Quantum key distribution method and quantum key distribution system

The method and system for QKD with an optical amplifier and controlled gain settings secure key distribution over long distances by minimizing detectable signal leakage, addressing security and energy efficiency issues in existing protocols.

JP7713246B2Active Publication Date: 2025-07-25TERRA QUANTUM AG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023179521
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-11-10
Filing Date
2023-10-18
Publication Date
2025-07-25
Estimated Expiration
2043-10-18

AI Technical Summary

Technical Problem

Existing quantum key distribution (QKD) protocols are limited by the need for repeaters to amplify optical signals over long distances, which can compromise security due to potential manipulation by eavesdroppers.

Method used

A method and system for QKD that includes an optical amplifier with an active fiber section and a pumping device, where the target maximum gain and operating gain are determined to minimize detectable optical signal leakage, preventing eavesdroppers from diverting optical signals while avoiding unnecessary high energy consumption.

Benefits of technology

Secures QKD by limiting eavesdropper manipulation and reducing energy waste, enabling secure key distribution over extended distances without compromising security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007713246000007
    Figure 0007713246000007
  • Figure 0007713246000008
    Figure 0007713246000008
  • Figure 0007713246000009
    Figure 0007713246000009
Patent Text Reader

Abstract

To provide a quantum key distribution method for increasing the security against potential eavesdropping when amplifying optical signals.SOLUTION: A method is implemented in a quantum key distribution system comprising: a transmission line 10 for transmitting optical signals between a first data processing device 11 and a second data processing device 12; and an optical amplifier 14 disposed at the transmission line, the optical amplifier comprising an active fiber section 15 and a pumping device 16. The method comprises: determining a ratio between a target maximum gain and a target operating gain of the optical amplifier; determining an active fiber section length such that the optical signals with a target maximum signal power are amplified with at most the target maximum gain; determining an operating pumping power of the pumping device below the maximum pumping power such that the optical signals are amplified with a target operating gain according to the ratio between the target maximum gain and the target operating gain, so as to operate the pumping device; and determining a shared key between the data processing devices by quantum key distribution comprising amplifying the optical signals via the optical amplifier.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a quantum key distribution method and a quantum key distribution system.

Background Art

[0002] Quantum key distribution (QKB) provides a way to secretly share a symmetric key between two parties by enhancing security during communication and authentication. However, existing QKB protocols are often limited to communications within a few kilometers. In particular, since the information carrying the quantum signal generally attenuates over long distances, a repeater along the quantum channel for amplifying the signal is required.

[0003] For example, U.S. Patent No. 11165570B2 describes a method of operating a QKB communication network node with an amplified optical section. Since the actual realization of QKB usually depends on an intermediate trusted node, security can be significantly compromised.

[0004] U.S. Patent Application Publication No. 2003 / 0035204A1 describes using amplified spontaneous emission as a pumping source to thereby enhance the amplification ability of a two-stage L-band erbium-doped fiber amplifier. A graph showing the gain versus the length of the erbium-doped fiber is presented. U.S. Patent No. 11271358B2 relates to the control of heating in an active-doped optical fiber.

Summary of the Invention

[0005] An object of the present disclosure is to provide an improved technique for quantum key distribution, particularly with respect to improving security against potential eavesdropping when amplifying an optical signal.

[0006] To solve this problem, according to the independent claims, a method and a system for quantum key distribution are provided. Further embodiments are disclosed in the dependent claims.

[0007] According to one aspect, a method for quantum key distribution (for amplifying an optical signal) is provided, which is realizable in a system comprising a transmission path for transmitting an optical signal between a first data processing device and a second data processing device. The optical amplifier comprises an active fiber section and a pumping device. The method includes determining a ratio between a target maximum gain and a target operating gain, determining a length of the active fiber section such that an optical signal having a target maximum signal power is amplified at most with the target maximum gain, determining an operating pumping power of the pumping device less than the maximum pumping power such that the optical signal is amplified with the target operating gain according to the ratio determined between the target maximum gain and the target operating gain, operating the pumping device with the operating pumping power, and determining a shared key between the first data processing device and the second data processing device by quantum key distribution for amplifying the optical signal through the optical amplifier.

[0008] According to another aspect, a system for quantum key distribution (for amplifying an optical signal) is provided, which comprises a transmission path for transmitting an optical signal between a first data processing device and a second data processing device, and further comprises an optical amplifier disposed in the transmission path comprising an active fiber section and a pumping device, and the system is configured to execute the method according to at least one of the preceding claims.

[0009] As a result, by preventing a eavesdropper who may access the pumping device from effectively manipulating the pumping power to divert a part of the optical signal, quantum key distribution can be securely performed. At the same time, unnecessary high-level energy consumption can be avoided.

[0010] Target maximum gain G max and target operating gain G op The ratio G max / G op is from an optical signal leakage related to the transmission path, preferably the minimum detectable optical signal leakage r E mincan be determined from the target maximum gain G max and the target operating gain G op The ratio G max / G op can be between 1 + 10 -7 and 1 + 10 -1 , preferably between 1 + 10 -6 and 1 + 10 -2 , more preferably between 1 + 10 -5 and 1 + 10 -3 and may be possible.

[0011] The target maximum gain G max and the target operating gain G op The difference between them is the minimum detectable optical signal leakage r E min (multiplication factor of the target operating gain G op ) and may be equal. The minimum detectable optical signal leakage r E min may depend on the length of the transmission line. When the distance between adjacent optical amplifiers (between amplifiers) is 50 km and the transmission line length is 1000 km, the target maximum gain G max and the target operating gain G op The difference between them may be equal to 10 -6 . When the transmission line length is 40,000 km, it may be equal to 10 -5 and may be equal. Therefore, the pumping device can operate regularly at a value close to the maximum gain possible for the pumping device. This can limit the possibility that an eavesdropper increases the pumping power to partially divert the optical signal.

[0012] The target operating gain can be between 3 and 100, preferably between 5 and 20, and more preferably between 9 and 11. The maximum operating gain is between 3 + 10 -6 and 100 + 10 -3 , preferably between 5 + 10 -6 and 20 + 10 -3 , more preferably between 9 + 10 -6 and 11 + 10 -3 and may be possible.

