1
program role
2
organizing roles
108
collaborators
2011–2025
years active
Contributions
QIP QCrypt TQC talk poster presenter award · △program ◇steering ○organizing · filled = chair
8 Talks
| Title | Conference | Type | Co-authors |
|---|---|---|---|
| Plug-and-play attack on a quantum key distribution system as black box | QCRYPT 2025 | regular | Anqi Huang, Qingquan Peng, Xialong Yuan, Junxuan Liu, Yichen Liu, Zihao Chen |
Quantum key distribution (QKD) protocol has been proven to be informationally-theoretical security. Unfortunately, due to device imperfections in practice, QKD systems have exposed various vulnerabilities that are exploited by an eavesdropper to conduct quantum hackings, such as laser-seeding attacks, blinding attacks, etc. Most of these attacks currently remain only at the stage of possibility verification or white-box testing. In this paper, we propose and implemented plug-and-play attack on a QKD system as a black box, whose interface and access for the public are the only known information. Through this attack, we actively modified the gate positions and synchronization parameters of the QKD system during the calibration procedure, allowing the attack operate during the whole lifetime of the system running without being noticed. Furthermore, the implemented hacking system only connects to the quantum channel but has no access to the inside of QKD engine, which takes minutes to optimize the hacking parameters to start the eavesdropping. This work illustrates Eve's capability to successfully eavesdrop on keys from QKD systems under current conditions in a more intuitive and concrete way. |
|||
| Challenges to Physical Security of Today’s Quantum Technologies | QCRYPT 2016 | tutorial ▸ presenter | — |
| Insecurity of Detector-Device-Independent Quantum Key Distribution | QCRYPT 2016 | regular | ▸Anqi Huang, Shihan Sajeed, Shihai Sun, Feihu Xu, Marcos Curty |
| (At 2:05) Laser Damage Creates Backdoors in Quantum Cryptography | QCRYPT 2016 | regular | Shihan Sajeed, Sarah Kaiser, Poompong Chaiwongkhot, Mathieu Gagne, Jean-Philippe Bourgoin, Carter Minshull, Matthieu Legré, Thomas Jennewein, Raman Kashyap |
| Spatial-mode detector efficiency mismatch security loophole in free-space QKD | QCRYPT 2015 | regular | Poompong Chaiwongkhot, Shihan Sajeed, Jean-Philippe Bourgoin, Thomas Jennewein, Norbert Lütkenhaus |
| Securing two-way quantum communication: the monitoring detector and its flaws | QCRYPT 2014 | regular | ▸Shihan Sajeed, Igor V. Radchenko, Sarah Kaiser, Jean-Philippe Burgoin, Laurent Monat, Matthieu Legré |
|
Experimental quantum key distribution with source flaws and tight finite-key analysis
Best Student Paper Award — Feihu Xu
|
QCRYPT 2014 | regular | ▸Feihu Xu, Shihan Sajeed, Sarah Kaiser, Zhiyuan Tang, Li Qian, Hoi-Kwong Lo |
| Loopholes in implementations of quantum cryptography | QCRYPT 2011 | invited ▸ presenter | — |
35 Posters
| Title | Conference | Co-authors |
|---|---|---|
| Enabling high-speed quantum random number generation by optically injection-locking a pulsed laser | QCRYPT 2025 | Anastasiya Ponosova, Dmitry Shkrabin, Daria Ruzhitskaya, Maxim Fadeev, Roman Shakhovoy |
Our study shows that the rate of random number generation by QRNG based on interference of laser pulses is significantly more limited than expected. An increase in generation speed requires shortening the duration of laser pulses. However, the interference of short laser pulses from a single laser diode is problematic due to jitter and phase modulation (chirp). The optically injection-locked configuration proposed by L. C. Comandar for MDI QKD does not have the above disadvantages and therefore enables the design of QRNG with a high speed of random number generation. |
||
| Overview of recent results on the optical-pumping attack on quantum key distribution sources | QCRYPT 2025 | Maxim Fadeev, Irina Zhluktova, Serafima Filatova, Vladimir Kamynin, Anatoliy Sotnikov, Roman Shakhovoy, Vladimir Tsvetkov, Anastasiya Ponosova |
