Method and system for quantum key distribution
By modulating optical pulses with time-dependent intensity and phase profiles, the method enhances the security of quantum key distribution by utilizing high-intensity states with weak distinguishability, addressing vulnerabilities in conventional encoding methods.
Patent Information
- Application Number
- JP2024207969
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-13
- Filing Date
- 2024-11-29
- Publication Date
- 2025-07-08
AI Technical Summary
Existing quantum key distribution (QKD) protocols face challenges in securely encoding and decoding classical information using conventional methods, which are vulnerable to eavesdropping and do not effectively utilize high-intensity quantum states with weak distinguishability.
A method involving time-dependent intensity and phase modulation of optical pulses is employed, where each optical pulse's intensity and phase profiles are modulated based on encoder values, allowing for robust encoding and decoding through classical post-processing, making it difficult for eavesdroppers to retrieve encoded logical bits.
This approach enhances security by utilizing high-intensity quantum states with weak distinguishability, significantly improving resistance against conventional encoding routines and maintaining information integrity during quantum key distribution.
Smart Images

Figure 2025102682000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to methods and systems for quantum key distribution, and more particularly to techniques for encoding classical information into quantum signals and decoding classical information from quantum signals.
Background Art
[0002] Typical quantum key distribution (QKD) protocols include two main stages: quantum communication and classical post-processing. In principle, at a transmitter device ("Alice"), a random bit sequence is generated, encoded into a quantum state, and transmitted via a quantum channel to a receiver device ("Bob"). Encoding uniformly includes generating a coherent state (e.g., by a laser) and applying optical elements such as a phase shifter, an attenuator, or a beam splitter. The transmitted state is measured at the receiver device, and then classical post-processing is performed to establish a shared secret key.
[0003] In a practical optical QKD setup, classical information is - polarization encoding (e.g., BB84 protocol): different logical bits are converted into different polarizations of a single photon or multi-photon signal / optical pulse, - phase encoding (e.g., DPS QKD): different logical bits are converted into different phases of a single photon or multi-photon signal, - intensity encoding (e.g., B92 using coherent states): different logical bits are converted into optical pulses of different intensities, or - time encoding (e.g., COW protocol): information is encoded in the time position of an optical pulse, and can be used to encode into a physical system.
[0004] UK Patent Application Publication No. 2529228 relates to an interference method for a quantum communication system. It refers to time-varying gain modulation including any pulse shape. However, classical information encoding is performed using the conventional BB84 method that sets the phase of the entire bit carrier signal.
[0005] US Patent No. 10153848 relates to a transmitter for a continuously variable quantum communication system. A sequence of optical pulses is created such that subsequent optical pulses have different phases or intensities relative to each other.
[0006] Chinese Patent Application Publication No. 110620655 discloses intensity modulation of optical pulses and subsequent phase modulation in the context of quantum key distribution. The intensity modulation (of the entire pulse) is performed to create decoy states. Chinese Utility Model No. 205961140 describes an optical intensity modulator that acts on an optical signal before encoding or after phase encoding. The intensity is not related to encoding but is related to decoy states.
Prior Art Documents
Patent Documents
[0007]
Patent Document 1
Patent Document 2
Patent Document 3
Patent Document 4
Summary of the Invention
[0008] The object of the present disclosure is to provide an improved technique for encoding classical information into a quantum signal and decoding classical information from the quantum signal in quantum key distribution.
[0009] To solve this problem, according to the independent claims, an encoding method, a decoding method, a method for quantum key distribution, a transmitter device, a receiver device, and a system for quantum key distribution are provided. Further embodiments are disclosed in the dependent claims.
[0010] According to one aspect of the present invention, an encoding method for quantum key distribution is provided, the method being executed in a transmitter device having a classical processor and means for preparing and transmitting a quantum signal, the method comprising: - generating an encoder initial bit sequence; - generating a quantum signal comprising a plurality of optical pulses from the encoder initial bit sequence, wherein generating each optical pulse of the plurality of optical pulses comprises: - modulating the intensity profile of the optical pulse according to an intensity function that depends on time and a first encoder value of at least one first bit of the encoder initial bit sequence; - modulating the phase profile of the optical pulse according to a phase function that depends on time and a second encoder value of at least one second bit of the encoder initial bit sequence, generating comprising at least one of: - transmitting the plurality of optical pulses to a receiver device via a quantum channel; - determining a shared key shared between the transmitter device and the receiver device from the encoder initial bit sequence by means of at least one of classical post-processing and transmitting classical information to the receiver device and receiving further classical information from the receiver device (12).
[0011] According to another aspect, a decoding method for quantum key distribution is provided, the method being executed in a receiver device having a classical processor and means for receiving and measuring a quantum signal, the method comprising: - receiving a quantum signal comprising a plurality of optical pulses from a transmitter device via a quantum channel; - Determining a decoder initial bit sequence from a plurality of optical pulses, wherein the determining is, for each optical pulse, - Determining an approximate intensity profile of an optical pulse by measuring a plurality of intensity values of the optical pulse for a plurality of time bins, and determining a first decoder value of at least one first bit of the decoder initial bit sequence from the approximate intensity profile; and - Determining an approximate phase profile of an optical pulse by measuring a plurality of phase values of the optical pulse for a plurality of time bins, and determining a second decoder value of at least one second bit of the decoder initial bit sequence from the approximate phase profile, the determining including at least one of the foregoing; and - Determining a shared key shared between the transmitter device and the receiver device from the decoder initial bit sequence by classical post-processing and / or by at least one of receiving classical information from the transmitter device and transmitting further classical information to the transmitter device.
[0012] According to another aspect, a method for quantum key distribution is provided, the method being performed within a system comprising a transmitter device having a classical processor and means for modulating and transmitting a quantum signal, and a receiver device having a further classical processor and means for receiving and measuring a quantum signal. The method comprises - Generating an encoder initial bit sequence within the transmitter device; and - Generating a quantum signal comprising a plurality of optical pulses within the transmitter device from the encoder initial bit sequence, wherein generating each optical pulse of the plurality of optical pulses is - Modulating the intensity profile of the optical pulse according to an intensity function that depends on time and on a first encoder value of at least one first bit of the encoder initial bit sequence; and - modulating the phase profile of the optical pulse according to a phase correlation function that depends on time and on a second encoder value of at least one second bit of the encoder initial bit sequence, and generating, including at least one of: - transmitting a plurality of optical pulses from a transmitter device to a receiver device via a quantum channel and receiving the plurality of optical pulses within the receiver device; - determining a decoder initial bit sequence from the plurality of optical pulses, the determining being for each optical pulse; - determining an approximate intensity profile of the optical pulse by measuring a plurality of intensity values of the optical pulse for a plurality of time bins and determining a first decoder value of at least one first bit of the decoder initial bit sequence from the approximate intensity profile; - determining an approximate phase profile of the optical pulse by measuring a plurality of phase values of the optical pulse for a plurality of time bins and determining a second decoder value of at least one second bit of the decoder initial bit sequence from the approximate phase profile, the determining including at least one of: - determining a shared key shared between the transmitter device and the receiver device by classical post-processing within the transmitter device from the encoder initial bit sequence and within the receiver device from the decoder initial bit sequence, and by at least one of transmitting classical information from the transmitter device to the receiver device and transmitting further classical information from the receiver device to the transmitter device.
[0013] According to another aspect, a transmitter device for quantum key distribution is provided, the transmitter comprising a classical processor and means for modulating and transmitting a quantum signal, the following steps, namely: - generating an encoder initial bit sequence; - generating a quantum signal comprising a plurality of optical pulses from the encoder initial bit sequence, generating each optical pulse of the plurality of optical pulses being: - Modulating the intensity profile of an optical pulse according to an intensity function that depends on time and a first encoder value of at least one first bit of an encoder initial bit sequence; - Generating, including at least one of: modulating the phase profile of an optical pulse according to a phase function that depends on time and a second encoder value of at least one second bit of an encoder initial bit sequence; - Transmitting a plurality of optical pulses to a receiver device via a quantum channel; - Determining a shared key shared between the transmitter device and the receiver device from the encoder initial bit sequence by at least one of classical post-processing and transmitting classical information to the receiver device and receiving further classical information from the receiver device; and being configured to perform.
[0014] According to another aspect, a receiver device for quantum key distribution is provided, the receiver device comprising a classical processor and means for receiving and measuring a quantum signal, the following steps, namely, - Receiving a quantum signal including a plurality of optical pulses from a transmitter device via a quantum channel; - Determining a decoder initial bit sequence from the plurality of optical pulses, the determining being for each optical pulse, - Determining an approximate intensity profile of the optical pulse by measuring a plurality of intensity values of the optical pulse for a plurality of time bins, and determining a first decoder value of at least one first bit of the decoder initial bit sequence from the approximate intensity profile; - Determining an approximate phase profile of the optical pulse by measuring a plurality of phase values of the optical pulse for a plurality of time bins, and determining a second decoder value of at least one second bit of the decoder initial bit sequence from the approximate phase profile, including at least one of the determining; - By classical post - processing and / or by receiving classical information from the transmitter device and / or by transmitting further classical information to the transmitter device, determining a shared key shared between the transmitter device and the receiver device from the decoder initial bit sequence, and is configured to perform.
