Innovative quantum key distribution transmission system
The QKD transmission system addresses the limitations of current QKD systems by using multi-photon pulses within a reliable area to achieve higher key rates and longer distances, balancing security and performance through active monitoring.
Patent Information
- Application Number
- JP2024203208
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-22
- Filing Date
- 2024-11-21
- Publication Date
- 2025-06-03
AI Technical Summary
Current quantum key distribution (QKD) systems face limitations in achievable key rate and communication distance due to high losses and noise in the quantum channel, particularly in fiber-based and satellite-based implementations.
The proposed QKD transmission system introduces a controllable trade-off between security and performance by transmitting multi-photon pulses through a reliable area up to a certain distance, ensuring single-photon pulses reach the receiver, thereby increasing the key transmission rate and communication distance.
This approach enhances the secret key rate in proportion to the reliable distance, allowing for longer communication distances and higher key rates while maintaining security by actively monitoring the reliable area for potential eavesdroppers.
Smart Images

Figure 2025084723000001_ABST
Abstract
Description
Technical Field
[0001] Cross - reference to related applications This patent application claims the priority of Italian Patent Application No. 102023000024831 filed on November 22, 2023, the entire disclosure of which is incorporated herein by reference.
[0002] The present invention generally relates to a quantum key distribution (QKD) transmission system.
Background Art
[0003] Today, quantum key distribution (QKD) systems are one of the most promising solutions for improving security in encrypted communications. QKD systems are applied across many fields, for example in space infrastructure, and are used both as a communication service and for encrypting important data in the fields of navigation and observation (for example, Earth observation).
[0004] Generally, the term quantum key distribution (QKD) refers to a set of protocols aimed at generating a string of secret bits called a key between two parties, generally called Alice and Bob, by exploiting the properties of quantum mechanics. The implementation of QKD protocols is based on the generation of a secret key containing a sequence of bits (i.e., 1 or 0) that are uniformly and randomly distributed, and only Alice and Bob know this sequence. In particular, QKD protocols are · quantum superposition, and · the impossibility of replicating quantum states with 100% fidelity (i.e., the no - cloning theorem) and are based on typical properties such as these.
[0005] Moreover, the properties of the QKD protocol are such that Alice and Bob can detect the presence of a malicious third party / eavesdropper, generally called Eve, whose aim is to infer the secret key without being detected. In practice, the possibility of directly identifying an eavesdropper results from the laws of quantum mechanics, which ensure that any interaction between the quantum system and the environment changes its state. In particular, changes in the properties of the quantum state can be measured and analyzed by Alice and Bob, who can choose to stop the protocol if Eve is listening in on the communication.
[0006] From a theoretical perspective, since the publication of the paper by Bennett and Brassard in 1984, in which they proposed the first QKD protocol, called BB84, many protocols have been conceived by studying different approaches, different operating principles, and different implementation concepts. In this regard, · C. H. Bennett and G. Brassard, International Conference on Computers, Systems & Signal Processing, Bangalore, India, December 9–12 (1984), 175–179, · Grunenfelder, Fadri et al., "Simple and high-speed polarization-based QKD", Applied Physics Letters 112.5 (2018): 051108, · Bennett, Charles H., "Quantum cryptography using any two nonorthogonal states", Physical review letters 68.21 (1992): 2121, and · Bennett, Charles H., Gilles Brassard, and N. David Mermin, "Quantum cryptography without Bell's theorem", Physical review letters 68.5 (1992): 557 can be referred to.
[0007] Furthermore, several QKD protocols have been proven to be theoretically secure. Research activities have not been limited to conceiving theoretically secure QKD protocols, and the experimental conditions under which QKD can be performed have been analyzed taking into account non-ideal features of the setup, environmental conditions, and real-life scenarios.
[0008] To classify QKD protocols, usually two main groupings are made, · The first grouping is with respect to the type of encoding used, i.e., whether the information is encoded in the continuous-valued degrees of freedom of the selected quantum system or in the discrete-valued degrees of freedom, giving rise to continuous-variable (CV) protocols and discrete-variable (DV) protocols respectively. Today, DV protocols are more advanced than CV protocols from both a theoretical and an experimental point of view. In particular, DV protocols are the first type of protocol to be experimentally proven, and many well-known QKD systems are based on said DV protocols. · The second grouping can be carried out according to the basic operating principle, i.e., whether the protocol is based on the prepare-and-measure (PM) - PM - technique (PM protocol) or on the entanglement-based (EB) - EB - technique (EB protocol).
[0009] The PM protocol or "trusted" protocol implies that one of the parties, for example Alice, generates a string of classical random bits, encodes each bit in the state of a quantum system, and sends it to a second party, for example Bob, who then measures the encoded bits to extract the information encoded by Alice.
