An estimation method and system for the information leakage amount of quantum key distribution
By improving the security code rate estimation method in the quantum key distribution system, considering the information leakage amount of multi-photon pulses, the problem of underestimation of the QKD security code rate is solved, and the security and transmission distance are improved. It is suitable for the discrete variable quantum key distribution protocol based on GLLP theory.
Patent Information
- Application Number
- CN202411689245.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-22
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2044-11-22
AI Technical Summary
When existing quantum key distribution (QKD) technologies repeatedly consider multi-photon pulse information known to the opponent before and after information negotiation, the security code rate is underestimated.
By establishing an actual discrete variable quantum key distribution system related to privacy amplification and error error correction, considering the information leakage of the multi-photon part, the Cascade negotiation protocol is used to calculate the actual information leakage during error error correction, and the asymptotic security code rate expression is improved.
The security key rate and transmission distance of quantum key distribution are improved, the accuracy of security code rate estimation is enhanced, the theoretical limit of information leakage is exceeded, and the development of quantum key distribution is promoted.
Smart Images

Figure CN119544208B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of quantum communication, and more particularly, to a method and system for estimating the information leakage amount of quantum key distribution. Background Art
[0002] Currently, the only cryptographic algorithm proven to have information-theoretic security is the One Time Pad (OTP). The combination of Quantum Key Distribution (QKD) technology and the OTP algorithm has successfully solved the problem of key distribution, making the practical use of the one-time pad possible and providing theoretically unconditionally secure confidential communication services for remote communication parties. Although QKD technology is considered secure in theory, in practical applications, its security is affected by various factors. For example, the non-ideality of devices leads to performance deviations, corresponding attack means can be implemented against the non-ideality of devices, and the output results of some devices may be controlled by eavesdroppers. The security analysis of QKD is far from sufficient, and it is necessary to resist the actual security problems brought by device non-ideality. Therefore, it is crucial to conduct actual security analysis.
[0003] Existing research has repeatedly considered the information of multi-photon pulses known to the adversary (Eve) before and after information negotiation, and the secure bit rate of QKD has been underestimated. Summary of the Invention
[0004] The technical problem to be solved by the present invention is:
[0005] To solve the problem that the secure bit rate of QKD is underestimated by repeatedly considering the information of multi-photon pulses known to the adversary before and after information negotiation.
[0006] The technical solution adopted by the present invention to solve the above technical problem:
[0007] The present invention provides a method for estimating the information leakage amount of quantum key distribution, including the following steps:
[0008] S100. Establish an expression for the asymptotic secure bit rate in a practical discrete-variable quantum key distribution system related to privacy amplification and error correction, consider the information leakage amount of the multi-photon part, and obtain the actual information leakage amount and the actual asymptotic secure bit rate during the error correction process;
[0009] S200. Considering the symmetry of the discrete-variable protocol, for the sequence of the sender Alice, establish a data bit set generated by vacuum, single-photon, and multi-photon pulses; select the Cascade negotiation protocol, estimate the secure bit rate of the decoy-state BB84 protocol and the decoy-state MDI protocol, and obtain a calculation formula for the actual information leakage amount during the error correction process;
[0010] S300. Generate data blocks according to the Cascade negotiation protocol, shuffle the data block sequence, evenly distribute the secret key therein, calculate the minimum ratio of the counting rate of the multi-photon pulse to the signal pulse, correspondingly obtain the actual information leakage amount after the PNS attack, and finally obtain the improved asymptotic security code rate expression.
