Method and system for quantum key distribution
By determining the inherent loss and total loss of the quantum channel, using error correction techniques to handle invalid signal locations, and combining shared key shortening and amplification, the problem of key length reduction in traditional quantum key distribution is solved, the key rate and distance between devices are improved, and security is enhanced.
Patent Information
- Application Number
- CN202210152957.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-04-14
- Filing Date
- 2022-02-18
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2042-02-18
AI Technical Summary
Traditional quantum key distribution technology assumes that all errors and losses are caused by eavesdropping, which leads to a drastic reduction in key length during privacy amplification to obtain a reliable and secure key.
By determining the inherent loss and total loss of the quantum channel, error correction techniques are used to handle invalid signal locations. The shared key is shortened and amplified, and a random binary Toeplitz matrix is used to adjust the key length. The signal pulse strength is optimized to maximize the shared key length.
It improves the key rate and distance between devices in quantum key distribution, enhances security, reduces the information advantage of eavesdropping devices, and enables longer secret key lengths.
Smart Images

Figure CN115021897B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to a method and system for quantum key distribution (QKD). BACKGROUND
[0002] Conventional quantum key distribution approaches require the assumption that all errors and losses are due to eavesdropping activities. This forces the legitimate users to equate the eavesdropper's knowledge about the shared raw key to the mutual information between the device of one of the legitimate users and the device describing the lost part of the signal. As a result, the key length needs to be drastically reduced during privacy amplification to obtain a reliably secure key. SUMMARY
[0003] It is an object of the present disclosure to provide improved techniques for communicating data via quantum key distribution, in particular to increase the achievable key rate and / or the distance between the legitimate devices.
[0004] To solve this problem, a method and system for quantum key distribution according to the independent claims are provided. Further embodiments are disclosed in the dependent claims.
[0005] According to an aspect, there is provided a method for quantum key distribution, the method comprising, in a system having a plurality of data processing devices: determining, in at least one of a first data processing device and a second data processing device, an intrinsic loss along a quantum channel between the first data processing device and the second data processing device; generating, in the first data processing device, a first signal; generating, in the first data processing device, a pulse sequence comprising at least one test pulse and a signal pulse generated from the first signal; transmitting, from the first data processing device, the pulse sequence to the second data processing device via the quantum channel; receiving, in the second data processing device, the pulse sequence and determining, in the second data processing device, a second signal from the pulse sequence; determining invalid signal positions and providing, in the first data processing device and the second data processing device, the invalid signal positions; determining, in the first data processing device, a first reconciliation signal from the first signal and the invalid signal positions and determining, in the second data processing device, a second reconciliation signal from the second signal and the invalid signal positions; determining a total loss along the quantum channel from the at least one test pulse received in the second data processing device, determining a signal loss from the total loss and the intrinsic loss, and providing, in the first data processing device and the second data processing device, the signal loss; determining a shared key in the first data processing device and the second data processing device by error correction of the first reconciliation signal in the first data processing device and the second reconciliation signal in the second data processing device; and determining an amplified key in the first data processing device and the second data processing device from the shared key by shortening the shared key by an amount determined from the signal loss.
[0006] According to another aspect, there is provided a system for quantum key distribution, the system comprising a plurality of data processing devices and being configured to perform: determining, in at least one of a first data processing device and a second data processing device, an intrinsic loss along a quantum channel between the first data processing device and the second data processing device; generating, in the first data processing device, a first signal; generating, in the first data processing device, a sequence of pulses comprising at least one test pulse and signal pulses generated from the first signal; transmitting, via the quantum channel, the sequence of pulses from the first data processing device to the second data processing device; receiving, in the second data processing device, the sequence of pulses and determining, in the second data processing device, a second signal from the sequence of pulses; determining invalid signal positions and providing, in the first data processing device and the second data processing device, the invalid signal positions; determining, in the first data processing device, a first reconciliation signal from the first signal and the invalid signal positions and determining, in the second data processing device, a second reconciliation signal from the second signal and the invalid signal positions; determining a total loss along the quantum channel from the at least one test pulse received in the second data processing device, determining a signal loss from the total loss and the intrinsic loss, and providing, in the first data processing device and the second data processing device, the signal loss; determining a shared key in the first data processing device and the second data processing device by error correction of the first reconciliation signal in the first data processing device and the second reconciliation signal in the second data processing device; and determining an amplified key in the first data processing device and the second data processing device from the shared key by shortening the shared key by an amount determined from the signal loss.
[0007] The first signal can be a bit string, which is preferably generated with a physical random number generator. Each signal pulse can correspond to a signal position of the first and second signal. A signal position can also correspond to two signal pulses or a plurality of signal pulses. The sequence of pulses can further comprise decoy pulses.
[0008] In the context of the present disclosure, determining the intrinsic loss along the quantum channel can comprise the step of measuring the intrinsic loss along the quantum channel. Alternatively or additionally, the intrinsic loss can also be determined based on pre-collected measurement values or manufacturer information.
[0009] The intrinsic loss can be detected using at least one optical reflectometer. The intrinsic loss can be determined by pre-detecting and recording naturally occurring events, preferably by an optical reflectometer. These events can include losses on connectors, welds, bends and / or cracks.
[0010] The quantum channel can comprise an optical fiber and / or the test pulses, and the signal pulses can be optical pulses.
[0011] The transmissivity of the optical fiber can be scaled to T = 10 -μ·Dwhere D denotes the length of the optical fiber between the first data processing device ("Alice") and the second data processing device ("Bob") (e.g., in km), and μ denotes a loss parameter, which, for example, can take a value between 10 -3 km -1 and 10 -1 km -1 . In particular, μ can be equal to 0.02 km -1 .
[0012] The intrinsic loss (intrinsic natural loss) can include Rayleigh scattering loss and Raman scattering loss. It can be assumed that the intrinsic loss is not caused by an eavesdropping device ("Eve").
