Transmitting device-independent quantum key distribution method and system

By integrating an untrusted quantum entanglement source at the transmitter and adopting an asymmetric layout, the input parameters are transferred to the entangled state itself, solving the device dependency problem, reducing photon loss, improving the practicality and security of quantum key distribution, and realizing long-distance transmission.

CN121864306AActive Publication Date: 2026-04-14BEIJING ACAD OF QUANTUM INFORMATION SCI
View PDF 17 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-18
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing quantum key distribution schemes have high equipment performance requirements, complex structures, are extremely sensitive to photon loss, and have very short transmission distances, making them impractical. The existing 1sDI-QKD scheme has security vulnerabilities, does not significantly improve the transmission distance, and cannot resist coherent attacks.

Method used

By integrating an untrusted quantum entanglement source into the transmitter, the input parameters are transferred from the measurement of the entangled state to the entangled state itself. An asymmetric layout is adopted to reduce photon loss at the transmitter and improve the practicality of the solution.

Benefits of technology

It significantly reduces photon loss at the transmitter, improves the feasibility of the scheme, achieves the same transmission distance as standard QKD, and can effectively resist coherent attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864306A_ABST
    Figure CN121864306A_ABST
Patent Text Reader

Abstract

The invention relates to a quantum key distribution method and system irrelevant to transmitting equipment, and mainly aims to solve the problem of equipment dependence of a light source end in quantum key distribution. According to the invention, the inherent asymmetric property of 1sDI is utilized, an entanglement source which is a third party originally is integrated into a transmitter, an entanglement state which is fixed originally is adjusted to be variable, measurement of an input parameter of a transmitting end is transferred to the entanglement state itself from the entanglement state, photon loss introduced by modulation equipment at the transmitting end is remarkably reduced, and the transmission efficiency is improved. Therefore, the practicability of the scheme is greatly improved. Moreover, the TDI-QKD scheme provided by the invention is simple in structure, has the same transmission distance as the standard QKD, and can effectively resist coherent attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of quantum key distribution technology, and in particular to a transmission device-independent quantum key distribution method and system. Background Technology

[0002] The concept of secret sharing has now far exceeded the scope of private communication and has become the cornerstone of information security in the modern information society. Unlike classical cryptography, which is based on the computational difficulty of large-scale mathematical operations, quantum technology provides a revolutionary means for information security. Within the framework of quantum theory, nonlocal correlation and measurement incompatibility can ensure that legitimate participants can securely share keys, and any interference from eavesdroppers can be detected. This constitutes the core idea of ​​quantum key distribution (QKD).

[0003] However, in practical implementations, the actual prepared quantum state and the applied measurement may deviate from the design values, necessitating precise device calibration. In extreme cases, malicious devices may report false results to interfere with security analysis, thereby concealing the presence of eavesdroppers, which seriously threatens real-world QKD systems. To address this, measurement-device-independent (MDI) methods have been introduced. MDI-QKD cleverly transforms the dependence on the measurement device into a dependence on the quantum source, thus becoming immune to all detector side-channel attacks. However, source-side device dependence, as a complementary issue, has long been neglected. In particular, numerous studies have shown that source-side device dependence is also highly destructive to the security of the entire system.

[0004] To address the issue of device dependency at the source end, a device-independent DI (DDoS) approach can be used. This approach treats the device as a black box, meaning its internal structure is assumed to be untrusted, even if it were provided by a potential adversary. In this approach, only the device's input-output statistics need to be considered; other calibrations are unnecessary. While DI-QKD achieves the highest level of security—due to its minimal prior requirements—its implementation demands sophisticated experimental setups, is extremely sensitive to loss, resulting in limited overall transmission distance and a very low usable key rate. In particular, even in proof-of-principle demonstrations, it is highly sensitive to the insertion loss of the input selection module.

