A method for determining the presence or absence of an eavesdropper on the quantum channel of a quantum cryptography communication system using TDC, and a quantum cryptography key distribution device for the same purpose.

The quantum cryptographic key distribution system uses a TDC to measure reception timing differences to detect eavesdroppers, addressing the real-time detection challenge in conventional systems, enhancing security through precise timing analysis.

JP2026524660APending Publication Date: 2026-07-23SDT INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
SDT INC
Filing Date
2024-07-12
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

Conventional quantum cryptography systems fail to detect the presence of eavesdroppers on the quantum channel in real time, relying on error ratios in generated encryption keys.

Method used

A quantum cryptographic key distribution system equipped with a Time to Digital Converter (TDC) that measures the reception timing of transmitted qubits by comparing it to a reference timing, detecting the presence of an eavesdropper if the time difference falls outside a predetermined critical range.

Benefits of technology

Enables precise, real-time detection of eavesdroppers by measuring the variance in reception timing, ensuring secure quantum key distribution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026524660000001_ABST
    Figure 2026524660000001_ABST
Patent Text Reader

Abstract

Disclosed is a detection device configured to detect a quantum signal transmitted through a quantum channel and output a data signal corresponding to the detected quantum signal, and a receiver for a quantum cryptographic key distribution system including a TDC configured to measure the occurrence time difference between the occurrence time of a first encoding pulse contained in the data signal and the occurrence time of a first reference pulse contained in a predetermined reference timing signal. If the measured occurrence time difference falls outside a predetermined critical range, it is determined that an eavesdropper is present in the quantum channel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to quantum key distribution technology, and more particularly to a technology for determining the presence or absence of eavesdroppers on a quantum channel by using a TDC (Time to Digital Converter).

Background Art

[0002] Quantum cryptographic communication technology is a field of quantum information technology. Quantum cryptographic communication technology is a digital information technology that utilizes the principles of quantum physics and is a physical layer security technology for communication networks. Since the security of quantum cryptographic communication technology is based on the principles of quantum mechanics, eavesdropping and wiretapping are impossible and its security is absolutely guaranteed. Quantum cryptographic communication technology can be implemented using existing buried optical fiber facilities, making large-scale commercialization possible.

[0003] Unlike an asymmetric public key cryptosystem such as the RSA cryptosystem, a symmetric cryptosystem in which a sender and a receiver share a one-time pad with each other and then use it as a cryptographic key is guaranteed absolute security. Quantum cryptographic communication technology is a technology for securely distributing such a one-time pad between a sender (transmitting device) and a receiver (receiving device) in real time based on laws of quantum physics such as quantum no-cloning, and is also called "quantum key distribution (QKD)" technology.

[0004] Generally, quantum cryptography uses two communication channels: a quantum channel (secret channel) for transmitting quantum states, and a classical channel (public channel) that is completely open to the outside, including eavesdroppers. That is, the quantum channel is the core communication channel of quantum cryptography, and its secrecy is maintained by the quantum non-replicability principle, while the classical channel is a communication channel used to detect eavesdroppers by publicly comparing randomly selected basis sets with each other, or by publicly comparing parts of the generated cryptographic key with each other, and refers to existing digital optical transmission channels and wireless communication channels. In quantum cryptography, the classical channel is considered, in principle, a channel that eavesdroppers can freely eavesdrop on or intercept. The classical channel is necessary for quantum cryptographic key distribution itself, such as when the sender (Alice) and receiver (Bob) compare their basis sets with each other, but it is also absolutely necessary for the function of publicly authenticating each other. In other words, without a classical channel, the encryption key could be leaked through a so-called "impersonation attack" in which an eavesdropper impersonates the sender (Alice) or receiver (Bob) along the way. Thus, classical or public channels are core elements of quantum cryptography and must be given important consideration when realizing actual quantum cryptography communication systems. However, in this specification, the quantum cryptography communication channel refers to the quantum channel used for transmitting quantum states, in that it uses existing developed technologies.

[0005] There are two methods for physically realizing quantum cryptography communication channels: one using optical fibers (wired) and another distributing encryption keys through the atmosphere (wireless). The optical fiber method is suitable for realizing long-distance quantum cryptography channels because, if single-mode optical fibers, which are standard in existing optical communications, are used, the spatial modes are maintained very well, and the transmission loss in the 1550nm band is very low, at about 0.2dB / km.

[0006] The encryption keys for quantum cryptography can be implemented in various ways, including coding using the polarization of light, phase coding, frequency coding, and coding using continuous variables. Coding techniques using the polarization and phase of light require additional techniques to continuously compensate for fluctuations in polarization and optical path caused by temperature and ambient environment.

[0007] The BB84 protocol, a quantum cryptography protocol that utilizes two basis sets, X and Y, uses the four quantum states that make up the two basis sets. For example, it utilizes the four polarization states of a single photon.

[0008] The usual way for the sender (Alice) and receiver (Bob) to share an encryption key and to know if an eavesdropper (Eve) is present is as follows:

[0009] In other words, in the first stage, the sender (Alice) randomly selects one from either the X basis or the Y basis.

[0010] In the second stage, the sender (Alice) arbitrarily chooses one of the two selected ground quantum states (the value of the encryption key), namely 0 or 1, and sends it to the receiver (Bob).

[0011] In the third stage, the receiver (Bob) receiving the quantum state also randomly selects one of the two basis states.

[0012] In the fourth stage, the receiver (Bob) measures the received quantum state using the selected ground.

[0013] In the fifth stage, after the receiver (Bob) has finished their measurement, the sender (Alice) and receiver (Bob) reveal to each other a basis of their choosing. If the basis chosen by the sender (Alice) and the receiver (Bob) are the same, the result measured by the receiver (Bob) matches the quantum state chosen by the sender (Alice), and therefore both users will have the same encryption key (sifted key).

[0014] If an eavesdropper (Eve) attempts to eavesdrop midway through, the fundamental principles of quantum mechanics would cause an error in the encryption key values ​​obtained by the two users (Alice and the receiver (Bob)). The sender (Alice) and receiver (Bob) would then reveal a portion of the generated key to each other, calculate the error ratio, and determine whether or not an eavesdropper (Eve) is present.

[0015] There are two main types of eavesdropping methods that an eavesdropper (Eve) can use: individual attacks (incoherent attacks), which attempt to access only one qubit at a time, and joint attacks (coherent attacks), which attempt to access several qubits simultaneously to obtain information.

[0016] One example of an individual attack method is the intercept-resend attack. In this method, the eavesdropper (Eve) intercepts the qubit that the sender (Alice) is sending to the receiver (Bob), performs the measurement as desired, and then sends the receiver (Bob) a qubit in a state that is advantageous to the eavesdropper (Eve). The basis that the eavesdropper (Eve) measures can be arbitrarily chosen from the two basis bases of the BB84 protocol, or it can be measured using an intermediate basis between the two basis bases.

[0017] Another example of an individual attack method is a cloning attack (symmetric individual attack). This method involves quantum cloning of the transmitted qubits. Although complete replication is impossible quantum mechanically (no cloning theorem), it is a form of attack that allows the attacker to obtain some information about the cryptographic key.

