Table of Contents
Fetching ...

Countermeasures for Trojan-Horse Attacks on self-compensating all-fiber polarization modulator

Alberto De Toni, Aynur Cemre Aka, Costantino Agnesi, Davide Giacomo Marangon, Giuseppe Vallone, Paolo Villoresi

TL;DR

This work analyzes Trojan Horse Attacks on the iPOGNAC self-compensating all-fiber polarization encoder used in QKD. It develops a theoretical framework bounding Eve’s information under optimal and fixed POVMs and experimentally characterizes strong-light (CW and pulsed) and weak-light THAs, revealing distinct leakage channels and defense requirements. The results show that strong-light attacks can be mitigated with moderate attenuation, while weak-light attacks necessitate substantially higher attenuation and isolation (e.g., roughly $A_{ ext{dB}} \approx \frac{1}{2}(10\log_{10}(\mu_{in}/\mu_{out}) - \Delta P)$ with $\Delta P$ capturing system losses) to constrain Eve’s guessing probability, approaching random guessing limits. The paper concludes by recommending a mixed passive-active countermeasure strategy and outlines future work, including machine-learning classifiers, to enhance state discrimination and THA resilience in practical QKD deployments.

Abstract

Quantum Key Distribution (QKD) leverages the principles of quantum mechanics to exchange a secret key between two parties. Unlike classical cryptographic systems, the security of QKD is not reliant on computational assumptions but is instead rooted in the fundamental laws of physics. In a QKD protocol, any attempt by an eavesdropper to intercept the key is detectable: this provides an unprecedented level of security, making QKD an attractive solution for secure communication in an era increasingly threatened by the advent of quantum computers and their potential to break classical cryptographic systems. However, QKD also faces several practical challenges such as transmission loss and noise in quantum channels, finite key size effects, and implementation flaws in QKD devices. Addressing these issues is crucial for the large-scale deployment of QKD and the realization of a global quantum internet. A whole body of research is dedicated to the hacking of the quantum states source, for example using Trojan-Horse attacks (THAs), where the eavesdropper injects light into the system and analyzes the back-reflected signal. In this paper, we study the vulnerabilities against THAs of the iPOGNAC encoder, first introduced in Avesani, Agnesi et al., to propose adapted countermeasures that can mitigate such attacks.

Countermeasures for Trojan-Horse Attacks on self-compensating all-fiber polarization modulator

TL;DR

This work analyzes Trojan Horse Attacks on the iPOGNAC self-compensating all-fiber polarization encoder used in QKD. It develops a theoretical framework bounding Eve’s information under optimal and fixed POVMs and experimentally characterizes strong-light (CW and pulsed) and weak-light THAs, revealing distinct leakage channels and defense requirements. The results show that strong-light attacks can be mitigated with moderate attenuation, while weak-light attacks necessitate substantially higher attenuation and isolation (e.g., roughly with capturing system losses) to constrain Eve’s guessing probability, approaching random guessing limits. The paper concludes by recommending a mixed passive-active countermeasure strategy and outlines future work, including machine-learning classifiers, to enhance state discrimination and THA resilience in practical QKD deployments.

Abstract

Quantum Key Distribution (QKD) leverages the principles of quantum mechanics to exchange a secret key between two parties. Unlike classical cryptographic systems, the security of QKD is not reliant on computational assumptions but is instead rooted in the fundamental laws of physics. In a QKD protocol, any attempt by an eavesdropper to intercept the key is detectable: this provides an unprecedented level of security, making QKD an attractive solution for secure communication in an era increasingly threatened by the advent of quantum computers and their potential to break classical cryptographic systems. However, QKD also faces several practical challenges such as transmission loss and noise in quantum channels, finite key size effects, and implementation flaws in QKD devices. Addressing these issues is crucial for the large-scale deployment of QKD and the realization of a global quantum internet. A whole body of research is dedicated to the hacking of the quantum states source, for example using Trojan-Horse attacks (THAs), where the eavesdropper injects light into the system and analyzes the back-reflected signal. In this paper, we study the vulnerabilities against THAs of the iPOGNAC encoder, first introduced in Avesani, Agnesi et al., to propose adapted countermeasures that can mitigate such attacks.
Paper Structure (15 sections, 30 equations, 11 figures, 3 tables)

This paper contains 15 sections, 30 equations, 11 figures, 3 tables.

Figures (11)

  • Figure 1: Scheme of the setup for the THA on the iPOGNAC. SM-Fibers in yellow, PM-Fibers in blue, electrical connections in black. The optical power entering inside Alice's setup is indicated as $\mu_{in}$, while the one coming out (subject to the attenuations of the Alice's system and therefore smaller than $\mu_{in}$) is indicated as $\mu_{out}$.
  • Figure 2: Theoretical prediction accuracy with respect to the mean photon number $\mu_{out}$, varying different POVMs, extinction ratios of the projective measurements, efficiencies, and experimental data for comparison.
  • Figure 3: Theoretical detection probabilities for each state and the total with respect to the mean photon number $\mu_{out}$ in the use-case of only two detectors (Extinction Ratio = 8.86 dB).
  • Figure 4: 2D-histogram of the waveform resulting from the oscilloscope, result of the optical modulation in continuous wavefront by the iPOGNAC during the THA, and $\ket{H}$, $\ket{V}$ and $\ket{D}$ symbols separately. All the waveforms presented are calculated by performing a modulo-period operation. In the top plot, the red vertical line shows the detected position of the first symbol in the original waveform.
  • Figure 5: Waveform with calculated symbol positions and classified symbols for the CWLA. Red dots show the estimated symbol locations, while thresholds are used to classify the symbol as $\ket{H}$, $\ket{V}$, or $\ket{D}$ (if the symbol location is above the threshold up, the symbol is classified as $\ket{V}$, if it is between the thresholds up and down, it is classified as $\ket{D}$, and if it is below the threshold down, it is classified as $\ket{H}$).
  • ...and 6 more figures