Quantum holds the key to secure conference calls(phys.org)
phys.org
Quantum holds the key to secure conference calls
https://phys.org/news/2021-06-quantum-key-conference.html
4 comments
Maybe not for consumer devices, but maybe to secure the connections of long communication links which are already physically switched (fiber, laser, etc) to protect against MITM?
Everything you said is right, except the part about quantum networks needing to do physical circuit switching.
For example, consider a series of quantum routers. Each just continuously builds entanglement with its neighbors. When you want to send a qubit to a destination, a path is calculated and routers along the path perform entanglement swapping until you and the receiver share an EPR pair. Then you use that EPR pair to teleport the qubit to the receiver. No cables get moved; it's just changing which qubit pairs are measured in the Bell basis.
...Admittedly this is way beyond current capabilities. It basically requires the routers to be error corrected quantum computers (you need to do entanglement distillation to pump noise out of the system).
For example, consider a series of quantum routers. Each just continuously builds entanglement with its neighbors. When you want to send a qubit to a destination, a path is calculated and routers along the path perform entanglement swapping until you and the receiver share an EPR pair. Then you use that EPR pair to teleport the qubit to the receiver. No cables get moved; it's just changing which qubit pairs are measured in the Bell basis.
...Admittedly this is way beyond current capabilities. It basically requires the routers to be error corrected quantum computers (you need to do entanglement distillation to pump noise out of the system).
The pre-shared key is not required, although you don’t really know who you are talking to, so maybe that’s how it’s used. See my response on this: https://news.ycombinator.com/item?id=27412636
QKD is snake oil. It rears its head once in a while. Wake me when quantum crypto provides authentication, on an end-to-end basis, and without having to use expensive kit. Until then, merely doing key exchange and encryption is not enough and is pointless because a) it's point-to-point rather than end-to-end, b) we already have superior classical technology that does authentication, key exchange, and encryption w/ integrity protection, all for very cheap and more than secure enough.
Actual research behind the article: https://arxiv.org/abs/2002.01491
This protocol depends on multipartite entanglement, so it does seem quite far away from being practical for anything yet.
If quantum routers were a solved problem and we had a quantum internet (last I checked, we do not), for this we would also need some form of 'coherent multicast routing'.
This protocol depends on multipartite entanglement, so it does seem quite far away from being practical for anything yet.
If quantum routers were a solved problem and we had a quantum internet (last I checked, we do not), for this we would also need some form of 'coherent multicast routing'.
There was a startup company I met with a long time ago that was selling QKD to Wall St. They kept saying that sales were the proof that it worked. I’m not so sure they were actually doing it right.
For some background, the security of QKD relies on a very ‘lucky’ chain of events. I will try to detail it from (very old) memory. Please, I encourage you to look it up and correct me.
First you need to generate a single coherent photon. This is impossible with a LED, so you have to pump it to threshold and then use a neutral-density filter to get one photon out. You cannot control this because both generation and absorption in the filter are random processes following Poisson statistics. So no matter what you do, you get a random stream of photons separated by exponential time distribution, and you want to set that time constant such that you are very unlikely to get more than one photon per time slice, because this can cause a measurement mismatch and ruin the whole key.
Then you have a 50% silvered mirror to split the photon state where it can either pass through a polarizer or not, and then combine these two states back into the same beam. Lossless combining is not trivial. Most setups just use another half-silvered mirror, but that cuts the probability of achieving coherent superposition by 75%.
Then you have to double that coherent state using maybe erbium-doped fiber. Exactly once, no losses. This is also a statistical phenomenon, and I forget the distribution of the number of doublings, but the protocol requires some high probability of exactly one. Note that at this point, you can start cheating by pumping the power and the key will still get transferred without mismatch errors, because you are amplifying a superposition state. The security, however, still depends on single photons.
Now split again, same half-silver mirror trick. You need a perfect split of one photon each way, which has a 50% probability. One of these photons gets measured by the sender, and the other gets sent to be measured by the receiver. The one that goes to the receiver has to make it through an un-amplified fiber without any losses. This is also a statistical phenomenon and of course very unlikely at significant distance.