[0011] Further, in step S100, it includes
[0012] Let R represent the asymptotic security code rate expression in the actual discrete variable system. The asymptotic security code rate expressions for the privacy method and error correction of each signal are as follows:
[0013]
[0014] Among them, Ppass is the probability that the signal passes the screening; S is the set of all density operators that satisfy the joint statistics of the sender Alice and the receiver Bob; represents the minimum relative entropy of two classical-quantum joint states in the quantum and classical joint system, and ρ is the density operator; is the number of bits used for each bit of the original key in the error correction process;
[0015] Actual information leakage amount is:
[0016]
[0017] Among them, is the probability that the system is in the state characterized by photons; S(·) represents the von Neumann entropy; Z R is the classical register obtained by converting R; is the classical register measured on the standard basis, is the register storing the measurement result of Bob for the given announcement; and are the classical registers storing the announcements of the sender Alice and the receiver Bob respectively; is the density operator with the output photon number of ;
[0018] Let
[0019]
[0020] Among them, represents the information leakage amount from the multi-photon part;
[0021] Then there is
[0022]
[0023] Among them, represents the amount of information leakage during the error correction process of all photons.
[0024] Furthermore, in step S200, it includes that due to the symmetry of the discrete variable protocol, without loss of generality, for the sequence of the sender Alice, let A0, A1, and A M respectively represent the data bit sets generated by vacuum, single-photon, and multi-photon pulses, satisfying A = A0 ∪ A1 ∪ A M , where A is the set containing all data bits; after information reconciliation, a set of data blocks Each block c ∈ C is a set containing several bits in A; each block C leaks 1 bit of information, and the length of the screening code is N, then the estimator of the original information leakage amount of information reconciliation is
[0025] Let be known to the other party in the multi-photon part and needs to be subtracted before information reconciliation, then the estimator of the actual leakage amount is
[0026] Let D represent the set of data block lengths after information reconciliation, and the set C l , satisfies where C l is the set of data blocks with block length l, is the set of data blocks with block length l and data bits from multi-photons; it is known that the sequence will be shuffled before each round, and then the key is uniformly distributed in the sequence, so there is
[0027]
[0028] where Δ M represents the ratio of the counting rate of multi-photon pulses to the signal pulses; represents the minimum ratio of the counting rate of multi-photon pulses to the signal pulses;
[0029] Finally, the improved SKR formula is obtained:
[0030]
[0031] where q is the probability of successful screening; Q μ is the response rate of the signal state; is the lower limit of Δ M .
[0032] Furthermore, in step S300, for the decoy state BB84 protocol, it is known that in the decoy state BB84 protocol wherein, is the upper limit of Δ i (i = o, 1); by using the decoy state method, there is
[0033]
[0034] wherein, Q i represents the counting rate of pulses with photon number i (i = 0, 1, 2,..., n); Δ i = Q i / Q μ ; Y i is the probability that the detector at the receiving end Bob responds when the sending end Alice sends a pulse containing i photons; v1 and v2 are the average photon numbers of the double decoy states, and v2 << v1 < μ, where μ is the average light amount in the signal state;
[0035] According to Equation (7), there is
[0036]
[0037] Then, the upper bounds of Y1 and Δ1 are obtained as:
[0038]
[0039] For Y0 and Δ0, according to Equation (7), there is
[0040]
[0041] Therefore, the upper bounds of Y0 and Δ0 are
[0042]
[0043] According to Equation (9) and Equation (11), the value of can be calculated and substituted into Equation (6) to obtain the secure key rate.
[0044] Furthermore, in step S300, for the decoy state MDI protocol, let Calculate and
[0045]
[0046] wherein, the subscripts i and j of Δ ij respectively represent the photon numbers sent by the sending end Alice and the receiving end Bob, wherein, Q μμ is the signal state response rate, Q ijDenote the pulse count rates when the photon numbers from Alice and Bob are \(i\) (\(i = 0, 1, 2, \ldots, n\)) and \(j\) (\(j = 0, 1, 2, \ldots, n\)) respectively. is the lower limit of \(\Delta\) MM and is the upper limit of \(\Delta\) ij (for \(i, j = 0, 1\));
[0047] Solve according to the decoy state analysis and the following linear constraints and
[0048]
[0049] where is the upper limit of \(Y\) ij (for \(i, j = 0, 1\)), denotes the probability that the decoy state intensities of the sending - end Alice and the receiving - end Bob are and the photon number is \(n\) A (where \(n\) B ), which follows a Poisson distribution:
[0050]
[0051] According to Equation (12), calculate the value of and substitute it into Equation (6) to obtain the secure key rate.
