Multiphoton and side-channel attacks in mistrustful quantum cryptography
arXiv:2103.06970 · doi:10.1103/PRXQuantum.2.030338
Abstract
Mistrustful cryptography includes important tasks like bit commitment, oblivious transfer, coin flipping, secure computations, position authentication, digital signatures and secure unforgeable tokens. Practical quantum implementations presently use photonic setups. In many such implementations, Alice sends photon pulses encoding quantum states and Bob chooses measurements on these states. In practice, Bob generally uses single photon threshold detectors, which cannot distinguish the number of photons in detected pulses. Also, losses and other imperfections require Bob to report the detected pulses. Thus, malicious Alice can send and track multiphoton pulses and thereby gain information about Bob's measurement choices, violating the protocols' security. Here, we provide a theoretical framework for analysing such multiphoton attacks, and present known and new attacks. We illustrate the power of these attacks with an experiment, and study their application to earlier experimental demonstrations of mistrustful quantum cryptography. We analyse countermeasures based on selective reporting and prove them inadequate. We also discuss side-channel attacks where Alice controls further degrees of freedom or sends other physical systems.
Section VII and clarifications added. Accepted version
References in corpus (17)
- Hacking commercial quantum cryptography systems by tailored bright illumination
- Photon number resolution using a time-multiplexed single-photon detector
- An avalanche-photodiode-based photon-number-resolving detector
- Controlling passively-quenched single photon detectors by bright light
- Squashing Models for Optical Measurements in Quantum Communication
- Cryptography from Noisy Storage
- Quantum digital signatures with quantum key distribution components
- Attacks exploiting deviation of mean photon number in quantum key distribution and coin tossing
- Quantum weak coin flipping with arbitrarily small bias
- Hacking the quantum key distribution system by exploiting the avalanche transition region of single photon detectors
- Robust countermeasure against detector control attack in practical quantum key distribution system
- Imperfect 1-out-of-2 quantum oblivious transfer: bounds, a protocol, and its experimental implementation
- Practical Quantum Key Distribution Secure Against Side-Channels
- Variable Bias Coin Tossing
- One-out-of- spacetime-constrained oblivious transfer
- Practical quantum tokens without quantum memories and experimental tests
- Unconditionally secure relativistic multi-party biased coin flipping and die rolling
Cited by in corpus (10)
- Breaking the Rate-Loss Bound of Quantum Key Distribution with Asynchronous Two-Photon Interference
- Enhancing quantum cryptography with quantum dot single-photon sources
- Demonstration of quantum-digital payments
- Quantum cryptography beyond key distribution: theory and experiment
- Practical quantum tokens without quantum memories and experimental tests
- Error-tolerant oblivious transfer in the noisy-storage model
- Ensemble-Based Quantum Token Protocol Benchmarked on IBM Quantum Processors
- Unconditionally secure relativistic multi-party biased coin flipping and die rolling
- Quantum Universally Composable Oblivious Linear Evaluation
- Performance of Practical Quantum Oblivious Key Distribution