[0010] In this context, FIG. 1 schematically shows an example of an implementation form of the PM protocol. In this context, attention is paid to the fact that FIG. 1 is immediately understandable to experts in the field of QKD, and therefore it is considered unnecessary to explain FIG. 1 in detail.
[0011] The EB protocol or "untrusted protocol" can be described as a system of entangled particles where the parts cannot be described independently of each other, based on the entanglement property of quantum mechanics. Generally, protocols based on the entanglement property do not require a preparation step, and it is possible to assume that the source of the quantum state is in the hands of an eavesdropper without loss in communication security. In this regard, FIG. 2 schematically shows an example of an implementation form of the BBM92 protocol. In this context, attention is paid to the fact that FIG. 2 can be readily understood by experts in the field of QKD, and thus it is considered unnecessary to explain FIG. 2 in detail.
[0012] Regardless of the type of protocol implemented, the general realization of QKD is accomplished by encoding information in the degrees of freedom of single photons (as is known, a photon is the minimum amount of energy of an electromagnetic field), and photons are selected as the quantum encoding system because they are suitable for communication purposes. In particular, in the CV protocol, the quadrature phase of the electric field is regarded as the degree of freedom for encoding, while in the DV protocol, the degrees of freedom for encoding used for QKD are the polarization of the photon, the arrival time of the photon at the detector, or the phase difference between two consecutive photons.
[0013] As is known, an indispensable characteristic in the implementation of a QKD system is that each bit of the secret key must be encoded by only one photon. In reality, when the same bit is encoded by two or more photons, an eavesdropper can steal one of the photons encoding the same bit and extract the encoded information within the stolen photon without Alice and Bob noticing the presence of the eavesdropper. To address the possibility of two or more photons encoding the same bit of the secret key, several countermeasures have been conceived, but the single-photon requirement must be met. Thus, this single-photon requirement has become one of the main bottlenecks in the implementation of QKD protocols. It is worth noting that photons scatter and suffer high losses during propagation, especially in fiber links where fiber propagation undergoes exponential decay due to absorption.
[0014] In particular, the no-cloning theorem prevents quantum states from being cloned or amplified during the propagation of photons (e.g., to increase the propagation distance), so loss is detrimental to the QKD protocol and poses a limitation in implementing the QKD protocol within a fiber-based infrastructure. In reality, at most a few hundred kilometers can be covered using fiber-based technology (in which case it can be done using dedicated ultra-low-loss fibers), but today it is extremely important to achieve long distances and wide coverage.
[0015] Experimental realizations of free-space and satellite QKD were accomplished by a Chinese research group in 2017, achieving high distance reach and wide coverage. However, in the best scenario, despite the relative increase in the number of photons that can be favorably exchanged with respect to fiber-based implementations, their absolute values are still limited by losses of approximately 30 - 40 dB in a typical low-earth orbit (LEO) satellite. Moreover, the achievable key rate and key volume in a typical QKD session are limited to tens of kilobits per second.
[0016] Subsequently, the very high compliance of security in communication and the increasing requirements for encryption keys in some applications require a smart solution that can increase the known achievable key rate. In fact, one of the main limitations of QKD systems is the achievable key rate, especially in networks characterized by particularly long user distances, which is always extremely low and often does not match the key rate required by users. Currently, the limitations related to the achievable key rate inherent in QKD protocols are usually accepted a priori, restricting the applicability of QKD solutions in terms of achievable performance and distance.
[0017] The implementation of the PM protocol is generally based on pulse techniques, where a pulsed laser is attenuated to the single - photon level by a high - performance attenuator. Specifically, the number of photons in each pulse follows a Poisson distribution, which is not constant due to the statistical properties of light. In particular, after the laser pulse is attenuated, each photon is polarized independently of each other to encode each bit of the secret key in each pulse at the single - photon level. Due to the Poisson distribution of the number of photons, each attenuated laser pulse does not necessarily and accurately generate exactly one photon. Generally, the attenuation is such that photons are not included in each pulse for the largest part of the pulse, but this does not prevent having more than two photons per pulse sometimes, thus causing a risk to the security in QKD. A common method to overcome this limitation is represented by the decoy - state method, which, in contrast to the standard BB84 protocol, uses pulses containing more than two photons per pulse, and the presence of eavesdroppers is inferred by monitoring the statistics of the incoming pulses. However, although the decoy - state method represents a countermeasure against photon - number - splitting attacks, the decoy - state method cannot be implemented simply by increasing the number of photons transmitted per pulse. In fact, the general average number of photons per pulse is lower than 1, and for this reason, it cannot increase the communication distance. Thus, the main limitation characterizing QKD implementation forms is the impossibility of associating with multi - photon states.
[0018] Today, general commercial systems are evolving to overcome the above limitations, but their application to real-life scenarios is limited by propagation loss.
