Source-linked AI summary
Trojan-horse attacks threaten the security of practical quantum cryptography
Nitin Jain, Elena Anisimova, Imran Khan, Vadim Makarov, Christoph Marquardt, Gerd Leuchs
TL;DR
Trojan-horse attacks use bright pulses and back-reflections to probe QKD hardware, threatening security when Bob’s basis encodes the raw key. The paper demonstrates this approach against Clavis2, analyzes afterpulsing constraints, and numerically shows positive key leakage for a Clavis2-like system with realistic lower-noise detectors.
Problem
Trojan-horse attacks may exploit QKD hardware imperfections, and reading Bob’s basis in SARG04 could reveal the raw key without detection.
Method
The paper experimentally demonstrates a Clavis2 attack setup and numerically models an optimized strategy under detector-noise and QBER constraints.
Results
Positive key leakage is obtained numerically for a Clavis2-like system with realistic lower-noise detectors, whereas Clavis2’s afterpulsing keeps Eve’s correlations below the abort threshold.
Takeaways & Limitations
Trojan-horse safeguards are needed because the demonstrated setup and strategy may extend to QKD systems lacking proper protection.
Takeaways & Limitations
The positive-leakage result assumes detector characteristics with efficiencies η0 = η1 = 0.25, dark count probabilities d0 = d1 = 10^-5 per gate, and afterpulse probability below 10%.
Abstract
from arXiv · showhide
A quantum key distribution system may be probed by an eavesdropper Eve by sending in bright light from the quantum channel and analyzing the back-reflections. We propose and experimentally demonstrate a setup for mounting such a Trojan-horse attack. We show it in operation against the quantum cryptosystem Clavis2 from ID~Quantique, as a proof-of-principle. With just a few back-reflected photons, Eve discerns Bob's secret basis choice, and thus the raw key bit in the Scarani-Acín-Ribordy-Gisin 2004 protocol, with higher than 90% probability. This would clearly breach the security of the cryptosystem. Unfortunately in Clavis2 Eve's bright pulses have a side effect of causing high level of afterpulsing in Bob's single-photon detectors, resulting in a high quantum bit error rate that effectively protects this system from our attack. However, in a Clavis2-like system equipped with detectors with less-noisy but realistic characteristics, an attack strategy with positive leakage of the key would exist. We confirm this by a numerical simulation. Both the eavesdropping setup and strategy can be generalized to attack most of the current QKD systems, especially if they lack proper safeguards. We also propose countermeasures to prevent such attacks.
1. Introduction
Trojan-horse attacks exploit unavoidable optical back-reflections to probe QKD hardware, and in SARG04 reading Bob’s basis can reveal the raw key without detection. The paper motivates a proof-of-principle attack on Bob in Clavis2 and frames the practical timing, measurement, detection-avoidance, and wavelength questions involved.
- Attack motivation: Optical imperfections create back-reflections that let bright probes reveal properties of QKD components from the quantum channel.The attack analyzes light scattered or reflected opposite to the input propagation direction.
- Countermeasure constraints: Passive monitoring is straightforward at Alice’s entrance but is difficult at Bob because attenuation would reduce already-weak quantum states and isolators cannot be used directly in two-way plug-and-play systems.The countermeasure constraints motivate examining Bob-side Trojan-horse vulnerabilities in Clavis2.
- Attack motivation: In SARG04, Bob’s phase-modulator setting determines the secret bit, so reading it can reveal Eve the raw key without detection.Eve can then perform sifting, error correction, and privacy amplification like Alice and Bob.
- Scope and contribution: The paper presents a first proof-of-principle attack on a practical QKD system targeting Bob, with a setup and strategy intended to generalize across QKD architectures lacking safeguards.The authors specifically target Clavis2 running SARG04 and discuss possible application to entanglement-based, continuous-variable, and measurement-device-independent systems.
- Attack preparation: The attack preparation requires determining when to launch the pulse, which back-reflection will return, which pulse properties to analyze, how to avoid detection, and which wavelength to use.These interrelated questions are addressed for Clavis2-Bob while it runs SARG04.
- Clavis2 operation: Clavis2 is a two-way plug-and-play system in which Bob sends bright pulse pairs to Alice, who phase-modulates and attenuates them before their return to Bob.For SARG04, Alice uses four relative phases, while Bob randomly applies 0 or π/2 modulation corresponding to the secret bit.
Time of launching the Trojan-horse pulse
Eve synchronizes Trojan-horse pulses to Bob’s internal modulation and characterizes the multiple reflections produced by his asymmetric optical hardware. Reflection timing and amplitude are mapped experimentally so that a useful phase-imprinted pulse can be selected.