[0018] This type of attack is an attack against a perfect quantum cryptography system, causing errors in the encryption keys of both the sender (Alice) and receiver (Bob), thus being detected by the user. Besides these methods, there are also attack methods that exploit vulnerabilities in the equipment used in quantum cryptography systems. [Overview of the Initiative] [Problems that the invention aims to solve]

[0019] Conventional techniques rely on the error ratio present in the generated encryption key to detect eavesdroppers, making it impossible to detect the presence of an eavesdropper or attacker on the quantum channel in real time. This invention aims to provide a technique that precisely measures the reception timing of transmitted qubits and detects the presence of an attacker in real time based on the difference between the measured reception timing and a reference timing. [Means for solving the problem]

[0020] In accordance with one aspect of the present invention, a receiver for a quantum cryptographic key distribution system may be provided, comprising: a detection device (260) configured to detect a quantum signal transmitted through a quantum channel and outputting a data signal (Sd) corresponding to the detected quantum signal; and a TDC (250) configured to measure the occurrence time difference between the occurrence time of a first encoding pulse included in the data signal and the occurrence time of a first reference pulse included in a predetermined reference timing signal, wherein if the measured occurrence time difference falls outside a predetermined critical range (threshold range), it is determined that an eavesdropper is present in the quantum channel.

[0021] At this time, the reference timing signal (Srt) may be a pulse train signal synchronized with the quantum signal output from the transmission device (100).

[0022] At this time, the reference timing signal (Srt) may be a pulse train signal having the same period as the generation period of the quantum signal output from the transmission device (100).

[0023] At this time, the generated time difference may be the time difference between the rising edge of the first encoding pulse and the rising edge of the first reference pulse.

[0024] At this time, the first encoding pulse may be the encoding pulse closest to the first reference pulse in the time axis among the plurality of encoding pulses included in the data signal (Sd).

[0025] At this time, the TDC may include: a first delay line part (20) to which an input pulse having a time difference between a first generation time point of the first reference pulse and a second generation time point of the first encoding pulse as a width is input; and an arithmetic part (60) for determining the generated time difference using a thermometer code output from the first delay line part.

[0026] At this time, the TDC may further include a code conversion part (30) for converting and outputting the order of elements of the thermometer code, and the arithmetic part is configured to determine the generated time difference using the conversion code output from the code conversion part, the conversion code arranges the order of elements of the thermometer code according to a predetermined criterion, and the predetermined criterion may be the data path delay from the output node of the input pulse to the output nodes of each of the plurality of flip - flops (FF) included in the first delay line part.

[0027] At this time, the TDC is implemented by any one of FPGA (Field Programmable Gate Array), ASIC (Application Specific Integrated Circuit), and IC (Integrated Circuit), and any one of the devices can be programmed to include the first delay line part and the arithmetic part.

[0028] At this time, the TDC further includes a second delay line part to which the input pulse is input; the code conversion part aligns and merges elements of the thermometer code output by the first delay line part and elements of the thermometer code output by the second delay line part according to a predetermined second criterion, and is configured to generate the conversion code, and the predetermined second criterion may be a data path delay from the output node of the input pulse to the output nodes of a plurality of flip-flops included in the first delay line part and the second delay line part.

[0029] At this time, the TDC is configured to use a clock signal (clk) having a period shorter than the generation period of the quantum signal output by the transmission device. The TDC includes an input signal generation part (10) that generates an input pulse having a time difference between the rising edge generation time of the first reference pulse and the rising edge generation time of the first encoding pulse as a width; a clock pulse counting part (40) that counts the number of clock pulses of the clock signal generated during the maintenance period of the input pulse; and an arithmetic part that determines the value of the generation time difference using the first thermometer code (TC1) output by the code conversion part at the rising edge of the first clock pulse among the generated clock pulses, the second thermometer code (TC2) output by the code conversion part at the rising edge of the clock pulse generated immediately after the last clock pulse among the generated clock pulses, and the counted number of clock pulses.

[0030] A receiver for a quantum cryptographic key distribution system is provided, comprising: a detection device (260) configured to detect a quantum signal transmitted through a quantum channel and outputting a data signal (Sd) corresponding to the detected quantum signal; and a TDC (250) configured to measure the time difference between the time of occurrence of an encoding pulse included in the data signal and the time of occurrence of a reference pulse included in a predetermined reference timing signal, wherein if the variance of the measured time difference falls outside a predetermined critical range, it is determined that an eavesdropper is present in the quantum channel.

[0031] In this case, the reference timing signal (Srt) may be a pulse train signal having the same period as the generation period of the quantum signal output by the transmitting device (100).

[0032] In this case, the generation time of any first encoding pulse among the encoding pulses can be compared with the generation time of the first reference pulse that is closest in the time axis to the first encoding pulse among the multiple reference pulses included in the data signal (Sd).

[0033] In this case, the TDC may include a first delay line part (20) to which an input pulse having a width equal to the time difference between the first generation time of the first reference pulse and the second generation time of the first encoding pulse is input, and a calculation part (60) that determines the generation time difference using the thermometer code output by the first delay line part.

[0034] In yet another aspect of the present invention, a receiver for a quantum cryptographic key distribution system may be provided, which includes a detection device that outputs a data signal corresponding to a quantum signal detected through a quantum channel, and a TDC configured to measure the time difference between a first generation time of a first reference pulse included in a reference timing signal and a second generation time of a first encoding pulse included in the data signal. In this case, the TDC includes a delay line part into which an input pulse having the time difference as its width is input; and a code conversion part configured to generate a conversion code by aligning the elements of a thermometer code output by the delay line part according to the data path delay from the output node of the input pulse to the output node of each of a plurality of flip-flops included in the delay line part. In this case, the receiver is configured to determine the time difference using the generated conversion code, and to determine that an eavesdropper is present in the quantum channel if the measured time difference falls outside a predetermined critical range.

[0035] In this case, the TDC may further include a calculation part configured to determine the time difference using the generated conversion code.

[0036] In this case, the TDC may further include a second delay line part to which the input pulse is input. The code conversion part may be configured to align and merge the elements of the thermometer code output by the delay line part and the elements of the thermometer code output by the second delay line part according to the data path delay from the output node of the input pulse to the output nodes of each of the multiple flip-flops included in the delay line part and the second delay line part to generate the conversion code.

[0037] In this case, the TDC may be configured to utilize a clock signal having a period shorter than the generation period of the quantum signal output by the transmitting device. The TDC may further include an input signal generation part that generates an input pulse having a width equal to the time difference between the rising edge of the first reference pulse and the rising edge of the first encoding pulse; and a clock pulse count part that counts the number of clock pulses of the clock signal that occurred during the duration of the input pulse. In this case, the calculation part may be configured to determine the value of the time difference using a first thermometer code (TC1) output by the code conversion part at the rising edge of the first clock pulse among the generated clock pulses, a second thermometer code (TC2) output by the code conversion part at the rising edge of the clock pulse that occurred immediately after the last clock pulse among the generated clock pulses, and the number of counted clock pulses.

[0038] In yet another aspect of the present invention, a receiver for a quantum cryptographic key distribution system may be provided, which includes a detection device that outputs a data signal corresponding to a quantum signal detected through a quantum channel, and a TDC configured to measure the time difference between a first generation time of a first reference pulse included in a reference timing signal and a second generation time of a first encoding pulse included in the data signal. The TDC includes a delay line part into which input pulses having the respective time difference as width are input; and a code conversion part configured to generate a conversion code by aligning the elements of a thermometer code output by the delay line part according to the data path delay from the output node of the input pulse to the output node of each of a plurality of flip-flops included in the delay line part. The receiver is configured to use the generated conversion code to determine the time difference, and to determine that an eavesdropper is present in the quantum channel if the variance of the measured time difference falls outside a predetermined critical range.

