Quantum key distribution system

The quantum key distribution system improves secret key generation efficiency by using decoy pulses to detect eavesdropping through distinct photon detection patterns, addressing inefficiencies in conventional systems.

JP2026075823APending Publication Date: 2026-05-11NIPPON TELEGRAPH & TELEPHONE CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
NIPPON TELEGRAPH & TELEPHONE CORP
Filing Date
2024-10-23
Publication Date
2026-05-11

AI Technical Summary

Technical Problem

Conventional quantum key distribution systems face inefficiencies in secret key generation due to the misinterpretation of bit errors, leading to reduced effective key generation efficiency, especially when noise and eavesdropping are indistinguishable.

Method used

A quantum key distribution system that inserts decoy pulses with higher photon counts into coherent pulse trains, allowing eavesdropping detection through unique photon detection patterns, independent of bit error rates.

Benefits of technology

Enhances secret key generation efficiency by accurately identifying eavesdropping attempts, reducing the need to assume all bit errors are due to eavesdropping, thus maintaining high security and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026075823000001_ABST
    Figure 2026075823000001_ABST
Patent Text Reader

Abstract

We provide a quantum key distribution system that detects eavesdropping without using bit error rates. [Solution] In the quantum key distribution system comprising a transmitting node and a receiving node of the present disclosure, the transmitting node transmits a pulse train in which decoy pulses with an average number of photons greater than the average number of photons of each pulse in the coherent pulse train are randomly inserted into an ultra-weak coherent pulse train in which the phase of each pulse is 0 or π. The receiving node inputs the received pulse train into a delayed Mach-Zehnder interferometer (MZI) with a delay phase difference of 0, detects the photons of the pulses output from the MZI, and the transmitting node and the receiving node each generate secret key bits from photon detection events from two consecutive pulses in the ultra-weak coherent pulse train. The receiving node is configured to detect eavesdropping using photon detection events in a time slot adjacent to the time slot in which the decoy pulse was received.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This invention relates to a quantum key distribution system. [Background technology]

[0002] Conventionally, research and development of quantum cryptography or quantum key distribution (QKD) has been underway as a system for securely supplying a common secret key to two parties engaged in encrypted communication for encrypting and decrypting communication data. One of the QKD systems is called differential phase shift (DPS) QKD (DPS-QKD) (see Non-Patent Literature 1).

[0003] The configuration of a conventional DPS-QKD system will be explained with reference to Figure 1. The DPS-QKD system 100 shown in Figure 1 has a transmitting node 120 and a receiving node 140. The transmitting node 120 and the receiving node 140 are connected via a transmission line 130.

[0004] The transmitting node 120 includes a coherent pulse light source 122, a phase modulator 124, and an attenuator 126. The transmitting node 120 corresponds to the node of the sender, which is one of the two parties performing encrypted communication. The transmitting node 120 is configured to generate and transmit a weak coherent pulse train in which the phase of each pulse is 0 or π.

[0005] The coherent pulse light source 122 is a light source that generates and transmits a train of coherent pulses.

[0006] The phase modulator 124 is a modulator that imparts a phase of 0 or π to each pulse in the coherent pulse train from the coherent pulse light source 122.

[0007] The attenuator 126 is an attenuator that applies attenuation to the phase-modulated pulses from the phase modulator 124. The attenuator 126 is configured to attenuate the average light energy per pulse in the pulse train to less than 1 photon energy (e.g., 0.1 photon energy). That is, the average number of photons per pulse in the pulse train emitted from the attenuator 126 is minuscule (e.g., 0.1 photons).

[0008] At the transmitting node 120, the coherent pulse train sent from the coherent pulse light source 122 is given phase by the phase modulator 124 and further attenuated by the attenuator 126, and sent to the transmission line 130 as a coherent pulse train 132 consisting of weak pulses with a phase of 0 or π.

[0009] The receiving node 140 has a delayed Mach-Zehnder interferometer (MZI) 150 and photon detectors D0162 and D1164 positioned at the two outputs of the MZI 150. The receiving node 140 corresponds to the receiver node, which is the other party in the encrypted communication. The receiving node 140 is configured to detect photons from adjacent pulses of a weakly coherent pulse train whose phase from the transmitting node 120 is 0 or π.