- Pulse timing: Eve launches a Trojan-horse pulse so an onward pulse or reflection traverses Bob’s phase modulator while its voltage is active.The returning pulse carries an imprint of Bob’s random phase shift.
- Pulse timing: Bob’s 5 MHz repetition provides the timing reference, and Eve can tap a few photons from Bob’s bright pulses to infer timing and polarization.Those measurements support preparation and synchronization of the Trojan-horse pulses.
- Reflection structure: The asymmetric interferometer and many fiber interfaces produce multiple back-reflections with different arrival times and amplitudes.The relevant reflection can follow different paths on entry and exit through Bob.
- Reflection characterization: The selected back-reflection exits Bob about 43 ns after the Trojan-horse pulse arrives, with reflection levels depending strongly on probe polarization.The polarization was set to maximize reflection from the phase-modulator connector.
Measurement of the back-reflected pulse
Eve reads Bob’s phase modulation by analyzing back-reflected weak coherent pulses, but brighter Trojan-horse pulses improve discrimination while increasing afterpulsing and detection risk.
- Measurement principle: A back-reflected pulse can reveal Bob’s modulation because Eve discriminates weak coherent states with opposite phases.For |α|^2 ≡ µB→E ≈4.0, the maximal success probability is 98.2%.
- Measurement constraints: Increasing µE→B supplies more photons for phase measurement but can produce anomalous component behavior that exposes Eve.The attack must balance measurement quality against side effects in Bob’s system.
- Measurement constraints: In Clavis2, afterpulses raise false-click rates and QBER, which must remain below the approximately 8% abort threshold.Bright pulses can also trigger a click in the attacked slot when arriving shortly after the detector gate.
- Measurement constraints: Eve must use dim Trojan-horse pulses because afterpulsing depends strongly on pulse brightness and attack frequency.Lowering attack frequency reduces probing coverage of slots contributing to the raw key.
- Wavelength dependence: Wavelength selection matters because optical-component behavior, fiber attenuation, and back-reflectance vary across wavelengths.Characterizing a broad attackable spectral range requires tunable, sensitive measurement equipment that may be impractical.
3. Phase readout experiment
The experiment uses synchronized Trojan-horse pulses and homodyne detection to read Bob’s phase modulation in Clavis2. Even with approximately three signal photons, Eve achieves above-90% discrimination.
- Setup: Eve’s apparatus sends synchronized, polarization-controlled Trojan-horse pulses into Bob and interferes back-reflections with a delayed local oscillator.The laser repetition rate was fEatt = 5 MHz, and the setup used couplers, delay, and homodyne detection.
- Setup: The pulse width and mean photon number are tuned through the electronic driving-pulse width τEatt.The delay is adjusted so the input pulse traverses Bob’s phase modulator while it is active.
- High-power readout: Correlations above 99% were obtained when µsig ≈100 using peak-to-peak measurements over complete Clavis2 frames.The system operates with 1075 slots per 215 µs frame.
- Low-power readout: With a 1/99 coupler and µsig ≈3, integrating each homodyne pulse over a time window produced correlations above 90%.The attacked slot did not click except due to a dark count.
- Low-power readout: Eve’s phase estimate is correct in more than 90% of slots when an appropriate threshold is applied to integrated homodyne values.The figure shows 500 integrated values and one phase-modulation estimate per 200 ns slot.
4. Eve’s attack strategy simulation
Because attacking every slot causes excessive afterpulsing, Eve filters Clavis2 frames and probes only strategically selected slots. The simulation combines attack bursts, substitution sequences, and extinguished slots to preserve useful detections while limiting noise.
- Motivation: Attacking every slot at fEatt = 5 MHz would create tremendous afterpulsing in Bob’s APDs, making a straightforward attack infeasible.The strategy instead seeks positive key leakage without severely affecting detection rate or crossing the QBER abort threshold.
- Target selection: Eve targets slots likely to produce valid detections, because probing low-probability slots wastes pulses and increases QBER through afterpulsing.She manipulates the frame of 1075 weak coherent pulses to control detection timing.
- Attack components: An attack burst of Nab consecutive Trojan-horse pulses raises Eve’s chance of probing a slot that eventually clicks but also creates afterpulsing.The strategy uses detector deadtime as part of the mitigation.
- Attack components: A substitution sequence of Nss low-loss slots maintains detection probability after the burst without adding Trojan-horse pulses.Clicks from Alice’s photons can compete with afterpulses and reduce the effective error probability.
- Attack components: Eve extinguishes Nel preceding slots to prevent earlier clicks from placing the subsequent attack burst inside detector deadtime.The frame-filtering setup uses fast optical switches and a low-loss line.
