Live data from Hacker News

Unforgeable Quantum Tokens Delivered over Fiber Network

spectrum.ieee.org

11–20 of 26 posts

Re: Unforgeable Quantum Tokens Delivered over Fiber Network

#11

I am worried about the future of quantum tokens... Whilst theoretically they are secure, I worry about potential huge side-channels allowing leaking of the key... All it takes is a few extra photons emitted at some harmonic frequency for the key to be leaked... I would much prefer dumb hardware and clever digital software, because at least software is much easier to secure against side channels, and much easier to au…

Security is never about absolutes. It’s about relative costs vs the attacker. It seems like this system adds a strong enough layer of security over the transport that the attacker would switch to going after the endpoints instead.

Re: Unforgeable Quantum Tokens Delivered over Fiber Network

#12
post #4

I am worried about the future of quantum tokens... Whilst theoretically they are secure, I worry about potential huge side-channels allowing leaking of the key... All it takes is a few extra photons emitted at some harmonic frequency for the key to be leaked... I would much prefer dumb hardware and clever digital software, because at least software is much easier to secure against side channels, and much easier to au…

In principle quantum communication has no side channels because side channels act like measurements, and measurements make it not a functioning quantum channel in the first place. So you need to have already solved side channel issues for basic function. That said, wherever you convert the quantum data into classical data there will be potential side channels. For example, there have been attacks based on using a las…

The larger issue for most quantum key exchange setups is the transition from classical to quantum: you want not to accidentally generate two unentangled photons in the same secret polarization.

Re: Unforgeable Quantum Tokens Delivered over Fiber Network

#13
Does this have anything resembling details? The press release is here:

https://www.nec.com/en/press/202411/global_20241118_01.html

And it has goodies like:

> Token: A digital certificate indicating certain rights and values, such as digital assets, user information, and access rights.

That is not much detail.

> Quantum key distribution (QKD) systems use quantum mechanics to share random secret keys between two communicating parties in order to guarantee secure communication, and then encrypt and decrypt information based on those keys. (Patented (as of November 18, 2024))

This sounds like rather old technology. What exactly is novel here?

In any case, the article’s drawing makes it look like the customer’s “token” is some classical information. This cannot work.

Re: Unforgeable Quantum Tokens Delivered over Fiber Network

#14

Earlier quoted context omitted.

Yes, in theory. In practice, photon generators won't behave perfectly. There are lots of possible attacks, like photon splitting [1]. [1] https://onlinelibrary.wiley.com/doi/full/10.1002/qute.202300...

Once you put error correction, doenn't you lose all the nice properties of the non cloning theorem? If the protocol tolerates 30% of errors, doesn't it tolerate 30% of MITM? (60%??)

You don't need error correction for some crypto primitives. There are QKD networks deployed that don't have that kind of error correction, as far as I know.

Re: Unforgeable Quantum Tokens Delivered over Fiber Network

#16
Is there any projected practical use for QKD apart from being a jobs program for researchers?

(This is a thing I am fine with, research is research and it doesn't necessarily need a near-term practical outcome, but why is it "sold" to the public as though there is some useful capability coming just around the corner?).

Who would use dedicated fiber to get secrets between point A and point B? Am I just insufficiently imaginative?

Whenever I read these headlines I am reminded of how much biological research needs to have a "could one day cure cancer" to give funders and journalists a hook.

Re: Unforgeable Quantum Tokens Delivered over Fiber Network

#18

Earlier quoted context omitted.

With quantum tokens, law enforcement have to crack your physical devices, so they at least have to good-old-fashion bug your devices. With classical schemes, they can intercept on the way. I wouldn't say that current side-channels, most certainly enabled by hardware, not software, are easier to audit.

“lawful intercept” can be mandated to be built into anything

Yes, but it's much easier to see it in hardware than in software.

Re: Unforgeable Quantum Tokens Delivered over Fiber Network

#19

Earlier quoted context omitted.

Yes, in theory. In practice, photon generators won't behave perfectly. There are lots of possible attacks, like photon splitting [1]. [1] https://onlinelibrary.wiley.com/doi/full/10.1002/qute.202300...

Once you put error correction, doenn't you lose all the nice properties of the non cloning theorem? If the protocol tolerates 30% of errors, doesn't it tolerate 30% of MITM? (60%??)

No-cloning theorem applies to logical qubits too! That "30% of errors" doesn't allow you to read out the logical state. Information is physical.

Re: Unforgeable Quantum Tokens Delivered over Fiber Network

#20

Is there any projected practical use for QKD apart from being a jobs program for researchers? (This is a thing I am fine with, research is research and it doesn't necessarily need a near-term practical outcome, but why is it "sold" to the public as though there is some useful capability coming just around the corner?). Who would use dedicated fiber to get secrets between point A and point B? Am I just insufficiently…

Large companies and governments go to some lengths to protect their internal communications between their sites.

Cloud providers also have some dedicated fiber between their data centers.

Post reply on HN