[0013] The intrinsic loss can be determined by measuring a decrease in intensity of an initial signal generated in the first data processing device and transmitted to the second data processing device via the quantum channel. The intrinsic loss can be provided in the first data processing device and the second data processing device. The initial signal can include at least one optical pulse.
[0014] The invalid signal locations can be provided in the first data processing device and the second data processing device via a public channel. The public channel can be an authenticated public classical channel. The first data processing device and the second data processing device can exchange classical signals via the public channel. The classical signals can also be exchanged via the quantum channel. The optical fiber can be shared by the quantum channel and the classical channel. Alternatively, the quantum channel and the classical channel can be separate.
[0015] The quantum channel can not include an amplifier or include no more than one amplifier (e.g., an in-line erbium-doped fiber amplifier (EDFA) or a Raman amplifier).
[0016] It can also be specified that the average amplifier density of the quantum channel is less than 2 amplifiers per 110 km, preferably one of the following: less than 2 amplifiers per 120 km, less than 2 amplifiers per 130 km, less than 2 amplifiers per 150 km, or less than 2 amplifiers per 200 km.
[0017] It can also be specified that the distance between two adjacent amplifiers in the quantum channel is greater than 55 km, preferably greater than one of the following: 60 km, 70 km, 80 km, or 100 km.
[0018] The quantum channel can be configured such that the intrinsic loss is homogeneously distributed along the quantum channel.
[0019] It can be specified that the eavesdropping device can only have local physical access to the quantum channel. For example, the eavesdropping device can access less than 1% or 0.1% of the length of the quantum channel.
[0020] The sequence of helper bits can be encoded in a single test pulse. In particular, the single test pulse can be verified in the second data processing device according to the sequence of helper bits.
[0021] Thus, the total loss can be determined from the single test pulse.
[0022] Encoding the sequence of helper bits in the single test pulse can comprise modifying at least one of the test pulse parameters. The test pulse parameters can comprise an intensity, a phase, a length and a shape of the test pulse. The phase can be sampled from the interval [0, π) and / or the length can be sampled from the interval [1 ns, 10 6 ns].
[0023] The sequence of pulses can comprise a plurality of test pulses (sequence of test pulses) and the sequence of helper bits can be encoded in the plurality of test pulses. Preferably, the plurality of test pulses can be verified in the second data processing device according to the sequence of helper bits.
[0024] Encoding the sequence of helper bits in the plurality of test pulses can further comprise modifying at least one of the test pulse parameters.
[0025] Verifying the single test pulse or the plurality of test pulses can comprise determining whether the sequence of helper bits is encoded in the single test pulse or the plurality of test pulses received in the second data processing device.
[0026] If it is determined that the sequence of helper bits is not encoded in the single test pulse or the plurality of test pulses received in the second data processing device, the single test pulse or the plurality of test pulses can be discarded. In case the single test pulse or the plurality of test pulses is discarded, another test pulse or another plurality of test pulses can be transmitted from the first data processing device to the second data processing device.
[0027] The sequence length of the test pulses can be greater than the signal pulse length. Preferably, the sequence length of the test pulses can be 10 3 to 10 6 times the signal pulse length. In particular, the sequence length of the test pulses can be 1 ms and the signal pulse length can be 1 ns.
[0028] The test pulses and the signal pulses can each have the same constant power, e.g. a value between 0.1 μW and 10 μW, in particular 2 μW.
[0029] The average number of photons per test pulse can be between 10 6 and 10 12 , in particular 10 10 .
[0030] The sequence of helper bits can be generated in the first data processing device and transmitted to the second data processing device, preferably after measuring the single test pulse or the plurality of test pulses in the second data processing device. The sequence of helper bits can be transmitted via a common channel. The sequence of helper bits can be generated randomly.
[0031] The first coordination signal can be determined from the first signal by discarding invalid signal positions from the first signal. Furthermore, the second coordination signal can be determined from the second signal by discarding invalid signal positions from the second signal.
[0032] The invalid signal positions can be determined in the first data processing device and / or in the second data processing device.
[0033] At least one of the invalid signal positions can be determined by detecting a non-deterministic measurement result for a corresponding signal pulse in the second data processing device.
[0034] At least one of the invalid signal positions can be determined by detecting a different preparation basis in the first data processing device and a measurement basis in the second data processing device for a corresponding signal pulse.
[0035] The total loss can be determined from a first intensity of the at least one test pulse generated in the first data processing device and a second intensity of the at least one test pulse received in the second data processing device.
[0036] In particular, the total loss can be determined from a decrease from the first intensity to the second intensity.
[0037] The signal loss can be determined by subtracting the intrinsic loss from the total loss.
[0038] The total loss and / or the signal loss can be determined in the first data processing device and / or in the second data processing device. The signal loss can be provided in the first data processing device and in the second data processing device by sharing the signal loss via a common channel.
[0039] The number of invalid positions can depend on the signal loss.
[0040] The method can further comprise estimating an error rate in the first data processing device and in the second data processing device from the first coordination signal and / or from the second coordination signal.
[0041] First error information from the first coordination signal can be generated in the first data processing device and transmitted to the second data processing device.
[0042] In contrast, second error information from the second coordination signal can be generated in the second data processing device and transmitted to the first data processing device.
[0043] An error rate can be determined in the first data processing device and the second data processing device from the first error information and the second error information. The first error information can comprise first parity bits or a portion thereof of the first coordination signal. The second error information can comprise second parity bits or a portion thereof of the second coordination signal. The error rate can be determined by comparing the first parity bits and the second parity bits.
[0044] The first error information can further comprise a first subset of digital positions of the first coordination signal and the second error information can comprise a second subset of digital positions of the second coordination signal.
[0045] The shared key can be shortened by applying a hash method to the shared key.