[0019] In recent years, several patents have been granted for inventions facing the above problems. For example, reference can be made to U.S. Patent No. 9,294,191, U.S. Patent No. 7,831,050, and U.S. Patent No. 10,348,493.
[0020] From a theoretical perspective, QKD has been proven to be information-theoretically secure. Therefore, QKD guarantees that an eavesdropper cannot obtain any information related to the secret key, except with a negligible probability.
[0021] Generally, quantum mechanics predicts the impossibility of observing a quantum mechanical system without changing its state. Therefore, if an eavesdropper tampers with the quantum channel, the protocol will recognize the attack and interrupt the key calculation.
[0022] As is known, the main limitation of QKD protocols relates to losses and noise in the quantum communication channel. In the theoretical analysis of QKD systems, a potential eavesdropper is considered to be able to fully control the quantum channel, and the eavesdropper can use unlimited classical and quantum resources to intrude on the secret communication between Alice and Bob. From an experimental perspective, this means that all losses must be due to the presence of the eavesdropper, because it is impossible to distinguish between natural noise and the activities of the eavesdropper.
[0023] In this context, Figure 3 shows the trade-off between the secret key rate (SKR) and channel loss for optical QKD applying different protocols. · The SKR is expressed as bits per mode (i.e., per QKD protocol). · The channel loss is due to noise and is expressed in dB.
[0024] As shown in FIG. 3, in all QKD protocols represented, the distribution of the secret key is good only when the noise level, and thus the channel loss, is sufficiently low, and the relationship between the SKR and the noise results in an exponential SKR-versus-distance trade-off.
[0025] Generally, QKD is based on pulses containing single photons, and QKD essentially carries a small amount of energy that has a high probability of losing these pulses during transmission, whereby QKD is extremely difficult to implement in high-noise channels as satellite-to-ground communication and long fiber-based communication.
[0026] In practice, even assuming ideal sources and detectors, the loss is related to the distance between Alice and Bob, and thus, after a certain distance, the secret key rate drops to zero, so that QKD cannot be used. Currently, the SKR-versus-distance trade-off is the main limiting factor for long-distance direct communication in QKD both on the ground and in satellites.
[0027] The upper limit of the secret key rate (SKR) has been shown to be a function of the channel loss, particularly the maximum allowable channel noise, regardless of how much optical power the protocol can use.
[0028] Today, quantum repeaters and / or trusted node architectures are the main technical solutions to overcome the above limitations, but these solutions are not technically ready and / or require strong assumptions about the network type theory.
[0029] Considering the above, there is a strong need today for an efficient QKD solution to overcome the limitations in direct communication, particularly those related to the SKR-versus-distance trade-off.
Prior Art Documents
Patent Documents
[0030]
Patent Document 1
[0031] [Non-Patent Document 1] C. H. Bennett and G. Brassard, International Conference on Computers, Systems & Signal Processing, Bangalore, India, December 9 - 12 (1984), pp. 175 - 17 [Non-Patent Document 2] Grunenfelder, Fadri et al., "Simple and high-speed polarization-based QKD", Applied Physics Letters 112.5 (2018): 051108 [Non-Patent Document 3] Bennett, Charles H., "Quantum cryptography using any two nonorthogonal states", Physical review letters 68.21 (1992): 2121 [Non-Patent Document 4] Bennett, Charles H., Gilles Brassard, and N. David Mermin, "Quantum cryptography without Bell's theorem", Physical review letters 68.5 (1992): 557 [Summary of the Invention] [Means for Solving the Problems]
[0032] In view of the limitations and drawbacks of known quantum key distribution (QKD) systems, an object of the present invention is to introduce a controllable trade-off between security and performance (achievable communication distance and secret key rate (SKR)) in a QKD transmission system.
[0033] This object and other objects are achieved by the present invention in that the present invention relates to a QKD transmission system, as defined in the appended claims.
[0034] In particular, the QKD transmission system according to the present invention includes a transmitter and a receiver, the transmitter being configured to transmit multi-photon pulses to the receiver through a reliable area extending from the transmitter to the receiver up to a reliable distance from the transmitter, and the transmitter being configured to transmit multi-photon pulses using a transmission power such that a single-photon pulse propagates from the reliable area to reach the receiver.
[0035] For a better understanding of the present invention, preferred embodiments, which are merely intended as non-limiting, non-binding examples, will now be described with reference to the accompanying drawings (not all to scale).
Brief Description of the Drawings
[0036]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
[0037] The following description is presented to enable a person skilled in the art to make and use the invention. Various modifications to the embodiments will be readily apparent to those skilled in the art without departing from the scope of the claimed invention. Therefore, the present invention is not intended to be limited to the embodiments shown and described, but is to be accorded the widest scope of protection consistent with the features defined in the appended claims.
