All-in-one quantum key distribution system makes its debut
physicsworld.com
physicsworld.com
The Physicists who read the critique I wrote all said "well the Physics arguments you're making are obviously right, but I don't have the background to judge the Cryptography details" and the Cryptographers all said "well the Crypto arguments you're making are obviously right, but I don't have the background to judge the Physics details."
Each side was in love with the idea of crossing over into each other's field, but neither side could see they'd built a house of cards in their joint ignorance of each other's fields. The amazing thing is from what I could tell it took more than a decade for any serious papers demonstrating its inherent limitations to be get properly published.
The need for the public (non-quantum) channel in this scheme to be immune to active eavesdropping can be relaxed if the Alex and Bob have agreed beforehand on a small secret key, which they use to create Wegman-Carter multiple-message authentication tags for their messages over the public channel.
Of course immediately raises the question why one should use QKD at all. If a shared secret is required anyway, why not simply use symmetric cryptography?
In many modern articles, QKD is presented as a replacement for asymmetric cryptography. This I think is very misleading, since the reason for using asymmetric cryptography is that one does not need a shared secret.
[1] http://researcher.watson.ibm.com/researcher/files/us-bennetc...
+1. Last I recall, AES is for the most part extremely resilient to attacks by quantum computers. It's RSA that drops dead.
* It suffers from a built-in vulnerability to denial-of-service attacks because eavesdropping destroys quantum information.
* It lacks an authentication mechanism and is vulnerable to MITM. In practice, classical protocols are used to add authentication and to protect against MITM.
* It is a hardware solution and thus expensive to deploy, upgrade and maintain.
At the same time, contrary to the usual claims of "security guaranteed by the laws of physics", its security is limited by the security of non-quantum elements of the implementation. IOW, the usual reference to the no-cloning theorem for quantum information is irrelevant because QKD uses both quantum and classical information and the latter is clonable and therefore implementations suffer from side channel leaks.
Thus, QKD is an expensive and impractical solution to a problem already solved robustly and cheaply by classical protocols. Hopefully, the hype around it fizzles out before it harms related fields with an actual promise, such as quantum computing.
I'm not sure about the second part regarding the MitM attack; doesn't BB84's requirement of "the existence of an authenticated public classical channel." mitigate this? What kind of authentication is required there? Would signing a message using a secret key (e.g. Lamport OTS or some other quantum-resistant/hash-based signature algorithm) suffice to establish an 'authenticated channel'?
The main problem I can see based on my limited understanding is that if an MitM attacker managed to intercept every key exchange attempt over a channel, they might not be able to intercept private messages, but they could prevent the encrypted channel from being formed.
The ultimate purpose of quantum crypto is to prevent eavesdropping on your channel. With quantum crypto, mitm attacks will almost always be the easiest form of attack so you can't trust quantum crypto if you can't prevent mitm attacks. If you share enough information to detect and prevent an mitm attack, you share enough info to form a classical crypto system with equivalent protection (as in, if you don't know who you are talking to, there's fundamentally no way to know if you've been mitm'ed, quantum crypto or not, so you have to share some kind of info with the other party in order to prove the end of the system is your intended recipient, and you can't bootstrap that sharing with your quantum crypto system so you must have found some secure key distribution mechanism to do so prior to using the quantum system - this is fundamentally the key distribution problem, and quantum doesn't actually help with this part it just obfuscates that it's happening because people get distracted by the shiny uncertainty principle math).
That required shared info is what the security of your quantum crypto "protected" system is actually built on. You can do just as well at protecting your transmissions against eavesdropping using classical methods far more cheaply and far more easily. Someone, (possibly Bernstein?, it's been a long time since I was thinking about this stuff), wrote a paper in the late 90's on communicating over noisy channels (or using noisy channels to a public random number source? as I said, it's been 20 years) and showed as long as you could estimate/demonstrate that your channel had lower noise than your opponents you could use the knowledge of that noise difference to deliver any desired level of security through the channel. That paper didn't make an explicit connection to quantum crypto because quantum crypto was so new and so niche at the time, but all Quantum Crypto is really doing is providing a way to get a good estimate of the noise ratios between your channel and your attacker's channel. That's handy, but mostly theater. The rest works just as well classically.
The NSA recently issued guidance to government agencies that it "does not consider QKD a practical security solution for protecting national security information".
https://media.defense.gov/2021/Aug/04/2002821837/-1/-1/1/Qua...