[0013] The target maximum gain may be the achievable maximum gain corresponding to the total inversion distribution in the active fiber section. The target maximum gain may be the gain at the maximum pumping power.

[0014] Target maximum gain G max is determined from the target operating gain G op and the detectable minimum optical signal leakage r determined from optical signal fluctuations or photon fluctuations (especially fluctuations occurring during the generation and / or amplification of optical signals). E min The target operating gain G op can be determined from the transmission coefficient indicating signal loss along the transmission path (especially signal loss from the first data processing device and / or the second data processing device to the optical amplifier, or signal loss from one optical amplifier to another optical amplifier).

[0015] The detectable minimum optical signal leakage r E min may be the minimum leakage caused by natural loss along the transmission path. The detectable minimum optical signal leakage r E min may be equal to the ratio of the value of the optical signal fluctuation to the number of photons per pulse of the optical signal. The detectable minimum optical signal leakage r E min may be determined from at least one of the number of optical amplifiers in the transmission path, the initial number of photons n per optical signal / optical pulse, and the transmission probability T. For example, the detectable minimum optical signal leakage r E min is r E min = √(MG / n) (or within the surrounding interval). Here, M is the number of optical amplifiers in the transmission path, n is the number of initial photons per optical signal / optical pulse, and T is the transmission probability of the transmission path section between two adjacent optical amplifiers. The detectable minimum optical signal leakage r E min is between 10 -4 and 10 -8 , preferably between 10 -5 and 10 -6 It can be within. The initial number of photons n is, for example, between 10 10 and 10 16Preferably between 10 13 and 10 16 It can be during. The transmission probability may be the reciprocal of the decrease in the number of photons per distance.

[0016] The length of the active fiber section may be defined as being determined so that an optical signal having a target maximum signal power is amplified at most with a target maximum gain, regardless of the pumping power of the pumping device and / or any pumping power of the pumping device. The pumping power may be limited by the maximum achievable pumping power of the pumping device and / or damage to the optical fiber component and / or non-linear processes in the optical fiber.

[0017] The target maximum gain G max is, δG = G op ·r E min As, G max = G op + δG and can be determined. Therefore, the target maximum gain G max is, G max = G op + G op ·r E min and can be determined.

[0018] Alternatively, the target maximum gain G max may be fixed regardless of the minimum detectable optical signal leakage.

[0019] This method may further include determining (and / or monitoring) the optical signal loss along the transmission path, preferably the optical signal loss according to the position along the transmission path. That is, the optical signal loss can be determined as a function of the position along the transmission path. In particular, for each position along the transmission path, the corresponding optical signal loss can be determined. Therefore, the optical signal loss can correspond to a signal loss profile.

[0020] Optical signal loss can be measured by optical time domain reflectometry. The optical signal loss may be determined during, before, and / or after the determination of the shared key. The optical signal loss can be measured repeatedly. For example, the optical signal loss can be repeatedly determined within one of the time intervals from 10 ns to 50 s, preferably from 10 ns to 10 s, particularly from 100 ns to 100 ms, 500 ns to 500 ms, 100 ms to 1000 ms, 0.5 ms to 5 s, 5 s to 10 s.

[0021] This method may include determining an intrusion event based on the optical signal loss and / or aborting (ending) the determination of the shared key based on the optical signal loss. This method may include discarding the shared key based on the optical signal loss.

[0022] This method may further include determining a target maximum signal power from at least one of the maximum signal intensity of the optical signal, the maximum number of photons per pulse of the optical signal, the (minimum) pulse duration of the optical signal, and the (maximum) signal frequency (or (minimum) signal wavelength) of the optical signal.

[0023] For example, the target maximum signal power is the (maximum) number of photons N per pulse, the signal wavelength λ s , the signal frequency ν s , the signal pulse duration t s , as P s,max = Nhν s / t s or P s,max = Nhc / (λ s t s ) and can be determined. The signal pulse duration t s can be, for example, between 0.1 ns and 1 μs. The signal wavelength λ s can be, for example, between 300 nm and 2500 nm.

[0024] The maximum signal intensity and / or the maximum number of photons per pulse can be determined by the distance between the first data processing device and the second data processing device, the distance between adjacent optical amplifiers, and the minimum detectable optical signal leakage.

[0025] Determining the length of the active fiber section includes at least one of: giving an initial length to the active fiber section, operating the pumping device at the maximum pumping power, repeatedly determining the gain value, adjusting the length of the active fiber section until the gain value equals the target maximum gain, and setting the length of the active fiber section as the length of the active fiber section where the gain value equals the target maximum gain. As a result, the length of the active fiber section can be determined with higher accuracy.

[0026] The initial length may be longer than the initial estimated value of the length of the active fiber section by a factor, for example, between 1% and 20%, preferably between 5% and 15%, more preferably between 9% and 11%.

[0027] The maximum pumping power may be the maximum pumping power achievable by the pumping device. Thus, the maximum pumping power may depend on the pumping device.

[0028] Adjusting the length of the active fiber section may include shortening and / or lengthening the active fiber section, for example, continuously cutting the active fiber section. The gain value can be determined, for example, from the input signal intensity (and / or the number of photons per pulse) to the optical amplifier and the output signal intensity (and / or the number of photons per pulse) from the optical amplifier.

[0029] The pumping device may be a diode and / or a laser. The pumping device may be configured to emit radiation having a pumping wavelength.

[0030] Determining the active fiber section length includes determining the active fiber section length via a function according to the target maximum gain, the maximum pumping power, and the maximum signal power. Preferably, the active fiber section length is l = lnG max / d(Pp,max , P s,max ) is determined as. Here, G max is the target maximum gain, P p,max is the maximum pumping power, P s,max is the maximum signal power, d is P p,max and P s,max is a function depending on. Therefore, the active fiber section length can be determined quickly and efficiently.

[0031] The function d is the metastable state population n2, the absorption cross section σ a (ν s ), the dopant concentration ρ, the maximum signal power P s,max , the maximum pumping power P p,max , and the signal frequency ν s As, d(P p,max ,P s,max ) = σ a (ν s )ρ((η s + 1)n2(P p,max ,P s,max ) - 1) can be. In particular, the active fiber section length l can be determined as l = lnG max / σ a (ν s )ρ((η s + 1)n2(P p,max ,P s,max ) - 1).