In this work, we demonstrate a new kind of attack on laser sources in quantum key distribution systems - the optical-pumping attack. We investigated its influence on a single distributed feedback laser diode and an optically injection-locked source configuration. The spectral dependency of this attack was also examined. We managed to increase the energy of emitted pulses using attackers light at several wavelengths. The developed optical-pumping attack should be considered as a possible threat to the security of QKD systems because the increase of pulse energy leads to overestimation of secret key rate between Alice and Bob, giving more information about secret key to Eve. |
||
| Cross polarization-intensity correlations in chip-based QKD | QCRYPT 2025 | Tianyi Xing, Álvaro Navarrete, Yongqiang Du, Zhengeng Zhao, Daniil Trefilov, Xin Hua, Xi Xiao, Kejin Wei, Marcos Curty, Anqi Huang |
Chip-based quantum key distribution (QKD) systems offer improved efficiency but may also introduce previously unrecognized security vulnerabilities. In this work, we identify and experimentally characterize cross-polarization-intensity (CPI) correlations in a real-world chip-based QKD system. Moreover, we introduce a security analysis that incorporates CPI correlations and apply it to evaluate the performance of an integrated high-speed QKD system. Our results emphasize the need for rigorous security assessments in chip-based QKD implementations. |
||
| Certification of a commercial quantum key distribution system against implementation loopholes | QCRYPT 2024 | Alexey Abrikosov, Poompong Chaiwongkhot, Aleksey Fedorov, Anqi Huang, Evgeny Kiktenko, Mikhail Petrov, Anastasiya Ponosova, Daria Ruzhitskaya, Andrey Tayduganov, Daniil Trefilov, Konstantin Zaitsev |
We report recent advances in the development of certification for quantum key distribution (QKD) systems. We give an example of a commercial QKD system that we have analysed for possible loopholes, improved to close the vulnerabilities identified, and designed a set of tests for that can be used by a certification lab [arXiv:2310.20107]. We explain some of the testbenches in this lab, such as an ultrawide spectral characterisation testbench, automated detector testing, and laser damage testbench that verifies the quality of a power limiter. This work is in line with the requirements of the ISO standard for QKD and paves the way for the creation of certification services. |
||
| Intensity correlations in decoy-state BB84 QKD systems | QCRYPT 2024 | Daniil Trefilov, Xoel Sixto, Víctor Zapatero, Anqi Huang, Marcos Curty |
The decoy-state method is a prominent approach to enhance the performance of quantum key distribution (QKD) systems that operate with weak coherent laser sources. Current experimental decoy-state QKD setups increase their secret key rate by raising the repetition rate of the transmitter, which can lead to correlations between subsequently emitted optical pulses. This phenomenon leaks information about the encoding settings, including the intensities of the generated signals, thus invalidating a basic premise of decoy-state QKD. Here, we experimentally characterize intensity correlations between the nearest-neigbouring optical pulses in two commercial prototypes of decoy-state BB84 QKD systems and show that they significantly reduce the asymptotic key rate. In addition, we study intensity correlations between pulses spaced further apart (higher-order correlations) and find that, in contrast to what has been conjectured, their impact on the intensity of the generated signals can be much higher than that of the nearest-neighbour (first-order) correlations. |
||
| Optical-pumping attack on a laser source in quantum key distribution | QCRYPT 2024 | Maxim Fadeev, Anastasiya Ponosova, Roman Shakovoi, Irina Zhluktova, Vladimir Tsvetkov |
