Under the Eggshell Disruptive Solutions
for a Healthy - Safe and Free World
For information regarding the Beta Test version of the C&T Command and Trust Simulation Game, please fill out the Contact Form.

Quantum Cryptography and Crime
what could be the application of Quantum Computing technologies for Crime Organisations - November 2022

What is Cryptography?
Cryptography refers to the methods of securing information so that only the intended recipients can view its content. This is mainly achieved using encryption and decryption.
Encryption is using a key to scramble readable text (like email or text messages) into unreadable form.
In secret key (symmetric) cryptography one key is used by the sender to encrypt the message, then the same key is used by the receiver to decrypt the message.
If an eavesdropper got access to the encrypted message without the key, they won’t understand it. But if an eavesdropper tapped into the secure line, they would get the key and decrypt the message.
Therefore the main challenge in secret key cryptography is protecting the secret key during transmission, also known as Key Distribution Problem.
Addressing this issue is another type of cryptography: public key (asymmetric) cryptography which uses two keys; a public key for encryption and a private one for decryption - or vice versa.
The advantage of asymmetric systems is that the public key can be freely published, allowing parties to establish secure communication without having a shared secret key. In practice, asymmetric systems are used to first exchange a secret key, and then secure communication proceeds via a more efficient symmetric system using that key.
Examples of asymmetric systems include Diffie–Hellman key exchange, RSA (Rivest–Shamir–Adleman), ECC (Elliptic Curve Cryptography), and Post-quantum cryptography.
In order to make the encryption hard to crack, these keys use mathematical problems that are easy to pose but hard to solve. For example large number factorization used in RSA cryptography, it is easy to multiply two large prime numbers to get a number, but it is very hard to factorize a large number into prime numbers. These problems take a very long time to solve on the current ‘classical’ computers, hence keys are currently safe. However Quantum Computers can solve them in much less time.
State of the art quantum computers haven’t reached the level required for them to pose a serious danger to current public-key cryptographic systems, and they are not expected to reach it anytime soon. However there are already solutions to the quantum danger: Post-Quantum Cryptography and Quantum cryptography.
Post-quantum Cryptography
Post-quantum Cryptography is cryptography safe from quantum computers.
Make Public Key Protocols more secure by using mathematical problems for which quantum computers don’t bring an advantage.
These post-quantum protocols don’t use quantum effects.
Many countries have plans to switch to post-quantum cryptography in the coming decades.
Quantum Cryptography
“Quantum cryptography hides information, not by besting a computer, but by storing information within the unknowability of nature itself.”
Quantum cryptography is the science of exploiting quantum mechanical properties to perform cryptographic tasks, i.e. using quantum effects to encode messages and exchange keys.
The best known example of quantum cryptography is Quantum Key Distribution (QKD) which offers an information-theoretically secure solution to the key exchange problem.
The advantage of quantum cryptography lies in the fact that it allows the completion of various cryptographic tasks that are proven or conjectured to be impossible using only classical (i.e. non-quantum) communication. For example, it is impossible to copy data encoded in a quantum state. If one attempts to read the encoded data, the quantum state will be changed due to wave function collapse (no-cloning theorem). This could be used to detect eavesdropping in quantum key distribution (QKD).
QKD exploits quantum effects to share a key that is secure from eavesdropping. The encoded message is sent through classical channel without quantum effects
Currently, QKD is the only quantum cryptography application that is commercially available.
Quantum Cryptography beyond QKD would use quantum effects to actually share messages and not just the key. It is only theoretical for now.
How quantum key distribution works:
Simplest example of the QKD protocol is BB84 (QKD protocol of Bennett and Brassard, 1984). To explain the basics of this protocol, suppose Alice wants to send a secret key to Bob.
A key is a sequence of 0’s and 1’s. The 0 and 1 are encoded in the spin state of particles. For example if spin direction is up it means 1, and if the spin direction is down it is 0.
The safety of QKD relies on the Heisenberg Uncertainty Principle, that is one cannot know everything about the state of a quantum particle. For a binary variable like the spin, this means that measurements in two orthogonal directions are uncorrelated.
Particles with spin up or down; Alice has to choose a direction along which to create the spin. If Alice chooses vertical direction ↕ the spin will be up ↑ or down ↓, if she chooses horizontal direction ↔ the spin will be either right → or left ←.
If the spin is created into one direction then the measurement into a perpendicular direction is maximally uncertain.
Alice and Bob agree that up and right mean 1, down and left mean 0.
Alice randomly chooses the direction of particle spin vertical or horizontal (up-down or left-right) and sends the particle to Bob through optical fiber or free space.
Bob (or any potential eavesdropper) does not know a priori these directions, so he will randomly choose to measure along the vertical or horizontal direction.
After, Alice uses an unencrypted channel to send Bob the directions she chose (and not what she measured).
Then Bob discards measurements he made along wrong directions.
The remaining measurements of both Alice and Bob should be completely correlated.
If an eavesdropper intercepts the particles before they reach Bob. The eavesdropper’s measurements will alter/decorrelate the spin states because she doesn’t know the right directions to measure along.