[0052] An estimation system for the information leakage amount of quantum key distribution according to the present invention, the system has program modules corresponding to the above steps, and when running, executes the steps in the above - mentioned method for estimating the information leakage amount of quantum key distribution.
[0053] A computer - readable storage medium according to the present invention, the computer - readable storage medium stores a computer program, and the computer program is configured to implement the steps of the method for estimating the information leakage amount of quantum key distribution when called by a processor.
[0054] Compared with the prior art, the beneficial effects of the present invention are:
[0055] The present invention relates to a method and system for estimating the information leakage amount of quantum key distribution. By proving the interdependence between quantum pulses and classical data bits, and considering the information leakage amount generated by multi-photon pulses during the post-processing of quantum key distribution, a more accurate information leakage amount for post-processing is obtained, improving the secure key rate and transmission distance of quantum key distribution. The present invention can also improve the accuracy of secure code rate estimation and the overall performance of quantum key distribution protocols. By eliminating the information leakage caused by multi-photon pulses, the theoretical limit of information leakage during the negotiation process is exceeded. The method proposed by the present invention significantly promotes the development of quantum key distribution, especially in the field of post-processing research of quantum key distribution. In addition, this method is applicable to all discrete variable quantum key distribution protocols based on the Gottesman-Lo-Lutkenhaus-Preskill (GLLP) theory, and has important theoretical and practical value for the actual application of quantum key distribution, with broad application prospects. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 FIG. is a flowchart of a method for estimating the information leakage amount of quantum key distribution in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0057] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the following detailed description of the specific embodiments of the present invention will be given with reference to the accompanying drawings.
[0058] Mathematical Model
[0059] The known asymptotic secure key rate (SKR) formula is given by the difference between two information-theoretic quantities, which are related to privacy amplification (PA) and error correction (EC) respectively. Privacy amplification explains the information that needs to be subtracted from the original key to ensure that the final key remains secure from any potential eavesdropping by an adversary (Eve). Due to the noise in the quantum channel and the defects in the measurement device, an error correction term is needed to reconcile the differences between the keys held by the legitimate parties, namely the sender Alice and the receiver Bob.
[0060] Let R represent the SKR in an actual discrete variable QKD system. The asymptotic secure key rate SKR expressions for the privacy method PA and error correction EC per signal are as follows:
[0061]
[0062] Among them, ppass is the probability that the signal passes the screening. The screening process is a key step. In this process, the sender Alice and the receiver Bob compare their data subsets through a public channel to detect and discard any mismatched signals, thereby enhancing the security of the remaining key; represents the minimum relative entropy of two classical-quantum joint states in a quantum and classical joint system, where ρ is the density operator; is the number of bits used for each bit of the original key in the error correction process; S is the set of all density operators that satisfy the joint statistics of Alice and Bob;.
[0063] According to the label state compression model, The expression of is as follows:
[0064]
[0065] Among them, represents the probability that the system is in a state characterized by photons. S(·) represents the von Neumann entropy. For each output photon number The conditional entropy is minimized over the set of feasible normalized states where is the density operator with the output photon number being The key information is stored in the standard basis |j> of the register system R R and then, on this basis, decoherence processing is performed on R to convert R into a classical register Z R . E is 's purification system. w represents the knowledge of the error positions of Alice and Bob's data. and are classical registers that store the announcements of Alice and Bob respectively.
[0066] According to Equation (2), can be written in the form of a combination of pulses with different photon numbers. Specifically, represents the minimization problem on the state space S, where each term in the summation corresponds to a different photon number Here, represents the probability that the system is in a state characterized by photons, and the conditional entropy of each is minimized over the subspace .