- Simulation: The simulation models filtered transmission, exponential afterpulsing in D0 and D1, final detection probabilities, and the resulting click pattern.The figure assumes TLL = 0.9 for attack-burst and substitution slots.
Evaluating the QKD frame manipulation
Frame manipulation lets Eve concentrate her probing on a small subset of slots while preserving enough detections for key formation. The simulation exposes a trade-off between information leakage, QBER, detection rate, and attack parameters.
- Frame evaluation: Eve’s manipulated frame delivers photons from Alice only during attack bursts and substitution sequences, while afterpulsing makes noise nonuniform.The model combines photonic input and detector noise to calculate slotwise detection probabilities.
- Frame evaluation: Although Eve attacks only 20 of 1075 slots, she learns Bob’s basis choice in 4 of 9 slots used for raw-key formation.The calculation includes double-click handling and detector deadtime.
- Trade-offs: Longer and more frequent attacks increase Eve’s information Iact_E but also increase QBER.This establishes a direct trade-off between leakage and detectability.
- Trade-offs: Higher TLL tends to increase γB and may lower QBER by reducing the relative contribution of dark noise, but TLL cannot exceed 1.These parameters constrain how much frame filtering can preserve normal-looking operation.
Classical processing and optimizing the simulation
The simulation combines selective Trojan-horse attacks with SARG04 security calculations to assess whether Eve’s actual information exceeds the security estimate without triggering abort. It also examines how preprocessing, QBER, and channel transmission affect the estimated leakage.
- Success conditions: The analysis compares Eve’s actual information with the amount inferred from the security proof, requiring QBER to remain below the abort threshold.The strategy also requires Eve’s known raw-key fraction to exceed the fraction estimated by Alice and Bob.
- Simulation strategy: Eve attacks only a fraction r of frames, selecting patterns defined by {Nab, Nel, Nss}, while leaving the remaining frames unchanged.For example, r = 0.8 means attacking 80 of 100 frames.
- Simulation strategy: Each simulation run uses nsim = 10000 frames to reduce stochastic fluctuations before basis reconciliation and QBER estimation.The procedure also estimates the fraction of valid slots in which Eve knows the secret bit.
- Classical processing: Error-correction leakage is modeled at the Shannon limit as leakEC = h(q), where h is the binary entropy of the QBER q.This leakage is combined with Eve’s known-key fraction to bound her actual correlations.
- Classical processing: The privacy-amplification calculation uses the SARG04 expression I(A : E), derived for attenuated-laser sources and optimized to lower-bound the secret-key fraction.The calculation includes preprocessing, which can reduce Bob’s and Eve’s information more adversely for Eve.
- Optimization results: At y = 0, Iest_E = 0.4844, implying that Alice and Bob compress almost half of the error-corrected key during privacy amplification.The reported estimated information is independent of incurred QBER but depends on channel transmission; these values use T = 0.25.
5. Results and discussion
The simulated attack is difficult to hide with Clavis2 detectors, but detector assumptions and preprocessing materially change the outcome. With less-noisy realistic detectors, simulations find attacks that satisfy abort constraints and leak secret-key information.
- Clavis2 detector characteristics: Clavis2 detectors make it difficult to satisfy the QBER, detection-rate, and information constraints simultaneously.Numerous parameter combinations satisfy two conditions, but the incurred QBER can greatly exceed the abort threshold.
- Preprocessing: At qabort ≈ 0.11, preprocessing can let Eve breach security with Clavis2-like detectors.For y = 0.4, Eve’s information can exceed Alice and Bob’s estimated value because both mutual informations scale by 1 − y.
- Less-noisy detector model: η0 = η1 = 0.25 and dark-count probabilities d0 = d1 = 10^-5 define the simulated low-noise detector model.The model also assumes a cumulative afterpulse probability below 10%.
- Less-noisy detector model: E = 0.5037 with no preprocessing in the low-noise model, and the resulting positive leakage implies a security breach.Figure 6(c) reports attacks satisfying all three conditions under the new detector parameters.
- Transmission dependence: At T < 0.25, positive final-key leakage may require more exhaustive optimization, while at T > 0.25 Eve’s attack may have better prospects.Higher transmission increases Alice’s photon number and can suppress afterpulsing, but the security expression is valid only for channel lengths above 24 km, roughly T < 0.33.
- Overall interpretation: The attack succeeds over a range of transmissions against less-noisy APDs, and preprocessing can relax Eve’s constraints.The strategy may also be combined with after-gate attacks to improve performance.
Possible improvements and extensions
The attack can be strengthened through broader parameter optimization, improved optical and measurement control, and selective targeting of pulses. Its setup is adaptable to multiple QKD architectures, including CVQKD and entanglement-based systems.