[0015] According to another aspect, a system for quantum key distribution is provided, the system comprising a transmitter device having a classical processor and means for modulating and transmitting a quantum signal, and a receiver device having a further classical processor and means for receiving and measuring a quantum signal. The system performs the following steps, namely, - Generating an encoder initial bit sequence within the transmitter device; - Generating, from the first initial bit sequence, a quantum signal within the transmitter device comprising a plurality of optical pulses, wherein generating each optical pulse of the plurality of optical pulses - Modulating the intensity profile of the optical pulse according to an intensity function that depends on time and on a first encoder value of at least one first bit of the encoder initial bit sequence; - Generating, including at least one of: modulating the phase profile of the optical pulse according to a phase function that depends on time and on a second encoder value of at least one second bit of the encoder initial bit sequence; - Transmitting the plurality of optical pulses from the transmitter device to the receiver device via a quantum channel and receiving the plurality of optical pulses within the receiver device; - Determining an encoder initial bit sequence from the plurality of optical pulses, wherein determining is performed for each optical pulse - Determining an approximate intensity profile of the optical pulse by measuring a plurality of intensity values of the optical pulse for a plurality of time bins, and determining a first decoder value of at least one first bit of the encoder initial bit sequence from the approximate intensity profile; - determining an approximate phase profile of an optical pulse by measuring a plurality of phase values of the optical pulse for a plurality of time bins, and determining, from the approximate phase profile, a second decoder value for at least one second bit of an initial decoder bit sequence, and including at least one of the above, the determining; - determining a shared key shared between the transmitter device and the receiver device by at least one of classical post-processing within the transmitter device from an initial encoder bit sequence and within the receiver device from an initial decoder bit sequence, and transmitting classical information from the transmitter device to the receiver device and transmitting further classical information from the receiver device to the transmitter device; is configured to execute.
[0016] Thus, modulating the intensity profile of each optical pulse depends specifically on a first encoder value of at least one first bit of the initial encoder bit sequence. Furthermore, modulating the phase profile of each optical pulse depends on a second encoder value of at least one second bit of the initial encoder bit sequence.
[0017] As a result, in particular, the shared key can be determined in a robust manner in order to increase the values that may potentially leak information to eavesdroppers. High-intensity quantum states with relatively weak distinguishability may be employed. In contrast, conventional quantum cryptography assumes that a potential eavesdropper can obtain all the losses that occur in the quantum channel between legitimate parties. Therefore, weak coherent states with a small number of photons per signal are generally used.
[0018] Due to their (non-trivial) time-dependence, the intensity function and the phase function can be assumed to not be constant in time. In other words, the intensity function and the phase function can be considered to change over time. Similarly, the intensity function and the phase function can be considered to change depending on the first encoder value and the second encoder value, respectively. Further, the modulation of the intensity profile and the modulation of the phase profile can be considered to depend on time as well as on the first encoder value and the second encoder value, respectively.
[0019] Time-dependent intensity and / or phase profiles can change rapidly in time, making it extremely difficult for an eavesdropper to retrieve information about the encoded logical bits contained in the scattered radiation. Therefore, the security against conventional encoding routines is significantly improved.
[0020] A quantum signal can include a plurality of quantum states. For example, each quantum state can correspond to one of the optical pulses. Each optical pulse can include a plurality of photons.
[0021] Each optical pulse can correspond to an optical wave packet that starts and ends on a time scale when its (instantaneous) intensity drops to zero and / or below a noise level that can be, for example, between 0.01% and 1.0% of the average peak value of a plurality of optical pulses. The pulse length of the optical pulse can correspond to the difference between its start and end on the time scale.
[0022] The intensity (time) profile (shape) of the optical pulse can correspond to the intensity and / or the number of photons and / or the optical power of the optical pulse depending on time. The phase (time) profile of the optical pulse can correspond to its phase depending on time.
[0023] The encoder initial bit sequence may preferably be randomly generated using a quantum random number generator (QRNG). Alternatively, a classical pseudo-random number generator may be employed.
[0024] At least one first bit of the encoder initial bit sequence may be different from at least one second bit of the encoder initial bit sequence. Thus, a lot of information can be encoded into the optical pulse.
[0025] Alternatively, at least one first bit and at least one second bit of the encoder initial bit sequence may be the same. In this case, the intensity function may depend on time and on the (first encoder) value of at least one (first) bit of the encoder initial bit sequence, and the phase function may depend on time and on the (first encoder) value of at least one (first) bit of the encoder initial bit sequence. Thus, the same one or more first bits can be encoded both in intensity and in phase, and redundancy and (e.g., robustness against noise) will be improved.
[0026] At least one first bit of the decoder initial bit sequence may be different from at least one second bit of the decoder initial bit sequence. Alternatively, at least one first bit and at least one second bit of the decoder initial bit sequence may be the same.
[0027] At least one of the first encoder value, the second encoder value, the first decoder value, and the second decoder value may be a binary value. For example, if the intensity function depends on a single first bit of the encoder initial bit sequence, the first encoder value may be a bit value, i.e., the first encoder value may be "0" or "1". If the intensity function depends on two first bits of the encoder initial bit sequence, the first encoder value may be one of "00", "01", "10", and "11".
[0028] Classical post - processing, transmitting classical information to a receiver device, and receiving further classical information from the receiver device may include classical post - processing and transmission and reception between at least one of bit adjustment, post - selection, error estimation, error correction, and privacy amplification. Classical post - processing, receiving classical information from a transmitter device, and transmitting further classical information to the transmitter device may include classical post - processing and transmission and reception between at least one of bit adjustment, post - selection, error estimation, error correction, and privacy amplification.
[0029] The total number of photons for each of a plurality of optical pulses and for each first encoder value may be constant.
[0030] (Each) optical pulse may be generated from a (pulse) laser beam and / or using a Mach - Zehnder interferometer (of an encoder device). The Mach - Zehnder interferometer may comprise a first phase modulator, a second phase modulator, a first beam splitter, and a second beam splitter. The laser beam may pass through the first beam splitter, the first phase modulator, the second beam splitter, and the second phase modulator.
[0031] Prior to modulation, each optical pulse may include, for example, a rectangular intensity profile. In particular, prior to modulation, each optical pulse may include a constant optical power (over the duration of the optical pulse).
[0032] The first beam splitter and / or the second beam splitter may be a 50:50 beam splitter. The laser beam may be split (into first and second parts) at the first beam splitter and recombined at the second beam splitter. The laser beam may be further split (again into third and fourth parts) at the second beam splitter. The first part may pass through the first phase modulator. The second part may reach the second beam splitter directly. The third part may be sent to the control detector. The fourth part may pass through the second phase modulator and subsequently be sent to the quantum channel (as optical pulses).
[0033] The input optical power of the laser for generating optical pulses may be 0.15 nW to 100.00 nW, preferably 1 nW to 20 nW. Each of the optical pulses may have a photon number of 100 to 80000, preferably 800 to 15000. The laser may include, for example, a DFB PM laser diode. The central wavelength of the optical pulse may be between 1510 nm and 1550 nm, preferably between 1529 nm and 1531 nm, more preferably 1530 nm. The linewidth may be 2 MHz or less.
[0034] Each of the (modulated) optical pulses may include an optical power (time-dependent) of 0.1 nW to 50.0 nW, preferably 1 nW to 20 nW, more preferably 5 to 15 nW from the start to the end on the time scale.
[0035] The intensity profile may be modulated by at least one of the first phase modulator and the laser source intensity (input intensity). The phase profile may be modulated by the second phase modulator.
[0036] The intensity function may depend on the first encoder value and preferably include an oscillating component having a time-dependent (instantaneous) frequency. Further, the phase function may depend on the second encoder value and include a (further) oscillating component having a time-dependent frequency.
[0037] Generally, the intensity function and / or the phase function may include at least two (local) maxima.
[0038] Modulating the intensity profile of an optical pulse according to (using) the intensity function may include at least one of multiplying the intensity profile by the intensity function (point - by - point), convolving the intensity profile with the intensity function, and adding the intensity function to the intensity profile (point - by - point). Further, modulating the phase profile of an optical pulse according to (using) the phase function may include at least one of multiplying the phase profile by the phase function (point - by - point), convolving the phase profile with the phase function, and adding the phase function to the phase profile (point - by - point).
[0039] For each first encoder value, the intensity function may be unique. In other words, for each first encoder value, the intensity function may be different from the intensity function of another first encoder value. In particular, for each first encoder value, the intensity function may have a unique time evolution. For example, for each first encoder value, the intensity function may be different from a constant multiple of the intensity function of another first encoder value. Correspondingly, for each second encoder value, the phase function may be unique. In other words, for each second encoder value, the phase function may be different from the phase function of another second encoder value. In particular, for each second encoder value, the phase function may have a unique time evolution. For example, for each second encoder value, the phase function may be different from a constant multiple of the phase function of another second encoder value.
