Novel quantum key distribution transmission system

By introducing trusted region and multi-photon pulse technology in the quantum key distribution system, the application restriction of existing QKD systems in long-distance and high-noise channels is solved, and compatibility between high key rates and long-distance communication is achieved.

CN120034319APending Publication Date: 2025-05-23THALES ALENIA SPACE ITALIA SPA CON UNICO SOCIO
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411660377.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-11-22
Filing Date
2024-11-20
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The application of existing quantum key distribution (QKD) systems in long-distance and high-noise channels is limited, with low key rates and difficult to achieve long-distance communications that are compatible with user needs.

Method used

By introducing a trusted area in the QKD transmission system, the transmitter is configured to transmit multi-photon pulses to the receiver through the trusted area, and use the trusted distance D to determine the transmission power, ensuring that the single-photon pulse propagates outside the trusted area, and achieving secure communication.

Benefits of technology

The key transmission rate and communication distance of the QKD system are improved, providing a controllable trade-off between security and performance, and are suitable for satellite and terrestrial communication scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034319A_ABST
    Figure CN120034319A_ABST
Patent Text Reader

Abstract

The present application relates to a quantum key distribution (QKD) transmission system (2, 3) comprising a transmitter (31) and a receiver (32), in which the transmitter (31) is configured to transmit multiphoton pulses to the receiver (32) through a trusted area (23, 33) extending from the transmitter (31) to the receiver (32) up to a trusted distance (D) from the transmitter (31); wherein the transmitter (31) is configured to transmit a multiphoton pulse at a transmit power such that a single photon pulse propagates out of the trusted area (23, 33) until reaching the receiver (32).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This patent application claims the priority of Italian Patent Application No. 102023000024831 filed on November 22, 2023, the entire disclosure of which is incorporated herein by reference. Technical Field

[0003] The present application generally relates to a Quantum Key Distribution (QKD) transmission system. Background Art

[0004] Today, quantum key distribution (QKD) systems are one of the most promising solutions for improving security in encrypted communications. QKD systems find horizontal applications in many areas, such as in space infrastructure, where they are used both as a communication service and for critical data encryption in the fields of navigation and observation (e.g., Earth observation).

[0005] In general, the term quantum key distribution (QKD) refers to a set of protocols whose purpose is to generate a secret bit string called a key between two parties, usually Alice and Bob, by exploiting the properties of quantum mechanics. The successful implementation of a QKD protocol is based on generating a key that consists of a uniformly and randomly distributed sequence of bits (i.e., 1s or 0s) known only to Alice and Bob. In particular, the QKD protocol is based on typical properties such as:

[0006] Quantum superposition; and

[0007] It is impossible to clone a quantum state with one hundred percent (100%) fidelity (ie, the no-cloning theorem).

[0008] In addition, the property of the QKD protocol is that Alice and Bob can detect the presence of a malicious third party / eavesdropper, usually referred to as Eve, whose purpose is to deduce the secret key without being noticed. In fact, the possibility of directly identifying the eavesdropper stems from the laws of quantum mechanics that ensure that any interaction of a quantum system with the environment changes its state. In particular, the changes in the properties of the quantum state can be measured and analyzed by Alice and Bob, who can choose to stop the protocol if Eve is listening in on the communication.

[0009] From a theoretical point of view, many protocols have been envisioned since the article by Bennett and Brassard in 1984, exploring different approaches, different functional principles and different implementation concepts, in which Bennett and Brassard proposed the first QKD protocol called BB84. In this regard, reference may be made to:

[0010] CH Bennett and G. Brassard, in International Conference on Computers, Systems & Signal Processing, Ban-galore, India, Dec 9-12 (1984) pp. 175-17;

[0011] Grünenfelder, Fadri, et al. "Simple and high-speed polarization-based QKD" Applied Physics Letters 112.5 (2018): 051108;

[0012] Bennett, Charles H. "Quantum cryptography using any two nonorthogonal states" Physical review letters 68.21 (1992): 2121); and

[0013] Bennett, Charles H., Gilles Brassard, and N. David Mermin. "Quantum cryptography without Bell's theorem" Physical review letters 68.5 (1992): 557.

[0014] In addition, several QKD protocols have been shown to be theoretically secure. This research work did not stop at conceiving that QKD protocols are theoretically secure, but analyzed the experimental conditions in which QKD can occur, taking into account non-ideal features of the setup, environmental conditions and real-world scenarios.

[0015] To classify QKD protocols, two main groupings are usually made, among which,

[0016] The first grouping concerns the type of encoding used, i.e. if the information is encoded in continuous-valued degrees of freedom or in discrete-valued degrees of freedom of the chosen quantum system, resulting in a continuous variable (CV) protocol and a discrete variable (DV) protocol, respectively; DV protocols are now considered to be more advanced than CV protocols from both theoretical and experimental points of view; in particular, DV protocols are the first class of protocols to be experimentally demonstrated and many known QKD systems are based on said DV protocols; and

[0017] The second grouping can be performed according to the basic functional principle, ie if the protocol is based on prepare and measure-PM-technology (PM protocol) or on entangling-EB-technology (EB protocol).