[0032] The metastable state parent population is the dopant concentration ρ, the pumping radiation frequency ν p , the signal frequency ν s , η s = σ e (ν s ) / σ a (ν s ), η p = σ e (ν p ) / σ a (ν p ), the emission cross section σ e (ν p ), σ e (ν s ), the absorption cross section σ a (ν p ), σ a (νs )), maximum signal power P s,max , maximum pumping power P p,max and saturation power P sat , P sat as, n2(P p,max , P s,max ) = ρ(P p,max / P sat +(1 / 1 + η s )P s,max / P sat ) / (1 + P s,max / P sat +P p,max / P sat ) may be possible.

[0033] Emission and absorption cross - sections σ e (ν p ), σ e (ν s ), σ a (ν p ), σ a (ν s ) can be determined via the emission spectrum and the absorption spectrum (e.g., from spectral analysis) and preferably by subsequent division by the dopant concentration ρ.

[0034] Determining the operating pumping power P p,op may include repeatedly determining the gain value and adjusting the pumping device until the optical signal is amplified with a target operating gain when operating the pumping device with the operating pumping power. Further or alternatively, the operating pumping power can be determined by an equation that depends on the signal maximum power, the target operating gain, and the active fiber section length.

[0035] The optical signal for determining the shared key may include a signal power below the target signal power.

[0036] This method may further include providing at least one of an erbium-doped fiber section, a thulium-doped fiber section, a neodymium-doped fiber section, and a ytterbium-doped fiber section as an active fiber section.

[0037] This method may further include providing a transmission path without an optical isolator and / or without a tap coupler.

[0038] In particular, all optical fiber sections between the first data processing device and the second data processing device may be provided without an optical isolator and / or without a tap coupler.

[0039] This method may further include providing the optical amplifier as a bidirectional optical amplifier. As a result, an optical signal can be transmitted from the first data processing device to the second data processing device and from the second data processing device to the first data processing device via the same optical fiber.

[0040] The optical signal is emitted within a signal wavelength range such that the spectral gain deviation of the optical amplifier is 10% or less, preferably 1% or less. Thereby, the gain stability of the optical amplifier can be controlled. The spectral gain deviation may indicate the (relative) gain deviation that may occur when the signal wavelength is changed.

[0041] The optical signal may be emitted, for example, within a signal wavelength range from 1200 nm to 1600 nm, preferably from 1526 nm to 1534 nm, more preferably from 1529 nm to 1531 nm.

[0042] This method may further comprise arranging a plurality of optical amplifiers in the transmission line, each optical amplifier comprising a (further) pumping device and a (further) active fiber section having an active fiber section length. Preferably, determining the shared key may include amplifying an optical signal through a plurality of optical amplifiers by operating each of the further pumping devices with an operating pumping power. Thus, effective signal transmission along a longer transmission line can be provided.

[0043] This method may further include arranging a plurality of optical amplifiers such that the optical amplification distance between two adjacent optical amplifiers is between 30 km and 200 km, preferably between 30 km and 60 km.

[0044] This method may include at least one of providing a transmission line (especially for transmitting an optical signal between a first data processing device and a second data processing device), providing an optical amplifier, arranging the optical amplifier in the transmission line, and providing an active fiber section and / or a pumping device to the optical amplifier. The transmission line may comprise and / or provide an optical fiber and / or a plurality of optical fiber sections. The optical fiber (section) may include a passive fiber (section). The optical fiber (section) may include, for example, an SMF-28 fiber (section).

[0045] The active fiber section may be part of the transmission line. The active fiber section may be connected, for example, via a splice connection, to the optical fiber (section) of the transmission line. The pumping device may be coupled to the transmission line, in particular to the active fiber section, via a supply (optical) fiber and / or a coupling element. In particular, the pumping radiation emitted from the pumping device can pass through the supply fiber and / or can be supplied to the transmission line via the coupling element (subsequently). The coupling element may be configured to direct radiation having different wavelengths and / or radiation from different optical fibers to a single optical fiber. The coupling element may be, for example, a wavelength division multiplexing (WDM) system / element. The supply fiber may be a passive fiber. The supply fiber may be configured to have a maximum transmittance of radiation at the pumping wavelength. For example, the supply fiber may be a HI1060FLEX fiber.

[0046] The pumping device includes a diode and / or a laser. The pumping device may be configured to emit radiation at the pumping wavelength of the active fiber section.

[0047] The transmission line may be (at least partially or completely) encapsulated with an encapsulation compound. In particular, the optical fiber (section) of the transmission line and / or the optical amplifier and / or the pumping device and / or the supply fiber may be (at least partially or completely) encapsulated with an encapsulation compound. The encapsulation compound may be silicon-based. The encapsulation compound may further contain metal particles, for example, aluminum particles. The length of the transmission line can be from 60 km to 40,000 km.

[0048] The system may or may not include a first and a second data processing device and / or further data processing devices. This method may be executed in a data processing device, for example a first, second, and / or further data processing device. The determination of the active fiber section length and / or the determination of the operating pumping power may or may not be executed by a data processing device such as a first, second, and / or further data processing device. The first, second, and / or further data processing devices may be connected to an optical amplifier, in particular a pumping device.

[0049] The optical signal may be emitted from the first and / or second data processing device.

[0050] Determining the shared key may include at least one of: determining a bit sequence in the first data processing device using a random number generator; encoding the bit sequence into an optical signal; transmitting the optical signal via a transmission line to the second data processing device; amplifying the optical signal by an optical amplifier with an operating pumping power and an active fiber section length; receiving and measuring the optical signal by the second data processing device; discarding non-deterministic signal bits from the (received) bit sequence in the first and / or second data processing device; disclosing, by the first and / or second data processing device, a part of the bit sequence and / or the received bit sequence via a classical channel and performing error correction on the bit sequence and the received bit sequence; and determining an amplified key sequence corresponding to the shared key from the error-corrected bit sequence using privacy amplification.

[0051] The foregoing embodiments relating to the quantum key distribution method can also be provided corresponding to a quantum key distribution system.

Brief Description of the Drawings

[0052] Hereinafter, as an example, embodiments will be described with reference to the drawings.