[0040] The intensity function and the phase function may be the same to match the first encoder value and the second encoder value. Alternatively, the intensity function and the phase function may be different when the first encoder value and the second encoder value match, in particular, for any (pair of) first encoder value and second encoder value.
[0041] The intensity function and / or the phase function may be quasi - periodic.
[0042] In the case of the first encoder value a, the vibration component is the coefficient c that depends on the first encoder value a and the angle η a and the angular function ζ a (t), and has the form c a cos(ζ a (t)+η a ). The coefficient c a and the angle η a may also be constant with respect to the first encoder value. In other words, the vibration component may have the form c cos(ζ a (t)+η). In the case of the second encoder value a, the additional vibration component is an additional coefficient that depends on the second encoder value
Number
Number
Number
Number
Number
Number
Number
[0043] The vibration component and / or further vibration components may include vibrations having an instantaneous period (local period) of 1 ns to 50 ns, preferably 1 ns to 20 ns, more preferably 1 ns to 10 ns. The instantaneous period may vary with time. The vibration component may also include vibrations having an instantaneous frequency (local frequency) of 10 MHz to 500 MHz, preferably 45 MHz to 300 MHz, more preferably 70 MHz to 130 MHz. The instantaneous frequency may vary with time.
[0044] The intensity function may also include a constant (offset) component (a component that is constant over time). The phase function may also include a further constant (offset) component. The intensity function may include the sum of a vibration component and a constant component. The phase function may include the sum of a further vibration component and a further constant component.
[0045] The intensity function may depend on the first encoder value and include at least one of a frequency chirp component, preferably a linear frequency chirp component, a quadratic frequency chirp component, a cubic frequency chirp component, and an exponential frequency chirp component. The phase function may depend on the second encoder value and include at least one of a (further) frequency chirp component, preferably a linear frequency chirp component, a quadratic frequency chirp component, a cubic frequency chirp component, and an exponential frequency chirp component. The (further) vibration component may be or include a (further) frequency chirp component.
[0046] The frequency chirp component may include a chirp rate depending on the first encoder value. The further frequency chirp component may include a further chirp rate depending on the second encoder value. The (further) chirp rate may be unique for each first (second) value.
[0047] The intensity function may depend on the first encoder value of at least two first bits of the encoder initial bit sequence, and / or the phase function may depend on the second encoder value of at least two second bits of the encoder initial bit sequence.
[0048] In other words, generating each optical pulse of a plurality of optical pulses may include at least one of modulating the intensity profile of the optical pulse according to an intensity function that depends on time and the first encoder value of at least two first bits of the encoder initial bit sequence, and modulating the phase profile of the optical pulse according to a phase function that depends on time and the second encoder value of at least two second bits of the encoder initial bit sequence.
[0049] The intensity function may also depend on the first encoder value of at least three first bits of the encoder initial bit sequence, and / or the phase function may depend on the second encoder value of at least three second bits of the encoder initial bit sequence. The intensity function may depend on the first encoder value of at least four first bits of the encoder initial bit sequence, and / or the phase function may depend on the second encoder value of at least four second bits of the encoder initial bit sequence.
[0050] Generally, the intensity function may depend on the first encoder value of at least one first bit and up to 100 first bits (in particular, up to 20 first bits, in particular, up to 4 first bits) of the encoder initial bit sequence. The phase function may depend on the second encoder value of at least one second bit and up to 100 second bits (in particular, up to 20 second bits, in particular, up to 4 second bits) of the encoder initial bit sequence.
[0051] When the intensity (phase) function depends on the first (second) bit, the intensity (phase) profile may be modulated according to two different shapes (according to the intensity (phase) function of bit value 0 and the intensity (phase) function of bit value 1). When the intensity (phase) function depends on two first (second) bits, the intensity (phase) profile may be modulated according to four different shapes (according to the intensity (phase) functions of bit values 00, 01, 10, and 11). Generally, when the intensity (phase) function depends on n first (second) bits, the intensity (phase) profile may be modulated according to 2 n different shapes.
[0052] The first bit of the encoder initial bit sequence may be different from the second bit of the first bit sequence. Alternatively, the first bit and the second bit may be the same or may partially overlap.
[0053] Each optical pulse may have a pulse length of 1 ns to 1000 ns, preferably 50 ns to 200 ns, more preferably 80 ns to 120 ns. Each optical pulse may have (essentially) the same pulse length. Each optical pulse may have a pulse length that is at most 0.1% different from the average pulse length of a plurality of optical pulses.
[0054] The modulation of the intensity profile and / or the phase profile may be performed such that the pulse length of each optical pulse changes by at most 10%, preferably at most 5%.
[0055] Determining the first decoder value may include comparing an approximate intensity profile to an ideal approximate intensity profile (for different possible first encoder values). Determining the second decoder value may include comparing an approximate phase profile to an ideal approximate phase profile (for different possible second encoder values).
[0056] The approximate intensity profile may include a plurality of intensity values. The approximate phase profile may include a plurality of phase values. For each time bin, the approximate intensity profile may include the corresponding intensity value and / or the approximate phase profile may include the corresponding phase value.
[0057] (For a plurality of time bins) Measuring the intensity value and / or the phase value may include performing a heterodyne measurement for each time bin. Performing a heterodyne measurement may include splitting the (received) optical pulse into two beams that interfere with two further beams of a local oscillator (LO), and measuring the interference event using a (photodiode) detector.
[0058] Each time bin may include a time bin length of 1 ns to 50 ns, preferably 1 ns to 5 ns, more preferably 1 ns to 2 ns.
[0059] The first decoder value of at least two first bits of the decoder initial bit sequence, and / or the second decoder value of at least two second bits of the decoder initial bit sequence may be determined. Further, the first decoder value of at least three first bits of the decoder initial bit sequence, and / or the second decoder value of at least three second bits of the decoder initial bit sequence may be determined. Further, the first decoder value of at least four first bits of the decoder initial bit sequence, and / or the second decoder value of at least four second bits of the decoder initial bit sequence may be determined. Generally, the first decoder value of at least one first bit and up to 100 first bits (in particular, up to 20 first bits, in particular, up to 4 first bits) of the decoder initial bit sequence, and / or the second decoder value of at least one second bit and up to 100 second bits (in particular, up to 20 second bits, in particular up to 4 second bits) of the decoder initial bit sequence may be determined.
[0060] Each of the possible first encoder values may correspond to one of the ideal approximate intensity profiles. Each of the possible second encoder values may correspond to one of the ideal approximate phase profiles. For example, when determining the first decoder value of a single first bit of the decoder initial bit sequence, the first decoder value may be 0 or 1. When determining the first decoder value of two first bits of the decoder initial bit sequence, the first decoder value may be any of 00, 01, 10, and 11. Generally, when determining the first (second) decoder value of n first (second) bits of the decoder initial bit sequence, the first (second) decoder value is 2 n possible. Therefore, when determining the first (second) decoder value of n first (second) bits of the decoder initial bit sequence, the ideal approximate intensity (phase) profile is 2 n is.
[0061] Comparing the approximate intensity profile with the ideal approximate intensity profile may include determining a first characteristic indicative of the approximate intensity profile associated with the ideal approximate intensity profile. Comparing the approximate phase profile with the ideal approximate phase profile may include determining a second characteristic indicative of the approximate phase profile associated with the ideal approximate phase profile.
[0062] The first characteristic may include, for example, a first measured correlation difference determined from the approximate intensity profile and the ideal approximate intensity profile. Then, determining the first decoder value may include comparing the first measured correlation difference with a first threshold. The second characteristic may include a second measured correlation difference determined from the approximate phase profile and the ideal approximate phase profile. Determining the second decoder value may include comparing the second measured correlation difference with a second threshold.
[0063] In other words, including variable symbols, the method is - approximate intensity profile [Number] and an ideal strength value N a (including (t)) ideal approximate strength profile {N a (t)} t to determine a first measurement correlation difference ΔQ from, and compare the first measurement correlation difference ΔQ with a first threshold [Number] to determine a first decoder value by comparison, and - approximate phase profile [Number] and an ideal phase value Π a (including (t)) ideal approximate phase profile {Π a (t)} t to determine a second measurement correlation difference ΔR from, and compare the second measurement correlation difference ΔR with a second threshold [Number] and may include at least one of determining a second decoder value by comparison.
[0064] Determining the first measurement correlation difference ΔQ may include determining the (preferably normalized) sum of the differences of the ideal strength value N a (t) that depends on the first encoder value a for each of a plurality of time bins, where each of the differences is weighted by the (measured) strength value of the respective time bin. Determining the second measurement correlation difference ΔR may include determining the (preferably normalized) sum of the differences of the ideal phase value Π a (t) that depends on the second encoder value a for each of a plurality of time bins, where each of the differences is weighted by the (measured) phase value of the respective time bin.
