Source-linked AI summary
Practical security bounds against the Trojan-horse attack in quantum key distribution
Marco Lucamarini, Iris Choi, Martin B. Ward, James F. Dynes, Zhiliang Yuan, Andrew J. Shields
TL;DR
The paper addresses the lack of quantitative security bounds for passive defenses against Trojan-horse attacks on QKD encoding devices. It models the attack as information leakage, connects leakage to measurable optical-component parameters, and finds that µout ∼10^-6 approaches the no-attack key-rate situation across nearly any distance, with no additional privacy amplification needed up to 70% of maximum distance. The analysis focuses on a unidirectional fiber-based setup and adopts conservative assumptions including noise-free retrieval by Eve.
Problem
Trojan-horse attacks can extract encoding information from QKD modules, but quantitative bounds linking passive optical components to system security were lacking.
Method
The paper models the Trojan-horse attack as an information-leakage side channel and bounds leakage using characterized passive components, optical isolation, and privacy amplification.
Results
µout ∼10^-6 approaches the no-Trojan-horse situation for nearly any distance, with no additional privacy amplification needed up to 70% of maximum working distance.
Takeaways & Limitations
Quantitative security bounds can guide practical passive-component choices for protecting a unidirectional fiber-based QKD transmitter against a general Trojan-horse attack.
Takeaways & Limitations
The analysis focuses on a particular unidirectional fiber-based QKD setup and assumes conservative conditions including noise-free retrieval of Trojan states by Eve.
Abstract
from arXiv · showhide
In the quantum version of a Trojan-horse attack, photons are injected into the optical modules of a quantum key distribution system in an attempt to read information direct from the encoding devices. To stop the Trojan photons, the use of passive optical components has been suggested. However, to date, there is no quantitative bound that specifies such components in relation to the security of the system. Here, we turn the Trojan-horse attack into an information leakage problem. This allows us quantify the system security and relate it to the specification of the optical elements. The analysis is supported by the experimental characterization, within the operation regime, of reflectivity and transmission of the optical components most relevant to security.
I. INTRODUCTION
The paper frames the Trojan-horse attack as an information-leakage problem in QKD and develops passive optical countermeasures with quantitative security bounds. It relates Eve’s injected and returned photon numbers to optical isolation and the resulting security of the system.
- Motivation: The Trojan-horse attack lacked a quantitative mitigation analysis despite demonstrations that phase information can be extracted with few photons.Phase values were experimentally discriminated with 90% success probability using only 3 photons.
- Threat model: Trojan photons can reach Alice’s encoding device, acquire private phase information, and return to Eve for measurement.The attack exploits reflected photons that carry information encoded inside Alice’s module.
- Prior countermeasures: Existing active countermeasures add complexity, while prior provably secure solutions are impractical or limited to specific receivers and protocols.A receiver delay line does not protect the transmitting side and does not apply to B92 or SARG04.
- Contribution: The proposed passive architecture treats the Trojan-horse attack as a side channel and bounds leakage through characterization of relevant optical components and privacy amplification.Alice can use component characterization to bound information escaping from her module.
- Quantitative framework: The returned Trojan-photon mean number is µout = γµin, so bounded injection and optical isolation let Alice control Eve’s leaked information.The analysis uses the LIDT to bound Eve’s injected photon number and relates µout to the phase-modulator clock rate and isolation.
- Quantitative framework: Eve’s optimal modeled strategy distributes Trojan photons evenly across pulses probing different phase values rather than concentrating them in fewer pulses.The paper attributes this result to convexity of the key rate as a function of each pulse’s mean photon number.
B. Key rate of single-photon BB84 protocol
The single-photon BB84 analysis models Trojan-horse photons as an information-leaking side channel and derives key rates as a function of the returned mean photon number µout. Security remains close to the no-attack case for sufficiently small µout but degrades at larger leakage.
- The THA is represented by excess photons tensor-producted with Alice’s single-photon states, creating a side channel whose leakage is controlled by µout.When µout = 0, only the intended single-photon states leave Alice’s module; positive µout gives Eve additional phase information.