Quantum key distribution (QKD) technology allows sharing secret keys between two parties over an insecure channel. But there are vulnerabilities in the technical implementation of systems. Laser seeding attack is one of the examples of imperfections in QKD systems. Recent works have demonstrated that Eve can manipulate output power of Alice's laser. This leads to an increase of the average photon number, emitted by Alice. But this attack can be prevented by using passive fiber-optic elements such as isolators or DWDM-filters. In this work, we demonstrate a new kind of attack namely, the optical pumping attack. This attack utilises imperfections in passive optic elements that are used in QKD systems to prevent other types of attack. Eve can use source at different wavelength to seed Alice laser, 1064 nm for example. This radiation would be absorbed by crystal within laser and create additional population inversion to inversion created by bias current, that drives Alice laser. This pumping would change average photon number at the output of Alice, leading to wrong estimation of lower bound on the secret key rate. This creates a side-channel for Eve for obtaining key information. In this work we performed this kind of attack for several wavelengths: 1064 nm, 1310 nm, 1480 nm and 2000 nm, measured changing of pulse energy, average output power and pulse shape under attacks at different wavelengths. Finally, we provide theoretical estimation of required isolation at the tested wavelengths to protect the source against the optical-pumping attack. |
||
| Optical fuse for protection of QKD transmitters against light-injection attacks | QCRYPT 2024 | Ekaterina Borisova, Anastasiya Ponosova, Boris Galagan, Vasiliy Koltashev, Natalia Arutyunyan, Elena Obraztsova, Alexey Shilko |
We propose an original device that can protect quantum key distribution (QKD) systems from the effects of intense laser radiation. Carbon nanomaterials dispersed in a polymer can be used as a fuse that interrupts key distribution when Eve tries to hack the system by high-power laser emission. Moreover, it saves system components from laser damage. |
||
| Characterisation of state preparation uncertainty in quantum key distribution | QCRYPT 2022 | Anqi Huang, Akihiro Mizutani, Hoi-Kwong Lo, Kiyoshi Tamaki |
| Creation of loopholes in QKD systems using high-power pulsed laser | QCRYPT 2022 | Daria Ruzhitskaya, Irina Zhluktova, Mikhail Petrov, Konstantin Zaitsev, Polina Acheva, Nikolay Zunikov, Alexey Shilko, Djeylan Aktas, Daniil Trefilov, Anastasiya Ponosova, Vladimir Kamynin |
| Automated testbench for checking vulnerability of single-photon detectors to bright-light attack | QCRYPT 2021 | Konstantin Zaitsev, Polina Acheva |
Quantum attacks to single-photon detectors with bright-light are known for more than a decade. Many countermeasures were suggested to protect detectors, but the most of them can close some attacks with given parameters but not a whole attack group. To solve the problem we are developing automated testbench that emulates attacks by an eavesdropper Eve. It combines emission of pulse laser and continuous-wave laser and observes detector's response. In future we hope to automatically prepare reports on detectors' safety or show bright-light attacks that were not covered by detectors' countermeasures. |
||
| Independent security analysis of a commercial quantum random number generator Quantis from ID Quantique | QCRYPT 2020 | Mikhail Petrov, Igor V. Radchenko, Damian Steiger, Renato Renner, Matthias Troyer |
