Feature Do the laws of physics trump mathematical complexity, or is Quantum Key Distribution (QKD) nothing more than 21st-century enterprise encryption snake oil? The number of QKD news headlines that have included unhackable, uncrackable or unbreakable could certainly lead you towards the former conclusion.
However, we at The Reg are unrelenting sceptics for our sins and take all such claims with a bulk-buy bag of Saxa. What this correspondent is not, however, is a physicist nor a mathematician, let alone a quantum cryptography expert. Thankfully, I know several people who are, so I asked them the difficult questions. Here's how those conversations went.
I can tell you what QKD isn't, and that's quantum cryptography. Instead, as the name suggests, it's just the part that deals with the exchange of encryption keys.
As defined by the creators of the first Quantum key distribution (QKD) protocol, (Bennett and Brassard, 1984) it is a method to solve the problem of the need to distribute secret keys among distant Alice and Bobs in order for cryptography to work. The way QKD solves this problem is by using quantum communication. "It relies on the fact that any attempt of an adversary to wiretap the communication would, by the laws of quantum mechanics, inevitably introduce disturbances which can be detected."
Quantum security expert, mathematician and security researcher Dr Mark Carney explains there "are a few fundamental requirements for QKD to work between Alice (A) and Bob (B), these being a quantum key exchange protocol to guarantee the key exchange has a level of security, a quantum and classical channel between A and B, and the relevant hardware and control software for A and B to enact the protocol we started with."
If you are the diagrammatical type, there's a nifty if nerdy explanatory one here.
It's kind of a given that, in and of themselves, quantum key exchange protocols are primarily very secure, as Dr Carney says most are derived from either BB84 (said QKD protocol of Bennett and Brassard, 1984) or E91 (Eckert, 1991) and sometimes a mixture of the two.
"They've had a lot of scrutiny, but they are generally considered to be solid protocols," Dr Carney says, "and when you see people claiming that 'quantum key exchange is totally secure and unhackable' there are a few things that are meant: that the key length is good (at least 256 bits), the protocol can detect someone eavesdropping on the quantum channel and the entropy of the system gives unpredictable keys, and the use of quantum states to encode these means they are tamper-evident."
So, if the protocol is accepted as secure, where do the snake oil claims enter the equation? According to Dr Carney, it's in the implementation where things start to get very sticky.
"We all know that hardware, firmware, and software have bugs even the most well researched, well assessed, widely hacked pieces of tech such as the smartphone regularly has bug updates, security fixes, and emergency patches. Bug-free code is hard, and it shouldn't be considered that the control systems for QKD are any different," Carney insists.
In other words, it's all well and good having a perfected quantum protocol, but if someone can do memory analysis on A or B's systems, then your "super secure" key can get pwned. "It's monumentally naive in my view that the companies producing QKD tech don't take this head on," Dr Carney concludes. "Hiding behind 'magic quantum woo-woo security' is only going to go so far before people start realising."
Professor Rob Young, director of the Quantum Technology Centre at Lancaster University, agrees that there is a gap between an ideal QKD implementation and a real system, as putting the theory into practice isn't easy without making compromises.
QKD connections can be blocked using a DDoS attack as simple as using a pneumatic drill in the vicinity of the cable
"When you generate the states to send from the transmitter," he explains, "errors are made, and detecting them at the receiver efficiently is challenging. Security proofs typically rely on a long list of often unmet assumptions in the real world."
Then there are the hardware limitations, with most commercially implemented QKD systems using a discrete-state protocol sending single photons down low-loss fibres. "Photons can travel a surprising distance before being absorbed, but it means that the data exchange rate falls off exponentially with distance," Young says.
"Nodes in networks need to be trusted currently, as we can't practically relay or switch quantum channels without trusting the nodes. Solutions to these problems are in development, but they could be years away from commercial implementation."
This lack of quantum repeaters is a red flag, according to Duncan Jones, head of Quantum Cybersecurity at Cambridge Quantum, who warns that "trusted repeaters" are not the same thing. "In most cases this simply means a trusted box which reads the key material from one fibre cable and re-transmits it down another. This is not a quantum-safe approach and negates the security benefits of QKD."
Then there's the motorway junction conundrum. Over to Andersen Cheng, CEO at Post-Quantum, to explain. Cheng points to problems such as QKD only telling you that a person-in-the-middle attack has happened, with photons disturbed because of the interception, but not where that attack is taking place or how many attacks are happening.
"If someone is going to put a tap along your 150km high-grade clear fibre-optic cable, how are you going to locate and weed out those taps quickly?" Cheng asks.
What if an attacker locates your cable grid and cuts a cable off? Where is the contingency for redundancy to ensure no disruption? This is where the motorway junction conundrum comes in.