- The security proof applies the Koashi refinement of GLLP to estimate phase errors in the Y basis and derive the efficient BB84 key rate.The analysis considers Eve’s strategies from measuring Trojan photons after basis reconciliation to using them during transmission.
- µout = 10^-8 makes the attacked and ideal key rates overlap over nearly the whole distance range, requiring negligible additional privacy amplification.For µout = 10^-6, the rates are indistinguishable up to 100 km, about 60% of the 170 km maximum distance.
- µout = 10^-2 leaves a positive key rate but limits the maximum distance to 9 km, while the largest positive-key value is µout = 0.015.
- The resulting key-rate expression applies to any QKD setup that can upper-bound the mean number of Trojan photons reflected back to Eve.
C. Key rate of decoy-state BB84 protocol
The decoy-state extension assumes that Trojan-horse leakage targets only Alice’s phase modulator and leaves decoy-state execution unaffected. Under this assumption, small µout values preserve rates close to the ideal case across most operating distances.
- The decoy-state key-rate formula generalizes the single-photon result while assuming Eve’s attack does not affect decoy-state execution.The THA is restricted to Alice’s phase modulator, with decoy-state devices untouched.
- The analysis uses conservatively bounded single-photon yields estimated through the decoy-state technique in the X and Y bases.
- µout = 10^-6 closely follows the ideal rate up to 100 km and remains positive to 140 km, or 96% of the 146 km maximum distance.The rate remains positive for µout values up to 0.012.
- µout = 10^-7 is indistinguishable from the ideal rate over nearly the whole distance range, although decoy-state rates and maximum distances are below the single-photon case.
- Three decoy states give a rate close to the infinite-decoy limit, making the plotted decoy-state rate achievable in a real system.
III. BOUNDS ON INPUT PHOTONS
The input-photon bound is based on the laser-induced damage threshold of Alice’s optical module, with pulse width, wavelength, and component exposure determining the conservative threshold. The analysis identifies fiber damage as a practical constraint on Eve’s injected light.
- The LIDT is defined as the highest incident laser radiation quantity for which the extrapolated probability of component damage is zero.It may be expressed as energy density, power density, or linear power density.
- Wider laser pulses produce less damage and therefore a higher LIDT, so Eve’s pulse should be as wide as compatible with Alice’s phase modulator.
- Longer wavelengths cause less damage, making Eve’s optimal wavelength as large as possible within the fiber’s transmission constraints.The LIDT remains reasonably constant across wavelengths transmitted by standard optical fiber.
- N is upper-bounded using the LIDT of the component most exposed to Eve’s light, while other components are assumed either to operate normally or fail detectably.
- A geometric estimate gives 4.3 × 10^23 photons per second at 1.55 µm and 50 µm^2, but this threshold is considered overly conservative for real fibers.Observed interface damage and fiber defects can occur before the calculated core-damage threshold.
B. Fiber thermal fuse-induced LIDT
The fiber thermal-fuse analysis uses experimentally observed catastrophic damage in standard silica fibers to choose a practical LIDT threshold. The transmitter architecture places a fiber loop at the entrance, followed by filtering, isolation, and attenuation.
- Alice can reduce the pulse width τA to lower the module’s damaging threshold N and make Eve’s strategy less effective.
- The conservative model assumes rectangular phase-modulator pulses, allowing Eve to match τE = τA while keeping the damage threshold high.
- N = 10^20 photons/s is adopted as a practical LIDT threshold after experiments found catastrophic thermal damage around 2–5 W in standard single-mode silica fibers.This threshold is 4.3 × 10^3 below the earlier estimate and corresponds to 12.8 W from a continuous-wave laser.
- A more conservative N can be used when stronger bounds independent of fiber fabrication details are required.
- The mitigation architecture uses an optical fiber loop to set the LIDT, followed by an optical filter, isolator, and attenuator; R denotes total upstream reflectivity.
A. Passive architecture against the THA
The proposed passive architecture bounds Trojan-horse leakage by combining photon-number limits with filtering, isolation, attenuation, and reflectivity characterization. The analysis identifies practical component combinations that reach the target excess photon number μout = 10^-6.
