Systems and methods for quantum key distribution
Novel QKD protocols using sub-Poissonian photon sources with controlled emission statistics and giant colloidal quantum dots enhance QKD performance by overcoming limitations of ideal sources, achieving superior channel loss and secure key rates.
Patent Information
- Application Number
- PCT/IL2025/050668
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-08
- Filing Date
- 2025-08-06
- Publication Date
- 2026-02-12
AI Technical Summary
Existing quantum key distribution (QKD) systems face limitations due to the lack of ideal single photon sources, leading to reduced secure key rate and maximal channel loss, especially with imperfect sources like weak coherent states, which are vulnerable to eavesdropping attacks and channel losses.
Implementing novel QKD protocols using sub-Poissonian photon sources (SPPS) with controlled photon emission statistics, allowing for dynamic adjustment of emission probabilities, enabling decoy-based and heralded purification protocols, utilizing giant colloidal quantum dots coupled to nanoantennas for enhanced photon emission.
Significantly enhances QKD performance by exceeding the maximum channel loss of ideal decoy state protocols, achieving a gain of at least 3 dB, even with non-ideal sources, and providing near-unity collection efficiencies.
Smart Images

Figure IL2025050668_12022026_PF_FP_ABST
Abstract
Description
[0001] SYSTEMS AND METHODS FOR QUANTUM KEY DISTRIBUTION
[0002] TECHNOLOGICAL FIELD
[0003] The present disclosure is in the general field pertaining to methods and apparatus for transmitting and receiving quantum communications.
[0004] BACKGROUND ART
[0005] References considered to be relevant as background to the presently disclosed subject matter are listed below:
[0006] 1. P. W. Shor and J. Preskill, Simple Proof of Security of the BB84 Quantum Key Distribution Protocol, Physical Review Letters 85, 441 (2000).
[0007] 2. S. Pirandola, S. Pirandola, U. L. Andersen, L. Banchi, M. Berta, D. Bunandar, R. Colbeck, D. Englund, T. Gehring, C. Lupo, C. Ottaviani, J. L. Pereira, M. Razavi, J. S. Shaari, J. S. Shaari, M. Tomamichel, M. Tomamichel, V. C. Usenko, G. Vallone, P. Villoresi, and P. Wallden, Advances in quantum cryptography, Advances in Optics and Photonics, Vol. 12, Issue 4, pp. 1012-1236 12, 1012 (2020).
[0008] 3. F. Xu, X. Ma, Q. Zhang, H. K. Lo, and J. W. Pan, Secure quantum key distribution with realistic devices, Reviews of Modern Physics 92, 025002 (2020).
[0009] 4. R. G. Pousa, D. K. L. Oi, and J. Jeffers, Comparison of non-decoy single-photon source and decoy weak coherent pulse in quantum key distribution, arXiv (2024).
[0010] 5. M. Pereira, M. Curty, and K. Tamaki, Quantum key distribution with flawed and leaky sources, npj Quantum Information 2019 5:1 5, 1 (2019).
[0011] 6. H. K. Lo, X. Ma, and K. Chen, Decoy state quantum key distribution, Physical Review Letters 94, 230504 (2005).
[0012] 7. X. Ma, B. Qi, Y. Zhao, and H. K. Lo, Practical decoy state for quantum key distribution, Physical Review A - Atomic, Molecular, and Optical Physics 72, 012326 (2005). 8. K. Sulimany, G. Pelc, R. Dudkiewicz, S. Korenblit, H. S. Eisenberg, Y. Bromberg, and M. Ben-Or, Highdimensional coherent one-way quantum key distribution, arXiv preprint arXiv:2105.04733 (2021).
[0013] 9. G. J. Fan- Yuan, Z. H. Wang, S. Wang, Z. Q. Yin, W. Chen, D. Y. He, G. C. Guo, and Z. F. Han, Optimizing Decoy-State Protocols for Practical Quantum Key Distribution Systems, Advanced Quantum Technologies 4, 2000131 (2021).
[0014] 10. Y. Chen, C. Huang, Z. Chen, W. He, C. Zhang, S. Sun, and K. Wei, Experimental study of secure quantum key distribution with source and detection imperfections, Physical Review A 106, 022614 (2022).
[0015] 11. Y. Zhang, X. Ding, Y. Li, L. Zhang, Y.-P. Guo, G.-Q. Wang, Z. Ning, M.-C. Xu, R.-Z. Liu, J.-Y. Zhao, G.Y. Zou, H. Wang, Y. Cao, Y.-M. He, C.-Z. Peng, Y.-H. Huo, S.-K. Liao, C.-Y. Lu, F. Xu, and J.-W. Pan, Experimental single-photon quantum key distribution surpassing the fundamental coherent-state rate limit, arXiv (2024).
[0016] 12. N. Somaschi, V. Giesz, L. De Santis, J. Loredo, M. P. Almeida, G. Hornecker, S. L. Portalupi, T. Grange, C. Anton, J. Demory, et al., Near-optimal singlephoton sources in the solid state, Nature Photonics 10, 340 (2016).
[0017] 13. J. C. Loredo, N. A. Zakaria, N. Somaschi, C. Anton, L. De Santis, V. Giesz, T. Grange, M. A. Broome, O. Gazzano, G. Coppola, I. Sagnes, A. Lemaitre, A. Auffeves, P. Senellart, M. P. Almeida, and A. G. White, Scalable performance in solid- state single-photon sources, Optica 3, 433 (2016).
[0018] 14. Y.-M. He, Y. He, Y.-J. Wei, D. Wu, M. Atature, C. Schneider, S. Hofling, M. Kamp, C.-Y. Lu, and J.W. Pan, On-demand semiconductor single-photon source with near-unity indistinguishability, Nature nanotechnology 8, 213 (2013).
[0019] 15. C. R. Kagan, L. C. Bassett, C. B. Murray, and S. M. Thompson, Colloidal Quantum Dots as Platforms for Quantum Information Science, Chemical Reviews 121, 3186 (2021).
[0020] 16. J.-H. Kim, T. Heindel, S. Reitzenstein, A. Rastelli, and N. Gregersen, Quantum dots for photonic quantum information technology, Advances in Optics and Photonics, Vol. 15, Issue 3, pp. 613-738 15, 613 (2023).
[0021] 17. D. Nelson, S. Byun, J. Bullock, K. B. Crozier, and S. Kim, Colloidal quantum dots as single photon sources, Journal of Materials Chemistry C 12, 5684 (2024). 18. A. Nazarov, Y. Bloom, B. Lubotzky, H. Abudayyeh, A. Mildner, L. Baldessarini, Y. Shemla, E. G. Bowes, M. Fleischer, J. A. Hollingsworth, et al., Ultrafast and highly collimated radially polarized photons at room temperature from a colloidal quantum dot coupled to a hybrid nanoantenna, ACS Photonics 11, 4453 (2024).
[0022] 19. H. Abudayyeh, A. Mildner, D. Liran, B. Lubotzky, L. Luder, M. Fleischer, and R. Rapaport, Overcoming the Rate-Directionality Trade-off: A Room- Temperature Ultrabright Quantum Light Source, ACS Nano 15, 17384 (2021).
[0023] 20. B. Lubotzky, A. Nazarov, H. Abudayyeh, L. Antoniuk, N. Lettner, V. Agafonov, A. V. Bennett, S. Majumder, V. Chandrasekaran, E. G. Bowes, H. Htoon, J. A. Hollingsworth, A. Kubanek, and R. Rapaport, Room-Temperature Fiber-Coupled Single-Photon Sources based on Colloidal Quantum Dots and SiV Centers in Back- Excited Nanoantennas, Nano Letters 24, 640 (2024).
[0024] 21. H. Abudayyeh, B. Lubotzky, A. Blake, J. Wang, S. Majumder, Z. Hu, Y. Kim, H. Htoon, R. Bose, A. V. Malko, J. A. Hollingsworth, and R. Rapaport, Single photon sources with near unity collection efficiencies by deterministic placement of quantum dots in nanoantennas, APL Photonics 6 (2021).
[0025] 22. D. Halevi, B. Lubotzky, K. Sulimany, E. G. Bowes, J. A. Hollingsworth, Y. Bromberg, and R. Rapaport, High-dimensional quantum key distribution using orbital angular momentum of single photons from a colloidal quantum dot at room temperature, arXiv preprint arXiv:2405.03377 (2024).
[0026] 23. B. Li, G. Zhang, Y. Zhang, C. Yang, W. Guo, Y. Peng, R. Chen, C. Qin, Y. Gao, J. Hu, R. Wu, J. Ma, H. Zhong, Y. Zheng, L. Xiao, and S. Jia, Biexciton dynamics in single colloidal cdse quantum dots, The Journal of Physical Chemistry Letters 11, 10425 (2020).
[0027] 24. H. Abudayyeh, B. Lubotzky, S. Majumder, J. A. Hollingsworth, and R. Rapaport, Purification of Single Photons by Temporal Heralding of Quantum Dot Sources, ACS Photonics 6, 446 (2019).
[0028] 25. D. J. Gauthier, H. Zheng, and H. U. Baranger, Decoystate quantum key distribution with nonclassical light generated in a one-dimensional waveguide, Optics Letters, Vol. 38, Issue 5, pp. 622-624 38, 622 (2013).
[0029] 26. Q. Wang, W. Chen, G. Xavier, M. Swillo, T. Zhang, S. Sauge, M. Tengner, Z. F. Han, G. C. Guo, and A. Karlsson, Experimental decoy-state quantum key distribution with a sub-poissionian heralded single-photon source, Physical Review Letters 100, 090501 (2008).
[0030] 27. C. L. Morrison, R. G. Pousa, F. Graffitti, Z. X. Koong, P. Barrow, N. G. Stoltz, D. Bouwmeester, J. Jeffers, D. K. Oi, B. D. Gerardot, et al., Single-emitter quantum key distribution over 175 km of fibre with optimised finite key rates, Nature Communications 14, 3573 (2023).
[0031] 28. K. Matsuzaki, S. Vassant, H. W. Liu, A. Dutschke, B. Hoffmann, X. Chen, S. Christiansen, M. R. Buck, J. A. Hollingsworth, S. Gbtzinger, and V. Sandoghdar, Strong plasmonic enhancement of biexciton emission: controlled coupling of a single quantum dot to a gold nanocone antenna, Scientific Reports 2017 7: 1 7, 1 (2017).
[0032] 29. D. Gottesman, Hoi-Kwong Lo, N. Lutkenhaus, and J. Preskill, Security of quantum key distribution with imperfect devices, International Symposium on Information Theory, 2004. ISIT 2004. Proceedings. 135 (2004).
[0033] 30. M. J. Stevens, S. Glancy, S. W. Nam, and R. P. Mirin, Third-order antibunching from an imperfect singlephoton source, Optics express 22, 3244 (2014).
[0034] 31. J.-Y. Hu, B. Yu, M.-Y. Jing, L.-T. Xiao, S.-T. Jia, G.Q. Qin, and G.-L. Long, Experimental quantum secure direct communication with single photons, Light: Science & Applications 5, el6144 (2016).
[0035] 32. J. M. Pietryga, Y.-S. Park, J. Lim, A. F. Fidler, W. K. Bae, S. Brovelli, and V. I. Klimov, Spectroscopic and device aspects of nanocrystal quantum dots, Chemical Reviews 116, 10513 (2016), https: / / doi.org / 10.1021 / acs.chemrev.6b00169.
[0036] 33. Y. Chen, J. Vela, H. Htoon, J. L. Casson, D. J. Werder, D. A. Bussian, V. I. Klimov, and J. A. Hollingsworth, "Giant" multishell CdSe nanocrystal quantum dots with suppressed blinking, Journal of the American Chemical Society 130, 5026 (2008).
[0037] 34. H. Htoon, A. V. Malko, D. Bussian, J. Vela, Y. Chen, J. A. Hollingsworth, and V. I. Klimov, Highly emissive multiexcitons in steady-state photoluminescence of individual "giant" CdSe / CdS Core / Shell Nanocrystals, Nano Letters 10, 2401 (2010).
[0038] 35. F. Garcia- Santamaria, Y. Chen, J. Vela, R. D. Schaller, J. A. Hollingsworth, and V. I. Klimov, Suppressed auger recombination in "Giant" nanocrystals boosts optical gain performance, Nano Letters 9, 3482 (2009). 36. P. Nagpal, D. J. Norris, and et al., Ultrasmooth patterned metals for plasmonics and metamaterials, Science 325, 594 (2009).
[0039] 37. J. Fulmes, M. Fleischer, and et al., Self-aligned placement and detection of quantum dots on the tips of individual conical plasmonic nanostructures, Nanoscale 7, 14691 (2015).
[0040] 38. A. J. Meixner, R. Jager, M. Fleischer, and et al., Coupling single quantum dots to plasmonic nanocones: optical properties, Faraday Discussions 184, 321 (2015).