[0010] The delay MZI150 has two splitters 152 and 154, and two mirrors 156 and 158. The two mirrors 156 and 158 are positioned in one of the two optical paths formed between splitter 152 and splitter 154. Nothing is positioned in the other optical path between splitter 152 and splitter 154. The optical path in which the two mirrors 156 and 158 are positioned is called the long path, and the optical path in which nothing is positioned is called the short path.

[0011] The two mirrors 156 and 158 are positioned in the delay MZI 150 such that the delay time imparted to the light propagating along the long path due to the difference between the long and short paths is equal to the time interval between two pulses in the pulse train. In addition, the two splitters 152 and 154, and the two mirrors 156 and 158 are configured such that the propagation phase difference between the light propagating along the long path and the light propagating along the short path is an integer multiple of 2π.

[0012] The operation of the delay MZI 150 will be explained with reference to Figure 2. Two adjacent pulses in the coherent pulse train 132 received from the transmitting node 120 are input to the delay MZI 150, split into two by the splitter 152, and propagate along a long path and a short path. The two pulses propagating along the long path are delayed by an amount equal to the time interval between them. Therefore, the second pulse of the two pulses propagating along the short path is incident on the splitter 154 simultaneously with the first pulse of the two pulses propagating along the long path, and they are combined again.

[0013] In the delayed MZI150 with the configuration described above, two adjacent pulses in the coherent pulse train 132 received from the transmitting node 120 overlap and interfere with each other at the splitter 154, resulting in the output. As a result of the interference, if the phase difference between two adjacent pulses is 0, a photon is detected at the photon detector D0162, and if the phase difference is π, a photon is detected at the photon detector D1164. However, because the average number of photons is very small, the detection of photons is rare and random.

[0014] Using the DPS-QKD system 100 configured as described above, the transmitting node 120 and the receiving node 140 generate secret key bits according to the following procedure. (1) After the transmitting node 120 and the receiving node 140 have sent and received the coherent pulse train 132, the receiving node 140 notifies the transmitting node 120 of the time slot in which the photon was detected. (2) The transmitting node 120 generates bit "0" if the phase difference between the two pulses resulting from the detection of the photon is 0, and generates bit "1" if the phase difference is π. (3) The receiving node 140 generates bit "0" if photon detector D0 detects a photon, and generates bit "1" if photon detector D1 detects a photon.

[0015] In this way, the bit values ​​generated at the transmitting node 120 and the receiving node 140 are identical. The transmitting node 120 and the receiving node 140 use these generated bit values ​​as the secret key bit. The security of the secret key bit shared through the above procedure is guaranteed by the fact that the optical signal transmitted from the transmitting node 120 to the receiving node 140 is a weak coherent pulse train.

[0016] For example, consider the case in the DPS-QKD system 100 described above where an eavesdropper attempts to extract a portion of the optical signal on the transmission path 130 and measure the phase difference between two pulses in order to obtain the secret key bit. As mentioned above, because the average number of photons per pulse is minuscule, the eavesdropper cannot measure all of the phase differences and can only measure a portion of them. Furthermore, the phase difference between the two pulses measured by the eavesdropper is not necessarily the same as the two pulses detected by the photon detector D0 or D1 of the receiving node 140 (i.e., the pulses that generated the key bit). Therefore, the eavesdropper cannot obtain all of the secret key bits through measurement. It is possible that the two pulses whose phase difference the eavesdropper measured are the same as the two pulses whose photons were detected by the receiving node 140. The probability that the two pulses whose phase difference the eavesdropper measured are the same as the two pulses whose photons were detected by the receiving node 140 can be quantitatively estimated from the photon count statistics of coherent light. By removing the bits of the secret key that could have been intercepted through a data compression operation called security enhancement, the secret key can be made secure.

[0017] Another eavesdropping method is called an intercept-resend attack. In this method, the eavesdropper intercepts the transmission path, measures the optical signal sent from the transmitting node, and then resends a disguised optical signal to the receiving node based on the measurement results. If the eavesdropper can send a disguised optical signal to the receiving node that is indistinguishable from the optical signal sent by the transmitting node (i.e., the receiving node cannot distinguish between the disguised optical signal and the optical signal sent by the transmitting node), the eavesdropper can obtain the secret key bit information without being detected.