To check for this, Alice and Bob compare part of the key they shared to see whether their measurements are correlated, and calculate the error rate. If the measurements are not correlated, they know that someone tried to intercept the message and send a new key.
QKD state of the art
Recent models have been able to send quantum keys over hundreds and thousands of kilometers. For example in China they launched their first national network of 4600 km of fibers connecting 150 banks, defense enterprises and governmental agencies. Developments include sending quantum keys over submarine optical fiber, in space to ground and intercontinental communications.
There is also progress towards drone-to-drone QKD [6]. Aerial drones are used in sensitive applications, including defense, law enforcement and environmental monitoring. Drones are also vulnerable to attacks on command and control signals aiming to disrupt or to cause an intentional crash, which makes securing wireless communications between drones in-flight is critical to ensure safe operation. This is an area where quantum communication protocols could provide significant enhancements over classical approaches.
Current commercial QKD systems are aimed at governments and corporations with high security requirements. That is because QKD has a big advantage on the currently used key distribution by human courier network, in that QKD is able to detect any interception of the key, in addition to being automatic with greater reliability and lower operating costs.
Challenges Facing QKD
When QKD is said to be totally secure and unhackable this is conditional on assumptions that are hard to ensure in practical implementation:
Getting Quantum Cryptography to work in real life is not easy.
Small disturbances can change photon polarization
Small errors in making the photons add up
Shining a bright light on quantum detectors sabotages them.
Hardware and software have bugs. Bug-free code is hard, and the control systems for QKD are no different. Several methods to successfully eavesdrop on commercial QKD systems were demonstrated [14].
QKD only tells you that a person-in-the-middle attack has happened, with photons disturbed because of the interception, but not where that attack is taking place or how many attacks are happening.
QKD connections can be blocked using a DDoS attack as simple as using a pneumatic drill in the vicinity of the cable.
Current QKD systems are currently expensive, slow and difficult to implement. The UK's National Cyber Security Centre (NCSC) and the National Security Agency (NSA) in the US has gone on the record to state it does not endorse the use of QKD for any government or military application.
The limitations are not fundamental, QKD technology is still maturing and it has an exciting future.
Quantum Cryptography in Crime?
Encryption is a valuable security tool, not just for sensitive transactions like banking and government services.This is especially true with the growing utilization and monetization of users’ data and the major data breaches that occur often.
Unfortunately, the technology intended to keep the public safe is also being exploited by criminal networks and terrorist groups. Criminals use encrypted communications to facilitate their illicit activities and to deny police access to evidence, creating significant challenges for the detection, investigation and prosecution of crime.
According to a major forensics tool provider, on average 6 out of 10 devices reaching police labs are now locked [12].
Cybercriminals are also increasingly exploiting cryptography to commit cybercrimes, most notably ransomware attacks
Cryptography is also being abused to disguise the malware in cyberattacks. Polymorphic viruses for instance use cryptography techniques to evade antivirus software
New technological developments in encryption are bound to complicate the situation further [12]. In this sense, it does not seem that QKD and Quantum Cryptography in general would pose a unique challenge to law enforcement.
In order for law enforcement to access the encrypted content, it has two basic choices:
Compel a user to decrypt the content (e.g. disclose the password),
Circumvent the encryption by attacking the authentication mechanisms using methods like probabilistic password guessing, memory leaks or brute force attacks.
However, with sufficiently strong cryptography, it may be infeasible to break the encryption with existing tools. Such development is particularly worrying given the broad adoption of end-to-end encryption (E2EE) in popular email and messaging platforms, since in E2EE systems even the service provider does not have access to the unencrypted data.
References
[1] https://www.youtube.com/watch?v=UiJiXNEm-Go
[2] https://www.youtube.com/watch?v=LaLzshIosDk
[3] https://www.youtube.com/watch?v=fLJ9mvTS68Y
[4] https://inspirehep.net/literature/2057029
[5] https://www.europol.europa.eu/sites/default/files/documents/report_do_criminals_dream_of_electric_sheep.pdf
[6] https://www.spiedigitallibrary.org/conference-proceedings-of-spie/11678/116780X/Drone-based-quantum-key-distribution-QKD/10.1117/12.2582376.short
[7] https://opg.optica.org/viewmedia.cfm?uri=CLEO_QELS-2015-FF1A.7&seq=0
[8] https://www.theregister.com/2021/07/06/quantum_key_distribution/
[9] https://en.wikipedia.org/wiki/Quantum_key_distribution
[10] https://en.wikipedia.org/wiki/Quantum_cryptography
[11] https://www.internetsociety.org/blog/2017/10/encryption-law-enforcement-can-work-together/
[12] https://www.interpol.int/es/content/download/17281/file/IC_07%20Policing%20Futures%20November%202021.pdf?inLanguage=eng-GB
[13] https://en.wikipedia.org/wiki/Cryptography
[14] The collaboration between the Norwegian University of Science and Technology in Norway and Max Planck Institute for the Science of Light in Germany