Quantum cipher receiver, quantum cipher communication system, and quantum cipher reception method

The quantum cryptography receiver equalizes detection probabilities across multiple single-photon detectors using beam splitters and logical OR elements, addressing eavesdropping risks in quantum key distribution systems.

JP2025134227APending Publication Date: 2025-09-17HOKKAIDO UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024031995
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-04
Publication Date
2025-09-17

AI Technical Summary

Technical Problem

Conventional quantum key distribution systems face variations in detection probability among single-photon detectors due to manufacturing differences, leading to potential eavesdropping risks.

Method used

A quantum cryptography receiver design that utilizes a decoder to distribute photons to multiple single-photon detectors, with beam splitters and logical OR elements to equalize detection probabilities, minimizing variations and enhancing security.

Benefits of technology

The design securely receives quantum keys by reducing detection probability differences, thereby minimizing the risk of eavesdropping.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025134227000001_ABST
    Figure 2025134227000001_ABST
Patent Text Reader

Abstract

To provide a quantum cipher receiver capable of safely receiving a quantum key, a quantum cipher communication system, and a quantum cipher reception method.SOLUTION: A quantum cipher receiver 30 comprises: a decryption section 5 for receiving a photon, to which a binarized bit is allocated, and distributing a 0-value photon in a quantum state corresponding to a 0-value and a 1-value photon in a quantum state corresponding to a 1-value respectively to a first output port 55 and a second output port 57; a first photon detection section 61 for detecting the 0-value photon in the first output port 55 and generating a 0-value signal; a second photon detection section 62 for detecting the 1-value photon in the second output port 57 and generating a 1-value signal; and a control section 7 for reproducing the binarized bit on the basis of the 0-value signal and the 1-value signal. Each of the first photon detection section 61 and the second photon detection section 62 includes a plurality of single photon detectors.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a quantum cryptography receiver, a quantum cryptography communication system, and a quantum cryptography reception method. [Background technology]

[0002] Conventionally, quantum cryptography communication systems for transmitting information securely in terms of information theory have been known (see, for example, Patent Document 1). In a quantum cryptography communication system, a sender of information transmits an encryption key to a receiver by quantum key distribution (QKD) using photons. This allows the sender and receiver to share information related to the encryption key without it being obtained (eavesdropped) by a third party. The sender encrypts information to be transmitted to the receiver using the encryption key. The sender then transmits the encrypted information to the receiver by any communication means. The receiver decrypts the encrypted information using the encryption key.

[0003] In quantum key distribution, if a third party eavesdrops on information about the encryption key from photons, the quantum state of the photons changes due to the uncertainty principle, leaving traces of the eavesdropping, allowing the sender and receiver to reliably detect the eavesdropping.

[0004] In a quantum key distribution system, a photon detector may be used at the receiver side to detect transmitted photons and generate binary bits (0 or 1) in a bit string that forms the encryption key. The photon detector may include, for example, one or more single-photon detectors, each generating a bit. The single-photon detectors are gated with a gate pulse time from a controller to synchronize the detection of optical pulses with the predicted pulse arrival time (see, for example, Patent Document 2). [Prior art documents] [Patent documents]

[0005] [Patent Document 1] International Publication No. 2017 / 135444 [Patent Document 2] International Publication No. 2005 / 057823 Summary of the Invention [Problem to be solved by the invention]

[0006] The single-photon detectors used in the conventional quantum key distribution described above have a detection probability that varies depending on the arrival time. The detection probability at a given arrival time of a single-photon detector may vary from one single-photon detector to another due to, for example, manufacturing variations in the single-photon detectors. This variation in detection probability among multiple single-photon detectors may lead to the possibility of eavesdropping. Therefore, there is a demand for a quantum cryptography receiver that can suppress the variation in detection probability among single-photon detectors and securely receive quantum keys.

[0007] The present disclosure provides a quantum cryptography receiver, a quantum cryptography communication system, and a quantum cryptography reception method that can securely receive a quantum key. [Means for solving the problem]

[0008] The gist of the present disclosure is as follows.

[0009] [1] A quantum cryptography receiver comprising: a decoder that receives photons assigned with binary bits, and distributes 0-value photons in a quantum state corresponding to a value of 0 and 1-value photons in a quantum state corresponding to a value of 1 to a first output port and a second output port, respectively; a first photon detector that detects the 0-value photons at the first output port and generates a 0-value signal; a second photon detector that detects the 1-value photons at the second output port and generates a 1-value signal; and a controller that reproduces the binary bits based on the 0-value signal and the 1-value signal, wherein each of the first photon detector and the second photon detector includes a plurality of single-photon detectors.

[0010] In the quantum cryptography receiver, the temporal distribution of the detection probability of a zero-value photon in the first photon detection unit is equal to the average of the detection probabilities of each of the multiple single-photon detectors. Similarly, the detection probability of a one-value photon in the second photon detection unit is equal to the average of the detection probabilities of each of the multiple single-photon detectors. This makes it possible to reduce the difference between the detection probability in the first photon detection unit and the detection probability in the second photon detection unit compared to when the first photon detection unit and the second photon detection unit are each composed of one single-photon detector. Therefore, it is possible to suppress the variation in the detection probability in the single-photon detectors and receive the quantum key securely.

[0011] [2] The quantum cryptography receiver according to [1], wherein the first photon detecting unit includes a first single-photon detector and a second single-photon detector as the plurality of single-photon detectors, the second photon detecting unit includes a third single-photon detector and a fourth single-photon detector as the plurality of single-photon detectors, the first photon detecting unit combines a signal generated by the first single-photon detector and a signal generated by the second single-photon detector to output the signal of value 0 to the control unit, and the second photon detecting unit combines a signal generated by the third single-photon detector and a signal generated by the fourth single-photon detector to output the signal of value 1 to the control unit. In this case, a simple configuration in which each of the first photon detecting unit and the second photon detecting unit is composed of two single-photon detectors can minimize the difference between the detection probability in the first photon detecting unit and the detection probability in the second photon detecting unit.

[0012] [3] The quantum cryptography receiver according to [2], wherein the first photon detector outputs to the control unit a logical sum of the signal generated by the first single-photon detector and the signal generated by the second single-photon detector, and the second photon detector outputs to the control unit a logical sum of the signal generated by the third single-photon detector and the signal generated by the fourth single-photon detector. In this case, the first photon detector outputs a signal when at least one of the first single-photon detector and the second single-photon detector generates a signal with a value of 0. Similarly, the second photon detector outputs a signal when at least one of the third single-photon detector and the fourth single-photon detector generates a signal with a value of 1. This allows the first photon detector and the second photon detector to output signals efficiently.