[0018] However, for weak coherent pulse trains, it is not possible to retransmit such a disguised optical signal. As mentioned above, it is rare for an eavesdropper to obtain measurement results. Therefore, the optical signal retransmitted by the eavesdropper will consist of two pulses with the measured phase difference. When such an optical signal is input to the delay MZI of the receiving node, there are three time slots in which photons can be detected by photon detector D0 or photon detector D1 (see Figure 2). These are the time slot in which the first pulse via the short path is output, the time slot in which the first pulse via the long path and the second pulse via the short path are output, and the time slot in which the second pulse via the long path is output. Of the three time slots, the photon detection in the time slots at both ends is not due to interference between the two pulses, so photons are detected randomly by photon detector D0 or photon detector D1. Consequently, the bit value generated at the receiving node from the event of this photon detection will be different from the bit value generated at the transmitting node.

[0019] Therefore, after generating the secret key bits, the transmitting node and the receiving node compare a part of them as test bits. If there is a mismatch in the bit values (bit error), it is determined that eavesdropping has occurred. The bit error rate caused by this eavesdropping can be estimated quantitatively. Conversely, the probability of eavesdropping can also be estimated quantitatively from the bit error rate. Therefore, after discarding the bits used for the test bits, the number of secret key bits that may have been eavesdropped is deleted by the data compression operation called secrecy enhancement described above. As a result, a secure secret key can be finally obtained.

[0020] However, in an actual system, bit errors are caused by factors other than eavesdropping, such as noise in the photon detector. In such a case, assuming the worst-case scenario, all bit errors are regarded as being caused by eavesdropping, and secrecy enhancement is performed.

Prior Art Documents

Non-Patent Documents

[0021]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0022] In the above prior art, the upper limit of the amount of eavesdropping is estimated from the bit error rate of the generated secret key, and that amount is deleted by secrecy enhancement to share a secure secret key. In secrecy enhancement, the original bit error rate of the system is also regarded as being due to eavesdropping, and the secret key is reduced. Therefore, in a system with a high bit error rate, the reduction amount due to secrecy enhancement increases, and there is a problem that the effective secret key generation efficiency decreases.

[0023] This disclosure is made in view of such problems and aims to provide a quantum key distribution system that can detect eavesdropping without using bit error rates. [Means for solving the problem]

[0024] To achieve this objective, one embodiment of the present disclosure provides a quantum key distribution system for supplying a secret key for symmetric-key cryptography, comprising a transmitting node and a receiving node. The transmitting node is configured to transmit a pulse train in which pulses with an average number of photons greater than the average number of photons of each pulse in the coherent pulse train are randomly inserted into an ultra-weak coherent pulse train in which the phase of each pulse is 0 or π. The receiving node has a delayed Mach-Zehnder interferometer with a delay phase difference of 0, and is configured to input the pulse train sent from the transmitting node into the delayed Mach-Zehnder interferometer and to detect the photons of the pulses output from the delayed Mach-Zehnder interferometer. The transmitting node and the receiving node are each configured to generate secret key bits from photon detection events from two consecutive pulses in the ultra-weak coherent pulse train. The receiving node is configured to detect eavesdropping using photon detection events in a time slot adjacent to the time slot in which a pulse with a large average number of photons was received. [Effects of the Invention]

[0025] As explained above, the quantum key distribution system for detecting eavesdropping without using the bit error rate of one embodiment of the present invention can protect against partial eavesdropping that is masked by the bit error rate caused by detector noise, etc., and can increase the efficiency of secret key generation after enhanced confidentiality. [Brief explanation of the drawing]

[0026] [Figure 1] This diagram shows the schematic configuration of a conventional DPS-QKD system. [Figure 2] This diagram illustrates the function of delayed MZI in a receiving device. [Figure 3]This figure shows a schematic configuration of the quantum key distribution system according to the embodiment of this disclosure. [Figure 4] This figure illustrates the operation of delayed MZI in a quantum key distribution system according to an embodiment of the present disclosure. [Figure 5] This figure shows three patterns (a), (b), and (c) in which photons are detected at a receiving node when the quantum key distribution system according to embodiments of the present disclosure is subjected to an intercept-resend attack. [Figure 6] This figure shows a schematic configuration of the control devices for the transmitting node and the receiving node in a quantum key distribution system according to an embodiment of the present disclosure. [Figure 7] This figure shows the procedure for generating a secret key bit in a quantum key distribution system according to an embodiment of this disclosure. [Modes for carrying out the invention]

[0027] Embodiments of the present invention will be described in detail below with reference to the drawings. Identical or similar reference numerals indicate identical or similar elements, and repeated descriptions may be omitted. The embodiments described below are illustrative, and it goes without saying that components can be added, modified, or omitted without departing from the spirit of this disclosure.