[0067] Similarly, the information leakage during the error correction process, denoted as can be expressed as the conditional entropy. The information that must be made public to correct the error codes between the keys of the sender Alice and the receiver Bob. It can be seen from the following analysis process that is also composed of pulse combinations with different photon numbers:
[0068]
[0069] Among them, can be regarded as a classical register measured on the standard basis, where is the register storing the measurement results of Bob for a given announcement. A S is an auxiliary system related to the photon number, which is private to the sender Alice and is well-known in the art.
[0070] The calculation method of the first term in Equation (3) is as follows:
[0071]
[0072] Because,
[0073]
[0074] Then,
[0075]
[0076] Then Equation (4) is,
[0077]
[0078] Because,
[0079]
[0080] We have,
[0081]
[0082] Similarly, the calculation result of the second term in Equation (3) is:
[0083]
[0084] Substituting Equation (9) and Equation (10) into Equation (3), we get,
[0085]
[0086] Equation (11) reflects the dependence of the quantum state for key generation on the statistical distribution of photon numbers during the error correction process. Substituting Equation (2) and Equation (11) into Equation (1), we get,
[0087]
[0088] As can be seen from Equation (12), SKR is composed of three components: zero-photon, single-photon, and multi-photon contributions. Each term in these components has a physical meaning and should be non-negative. Assuming Eve launches the strongest attack without violating the principles of quantum mechanics, for polarization-encoded phase-randomized pulses, Eve can perform a PNS attack. This means that the PA part of the third term in the second equality in Equation (12) is theoretically zero because Eve can obtain complete information about the multi-photon state using a PNS attack. In previous calculations, it was assumed that the multi-photon part is greater than zero, i.e.,
[0089]
[0090] Therefore, the SKR contribution from the multi-photon part is a negative number, which does not conform to the actual physical meaning.
[0091] Specific implementation method 1: As shown in Figure 1 , the present invention provides a method for estimating the information leakage amount of quantum key distribution, including the following steps:
[0092] From Equation (12) and , the combination of pulses with different photon numbers emphasizes the complexity of the quantum key distribution process, where each photon number component has a different contribution to the overall security and efficiency of the QKD system. These components need to be analyzed and optimized to ensure the security of the final key while minimizing information leakage during error correction. The present invention focuses on the EC part and proposes an improvement in the estimation of this part. This improvement ensures that the third term in Equation (12) is greater than or equal to zero, thus conforming to the actual physical meaning.
[0093] Considering the actual information leakage amount Equation (1) should be:
[0094]
[0095] The actual information leakage amount is:
[0096]
[0097] Let
[0098]
[0099] where represents the information leakage amount from the multi-photon part. Then,
[0100]
[0101] Due to the complexity of von Neumann entropy calculation, we propose a simple and easy-to-understand method to estimate the information leakage of the EC part. Due to the symmetry of discrete-variable QKD protocols, without loss of generality, we only focus on the sequence of the sender Alice. Let A0, A1, and A M denote the sets of data bits generated by vacuum, single-photon, and multi-photon pulses respectively, satisfying A = A0 ∪ A1 ∪ A M , where A is the set containing all data bits. Regardless of which negotiation protocol is applied, a set of data blocks will be generated after information negotiation Each block c ∈ C is a set containing several bits in A. Ideally, all blocks of C are linearly independent. In this case, each block C leaks 1 bit of information, and the original information leakage of information negotiation where N is the length of the sifted key. Let Since Eve has carried out the PNS attack, the information in the multi-photon part has been completely known to Eve and has been subtracted before information negotiation. Therefore, the information leakage of this part should not be calculated again during information negotiation. Then there is It should be emphasized that this does not violate Shannon's theorem. During information negotiation, the amount of information that still needs to be interacted is.