[0041] 39. N. J. Orfield, S. Majumder, J. R. McBride, F. YikChing Koh, A. Singh, S. J. Bouquin, J. L. Casson, A. D. Johnson, L. Sun, X. Li, et al., Photophysics of thermallyassisted photobleaching in "giant" quantum dots revealed in single nanocrystals, Acs Nano 12, 4206 (2018).
[0042] Acknowledgement of the above references herein is not to be inferred as meaning that these are in any way relevant to the patentability of the presently disclosed subject matter.
[0043] BACKGROUND
[0044] Quantum key distribution (QKD) can be used for the post-quantum-computer optical communication, enabling a secure key-establishing protocol between two parties employing the quantum nature of light [1], In theory, encoding the information for QKD onto pure single photon states is ultimately secured. In practice, it is limited by imperfections of the transmitter and the receiver, making security proofs a challenging task [2,3], thus reducing the maximal secure key rate (SKR) and the maximal losses in the communication channel over which SKR is achievable.
[0045] One of the main practical limitations of QKD systems is the lack of ideal single photons sources (SPSs), required to prevent eavesdropping attacks such as photon number splitting attack (PNS) [4], The SKR and maximal allowed channel loss (MCL) of simple QKD protocols decrease dramatically with the increase of two-or-more photon events being transmitted from the source [5], This leads to very stringent requirements on both the single photon purity and the photon emission rate of any practical single photon source (SPS) [6], Despite many years of exploration and engineering [2], a simple, stable SPS system that has the required aforementioned properties and can be employed in real-life QKD applications is still an outstanding challenge, which led researchers to suggest and utilize protocols employing attenuated lasers emitting weak coherent states (WCS) [6], As WCS has a Poissonian distribution of photons, and thus a two-or-more photons probability is never vanishing, advanced protocols such as decoy state protocols have been developed to enhance both SKR and MCL [7,8],
[0046] Decoy state protocols introduce variations in the distribution of the emitted photons to better characterize the channel and obtain a tighter bound on the SKR, allowing detection of PNS attacks [9], Yet, even with decoy state protocols, WCS are highly sensitive
[0010] to the high probability of the vacuum state, due to the dependence between the different photon number emission probabilities, which overall limits the possible SKR [4], The above solutions and inherent limitations of WCS for QKD set clear opportunities for improving the security and efficiency of QKD applications using realistic SPS systems [11-14], Yet, while efforts to develop a nearly ideal SPS are still ongoing by many groups [15-17], they still fall short as compared to the performance of QKD protocols based on WCS incorporating decoy states.
[0047] GENERAL DESCRIPTION
[0048] There is a need in the art for a novel approach in QKD based communication between transmitter and receiver devices, enabling simple-to-implement QKD protocols that allow the use of practical, far from ideal sub-Poissonian photon sources (SPPSs), to outperform state-of-the-art decoy state protocols using weak coherent states (WCS), without the hindering requirements on the single photon purity of the photon source.
[0049] The present disclosure provides a radically different from the state-of-the-art, more realistic approach. By utilizing new simple QKD protocols on compact, imperfect SPS sources, the technique of the present disclosure significantly enhances the QKD performance, in terms of the MCL, as compared to even ideal, infinite decoy state protocols using WCS.
[0050] The technique of the present disclosure utilizes controlling photon emission statistics of the SPPS, based on the ability to vary and control the probabilities of emitting the different Fock states, {Po, PltP2] over a wide range of values, by simply varying the optical excitation power. The first protocol implemented in the present disclosure is a simple and realistic decoy state protocol for such a source. The inventors have shown that with this new protocol, one can significantly exceed, by more than 3 dB, the MCL value of an ideal decoy state protocol using a WCS source. The second protocol uses an alternative approach based on heralded photon purification under saturated excitation. The inventors have shown that a similar performance enhancement can also be achieved. Also, the inventors have experimentally verified that the probability for N > 2 ( PN>2) is negligibly small, justifying the protocols’ assumptions. The third protocol is a passive decoy-state protocol based on passively modulating photon statistics through a selected T:R (transmission / reflection) ratio beam splitter introduced before the Hanbury -Brown Twiss (HBT) purification system of the setup of the second protocol. The configuration of the third protocol may be easily changed from being decoy -based to that of heralded photon purification by modifying the analysis of the recorded data after finishing the distribution of the secret key.
[0051] The inventors utilized a room temperature operating SPPS based on a giant colloidal nanocrystal quantum dot (gCQD) coupled to nanoantennas and resonators (a hybrid nanoantenna and plasmonic nanocone) providing directionality and emission rate enhancement [18-22], These SPPS devices displayed a highly enhanced rate of photon emission approaching the GHz range, together with near-unity collection efficiencies (> 90%) of the emitted photons. The photon emission from such gCQDs is based on the biexciton - exciton (BX-X) emission cascade under optical excitation
[0023] and has been shown to be well described by a truncated photon-number Fock space with N = 0,1, and 2 photons, with a negligible probability of N > 2 photons
[0024] ,
[0052] The inventors utilized quantum superposition-based protocols to encode quantum information on the emitted photons. More specifically, the inventors experimentally fully emulate a free-space BB84 QKD using a bare gCQD source without an antenna. The results agree well with the models and demonstrate the superiority of the protocols of the present disclosure over the best possible BB84 based on WCS performance even for such a simple imperfect SPS source. This shows that even existing SPPS, which are far from being ideal, can outperform the current state-of-the-art protocols based on WCS sources. According to one broad aspect of the present disclosure, it provides a method for use in quantum key distribution (QKD) between a transmitter device and a receiver device over a quantum channel, the method comprising: controlling photon emission statistics of a sub-Poissonian photon source (SPPS), configured to emit quantum states in a plurality of different Fock states |n=0,l,2> where n represents the photon number, and having controllable photon emission statistics in a truncated photon-number basis comprising zero-photon (Po), single-photon (Pi), and two- photon (P2) emission probabilities, said controlling of the photon emission statistics comprising performing at least one of the following: dynamically varying an optical excitation parameter to dynamically adjust relative emission probabilities Po, Pi, and P2 over a continuous range of probability values between 0 and 1, to thereby enable implementation of a decoy -based QKD protocol; and
[0053] - varying an optical excitation parameter to control at least the P2 emission probability, to thereby enable implementation of at least one of a passive decoybased QKD protocol and heralded purification QKD protocol.
[0054] THE FOLLOWING IS THE CLAIM LANGUAGE
[0055] The QKD based on the controllable photon emission statistics of SPPS provides a maximum channel loss (MCL) value exceeding by at least 3dB the MCL value of an ideal decoy state protocol using weak coherent state (WCS) source.
[0056] In some embodiments, the SPPS is based on biexciton-exciton emission cascade in room temperature and comprises giant colloidal quantum dots (gCQD) coupled to nanoantennas and resonators providing directionality and emission rate enhancement.
[0057] In some embodiments, the optical excitation parameter comprises a relative optical excitation power S of the SPPS defined as a ratio, S = I / Is, where I is an optical excitation power of the SPPS, and Is- a saturation power for which a count rate of detected photons emitted by the SPPS reaches 90% of a predefined maximum value.
[0058] For example, the dynamically varying of the optical excitation parameter to dynamically adjust relative values of the emission probabilities Po, Pi, and P2 comprises dynamically varying the optical excitation power I of the SPPS between corresponding relative optical excitation powers So, Si, and S2. The decoy -based protocol may comprise the following: for each clock cycle, defined by an optical excitation pulse repetition rate of the SPPS, performing the following: randomly selecting the relative optical excitation powers So, Si, S2 where the quantum state achieved using S2 is a signal state with a single photon probability Pi(S2), the quantum state achieved using Si is a first decoy state, and the quantum state achieved using So is a second decoy state corresponding to vacuum state; exciting the SPPS with said relative optical excitation powers So, Si, S2 being randomly selected to provide emitted photons; encoding quantum information on each of the emitted photons to produce encrypted photons propagating to the quantum channel, to be received at the receiver device, thereby enabling to obtain a raw key via measurements of received photons per clock cycle; and performing post-processing of the raw key via communication with the receiver device through a classical channel to obtain a final secure key.
[0059] The dynamically varying of the optical excitation parameter to dynamically adjust the relative probabilities Po, Pi, and P2 may comprise providing relatively high Pi and relatively I0W P2 satisfying a relationship: Pi > 1.125P2 + 0.1927.
[0060] In some embodiments, a relative gain, y, defined as a ratio between maximum channel loss, MCL, of said decoy-based protocol and maximum channel loss MCLwcs, of an ideal decoy state protocol using weak coherent state (WCS) source, satisfies a condition y = MCL / MCLwcs) > OdB.
[0061] The heralded purification protocol may comprise the following: selecting a relative optical excitation power S3 of the SPPS, corresponding to a saturation power maximizing emission probability P2; for each clock cycle, defined by an optical excitation pulse repetition rate of the SPPS, performing the following: exciting the SPPS by an optical excitation pulse with the relative optical excitation power S3 to provide a number of emitted photons; splitting the emitted photons into a number of first photons and a number of second photons with a predetermined splitting probability; encoding quantum information on the number of first photons to provide a number of encrypted first photons propagating to the quantum channel; applying heralding detection of the number of second photons and recording detection results; and applying sifting to the detection results by selectively performing one of the following and recording classification results: (i) upon identifying detection of a second photon, classifying said detection as successful detection; and (ii) upon identifying lack of detection of the second photon, discarding the optical excitation pulse; transmitting data indicative of the detection results classified as the successful detections to the receiver device via a classical communication channel, thereby informing the receiver device which pulses were heralded to enable retaining of only matching heralded detection events by the transmitter and receiver devices, and enable to obtain a raw key via measurements of received photons per clock cycle; and performing post-processing of the raw key via communication with the receiver device through a classical channel to obtain a final secure key.
[0062] The varying of the optical excitation parameter to independently control at least the P2 emission probability may comprise providing relatively high P2, regardless of Pi, satisfying a relationship: P2 > 0.37 / T]D, T]Dbeing efficiency of the heralding detection.
[0063] A relative gain, y, defined as a ratio between maximum channel loss, MCL, of said heralded purification protocol and maximum channel loss MCLwcs, of an ideal decoy state protocol using weak coherent state (WCS) source, may satisfy a condition y = (MCL / MCLwcs) > OdB.
[0064] In some embodiments, the passive decoy-based QKD protocol comprises the following: selecting a relative optical excitation power S3 of the SPPS, corresponding to a saturation power maximizing emission probability P2; for each clock cycle, defined by an optical excitation pulse repetition rate of the SPPS, performing the following: exciting the SPPS with the relative optical excitation power S3 being selected to provide emitted photons; splitting the emitted photons in at least a first splitting stage with a first predetermined ratio of split probabilities to produce a number of first split photons and a number of second split photons, encoding quantum information on said number of the first split photons to produce a corresponding number of encrypted first photons; applying heralding detection to a number of non-encoded photons resulting from said at least first splitting stage, said heralding detection being capable of identifying detection events corresponding to detection of 0, 1 or 2 photons, and generating herald detection results indicative of the detection events, and processing said herald detection results and classifying the detection events as signal states and decoy states according to predetermined detection criteria; transmitting data indicative of the detection results being classified to the receiver device via a classical communication channel, enabling to obtain a raw key via measurements of received photons per clock cycle; and performing post-processing of the raw key via communication with the receiver device through a classical channel to obtain a final secure key.
[0065] In some embodiments, the heralding detection comprises photon counting.
[0066] In some embodiments, the splitting of the emitted photons further comprises a second splitting stage comprising splitting with a second predetermined split probability the number of said second photons being the non-encrypted photons thereby providing a number of transmitted second photons and a number of reflected second photons, and said heralding detection comprises heralding detection applied to said number of transmitted second photons and heralding detection applied to said number of the reflected second photons.
[0067] The predetermined criteria may comprise: assigning the signal state with a single photon probability of Pi(S3)to the recorded detection results corresponding to the detections events of 0 photons; assigning a first decoy state to the recorded detection results corresponding to the detection event of 1 photon; and assigning a second decoy state to the recorded detection results corresponding to the detection events of 2 photons. In some embodiments of the passive decoy-based QKD protocol, the method further comprises processing of the recorded detection results comprising: utilizing the heralding detection result to implement the heralded purification protocol by selectively performing one of the following:
[0068] (i) upon identifying that said heralding detection result corresponds to detection of 1 or 2 of said non-encoded photons, classifying said detection result as successful detection; and (ii) upon identifying that said heralding detection result corresponds to detection of 0 of said non-encoded photons, discarding the corresponding heralding detection result; transmitting data indicative of the heralding detection results classified as successful detection to the receiver device via a classical communication channel, thereby informing the receiver device which pulses were heralded to enable retaining of only matching heralded detection events by the transmitter and receiver devices, and enable to obtain a raw key via measurements of received photons per clock cycle; and performing post-processing of the raw key via communication with the receiver device through a classical channel to obtain a final secure key.
[0069] In some embodiments, the encoding quantum information to produce the encrypted photons is performed using at least one quantum superposition-based protocol, e.g., BB84 protocol.
[0070] In the above-mentioned embodiments, the first predetermined splitting probability may be determined based on at least one of the two-photon emission probability (P2), and a probability of detecting a dark count, PDC.
[0071] In some of the above-mentioned embodiments, the second predetermined split probability may be determined based on at least one of the two-photon emission probability (P2), and a probability of detecting a dark count, PDC.
[0072] According to another broad aspect of the present disclosure, it provides a system for quantum key distribution (QKD) comprising: a transmitter device configured and operable to communicate with a remote receiver device via a quantum channel and a classical communication channel while implementing at least one predefined QKD protocol, the transmitter device comprising: a sub-Poissonian photon source (SPPS), configured to emit quantum states in a plurality of different Fock states |n=0,l,2> where n represents the photon number in response to optical excitations, and having controllable photon emission statistics in a truncated photon-number basis comprising zero-photon (Po), single-photon (Pi), and two-photon (P2) emission probabilities; and an excitation control unit configured to selectively control an optical excitation parameter of said optical excitations to provide generation of different photon-number distributions by said SPPS; and a control system configured and operable to control the photon emission statistics of the SPPS by carrying out at least one of the following: dynamically varying the optical excitation parameter to dynamically adjust relative emission probabilities Po, Pi, and P2 over a continuous range of probability values between 0 and 1, to thereby enable implementation of a decoy -based QKD protocol; and
[0073] - varying the optical excitation parameter to control at least the P2 emission probability, to thereby enable implementation of at least one of a passive decoybased QKD protocol and heralded purification QKD protocol.
[0074] The system may be configured to implement all the embodiments of the above method.
[0075] BRIEF DESCRIPTION OF THE DRAWINGS
[0076] In order to better understand the subject matter that is disclosed herein and to exemplify how it may be carried out in practice, embodiments will now be described, by way of non-limiting examples only, with reference to the accompanying drawings, in which:
[0077] Fig- 1 shows schematically a general art secure communication scheme for encryption of keys based on quantum mechanical principles;
[0078] Fig- 2 shows the principles of the novel approach of the present disclosure;
[0079] Figs. 3A and 3B exemplify the principles and implementation of the technique of the present disclosure, wherein Fig. 3A exemplifies, by way of a block diagram, a quantum key distribution (QKD) system of the present disclosure, and Fig. 3B is a flow diagram exemplifying a method of the present disclosure in a top-level manner;
[0080] Figs. 4A to 4D show several properties of single gCQDs, wherein Fig. 4A shows schematically the structure of the gCQD suitable to be used in the present disclosure; Fig. 4B shows lifetime measurement of a single gCQD on glass, with extracted values of TX= 49.3 ± 3.7[ ns] and TXX= 3.58 ± 0.16[ ns], for the X and BX emission respectively; Fig. 4C shows stability measurement of the photon emission from the gCQD, demonstrating highly stable and non-blinking emission; and Fig. 4D shows spectrum of the gCQD corresponding to the emission from both the X and BX states, centered around ~ 650 nm;
[0081] Fig. 5A shows schematically the BX-X cascade in an optically excited gCQD, using a non-resonant pulsed excitation with a normalized intensity inset is a sketch of a typical gCQD, consisting of a CdSe core and a CdS shell;
[0082] Fig. 5B shows normalized emission counts (blue open circles) as a function of the relative optical excitation power S, displaying a saturation behavior, the dashed black line is a fit to a model, the orange circles show the experimentally extracted for the different powers;
[0083] Fig. 5C shows photon emission probabilities Pi as a function of S. The dashed black lines mark the intensities chosen for the signal S2, and the two decoy states So, S , for the decoy state on a truncated basis (DTB) protocol, and the intensity S3, chosen for the heralded purification (HP) protocol;
[0084] Fig. 6A exemplifies an experimental setup and sketch of the decoy state on a truncated basis (DTB) protocol, where the transmitter (Alice) dynamically adjusts the excitation power on the SPPS (SPS1) between to control the emitted photon statistics for the 2-decoy protocol, followed by collection optics with efficiencyηcand a standard BB84 encoding unit;
[0085] Fig. 6B exemplifies, by way of a flow diagram, the method of implementing the decoy state on a truncated bases (DTB) protocol of Fig. 6A;
[0086] Fig. 7A exemplifies an experimental setup and sketch of the heralded purification (HP) protocol, where a single excitation power S3> 1, near the gCQD saturation, is used to excite the SPPS (SPS2) followed by collection optics with efficiency ηc, a beamsplitter (BS), a high efficiency single photon detector (SPD) with detection efficiency r / D, and a standard BB84 encoding unit;
[0087] Fig. 7B exemplifies, by way of a flow diagram, the method of implementing the heralded purification (HP) protocol of Fig. 7 A;
[0088] Figs. 8A and 8B show QKD analysis with imperfect single photon sources, wherein Fig. 8A shows the secure key rate (SKR) of the BB84 protocol as a function of channel loss for a perfect SPS (blue line), WCS with infinite decoy states and optimized intensities (WCS+Inf. Decoy, red), SPS1 with the decoy state on a truncated Fock basis protocol (SPS1+DTB, purple), SPS2 with the heralded purification protocol (SPS2+HP, black), and a typical gCQD (bare gCQD, green), with a visual representation of y, the relative gain; and Fig. 8B shows the relative gain of the MCL, y, as a function of PltP2showing two advantageous regimes for SPPS with either DTB or HP separated by black dashed lines with their respective conditions, the sources used in the present disclosure are also shown: a bare single gCQD experimentally measured for the DTB protocol (purple circle) and the HP scheme (black circle) at different intensities (hence different photon statistics), SPS1 in the purification regime (purple square), SPS2 in the decoy state regime (black square), and two, previously analyzed, non-classical sources [25, 26] marked with an orange square / dot;
[0089] Figs. 9A to 9F exemplify implementation of a passive DTB protocol, wherein Fig. 9A shows a first exemplary configuration of the transmitter device; Fig. 9B shows a second exemplary configuration of the transmitter device; Fig. 9C shows a flow diagram describing the passive DTB protocol; Fig. 9D shows the optimized beam splitter transmission of the transmitter’s beam splitter BS1, for the relative maximal channel loss y, per P and P2, the color bar is the T1values; Fig. 9E shows the SKR of the BB84 protocol as a function of channel loss for a perfect SPS (blue line), WCS with infinite decoy states and optimized intensities (WCS+Inf. Decoy, red), SPS1 with the decoy state on a truncated Fock basis protocol (DTB Active, black), passive DTB protocol with T=0.5 of beamsplitter BS1 (DTB Passive T=0.5, purple dashed), and passive DTB protocol with T=0.9 of beamsplitter BS1 (DTB Passive T=0.9, green dashed); and Fig. 9F shows a flow diagram describing a method allowing to choose the QKD protocol (passive DTB or heralded purification) after finishing transmission of the encoded key;
[0090] Fig. 10 illustrates an optical setup for correlation measurements and the BB84 QKD protocol demonstration, including a pulsed laser non-resonantly exciting the quantum dot-based device and the collection optics of the emitted photons from such a device into the channel;
[0091] Figs. 11A to 11C show experimental results for emulating the decoy -based (DTB) protocol, wherein Fig. 11A exemplifies controlling the photon emission counts by the excitation laser intensity ( 405 nm, 2 MHz rep. rate, 2 ns pulse duration), red regions mark So, green regions mark and purple regions mark S2appearing in Fig. 5C; Fig. 11B show for the two different intensities Fig. 11C shows calculation of y values as a function of gc, the blue box represents the gcrange demonstrated in the devices [39, 41], all with y > 2 dB;
[0092] Figs. 12A to 12D show experimental results for emulating the heralded purification (HP) protocol, wherein Figs. 12A and 12B show second-order correlation measurements of the bare gCQD SPPS without (Fig. 12A) and with (Fig. 12B) the HP post-processing scheme, resulting in near-zer , the error is mainly due to the SPD dark noise; Fig. 12C shows calculation of the optimal transmission T, of Alice's beamsplitter BS, required for maximizing y as a function of P2of the SPPS, for two values of detector dark count, PDC, corresponding to 100 dark counts per second of the SPD, and SPPS excitation repetition rates of 2 (blue) and 500 (red) MHz; and Fig. 12D shows calculation of y as a function of collector efficiency, gc, with a fixed r / D(blue line) and as a function of r / Dwith a fixed (red line), the blue box represents the range demonstrated in the devices of the present disclosure [39, 41]; and
[0093] Figs. 13A and 13B exemplify two experimental QKD systems for performing polarization-based BB84 QKD measurements of a bare gCQD sample generated using the protocols of the present disclosure, wherein the transmitter’s (Alice's) setup of Fig. 13A includes a purification unit with a beam-splitter (BS) and a single photon detector (SPD), and an encryption unit with a linear polarizer (LP) and half-wave plate ( / 2), the free-space quantum channel includes ND filters to vary the channel loss the receiver’s (Bob's) setup includes the BB84 decryption unit with a / 2, a polarizing beam- splitter (PBS) and two SPDs; and Fig. 13B includes two beam splitters BS1 and BS2 and two SPDs;
[0094] Figs. 14A to 14C show tomography mapping results for different excitation laser intensities: S1(Fig. 14A), S2(Fig. 14B), and S3(Fig. 14C), respectively, corresponding to the decoy (green frame) and signal (purple frame) states in the DTB protocol, and S > 1 intensity (blue frame) state in the HP protocol;
[0095] Figs. 14D to 14F show tomography mapping results for different excitation laser intensities, intensity corresponding to the decoy state (Fig. 14D) and the signal state S2(Fig. 14E) in the DTB protocol, measured with a 1.0 dB ND filter (left) and a 2.0 dB ND filter (right), the intensity used in the HP protocol S3(Fig. 14F), measured with a 1.0 dB ND filter; and
[0096] Fig. 15 shows the SKR results extracted from the measurements from a bare gCQD sample compared to WCS with infinite decoy, the different measured points along represent the extracted SKR results for several ND filter settings using the DTB protocol (purple), the dashed line represent the corresponding calculated SKR.
[0097] DETAILED DESCRIPTION OF EMBODIMENTS
[0098] Reference is made to Fig. 1 showing a general art secure communication scheme for encryption of keys based on quantum mechanical principles. Alice and Bob wish to establish a secret key at a distance via communication between a transmitter device 10 (Alice) and a receiver device 50 (Bob), which are connected by two channels: a quantum channel 40, allowing Alice and Bob to share quantum signals, and a classical channel 60, on which they can send classical messages forth and back. The classical channel 60 needs to be authenticated, i.e., Alice and Bob identify themselves, while a third person can listen to their conversation, but cannot participate in it. The quantum channel 40, however, is open to eavesdropping, i.e., any possible manipulation from a third person (Eve).
[0099] Quantum Key Distribution (QKD) sets as a goal to deliver a “secure key”. To this end, after the transmission of a sequence of symbols, Alice and Bob are to estimate how much information about the transmitted list of bits has leaked out to Eve. In a quantum channel, leakage of information is quantitatively related to a degradation of the communication. Thus, security of QKD relies on fundamental principles of quantum physics, among them the well-known principle stating that a measurement in general modifies the state of the measured system.
[0100] The QKD is nearly always implemented with light, and many known QKD systems rely on weak lasers instead of single photons. To enhance the security, additional decoy states are used, being fake pulses which can be compared to detect eavesdropping.
[0101] In short, Alice changes the nature of the quantum signal at random during the protocol; at the end of the exchange of quantum signals, she reveals which state she sent in each run. This way, Eve cannot adapt her attack to Alice’s state, but in the postprocessing Alice and Bob can estimate their parameters conditioned to that knowledge.
[0102] The use of decoy states improved performance for QKD efficiency and range. However, many disadvantages were found in using weak lasers. Among them is the fact that lasers are vulnerable to attacks, such as photon number splitting (PNS) attack, as well as their sensitivity to background noise and loss in the quantum channel.
[0103] Single photon sources (SPSs) have shown a potential to surpass weak lasers providing higher security (eliminating PNS attacks), higher reliability and higher efficiency. However, currently available photon sources lack the single photon purity, i.e., have non-zero probability of two-or-more photon events. This decreases dramatically the secure key rate (SKR) and the maximal channel loss (MCL). In fact, a true singlephoton source can never be made in practice. Practical devices can only produce states with a sub-Poissonian distributed photon count, in which vacuum and multiphoton components still exist.
[0104] Fig- 2 shows, in a self-explanatory manner, the novel approach of the present disclosure enabling implementation of QKD protocols while using far from ideal (imperfect) single photon sources, providing an ability to control the statistical distribution of the truncated photon-number basis comprising zero-photon (Po), singlephoton (Pi), and two-photon (P2) emission probabilities. The QKD protocols implemented using the technique of the present disclosure beat the state-of-the-art performance of weak coherent states (WCS) with decoy protocols and provide for achieving > 3 dB enhancement in terms of the secure key rate.
[0105] The inventors have shown that even room temperature, on-chip, compact, and easily integrated single photon devices, such as those based on a giant colloidal nanocrystal quantum dot (gCQD) coupled to nanoantennas, are already well within the parameter range for superior performance over WCS with decoy states by employing either a decoy-on-a-truncated-basis (DTB) protocol or a heralded purification (HP) protocol. Both types of protocols have very simple requirements, and their application is very general. These protocols can be employed efficiently on a vast range of sub-Poisson quantum emitters, providing photon sources with superior QKD performance.
[0106] Reference is made to Figs. 3A and 3B illustrating the principles and implementation of the technique of the present disclosure. Fig. 3A exemplifies, by way of a block diagram, a quantum key distribution (QKD) system 100 of the present disclosure involving communication between a transmitter device 10 and a remote receiver device 50 via a quantum channel 40 and a classical communication channel 60.
[0107] The transmitter device 10, as well as the receiver device 50, includes a computerized system which includes inter alia such software / hardware utilities as data input and output utilities and a memory and processing circuitry ,and the transmitter and receiver devices are properly equipped with communication utilities and are capable of implementing communication with one another via the authenticated classical channel 60
[0108] It should be noted that the QKD protocols of the present disclosure may be implemented using any known in the art quantum channel 40, classical channel 60, and receiver device 50. The configuration and operation of such elements are known per se and do not form part of the present disclosure and therefore need not be described in detail.
[0109] It should also be noted that the transmitter and receiver devices may actually be configured as transceiver devices, each transceiver device being capable of performing the transmitting and receiving sessions with respect to other transmitter / receivers.
[0110] The transmitter device 10 is configured and operable to perform quantum key distribution (QKD) with the receiver via the quantum channel 40 according to the technique of the present disclosure. To this end, the transmitter device 10 includes a sub- Poissonian photon source (SPPS) 12, an excitation control unit 14 associated with a processing circuitry 16, and a control system 20. The SPPS 12 is configured to emit quantum states in a plurality of different Fock states |n=0,l,2> where n represents the photon number in response to optical excitations. Additionally, the SPPS 12 provides controllable photon emission statistics in a truncated photon-number basis including zerophoton (Po), single-photon (Pi), and two-photon (P2) emission probabilities. The emission probabilities may be modified in response to variation of an optical excitation parameter.
[0111] The SPPS 12 may be any one of the following photon sources: a self-assembled quantum dot (SAQD), a defect in crystal, a colloidal quantum dot (CQD), nitrogen vacancy centers in diamond, silicon vacancy centers in diamond, a multiplexed parametric source, and any other sub-Poissonian quantum emitter with controllable photon statistics between Fock states of |n = 0,1, 2)s. In the present non-limiting example, the novel QKD protocols are exemplified using a SPPS based on biexcitonexciton emission cascade in room temperature and comprises giant colloidal quantum dots (gCQD) coupled to nanoantennas and resonators providing directionality and emission rate enhancement
[0112] The SPPS 12 may further include a collector unit 22 for collecting the photons being emitted by the SPPS and allowing their free space propagation.
[0113] It will be shown further below that unlike decoy state QKD protocols based on WCS, which require an infinite set of decoy states for an exact solution (of gain and error rates), a truncated sub-Poissonian source with measurable relative probabilities Po, Pi, and P2 only is sufficient to enable efficient quantum key distribution.
[0114] The excitation control unit 14 is configured to selectively control an optical excitation parameter of the optical excitations, to generate different photon-number distributions. The optical excitation parameter may be a relative optical excitation power S of the SPPS defined as a ratio, S = I / Is, where I is an optical excitation power of the SPPS, and Is- a saturation power for which a count rate of detected photons emitted by the SPPS reaches 90% of a predefined maximum value.
[0115] Thus, as shown in the flow diagram 100 of Fig. 3B, in order to the implement QKD protocols of the present disclosure the sub-Poissonian photon source (SPPS) is provided with controllable photon emission statistics in a truncated photon number basis including zero-photon (Po), single-photon (Pi), and two-photon (P2) emission probabilities and controlled corresponding relative optical excitation powers So, Si, and S2 (step 110). According to the present disclosure, the excitation control unit 14 is configured to perform at least one of two general modes of control. For the first general mode of control, the control system 20 is configured and operable to control the photon emission statistics of the SPPS to dynamically adjust the relative probabilities Po, Pi, and P2 over a continuous range of probability values between 0 and 1 (step 120), by dynamically varying an optical excitation parameter of the SPPS. For the second general mode of control, the control system 20 is configured and operable to control at least the P2 emission probability (step 130) by varying the optical excitation parameter, e.g., the relative optical excitation power S.
[0116] The first general mode of control, performed by the excitation control unit 14 and the control system 20, enables to implement a decoy-based QKD protocol (step 140), also termed in the present disclosure as “Decoy on a truncated basis protocol” (DTB). To implement this decoy-based QKD protocol, the processing circuitry 16 of the transmitter device 10 operates to randomly select between at least two different excitation levels to be applied by the excitation control unit 14 to the SPPS 12, thereby creating signal states and decoy states with different photon-number distributions. This protocol is also termed at times as (active) DTB since it requires a dynamic adjustment of the excitation levels in real time.
[0117] In some embodiments of implementing the DTB protocol, the excitation control unit 14 is operated by the control system 20 to dynamically vary the optical excitation parameter to provide relatively high probability Pi and relatively low probability P2 satisfying a relationship: Pi > 1.125P2 + 0.1927.
[0118] The second general mode of control, performed by the excitation control unit 14 and the control system 20, enables to selectively implement two types of QKD protocols: a heralded purification QKD protocol (step 150) or a passive decoy protocol, termed also as “passive DTB” (step 160). In this mode of control, a single specific relative optical excitation power S may be selected, designated as S3 in the description below, having a predetermined photon emission probability, as will be described below.
[0119] To implement the heralded purification protocol (150), the control system 20 (its processing circuitry 25) manages operation of the excitation control unit 14 to operate the SPPS at high excitation level (designated as relative optical excitation power S3 in the description below), corresponding to a saturation power maximizing P2 emission probability. As shown in Fig. 3A, the control system 20 further includes a purification system 26 configured and operable to perform heralding detection of the photons emitted by the SPPS being excited by the high excitation level. To this end, the purification system 26 includes a Hanbury-Brown Twiss (HBT) system 30 with its associated Single-Photon Detector (SPD) which serves as a herald detector. More specifically, as will be described further below, a beam splitter of the HBT is positioned with respect to the SPPS to split photons emitted by the SPPS with a predetermined T:R split ratio, and the herald detector is configured to detect photons from one output of the beam splitter.
[0120] In some embodiments, for implementing the heralding purification protocol, the excitation control unit 14 is configured and operable to vary the optical excitation parameter to provide relatively high probability P2, regardless of the probability Pi, satisfying a relationship being efficiency of the heralding detection.
[0121] To implement the passive decoy protocol (160) the control system 20 (its processing circuitry 25) manages operation of the excitation control unit 14 to operate the SPPS at a high excitation level (designated as relative optical excitation power S3 in the description below), corresponding to a saturation power maximizing P2 emission probability. The control system 20 may thus further include an auxiliary T :R beam splitter 24 configured with a predetermined T:R split ratio (transmission / reflection ratio) to split emitted photons before reaching the HBT system, thereby enabling to define signal and decoy states according to the number of clicks at the HBT detectors, as will be described further below.
[0122] As shown in Fig. 3A, transmitter device 10 also includes the quantum information encoding unit 28. The latter is configured to encode quantum information onto photons emitted by the SPPS. The receiver (Bob) 50 includes a quantum information decoding unit 52 to decode the quantum information of photons arriving from the quantum channel 40. In the present disclosure, the decoy-based and the heralded purification protocols are exemplified using the well-known BB84 protocol (being an example of quantum superposition-based protocols) for encoding the quantum information. However, other superposition-based types of protocols may be implemented, for example, SARG04 (introduced by Scarani, Acin, Ribordy, and Gisin in 2004) or MDI-QKD (Measurement- Device-Independent Quantum Key Distribution). Once a large number N of signals have been exchanged via the quantum channel and measured at the receiver side, Alice and Bob (i.e., transmitter and receiver devices) start processing their data based on communication via the classical channel. According to standard procedure, Alice and Bob estimate the statistics of their data, in particular, they extract the meaningful parameters of the quantum channel, e.g., error rate in decoding, transmission rate, detection rates, etc. The parameter estimation is preceded by a sifting phase, in which Alice and Bob agree to discard some symbols, typically because Bob learns that he has not applied the suitable decoding on those items. After sifting and parameter estimation, both Alice and Bob hold a list of n <N symbols representing raw keys. These raw keys are only partially correlated and only partially secret.
[0123] To extract a short secret key from the raw key, two steps of classical postprocessing are performed. The first step is error correction, at the end of which the lists of symbols of Alice and Bob have become shorter but perfectly correlated. The second step is privacy amplification. This procedure is aimed at destroying Eve’s knowledge on a reference raw key. The post-processing comprises transforming the raw key into a fully secure (secret) key K of length 1 <n . The length I of the final secret key K depends of course on information on the raw key eavesdropped by Eve.
[0124] It should be noted that the QKD protocols of the present disclosure may utilize any known technique of processing / post-processing of the measured data (i.e., sifting, parameter extraction, error correction, and privacy amplification) to extract the final secure key from the raw key, where the raw key has been created using the technique of the present disclosure. It should be noted that according to the technique of the present disclosure, the raw key creation process also includes classification criteria for interpretation of the detection results during the raw key creation. It should also be noted that the present disclosure is aimed at providing novel techniques to encode information into photon states of imperfect sub-Poissonian photon sources to implement various types of QKD protocols with enhanced secure key rate.
[0125] In the following, the optical control of photon statistics from the biexciton-exciton (BX-X) emission cascade in a gCQD is described.
[0126] Giant colloidal nanocrystal quantum dots (gCQD) of CdSe / CdS core-shell type were used as the quantum emitters to demonstrate the novel QKD protocols of the present disclosure. Fig. 4A illustrates schematically the structure of the gCQD used in the present disclosure. The gCQD core has a diameter of ~ 3 nm, while the shell has a diameter of ~ 15 nm. The emission wavelength of the gCQD is centered around 650 nm at room temperature. The properties of these quantum dots were investigated in many works [32-35,39], The gCQD is an example of SPPS based on biexciton-exciton emission cascade in room temperature and comprises giant colloidal quantum dots (gCQD) coupled to nanoantennas and resonators providing directionality and emission rate enhancement. The gCQD is accurately positioned at the tip of a metal nanocone centered inside a hybrid metal-dielectric bullseye antenna. The inventors have shown that the bullseye metal-dielectric antenna provides excellent collimation effect (i.e., directionality) and the monolithic photonic resonator constructed of a gold nanocone provides rate enhancement.
[0127] Figs. 4B to 4D show several properties of single gCQDs. The extracted lifetime of the gCQD from a bi-exponential fit due to the emission both from the BX and the X states in presented in Fig. 4B, demonstrating nanosecond radiative transitions on bare gCQDs. As investigated in [18,19,28,37,38], the plasmonic coupling of the gCQD to the metallic resonator shortens the photon lifetime to ~10-100 ps. The stability of the bare gCQD is shown in Fig. 4C, with a stable emission of a single gCQD on glass at room temperature, exhibiting a non-blinking emission for long times
[0033] , In Fig. 4D, the spectrum of the gCQD is plotted, with a broad emission (FWHM of ~ 25 nm) at room temperature. This demonstrates the spectral overlapping between the BX and X states at high temperatures.
[0128] The gCQDs were initially diluted in a Hexane and polymethyl methacrylate 495 A5 (PMMA) solution with sparse ratios among each material (1 :200:5000), to ensure the distribution of single gCQDs on the sample. To achieve this, the inventors used an iterative method where different ratios were tested, stirred with a shaker and then spin- coated on a glass slide using a two-step process ( 500 RPM for 5 seconds, 4000 RPM for 40 seconds).
[0129] The plasmonic device was fabricated using methods similar to those presented in [18,19,21], employing the template stripping method
[0036] to create an Au metallic device consisting of a bullseye concentric antenna with and without a nanocone resonator. The gCQDs were coupled to the nanoantennas using fabrication methods similar to those described in [18,21,37,38],
[0130] Fig. 5A presents a schematic sketch of the BX-X cascade in a gCQD following a nonresonant pulse excitation with power I. Modelling this process, a BX state \XX is excited by the absorption of two pump photons. This process happens with a probability:
[0131] The probability of excitation of only the X state, |X), by the absorption of only one pump photon, is given by:
[0132] Here a is a constant related to the absorption crosssection of the gCQD and it is assumed that any larger excitonic complexes are negligible
[0024] , as will be verified further in the description below.
[0133] In the following, the inventors present a model for the probabilities to excite one or two excitons depending on the excitation laser power. One can use this model to combine the emission distribution and the quantum yields (QYs) of the source.
[0134] Given that a single exciton was excited, the probability to emit two photons is zero, while the probability to emit one photon is given by the exciton quantum yield, QYX. Given that two excitons are excited (as in the biexciton state |XX)), the biexciton state \XX decays into a single exciton state |X) either radiatively, by emitting a single photon with a probability QYXX, representing the BX quantum yield, or non-radiatively with a probability 1 — QYXX. The probability to emit two photons is the probability that both the exciton and the biexciton recombined radiatively, suggesting that the probability is Therefore, the probability of a single photon emission is the probability that either the exciton or the biexciton recombined radiatively, giving The exciton state |X) can recombine radiatively (nonradiatively) with probabilities to the ground state such that the probability to emit zero, one or two photons, defined as espectively, is:
[0135] Since Pxx, Pxdepend on the excitation power, the probabilities to emit two, one or zero photons following excitation become excitation power dependent, allowing an external control over the emitted photon statistics as is required for decoy states protocols. Such a saturable behavior of the excitonic population allows one to define a relative
[0136] Fig. 5B demonstrates the experimental data of the photon statistics control by varying the excitation power from a single bare gCQD. As S increases, the collected photon emission intensity increases sublinearly and saturates at S > 1. A good fit of the theoretical model, based on the absorption probabilities given in Eqs. (1), (2) and on the subsequent emission probabilities QYX, QYXXis shown. A quantitative metric for the goodness of the fit, the normalized root mean square error (NRMSE), was generated by comparing the theoretical model for the probabilities with the saturable behavior of the source. In the case described in Fig. 5B, the fit gave a result of NRMSE < 0.012, showing a good correlation between the theoretical model and experimental results. This fit confirms the basic assumptions given above for the BX-X cascade process. By measuring both and the count-rate C(S), the probability distribution may be extracted precisely.
[0137] In the following, extraction of the probability distribution from a truncated Fock basis is described.
[0138] The second order correlation function is given by: The experimentally measured Poand are used to solve these equations for and P2, and to obtain the first two moments of the distribution. In the case considered herein, this contains all the required statistical information, thus allowing extraction of the whole probability distribution for the truncated Fock basis from just two measured quantities.
[0139] In the following, extraction of the probability measurements is described.
[0140] By introducing another detector to the system of the present disclosure, as explained further below for the heralded purification protocol, a similar set of equations can be used, as above (Eqs. (6)-(10)) with minor adjustments to estimate P3, the probability of an emission of three photons from the source. This allows estimating the probability of higher photon probabilities, to justify the assumptions regarding the photon statistics used in the present disclosure.
[0141] In this case, the third-order correlation function at zero delay can also be described by the relation between the distribution mean and variance. Here, (n) = P + 2P2+
[0142] Now, by using Eqs. (6), (5), (10a) another set of equations is obtained that relate where it is assumed PN>3= 0. Therefore, one can extract PltP2and P3from the measured which gives the first three moments of the distribution. In the case described herein, the third order correlation at zero delay was measured in the S > 1 regime, with the highest probability for higher multiexciton emission. The measured result of correlations between the three detectors was found to be: 0.00065 (14)
[0143] the probability is negligible. This finalizes the assumptions taken in the present disclosure, regarding the characterization of the photon statistics.
[0144] In Fig. 5C, the extracted photon emission probabilities are presented. As expected, the probability of emitting one or two photons increases with excitation power, but at a different rate, allowing optical control of the emitted photon statistics with only varying S.
[0145] After establishing the control of the different photon number probabilities, this capability can be utilized for providing various novel MCL-enhancing protocols, including decoy-state protocols and heralded purification protocols.
[0146] Fig. 6A shows the conceptual experimental setup of a decoy state (active DTB) protocol according to the principles of the present disclosure. The transmitter device 10 (Alice) includes an SPPS 12 with a near unity photon collection efficiency, gc— 1
[0021] (titled as SPS1 in the figure), used for implementing a BB84 protocol, but where Alice controls the excitation powers, This in turn modifies the photon number statistics, thus allowing for the implementation of decoy and signal states [6,7],
[0147] Fig. 6B exemplifies by way of a flow diagram 600 a decoy-based protocol, e.g., using the gCQD source described above. In general, such protocol may be implemented by providing a sub-Poissonian photon source (SPPS) with controllable photon emission statistics in a truncated photon number basis comprising zero-photon (Po), single-photon (Pi), and two-photon (P2) emission probabilities and dynamically controlled corresponding relative optical excitation powers So, Si, and S2 (step 602).
[0148] The protocol starts (step 604) when for each clock cycle, defined by an optical excitation pulse repetition rate of the SPPS, the transmitter performs the following: randomly selecting So, Si, S2 where the quantum state achieved using S2 is a signal state with a single photon probability Pi(S2), the quantum states achieved using Si and So, respectively, are a first and a second decoy states (step 606); exciting the SPPS with the optical excitation powers So, Si, S2 to provide emitted photons, encoding quantum information on each of the emitted photons using a selected protocol (e.g., BB84) to produce encrypted photons, and directing the encrypted photons into the quantum channel, to be received at the receiver device (Bob) (Step 608); measuring each received photon per clock cycle in the selected protocol and recording the outcomes, thereby obtaining a raw key (step 610). Here the loop of quantum key distribution ends and the post-processing stage starts. In this step 612, post-processing of the raw key is performed via communication with the receiver device through a classical channel to obtain a final secure key.
[0149] For example, in case BB84 protocol is used for encoding, in the sifting step, the transmitter (Alice) and the receiver (Bob) reveal their bases over a classical channel and retain only matching basis detection events. Alice informs Bob which detections are signal or decoy states. The gains and errors of the signal and decoy states are estimated as described in detail below.
[0150] To establish the (active) DTB protocol, the inventors define the gain of the signal (decoy;) state, as the fraction of encoded photon pulses sent by Alice and detected by Bob (Eq. (11)). Also, the error rate of the signal (decoy;), Es(Ed;), is defined as the fraction of detected encoded photons that had errors (Eq. (12)). The signal pulses correspond to pulses with excitation S2, while the decoy pulses are those excited with S1, S0. It is shown in the following that due to the truncated photon number basis of the SPPS used in the present disclosure, only two different decoy states are enough for exact analysis in the framework of the decoy state protocol [6],
[0151] Within the DTB protocol, Alice can randomly choose to replace the signal pulse with one of the two decoy states with different photon number distributions. These decoy states are not used to create the secure key but to improve the information about the channel and discover any possible eavesdroppers [7], In the post-processing stage, Alice and Bob can verify the fraction of detected events and the errors for both signal pulses and decoy pulses, thus obtaining the gain and error rates
[0152] On the other hand, due to the uncertainty of the photon-number in each pulse, the gain and error rate for a specific n-photon state, cannot be measured directly and have to be estimated or calculated. Out of this set, the single photon gain ( Q ) and error rate ( e ), which are the probability of a detected event (Bob) to originate from a single photon pulse (Alice) and the error rate for single photon pulses respectively are of particular importance. This is since, considering a possible PNS attack by Eve, only information encoded on the single photon pulses is secured.
[0153] It should be noted that, unlike the decoy state protocol implemented for WCS where n -> oo, which requires an infinite set of decoy states for an exact solution [6], here (in the present disclosure) n = 0,1,2 only, due to the truncated sub-Poissonian nature of the gCQD photon emission ( N > 2 photon emissions are neglected). Thus, the equations have only six unknowns suggesting that two decoy states are enough for an exact solution to these equations. This makes the DTB implementation particularly viable, whereas for WCS using two decoy states would only give a bounded approximation for the yield and errors [7],
[0154] The solution of these equations can then be used to estimate the minimum SKR after privacy amplification and error correction, defined as for the DTB protocol [6]: where q = 0.5 for the BB 84 protocol [1], H2is the binary Shannon information function [6] and f Es) is the error correction efficiency (taken to be 1.22 ). To do this, the inventors use the channel model connecting the losses, yields, gains and the error rates, shown in [6] and described in the following with the parameters values (from [19,21]) presented in Table 1. Specifically, the probability to reach the wrong detector is set to ed= 3.3% and Bob's detection efficiency is set to where edis the probability to reach the wrong detector. Using = Y1P1, where Y can be experimentally calculated by solving Eqs. ( 18)-(21 ), as explained further below. In the numerical performance, presented in Fig. 8A, the gain is estimated using Eq. (22), by measuring the dark count probability PDCin the system and setting the overall transmission rj. This gives all the required parameters for (Eq. (17)), which are valued and can be inserted to yield the bound of the SKR. To obtain the secure key rate per channel loss, the inventors iterate through different transmissions.
[0155] Fig. 8A shows the calculated SKR under different channel losses for a standard WCS with decoy states in the ideal, asymptotic case (infinite number of decoy states) with optimized intensities, given by Ref. [7], compared to an SPPS based on a gCQD coupled to a nanoantenna (SPS1)
[0021] using the above DTB protocol with the realistically obtainable probabilities of the signal state for such a device. The parameters used for this calculation are detailed further below. A clear improvement in the SKR and the MCL of the imperfect SPS used in the present disclosure, over WCS is seen, with over 3 dB MCL enhancement, and also an improvement over the best existing cryogenic state-of-the-art SPS [12-14] or comparable cryogenic, fiber-coupled results
[0027] , A comparison to a perfect single photon source ( P1= 1 ) is also shown in the figure. Surprisingly, applying the truncated decoy-state protocol of the disclosure yields performance not far worse than a perfect SPS, even though the SPS, operating under ambient conditions, is far from being ideal.
[0156] Fig. 7A, presents the experimental configuration of the heralded purification protocol (BB84+HP). In this scheme, an SPPS 12 consisting of a gCQD on a hybrid nanocone-antenna device is considered (titled here SPS2). Such a device showed both rjc— 1 together with high attainable values of P2, resulting from a large Purcell factor induced by the nanocone which significantly enhances QYXX[19,28].
[0157] Fig. 7B exemplifies by way of a flow diagram 700 a heralded purification protocol, e.g., using the gCQD source described above. As described above, the gCQD source provides a sub-Poissonian photon source (SPPS) with controllable photon emission statistics in a truncated photon number basis comprising zero-photon (Po), single-photon (Pi), and two-photon (P2) emission probabilities and controlled corresponding relative optical excitation powers So, Si, and S2 (step 602 of method 600). The transmitter 10 (Alice) is operated at a single excitation power S3> 1, deep in the saturation regime (step 702), to excite the BX state with a very high probability, thus maximizing P2, which is now only limited by QYXXand QYX
[0019] , The purification system 26 includes an HBT system 30. The HBT system 30 includes a beam-splitter (BS) and a single photon detector (SPD). The beam splitter BS is located in the emission line of the SPPS and before the standard BB84 encoding unit 28. As PN>2are negligible, as was shown above, a real photon detection event in Alice's detector sets P2= 0 for that pulse, where Pnis the effective photon number probability after the purification stage.
[0158] The beam splitter BS is configured with a predetermined T:R ratio which may be calculated and optimized by adjusting the T and R values depending on the emission probability P2 of the source, as will be explained further below with reference to Fig. 12C. It should also be noted that the SPD reports (heralds) a single detection event (clicks) for any number of photons, i.e., a single click is obtained for a detection of either one, two or more photons, as long as the photons arrive during a predetermined detection time window of the SPD. Further below, the use of a photon counting detector (PCD), able to provide a count number of the detected photons, in other protocols of the present disclosure, is described. Such photon counting detector (PCD) may be used for the heralded purification protocol described in Fig. 7A but is not required.
[0159] For each clock cycle, defined by an optical excitation pulse repetition rate of the SPPS, the transmitter performs the following (step 704): exciting the SPPS 12 with the relative excitation power S3 to provide a number of emitted photons; splitting the emitted photons into a number of first photons and a number of second photons with a predetermined splitting probability (step 706); encoding quantum information on the number of first photons to provide a number of encrypted first photons propagating to the quantum channel (step 708); applying heralding detection of the number of second photons, and recording detection results (step 710). Here the loop of quantum key distribution ends and the post-processing stage starts: applying sifting to the detection results by selectively performing one of the following and recording classification results (step 712): (i) upon identifying detection of a second photon, classifying said detection as successful (step 714); and (ii) upon identifying lack of detection of the second photon, discarding the optical excitation pulse, even if receiver device received photons (step 716). The transmitter transmits data indicative of the detection results classified as successful to the receiver device via a classical communication channel (step 718). As described above, in the sifting step of the QKD protocol, only events with same-pulse detections by the transmitter (Alice) and the receiver (Bob) are considered for the secure key, thus eliminating all multiphoton events at a cost of lower signal rates. In other words, informing the receiver device which pulses were heralded enables retaining of only matching heralded detection events by the transmitter and receiver devices, and enable to obtain a raw key via measurements of received photons per clock cycle. In the last step (720), post-processing of the raw key is performed via communication with the receiver device through a classical channel to obtain a final secure key, as described below.
[0160] Given an SPSS having {Po, PltP2}, the effective distribution sent to Bob with the HP protocol depends on the reflectance and transmission ( R and T ) of the BS and the detection efficiency of Alice's detector , as well as the probability of a dark count at Alice's detector (PDC) :
[0161] Given this new distribution, the well-established method is again followed to estimate the SKR of a BB84 protocol (but now implemented with HP) [6,29], Here, the estimated SKR after privacy amplification and error correction, defined as R2for the HP protocol, is given by [3]: where is the relative error of the quantum channel, and are defined similarly to the DTB protocol.
[0162] The black line in Fig. 8A shows a realistic calculation of the SKR using actual parameters of SPS2 measured in Ref.
[0019] (presented in Table 1). A BS reflectance of 50% was chosen, and the inventors specifically use PDC= 2 • 10-7corresponding to 100 dark counts per second for a 500 MHz signal rate which are both commonly attainable with current technology. Again, as is seen in the figure, the new BB84 + HP allows for a higher MCL ( ~ 1 dB ) compared to WCS with infinite decoy, due to the extremely low P2. Remarkably, this SKR enhancement can be achieved with SPS far from being ideal having a very low single photon purity.
[0163] Next, the expected performance of realistic SPPS-based BB84-QKD is analyzed using the above protocols of the present disclosure, in comparison to that of WCS with ideal decoy protocols. In particular, the expected performance of the existing roomtemperature high brightness, high collection efficiency SPPS [19,21] is compared. The relative gain in the MCL is defined as y = MCL / MCLwcs), and this parameter is used to evaluate the relative performance gain.
[0164] Fig. 8B shows a colormap of the calculated y for different values of P2of the SPPS. For high P and sufficiently low P2, namely for P > 1.125P2+ 0.1927, there is a region (marked as "DTB superiority region") where y > 0 dB, indicating that the use of an SPPS with BB84 + DTB protocol is advantageous over WCS with BB84 including infinite decoy states (marked as "WCS+Decoy"). In this region, orange dots are highlighting two known non-classical sources [25,26] along with the device (SPS1) consisting of a gCQD coupled to a metal-dielectric Bragg nanoantenna
[0021] (purple), demonstrating that already existing sources, when combined with the DTB protocol, can outperform even ideal WCS protocols. Notably, the use of DTB allows for an SPPS with higher probabilities of two-photon events and shows that bright devices (with fewer vacuum events) can be used for QKD even with single photon purities as low as ~ 65% and 5,(-2-)(0) values as high as ~ 0.6.
[0165] On the other hand, for an SPPS with high enough values of P2, there is a region where BB84 + HP is advantageous over WCS+Decoy, as shown in the right corner of Fig. 8B (marked as "HP superiority region"), where again y > 0 dB. In the implementation of the HP protocol, most one-photon events are discarded, and the key is composed largely of two-photon emission events, as indicated in Eq. (24), where the first term is dominant since PDC« PltP2. Therefore, the HP method is most advantageous in the regime where P2is large, regardless of P1. The negligible probability of two-photon events after purification (< 10-7) and minor contributions of the second and third terms in Eq. (24) result in an effectively pure source, differing from a perfect SPS only in brightness (through the zero-photon probability).
[0166] As indicated by the first term of Eq. (24), the probability of sending one photon is linearly dependent on r / D, suggesting that the minimum value of P2required for y > 0 dB is inversely proportional to Alice's detection efficiency. Calculations yield this relation, giving the condition for a balanced 50: 50BS. The values of y and the separation line between the WCS and HP in Fig. 8B are evaluated for the realistic case r / D= 0.9, yielding an expected enhancement over WCS when P2> 0.41. The black dot in Fig. 8B represents an actual SPPS device consisting of a gCQD coupled to a Bragg antenna with a plasmonic nanocone (SPS2), demonstrated in Ref.
[0019] , again showing that existing imperfect SPS+HP can compete with WCS+Decoy.
[0167] The experimental results are presented for a bare gCQD sample (shown in Fig. 8A in purple and black circles with corresponding error bars), where the photon probabilities were experimentally obtained as explained above, and the SKR was extracted separately for each protocol with Eqs. (17), (26), respectively. The gCQD, excited at several intensities, exhibits different photon emission statistics for each intensity, thus allowing to demonstrate both the DTB and HP protocols. As seen, even bare gCQDs emitting at room temperature, without any special antennas, can reach a superior regime over WCS+Decoy.
[0168] In the following, another protocol is described being implemented using passive decoy states on sub-Poissonian sources (passive DTB) of the present disclosure. The passive DTB can be simply demonstrated on imperfect yet realistic sub-Poissonian photon sources (SPPSs), also outperforming WCS with ideal decoy states.
[0169] This passive DTB approach offers similar security performance as the (active) DTB protocol described above, yet it is less prone to side-channel attacks and is simpler to implement - without requiring a modulation of the optical excitation power (e.g., laser intensity).
[0170] In addition, as will be described below, the passive DTB and the HP protocols can both be implemented with the same optical system, with the decision about which protocol to use being made during the sifting step between the transmitter (Alice) and the receiver (Bob). The optimized parameters for the passive DTB and HP protocols are slightly different, therefore, according to the used SPPS, the decision which protocol to choose may vary according to different requirements. This flexibility advantageously provides a generalized QKD system with optimized performance, covering a wide range of sources and distributions.
[0171] Reference is made to Figs. 9A to 9F describing the passive DTB protocol. Figs. 9A and 9B show two exemplary configurations of the transmitter device 10 and Fig. 9C shows a flow diagram 900 describing the general logic of the passive DTB protocol. In the following, the general logic of the passive DTB protocol, irrespective of the particular hardware implementation, is described.
[0172] The passive DTB protocol utilizes the same SPPS described is step 602 of method 600. The relative optical excitation power S3 is selected similar to step 702 of method 700. For each clock cycle, defined by an optical excitation pulse repetition rate of the SPPS, the following is performed (step 902): exciting the SPPS with the relative excitation power S3 to provide emitted photons and splitting the emitted photons, with a predetermined ratio (R:T) of split probabilities, to produce a number of first photons and a number of second photons (step 904); encoding quantum information on the number of first photons to produce a corresponding number of encrypted first photons propagating to the quantum channel (step 906); applying heralding detection to the number of nonencoded photons, being capable of identifying detection events corresponding to detection of 0, 1 or 2 photons, and generating herald detection results indicative of the detection events (step 908). Here the loop of quantum key distribution ends and the postprocessing stage starts: applying post-processing to the herald detection results and classifying the detection events as signal states and decoy states according to the following criteria (step 910): (i) assigning the signal state with a single photon probability of Pi(S3)to the recorded detection results corresponding to the detections events of 0 photons; (ii) assigning a first decoy state to the recorded detection results corresponding to the detection event of 1 photon; (iii) assigning a first decoy state to the recorded detection results corresponding to the detection event of 2 photons; during the sifting stage (step 912), transmitting data indicative of the detection results being classified to the receiver device via a classical communication channel, enabling to obtain a raw key via measurements of received photons per clock cycle; performing post-processing of the raw key via communication with the receiver device through a classical channel to obtain a final secure key (step 912).
[0173] Thus, the classification of the detection events as signal states and decoy states is performed according to predetermined criteria which depend on the number of detection events (clicks) at the detectors. In the configuration of Fig. 9A, the purification system 26 includes two beam splitters, BS1 and BS2, successively interacting with photons emitted by the SPPS, and two single-photon detectors (SPDs) at respective two outputs of the second beam splitter BS2. The first beam splitter, BS1, is configured to split the emitted photons, with a predetermined ratio of split probabilities, into a number of first photons and a number of second photons. The first photons are propagated towards the quantum information encoding unit 28 to be encoded with quantum information and propagate to the quantum channel 40. The non-encoded (second) photons are allowed to interact with a HBT system 30 including the second beam-splitter (BS2) and the two single photon detectors (SPDs) to perform heralding detection being capable of identifying detection events corresponding to detection of 0,1 ,or 2 photons. Specifically, the second beam splitter BS2 is configured to perform a second splitting stage including splitting with a second predetermined split probability the number of the second photons being the non-encoded photons, thereby providing a number of transmitted second photons and a number of reflected second photons. A heralding detection is applied to the number of transmitted second photons and the number of the reflected second photons. During sifting, detection events corresponding to detection of 0,1 ,or 2 photons are classified as signal and decoy states according to the criteria described in step 910 above.
[0174] The passive DTB protocol may be implemented also by using the configuration shown in Fig. 9B. In this configuration, instead of the HBT system of Fig. 9A, a photon count detector (PCD) 32 is used to perform heralding detection. Contrary to SPD, the PCD directly provides the information about the number of photons detected ( i.e., zero, one, two). During sifting, detection events corresponding to detection of 0, 1 ,or 2 photons are classified as signal or decoy states according to the criteria described in step 910 above.
[0175] In the following, the estimation of the probabilities of the signal and decoy states, for the passive decoy protocol, is described. The different states are classified according to the following equations, using the notation: probability of i photons in the channel assuming j clicks in Alice.
[0176] The following assumptions and notations are used: - photon distribution of emission; TltRt- Alice's Heralding beam splitter (BS1 in Fig. 9A), T2, R2- Alice's HBT beam splitter (BS2 in Fig. 9A), PDC— probability of dark counts, r / D— detector efficiency. There are total 9 probabilities of outcomes for each i, j in P£7where i, j = 0,1,2 according to the Fock states. The sum of all the probabilities equals 1 as required from normalization:
[0177] The estimations were performed for T2= R2= 0.5 for Alice's HBT beam splitter.
[0178] The probabilities describing detection events where zero photons were detected at the transmitter (Alice got 'O' clicks) are given by:
[0179] The probabilities describing detection events where 1 photon was detected at the transmitter (Alice got T clicks) are given by:
[0180] The probabilities describing detection events where 2 photons were detected at the transmitter (Alice got '2' clicks) are given by:
[0181] It is noted that the solution of the decoy state protocol equations for the passive and the active DTB protocols are the same. They are used to extract the gains and errors, which in turn are inserted into the secure key rate equation to find the secure key rate (see Eqs. (16), (17)).
[0182] It is further noted that in the passive DTB protocol, the T:R ratio of the first beamsplitter BS1 may be calculated and optimized for given values of relative emission probabilities Po, Pi, and P2 of a particular SPPS. The calculation and optimization may take into account other physical parameters of the system as well, e.g., collection efficiency of the SPPS source, dark currents of the SPDs, detection efficiencies of the SPDs (at the receiver and the transmitter), known losses of the quantum channel, etc. maximal channel loss y. Fig. 9D shows the optimized beam splitter transmission T of the transmitter’s beam splitter BS1, where for the relative maximal channel loss y, per and P2. The color bar is the values.
[0183] Fig. 9E presents the security performance of the active decoy -based protocol (DTB) presented in Figs. 6A and 6B as compared to the performance of the passive decoy -based protocol presented in Figs. 9A-9C. Here, the inventors used Eq. (17) to simulate the secure key rate generation, but with different parameters corresponding to the two protocols. The DTB passive plot with T=0.5 (dashed purple) corresponds to a transmission of 50% of BS1 presented in Figs. 9A and 9B, while the plot with T=0.9 (dashed green) corresponds to a transmission of 90%. The photon statistics were calculated using the equations given above.
[0184] As mentioned above, the configuration of the passive DTB protocol may be easily changed from being decoy -based to that of heralded photon purification by modifying the analysis of the recorded data after finishing the distribution of the secret key. Fig. 9F illustrates a flow diagram 1000 describing the method of the passive DTB up to step 908 (refer to Fig. 9C). At the sifting stage (step 1002), the detection results are sifted by selectively performing one of the following and recording classification results: (i) upon identifying that the heralding detection results correspond to detection of 1 or 2 photons, classifying the detection result as successful detection; and (ii) upon identifying that the heralding detection results correspond to detection of 0 photons, discarding the corresponding heralding result. Following the sifting, the raw key is obtained as described in step 718 of the heralding purification protocol, and the post-processing is performed as in step 914 of method 900.
[0185] After theoretically showing that existing SPPSs, combined with the new protocols of the present disclosure, can outperform WCS in terms of MCL, the inventors demonstrate in the following experimental proof-of-concept emulations of both types of protocols (DTB and HPP) using the bare single gCQD presented in Fig. 5C as the imperfect SPS emulator.
[0186] To experimentally demonstrate the feasibility of the DTB scheme, the inventors use three different pulsed excitation intensities generated by a 405 nm diode laser, marked as So= 0, S15and S2in Fig. 5C The optical setup for correlation measurements and the BB84 QKD protocol demonstration is illustrated in Fig. 10. A pulsed diode laser operating at a wavelength in the range of 405-632 nm generates non-resonant pulses at repetition rates that can be modulated between 2-100 MHz . The excitation laser properties were chosen to allow for a full relaxation of the biexciton and exciton states through the radiative transition channels
[0039] , using non-resonant phonon-assisted excitation for a radiative relaxation of the quantum dot-based source, thus eliminating unwanted non-radiative effects.
[0187] In the (active) DTB scheme, the excitation power was tuned between three different intensities, one which is zero, to obtain information on the photon statistics for each pump. The two other intensities correspond to an average power of ~ 0.01 mW and S2~ 0.05 mW, but can be chosen according to the user’s requirements.
[0188] In the HP scheme, the excitation power was set to a high intensity as described above, corresponding to an average power of S3~ 0.15 mW, which may correspond to an excitation power in the saturated regime of the quantum dot.
[0189] In the (passive) DTB scheme, the excitation power was set to a similar intensity of S3~0.15 mW to correspond to an excitation power in the saturated regime of the quantum dot.
[0190] The excitation laser was focused on the gCQD sample with a 0.9 NA objective (Olympus MPLFLNIOOxBD) and was scanned using Galil and Zaber electrical stages. The emission from the gCQD devices was collected using the same objective and spectrally filtered from the excitation laser using a 567 nm long-pass dichroic mirror.
[0191] Photoluminescence (PL) measurements were performed using a Hamamatsu CMOS camera to identify single gCQDs and the SPPS devices. A white light source was introduced to the optical setup alongside the excitation laser path, to scan the device area and located PL from active emitters.
[0192] To ensure the emission originated from gCQD based devices, the emission was directed to a spectrometer (Princeton SpectraPro 2500) connected to a CCD camera (PIXIS 256BR), verifying that the emission is centered around the gCQD emission energy [18,19],
[0193] For time-resolved single photon correlation measurements, the emission was directed to a Hanbury-Brown Twiss (HBT) module, consisting of a beam-splitter (BS) and a set of single photon detectors (Excelitas SPCM-AQRH-14-FC), referred to as Bob's detectors, which were coupled to the system using multimode fibers. The signal from each detector was routed to different channels in the time tagging instrument (Swabian TimeTagger 20). The time tagger provided output of all arrival times and channel labels of photons within the set of exposure times, commonly referred to as global times.
[0194] Another channel in the time tagger recorded the excitation pulse times, commonly referred to as local times, which served as a trigger channel for the detectors. The histogram of local times is required for lifetime extraction
[0019] ,
[0195] Specifically in the HP scheme, a second BS was introduced to the system and coupled to a third single photon detector (referred as Alice's detector). During a postprocessing step, data was retained only when both Alice's detector and either of Bob's detectors registered a photon appearance in the same pulse. This was determined using the local times issued for each channel in the time tagger recorded data. The dark count rate of the single photon detectors, as provided by the manufacturer and verified experimentally, is approximately 100 counts per second.
[0196] Specifically for the (passive) DTB scheme, a second BS and another HBT system was introduced in the system to couple into two additional single photon detectors (referred as Alice’s detectors). During a post-processing step, data was retained according to the different photon probabilities, corresponding to two decoy states and the signal state. This was determined using the local times issued for each channel in the time tagger recorded data. The dark count rate of the single photon detectors, as provided by the manufacturer and verified experimentally, is approximately 100 counts per second.
[0197] Table 1 presents realistic parameter values for the analysis presented in Figs. 8A and 8B and Fig. 15, done for the DTB protocol using a gCQD-based nanoantenna device
[0021] (SPS 1), the HP protocol using a gCQD-based nanocone and nanoantenna device
[0019] (SPS2), and an experimental demonstration of both protocols using a bare gCQD. P1, P2denote the one- and two-photon probabilities respectively.
[0198] Table 1
[0199] As described above (see Fig. 8A), the gCQD SPPS with a near unity collection efficiency can outperform WCS with decoy states, if implemented with the DTB protocol. In Fig. 11C, the expected y of a gCQD SPPS device is numerically calculated in terms of rjc. Remarkably, with the current measured parameters, y > 0 dB already for gc> 0.3, which is easily attainable even for bare gCQDs, as is shown later. The previously demonstrated gCQD based SPPS devices
[0021] has r / c> 0.7 (marked by a blue rectangle) leading to an expected already constituting a significant improvement over WCS+Decoy.
[0200] To examine the dependence of the probability distributions on the collection and detection efficiencies and on the beam-splitter (BS) as shown above, the inventors included some modifications to the emission distributions.
[0201] Here, the modification is not added to the channel loss, as this loss is fully defined inside Alice's setup and is inaccessible to Bob and Eve. The consideration of the BS's parameters and of in the HP scheme is shown in Eq. (24) above.
[0202] With the new emission distributions and the model for the channel described above, the calculated parameters can be inserted to the SKR equations for either the regular BB84 protocol (for HP) or the decoy state protocol (for DTB), given in [6], to obtain the behavior for different channel losses. This yields the corresponding MCL as shown above.
[0203] Moving to emulation of the HP protocol, Figs. 12A to 12D show experimental results of the purification of the gCQD emission using a 50:50 BS. The second-order correlation measurements of the gCQD without (Fig. 12A) and with (Fig. 12B) the HP post-processing protocol are presented. As can be seen, a near-zero limited only by detector noise is achieved, competing with state-of-the-art demonstrations [12,17], It is noted that with HP , the photon rate decreases but the collection efficiency gcis not affected.
[0204] Using the results in Figs. 12A (including the full photon statistics without doing the post-processing scheme) and 12B (including only the photon statistics where both Alice and Bob got a click with the post-processing scheme), one can extract the third- order correlation measurements to determine P3, the probability for a three-photon emission (see above Eqs. (10a) - (14). Using this method, it is found that therefore it is concluded that is negligible compared to P1and P2, justifying the initial assumptions.
[0205] It should be noted that the HP efficiency can be optimized by adjusting T, R of Alice's BS, depending on the P2of the source. Fig. 12C shows a calculation of the optimal BS transmission T to reach the highest MCL, as a function of P2, for two dark-counts probabilities PDC. For low PDCthe optimal transmittance is roughly 0.5. However, for higher values of PDC, the optimal T is smaller than 0.5 and decreases with increasing two- photon probability, in order to minimize the probability for a dark count at Alices' detector simultaneously with two-photons transmission to Bob. Lastly, in Fig. 12D the calculated y for a gCQD-based SPPS with the above parameters is plotted, as a function of r / D, for a fixed r / c= 0.9, and as a function of gcfor a fixed r / D= 0.9. Again, the blue box, representing demonstrated values of SPPS devices based on gCQD coupled to nanoantennas, shows an improvement over WCS+Decoy.
[0206] In the following, the use of BB84 protocol is demonstrated using a bare gCQD as the imperfect SPS and utilizing either DTB or HP protocols.
[0207] Figs. 13A and 13B, show two QKD systems that were used to demonstrate a polarization-based BB84 protocol. The photons emitted from the gCQD sample are collected to Alice's encryption unit, which randomly defines both the qubit value and basis [1], The encryption unit includes a linear polarizer (LP) and half-wave plate ( / 2). The photons are then propagated through the quantum channel in free-space, where ND filters are introduced in the optical path to simulate channel loss, before arriving at Bob's decryption unit. Here, the two mutually unbiased bases are defined as ' + ' (|H), |IQ) and ' X ' ( \D), |i4) ). The receiver’s (Bob's) setup includes the BB84 decryption unit with a a polarizing beam-splitter (PBS) and two SPDs.
[0208] The transmitter of Fig. 13A includes a purification unit with a beam-splitter (BS) and a single photon detector (SPD) and is suitable to be used for implementation of a heralded purification protocol (see Fig. 7A). Fig. 13B is suitable to be used for implementation of the passive DTB protocol (see Fig. 9A), or the heralded purification protocol, as described in Fig. 9F. The transmitter of Fig. 13B includes two beam splitters, BS1 with a predetermined T:R ratio, and BS2 with 50:50 ratio. The two SPDs of the “Passive Unit” of Fig. 13B perform the heralding detection classified according to the method described above with reference to Fig. 9A.
[0209] By manipulating the different basis settings of both Alice and Bob, the full tomography mapping can be measured. The BB84 experimental demonstration was done by measuring the full Hilbert space of polarization-based encryption, given a qubit value in a specific basis sent by Alice and a given basis measured by Bob. Figs. 14A-14C, show the tomography results, obtained using the system of Fig. 13A, for three different excitation intensities: S1,S2, and S3without an ND filter in the quantum channel. Figs. 14D - 14F show the respective tomography results with an ND filter placed in the quantum channel. The ND filters are used to demonstrate the channel losses.
[0210] From these results, the gain and error rates for intensity i are extracted using the following relations:
[0211] The total number of detected qubits is the measured counts at both of Bob's detectors at a given basis, and the total number of error qubits is the number of counts measured on the wrong detector (assuming Alice and Bob randomly chose the same basis, according to the BB 84 protocol). The total number of qubits sent by Alice is estimated by the following:
[0212] In Fig. 15, the SKR of the gCQD measured with the DTB protocol is plotted for several channel losses set with various ND filters, compared to WCS with infinite decoy states. A clear improvement of ~ 2 dB is demonstrated with the DTB protocol, which agree well with the theoretical curve.
[0213] Thus, the present disclosure provides the system and methods for use in QKD between a transmitter device and a receiver device over a quantum channel. Various embodiments and examples of this technique are described above. However, it should be understood that the technique of the present disclosure is not limited to any of the specific examples and should be interpreted as defined by the claims.
Claims
CLAIMS:
1. A method for use in quantum key distribution (QKD) between a transmitter device and a receiver device over a quantum channel, the method comprising: controlling photon emission statistics of a sub-Poissonian photon source (SPPS), configured to emit quantum states in a plurality of different Fock states |n=0,l,2> where n represents the photon number, and having controllable photon emission statistics in a truncated photon-number basis comprising zero-photon (Po), single-photon (Pi), and two- photon (P2) emission probabilities, said controlling of the photon emission statistics comprising performing at least one of the following: dynamically varying an optical excitation parameter to dynamically adjust relative emission probabilities Po, Pi, and P2 over a continuous range of probability values between 0 and 1, to thereby enable implementation of a decoy -based QKD protocol; and- varying an optical excitation parameter to control at least the P2 emission probability, to thereby enable implementation of at least one of a passive decoybased QKD protocol and heralded purification QKD protocol.
2. The method of claim 1, wherein the QKD based on the controllable photon emission statistics of SPPS provides a maximum channel loss (MCL) value exceeding by at least 3dB the MCL value of an ideal decoy state protocol using weak coherent state (WCS) source.
3. The method of claim 1 or 2, wherein said SPPS is based on biexciton-exciton emission cascade in room temperature and comprises giant colloidal quantum dots (gCQD) coupled to nanoantennas and resonators providing directionality and emission rate enhancement.
4. The method of any one of the preceding claims, wherein said optical excitation parameter comprises a relative optical excitation power S of the SPPS defined as a ratio, S = I / Is, where I is an optical excitation power of the SPPS, and Is- a saturation power for which a count rate of detected photons emitted by the SPPS reaches 90% of a predefined maximum value.
5. The method of claim 4, wherein said dynamically varying of the optical excitation parameter to dynamically adjust relative values of the emission probabilities Po, Pi, andP2 comprises dynamically varying the optical excitation power I of the SPPS between corresponding relative optical excitation powers So, Si, and S2.
6. The method of claim 5, wherein said decoy-based protocol comprises: for each clock cycle, defined by an optical excitation pulse repetition rate of the SPPS, performing the following: randomly selecting the relative optical excitation powers So, Si, S2 where the quantum state achieved using S2 is a signal state with a single photon probability Pi(S2), the quantum state achieved using Si is a first decoy state, and the quantum state achieved using So is a second decoy state corresponding to vacuum state; exciting the SPPS with said relative optical excitation powers So, Si, S2 being randomly selected to provide emitted photons; encoding quantum information on each of the emitted photons to produce encrypted photons propagating to the quantum channel, to be received at the receiver device, thereby enabling to obtain a raw key via measurements of received photons per clock cycle; and performing post-processing of the raw key via communication with the receiver device through a classical channel to obtain a final secure key.
7. The method of claim 6, wherein said dynamically varying of the optical excitation parameter to dynamically adjust the relative probabilities Po, Pi, and P2 comprises providing relatively high Pi and relatively low P2 satisfying a relationship: Pi > 1.125P2 + 0.1927.
8. The method of any one of claims 1 to 7, wherein a relative gain, y, defined as a ratio between maximum channel loss, MCL, of said decoy -based protocol and maximum channel loss MCLwcs, of an ideal decoy state protocol using weak coherent state (WCS) source, satisfies a condition y = MCL / MCLwcs) > OdB.
9. The method of claim 4, wherein said heralded purification protocol comprises: selecting a relative optical excitation power S3 of the SPPS, corresponding to a saturation power maximizing emission probability P2; for each clock cycle, defined by an optical excitation pulse repetition rate of the SPPS, performing the following:exciting the SPPS by an optical excitation pulse with the relative optical excitation power S3 to provide a number of emitted photons; splitting the emitted photons into a number of first photons and a number of second photons with a predetermined splitting probability; encoding quantum information on the number of first photons to provide a number of encrypted first photons propagating to the quantum channel; applying heralding detection of the number of second photons and recording detection results; and applying sifting to the detection results by selectively performing one of the following and recording classification results: (i) upon identifying detection of a second photon, classifying said detection as successful detection; and (ii) upon identifying lack of detection of the second photon, discarding the optical excitation pulse; transmitting data indicative of the detection results classified as the successful detections to the receiver device via a classical communication channel, thereby informing the receiver device which pulses were heralded to enable retaining of only matching heralded detection events by the transmitter and receiver devices, and enable to obtain a raw key via measurements of received photons per clock cycle; and performing post-processing of the raw key via communication with the receiver device through a classical channel to obtain a final secure key.
10. The method of claim 9, wherein said varying of the optical excitation parameter to independently control at least the P2 emission probability comprises providing relatively high P2, regardless of Pi, satisfying a relationship: P2 > 0.37 / i]D, r / Dbeing efficiency of the heralding detection.
11. The method according to claim 10, wherein a relative gain, y, defined as a ratio between maximum channel loss, MCL, of said heralded purification protocol and maximum channel loss MCLwcs, of an ideal decoy state protocol using weak coherent state (WCS) source, satisfies a condition y = (J CL / MCLWCS) > OdB.
12. The method of claim 4, wherein said passive decoy-based QKD protocol comprises: selecting a relative optical excitation power S3 of the SPPS, corresponding to a saturation power maximizing emission probability P2;for each clock cycle, defined by an optical excitation pulse repetition rate of the SPPS, performing the following: exciting the SPPS with the relative optical excitation power S3 being selected to provide emitted photons; splitting the emitted photons in at least a first splitting stage with a first predetermined ratio of split probabilities to produce a number of first split photons and a number of second split photons, encoding quantum information on said number of the first split photons to produce a corresponding number of encrypted first photons; applying heralding detection to a number of non-encoded photons resulting from said at least first splitting stage, said heralding detection being capable of identifying detection events corresponding to detection of 0, 1 or 2 photons, and generating herald detection results indicative of the detection events, and processing said herald detection results and classifying the detection events as signal states and decoy states according to predetermined detection criteria; transmitting data indicative of the detection results being classified to the receiver device via a classical communication channel, enabling to obtain a raw key via measurements of received photons per clock cycle; and performing post-processing of the raw key via communication with the receiver device through a classical channel to obtain a final secure key.
13. The method of claim 12, wherein said heralding detection comprises photon counting.
14. The method of claim 12, wherein: said splitting of the emitted photons further comprises a second splitting stage comprising splitting with a second predetermined split probability the number of said second photons being the non-encrypted photons thereby providing a number of transmitted second photons and a number of reflected second photons, and said heralding detection comprises heralding detection applied to said number of transmitted second photons and heralding detection applied to said number of the reflected second photons.
15. The method of any one of claims 12 to 14, wherein said predetermined criteria comprises: assigning the signal state with a single photon probability of Pi(S3)to the recorded detection results corresponding to the detections events of 0 photons; assigning a first decoy state to the recorded detection results corresponding to the detection event of 1 photon; and assigning a second decoy state to the recorded detection results corresponding to the detection events of 2 photons.
16. The method of any one of claims 12 to 15, further comprising processing of the recorded detection results comprising: utilizing the heralding detection result to implement the heralded purification protocol by selectively performing one of the following:(i) upon identifying that said heralding detection result corresponds to detection of 1 or 2 of said non-encoded photons, classifying said detection result as successful detection; and (ii) upon identifying that said heralding detection result corresponds to detection of 0 of said non-encoded photons, discarding the corresponding heralding detection result; transmitting data indicative of the heralding detection results classified as successful detection to the receiver device via a classical communication channel, thereby informing the receiver device which pulses were heralded to enable retaining of only matching heralded detection events by the transmitter and receiver devices, and enable to obtain a raw key via measurements of received photons per clock cycle; and performing post-processing of the raw key via communication with the receiver device through a classical channel to obtain a final secure key.
17. The method of any one of claims 6 to 16, wherein said encoding quantum information to produce the encrypted photons is performed using at least one quantum superposition-based protocol.
18. The method of claim 17, wherein said encoding quantum information to produce the encrypted photons is performed using BB84 protocol.
19. The method of any one of claims 9 to 18, wherein said first predetermined splitting probability is determined based on at least one of the two-photon emission probability (P2), and a probability of detecting a dark count, PDC.
20. The method of any one of claims 14 to 18, wherein said second predetermined split probability is determined based on at least one of the two-photon emission probability (P2), and a probability of detecting a dark count, PDC.
21. A system for quantum key distribution (QKD) comprising: a transmitter device configured and operable to communicate with a remote receiver device via a quantum channel and a classical communication channel while implementing at least one predefined QKD protocol, the transmitter device comprising: a sub-Poissonian photon source (SPPS), configured to emit quantum states in a plurality of different Fock states |n=0,l,2> where n represents the photon number in response to optical excitations, and having controllable photon emission statistics in a truncated photon-number basis comprising zero-photon (Po), single-photon (Pi), and two-photon (P2) emission probabilities; and an excitation control unit configured to selectively control an optical excitation parameter of said optical excitations to provide generation of different photon-number distributions by said SPPS; and a control system configured and operable to control the photon emission statistics of the SPPS by carrying out at least one of the following: dynamically varying the optical excitation parameter to dynamically adjust relative emission probabilities Po, Pi, and P2 over a continuous range of probability values between 0 and 1, to thereby enable implementation of a decoy -based QKD protocol; and- varying the optical excitation parameter to control at least the P2 emission probability, to thereby enable implementation of at least one of a passive decoybased QKD protocol and heralded purification QKD protocol.
22. The system of claim 21, wherein said SPPS is based on biexciton-exciton emission cascade in room temperature and comprises giant colloidal quantum dots (gCQD) coupled to nanoantennas and resonators providing directionality and emission rate enhancement.
23. The system of any one of claims 21 or 22, wherein said optical excitation parameter comprises a relative optical excitation power S of the SPPS defined as a ratio, S = I / Is, where I is an optical excitation power of the SPPS, and Is- a saturation power for which a count rate of detected photons emitted by the SPPS reaches 90% of a predefined maximum value.
24. The system of any one of claims 21 to 23, further comprising a collector unit for collecting the photons being emitted by the SPPS and allowing their free space propagation.
25. The system of any one of claims 21 to 24, wherein the transmitter device further comprises a quantum information encoding unit configured to encode quantum information onto the photons being emitted by the SPPS.
26. The system of claim 25, wherein the transmitter device comprises an excitation control unit controllably operable by the control system to dynamically vary an optical excitation power / of the SPPS between relative optical excitation powers So, Si, and S2 thereby providing dynamic variation of the optical excitation parameter to dynamically adjust relative values of the emission probabilities Po, Pi, and P2.
27. The system of claim 26, configured and operable to enable implementation of the decoy-based protocol, wherein: the transmitter device comprises a processing circuitry configured and operable to randomly select the relative optical excitation powers So, Si, S2, where the quantum state achieved using S2 is a signal state with a single photon probability Pi(S2), the quantum state achieved using Si is a first decoy state, and the quantum state achieved using So is a second decoy state corresponding to vacuum state, the control system is configured to carry out the following: operate said excitation control unit to excite the SPPS with said relative optical excitation powers So, Si, S2 to provide emitted photons; operate the quantum information encoding unit to encode the quantum information on each of the emitted photons to produce encrypted photons propagating to the quantum channel, to be received at the receiver device, thereby enabling to obtain a raw key via measurements of received photons per clock cycle; andperforming post-processing of the raw key via communication with the receiver device through a classical channel to obtain a final secure key.
28. The system of claim 27, wherein the excitation control unit is configured and operable to dynamically vary the optical excitation parameter to provide relatively high probability Pi and relatively low probability P2 satisfying a relationship: Pi > 1.125P2 + 0.1927.
29. The system of any one of claims 21 to 28, wherein the transmitter device further comprises at least a first beam splitter at an output of the SPPS performing at least a first splitting stage, and comprises at least one single-photon detector (SPD).
30. The system of claim 29, configured and operable to enable implementation of the heralded purification protocol, wherein: the transmitter device comprises a processing circuitry configured and operable to select a relative optical excitation power S3 of the SPPS corresponding to a saturation power maximizing emission probability P2; the control system comprises a processing and memory circuitry configured and operable to carry out the following: operate said excitation control unit to excite the SPPS by an optical excitation pulse with the relative optical excitation power S3 to provide a number of emitted photons propagating towards the first beam splitter thereby causing the first stage splitting of the emitted photons into a number of first photons and a number of second photons with a predetermined splitting probability; encoding quantum information on the number of first photons to provide a number of encrypted first photons propagating to the quantum channel; and applying heralding detection of the number of second photons by the SPD and recording detection results; sifting the detection results by selectively performing one of the following:(i) upon identifying detection of the second photon, classifying said detection as successful detection; and(ii) upon identifying lack of detection of the second photon, discarding a corresponding optical excitation pulse; and transmitting data indicative of the detection results classified as the successful detections to the receiver device via the classical communicationchannel, thereby informing the receiver device which pulses were heralded to enable retaining of only matching heralded detection events by the transmitter and receiver devices, and enable to obtain a raw key via measurements of received photons per clock cycle; and performing post-processing of the raw key via communication with the receiver device through the classical communication channel to obtain a final secure key.
31. The system of claim 30, wherein said excitation control unit is configured and operable to vary the optical excitation parameter to provide relatively high probability P2, regardless of the probability Pi, satisfying a relationship: P2 > 0.37 / i]D, r / Dbeing efficiency of the heralding detection.
32. The system of claim 29, configured and operable to enable implementation of said passive decoy-based QKD protocol, wherein comprising: the transmitter device comprises a processing circuitry configured and operable to select a relative optical excitation power S3 of the SPPS, corresponding to a saturation power maximizing emission probability P2; the control system comprises a processing and memory circuitry configured and operable to carry out the following: operate said excitation control unit to excite the SPPS with the relative optical excitation power S3 being selected to provide emitted photons propagating towards the first beam splitter thereby causing a first stage splitting of the emitted photons with a first predetermined ratio of split probabilities to produce a number of first photons and a number of second photons, operate the quantum information encoding unit to encode quantum information on said number of the first photons to produce a corresponding number of encrypted first photons; apply heralding detection to a number of non-encoded photons resulting from said first splitting stage, said heralding detection being capable of identifying detection events corresponding to detection of 0, 1 or 2 photons, and generating herald detection results indicative of the detection events, and processing said herald detection results and classifying the detection events as signal states and decoy states according to predetermined detection criteria;transmitting data indicative of the detection results being classified to the receiver device via a classical communication channel, enabling to obtain a raw key via measurements of received photons per clock cycle; and performing post-processing of the raw key via communication with the receiver device through a classical channel to obtain a final secure key.
33. The system of claim 32, wherein said heralding detection comprises photon counting.
34. The system of claim 29, configured and operable to enable implementation of the passive decoy-based QKD protocol, wherein: the transmitter device further comprises a second beam splitter, arranged such that said first and second beam splitters successively interact with photons emitted by the SPPS, and comprises two single-photon detectors (SPD) at respective two outputs of the second beam splitter; the transmitter device comprises a processing circuitry configured and operable to select a relative optical excitation power S of the SPPS, corresponding to a saturation power maximizing emission probability P2; the control system comprises a processing and memory circuitry configured and operable to carry out the following: operate said excitation control unit to excite the SPPS with the relative optical excitation power S3 being selected to provide a number of emitted photons propagating towards the first beam splitter thereby causing first stage splitting of the emitted photons with a first predetermined ratio of split probabilities into a number of first photons and a number of second photons; and operate the quantum information encoding unit to encode the quantum information on the number of first photons to produce a corresponding number of encrypted first photons propagating to the quantum channel; splitting, by the second beam splitter, the number of second photons with a second predetermined split probability into a number of reflected second photons and a number of transmitted second photons; applying heralding detections by the two SPDs to said number of transmitted second photons and said number of the reflected second photons, respectively, and recording detection results indicative of detection events;classifying the detection events as signal states and decoy states according to predetermined criteria; transmitting data indicative of the detection results being classified to the receiver device via the classical communication channel, enabling to obtain a raw key via measurements of received photons per clock cycle; and perform post-processing of the raw key via communication with the receiver device through the classical communication channel to obtain a final secure key.
35. The system of any one of claims 31 to 34, wherein said predetermined criteria comprises: assigning the signal state with a single photon probability of Pi(S3)to the recorded detection results corresponding to the detections events of 0 photons; assigning a first decoy state to the recorded detection results corresponding to the detection event of 1 photon; and assigning a second decoy state to the recorded detection results corresponding to the detection events of 2 photons.
36. The system of any one of claims 30 to 35, wherein said first predetermined splitting probability is determined based on at least one of the two-photon emission probability (P2), and a probability of detecting a dark count, PDC.
37. The system of any one of claims 32 to 36, wherein said second predetermined split probability is determined based on at least one of the two-photon emission probability (P2), and a probability of detecting a dark count, PDC.
38. The system of any one of claims 21 to 37, wherein said quantum information encoder is configured and operable to produce the encrypted photons using at least one quantum superposition-based protocol.
39. The system of claim 38, wherein said at least one quantum superposition-based protocol comprises BB84 protocol.