[0028] The quantum key distribution system of this disclosure will be described with reference to Figure 3. The quantum key distribution system of this disclosure is an improved version of the DPS-QKD system described above with reference to Figure 1. The quantum key distribution system 300 shown in Figure 3 is a system that supplies a secret key for symmetric-key cryptographic communication to two distant parties. The quantum key distribution system 300 comprises a transmitting node 320 corresponding to the node of the sender, which is one of the two distant parties, and a receiving node 340 corresponding to the node of the receiver, which is the other party.

[0029] The transmitting node 320 includes a coherent pulse light source 122, an intensity modulator 324, a phase modulator 124, an attenuator 126, and a control device 326. The transmitting node 320 differs from the transmitting node 120 shown in Figure 1 in that it is equipped with an intensity modulator 324 and a control device 326.

[0030] The control device 326 is a control device that controls the control device 326 and the phase modulator 124 via the signal line 328. Further details will be described later.

[0031] The intensity modulator 324 is a modulator that modulates the intensity of each pulse in the coherent pulse train sent from the coherent pulse light source 122. For example, the intensity modulator 324 is a modulator that modulates the intensity of each pulse at one of two intensity levels. The intensity modulator 324 is configured to modulate pulses randomly selected from the coherent pulse train to a high intensity according to instructions from the control device, and to leave the intensity of the unselected pulses unmodulated or modulate them to a low intensity. The pulses modulated to a high intensity in the intensity modulator 324 undergo modulation and attenuation in the phase modulator 124 and the attenuator 126, and are sent to the transmission line 130 as decoy pulses 322 inserted into the coherent pulse train 132.

[0032] At the transmitting node 320, the phase modulator 124 assigns a phase of 0 or π to each pulse in the intensity-modulated coherent pulse train from the intensity modulator 324, according to instructions from the control unit.

[0033] Furthermore, at the transmitting node 320, the attenuator 126 applies attenuation to the phase-modulated pulses from the phase modulator 124. For the coherent pulse train transmitted from the attenuator 126, the average number of photons of pulses that are not modulated in intensity or are modulated at low intensity is μ0 (e.g., 0.1), and the average number of photons of pulses that are modulated at high intensity is αμ0 (where α>1). High-intensity modulated pulses are called decoy pulses, and pulses that are not modulated in intensity or are modulated at low intensity are called signal pulses.

[0034] The receiving node 340 includes the MZI 150, photon detectors D0162 and D1164 located at the two outputs of the MZI 150, and a control device 342. The receiving node 340 differs from the receiving node 140 shown in Figure 1 in that it is equipped with a control device 342.

[0035] The control device 342 is a control device that acquires information regarding photon detection from photon detectors D0162 and D1164 via signal line 344. Further details will be described later.

[0036] In the quantum key distribution system 300 shown in Figure 3, the transmitting node 320 sends a signal light to the transmission path 130 in which a decoy pulse 322 with an average number of photons αμ0 is inserted into a weak coherent pulse train 132 with a phase of 0 or π and an average number of photons per pulse of μ0. The insertion position of the decoy pulse is random and unknown to the outside.

[0037] At the receiving node 340, the signal light from the transmitting node 320 is split into two by the splitter 152 of the MZI152. The pulses that propagate along the long path and receive a delay equal to the pulse time interval, and the pulses that propagate along the short path, are combined again by the splitter 154 and emitted. The photons of the pulses emitted from the splitter 154 are detected by the photon detector D0162 or the photon detector D1164.

[0038] Refer to Figure 4 to explain the operation of the delay MZI150 in the quantum key distribution system 300. Figure 4 shows the pulse train in the vicinity of the decoy pulse 332, represented by the thick black line. For each pulse time slot, the pulse train input to the delay MZI150 has a value of t relative to the decoy pulse. k (k is an integer), the pulse train output from the delayed MZI150 has τ k Each is numbered accordingly. Using this notation, for example, in the time slot τ2 of the output of the delay MZI150, the pulses in time slot t1 and time slot t2 of the input pulse train interfere with each other.

