4 ms·
But if you have a secure way of getting your quantum bits to Bob, couldn't you get your OTP there in the same way? I mean, yes, you could detect it if your stre
by cryptarch 10y ago
But if you have a secure way of getting your quantum bits to Bob, couldn't you get your OTP there in the same way? I mean, yes, you could detect it if your stream of entangled bits is intercepted while it is going, but you couldn't detect it if it was intercepted from the get go and MITM'd.
- dsacco 10y ago>>But if you have a secure way of getting your quantum bits to Bob, couldn't you get your OTP there in the same way? No, because you do not choose the information to be verified on either side. You're not choosing a key and "encoding" it into "quantum bits", you're measuring the quantum state of two entangled particles. If the quantum state matches, you have provably secure transmission. If the transmission were intercepted, the act of intercepting it would cause the measurement verification to fail due to the observer effect. The parties would be able to see that the key was intercepted because the particles were prematurely disentangled. This is quantum key distribution, which is a subset of (and often misleadingly conflated with) quantum cryptography. It is not possible to use quantum cryptography to send provably secure arbitrary data of your choosing, it's only possible to generate and distribute provably secure keys and use those for classical cryptographic communication. The reason why it's important to call it quantum key distribution is because it makes it clearer that this only solves one problem in a greater cryptosystem. Key distribution is a significant problem in cryptography, and provably secure key distribution is a great leap forward, but it's not the only problem.
- cryptarch 10y agoIs it possible to know when particles were prematurely untangled? Wouldn't that constitute transmitting information? How would you tell the difference between a set of qbits entangled with the right other set of qbits, and with a different set of qbits? If an attacker were to intercept the whole stream/set of entangled particles, wouldn't he be able to perform a MITM attack by sending you particles entangled with his particles instead? The way I mentally model "sending entangled particles and measuring them" is "sending two streams or blocks of exactly inverted random data to two locations, in a format that is impossible to recreate/forge as setting the right spins of particles is not possible". Is it so that this measurement can only be performed once, or can it be measured again later, giving the same results? Does the security of quantum entanglement come from an inability to create entangled particles with specific values, and if so, how does that solve wholesale MITM'ing, were the hole stream is intercepted on the way to one party, and then replaced by a wholy different stream with an attacker-controlled "twin" set/stream? What I mean is, if one or both streams/sets of entangled particles were intercepted as a whole before arriving at A or B (or replaced before measurement and after arrival), wouldn't that allow for an effective MITM attack? I just find it hard to see how this technology solves the physical access problem.
- jdmichal 10y agoAn important part is that no information is actually transmitted through the qubits. Information is only effectively "transferred" when measurements can be correlated. So, you can pass a key through the qubit, but the other side won't know the key until the additional measurement information arrives for correlation. A third party also viewing the entangled qubit would necessarily modify the measurements also, causing correlation failure. A man-in-the-middle attack would only be effective if they also intercepted the measurement information and replaced it with their own. In which case, yes naturally someone who can intercept all your communication and replace it arbitrarily can arbitrarily control your communication. As is used today, signing the measurement information would be an effective mechanism for preventing this. The attacker should be unable to correctly sign their own measurement information, and so you will be able to detect that the key transfer is unreliable. Once the key is reliably transferred, then it's theoretically a secure one-time pad. That is, you know that it was transferred to the party at the other end of the entangled qubit, and that it was not intercepted along the way.