[0039] In this case, the TDC may further include a second delay line part to which the input pulse is input. The code conversion part may be configured to align and merge the elements of the thermometer code output by the delay line part and the elements of the thermometer code output by the second delay line part according to the data path delay from the output node of the input pulse to the output nodes of each of the multiple flip-flops included in the delay line part and the second delay line part to generate the conversion code. [Effects of the Invention]

[0040] According to the present invention, it is possible to provide a technology that can precisely measure the reception timing of transmitted qubits and detect the presence of an attacker in real time based on the difference between the measured reception timing and a reference timing. [Brief explanation of the drawing]

[0041] [Figure 1] This shows an example configuration of a quantum key cryptography distribution system provided according to one embodiment. [Figure 2] This shows an example configuration of a quantum key cryptographic distribution system provided according to one embodiment of the present invention. [Figure 3] Figure 2 is a diagram illustrating the interaction between the TDC, detection device, and receiver control unit. [Figure 4] This describes a situation in a quantum key cryptography distribution system where an eavesdropper in the quantum channel intercepts the qubits sent by the sender to the receiver, performs the measurement they desire, and then sends qubits to the receiver that are advantageous to the eavesdropper. [Figure 5] This is an example of a data signal generated when a receiving device's detection device detects a quantum signal retransmitted by an eavesdropper. [Figure 6] The receiver's TDC, provided according to one embodiment of the present invention, represents a concept that measures the time difference between a pulse of a predetermined reference timing signal provided by the receiving control unit and a pulse of a data signal output by the detection device. [Figure 7] Figure 6 illustrates the configuration in which the roles of the start signal and the end signal are swapped. [Figure 8] This is a flowchart illustrating a method for determining whether or not an eavesdropper is present in a quantum channel, provided according to one embodiment of the present invention. [Figure 9] This is a flowchart illustrating a method for determining the presence or absence of an eavesdropper on a quantum channel, provided according to another embodiment of the present invention. [Figure 10] This diagram shows the configuration of an FPGA that embodies TDC according to one embodiment of the present invention. [Figure 11] This is a diagram illustrating the input pulses input to the first delay line part of an FPGA according to one embodiment of the present invention. [Figure 12] This shows the configuration of the first delay line part according to one embodiment of the present invention. [Figure 13] This is a diagram illustrating the buffer index in Figure 12. [Figure 14] This table illustrates data path delays. [Figure 15] Figures 15a and 15b show a configuration in parallel of multiple delay line parts according to one embodiment of the present invention. [Figure 16] Figure 16a shows the configuration of the first and second delay line parts in Figure 15b, and Figure 16b is for illustrating the operation of the code conversion part when two delay line parts are used according to one embodiment of the present invention. [Figure 17] This graph shows the delay depending on whether or not the code conversion part according to one embodiment of the present invention can be applied. [Figure 18] This diagram illustrates the array criteria for flip-flop output values ​​based on whether or not the code conversion part according to one embodiment of the present invention can be applied, and the increase in the number of taps in Figure 17. [Modes for carrying out the invention]

[0042] Embodiments of the present invention will be described below with reference to the accompanying drawings. However, the present invention is not limited to the embodiments described herein and can be embodied in various other forms. The terms used herein are for the purpose of aiding the understanding of the embodiments and are not intended to limit the scope of the present invention. Furthermore, the singular form used herein also includes the plural form unless the wording expressly indicates the opposite.

[0043] Figure 1 shows an example configuration of a quantum key cryptography distribution system provided according to one embodiment.

[0044] A quantum key cryptographic distribution system (1001) may consist of a sender (Alice) (100), a receiver (Bob) (200), a quantum channel (300), and a public channel (400).

[0045] The transmitter (Alice) (100) may include a laser diode (LD) (110), an intensity modulator (IM) (140), an unbalanced Mach-Zehnder interferometer, a fiber-integrated beam splitter (BS) (150), a phase modulator (PM) (180), a polarizing beam splitter (PBS) (190), a variable attenuator (VA) (160), a second beam splitter (175), and an optical power meter (OPM) (195).

[0046] The laser diode (LD) (110) can, for example, emit light pulses of 1550 nm at a frequency of 1 GHz.

[0047] The intensity modulator (IM) (140) and the unbalanced Mach-Zehnder interferometer transmit the emitted light pulses to the optical fiber integrated beam splitter (BS) (150).

[0048] One of the outputs of the beam splitter (BS) (150) reaches the final polarized BS (PBS) (190) via a first path that passes through the phase modulator (PM) (180), and the other reaches the final polarized BS (PBS) (190) via a second path that is longer than the first path.

[0049] The variable attenuator (VA) (160) sets the pulse intensity of the signal output by the final polarization BS (PBS) (190) to a desired level.

[0050] The optical power meter (OPM) (195) measures the total flux of the optical fiber observed through the second beam splitter (175) and adjusts the VA (160) in real time to maintain a constant value.

[0051] The receiver (200) includes a polarization control (PC) (250), a second interferometer, a receiving polarization BS (PBS) (290), a fiber-stretcher (FS) (233), a receiving phase modulator (PM) (280), a final BS (210), and a detection unit (DU) (260). The detection unit (DU) (260) may include a sensor that detects a single photon. The detection unit may be configured to receive an optical signal as input and output an electrical signal.

[0052] The signal output from the transmitter (Alice) (100) passes through a quantum channel, which is an optical fiber spool (300), and then through a second interferometer and polarization control (PC) (250) having a configuration matching that of the transmitter (Alice) (100).

[0053] In one arm, the optical fiber extender (FS) (233) is used to match the arm lengths between two separate interferometers, and the interference is generated in the final BS (210).

[0054] The pulse output by the final BS(210) is ultimately measured by the detection device (DU). The final BS(210) receives input from a portion of the photons that have passed through the receiving phase modulator (280) and a portion of the photons that have passed through the optical fiber expander (233). The final BS(210) has a first output port and a second output port. If the portions of the photons interfere with each other in a reinforcement manner (reinforcement interference), the photons may be output through the first output port, and if they interfere with each other in a destructive manner (cancellation interference), the photons may be output through the second output port.

[0055] The detection device (260) has a first input port and a second input port. The first output port of the final BS (210) is connected to the first input port of the detection device (DU), and the second output port of the final BS (210) is connected to the second input port of the detection device (DU). A photon representing a single qubit is input to only one of the first or second input ports of the detection device (260). The detection device (260) can determine that a bit of "1" is encoded when the photon is input through the first input port, and that a bit of "0" is encoded when the photon is input through the second input port.

[0056] The detection device (260) can output a digital signal (Sd) representing the binary value decoded from the photon at the time the photon is detected. The digital signal (Sd) is provided to the receiving control unit (270).

[0057] The transmitting control unit (170) included in the sender (100) can perform the function of randomly selecting the base and the binary information to be encoded, which are used to encode each qubit transmitted by the sender (100).

[0058] The receiver control unit (270) included in the receiver (200) can perform the function of randomly selecting a basis to be used to decode each received qubit.

[0059] The transmitting control unit (170) and the receiving control unit (270) can exchange predetermined information via a public channel (400) through a communication unit (not shown). The predetermined information may include information about a series of bases used by the transmitting control unit (170) and the receiving control unit (270).

[0060] The transmitting control unit (170) and the receiving control unit (270) may consist of a single device in a single package, or they may consist of a collection of multiple devices. The collection of multiple devices may include a high-speed FPGA, memory, and RAM.