[0005] To improve practicality, researchers consider characterizing only a portion of the characteristics of one side of the device; this is the relaxed DI method, often referred to as one-sided device-independent (1sDI) quantum key distribution (QKD). 1sDI-QKD is widely considered to have significant practical implications because in future quantum networks, the security capabilities of the communicating parties are likely to be unequal. For example, in communication between a user and a bank, the user's device, due to cost constraints, cannot be perfectly characterized and is therefore considered a black box. The bank's device, however, needs to provide a large volume of high-concurrency services, thus allowing for greater resource investment in characterization and improved trustworthiness. It's worth noting that even with DI-QKD, a trusted third-party institution (similar to a certificate authority in current communications) is still required to provide an initial trusted random seed to verify identity and establish subsequent trust chains.

[0006] The concept of 1sDI-QKD was first introduced with the advent of the entropy uncertainty relation, but its implementation remains an open question, attracting widespread attention and in-depth research. The earliest experimental demonstrations of 1sDI-QKD were implemented in continuous variable (CV) systems, but the scheme still places high demands on experimental equipment, limiting its safe distance. On the other hand, while 1sDI-QKD schemes based on discrete variable (DV) systems were also proposed earlier, they did not attract widespread attention or corresponding experimental demonstrations because they only brought minor improvements in the detection efficiency threshold and relied on a post-selection mechanism, making them vulnerable to coherent attacks. Existing receiver-device-independent (RDI) QKD, employing a prepare & measure (P&M) configuration, significantly reduces the receiver detection efficiency threshold, but at the cost of preparing a large number of high-quality quantum states.

[0007] The latest numerical simulation results show that 1sDI-QKD has a secure transmission distance comparable to that of traditional QKD schemes (over 200 kilometers). However, if the implementation of 1sDI-QKD still follows the symmetrical layout of DI-QKD, it will still be unable to avoid photon loss caused by dynamic modulation, thus making it difficult to guarantee a high detection efficiency to obtain a positive secure code rate. Summary of the Invention

[0008] The inventors discovered that existing DI-QKD schemes have extremely high equipment performance requirements, complex structures, are extremely sensitive to photon loss, and have extremely short transmission distances, making them completely impractical. Existing 1s DI-QKD schemes, such as continuous variable 1s DI-QKD, still have unresolved vulnerabilities in security analysis, and their transmission distance has not been significantly improved. 1s DI-QKD schemes using P&M configurations, such as RDI-QKD, are inherently vulnerable to coherent attacks. 1s DI-QKD schemes using traditional symmetric entanglement configurations are also inherently vulnerable to coherent attacks and have poor practicality.

[0009] To address the aforementioned problems in the existing technology, this application provides a transmitter-device-independent quantum key distribution (TDI-QKD) scheme. Utilizing the inherent asymmetric properties of 1sDI, it integrates the entangled source, which was originally a third party, into the transmitter and adjusts the originally fixed entangled state to be variable. This corresponds to shifting the input parameters of the transmitter from the measurement of the entangled state to the entangled state itself, significantly reducing the photon loss introduced by the modulation device at the transmitter, thereby greatly improving the practicality of the scheme.

[0010] According to a first aspect of this application, a transmitter-independent quantum key distribution method is provided, applied at a transmitter, characterized in that it includes:

[0011] For photons allocated by an untrusted quantum entanglement source, an input method is selected from the corresponding first input set and the output result is determined to generate a preset number of first input-output pairs, wherein the untrusted quantum entanglement source is integrated in the transmitting end; Determine the rounds to be used for security analysis; The receiver receives a second input-output pair corresponding to the round used for security analysis via a classic communication channel, wherein the second input-output pair includes the input method selected by the receiver from the second input set and the corresponding determined output result; Security analysis is performed on the first input-output pair and the second input-output pair corresponding to the rounds used for security analysis to determine the probability distribution; Determine the key rate based on the probability distribution; and When the key rate is positive, the information corresponding to photons outside the rounds used for security analysis is used for key generation.

[0012] According to a second aspect of this application, a transmitter-independent quantum key distribution method is provided, applied at a receiving end, characterized in that it includes: Photons are received from an untrusted quantum entangled source via a quantum channel, wherein the untrusted quantum entangled source is integrated into the transmitter. For photons assigned by an untrusted quantum entanglement source, an input method is selected from the corresponding second input set and the output result is determined to generate a preset number of second input-output pairs; The rounds for security analysis are negotiated with the sending end via a classic communication channel; The second input-output pair corresponding to the round used for security analysis is sent to the sending end via the classic communication channel; The key rate calculation result is received from the sending end through the classic communication channel. The key rate calculation result is determined by the sending end through security analysis of the first input-output pair and the second input-output pair corresponding to the round used for security analysis to determine the probability distribution, and is determined according to the probability distribution. The first input-output pair includes the input method selected by the sending end from the first input set and the corresponding determined output result. In response to a positive key rate, information corresponding to photons outside the rounds used for security analysis is used for key generation.

