Method for determining whether eavesdropper exists on quantum channel of plug-and-play quantum cryptography communication system by using TDC, and quantum encryption key distribution device therefor

The integration of a TDC in QKD systems allows for real-time eavesdropper detection by measuring pulse timing deviations, addressing the vulnerability of phase remapping attacks in plug-and-play QKD systems.

WO2025154987A1PCT designated stage expired Publication Date: 2025-07-24SDT INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/021441
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-18
Filing Date
2024-12-30
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Conventional plug-and-play quantum key distribution (QKD) systems fail to detect the presence of eavesdroppers in real time, particularly due to phase remapping attacks that manipulate laser pulse timing, compromising security.

Method used

Implementing a Time to Digital Converter (TDC) in the transmitter to measure the time interval between consecutive laser pulses and detect deviations from a predetermined reference interval, indicating potential eavesdropping activity.

Benefits of technology

Enables real-time detection of eavesdroppers by analyzing the timing differences between laser pulses, enhancing the security of quantum channels against phase remapping attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024021441_24072025_PF_FP_ABST
    Figure KR2024021441_24072025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed is a transmission device for determining the existence of an eavesdropper in a quantum channel in a plug-and-play type QKD system. The transmission device comprises: a photodetector configured to detect a pair of consecutive laser pulses transferred through a quantum channel, and output a laser pulse detection signal including a pair of consecutive electrical pulses corresponding to the detected pair of laser pulses; and a TDC for measuring a time interval between the pair of electrical pulses. Information about the measured time interval is used to determine whether the eavesdropper exists in the quantum channel.
Need to check novelty before this filing date? Find Prior Art

Description

Method for determining the presence of an eavesdropper on a quantum channel of a plug-and-play quantum cryptography communication system using TDC and a quantum cryptography key distribution device therefor

[0001] The present invention relates to a quantum cryptographic key distribution technology, and more particularly, to a technology for determining the presence of an eavesdropper on a quantum channel of a plug-and-play quantum cryptographic communication system using a TDC (Time to Digital Converter).

[0002] Quantum cryptography is a branch of quantum information technology. Quantum cryptography is a digital information technology that leverages the principles of quantum physics and serves as a physical layer security technology for communications networks. Because its security is based on quantum mechanics, quantum cryptography is absolutely secure, preventing eavesdropping or wiretapping. Wired quantum cryptography can utilize existing optical fiber infrastructure, making it feasible for commercialization.

[0003] Unlike asymmetric public-key cryptosystems like RSA, symmetric cryptosystems, which share a one-time random number table (a one-time pad) between the sender and receiver and use this as an encryption key, guarantee absolute security. Quantum cryptography technology, also known as "quantum key distribution (QKD)," securely distributes this one-time random number table between the sender (transmitting device) and receiver (receiving device) in real time based on the laws of quantum physics, such as the impossibility of quantum cloning.

[0004] Typically, quantum cryptography uses two communication channels: a quantum channel (secret channel) that transmits quantum states, and a classical channel (public channel) that is completely open to the outside world, including eavesdroppers (=attackers). In other words, the quantum channel is the core of quantum cryptography and is completely secret due to the principle of quantum unclonability, whereas the classical channel is a communication channel that the sender (Alice) and receiver (Bob) use to detect eavesdroppers by publicly comparing randomly selected bases or portions of generated cryptographic keys. It refers to existing digital optical transmission channels or wireless communication channels. In quantum cryptography, all channels are considered, in principle, channels through which eavesdroppers can freely eavesdrop or wiretap. The classical channel is necessary not only for the distribution of quantum cryptographic keys, such as for the sender (Alice) and receiver (Bob) to compare their bases, but also for the function of publicly authenticating each other. That is, in the absence of a classical channel, the encryption key can be leaked through a so-called impersonation attack, in which an eavesdropper impersonates the sender (Alice) or the receiver (Bob). Thus, classical or public channels are core elements of quantum cryptography and should be considered important when implementing a practical quantum cryptography system. However, since they utilize existing developed technologies, the quantum cryptography channel referred to in this specification refers to the quantum channel used for quantum state transmission.

[0005] There are two ways to physically implement quantum cryptography communication channels: using optical fiber (wired) and distributing encryption keys through the air (wireless). Optical fiber, which utilizes single-mode optical fiber, the standard for conventional optical communications, maintains spatial modes very well. Furthermore, its transmission loss is extremely low, at approximately 0.2 dB / km in the 1550 nm band, making it suitable for implementing long-distance quantum cryptography channels.

[0006] Quantum cryptography encryption keys can be implemented using various methods, including coding using light polarization, phase coding, frequency coding, and continuous variable coding. Coding techniques utilizing light polarization or phase require additional technology to continuously compensate for fluctuations in polarization or optical paths caused by factors such as temperature and ambient conditions.

[0007] The BB84 protocol, a quantum cryptography protocol that utilizes two basis systems, X-basis and Y-basis, utilizes four quantum states that constitute the two basis systems. For example, it utilizes the four polarization states of a single photon.

[0008] A common way to detect the presence of an eavesdropper (Eve) while sharing a cryptographic key between a sender (Alice) and a receiver (Bob) is as follows. In step 1, the sender (Alice) randomly selects either a basis X or a basis Y. In step 2, the sender (Alice) randomly selects one of two quantum states (cipher key values), 0 or 1, of the selected basis and sends it to the receiver (Bob). In step 3, the receiver (Bob), who receives the quantum state, also randomly selects one of the two bases. In step 4, the receiver (Bob) measures the received quantum state using the selected basis. In step 5, after the receiver (Bob) completes his measurement, the sender (Alice) and the receiver (Bob) reveal to each other the basis they randomly selected. If the basis chosen by the sender (Alice) and the basis chosen by the receiver (Bob) are the same, the result measured by the receiver (Bob) matches the quantum state randomly chosen by the sender (Alice), and therefore, both users have the same encryption key (sifted key).

[0009] If an eavesdropper (Eve) attempts to eavesdrop in the middle, the basic principles of quantum mechanics will cause an error in the encryption key values ​​obtained by the two users (Alice and receiver (Bob)). The sender (Alice) and receiver (Bob) can reveal part of the generated key to each other and calculate the error rate to determine whether an eavesdropper (Eve) exists.

[0010] There are two main types of eavesdropping methods that an eavesdropper (Eve) can perform: an individual attack (incoherent attack) that attempts to access only one qubit at a time, and a joint attack (coherent attack) that accesses several qubits at once to obtain information.

[0011] An example of an individual attack is the intercept-resend attack. This method involves an eavesdropper (Eve) intercepting a qubit sent by a sender (Alice) to a receiver (Bob), performing a desired measurement, and then sending the qubit to Bob in a state favorable to her. The eavesdropper (Eve) can measure based on any of the two BB84 protocol bases, or she can measure based on a middle ground between the two.

[0012] Another example of an individual attack is the cloning attack (also known as a symmetric individual attack). This attack involves quantum cloning of the qubit being transmitted. While complete cloning is impossible under quantum mechanics (no cloning theorem), it is a form of attack that allows for the acquisition of some information about the cryptographic key.

[0013] These attack methods target perfect quantum cryptography devices and introduce errors into the encryption keys of the sender (Alice) and receiver (Bob), making them detectable to the user. In addition to these methods, there are also attacks that exploit vulnerabilities in devices used in quantum cryptography systems.