[0065] The first threshold [Number] may be determined from the correlation mean differences e0 and e1 for the first decoder value of at least one first bit, in particular, from the arithmetic mean of the correlation mean differences e0 and e1 for the first decoder value of at least one first bit. The second threshold
Number
Number
Number
Number
Number
Number
Number
Number
Number
[0066] The first decoder value is the first threshold
Number
Number
[0067] In particular, the first decoder value is determined by a first post-selection parameter to be a first threshold value
Number
Number
Number
Number
[0068] The first post-selection parameter and / or the second post-selection parameter may be determined such that the key generation rate for determining the shared key is maximized. In particular, the first post-selection parameter and / or the second post-selection parameter may be determined by numerical optimization for a candidate set of post-selection parameters, preferably by varying the initial bit sequence of the encoder and / or the test input bit sequence for an assumed signal leakage value.
[0069] The first post-selection parameter and / or the second post-selection parameter may be 0.01 to 0.30, preferably 0.05 to 0.20, more preferably 0.08 to 0.10.
[0070] This method may include determining (and / or monitoring) the optical signal loss along a quantum channel (and / or transmission line), in particular, the position-dependent optical signal loss along an optical fiber. In other words, the optical signal loss may be determined as a function of the position along the quantum channel. In particular, for each position along the quantum channel, the corresponding optical signal loss may be determined. Thus, the optical signal loss may correspond to a signal loss profile. The optical signal loss may be determined via an optical test pulse (different from the plurality of optical pulses). The optical test pulse may include an optical power that is preferably at least 10 times, more preferably at least 100 times greater than that of the optical pulse.
[0071] The optical signal loss may be determined by optical time domain reflectometry. The optical signal loss may be determined during, and / or before, and / or after the determination of the shared key. The optical signal loss may be determined repeatedly. For example, the optical signal loss may be repeatedly determined within one of the time intervals of 10 ns to 50 s, preferably 10 ns to 10 s, in particular 100 ns to 100 ms, 500 ns to 500 ms, 100 ms to 1000 ms, 0.5 s to 5 s, and 5 s to 10 s.
[0072] The method may include determining an intrusion event based on an optical signal loss and / or aborting (terminating) the determination of a shared key based on the optical signal loss. The method may include discarding a shared key based on the optical signal loss.
[0073] Within the context of this disclosure, intervals and ranges of values (e.g., “from... to...,” “between... and...”) include their boundary points.
[0074] The foregoing embodiments relating to a method for quantum key distribution can be provided in correspondence with a transmitter device, a receiver device, and a system for quantum key distribution.
Brief Description of the Drawings
[0075] Hereinafter, embodiments will be described by way of example with reference to the drawings.
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Embodiments for Carrying Out the Invention
[0076] FIG. 1 shows a visual representation of a configuration comprising a system for quantum key distribution and an eavesdropping device 13 (“Eve”). The system comprises a communication channel (transmission line) 10 for transmitting classical signals and / or quantum signals, in particular optical pulses, between a transmitter device 11 (“Alice”) and a receiver device 12 (“Bob”). The communication channel 10 may comprise or consist of a classical channel and / or a quantum channel 10a. Further, the communication channel 10 may comprise at least one optical fiber for transmitting optical pulses. To amplify the optical pulses, at least one (optical) amplifier (not shown) may be provided along the communication channel 10. The optical amplifier may compensate for losses occurring in a section preceding the communication channel 10.
[0077] The transmitter device 11 may comprise a (classical) processor 11a and a (classical) memory 11b, and the receiver device 12 may further comprise a further (classical) processor 12a and a further (classical) memory 12b. The transmitter device 11 and the receiver device 12 may be part of the system. The transmitter device 11 and the receiver device 12 are connected to the quantum channel.
[0078] The eavesdropper device 13 having an eavesdropping processor 13a and an eavesdropping memory 13b represents a device outside the system having potential access to the quantum channel 10. The eavesdropping device 13 may be arranged on the transmission line 10 such that an optical signal transmitted via the transmission line 10 is at least partially received and / or retransmitted by the eavesdropping device 13. The eavesdropping device 13 may also access a further communication channel.
[0079] At least one of the transmitter device 11, the receiver device 12, and the eavesdropping device 13, preferably each, may include at least one means for preparing, transmitting, receiving, and measuring a quantum state, particularly an optical quantum state. In particular, the transmitter device 11 may include means for preparing and transmitting a quantum signal and / or a quantum state, for example, a (quantum state) preparation device 11c. Further, the receiver device 12 may include means for receiving and measuring a quantum signal and / or a quantum state, for example, a (quantum state) measurement device 12c. Similarly, the eavesdropping device 13 may include a preparation and / or measurement device 13c. The transmitter device 11 and the receiver device 12 may each include means for receiving and transmitting (additional) classical information (e.g., via a classical channel).
[0080] The first memory 11b, the second memory 12b, and the eavesdropping memory 13b may each include a quantum memory configured to store a quantum signal and a classical memory configured to store a classical signal. The quantum memory may be provided using an optical delay line, controlled reversible inhomogeneous broadening (CRIB), Duan-Lukin-Cirac-Zoller (DLCZ) scheme, revival of silenced echo (ROSE), and / or hybrid photon echo rephasing (HYPER).
[0081] (a) Quantum key distribution Hereinafter, the steps of determining a shared key by quantum key distribution will be briefly described. In FIG. 2, a visual representation of the corresponding steps is shown.
[0082] Specific steps, particularly loss control of the transmission line (transmission line control) (step 21, section b), encoding (step 23, section c), decoding (step 25, section d), and post-processing (steps 26 to 28, section e), will be described in detail in the subsequent sections.
[0083] The transmitter device 11 and the receiver device 12 are connected via an authenticated (public) classical channel, and the optical fiber of the transmission line 10 functions as a quantum channel 10a.
[0084] In the first step 20, the initial internal loss profile of the transmission line 10 (especially its optical fiber segment) is determined, which essentially represents the natural signal loss in the transmission line 10. In this preliminary step, it should be ensured that no eavesdropper has access to the transmission line 10. The initial loss profile may be shared between the transmitter device 11 and the receiver device 12 via an authenticated classical communication channel.
[0085] In the first step 21, the physical loss control of the transmission line 10 is performed by the transmitter device 11 and the receiver device 12 by transmitting an optical test pulse. In particular, the loss profile is determined and preferably shared between the transmitter device 11 and the receiver device 12 via a classical channel.
[0086] In this way, by comparing the updated internal loss profile with the initial internal loss profile, the ratio r E of the signals that may be intercepted by the eavesdropper can be determined. For example, in a section of the transmission line 10, the natural signal loss of this section is represented by r0, and when the eavesdropper intercepts the interception ratio r E of the signal, the interception ratio r E can be derived from the total loss r t through the relationship (1 - r E ) = (1 - r t )(1 - r0).
[0087] If the interception ratio r E becomes too large, causing the legitimate user to lose the information advantage over the eavesdropper, the protocol ends. The end of the protocol depends on the length of the transmission line 10. The protocol may end especially when the effective key rate is below the target key rate value.
[0088] Based on the loss profile, protocol settings such as signal shape, post-selection parameters, error correction codes, etc. may be determined. Physical loss control including the transmission of optical test pulses may be performed in parallel with the transmission of optical (signal) pulses for determining the shared key. r E If a change in r is detected, the protocol settings may be adapted.
[0089] In a second step 22, a bit sequence is determined in the transmitter device 11 using a random number generator.
[0090] In a third step 23, the encoder initial bit sequence is encoded into the intensity profile and / or phase profile of each of a plurality of optical (signal) pulses.
[0091] In a fourth step 24, the optical pulses are transmitted to the receiver device 12 via the quantum channel 10a.
[0092] In a fifth step 25, the optical pulses are received and measured by the receiver device 12. The corresponding decoder initial bit sequence is determined in the receiver device 12. Due to quantum and classical noise, the quantum state of a particular optical pulse corresponding to different bit values cannot be accurately determined. Thus, the second initial bit string may contain additional errors.
[0093] In a sixth step 26, the uncertain bits corresponding to the quantum measurement values determined to be uncertain in the receiver device 12 are discarded (post-selection) from the encoder initial bit sequence in the transmitter device 11 and the decoder initial bit sequence in the receiver device 12. Thereby, a first raw key in the transmitter device and a second raw key in the receiver device are obtained. To discard the uncertain bits, the bit positions of the uncertain signal bits (as part of additional classical information) may be transmitted from the receiver device 12 to the transmitter device 11 via a classical channel.
[0094] In the seventh step 27, the error rate may be determined by disclosing (as part of classical information and / or a part of further classical information) via a classical channel, a part of the encoder initial bit sequence (in particular, the first / encoder raw key), and / or a part of the decoder initial bit sequence (in particular, the second / decoder raw key), and error correction may be performed on the first raw key and the second raw key by the transmitter device 11 and the receiver device 12 respectively. The error correction may be performed by adopting an error correction code, for example, a low-density parity-check (LDPC) code, a Hamming code, or a cascade protocol. As a result, the error-corrected bit sequence is determined from the first raw key at the transmitter device 11 and from the second raw key at the receiver device 12.