[0039] As a result of interference, if the phase difference between two adjacent pulses in the input pulse train is 0, a photon is detected by photon detector D0162; if the phase difference is π, a photon is detected by photon detector D1164. In other words, the phase difference between two adjacent pulses can be determined from the photon detection result. However, because the average number of photons per pulse is small, determining the phase difference is rare and random.

[0040] Here, the probability of detecting a photon is determined by the average number of photons in the combined pulse and is known quantum mechanically to be given by 1-exp(-μ). Here, μ is the average number of photons, and the detection efficiency of the photon detector is set to 1. If the average number of photons in the signal pulse and decoy pulse input to the delay MZI150 are μ0 and αμ0, respectively, then the average number of photons in the pulse output from the delay MZI150 is μ0 / 2 + μ0 / 2 = μ0 in the time slot where the signal pulses overlap, and μ0 / 2 + αμ0 / 2 = μ0(1+α) / 2 in the time slot where the signal pulse and decoy pulse overlap. Therefore, the photon detection probability in the former is given by 1-exp(-μ0), and the photon detection probability in the latter is given by 1-exp[-μ0(1+α) / 2]. The quantum key distribution system 300 of this embodiment uses this photon detection probability to detect intercept-resend eavesdropping.

[0041] In the quantum key distribution system 300, the transmitting node 320 and the receiving node 340 generate secret key bits using the following procedure. (1) The transmitting node 320 sends out a coherent pulse train 132 with a decoy pulse 332 inserted, and the receiving node 340 receives it. (2) The receiving node 340 notifies the transmitting node 320 of the time slot in which the photon was detected as a photon detection event. (3) The transmitting node 320 generates a bit "0" if the phase difference between the two pulses (the two pulses sent by the transmitting node 320) caused by the photon detection event at the receiving node 340 is 0, and generates a bit "1" if the phase difference is π. However, the transmitting node 320 ignores the photon detection caused by the decoy pulse 332 that it sent. Furthermore, the transmitting node 320 informs the receiving node of the time slot of the decoy pulse inserted into the coherent pulse train 132. (4) The receiving node 340 generates bit "0" if the photon detection event is due to photon detection by photon detector D0162, and bit "1" if the photon detection event is due to photon detection by photon detector D1164. However, the receiving node 340 excludes photon detections caused by the decoy pulse 332. Furthermore, the receiving node 340 compares the number of photons detected in the time slot in which the decoy pulse 332 is involved and in time slots adjacent to that time slot with the number of photons detected in the time slot in which the bit was generated to detect whether or not eavesdropping is occurring. If the receiving node 340 detects eavesdropping, it notifies the transmitting node 320 of this fact and discards the generated secret key. As described above, the bit value generated at the transmitting node 320 matches the bit value generated at the receiving node 340. This is the secret key bit.

[0042] Next, the principle of eavesdropping detection in the quantum key distribution system 300 of this embodiment will be explained. The eavesdropping method under consideration is an intercept-resend attack.

[0043] In an intercept-resend attack, the eavesdropper interrupts the transmission path and uses an eavesdropper receiving node 540, which has a delay MZI 150 similar to that of the receiving node 340, and two photon detectors D0162 and D1164, to measure the phase difference between two pulses sent by the transmitting node 320. In this case, since the number of photons in the coherent pulse train 132 into which the decoy pulse 332 is inserted is minuscule, the detection of a photon and the measurement of the phase difference between two pulses are rare and random. When the eavesdropper receiving node 540 detects a photon, it retransmits two consecutive pulses with the measured phase difference to the receiving node 340.

[0044] Consider the probability of photon detection in the time slot adjacent to the time slot in which the decoy pulse 332 is received at receiving node 134 (τ2 in Figure 4) when two such consecutive pulses are retransmitted. There are three patterns in which a photon may be detected in that slot when an intercept-resend attack occurs.

[0045] Figure 5 shows the pulse train in three patterns in which photons are detected at receiving node 134 when an intercept-resend attack occurs. For the sake of simplicity in the following explanation, the average number of photons μ is assumed to be small, and the photon detection probability is expressed by the approximate formula [1-exp(-μ)≈μ].