[0013] [4] The quantum cryptography receiver according to any one of [1] to [3], wherein the first photon detection unit further includes a first beam splitter that splits the zero-value photons toward the first single-photon detector and the second single-photon detector, and the second photon detection unit further includes a second beam splitter that splits the one-value photons toward the third single-photon detector and the fourth single-photon detector. In this case, the first beam splitter splits the zero-value photons into equal light intensities and outputs them to the first single-photon detector and the second single-photon detector. Similarly, the second beam splitter splits the one-value photons into equal light intensities and outputs them to the third single-photon detector and the fourth single-photon detector. This allows photons to be detected accurately in each of the first photon detection unit and the second photon detection unit.

[0014] [5] The quantum cryptography receiver according to any one of [1] to [4], wherein each of the plurality of single-photon detectors is a single-photon detection avalanche photodiode. In this case, the single-photon detection avalanche photodiode is driven in a high-sensitivity state at the timing when the photon train reaches the single-photon detector by a gate signal synchronized with the timing, which makes it easier to further suppress variations in detection probability.

[0015] [6] The quantum cryptography receiver according to [2] or [3], wherein the single-photon detectors applied to the first single-photon detector, the second single-photon detector, the third single-photon detector, and the fourth single-photon detector are such that the difference between the average value of the detection efficiencies of the first single-photon detector and the second single-photon detector and the average value of the detection efficiencies of the third single-photon detector and the fourth single-photon detector is minimized. In this case, the mutual information can be kept low, thereby reducing the possibility of eavesdropping.

[0016] [7] A quantum cryptography communication system comprising: the quantum cryptography receiver according to any one of [1] to [6]; a semiconductor laser device that generates laser light including the photons; an interferometer that divides the laser light into double pulses that are coherent with each other; a quantum cryptography transmitter that includes a coding unit that assigns the binarized bits to the photons; and an optical fiber that propagates the photons to which the binarized bits are assigned from the quantum cryptography transmitter to the quantum cryptography receiver. A quantum cryptography communication system can be suitably configured by a quantum cryptography receiver that achieves the above-mentioned effects.

[0017] [8] A quantum cryptography receiving method comprising the steps of receiving photons to which binary bits are assigned, and distributing 0-value photons in a quantum state corresponding to a value of 0 and 1-value photons in a quantum state corresponding to a value of 1 to a first output port and a second output port, respectively; detecting the 0-value photons at the first output port and generating a 0-value signal; detecting the 1-value photons at the second output port and generating a 1-value signal; and regenerating the binary bits based on the 0-value signal and the 1-value signal, wherein the 0-value photons are detected using a plurality of single-photon detectors in the 0-value signal generating step, and the 1-value photons are detected using a plurality of single-photon detectors in the 1-value signal generating step.

[0018] In the quantum cryptography receiving method, the time distribution of the detection probability of a 0-value photon in the step of generating a 0-value signal is equal to the average of the detection probabilities of each of the multiple single-photon detectors. Similarly, the detection probability of a 1-value photon in the step of generating a 1-value signal is equal to the average of the detection probabilities of each of the multiple single-photon detectors. This makes it possible to suppress variations in the detection probability in the single-photon detectors and receive the quantum key securely. [Effects of the Invention]

[0019] According to one exemplary embodiment, there are provided a quantum cryptography receiver, a quantum cryptography communication system, and a quantum cryptography reception method that are capable of securely receiving a quantum key. [Brief explanation of the drawings]

[0020] [Figure 1] FIG. 1 is a schematic diagram showing the functional configuration of a quantum cryptography communication system including a quantum cryptography receiver according to an embodiment of the present disclosure. [Figure 2] Figure 2(a) shows the quantum state of a photon when it is assigned the Z basis and a value of 0. Figure 2(b) shows the quantum state of a photon when it is assigned the Z basis and a value of 1. Figure 2(c) shows the quantum state of a photon when it is assigned the X basis and a value of 0. Figure 2(d) shows the quantum state of a photon when it is assigned the X basis and a value of 1. [Figure 3] FIG. 3 is a block diagram showing an example of the first photon detector. [Figure 4] FIG. 4 is a block diagram showing an example of the second photon detector. [Figure 5] FIG. 5 is a diagram illustrating an example of a time shift attack. [Figure 6] FIG. 6 is a block diagram showing a photon detector according to a comparative example. [Figure 7] FIG. 7 is a graph showing an example of response characteristics of a detector sample applied to the photon detector in each quantum cryptography receiver. [Figure 8]8(a) shows the calculation results of the mutual information amount in the quantum cryptography receiver of the comparative example, and FIG. 8(b) shows the calculation results of the mutual information amount in the quantum cryptography receiver of the first embodiment. [Figure 9] 9(a) shows the calculation results of the mutual information amount in the quantum cryptography receiver of Example 2. FIG. 9(b) shows the calculation results of the mutual information amount in the quantum cryptography receiver of Example 3. [Figure 10] FIG. 10 is a diagram showing the relationship between the transmission distance of the encryption key information and the encryption key generation rate. [Figure 11] FIG. 11 is a schematic diagram showing the functional configuration of a quantum cryptography communication system including a quantum cryptography receiver according to a modified example. DETAILED DESCRIPTION OF THE INVENTION

[0021] Various exemplary embodiments will be described in detail below with reference to the drawings, in which the same or equivalent parts are designated by the same reference numerals.

[0022] [Configuration of quantum cryptography communication system] Fig. 1 is a schematic diagram showing the functional configuration of a quantum cryptography communication system 100 including a quantum cryptography receiver according to an embodiment of the present disclosure. As shown in Fig. 1, the quantum cryptography communication system 100 includes a quantum cryptography transmitter 10, an optical transmission path 20 including an optical fiber or the like, and a quantum cryptography receiver 30. The quantum cryptography communication system 100 is a system in which information related to an encryption key (hereinafter referred to as "encryption key information") is shared between the quantum cryptography transmitter 10 and the quantum cryptography receiver 30 without being intercepted by a third party. In other words, the encryption key information shared by the quantum cryptography communication system 100 allows information to be transmitted (hereinafter referred to as "message") to be encrypted and transmitted in an information-theoretically secure manner.

[0023] The quantum cryptography transmitter 10 generates a random number sequence and obtains an encryption key to be used for encrypting a message based on the generated random number sequence. The quantum cryptography transmitter 10 also assigns encryption key information to photons and outputs the photons to an optical transmission path 20. The encrypted message is transmitted by any communication means, such as the Internet. The optical transmission path 20 transmits the photons from the quantum cryptography transmitter 10 to a quantum cryptography receiver 30. The quantum cryptography receiver 30 obtains the encryption key from the encryption key information contained in the photons input from the optical transmission path 20.

[0024] The quantum cryptography transmitter 10 comprises a semiconductor laser device 1, an interferometer 2, an encoding unit 3, and a random number source 4. The random number source 4 is not limited to a specific configuration as long as it can generate physical random numbers that are information theoretically unpredictable and can generate a random number sequence at a generation speed of, for example, several Gb / s or more. The random number source 4 is provided independently of the semiconductor laser device 1 and the interferometer 2.