[0102] Let D denote the set of data block lengths after information negotiation. For example, the set of data block lengths of Cascade is D = {8, 4, 2, 1}. The set C l , satisfies where, C l is the set of data blocks with block length l, is the set of data blocks with block length l and data bits from multi-photons. Given that the sequence is scrambled before each round and then the key is uniformly distributed in the sequence, we have
[0103]
[0104] where, Δ M represents the ratio of the counting rate of multi-photon pulses to the signal pulses; represents the minimum ratio of the counting rate of multi-photon pulses to the signal pulses.
[0105] We finally obtain the improved SKR formula:
[0106]
[0107] where, q is the probability of successful sifting; Q μ is the response rate of the signal state; is Δ M the lower limit.
[0108] Security key rate estimation for decoy state BB84 and MDI
[0109] As can be seen from Equation (19), the key parameter is For this reason, the present invention gives the calculation method for two typical discrete-variable QKD protocols (i.e., decoy BB84 and MDI protocols) based on the GLLP (Gottesman-Lo-Lutkenhaus-Preskill) theory. We can clearly see from Equation (19) that the smaller the data block length l, the better our method performs. However, in commonly used non-interactive information reconciliation protocols, a larger l is usually applied to achieve a higher reconciliation efficiency f. Therefore, we believe that these information reconciliation protocols cannot obtain a significant SKR improvement from our method. In contrast, after Cascade reconciliation, a set of data blocks with different lengths will be obtained, and the length can be as low as 1. Therefore, we conclude that using Cascade reconciliation can obtain a greater SKR improvement. In addition, considering that the reconciliation efficiency f of Cascade is quite high, we believe that Cascade is the most suitable information reconciliation protocol for the present invention.
[0110] Decoy state BB84 protocol
[0111] The most special protocol type in the decoy state protocol is called the "weak + vacuum" decoy state protocol, where the average number of photons in the optical pulse satisfies v2 << ν1 < μ (where μ is the average optical amount in the signal state, and v1 and v2 are the average numbers of photons in the two decoy states). It is known that in the decoy state BB84 protocol We only need to focus on calculating and where, is Δ i (i = 0, 1) the upper limit. By using the decoy state method, we have,
[0112]
[0113] where, Q i represents the counting rate of the pulse with the photon number i (i = 0, 1, 2,..., n), Δ i = Q i / Q μ , Y i is the probability of the detector response at the receiving end Bob when the sending end Alice sends a pulse containing i photons, and v1 and v2 are the average numbers of photons in the double decoy state.
[0114] According to Equation (20), we have,
[0115]
[0116] Then, the upper bounds of Y1 and Δ1 are obtained as:
[0117]
[0118] For Y0 and Δ0, according to Equation (20), we have
[0119]
[0120] Therefore, the upper bounds of Y0 and Δ0 are
[0121]
[0122] According to Equation (22) and Equation (24), we can calculate the value of, and substitute it into Equation (19) to obtain the secure code rate.
[0123] Decoy state MDI protocol
[0124] Similar to the decoy state BB84 protocol, we need to calculate and where Q μμ is the signal state response rate, and Q ij represents the pulse counting rate when the number of photons from Alice and Bob is i (i = 0, 1, 2,..., n) and j (j = 0, 1, 2,..., n), respectively. is the lower limit of Δ MM , is the upper limit of Δ ij (i, j = 0, 1). We have:
[0125]
[0126] According to the decoy state analysis and the following linear constraints,
[0127]
[0128] we can solve for and where is the upper limit of Y ij (i, j = 0, 1). represents the probability that the decoy state intensity of Alice (Bob) is when the number of photons is n A (n B ), which follows a Poisson distribution:
[0129]
[0130] According to Equation (25), we can calculate the value and substitute it into Equation (19) to obtain the secure key rate.
[0131] Specific Embodiment 2: An estimation system for information leakage amount of quantum key distribution in the present invention. This system has program modules corresponding to the above steps and executes the steps in the above-mentioned method for estimating information leakage amount of quantum key distribution when running.