[0018] The PM protocol or "trusted" protocol implies that one of the parties, say Alice, generates a classical random bit string, encoding each bit in the state of the quantum system, and transmits it to the second party, say Bob, who in turn measures the encoded bits in order to extract the information encoded by Alice.

[0019] in this regard, Figure 1 An example of implementing the PM protocol is schematically shown. In this regard, it is noted that Figure 1 It is immediately understandable to experts in the field of QKD, so it is considered that the detailed description Figure 1 is redundant.

[0020] EB protocols or "trustless protocols" are based on the entanglement property of quantum mechanics, where entangled particles can be described as a system whose parts cannot be described independently of each other. In general, protocols based on the entanglement property do not require any preparation steps and can assume that the source of the quantum state is in the hands of an eavesdropper without any loss of communication security. In this regard, Figure 2 An example of implementing the BBM92 protocol is schematically shown. In this regard, it is noted that Figure 2 It is immediately understandable to experts in the field of QKD, so it is considered that the detailed description Figure 2 is redundant.

[0021] Regardless of the type of protocol implemented, a typical implementation of QKD is performed by encoding information in the degrees of freedom of a single photon (where, as is known, a photon is the smallest amount of energy in an electromagnetic field), where photons are chosen as encoding quantum systems due to their suitability for communication purposes. In particular, in the CV protocol, the orthogonality of the electric field is considered as the encoding degree of freedom, while in the DV protocol, the encoding degree of freedom used for QKD is the polarization of the photon, the time of arrival of a photon at a detector, or the phase difference between two consecutive photons.

[0022] As is known, a non-negotiable property in the implementation of a QKD system is that each bit of the key must be encoded by only one photon. In fact, if the same bit is encoded by more than one photon, an eavesdropper can steal one of the photons encoding the same bit, thereby extracting the information encoded in the stolen photon, without Alice and Bob being able to notice the presence of the eavesdropper. Although some countermeasures have been envisioned to deal with the possibility that more than one photon encodes the same bit of the key, the single-photon requirement must be met, making it one of the main bottlenecks in the implementation of the QKD protocol. It is worth noting that photons are subject to scattering and high losses during their propagation, especially in optical fiber links, where they undergo exponential decay due to absorption.

[0023] In particular, losses are detrimental to QKD protocols, since the no-cloning theorem prevents quantum states from being copied or amplified during photon propagation (e.g., for extending propagation distances), thus placing limitations on implementing QKD protocols in fiber-based infrastructures. In practice, no more than a few hundred kilometers can be covered with fiber-based technologies (in this case, this can be done with dedicated ultra-low-loss optical fibers), which is now extremely relevant to achieve long distances and wide coverage.

[0024] In 2017, the research team performed experimental implementations of free-space and satellite QKD, achieving long-distance reach and wide coverage. However, in the best-case scenario, despite the relative increase in the number of photons that can be successfully exchanged relative to fiber-based implementations, their absolute value is still limited by the approximately 30-40dB loss in a typical low-Earth orbit (LEO) satellite; in addition, the key rate and key capacity achievable in a typical QKD session are limited to tens of kilobits per second.

[0025] Then, the extremely high relevance of the security of communications and the increased need for cryptographic keys in some applications require smart solutions capable of increasing the known achievable key rate. In fact, one of the main limitations of QKD systems is the achievable key rate, especially in networks characterized by long distances between users, where the key rate is always extremely low and often incompatible with the key rate required by the users. Currently, the limitations related to the achievable key rate inherent in the QKD protocol are often accepted a priori, limiting the applicability of QKD solutions in terms of performance and achievable distances.

[0026] The implementation of PM protocols is usually based on pulse technology, in which a pulsed laser is attenuated to the level of single photons by means of a high-performance attenuator. In detail, the number of photons within each pulse follows a Poisson distribution and is not constant due to the statistical properties of light. In particular, after the attenuation of the laser pulse, each photon is polarized independently of each other so that each bit of the key is encoded in each single-photon level pulse, wherein, due to the Poisson distribution of the number of photons, it is not certain that each attenuated laser pulse produces exactly a single photon; usually, the attenuation is such that for the largest part of the pulse no photons are accommodated in each pulse, but this does not prevent that sometimes each pulse has more than one photon, thus posing a risk to security in QKD. A typical way to overcome this limitation is represented by the decoy state method, which, contrary to the standard BB84 protocol, uses pulses comprising more than one photon per pulse, wherein the presence of an eavesdropper is inferred by monitoring the statistics of the arriving pulses. However, although the decoy state method represents a countermeasure to photon number splitting attacks, the decoy state method cannot be implemented by simply increasing the number of photons emitted per pulse; in fact, the typical average number of photons per pulse is below 1, thereby failing to increase the communication distance. It is clear that the main limitation that characterizes the implementation of QKD is the impossibility of working with multi-photon states.

