Source-linked AI summary

Preventing Calibration Attacks on the Local Oscillator in Continuous-Variable Quantum Key Distribution

Paul Jouguet, Sébastien Kunz-Jacques, Eleni Diamanti

arXiv:1304.7024v2quant-ph

TL;DR

This paper examines a calibration loophole in continuous-variable QKD, where manipulating local oscillator pulses alters clock pulses and biases shot-noise estimation. It characterizes the attack, shows that it can enable intercept-resend attacks without detection, and evaluates real-time shot-noise measurement as a countermeasure.

  • Problem

    Practical continuous-variable QKD requires secure calibration procedures, but the link between local oscillator calibration and clock generation creates a potential security loophole.

  • Method

    The paper analyzes and experimentally investigates manipulation of local oscillator pulses, its effects on clock generation and parameter estimation, and real-time shot-noise measurement countermeasures.

  • Results

    The attack can bias shot-noise estimation, conceal intercept-resend noise, and make Alice and Bob establish a key despite introduced noise above the entanglement-breaking limit.

  • Takeaways & Limitations

    Preventing the attack requires real-time shot-noise measurement, using randomly attenuated signal pulses or an additional homodyne detector.

Abstract

from arXiv · show

Establishing an information-theoretic secret key between two parties using a quantum key distribution (QKD) system is only possible when an accurate characterization of the quantum channel and proper device calibration routines are combined. Indeed, security loopholes due to inappropriate calibration routines have been shown for discrete-variable QKD. Here, we propose and provide experimental evidence of an attack targeting the local oscillator calibration routine of a continuous-variable QKD system. The attack consists in manipulating the classical local oscillator pulses during the QKD run in order to modify the clock pulses used at the detection stage. This allows the eavesdropper to bias the shot noise estimation usually performed using a calibrated relationship. This loophole can be used to perform successfully an intercept-resend attack. We characterize the loophole and suggest possible countermeasures.

I. INTRODUCTION

QKD security depends on accurate channel characterization and implementation assumptions, yet practical device imperfections can expose attacks. This paper focuses on a calibration loophole in continuous-variable QKD involving the local oscillator and clock generation.

  • QKD can detect eavesdropping because disturbances alter transmitted quantum states and Alice and Bob’s correlated data.
  • Practical deviations from the theoretical QKD model can be exploited by an eavesdropper.
  • Discrete-variable QKD has faced attacks exploiting detector imperfections, calibration procedures, illumination, timing, phase, and optical components.
  • Continuous-variable QKD attacks often manipulate the local oscillator, the classical phase reference sent with the quantum signal for coherent detection.
  • The paper identifies a calibration attack arising from the link between local-oscillator calibration and clock generation in Gaussian-modulated coherent-state systems using homodyne detection.

II. SECURITY ASSUMPTIONS AND CALIBRATION TECHNIQUES

CVQKD implementations commonly assume the local oscillator is not manipulated, while calibration links its measured power to shot noise. Because the same photodiode supports clocking and power measurement, modifying the local-oscillator pulse can alter detection timing and invalidate that relationship.

  • CVQKD security designs commonly assume that an eavesdropper cannot manipulate the local oscillator.Because it is an intense classical signal, it can be measured, regenerated, or amplified without additional disturbance.
  • Current security proofs do not explicitly include the local oscillator, although shot-noise knowledge is required because key-rate quantities use shot-noise units.
  • Bob’s entrance PIN photodiode generates both the clock and a signal proportional to local-oscillator power.
  • A secure pre-run calibration establishes a linear relation between shot-noise variance and local-oscillator power for use during QKD.During the run, Bob measures local-oscillator intensity over a period intended to match the homodyne integration window.
  • After a 100 ns integration period, capacitor discharge and measurement timing make homodyne variance depend on when the signal is sampled.
  • An eavesdropper can modify the local-oscillator signal so the clock trigger is altered, creating the calibration loophole examined in the paper.

III. DESCRIPTION OF THE LOCAL OSCILLATOR CALIBRATION ATTACK

The attack reshapes selected local-oscillator pulses to delay homodyne triggering, changing Bob’s measured variance without changing the calibrated shot-noise estimate. Combined with partial intercept-resend, this can conceal injected noise and enable key establishment.

  • Attenuating the beginning of a local-oscillator pulse delays the trigger and changes the homodyne measurement timing.
  • A 10 ns trigger delay produces a different linear relation between homodyne-measurement variance and local-oscillator power.
  • The proposed attack is practical with current technology and does not require a quantum memory.
  • Eve attenuates a fraction ν of local-oscillator pulses by factor α, delaying their homodyne triggers by δ.The parameters satisfy 0 ≤ α ≤ 1 and 0 ≤ ν ≤ 1.
  • Eve performs partial intercept-resend on a fraction µ of signal pulses while eavesdropping with a beam splitter on the remainder.
  • The local-oscillator attenuation fraction and factor scale Bob’s measured variance while leaving shot-noise estimation unchanged, so Alice and Bob may infer no added channel noise.

IV. ANALYSIS OF THE EXCESS NOISE

The analysis models CVQKD parameter estimation through a normal linear model and examines how calibration and partial intercept-resend attacks alter excess-noise estimates. A full intercept-resend attack produces excess noise dominated by Eve’s measurement noise, while calibration attacks change the shot-noise reference used in estimation.

