Source-linked AI summary

Quantum-Secure Authentication with a Classical Key

Sebastianus A. Goorden, Marcel Horstmann, Allard P. Mosk, Boris Škorić, Pepijn W. H. Pinkse

arXiv:1303.0142v3quant-ph

TL;DR

Classical challenge-response authentication of physical keys remains susceptible to digital emulation attacks. The paper demonstrates Quantum-Secure Authentication using high-dimensional optical challenges and weak coherent light, reporting negligible false-decision rates after repeated verification while arguing that emulation requires technologically infeasible optical devices.

  • Problem

    Classical challenge-response protocols for physical keys are generally susceptible to emulation attacks.

  • Method

    QSA uses high-dimensional optical challenges and weak coherent pulses to authenticate a classical physical key through quantum-secure readout.

  • Results

    After 20 repetitions, both false accept and false reject probabilities are of order 10-9.

  • Takeaways & Limitations

    QSA provides authentication without secret information and is presented as secure against digital emulation because adversaries cannot accurately estimate the quantum challenge.

Abstract

from arXiv · show

Authentication provides the trust people need to engage in transactions. The advent of physical keys that are impossible to copy promises to revolutionize this field. Up to now, such keys have been verified by classical challenge-response protocols. Such protocols are in general susceptible to emulation attacks. Here we demonstrate Quantum-Secure Authentication ("QSA") of an unclonable classical physical key in a way that is inherently secure by virtue of quantum-physical principles. Our quantum-secure authentication operates in the limit of a large number of channels, represented by the more than thousand degrees of freedom of an optical wavefront shaped with a spatial light modulator. This allows us to reach quantum security with weak coherent pulses of light containing dozens of photons, too few for an adversary to determine their complex spatial shapes, thereby rigorously preventing emulation.

F = FOK /(S+1), (2)

The verification discriminates a correct key from an optimal digital-emulation attack using photon-count thresholds. Repeating measurements with different challenges drives false-decision probabilities down to negligible levels.

  • Security analysis: With S = 4, an optimal digital-emulation attack produces a Poissonian photon-count distribution with mean 0.86.The verification compares this attack distribution with the correct-key response.
  • Verification performance: A threshold of 3 or more photodetections yields a 9% measured false reject ratio and a 1.7×10-4 % false accept ratio for random challenges.The theoretical maximum false accept probability for digital emulation is 6%.
  • Repeated verification: After 10 repetitions, false accept and false reject probabilities are of order 10-4.Each repetition uses a different challenge and its corresponding SLM2 setting, and photon counts are combined before thresholding.
  • Repeated verification: After 20 repetitions, both false accept and false reject probabilities are of order 10-9.The authors therefore report that false decision rates can be made negligible with a small number of repetitions.
  • Implementation: The implementation’s readout takes about 100 ms, while faster micromirror-based SLMs could reduce 20-repetition authentication below 1 ms.One-time key enrolment takes on the order of a second.

Appendix Shaping the challenge and response wavefronts

The apparatus uses two halves of one phase-only spatial light modulator to shape challenge wavefronts and decode response wavefronts. The optical system samples thousands of spatial segments and flattens the measured response phase.

  • Hardware: SLM1 and SLM2 are two halves of the same reflective phase-only spatial light modulator used for challenge shaping and response decoding.The device is a Holoeye HEO 1080P modulator.
  • Challenge shaping: SLM1 uses 50×50 segments of 16×16 pixels to shape challenge wavefronts, with 1963 effectively illuminated segments.The cylindrical beams leave the corners of the nominal 50×50 area unilluminated.
  • Response measurement: The response is collected through a 0.95 NA 63x microscope objective and measured in 130x130 segments by phase-shifting interferometry.The measured response comprises the phases of corresponding wavefront segments.
  • Response decoding: SLM2 uses the measured response data to flatten its phase by adding the conjugate response phase.The response data spans 800x800 pixels on SLM2.