[0027] Currently, typical commercial systems are being developed to overcome the limitations described above, but their application in real-life scenarios is limited by propagation losses.

[0028] In recent years, some patents have been granted for inventions facing the above problems; for example, reference may be made to US9294191B2, US7831050B2 and US10348493B2.

[0029] From a theoretical point of view, QKD has been proven to be information-theoretically secure, so it guarantees that an eavesdropper does not obtain any information related to the key, except with negligible probability.

[0030] In general, quantum mechanics predicts that it is impossible to observe a quantum mechanical system without changing its state, so if an eavesdropper tampers with the quantum channel, the protocol identifies the attack and the calculation of the secret key is interrupted.

[0031] As is known, the main limitations of the QKD protocol involve losses and noise in the quantum communication channel; in the theoretical analysis of QKD systems, it is assumed that a potential eavesdropper has full control over the quantum channel and that he / she can use unlimited classical and quantum resources to eavesdrop on the secret communication between Alice and Bob; from an experimental point of view, this means that all losses must be attributed to the presence of the eavesdropper, since no distinction can be made between natural noise and the actions of the eavesdropper.

[0032] in this regard, Figure 3 The key rate (SKR)-channel loss tradeoff for optical QKD applying different protocols is shown, where:

[0033] SKR is expressed as the number of bits per mode (i.e., per QKD protocol), and

[0034] Channel loss is due to noise and is expressed in dB.

[0035] like Figure 3 As shown in , in all presented QKD protocols, the key distribution is successful only when the noise level as well as the channel loss is low enough, where the relationship between SKR and noise leads to an exponential SKR distance tradeoff.

[0036] Typically, QKD is based on pulses consisting of single photons, which inherently transmit small amounts of energy, resulting in a high probability of losing these pulses during transmission, making QKD very difficult to implement in high-noise channels as satellite-to-ground and long-fiber based communications.

[0037] In practice, even assuming ideal sources and detectors, the losses are related to the distance between Alice and Bob, so after a certain distance, QKD cannot be used because the key rate drops to zero. Currently, the SKR-distance tradeoff is the main limiting factor for QKD long-distance direct communications, both terrestrial and satellite.

[0038] It has been shown that the upper bound of the secure key rate (SKR) is a function of the channel loss, in particular of the maximum allowable channel noise, regardless of how much optical power is available to the protocol.

[0039] Currently, quantum repeaters and / or trusted node architectures are the main technical solutions to overcome the said limitations, but these solutions are not technically mature and / or require strong assumptions about the type of network.

[0040] Given the above, there is a strong need for effective QKD solutions to overcome the limitations in direct communication, especially with respect to the SKR-distance trade-off. SUMMARY OF THE INVENTION

[0041] In view of the limitations and drawbacks of known quantum key distribution (QKD) systems, the purpose of the present application is to introduce a controllable trade-off between security and performance (achievable communication distance and key rate (SKR)) in a QKD transmission system.

[0042] The present application achieves this purpose and other purposes, because the present application relates to a QKD transmission system as defined in the appended claims.

[0043] Specifically, the QKD transmission system according to the present application includes a transmitter and a receiver, wherein the transmitter is configured to emit multi-photon pulses through a trusted region towards the receiver, the trusted region extending from the transmitter towards the receiver up to a trusted distance from the transmitter, and wherein the transmitter is configured to emit the multi-photon pulses with an emission power such that single-photon pulses propagate out of the trusted region until they reach the receiver. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] To better understand the present application, preferred embodiments will now be described by way of non-limiting examples, purely by way of non-restrictive examples, with reference to the accompanying drawings (none of which are drawn to scale), in which:

[0045] Figure 1 An example of implementing the PM protocol is schematically shown;

[0046] Figure 2 An example of implementing the BBM92 protocol is schematically shown;

[0047] Figure 3 The key rate-channel loss trade-off for optical QKD and for different QKD protocols is shown;

[0048] Figure 4 The typical structure of a known type of satellite QKD transmission system is schematically shown;

[0049] Figure 5 Schematically shows a satellite QKD transmission system according to a preferred embodiment of the present application;

[0050] Figure 6 Schematically shows a QKD transmission system according to another preferred embodiment of the present application;

[0051] Figure 7 Schematically shows Figure 5 and Figure 6 The operation logic of the QKD transmission system shown in;

[0052] Figure 8 Schematically shows Figure 5 and Figure 6 The functional structure of the transmitter of the QKD transmission system shown in;

[0053] Fig. 9 schematically illustrates an example of a fiber-based experimental setup for implementing QKD according to the teachings of the present application; and

[0054] Fig.10 Schematically shows the Figure 5 and Figure 6 Examples of different sizes of trusted regions for the QKD transmission system shown in . DETAILED DESCRIPTION

[0055] The following description is given to enable those skilled in the art to understand, make and use the present application. Various modifications to the embodiments will be apparent to those skilled in the art without departing from the scope of the present application as claimed. Therefore, the present application is not intended to be limited to the embodiments shown and described, but to conform to the broadest scope of protection consistent with the features defined in the appended claims.