[0095] In the eighth step 28, the amplified key sequence is determined from the error-corrected bit sequence using privacy amplification. A known privacy amplification method in which (further) classical information is exchanged may be adopted. The amplified key sequence is shorter than the error-corrected bit sequence, and potential eavesdroppers have no information about or negligibly small information about the amplified key sequence. The amplified key sequence represents a shared key sequence between the transmitter device 11 and the receiver device 12 as a result of quantum key distribution. The privacy amplification may be based on the determined value of r E of.
[0096] The steps from the first step 21 to the eighth step 28 may be repeated (arrow 29), and the amplified key sequence may be concatenated to the (total) shared key until the full length of the shared key reaches the length required by the application at hand.
[0097] During all steps 21 to 28, the transmission line 10 may be continuously controlled (arrow 20a). Thus, a signal loss profile is determined and preferably shared between the transmitter device 11 and the receiver device 12 via a classical channel. If the integrity of the transmission line 10 is impaired to such an extent that there is a significant risk that an eavesdropper will decode the scattering loss, the protocol may be terminated.
[0098] (b) Transmission line control / Loss control Hereinafter, the first step 21 of physical loss control of the transmission line 10 will be described in detail.
[0099] FIG. 3 shows an exemplary reflectivity diagram obtained from an optical time domain reflectometry corresponding to a signal loss profile. The measurements below were performed using a 2 μs, 1550 nm pulsed laser with an output of less than 100 mW. The experimental data is averaged over 16,000 measurements.
[0100] The reflectivity indicates the logarithmic power of the backscattered light test pulse as a function of the distance between the reflectometer and the corresponding discontinuity. The reflectometer may be disposed inside and / or near the transmitter device 11 and / or the receiver device 12.
[0101] The natural signal loss along the quantum channel 10a / transmission line 10 is due to uniform scattering and results in an exponential decay of the power corresponding to the linear region 30. Reflectivity characteristics 31 to 34, including in particular sharp peaks and / or drops in the reflectivity curve, which deviate from the exponential decay of the reflectivity curve, make it possible to classify the signal loss at the corresponding positions of the transmission line 10. This is particularly useful in the initial step 20 where the identification and mitigation of local losses is important for comparison with the determined losses during key exchange.
[0102] The reflectivity characteristics 31 to 34 generally correspond to defects in the transmission line 10 and may represent, for example, low-quality splices, bends, and different connectors. The scattering losses from such regions are localized with respect to the transmission line 10. The peaks of the reflectivity characteristics 31 to 34 may result from excessive scattering caused by the test pulse undergoing Fresnel reflection in the case of a physical connector. The noisy region 35 on the right side of the reflectivity represents the termination of the backscattered signal.
[0103] Additionally or alternatively, the transmission line control may include transmittance measurements, i.e., the intensity of the optical test pulse transmitted by the transmitter device 11 and received by the receiver device 12 is analyzed to classify the signal loss at each position of the transmission line 10. The classification by analysis of the received optical signal in the receiver device 12 may be performed within the receiver device 12. The transmitter device 11 may also be configured to perform the classification, in particular, by combining the measured values of the backscattered test pulse component and the optical test pulse received by the receiver device 12.
[0104] When enhancing accuracy, an optical test pulse having the highest intensity, in particular, an intensity greater than the intensity of the optical (signal) pulse. The parameters of the transmitted optical test pulse, such as intensity, phase, length, and shape, are randomly determined in the transmitter device 11. The parameters remain secret until the quantum measurement is completed by the receiver device 12. Next, the transmitter device 11 announces the parameters adopted, and the transmitter device 11 and the receiver device 12 perform parameter verification to determine the loss of the transmission line 10. The time interval between optical test pulse transmissions may be determined according to a pre-shared secret bit sequence. This ensures that potential eavesdroppers cannot distinguish the optical test pulse from the optical (signal) pulse. As a result, it is impossible for eavesdroppers to create additional permanent leakage constants or leakage targets for specific optical signal pulses and optical test pulses. By analyzing the optical test pulse, the knowledge of eavesdroppers regarding the optical signal pulse can be evaluated.
[0105] (c) Encoding Next, a third step 23 of encoding the encoder initial bit sequence into the intensity profile and / or phase profile of each of a plurality of optical (signal) pulses will be described in detail.
[0106] FIG. 4 shows a visual representation of an apparatus for preparing an optical pulse. The apparatus may correspond to the preparation device 11c of the transmitter device 11.
[0107] Each optical pulse is generated from the laser pulse of the laser 40 using a Mach-Zehnder (MZ) interferometer 41. The laser pulse (generated by the laser 40) has a time duration T s and a constant input optical power
Number
[0108] The MZ interferometer 41 may include a first phase modulator 43, a second phase modulator 45, a first beam splitter 42, and a second beam splitter 44. The laser pulse may pass through the first beam splitter 42, the first phase modulator 43, the second beam splitter 44, and the second phase modulator 45.
[0109] The first beam splitter 42 and the second beam splitter 44 are 50:50 beam splitters. The laser pulse is split into a first part and a second part at the first beam splitter 42 and recombined at the second beam splitter 44. The laser pulse is split again into a third part and a fourth part at the second beam splitter 44. The first part passes through the first phase modulator 43. The second part reaches the second beam splitter 44 directly. The third part is sent to the control detector 46. The fourth part passes through the second phase modulator 45 and is subsequently sent to the quantum channel 10a (as one of the optical pulses among a plurality of optical pulses). The detector 46 can monitor the proper preparation of the optical pulse.
[0110] The parameters of both phase modulators 43, 45 may be controlled in a timely manner to modulate the intensity profile and / or phase profile of the optical pulse.
[0111] Input state (0,γ) via the MZ interferometer 41 T (Conversion of (vacuum on one port and a pulse having a complex amplitude γ on the other port)) can be represented as follows.
[0112]
Number
[0113] Here,
Number
[0114]
Number
Number
Number
[0115]
Number
[0116] The intensity profile P line (with respect to the optical power) and the phase profile φ line (t) can be expressed as follows.
[0117]
Number
[0118] P γ represents the (constant) input optical power from the laser 40. For the intensity profile |F(t)| 2 with respect to the intensity, the intensity profile P line (t) =
Number
[0119]
Number
[0120] Here, the following is used.
[0121] [Number]
[0122] Since |cos(φ(t))| ≤ 1, for the input optical power P γ with respect to [Number] is applied. Therefore, the input optical power P γ is greater than the intensity profile (with respect to power) for each time t.
[0123] By compensating the first phase shift φ(t) and controlling the second phase shift ψ(t), a desired phase profile φ line (t) may be prepared.
[0124] In a specific example, the classical (first) bit of the encoder initial bit sequence is encoded only in the intensity profile. In this case, the phase profile may be time-dependent for each optical pulse, but may be the same for each first encoder value (i.e., independent of the first encoder value). Further, for each optical pulse, a single first bit is encoded. Therefore, for each optical pulse, the intensity function depends on the first encoder value of the (single) first bit of the encoder initial bit sequence).
[0125] The intensity profile with respect to the optical power for the first (bit) value a can be written as follows.
[0126] (P a (t) = P’ + P’’·cos(ζ a (t)), a ∈ {0,1} (7)
[0127] Here, ζ a (t) is a time-dependent function, which depends on / is determined by a, P’ is a constant (optical power) component, and P’’ is a modulation component, here the amplitude of the oscillating component. The function P’ + P’’·cos(ζ a(t)) may be considered as an intensity function whose intensity profile is modulated (up to a certain coefficient). By combining equations (4) and (7), that is, it is represented by the following equation.
[0128]
Number
[0129] The first phase shift φ(t) adopted (depending on the first encoder value a) may be determined as follows.
[0130]
Number
[0131] Here, (since |cos(φ_a(t))| ≤ 1) P γ ≥ P’ + P’’.
[0132] Figure 5 shows a plot of the intensity profile of the optical power as a function of time. The intensity profile for the first encoder value equal to 0 (a = 0) corresponds to the first time-dependent curve 50, and the intensity profile for the first encoder value equal to 1 (a = 1) corresponds to the second time-dependent curve 51.
[0133] When a = 0, the intensity profile can be represented as follows.
[0134]
Number
[0135] When a = 1, it is as follows.
[0136]
Number
[0137] Here, P’ = 10 -8W, P’’ = 10 -9 W, T s = 100 ns, f0 = 90 MHz, and f1 = 110 MHz. As can be seen from curves 50 and 51, when a = 0, the instantaneous frequency increases with time, while when a = 1, the instantaneous frequency decreases with time. The coefficients
Number
Number
[0138] (d) Measurement and Decoding Hereinafter, the measurement and decoding (step 25) of the optical pulses received by the receiver device 12 will be described in detail.