[0014] Due to practical limitations related to phase, polarization, and birefringence instabilities over long-distance optical fibers, bidirectional QKD schemes such as the "plug-and-play" architecture and the Sagnac QKD architecture have been developed. The "plug-and-play" architecture, in particular, is widely used in commercial QKD systems. In this system, the receiver (Bob) first transmits two powerful laser pulses (a signal laser pulse and a reference laser pulse) to the sender (Alice). Alice uses the reference laser pulse as a synchronization signal to activate a phase modulator. Alice then modulates only the phase of the signal laser pulse, attenuates both the reference and signal laser pulses to a single photon level, and then retransmits them to the receiver (Bob). Because Alice allows signals to enter and exit Alice's device, there is a potential backdoor through which an eavesdropper (Eve) can launch various attacks. One such attack is the phase-remapping attack. Therefore, to build a system that is secure against quantum hacking, the sender (Alice) must continuously monitor the incoming signals (signal laser pulse and reference laser pulse).

[0015] In conventional 'plug-and-play' QKD systems, there is a need to detect the presence of eavesdroppers or attackers on the quantum channel.

[0016] Conventional techniques rely on the error rate in generated cryptographic keys to detect eavesdroppers. Therefore, even with specific quantum hacking techniques, the presence of eavesdroppers or attackers on quantum channels cannot be detected in real time. The present invention provides a technology capable of detecting the presence of an attacker (Eve) in real time based on differences in the reception times of laser pulses transmitted by a receiver (Bob).

[0017] FIG. 1 is a diagram illustrating a plug-and-play QKD system provided according to one embodiment.

[0018] The sender (Alice) (100) and the receiver (Bob) (200) are connected to each other through a quantum channel (300) and a public channel (400).

[0019] The above receiver (Bob) (200) may include a laser diode (LD) (230), a first single photon detector (Det1) (210), a second single photon detector (Det2) (220), a receiving-side phase modulator (PMB) (250), a circulator (C) (240), a polarizing beam splitter (PBS) (260), and a receiving-side control unit (270).

[0020] The above transmitter (Alice) (100) may include a conventional photodetector (CD; Classical Detector) (110), a delay line (DL), a Faraday mirror (FM) (120), a transmission-side phase modulator (PMA) (130), and a transmission-side control unit (170).

[0021] The transmitting control unit (170) and the receiving control unit (270) can exchange predetermined information through a public channel (400) via a communication unit (not shown). The predetermined information can include information regarding a series of bases used by the transmitting control unit (170) and the receiving control unit (270).

[0022] A public channel (400) is used as a communication channel for a sender (Alice) and a receiver (Bob) to publicly compare randomly selected bases or portions of generated encryption keys. The public channel (400) may be a conventional digital optical transmission channel or a wireless communication channel.

[0023] The above photodetector (110) is a device that cannot detect a single photon and can detect a laser pulse stronger than a single photon.

[0024] Figure 2 illustrates an example of a blocking and retransmission method in which an eavesdropper (Eve) blocks the quantum channel between the transmitter (Alice) and receiver (Bob) of Figure 1, intercepts the laser pulse transmitted by the receiver (Bob), and retransmits it through the quantum channel.

[0025] In Figure 2, the receiver (Bob) is not shown. An eavesdropper (Eve) (500) can intervene in the quantum channel (300) and act as if he is the receiver (Bob).

[0026] The eavesdropper (Eve) (500) may include the same components as those included in the receiver (Bob) (200), a variable optical delay line (VODL) (570), and a polarization controller (PC) (580).

[0027] Figure 3 is a diagram of the phase modulation (PM) signal of the transmitter (Alice).

[0028] In Figure 3, t0 is the original time when the signal laser pulse of the receiver (Bob) (200) is appropriately modulated to have a phase φ0. An eavesdropper (Eve) can attack by shifting the signal laser pulse from time t0 to time t1. The pulse thus shifted has a new modulation phase φ1.

[0029] The signal laser pulse of the above receiver may be a laser pulse transmitted by the receiver (Bob) (200) using the laser diode (230).

[0030] LiNbO3 waveguide phase modulators are commonly used to encode arbitrary bits in fiber-based phase-coded BB84 QKD systems. In practice, phase modulators have finite response times, as shown in FIG. 3. Ideally, the signal laser pulse of a receiver (Bob) (200) is properly modulated by passing through the phase modulator (130) of a transmitter (Alice) (100) in the middle of the modulation signal (time t0 in FIG. 3). However, if an eavesdropper (Eve) (500) changes the time difference between the reference laser pulse and the signal laser pulse, the signal laser pulse passes through the phase modulator (130) of the transmitter (Alice) (100) at a different time (time t1 in FIG. 3), resulting in a different encoded phase. The original sender (Alice) (100) uses {0, π / 2, π, 3π / 2} to encode {01 (bit '0' of base 1), 02 (bit '0' of base 2), 11 (bit '1' of base 1), 12 (bit '1' of base 2)}. Now, after the remapping process of the eavesdropper (Eve) (500), the encoded phase {0, π / 2, π, 3π / 2} of the sender (Alice) is mapped to {0, φ1, φ1+ φ2, φ1+ φ2+ φ3}, where φ i (i = 1, 2, 3) is the new phase difference between two adjacent states. To simplify the explanation, we can assume that the phase modulator (130) has the same rise time and proportional phase modulation for each encoded phase (i.e., φ1 = φ2 = φ3). Or, for a more general explanation, φ iThe exact value of can be seen to depend on the time shift introduced by the eavesdropper (Eve) and the actual phase modulation system. Through the phase remapping process, the eavesdropper (Eve) (500) can launch a new 'block and replay' attack, i.e., a phase remapping attack. For example, an actual attack strategy may be as follows.

[0031] (1) The eavesdropper (Eve) (500) can intercept the strong pulse of the receiver (Bob) (200) and send the time-shifted pulse to the sender (Alice) (100) through her device (500). The eavesdropper (Eve) (500) can change the time shift to φ i You can change the actual values ​​of (i = 1, 2, 3).

[0032] (2) The strategy of the eavesdropper (Eve) (500) is to distinguish {01} from {02, 11, 12} or {12} from {01, 02, 11} with minimal error. To distinguish {01}, the eavesdropper (Eve) (500) uses its phase modulator (250) to introduce a phase shift of φ1 + φ2 to the reference pulse (attenuated reference pulse) resent by the sender (Alice) (100) and performs interference measurement. If it is detected by the detector 1 (Det1) (210), the eavesdropper (Eve) (500) sends the standard BB84 state {01} to the receiver (Bob). Otherwise, the eavesdropper (Eve) (500) simply discards it. A similar procedure is performed to identify {12}, where the eavesdropper (Eve) (500) introduces a phase shift of φ1. Here, the phase shift φ1 of the eavesdropper (Eve) (500) can be defined as the basis X, and φ1+φ2 can be defined as the basis Y.

[0033] If the phase difference between the attenuated reference pulse and the reduced signal pulse after the Mach-Zehnder interferometer is π, it can be detected by detector 1 (210), and if the phase difference is 0, it can be detected by detector 2 (220).

[0034] Assuming that the eavesdropper (Eve) (500) uses the basis Y to identify {01}, when the sender (Alice) (100) sends different states {01, 02, 11, 12}, the detection probability of detector 1 (Det1) (210) is {P(01), P(02), P(11), P(12)} is {sin 2 ((φ1+ φ2) / 2), sin 2 (φ2 / 2), 0, sin 2 (φ3 / 2)). After the attack of eavesdropper (Eve)(500), the introduced error probability is {0, 1 / 2. 1. 1 / 2}. The analysis for basis X can be performed in a similar manner. In this case, the overall QBER for basis X and basis Y is QBER = sin 2 (φ / 2) / { sin 2 (φ) + 2sin 2 (φ / 2)}.

[0035] Again, this is explained with reference to Fig. 2.