[0056] The present application relates to a quantum key distribution (QKD) transmission system including a transmitter and a receiver.

[0057] The transmitter is configured to transmit a multi-photon pulse to a receiver through a trusted region extending from the transmitter to the receiver up to a trusted distance from the transmitter.

[0058] In particular, the transmitter is configured to transmit the multi-photon pulse at a transmit power such that the single-photon pulse propagates out of the trusted region until it reaches the receiver.

[0059] Preferably, the QKD transmission system according to the present application can control the security / performance tradeoff in the following ways:

[0060] defining an area of ​​predetermined size that is assumed to be protected by ad hoc means (e.g., monitoring systems / equipment / sensors) or assumed to be secure, wherein the assumed secured / secure area extends a trusted distance D (e.g., expressed in km) from the transmitter, and

[0061] Therefore, calculate the optical power to be sent by the transmitter to the receiver.

[0062] In the following, for simplicity of description without loss of generality, the expression "trusted region" will be used as a synonym for the expression "region of a predetermined size assumed to be safe / secure", in which the multi-photon states encoding the key bits can also be considered safe. This is because in the trusted region, it is defined that there are no eavesdroppers.

[0063] The QKD transmission system according to the present application increases the key transmission rate in proportion to the trusted distance D, so that a higher D results in higher transmission performance (i.e., a higher key rate SKR) but lower security assurance, while a lower D results in lower transmission performance (i.e., a lower SKR) but higher security.

[0064] Hereinafter, a satellite QKD transmission system according to a preferred embodiment of the present application will be described in detail. However, the satellite application of the present application is not restrictive and has no boundaries, as the latter can be advantageously used for terrestrial applications when necessary.

[0065] In the satellite scenario, it is reasonable to assume that the presence of a potential observer in a certain region is easily detected from the source, thereby relaxing some constraints on the single-photon state.

[0066] In this article, Figure 4 A typical structure of a satellite QKD transmission system of a known type, generally designated 1, is schematically shown. The satellite QKD transmission system 1 comprises a transmitter (TX) mounted on a satellite 11 and a receiver (RX) integrated into a ground station 12, wherein an optical link 13 is established between TX and RX based on the transmission of single photon pulses.

[0067] Figure 5 The high-level architecture of the satellite QKD transmission system 2 according to the preferred embodiment of the present application is schematically shown. Figure 5 As shown in , the satellite QKD transmission system 2 includes a transmitter (TX) mounted on a satellite 21 and a receiver (RX) integrated into a ground station 22, wherein a trusted area 23 extends from TX to RX until it is a trusted distance D (e.g., expressed in km) from TX.

[0068] Preferably, if Figure 5As shown in , the trusted area 23 is shaped as a right circular cone with a vertex located at TX, wherein the height of the right circular cone coincides with the trusted distance D.

[0069] In use, TX transmits high power multi-photon pulses to RX through the trusted region 23, thereby increasing the total probability of photons reaching RX. However, the transmission of high power, multi-photon pulses implies that the communication cannot be considered inherently secure for the trusted region 23, but the trusted region 23 can be assumed to be secure because there is no possibility of an eavesdropper in the vicinity of TX for the geometry of the satellite QKD transmission system 2, or because active monitoring of the trusted region 23 is achieved.

[0070] Compared to the satellite QKD transmission system 1 of the known type, the satellite QKD transmission system 2 has the following advantages (more generally, compared to all known satellite QKD systems):

[0071] Increase the achievable communication distance by any amount,

[0072] The achievable key rate increases proportionally with the increase in the trust distance D,

[0073] By limiting the size of the trusted region 23, we can increase the controllable tradeoff between achievable communication distance and SKR activation,

[0074] Security is limited to areas that require it, thus improving system performance.

[0075] By actively monitoring areas excluded from QKD security, a security balance can be achieved.

[0076] In addition, the advantages result in:

[0077] Enabling new applications and use cases for QKD transmission systems that were previously not feasible due to:

[0078] Over the entire communication distance, and

[0079] The achievable key rate is incompatible with the encryption system requirements;

[0080] Improving the performance of existing QKD applications, for example by:

[0081] Dynamically select trusted zones to achieve the best tradeoff between SKR and security based on specific circumstances.