[0046] In particular, a hash function that maps a key having a first key length to a key having a second key length can be applied to the shared key. The first key length can be equal to the length of the shared key. The second key length can be the first key length minus a shortening amount. The hash function can be determined randomly. Subsequently, the hash function can be shared between the first data processing device and the second data processing device.
[0047] Preferably, a random binary Toeplitz matrix can be applied to the shared key. The Toeplitz matrix can comprise a number of columns equal to the first key length and a number of rows equal to the first key length minus the shortening amount.
[0048] The shortening amount can be determined from the signal loss and further from an intensity of at least one signal pulse, preferably an average intensity of the signal pulse. In particular, the shortening amount can be determined from the signal loss and further from a mean photon number of the signal pulse in the first data processing device and / or the second data processing device.
[0049] The shortening amount can be determined from a product of the signal loss and an intensity of at least one signal pulse, preferably an average intensity of the signal pulse, in the first data processing device and / or the second data processing device.
[0050] In particular, the shortening amount can be determined from a product of the signal loss and a mean photon number of the signal pulse in the first data processing device and / or the second data processing device.
[0051] The shortening amount can be determined by calculating the mutual information, preferably between the first data processing device and the eavesdropping device.
[0052] The strength of the signal pulses can be adjusted such that the length of the shared key is maximized. In particular, the strength of each signal pulse and / or the average strength of the signal pulses can be adjusted such that the length of the shared key is maximized.
[0053] More generally, the first strength of the test pulse and / or the strength of the signal pulses can be adjusted depending on the intrinsic loss.
[0054] The method can follow at least one of (in particular one of) the following: the coherent one-way protocol, the differential phase shift protocol, the BB-84 protocol, the B-92 protocol, the T-12 QKD protocol, the Y-00 QKD protocol, the (4+2)-QKD protocol, the SARG04 QKD protocol, and the six-state protocol.
[0055] Furthermore, the protocol according to Corndorf et al. (Quant. Inf. Comp. II, 5436: 12-20, 2004) can be employed.
[0056] In the context of the present disclosure, each of the following can also include variants of the respective protocol: the coherent one-way protocol, the differential phase shift protocol, the BB-84 protocol, the B92 protocol (Bennett, PRL 68, 21 :3121-3124, 1992), the T-12 QKD protocol (see Lucamarini et al., Opt. Expr. 21 (21):24550-24565, 2013), the Y-00 QKD protocol (see Hirota et al., Quant. Comm. Quant. Im., 5161:320-331, 2004), the (4+2)-QKD protocol (B. Huttner et al., PRA 51:1863-1869, 1995), the SARG04 QKD protocol (V. Scarani et al., PRL 92(5):057901, 2004), and the six-state protocol (Bechmann-Pasquinucci et al., PRA 59(6):4238-4248).
[0057] The above-described embodiments regarding the method for quantum key distribution can be correspondingly provided for a system for quantum key distribution. BRIEF DESCRIPTION OF DRAWINGS
[0058] In the following, embodiments are described by way of example with reference to the accompanying drawings, in which:
[0059] Figure 1 A graphical representation of an arrangement of a system for quantum key distribution and a potential eavesdropping device is shown;
[0060] Figure 2 A graphical representation of a method for quantum key distribution is shown.
[0061] Figure 3 a graph showing the test pulse strength value of a test pulse as a function of signal loss and distance;
[0062] Figure 4 a graphical representation of a system for quantum key distribution and an arrangement of eavesdropping devices for a coherent one-way protocol;
[0063] Figure 5 a graph showing the optimal strength of a signal pulse as a function of distance and signal loss;
[0064] Figure 6 a graph showing the maximum key rate as a function of distance and signal loss;
[0065] Figure 7 a graph showing the key rate ratio as a function of distance and signal loss;
[0066] Figure 8 a graphical representation of a system for quantum key distribution and an arrangement of eavesdropping devices for a differential phase shift protocol;
[0067] Figure 9 a graph showing the maximum key rate as a function of distance and signal loss for a BB 84 protocol; and
[0068] Figure 10 a graph showing the key rate ratio as a function of distance and signal loss for a BB 84 protocol. DETAILED DESCRIPTION
[0069] In Figure 1 , a graphical representation of a system for quantum key distribution and an arrangement of potential eavesdropping devices 12 (often referred to as "Eve") is shown. The system comprises a first data processing device 10 (often referred to as "Alice") and a second data processing device 11 (often referred to as "Bob"). Alice and Bob, unlike Eve, correspond to legitimate users of the system.
[0070] The first data processing device 10 and the second data processing device 11 can exchange signals, in particular quantum signals and quantum states, via a quantum channel 13 (transmission line). The quantum channel 13 comprises an optical fiber.
[0071] The first data processing device 10 and the second data processing device 11 can further exchange classical signals, in particular via a common channel 14. Classical signals can also be exchanged via the quantum channel 13. The optical fiber can be shared by the quantum channel 13 and the classical channel. Alternatively, the quantum channel and the classical channel can be physically separated.
[0072] It is assumed that the eavesdropping device 12 has access to both the quantum channel 13 and the public channel 14.
[0073] Figure 2 A graphical representation of a method for quantum key distribution is shown.
[0074] The proposed method involves physical control of the transmission line for detecting any intrusion of the eavesdropping device 12. One fundamental aspect is that when the eavesdropping device tries to gain information from the transmission pulses carrying photons in the optical fiber, physical access to the propagation mode is inevitable. The formation of this physical access, which is local, can be detected via control of the propagation of the electromagnetic pulses through the transmission line.
[0075] According to the proposed method, the exact proportion of the signal diverted by the eavesdropping device 12 can be determined and distinguished from the natural losses in the quantum channel 13. Thus, the information advantage of the first and second data processing devices 10, 11 with respect to the eavesdropping device 12 can be estimated accurately, allowing significantly longer secret keys after privacy amplification.