[0013] According to a third aspect of this application, a transmission device-independent quantum key distribution system is provided, characterized in that it comprises: The sending end is used to execute the method described in the first aspect; The receiving end is used to perform the method described in the second aspect; and A quantum entanglement source, which is integrated in the transmitter.

[0014] The transmission device-independent quantum key distribution method and system provided in this application mainly solve the device dependency problem at the light source end in quantum key distribution. It transfers the input parameters at the transmitter from the measurement of the entangled state to the entangled state itself, reducing photon loss introduced by the modulation device at the transmitter, thereby greatly improving the feasibility of the scheme. Furthermore, the TDI-QKD scheme proposed in this application has a simple structure, possesses the same transmission distance as standard QKD, and can effectively resist coherent attacks. Attached Figure Description

[0015] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings, without exceeding the scope of protection claimed by this application.

[0016] Figure 1 This is a schematic diagram of a quantum key distribution system according to one embodiment.

[0017] Figure 2This is a schematic diagram of a transmitter-independent quantum key distribution system according to an embodiment of this application.

[0018] Figure 3 This is a flowchart of a transmitter-independent quantum key distribution method implemented at the transmitter end according to an embodiment of this application.

[0019] Figure 4 This is a flowchart of a transmitter-independent quantum key distribution method implemented at the receiver end according to an embodiment of this application.

[0020] Figure 5 This is a schematic diagram illustrating the principle of an embodiment of this application.

[0021] Figure 6 This is a state tomography result diagram according to an embodiment of this application.

[0022] Figure 7 This is a key rate result diagram according to an embodiment of this application.

[0023] Figure 8 This is a probability distribution result diagram according to an embodiment of this application.

[0024] Figure 9 This is a comparison graph showing the relationship between the original key rate and transmission distance for different detectors according to one embodiment of this application. Detailed Implementation

[0025] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0026] In the 1sDI scenario, in addition to the minimum set of assumptions—namely: 1. Quantum theory is correct and complete; 2. Both communicating parties possess credible local randomness to generate inputs; 3. Input and output information is isolated from adversaries; 4. Authenticated classical channels and credible classical post-processing methods—a fifth assumption is added: the result produced by the device at the trusted end is independent of input selection, which is known as the fair sampling assumption in the Bell test. In this application, the two users are referred to as Alice and Bob, where Alice can represent the sender and Bob can represent the receiver, who is trusted. A convenient solution for constructing Bob's measurement device is to perform quantum measurements on the entangled state based on the aforementioned assumptions 1 and 5. In this application, Bob's two inputs and two results can be considered; therefore, Bob's measurement is represented by {B1, B2}, and the result is represented by {…}. , The following is an explanation of the TDI-QKD protocol. Specifically, it can be required that these two measurements satisfy the anti-commutation relation: {B1, B2} = 0. Correspondingly, the inputs to Alice can be represented by {A1, A2}, and the results by {a1, a2, a3}, without making any assumptions about the measurements or the entities being measured. The third result, a3, represents the case where Alice's device fails to respond—in reality, this typically corresponds to photon loss. The implementation of the TDI-QKD protocol is described below.

[0027] The TDI-QKD protocol execution steps include statistical data accumulation, security analysis, and key generation.

[0028] For the accumulation of statistical data, in one embodiment, such as Figure 1 and Figure 2 As shown, an untrusted quantum entanglement source distributes photons to Alice and Bob via a quantum channel. For each photon, Alice and Bob each randomly select an input from their respective input sets, send it to the device, and receive the output. Each input-output result is recorded as one round, accumulating to a predetermined number. For example, the photon distribution process by the entanglement source takes 10 rounds. 6 In each round, the accumulated statistics of Alice and Bob can be referred to as the first input-output pair and the second input-output pair, respectively, and the accumulated 10 6 One input / output pair.