[0082] The area around the transmission system is exploited statically (in many environments, the area around the transmitter can be considered a priori safe).

[0083] Additionally, the satellite QKD transmission system 2 is able to introduce these benefits with minimal impact on the design of the QKD standalone transmission system, specifically:

[0084] There is no impact on the receiver of the QKD transmission system;

[0085] No impact on channel infrastructure;

[0086] There is no impact on the end-to-end QKD protocol;

[0087] Modifications to the transmitter hardware design are minor.

[0088] In detail, by relaxing the constraints of the single-photon based coded key exchange for a certain portion of the link (i.e., the trusted distance D from the transmitter), the achievable communication distance and the achievable key rate can be increased. However, it is worth noting that the trusted region 23 is not protected by single-photon pulses, thus opening the trusted region 23 to photon splitting attacks, which is a powerful vulnerability in the QKD protocol.

[0089] In the following, two features of the satellite QKD transmission system 2 will be described in detail, namely, how the limitation of the trusted area 23 implies an increase in the achievable communication distance and key rate, and how to deal with the above vulnerabilities.

[0090] The trusted region 23 is used to transmit multi-photon pulses that transmit higher energy per pulse, thereby increasing the probability that one or more photons survive during their propagation. The satellite QKD transmission system 2 utilizes a multiphoton bucket of a calculated size to allow the condition of a single photon to be statistically achieved at a trusted distance D. In this way, single-photon transmission is achieved outside the trusted region 23 (or safe region), and therefore secure communications are achieved.

[0091] The secure zone concept can be advantageously used for space-to-Earth, space and terrestrial communications, either through guided means (eg, optical fiber) or free space.

[0092] The secure area (ie, trusted area 23) is actively monitored to detect possible eavesdroppers (eg, unauthorized users).

[0093] In use, the TX of the satellite QKD transmission system 2 determines the transmission power P based on the trusted distance D (which defines the size of the trusted area 23). Tx, so that it is statistically guaranteed that the single photon pulse propagates from the boundary of the trusted region 23. That is, in mathematical terms: the trusted distance D will be the value of Number_photons(D)=1, where Number_photons(·) is a decreasing function of the distance of the photon from TX (i.e., Number_photons(·) decreases as the distance of the photon from TX increases). The photon reduction is modeled using a channel model, where the more accurate the channel model, the better the assessment of the trusted distance D. It is worth noting that for satellite applications, the main parameter to be considered is the atmospheric loss.

[0094] Figure 6 The high-level architecture of the QKD transmission system 3 according to the preferred embodiment of the present application is schematically shown. Figure 6 As shown in FIG. 1 , the QKD transmission system 3 includes a transmitter (TX) 31 and a receiver (RX) 32 , wherein a trusted area 33 extends from TX 31 to RX 32 until a trusted distance D from TX 31 .

[0095] In use, TX 31 emits a high-energy multi-photon pulse, which travels through the trusted region 33 via the multi-photon link 34, while the number of photons decreases as the distance from TX 31 increases until, at the boundary of the trusted region 33, the high-energy multi-photon pulse has become a single-photon pulse, which travels via the single-photon link 35 and reaches the receiver 32.

[0096] The high energy multi-photon pulse emitted by TX 31 is repeated as many times as needed to obtain the entire quantum key exchange, thereby achieving the compatibility and advantages of the QKD protocol, but with a higher data rate and better quantum bit error rate (QBER).

[0097] It is worth noting that users with rights to a class of service (CoS) for encryption, together with their priority and the amount of keys required, can use the CoS, priority and the amount of keys required as information to define the size of the trusted zone, and thus the trusted distance D of the trusted zone. For example, if the CoS requires a small number of key bits for encryption, then extending the trusted zone 33 and therefore the key rate may not be relevant, whereby the QKD transmission system 3 may choose to reduce the size of the trusted zone 33, and thus reduce the trusted distance D from the transmitter 31.

[0098] Figure 7 Schematically shows the operating logic of the QKD transmission system 3 (indicated as a whole by 4) according to the preferred embodiment of the present application, which is used to determine the size of the trustworthy area 33 and the transmission power P for transmitting the multi-photon pulse Tx , wherein determining the size of the credible area 33 is to determine the credible distance D.