"QKD is like two junctions of a motorway," Cheng explains. "You know car accidents are happening because the road surface is being attacked, but you do not know how many accidents have happened or where or who the culprit is, so you cannot go and kick the offenders out and patch up the road surface."
This all comes to the fore when Anderson insists: "QKD connections can be blocked using a DDoS attack as simple as using a pneumatic drill in the vicinity of the cable."
Sally Epstein, head of Strategic Technology at Cambridge Consultants, throws a couple of pertinent questions into the "ask any QKD vendor" ring.
Quantum-safe cryptography, coupled with verifiable quantum key generation, is an excellent approach to the same problem and works perfectly today
"1. Supply chain: There is a much greater potential for well-funded bad actors to get into the supply chain. How do they manage their supply chain security?
"2. Human fallibility: There are almost certainly exploitable weaknesses in the control software, optical sub-assemblies, electronic, firmware, etc. What penetration testing has the supplier conducted in terms of software and hardware?"
Professor Young thinks that QKD currently offers little return on investment for your average enterprise. "QKD can distribute keys with provable security metrics, but current systems are expensive, slow and difficult to implement," he says.
As has already been pointed out, security proofs are generally based on ideal cases without taking the actual physical implementation into account. This, Young says, "troubles the central premise of using QKD in the first place."
However, he doesn't think that the limitations are fundamental and sees an exciting future for the technology.
Because QKD technology is still maturing, and keys can only be sent across relatively short distances using dedicated fibre-optic cables, Jones argues that "only the biggest enterprises and telcos should be spending any money on researching this technology today."
Not least, he says, because the problems QKD solves are equally well addressed through different means. "Quantum-safe cryptography, coupled with verifiable quantum key generation, is an excellent approach to the same problem and works perfectly today," Jones concludes.
Professor Andrew Lord, head of Optical Network Research at BT, has a less pessimistic outlook.
"Our trial with NCC in Bristol illustrates a client with a need to transmit data which should remain secure for many years into the future," Lord told The Reg. "QKD is attractive here because it provides security against the 'tap now, decrypt later' risk, where data could be stored and decrypted when a quantum computer becomes available."
The UK's National Cyber Security Centre (NCSC) has gone on the record to state it does not endorse the use of QKD for any government or military application, and the National Security Agency (NSA) in the US has reached the same conclusion.
Jones of Cambridge Quantum says he completely agrees with the NCSC/NSA perspectives because the "first generation of quantum security technologies has failed to deliver tangible benefits for commercial or government applications."
Young goes further: "Both NCSC and NSA echo the views of all serious cryptographers with regards to QKD, and I am in complete agreement with them."
So what needs to change to make QKD solutions relevant to enterprises in the real world? Lord admits that the specialised hardware requirements of QKD does mean it won't be the best solution for all use cases, but foresees "photonic-chip based QKD ultimately bringing the price down to a point where it can be integrated into standard optical transmission equipment."
Dr Carney adds: "In closing, all this leaves us with the biggest misunderstanding about QKD vs classical key exchange; in classical key exchange the mathematics that makes Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) or your favourite Post-Quantum Cryptography (PQC) key exchange secure is distinct and independent of the physical channel (the classical channel) that is being used for the protocol.
"On a QKD system, the mathematics is in some way intrinsically, and necessarily, linked to the actual physicality of the system. This situation is unavoidable, and we would do well to design for and around it."
More:
- Physicists breed Schrdinger's cats to find boundaries of the | Cosmos - Cosmos [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- The application of three-axis low energy spectroscopy in quantum physics research - Phys.Org [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Scientists 'BREED' Schrodinger's Cat in massive quantum physics breakthrough - Express.co.uk [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Quantum Physics: Are Entangled Particles Connected Via An Undetected Dimension? - Forbes [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- The World Of Quantum Physics: EVERYTHING Is Energy : In5D ... [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Introduction to quantum mechanics - Wikipedia [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- A general election, like quantum physics, is a thing of waves and particles - The Tablet [Last Updated On: May 4th, 2017] [Originally Added On: May 4th, 2017]