[0029] For security analysis, after collecting a sufficient amount of data (reaching a preset quantity), the quantum channel ceases operation. Bob and Alice then coordinate which rounds are used for security analysis via a classical channel, announcing the inputs and corresponding outputs for each round through a classical communication channel, for example, by broadcasting their inputs and outputs for each security analysis round. In one embodiment, Alice and Bob negotiate the rounds used for security analysis via a classical communication channel. For example, in the aforementioned 10... 6 In a pair of inputs and outputs, negotiate 10 of them. 3 Each input-output pair is used for security analysis. Alice receives the results of Bob's coordination rounds and performs security analysis based on the input-output pairs corresponding to the negotiated rounds, calculating the probability distribution p(a, b│A, B). For example, Alice can use the negotiated 10 input-output pairs as a basis for security analysis. 3 The first input / output pair and 10 3 Security analysis is performed on the second input / output pair.

[0030] For key generation, Alice calculates the key rate using a numerical algorithm, substituting p(a, b│A, B). Alice can then announce the key rate calculation result to Bob via a classic communication channel. In one specific embodiment, Alice can broadcast the key rate calculation result to Bob. Using broadcasting prevents man-in-the-middle attacks from impersonating Alice and providing Bob with incorrect information.

[0031] When the key rate is positive, Alice and Bob perform error correction and privacy amplification on the key generation result, using information from photons other than those used for security analysis in key generation. For example, 10 6 10 of the input / output pairs 3 If 10 input / output pairs are used for security analysis, then... 6 -10 3 Each input-output pair can be used to generate a key. If the key rate is not positive, Alice and Bob will abort the protocol and delete the previously accumulated statistics.

[0032] In one embodiment, without loss of generality, A1 and B1 are taken as the key generation combination for calculating the key rate. Since the TDI-QKD protocol (belonging to the 1sDI-QKD protocol) satisfies the signaling-free condition, the key rate can be asymptotically evaluated using the Devetak-Winter bound in a one-way classic post-processing from Alice to Bob: r ∞ ≥ H(b│E,B1) H(b│a, A1, B1) Here, H(b│E,B1) represents the conditional von Neumann entropy required for the intermediary Eve to infer Bob's result based on the side information she possesses and Bob's measurement choice B1. H(b│a, A1, B1) represents the conditional von Neumann entropy required for Alice to infer b, given that she has the relevant information: Bob's measurement choice B1, Alice's own choice A1, and its corresponding result a. These two quantities essentially reflect the extent to which Eve and Alice can reproduce Bob's measurement result. The value of H(b│a, A1, B1) can be directly inferred from the input-output data obtained from the measurements of A1 and B1.

[0033] Accurate estimation of H(b│E,B1) involves considering all possible side channels of Eve. It is known from the literature that considering complete input-output statistics, rather than specific combinations (such as Bell's inequality), can yield higher confidentiality. Recent advances show that a stricter lower bound on the DI protocol rate can be derived by formulating the conditional von Neumann entropy of the discrete quantum system as a series of optimization problems. In particular, the minimum detection efficiency threshold allowed by quantum incompatibility theory has been achieved using newly developed numerical techniques. Furthermore, these numerical methods do not involve any post-selection, thus making the protocol compatible with the Entropy Accumulation Theorem (EAT), which allows for relatively simple security proofs, preventing coherent attacks and the effects of finite-round cases.

[0034] In common entanglement-based QKD, the assigned quantum entangled states are fixed, and the two users, the sender and receiver, choose their own inputs and obtain the results. For example, ... Figure 1 The conventional layout shown, quantum entangled state Alice and Bob choose sets , The measurement methods in the middle, among which and It is a Pauli operator. The result is represented by "1" or "2" depending on the detector click; "3" in Alice indicates a lost result. It's important to note that the specific internal mechanisms of Alice's device are not assumed. If Alice and Bob share entangled states, they will obtain perfect correlation, meaning the results will be consistent, when they choose the same measurement.

[0035] Where X is The eigenstate of Y is The eigenstates.