[0061] The sender (100) and receiver (200) can share information regarding the transmission period of a series of qubits. The receiver (200) can also obtain information regarding the time or time interval at which the sender (100) begins transmitting the series of qubits, and thus the receiver (200) can prepare for receiving the transmitted qubits. The receiver (200) can then synchronize the time at which a single photon arrives at the receiver (200) with the time at which the receiver (200) detects the single photon. Specific configurations for the aforementioned techniques are already well known in this field.

[0062] In one embodiment, the single-photon detector may be configured to operate only when the enable signal input to the detection device (260) is in a specific logic state (e.g., logical high). The enable signal may be a predetermined reference timing signal (Srt). The generation period of a series of pulses included in the reference timing signal (Srt) may coincide with the generation period of a qubit generated by the transmitter (100).

[0063] The public channel (400) is used as a communication channel for the sender (Alice) and receiver (Bob) to publicly compare randomly selected bases with each other, or to publicly compare portions of generated cryptographic keys with each other. The public channel (400) can be an existing digital optical transmission channel or wireless communication channel.

[0064] Figure 2 shows an example configuration of a quantum key cryptographic distribution system provided according to one embodiment of the present invention.

[0065] The configuration of the quantum key cryptographic distribution system (1000) provided according to one embodiment of the present invention is the same as the configuration of the quantum key cryptographic distribution system (1001) presented in the comparative embodiment shown in Figure 1, except that the receiver (200) further includes a TDC (250) and a configuration for connecting the TDC (250) to other devices within the receiver (200). The following description will omit explanations of content common to Figure 1 and will focus on the differences from Figure 1.

[0066] Figure 3 is a diagram illustrating the interaction between the TDC, detection device, and receiver control unit shown in Figure 2.

[0067] TDC(250) can receive a data signal (Sd) output by the detection device (DU)(260). The data signal may also be provided to the receiving control unit (270).

[0068] TDC(250) can receive the reference timing signal (Srt) prepared and provided by the receiving control unit (270). The reference timing signal (Srt) may be a pulse train having the same period as the generation period of the qubit generated by the transmitter (100), or a pulse train signal synchronized with the generation period of the qubit.

[0069] TDC(250) can provide the receiving control unit (270) with a timing error (Te) value, which is information that allows it to determine whether or not the synchronization state between the data signal (Sd) and the reference timing signal (Srt) is maintained without interruption.

[0070] The TDC(250) can additionally utilize a clock signal (clk) provided by the receiving control unit (270) to generate the timing error (Te). An example of the clock signal (clk) is illustrated in Figure 11, which will be described later.

[0071] The data signal (Sd) and the reference timing signal (Srt) are both signals in the form of pulse trains. If there is no eavesdropper (Eve) in the quantum channel (300), the pulses in the data signal (Sd) remain synchronized with the pulses in the corresponding reference timing signal (Srt). That is, for example, if the time difference between the rising edge of the first pulse in the data signal (Sd) and the rising edge of the first pulse in the corresponding reference timing signal (Srt) is ΔT1, then the time difference between the rising edge of any other second pulse in the data signal (Sd) and the rising edge of the corresponding second pulse in the reference timing signal (Srt) will also be ΔT1.

[0072] However, if an eavesdropper (Eve) is present in the quantum channel (300), the pulses contained in the data signal (Sd) and the pulses contained in the reference timing signal (Srt) may be out of synchronization (the specific reason for this will be explained later in Figure 4). That is, for example, if the time difference between the rising edge of the first pulse contained in the data signal (Sd) and the rising edge of the corresponding first pulse of the reference timing signal (Srt) is ΔT1, then the time difference between the rising edge of any other second pulse contained in the data signal (Sd) and the rising edge of the corresponding second pulse of the reference timing signal (Srt) may be ΔT1, or it may be a different ΔT2 or ΔT3.

[0073] Figure 4 illustrates a situation in a quantum key cryptography distribution system where an eavesdropper in the quantum channel intercepts the qubit that the sender (Alice) is sending to the receiver (Bob), performs the measurement they desire, and then sends a qubit to the receiver (Bob) that is in a state advantageous to them.

[0074] Figure 4 illustrates five quantum signals (QI1 to QI5) transmitted by the sender (100) through the quantum channel (300).

[0075] The eavesdropper (700) can intrude into the quantum channel (300) and block the quantum signal transmitted by the sender (100) so that it does not reach the receiver (200).

[0076] The eavesdropper (700) can measure the quantum signal transmitted by the transmitter (100) and retransmit the reconstructed quantum signal to the receiver (200) according to rules set by the eavesdropper (700). In this case, the reconstructed quantum signal is reconstructed based on the quantum signal measured by the eavesdropper (700), and the rules for reconstruction may be set by the eavesdropper (700). In other words, the eavesdropper (Eve) (700) can use the efficiency mismatch of the single-photon detector (single-photon detection unit) to arbitrarily adjust the delay of signal generation to the side with higher efficiency and determine the output (time shift attack).

[0077] In the example shown in Figure 4, the eavesdropper (700) has determined that the qubits represented by quantum signals (QI1), (QI2), (QI3), (QI4), and (QI5), respectively, detected through the quantum channel (301), are 1, 1, 1, 0, and 0. The eavesdropper (700) can then retransmit the determined qubits and the reconstructed quantum signals (QI1'~QI5') according to the basis set he or she has chosen to the receiver (200).

[0078] The graph in the center right of Figure 4 (@700) shows, in pulse form, the timing at which the eavesdropper (700) detected the quantum signal input to the eavesdropper (700) through the quantum channel (301).

[0079] Since the quantum signals (QI1~QI5) transmitted by the sender (100) occur according to a fixed generation interval T, the eavesdropper (700) detects the quantum signals at fixed intervals T. However, the eavesdropper (700) does not fix the generation interval of the quantum signals (QI1'~QI5') that it reproduces to T. That is, while the generation interval of the quantum signals (QI1~QI5) transmitted by the sender (100) is a fixed value T, the generation interval of the quantum signals (QI1'~QI5') retransmitted by the eavesdropper (700) may not be a fixed value. The variation in the generation interval of the quantum signals (QI1'~QI5') retransmitted by the eavesdropper (700) may be intentional on the part of the eavesdropper (700). For example, the difference in the generation times of two consecutive quantum signals retransmitted by the eavesdropper (700) could be T, or T+2*ΔTad, T-2*ΔTad, or any other value.

[0080] Here, ΔTa can be a very small value compared to T. Therefore, in order for the receiver (200) to know that there is variation in the reception time interval of the quantum signals (QI1'~QI5') received by the receiver (200), the receiver (200) must use a very sophisticated timing measurement device. In Figure 4, the difference in the generation interval between the quantum signals (QI1'~QI5') retransmitted by the eavesdropper (700) is visually clearly shown, but this may be an exaggeration for the sake of explanation.

[0081] Even if ΔTad is a very small value compared to T, the state of a quantum signal determined when the receiver's (200) detection device (260) measures a quantum signal at time t1 may be different from the state of the quantum signal determined when it is measured at time t1+ΔTad or t1-ΔTad.

[0082] In this way, the eavesdropper (700) can intercept the quantum signal transmitted by the sender (100), adjust the transmission interval of the quantum signal, and re-transmit the reconstructed quantum signal to the receiver (200), thereby interfering with the quantum key cryptography distribution system (1000).

[0083] Figure 5 shows an example of a data signal generated when a receiving device's detection device detects a quantum signal retransmitted by an eavesdropper.