[0076] That is, in order to monitor the activities of the eavesdropping device 12, test pulses are transmitted from the first data processing device 10 at appropriate intervals, and the corresponding intensities are cross-checked with the second data processing device 11.
[0077] It is assumed that the transmission line / optical fiber is installed correctly (i.e. it has no significant kinks and rough points), the majority of the inherent losses occur due to Rayleigh scattering and Raman scattering. Such losses are distributed over the entire line. Therefore, the eavesdropping device 12 cannot effectively pick up the dissipated signal, unless the eavesdropping device 12 comprises an antenna that covers a significant portion of the transmission line. However, the concealment structure of such an antenna is practically not feasible.
[0078] The only remaining option for the eavesdropper is to divert a portion of the signal, i.e. to create and exploit additional losses in addition to the inherent losses (e.g. due to a curved optical fiber).
[0079] However, such artificial losses can be identified and measured by the first and second data processing devices 10, 11. This can be achieved by first determining the magnitude of the losses that are not associated with the activities of the eavesdropper (i.e. by measuring the losses that appear homogeneously across the entire line before transmitting the data signal). Subsequently, the newly occurring local signal leakage that can be intercepted by the eavesdropping device 12 can be determined accurately. This knowledge ensures the most efficient encryption and measurement procedure, which in turn determines the post-selection process.
[0080] Thus, in a first step 21, the inherent (natural) losses 1-T of the quantum channel 13 between the first data processing device 10 and the second data processing device 11 are determined, where the transmissivity T of the optical fiber is scaled as T = 10 -μ·D, the length of the optical fiber, and a normalization constant μ) is determined. The intrinsic loss 1 - T is determined by measuring the reduction in intensity of an initial signal generated in the first data processing device 10 and transmitted via the quantum channel 13 to the second data processing device 11 and received therein. The initial signal can comprise at least one optical pulse.
[0081] The intrinsic loss 1 - T can also be determined as a given and predetermined parameter or characteristic of the optical fiber, such as by reference to a parameter table or fiber manufacturer information, as long as the parameter table or manufacturer information can be considered a sufficiently trustworthy source in the context of the present disclosure.
[0082] The local loss that can be caused by the eavesdropping device 12 can thus be distinguished from the intrinsic loss 1 - T, which is homogeneous over the entire optical fiber. As part of the initial device setup, the determined intrinsic loss value 1 - T is shared in the first and second data processing devices 10, 11 via the public channel.
[0083] The main contribution to the intrinsic loss in the optical fiber line can be attributed to Rayleigh scattering (which is caused by irregularities in the fiber density and does not exceed 0.2 dB / km for modern optical fibers) and losses associated with the wiring details, i.e. losses on connectors, solder joints, bends, cracks (also referred to as "events").
[0084] These intrinsic losses can be detected using an optical reflectometer. In order to distinguish the intrinsic loss from the loss that occurs due to the eavesdropping device, all naturally occurring events can be detected and recorded in advance with the help of the optical reflectometer.
[0085] The operation of the optical reflectometer is based on measuring the backscattered optical radiation, calculating the distance to the event by the time delay of the signal arrival and displaying a reflection map, which allows the events to be classified. Modern reflectometers allow events at distances of up to 500 km to be identified in real time.
[0086] In a second step 22, a first signal, i.e. a first bit sequence (bit string) R A of length L, is generated in the first data processing device 10.
[0087] Additionally, a single test pulse or a plurality of test pulses is generated in the first data processing device 10, which together with the signal pulses forms a pulse sequence of optical pulses. The test pulse(s) do not contain information about the first bit sequence R A , but are used for intrusion estimation. The test pulse(s) should preferably have as high an intensity as possible while ensuring that the detection means of the second data processing device 11 are not damaged.
[0088] Length of the test pulse sequence τ test Should be much larger than the length of the signal pulse τ signal For example τ test = 1 ms and τ signal = 1 ns. The test pulse sequence should contain much more photons than one signal pulse. Both types of pulses can comprise the same constant power P, for example P = 2 μW. The average number of photons per test pulse is where v is the optical frequency.
[0089] In order to ensure that the test pulses are not manipulated by eavesdropping devices 12, for example, the test pulse(s) are adjusted as follows.
[0090] In the case of a single test pulse, the sequence of helper bits is generated in the first data processing device 10 and encoded in the test pulse. The sequence of helper bits can be encoded in the test pulse by modifying certain test pulse parameters (e.g. the intensity, the phase (e.g. from 0 to π), the length (e.g. from 1 ns to 10 6 ns) and / or the shape of the test pulse).
[0091] In the case of multiple test pulses (test pulse sequence), the generated sequence of helper bits is encoded into the test pulse sequence. To this end, the intensity or the phase of different test pulses can be adjusted in the multiple test pulses.
[0092] If an eavesdropper knows the parameters of the test pulses, it is in principle possible to intercept the test pulses and manipulated test pulses can be sent from the eavesdropper to mask their presence. In order to prevent such manipulation, the sequence of helper bits should be generated randomly and the parameters are only compared after the test pulses have been measured in the second data processing device 11. In this way, the eavesdropper will be forced to first measure the pulses and then reproduce them, which in turn will lengthen the transmission. This delay is easily detected by the legitimate devices.
[0093] In a third step 23, the pulse sequence is transmitted from the first data processing device 10 to the second data processing device 11 via the quantum channel 13.
[0094] In a fourth step 24, the pulse sequence is received and measured in the second data processing device 11. Further, in the second data processing device 11, the second sequence of bits R B corresponding to the second signal.
[0095] When the single test pulse or the multiple test pulses have been received and measured in the second data processing device 11, the sequence of helper bits is transmitted to the second data processing device 11 and the corresponding test pulse parameters are verified.
[0096] Some of the pulse measurements in the second data processing device 11 can result in non-deterministic outcomes or can have selected a wrong measurement basis for one of the pulses. The corresponding bit positions (invalid signal positions) should be discarded.