[0036] A phase remapping attack can be implemented as shown in Fig. 2. The signal laser pulse of the receiver (Bob) (200), the reference laser pulse, and the phase modulation signal of the transmitter (Alice) (100) of the original QKD system are presented in Fig. 4.

[0037] Figure 4 illustrates the temporal patterns of a reference laser pulse (Ref), a signal laser pulse (Sig), and a phase-modulated signal observable at a transmitter (Alice). In Figure 4, the encoding phase of the transmitter (Alice) is {π}, and only the pulses (forward pulses) input to the transmitter (Alice) are shown.

[0038] In Fig. 4, since the transmitter (Alice) (100) uses the reference laser pulse (701) as a trigger signal, the time delay Δt1 is determined by the internal delay of the transmitter (Alice) (100) system and cannot be controlled by the eavesdropper (Eve) (500). On the other hand, since the transmitter (Alice) (100) usually does not monitor the arrival time of the signal laser pulse (702) in the system, the eavesdropper (Eve) (500) can change the time delay Δt3 without being detected. In addition, the rising edge time (10-90%) of the phase modulation signal (703) is about 6 ns, while the width of the laser pulse is about 500 ps (width at half maximum). The eavesdropper (Eve) (500) can easily place its own pulse (500) on the rising edge to obtain partial phase modulation. By opening a security vulnerability in this way, an eavesdropper (Eve) (500) can launch a phase remapping attack.

[0039] We can assume a situation where an eavesdropper (Eve) (500) initiates an attack using the same settings as a receiver (Bob) (200). In this case, the eavesdropper (Eve) (500) can modify the short arm length of the Mach-Zehnder interferometer by adding a variable optical delay line (570) (VODL in FIG. 2) to shift the time delay between the reference laser pulse (701) and the signal laser pulse (702).

[0040] According to one aspect of the present invention, a transmitter (100) for determining the presence of an eavesdropper (500) in a quantum channel (300) in a plug-and-play QKD system may be provided. The transmitter includes a photodetector (110) configured to detect a pair of consecutive laser pulses transmitted through the quantum channel (300) and output a laser pulse detection signal (800) including a pair of consecutive electric pulses corresponding to the detected pair of laser pulses; and a TDC (150) for measuring a time interval between the pair of electric pulses. Information regarding the measured time interval is used to determine whether an eavesdropper exists in the quantum channel.

[0041] At this time, the transmitting device may further include a control unit (170). At this time, the control unit may be configured to determine that an eavesdropper exists in the quantum channel if the measured time interval is different from a predetermined reference time interval.

[0042] At this time, the energy of the pair of laser pulses is attenuated and then transmitted to the quantum channel again, and the phase of one of the pair of laser pulses may be modulated.

[0043] At this time, the transmitting device may be configured to randomly select one of the plurality of bases for the modulation, and the transmitting device may be configured to randomly select one of the plurality of quantum states and encode the signal laser pulse into the selected quantum state.

[0044] At this time, the time interval may be the time difference between the rising edge of the first electric pulse that occurs first among the pair of electric pulses and the rising edge of the second electric pulse that occurs later.

[0045] At this time, the TDC may include a first delay line part (20) into which an input pulse having a time difference as a width between the first occurrence time of the first electric pulse and the second occurrence time of the second electric pulse is input; and an operation part (60) that determines the time interval using a thermometer code output by the first delay line part.

[0046] At this time, the TDC may further include a code conversion part (30) that converts and outputs the order of elements of the thermometer code. And the operation part is configured to determine the occurrence time difference using the conversion code output by the code conversion part, and the conversion code is a code that arranges the order of elements of the thermometer code according to a predetermined standard, and the predetermined standard may be a data path delay from the output node of the input pulse to the output nodes of each of the plurality of flip-flops (FF) included in the first delay line part.

[0047] At this time, the TDC is implemented by any one of a FPGA (Field Programmable Gate Array), an ASIC (Application Specific Integrated Circuit), and an IC (Integrated Circuit), and any one of the devices may be programmed to include the first delay line part and the operation part.

[0048] At this time, the TDC further includes a second delay line part into which the input pulse is input; and the code conversion part is configured to generate the conversion code by arranging and merging elements of the thermometer code output by the first delay line part and elements of the thermometer code output by the second delay line part according to a predetermined second criterion, and the predetermined second criterion may be a data path delay from an output node of the input pulse to output nodes of each of a plurality of flip-flops included in the first delay line part and the second delay line part.

[0049] At this time, the TDC may be configured to use a clock signal (clk) having a period shorter than the time difference between the pair of laser pulses output by the receiving device of the QKD system. And the TDC may further include: an input signal generating part (10) that generates the input pulse having a width of a time difference between the time of occurrence of a rising edge of the first electric pulse and the time of occurrence of a rising edge of the second electric pulse; a clock pulse counting part (40) that counts the number of clock pulses of the clock signal generated during the maintenance period of the input pulse; and an operation part that determines a value of the generation time difference by using the first thermometer code (TC1) output by the code conversion part at the time of the rising edge of the first clock pulse among the generated clock pulses, the second thermometer code (TC2) output by the code conversion part at the time of the rising edge of a clock pulse generated immediately after the last clock pulse among the generated clock pulses, and the number of the counted clock pulses.

[0050] According to another aspect of the present invention, there may be provided a non-volatile recording medium readable by an electronic device, in which a binary file including configuration data is recorded, which is configured to program the FPGA to configure a digital circuit including a signal receiving part (71) for receiving a laser pulse detection signal (800) including a pair of consecutive electric pulses generated from a photodetector included in a transmitter of the QKD system in a plug-and-play manner; and a time difference determining part (72) configured to determine a time interval between the pair of electric pulses.

[0051] At this time, the digital circuit may further include a wiretapping judgment part (73) that determines that an eavesdropper exists in the quantum channel when the determined time interval is different from a predetermined reference time interval.

[0052] At this time, the digital circuit may further include a first delay line part (20) into which an input pulse having a time difference between the first occurrence time of the first electric pulse that occurred first among the pair of electric pulses and the second occurrence time of the second electric pulse that occurred later is input; and an operation part (60) that determines the time interval using a thermometer code output by the first delay line part.

[0053] At this time, the digital circuit may further include a code conversion part (30) that converts and outputs the order of elements of the thermometer code. And the operation part is configured to determine the time interval using the conversion code output by the code conversion part, and the conversion code is a code that arranges the order of elements of the thermometer code according to a predetermined standard, and the predetermined standard may be a data path delay from the output node of the input pulse to the output nodes of each of the plurality of flip-flops (FF) included in the first delay line part.

[0054] At this time, the digital circuit may further include a second delay line part into which the input pulse is input. And the code conversion part is configured to generate the conversion code by arranging and merging elements of the thermometer code output by the first delay line part and elements of the thermometer code output by the second delay line part according to a predetermined second criterion, and the predetermined second criterion may be a data path delay from an output node of the input pulse to output nodes of each of a plurality of flip-flops included in the first delay line part and the second delay line part.

[0055] At this time, the digital circuit may be configured to use a clock signal (clk) having a period shorter than the time difference between the pair of laser pulses output by the receiving device of the QKD system. And the digital circuit may further include: an input signal generating part that generates the input pulse having a width of a time difference between the time of occurrence of a rising edge of the first electric pulse and the time of occurrence of a rising edge of the second electric pulse; a clock pulse counting part that counts the number of clock pulses of the clock signal generated during the maintenance period of the input pulse; and an operation part that determines a value of the generation time difference by using the first thermometer code output by the code conversion part at the time of the rising edge of the first clock pulse among the generated clock pulses, the second thermometer code output by the code conversion part at the time of the rising edge of a clock pulse generated immediately after the last clock pulse among the generated clock pulses, and the number of counted clock pulses.

