26C3: Researchers demonstrate brilliant quantum hack
Two researchers have shown how they can eavesdrop unnoticed on a provably secure quantum key distribution. To do so, Qin Liu and Sebastien Sauge did not of course change the laws of quantum physics. Instead, in archetypal hacker fashion, they successfully attacked the weakest point of a real world, and thus imperfect, implementation of a quantum key distribution system.
Quantum key distribution (QKD) is aimed at permitting absolute security in exchanging secret keys. Simplifying somewhat, it is based on sending two quantum mechanically entangled photons, which can be measured as having a value of 0 or 1, to Alice and Bob. Until either Alice or Bob actually determines the state of one of the photon, that state remains indeterminate. The only certainty is that if Alice at some point measures a 1, Bob will also subsequently measure a 1. If a malicious Eve intercepts the photons, she can read the value, but having done so is unable, according to Heisenberg's uncertainty principle, to generate another photon with the same properties, thus allowing Bob to discover the subterfuge.
And this is where many real – and in some cases already commercially available – QKD systems fall down. Their detectors for measuring individual photons are in fact macroscopic systems. Liu and Sauge gave a live demonstration in Berlin, in which they blinded the detector from a typical QKD system using a bright light source so that it no longer responded to individual photons. The researchers could, though, still trigger the detector using intense targeted pulses. Instead of acting as a quantum mechanical measuring device, they turned Bob's detector into a kind of macroscopic switch, which they operated manually to spoof Bob photons with a specific (polarization) value.
The team was able to use this technique to eavesdrop on a real world QKD system which distributed keys over distances of 290 metres via fibre optic cables. Eve was able to successfully insert herself into the optical fibre and eavesdrop the full secret key without either Alice or Bob becoming aware of her subterfuge.