[0025] The semiconductor laser device 1 performs pulse oscillation and repeatedly generates pulsed laser light L in which the phase of each pulse is random. The semiconductor laser device 1 repeatedly generates pulsed laser light, for example, at the clock frequency of a synchronization signal shared by the quantum cryptography transmitter 10 and the quantum cryptography receiver 30. The figure shows an example of pulsed laser light L generated at timings that differ from each other by one clock. The semiconductor laser device 1 inputs the pulsed laser light L to an interferometer 2.

[0026] The interferometer 2 splits each pulsed laser beam L into a mutually coherent double pulse (a pair of pulses). The interferometer 2 is configured, for example, by an asymmetric Mach-Zehnder interferometer. The interferometer 2 has an input end 21, an output end 22, and a first transmission line 23 and a second transmission line 24 connecting the input end 21 and the output end 22. The transmission line length of the first transmission line 23 is longer than the transmission line length of the second transmission line 24. The interferometer 2 further has a first port 25 connected to the input end 21 side and a second port 26 connected to the output end 22 side. The semiconductor laser device 1 is connected to the upstream side of the first port 25. Meanwhile, the encoding unit 3 is connected to the downstream side of the second port 26. In the example of FIG. 1, the interferometer 2 has ports other than the first port 25 and the second port 26 on the input end 21 side and the output end 22 side, respectively, but nothing is connected to these ports.

[0027] The pulsed laser light L generated by the semiconductor laser device 1 reaches the input end 21 via the first port 25 and is split into a double pulse consisting of a pulse that propagates through the first transmission line 23 and a pulse that propagates through the second transmission line 24. The pulses that make up the double pulse are separated in time and space while maintaining coherence with each other. Each pulse reaches the output end 22 and is output to the encoding unit 3 via the second port 26.

[0028] The encoding unit 3 includes an intensity modulation unit 31, a state generation unit 32, and an attenuation unit 33. The encoding unit 3 randomly modulates the optical intensity (i.e., the average number of photons) and phase of the pulsed laser light forming the double pulse to generate a pulsed laser light for transmission. The encoding unit 3 outputs the generated pulsed laser light for transmission to the optical transmission line 20. The intensity modulation unit 31 may be a known modulator used in ordinary optical communications. For example, the intensity modulation unit 31 may be a Mach-Zehnder modulator using lithium niobate (LN:LiNbO3) crystal. When the pulsed laser light L forming the double pulse is input, the intensity modulation unit 31 modulates the optical intensity so as to obtain a desired average number of photons that is randomly selected based on the random number generated by the random number source 4. The intensity modulation unit 31 modulates the optical intensity so as to obtain the desired average number of photons, combined with the attenuation amount of the optical intensity by the attenuation unit 33.

[0029] A known phase modulator, for example, can be used as the state generator 32. When the pulsed laser light L constituting the double pulse is input, the state generator 32 modulates the phase of the pulsed laser light L constituting the double pulse so that the quantum state is randomly selected based on a random number generated by a random number source 4. In addition, the polarization of one of the double pulses is rotated by 90 degrees using, for example, a known polarization modulator. Here, as a basis for describing the quantum state of the pulsed laser light L constituting the double pulse, the quantum state of the pulse that is transmitted first is written as |0>, and the quantum state of the pulse that is transmitted later is written as |1>.

[0030] When the decoy BB84 protocol is used in quantum key distribution, the X basis, Z basis, or Y basis is selected as the basis assigned to each photon constituting the pulsed laser light L. The Z basis includes a horizontally or vertically polarized state consisting of one of the double pulses. The two states constituting the Z basis are denoted as |0> and |1>. The X basis uses both double pulses and includes a state in which the mutual phase difference is 0 degrees and a state in which the mutual phase difference is 180 degrees. The Y basis uses both double pulses and includes a state in which the mutual phase difference is 90 degrees and a state in which the mutual phase difference is -90 degrees. In this case, as an example of a state required for the decoy BB84 protocol, the state corresponding to the X basis is expressed by the following equations (1) and (2). The state corresponding to the Y basis is expressed by equations (3) and (4).

number

number

number

number

[0031] The encoding unit 3 randomly modulates the quantum state of the pulsed laser light L constituting the double pulse, and assigns a binary bit of 0 or 1 to each photon constituting the pulsed laser light L. At this time, each bit is described by a basis selected randomly from either the X basis or the Y basis. The quantum cryptography transmitter 10 may record the bit and basis assigned to each photon by the encoding unit 3, for example, in a recording unit (not shown).

[0032] FIG. 2 is a diagram showing an example of a basis and a quantum state of a binarized bit assigned to each photon. In FIG. 2, as an example, a quantum state in the Z basis and a quantum state in the X basis are shown, and the quantum state in the Y basis is not shown. In FIGS. 2(a) to 2(d), the horizontal axis represents time, and the vertical axis represents optical amplitude. FIG. 2(a) shows the quantum state of a photon when the Z basis and a bit value of 0 (value 0) are assigned. This is shown as quantum state Z0. FIG. 2(b) shows the quantum state of a photon when the Z basis and a bit value of 1 (value 1) are assigned. This is shown as quantum state Z1. When a photon is in quantum state Z0, it may be transmitted earlier on the time axis than when the photon is in quantum state Z1. FIG. 2(c) shows the quantum state of a photon when the X basis and a value 0 are assigned. This quantum state corresponds to Equation (1) and is shown as quantum state X0. FIG. 2(d) shows the quantum state of a photon when the X basis and a value 1 are assigned. This quantum state corresponds to equation (2) and is illustrated as quantum state X1. When the photon is in quantum state X0, the phase of the photon component that makes up |0> and the phase of the photon component that makes up |1> are both equal. On the other hand, when the photon is in quantum state X1, the phase of the photon component that makes up |0> and the phase of the photon component that makes up |1> are 180 degrees apart. Similarly, the quantum state of the photon when the Y basis and a value of 0 are assigned is the quantum state Y0, which corresponds to equation (4). The quantum state of the photon when the Y basis and a value of 1 are assigned is the quantum state Y1, which corresponds to equation (3). When the photon is in quantum state Y0, the phase of the photon component that makes up |0> and the phase of the photon component that makes up |1> are -90 degrees apart, whereas when the photon is in quantum state Y1, the phase of the photon component that makes up |0> and the phase of the photon component that makes up |1> are 90 degrees apart.

[0033] The semiconductor laser device 1 repeatedly generates pulsed laser light L. Therefore, the encoding unit 3 generates a photon sequence L1 in which each bit, binarized as 0 or 1, is randomly arranged. This photon sequence L1 is the source of the encryption key.