[0099] In particular, Figure 7 The operation logic 4 of the QKD transmission system 3 shown in FIG. 4 includes:

[0100] 1) Determine the size of the trusted zone 33 (i.e., trusted distance D) based on cryptographic service priorities and performance requirements (i.e., service, security, and key rates required by the user) and optionally based on CoS (block 41);

[0101] 2) based on continuous monitoring of the area around TX 31 (e.g., the area around the satellite) by sensors (e.g., LIDAR, radar, etc.) (block 43) or based on earth monitoring, assessing the risk extending from the area around TX 31 (e.g., the area around the satellite) to the receiver 32 up to a determined trusted distance D from TX 31 (block 42); in addition, optionally, information related to the encryption service itself, such as the rate at which a particular service is increased and the importance of its relative criticality, can be conveniently considered in the risk assessment (block 42);

[0102] 3) Check the safety of the area around TX 31 (block 44); if the area is safe, define a trusted area 33 of a trusted distance D; otherwise, re-evaluate the trusted distance D by performing step 1) again, for example, by taking into account the reduced trusted distance; in this way, the trusted distance D may be periodically and dynamically re-evaluated;

[0103] 4) determining a transmission power (block 45) for transmitting N photons (N being a positive integer greater than 1) such that the propagation of the N photons over a credible distance D statistically results in a high probability that the number of photons is equal to 1, i.e., above a predetermined threshold; in mathematical terms,

[0104] P{Nphotons(N,D,P Tx ,Channel_Model)=1}>Threshold,

[0105] Where N represents the transmitted and transmitted power P Tx The number of related photons, Channel_Model represents the predetermined model assumed for the transmission channel and the model channel loss during photon propagation, and Nphotons represents the channel loss based on the number of transmitted photons N, the credible distance D, and the transmission power P Txand the channel model Channel_Model provides a function of the number of photons present at a distance D (i.e., a trusted distance) from the transmitter 31, P represents a probability function, in particular a function of Nphotons=1, and Threshold represents a numerical value (between 0 and 1) that is defined as an input (e.g., by system design) and represents how conservative the system is and how tolerant of security vulnerabilities; specifically, this parameter characterizes the tolerable probability of an error in achieving single-photon transmission at the exit of a particular region (if Threshold is low, such as 0.3, the system can achieve high communication performance at the expense of a possible acceptable transmission power, so that the probability of multi-photon occurrence can be as high as 70% (0.7=1.0-0.3), which may lead to security issues); for the channel model, it is worth noting that the more accurate the channel model, the more effective the QKD transmission system 3 is in determining the trusted distance D; for example, in the case of a simple channel model, an arbitrarily conservative trusted region 33 can be assumed, resulting in a reduced efficiency in determining the trusted distance D, reducing the benefits of the solution itself; and

[0106] 5) The transmission power P determined by the transmitter 31 Tx A pulse carrying N photons is emitted for a time T (e.g., expressed in seconds) (box 46); conveniently, if a potential threat to the security of the trusted area 33 (or, more generally, a potential threat to the emission) is detected based on continuous monitoring of the area around the emitter 31 (box 43), the emission is stopped, and conveniently, the process is started again from step 1) (box 41) based on a different size of the trusted area 33 (i.e., a different trusted distance D).

[0107] In this way, a two-way classical communication can be established between two users and a protocol can be implemented by both users in order to agree on a key.

[0108] It is noteworthy that the above operation logic 4 of the QKD transmission system 3 ensures the security of the trusted area 33 where there can be secure photon propagation from the transmitter 31. The concept of security is intended from the communication point of view, thereby ensuring that it is impossible to sniff the emitted photons.

[0109] In particular, security inside the trusted area 33 is ensured by monitoring the area and by ensuring that there are no eavesdroppers. Monitoring of sensitive areas, such as ensuring the trusted area 33, can be performed continuously by detecting the following aspects:

[0110] Entities present in the area and

[0111] Emissions in the radio frequency (RF) or light spectrum.

[0112] It is important to note the fact that Figure 5The satellite QKD transmission system 2 shown in and previously described is configured / designed to implement the above operating logic 4.

[0113] With specific reference to satellite applications, both detection approaches have been available using ground-based facilities (e.g., Kratos Sensor Network), and with the commercial push for SSA, SDA, and security, research has been conducted to expand the concept of space resource monitoring while also utilizing space-based sensors.

[0114] It is worth noting that, in addition to satellite / space-to-Earth communications, the present application is applicable to any user-advantaged utilization of the pulse-based DV QKD protocol. More generally, the present application is applicable to any user pair implementing QKD connected via an absorbing medium.

[0115] Figure 8 An example of a functional architecture of a transmitter 31 for implementing the operating logic 4 is schematically shown. Figure 8 As shown in , the transmitter 31 includes:

[0116] A first module 311 for evaluating the trusted region 33 (blocks 41 , 42 , 44 of the operating logic 4 );

[0117] a second module 312 for determining the transmit power (block 45 of operational logic 4); and

[0118] A third module 313 for transmitting multi-photon pulses via a controllable optical attenuator 314 operated by the transmit power determination module 312 by means of a control signal (block 46 of the operational logic 4).

[0119] Fig. 9 An example of a fiber-based experimental setup for implementing QKD according to the teachings of the present application is schematically shown.

