Skip to navigation
Latest News

Scientists uncover quantum encryption system weakness

dfata

By Stewart Mitchell

Posted on 31 Aug 2010 at 16:11

Quantum cryptography might provide everlasting security – but only if it is well implemented, according to researchers.

Quantum cryptography is supposed to be practically bomb proof. Based on the Heisenberg uncertainty principle in which observation causes perturbation, anyone trying to eavesdrop on a Quantum Key Distribution system should quickly be discovered.

However, experts have developed and demonstrated a technique exploiting imperfections in quantum cryptography systems to implement an attack.

Such commercial systems usually use photons to carry the quantum states and, according the scientists, overwhelming the photon light signals within network equipment can leave them open to an attack.

“We found that bright illumination of the detectors changed their behaviour,” said Christoffer Wittmann, a researcher at the Max Planck Institute, which developed the technique alongside experts at the Norwegian University of Science and Technology and the University of Erlangen-Nuremberg.

By flooding the detectors with bright light, we were able to send in faked light states that are classical rather than quantum

“Usually detectors are sensitive to a single photon and that is what should emerge at the other end and which shows the connection is secure. By flooding the detectors with bright light, we were able to send in faked light states that are classical rather than quantum.”

More concerning still, the hack was demonstrated using off the shelf components. However, the researchers noted the vulnerability lay with the way both the tested quantum systems - the MagiQ Technology's QPN 5505 and the ID Quantique Clavis2 - had been implemented, rather than quantum cryptography as a concept.

“It is an imperfection in the device that allows a man-in-the-middle attack, which should not normally be possible,” said Wittmann. “This is not an inherent weakness in Quantum Key Distribution, but of this implementation. By our work, we would like to strengthen the practical security of quantum cryptography systems.”

ID Quantique, a network security provider that has been collaborating with the researchers, said it was already working on counter measures to fix the problem.

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.