[0038] The present invention relates to a quantum key distribution (QKD) transmission system including a transmitter and a receiver.
[0039] The transmitter is configured to transmit multi-photon pulses to the receiver through a reliable area extending from the transmitter to the receiver up to a reliable distance from the transmitter.
[0040] In particular, the transmitter is configured to transmit multi-photon pulses using a transmission power such that a single-photon pulse propagates from the reliable area and reaches the receiver.
[0041] Preferably, the QKD transmission system according to the present invention ·Either the area guaranteed by a means limited to the spot (e.g., a monitoring system / device / sensor), or the area assumed to be guaranteed / safe, is defined as a predetermined size area that is assumed to be safe based on the assumption that it extends over a reliable distance D (e.g., expressed in km) from the transmitter, and ·Accordingly, calculating the optical power transmitted from the transmitter to the receiver has the ability to control the security / performance trade-off.
[0042] In the following, for the sake of brevity of explanation and without loss of generality, the expression "reliable area" is used as a synonym for the expression "predetermined size area assumed to be guaranteed / safe", and a multi-photon state encoding secret key bits can also be regarded as secure. This is because, by definition, there are no eavesdroppers in the reliable area.
[0043] The QKD transmission system according to the present invention increases the key transmission rate in proportion to the reliable distance D. Thus, a higher D results in higher transmission performance (i.e., a higher secret key rate - SKR), but lower security guarantee, while a lower D results in lower transmission performance (i.e., a lower SKR), but higher security.
[0044] In the following, a satellite QKD transmission system according to a preferred embodiment of the present invention will be described in detail. However, the satellite application of the present invention is not restrictive nor indicative of a boundary. This is because the latter can be advantageously utilized for terrestrial applications with appropriate modifications.
[0045] In the satellite scenario, it is reasonable to assume that it is easy to detect the presence of potential observers within a certain area from the source, and therefore, some of the constraints on the single-photon state can be relaxed.
[0046] In this context, FIG. 4 schematically shows a general architecture of a satellite QKD transmission system of a known type (denoted generally by 1). The satellite QKD transmission system 1 includes a transmitter (TX) installed on the satellite 11 and a receiver (RX) integrated into the ground station 12, and an optical link 13 is established between the TX and the RX based on the transmission of single-photon pulses.
[0047] FIG. 5 schematically shows a high-level architecture of a satellite QKD transmission system 2 according to a preferred embodiment of the present invention. As shown in FIG. 5, the satellite QKD transmission system 2 includes a transmitter (TX) installed on the satellite 21 and a receiver (RX) integrated into the ground station 22, and a reliable area 23 extends from the TX towards the RX up to a reliable distance D (expressed, for example, in km).
[0048] Preferably, as shown in FIG. 5, the reliable area 23 is shaped as a right circular cone having a vertex located at the TX, and the height of the cone coincides with the reliable distance D.
[0049] In use, the TX transmits high-power multi-photon pulses through the reliable area 23 to the RX, thereby increasing the overall probability of the photons reaching the RX. However, the transmission of high-power multi-photon pulses means that for the reliable area 23, the communication cannot be considered to be essentially secure, but the reliable area 23 can be assumed to be secure because no eavesdropper can exist in the vicinity of the TX with respect to the geometry of the satellite QKD transmission system 2, or because active monitoring of the reliable area 23 is carried out.
[0050] The satellite QKD transmission system 2 has the following advantages compared to a satellite QKD transmission system 1 of a known type (more generally, compared to all known satellite QKD systems). · Increasing the achievable communication distance by any amount, · Increasing the achievable key rate in proportion to the increase in the reliable distance D, ·Activation of a controllable trade-off between achievable communication distance and SKR increases by restricting the size of the reliable area 23, ·Security guarantees are restricted only for the areas where they are required, thus enhancing system performance, ·A security balance can be achieved by actively monitoring the areas excluded from QKD security.
[0051] Moreover, the above advantages ·Enable new applications and applicable scenarios - Beyond the full communication distance, and - The achievable key rate does not meet the requirements of the encryption system for QKD transmission systems that were previously impossible to achieve, ·Enhance the performance of existing QKD applicable scenarios, for example, - Dynamically select a reliable area to achieve the best trade-off between SKR and security based on a specific context, - Static utilization of the area around the transmission system (in many contexts, the area around the transmitter can be considered a priori safe) through resulting in
[0052] Furthermore, the satellite QKD transmission system 2 can bring these benefits with minimal impact on the QKD-independent transmission system design, especially ·Not affecting the receiver of the QKD transmission system, ·Not affecting the channel infrastructure, ·Not affecting the end-to-end QKD protocol, ·Requiring few modifications to the transmitter hardware design can be achieved.