[0139] From the optical pulses, in the receiver device 12, a decoder initial bit sequence is determined. For this purpose, by measuring the intensity values of the optical pulses for a plurality of time bins, an approximate intensity profile of each optical pulse is determined. By using the approximate intensity profile, the (first decoder) value of the decoder initial bit sequence can be determined. Further, by measuring the phase values of the optical pulses for a plurality of time bins, an approximate phase profile of the optical pulses is determined. From the approximate phase profile, a further (second decoder) value of the decoder initial bit sequence can be determined.
[0140] Measuring the intensity value and / or the phase value may include performing a heterodyne measurement for each time bin. The heterodyne measurement includes splitting the received optical pulse into two beams that interfere with two further beams of a local oscillator (LO), and measuring the interference event using a photodiode detector.
[0141] When the phase of the local oscillator is made to coincide with the phase of the laser (where the optical pulse is generated), a continuous-wave optical pulse (of a constant intensity and phase) may be transmitted from the laser via an additional quantum channel (in parallel with the (modulated) optical pulse).
[0142] In the following example, the approximate intensity profile is determined without determining the approximate phase profile. Thus, the phase of the optical pulse may remain constant in time. Thus, there is no phase difference between different optical pulses and within one optical pulse. The intensity profile of each optical pulse of the plurality of optical pulses is modulated in the transmitter device 11 according to an intensity function that depends on time and on the first encoder value of the first bit of the encoder initial bit sequence. Further, the plurality of optical pulses are transmitted via the quantum channel 10a and received by the receiver device 12.
[0143] In the receiver device 12, a plurality of quantum measurements are performed such that a plurality of (average) photon numbers are determined for a plurality of time bins characterized by a time interval Δt. For each time interval Δt, an intensity value (i.e., the number of photons received during the time interval Δt) is determined. Thus, a discrete set of time values and corresponding photon numbers is determined (approximate / discretized intensity profile). From the approximate intensity profile, the intensity profile initially generated in the transmitter device 11 can be reconstructed with a certain accuracy, and thus the corresponding bit value can be estimated.
[0144] The intensity profiles may be generated such that their total energy remains constant for each of the plurality of optical pulses and for each of the possible bit values. That is, the total number of photons of each optical pulse is constant and is given by the following equation.
[0145]
Equation
[0146] Here, N a(t) represents the average number of photons of the optical pulse in the time interval [t, t + Δt] when the first (bit) value is a. Due to Poisson noise, the determined approximate intensity profile generally does not coincide with the ideal intensity profile. The number of photons measured in the time interval [t, t + Δt] for the bit value a can be expressed as follows.
[0147] [Number]
[0148] Here, n a (t) is a random variable related to noise. In the case of high signal intensity, n a (t) may be treated as a Gaussian random variable at all times t. According to the boson model of the optical amplifier, the resulting mean value and variance can be written as follows.
[0149] [Number]
[0150] Here, M is the number of optical amplifiers along the quantum channel 10a, and G is the amplification factor of one optical amplifier. Thus, M = D AB / d and G = 1 / T, where D AB is the distance between the transmitter device 11 and the receiver device 12, d is the distance between adjacent optical amplifiers, and T = 10 -0.02·d is the attenuation parameter of the optical fiber. The number of photons and the optical power P a (t) at time t with time discretization Δt are related as follows.
[0151] [Number]
[0152] Here, [Number] is the energy of one photon. To determine the (first decoder) value of one (first) bit of the decoder initial bit sequence in the receiver device 12, the approximate intensity profiles
Number
[0153] To establish the procedure for determining the first decoder value a, the correlation
Number
Number
Number
Number
[0154]
Number
[0155] Here, Σ t |N0(t)N1(t) is the normalization coefficient. Since the correlation can be expressed as a weighted sum of Gaussian variables, it may be treated as a Gaussian probability random variable. Therefore,
Number
[0156] [Mathematics]
[0157] Therefore, the correlation mean difference e a can be explicitly expressed as the sum of Gaussian random variables. Therefore, using Equation (15), the variance of the correlation difference ΔQ a is also the weighted sum of variances.
[0158] [Mathematics]
[0159] In summary, the correlation difference ΔQ a can be treated as a normal distribution random variable with an average value e a (Equation (18)), and a variance [Mathematics] (Equation (19)). Therefore, under the condition that the transmitted bit has the first encoder value a, the probability of the measurement result of the correlation difference ΔQ is as follows.
[0160] [Mathematics]
[0161] According to Bayes' law, the probability that the transmitted bit has the first encoder value a, given that the measurement correlation difference has the value ΔQ, can be written as follows.
[0162]
Number
[0163] For further selection and error correction procedures, the (first) threshold
Number
Number
Number
[0164]
Number
[0165]
Number
Number
[0166]
Number
[0167] The determined threshold
Number
[0168] Approximation intensity profile
Number
Number
[0169]
Number
[0170] If the measured correlation difference ΔQ is greater than the threshold value
Number
Number
[0171]
Number
[0172]
Number
[0173] In another example, if an approximate phase profile [Number] is determined, a second measured correlation difference ΔR = R (0) -R (1) can be determined in the same way from the measured phase values [Number] as follows.
[0174] [Number]
[0175] Furthermore, a second threshold value (as a reconstruction in the receiver device 12 of the second encoder value of the second bit from the transmitter device 11) is compared with a second decoder value of the second bit in order to determine the second decoder value of the second bit. [Number]
[0176] (e) Classical post - processing and key generation rate In this section, specific aspects of the classical post - processing steps (including error correction and privacy amplification after selection in steps 26 - 28) performed at the transmitter device 11 and / or the receiver device 12 are described in detail. During these steps, (further) classical information is exchanged between the transmitter device 11 and the receiver device 12.
[0177] In the post - selection step (step 26), measurement results that do not lead to information superiority for the eavesdropping device 13 are discarded by the receiver device 12.
[0178] In particular, the measurement result and / or value assignment of at least one first (second) bit of the decoder initial bit sequence is determined by determining whether the first (second) measured correlation difference ΔQ (ΔR) is greater than the first (second) selected parameter
number
number
number
[0179] Thus, for a single first bit of the decoder initial bit sequence, the assignment of a first decoder value may be performed as follows:
[0180]
number
number
number
[0181] Four values may be assigned in the same way. First (Second) Post-Selection Parameter
number
[0182] The normalized key generation rate after error correction and privacy amplification may be expressed as:
[0183]
number
[0184] Here, L is the length of the encoder initial bit sequence generated in the transmitter device 11. The expressions in Equation (27) and its constituent terms are derived in the following subsections.
[0185] FIG. 6 shows Equation (10) and Equation (11), that is, [Number] , [Number] , P’10 -8 W, P’’ = 10 -9 W, T s When the intensity profiles with = 100 ns, f0 = 90 MHz, and f1 = 110 MHz are adopted, the received signal r E (signal leakage value) as a function of the normalized key generation rate L f / L is plotted. The distance between the transmitter device 11 and the receiver device 12 is D AB = 1000 km.
[0186] The key generation rate is obtained by numerical optimization with respect to the post-selection parameter θ. For the considered signal leakage value r E , the optimal post-selection parameter θ is within the interval [0.08; 0.1]. These values are of the order of the difference between the correlation mean differences |e1 - e0|.
[0187] Derivation of the key generation rate Regarding the mutual information "I" (A:B) between the transmitter device 11 and the receiver device 12, the conditional probabilities p(0|a), p(1|a) of obtaining the bit value b ∈ {0, 1} when sending the bit a are determined as follows.
[0188] [Number] and
Number
[0189] Equations (28) and (29) can be combined as follows.
[0190]
Number
[0191] Therefore, the mutual information "I"(A:B) between the transmitter device 11 and the receiver device 12 is as follows.
[0192]
Number
[0193] Final result
Number
[0194]
Number
[0195] Here, H(X) is the Shannon entropy of system X, and h2(x)=-x·log2(x)-(1-x)·log2(1-x) is the binary entropy function.
[0196] When the LDPC code estimates the error probability for each bit independently instead of batch estimating the average error, it results in efficient error correction. In such a case, according to Equation (31), the mutual information "I"(A:B) between the transmitter device 11 and the receiver device 12 is as follows.
[0197]
Number
[0198] J0 and J1 can be introduced as follows.
[0199]
Number
Number
[0200] The mutual information "I" (A:B) takes the following form.
[0201] I(A:B) = 1 - J0 - J1(34)
[0202] Physical loss control (step 21) further restricts potential eavesdropping attacks that may go unnoticed, and the only option left for the eavesdropper is to create relatively small artificial signal leakage. The coefficient r in the quantum channel 10a near the transmitter device 11 E For the case of one leakage position with, the mutual information "I" (A:E) between the eavesdropping device 13 and the transmitter device 11 can be estimated as the Holevo quantity of the ensemble
Number
[0203]
Number
[0204] Here,
Number
[0205] From this, the final key generation rate after the error correction and privacy amplification procedures according to Equation (27)
Number
[0206] The scalar product |<α0|α1>| may be determined as follows.