We reverse-engineer, test and analyse hardware and firmware of the commercial quantum-optical random number generator Quantis from ID Quantique. We show that > 99% of its output data originates in physically random processes: random timing of photon absorption in a semiconductor material, and random growth of avalanche owing to impact ionisation. We have also found minor non-random contributions from imperfections in detector electronics and an internal processing algorithm. Our work shows that the design quality of a commercial quantum-optical randomness source can be verified without cooperation of the manufacturer and without access to the engineering documentation. |
||
| Protecting QKD sources against light-injection attacks | QCRYPT 2020 | Daria Ruzhitskaya, Anastasiya Ponosova, Friederike Johlinger, Poompong Chaiwongkhot, Vladimir Egorov, Djeylan Aktas, John Rarity, Christopher Erven, Anqi Huang |
In the age of measurement-device-independent quantum key distribution (MDI QKD) and twin- field QKD (TF QKD), the source units of these QKD schemes may become a new ``Achilles' heel" of the whole system. An adversary, Eve, can conduct various attacks on the sources by injecting lasers, whose power is limited by the laser-induced damage threshold of the quantum channel. Such an amount of power may modify the characteristics of components in a source. In this work, we study possible components to protect the source from the light-injected attacks, i.e., Trojan-horse attack, the laser-seeding attack, and the laser-damage attack. Experimental testing shows that fiber-optics isolators and circulators are good passive countermeasures because they sacrifice themselves' isolation under a high-power laser to protect other components behind them. Moreover, we find that illuminated by the high-power laser, integrated photonics QKD chips only lose the transmission of the coupler before any other change happens for the other components in the chips. |
||
| Faking photon number on transition-edge sensor | QCRYPT 2019 | Poompong Chaiwongkhot, Anqi Huang, Jiaqiang Zhong, Hao Qin, Sheng-Cai Shi |
| Controlling single-photon negative-feedback avalanche diodes using bright illumination | QCRYPT 2019 | Nigar Sultana, Anqi Huang, Thomas Jennewein |
| Controlling single-photon detector ID210 with bright light | QCRYPT 2019 | Vladimir Chistiakov, Anqi Huang, Vladimir Egorov |
| An approach for security evaluation and certification of a complete quantum communication system | QCRYPT 2019 | Shihan Sajeed, Poompong Chaiwongkhot, Anqi Huang, Hao Qin, Vladimir Egorov, Artur Gleim, Anton Kozubov, Andrei Gaidash, Vladimir Chistiakov, Artur Vasiliev |
| An optimal local model to practically emulate Bell inequalities | QCRYPT 2019 | Shihan Sajeed, Nigar Sultana, Charles Ci Wen Lim |
| Laser damage attack against optical attenuators in quantum key distribution | QCRYPT 2018 | Anqi Huang, Ruoping Li, Serguei Tchouragoulov, Vladimir Egorov |
| Generalized spatial-mode detection eciency mismatch in a free-space QKD system with Zernike polynomials | QCRYPT 2018 | Poompong Chaiwongkhot, Katanya Kuntz, Jean-Philippe Bourgoin, Norbert Lütkenhaus, Thomas Jennewein |
| Security vulnerabilities of trusted noise detector model in continuous-variable quantum key distribution | QCRYPT 2018 | Hao Qin, Jan Gulla, Anqi Huang |
| Eve strikes back in the era of measurement-device-independent quantum key distribution | QCRYPT 2018 | Anqi Huang, Álvaro Navarrete, Ruoping Li, Vladimir Egorov, Shi-Hai Sun, Poompong Chaiwongkhot, Marcos Curty |
| Invisible Trojan-horse attack | QCRYPT 2017 | Shihan Sajeed, Carter Minshull, Nitin Jain |
| CubeSat detector assembly for investigating in-orbit mitigation of radiation damage | QCRYPT 2017 | Nigar Sultana, Jin Gyu Lim, Jean-Philippe Bourgoin, Thomas Jennewein |
| Effect of atmospheric turbulence on spatial-mode detector efficiency mismatch | QCRYPT 2017 | Poompong Chaiwongkhot, Katanya Kuntz, Anqi Huang, Jean-Philippe Bourgoin, Shihan Sajeed, Norbert Lütkenhaus, Thomas Jennewein |
| Short pulse attack on continuous-variable quantum key distribution system | QCRYPT 2017 | Hao Qin, Anqi Huang |