[0056] According to the present invention, a technology can be provided that can detect the presence of an attacker in real time based on the difference between the reception times of a pair of pulses transmitted by a receiver in a plug-and-play manner.

[0057] FIG. 1 is a diagram illustrating a plug-and-play QKD system provided according to one embodiment.

[0058] Figure 2 illustrates an example of a blocking and retransmission method in which an eavesdropper (Eve) blocks the quantum channel between the transmitter (Alice) and receiver (Bob) of Figure 1, intercepts the laser pulse transmitted by the receiver (Bob), and retransmits it through the quantum channel.

[0059] Figure 3 is a diagram of the phase modulation (PM) signal of the transmitter (Alice).

[0060] Figure 4 shows the time patterns of a reference laser pulse (Ref), a signal laser pulse (Sig), and a phase modulated signal observable from a transmitter (Alice).

[0061] FIG. 5 illustrates the configuration of a transmitter (transmitter) (Alice) used in a plug-and-play QKD system provided according to one embodiment of the present invention.

[0062] Figure 6 illustrates in more detail the interoperability relationship between the photodetector, TDC, and transmitter control unit presented in Figure 5.

[0063] Figure 7 shows the timing alignment relationship of the quantum channel signal, laser pulse detection signal, and start signal and end signal used in TDC presented in Figure 5.

[0064] Figure 8 compares the cases where there is no eavesdropper (Eve) in the quantum channel and the cases where there is.

[0065] FIG. 9 is a flowchart illustrating a method for a transmitter of a plug-and-play QKD system to determine whether an eavesdropper exists in a quantum channel, according to one embodiment of the present invention.

[0066] FIG. 10 is a block diagram of an FPGA that implements a TDC according to one embodiment of the present invention.

[0067] FIG. 11 is a drawing for explaining an input pulse input to a first delay line part of an FPGA according to one embodiment of the present invention.

[0068] Fig. 12 illustrates the configuration of a first delay line part according to one embodiment of the present invention.

[0069] Figure 13 is a drawing for explaining the indexes of the buffers of Figure 12.

[0070] Figure 14 shows a table for explaining data path delay.

[0071] FIG. 15a and FIG. 15b illustrate a parallel configuration of multiple delay line parts according to one embodiment of the present invention.

[0072] FIG. 16a illustrates the configuration of the first delay line part and the second delay line part of FIG. 15b, and FIG. 16b is for explaining the operation of the code conversion part when two delay line parts are used according to one embodiment of the present invention.

[0073] Figure 17 is a graph showing delay depending on whether a code conversion part is applied according to one embodiment of the present invention.

[0074] FIG. 18 is a drawing for explaining the arrangement criteria of flip-flop output values ​​and the increase value of the number of taps of FIG. 17 depending on whether a code conversion part is applied according to one embodiment of the present invention.

[0075] FIG. 19 is a block diagram showing the main functional parts of a PCB board including an FPGA provided according to one embodiment of the present invention.

[0076] Hereinafter, embodiments of the present invention will be described with reference to the attached drawings. However, the present invention is not limited to the embodiments described herein and may be implemented in various other forms. The terminology used herein is intended to aid understanding of the embodiments and is not intended to limit the scope of the present invention. Furthermore, the singular forms used below also include the plural forms, unless the context clearly indicates otherwise.

[0077] FIG. 5 illustrates the configuration of a transmitter (transmitter) (Alice) used in a plug-and-play QKD system provided according to one embodiment of the present invention.

[0078] Figure 6 shows in more detail the mutual operation relationship of the photodetector (110), the TDC (150), and the transmission side control unit (170) presented in Figure 5.

[0079] Fig. 7 shows the timing alignment relationship of the quantum channel signal (700), the laser pulse detection signal (800), and the start signal and end signal used in the TDC presented in Fig. 5.

[0080] Hereinafter, the description will be given with reference to FIGS. 5 to 7.

[0081] The above transmitter (Alice) (100) is connected to the quantum channel (300) and can receive laser pulses transmitted through the quantum channel (300). The laser pulse may be the above-described reference laser pulse or a signal laser pulse.

[0082] The transmitter (Alice) (100) may include the photodetector (110), the Faraday mirror (120), and the transmission-side phase modulator (130). In addition, the transmitter (Alice) (100) may further include a TDC (150) and a control unit (170) provided according to one embodiment of the present invention.

[0083] The input terminal of the above TDC (150) may be connected to the output terminal of the above photodetector (110).

[0084] The output terminal of the photodetector (110) can output a laser pulse detection signal (800). The photodetector (110) can output one electric pulse corresponding to the detected laser pulse when it detects one laser pulse having a predetermined intensity or higher from the quantum channel signal (700) detected at the input of the photodetector (110). The one electric pulse can have a constant time width. Therefore, the laser pulse detection signal (800) can be a signal including an electric pulse generated by the photodetector (110) whenever a laser pulse is detected in the quantum channel signal (700), that is, whenever a laser pulse reaches the transmitter (Alice) (100) through the quantum channel (300).

[0085] When the reference laser pulse is detected from the quantum channel signal (700), the signal laser pulse is detected within a predetermined time. That is, the laser pulse can be detected in pairs.

[0086] When a pair of laser pulses is detected from the quantum channel signal (700), the photodetector (110) can output a pair of corresponding electric pulses.

[0087] The above TDC (150) is the time interval (T) between a pair of output electric pulses. DM ) may be determined. The TDC (150) may be determined based on the determined time interval (T DM ) itself may be transmitted to the above-determined transmission control unit (170), or the determined time interval (T DM ) and a preset reference time interval (T DR ) can be used to calculate the error value (Te) and transmit the error value to the transmission side control unit (170).

[0088] The above-mentioned transmitting control unit (170) can determine that an eavesdropper (Eve) exists in the quantum channel (300) if the above-mentioned error value (Te) is greater than a predetermined value δ. Here, the predetermined value δ may be 0 or a predetermined positive number.

[0089] The above-determined result can be provided to a remote server by the sender (Alice) (100) using a communication module.

[0090] In Figure 7, the horizontal axis is the time axis, and the left side indicates a time that occurred earlier than the right side.

[0091] In FIG. 7, reference numbers 701 and 702 represent a reference laser pulse and a signal laser pulse, respectively, received by the transmitter (Alice) (100) from the quantum channel (300), and reference numbers 801 and 802 represent electric pulses generated by the photodetector (110) in response to the reference laser pulse and the signal laser pulse, respectively.

[0092] The above TDC (150) may regard the first electric pulse (801) as a start signal (S1) and the second electric pulse (802) as a stop signal (S2).

[0093] The above TDC (150) can generate a first internal signal (810) and a second internal signal (820) from the laser pulse detection signal (800). The first internal signal (810) is a signal that includes only the first electric pulse (801) among the laser pulse detection signal (800), and the second internal signal (820) is a signal that includes only the second electric pulse (802) among the laser pulse detection signal (800).

[0094] Figure 8 compares the cases where an eavesdropper (Eve) does not exist in the quantum channel (300) and the cases where an eavesdropper (Eve) exists.

[0095] It is divided into the upper and lower parts of Fig. 8. The upper part shows a case where the eavesdropper (Eve) (500) does not exist in the quantum channel (300), and the lower part shows a case where the eavesdropper (Eve) (500) exists in the quantum channel (300).

[0096] When the above-mentioned eavesdropper (Eve) (500) does not exist, the quantum channel signal (700) is given as reference number 700[B] of Fig. 8, and the laser pulse detection signal (800) is given as reference number 800[B] of Fig. 8. The time interval (T) between the first electric pulse (801[B]) and the second electric pulse (802[B]) of the laser pulse detection signal (800[B]) DM ) is a pre-arranged reference time interval (T DR ) is the same as .

