y).

PROOF OF THE THEOREM

The proof purifies the conditional mixed state by introducing an ancillary system assigned to Eve, then relates the resulting information terms to Alice and Bob’s conditional state. This identifies the relevant rate expression with conditional coherent information, under a rank-one measurement assumption.

  • Purification: Purification introduces an ancillary system ˜E assumed to be in Eve’s hands, making Eve’s global system E˜E.The purified conditional state is denoted ΦABE˜E|L′.
  • Purification: The purified conditional state ΦBE˜E|XL′ is obtained after measuring and discarding X from the purified scenario.The proof uses this reduced conditional state to compute the relevant rate.
  • Information decomposition: I(X : E˜E|L′) = I(X : E|L′) + γ, with γ ≥ 0, so purification can only increase the conditional Holevo information.The additional term is γ ≡ I(X : ˜E|EL′)Ψ.
  • Conditional entropies: Because the purified state is pure, H(E˜E|L′) equals H(AB|L′), allowing the rate expression to be evaluated from ρAB|L′.The state ρAB|L′ is obtained by tracing E˜E out of the purified state.
  • Conditional entropies: The resulting expression is recognized as the conditional coherent information associated with Alice and Bob’s conditional state ρAB|L′.The proof then sets the corresponding rate expression to this conditional coherent information.
  • Measurement assumption: Assuming Alice’s measurement is a rank-one POVM makes ΦBE˜E|XL′ pure and yields R′′ = I(A⟩B|L′).This uses H(E˜E|XL′)Φ = H(B|XL′)Φ.
Loading 1109.2330v3…