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

[0053] FIG. 1 shows a diagram of a configuration including a system for quantum key distribution and an eavesdropping device 13 (“Eve”). This system includes a transmission path 10 provided with an optical fiber for transmitting optical signals, particularly classical signals and / or quantum signals, between a first data processing device 11 (“Alice”) and a second data processing device 12 (“Bob”). The optical fiber may include, for example, an SMF-28 fiber.

[0054] At least one optical amplifier 14 provided with an active fiber section 15 and a pumping device 16 may be provided / arranged / installed in the transmission path 10. In particular, a plurality of optical amplifiers 14 may be provided in the transmission path 10. The optical amplifiers 14 can be arranged at equal distances along the transmission path 10 at amplifier intervals, for example, between 30 km and 200 km, preferably between 30 km and 100 km, more preferably between 30 km and 60 km. By increasing the amplifier interval, crosstalk between individual optical amplifiers 14 can be reduced or prevented. The distance between any one of the optical amplifiers 14 and any one of the first and second data processing devices 11, 12 may be at least 30 km.

[0055] The first data processing device 11 may include a first processor 11a and a first memory 11b, and the second data processing device 12 may include a second processor 12a and a second memory 12b. The first and second data processing devices 11 and 12 may or may not be part of the system. The first data processing device 11 and the second data processing device 12 are connected to the transmission line 10. The transmission line 10 may include a quantum channel configured to transmit quantum signals. Further, a classical channel configured to transmit classical signals may be provided. The classical channel may be provided within the transmission line 10 or separately.

[0056] This system may include a plurality of additional data processing devices, particularly a third data processing device having a third processor and a third memory (not shown). The third data processing device may be connected to the transmission line 10. Further or alternatively, the third data processing device may exchange classical signals and / or quantum signals with the first data processing device 11 and / or the second data processing device 12 via an additional communication channel. If the system is configured to execute steps, such steps may be executed, for example, by at least one of the first data processing device 11, the second data processing device 12, and the third data processing device.

[0057] The eavesdropping device 13 having an eavesdropping processor 13a and an eavesdropping memory 13b represents a device external to the system that may have access to the transmission line 10, particularly the pumping device 16. The eavesdropping device 13 may be arranged on the transmission line 10 such that an optical signal transmitted via the transmission line 10 is at least partially received and / or retransmitted by the eavesdropping device 13. The eavesdropping device 13 may also access an additional communication channel.

[0058] The first memory 11b, the second memory 12b, the third memory, and the eavesdropping memory 13b may each include a quantum memory for storing quantum signals and a classical memory for storing classical signals. The quantum memory may be provided using an optical delay line, controlled reversible inhomogeneous broadening (CRIB), Duan-Lukin-Cirac-Zoller (DLCZ) scheme, revival of silenced echo (ROSE), and / or hybrid photon echo phase (HYPER).

[0059] The first data processing device 11, the second data processing device 12, the third data processing device, and the eavesdropping processing device 13 may each include means for transmitting and / or receiving a quantum state via an optical signal.

[0060] (a) Optical amplification The optical signal is amplified / repeated by optical amplification by stimulated emission. The optical amplification is performed in the active fiber (section) 15 of the optical amplifier 14. The active fiber section 15 is pumped, for example, at a pumping wavelength of 980 nm via a pumping device 16, and includes an Er 3+ doped fiber. Additionally or alternatively, a thulium-doped fiber (pumped at 1450 nm to 1490 nm), a neodymium-doped fiber (pumped at 1300 nm), or an ytterbium-doped fiber (pumped at 1000 nm) may be used. The adoption of an erbium-doped fiber is advantageous in that the amplified signal wavelength well matches the transmission window of a standard silica fiber.

[0061] FIG. 2 shows an energy diagram showing the amplification of light in the active fiber section 14, which is an erbium-doped fiber section. Pumping radiation 20 having a pumping wavelength of 980 nm emitted from the pumping device 16 is absorbed in the erbium-doped fiber section, and as a result, the erbium ions are in the ground state 21 ( 4 I 15 / 2from the relaxation time τ 32 ≒ 20 μs to the short-lived state 23( 4 I 11 / 2 ) transitions. The erbium ion relaxes non-radiatively from the short-lived state 23 to the metastable state 22( 21 ≒ 10 ms 4 I 13 / 2 ).

[0062] The optical signal / optical pulse passing through the erbium-doped fiber section causes a stimulated transition from the metastable state 22 to the ground state 21, along with the coherent and synchronous emission of photons 24 added as part of the optical signal. The magnitude of the resulting signal amplification depends on the concentration of erbium ions, the length of the active fiber section 14, and the intensity of the pumping radiation.

[0063] The gain (amplification factor) depends particularly on the wavelength of the input signal. Figure 3 plots the gain coefficient (depending on the fiber length) in units of m -1 as a function of the signal wavelength (nm). The operating range of the signal wavelength can be limited to the region around 1530 nm that constitutes a relatively flat peak region of the gain coefficient. In particular, the gain coefficient in the signal wavelength range 30 from 1529 nm to 1531 nm results in a 1% spectral gain deviation 31, and the signal wavelength range 30 from 1526 nm to 1534 nm results in a 10% spectral gain deviation 31.

[0064] Referring back to FIG. 1, the pumping radiation 20 from the pumping device 16 is supplied to the transmission line 10, particularly to the active fiber section 15, via a coupling element 18 such as a supply fiber 17 and a wavelength division multiplexing (WDM) element. Thus, the active fiber section 15 where optical amplification is performed is supplied with the pumping radiation 20 necessary to excite the dopant atoms. The WDM element is a beam splitter-like device for guiding radiations of different wavelengths to a single optical fiber and is connected to the active fiber section 15 and the pumping device 16. The pumping device 16 may be, for example, a diode or a laser and is particularly configured to emit radiation of a pumping wavelength.

[0065] In the case of the erbium-doped active fiber section 14, the pumping device 16 operates at a wavelength of 980 nm and can be connected to the WDM via a passive HI1060FLEX fiber optimized for this wavelength. Amplification is performed on an optical signal having a wavelength near 1530 nm. In order to suppress unnecessary local losses to about 0.1%, all fiber connections (for example, between the active fiber section and the passive fiber section of the transmission line) can be connected.