[0132] Other combinations and connection relationships in this embodiment are the same as those in Specific Embodiment 1.
[0133] Specific Embodiment 3: A computer-readable storage medium in the present invention. The computer-readable storage medium stores a computer program, and the computer program is configured to implement the steps of the method for estimating information leakage amount of quantum key distribution when called by a processor.
[0134] Other combinations and connection relationships in this embodiment are the same as those in Specific Embodiment 1.
[0135] In the present invention, we propose a new method. By proving the interdependence between quantum pulses and classical data bits, we can improve the accuracy of secure key rate estimation and enhance the overall performance of the QKD protocol. By eliminating the information leakage caused by multi-photon pulses, the method we proposed surpasses the previous theoretical limit of information leakage during the negotiation process. We predict that the present invention can significantly promote the development of QKD, especially in the field of QKD post-processing research. It should be noted that our method is applicable to all discrete-variable QKD protocols based on the GLLP (Gottesman-Lo-Lutkenhaus-Preskill) theory. It must be emphasized that this method conforms to Shannon's theorem, and the required information leakage amount L all = Nh(e) ensures reliable negotiation. However, before information negotiation, Eve already knows a part of L all Therefore, Eve's actual information leakage L actual is less than Nh(e).
[0136] In addition, the core idea of the present invention indicates that quantum signal and classical signal processing are not completely independent, which may also have a significant impact on continuous-variable QKD protocols. Therefore, when estimating the information leakage amount through the classical channel, the influence of quantum pulses on classical data bits should be considered. Once some information leakage has been obtained by Eve before negotiation, regardless of the type of QKD protocol, this part of the leaked information amount should not be ignored when calculating the SKR Therefore, if there is a similar interdependence, continuous-variable QKD can also achieve a higher SKR.
[0137] Although the present invention is disclosed as above, the scope of protection of the present invention is not limited thereto. Those skilled in the art of the present invention can make various changes and modifications without departing from the spirit and scope of the present disclosure, and these changes and modifications will all fall within the scope of protection of the present invention.
Claims
1. A method for estimating the information leakage amount of quantum key distribution, characterized in that Including the following steps: S100. Establish the asymptotic security code rate expression in the actual discrete variable quantum key distribution system related to privacy amplification and error correction. Considering the information leakage amount of the multi-photon part, obtain the actual information leakage amount and the actual asymptotic security code rate during the error correction process; Including Let R represent the asymptotic security code rate expression in the actual discrete variable system. The privacy method for each signal and the asymptotic security code rate expression for error correction are as follows: where p pass is the probability that the signal passes the screening; S is the set of all density operators that satisfy the joint statistics of the sender Alice and the receiver Bob; represents the minimum relative entropy of two classical-quantum joint states in a quantum and classical joint system, and ρ is the density operator; is the amount of information leakage of each bit of the original key during the error correction process; Actual information leakage volume is as follows: wherein, is the probability that the system is in a state characterized by photons; S(·) represents the von Neumann entropy; Z R is the classical register obtained by converting R; is the classical register measured on the standard basis of ; is the register storing the measurement result of Bob for a given announcement; and are the classical registers storing the announcements of the sender Alice and the receiver Bob respectively; is the density operator with the output photon number being ; Let Among them, represents the amount of information leakage from the multi-photon part; Then Among them, is the amount of information leakage of each bit of the original key during the error correction process; S200. Considering the symmetry of the discrete variable protocol, for the sequence of the sender Alice, establish the data bit sets generated by vacuum, single-photon, and multi-photon pulses; select the Cascade negotiation protocol, and perform the security code rate estimation of the decoy state BB84 protocol and the decoy state MDI protocol to obtain the calculation formula for the actual information leakage amount during the error correction process; S300. Generate data blocks according to the Cascade negotiation protocol, shuffle the data block sequence, and evenly distribute the secret key among them. Calculate the minimum ratio of the multi-photon pulse count rate to the signal pulse, and correspondingly obtain the actual information leakage amount after the PNS attack, and finally obtain the improved asymptotic security code rate expression.