[0034] The quantum cryptography communication system 100 performs the key distillation process described below on an encryption key. The quantum cryptography transmitter 10 transmits a photon sequence L1, which is the source of the encryption key, to the quantum cryptography receiver 30. Due to transmission losses, only a portion of the transmitted photon sequence L1 reaches the quantum cryptography receiver 30. The quantum cryptography receiver 30 includes a decryption unit 5, a photon detection unit 6, a control unit 7, and a random number source 8. The random number source 8 is not limited to a specific configuration as long as it can generate physical random numbers that are information-theoretically unpredictable and can generate a random number sequence at a generation speed of, for example, several Gb / s or more.

[0035] Based on the received photon sequence L1, the decryption unit 5 sorts photons constituting each bit of the bit sequence that is the source of the encryption key according to their bit values, and then outputs them to the photon detection unit 6. In the example of FIG. 1 , the decryption unit 5 has an input terminal 50, an output terminal 51, and a first transmission line 52 and a second transmission line 53 that connect the input terminal 50 and the output terminal 51. The transmission line length of the first transmission line 52 is longer than the transmission line length of the second transmission line 53. The decryption unit 5 further has a first input port 56 connected to the input terminal 50, and a first output port 55 and a second output port 57 connected to the output terminal 51. The optical transmission line 20 is connected to the upstream side of the first input port 56. Meanwhile, the photon detection unit 6 is connected to the downstream side of the first output port 55 and the downstream side of the second output port 57.

[0036] The decoding unit 5 includes, for example, a phase modulator, which is provided on the transmission path of the second transmission path 53. In this case, the phase modulator modulates the phase of the photon sequence L1 so that a basis is randomly selected based on, for example, a random number generated by the random number source 8. The input terminal 50 is provided with, for example, a polarizing beam splitter. The photon components constituting |0> are reflected by, for example, the polarizing beam splitter and propagate through the first transmission path 52. The polarization of the photon components propagating through the first transmission path 52 is rotated 90 degrees at the end of the first transmission path 52. This can be achieved, for example, by the decoding unit 5 being composed of a polarization-maintaining fiber and the end of the polarization-maintaining fiber being twisted 90 degrees from the axial direction. The photon components constituting |1> are transmitted through, for example, the polarizing beam splitter and propagate through the second transmission path 53. The photon components constituting |1> are phase-modulated to a predetermined phase value by the phase modulator while propagating through the second transmission path 53. An optical dividing element such as a beam splitter is provided at the output end 51. The optical dividing element, for example, causes interference between a photon component propagating through the first transmission path 52 and a photon component propagating through the second transmission path 53, and outputs the interfered photon component from the first output port 55 or the second output port 57.

[0037] For example, the photon allocation operation in the decoding unit 5 is performed as follows. As shown in FIG. 2( c), when photons in quantum state X0 including a photon component constituting |0> and a photon component constituting |1> are targeted, the decoding unit 5 propagates the photon component constituting |0> among the photons in quantum state X0 to the first transmission line 52. At the same time, the decoding unit 5 propagates the photon component constituting |1> among the photons in quantum state X0 to the second transmission line 53. Then, the decoding unit 5 causes the photon component propagated through the first transmission line 52 and the photon component propagated through the second transmission line 53 to interfere with each other in the optical splitter element, and outputs the photon components that have constructively interacted as a result of the interference from the first output port 55.

[0038] Similarly, as shown in FIG. 2(d), in the case of a photon in quantum state X1 including a photon component constituting |0> and a photon component constituting |1>, the decoding unit 5 causes the photon component propagating through the first transmission path 52 and the photon component propagating through the second transmission path 53 to interfere with each other in the optical splitting element, and outputs the photon component that has been reinforced as a result of the interference from the second output port 57.

[0039] When photons in quantum state Y0 including a photon component constituting |0> and a photon component constituting |1> are targeted, the decoding unit 5 propagates the photon component constituting |0> among the photons in quantum state Y0 to the first transmission line 52. At the same time, the decoding unit 5 propagates the photon component constituting |1> among the photons in quantum state Y0 to the second transmission line 53, while simultaneously adding a phase of 90 degrees. Then, the decoding unit 5 causes the photon component propagated through the first transmission line 52 and the photon component propagated through the second transmission line 53 to interfere with each other in the optical splitter element, and outputs the photon component that has constructively interfered as a result of the interference from the first output port 55. When targeting photons in quantum state Y1 including photon components constituting |0> and photon components constituting |1>, the decoding unit 5 causes the photon components that have propagated through the first transmission path 52 and the photon components that have propagated through the second transmission path 53 and have a phase difference of 90 degrees to interfere with each other in the optical splitting element, and outputs the photon components that have reinforced each other as a result of the interference from the second output port 57.

[0040] The photon detector 6 has a first photon detector 61 and a second photon detector 62. The first photon detector 61 is connected to the first output port 55. The first photon detector 61 receives as input a photon component generated by the decoding unit 5 based on a photon in quantum state X0 or quantum state Y0. The first photon detector 61 detects a photon with a value of 0 at the first output port 55 and generates a signal with a value of 0. The second photon detector 62 is connected to the second output port 57. The second photon detector 62 receives as input a photon component generated by the decoding unit 5 based on a photon in quantum state X1 or quantum state Y1. The second photon detector 62 detects a photon with a value of 1 at the second output port 57 and generates a signal with a value of 1. The photon detector 6 outputs the signals generated in the first photon detector 61 and the second photon detector 62 to the controller 7.

[0041] The control unit 7 reproduces the binarized bits based on the 0-value signal and the 1-value signal. As a result, each binarized bit of 0 or 1 is generated in the control unit 7. That is, a part of the bit string generated in the encoding unit 3 is reproduced in the control unit 7. Based on the reproduced information, the control unit 7 may record the bit and basis assigned to each photon in, for example, a recording unit (not shown). Thereafter, the control unit 7 notifies the quantum cryptography transmitter 10 of information regarding which photon detection unit detected the photon. Then, the bit string reproduced in the quantum cryptography receiver 30 is used as the raw key.

[0042] Next, the quantum cryptography transmitter 10 performs basis matching. That is, the quantum cryptography transmitter 10 matches the basis used in the quantum cryptography transmitter 10 (transmission basis) with the basis used in the quantum cryptography receiver 30 (reception basis). The basis matching may be performed, for example, by comparing the bases recorded in the quantum cryptography transmitter 10 and the quantum cryptography receiver 30. A bit string consisting of bits other than those at which the transmission basis and the reception basis are different from each other is used as a sifted key.

[0043] Next, the quantum cryptography receiver 30 discloses a part of the sifted key to the quantum cryptography transmitter 10. Based on the disclosed sifted key, the quantum cryptography transmitter 10 estimates an error rate, which is the ratio of erroneous bits received by the quantum cryptography receiver 30 to bits transmitted by the quantum cryptography transmitter 10.