[0097] To this end, in a fifth step 25, the signal positions corresponding to the non-deterministic outcomes are transmitted from the second data processing device 11 to the first data processing device 10 via the public channel 14. Further, the corresponding preparation basis and measurement basis of each signal position can be shared between the first data processing device and the second data processing device via the public channel 14 in order to identify basis mismatches.
[0098] Thus, a first coordinated signal can be determined from the first signal and the invalid signal positions by discarding the invalid signal positions from the first signal. Similarly, a second coordinated signal can be determined from the second signal and the invalid signal positions by discarding the invalid signal positions from the second signal. Denoting the probability of a deterministic measurement outcome at the second data processing device by p'(√), the length of the first and second coordinated signal will on average equal p'(√) · L.
[0099] In a sixth step 26, the total loss (value) r total along the quantum channel 13 is determined from the at least one test pulse received in the second data processing device 11. total To this end, the decrease in intensity of the at least one test pulse from the first data processing device to the second data processing device is determined. In particular, the total loss r total may be determined via the scattering matrix.
[0100] Subsequently, the signal loss (value) r E is determined from the total loss r total and the intrinsic loss 1 - T by subtracting the intrinsic signal loss 1 - T from the total loss r total , i.e. r E = r total - (1 - T). Further, the signal loss is shared between the first and second data processing devices 10, 11 via the public channel 14.
[0101] The measurement error of the test pulse intensity at the second data processing device 11 occurs due to the Poisson statistics of the light, so that:
[0102]
[0103] wherein corresponds to the test pulse intensity at the first data processing device 10. One test pulse allows to detect a leakage of magnitude . For the smallest detectable signal loss r E,min , the following holds:
[0104]
[0105] Figure 3 a plot of the test pulse strength value as a function of r E,min and D (scaled in km) A plot of the test pulse strength value as a function of r E,min Lower values of r correspond to larger values of D.
[0106] In a seventh step 27 (see Figure 2 ), the first and second coordination signals are error corrected. For this, first parity data can be generated in the first data processing device 10 from the first coordination signal and transmitted to the second data processing device. Additionally or alternatively, second parity data can be generated in the second data processing device 11 from the second coordination signal and transmitted to the first data processing device 10.
[0107] Subsequently, differences of the first and second coordination signals can be determined and corrected. The first parity data can comprise first parity bits of first data blocks of the first coordination signal and the second parity data can comprise second parity bits of second data blocks of the second coordination signal (CASCADE method). Alternatively, the first parity data can comprise first syndromes of the first coordination signal and the second parity data can comprise second syndromes of the second coordination signal (linear error correcting code / linear block code method).
[0108] From the first and / or second parity data, an error rate can be estimated.
[0109] By error correcting the first and second coordination signals, a shared key is determined in both the first and second data processing devices 10, 11.
[0110] In an eighth step 28, an amplified key in the first and second data processing devices 10, 11 is determined from the shared key by shortening the shared key (privacy amplification). The shared key is shortened by an amount determined from the signal loss. Thus, an eavesdropper will have almost no information about the amplified key.
[0111] For this, a random binary Toeplitz matrix T can be determined and openly shared. The amplified key can be determined by multiplying (preferably left multiplying) the shared key (preferably as a row vector) by the Toeplitz matrix T. The number of columns of T can correspond to the length of the shared key, while the number of rows of T can correspond to the length of the key minus the amount of shortening determined from the signal loss.
[0112] Let max I′(A,E) represent the maximum mutual information between the first data processing device 10 and the eavesdropping device 12 (considering signal loss determined according to this method), and the length of the amplified key can be expressed as...
[0113] L′ f =p′(√)L·(1-max I′(A,E)). (3)
[0114] By taking into account the signal loss determined in this method, the amount of shortening will be significantly smaller compared to traditional methods, resulting in an amplified key with increased length.
[0115] The method will be further illustrated below with some exemplary quantum key distribution protocols. However, the techniques disclosed herein can also be practiced with variations of these protocols or with other quantum key distribution protocols.
[0116] Coherent one-way (COW) quantum key distribution protocol
[0117] In the COW QKD protocol (see, for example, Stucki et al., Applied Physics Letters 87(19):194108, 2005), the first data processing device 10 includes a decaying laser 40 and an intensity modulator 41 (see...). Figure 4 Laser 40 is configured to produce a laser with an average photon number |γ|. 2 The coherent states are used to encode the first signal (random bit string) into a double pulse consisting of a non-empty pulse (corresponding to quantum state |γ>) and an empty pulse (corresponding to quantum state |0>). Therefore, 0-value bits can be encoded as |0>|γ>, and 1-value bits can be encoded as |γ>|0>.
[0118] The second data processing device 11 includes a main detector 42, a second detector 43, and a third detector 44. The first and second data processing devices 10 and 11 can estimate the visibility of interference to the second and third detectors 43 and 44, and use it to estimate the information intercepted by the eavesdropping device 12.
[0119] A small fraction of all double pulses, f << 1, corresponds to the decoy state (decoy pulse) |γ>|γ>. The long arm of the interferometer in the second data processing device 11 has a feature that allows two non-empty adjacent pulses to be split at the final beam splitter ( Figure 4 The length of the interference at (not shown in the diagram) is such that the third detector 44 will not be triggered for the decoy state. The main detector 42 is used to monitor the arrival time of one of the pulses. Due to the Poisson statistics of the number of photons in the coherent pulse, the main detector 42 will sometimes not be triggered for non-empty pulses. In the second data processing device 11, such measurement results will be interpreted as indeterminate.
[0120] After all pulses have been transmitted, the first data processing device 10 transmits information to the second data processing device 11 whether a decoy pulse or a signal pulse has been prepared. The post-selection procedure involves analyzing the decoy pulses and discarding invalid signal positions, in particular signal positions corresponding to inconclusive results. A potential eavesdropping device 12 can introduce additional errors. Therefore, due to corresponding losses in the quantum channel 13, the second data processing device 11 will obtain more inconclusive results than expected.