[0046] In the pattern shown in Figure 5(a), the eavesdropper receiving node 540 detects a photon in time slot τ3, indicated by the star, and retransmits two pulses in time slots t2 and t3. The average number of photons in the retransmitted pulses is set to one per two pulses to make the number of photons received by the receiving node 34 the same as under normal conditions. When the receiving node 340 receives these two retransmitted pulses, it can detect photons in time slots τ2, τ3, and τ4 at a rate of 1 / 4, 1 / 2, and 1 / 4, respectively. The probability that the eavesdropper receiving node 540 detects a photon in time slot τ3 (i.e., the probability of retransmitting two pulses) is μ0. Therefore, the probability that the receiving node 340 detects a photon in time slot τ2 in this pattern is μ0 × 1 / 4.

[0047] In the pattern shown in Figure 5(b), the eavesdropper receiving node 540 detects a photon in time slot τ2, indicated by the star, and retransmits the two pulses in time slots t1 and t2. When the receiving node 340 receives these two retransmitted pulses, it can detect photons in time slots τ1, τ2, and τ3 with probabilities of 1 / 4, 1 / 2, and 1 / 4, respectively. The probability that the eavesdropper receiving node 540 detects a photon in time slot τ2 (i.e., the probability of retransmitting the two pulses) is μ0. Therefore, the probability that the receiving node 340 detects a photon in time slot τ2 in this pattern is μ0 × 1 / 2.

[0048] In the pattern shown in Figure 5(c), the eavesdropping receiving node 540 detects a photon in time slot τ1, indicated by the asterisk, and retransmits the two pulses in time slots t0 and t1. When the receiving node 340 receives these two retransmitted pulses, it retransmits the two pulses in time slot τ -1 At τ1 and τ2, the probability of detecting a photon is 1 / 4, 1 / 2, and 1 / 4, respectively. The probability that the eavesdropping receiving node 540 detects a photon in time slot τ2 (i.e., the probability of retransmitting both pulses) is μ0(1+α) / 2. Therefore, the probability that the receiving node 340 detects a photon in time slot τ2 in this pattern is μ0(1+α) / 2 × 1 / 4.

[0049] Summing up the three patterns above, the probability that receiving node 340 will detect a photon in time slot τ2 when an intercept-resend attack occurs is μ0 × 1 / 4 + μ0 × 1 / 2 + μ0(1 + α) / 2 × 1 / 4 = μ0(7 + α) / 8.

[0050] On the other hand, in the absence of an intercept-resend attack, the probability of receiving node 340 detecting a photon in time slot τ2 is μ0. That is, an intercept-resend attack increases the probability of photon detection in time slot τ2 by (7+α) / 8 times, for example, 1.5 times when α=5. This is due to the time slot τ -2 But the same applies.

[0051] Therefore, after receiving the coherent pulse train 132, the receiving node 340 refers to the time slot in which the decoy pulse, notified by the transmitting node 320, was inserted, and selects a time slot adjacent to the time slot in which the decoy pulse was received (t0 in the explanation of Figure 4) (τ2 or τ in the explanation of Figure 4). -2 The photon detection probability at ) is compared with the photon detection probability at the time slot in which the signal pulse was received, and if the ratio is 1 or greater, it is determined that eavesdropping has occurred.

[0052] Referring to Figures 6 and 7, the configuration and operation of the control device 326 of the transmitting node 320 and the control device 342 of the receiving node 340 for carrying out the procedure for generating secret key bits in the quantum key distribution system 300 described above will be explained.

[0053] As shown in Figure 6, the control device 326 and the control device 342 each include a communication device 602, a storage device 604, and an arithmetic unit 606 configured to operate together with the communication device 602 and the storage device 604.

[0054] The arithmetic unit 606 can be a general-purpose device that performs various tasks, such as a microprocessor or CPU, or a dedicated device, such as an FPGA or ASIC.

[0055] The arithmetic unit 606 of the transmitting node 320 generates control signals to the intensity modulator 324 and the phase modulator 124. Specifically, the arithmetic unit 606 randomly generates control signals in time slots (t k A control signal is generated to instruct the intensity modulator 324 to select a pulse (which will be a decoy pulse) and modulate it with high intensity, and this signal is supplied to the communication device 602, and the time slot (t) into which the decoy pulse is inserted is stored in the memory device 604. k ) is stored. In addition, the arithmetic unit 606 stores each time slot (t k A control signal is generated to instruct the phase modulator 124 to assign a phase (0, π) to the pulse, and this signal is supplied to the communication device 602. At the same time, the phase difference between two pulses in adjacent time slots is recorded in the memory device 604.