[0066] The transmission line 10 can be encapsulated with a sealing compound (for example, silicon-based) mixed with a metal powder (for example, aluminum). The encapsulating compound may have a high thermal conductivity (to prevent overheating). The encapsulating compound substantially complicates external mechanical intrusion (particularly without being detected) and can suppress the leakage of radiation to the environment. The metal powder diffuses the optical signal leaking outside the fiber as heat. As a result, even if the optical signal leaks, it cannot be decoded.

[0067] Unlike the settings of a standard optical amplifier, this system does not include an optical isolator or a tap coupler. An isolator is configured to allow light to pass only in one direction and is typically used to minimize the risk of multiple reflections within the active fiber section 15 where the optical amplifier 14 could potentially become a laser substantially.

[0068] A tap coupler typically directs about 1% of the optical pulse towards a photodetector in order to monitor the optical amplifier 14 (particularly the input and output power, the operating mode, and the gain coefficient). This part could potentially be stolen by an eavesdropper.

[0069] Since this method does not use an isolator or a tap coupler, reducing back reflection and avoiding any laser oscillation modes in the active fiber section 15 could depend only on the connection.

[0070] (b) Operation of the optical amplifier for quantum key distribution Figure 4 shows a graphical representation of the quantum key distribution method.

[0071] First (step 40), a transmission path 10 for transmitting an optical signal between the first data processing device 11 and the second data processing device 12 is provided, and an optical amplifier 14 having an active fiber section 15 and a pumping device 16 is disposed on the transmission path 10.

[0072] The gain / amplification factor G of the optical amplifier 14 also depends on the power of the pumping radiation (pumping power) P p , the length l of the active fiber (section), and the concentration of dopant atoms within the active fiber section 15. As a possibility of an attack by an eavesdropper on the optical amplifier 14, it is conceivable to increase the pumping power P p and divert the surplus of the resulting amplified optical signal. In other words, an eavesdropping device 13 could access the optical amplifier 14 and provide a copy of the optical signal by "overclocking" its amplification ability.

[0073] This type of attack can be prevented as follows.

[0074] The target maximum gain G of the optical amplifier 14 max and the target operating gain G op The ratio G between max / G op is determined from the minimum detectable optical signal leakage r E min and / or the resolution for measuring the optical signal. The minimum detectable optical signal leakage r E min can be determined from the ratio of the value of the optical signal fluctuation to the number of photons per pulse. Further, the active fiber section length l is such that the optical signal radiated from the first or second data processing device 11, 12 at the target maximum signal power P s,max is amplified at a maximum of the target maximum gain G max for any pumping power (step 41).

[0075] In the next step 42, the operating pumping power P of the pumping device 16 p,op is determined to be such that the optical signal is amplified at a target operating gain G max smaller than the target maximum gain G op according to the ratio G max / G op determined between the target maximum gain G max and the target operating gain G op (step 42).

[0076] After determining the active fiber section length l (step 41) and the operating pumping power P p,op (step 42) as described above, the shared key between the first data processing device 11 and the second data processing device 12 is determined by quantum key distribution including amplifying an optical signal (emitted from the first or second data processing device 11, 12) via the optical amplifier 14 by operating the pumping device 16 with the operating pumping power (step 43).

[0077] The active fiber section 15 has a target maximum gain G maxPrecisely contains the minimum (optimal) number of dopant ions necessary for amplifying an optical signal. Assuming that the optical amplifier 14 operates with a sufficiently large pumping power, almost all dopant atoms are inversely populated, and increasing the pumping power further results in a negligible increase in gain. Therefore, the above attack becomes ineffective.

[0078] The optimal number of dopant atoms in the active fiber section 15 can be determined by adjusting the active fiber section length l, as described below. The number of second energy levels, metastable state 22, at the position z of the active fiber section 15 is obtained by the following equation.

[0079] [Number]

[0080] Here, the dopant concentration is ρ, the pumping radiation frequency is ν p , the signal frequency is ν s , the ratio is η s = σ e (ν s ) / σ a (ν s ), η p = σ e (ν p ) / σ a (ν p ), the emission cross - section is σ e (ν p ), σ e (ν s ), the absorption cross - section σ a (ν p ), σ a (ν s ), the (local) pumping power is P p (z), the (local) signal power is P s (z), and the saturation power is P sat (ν p ), P sat (ν s ).

[0081] The emission cross - section σ e (νp )、σ e (ν s ) and the absorption cross section σ a (ν p )、σ a (ν s ) represents the probability that the dopant ions emit or absorb photons of frequency ν p or ν s respectively. σ e (ν p )、σ e (ν s )、σ a (ν p ) and σ a (ν s ) can be determined through the emission and absorption spectra (e.g., from spectral analysis) and subsequent division by the dopant concentration ρ. The emission spectrum is the output spectrum of the active fiber section 15 that is pumped but has no input optical signal (in particular, when G ≈ 10, a large pumping power of about 500 mW can be used). The absorption spectrum corresponds to the difference between the input spectrum and the output spectrum of the active fiber section 15 when no pumping is performed.

[0082] The saturation power P sat (ν s ) of the signal and the saturation power P sat (ν p ) of the pump can be determined as follows.

[0083]

Equation

[0084] Here, ω s is the mode power radius (i.e., the radius of the signal power distribution in the optical fiber that depends on the fiber core radius, the refractive indices of the fiber core and the cladding, and the signal wavelength), and τ is the relaxation time from the metastable state 22 to the ground state 21 (usually 10 ms for erbium in silica). When n2 is close to a constant value along the active fiber, the amplification factor / gain G can be determined as follows.

[0085] [Number]

[0086] The condition when n2 is close to a constant value is that P p >>P sat (ν p ) holds when

[0087] The active fiber section length l can be determined as follows.

[0088] [Number]

[0089] The denominator σ a (ν s )ρ·((η s +1)n2 - 1) determines the gain G as the ratio of the output optical signal photon number to the input signal photon number for a specific active fiber section length l and can be determined by using Equation (4). To provide an essentially complete inversion distribution, the pumping power may be particularly large. For example, when G ≒ 10, the pumping power may be 500 mW or more.