[0084] The detection device (260) can output detection information at the time of reception of quantum signals (QI1'~QI5') retransmitted by the eavesdropper (700) through the quantum channel (302), and the detection information can be provided as pulses of data signals (Sd) output by the detection device (260). In the example shown in Figure 5, the time interval between the received quantum signals is not synchronized with a predetermined reference timing signal (exemplified in Figure 6) having a constant period, so the interval between pulses of the data signal (Sd) is not fixed to a value T. That is, the time difference between the rising edge of any selected encoding pulse from the data signal (Sd) and the rising edge of the reference pulse of the reference timing signal corresponding to the selected encoding pulse is not fixed to a constant value for each pulse.

[0085] Figure 6 illustrates a concept in which a receiver's TDC, provided according to one embodiment of the present invention, measures the time difference between a pulse of a predetermined reference timing signal provided by the receiving control unit and a pulse of a data signal output by the detection device.

[0086] As described above, the receiver control unit (270) of the receiver (200) can prepare and provide to the TDC (250) a reference timing signal (Srt) consisting of pulses with a fixed time interval. In this specification, each pulse of the reference timing signal (Srt) is referred to as a reference pulse.

[0087] Furthermore, the receiver's (200) detection device (260) can provide the data signal (Sd) to the TDC (250). If an eavesdropper (700) is present in the quantum channel (200), the time intervals of the pulses contained in the data signal (Sd) may not be constant, as shown in Figure 5. In this specification, each pulse of the data signal (Sd) is referred to as an encoding pulse.

[0088] A TDC(250) provided according to one embodiment of the present invention is configured to measure and output the difference in the generation times of a start signal and an end signal input to the TDC(250). In one embodiment, the start signal may be the respective reference pulse, and the end signal may be the respective encoding pulse. For this purpose, a reference timing signal (Srt) and a data signal (Sd) may be input to the TDC(250), as shown in Figure 3. The reference timing signal (Srt) may have multiple start signals, and the data signal (Sd) may have multiple end signals. Each pulse in the reference timing signal (Srt) is its respective start signal, and each pulse in the data signal (Sd) is its respective end signal.

[0089] A reference pulse is generated at regular reference time intervals (T) for the reference timing signal (Srt), but encoding pulses may not be present in the data signal (Sd) for a period of time more than twice the reference time interval (T). This is because, even if the transmitter (100) transmits a photon signal, some photon signals may not be output from the transmitter (100) due to practical factors of the transmitter's (100) equipment, and photon signals traveling in the quantum channel (300) may disappear due to environmental influences. Figure 6 shows an example in which five photon signals continuously transmitted by the transmitter (100) are all detected by the eavesdropper (700), and all photon signals retransmitted by the eavesdropper (700) are detected by the receiver (200).

[0090] The example shown in Figure 6 illustrates a scenario where all photons intended by the sender are transmitted and detected; however, this is merely an example presented for illustrative purposes. In real-world environments, the probability of detection is extremely low due to quantum efficiency, and losses are highly likely to occur during the laser-based photon generation and transmission process.

[0091] As shown in Figure 6, the rising edge of the first reference pulse (Pr1) of the reference timing signal (Srt) lags behind the rising edge of the first encoding pulse (Pq1) of the data signal (Sd) by ΔTad. The rising edge of the second reference pulse (Pr2) lags behind the rising edge of the second encoding pulse (Pq2) by ΔTad. The rising edge of the third reference pulse (Pr3) lags behind the rising edge of the third encoding pulse (Pq3) by ΔTad. The rising edge of the fourth reference pulse (Pr4) leads the rising edge of the fourth encoding pulse (Pq4) by ΔTad. The rising edge of the fifth reference pulse (Pr5) leads the rising edge of the fifth encoding pulse (Pq5) by ΔTad.

[0092] In other words, the generation times of the five encoding pulses shown in Figure 6 are +ΔTad, +ΔTad, +ΔTad, -ΔTad, and -ΔTad respectively, ahead of the generation times of the five corresponding reference pulses.

[0093] In other words, if an eavesdropper (700) is present in the quantum channel (300), the time difference between the generation time of the encoding pulse contained in the data signal (Sd) output by the detection device that detects the quantum signal and the generation time of the reference pulse contained in a predetermined reference timing signal (Srt) has a non-zero variance.

[0094] In contrast, if there is no eavesdropper (700) in the quantum channel (300), it can be understood that the variance of the value relating to the time difference between the generation time of the encoding pulse contained in the data signal (Sd) output by the detection device that detects the quantum signal and the generation time of the reference pulse contained in a predetermined reference timing signal (Srt) is theoretically 0.

[0095] Figure 7 illustrates the configuration shown in Figure 6, but with the roles of the start signal and end signal reversed.

[0096] Figure 7 shows an embodiment in which the start signal is the respective encoding pulse and the end signal is the respective reference pulse.

[0097] Figure 8 is a flowchart illustrating a method for determining the presence or absence of an eavesdropper on a quantum channel, provided according to one embodiment of the present invention.

[0098] In step (S110), the receiver (200)'s TDC (250) can measure the time difference between the generation time of the first encoding pulse included in the data signal (Sd) output by the receiver (Bob) (200)'s detection device (260) and the generation time of the first reference pulse included in a predetermined reference timing signal (Srt).

[0099] The reference timing signal (Srt) may be a pulse train having the same period as the generation period of the qubit generated by the transmitter (100), or a pulse train signal synchronized with the generation period of the qubit.

[0100] The aforementioned reference timing signal (Srt) may be a pulse train signal having the same period as the generation period of the quantum signal transmitted by the transmitter (100).

[0101] In one embodiment, the time difference may be the time difference between the rising edge of the first encoding pulse and the rising edge of the first reference pulse.

[0102] Here, the first encoding pulse may be the encoding pulse that is closest in time to the first reference pulse among a plurality of encoding pulses included in the data signal (Sd).

[0103] Here, the first reference pulse may be one of several reference pulses included in the reference timing signal (Srt) that is closest in the time axis to the first reference encoding pulse.

[0104] In step (S120), the receiver's (200) receiver control unit (270) can determine that if the measured time difference falls outside a predetermined critical range, an eavesdropper is present in the quantum channel through which the quantum signal passes for quantum cryptographic communication.

[0105] Figure 9 is a flowchart illustrating a method for determining the presence or absence of an eavesdropper on a quantum channel, provided according to another embodiment of the present invention.

[0106] In step (S210), the receiver (200)'s TDC (250) can measure the time difference between the generation time of the encoding pulse included in the data signal (Sd) output by the receiver (Bob) (200)'s detection device (260) and the generation time of the reference pulse included in a predetermined reference timing signal (Srt).

[0107] In step (S220), the receiver's (200) receiver control unit (270) can determine that if the variance of the measured time difference falls outside a predetermined critical range, an eavesdropper is present in the quantum channel through which the quantum signal passes for quantum cryptographic communication.

[0108] For example, in one embodiment, if the variance of the measured time difference is substantially zero, it can be determined that there is no eavesdropper, and if the variance is substantially greater than zero, it can be determined that there is an eavesdropper.

[0109] In other embodiments, if the variance of the measured time difference is less than δ, it can be determined that there is no eavesdropper, and if the variance is substantially greater than δ, it can be determined that there is an eavesdropper (provided that δ > 0).

[0110] The operating principle of TDC(250) provided according to one embodiment of the present invention will be described in detail below. The TDC(250) is implemented in FPGA(1). Alternatively, in other embodiments, the TDC(250) may be implemented in an IC or ASIC, etc.