[0056] The arithmetic unit 606 of the receiving node 340 generates a bit ("0" or "1") in response to a signal indicating that photons have been detected by the photon detector D0162 and the photon detector D1164, and records the time slot (τ k ) when the photons were detected and the generated bit in the storage device 604. The arithmetic unit 606 executes an operation for detecting the presence or absence of eavesdropping as described above, and generates a signal notifying the transmitting node 320 to that effect when eavesdropping is detected, and supplies it to the communication device 602.

[0057] The communication device 602 is a device that transmits a control signal to the intensity modulator 324 and the phase modulator 124 via the signal line 328, or a device that receives a signal indicating that photons have been detected from the photon detector D0162 and the photon detector D1164 via the signal line 344.

[0058] The storage device 604 can be a semiconductor memory such as a hard disk, ROM, or RAM. The storage device 604 provides an area for storing programs executed by the arithmetic unit 606 and information useful for the processing by the arithmetic unit, and an area for recording various data.

[0059] The storage device 604 of the transmitting node 320 provides an area for recording the time slot (t k ) in which the decoy pulse was inserted and the phase (0, π) given to the pulse of each time slot (t k ).

[0060] The storage device 604 of the receiving node 340 provides an area for recording the time slot (τ k ) when the photons were detected and the generated bit.

[0061] Referring to FIG. 7, the details of the procedure for generating the secret key bits in the quantum key distribution system 300 will be described.

[0062] In step 702, the transmitting node 320 sends signal light to the transmission line 130, which includes a coherent pulse train 132 into which a decoy pulse 322 is inserted. More specifically, the arithmetic unit 606 of the control device 326 determines the time slot (t) into which the decoy pulse is inserted. k The control device 326 randomly selects a time slot (t) and generates a control signal indicating the randomly selected time slot, which is then supplied to the communication device 602. Furthermore, the arithmetic unit 606 of the control device 326 processes each time slot (t k The phase (0, π) to be applied to the pulse is determined, and a control signal indicating the phase (0, π) of each time slot is generated and supplied to the communication device 602. In accordance with the control signal from the control device 326, the intensity modulator 324 and the phase modulator 124 operate, causing a signal light containing a coherent pulse train with a decoy pulse inserted to be sent from the transmitting node 320 to the transmission line 130.

[0063] In step 702, at the transmitting node 320, the arithmetic unit 606 of the control device 326 inserts a decoy pulse into the memory device 604 in a time slot (t k ) is stored. In addition, the arithmetic unit 606 of the control device 326 records the phase difference between two pulses in adjacent time slots in the storage device 604.

[0064] In step 752, the receiving node 340 receives signal light containing the coherent pulse train 132 and detects photons using the photon detector D0162 or the photon detector D1164.

[0065] In step 754, the receiving node 340 detects the photon as a photon detection event in the time slot (τ k ) is recorded. More specifically, the arithmetic unit 606 of the control device 342 records in the storage device 604 whether the signal indicating the detection of a photon received via the communication device 602 was received from either the photon detector D0162 or the photon detector D1164. Furthermore, the arithmetic unit 606 records the time slot (τ) in which the photon was detected. k The generated bits are recorded in the storage device 604.

[0066] In step 756, the receiving node 340 detects the photon as a photon detection event in the time slot (τ k The receiving node 340 notifies the transmitting node 302 of the information to be notified by the computing unit 606 and supplies it to the communication device 602.

[0067] In step 706, the transmitting node 320 receives the time slot (τ) notified by the receiving node 340 as a photon detection event. k ) corresponds to two time slots (t k ) generates a bit according to the phase difference between the two pulses transmitted. More specifically, at the transmitting node 320, the arithmetic unit 606 of the control device 326 generates a bit "0" if the phase difference is 0, and generates a bit "1" if the phase difference is π. However, the time slot (τ) notified from the receiving node 340 k ) corresponds to two time slots (t k If a decoy pulse was transmitted in the ), it is ignored. The arithmetic unit 606 of the control device 326 also records the generated bits in the storage device 604.

[0068] In step 708, the transmitting node 320 inserts a decoy pulse into a time slot (t k The receiving node 340 is notified of the information to be notified by the arithmetic unit 606 at the transmitting node 320 and supplies it to the communication device 602.