[0097] The above reference time interval (T DR ) is a predetermined value and is equal to the time interval between generating a reference laser pulse and a signal laser pulse that are intertwined by the interferometer (delay line of 250, 260, 48 ns) of the receiver (Bob) (200).

[0098] When the above-mentioned eavesdropper (Eve) (500) exists, the quantum channel signal (700) is given as reference number 700[E] of Fig. 8, and the laser pulse detection signal (800) is given as reference number 800[E] of Fig. 8. The time interval (T) between the first electric pulse (801[E]) and the second electric pulse (802[E]) of the laser pulse detection signal (800[E]) DM ) is a pre-arranged reference time interval (T DR ) may be greater or less than . The value of this timing error may be denoted by the reference symbol Te.

[0099] The above TDC (150) is the time interval (T DM ) and / or the above time can produce an error (Te) and provide it to the transmission side control unit (170).

[0100] The above TDC (150) is the time interval (T DM ) may be directly used to determine the laser pulse detection signal (800), or the first internal signal (810) and the second internal signal (820) generated from the laser pulse detection signal (800) or the clock signal (clk) provided by the control unit (170) may be used.

[0101] FIG. 9 is a flowchart illustrating a method for a transmitter of a plug-and-play QKD system to determine whether an eavesdropper exists in a quantum channel, according to one embodiment of the present invention.

[0102] In step (S10), the transmitter (100) can generate a laser pulse detection signal (800) including a pair of continuous electric pulses corresponding to a pair of continuous laser pulses transmitted through a quantum channel (300) using a photodetector (110) included in the transmitter.

[0103] In step (S20), the transmitter (100) can measure the time interval between the pair of electric pulses using the TDC (150) included in the transmitter.

[0104] In step (S30), the transmitter (100) can determine that there is an eavesdropper in the quantum channel if the measured time interval is different from a predetermined reference time interval using the control unit (170) included in the transmitter.

[0105] Hereinafter, the operating principle of the TDC (150) provided according to one embodiment of the present invention will be described in detail. The TDC (150) is implemented as an FPGA (1). Alternatively, in another embodiment, the TDC (150) may be implemented as an IC or ASIC, etc.

[0106] FIG. 10 is a block diagram of an FPGA that implements a TDC according to one embodiment of the present invention.

[0107] In the case where the transmission side control unit (170) shown in Fig. 5 is implemented as an FPGA, the FPGA (1) implementing the TDC (150) may include the transmission side control unit (170).

[0108] In contrast, if the transmission side control unit (170) shown in FIG. 5 is not an FPGA, the TDC (150) may be implemented as an FPGA provided separately from the transmission side control unit (170).

[0109] The above TDC (150) can be implemented not with a high-speed FPGA operating at a clock of, for example, 10 GHz, but with a relatively low-speed FPGA operating at a clock of, for example, 100 to 300 MHz.

[0110] FIG. 11 is a drawing for explaining an input pulse input to a first delay line part of an FPGA according to one embodiment of the present invention.

[0111] Hereinafter, the description will be made with reference to FIGS. 10 and 11.

[0112] FPGA (1) may include an input signal generation part (10), a first delay line part (20), a code conversion part (30), a clock pulse counter part (40), a priority encoder part (50), and an operation part (60).

[0113] Specifically, the configurations of the FPGA (1) described above may be configurations of a TDC (Time to Digital converter).

[0114] As shown in FIGS. 10 and 11, the input signal generation part (10) can generate an input pulse (P1) having a width equal to the time difference (T) between the rising edge (E1) of a given start signal (S1) and the rising edge (E2) of a given end signal (S2). The input signal generation part (10) can be composed of logic gates necessary for the above generation.

[0115] The first delay line part (20) can receive an input pulse (P1) having a width equal to the time difference (T) between the occurrence of a start signal (S1) and an end signal (S2). In addition, the first delay line part (20) can output a thermometer code (O1). At this time, the thermometer code is a value of, for example, 8 bits, composed of output values ​​of flip-flops included in the first delay line part (20), and the output value of each flip-flop can be referred to as an element of the thermometer code.

[0116] Fig. 12 illustrates the configuration of a first delay line part according to one embodiment of the present invention.

[0117] Figure 13 is a drawing for explaining the indexes of the buffers of Figure 12.

[0118] The first delay line part (20) may include a delay line (D_L) including a plurality of buffers (delay elements, delay components) (B) and D-flip-flops (FF) tapped to the output terminals of each buffer (B) of the delay line.

[0119] Multiple buffers can be connected in a cascade delay manner. That is, multiple buffers can be arranged in the order in which the input pulses (P1) flow.

[0120] The waveform (Signal) of the input pulse (P1) of Fig. 12 can be output with a predetermined delay from the output terminal of each buffer (B). That is, the output value of the first buffer (B1) is output with a predetermined delay from the output terminal of the first buffer (B1), and the output terminal of the first buffer (B1) is connected to the input terminal of the second buffer (B2). The output value (e.g., '1') of the first buffer (B1) can also be input to the first flip-flop (FF1).

[0121] At this time, a data path delay may occur between each buffer (B) and through the flip-flop (FF). For example, a delay of d1 may occur until the input value ('1') of the first buffer (B1) is transmitted to the second buffer (B2), and a delay of d11 may occur until the output value ('1') of the first buffer (B1) is transmitted to the first flip-flop (FF1). Similarly, a delay may occur whenever data is transmitted from the previous buffer to the next buffer, and a delay may occur whenever data is transmitted from any buffer to a flip-flop connected to any buffer.

[0122] FIG. 13 is a diagram for explaining the index of a buffer according to one embodiment of the present invention.

[0123] Each field in the table in Figure 13 represents the buffer name, index, and output value of the buffer.

[0124] Each buffer may be assigned an index that defines the order of each buffer. For example, the first buffer (B1) may be assigned an index of '1', the second buffer (B2) may be assigned an index of '2', and similarly, the eighth buffer (B8) may be assigned an index of '8'. In this way, when each buffer (B) is arranged according to the order in which the input pulse (P1) flows and the indexes are arranged according to that order, for example, 1000 buffers may each be assigned an index of 1 to 1000.

[0125] Figure 14 shows a table for explaining data path delay.

[0126] Referring to FIGS. 10 and 14, the code conversion part (30) can convert and output the order of elements (e.g., 1, 2, 3, 4, 5, 6, 7, 8) of the thermometer code (O1) (e.g., 11100000) output from the first delay line part (20). At this time, the code (e.g., 11010000) (the order of the indexes of the corresponding buffer is 1, 2, 4, 5, 3, 6, 7, 8) output by the code conversion part (30) can be referred to as a 'conversion code (CO1)'.

[0127] The conversion code (CO1) output by the code conversion part (30) may be a sequence of elements of the thermometer code (O1) arranged according to a predetermined standard. In this case, the predetermined standard may be the data path delay from the output node (N1) of the input pulse (P1) to the output nodes (N2) of each of the plurality of flip-flops (FF) included in the first delay line part (20). This will be described in detail with reference to Fig. 14.

[0128] Each field in the table may represent a buffer index number, a first delay value, a second delay value, and a sum (rank). The rank may represent a ranking of all sums. The buffer with the smallest sum may have the first rank, while the buffer with the highest sum may have the last rank. Alternatively, the reverse may be true in other embodiments.

[0129] As described above in Fig. 12, the above sum value may mean the time taken for data to be transmitted from the node (N1) where the input pulse (P1) is output to an arbitrary flip-flop (e.g., FF4).

