Quantum Secured Internet Transport

Bernardo Huberman,Bob Lund,Jing Wang
DOI: https://doi.org/10.48550/arXiv.2007.05522
2020-07-11
Abstract:Quantum computing represents an emerging threat to the public key infrastructure underlying transport layer security (TLS) widely used in the Internet. This paper describes how QKD symmetric keys can be used with TLS to provide quantum computing resistant security for existing Internet applications. We also implement and test a general hybrid key delivery architecture with QKD over long distance fibers between secure sites, and wireless key distribution over short distance within each site Finally we show how this same capability can be extended to a TLS cipher scheme with perfect security.
Cryptography and Security,Computers and Society,Networking and Internet Architecture,Quantum Physics
What problem does this paper attempt to address?
The problem that this paper attempts to solve is: **The threat of quantum computing to the existing Internet Transport Layer Security (TLS), especially to the Public Key Infrastructure (PKI)**. Specifically: 1. **The threat of quantum computing to PKI**: - Quantum computers can crack the current public - key encryption algorithms (such as RSA) based on the large - number factorization problem at an exponential speed, which makes the existing Internet transmission encryption no longer secure. - The Public Key Infrastructure (PKI) depends on the computationally difficult large - number factorization problem to generate and distribute symmetric keys, and quantum computers can use Shor's algorithm to quickly crack these keys. 2. **Solution: Quantum Key Distribution (QKD)**: - The paper proposes to use Quantum Key Distribution (QKD) technology to generate symmetric keys and combine it with the TLS protocol to provide quantum - computing - resistant security. - QKD ensures the security of key distribution through the principles of quantum mechanics and can remain secure even in the face of attacks from quantum computers. 3. **Specific goals**: - Design and implement a system that integrates QKD with existing Internet services, enabling standard protocols to utilize the secure keys provided by QKD. - Provide a hybrid key distribution architecture, including QKD key distribution over long - distance optical fibers and key distribution wirelessly within each site. - Demonstrate how to extend this capability to achieve a TLS cipher scheme with "perfect security". In summary, the paper aims to enhance the security of existing Internet transmissions by introducing QKD technology, enabling it to resist the potential threats posed by future quantum computers.