- Attack optimization: Optimizing the full attack-parameter space could yield better performance than the combinations examined here.The authors also consider manipulating frames traveling from Bob to Alice, although increased power may trigger Alice’s monitoring detectors.
- Attack optimization: Non-demolition photon-number measurements could let Eve skip zero-photon slots, reducing afterpulsing-related dark counts and increasing raw-key correlations.The proposed selection targets slots containing photons while withholding the attack from empty slots.
- Readout improvements: Multiple back-reflection homodyne measurements, phase-drift tracking, and improved quantum measurements could approach 100% correlations while reducing the required pulse brightness.The proposed methods include integrating consecutive-pulse differences over an appropriate time window.
- Scope of applicability: The setup can be adapted to virtually any QKD system with delay, polarization, and interferometric control.The authors specifically include CVQKD and entanglement-based systems, and state that BB84 may also be vulnerable in systems lacking safeguards.
Countermeasures
Countermeasures include optical isolation and filtering, monitoring of Bob’s receiver, and electronic changes that limit Eve’s access. Their relevance depends on the QKD architecture and protocol.
- General countermeasures: Isolators and wavelength filters are suitable countermeasures for one-way QKD, while filters remain useful for two-way Clavis2.Analyzing internal back-reflections may support incorporating Trojan-horse attacks into security proofs and privacy amplification.
- Clavis2 countermeasures: A watchdog detector, shorter phase-modulation windows, and real-time APD monitoring are proposed specifically for Clavis2.The watchdog randomly routes a small fraction of incoming signals to a detector.
- Clavis2 countermeasures: All proposed Clavis2 countermeasures except the watchdog detector require only electronic-control modifications and are recommended.The recommendation applies to reducing the phase-modulation pulse width and monitoring Bob’s APDs in real time.
- Protocol scope: Bob’s vulnerability arises for SARG04 because his basis choice carries the secret bit; interrogating Bob provides no advantage in BB84 except in a specified detector-mismatch counterattack.Both protocols remain vulnerable to interrogating Alice’s modulator.
6. Conclusion
The study demonstrates a real-time Trojan-horse phase-readout attack against Clavis2-Bob running SARG04, while showing that detector afterpulsing constrains its practical impact. Numerical modeling indicates that less-noisy realistic detectors could permit positive key leakage.
- A real-time setup successfully reads Bob’s phase-modulator state in a commercial Clavis2 QKD system.The attack targets the SARG04 protocol by extracting Bob’s basis choice.
- Bright Trojan-horse pulses induce afterpulsing noise in Bob’s single-photon detectors, increasing the QBER.This detector noise is the main practical constraint identified for the attack.
- On the tested Clavis2 system, the attack’s raw-key correlations remain below Alice and Bob’s theoretical security estimate.Thus, the demonstrated system is not shown to yield positive exploitable leakage under the modeled conditions.
- Similar or future QKD systems with less-noisy detectors could be vulnerable to the modeled attack strategy.The authors also propose modifications intended to improve attack performance.
Appendix
The appendix models Clavis2’s frame-level photon transmission, detection, deadtime, and afterpulsing, then specifies an optical-switch implementation that redirects selected slots through a low-loss channel. Eve uses attack bursts to read Bob’s phase-modulator settings and substitution sequences to preserve detection probability afterward.
- Frame and detector simulation: Clavis2 frames contain Nf = 1075 slots, with Bob opening Nf detection gates for returning weak coherent pulses.The simulation uses experimental parameters and models photon numbers with Poisson statistics and transmission or detection events with Bernoulli trials.
- Frame and detector simulation: At T = 0.25, the simulation tracks photon arrival, detector probabilities, clicks, and Ndt = 50 withdrawn gates caused by deadtime.The assumed channel transmission corresponds to approximately a 30 km channel under the stated attenuation, with TB = 0.45 inside Bob.
- Detector noise: The detector model includes D0 and D1 efficiencies, dark counts, and afterpulse parameters, with afterpulses alone exceeding 80% cumulative random-click probability after Ndt = 50 gates.The afterpulse parameters are estimated from prior experimental work.
- Optical implementation: Eve’s implementation uses two bidirectional 2×2 fast optical switches, an optical tap, and a highly transmissive low-loss channel to manipulate frame slots.The forward path remains essentially undisturbed, while the tap supplies polarization information and synchronization for preparing Trojan-horse pulses.
- Frame manipulation: The frame pattern repeats attack bursts, extinguished slots, and substitution sequences; Eve reads Bob’s phase-modulator settings during the first Nab slots and forwards the remaining Nss slots without Trojan-horse pulses.The number of complete triads is k = floor(Nf/(Nab + Nel + Nss)), with leftover slots handled by an additional burst or extinction.