- 14-Year-Old Earns Physics Degree From TCU CBS Dallas / Fort ... - CBS DFW [Last Updated On: May 11th, 2017] [Originally Added On: May 11th, 2017]
- Quantum Entanglement Persists Even Under High Accelerations ... - International Business Times [Last Updated On: May 11th, 2017] [Originally Added On: May 11th, 2017]
- Quantum Entanglement Persists Even Under High Accelerations, Experiments Reveal - International Business Times [Last Updated On: May 11th, 2017] [Originally Added On: May 11th, 2017]
- Quantum - Wikipedia [Last Updated On: May 11th, 2017] [Originally Added On: May 11th, 2017]
- Unbreakable quantum entanglement - Phys.Org [Last Updated On: May 11th, 2017] [Originally Added On: May 11th, 2017]
- Physics may bring faster solutions for tough computational problems - Phys.Org [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- UBC researchers propose answer to fundamental space problem - CBC.ca [Last Updated On: May 17th, 2017] [Originally Added On: May 17th, 2017]
- Quantum Biology and the Frog Prince - ScienceBlog.com (blog) [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- The Marriage Of Einstein's Theory Of Relativity And Quantum Physics Depends On The Pull Of Gravity - Forbes [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- New Research May Reconcile General Relativity and Quantum Mechanics - Futurism [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- The Bizarre Quantum Test That Could Keep Your Data Secure - WIRED [Last Updated On: May 20th, 2017] [Originally Added On: May 20th, 2017]
- Testing quantum field theory in a quantum simulator - Phys.org - Phys.Org [Last Updated On: May 20th, 2017] [Originally Added On: May 20th, 2017]
- A classic quantum test could reveal the limits of the human mind - New Scientist [Last Updated On: May 20th, 2017] [Originally Added On: May 20th, 2017]
- Teleportation Could Be Possible Using Quantum Physics - Futurism - Futurism [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- Nobel winner to talk cats, computers and quantum physics - AroundtheO [Last Updated On: May 23rd, 2017] [Originally Added On: May 23rd, 2017]
- Could Ant-Man Beat Superman With Quantum Physics? - Heroic Hollywood (blog) [Last Updated On: May 26th, 2017] [Originally Added On: May 26th, 2017]
- Physicists Discover Geometry Underlying Particle Physics [Last Updated On: May 26th, 2017] [Originally Added On: May 26th, 2017]
- Home - Center for Quantum Activism [Last Updated On: May 26th, 2017] [Originally Added On: May 26th, 2017]
- Physics - Wikipedia [Last Updated On: May 26th, 2017] [Originally Added On: May 26th, 2017]
- What Quantum Physics Can Tell Us about the Afterlife ... [Last Updated On: May 26th, 2017] [Originally Added On: May 26th, 2017]
- A Quantum Physicist Explains How Ant-Man Can Beat Superman - Inverse [Last Updated On: May 28th, 2017] [Originally Added On: May 28th, 2017]
- Academic Journal: Quantum Physics Is 'Oppressive' to Marginalized People - National Review [Last Updated On: May 30th, 2017] [Originally Added On: May 30th, 2017]
- University of Arizona Scholar Creates a Feminist Brand of Physics to ... - Breitbart News [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Feminist Launches 'Intersectional Quantum Physics' to End Newton's 'Oppression' - PJ Media [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- In atomic propellers, quantum phenomena can mimic everyday ... - Phys.Org [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Quantum physics is oppressive - Patheos - Patheos (blog) [Last Updated On: June 5th, 2017] [Originally Added On: June 5th, 2017]
- It's widely abused as a buzzword. But can quantum mechanics explain how we think? - National Post [Last Updated On: June 5th, 2017] [Originally Added On: June 5th, 2017]
- Quantum Physics and Love are Super Weird and Confusing, but This Play Makes Sense of Them Both - LA Magazine [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- One step closer to the quantum internet by distillation - Phys.Org [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Solving systems of linear equations with quantum mechanics - Phys.Org [Last Updated On: June 10th, 2017] [Originally Added On: June 10th, 2017]
- Neural networks take on quantum entanglement - Phys.Org [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Chinese satellite breaks a quantum physics record, beams entangled photons from space to Earth - Los Angeles Times [Last Updated On: June 15th, 2017] [Originally Added On: June 15th, 2017]
- Cybersecurity Attacks Are a Global Threat. Chinese Scientists Have the Answer: Quantum Mechanics - Newsweek [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- New Quantum-Entanglement Record Could Spur Hack-Proof Communications - Yahoo News [Last Updated On: June 18th, 2017] [Originally Added On: June 18th, 2017]
- What Is Quantum Mechanics? - livescience.com [Last Updated On: June 18th, 2017] [Originally Added On: June 18th, 2017]
- China sets new record for quantum entanglement en route to build new communication network - NEWS.com.au [Last Updated On: June 19th, 2017] [Originally Added On: June 19th, 2017]