[0069] In step 758, the receiving node 340 receives notification from the transmitting node 320 regarding the time slot (t) in which the decoy pulse was inserted. k Excluding photon detection in the time slot (τ), bits are generated according to the photon detector that detected the photon. More specifically, at the receiving node 340, the arithmetic unit 606 generates bit "0" when it receives a signal from photon detector D0162 indicating that a photon has been detected, and generates bit "1" when it receives a signal from photon detector D1164 indicating that a photon has been detected. Furthermore, the arithmetic unit 606 generates bits according to the time slot (τ) in which the photon was detected. k The generated bits are recorded in the storage device 604.

[0070] In step 760, the receiving node 340 refers to the time slot in which the decoy pulse notified by the transmitting node 320 was inserted, and selects the time slot adjacent to the received time slot (t0 in the description of Figure 4) (τ2 or τ in the description of Figure 4). -2 The presence or absence of eavesdropping is determined based on a comparison between the photon detection probability at the time slot in which the signal pulse was received and the photon detection probability at the time slot in which the signal pulse was received. The photon detection probability at the time slot in which the signal pulse was received used for comparison can be a predetermined or predetermined average photon detection probability. The determination of whether or not eavesdropping is present is performed by the arithmetic unit 606 of the receiving node 340.

[0071] In step 762, if the receiving node 340 determines that eavesdropping has occurred, it discards the generated bits and notifies the transmitting node 320 that it has determined that eavesdropping has occurred. The transmitting node 320 generates the information to be notified by the arithmetic unit 606 and supplies it to the communication device 602.

[0072] In step 710, if the transmitting node 320 is notified by the receiving node 340 that it has determined that eavesdropping has occurred, it discards the generated bits.

[0073] In step 712, if the transmitting node 320 is not notified by the receiving node 340 that it has determined that eavesdropping has occurred, it uses the generated bits as the secret key.

[0074] In step 764, if the receiving node 340 determines that there was no eavesdropping, it uses the generated bits as the secret key.

[0075] As explained above, while conventional methods detected eavesdropping based on the bit error rate, this disclosure allows for eavesdropping detection from simultaneous photon detection events. Therefore, it is unnecessary to assume that the bit error rate inherent in the system is due to eavesdropping and to reduce the secret key accordingly. This enables the provision of a quantum key distribution system with high effective secret key generation efficiency. [Explanation of symbols]

[0076] 100 DPS-QKD System 120 transmitting nodes 122 Coherent pulsed light source 124 Phase Modulator 126 Attenuator 130 transmission lines 132 Coherent pulse train 140 receiving nodes 150 Delay MZI 152,154 splitter 156,158 Miller 162 Photon Detector D0 164-photon detector D1 300 Quantum Key Distribution Systems 320 transmitting nodes 324 Intensity Modulator 326 Control device 328 signal line 332 Decoy Pulse 340 receiving nodes 342 Control device 344 signal line 350 communication paths 532a, 532b, 532c Two pulses retransmitted from the eavesdropping receiving node 540 Eavesdropper Receiving Nodes 602 Communication equipment 604 Storage device 606 Arithmetic equipment

Claims

1. A quantum key distribution system that supplies secret keys for symmetric-key cryptography, It comprises a transmitting node and a receiving node, The transmitting node is configured to transmit a pulse train in which pulses with an average number of photons greater than the average number of photons of each pulse in the coherent pulse train are randomly inserted into an ultra-weak coherent pulse train in which the phase of each pulse is 0 or π. The receiving node has a delayed Mach-Zehnder interferometer with a delay phase difference of 0, and is configured to input the pulse train sent from the transmitting node to the delayed Mach-Zehnder interferometer and to detect the photons of the pulses output from the delayed Mach-Zehnder interferometer. The transmitting node and the receiving node are each configured to generate a secret key bit from photon detection events from two consecutive pulses in an ultra-weak coherent pulse train. A quantum key distribution system in which the receiving node is configured to detect eavesdropping using photon detection events in time slots adjacent to the time slot in which a pulse with a large average number of photons was received.

2. The quantum key distribution system according to claim 1, wherein the receiving node is configured to detect eavesdropping by comparing a photon detection event in a time slot adjacent to the time slot in which a pulse with a large average number of photons was received with a predetermined photon detection event.

3. The transmitting node is configured to notify the receiving node of a time slot in which a pulse with a large average number of photons is inserted. The quantum key distribution system according to claim 1, wherein the receiving node is configured to detect eavesdropping based on a notification from the transmitting node, using a photon detection event in a time slot adjacent to the time slot in which the pulse with a large average number of photons was received.