[0044] Next, the quantum cryptography transmitter 10 and the quantum cryptography receiver 30 perform error correction. The same method as that used in normal communications can be used for error correction. Next, the quantum cryptography transmitter 10 and the quantum cryptography receiver 30 perform privacy amplification. First, the quantum cryptography transmitter 10 and the quantum cryptography receiver 30 estimate an upper limit M of the number of bits (amount of leaked information) that may have been intercepted by a third party in the N-bit sifted key based on the estimated error rate. Then, the quantum cryptography transmitter 10 and the quantum cryptography receiver 30 randomly discard M+s bits, which is the upper limit M plus a constant s, from the N-bit sifted key, and use the remainder as the final key. As a result, the probability that an eavesdropper can obtain the final key is 2 -s It can be reduced to the following:

[0045] The bits to be randomly discarded from the sifted key are selected using a universal hash function, which can be a matrix in which the values ​​of each component are randomly selected (0, 1) based on the random numbers generated by the random number source 4.

[0046] The amount of leaked information estimated in privacy amplification differs depending on the phase correlation between the pulsed laser beams repeatedly generated by the semiconductor laser device 1. When it is assumed that there is phase correlation, the amount of leaked information is estimated to be larger than when it is assumed that there is no phase correlation.

[0047] The final key obtained in this manner is used to decrypt the encrypted message.

[0048] [Configuration of photon detection unit] Next, a specific configuration of the photon detection unit 6 will be described. FIG. 3 is a block diagram showing an example of the first photon detection unit 61. The example in FIG. 3 shows a case where a photon in quantum state X0 is input, but the configuration is similar when a photon in quantum state Y0 or quantum state Z0 is input. The first photon detection unit 61 includes multiple single-photon detectors 63 and 64, a beam splitter 67, and an OR element 68. The first photon detection unit 61 combines a signal generated by the single-photon detector 63 (first single-photon detector) and a signal generated by the single-photon detector 64 (second single-photon detector) and outputs a zero-value signal to the control unit 7.

[0049] The beam splitter 67 (first beam splitter) is optically connected to the first output port 55 of the decoding unit 5. The beam splitter 67 splits the zero-value photons input from the decoding unit 5 into equal light intensities and outputs them to each of the multiple single-photon detectors 63, 64. The beam splitter 67 is, for example, a non-polarizing beam splitter. In this case, the beam splitter 67 splits the zero-value photons into reflected light and transmitted light in equal proportions, regardless of polarization.

[0050] The single-photon detector 63 is connected to the beam splitter 67 on the optical path of the zero-value photons reflected by the beam splitter 67. The single-photon detector 63 detects the reflected zero-value photons and generates a zero-value signal. The single-photon detector 64 is connected to the beam splitter 67 on the optical path of the zero-value photons that have passed through the beam splitter 67. The single-photon detector 64 detects the transmitted zero-value photons and generates a zero-value signal. The single-photon detectors 63 and 64 output the generated zero-value signals to the logical OR element 68.

[0051] The single-photon detectors 63, 64 are, for example, single-photon detection avalanche photodiodes (SPADs). In this case, the single-photon detectors 63, 64 may be driven by a gate signal generated by the control unit 7. For example, the control unit 7 may drive the single-photon detectors 63, 64 by a gate signal synchronized with the timing at which the photon train L1 reaches the single-photon detectors 63, 64. Alternatively, the single-photon detectors 63, 64 may be supplied with a DC voltage below breakdown from a power supply (not shown).

[0052] One input terminal of the OR element 68 is connected to the single-photon detector 63. The other input terminal of the OR element 68 is connected to the single-photon detector 64. The output terminal of the OR element 68 is connected to the control unit 7. The OR element 68 outputs the logical sum of the signal generated by the single-photon detector 63 and the signal generated by the single-photon detector 64 to the control unit 7. The OR element 68 outputs a signal with a value of 0 to the control unit 7 when at least one of the single-photon detector 63 and the single-photon detector 64 detects 0.

[0053] FIG. 4 is a block diagram showing an example of the second photon detection unit 62. While the example in FIG. 4 shows a case where a photon in quantum state X1 is input, the same configuration applies when a photon in quantum state Y1 or quantum state Z1 is input. The second photon detection unit 62 includes multiple single-photon detectors 65 and 66, a beam splitter 69, and an OR element 70. The second photon detection unit 62 combines a signal generated by the single-photon detector 65 (third single-photon detector) and a signal generated by the single-photon detector 66 (fourth single-photon detector) and outputs a one-valued signal to the control unit 7. The connection configuration between the multiple single-photon detectors 65 and 66 and the beam splitter 69 is the same as the connection configuration between the multiple single-photon detectors 63 and 64 and the beam splitter 67. The connection configuration between the multiple single-photon detectors 65 and 66 and the OR element 70 is the same as the connection configuration between the multiple single-photon detectors 63 and 64 and the OR element 68.

[0054] The beam splitter 69 (second beam splitter) is optically connected to the second output port 57 of the decoding unit 5. The beam splitter 69 splits the photons of value 1 input from the decoding unit 5 into photons of equal light intensity and outputs the photons to each of the multiple single-photon detectors 65, 66. The single-photon detector 65 detects the reflected photons of value 1 and generates a signal of value 1. The single-photon detector 66 detects the transmitted photons of value 1 and generates a signal of value 1. The single-photon detectors 65 and 66 output the generated signal of value 1 to the OR element 70. Like the single-photon detectors 63, 64, the single-photon detectors 65, 66 are, for example, single-photon detection avalanche diodes (SPADs).

[0055] The logical sum element 70 outputs the logical sum of the signal generated by the single-photon detector 65 and the signal generated by the single-photon detector 66 to the control unit 7. The logical sum element 70 outputs a signal with a value of 1 to the control unit 7 when at least one of the single-photon detectors 65 and 66 detects a value of 1.

[0056] A quantum cryptography receiving method implemented by the quantum cryptography receiver 30 includes, for example, the decryption unit 5 receiving photons assigned with binarized bits and distributing photons of value 0 in a quantum state corresponding to value 0 and photons of value 1 in a quantum state corresponding to value 1 to the first output port 55 and the second output port 57, respectively; the first photon detection unit 61 detecting the photons of value 0 at the first output port 55 and generating a signal of value 0; the second photon detection unit 62 detecting the photons of value 1 at the second output port 57 and generating a signal of value 1; and the control unit 7 regenerating the binarized bits based on the signal of value 0 and the signal of value 1. In generating the signal of value 0, the first photon detection unit 61 detects the photons of value 0 using a plurality of single-photon detectors 63, 64, and in generating the signal of value 1, the second photon detection unit 62 detects the photons of value 1 using a plurality of single-photon detectors 65, 66.