- Passive components: The architecture combines an optical-fiber loop, wavelength filter, optical isolator, and attenuator to limit injected photons and enforce unidirectional propagation.The fiber loop regulates high-power input and filters longer wavelengths, while the filter blocks unwanted wavelengths; the isolator attenuates Eve’s input and the attenuator adds isolation when used.
- Security accounting: The total isolation is expressed in dB as γ˙ = 2F˙ + nI˙ + 2A˙ + R˙, accounting for double passage through filters and attenuators and n isolators.The isolator term is not doubled because one direction of the Trojan-horse double pass has zero attenuation.
- Security target: μout = 10^-6 is selected as a security target requiring only negligible or limited additional privacy amplification across short-, middle-, and long-range QKD transmissions.The example uses N = 10^20 photons/s/a50 and a system clock rate fA = 10^9 Hz.
- Practical combinations: Two or more optical isolators may be needed to meet μout = 10^-6, although one isolator suffices at a sufficiently high clock rate.The listed combinations are considered feasible and relatively inexpensive because filters, attenuators, and isolators have low cost and insertion loss.
- Experimental characterization: Reflectivity is characterized with ν-OTDR by summing polarization-resolved reflection peaks for a worst-case estimate using only components in the specified module region.The measurement traces follow the short and long interferometer arms, and the relevant distance begins at connector J1.
B. Components characterization
The work characterizes the optical components most relevant to Trojan-horse security and shows that the required passive-component values are experimentally feasible.
- B. Components characterization: Experimental characterization across the components’ operational range is required to ensure their behavior under the conditions used in the security argument.The measurements target reflectivity and transmission in a unidirectional GHz-clocked QKD transmitter.
- B. Components characterization: −42.87 dB total reflectivity meets the requirement R < −40 dB for the transmitting apparatus.The reflectivity was obtained by summing the relevant peaks measured with single-photon optical time-domain reflectometry.
- B. Components characterization: At least −60 dB additional isolation is needed to reach the |γ| = 170 dB condition with the characterized −35 dB attenuator.A tested dual-stage isolator provided more than 65 dB isolation near 1550 nm; outside that wavelength, the filter supplied more than 160 dB additional isolation.
- B. Components characterization: µout ∼10^-6 approaches the no-attack key-rate situation over nearly any user distance, without additional privacy amplification up to 70% of maximum distance.The result follows from the derived key-rate analysis under the stated assumptions.
- B. Components characterization: The practical passive architecture relates QKD security to clock rate, detection rate, reflectivity, and the sequence of fiber loops, filters, and isolators.The component combinations in Table I indicate that many existing QKD systems can potentially be protected when sufficient isolators are used and components behave as expected.
A. Security-related assumptions
The security proof assumes bounded Trojan-photon input, characterized components, restricted state preparation, receiver conditions, asymptotic operation, and linear reflectivity measurements.
- A. Security-related assumptions: Security requires Alice to bound the number of incoming Trojan photons and characterize her components under all relevant conditions.Without this assumption, the optical isolation cannot relate the injected-photon bound to the outgoing Trojan-photon number.
- A. Security-related assumptions: The model assumes Eve uses tensor products of coherent states and that Alice emits perfectly encoded single-photon or phase-randomized coherent states.Imperfect initial-state encoding and side channels other than the specified attack on Alice’s phase modulator are excluded.
- A. Security-related assumptions: The receiver’s detection efficiency is assumed basis-independent, with randomly chosen bases, infinitely many signals and decoy states, and asymptotic key-rate estimation.These assumptions support the rate equations used in the security proof.
- A. Security-related assumptions: The OTDR-measured reflectivity is assumed linear in input polarization, and the characterization uses low laser intensity to avoid nonlinear effects.The reported measurement intensity was about 6 nW.
- A. Security-related assumptions: Phase randomization is assumed, while its implementation must avoid giving Eve access to an additional active component.An intensity modulator can be shielded by the same optical isolation or by a perfect isolator between it and the interferometer.