2. The estimation method for the information leakage amount of quantum key distribution according to claim 1, characterized in that: In step S200, due to the symmetry of the discrete variable protocol, without loss of generality, for the sequence of the sender Alice, let A0, A1, and A M respectively represent the data bit sets generated by vacuum, single-photon, and multi-photon pulses, satisfying A = A0 ∪ A1 ∪ A M , where A is the set containing all data bits; after information reconciliation, a set of data blocks is generated. Each block c ∈ C is a set containing several bits in A; each block C leaks 1 bit of information. If the length of the screening code is N, then the estimator of the original information leakage of information reconciliation is Suppose If the multi - photon part has been known to the other party and needs to be subtracted before information negotiation, then the estimated value of the actual leakage is Let D denote the set of data block lengths after information negotiation, the set satisfies where C l is the set of data blocks with block length l, is the set of data blocks with block length l and data bits from multi-photons; given that the sequence is scrambled before each round and then the keys are uniformly distributed in the sequence, then where, Δ M represents the ratio of the count rate of multi-photon pulses to the signal pulses; represents the minimum ratio of the count rate of multi-photon pulses to the signal pulses; Finally, obtain the improved SKR formula: where q is the probability of successful screening; Q μ is the response rate of the signal state.
3. The estimation method for the information leakage amount of quantum key distribution according to claim 2, characterized in that: In step S200, for the decoy state BB84 protocol, it is known that in the decoy state BB84 protocol wherein, is the upper limit of Δ i , i = 0, 1; by using the decoy state method, there is Among them, Q i represents the counting rate of pulses with the number of photons being i, where i = 0, 1, 2, …, n; Δ i = Q i / Q μ ; Y i is the probability of the detector response at the receiving end Bob when the transmitting end Alice sends a pulse containing i photons; ν1 and ν2 are the average photon numbers of the two decoy states, and ν2 << ν1 < μ, where μ is the average light amount in the signal state; According to Equation (7), there is Then, obtain the upper bounds of Y1 and Δ1 as: For Y0 and Δ0, according to Equation (7), there is Therefore, the upper bounds of Y0 and Δ0 are According to Equation (9) and Equation (11), it is possible to calculate the value, and substituting it into Equation (6) gives the secure code rate.
4. The estimation method for the information leakage amount of quantum key distribution according to claim 3, characterized in that: In step S300, for the decoy-state MDI protocol, assume Calculate and where, Δ ij The subscripts i and j respectively represent the number of photons sent by the sender Alice and the receiver Bob. where, Q μμ is the signal state response rate, and Q ij represents the pulse count rates when the number of photons from Alice and Bob are i, i = 0, 1, 2,..., n and j, j = 0, 1, 2,..., n respectively. is the lower limit of Δ MM and is the upper limit of Δ ij for i, j = 0, 1. Solve according to the decoy state analysis and the following linear constraints and Among them, among them is Y ij , the upper limit for i, j = 0, 1 indicates that the intensity of the decoy state of the sender Alice is when the number of photons is n A probability indicates that the intensity of the decoy state of the receiver Bob is when the number of photons is n B probability, following the Poisson distribution: According to Equation (12), calculate the value, and substitute it into Equation (6) to obtain the secure code rate.
5. An estimation system for the information leakage amount of quantum key distribution, characterized in that: The system has program modules corresponding to the steps of any one of the above claims 1-4, and executes the steps in the above method for estimating the information leakage amount of quantum key distribution when running.
6. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and the computer program is configured to implement the steps of the method for estimating the information leakage amount of quantum key distribution according to any one of claims 1-4 when called by a processor.
Citation Information
Patent Citations
A key error correction method and a quantum key distribution system
CN109936445A
System and method for protecting conventional quantum key distribution protocols
US20230216671A1