[0057] [Time shift attack explanation] When the single-photon detectors 63-66 are single-photon detection avalanche photodiodes, the photon detection efficiency of the single-photon detectors 63-66 changes depending on the arrival time of the photon train L1. If the relationship between the arrival time of the photon train L1 and the photon detection efficiency is defined as the response characteristic of single-photon detection, the response characteristic may vary among the single-photon detectors 63-66. The variation in response characteristic may be caused by, for example, an error in manufacturing conditions. Due to the variation in response characteristic, there is a risk that encryption key information may be intercepted by a third party when it is transmitted from the quantum cryptography transmitter 10 to the quantum cryptography receiver 30. This type of interception technique is called a time-shift attack.

[0058] FIG. 5 is a diagram illustrating an example of a time shift attack. As shown in FIG. 5, among the single-photon detectors 63 to 66, for example, the response characteristic RS1 of the single-photon detector 63 and the response characteristic RS2 of the single-photon detector 64 differ on the time axis. For example, at time t0, the detection efficiency of the single-photon detector 63 is approximately half of its maximum value, while the detection efficiency of the single-photon detector 64 is almost zero. In this case, for example, if an eavesdropper shifts the arrival time of the photon string L1 to time t0, the single-photon detector 63 is more likely to detect a photon. This raises the risk of eavesdropping on encryption key information on the optical path to the single-photon detector 63. The eavesdropper may shift the arrival time of the photon string L1 by, for example, switching the length of the optical path using a switch or the like.

[0059] In the following description, the time shift attack will be further explained using a photon detection unit 610 according to a comparative example. FIG. 6 is a block diagram showing the photon detection unit 610 according to the comparative example. The photon detection unit 610 includes single photon detectors 71 and 72. Unlike the first photon detection unit 61 and the second photon detection unit 62, the photon detection unit 610 does not include a beam splitter or an OR element. In the photon detection unit 610, the single photon detector 71 detects a photon with a value of 0 from a photon component based on a photon in quantum state Y0 or quantum state X0 input from the decoding unit 5. The single photon detector 71 then generates a signal with a value of 0 and outputs it to the control unit 7. In the photon detection unit 610, the single photon detector 72 detects a photon with a value of 1 from a photon component based on a photon in quantum state Y1 or quantum state X1 input from the decoding unit 5. The single photon detector 72 then generates a signal with a value of 1 and outputs it to the control unit 7.

[0060] The ratio r(t) of the response characteristics of the single-photon detector 71 and the single-photon detector 72 can be expressed by equation (5).

number

[0061] If the arrival time of the photon string L1 by an eavesdropper is t0 or t1, the quantum cryptography receiver 30 detects a value of 0 or 1 with a probability of 1 / (1+r(t)). The error rate ER of the eavesdropper in this case is expressed by equation (6).

number

[0062] Furthermore, the mutual information I is expressed by equation (7) based on the eavesdropper's error rate ER. Here, the mutual information I indicates the proportion of the encryption key information transmitted by the quantum cryptography transmitter 10 and received by the quantum cryptography receiver 30 that has been eavesdropped by an eavesdropper.

number

[0063] As described above, variations in response characteristics between the single-photon detectors 71 and 72 may give rise to the risk of eavesdropping. In response to this, in the quantum cryptography receiver 30 according to the present disclosure, the first photon detecting unit 61 includes a plurality of single-photon detectors 63 and 64, and the second photon detecting unit 62 includes a plurality of single-photon detectors 65 and 66. Additionally, the single-photon detectors used for the single-photon detectors 63 to 66 may be selected so as to minimize the difference between the average detection efficiency of the single-photon detectors 63 and 64 and the average detection efficiency of the single-photon detectors 65 and 66. As will be described in detail later, this minimizes the difference in response characteristics between the single-photon detectors, thereby keeping the mutual information I low and reducing the possibility of eavesdropping.

[0064] [Example] Next, examples of the present disclosure will be described to further explain the effects of the quantum cryptography receiver 30 according to the present disclosure. Here, the characteristics of the quantum cryptography receivers according to Examples 1, 2, and 3, as well as a comparative example, were considered. Samples A to D having the characteristics shown in FIG. 7 were prepared as detector samples to be applied to the single-photon detectors in each quantum cryptography receiver. The response characteristics of Samples A to D differ from one another, and differences arise particularly between the response characteristics of Sample A, Sample B, and Sample D from around +25 ps to around +225 ps based on the arrival time. For each quantum cryptography receiver employing Samples A to D having such characteristics, the mutual information I was calculated based on Equation (7).

[0065] As a comparative example, in the quantum cryptography receiver having the photon detection unit 610 shown in FIG. 6, sample A was applied to the single photon detector 71, and sample D was applied to the single photon detector 72.

[0066] As Example 1, a quantum cryptography receiver equipped with a first photon detection unit 61 and a second photon detection unit 62 shown in Figures 3 and 4 was assumed. In Example 1, Sample A was applied to the single-photon detector 63 included in the first photon detection unit 61, and Sample D was applied to the single-photon detector 64 included in the first photon detection unit 61. Sample B was applied to the single-photon detector 65 included in the second photon detection unit 62, and Sample C was applied to the single-photon detector 66 included in the second photon detection unit 62.

[0067] Example 2 was assumed to be a quantum cryptography receiver equipped with a first photon detection unit 61 and a second photon detection unit 62 shown in Figures 3 and 4. In Example 2, Sample A was applied to the single-photon detector 63 included in the first photon detection unit 61, and Sample B was applied to the single-photon detector 64 included in the first photon detection unit 61. Sample C was applied to the single-photon detector 65 included in the second photon detection unit 62, and Sample D was applied to the single-photon detector 66 included in the second photon detection unit 62.

[0068] Example 3 was assumed to be a quantum cryptography receiver equipped with a first photon detection unit 61 and a second photon detection unit 62 shown in Figures 3 and 4. In Example 3, Sample A was applied to the single-photon detector 63 included in the first photon detection unit 61, and Sample C was applied to the single-photon detector 64 included in the first photon detection unit 61. Sample B was applied to the single-photon detector 65 included in the second photon detection unit 62, and Sample D was applied to the single-photon detector 66 included in the second photon detection unit 62.

[0069] 8 and 9 show the calculation results of the mutual information in each quantum cryptography receiver. In FIGS. 8 and 9, the horizontal axis represents time and the vertical axis represents the mutual information. FIG. 8(a) shows the calculation results of the mutual information in the quantum cryptography receiver of the comparative example. FIG. 8(b) shows the calculation results of the mutual information in the quantum cryptography receiver of Example 1. As shown in FIG. 8(a), in the quantum cryptography receiver of the comparative example, the mutual information is maximized at approximately 175 ps of arrival time, which is 0.67. In contrast, as shown in FIG. 8(b), in the quantum cryptography receiver of Example 1, the mutual information is maximized at approximately -275 ps of arrival time, which is 0.22. From these results, it can be said that the mutual information in the quantum cryptography receiver of Example 1 is significantly lower than the mutual information in the quantum cryptography receiver of the comparative example. 3 and 4, the detection efficiency of 0-value photons in the first photon detecting unit 61 is the average value of the detection efficiencies of the single-photon detectors 63 and 64. Similarly, the detection efficiency of 1-value photons in the second photon detecting unit 62 is the average value of the detection efficiencies of the single-photon detectors 65 and 66. This makes it possible to reduce the difference between the detection efficiency in the first photon detecting unit 61 and the detection efficiency in the second photon detecting unit 62 compared to the comparative example.