[0053] Specifically, by relaxing the constraints of single - photon - based key - exchange for a certain portion of the link (i.e., for the reliable distance D from the transmitter), it is possible to increase the achievable communication distance and the achievable key rate. However, it should be noted that the reliable area 23 becomes insecure as single - photon pulses thus expose the reliable area 23 to photon - splitting attacks, which is a strong vulnerability in the QKD protocol.
[0054] Below, two features of the satellite QKD transmission system 2 are described in detail, namely, how the definition of the reliable area 23 implies an increase in the achievable communication distance and key rate, and how the above - mentioned vulnerability is addressed.
[0055] The reliable area 23 is used to transmit multi - photon pulses that carry higher energy per pulse, thereby increasing the probability that one or more photons survive during their propagation. The satellite QKD transmission system 2 utilizes multi - photon buckets whose size is calculated to enable the statistical achievement of the single - photon condition at the reliable distance D. In this way, single - photon transmission, and thus secure communication, is achieved outside the reliable area 23 (or the secure region).
[0056] The concept of the secure region is advantageously applicable to space - to - earth communication, space communication, and terrestrial communication via guiding means (e.g., fiber) or via free space.
[0057] The secure region (i.e., the reliable area 23) is actively monitored to detect potential eavesdroppers (e.g., unauthorized users).
[0058] During use, the TX of the satellite QKD transmission system 2 sets the transmission power P based on the reliable distance D (which defines the size of the reliable area 23) to ensure in statistical terms that single - photon pulses propagate from the boundary of the reliable area 23.Tx Determine it. That is, in mathematical terms, the guaranteed distance D is the value for which Number_photons(D)=1, where Number_photons(·) is a decreasing function of the distance of photons from the TX (i.e., Number_photons(·) decreases as the distance of photons from the TX increases). The decrease in photons is modeled using a channel model, and the more accurate the channel model, the better the estimation of the reliable distance D. It is worth noting that for satellite applications, the main parameter to consider is atmospheric loss.
[0059] Figure 6 schematically shows a high-level architecture of a QKD transmission system 3 according to a preferred embodiment of the present invention. As shown in Figure 6, the QKD transmission system 3 includes a transmitter (TX) 31 and a receiver (RX) 32, and a reliable area 33 extends from the TX 31 towards the RX 32 up to a reliable distance D from the TX 31.
[0060] In use, while the TX 31 emits high-energy multi-photon pulses that travel through the reliable area 33 via a multi-photon link 34, at the boundary of the reliable area 33, as the distance from the TX 31 increases, the number of photons decreases until the high-energy multi-photon pulse becomes a single-photon pulse that travels via a single-photon link 35 and reaches the receiver 32.
[0061] The emission of high-energy multi-photon pulses by the TX 31 is repeated a number of times necessary to obtain full quantum key exchange, enabling the compatibility and advantages of the QKD protocol, but with a higher data rate and a better quantum bit error rate (QBER).
[0062] It is worth noting that a user having rights to a service class (CoS) for encryption, along with its priority and the amount of keys required, can use the CoS, priority, and the amount of keys required as information for defining the size of a trusted area, and thus the trusted distance D of the trusted area. For example, when the CoS requires a small number of key bits for encryption, it is not appropriate to extend the trusted area 33 and thus the key rate, whereby the QKD transmission system 3 may choose to reduce the size of the said trusted area 33 and thus the trusted distance D from the transmitter 31.
[0063] FIG. 7 schematically shows the logic of the operation of the QKD transmission system 3 according to a preferred embodiment of the present invention for determining the size of the trusted area 33, i.e., the trusted distance D, and the transmission power P used for transmitting multi-photon pulses. Tx shown generally by 4 as a whole.