[0121] To provide an upper bound estimate of the key rate in the original COW QKD protocol, any possible eavesdropping attack can be considered. For example, the eavesdropping device 12 can be considered to have obtained the missing part of the signal. The maximum amount of information max I(A, E) about the bits sent from the first data processing device 10 ("A") that can be obtained in the eavesdropping device 12 ("E") can be estimated via the Holevo bound, which yields for equiprobable states
[0122]
[0123] where I(A, E) denotes the mutual information between the first data processing device 10 and the eavesdropping device 12, X denotes the Holevo quantity / Holevo bound, h2denotes the binary entropy function, T = 10 -μD denotes the transmissivity of the quantum channel 13 (the whole optical link), D denotes the length of the optical link, and μ denotes the loss parameter. A typical value for the loss in optical fiber is μ = 0.02 km -1 .
[0124] The probability p(√) of a conclusive measurement result at the second data processing device 11 can be expressed as
[0125] p(√) = 1 - exp(-10 -μD · |γ| 2 ), (5)
[0126] where |γ| 2 denotes the pulse intensity at the first data processing device 10.
[0127] To eliminate the information available in the eavesdropping device, privacy amplification / key distillation can be performed on the established shared key. For example, the first and second data processing devices can agree on a random (hashing) function via the public authenticated channel 14, or alternatively, before the protocol execution, such that the shared key of length p(√)L obtained after the post-selection procedure is reduced to the following length
[0128]
[0129] In the case where the signal loss r E is determined according to the proposed method, the probability of a deterministic measurement result is
[0130] p'(r) = 1 - exp(-10 -μD ·(1-r E )·|γ| 2 ). (7)
[0131] In order to estimate the maximum information that can be obtained by the eavesdropping device 12, the corresponding Holevo bound yields
[0132]
[0133] Therefore, after the post-selection process and the privacy amplification, the amplified key according to the proposed method has the following length
[0134]
[0135] The intensity |γ| 2 can be optimized in order to provide the maximum key rate for a specific attenuation value 10 -μD . This also allows to compare the key rate (corresponding to the key length L f ) of the original COW protocol together with the COW protocol with the key rate (corresponding to the key length L' f ) of the proposed method with each other.
[0136] To this end, equation (6) and equation (9) are optimized and the respective corresponding optimal intensities are determined, respectively. For different values of r E different optimal intensities can be determined.
[0137] Figure 5 A plot showing the optimal intensity that maximizes equation (9) for a signal pulse as a function of the distance D and the signal loss rEis shown for μ = 1 / 50 km -1 . The optical channel transmission is 10 -μD for any distance value D. By substituting the optimal intensity for 10 -μD in equations (6) and (9), the maximum key rate is calculated as a function of r E and D.
[0138] Figure 6 A corresponding plot showing the maximum key rate as a function of the distance D and the signal loss r -1 is shown for μ = 1 / 50 km E .
[0139] For comparison, the key rate R = L' f / L determined for the proposed method is calculated with the key rate R of the original COW protocol.orig = L f Key rate ratio R / R between L and L orig .
[0140] Figure 7 shows plots of the key rate ratio R / R as a function of the distance D and the signal loss r -1 for μ = 1 / 50 km E . orig For the COW QKD protocol, the proposed method yields higher key rate values than the original approach, even in the pessimistic case where the eavesdropping device 12 is able to obtain around 10% of the signal (see the upper region in Figure 7 ). A leakage control of roughly 10% still provides key rate values that are several times larger than for the original COW QKD protocol, especially at a distance D of around 100 km. For r E around 1%, the key rate that can be obtained from the proposed method is around 80 times larger.
[0141] Different types of eavesdropping attacks can be considered, where the eavesdropping party blocks pulses or introduces additional signals. Such attacks can be immediately detected, because some test pulses will be blocked. Moreover, the wave packet shape of the test pulses will be significantly altered by the interaction with the eavesdropping device 12. In the case of the COW QKD protocol, this means that the decoy states and the analysis of the large number of bits corresponding to the decoy pulses are not necessary.
[0142] As a result, the framework of the COW QKD protocol can be significantly simplified by removing the interference unit from the second data processing device comprising the second and third detectors 43, 44. These modifications can lead to cost reduction and make QKD implementations more widely available.
[0143] Differential phase shift (DPS) QKD protocol
[0144] Figure 8 shows a graphical representation of a system for quantum key distribution and an arrangement of an eavesdropping device for a differential phase shift QKD protocol.
[0145] In the DPS QKD protocol (see Inoue et al., Physical Review Letters 89:037902, 2002 and Inoue et al., Physical Review A 68:022317, 2003), the coherent pulses generated in the coherent light source 80 of the first data processing device 10 are randomly phase-modulated by the phase modulation unit 81 by 0 or π and attenuated in the attenuation unit 82 for each time bin. In the second data processing device 11, each received pulse is split by a first 50:50 beam splitter 83 along a shorter path 84 and a longer path 85 and then recombined by a second 50:50 beam splitter 86. The beam splitters 83, 86 together with the paths 84, 85 form an interferometer. The longer path 85 has a length such that two adjacent pulses interfere at the second beam splitter 86.
[0146] This setup allows the partial wave functions of two consecutive pulses to interfere with each other. For a suitably determined phase in the interferometer, the first detector 87 clicks for a phase difference 0 between two consecutive pulses and the second detector 88 clicks for a phase difference π. After receiving a pulse, the second data processing device 11 has detected the detection time of the pulse and shares it with the first data processing device 10. From the detection times and the modulation data comprising the phase modulation of each pulse, the first data processing device 10 can determine which of the first and second detectors 87, 88 clicked for which pulse.