[0070] FIG. 9(a) shows the calculation results of the mutual information in the quantum cryptography receiver of Example 2. FIG. 9(b) shows the calculation results of the mutual information in the quantum cryptography receiver of Example 3. As shown in FIG. 9(a), in the quantum cryptography receiver of Example 2, the mutual information is maximized at 0.54 around the arrival time of 200 ps. As shown in FIG. 9(b), in the quantum cryptography receiver of Example 3, the mutual information is maximized at 0.28 around the arrival time of −250 ps. From the results of FIGS. 8(b), 9(a), and 9(b), it can be seen that the mutual information changes depending on which of samples A to D is applied to each single-photon detector constituting the first photon detection unit 61 and the second photon detection unit 62. Since the mutual information in the quantum cryptography receiver of Example 1 is the smallest, it can be said that the mutual information can be reduced by applying samples that minimize the difference between the average detection efficiency of each of the single-photon detectors 63 and 64 and the average detection efficiency of each of the single-photon detectors 65 and 66.

[0071] Next, as shown in FIG. 10 , the relationship between the transmission distance of the encryption key information and the encryption key generation rate was verified. The verification targets were a case where a time shift attack was performed on the quantum cryptography receiver of the comparative example at an arrival time of 175 ps, a case where a time shift attack was performed on the quantum cryptography receiver of Example 1 at an arrival time of −275 ps, and a case where a time shift attack was not performed on the quantum cryptography receiver of Example 1. In FIG. 10 , the horizontal axis represents the transmission distance of the encryption key information, and the vertical axis represents the number of bits (key generation rate per pulse) that can be generated with guaranteed security when one pulse laser beam is transmitted from the quantum cryptography transmitter 10 to the quantum cryptography receiver 30. In other words, the lower the mutual information, the lower the possibility of eavesdropping, and therefore the longer the transmission distance can be. As shown in FIG. 10 , Example 1 achieved a transmission distance that was 2.5 times longer than that of the comparative example.

[0072] [Action and effect] As described above, in the quantum cryptography receiver 30 and the quantum cryptography receiving method implemented by the quantum cryptography receiver 30 according to one aspect of the present disclosure, the time distribution of the detection probability of a zero-value photon in the first photon detecting unit 61 is equal to the average value of the detection probabilities of each of the multiple single-photon detectors 63 and 64. Similarly, the detection probability of a one-value photon in the second photon detecting unit 62 is equal to the average value of the detection probabilities of each of the multiple single-photon detectors 65 and 66. This makes it possible to reduce the difference between the detection probability in the first photon detecting unit 61 and the detection probability in the second photon detecting unit 62 compared to when the first photon detecting unit 61 and the second photon detecting unit 62 are each composed of a single single-photon detector. This reduces the variation in the detection probability in the single-photon detectors, enabling secure reception of the quantum key.

[0073] The first photon detecting unit 61 includes single photon detector 63 and single photon detector 64 as the multiple single photon detectors, and the second photon detecting unit 62 includes single photon detector 65 and single photon detector 66 as the multiple single photon detectors, and the first photon detecting unit 61 may combine the signal generated by single photon detector 63 and the signal generated by single photon detector 64 to output a signal with a value of 0 to the control unit 7, and the second photon detecting unit 62 may combine the signal generated by single photon detector 65 and the signal generated by single photon detector 66 to output a signal with a value of 1 to the control unit 7. In this case, the difference between the detection probability in the first photon detecting unit 61 and the detection probability in the second photon detecting unit 62 can be kept small by using a simple configuration in which each of the first photon detecting unit 61 and the second photon detecting unit 62 is composed of two single photon detectors.

[0074] The first photon detecting unit 61 may output the logical sum of the signal generated by the single-photon detector 63 and the signal generated by the single-photon detector 64 to the control unit 7, and the second photon detecting unit 62 may output the logical sum of the signal generated by the single-photon detector 65 and the signal generated by the single-photon detector 66 to the control unit 7. In this case, in the first photon detecting unit 61, a signal is output from the first photon detecting unit 61 when at least one of the single-photon detectors 63 and 64 generates a signal with a value of 0. Similarly, in the second photon detecting unit 62, a signal is output from the second photon detecting unit 62 when at least one of the single-photon detectors 65 and 66 generates a signal with a value of 1. This allows the first photon detecting unit 61 and the second photon detecting unit 62 to output signals efficiently.

[0075] The first photon detecting unit 61 may further include a beam splitter 67 that splits photons with a value of 0 toward the single photon detectors 63 and 64, and the second photon detecting unit 62 may further include a beam splitter 69 that splits photons with a value of 1 toward the single photon detectors 65 and 66. In this case, the beam splitter 67 splits the photons with a value of 0 into equal light intensities and outputs them to the single photon detectors 63 and 64. Similarly, the beam splitter 69 splits the photons with a value of 1 into equal light intensities and outputs them to the single photon detectors 65 and 66. This allows the first photon detecting unit 61 and the second photon detecting unit 62 to detect photons with high accuracy.

[0076] Each of the single-photon detectors 63 to 66 may be a single-photon detection avalanche photodiode. In this case, the single-photon detection avalanche photodiode is driven in a high-sensitivity state at the timing when the photon train L1 reaches the single-photon detector by a gate signal synchronized with the timing, which makes it easier to further suppress variations in detection probability.

[0077] As the single-photon detectors applied to single-photon detector 63, single-photon detector 64, single-photon detector 65, and single-photon detector 66, single-photon detectors may be applied so as to minimize the difference between the average value of the detection efficiencies of single-photon detector 63 and single-photon detector 64 and the average value of the detection efficiencies of single-photon detector 65 and single-photon detector 66. In this case, the mutual information I can be kept low, and the possibility of eavesdropping can be reduced.

[0078] The quantum cryptography communication system 100 may include a quantum cryptography receiver 30, a semiconductor laser device 1 that generates pulsed laser light L containing photons, an interferometer 2 that divides each pulsed laser light L into mutually coherent double pulses (a pair of pulses), a quantum cryptography transmitter 10 that includes an encoding unit 3 that assigns binarized bits to photons, and an optical transmission line 20 that propagates the photons to which the binarized bits are assigned from the quantum cryptography transmitter 10 to the quantum cryptography receiver 30. In this case, the quantum cryptography communication system 100 can be suitably configured using the quantum cryptography receiver 30 that achieves the above-described effects.