[0036] Actively switching Alice's measurement basis vectors is typically achieved through phase modulation. However, in practice, phase modulators usually introduce about 50% photon loss, and this 50% loss alone is enough to cause the protocol to abort, not to mention the insertion loss of other optical elements.

[0037] This application considers an asymmetric layout, namely the TDI layout, such as... Figure 2 As shown. In this layout, this application keeps the measurement method of the transmitter (Alice) unchanged, thereby bypassing the insertion loss caused by the random measurement selection module. However, if it is desired to reproduce the above correlation results while keeping Alice's measurement method unchanged, for example, it could be... This is equivalent to modifying the entangled state of the input as follows:

[0038] The above transformation illustrates the key concept of TDI-QKD in this application, namely, Alice from { , The set selects quantum entangled states as input, rather than the measurement method, where , in It is the visibility of entanglement.

[0039] In the TDI layout of this application, an untrusted entanglement source is embedded or integrated into the transmitting end (Alice) device, and then the input set changes from two different measurements to two different entangled states. This transformation does not affect the security proof of 1sDI at all, because the security theory abstracts Alice's device as a black box from the beginning and makes no assumptions about its internal operating mechanism.

[0040] It is worth noting that although the TDI protocol uses different states as inputs, it is fundamentally different from the Prepare for Measurement (P&M) protocol, which is device-dependent and requires defense against attacks on the source end. Furthermore, the TDI scheme of this application is not limited to a specific input configuration; as mentioned above, Alice's input set { , } and Bob's input set { , } can be replaced by any pair of sets after undergoing the same unitary transformation.

[0041] In the above embodiments, the number of corresponding input sets for the sending end and the receiving end is two. Those skilled in the art will understand that the number of input sets can also be more than two, and this application does not impose any restrictions on this.

[0042] In the scheme of this application, the quantum entanglement source is integrated into the transmitter. The input is changed from the original measurement method to the quantum output state. The transmitter can choose between two different quantum entanglement states, which can avoid losses, increase the practicality of the whole scheme, and achieve long transmission distance.

[0043] Based on the above embodiments, according to one aspect of this application, a transmission device-independent quantum key distribution method is provided. Figure 3 This is a flowchart of a transmitter-independent quantum key distribution method implemented at the transmitter according to an embodiment of this application. Figure 3 As shown, the method includes the following steps.

[0044] Step S301: For the photons allocated by the untrusted quantum entanglement source, select the input method from the corresponding first input set and determine the output result to generate a preset number of first input-output pairs, wherein the untrusted quantum entanglement source is integrated in the transmitting end; Step S302: Determine the rounds to be used for security analysis; Step S303: Receive a second input-output pair corresponding to the round used for security analysis from the receiving end via a classic communication channel. The second input-output pair includes the input method selected by the receiving end from the second input set and the corresponding determined output result. Step S304: Perform security analysis on the first input-output pair and the second input-output pair corresponding to the round used for security analysis, and determine the probability distribution; Step S305: Determine the key rate based on the probability distribution; and Step S306: If the key rate is positive, use the information corresponding to the photons outside the rounds used for security analysis for key generation.

[0045] In one embodiment, such as Figure 1 and Figure 2 As shown, an untrusted quantum entanglement source distributes photons to the transmitter Alice and the receiver Bob via a quantum channel. For each photon, Alice and Bob each randomly select an input from their respective input sets, send it to the device, and receive the output. Each input-output result is recorded as one round, and a preset number of rounds are accumulated.

[0046] After collecting a sufficient amount of data (reaching a preset quantity), the quantum channel ceases operation. Bob and Alice then coordinate which rounds will be used for security analysis via a classical channel, announcing the inputs and corresponding outputs for each round through a classical communication channel, for example, by broadcasting. In one embodiment, Alice and Bob negotiate the rounds used for security analysis via a classical communication channel. Alice receives the results of Bob's coordination rounds and performs security analysis based on the input-output pairs corresponding to the negotiated rounds, calculating the probability distribution p(a, b│A, B).

[0047] For key generation, Alice calculates the key rate using a numerical algorithm, substituting p(a, b│A, B). Alice can then announce the key rate calculation result to Bob via a classic communication channel. In one specific embodiment, Alice can broadcast the key rate calculation result to Bob. Using broadcasting prevents man-in-the-middle attacks from impersonating Alice and providing Bob with incorrect information.