[0064] In particular, the logic 4 of the operation of the QKD transmission system 3 shown in FIG. 7 includes the following. 1) Determining the size of the trusted area 33, i.e., the trusted distance D, based on the encryption service priority and performance requirements (i.e., the service, security, and key rate required by the user), and optionally based on the CoS (block 41), 2) Estimating the risk of the area around the TX 31 extending up to the trusted distance D determined from the TX 31 towards the receiver 32 based on continuous monitoring of the area by sensors (e.g., LIDAR, radar, etc.) (block 43), or based on earth monitoring (block 42), and furthermore, optionally, information related to the encryption service itself, such as the importance of increasing the rate for a particular service and its associated importance, can preferably be considered in the risk estimation (block 42). 3) Check the safety of the area around TX31 (block 44). If the area is safe, a reliable area 33 within range D is defined. If it is not safe, the reliable distance D is re-evaluated by, for example, considering a reduced reliable distance and re-executing step 1). In this way, the reliable distance D can be re-evaluated periodically and dynamically. 4) Determine the transmission power used to transmit an amount of photons N (where N is a positive integer greater than 1) such that the propagation of N photons over the reliable distance D statistically results in a high probability, i.e., a probability higher than a predetermined threshold, that the number of photons equals 1. In mathematical terms, P{Nphotons(N, D, P Tx , Channel_Model)=1}>Threshold, where N represents the number of photons transmitted in relation to the transmission power P Tx , Channel_Model represents a predetermined model that assumes the losses of the transmission channel and the modeling channel during photon propagation, and Nphotons represents the number of photons N transmitted, the reliable distance D, and the transmission power P Txand a function that provides the number of photons present at the distance D (i.e., the reliable distance) from the transmitter 31 based on the channel model Channel_Model, where P represents a probability function for which the function Nphotons is equal to 1, and Threshold represents a numerical value (between 0 and 1) defined as an input (e.g., by the system design) that indicates how conservative and how tolerant the system is with respect to security leaks. In particular, this parameter characterizes the acceptable probability of an error occurring in achieving single-photon transmission at the exit of a particular area. (When Threshold is low, e.g., 0.3, the system may accept transmitted powers that may result in a high probability, e.g., 70% (0.7 = 1.0 - 0.3), of multiphotons being generated and may pose security problems, in exchange for achieving high communication performance.) Regarding the channel model, it is worth noting that the more accurate the channel model is, the more efficient the QKD transmission system 3 is in determining the reliable distance D. For example, in the case of single-channel modeling, an arbitrarily conservative reliable area 33 may be assumed, leading to a decrease in efficiency in determining the reliable distance D and reducing the benefits of the solution itself. 5) The determined transmission power P Tx transmitting, by the transmitter 31, for a time T (expressed, for example, in seconds) using a pulse that carries N photons (block 46). Preferably, if a potential threat to the security of the reliable area 33 (or, more generally, to the transmission) is detected based on continuous monitoring of the area around the transmitter 31 (block 43), the transmission is stopped. Preferably, the procedure is restarted from step 1) (block 41) based on different sizes of the reliable area 33 (i.e., different reliable distances D).
[0065] In this way, two-way classical communication is established between the two users, and an agreement protocol can be implemented by the two users to agree on the secret key.
[0066] It is worth noting that the above logic 4 of the operation of the QKD transmission system 3 ensures the security of the trustworthy area 33 and enables secure photon propagation from the transmitter 31. The security concept should be intended from the perspective of communication, thereby guaranteeing that snooping on the transmitted photons is impossible.
[0067] In particular, security is guaranteed within the trustworthy area 33 by monitoring the area and by verifying the absence of eavesdroppers. For example, monitoring of the sensitive area such as to ensure the trustworthy area 33 can be · entities existing within that area, and · radiation within the radio frequency (RF) or optical spectrum by detecting, and preferably, can be accomplished.
[0068] It is important to note the fact that the satellite QKD transmission system 2 shown in FIG. 5 and previously described is also configured / designed to implement the above logic 4 of the operation.
[0069] Particularly with regard to satellite applications, these two detection methods can already be achieved using terrestrial facilities (e.g., Kratos sensor network), but research is already underway to develop the concept of space resource monitoring with space-based sensors in conjunction with SSA, SDA, and commercial activities regarding security protection.
[0070] It is worth noting that the present invention can be advantageously utilized by any pair of users employing DV QKD based on pulses implementation in addition to satellite / cosmic - terrestrial communication. More generally, the present invention can be applied to any set of users connected via an absorptive medium that implements QKD.
[0071] FIG. 8 schematically shows an example of the functional architecture of the transmitter 31 for implementing the logic 4 of the operation. As shown in FIG. 8, the transmitter 31 ·A first module 311 (blocks 41, 42, 44 of operation logic 4) for the evaluation of the reliable area 33, and ·A second module 312 (block 45 of operation logic 4) for the determination of the transmission power, and ·A third module 313 for multi - photon pulse transmission (block 46 of operation logic 4) via a controlled optical attenuator 314 operated by the transmission power determination module 312 using a control signal are included.
[0072] Figure 9 schematically shows an example of an experimental fiber - based setup for implementing QKD according to the teachings of the present invention.
[0073] As shown in Figure 9, a first user in the QKD sector, generally called Alice, who uses a transmitter 51, needs to share a secret key with a second user in the QKD sector, generally called Bob, who uses a receiver 52. The transmitter 51 and the receiver 52 are linked by a fiber - based quantum channel 53 used for QKD. The transmitter 51 includes a laser source 511 that injects a laser beam into the fiber - based quantum channel 53 via an optical attenuator 512. The laser beam propagates through the fiber - based quantum channel 53 (e.g., an optical fiber). As is known, an optical fiber is characterized by a typical loss of about 0.2 dB per kilometer, so that after 100 km, a total loss of 20 dB is measured, reducing the input power to 1 / 100.