[0079] [Variations] Although the embodiments of the present disclosure have been described above, the present disclosure is not necessarily limited to the above-described embodiments, and various modifications are possible without departing from the spirit of the present disclosure.

[0080] 11 is a schematic diagram showing the functional configuration of a quantum cryptography communication system 100A including a quantum cryptography receiver 30A according to a modified example. The quantum cryptography receiver 30A differs from the quantum cryptography receiver 30 in that the decryption unit 5 has two first output ports 55A and 55B and two second output ports 57A and 57B, and the photon detection unit 6 has first photon detection units 61A and 61B and second photon detection units 62A and 62B corresponding to the X and Z bases, respectively. The configurations of the first photon detection units 61A and 61B are the same as that of the first photon detection unit 61. The configurations of the second photon detection units 62A and 62B are the same as that of the second photon detection unit 62.

[0081] Based on the received photon sequence L1, the decryption unit 5 sorts the photons constituting each bit of the bit sequence that forms the encryption key according to the bit value and quantum state. The decryption unit 5 outputs photon components based on photons in quantum state Z0 from a first output port 55A, and photon components based on photons in quantum state X0 from a first output port 55B. Similarly, the decryption unit 5 outputs photon components based on photons in quantum state X1 from a second output port 57A, and photon components based on photons in quantum state Z1 from a second output port 57B.

[0082] The photon detector 6 has first photon detectors 61A and 61B and second photon detectors 62A and 62B corresponding to the X and Z bases, respectively. The first photon detector 61A receives photon components based on photons in quantum state Z0 from the first output port 55A, detects the photons with a value of 0, and generates a signal with a value of 0. The first photon detector 61B receives photon components based on photons in quantum state X0 from the first output port 55B, detects the photons with a value of 0, and generates a signal with a value of 0. The second photon detector 62A receives photon components based on photons in quantum state X1 from the second output port 57A, detects the photons with a value of 1, and generates a signal with a value of 1. The second photon detector 62B receives photon components based on photons in quantum state Z1 from the second output port 57B, detects the photons with a value of 1, and generates a signal with a value of 1.

[0083] In the quantum cryptography receiver 30A, the temporal distribution of the detection probability of a zero-value photon in each of the first photon detecting units 61A, 61B is equal to the average value of the detection probability of each of the multiple single-photon detectors 63, 64. Similarly, the detection probability of a one-value photon in each of the second photon detecting units 62A, 62B is equal to the average value of the detection probability of each of the multiple single-photon detectors 65, 66. This makes it possible to suppress variations in the detection probability in the single-photon detectors and to receive the quantum key securely. [Explanation of symbols]

[0084] 1...semiconductor laser device, 3...encoding unit, 5...decoding unit, 7...control unit, 10...quantum cryptography transmitter, 20...optical transmission path, 30, 30A...quantum cryptography receiver, 61, 61A, 61B...first photon detection unit, 62, 62A, 62B...second photon detection unit, 63...single photon detector (first single photon detector), 64...single photon detector (second single photon detector), 65...single photon detector (third single photon detector), 66...single photon detector (fourth single photon detector), 67...beam splitter (first beam splitter), 69...beam splitter (second beam splitter), 100, 100A...quantum cryptography communication system, L...pulsed laser light.

Claims

1. a decoding unit that receives photons to which binarized bits are assigned, and distributes photons with a value of 0 in a quantum state corresponding to a value of 0 and photons with a value of 1 in a quantum state corresponding to a value of 1 to a first output port and a second output port, respectively; a first photon detector that detects the zero-value photons at the first output port and generates a zero-value signal; a second photon detector that detects the one-valued photons at the second output port and generates a one-valued signal; a control unit that reproduces the binarized bits based on the signal with a value of 0 and the signal with a value of 1, A quantum cryptography receiver, wherein each of the first photon detection unit and the second photon detection unit includes a plurality of single-photon detectors.

2. the first photon detection unit includes a first single-photon detector and a second single-photon detector as the plurality of single-photon detectors; the second photon detection unit includes a third single-photon detector and a fourth single-photon detector as the plurality of single-photon detectors; the first photon detection unit combines the signal generated by the first single-photon detector and the signal generated by the second single-photon detector and outputs the zero-value signal to the control unit; 2. The quantum cryptography receiver according to claim 1, wherein the second photon detection unit combines the signal generated by the third single-photon detector and the signal generated by the fourth single-photon detector and outputs the one-valued signal to the control unit.

3. the first photon detection unit outputs a logical sum of the signal generated by the first single-photon detector and the signal generated by the second single-photon detector to the control unit; 3. The quantum cryptography receiver according to claim 2, wherein the second photon detection unit outputs a logical sum of the signal generated by the third single-photon detector and the signal generated by the fourth single-photon detector to the control unit.

4. the first photon detection unit further includes a first beam splitter that splits the zero-value photons toward a first single-photon detector and a second single-photon detector; 4. The quantum cryptography receiver according to claim 1, wherein the second photon detection unit further includes a second beam splitter that splits the one-valued photon toward a third single-photon detector and a fourth single-photon detector.

5. 4. The quantum cryptography receiver according to claim 1, wherein each of the plurality of single-photon detectors is a single-photon detection avalanche photodiode.

6. 4. The quantum cryptography receiver according to claim 2, wherein single-photon detectors applied to the first single-photon detector, the second single-photon detector, the third single-photon detector, and the fourth single-photon detector are applied so as to minimize a difference between an average value of detection efficiencies of the first single-photon detector and the second single-photon detector and an average value of detection efficiencies of the third single-photon detector and the fourth single-photon detector.

7. A quantum cryptography receiver according to any one of claims 1 to 3; a quantum cryptography transmitter including a semiconductor laser that generates laser light including the photons, an interferometer that divides the laser light into double pulses that are coherent with each other, and an encoding unit that assigns the binarized bits to the photons; an optical fiber that propagates the photons to which the binarized bits are assigned from the quantum cryptography transmitter to the quantum cryptography receiver.

8. receiving photons assigned with binarized bits, and distributing photons with a value of 0 in a quantum state corresponding to a value of 0 and photons with a value of 1 in a quantum state corresponding to a value of 1 to a first output port and a second output port, respectively; detecting the zero-value photons at the first output port and generating a zero-value signal; detecting the one-valued photons at the second output port to generate a one-valued signal; and regenerating the binarized bits based on the 0-value signal and the 1-value signal, generating the zero-value signal includes detecting the zero-value photons using a plurality of single-photon detectors; A quantum cryptography receiving method, wherein generating the one-valued signal comprises detecting the one-valued photon using a plurality of single-photon detectors.

Citation Information

Patent Citations

  • Detector autocalibration in QKD systems

    WO2005057823A1

  • Random number sequence generation apparatus, quantum encryption transmitter, and quantum encryption communication system

    WO2017135444A1