[0207] Derivation of the Scalar Product (Time-dependent amplitude with intensity profile F(t) and carrier frequency Ω)
Number
[0208]
Number
[0209] Here, the integral is obtained over R or over the subspace {t|F(t)≠0}. Thus, ∫dt|f(t)| 2 = 1. The spectrum of the intensity profile considered can be found as the Fourier transform of the normalized amplitude f(t)e iΩt i.e., is given by the following equation.
[0210]
Number
[0211] The normalized intensity profile f(t) can define an optical quantum mode. The creation operator associated with the mode is given by the following equation.
[0212]
Number
[0213] Additional operators are introduced as follows.
[0214]
Number
[0215]
Number
[0216] The creation operator can be written as follows.
[0217]
Number
[0218] Creation operator
Number
Number
[0219]
Number
[0220] The coherent state |α> in mode f(t) is defined as the eigenstate of the corresponding annihilation operator.
[0221]
Number
[0222] α may be a non - negative real number. Thus, all information regarding the time - dependent phase of the pulse is contained in the complex - valued function f(t).
[0223] α 2 = |α| 2 = |α| 2 ·∫dt|f(t)| 2 = ∫dt|F(t)| 2 (45)
[0224] The scalar product of the Fock states in different modes f(t) and g(t) is calculated as follows.
[0225]
Number
[0226] Here, the sum is taken over all permutations σ of the set {1,..., n}. After integration, each of the n! components corresponding to different permutations contributes equally to the overall sum, which results in a coefficient of n!.
[0227] The scalar product of coherent states of different shapes (i.e., those of coherent states in different modes) can be calculated as follows.
[0228]
Number
[0229] Thus, the following equation holds.
[0230]
Number
[0231] Equation (48) describes the most general case. For each intensity profile F(t), G(t) at a fixed time t, since they are complex numbers, we can write them in terms of the absolute value and phase as F(t)=|F(t)|eiφF(t) and \(G(t) = |G(t)|e\) iφG(t) It may be represented by. For two modulation states that differ only in a constant phase coefficient and the average number of photons, an expression for the scalar product of the standard coherent states can be obtained.
[0232] Constant phase (\(\varphi\) F (t)=\(\varphi\) G (t) = constant, that is, the intensity profile \(|F(t)|\) 2 , \(|G(t)|\) 2 is the only time-dependent function), in an exemplary case, the scalar product is as follows.
[0233] \(|\langle\beta,g|\alpha,f\rangle|\) 2 =\(\exp\left(-\int dt\cdot\left\{|F(t)| - |G(t)|\right\}\right)\) (49) 2 )
[0234] Express the intensity profile not in terms of the photon number density \(|F(t)|\) at time 2 but as a term of the optical power \(P\) F (t) (energy density at time) (where
Number
Number
[0235]
Number
[0236] Equation (48) can alternatively be derived as follows. With real numbers \(\alpha\) and \(\beta\) and \(|\alpha|\) 2 =\(\int dt|F(t)|\) 2 and \(|\beta|\) 2 =\(\int dt|G(t)|\) 2 used, the two coherent states can be written as follows.
[0237] [Number]
[0238] Similarly, for e X+Y = e X e Y e -[X,Y] / 2 using it, the following is derived.
[0239] [Number]
[0240] Therefore, the commutator [Number] can be written as follows.
[0241] [Number]
[0242] e X+Y = e X e Y e -[X,Y] / 2 = e Y e X e [X,Y] / 2 using it, the scalar product <α,f|β,g> becomes as follows.
[0243] [Number]
[0244] (f) Comparison with phase encoding To explain the effectiveness of the proposed intensity / phase profile encoding method, the key generation rates of other encoding methods may be compared.
[0245] Plots of the key generation rate for phase encoding (for different values of the input optical power P (0.05 nW and 0.1 nW)) and for the proposed method (“shape encoding”) as a function of r E are shown in FIG. 7. The length of the quantum channel 10a is 1000 km, and the distance between adjacent optical amplifiers is 50 km. The value of the shape encoding corresponds to the value of d = 50 km in FIG. 6. As illustrated by FIG. 7, the proposed encoding method is more robust to an increase in the leakage value r E . Thus, with the proposed encoding method, legitimate users can utilize high-intensity quantum states with weak distinguishability.
[0246] In phase encoding, the optical pulses corresponding to different logical bits have different phases by π or alternatively by some other value. Here, both optical pulses have the same arbitrary intensity profile, which does not affect the security analysis.
[0247] Thus, a constant (time-independent) intensity profile may be considered for comparison. To generate such a state, it is not necessary to employ a Mach-Zehnder interferometer, and only one controllable phase modulator is needed. In the case of a phase difference of π, the scalar product of the quantum states intercepted by an eavesdropper (Equation (50)) is as follows.
[0248]
Equation
[0249] Here, the terms of the optical power are equal and time-independent: P0(t) = P1(t) = P. Here, it is assumed that the eavesdropping device 13 is in the quantum channel 10a close to the transmitter device 11. Thus, there is no additional correlation between the subsystems of the eavesdropping device 13 and the receiver device 12 caused by the optical amplifier. Thus, to estimate the intercepted information, the Holevo value of an ensemble of pure states may be employed. The error probability p err of the final result at the receiver device and the probability
Number
[0250]
Number
[0251] Here, θ is the post - selection parameter, and
Number
[0252] (g) Comparison with intensity encoding In intensity encoding, different logical bits are encoded into coherent states with different average numbers of photons (i.e., different average optical powers). Therefore, optical pulses corresponding to different bit values have the same temporal distribution of photons but different average numbers of photons.
[0253] Figure 8 shows plots of the key generation rate as a function of r for intensity encoding and for the proposed method ( "shape encoding"). The length of the quantum channel 10a is 1000 km and the distance between adjacent optical amplifiers is 50 km. The value of shape encoding corresponds to the value of d = 50 km in Figure 6. As shown in the figure, the proposed method provides an increased key generation rate for a given r E value. E
[0254] To prepare a quantum state using intensity encoding, the transmitting device 11 may control only the first phase shift φ(t). For the purpose of security analysis, it is sufficient to consider a rectangular pulse having a constant phase value of 0. After preparation, the pure quantum state passes through the quantum channel 11a equipped with an optical amplifier. Therefore, in the receiver device 12, the obtained quantum state is mixed.
[0255] [Number]
[0256] Here, |α a > is [Number] a coherent state with. To distinguish between the mixed states ρ0 and ρ1, in the receiver device 12, a simple intensity measurement can be performed. The photon number distribution may be approximated by a Gaussian distribution. Therefore, the random variable describing the result of the measurement in the receiver device 12 having the bit "a" has a normal distribution with the following parameters.
[0257] [Number]
[0258] Here, M represents the number of optical amplifiers along the quantum channel 10a, and G represents the amplification factor of each amplifier. The variable P 0(1) represents the average optical power of each signal. The discrete value N may be treated as a continuous value such that the probability density distribution describing the result of the measurement can be expressed as follows.
[0259] [Number]
[0260] Therefore, it becomes as follows.
[0261]
Number
[0262] This is equal to the following.
[0263]
Number
[0264] Without loss of generality, assuming e1 > e0, the error probability can be expressed as follows.
[0265]
Number
[0266] Here,
Number
[0267] Taking into account Equation (58), we obtain the following.
[0268]
Number
[0269] Similar to the previous section, the equation obtained for the probability of the final result is as follows.
[0270]
Number
[0271] Corresponding to Equations (31) and (32), the mutual information between the transmitter device 11 and the receiver device 12 can be calculated as follows.
[0272]
Number
[0273] To estimate the information of the eavesdropper, the scalar product of the intercepted quantum states is required, which is as follows for certain phase values and different average photon numbers.
[0274]
Number
[0275] In FIG. 8, values of different average powers
Number
[0276] The features disclosed in this specification, the figures and / or the claims may be materials for realizing various embodiments, which can be interpreted alone or in various combinations thereof.
Claims
1. An encoding method for quantum key distribution, the method being executed within a transmitter device (11) having a classical processor (11a) and means for preparing and transmitting quantum signals, the method comprising: generating an encoder initial bit sequence; generating a quantum signal comprising a plurality of optical pulses from the encoder initial bit sequence, wherein generating each optical pulse of the plurality of optical pulses comprises: modulating the intensity profile of the optical pulse according to an intensity function that depends on time and a first encoder value of at least one first bit of the encoder initial bit sequence; and modulating the phase profile of the optical pulse according to a phase function that depends on time and a second encoder value of at least one second bit of the encoder initial bit sequence, including at least one of the above; transmitting the plurality of optical pulses to a receiver device (12) via a quantum channel (10a); and determining a shared key shared between the transmitter device (11) and the receiver device (12) from the encoder initial bit sequence by means of classical post-processing and at least one of transmitting classical information to the receiver device (12) and receiving further classical information from the receiver device (12). An encoding method.
