Skip to main content
QUICK REVIEW

[论文解读] Laser damage creates backdoors in quantum communications

Vadim Makarov, Jean‐Philippe Bourgoin|arXiv (Cornell University)|Oct 12, 2015
Ocular and Laser Science Research被引用 4
一句话总结

本文表明,光学元件中的激光损伤可在量子通信协议(如量子密钥分发(QKD)和抛币协议)中引发可被利用的侧信道漏洞,从而绕过既定的安全保证。作者通过实验表明,激光损伤的器件会以无法察觉的方式泄露信息,证明仅靠量子协议本身无法确保安全,必须辅以针对物理层攻击的额外防护措施。

ABSTRACT

Quantum communication protocols such as quantum cloud computing, digital signatures, coin-tossing, secret-sharing, and key distribution, using similar optical technologies, claim to provide unconditional security guaranteed by quantum mechanics. Among these protocols, the security of quantum key distribution (QKD) is most scrutinized and believed to be guaranteed as long as implemented devices are properly characterized and existing implementation loopholes are identified and patched. Here we show that this assumption is not true. We experimentally demonstrate a class of attacks based on laser damage, capable of creating new security loopholes on-demand. We perform it on two different implementations of QKD and coin-tossing protocols, and create new information leakage side-channels. Our results show that quantum communication protocols cannot guarantee security alone, but will always have to be supported by additional technical countermeasures against laser damage.

研究动机与目标

  • 调查光学元件中的物理损伤是否会在量子通信协议中引入新的安全漏洞。
  • 检查激光诱导的损伤是否能创建无法检测的侧信道,从而破坏量子密钥分发(QKD)及其他协议的安全性。
  • 通过实验演示激光损伤可被武器化为量子通信系统中的针对性攻击向量。
  • 挑战量子协议中设备经充分表征即固有安全的假设。

提出的方法

  • 研究人员在QKD和抛币协议所用的光学组件中诱导了受控的激光损伤。
  • 他们分析了器件行为的变化,以识别新的信息泄露通道。
  • 团队对受损器件进行了侧信道分析,以检测并利用无意中的数据泄露。
  • 实验在两种不同的QKD实现和一种抛币协议上进行,以验证攻击的普适性。
  • 该攻击被设计为可逃避标准安全验证程序的检测。

实验结果

研究问题

  • RQ1光学元件中的激光损伤是否会在量子通信协议中创建新的、可被利用的侧信道漏洞?
  • RQ2激光损伤的器件在不触发标准安全检查的情况下,能在多大程度上泄露信息?
  • RQ3当引入物理层损伤时,量子密钥分发及其他量子协议是否真正安全?
  • RQ4此类攻击是否可以系统性地创建并按需控制?
  • RQ5需要何种技术防护措施,以防止激光损伤破坏量子通信的安全性?

主要发现

  • 光学元件中的激光损伤可在量子通信系统中创建新的、按需触发的侧信道泄露路径。
  • 激光损伤引发的侧信道漏洞在QKD和抛币协议中均被成功利用。
  • 该攻击未被标准安全验证程序检测到,表明当前信任假设中存在关键缺陷。
  • 研究结果表明,若无额外的物理防护措施,量子协议无法保证安全性。
  • 本研究证明,仅靠设备表征不足以确保在存在物理损伤时的安全性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。