[0120] like Fig. 9 As shown in , a first user using a transmitter 51 in the QKD part (generally referred to as Alice) needs to share a key with a second user using a receiver 52 in the QKD part (generally referred to as Bob), where the transmitter 51 and the receiver 52 are linked by a fiber-based quantum channel 53 for QKD. The transmitter 51 includes a laser source 511 that injects a laser beam into the fiber-based quantum channel 53 via an optical attenuator 512. The laser beam propagates through the fiber-based quantum channel 53 (e.g., an optical fiber). As is known, optical fibers are characterized by typical losses, such as a loss of about 0.2 dB per kilometer, whereby after one hundred kilometers, a total loss of 20 dB is measured, thereby reducing the input power by a factor of one hundred.

[0121] The receiver 52 comprises a symmetrical beam splitter 521 which splits the received laser beam for base selection.

[0122] It is worth noting that photons are low-intensity light pulses, so fiber losses limit the maximum QKD distance on the ground to about 400 km, which is insufficient to cover the needs of a national QKD infrastructure for direct communications.

[0123] Considering the above, Fig. 9 The QKD transmission system shown in can achieve a loss reduction proportional to αD, where α [dB / Km] is the attenuation coefficient of the optical fiber, and D is the trusted distance. For example, considering the decoy state BB84 protocol, where α = 0.2 dB / Km and D = 20 km, the QKD transmission system can reduce the loss by 5 dB (relative to two users 150 km apart), thus achieving about 200% (up to 3×10 5 bit / s).

[0124] In particular, the speed achievable in the key rate (SKR) may be better than in the satellite scenario, but it is difficult to define a trusted area; in fact, even if it is a well-defined part of the ground (i.e., the surface), the trusted area strongly depends on the level of assumptions made about the security of the area and the possible presence of eavesdroppers. For example, the trusted area may be:

[0125] the perimeter of the building housing the light source;

[0126] regional boundaries; or

[0127] National borders.

[0128] Based on these assumptions, the expansion of the trusted region may lead to a large range of possible values ​​and it is difficult to quantify the actual performance improvement. Fig.10 Examples of trusted areas of different sizes (at company, city, region, and country level) are shown, where different trusted distances D may be defined based on the area that is considered trusted.

[0129] In view of the above, it is noteworthy that the present application involving an adaptive QKD solution based on the trusted region concept is able to achieve high-performance key rate transmission by relaxing the security conservativeness of the QKD protocol.

[0130] In fact, the application teaches:

[0131] 1) Use a power-adaptive QKD transmitter that employs the concept of a trusted region (i.e., a region that is considered safe), either by assumption or by other control means (e.g., sensor monitoring);

[0132] 2) Calculate the transmission power from the transmitter to the receiver using the QKD protocol, where the calculation includes determining the power that needs to be transmitted so that single-photon communication is obtained only when propagating out of the trusted region; and

[0133] 3) Based on the risk assessment of the trusted region and the policy of the service to be encrypted, perform dynamic adaptation of the size of the trusted region.

[0134] In summary, it is obvious that various modifications and variations can be made to this application, and all these modifications and variations fall within the scope of this application as defined in the appended claims.

Claims

1. A quantum key distribution (QKD) transmission system (2, 3), comprising a transmitter (31) and a receiver (32), wherein: The transmitter (31) is configured to transmit a multi-photon pulse to the receiver (32) through a trusted area (23, 33), wherein the trusted area (23, 33) extends from the transmitter (31) to the receiver (32) until it is a trusted distance (D) from the transmitter (31); wherein the transmitter (31) is configured to transmit the multi-photon pulse at a transmission power such that a single-photon pulse propagates from the trusted area (23, 33) until it reaches the receiver (32).

2. The quantum key distribution transmission system according to claim 1, wherein: The transmitter (31) is configured as follows: a) determining the trust distance (D) to define the size of the trust area; b) evaluating the security of the trusted area (23, 33); c) If the trusted area (23, 33) is safe, then: i. determining a transmission power such that, by transmitting a multi-photon pulse having said transmission power, a single-photon pulse propagates out from said trusted region (23, 33) until it reaches said receiver (32), and ii. emitting a multi-photon pulse having a determined emission power; d) If the trusted area (23, 33) is not secure, performing steps a), b) and c) or d) by determining a different trusted distance (D).

3. The quantum key distribution transmission system according to claim 2, wherein: determining said trusted distance (D) based on a priority and performance requirements associated with a requested cryptographic service, and optionally also based on a service class of said cryptographic service; Assessing the security of the trusted area (23, 33) based on continuous monitoring of the trusted area (23, 33) or the area around the transmitter (31); Determining the emission power so that the propagation of N emission photons through the trusted area (23, 33) statistically results in the number of photons at the trusted distance (D) being equal to 1, with a probability higher than a predetermined threshold, N being a positive integer higher than 1; The emitted multiphoton pulse carries the N photons.