| Decoy state quantum key distribution with imperfect source | QCRYPT 2017 | Anqi Huang, Shi-Hai Sun, Zhihong Liu |
| An Advanced Eve of QKD: Breaking a Security Assumption and Hacking a Black Box | QCRYPT 2016 | Anqi Huang, Shihan Sajeed, Poompong Chaiwongkhot, Mathilde Soucarros, Matthieu Legré |
| Laser Annealing Heals Radiation Damage in Single-Photon Avalanche Photodiodes | QCRYPT 2016 | Jin Gyu Lim, Elena Anisimova, Thomas Jennewein |
| Finite-Key-Size Effect in Commercial Plug-and-Play QKD System | QCRYPT 2016 | Poompong Chaiwongkhot, Shihan Sajeed, Lars Lydersen |
| Measurements of light emission from silicon avalanche photodetectors | QCRYPT 2015 | Paulo Vinicius Pereira Pinheiro, Poompong Chaiwongkhot, Shihan Sajeed, Rolf T. Horn, Jean-Philippe Bourgoin |
| Low-noise single-photon detector for long-distance free-space quantum communication | QCRYPT 2015 | Elena Anisimova, Dmitri Nikulov, Simeng Simone Hu, Mark Bourgon, Rupert Ursin, Thomas Jennewein |
| Demonstration of suitability of avalanche photodiodes for quantum communications in the low-Earth-orbit radiation environment | QCRYPT 2015 | Elena Anisimova, Brendon Higgins, Jean-Philippe Bourgoin, Miles Cranmer, Eric Choi, Danya Hudson, Louis Piche, Alan Scott, Thomas Jennewein |
| Gap between industrial and academic solutions to implementation loopholes: testing random-gate-removal countermeasure in commercial QKD system | QCRYPT 2015 | Anqi Huang, Shihan Sajeed, Poompong Chaiwongkhot, Mathilde Soucarros, Matthieu Legré |
| Low-noise single-photon detectors for long-distance free-space quantum communication | QCRYPT 2014 | Elena Anisimova, Simeng Simone Hu, Dmitri Nikulov, Rupert Ursen, Thomas Jennewein |
| Quantum hacking: demonstrating feasibility of a Trojan-horse attack on a commercial QKD system | QCRYPT 2013 | Nitin Jain, Imran Khan, Elena Anisimova, Christoffer Wittmann, Christoph Marquardt, Gerd Leuchs |
We propose and experimentally demonstrate the tools to implement a Trojan-horse attack to break the security of the commercial quantum cryptosystem ‘Clavis2’ from ID Quantique while it is operating the Scarani-Acin-Ribordy-Gisin 2004 (SARG04) protocol. Eve launches a bright optical pulse into Bob and analyses the back-reflections that arise from different components and interfaces in Bob. By homodyning the weak coherent state in a suitable back-reflected pulse with an appropriately delayed local oscillator, Eve can get information about Bob’s basis choice with high accuracy. Since the basis choice is essentially the raw secret key in SARG04 protocol, Eve could in principle know the whole key. However, a problem that needs to be circumvented is that of afterpulsing caused by the bright Trojan-horse pulses impinging on the avalanche photodiode based single-photon detectors in Bob. This increases the dark counts or false clicks, thus directly translating into a higher quantum bit error rate (QBER) that could expose Eve. Nonetheless, we show that there exist attack regimes that allow Eve to get a partial information of the key without being discovered, thus breaching the security of the QKD system. |
||
Committee service
| Conference | Committee | Position | Title |
|---|---|---|---|
| QCRYPT 2024 | organizing | member | — |
| QCRYPT 2020 | program | member | — |
| QCRYPT 2013 | organizing | member | — |
Collaborators
| Co-author | Joint talks |
|---|---|
| Anqi Huang | 19 |
| Poompong Chaiwongkhot | 13 |
| Shihan Sajeed | 13 |
| Thomas Jennewein | 10 |
| Anastasiya Ponosova | 7 |
| Jean-Philippe Bourgoin | 7 |
| Elena Anisimova | 5 |
| Vladimir Egorov | 5 |
| Daniil Trefilov | 4 |
| Daria Ruzhitskaya | 4 |
| Hao Qin | 4 |
| Marcos Curty | 4 |
| Matthieu Legré | 4 |
| Irina Zhluktova | 3 |
| Konstantin Zaitsev | 3 |
| Maxim Fadeev | 3 |
| Mikhail Petrov | 3 |
| Nigar Sultana | 3 |
| Norbert Lütkenhaus | 3 |
| Sarah Kaiser | 3 |