[0048] When the key rate is positive, Alice and Bob will perform error correction and privacy amplification on the key generation results, using information from photons other than those used for security analysis in key generation. When the key rate is not positive, Alice and Bob will abort the protocol and delete previously accumulated statistics.

[0049] Accordingly, Figure 4 This is a flowchart of a transmitter-independent quantum key distribution method implemented at a receiver according to an embodiment of this application. Figure 4 As shown, the method includes the following steps: Step S401: Receive photons from an untrusted quantum entanglement source via a quantum channel, wherein the untrusted quantum entanglement source is integrated into the transmitter. Step S402: For the photons allocated by the untrusted quantum entanglement source, select the input method from the corresponding second input set and determine the output result to generate a preset number of second input-output pairs; Step S403: Negotiate the rounds for security analysis with the sending end through the classic communication channel; Step S404: The second input-output pair corresponding to the round used for security analysis is sent to the sending end through the classic communication channel; Step S405: Receive the key rate calculation result from the sending end through the classic communication channel. The key rate calculation result is determined by the sending end through security analysis of the first input-output pair and the second input-output pair corresponding to the round used for security analysis, and based on the probability distribution. The first input-output pair includes the input method selected by the sending end from the first input set and the corresponding determined output result. Step S406: In response to the key rate being positive, the information corresponding to the photons outside the rounds used for security analysis is used for key generation.

[0050] To verify the scheme of this application, a proof-of-principle experiment is demonstrated here. For example... Figure 5As shown, the transmitter (Alice) is not characterized. Within the transmitter, a continuous-wave (CW) pump laser with a center wavelength of 775 nm and a linewidth of 2.5 kHz is guided into the optical path. After modulation by an active half-wave plate (a-HWP) and an active quarter-wave plate (a-QWP), it is reflected by a dichroic mirror (DM) and sent to the Sagnac loop interferometer. The entangled state is generated through a spontaneous parametric down-conversion process, i.e., the pump light incident on a periodically polarized lithium niobate (PPLN) crystal. A fixed 45° HWP in the interferometer is used to rotate the V-polarized pump light. A 400 mm focal length lens combined with an 11 mm focal length collimator maximizes the coupling efficiency between the photons and the single-mode fiber. A fixed 22.5° HWP is coupled to a polarization beam splitter (PBS) for Alice to implement. Measurements. A superconducting nanowire single-photon detector (SNSPD) is deployed here to detect photons with a detection efficiency of 90% and a dark count rate of approximately 50 Hz. For simplicity, the necessary filtering components to isolate the pump light and other background photon noise are omitted from the figure.

[0051] The overall collection efficiency on Alice's side is calibrated to 65%, including the spatial optical path components ( 0.35 dB), fiber optic assembly ( 0.3 dB), space-to-fiber coupling ( 0.66 dB), correlated mode coupling ( 0.06 dB) and detector ( 0.5 dB). The combination of a-HWP and a-QWP in the transmitter modulates the pump light to the desired state, i.e. HWP 22.5° and QWP removal and HWP removal and QWP 45°. A similar configuration is used at the receiver for measurement. and The combination of events at the SNSPD is used. Response events at the SNSPD are recorded by a time stamp, where the null result at the transmitter is extracted by excluding coincidence events from the single-channel detection events at the receiver. This method is also used to estimate the detection efficiency at the transmitter, referred to as the prediction efficiency or Klyshko efficiency, defined as the coincidence count divided by the single count of the opposite arm.

[0052] The feasibility of this protocol largely depends on the performance of the transmitter equipment, so we first simulate the theoretical rate limited by imperfect photon detection and generation in the transmitter (Alice), which is determined by the predicted efficiency. and state visibility Let's characterize them separately. To demonstrate the quality of the generated entangled states, state tomography was performed, and the results are as follows: Figure 6 As shown. and The visibility of the statuses were 99.25% and 99.03%, respectively.