[0147] The bit value "0" can be identified with one of the quantum states |γ> or |-γ>, while the bit value "1" can be identified with one of the quantum states |γ> or |-γ>.
[0148] Defining that a first detector click corresponds to the bit value "0" and a second detector click corresponds to the bit value "1", the same bit string corresponding to the shared secret key can be established in both the first and second data processing devices 10, 11.
[0149] Considering an attack in which the eavesdropping device 12 obtains the entire lost part of the signal, for the original DPS QKD protocol, the maximum amount of information obtained in the eavesdropping device 12 about the bits sent from the first data processing device 10 corresponds to
[0150]
[0151] The structure for the probability p( ) of a deterministic measurement in equation (5) is preserved. The key length after post-selection and privacy amplification corresponds to
[0152]
[0153] In contrast, in the case where the signal loss r E is determined according to the proposed method, the maximum information obtainable by the eavesdropping device 12 is
[0154]
[0155] and the amplified key has the following key length
[0156]
[0157] Due to the similarity of the expressions for the DPS protocol in equations (10) to (13) to the corresponding expressions for the COW protocol, the analysis of the optimal signal strength, the key rate and the key rate ratio R / R orig between the key rate of the protocol according to the proposed method and the original protocol will yield similar results to the DPS protocol.
[0158] BB-84 protocol
[0159] In the BB-84 protocol (Bennett, Brassard, "Quantum cryptography: Public key distribution and coin tossing", IEEE International Conference on Computer, Systems and Signal Processing, Proceedings, vol. 175, p. 8, New York, 1984), in the first data processing device 10, each bit of a randomly generated string is encoded into one of the four quantum states {|0 x >|1 x >, |0 z >, |1 z}, thus forming two mutually unbiased orthogonal bases X and Z. The i-th bit can be encoded into |i x > or |i z >; the choice of the corresponding preparation basis is performed randomly. The resulting sequence of pulses is transmitted to the second data processing device 11.
[0160] In the second data processing device 11, for each bit, one of the measurement bases {X, Z} is chosen (with a success probability of 1 / 2) and the received state / pulse is measured in the chosen measurement basis. Subsequently, the preparation basis (and / or the measurement basis) used is shared between the first and second data processing devices 10, 11, for example via the public channel 14. Thus, on average half of the shared bits are discarded to obtain the shared key.
[0161] Initially, the BB-84 protocol has been conceived to use single-photon pulses. In experimental BB-84 implementations, attenuated coherent laser light is often used as a source of single-photon states. The laser generates weak coherent pulses with an unknown random general phase (with low intensity |γ 2 ), which is a statistical mixture of photon number states |n> (Fock states) with a Poisson distribution P n = exp(-|γ 2 ) · |γ 2n / n!, resulting in quantum states
[0162]
[0163] Correspondingly, the laser can also generate multi-photon pulses. This is in principle advantageous for a potential eavesdropper who can perform a photon number splitting (PNS) attack, gain all the remaining photons and store them in a quantum memory until the first data processing device 10 communicates the employed preparation basis to the second data processing device 11. The orthogonality condition x |1 x > = <0 z |1 z > = 0 allows the eavesdropping device 12 to distinguish between the logical bits "0" and "1" without any additional error. Thus, only single-photon pulses emitted by the laser of the first data processing device 10 guarantee a secure quantum key distribution. The secret key length that can be achieved in this case is
[0164]
[0165] where Q denotes the gain of the signal state / signal pulse (i.e. the probability that the signal state will be detected by the second data processing device 11) and E denotes the quantum bit error rate (QBER). Both Q and E can be easily obtained experimentally. Further, f(E) e [0, 1] denotes the error correction efficiency, Q1 denotes the gain of the single-photon state (i.e. the joint probability that a single-photon pulse has been emitted by the first data processing device 10 and detected by the second data processing device 11) and e1 denotes the error rate of the single-photon pulse.
[0166] The second data processing device 11 cannot usually distinguish between photons originating from single-photon pulses and photons originating from multi-photon pulses. Thus, Q1 and e1 cannot be determined directly and have to be estimated. At present, the most efficient estimation method is based on decoy states (see Lo et al., Physical Review Letters 94:230504, 2005 and Ma et al., Physical Review A 72:012326, 2005). To determine L fThe upper bound of L can be obtained by using the nonnegativity of the binary entropy function h2. f ≤L·1 / 2Q1.
[0167] The activity of the eavesdropping device 12 causes a decrease in the gain of the single-photon state Q1, which is the largest when there is no eavesdropping: Therefore, the upper bound of the shared secret key length of the original BB-84 protocol can be determined as follows:
[0168]
[0169] In applying the proposed technique to the BB-84 protocol, similar to the analysis of the wire-controlled COW protocol, the determined signal loss r is taken into account. E The probability of obtaining a deterministic result is...
[0170]
[0171] The factor 1 / 2 arises due to basis coordination. Assuming the eavesdropping device 12 possesses a quantum memory, it can store intercepted photons until basis coordination is achieved and optimal measurements are applied, thus obtaining complete information about the bit. Therefore, whenever at least one photon is intercepted by the eavesdropping device 12, the obtained information about the corresponding bit is...
[0172] max I′(A, E)=0·P E (0)+1·P E (≥1), (18)
[0173] Among them, P E (0) and P E (≥1)=1-P E (0) represents the probability of a vacuum state being intercepted and the probability of any positive number of photons being intercepted, respectively. Attributable to Poisson statistics, P E (0) = exp(-r E |γ| 2 The amplified key is established. After post-selection and privacy amplification, the amplified key has the following length.
[0174]
[0175] As described above in the context of the COW QKD protocol, the optimal strength of the signal pulse can be determined in order to maximize the key length L in equations (16) and (19), respectively. f and L′ f Subsequently, using the optimal intensity, the signal loss r can be determined. E The maximum key rate as a function of distance D. Figure 9 This is a graph showing the maximum key rate, where μ = 1 / 50km.-1 .