B. Rate equations for the Trojan-horse attack: general case
The rate-equation analysis models Trojan-horse leakage as basis dependence between Alice’s prepared states and incorporates that dependence into the secure-key-rate bound.
- B. Rate equations for the Trojan-horse attack: general case: The security proof uses an entanglement-based preparation with a private quantum coin to relate X- and Y-basis error rates.Because Eve cannot access the coin, the virtual preparation is equivalent to Alice’s actual preparation; a complementarity argument then yields the phase-error bound.
- B. Rate equations for the Trojan-horse attack: general case: The ideal single-photon BB84 rate depends on the X-basis detection rate, Y- and X-basis error rates, and error-correction inefficiency.The general Trojan-horse analysis modifies this ideal expression through the basis-dependent phase-error estimate.
- B. Rate equations for the Trojan-horse attack: general case: The key-rate expression replaces the ideal phase-error rate with a larger rate when preparation is imperfect or basis information leaks.For decoy-state sources, the corresponding rate is obtained by estimating the single-photon quantities with the decoy-state technique.
- B. Rate equations for the Trojan-horse attack: general case: The quantum-coin imbalance Δ quantifies the probability that Alice’s X- and Y-basis states differ, thereby measuring basis dependence.The imbalance is obtained from the probability of the |1X⟩C outcome when the coin is measured in the X basis.
- B. Rate equations for the Trojan-horse attack: general case: µout = 0 makes Alice’s emitted states basis independent, whereas µout > 0 carries basis information outside her enclosure.Eve can exploit this information together with channel losses by selectively forwarding favorable states.
1. Trojan-horse attack with a passive use of the Trojan photons
The analysis treats passive Trojan-horse leakage through an entanglement-based virtual protocol and derives key-rate bounds from measured transmission rates. Under passive attacks, the resulting rates remain close to the ideal case for low Trojan photon numbers and positive at substantially higher values.
- Attack model: Eve’s passive strategy stores leaked auxiliary states and measures them after basis reconciliation, without selectively modifying qubit transmission during the quantum stage.This restriction is captured by the assumption that Eve cannot access the auxiliary system during quantum transmission.
- Security proof: The proof bounds phase errors by relating virtual-protocol quantities to transmission rates measured in the real protocol.The construction uses an entanglement-based virtual protocol, Pauli-matrix transmission rates, and a key-rate expression based on the estimated phase error.
- Decoy-state extension: For decoy-state BB84, the same bound is adapted by replacing relevant quantities with decoy-state estimates under the stated assumption about decoy estimation.The tilde notation marks quantities estimated using the decoy-state technique.
- Results: The key rates coincide with the ideal no-attack rate for µout below approximately 10^-2 and remain positive up to 0.5 for single-photon and 0.38 for decoy-state sources.The reported behavior shows little dependence on µout in the passive-attack regime and improves by several orders of magnitude over the general-attack rates.
2. Trojan-horse attack with active unambiguous state discrimination of the Trojan photons
The active attack lets Eve use unambiguous state discrimination on Trojan photons during transmission, forwarding conclusive events and blocking inconclusive ones. Security is recovered by accounting for the insecure fraction and adapting the resulting rate to decoy-state estimation.
- Attack model: Eve identifies X-basis Trojan states with unambiguous state discrimination and learns the key bit without perturbing Alice’s qubit whenever the measurement succeeds.For inconclusive outcomes, she blocks the pulse, introducing losses conditional on her measurement result.
- Security accounting: The users separate detected X-basis events into insecure conclusive outcomes and secure inconclusive outcomes, with δ denoting the insecure fraction.The inconclusive fraction cannot be selectively modified using the auxiliary Trojan system.
- Single-photon protocol: The phase-error bound is adjusted by the factor 1/(1−δ), yielding a secure key-rate expression for single-photon efficient BB84.Only the fraction 1−δ provides faithful error-rate estimation in this attack model.
- Decoy-state extension: The corresponding decoy-state extension uses decoy-estimated quantities, while the Y-basis phase-error expression remains unchanged because Eve cannot selectively modify those events.The unchanged Y-basis estimation follows from the lack of useful X-basis information in Eve’s Trojan states for Y-basis preparations.