An Application of Quantum Networks for Secure Video Surveillance
Alan Mink, Lijun Ma, Barry Hershman, Xiao Hong Tang · InTech eBooks · 2011
IntroductionSecurity is an increasingly growing concern for network communications and video is an emerging segment of network traffic that uses large amounts of bandwidth.Streaming video, vs. downloading a video for later viewing, requires a continuous, high data rate.The data rate will vary depending on the quality of the video.Video surveillance is a streaming video application that in addition may require securing the data stream to prevent others from viewing it as well as prevent any tampering of that video stream.There are two parts to secure communication, key distribution and ciphers.A cipher requires a secret key that is used to encrypt data (plaintext), transforming it into an unreadable form (ciphertext) and then to decrypt it back into its original form.Key distribution is the method used to exchange the secret key between the desired end users and no one else.Current block ciphers are relatively slow compared to existing bandwidth because they require a substantial amount of processing that must compete for CPU cycles with the video encoding and compression processing.Frequently changing keys is thought to increase security, but the public key exchange method requires even more processing than the cipher.Cipher and key exchange processing can be off-loaded from the CPU, when the communication end point is the other end of the link, by using dedicated hardware called a link encryptor.Current classical security algorithms are based on the perceived computational complexity of certain mathematical functions and have not been proved secure.The public key algorithm is at risk from future quantum computers, whereas block ciphers are only weakened and an easy fix is to double the length of the key.Both are constantly at risk from a potential break through algorithm.Communications channels that exploit properties unique to quantum systems have been shown to enable functionality that cannot be achieved by classical means.If a high level of security is deemed necessary for the video stream, one might consider the use of a One-Time-Pad cipher [Wikipedia 2010], the only provably secure cipher, along with Quantum Key Distribution (QKD), also a provably secure method of exchanging the secret keys used by a cipher.QKD is a protocol based on the quantum laws of physics and is provably information theoretically secure to accomplish key distribution [Gisin, et al., 2002].QKD keys, when used with a One-Time-Pad cipher, can provide secure communications.A One-Time-Pad cipher algorithm performs an Exclusive OR (XOR) on a random secret key and the message.This is a simple operation that incurs little overhead compared to the more common www.intechopen.comVideo Surveillance 74 computationally intensive ciphers, but it requires the key to be the same length as the message and discarded once used.For video, that requires a continuous stream of random secret keys, which is one of the features of QKD.Because of that feature, QKD is considered to have a long-term security perspective because of its "perfect forward security" attribute.The term perfect forward security means that any compromised keys cannot be used to determine other keys, either past or future.Since QKD keys are random strings and are not produced by a mathematical function, any compromised keys cannot be used to determine other keys.QKD is still a technology under development even though a few commercial systems are available [Ouellette, 2004].Some of the limitations of QKD are speed, distance and cost.Distance is a major concern, since without a break-through in developing a quantum repeater the quantum signal is limited to a few 100 km at best.Amplification is not possible since the quantum "no cloning law" specifies that a quantum state cannot be copied.If trusted, intermediate nodes are acceptable, then longer distances are possible via a multihop propagation of the key over multiple QKD links.This is not always acceptable and for these situations a quantum repeater would be required.It is currently under development, but none have yet been demonstrated.Speed, the ability to produce secure keys at a high rate is important to cope with the large amount of communication traffic over high-speed connections and hardware implementations that off-load the CPU have been demonstrated.Cost is an ever-present constraint and designs that use lower cost components and share rather than replicate components reduce the cost.In some cases, designs that share rather than duplicate components help to reduce concerns of side channel attacks upon engineered components (vs theoretical ones), but usually at the detriment of speed.This chapter includes a short summary of the BB84 QKD protocol and its various stages.We then present a section on the configuration of a QKD system targeted for short distances and how a number of innovations lowered the cost and evolved that core design for longer distance communication and current infrastructure use.Another section will discuss hardware support for the data handling necessary to implement high-speed QKD.Extending QKD point-to-point systems to form QKD networks makes it even more attractive for applications such as video surveillance and we will discuss early networking demonstrations.In closing, we will discuss initial QKD standards efforts currently being conducted How to referenceIn order to correctly reference this scholarly work, feel free to copy and paste the following: