QKD system and method with improved start-up phase

The QKD system improves start-up efficiency by incorporating a dummy key exchange phase to optimize performance and confirm a positive key rate before initiating normal key exchange, addressing the need for manual intervention in conventional systems.

WO2025252809A1PCT designated stage Publication Date: 2025-12-11ID QUANTIQUE SA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/065493
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-06
Filing Date
2025-06-04
Publication Date
2025-12-11

AI Technical Summary

Technical Problem

Conventional Quantum Key Distribution (QKD) systems face challenges in achieving a high success rate and efficient start-up phase, often requiring manual intervention when pre-shared keys are depleted due to errors or channel losses, leading to system shutdown.

Method used

A QKD system and method that includes a dummy key exchange phase without authentication to optimize system performance and check QKD statistics, followed by a normal key exchange using initial keys only after a positive key rate is confirmed, and employs parameter tracking and retrieval to expedite subsequent start-ups.

Benefits of technology

Enhances the success rate of the start-up phase by reducing the need for manual intervention and optimizing system performance, ensuring efficient key exchange without wasting initial keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025065493_11122025_PF_FP_ABST
    Figure EP2025065493_11122025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a Quantum Key Distribution system comprising an emitter and a receiver adapted to exchange QKD-based keys comprising at least one controller wherein, when the system is switched on, the controller is configured to execute a start-up phase comprising an optics calibration and a subsequent preliminary qubit exchange phase wherein the controller is configured to improve system performance and to judge whether the QKD statistics results in a positive key rate, characterized in that the qubit exchange phase comprises the emitter and the receiver exchanging qubits without authentication and without sending keys to the user.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] QKD SYSTEM AND METHOD WITH IMPROVED START-UP PHASE

[0002] Technical Field

[0003] The present invention relates to Quantum Key Distribution (QKD) technology and more particularly to a method and a system for improving the start-up phase of a QKD communication process.

[0004] Background of the art

[0005] Quantum key distribution, in the following also referred to as QKD, is part of the general quantum cryptography technology and is a method allowing the distribution of a secret key between two distant parties: the emitter, usually called Alice, and the receiver, usually called Bob, with a provable absolute security. Quantum key distribution relies on quantum physics principles and encoding information in quantum states, or qubits, as opposed to classical communication's use of bits. Usually, photons are used for these quantum states. Quantum key distribution exploits certain properties of these quantum states to ensure its security.

[0006] More particularly, the security of this method comes from the fact that the measurement of a quantum state of an unknown quantum system modifies the system itself. In other words, a spy eavesdropping on a quantum communication channel cannot get information on the key without introducing errors in the key exchanged between the emitter and the receiver, thereby informing the user of an eavesdropping attempt.

[0007] In a QKD system, many protocols may be used, for example BB84, which itself may have several forms or implementation, COW, BB92 and the same.

[0008] In any QKD protocol, the security proof of the protocol itself is based on the assumption that the two parties (Alice / transmitter, Bob / receiver) communicate over an authenticated channel during the key exchange. To authenticate the communication between Alice and Bob, different authentication protocols can be used, e.g. Wegman- Carter authentication. All these protocols require that Alice and Bob share a key used to authenticate a certain amount of information exchanged in the channel. An initial pre-shared key is loaded in the systems by the users when they install it for the first time, with a USB key for example. Once the authentication is started, this key is consumed, and it is replaced by keys that Alice and Bob share between them during the quantum key distribution protocol.

[0009] In practice, a part of the keys generated goes to the user (main functionality of a QKD system) and the rest is used to make sure that Alice and Bob always have keys to perform the authentication between them.

[0010] However, if there is a problem with the quantum key distribution protocol, for example because of too many errors or too much loss in the quantum channel, Alice and Bob might run out of keys to use and “consume” all their stock. In this case, the QKD protocol cannot continue, the system will stop, and the user is required to manually upload fresh “pre-shared keys”.