[0111] Figure 10 shows a diagram of the FPGA configuration that embodies TDC according to one embodiment of the present invention.

[0112] When the receiving control unit (270) shown in Figure 2 is an FPGA, the FPGA (1) that embodies the TDC (250) can be the receiving control unit (270).

[0113] In contrast, if the receiving control unit (270) shown in Figure 2 is not an FPGA, the TDC (250) can be implemented with an FPGA provided separately from the receiving control unit (270).

[0114] The aforementioned TDC(250) can be realized not only with a high-speed FPGA operating at a clock speed of, for example, 10 GHz, but also with a relatively low-speed FPGA operating at a clock speed of, for example, 100-300 MHz.

[0115] Figure 11 is a diagram illustrating the input pulses input to the first delay line part of an FPGA according to one embodiment of the present invention.

[0116] The following explanation will refer to both Figure 10 and Figure 11.

[0117] The FPGA(1) may include an input signal generation part (10), a first delay line part (20), a code conversion part (30), a clock pulse count part (40), a priority encoder part (50), and an arithmetic part (60).

[0118] Specifically, the FPGA(1) configuration described above could be a TDC (Time to Digital converter) configuration.

[0119] As shown in Figures 10 and 11, the input signal generation part (10) can generate an input pulse (P1) whose width is the time difference (T) between the rising edge (E1) of a predetermined given start signal (S1) and the rising edge (E2) of a predetermined given end signal (S2). The input signal generation part (10) may consist of logic gates necessary for the above generation.

[0120] The first delay line part (20) can receive an input pulse (P1) having a width equal to the time difference (T) between the start signal (S1) and the end signal (S2). The first delay line part (20) can output a thermometer code (O1). In this case, the thermometer code can be defined as an 8-bit value consisting of the output values ​​of the flip-flops included in the first delay line part (20), and the output values ​​of each flip-flop can be referred to as elements of the thermometer code.

[0121] Figure 12 shows the configuration of the first delay line part according to one embodiment of the present invention.

[0122] Figure 13 is a diagram illustrating the buffer index in Figure 12.

[0123] The first delay line part (20) may include a delay line (D_L) containing a plurality of buffers (delay elements) (B), and D-flip-flops (FFs) tapped to the output terminals of each buffer (B) of the delay line.

[0124] Multiple buffers can be linked together in a cascade delay scheme. That is, multiple buffers can be arranged according to the order in which the input pulses (P1) flow.

[0125] The waveform (Signal) of the input pulse (P1) in Figure 12 can be output at the output terminals of each buffer (B) with a predetermined delay. That is, the output value of the first buffer (B1) is output at the output terminal of the first buffer (B1) with a predetermined delay, and the output terminal of the first buffer (B1) is connected to the input terminal of the second buffer (B2). The output value of the first buffer (B1) (for example, '1') can also be input to the first flip-flop (FF1).

[0126] In this process, data path delays may occur between each buffer (B) and through the flip-flops (FF). For example, a delay of d1 may occur before the input value ('1') of the first buffer (B1) is transmitted to the second buffer (B2), and a delay of d11 may occur before the output value ('1') of the first buffer (B1) is transmitted to the first flip-flop (FF1). Similarly, a delay may occur each time data is transmitted from one buffer to the next, and each time data is transmitted from any buffer to a flip-flop connected to that buffer.

[0127] Figure 13 is a diagram illustrating the buffer index according to one embodiment of the present invention.

[0128] Each field in the table in Figure 13 represents the buffer name, index, and buffer output value.

[0129] Each buffer may be assigned an index that defines the order of the buffers. For example, the first buffer (B1) may be assigned index '1', the second buffer (B2) may be assigned index '2', and similarly the eighth buffer (B8) may be assigned index '8'. When each buffer (B) is arranged in the order in which the input pulses (P1) flow, and the indices are arranged according to that order, for example, 1000 buffers may each be assigned an index from 1 to 1000.

[0130] Figure 14 shows a table illustrating data path delay.

[0131] Referring to Figures 10 and 14, the code conversion part (30) can convert the order of elements (e.g., 1, 2, 3, 4, 5, 6, 7, 8) of the thermometer code (O1) (e.g., 11100000) output by the first delay line part (20) and output it. At this time, the code output by the code conversion part (30) (e.g., 11010000) (the order of the indices in the buffer is 1, 2, 4, 5, 3, 6, 7, 8) can be called the "converted code (CO1)".

[0132] The converted code (CO1) output by the code conversion part (30) may be an arrangement of the elements of the thermometer code (O1) according to a predetermined criterion. In this case, the predetermined criterion may be the data path delay from the output node (N1) of the input pulse (P1) to the output node (N2) of each of the multiple flip-flops (FF) included in the first delay line part (20). This will be explained in detail with reference to Figure 14.

[0133] Each field in the table can represent a buffer index number, a first delay value, a second delay value, and a summation value (rank). In this case, the rank can represent the rank relative to the overall summation value. In this case, the buffer with the smallest summation value can have rank 1, and the buffer with the highest summation value can have the last rank, or the opposite in other embodiments.

[0134] As detailed in Figure 12, the sum value may represent the time it takes for data to be transmitted from the node (N1) where the input pulse (P1) is output to any flip-flop (e.g., FF4).

[0135] A first delay may occur, which is the time it takes for the input value of any buffer to be transmitted to another buffer adjacent to that buffer, and a second delay may occur, which is the time it takes for the output value of any buffer to be transmitted to the input of a flip-flop connected to that buffer.

[0136] In this case, the sum of the first delay value and the second delay value for each buffer can be called the data path delay.

[0137] Referring to both Figures 12 and 14, when the indices of each buffer are listed in order, the rank of the sum of the values ​​of the first and second delays may differ from the rank of the index numbers of each buffer. For example, in the case of the third buffer, the buffer array rank is 3, so the index number is '3', but the rank of the sum may be '5'. Looking at it in more detail, in order for data to be transmitted to the third flip-flop (FF3), it must pass through the first buffer (B1), the second buffer (B2), and the third buffer (B3). At this time, predetermined delays (d1, d2, d3) occur each time the data passes through the first buffer (B1), the second buffer (B2), and the third buffer (B3), and a delay (d13) may also occur before the data output from the third buffer (B3) is output as the output value of the third flip-flop (FF3). In other words, the delay from the output node (N1) of the input pulse (P1) to the output nodes (N2, N23) of the third flip-flop (FF3) can be the sum of d1, d2, d3, and d13.

[0138] In this way, the delay (i.e., the sum) until data is transmitted to the output node of each flip-flop (FF3) can be calculated.

[0139] For example, in this embodiment, the buffer index for the third flip-flop (FF3) is 3, and the buffer index for the fourth flip-flop (FF4) is 4. That is, even though the fourth flip-flop (FF3) must pass through one more buffer than the third flip-flop (FF4), the combined delay to the output node of the third flip-flop, which has a buffer index of 3, may be greater.

[0140] The code conversion part (30) can convert the order of the elements of the thermometer code (O1) based on the calculated delay (sum value) (for example, from smallest sum value to largest).

[0141] The converted code (CO1) output by the code conversion part (30) may be provided to the priority encoder part (50).

[0142] The priority encoder part (50) can digitize long thermometer codes. For example, the priority encoder part (50) can convert a 5200-bit thermometer code into a 13-bit thermometer code. For example, if there are 5200 buffers (delay elements) (B) and 5200 flip-flops (FFs) connected to the buffers, as detailed in Figure 12, then 5200 consecutive binary numbers will be output, which can be represented as a 13-bit binary number.