[0053] Since the detector at the receiving end is trustworthy, this means that undetected events can be safely discarded, and Bob's measurement can thus be reformulated as:

[0054] and ,in It refers to The corresponding result is the projection operator of j. In the actual experiment, an attenuator was inserted at Bob to simulate the transmission loss of a 20-kilometer fiber optic cable, which made... =25%. Actual measurement It is defined as the dark count rate divided by the single-channel count rate, approximately 2.6 × 10⁻⁶. -3 .

[0055] On the Alice side, to take into account the lost results, the expression for its measurement can be modified as follows: ,

[0056] Among them, subscript This corresponds to the case where no photons are detected.

[0057] By substituting the calculated probability distribution p(a,b|A,B) into the numerical method, a critical prediction efficiency of 54.8% and a critical state visibility of 79.6% were obtained. The overall results are as follows: Figure 7 As shown, without the TDI layout, the prediction efficiency is affected by the modulator loss and will not meet the critical prediction efficiency requirement, resulting in a negative key rate.

[0058] Based on the density of states matrix of the tomography and the calibrated collection efficiency, the expected value of the full probability distribution of the 24 entries was calculated, such as... Figure 8 As shown, a transparent bar chart is used. In the experiment, 10 [units] were performed on each of the four input combinations. 7 The correlation test of the wheel, the normalized result is as follows Figure 8 As shown, this is represented by a solid bar chart. It is well known that the probability distribution follows probability conservation; furthermore, the no-signal principle imposes additional constraints on the probability. In other words, only 14 of the 24 independent parameters exist, and the inventors noted that adding redundant constraints (represented in gray) to the algorithm might ultimately lead to incorrect results because it cannot find a solution that satisfies all constraints. Clearly, the experimental data matches the theoretical values.

[0059] By substituting the independent probabilities of the 14 experiments into the numerical algorithm, the following can be calculated: Figure 7 The key rate represented by the pentagram corresponds to a key rate of 0.152 bits per unit time. The inventors noted that post-processing techniques can be used to further increase the key rate in actual implementation.

[0060] If Alice and Bob each choose between the two inputs with a 50% probability, the estimated key rate over an equivalent transmission distance of 20 kilometers is approximately 1 kbps. (See...) Figure 9 Assuming It can maintain its position over longer distances, under the current settings. The maximum tolerance is estimated at 7.5%, corresponding to 46 km of fiber optic transmission, while the maximum distance can be increased to over 132 km if a state-of-the-art single-photon detector (i.e., a dark count rate of 1 Hz) is used at the receiver.

[0061] There are two approaches to building a trustworthy detector for the receiver. First, acknowledging that the strongly fair sampling assumption is unrealistic, an approximate fair sampling assumption is adopted. Under this assumption, a destructive measurement device can be modeled as an approximately unbiased filter coupled to an ideal, non-destructive detector. In practice, the approximate fair sampling assumption can be verified by: 1. pre-calibrating the detection efficiency using a trusted quantum source; 2. publishing the data and quantifying the impact of the approximation error. Another approach is to combine semi-quantum game theory and self-testing to circumvent potential detection vulnerabilities in the receiver device. However, this requires complex setups and near-perfect state fidelity. The inventors note that recent advances in improving the detection efficiency of integrated quantum photonics offer a viable solution.

[0062] The 1sDI scenario is closely related to the concept of quantum steering in earlier research phases. Rigorous authentication of quantum steering involves a complete state tomography scan of the state received by the steering party, which is resource-intensive. Alternatively, quantum steering can be proven by violating the steering inequality, which is based on the correlation function of the same input. Unlike the Bell test, the framework of the steering test requires that the untrusted steering party (Alice) can only access the measurement setup after the steered party (Bob) performs the measurement or receives the quantum state to be measured. In practice, this causal requirement ultimately necessitates a symmetric layout, and if a TDI layout is adopted, it introduces an inherent locality vulnerability.

[0063] The proposed TDI-QKD is immune to transmitter-side attacks and is estimated to have a secure transmission distance comparable to standard QKD protocols. The asymmetric layout allows for high modulation rates without sacrificing detection efficiency, which greatly facilitates the integration of transmitter devices. Further research could be extended to various measurement settings and higher-dimensional quantum systems to achieve lower detection efficiency thresholds to accommodate readily available components.

