QKD Oracles for Authenticated Key Exchange

Authors

Abstract

Authenticated Key Exchange (AKE) establishes shared (‘symmetric’) cryptographic keys which are essential for secure online communication. Alternatively, symmetric keys could be established via Quantum Key Distribution (QKD), which uses quantum communication. Although point-to-point QKD can offer information-theoretic security (ITS), this guarantee crucially hinges on proper implementation. In practice, QKD is expected to be combined with conventional cryptography – raising the question whether such ‘hybrid’ combinations actually preserve QKD’s main benefit, ITS.

We perform an extensive review of existing AKE-QKD hybrids and their analysis. Our review shows that it is currently unclear both how to design such protocols and how to quantify their security. As our review shows, many proposed solutions do not preserve the ITS property of QKD, and finding a solution that does is less straightforward then expected. Moreover, we found that known designs do not even achieve computational security. In more detail, usage of the QKD keys needs to be coordinated across endpoints. This coordination currently requires that the keys are accompanied by a key ID. Although key IDs are introduced solely to ensure correct functionality, we show that they introduce subtle vulnerabilities – specifically, we identify dependent-key attacks on several existing protocols that arise from improper key-ID handling.

To address these issues, we propose a security model for AKE-QKD hybrids that also catches dependent-key attacks. As our main conceptual contribution, we model QKD via an oracle that closely resembles the standard ETSI 014 interface. We demonstrate the usefulness of this oracle for cryptographic analyses by integrating it into a prominent security model for AKE, called CK+ model.

Lastly, we present a new protocol that combines QKD with a triple-KEM handshake, and prove it secure in our integrated model. This is the first hybrid protocol that provably preserves the ITS of QKD.