[0074] The receiver 52 includes a symmetric beam splitter 521 that splits the received laser beam to perform basis selection.
[0075] Photons are low - intensity pulses of light. Thus, it is worth noting that fiber optic losses limit the maximum terrestrial QKD distance to about 400 km, and thus this distance is not sufficient to cover the needs of a national QKD infrastructure for direct communication.
[0076] In view of the above, the QKD transmission system shown in FIG. 9 can achieve loss reduction proportional to αD, where α [dB / Km] is the attenuation coefficient of the optical fiber and D is the reliable distance. For example, considering the decoy state BB84 protocol with α = 0.2 dB / Km and D = 20 Km, the QKD transmission system can reduce the loss by 5 dB (related to two users 150 km apart), and thus achieve an increase in the SKR of about 200% (up to 3×10 5 bit / s).
[0077] In particular, the achievable speedup in the secret key rate (SKR) can be better than that in the satellite scenario, but it is difficult to define the reliable area. In fact, even when it is a clearly defined part on the ground (i.e., the surface), the reliable area strongly depends on the level of speculation set against the security of the territory and the presence of possible eavesdroppers. For example, the reliable area can be · the perimeter of the building housing the light source, · the boundary of the region, or · the national border and so on.
[0078] Based on these assumptions, the expansion of the reliable area can bring a wide range of possible values, and it is difficult to quantify the actual performance improvement. In this regard, FIG. 10 shows an example of reliable areas of different sizes (at the company, city, regional, national levels), and different reliable distances D can be defined based on what is considered reliable.
[0079] In view of the above, it is important to note that the present invention regarding the adaptive QKD solution based on the concept of the reliable area can enable high-performance key rate transmission by relaxing the security conservatism of the QKD protocol.
[0080] In fact, the present invention 1) Employ a power-adaptive QKD transmitter that adopts the concept of a reliable area (i.e., an area regarded as safe) by means of either assumptions or other control means (e.g., sensor monitoring); 2) Execute the calculation of the power transmitted from the transmitter to the receiver using the QKD protocol, where the calculation involves determining the power that needs to be transmitted such that single-photon communication is just obtained at the exit of the propagation from the reliable area; 3) Perform dynamic adaptation of the size of the reliable area based on the risk assessment of the reliable area and the policy of the service to be encrypted. It is taught to perform the above.
[0081] In conclusion, it is obvious that many modified forms and variations can be created for the present invention, and all of them are included within the scope of the present invention defined in the appended claims.
Explanation of Reference Numerals
[0082] 1 Satellite quantum key distribution (QKD) transmission system 2 Satellite QKD transmission system 3 QKD transmission system 4 Logic of operation 11 Satellite 12 Ground station 13 Optical link 21 Satellite 22 Ground station 23 Reliable area 31 Transmitter (TX) 32 Receiver (RX) 33 Reliable area 34 Multi-photon link 35 Single-photon link 51 Transmitter 52 Receiver 53 Fiber-based quantum channel 311 First module 312 Second module 313 Third module 314 Controlled optical attenuator 511 Laser source 512 Optical attenuator 521 Symmetric beam splitter
Claims
1. 1. A quantum key distribution (QKD) transmission system (2, 3) comprising a transmitter (31) and a receiver (32), wherein the transmitter (31) is configured to transmit a multi-photon pulse to the receiver (32) through a trusted area (23, 33) extending from the transmitter (31) towards the receiver (32) a trusted distance (D) from the transmitter (31), and the transmitter (31) is configured to transmit the multi-photon pulse with a transmission power such that a single photon pulse propagates out of the trusted area (23, 33) until it reaches the receiver (32).
2. The transmitter (31) a) determining said trusted distance (D) and thereby defining the size of a trusted area; b) evaluating the security of said trusted area (23, 33); c) if the trusted area (23, 33) is secure, i. determining a transmission power such that a single photon pulse propagates out of the trusted area (23, 33) until it reaches the receiver (32) by transmitting a multiphoton pulse using said transmission power; ii. transmitting a multi-photon pulse using the determined transmit power; d) performing steps a), b) and c) or d) by determining a different trusted distance (D) if the trusted area (23, 33) is not secure; 2. The quantum key distribution transmission system of claim 1, configured to:
3. the trusted distance (D) is determined based on priority and performance requirements for the requested cryptographic service, and optionally also based on a service class of the cryptographic service; the security of the trusted area (23, 33) is assessed based on a continuous monitoring of the trusted area (23, 33) or of the area around the transmitter (31); the transmission power is determined such that the propagation of N transmitted photons through the trusted area (23, 33) statistically results in a number of photons equal to 1 at the trusted distance (D) with a probability higher than a predefined threshold, N being a positive integer greater than 1; 3. The quantum key distribution transmission system of claim 2, wherein the transmitted multi-photon pulse carries N photons.