[0176] Figure 10 The key rate R = L′ determined for the proposed method is shown. f / L and the distance D and signal loss r used in the original COW protocol E The function (where, for the BB-84 decoy protocol, μ = 1 / 50km) -1 The key rate R orig =L f The key rate ratio between / L and R / R orig The chart. From Figure 10 It can be seen that if r can be E By controlling the signal strength to 1%, a key rate more than 20 times that of the original protocol can be achieved at a distance of 100km.
[0177] The features disclosed in this specification, drawings and / or claims may be material for implementing various embodiments, either individually or in various combinations thereof.
Claims
1. A method for quantum key distribution, the method being implementable in a system having multiple data processing devices (10, 11), the method comprising: – Determine the inherent loss of the quantum channel (13) between the first data processing device (10) and the second data processing device (11) in at least one of the first data processing device (10) and the second data processing device (11); – Generate a first signal in the first data processing device (10); – Generate a pulse sequence in the first data processing device (10) including at least one test pulse and a signal pulse generated from the first signal; – The pulse sequence from the first data processing device (10) is transmitted to the second data processing device (11) via the quantum channel (13); – The pulse sequence is received in the second data processing device (11), and a second signal is determined in the second data processing device (11) based on the pulse sequence; – Determine the location of the invalid signal and provide the location of the invalid signal in the first data processing device (10) and the second data processing device (11); – A first coordination signal is determined in the first data processing device (10) based on the first signal and the position of the invalid signal, and a second coordination signal is determined in the second data processing device (11) based on the second signal and the position of the invalid signal; – Determine the total loss along the quantum channel (13) based on the at least one test pulse received in the second data processing device (11), determine the signal loss based on the total loss and the inherent loss, and provide the signal loss in the first data processing device (10) and the second data processing device (11); – The shared key in the first data processing device (10) and the second data processing device (11) is determined by correcting the first coordination signal in the first data processing device (10) and correcting the second coordination signal in the second data processing device (11); as well as – By shortening the shared key by a shortening amount, the amplification key in the first data processing device (10) and the second data processing device (11) is determined based on the shared key, wherein the shortening amount is determined based on the signal loss and further based on the strength of at least one of the signal pulses.
2. The method according to claim 1, wherein, The quantum channel (13) includes an optical fiber, and / or wherein the at least one test pulse and the signal pulse are optical pulses.
3. The method according to claim 1 or 2, wherein, The quantum channel is configured such that the inherent loss is uniformly distributed along the quantum channel.
4. The method according to claim 1 or 2, wherein, The auxiliary bit sequence is encoded in a single test pulse.
5. The method according to claim 1 or 2, wherein, The pulse sequence includes multiple test pulses, wherein an auxiliary bit sequence is encoded in the multiple test pulses.
6. The method according to claim 1 or 2, wherein, The first coordination signal is determined based on the first signal by discarding invalid signal positions from the first signal, and / or the second coordination signal is determined based on the second signal by discarding invalid signal positions from the second signal.
7. The method according to claim 1 or 2, wherein, The total loss is determined based on the first intensity of the at least one test pulse generated in the first data processing device (10) and the second intensity of the at least one test pulse received in the second data processing device (11).
8. The method according to claim 1 or 2, wherein, The signal loss is determined by subtracting the inherent loss from the total loss.
9. The method according to claim 1 or 2, wherein, The method further includes estimating the error rate based on the first coordination signal and / or the second coordination signal.
10. The method according to claim 1 or 2, wherein, The shared key is shortened by applying a hash method to the shared key.
11. The method according to claim 1 or 2, wherein, The shortening amount is determined based on the product of the signal loss and the intensity of at least one of the signal pulses.
12. The method according to claim 1 or 2, wherein, The intensity of the signal pulse is adjusted to maximize the length of the shared key.
13. The method according to claim 1 or 2, wherein, The method follows at least one of the following: coherent one-way protocol, differential phase shift protocol, BB-84 protocol, B-92 protocol, T-12 QKD protocol, Y-00 QKD protocol, (4+2)-QKD protocol, SARG04 QKD protocol, and six-state protocol.
14. A system for quantum key distribution, the system comprising a plurality of data processing devices and configured to perform: – Determine the inherent loss of the quantum channel (13) between the first data processing device (10) and the second data processing device (11) in at least one of the first data processing device (10) and the second data processing device (11); – Generate a first signal in the first data processing device (10); – Generate a pulse sequence in the first data processing device (10) including at least one test pulse and a signal pulse generated from the first signal; – The pulse sequence from the first data processing device (10) is transmitted to the second data processing device (11) via the quantum channel (13); – The pulse sequence is received in the second data processing device (11), and a second signal is determined in the second data processing device (11) based on the pulse sequence; – Determine the location of the invalid signal and provide the location of the invalid signal in the first data processing device (10) and the second data processing device (11); – A first coordination signal is determined in the first data processing device (10) based on the first signal and the position of the invalid signal, and a second coordination signal is determined in the second data processing device (11) based on the second signal and the position of the invalid signal; – Determine the total loss along the quantum channel (13) based on the at least one test pulse received in the second data processing device (11), determine the signal loss based on the total loss and the inherent loss, and provide the signal loss in the first data processing device (10) and the second data processing device (11); – The shared key in the first data processing device (10) and the second data processing device (11) is determined by correcting the first coordination signal in the first data processing device (10) and correcting the second coordination signal in the second data processing device (11); as well as – By shortening the shared key by a shortening amount, the amplification key in the first data processing device (10) and the second data processing device (11) is determined based on the shared key, wherein the shortening amount is determined based on the signal loss and further based on the strength of at least one of the signal pulses.
Citation Information
Patent Citations
Quantum key distribution device, quantum key distribution system, and computer program product
US20160218868A1