Guy Roberts Quantum Key Distribution in the GÉANT network Linz 31 May 2017 The security in current encryption algorithms typically relies on hard mathematical problems: the integer factorization problem, the discrete logarithm problem or
"Guy Roberts Quantum Key Distribution in the GÉANT" is the property of its rightful owner. Permission is granted to
download and print the materials on this website for personal, non-commercial use only, and to display it
on your personal computer provided you do not modify the materials and that you retain all copyright
notices contained in the materials. By downloading content from our website, you accept the terms of this
agreement.
Presentation Transcript
01
Guy Roberts Quantum Key Distribution in the GÉANT network Linz 31 May 2017<br>
02
The security in current encryption algorithms typically relies on hard mathematical problems: the integer factorization problem, the discrete logarithm problem or the elliptic-curve discrete logarithm problem.
These hard math problems are expected to be overcome once quantum computers become available.
Network providers need to start thinking nowabout ways building quantum-proof encryption.
Quantum Key Distribution (QKD) is one solution The Challenge<br>
03
Page text Page title<br>
04
The Challenge:
Can GÉANT deliver this Quantum Manifesto goal?
How far have can we go based on the current generation of technology?
What still needs to be do be done?
Action plan:
Lab testing has been carried out with Toshiba on the GÉANT transmission equipment to understand what we can do with the current generation equipment
Find applications for current generation technology
Plan for the future Can GÉANT deliver on the Quantum Manifesto goal?<br>
05
Single photon QKD
In quantum mechanics, the principle of quantum indeterminacy means that measuring an unknown quantum state changes that state in some way.
Indeterminacy is used to detect any eavesdropping on single photon based information.
Entanglement based QKD
Entanglement occurs when the quantum states of two objects become linked together in such a way that they must be described by a combined quantum state.
Entanglement means that, performing a measurement on one object affects the other.
If an entangled pair of objects is shared between two parties, anyone intercepting either object alters the overall system, revealing the presence of the third party (and the amount of information they have gained). Types of QKD<br>
06
Implementing QKD Data for transmission is encrypted using one-time pad method.
This allows a large volume of data to be sent with one short key that can be refreshed rapidly.
Keys are distributed between Alice and Bob using a quantum channel.
A quantum key protocol such as BB84 is used for key transmission. QKD Alice QKD Bob Data AES256 AES256 BB84<br>
07
BB84 is a quantum cryptography protocol that is ‘provably’ secure
Relies on the quantum property that information gain is only possible at the expense of disturbing the signal (single photon method).
However, in QKD protocols, such as BB84, a single photon source is assumed to be used by the sender, Alice.
In reality, a perfect single photon source will slow down key distribution over high-loss links.
Need to increase key rate – solution: Decoy State. Key exchange protocol: BB84<br>
08
Real-world QKD optical sources are multi-photon. A potential security loophole exists when Alice uses multi-photon states.
To minimize the effects of multi-photon states, Alice would have to use a low-power source, which results in a relatively low speed of QKD.
To solve this, ‘Decoy State’ QKD varies the photon intensity.
States are transmitted by Alice using randomly chosen intensity levels (one signal state and several decoy states), resulting in varying photon number statistics throughout the channel.
The resulting key transmission rate is higher, but the risk of attack remainsvery low <10-10 Decoy state for BB84<br>
09
Toshiba Quantum Encryption System Features:
World’s leading 1Mbit/s secure key rate Quantum Key Distribution (QKD)
Highest level of verifiable security with theoretically rigorous proof
Operation over normal fibre networks Proprietary Technology:
Active status tracking for stable operation
Self-differencing semiconductor detectors – room-temperature operation for improved reliability and reduced power consumption
BB84 protocol with decoy states - failure probability < 10-10<br>
10
Quantum Key distribution technology<br>
11
Add/drop of quantum channel into Infinera Infinera DTN-X: 500Gbps super-channel with 10 waves on photonic Integrated Circuit (PIC)
QKD operates at 1GHz with quantum channel at 1550nm
Multiplexed QKD and DTN-X traffic in the forward direction<br>
12
Combing Toshiba QKD with Infinera DTN-X Optical spectrum shows the Infinera OCG data channels and amplified spontaneous emission (ASE) from DTN-X dominates quantum signal
Designed filtering system to remove ASE at quantum wavelength
Filtering also removes effect of Raman scattering in the fibre
Mux also used to insert quantum channel<br>
13
QKD Mux testing in GÉANT lab in May
James Dynes Toshiba researcher adjusts quantum mux In the Lab<br>
14
Multiplexing Results – Infinera DTN-X Pre FEC Bit Error Rate (BER) depends on receiver power.
Obtain minimum receiver power of just over -30dBm for both 50km and 100km
More sensitive receiver card would give a further 4dB improvement<br>
15
Multiplexing Results – Infinera DTN-X Used minimum receiver power to model QKD secure bit rate.
Obtain > 1Mbps @ 50km of fibre.
With a narrow 15GHz filter in the quantum channel, reach > 90km.
More sensitive receiver card further extends QKD reach > 100km
note: multiple OCGs will reduce reach<br>
16
Limitations and next steps We have demonstrated distribution Quantum keys over 100km of with Infinera
Excellent key transmission rate of >1Mbps at 50km
Currently technology will not work over optical amplifiers, so limited to single optical spans.
Trusted nodes are needed to create new keys for each span
In the future QKD-friendly amplifiers need to be developed to allow QKD channel to bypass amplifiers.<br>