[0090] The gain G depends on the signal power P s and becomes smaller as the value of the signal power P s is larger. Therefore, the target maximum gain G max and the target operating gain G op can be determined for the intended (target) maximum signal power P s,max . Due to the monotonicity of the quantum relative entropy, the signal power P sThe fact that smaller optical signals are amplified more does not make them easier to distinguish. Therefore, an eavesdropper cannot extract more information from the amplified optical signals than is allowed. In particular, the signal strength can be reduced by the first data processing device 11 and / or the second data processing device 12 so that it is difficult to distinguish between a 0-bit optical signal and a 1-bit optical signal when a part of the optical signal is detected as diverted / stolen.

[0091] The maximum pumping power P p,max is typically limited by the physical capacity of the pumping device 16 and / or the electronically set limits. An eavesdropper may try to connect another pumping device to the active fiber section 15, but this can be detected by physical line control. Furthermore, it may be necessary to penetrate the encapsulant, which can damage the equipment. Therefore, an eavesdropper may be limited to manipulating the gain G only by increasing the pumping power of the pumping device 16 of the optical amplifier 14 up to the physical limit at most.

[0092] In an exemplary transmission line 10 with a transmission line length of 1000 km, the number of photons per pulse N can be in the range from about 10 2 photons to 10 5 photons, and the signal pulse time can be t s = 0.8 ns, which corresponds to a signal power P s = Nhν s / t s of the signal. When the signal wavelength λ s = c / ν s = 1530 nm, the signal power P s can be at most 10.81 μW. If the amplifier spacing is 50 km, i.e., the optical amplifier 14 is arranged every 50 km, the number of photons decreases by a factor of 10 between two optical amplifiers 14 (transmission coefficient T = 0.1). Accordingly, the target operating gain G s of a single optical amplifier 14 must be G op = 10 in order to compensate for the attenuation of the optical signal. op = 10.

[0093] Initially, n = 10 14 In the case of an optical pulse with photons, the number of photons is Tn = 10 after 50 km 13 and decreases. The optical amplifier 14 returns the number of photons to GTn = 10 14 but also adds noise. Since the photons follow Poisson statistics, the fluctuations of the optical signal near the amplifier are δn = √(T·n) ≒ 3×10 6 . These fluctuations are amplified by a factor G by the optical amplifier 14, and as a result, δn G ≒ G·√(T·n) ≒ 3×10 7 .

[0094] When passing through M optical amplifiers 14 where each independently contributes to the fluctuations, the total fluctuations increase by a factor of √(M). For example, in the case of 400 optical amplifiers 14 on a transmission line 10 with a length of 20000 km, the fluctuations increase by 20 times.

[0095] Therefore, the fluctuations in the second data processing device 12 are δn B ≒ √(M)δn G ≒ 6×10 8 . Thus, the minimum detectable (optical signal) leakage r E min is r E min ≒ δn B / n ≒ 10 -5 .

[0096] When the target operating gain G op is 10, the surplus that a eavesdropper might be able to use should not exceed δG = 10 -4 , so δG / G ≒ r E min≒ 10 -5 (in the case of a single amplifier, r E min ≒ 10 -7 ). Therefore, the active fiber section length l should be such that the gain G (target maximum gain G p,max ) corresponding to the maximum pumping power P max is equal to 10 + 10 -4 (however, the target operating gain G op is 10).

[0097] The active fiber section length l is such that G = G max and P p = P p,max and can be determined by Equation (4). The active fiber section length l can also be determined by: (1) giving an initial length l init (for example, 110% of the initial estimated value of the active fiber section length l) to the active fiber section, (2) operating the pumping device 16 with the maximum pumping power P p,max (which depends on the pumping device 16) to determine the gain G, and (3) adjusting (for example, decreasing) the length of the active fiber section 15. This is repeatedly executed until the gain G becomes equal to the target maximum gain G max . Then, the active fiber section length l is set as the active fiber section length at which the gain G is equal to the target maximum gain G max .

[0098] When determining the active fiber section length l (step 41), the operating pumping power P p,op can be determined as follows. The operating pumping power P p,op is smaller than the maximum pumping power P p,max . The pumping device 16 can also be operated at the maximum pumping power P p,max during QKD to ensure the maximum inversion distribution. However, this may be accompanied by high energy consumption and device degradation (especially of the (active) optical fiber and the pumping device 16). According to the proposed method, the operating pumping power P p,op is determined such that an eavesdropper accessing the pumping device 16 cannot extract a proportion of the optical signal larger than the minimum leakage r E min that can be detected by the transmission line control, no matter how much the eavesdropper increases the pumping power.

[0099] FIG. 5 shows different signal powers P sShown is the gain G of the optical amplifier 14 plotted in dB as a function of the pumping power (pump power) W at a defined active fiber section length l with respect to. In this example, the pumping power of the optical amplifier 14 is limited to 400 mW (P p,max = 400 mW). The target operating gain G op is indicated by the horizontal line 50, and the target maximum gain G max is indicated by the horizontal line 51.

[0100] (Optimal) operating pumping power P p,op corresponds to the intersection of the curve specific to each signal power and the horizontal line 50. The specific value of P p,op can be determined by equations (1) to (3), assuming that G = G op and l are determined by step 41. Note that n2 in equation (3) depends on the pumping power P p and the signal power P s . The optimal operating pumping powers P p,op for different signal powers are indicated by the vertical lines 52 to 55. In FIG. 5, the following parameters were used. σ a (ν s ) = 8.23×10 -25 m 2 , σ e (ν s ) = 7.2×10 -25 m 2 , σ a (ν p ) = 4.93×10 -25 m 2 , σ e (ν p ) = 1×10 -25 m 2 , λ s = 1530 nm, λ p = 980 nm, τ = 10 ms, ρ = 1×10 -25 m 2 , ω s = 1.68 μm, ω p = 1.41 μm.

[0101] For a given target maximum photon number N and target maximum signal power P s,maxFor this, the following operating pumping power P p,op is determined.

[0102]

Table 1

[0103] The active fiber section length l is determined by step 41, and after determining the operating pumping power P p,op , the shared key between the first data processing device 11 and the second data processing device 12 can be determined by quantum key distribution according to step 43, including amplifying in correspondence with the optical signal transmitted between the first data processing device 11 and the second data processing device 12.