Now we are at the measurement phase. We take a random choice of mirror orientation to measure either the transverse or circular polarization state. Split again by half and pass the amplified state through a Polaroid disk of each orientation and then collect at a photomultiplier tube. There is only a 50% chance of the photon going down the right path to be detected, but if you do get a signal, then you have a fairly good probability that you are making the correct call.
Then, you tell the other side which type of polarization you measured at each side, and whether you got any signal, but not which signal, and the key is the result from each state which was measured in the same way and both sides got a signal. So there is another 50% probability of matching.
I’ll not do the math, but you can see how unlikely this is, even in perfect conditions. Buts it’s easy to cheat in several ways to get a key that is consistent among participants, but not actually secure to eavesdroppers. I suppose you’d want to layer this along with Diffe-Hellman anyway though, so I guess it can’t hurt.
For some background, the security of QKD relies on a very ‘lucky’ chain of events. I will try to detail it from (very old) memory. Please, I encourage you to look it up and correct me.
First you need to generate a single coherent photon. This is impossible with a LED, so you have to pump it to threshold and then use a neutral-density filter to get one photon out. You cannot control this because both generation and absorption in the filter are random processes following Poisson statistics. So no matter what you do, you get a random stream of photons separated by exponential time distribution, and you want to set that time constant such that you are very unlikely to get more than one photon per time slice, because this can cause a measurement mismatch and ruin the whole key.
Then you have a 50% silvered mirror to split the photon state where it can either pass through a polarizer or not, and then combine these two states back into the same beam. Lossless combining is not trivial. Most setups just use another half-silvered mirror, but that cuts the probability of achieving coherent superposition by 75%.
Then you have to double that coherent state using maybe erbium-doped fiber. Exactly once, no losses. This is also a statistical phenomenon, and I forget the distribution of the number of doublings, but the protocol requires some high probability of exactly one. Note that at this point, you can start cheating by pumping the power and the key will still get transferred without mismatch errors, because you are amplifying a superposition state. The security, however, still depends on single photons.
Now split again, same half-silver mirror trick. You need a perfect split of one photon each way, which has a 50% probability. One of these photons gets measured by the sender, and the other gets sent to be measured by the receiver. The one that goes to the receiver has to make it through an un-amplified fiber without any losses. This is also a statistical phenomenon and of course very unlikely at significant distance.
Now we are at the measurement phase. We take a random choice of mirror orientation to measure either the transverse or circular polarization state. Split again by half and pass the amplified state through a Polaroid disk of each orientation and then collect at a photomultiplier tube. There is only a 50% chance of the photon going down the right path to be detected, but if you do get a signal, then you have a fairly good probability that you are making the correct call.
Then, you tell the other side which type of polarization you measured at each side, and whether you got any signal, but not which signal, and the key is the result from each state which was measured in the same way and both sides got a signal. So there is another 50% probability of matching.
I’ll not do the math, but you can see how unlikely this is, even in perfect conditions. Buts it’s easy to cheat in several ways to get a key that is consistent among participants, but not actually secure to eavesdroppers. I suppose you’d want to layer this along with Diffe-Hellman anyway though, so I guess it can’t hurt.
Another serious drawback is that QKD requires having some kind of direct physical connection between the communicating partners. Even if we had perfect quantum repeaters (which we really don't), this would require going back to 19th century telephone exchanges that physically plug together cables (or fibers in this case). The scaling of a global network would be infinitely worse than the modern packet-switched internet.
At best, QKD could provide a type of forward secrecy against someone stealing your keys or breaking AES in the far future. This comes at the cost of extreme impracticability. Not to speak of the host of side-channel attacks and other implementation vulnerabilities that have been found in commercial QKD systems.
I think that QKD is a fun idea to explore, but I find it really disheartening that these pratical issues are almost never openly discussed in the community. And pop-sci articles usually get pretty much everything wrong about the topic.