[0130] A first delay, which is the time it takes for an input value of an arbitrary buffer to be transmitted to another buffer connected to the arbitrary buffer, and a second delay, which is the time it takes for an output value of the arbitrary buffer to be transmitted to an input of a flip-flop connected to the arbitrary buffer, may occur.

[0131] At this time, the value obtained by adding the value of the first delay and the value of the second delay for each buffer can be referred to as the data path delay.

[0132] Referring to FIGS. 12 and 14 together, when the indexes of each buffer are listed in order, the order of the sum of the first delay value and the second delay value may be different from the order of the index numbers of each buffer. For example, in the case of the third buffer, since the buffer array order is 3rd, the index number may be '3', but the order of the sum value may be '5'. Looking at it in detail, in order for data to be transmitted to the third flip-flop (FF3), it passes through the first buffer (B1), the second buffer, and the third buffer. At this time, a predetermined delay (d1, d2, d3) occurs each time it passes through the first buffer (B1), the second buffer (B2), and the third buffer (B3), and a delay (d13) may also occur until the data output from the third buffer (B3) is output as the output value of the third flip-flop (FF3). That is, the delay until data is transmitted from the output node (N1) of the input pulse (P1) to the output node (N2, N23) of the third flip-flop (FF3) may be the sum of d1, d2, d3, and d13.

[0133] In this way, the delay (i.e., the sum value) until data is transmitted to the output node of each flip-flop (FF3) can be calculated.

[0134] For example, in this embodiment, the buffer index for the third flip-flop (FF3) is 3 and the buffer index for the fourth flip-flop (FF4) is 4. That is, the fourth flip-flop (FF3) must pass through one more buffer than the third flip-flop (FF4), but despite this, the sum of the delays to the output node of the third flip-flop with a buffer index of 3 may be greater.

[0135] The code conversion part (30) can convert the order of elements of the thermometer code (O1) based on the calculated delay (sum value) (e.g., from the smallest sum value).

[0136] The conversion code (CO1) output by the code conversion part (30) can be provided to the priority encoder part (50).

[0137] The priority encoder part (50) can digitize a long thermometer code. For example, the priority encoder part (50) can convert a 5200-bit thermometer code into a 13-bit thermometer code. For example, if the number of buffers (delay elements) (B) described above in FIG. 12 and the number of flip-flops (FFs) connected to the buffers are 5200, 5200 consecutive binary number sequences are output, which can be expressed as 13-bit binary numbers.

[0138] That is, the priority encoder part (50) can express the first thermometer code (TC1) of 5200 bits and the second thermometer code (TC2) as a 13-bit binary number as the time-dependent output value (CO1) of the code conversion part (30).

[0139] Referring to Fig. 11, the first thermometer code (TC1) may be a code output by the code conversion part (30) in relation to the rising edge of the input pulse (P1) at the time of the rising edge (E4) of the clock pulse (CK2) that first occurs after the rising edge (E1) of the input pulse (P1) among the generated clock pulses (CK). The first thermometer code (TC1) expressed in 13 bits may be provided as an input to the operation part (60).

[0140] And the second thermometer code (TC2) may be a code output by the code conversion part (30) in relation to the falling edge (E2) of the input pulse (P1) at the time of the rising edge (E6) of the clock pulse (CK4) that first occurs after the falling edge (E2) of the input pulse (P1) among the generated clock pulses (CK). The second thermometer code (TC2) expressed in 13 bits may be provided as an input to the operation part (60).

[0141] At this time, the time period of the first thermometer code (TC1) and the time period of the second thermometer code (TC2) may be smaller than the period of the clock pulse (CK).

[0142] Referring again to FIGS. 10 and 11, the clock pulse counter part (40) can receive an input pulse (P1) from the input signal generation part (10).

[0143] The clock pulse counter part (40) can count the number of clock pulses (CK) generated during the maintenance period (T) of the input pulse (P1). For example, in Fig. 11, since there are two rising edges of the clock pulses generated during the period when the input pulse (P1) is in the ON state, such as edges (E4, E5), the counted value can be two.

[0144] The output value (Coarse count) of the clock pulse counter part (40), i.e. the counted value, can be provided to the operation part (60).

[0145] Referring to FIGS. 10 and 11, the operation part (60) can determine the value of the occurrence time difference using the first thermometer code (TC1), the second thermometer code (TC2), and the number of counted clock pulses. For example, the occurrence time difference can be 2*Period+TC1-TC2.

[0146] FIG. 15a and FIG. 15b illustrate a parallel configuration of multiple delay line parts according to one embodiment of the present invention.

[0147] As shown in Fig. 15a, two or more delay line parts (20) may be connected in parallel. At this time, the input pulse (P1) output from the input signal generation part (10) may be input to the first delay line part (21), the second delay line part (22), the third delay line part (23), and the fourth delay line part (24), respectively. In addition, the first thermometer code (O1), the second thermometer code (O2), the third thermometer code (O3), and the fourth thermometer code (O4) output from the first delay line part (21), the second delay line part (22), the third delay line part (23), and the fourth delay line part (24) may be input to the code conversion part (30).

[0148] In another embodiment, as shown in Fig. 15b, it can be assumed that two delay line parts (20) are connected in parallel.

[0149] For example, an input pulse (P1) output from an input signal generating part (10) can be provided along a first path (path1) in which the output terminal of the input signal generating part (10) and the input terminal of the first delay line part (21) are connected to each other, and a second path (path2) in which the output terminal of the input signal generating part (10) and the input terminal of the second delay line part (22) are connected to each other.

[0150] At this time, the time at which the input pulse (P1) output from the input signal generation part (10) reaches the input terminal of the first delay line part (21) and the input terminal of the second delay line part (22) may be different. This is because there is an input delay due to the difference in length between the first path (path1) and the second path (path). In the embodiment of Fig. 15a, since the length of the first path (path1) is shorter than the length of the second path (path2), it can be seen that the input time interval of the input pulse (path1) through the first path (path1) is shorter than the input time interval of the input pulse (path2) through the second path (path2).

[0151] FIG. 16a illustrates the configuration of the first delay line part and the second delay line part of FIG. 15b, and FIG. 16b is for explaining the operation of the code conversion part when two delay line parts are used according to one embodiment of the present invention.

[0152] For convenience of explanation in Fig. 16a, each delay line part is illustrated as containing four buffers and four flip-flops.

[0153] In Fig. 16b, each field of the table may represent a delay line part number, a buffer index number, a first delay value, a second delay value, a first sum value (first priority), and a first sum value (overall ranking). At this time, the first priority may represent a rank for each sum value for the buffer index of the buffers in each delay line part. And the overall ranking may represent a rank for each sum value for the buffer index of all buffers in the first delay line part and the second delay line part. At this time, the first priority and the overall ranking may be such that the buffer with the smallest sum value may have the first rank and the buffer with the highest sum value may have the last rank. Or, in another embodiment, the opposite may be possible. The method for obtaining the sum value may be the same as described in Fig. 10.

[0154] The code conversion part (30) may be configured to generate one conversion code by merging the elements of the first set (e.g., {(D1, 1), (D2, 2), (D3, 3), (D4, 4)}) in which the sum of the elements of the thermometer code output by the first delay line part (21) and the buffer index pairs are listed in descending order of sum values, and the elements of the second set (e.g., {(D5, 5), (D6, 6), (D7, 7), (D8, 8)}) in which the sum of the elements of the thermometer code output by the second delay line part (22) and the index pairs are listed in descending order of sum values.

[0155] That is, each element of the first set and each element of the second set can be sorted in order of lowest sum value.

[0156] For example, in the first delay line part (21), the output values ​​based on the buffer index may be {1, 2, 3, 4}, and in the second delay line part (22), the output values ​​based on the buffer index may be {5, 6, 7, 8}. In addition, in the embodiments of FIGS. 15b and 16a, the delay (d1) may be smaller than the delay (d5). Therefore, the sorted order may be (D1, 1), (D2, 2), (D5, 5), (D3, 3), (D6, 6), (D4, 4), (D7, 7), (D8, 8). The output values ​​of the flip-flops for each buffer index may be sorted in the sorted order. For example, the sorted values ​​(buffer indices) can be 0(1), 0(2), 1(4), 1(6), 1(3), 1(5), 0(7), 0(8).

[0157] As described above, when multiple delay line parts (20) are used, slightly different input delays may be achieved depending on the arrangement. Figure 17, described below, shows the delays according to the arrangement when multiple delay line parts are used.

[0158] Fig. 17 is a graph showing delay depending on whether a code conversion part is applied according to one embodiment of the present invention.

[0159] FIG. 18 is a drawing for explaining the arrangement criteria of flip-flop output values ​​and the increase value of the number of taps of FIG. 17 depending on whether a code conversion part is applied according to one embodiment of the present invention.

[0160] Figure 17 (a) shows a delay graph according to the number of taps in a state where the code conversion part (30) is not applied, and Figure 17 (b) shows a delay graph according to the number of taps in a state where the code conversion part (30) is applied.

[0161] The fields in the table of Figure 18 include the arrangement order of the flip-flop output values ​​before and after sorting, and the arrangement order of the total delay sum value.

[0162] Hereinafter, the description will be made with reference to FIGS. 17 and 18.

[0163] The horizontal axis of graphs (g1, g2) represents the number of taps. Referring to Fig. 16b, one tap may mean a pair of buffers (delay elements) (e.g., B1) and flip-flops (FF1) connected thereto. For example, if the total number of buffers and pairs of flip-flops connected thereto is 1000, the total number of taps may be 1000.

[0164] The vertical axis of graphs (g1, g2) represents the delay time (ns). The delay time may refer to the sum of the delays required for data to be transmitted to the output nodes of the flip-flops tapped in each buffer described above in Fig. 14.

[0165] Referring to FIGS. 16a to 18 together, an increase in the number of taps in the graph (g1) may mean, for example, an increase in the buffer index. For example, if the number of taps on the horizontal axis of the graph (g1) is 4, it may mean a buffer index of 4. At this time, the delay value on the vertical axis of the graph (g1) may be D4 (= d1 + d2 + d3 + d4 + d14) as in FIG. 16b. For example, if the number of taps is 5, it may mean a buffer index of 5. At this time, the delay value on the vertical axis of the graph (g1) may be D5 (= d5 + d15) as in FIG. 16b. At this time, referring to FIG. 18, D4 > D5. Here, it can be seen that the delay observed in the flip-flop of each tap does not increase as the index of the tap (e.g., index 4 -> index 5) increases, but sometimes decreases locally even when the index of the tap increases.

[0166] On the other hand, an increase in the number of taps in the graph (g2) may not mean an increase in the buffer index, but may mean an increase in the position according to the sorting order in which the output values ​​of each flip-flop are sorted by the code conversion part (30). For example, if the number of taps on the horizontal axis of the graph (g2) is 4, the position order of the sorted buffer index may be 1, 2, 5, 3, which may mean buffer index 3. In this case, the delay value on the vertical axis of the graph (g2) may be D3 (= d1 + d2 + d3 + d13). For example, if the number of taps is 5, the position order of the sorted buffer index may be 1, 2, 5, 3, 6, which may mean buffer index 6. In this case, the delay value may be D6 (= d5 + d6 + d16). At this time, referring to FIG. 18, D3 <D6 일 수 있다.

[0167] That is, as shown in (a) of Fig. 17, when the code conversion part (30) of the present invention is not applied, it can be seen that the graph (g1) for the delay according to the increase in the number of taps does not have a monotonically increasing property. On the other hand, as shown in (b) of Fig. 17, when the code conversion part (30) of the present invention is applied, it can be seen that the graph (g2) for the delay according to the increase in the number of taps shows an increasing phenomenon without a decreasing phenomenon.

[0168] For example, unlike ASICs, which are application-specific integrated circuits (ASICs), FPGAs can be directly designed through programming, allowing the chip's functionality to be changed based on programming. Therefore, unlike ASICs, the functionality of each component within an FPGA can vary (or depend on the configuration). Therefore, as the number of taps increases, delay may not always increase but instead decrease, preventing a phenomenon of constant increase without decreasing.

[0169] However, as explained, it can be confirmed through the graph (g2) that the code conversion part (30) can compensate for the monotonically increasing nature of the first delay line part (20).

[0170] As described above, when multiple delay line parts (20) are used, delay alignment can be provided through the code conversion part. As a result, errors due to jitter can be compensated for and a TDC with high temporal resolution can be provided. For example, when four delay line parts are configured in parallel to have a total of 9,600 taps, a TDC with a resolution of 0.8 ps per tap can be provided.

[0171] FIG. 19 is a block diagram showing the main functional parts of a PCB board including an FPGA provided according to one embodiment of the present invention.

[0172] The transmitter (100) of FIG. 5 may include an electronic device including a TDC (150) and a control unit (170). At this time, the TDC (150) and / or the control unit (170) may be implemented as an FPGA (1). In addition, the FPGA (1) may be mounted on a PCB board (600) installed in the transmitter (100).

[0173] The PCB board (600) is a device capable of digital signal processing and may include not only an FPGA (1), but also a data interface (601), a clock generation unit (603), a power supply unit (604), and other functional units not shown in FIG. 19.

[0174] The data interface (601) is a device that enables data exchange between the PCB board (600) and the computing device (700), and may be formed of, but is not limited to, USB, Ethernet, or UART.

[0175] The clock generation unit (603) can provide a train of clock pulses counted by the FPGA (1).

[0176] The time interval of the two selected signals calculated by the FPGA (1) can be output from the FPGA (1) and provided to the data interface (601). The data interface (601) can provide the time interval of the two signals to the computing device (700).

[0177] The power supply unit (604) supplies power used in the PCB board (600).

[0178] A computing device (700) may include a data interface (701), a CPU (702), and a memory (703). A binary file containing configuration data for programming the FPGA (1) may be recorded in the memory (703). The CPU (702) may transmit the binary file to the data interface (601) via the data interface (701).

[0179] The above binary file can be stored in the ROM (80) of the FPGA (1) and used by the FPGA (1).

[0180] The above configuration data may be configured to allow the FPGA (1) to configure a predetermined digital circuit therein.

[0181] The above digital circuit may include a signal receiving part (71) that receives a laser pulse detection signal (800) including a pair of continuous electric pulses generated from a photodetector (110) included in a transmitter (100) of a plug-and-play QKD system, a time difference determining part (72) that determines a time interval between the pair of electric pulses, and an eavesdropping determination part (73) that determines that an eavesdropper is present in the quantum channel (300) when the determined time interval is different from a predetermined reference time interval. The names of the parts indicated by reference numbers 71, 72, and 73 are presented as above for convenience of explanation, but the specific names may be modified and presented with other names.

[0182] In addition, the digital circuit may further include the above-described input signal generation part (10), the first delay line part (21), the second delay line part (22), the code conversion part (30), the clock pulse counter part (40), the priority encoder part (50), and the operation part (60).

[0183] In one embodiment, the input signal generation part (10), the first delay line part (21), the second delay line part (22), the code conversion part (30), the clock pulse counter part (40), the priority encoder part (50), and the operation part (60) may be included in the time difference determination part (72).