- Physicists Demonstrate Record Breaking Long-Distance Quantum Entanglement in Space - Futurism [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Viewpoint: A Roadmap for a Scalable Topological Quantum Computer - Physics [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- How Schrdinger's Cat Helps Explain the New Findings About the Quantum Zeno Effect - Futurism [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- BMW and Volkswagen Try to Beat Apple and Google at Their Own Game - New York Times [Last Updated On: June 23rd, 2017] [Originally Added On: June 23rd, 2017]
- How quantum physics could revolutionize casinos and betting if you can understand it - Casinopedia [Last Updated On: June 23rd, 2017] [Originally Added On: June 23rd, 2017]
- Quantum thermometer or optical refrigerator? - Phys.org - Phys.Org [Last Updated On: June 23rd, 2017] [Originally Added On: June 23rd, 2017]
- Atomic imperfections move quantum communication network closer ... - Phys.Org [Last Updated On: June 24th, 2017] [Originally Added On: June 24th, 2017]
- DoE Launches Chicago Quantum Exchange - HPCwire (blog) [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Google to Achieve "Supremacy" in Quantum Computing by the End of 2017 - Big Think [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- Physicists settle debate over how exotic quantum particles form - Phys.Org [Last Updated On: June 27th, 2017] [Originally Added On: June 27th, 2017]
- Physicists make quantum leap in understanding life's nanoscale machinery - Phys.Org [Last Updated On: June 27th, 2017] [Originally Added On: June 27th, 2017]
- How quantum trickery can scramble cause and effect - Nature.com [Last Updated On: June 28th, 2017] [Originally Added On: June 28th, 2017]
- Berkeley Lab Intern Finds Her Way in Particle Physics | Berkeley Lab - Lawrence Berkeley National Laboratory [Last Updated On: June 28th, 2017] [Originally Added On: June 28th, 2017]
- Quantum Physics News - Phys.org - News and Articles on ... [Last Updated On: June 28th, 2017] [Originally Added On: June 28th, 2017]
- Quantum computers are about to get real - Science News Magazine [Last Updated On: June 29th, 2017] [Originally Added On: June 29th, 2017]
- Physics4Kids.com: Modern Physics: Quantum Mechanics [Last Updated On: June 29th, 2017] [Originally Added On: June 29th, 2017]
- Payments Innovation - A Quantum World Of Payments - Finextra (blog) [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- Why can't quantum theory and relativity get along? - Brantford Expositor [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- New method could enable more stable and scalable quantum computing, physicists report - Phys.Org [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- Telecommunications, Meet Quantum Physics - Electronics360 [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- How young is too young to talk to kids about science? Never, says one quantum physicist - ABC Local [Last Updated On: July 9th, 2017] [Originally Added On: July 9th, 2017]
- Supercool breakthrough brings new quantum benchmark - Phys.org - Phys.Org [Last Updated On: July 9th, 2017] [Originally Added On: July 9th, 2017]
- Physics For Toddlers . News | OPB - OPB News [Last Updated On: July 9th, 2017] [Originally Added On: July 9th, 2017]
- Quantum Physics Provide Evidence that the Future Influences the Past - Edgy Labs (blog) [Last Updated On: July 9th, 2017] [Originally Added On: July 9th, 2017]
- This quantum theory predicts that the future might be influencing the ... - ScienceAlert [Last Updated On: July 9th, 2017] [Originally Added On: July 9th, 2017]
- Physicists May Have Discovered One of the Missing Pieces of Quantum Theory - Futurism [Last Updated On: July 9th, 2017] [Originally Added On: July 9th, 2017]
- Something New For Baby To Chew On: Rocket Science And ... - NPR - NPR [Last Updated On: July 9th, 2017] [Originally Added On: July 9th, 2017]
- A New Quantum Theory Predicts That the Future Could Be Influencing the Past - Big Think [Last Updated On: July 14th, 2017] [Originally Added On: July 14th, 2017]
- Basic Assumptions of Physics Might Require the Future to Influence ... - Gizmodo [Last Updated On: July 14th, 2017] [Originally Added On: July 14th, 2017]
- Scientists teleport particle into space in major breakthrough for quantum physics - The Independent [Last Updated On: July 14th, 2017] [Originally Added On: July 14th, 2017]
- Rockstar scientist David Reilly takes the axe to quantum physics - The Sydney Morning Herald [Last Updated On: July 14th, 2017] [Originally Added On: July 14th, 2017]
- Quantum Mechanics Could Shake Up Our Understanding of Earth's ... - Gizmodo [Last Updated On: July 14th, 2017] [Originally Added On: July 14th, 2017]
- The Standard Model of particle physics is brilliant and completely flawed - ABC Online [Last Updated On: July 17th, 2017] [Originally Added On: July 17th, 2017]
- Quantum mechanics inside Earth's core - Phys.org - Phys.Org [Last Updated On: July 17th, 2017] [Originally Added On: July 17th, 2017]
- Making a quantum leap in space research - Shanghai Daily (subscription) [Last Updated On: August 6th, 2017] [Originally Added On: August 6th, 2017]
- Unlocking the Secrets of Quantum Physics to Create New Materials - Yu News (blog) [Last Updated On: August 6th, 2017] [Originally Added On: August 6th, 2017]
- China's Silicon Valley aims to become the country's top research center - Abacus [Last Updated On: October 16th, 2019] [Originally Added On: October 16th, 2019]







