Feeds

Quantum crypto backdoor closed

Cambridge boffins patch photon-splitting vuln

Protecting against web application threats using SSL

Researchers believe they have secured a potential backdoor in a cryptography technique known as Quantum Key Distribution (QKD).

The QKD method involves the use of laser diodes to transmit crypto keys along fibre optic lines as streams of light quanta – individual photons. Any attempt to eavesdrop on the transmission involves measuring it in some way at a quantum level, which will necessarily alter the transmitted data and reveal to the communicating parties that the key is compromised.

The scientists at the Toshiba Research Europe Labs at Cambridge found that the laser diodes sometimes transmitted an extra photon in response to an energy pulse designed to elicit only one. This would allow an attacker to measure the second photon and leave the first untouched, potentially reading the secret key without being rumbled. This problem was especially prevalent when using stronger pulses so as to increase the rate at which key data could be sent.

But a team bossed by Dr Andrew Shields, Quantum Information group leader at Toshiba Research Europe, has stymied such so-called "pulse-splitting" attacks by introducing lower-intensity "decoy photons" to verify that a transmission is unmonitored.

According to Shields and his team, these decoy pulses seldom have a trailing partner and as such are impossible to read covertly. The communicating parties can use the decoys to check that no eavesdropping has taken place, so be assured that their higher-intensity, higher-bandwidth multiphoton stream of keys is uncompromised.

"Using these new methods for QKD we can distribute many more secret keys per second, while at the same time guaranteeing the unconditional security of each," says Shields. "This enables QKD to be used for a number of important applications such as encryption of high bandwidth data links."

QKD can now transmit at 5.5kbits/sec over a 25km optical fibre, a hundred times the previous rate.

Shields' crew has also, in a further burst of enthusiasm, rendered its own research ultimately irrelevant. The team has developed a new class of nano-diodes which are so small – at 45nm across – they can contain only a few electrons. This means they can only ever emit a single photon at the selected wavelength, so sidestepping the multi-photon minefield entirely. ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
China hacked US Army transport orgs TWENTY TIMES in ONE YEAR
FBI et al knew of nine hacks - but didn't tell TRANSCOM
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.