[0104] (c) Step of determining the shared key FIG. 6 shows a graphical representation of the (sub) steps for determining the shared key by quantum key distribution corresponding to step 43. The first data processing device 11 and the second data processing device 12 are connected via an authenticated (public) classical channel, and the optical fiber of the transmission line 10 functions as a quantum channel.

[0105] In the initial step 60, the initial internal loss profile of the transmission line 10 (especially its optical fiber segment) is determined, which essentially represents the natural signal loss in the transmission line 10. In this preparatory step, it should be ensured that no eavesdropper has access to the transmission line 10. The initial loss profile can be shared between the first and second data processing devices 11 and 12 via an authenticated classical communication channel.

[0106] In the first step 61, physical loss control of the transmission line 10 is performed (e.g., by the first and second data processing devices 10 and 11). In particular, the internal loss profile is determined and preferably shared between the first data processing device 11 and the second data processing device 12 via the classical channel.

[0107] By comparing the internally updated loss profile thus obtained with the initial internal loss profile, the part r of the signal that might have been intercepted by an eavesdropper can be determined. For example, in a section of the transmission line 10 that does not include the optical amplifier 14, the natural signal loss in this section is represented by r0, and if an eavesdropper intercepts the intercepted part r of the signal E of the signal, the intercepted part r E from the total loss r can be derived through the following relationship when intercepted t of the signal E .

[0108]

Equation

[0109] If the intercepted part r E becomes too large and the legitimate user loses the information advantage over the eavesdropper, the protocol ends. The end of the protocol depends on the length of the transmission line 10 and the distance between the two optical amplifiers 14. The protocol can be ended especially when the actual key rate is below the target key rate value.

[0110] In the second step 62, a random number generator is used to determine a bit sequence of sequence length L at the first data processing device 11.

[0111] In the third step 63, the bit sequence is encoded into an optical signal including a series of L key signal pulses (coherent optical pulses), and the optical signal is transmitted (via the transmission line 10) to the second data processing device 12.

[0112] The signal bits 0 and 1 correspond to the coherent states |γ0〉 and |γ1〉 respectively. The specific method of encoding the signal bits 0 and 1 into the parameters of the coherent states |γ0〉 and |γ1〉 may be different. For example, the signal bits may be encoded into coherent optical pulses having different intensities / photon numbers and the same phase, or may be encoded into coherent optical pulses having the same intensity and different phases.

[0113] Optical signals with relatively high signal strength can be used as long as the proportion of signals available to eavesdroppers is small and the eavesdropping device 13 can only obtain the quantum number of photons, that is, as long as the measurement accuracy is masked by quantum noise. In the case of intensity encryption, max(|γ0|,|γ1|)~||γ1| 2 -|γ0| 2 | corresponds to this case.

[0114] In the fourth step 64, the optical signal / coherent optical pulse is amplified by one or more optical amplifiers 14 provided along the transmission path 10. Each optical amplifier 14 includes an active fiber section 15 with an active fiber section length l determined by step 41. Further, each optical amplifier 14 operates with an operating pumping power P p,op and is provided with a pumping device 16 that provides a target operating gain G op . Even if an eavesdropper increases the pumping power beyond the operating pumping power P p,op to the maximum pumping power P p,max , the corresponding possible signal leakage is limited to the order of magnitude of the minimum detectable (optical signal) leakage r E min .

[0115] In the fifth step 65, the optical signal is received and measured by the second data processing device 12. The corresponding received bit sequence is determined in the second data processing device 12. All artificially determined losses can be assumed to represent the intercepted part r E of the signal.

[0116] In the sixth step 66, the non-deterministic signal bits determined not to be deterministic in the quantum measurement values in the second data processing device 12 are discarded from the bit sequence of the first data processing device 11 and the received bit sequence of the second data processing device 12. For this purpose, the bit positions of the non-deterministic signal bits are transmitted from the second data processing device 12 to the first data processing device 11 via the classical channel.

[0117] In the seventh step 67, by disclosing a part of the bit sequence and / or the received bit sequence via the classical channel, the first data processing device 11 and the second data processing device 12 can respectively determine the error rate for the bit sequence and the received bit sequence, and can perform error correction. Error correction can be performed, for example, using a low-density parity-check (LDPC) code. As a result, in the first and second data processing devices 11, 12, a bit sequence with errors corrected is determined.

[0118] In the eighth step 68, privacy amplification is used to determine an amplified key sequence from the bit sequence with errors corrected. The amplified key sequence is shorter than the bit sequence with errors corrected, and potential eavesdroppers have no information about the amplified key sequence or have negligible information. The amplified key sequence represents the shared key sequence between the first data processing device 11 and the second data processing device 12 as a result of quantum key distribution.

[0119] The steps from the first step 61 to the eighth step 68 are repeated (arrow 69), and the amplified key sequence is concatenated to the (overall) shared key until the full length of the shared key reaches the length required in the current application.

[0120] During all of steps 61 through 68, the transmission line 10 can be continuously controlled (60a). Thus, a signal loss profile is determined and preferably shared between the first data processing device 11 and the second data processing device 12 via a classical channel. If the integrity of the transmission line 10 is impaired to such an extent that there is a significant risk that an eavesdropper will decode the scattering loss, the protocol can be terminated. (d) Transmission line control FIG. 7 shows an exemplary reflectogram obtained from an optical time domain reflectometry measurement corresponding to a signal loss profile. The basic measurement was performed using a 2 μs, 1550 nm pulsed laser with an output of less than 100 mW. The experimental data is an average of 16,000 measurements.

[0121] The reflectogram shows the logarithm of the backscattered optical signal (especially the high-intensity optical test pulse) power as a function of the distance between the reflectometer and the corresponding discontinuity. The reflectometer can be located inside or near the first data processing device 11 and / or the second data processing device 12.

[0122] The natural signal loss along the transmission line 10 is due to homogeneous scattering and results in an exponential decay of the power corresponding to the linear region 70. Features 71 through 74 of the reflectogram are composed of deviations from the exponential decay of the reflectogram curve, especially sharp peaks and / or drops of the reflectogram curve, and enable the classification of the signal loss at the corresponding positions of the transmission line 10. This is particularly useful in step 60, where it is important to identify and mitigate local losses for comparison with the losses determined during key exchange.