4. The transmission power is expressed by the following formula: P{Nphotons(N, D, P Tx , Channel_Model)=1}>Threshold、 where D denotes the trusted distance, and P Tx denotes the transmission power, and N denotes the transmission power P Tx where Nphotons is the number of transmitted photons, N is the reliable distance D, and P is the transmission power P. Tx 4. The quantum key distribution transmission system of claim 3, wherein Nphotons denotes a function providing the number of photons present at the trusted distance D from the transmitter (31) based on the predetermined channel model Channel_Model, P denotes the probability that the function Nphotons is equal to 1, and Threshold denotes a predetermined threshold value.
5. 5. The quantum key distribution transmission system according to claim 3 or 4, wherein the continuous monitoring of the trusted area (23, 33) or of the area around the transmitter (31) is performed by one or more sensors and / or based on terrestrial monitoring.
6. 6. The quantum key distribution transmission system according to claim 3, wherein the transmitter (31) is configured to stop transmitting the multi-photon pulses if a potential threat to the security of the trusted area (23, 33) is detected based on the continuous monitoring.
7. 7. The quantum key distribution transmission system of claim 6, wherein the transmitter (31) is configured to perform steps a), b), and c) or d) by determining a different trusted distance (D) if the transmitter (31) stops transmitting due to a detected potential threat.
8. 8. The quantum key distribution transmission system according to claim 1, wherein the quantum key distribution transmission system is integrated into a space or satellite or terrestrial or space / satellite-earth communication system.
9. A transmission system configured as the transmitter (31) of a quantum key distribution transmission system (2, 3) according to any one of claims 1 to 8.
10. 1. A method for quantum key distribution (QKD) transmission from a transmitter (31) to a receiver (32), comprising the step of transmitting a multi-photon pulse by the transmitter (31) to the receiver (32) through a trusted area (23, 33) extending from the transmitter (31) towards the receiver (32) a trusted distance (D) from the transmitter (31), wherein transmitting comprises transmitting the multi-photon pulse with a transmission power such that a single photon pulse propagates out of the trusted area (23, 33) until it reaches the receiver (32).
11. a) determining said trusted distance (D) and thereby defining the size of a trusted area; b) evaluating the security of said trusted area (23, 33); c) if the trusted area (23, 33) is secure, i. determining a transmission power by said transmitter (31) such that a single photon pulse propagates out of said trusted area (23, 33) until it reaches said receiver (32) by transmitting a multiphoton pulse with said transmission power; ii. transmitting, by said transmitter (31), a multi-photon pulse using said determined transmission power; d) performing steps a), b) and c) or d) by determining a different trusted distance (D) if the trusted area (23, 33) is not secure; The method of claim 10, comprising:
12. the trusted distance (D) is determined based on priority and performance requirements for the requested cryptographic service, and optionally also based on a service class of the cryptographic service; the security of the trusted area (23, 33) is assessed based on a continuous monitoring of the trusted area (23, 33) or of the area around the transmitter (31); the transmission power is determined such that the propagation of N transmitted photons through the trusted area (23, 33) statistically results in a number of photons equal to 1 at the trusted distance (D) with a probability higher than a predefined threshold, N being a positive integer greater than 1; The method of claim 11 , wherein the transmitted multi-photon pulse carries N photons.
13. The transmission power is expressed by the following formula: P{Nphotons(N, D, P Tx , Channel_Model)=1}>Threshold、 where D denotes the trusted distance, and P Tx denotes the transmission power, and N denotes the transmission power P Tx where Nphotons is the number of transmitted photons, N is the reliable distance D, and P is the transmission power P. Tx 13. The method of claim 12, wherein Nphotons denotes a function providing the number of photons present at the reliable distance D from the transmitter (31) based on the predetermined channel model Channel_Model, P denotes the probability that the function Nphotons is equal to 1, and Threshold denotes a predetermined threshold value.
14. 14. The method according to claim 12 or 13, wherein the continuous monitoring of the trusted area (23, 33) or of the area around the transmitter (31) is performed by one or more sensors and / or based on terrestrial monitoring.
15. 15. The method according to claim 12, further comprising the step of ceasing to transmit the multi-photon pulses if a potential threat to the security of the trusted area (23, 33) is detected based on the continuous monitoring.
16. 16. The method of claim 15, further comprising performing steps a), b), and c) or d) by determining a different reliable distance (D) if transmitting the multi-photon pulses is stopped due to a detected potential threat.
Citation Information
Patent Citations
US10,348,493
Fast multi-photon key distribution scheme secured by quantum noise
US7831050B2
Method to mitigate propagation loss in waveguide transmission of quantum states
US9294191B2