AI 中文总结
针对量子密钥分发硬件监测盲区,形式化密码学伪装攻击,证明量子核可恢复离散对数并精确检测,在Ghillie模拟器上验证,使防御者能精准丢弃受损密钥材料。
AI 中文摘要
量子密钥分发证明了其协议的安全性,却对其底层硬件一无所知,因此部署该协议以获取指挥控制密钥的军事和政府运营商会对信道进行实施攻击监测,而这种监测存在盲区。若攻击者在公共逐块值\\(x=g^v \pmod p\\)的生成器中植入密码盗窃立足点,便可将受攻击的块隐藏在正常噪声中,并以该值离散对数的谓词作为门控条件,使检测成为一个离散对数问题,该问题击败所有高效的经典监测器,却可通过Shor算法恢复\\(v\\)的量子核得以解决。我形式化了这些密码学伪装攻击,将其难度归结为一个既有的学习分离问题,证明单频保真度核无法表示区间谓词,并在Ghillie(一种诱骗态BB84模拟器,正密钥率可达142公里)上进行了测试。在两组种子上的10至14位分组中,经典监测器对伪装攻击的读取值为0.458至0.516,而量子核的读取值为1.000,两者对公开攻击的检测均高于0.99。在去极化噪声和强化谓词下的有限精度恢复将量子结果降至0.916至0.983,而经典监测器仅处于随机水平;在IBM Heron处理器上的可行性探针与精确核的偏差在0.034以内。因此,防御者可以精确丢弃受损的密钥材料,尽管该优势是渐近的,有待容错实现,且仅在特征映射与攻击者谓词匹配时成立,因为低频映射对残差模式的读取值为0.545,对齐后则为0.982。
英文摘要
Quantum key distribution proves its protocol secure and says nothing about the hardware beneath it, so military and government operators fielding it for command-and-control keys monitor the channel for implementation attacks, and that monitoring has a blind spot. An adversary with a kleptographic foothold in the generator of a public per-block value \(x=g^v \pmod p\) can hide attacked blocks in honest noise, gating them on a predicate of its discrete logarithm, making detection a discrete logarithm problem that defeats every efficient classical monitor yet yields to a quantum kernel recovering \(v\) through Shor's algorithm. I formalise these cryptographically camouflaged attacks, reduce their hardness to an established learning separation, prove a single-frequency fidelity kernel cannot represent an interval predicate, and test them on Ghillie, a decoy-state BB84 simulator with a positive key rate to 142 km. From 10- to 14-bit groups over two seeds, a classical monitor reads 0.458 to 0.516 on camouflaged attacks while the quantum kernel reads 1.000, and both catch overt attacks above 0.99. Finite-precision recovery under depolarising noise and a hardened predicate lower the quantum result to 0.916 through 0.983 with the classical monitor at chance, and a feasibility probe on IBM Heron processors tracks the exact kernel within 0.034. A defender can therefore discard precisely the compromised key material, although the advantage is asymptotic, awaits fault tolerance, and holds only when the feature map matches the adversary's predicate, since a low-frequency map reads 0.545 on a residue pattern and 0.982 once aligned.