Security loophole in error verification in quantum key distribution
arXiv:2507.21416 · doi:10.1103/3vms-bx5d
Abstract
The security of quantum key distribution (QKD) is evaluated based on the secrecy of Alice's key and the correctness of the keys held by Alice and Bob. A practical method for ensuring correctness is known as error verification, in which Alice and Bob reveal a portion of their reconciled keys and check whether the revealed information matches. In this paper, we point out that when error verification is performed in a QKD protocol, the definition of secrecy must be revised accordingly. We illustrate the necessity of this revision with a counterexample, showing that neglecting it can lead to an incorrect security claim. In particular, we observe that in the case of security proof method based on phase error correction, which is one of the mainstream approaches and also known as Koashi's approach, no explicit method has been established to properly incorporate the revised secrecy definition. To resolve this issue, we present a way to translate the phase error correction-based approach into another mainstream approach, called the leftover hashing lemma-based approach, also known as Renner's approach, where a solution has already been formulated. As a consequence, security proofs under the phase error correction-based approach automatically remain valid without any change in the secret key length, even if they implicitly consider error verification without revising the secrecy definition.
9 pages,no figure. v2: Main results have been revised
References in corpus (34)
- Simple Proof of Security of the BB84 Quantum Key Distribution Protocol
- Advances in Quantum Cryptography
- Secure quantum key distribution with realistic devices
- Secure Quantum Key Distribution
- The operational meaning of min- and max-entropy
- Tight Finite-Key Analysis for Quantum Cryptography
- The Uncertainty Relation for Smooth Entropies
- Finite-key analysis for measurement-device-independent quantum key distribution
- Concise Security Bounds for Practical Decoy-State Quantum Key Distribution
- Security in Quantum Cryptography
- Loss-tolerant quantum cryptography with imperfect sources
- Secure quantum key distribution with an uncharacterized source
- Experimental demonstration of quantum key distribution without monitoring of the signal disturbance
- Squashing Models for Optical Measurements in Quantum Communication
- A largely self-contained and complete security proof for quantum key distribution
- Composability in quantum cryptography
- Experimental quantum key distribution without monitoring signal disturbance
- Concise and Tight Security Analysis of the Bennett-Brassard 1984 Protocol with Finite Key Lengths
- Experimental Passive Round-Robin Differential Phase-Shift Quantum Key Distribution
- Security proof for QKD systems with threshold detectors
- More Efficient Privacy Amplification with Less Random Seeds via Dual Universal Hash Function
- Security analysis of the decoy method with the Bennett-Brassard 1984 protocol for finite key lengths
- Finite-size security of continuous-variable quantum key distribution with digital signal processing
- Finite-key security analysis of quantum key distribution with imperfect light sources
- Squashing model for detectors and applications to quantum key distribution protocols
- Dual universality of hash functions and its applications to quantum cryptography
- Universal Squash Model For Optical Communications Using Linear Optics And Threshold Detectors
- Finite-key security analysis of differential-phase-shift quantum key distribution
- Leftover hashing from quantum error correction: Unifying the two approaches to the security proof of quantum key distribution
- Squash Operator and Symmetry
- Quantum key distribution with simply characterized light sources
- Finite-key analysis of loss-tolerant quantum key distribution based on random sampling theory
- Security of differential phase shift QKD from relativistic principles
- Refined finite-size analysis of binary-modulation continuous-variable quantum key distribution