[0143] In other words, the priority encoder part (50) can represent the 5200-bit first thermometer code (TC1) and the second thermometer code (TC2) as 13-bit binary numbers, respectively, as the time-dependent output value (CO1) of the code conversion part (30).

[0144] Referring to Figure 11, the first thermometer code (TC1) may be a code output by the code conversion part (30) in relation to the rising edge of the input pulse (P1) at the rising edge (E4) of the first clock pulse (CK2) that occurred after the rising edge (E1) of the input pulse (P1) among the generated clock pulses (CK). The first thermometer code (TC1), represented in 13 bits, may be provided as input to the arithmetic part (60).

[0145] The second thermometer code (TC2) may be the code output by the code conversion part (30) in relation to the falling edge (E2) of the input pulse (P1) at the time of the rising edge (E6) of the first clock pulse (CK4) that occurred after the falling edge (E2) of the input pulse (P1) among the generated clock pulses (CK). The second thermometer code (TC2), represented in 13 bits, may be provided as input to the arithmetic part (60).

[0146] In this case, the time intervals of the first thermometer code (TC1) and the second thermometer code (TC2) may be smaller than the period of the clock pulse (CK).

[0147] Referring again to Figures 10 and 11, the clock pulse count part (40) can receive an input pulse (P1) from the input signal generation part (10).

[0148] The clock pulse count part (40) can count the number of clock pulses (CK) that occur during the duration (T) of the input pulse (P1). For example, in Figure 11, since there are two rising edges of the clock pulses that occur during the period when the input pulse (P1) is ON, such as edges (E4, E5), the counted value may be 2.

[0149] The output value (coarse count) of the clock pulse count part (40), i.e., the counted value, may be provided to the calculation part (60).

[0150] Referring to Figures 10 and 11, the calculation part (60) can determine the value of the occurrence time difference using the first thermometer code (TC1), the second thermometer code (TC2), and the number of counted clock pulses. For example, the occurrence time difference may be 2*Period+TC1-TC2.

[0151] Figures 15a and 15b show a configuration in parallel of multiple delay line parts according to one embodiment of the present invention.

[0152] As shown in Figure 15a, two or more delay line parts (20) can be connected in parallel. In this case, the input pulse (P1) output from the input signal generation part (10) can be input to the first delay line part (21), the second delay line part (22), the third delay line part (23), and the fourth delay line part (24), respectively. The first thermometer code (O1), the second thermometer code (O2), the third thermometer code (O3), and the fourth thermometer code (O4) output from the first delay line part (21), the second delay line part (22), the third delay line part (23), and the fourth delay line part (24) can then be input to the code conversion part (30).

[0153] As shown in Figure 15b, in another embodiment, we can assume that two delay line parts (20) are connected in parallel.

[0154] For example, an input pulse (P1) output from the input signal generation part (10) can be provided along a first path (path1) through which the output terminal of the input signal generation part (10) and the input terminal of the first delay line part (21) are connected, and along a second path (path2) through which the output terminal of the input signal generation part (10) and the input terminal of the second delay line part (22) are connected.

[0155] In this case, the time it takes for the input pulse (P1) output from the input signal generation part (10) to reach the input terminal of the first delay line part (21) and the input terminal of the second delay line part (22) may be different. This is because there is an input delay due to the difference in length between the first path (path1) and the second path (path2). In the embodiment shown in Figure 15a, since the length of the first path (path1) is shorter than the length of the second path (path2), it can be seen that the input time interval of the input pulse (path1) through the first path (path1) is smaller than the input time interval of the input pulse (path2) through the second path (path2).

[0156] Figure 16a shows the configuration of the first and second delay line parts in Figure 15b, and Figure 16b is for illustrating the operation of the code conversion part when two delay line parts are used according to one embodiment of the present invention.

[0157] In Figure 16a, for the sake of explanation, each delay line part is shown to contain four buffers and four flip-flops.

[0158] In Figure 16b, each field in the table can represent the delay line part number, buffer index number, first delay value, second delay value, first sum value (first rank), and first sum value (overall rank). In this case, the first rank can represent the rank of each sum value relative to the buffer index of the buffers within each delay line part. The overall rank can represent the rank of each sum value relative to the buffer index of all buffers in the first and second delay line parts. In this case, the buffer with the smallest sum value can have rank 1, and the buffer with the highest sum value can have rank 3. Or, in other embodiments, the opposite is possible. The method for calculating the sum value is as described in Figure 10.

[0159] The code conversion part (30) may be configured to sort and merge the elements of a first set (e.g., {(D1, 1), (D2, 2), (D3, 3), (D4, 4)}) which is a list of pairs of sums of elements and buffer indices of the thermometer code output by the first delay line part (21) in ascending order of sum, and the elements of a second set (e.g., {(D5, 5), (D6, 6), (D7, 7), (D8, 8)}) which is a list of pairs of sums of elements and indices of the thermometer code output by the second delay line part (22) in ascending order of sum, in order to generate a single conversion code.

[0160] In other words, each element in the first set and each element in the second set can be sorted in descending order of their summation.

[0161] For example, the buffer index reference output values ​​in the first delay line part (21) may be {1, 2, 3, 4}, and the buffer index reference output values ​​in the second delay line part (22) may be {5, 6, 7, 8}. In the embodiments of Figures 15b and 16a, delay (d1) may be smaller than delay (d5). Therefore, the sorted order may be (D1, 1), (D2, 2), (D5, 5), (D3, 3), (D6, 6), (D4, 4), (D7, 7), (D8, 8). The flip-flop output values ​​for each buffer index can be sorted according to the sorted order described above. For example, the sorted values ​​(buffer indices) may be 0(1), 0(2), 1(4), 1(6), 1(3), 1(5), 0(7), 0(8).

[0162] As mentioned above, when multiple delay line parts (20) are used, they may have slightly different input delays depending on their arrangement. Figure 17, described below, shows the delays due to the arrangement when multiple delay line parts are used.

[0163] Figure 17 shows a graph of delays depending on whether the code conversion part according to one embodiment of the present invention can be applied.

[0164] Figure 18 is a diagram illustrating the array criteria for flip-flop output values ​​depending on whether the code conversion part according to one embodiment of the present invention can be applied, and the increase in the number of taps in Figure 17.

[0165] Figure 17(a) shows a delay graph based on the number of taps when the code conversion part (30) is not applied, and Figure 17(b) shows a delay graph based on the number of taps when the code conversion part (30) is applied.

[0166] The fields in the table in Figure 18 include the sorting order, the sorting criteria for the flip-flop output values, and the sorting order of the total delay sum.

[0167] The following explanation will refer to both Figures 17 and 18.

[0168] The horizontal axis of the graph (g1, g2) represents the number of taps. Referring to Figure 16b, one tap may represent a pair of buffers (delay elements) (e.g., B1) and a flip-flop (FF1) connected to it. For example, if the total number of pairs of buffers and connected flip-flops is 1000, then the total number of taps may be 1000.

[0169] The vertical axis of the graph (g1, g2) represents the delay time (ns). This delay time can represent the sum of the delays required for data to be transmitted to the output nodes of the flip-flops tapped to each buffer, as detailed in Figure 14.