[0064] The transmission device-independent quantum key distribution method and system provided in this application mainly solve the device dependency problem at the light source end in quantum key distribution. It transfers the input parameters at the transmitter from the measurement of the entangled state to the entangled state itself, reducing photon loss introduced by the modulation device at the transmitter, thereby greatly improving the feasibility of the scheme. Furthermore, the TDI-QKD scheme proposed in this application has a simple structure, possesses the same transmission distance as standard QKD, and can effectively resist coherent attacks.

[0065] The embodiments of this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only for the purpose of helping to understand the method and core ideas of this application. Furthermore, any changes or modifications made by those skilled in the art based on the ideas of this application, and on the specific implementation methods and application scope of this application, are all within the scope of protection of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A transmitter-independent quantum key distribution method, applied at the transmitting end, characterized in that, include: For photons allocated by an untrusted quantum entanglement source, an input method is selected from the corresponding first input set and the output result is determined to generate a preset number of first input-output pairs, wherein the untrusted quantum entanglement source is integrated in the transmitting end; Determine the rounds to be used for security analysis; The receiver receives a second input-output pair corresponding to the round used for security analysis via a classic communication channel, wherein the second input-output pair includes the input method selected by the receiver from the second input set and the corresponding determined output result; Security analysis is performed on the first input-output pair and the second input-output pair corresponding to the rounds used for security analysis to determine the probability distribution; Determine the key rate based on the probability distribution; and When the key rate is positive, the information corresponding to photons outside the rounds used for security analysis is used for key generation.

2. The method as described in claim 1, characterized in that, Also includes: If the key rate is not positive, delete the preset number of first input-output pairs.

3. The method as described in claim 1, characterized in that, The first input set includes a variety of different quantum entangled states, and the second input set includes a variety of different measurement methods.

4. The method according to any one of claims 1 to 3, characterized in that, The measurement method used by the transmitting end is fixed, while the receiving end is trusted.

5. The method according to any one of claims 1 to 3, characterized in that, Also includes: The key rate is published through the classic communication channel, which includes a broadcast channel.

6. A transmitter-independent quantum key distribution method, applied at the receiver, characterized in that, include: Photons are received from an untrusted quantum entangled source via a quantum channel, wherein the untrusted quantum entangled source is integrated into the transmitter. For photons assigned by an untrusted quantum entanglement source, an input method is selected from the corresponding second input set and the output result is determined to generate a preset number of second input-output pairs; The rounds for security analysis are negotiated with the sending end via a classic communication channel; The second input-output pair corresponding to the round used for security analysis is sent to the sending end via the classic communication channel; The key rate calculation result is received from the sending end through the classic communication channel. The key rate calculation result is determined by the sending end through security analysis of the first input-output pair and the second input-output pair corresponding to the round used for security analysis to determine the probability distribution, and is determined according to the probability distribution. The first input-output pair includes the input method selected by the sending end from the first input set and the corresponding determined output result. In response to a positive key rate, information corresponding to photons outside the rounds used for security analysis is used for key generation.

7. The method as described in claim 6, characterized in that, Also includes: In response to a non-positive key rate, delete the preset number of second input-output pairs.

8. The method as described in claim 6, characterized in that, The first input set includes a variety of different quantum entangled states, and the second input set includes a variety of different measurement methods.

9. The method according to any one of claims 6 to 8, characterized in that, The receiving end is authorized, and the classic communication channel includes a broadcast channel.

10. A quantum key distribution system independent of the transmission device, characterized in that, include: The sending end is configured to perform the method as described in any one of claims 1 to 5; The receiving end is configured to perform the method as described in any one of claims 6 to 9; as well as A quantum entanglement source, which is integrated in the transmitter.

Citation Information

Patent Citations

  • Two-node measuring equipment unrelated quantum key distribution system

    CN104579643A

  • High-speed quantum key distribution method

    CN107453819A

  • Device-independent high channel capacity quantum communication system and method

    CN108365955A

  • Channel capacity increasing method for quantum safety communication irrelevant to measuring equipment

    CN111092664A

  • Continuous variable measurement equipment independent quantum key distribution method and system

    CN112073189A