Cryptographic context

The cryptographic context contrasts QSA with established physical, mathematical, and quantum methods. QSA is presented as experimentally demonstrated and unconditionally secure against digital emulation, while other approaches carry different assumptions or practical constraints.

  • Comparison framework: Table T1 organizes cryptographic methods by their security assumptions and status across physical and mathematical categories.The table is an overview of important cryptographic methods, not only authentication methods.
  • Mathematical methods: Mathematical methods rely on assumptions including difficult decoding, discrete logarithms, factoring, or infeasible quantum computers.The table also records differing practical assessments, including methods considered less practical than other asymmetric cryptography.
  • Physical methods: Classical physical methods rely on assumptions such as difficult lock inference or physical unclonability, with some entries described as experimentally demonstrated.The listed statuses distinguish proposed, commercially available, and experimentally demonstrated methods.
  • QSA: QSA is described as new and proven unconditionally secure against digital emulation.The corresponding table entry identifies this status for QSA.
  • Practical limitations: Lossless implementation of high-dimensional arbitrary unitaries is infeasible.This is listed as a limitation in the cryptographic overview.
  • Quantum and classical alternatives: Unconditionally secure quantum-key methods require long-lived quantum memory not yet achieved and are infeasible with current technology.Unconditionally secure classical authentication procedures typically require symmetric secret-key distribution and storage between authenticating parties.

Security analysis

QSA addresses digital emulation and physical-copy attacks through quantum-limited challenge estimation and the large optical complexity of the PUF. The security analysis combines attack-specific rejection arguments with experimentally tested scaling.

  • Challenge-estimation attacks: Digital emulation attacks fail because an adversary measuring a challenge cannot estimate the response accurately when the challenge contains fewer quanta than modes.The scheme is stated to be secure against all challenge-estimation attacks for n < K quanta in the same state.
  • Challenge-estimation attacks: At S = 4, the attacker’s expected 0.8 detector clicks remain below the acceptance threshold of 3, while the correct challenge yields 4.3 expected photons.The best estimate has expected squared inner product 1/(S+1) = 1/5 with the correct challenge.
  • Experimental scaling: The measured challenge-response scaling follows F = 0.6|C1*·C0|^2, linking focused-light fraction to the squared overlap between tested and optimal wavefronts.The experiment parameterizes wavefronts by K-dimensional complex vectors and tests their proximity through an inner product.
  • Physical emulation: Physical emulation requires reproducing a nonlocal reflection matrix, whereas a single scattering surface has a local reflection matrix.The PUF connects spatially separated surface points by up to 5 µm and exhibits about 10^3 speckles.
  • Physical emulation: A passive K-mode emulator requires K^2 connecting elements, making scaling to 10^5 modes imply about 10^10 optical elements and roughly 20000 dB loss.The stated estimate also places the network over an area of approximately 1 m^2.
  • Quantum emulation: Quantum-computer emulation would require arbitrary low-loss unitary operations on K-dimensional optical states, at least as difficult as the passive emulator.The paper identifies this requirement as infeasible under the same technological arguments used for passive optical emulation.

Repetition for exponential security gain

Repeated authentication rounds reduce false decisions rapidly. The calculated error probability is already about 10^-4 after 10 repetitions at moderate security, and decreases exponentially with further repetitions.

  • Error reduction: 10^-4 is the approximate erroneous-decision probability after 10 repetitions at moderate S.The threshold is selected between the true-PUF and optimal-attack photon distributions, making false-positive and false-negative probabilities approximately equally small.
  • Error reduction: For larger numbers of repetitions, the probability of an incorrect decision decreases exponentially and can be made arbitrarily small.At high S and fixed K, lower photon number can require more repetitions because the threshold is restricted to an integer photon count.
  • Error reduction: False-positive and false-negative probabilities are evaluated as functions of S and repetition count while K = 1062 remains fixed.The calculation varies n and chooses the optimal threshold for each point.
Loading 1303.0142v3…