[0011] In such case, the authentication key is used up but never replenished, arriving at a point where manual user intervention is required to provide fresh pre-shared keys.

[0012] In conventional systems, one tries to optimize as much as possible in terms of success rate the key exchange by checking if the conditions are not good, but it doesn’t assure a 100 % success rate.

[0013] In view of the above, there is a need to improve the time and the success rate of the key exchange step needed to run the start-up phase.

[0014] The object of the present invention is therefore to provide a system and a method which permit to improve the success rate of the start-up phase.

[0015] Summary of the invention

[0016] The above problems are solved by the present invention which is based on a new functioning mode of the start-up phase where the QKD system launches a dummy key exchange, equivalent to a normal key exchange but without authentication and without sending keys to the user. This dummy key exchange is used to run the optimization algorithms to improve system performance and to check that the QKD statistics are good enough to have a positive key rate. If this step is successful, the normal key exchange starts, uses an initial key and outputs secret keys to the user.

[0017] This allows a direct evaluation of the possibility to exchange keys via a dummy key exchange. In this way no initial key is wasted, and manual user intervention is not needed any more in case of problems.

[0018] A first aspect of the invention is a quantum Key Distribution system comprising an emitter and a receiver adapted to exchange QKD-based key comprising at least one controller wherein, when the system is switched on, the controller is configured to execute a start-up phase comprising an optics calibration and a subsequent preliminary qubit exchange phase wherein the controller is configured to improve system performance and to judge that the QKD statistics results in a positive key rate, characterized in that the qubit exchange phase comprises the emitter and the receiver exchanging qubits without authentication and without sending keys to the user

[0019] Preferably, in the subsequent preliminary qubit exchange phase, the controller is configured to run an optimization algorithm.

[0020] Advantageously, when the controller judges that the QKD statistics results in a positive key exchange, the normal key exchange starts and uses an initial key and outputs secret keys to the user.

[0021] According to a preferred embodiment of the present invention, once the normal key exchange starts, the emitter and the receiver carry out a Privacy Amplification.

[0022] Preferably, after the Privacy Amplification, the emitter and the receiver share an error corrected and secure set of bits that can be used as keys.

[0023] Advantageously, a part of the set of bits are used to fill up an authentication buffer to authenticate the communication between the emitter and the receiver and the rest is sent to the user to be used as keys.

[0024] Preferably, during the optics calibration, the controller is configured to track parameters of the system and record them in said memory upon switch off of the system, and is configured to retrieve said recorded parameters of the system and apply them to the system upon a subsequent start-up phase.

[0025] A second aspect of the invention is a Quantum Key Distribution method to be implemented by the Quantum Key Distribution system of the first aspect comprising Alice sending random qubits to Bob, Bob decoding the qubits and sends information to Alice about its measurement, Alice and Bob then performing error correction on their respective bits, Alice, using the statistics measured and announced by Bob and the security proof typical of the protocol, deciding how many of the bits they shared have to be discarded because potentially unsafe, Alice and Bob using the same statistics as a feedback value to optimize their encoding and decoding strategy, and judging whether the QKD statistics results in a positive key rate.

[0026] Advantageously, the Quantum Key Distribution method comprises a first step prior to the qubit exchange step including a calibration start-up phase including a parameter tracking step comprising tracking and measuring optical parameters of the system, a last parameter recording step comprising recording the last parameters upon switch off of the QKD system, a retrieving step comprising retrieving said last recorded parameters of the system and apply them to the system upon a subsequent start-up phase following said switch off.

[0027] Brief description of the drawings

[0028] Further particular advantages and features of the invention will become more apparent from the following non-limitative description of at least one embodiment of the invention which will refer to the accompanying drawings, wherein:

[0029] - Figure 1 is a block diagram showing a conventional QKD system,

[0030] - Figure 2 is a block diagram showing a QKD calibration method according to a first embodiment of the present invention, and

[0031] - Figure 3 is a block diagram showing a QKD calibration method according to a second embodiment of the present invention, and - Figure 4 is a block diagram showing a QKD calibration method according to combination of the first embodiment of the present invention and the second embodiment.

[0032] Detailed description of the invention

[0033] The present detailed description is intended to illustrate the invention in a non- limitative manner since any feature of an embodiment may be combined with any other feature of a different embodiment in an advantageous manner.

[0034] Figure 1 shows a conventional start-up sequence of a QKD calibration method where the start-up sequence comprises a parameter optimization and a key exchange.

[0035] The parameter optimization concretely consists in calibrating the optics of the emitter and / or the receiver of the QKD system. It is followed by the key exchange where one starts exchanging a key between the emitter and the receiver and where an initial key is a pre-shared key and during which the optimization continues while key exchange is performed.

[0036] However, before entering the details, we shall remember the basics of QKD key exchange.

[0037] QKD involves two parties, typically named Alice and Bob, who want to share a secret key, to be used later on for any cryptographic application. For increased security, they decide to use Quantum Key Distribution (QKD) to accomplish this task. To perform QKD or at least any prepare & measure protocol, like the well-known BB84, they need two elements: a quantum channel and a classical communication channel. The classical communication channel is used between Alice and Bob to exchange all the information needed to perform the QKD protocol. In this regard, the classical communication channel needs to be authenticated but not necessarily encrypted, in other words, the exchanged information can be public, but Alice and Bob need to be sure that they are talking to each other and there is no “man-in-the-middle” type of attacker.

[0038] It has to be highlighted that a typical QKD security proof requires a number of steps / actions to be taken by Alice and Bob to be able to successfully share a key securely, these actions are only the ones strictly related to the key exchange itself and do not cover all technical steps that typically Alice and Bob need to perform to arrive at a stage where they can start a key exchange. These technical steps are considered not critical from a security perspective because they don’t involve sharing information related to the secret key and constitute the start-up sequence which is detailed in the following.

[0039] Such start-up sequence in a QKD protocol comprises the following steps:

[0040] Step 1 : Alice powers-up.

[0041] Step 2: Pre-sharing of authentication keys. Alice generates a set N of authentication key pairs and store half of them in its internal memory. The other half is sent to Bob via a secure channel, independent of the QKD protocol (these are called pre-shared keys, and they will be later used by Alice and Bob for authenticating their communication). Usually, a secure channel involves an operator to physically go from Alice location to Bob location with a secure drive to install the keys, (this step is only needed if there are not already authentication keys present at Alice and Bob, e.g. first time Alice and Bob are used, or they depleted their stock of keys).

[0042] Step 3: Alice self-calibration. Alice performs an internal self-calibration of some electrical and optical components needed for the key exchange, depending on the specific HW implementation, (e.g. optimization of the bias point of the intensity modulator, optimization of the internal delays between the modulation signal of the laser source and the different modulators, optimization of the working point of the optical interferometer)

[0043] Step 4: Bob powers up (this step and step 5 can start in parallel with point 1 and 2)

[0044] Step 5: Bob self-calibration. Bob performs an internal self-calibration of some electrical and optical components needed for the key exchange, depending on the specific HW implementation, (e.g. optimization of the bias point of the single-photon detectors, optical modulators, optimization of the working point of the optical interferometer) Step 6: Clock synchronization. Alice and Bob synchronize their clocks via a shared clock channel (typically the same classical communication channel can be used for this task)

[0045] Step 7: HW parameter tuning at start-up. Alice and Bob perform some optical and electrical alignment steps between each other (e.g. they align the encoding and decoding mechanisms used to prepare and detect photons at the two sides like time bin, phase or polarization, they align their counters to make sure that once Bob announces the detection of a photon, Alice can retrieve exactly which photon he has detected etc.)

[0046] As explained above, this conventional method requires some time to optimize communication. There is therefore a need to shorten this first step.

[0047] Once this start-up phase is executed, Alice and Bob are ready to start a key exchange. From now on, every step from here is critical for the security of the QKD protocol and the generated key.

[0048] The QKD exchange is executed according to the following steps:

[0049] Step T: Qubit preparation. Alice sends a block of N photons to Bob through the quantum channel; each photon is encoded with a certain bit and base according to the specific QKD protocol (e.g. BB84).

[0050] Step 2': Qubit measurement. Bob detects the photons and announces to Alice a part of its results again according to the specific protocol (e.g. for BB84 he will announce which photon he detected in which base, without disclosing the measured state for the secret key encoding base), through the classical communication channel.

[0051] Step 3': Block statistics. By measuring some statistical properties of this photon exchange (e.g. quantum bit error rate, visibility, decoy state statistics etc.) they decide if the quality of the key exchange is good enough to extract some secret bits (or in other words, to have a positive key). If so, they proceed to step 4', otherwise they restart from step T. Step 4': HW parameter tuning during run-time. Alice and Bob tune some of their optical and electrical components (mainly the same ones involved in step 3, 5 and 7 of the start-up sequence) to compensate for possible drifts in their optimum working point. They use the statistics collected in step 3' as feedback signal for such tuning process (e.g. in a time-bin BB84 system, they can tune the bias point of the intensity modulator at Alice by looking at the QBER retrieved during the block statistics and optimize the system to have the smallest possible QBER in order to have the highest possible secret key rate).

[0052] Step 5': Post-processing. If step 3' is successful, they both perform certain post-processing steps to be able to generate a shared key from their measurement results. Typical post-processing steps are sifting, error correction and privacy amplification.

[0053] It is important to note that all communications through the classical communication channel performed during steps T, 2', 3' and 4' need to be authenticated. To do so, Alice and Bob use the keys they had pre-shared in step 2. One key is used every M bits of information between the two (where M depends on the specific authentication protocol used).

[0054] Step 6': Key available to user. If all the above steps are successful, Alice and Bob share a number X of secret bits. Part of these bits are used to replenish the stock of authentication keys between them (to be used for the next round of QKD), the rest of the bits are available to the final user to be used as secret key for its cryptographic needs

[0055] Step 7': Loop. Alice and Bob loop again starting from step T.

[0056] At this point, we will now describe the different embodiments of the present invention which the present invention provides a solution to enhance the start-up sequence or the QKD exchange or both.

[0057] Figure 2 is a block diagram showing a QKD calibration method according to a first embodiment of the invention, where the QKD system comprises an emitter and a receiver adapted to communicate through a quantum channel. By referencing the above different steps of the start-up sequence, the first embodiment aims at reducing the time taken to perform the start-up sequence (which can typically take up to 10-15 minutes in a commercial QKD system).

[0058] The main feature in this embodiment is to introduce an additional step during the QKD exchange, right after step 5':

[0059] Step 5'b. Storing last “good values”. Alice and Bob evaluate if the result of their key exchange with a specific block of N photons was successful (a positive secret key rate was generated) and if the performance was better or worse than the previous block (in terms of how much secret keys were generated). If the block was successful and the result was better than the previous block, the hardware parameters (typically tuned during step 4' at run-time and at step 3, 5 and 7 at start-up) are stored in a memory for later use.

[0060] By doing so, the start-up sequence can be also modified by using these last good parameters in steps 3, 5 and 7.

[0061] It is important to note that this process is different from just retrieving a setting from a system at power-up (like in a TV set) because here the system is just making a guess based on the last know good values instead of performing a complete tuning algorithm. The last known good value will not work 100 % of the time (e.g. if the system hasn’t been exchanging keys for a long time) but most of the time it will speed up the start-up sequence.

[0062] Then the process also adds two additional steps :

[0063] Step 8' where ones checks if the system is running correctly (by performing a “dummy” key exchange for example, see below) to avoid going directly to the QKD exchange, and

[0064] If performance is above set threshold (e.g. we have an estimated positive key rate). Step 8 : The system can move to the QKD exchange, otherwise it can restart and perform a “standard” start-up sequence without using the last “good values”. Also note that even if the last good values are just a good guess and not the best values to optimize performance, the system will eventually converge to the best operating conditions through the HW tuning step performed at the end of every block of exchanged photons, either during the “dummy” key exchange or later during the QKD exchange.

[0065] In order to carry out this first embodiment, the system comprises at least one memory and at least one controller, wherein the controller is adapted to track and measure the different parameters of the system and record them in the memory when it detects that the system is switched off. Preferably, the controller can continuously record the parameters of the system in a dedicated memory which is preferably a cache memory.

[0066] This allows to keep the last implemented parameters, which are preferably the last optimized parameters thanks to the tracking and optimizing process, recorded in a memory which can be embedded or not in the system.

[0067] Subsequently, when the QKD system is switched-on again and a subsequent start-up phase is carried out, the controller is able to immediately retrieve said parameters, which were lastly recorded in said memory, and apply them to the system. This allows therefore to avoid a full recalibration phase like in the first phase of the conventional system depicted in figure 1 , and to carry out an immediate application of the best parameters previously measured. As a result, the first phase is drastically shortened.

[0068] The above system and method were described for a system comprising a single emitter and a single receiver, however, of course, the system can be configured for a network comprising several emitters and several receivers in an NxM model, where N is the number of emitters and M is the number of receivers. In such case, at least one controller, preferably each controller i.e. one per link, is capable of tracking and recording the parameters for each communication couple (link) independently and retrieve the last optimized parameters for each communication link independently. The above-mentioned parameters, which are optimized, may vary. Indeed, examples of optical alignment steps needed may comprise anyone of the following provided that they depend on the protocol:

[0069] The first one is the bias voltage of the intensity modulator at the emitter.

[0070] An optimization of the bias voltage of the intensity modulator at the emitter is needed to optimize the extinction ratio of the modulator and hence the Quantum Bit Error Rate (QBER). The principle here is to measure the received errors at the receiver and tune the bias voltage of the modulator at the emitter to get the best QBER.

[0071] A second one is the phase between the interferometer of the emitter and the receiver.

[0072] An optimization of the phase between the interferometer of the emitter and the receiver because these two interferometers need to be phase locked. To do so, a measurement of the interferometer of the receiver is performed (typically its visibility) and some parameters of the interferometer of the emitter is tuned (e.g. its temperature, or the delay of one of the two arms with a piezo-electric controller) while a light signal is transmitted between Alice and Bob.

[0073] Additional parameters may comprise the laser bias current at the emitter or the modulation voltage of the phase modulator at the emitter and / or the receiver.

[0074] In addition to the above-described first embodiment improving the start-up phase, the present invention also comprises a second embodiment which allows to improve the key exchange.

[0075] Figure 3 is a block diagram showing a QKD calibration method according to a second embodiment, where the QKD system comprises an emitter and a receiver adapted to communicate through a quantum channel.

[0076] As mentioned above, the normal QKD key exchange requires the following steps:

[0077] 1. First, Alice sends random qubits, i.e. photons encoded in different states / basis, to Bob through the quantum channel. 2. When Bob receives the qubits, it decodes the qubits and sends information to Alice about its measurement. This phase is called sifting.

[0078] 3. Alice and Bob then measure some statistical properties of this photon exchange and perform error correction on their respective bits.

[0079] 4. Alice, using the statistics measured and announced by Bob and the security proof typical of the protocol (e.g. BB84), decides how many of the bits they shared have to be discarded because potentially unsafe, and they use the same statistics as feedback value to optimize their encoding and decoding strategy, e.g. they might change the bias voltage of the Intensity Modulator at Alice to minimize the QBER.

[0080] 5. Alice and Bob discard these bits with a processing mechanism called Privacy Amplification and share an error corrected and secure set of bits that can be used as keys.

[0081] 6. Part of these bits are used to fill up the authentication buffer to authenticate the communication between Alice and Bob, the rest is sent to the user to be used as “keys”.

[0082] All communication between Alice and Bob, from point 1 to 6 is authenticated. It’s a security requirement of the protocol.

[0083] Referring to steps T to 7' above and to steps 1 -6 just before, it is important to note that if multiple loops fail before being able to generate key material (for example because the quality of the quantum channel is not good enough to have good statistical data on the photons), Alice and Bob can arrive at a point where they completely consume their authentication keys, if this happen they cannot continue their protocol anymore and they need to wait for an operator to physically replenish the keys (go back to the start-up sequence and wait for operator intervention).

[0084] In order to solve this problem, the inventors have noted that outside of the key exchange functionality, a QKD system doesn’t need an authenticated communication and that Alice and Bob can communicate without authentication and without key exchange between each other for a lot of auxiliary tasks like the calibration I alignment routines that must be performed when the system I switched on. This is the case, for example, when the clock of Alice and Bob must be aligned in frequency and phase, and in some protocols when the phase of the interferometer of Alice must be aligned with the phase of the interferometer of Bob and the same.

[0085] A second embodiment of the present invention therefore relates to a QKD system and method which avoids consuming “pre-shared keys” when Alice and Bob are not able to perform a normal QKD exchange and hence generate new ones .The aspect of this second embodiment is here called “Dummy” key exchange at start-up.

[0086] In this aspect, Alice and Bob perform QKD steps T to 7' without authentication of their classical communication channel. In other words, to positively phrase this we can say that we add a non-authenticated version of step T to 7’ to the start-up phase what is called dummy key exchange to check, with something as similar as possible to the “real” key exchange that the protocol and the system will work, without consuming authentication keys. The outcome of this dummy sequence is not keys to be provided to the user but just the information that Alice and Bob can successfully exchange keys (since they tried to do so and succeeded, in a controlled environment without authentication).

[0087] Although they arrive at a stage where they have secret keys, they do not provide these keys to the final user at step 6' (since they are not secure and we are still in the start-up sequence part of the protocol). This is done only to verify that they are able to successfully exchange keys before launching the real protocol. In this way they do not consume authentication keys for nothing. After X blocks of dummy key exchange, the system can decide to move to the QKD stage (if the measured key rate is positive and above a set threshold) or to stop there and raise an error.

[0088] In order to be able to do so, the Quantum Key Distribution system typically comprises an emitter and a receiver adapted to exchange QKD-based key and at least one controller which executes a start-up phase comprising an optics calibration and a subsequent preliminary qubit exchange phase. According to this second embodiment, the controller is configured to improve system performance and to judge that the QKD statistics are good enough, which means that it results in a positive key rate. The qubit exchange phase comprises the emitter and the receiver exchanging qubits without authentication and without sending keys to the user. A positive key-rate means, for example, in a BB84 security proof, that one measures a set of statistics and we input them in a formula that calculates the compression ratio (basically how many bits are kept and how many are discarded. During the dummy key exchange, one calculates this. If the system can exchange a positive key rate (hence > 0) then the result is positive, and when the controller judges that the QKD statistics results in a positive key exchange, the normal key exchange starts and uses an initial key and outputs secret keys to the user.

[0089] In other words, the method and the system of the present invention carries out a start-up phase where the second step consists in a so-called “dummy keyexchange”, where Alice and Bob, after the first calibration step explained above in reference to figure 2, starts a QKD key exchange described in points 1 to 5 above like a conventional one but with two main differences:

[0090] (i) all the communication between Alice and Bob in point 1 to 5 is not authenticated and it doesn’t consume authentication keys, and

[0091] (ii) the process stops at step 5, therefore steps 6-8 are avoided, and no keys are given to the user, since they are not secure.