  • Parameter estimation: CVQKD parameter estimation uses m = N − n correlated samples to estimate Alice’s variance, Bob’s variance, and their covariance.These quantities determine the covariance matrix shared by Alice and Bob.
  • Statistical model: The analysis assumes the linear model y = tx + z, with t = √ηT and centered Gaussian noise variance σ2 = N0 + ηTξ + vel.The normal assumption is practical but is not justified by current proof techniques until the covariance matrix is known.
  • Statistical model: The estimated channel transmittance and excess noise are computed from the maximum-likelihood estimators and the calibrated shot-noise value N′0.The expressions use T = ˆt2/η and infer excess noise from the estimated variance after subtracting the calibrated reference and electronic noise.
  • Calibration attack: A calibration attack changes the homodyne response slope, so N′0 = N0 no longer holds and the inferred excess-noise estimate is altered.The resulting estimate is then expressed in shot-noise units using the attacked calibration value.
  • Intercept-resend attack: Partial intercept-resend measurements produce a weighted mixture of Gaussian outputs, with weight µ for intercepted-and-resent data and 1 − µ for transmitted data.For µ = 1, the excess noise is dominated by the second term arising from Eve’s measurements.
  • Combined attack: Combining calibration manipulation with partial intercept-resend changes the excess-noise expression in shot-noise units, while the system analysis assumes unchanged electronic noise.The electronic-noise assumption is considered reasonable because electronic noise is typically 10–20 dB below shot noise.

V. A QUANTITATIVE EXAMPLE

A full intercept-resend attack introduces noise above the entanglement-breaking limit, but manipulating local-oscillator calibration can make the estimated excess noise nearly zero.

  • ξ_PIR/N_0 = 2.1 under full intercept-resend, exceeding the entanglement-breaking limit and preventing secret-key exchange at any distance.This result assumes μ = 1 and ξ/N_0 = 0.1.
  • With the local-oscillator calibration attack additionally applied, Alice and Bob estimate the excess noise as close to zero for T = 0.5 and η = 0.5.The example uses a realistic local-oscillator attenuation value of approximately 1.5 relative to the stated calibration relationship.
  • The combined attack can therefore make Alice and Bob conclude that they can share a secret key despite the full intercept-resend attack.The calibration manipulation conceals the noise introduced by intercept-resend in the parameter estimation.

VI. COUNTERMEASURE: REAL-TIME SHOT NOISE MEASUREMENT TECHNIQUES

The proposed countermeasures measure shot noise in real time rather than relying on a calibrated local-oscillator relationship, using randomized signal attenuation or an additional homodyne detector. The optical-switch implementation reduces the modeled maximum secure distance from 80 km to 70 km.

  • Real-time shot noise measurement: Real-time shot-noise estimation replaces the insecure calibrated relationship in the presence of an eavesdropper.The paper proposes measuring two noise levels on separate pulse sets and extracting shot noise and signal noise by inverting a linear system.
  • Real-time shot noise measurement: One technique strongly attenuates Bob’s signal path for randomly chosen pulses using an optical switch or amplitude modulator.The figure includes an amplitude-modulator implementation on Bob’s signal path.
  • Real-time shot noise measurement: A second technique adds a homodyne detector dedicated to real-time shot-noise measurement through a beam splitter in Bob’s local-oscillator path.The relative sensitivity of the two homodyne detectors is calibrated.
  • Impact on secret-key rate: 80 km to 70 km: the modeled maximum secure distance decreases when the optical-switch countermeasure is implemented.The reduction reflects discarding 10% of pulses and the optical switch’s typical 2.7 dB loss, which lowers Bob’s detection efficiency.

VII. CONCLUSION

The paper identifies a realistic local-oscillator calibration attack that can make Alice and Bob negotiate a key despite noise above the entanglement-breaking limit. Preventing it requires real-time shot-noise measurement, which is possible but not trivial.

  • The attack can make Alice and Bob negotiate a key despite introduced noise above the entanglement-breaking limit.
  • Preventing the attack requires real-time shot-noise measurement, a feasible but nontrivial countermeasure.
  • The work emphasizes rigorous practical-security testing for current continuous-variable QKD implementations.

Appendix A: Local oscillator power measurement and clock signal generation

The appendix examines how local-oscillator power measurement and trigger generation can be decoupled, allowing equal-energy pulses to produce different trigger timings and undermining calibrated shot-noise relationships.

  • The trigger function U1 detects when the signal exceeds threshold x after delay r, while U2 detects a positive difference across one pulse duration δ.U2 is independent of signal level but requires knowing δ, which cannot be assumed with an active eavesdropper.
  • Power measurement P can remain unchanged while trigger outputs U1 or U2 change, because P is not a multiple of the trigger functional φ.Thus, added signal components can alter clock generation without changing the measured local-oscillator power.
  • Both local-oscillator pulses in the example have the same energy, yet their trigger rising times differ from the pulse end.Figure 6 illustrates this timing mismatch using rising times t1 and t2.
  • A calibrated linear relationship between shot noise and local-oscillator power cannot be trusted during the QKD run when an eavesdropper can modify the relationship.The vulnerability follows from manipulating the trigger timing while preserving the relevant power measurement.
Loading 1304.7024v2…