[0123] Features 71 to 74 of the reflectogram generally correspond to the imperfections of the transmission line 10 and can represent, for example, poor connections, bends, and different connectors. The scattering losses from such regions occur locally with respect to the transmission line 10. The peaks of features 71 to 74 of the reflectogram can be due to excessive scattering and, in the case of physical connectors, due to the test pulse experiencing Fresnel reflection. The noisy region 75 on the right side of the reflectogram represents the end of the backscattered signal.

[0124] Additionally or alternatively, the transmission line control may include transmission measurements. That is, the intensity of the test pulse transmitted by the first data processing device 11 and received by the second data processing device 12 is analyzed to classify the signal loss at each position of the transmission line 10. The classification by analyzing the optical signal received at the second data processing device 12 may be performed at the second data processing device 12. The first data processing device 11 may also be configured to perform the classification, in particular by combining the measured values of the backscattered test pulse component and the measured values of the test pulse received at the second data processing device 12.

[0125] To distinguish between inherent signal losses and artificial signal losses, an initial signal loss profile is used as a reference. To provide an irreproducible profile, i.e., a physically non-replicable structure of the transmission line 10, the (passive) optical fiber segment may be slightly doped with, for example, aluminum, phosphorus, nitrogen, or germanium. The most common eavesdropping attacks correspond to the unitary transformation of the quantum state of the coupled system including the propagating signal and the auxiliary system. However, the only way to change the direction of a photon is to introduce significant changes to the optical fiber medium, which will necessarily result in changes from the (initial) reflectogram and become detectable.

[0126] The features disclosed in this specification, the drawings, and / or the claims can be materials for realizing various embodiments either alone or in various combinations thereof.

Claims

1. A quantum key distribution method, wherein the method can be realized by a system having the following configuration, a transmission line (10) for transmitting an optical signal between a first data processing device (11) and a second data processing device (12), an optical amplifier (14) installed on the transmission line (10), and the optical amplifier (14) includes an active fiber section (15) and a pumping device (16), the method comprising: determining a ratio between a target maximum gain and a target operating gain of the optical amplifier (14); determining an active fiber section length such that the optical signal having a target maximum signal power is amplified at the target maximum gain; determining an operating pumping power of the pumping device (16) less than the maximum pumping power such that the optical signal is amplified at the target operating gain according to the ratio determined between the target maximum gain and the target operating gain; determining a shared key between the first data processing device (11) and the second data processing device (12) by quantum key distribution including amplifying the optical signal through the optical amplifier (14) by operating the pumping device (16) at the operating pumping power. A quantum key distribution method.

2. The ratio between the target maximum gain and the target operating gain is determined from optical signal leakage related to the transmission line (10). The quantum key distribution method according to Claim 1.

3. The ratio between the target maximum gain and the target operating gain is between 1 + 10 -7 and 1 + 10 -1 and is The quantum key distribution method according to Claim 1 or 2.

4. The target maximum gain is an achievable maximum gain corresponding to the total inversion distribution in the active fiber section (15), and / or the target maximum gain is the gain at the maximum pumping power. The quantum key distribution method according to Claim 1 or 2.

5. Further comprising determining an optical signal loss along the transmission line (10). The quantum key distribution method according to Claim 1 or 2.

6. Further comprising determining the target maximum signal power from at least one of the maximum signal intensity of the optical signal, the maximum number of photons of the optical signal, the pulse width of the optical signal, and the signal frequency of the optical signal. The quantum key distribution method according to Claim 1 or 2.

7. Determining the active fiber section length comprises: giving an initial length to the active fiber section (15). operating the pumping device (16) at maximum pumping power; repeatedly determining a gain value and adjusting the length of the active fiber section (15) until the gain value equals the target maximum gain; determining the length of the active fiber section as the length of the active fiber section (15) at which the gain value equals the target maximum gain, The quantum key distribution method according to claim 1 or 2.

8. Determining the length of the active fiber section includes determining the length of the active fiber section via a function according to the target maximum gain, the maximum pumping power, and the maximum signal power. The quantum key distribution method according to claim 1 or 2.

9. Determining the length of the active fiber section includes determining the length of the active fiber section as l = lnGmax / d(Pp,max, Ps,max), where Gmax is the target maximum gain, Pp,max is the maximum pumping power, Ps,max is the maximum signal power, and d is a function depending on Pp,max and Ps,max. The quantum key distribution method according to claim 1 or 2.

10. The optical signal for determining the shared key includes a signal power not exceeding the target maximum signal power. The quantum key distribution method according to claim 1 or 2.

11. Further, providing at least one of an erbium-doped fiber section, a thulium-doped fiber section, a neodymium-doped fiber section, and an ytterbium-doped fiber section in the active fiber section (15). The quantum key distribution method according to claim 1 or 2.

12. Further, providing the transmission line (10) without an optical isolator and a tap coupler. The quantum key distribution method according to claim 1 or 2.

13. Further, providing the optical amplifier (14) as a bidirectional optical amplifier. The quantum key distribution method according to claim 1 or 2.

14. The optical signal is emitted within a signal wavelength range such that the spectral gain deviation of the optical amplifier (14) is 10% or less. The quantum key distribution method according to claim 1 or 2.

15. Furthermore, a plurality of optical amplifiers (14) are arranged in the transmission line (12), each optical amplifier comprising a further pumping device (16) and a further active fiber section (15) having the active fiber section length, determining the shared key includes amplifying the optical signal via the plurality of optical amplifiers (14) by operating the further pumping device (16) with the operating pumping power, The quantum key distribution method according to claim 1 or 2.

16. Furthermore, arranging the plurality of optical amplifiers (14) such that the distance between two adjacent optical amplifiers (14) is between 30 km and 200 km, The quantum key distribution method according to claim 15.

17. A system for quantum key distribution comprising a transmission line (10) for transmitting an optical signal between a first data processing device (11) and a second data processing device (12), the system further comprising an active fiber section (15) and a pumping device (16), and an optical amplifier (14) arranged in the transmission line (10), A system configured to execute the quantum key distribution method according to claim 1 or 2.

Citation Information

Patent Citations

  • Method for distributing cipher key and its device

    JP2002118545A

  • Apparatus and method for direct implementation of quantum cryptography systems over WDM communication networks

    JP2019537863A

  • Long-distance quantum key distribution

    JP2022126611A