4. The quantum key distribution transmission system according to claim 3, wherein: The transmit power is determined based on the following mathematical formula: P{Nphotons(N,D,P Tx ,Channel_Model)=1}>Threshold, Where D represents the credible distance, P Tx represents the transmission power, N represents the transmission power P Tx The number of photons emitted, Channel_Model represents a predetermined channel model assumed for the emission channel and the simulated channel loss during photon propagation, and Nphotons represents a channel model based on the number of emitted photons N, the trusted distance D, and the emission power P Tx The predetermined channel model Channel_Model provides a function of the number of photons present at the trusted distance D from the emitter (31), P represents the probability that the function Nphotons is equal to 1, and Threshold represents a predetermined threshold value.

5. The quantum key distribution transmission system according to claim 3 or 4, wherein: Continuous monitoring of the trusted area (23, 33) or the area around the transmitter (31) is performed by one or more sensors and / or earth-based monitoring.

6. The quantum key distribution transmission system according to any one of claims 3 to 5, wherein: The emitter (31) is configured to stop emitting the multi-photon pulses if a potential threat to the security of the trusted area (23, 33) is detected based on the continuous monitoring.

7. The quantum key distribution transmission system according to claim 6, wherein: The transmitter (31) is configured to perform steps a), b) and c) or d) by determining different trust distances (D) if transmission is stopped due to detection of a potential threat.

8. A quantum key distribution transmission system according to any one of the preceding claims, wherein: The quantum key distribution transmission system is integrated into a space or satellite or terrestrial or space / satellite-earth communication system.

9. Transmission system configured as a transmitter (31) of a quantum key distribution transmission system (2, 3) according to any one of the preceding claims.

10. A method for performing quantum key distribution (QKD) transmission from a transmitter (31) to a receiver (32), comprising: A multi-photon pulse is emitted by the transmitter (31) to the receiver (32) through a trusted area (23, 33), wherein the trusted area (23, 33) extends from the transmitter (31) to the receiver (32) until it is a trusted distance (D) from the transmitter (31); wherein the emission includes emitting the multi-photon pulse at an emission power such that a single-photon pulse propagates from the trusted area (23, 33) until it reaches the receiver (32).

11. The method according to claim 10, comprising: a) determining the trust distance (D) to define the size of the trust area; b) evaluating the security of the trusted area (23, 33); c) If the trusted area (23, 33) is safe, then: i. determining a transmission power so that, by emitting a multi-photon pulse having the transmission power by the transmitter (31), a single-photon pulse propagates out of the trusted region (23, 33) until it reaches the receiver (32), and ii. transmitting a multi-photon pulse having a determined transmission power through the transmitter (31); d) If the trusted area (23, 33) is not secure, performing steps a), b) and c) or d) by determining a different trusted distance (D).

12. The method according to claim 11, wherein: determining said trusted distance (D) based on a priority and performance requirements associated with the requested cryptographic service, and optionally also based on a service class of said cryptographic service; Assessing the security of the trusted area (23, 33) based on continuous monitoring of the trusted area (23, 33) or the area around the transmitter (31); Determining the emission power so that the propagation of N emission photons through the trusted area (23, 33) statistically results in the number of photons at the trusted distance (D) being equal to 1, with a probability higher than a predetermined threshold, N being a positive integer higher than 1; The emitted multi-photon pulse carries the N photons.

13. The method according to claim 12, wherein: The transmit power is determined based on the following mathematical formula: P{Nphotons(N,D,P Tx ,Channel_Model)=1}>Threshold, Where D represents the credible distance, P Tx represents the transmission power, N represents the transmission power P Tx The number of photons emitted, Channel_Model represents a predetermined channel model assumed for the emission channel and the simulated channel loss during photon propagation, and Nphotons represents a channel model based on the number of emitted photons N, the trusted distance D, and the emission power P Tx The predetermined channel model Channel_Model provides a function of the number of photons present at the trusted distance D from the emitter (31), P represents the probability that the function Nphotons is equal to 1, and Threshold represents a predetermined threshold value.

14. The method according to claim 12 or 13, wherein: Continuous monitoring of the trusted area (23, 33) or the area around the transmitter (31) is performed by one or more sensors and / or earth-based monitoring.

15. The method according to any one of claims 12 to 14, further comprising: If a potential threat to the security of the trusted area (23, 33) is detected based on the continuous monitoring, the emission of the multi-photon pulses is stopped.

16. The method according to claim 15, further comprising: If the emission of the multiphoton pulses is stopped due to the detection of a potential threat, the steps a), b) and c) or d) are performed by determining a different trustworthy distance (D).

Citation Information

Patent Citations

  • Quantum key distribution system, method and apparatus based on trusted relay

    US10348493B2

  • Fast multi-photon key distribution scheme secured by quantum noise

    US7831050B2

  • Method to mitigate propagation loss in waveguide transmission of quantum states

    US9294191B2