[0170] Referring to FIGS. 16a to 18 together, an increase in the number of taps in graph (g1) may mean, for example, an increase in the buffer index. For example, when the number of taps on the horizontal axis of graph (g1) is 4, it may mean buffer index 4. At this time, the delay value on the vertical axis of graph (g1) may be D4 (= d1 + d2 + d3 + d4 + d14) as shown in FIG. 16b. For example, when the number of taps is 5, it may mean buffer index 5. At this time, the delay value on the vertical axis of graph (g1) may be D5 (= d5 + d15) as shown in FIG. 16b. At this time, referring to FIG. 18, D4 > D5 may be possible. Here, it can be known that the delay observed in each flip-flop of the tap does not increase as the index of the tap (for example, index 4 -> index 5) increases, but there may also be a case where it locally decreases even when the index of the tap increases.

[0171] On the other hand, an increase in the number of taps in graph (g2) does not mean an increase in the buffer index, but may mean an increase in the position according to the alignment order in the state where the output values of each flip-flop are aligned by the code conversion part (30). For example, when the number of taps on the horizontal axis of graph (g2) is 4, the position order of the aligned buffer index is 1, 2, 5, 3, which may mean buffer index 3. And the delay value on the vertical axis of graph (g2) in this case may be D3 (= d1 + d2 + d3 + d13). For example, when the number of taps is 5, the position order of the aligned buffer index is 1, 2, 5, 3, 6, which may mean buffer index 6. And the delay value in this case may be D6 (= d5 + d6 + d16). At this time, referring to FIG. 18, D3 < D6 may be possible.

[0172] In other words, as shown in Figure 17(a), when the code conversion part (30) of the present invention is not applied, it can be seen that the graph (g1) for delay due to an increase in the number of taps does not exhibit a monotonically increasing property. On the other hand, as shown in Figure 17(b), when the code conversion part (30) of the present invention is applied, it can be seen that the graph (g2) for delay due to an increase in the number of taps exhibits an increasing phenomenon without decrease.

[0173] For example, unlike ASICs, which are custom-ordered semiconductors, FPGAs can be directly designed through programming, allowing the chip's functionality to be changed through programming. Therefore, unlike ASICs, the functionality of each component included in an FPGA can change (or depending on the arrangement of the components), so the delay does not always increase with each increase in the number of taps; it may decrease, and it may not even result in an increase without a decrease.

[0174] However, as explained, through graph (g2), we can see that the code conversion part (30) can compensate for the monotonically increasing property of the first delay line part (20).

[0175] As described above, when multiple delay line parts (20) are used, delay alignment can be provided through the code conversion part. As a result, errors due to jitter can be corrected and a TDC with high time resolution can be provided. For example, if four delay line parts are configured in parallel and have a total of 9600 taps, a TDC with a resolution of 0.8 ps per tap can be provided.

[0176] By utilizing the embodiments of the present invention described above, those in the art of the present invention will be able to easily make a variety of changes and modifications without deviating from the essential characteristics of the invention. The content of each claim may be combined with other unreferenced claims as can be understood herein.

Claims

1. A receiving device for a quantum cryptographic key distribution system, comprising: a detection device that outputs a data signal corresponding to a quantum signal detected through a quantum channel; and a TDC configured to measure the time difference between a first generation time of a first reference pulse included in a reference timing signal and a second generation time of a first encoding pulse included in the data signal, wherein the TDC includes a delay line part into which an input pulse having the time difference as its width is input; and a code conversion part configured to generate a conversion code by aligning the elements of a thermometer code output by the delay line part according to the data path delay from the output node of the input pulse to the output node of each of a plurality of flip-flops included in the delay line part, and configured to determine the time difference using the generated conversion code, and is configured to determine that an eavesdropper is present in the quantum channel if the measured time difference falls outside a predetermined critical range.

2. The receiving device for a quantum cryptographic key distribution system according to claim 1, wherein the reference timing signal is a pulse train signal synchronized with the quantum signal output by the transmitting device.

3. The receiving device for a quantum cryptographic key distribution system according to claim 1, wherein the reference timing signal is a pulse train signal having the same period as the generation period of the quantum signal output by the transmitting device.

4. The receiving device for a quantum cryptographic key distribution system according to claim 1, wherein the time difference is the time difference between the rising edge of the first encoding pulse and the rising edge of the first reference pulse.

5. The receiving device for a quantum cryptographic key distribution system according to claim 1, wherein the first encoding pulse is the encoding pulse that is closest in time to the first reference pulse among a plurality of encoding pulses included in the data signal.

6. The receiving device for a quantum cryptographic key distribution system according to claim 1 further comprises: a computation part configured to determine the time difference using the generated conversion code;

7. The receiving device for a quantum cryptographic key distribution system according to claim 1, wherein the TDC further includes a second delay line part to which the input pulse is input, and the code conversion part is configured to align and merge the elements of the thermometer code output by the delay line part and the elements of the thermometer code output by the second delay line part according to the data path delay from the output node of the input pulse to the output nodes of each of the plurality of flip-flops included in the delay line part and the second delay line part to generate the conversion code.

8. The receiving device for a quantum cryptographic key distribution system according to claim 6, wherein the TDC is embodied by one of the following devices: FPGA (Field Programmable Gate Array), ASIC (Application Specific Integrated Circuit), and IC (Integrated Circuit), and the one of the following devices is programmed to include the delay line part and the arithmetic part.

9. The receiving device for a quantum cryptographic key distribution system according to claim 8, wherein the TDC is configured to utilize a clock signal having a period shorter than the generation period of the quantum signal output by the transmitting device, and the TDC further includes an input signal generation part that generates an input pulse having a width equal to the time difference between the time of occurrence of the rising edge of the first reference pulse and the time of occurrence of the rising edge of the first encoding pulse; and a clock pulse count part that counts the number of clock pulses of the clock signal that occurred during the maintenance period of the input pulse, and the calculation part is configured to determine the value of the time difference using a first thermometer code (TC1) output by the code conversion part at the time of the rising edge of the first clock pulse among the generated clock pulses, a second thermometer code (TC2) output by the code conversion part at the time of the rising edge of the clock pulse that occurred immediately after the last clock pulse among the generated clock pulses, and the number of counted clock pulses.

10. A receiving device for a quantum cryptographic key distribution system, comprising: a detection device that outputs a data signal corresponding to a quantum signal detected through a quantum channel; and a TDC configured to measure the time difference between a first generation time of a first reference pulse included in a reference timing signal and a second generation time of a first encoding pulse included in the data signal, wherein the TDC includes a delay line part into which input pulses having the respective time difference as width are input; and a code conversion part configured to generate a conversion code by aligning the elements of a thermometer code output by the delay line part according to the data path delay from the output node of the input pulse to the output node of each of a plurality of flip-flops included in the delay line part, and configured to determine the time difference using the generated conversion code, and configured to determine that an eavesdropper is present in the quantum channel if the variance of the measured time difference falls outside a predetermined critical range.

11. The receiving device for a quantum cryptographic key distribution system according to claim 10, wherein the reference timing signal is a pulse train signal having the same period as the generation period of the quantum signal output by the transmitting device.

12. The receiving device for a quantum cryptographic key distribution system according to claim 10, characterized in that the first encoding pulse is the occurrence time of any selected encoding pulse, and the first reference pulse is compared with the occurrence time of the reference pulse closest to the selected encoding pulse in the time axis.

13. The receiving device for a quantum cryptographic key distribution system according to claim 12, wherein the TDC further includes a second delay line part to which the input pulse is input, and the code conversion part is configured to align and merge the elements of the thermometer code output by the delay line part and the elements of the thermometer code output by the second delay line part according to the data path delay from the output node of the input pulse to the output nodes of each of the plurality of flip-flops included in the delay line part and the second delay line part to generate the conversion code.