[0092] In this manner, Alice and Bob have all the statistical analysis like in a real key exchange thanks to steps 1 -5. They can also use it to optimize their protocol and check that the quality of their qubit exchange is good enough to have a key > 0 at the end of the process. However, here, steps 6, 7 and 8 are not performed and no keys are sent to the user.

[0093] This key exchange is used to make sure that Alice and Bob are able to perform the protocol. During this step, one can measure the errors generated, the number of keys per second generated and other parameters that we can use as a go / no-go threshold to decide to move to a real key exchange that consumes authentication keys but also generates new keys for the system and for the user.

[0094] A third embodiment of the invention is shown in figure 4 and relates to a combination of the first and second embodiment. In this third embodiment, the first, calibration, step of the start-up phase is using the last optimized, recorded, parameters as described above, and is followed by a second step without authentication and with no key exchange.

[0095] While the embodiments have been described in conjunction with a number of embodiments, it is evident that many alternatives, modifications and variations would be or are apparent to those of ordinary skill in the applicable arts. Accordingly, this disclosure is intended to embrace all such alternatives, modifications, equivalents and variations that are within the scope of this disclosure. This is, for example, particularly the case regarding the different apparatuses which can be used.

Claims

CLAIMS1. Quantum Key Distribution system comprising an emitter and a receiver adapted to exchange QKD-based keys comprising at least one controller wherein, when the system is switched on, the controller is configured to execute a start-up phase comprising an optics calibration and a subsequent preliminary qubit exchange phase wherein the controller is configured to improve system performance and to judge that the QKD statistics results in a positive key rate, characterized in that the qubit exchange phase comprises the emitter and the receiver exchanging qubits without authentication and without sending keys to the user2. Quantum Key Distribution system according to claim 1 , characterized in that in the subsequent preliminary qubit exchange phase, the controller is configured to run optimization algorithm.

3. Quantum Key Distribution system according to any one of claims 1 or 2, characterized in that when the controller judges that the QKD statistics results in a positive key exchange, the normal key exchange starts and uses an initial key and outputs secret keys to the user.

4. Quantum Key Distribution system according to claim 3, characterized in that once the normal key exchange starts, the emitter and the receiver carry out a Privacy Amplification.

5. Quantum Key Distribution system according to claim 4, characterized in that after the Privacy Amplification, the emitter and the receiver share an error corrected and secure set of bits that can be used as keys.

6. Quantum Key Distribution system according to claim 5, characterized in that a part of the set of bits are used to fill up an authentication buffer to authenticate the communication between the emitter and the receiver and the rest is sent to the user to be used as keys.

7. Quantum Key Distribution method according to any one of claims 1 to 6, characterized in that during the optics calibration, the controller is configured to trackparameters of the system and record them in said memory upon switch off of the system, and is configured to retrieve said recorded parameters of the system and apply them to the system upon a subsequent start-up phase.

8. Quantum Key Distribution method to be implemented by the Quantum Key Distribution system of claims 1 to 7 comprisingAlice sending random qubits to Bob,Bob decoding the qubits and sending information to Alice about its measurement,Alice and Bob then performing error correction on their respective bits,Alice, using the statistics measured and announced by Bob and the security proof typical of the protocol, deciding how many of the bits they shared have to be discarded because potentially unsafe,Alice and Bob using the same statistics as a feedback value to optimize their encoding and decoding strategy, andJudging whether the QKD statistics results in a positive key rate.

9. Quantum Key Distribution method of claim 8 comprising a first step prior to the qubit exchange step including a calibration start-up phase including a parameter tracking step comprising tracking and measuring optical parameters of the system, a last parameter recording step comprising recording the last parameters upon switch off of the QKD system, a retrieving step comprising retrieving said last recorded parameters of the system and applying them to the system upon a subsequent start-up phase following said switch off.

Citation Information

Patent Citations

  • Apparatus and method for adding an entropy source to quantum key distribution systems

    US20200153619A1

  • A network node, a transmitter and a receiver for quantum key distribution over an optical fiber network

    US20240056294A1