2. Each optical pulse is generated from a laser beam using a Mach-Zehnder interferometer (41). The encoding method according to claim 1.
3. The intensity profile is modulated by at least one of a first phase modulator and laser source intensity, and / or The phase profile is modulated by a second phase modulator. The encoding method according to claim 1 or 2.
4. The intensity function includes an oscillatory component having a time-dependent frequency depending on the first encoder value, and / or The phase function includes a further oscillatory component having a time-dependent frequency depending on the second encoder value. The encoding method according to claim 1 or 2.
5. The intensity function includes at least one of a frequency chirp component, preferably a linear frequency chirp component, a quadratic frequency chirp component, a cubic frequency chirp component, and an exponential frequency chirp component, depending on the first encoder value. The encoding method according to claim 1 or 2.
6. The intensity function depends on the first encoder value of at least two first bits of the encoder initial bit sequence, and / or the phase function depends on the second encoder value of at least two second bits of the encoder initial bit sequence. The encoding method according to claim 1 or 2.
7. Each optical pulse has a pulse length of 1 ns to 1000 ns, preferably 50 ns to 200 ns, more preferably 80 ns to 120 ns. The encoding method according to claim 1 or 2.
8. A decoding method for quantum key distribution, the method being executed in a receiver device (12) having a classical processor (12a) and means for receiving and measuring a quantum signal, the method comprising: Receiving a quantum signal including a plurality of optical pulses from a transmitter device (11) via a quantum channel (10a); Determining a decoder initial bit sequence from the plurality of optical pulses, the determining being for each optical pulse: Determining an approximate intensity profile of the optical pulse by measuring a plurality of intensity values of the optical pulse for a plurality of time bins, and determining a first decoder value of at least one first bit of the decoder initial bit sequence from the approximate intensity profile; Determining an approximate phase profile of the optical pulse by measuring a plurality of phase values of the optical pulse for a plurality of time bins, and determining a second decoder value of at least one second bit of the decoder initial bit sequence from the approximate phase profile, including at least one of: Determining a shared key shared between the transmitter device (11) and the receiver device (12) from the decoder initial bit sequence by at least one of classical post-processing and receiving classical information from the transmitter device (11) and transmitting further classical information to the transmitter device (11). Decoding method.
9. Determining the first decoder value includes comparing the approximate intensity profile with an ideal approximate intensity profile, and / or Determining the second decoder value includes comparing the approximate phase profile with an ideal approximate phase profile, The decoding method according to claim 8.
10. Determining a first measured correlation difference from the approximate intensity profile and the ideal approximate intensity profile, and determining the first decoder value by comparing the first measured correlation difference with a first threshold; Determining a second measured correlation difference from the approximate phase profile and the ideal approximate phase profile, and determining the second decoder value by comparing the second measured correlation difference with a second threshold, including at least one of: The decoding method according to claim 9.
11. Further including determining the optical signal loss along the quantum channel (10a), preferably the optical signal loss depending on the position along the quantum channel (10a), The decoding method according to any one of claims 8 to 10.
12. A method for quantum key distribution, the method comprising: A transmitter device (11) having a classical processor (11a) and means for modulating and transmitting a quantum signal; A receiver device (12) having a further classical processor (12a) and means for receiving and measuring a quantum signal Executed within a system comprising: The method comprising: Generating an encoder initial bit sequence within the transmitter device (11); Generating a quantum signal including a plurality of optical pulses within the transmitter device (11) from the encoder initial bit sequence, wherein generating each optical pulse of the plurality of optical pulses Modulating the intensity profile of the optical pulse according to an intensity function that depends on time and a first encoder value of at least one first bit of the encoder initial bit sequence; Modulating the phase profile of the optical pulse according to a phase function that depends on time and a second encoder value of at least one second bit of the encoder initial bit sequence, including at least one of: Transmit the plurality of optical pulses from the transmitter device (11) to the receiver device (12) via the quantum channel (10a) and receive the plurality of optical pulses within the receiver device (12); Determining a decoder initial bit sequence from the plurality of optical pulses, wherein the determining is, for each optical pulse, Determining an approximate intensity profile of the optical pulse by measuring a plurality of intensity values of the optical pulse for a plurality of time bins, and determining a first decoder value of at least one first bit of the decoder initial bit sequence from the approximate intensity profile; Determining an approximate phase profile of the optical pulse by measuring a plurality of phase values of the optical pulse for a plurality of time bins, and determining a second decoder value of at least one second bit of the decoder initial bit sequence from the approximate phase profile, including at least one of: Determining a shared key shared between the transmitter device (11) and the receiver device (12) by classical post-processing within the transmitter device (11) from the encoder initial bit sequence and within the receiver device (12) from the decoder initial bit sequence, and transmitting classical information from the transmitter device (11) to the receiver device (12), and transmitting further classical information from the receiver device (12) to the transmitter device (11), including at least one of: Method.
13. A transmitter device (11) for quantum key distribution, comprising a classical processor (11a) and means for modulating and transmitting a quantum signal, the following steps, namely, Generating an encoder initial bit sequence; Generating a quantum signal including a plurality of optical pulses from the encoder initial bit sequence, wherein generating each optical pulse of the plurality of optical pulses is Modulating the intensity profile of the optical pulse according to an intensity function that depends on time and a first encoder value of at least one first bit of the encoder initial bit sequence; modulating the phase profile of the optical pulse according to a phase correlation function that depends on time and a second encoder value of at least one second bit of the encoder initial bit sequence, and generating, including at least one of the above; transmitting the plurality of optical pulses to a receiver device (12) via a quantum channel (10a); determining a shared key shared between the transmitter device (11) and the receiver device (12) from the encoder initial bit sequence by at least one of classical post-processing and transmitting classical information to the receiver device (12) and receiving further classical information from the receiver device (12), and being configured to perform; Transmitter device (11).
14. A receiver device (12) for quantum key distribution, comprising a classical processor (12a) and means for receiving and measuring a quantum signal, the following steps: receiving a quantum signal including a plurality of optical pulses from a transmitter device (11) via a quantum channel (10a); determining a decoder initial bit sequence from the plurality of optical pulses, the determining being for each optical pulse; determining an approximate intensity profile of the optical pulse by measuring a plurality of intensity values of the optical pulse for a plurality of time bins, and determining a first decoder value of at least one first bit of the decoder initial bit sequence from the approximate intensity profile; determining an approximate phase profile of the optical pulse by measuring a plurality of phase values of the optical pulse for a plurality of time bins, and determining a second decoder value of at least one second bit of the decoder initial bit sequence from the approximate phase profile, including at least one of the above, determining; determining a shared key shared between the transmitter device (11) and the receiver device (12) from the decoder initial bit sequence by at least one of classical post-processing and receiving classical information from the transmitter device (11) and transmitting further classical information to the transmitter device (11); being configured to perform; Receiver device (12).
15. A system for quantum key distribution, comprising a transmitter device (11) having a classical processor (11a) and means for preparing and transmitting a quantum signal, a receiver device (12) having a further classical processor (12a) and means for receiving and measuring a quantum signal, wherein the system performs the following steps, namely: generating an encoder initial bit sequence within the transmitter device (11); generating a quantum signal comprising a plurality of optical pulses within the transmitter device (11) from the first initial bit sequence, wherein generating each optical pulse of the plurality of optical pulses comprises modulating the intensity profile of the optical pulse according to an intensity function that depends on time and a first encoder value of at least one first bit of the encoder initial bit sequence; modulating the phase profile of the optical pulse according to a phase function that depends on time and a second encoder value of at least one second bit of the encoder initial bit sequence, transmitting the plurality of optical pulses from the transmitter device (11) to the receiver device (12) via a quantum channel (10a) and receiving the plurality of optical pulses within the receiver device (12); determining a decoder initial bit sequence from the plurality of optical pulses, wherein determining comprises determining an approximate intensity profile of the optical pulse by measuring a plurality of intensity values of the optical pulse for a plurality of time bins and determining a first decoder value of at least one first bit of the decoder initial bit sequence from the approximate intensity profile; determining an approximate phase profile of the optical pulse by measuring a plurality of phase values of the optical pulse for a plurality of time bins and determining a second decoder value of at least one second bit of the decoder initial bit sequence from the approximate phase profile, wherein determining comprises at least one of the above. Determining a shared key shared between the transmitter device (11) and the receiver device (12) by at least one of: within the transmitter device (11) from the encoder initial bit sequence and within the receiver device (12) from the decoder initial bit sequence by classical post-processing, and transmitting classical information from the transmitter device (11) to the receiver device (12), and transmitting further classical information from the receiver device (12) to the transmitter device (11). System.
Citation Information
Patent Citations
Data transmission apparatus and data reception apparatus
JP2007020159A
Communication equipment in optical communication system, and interferometer synchronization control method thereof
JP2011188043A
Method and system for quantum key distribution
JP2022115095A
Method and system for quantum key distribution
JP2022126613A
Optical transmitter and modulation timing correctness / incorrectness determination method
WO2021250829A1