[0184] In FIG. 19, the computing device (700) is presented as including a data interface (701), a CPU (702), and a memory (703), but may have a different configuration than that presented in FIG. 19 as long as the binary file can be provided to the FPGA (1).

[0185] The name of the file containing the configuration data that is to program the above FPGA (1) may have a name other than the binary file described above.

[0186] The above ROM (80), the FPGA (1) including the ROM (80), and the memory (703) may all be considered as non-volatile recording media readable by an electronic device, each provided according to one embodiment of the present invention.

[0187] By utilizing the embodiments of the present invention described above, those skilled in the art will be able to easily implement various changes and modifications without departing from the essential characteristics of the present invention. The content of each claim may be combined with other claims that are not in a citation relationship within the scope of this specification, as long as it is understood.

Claims

1. A transmitter (100) that determines the presence of an eavesdropper (500) in a quantum channel (300) in a plug-and-play QKD system, A photodetector (110) configured to detect a pair of consecutive laser pulses transmitted through a quantum channel (300) and output a laser pulse detection signal (800) including a pair of consecutive electric pulses corresponding to the detected pair of laser pulses; and TDC (150) measuring the time interval between the above pair of electric pulses; Including, Information about the measured time interval is characterized in that it is used to determine whether an eavesdropper exists in the quantum channel. Transmitter for QKD system with plug-and-play operation.

2. In paragraph 1, It further includes a control unit (170); The above control unit is configured to determine that there is an eavesdropper in the quantum channel if the measured time interval is different from a predetermined reference time interval. Transmitter for QKD system with plug-and-play operation.

3. In paragraph 1, After attenuating the energy of the above pair of laser pulses, they are transmitted back to the quantum channel. configured to modulate the phase of one of the above pair of laser pulses, Transmitter for QKD system with plug-and-play operation.

4. In paragraph 3, The above transmitter is configured to randomly select one of the multiple bases for the modulation, The above transmitter is configured to randomly select one of a plurality of quantum states and encode the signal laser pulse into the selected quantum state. Transmitter for QKD system with plug-and-play operation.

5. In paragraph 1, The above time interval is the time difference between the rising edge of the first electric pulse that occurred first among the above pair of electric pulses and the rising edge of the second electric pulse that occurred later. Transmitter for QKD system with plug-and-play operation.

6. In paragraph 1, The above TDC is, A first delay line part (20) into which an input pulse having a time difference between the first occurrence time of the first electric pulse and the second occurrence time of the second electric pulse is input; and An operation part (60) that determines the time interval using the thermometer code output by the first delay line part; Including, Transmitter for QKD system with plug-and-play operation.

7. In paragraph 6, The above TDC further includes a code conversion part (30) that converts and outputs the order of elements of the thermometer code. The above operation part is configured to determine the occurrence time difference using the conversion code output by the code conversion part. The above conversion code arranges the order of elements of the above thermometer code according to a certain standard. The above-mentioned predetermined criterion is a data path delay from the output node of the input pulse to the output nodes of each of the plurality of flip-flops (FF) included in the first delay line part. Transmitter for QKD system with plug-and-play operation.

8. In paragraph 6, The above TDC is implemented by one of a device among a Field Programmable Gate Array (FPGA), an Application Specific Integrated Circuit (ASIC), and an Integrated Circuit (IC), and the one of the devices is programmed to include the first delay line part and the operation part. Transmitter for QKD system with plug-and-play operation.

9. In paragraph 7, The above TDC further includes a second delay line part into which the input pulse is input; The above code conversion part is configured to generate the conversion code by arranging and merging elements of the thermometer code output by the first delay line part and elements of the thermometer code output by the second delay line part according to a predetermined second criterion. The above-mentioned second criterion is a data path delay from the output node of the input pulse to the output nodes of each of the plurality of flip-flops included in the first delay line part and the second delay line part. Transmitter for QKD system with plug-and-play operation.

10. In paragraph 8, The above TDC is configured to use a clock signal (clk) having a shorter period than the time difference between a pair of laser pulses output by the receiving device of the QKD system, The above TDC is, An input signal generating part (10) that generates the input pulse having a time difference between the occurrence time of the rising edge of the first electric pulse and the occurrence time of the rising edge of the second electric pulse as the width; A clock pulse counter part (40) that counts the number of clock pulses of the clock signal that occur during the maintenance period of the input pulse; and The arithmetic part determines the value of the occurrence time difference by using the first thermometer code (TC1) output by the code conversion part at the time of the rising edge of the first clock pulse among the generated clock pulses, the second thermometer code (TC2) output by the code conversion part at the time of the rising edge of the clock pulse that occurs immediately after the last clock pulse among the generated clock pulses, and the number of the counted clock pulses; Including more, Transmitter for QKD system with plug-and-play operation.

11. FPGA included in the plug-and-play QKD system, A signal receiving part (71) that receives a laser pulse detection signal (800) including a pair of continuous electric pulses generated from a photodetector included in a transmitter of the above QKD system; A time difference determining part (72) configured to determine the time interval between the above pair of electric pulses; and A wiretapping judgment part (73) that determines that there is an eavesdropper in the quantum channel if the above-determined time interval is different from a predetermined standard time interval; To construct a digital circuit including: A binary file containing configuration data that is intended to program the above FPGA is recorded, A nonvolatile storage medium that can be read by an electronic device.

12. In paragraph 11, The above digital circuit, A first delay line part (21) into which an input pulse having a time difference between the first occurrence time of the first electric pulse that occurred first among the above pair of electric pulses and the second occurrence time of the second electric pulse that occurred later is input; and An operation part (60) that determines the time interval using the thermometer code output by the first delay line part; Including more, A nonvolatile storage medium that can be read by an electronic device.

13. In paragraph 11, The above digital circuit further includes a code conversion part (30) that converts and outputs the order of elements of the thermometer code; The above operation part is configured to determine the time interval using the conversion code output by the code conversion part. The above conversion code arranges the order of elements of the above thermometer code according to a certain standard. The above-mentioned predetermined criterion is a data path delay from the output node of the input pulse to the output nodes of each of the plurality of flip-flops (FF) included in the first delay line part. A nonvolatile storage medium that can be read by an electronic device.

14. In paragraph 13, The above digital circuit further includes a second delay line part into which the input pulse is input; The above code conversion part is configured to generate the conversion code by merging elements of the thermometer code output by the first delay line part and elements of the thermometer code output by the second delay line part by aligning them according to a predetermined second criterion. The above-mentioned second criterion is a data path delay from the output node of the input pulse to the output nodes of each of the plurality of flip-flops included in the first delay line part and the second delay line part. A nonvolatile storage medium that can be read by an electronic device.

15. In paragraph 12, The above digital circuit is configured to use a clock signal (clk) having a shorter period than the time difference between a pair of laser pulses output by the receiving device of the QKD system, The above digital circuit, An input signal generating part that generates the input pulse having a time difference between the occurrence time of the rising edge of the first electric pulse and the occurrence time of the rising edge of the second electric pulse as the width; A clock pulse counter part that counts the number of clock pulses of the clock signal that occur during the maintenance period of the input pulse; and The arithmetic part that determines the value of the occurrence time difference by using the first thermometer code output by the code conversion part at the time of the rising edge of the first clock pulse among the generated clock pulses, the second thermometer code output by the code conversion part at the time of the rising edge of the clock pulse that occurs immediately after the last clock pulse among the generated clock pulses, and the number of the counted clock pulses; Including more, A nonvolatile storage medium that can be read by an electronic device.

Citation Information

Patent Citations

  • Method for manufacturing black matrix and display manufacturing method including the same

    KR1020250031800A

  • Synchronization system for quantum networks

    US20230206105A1