Secure key extraction method and device for quantum key distribution using time bin

The method addresses vulnerabilities in QKD by detecting and managing satellite time bins in QKD protocols, enhancing security through a quantum key distribution device with optical elements and interferometers, ensuring secure key generation.

WO2026048009A1PCT designated stage Publication Date: 2026-03-05NT T INC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/031311
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-30
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

Existing quantum key distribution (QKD) protocols using time bins are vulnerable to eavesdropping methods that exploit satellite time bins, compromising key security when using passive delay interferometers.

Method used

A method and apparatus for detecting and processing satellite time bins by using a quantum key distribution device that includes a light source, optical elements, photon detectors, and delay interferometers to decode quantum information based on detection times, ensuring secure key generation by discarding or managing satellite time bins.

Benefits of technology

Enables secure key extraction in QKD by effectively managing satellite time bins, preventing information leakage, and ensuring secure communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024031311_05032026_PF_FP_ABST
    Figure JP2024031311_05032026_PF_FP_ABST
Patent Text Reader

Abstract

Provided is a quantum key distribution device for performing secure key extraction in quantum key distribution using a time bin and a delay interferometer. Specifically, the present invention provides a quantum key distribution device that uses time and a phase difference as quantum information, and transmits the quantum information from a transmitting unit to a first receiving unit, the quantum key distribution device comprising the transmitting unit, which includes a light source, and the first receiving unit, wherein: the first receiving unit comprises an optical element that branches an optical pulse of a time bin from the transmitting unit, a delay interferometer that interferes with the optical pulse of the time bin, a plurality of photon detectors that detect the optical pulse, and a plurality of photon time measuring instruments that are respectively connected to the plurality of photon detectors and are configured to measure the detection time of the optical pulse of the time bin; and the quantum key distribution device decodes the quantum information using the detection time of the optical pulse of the time bin detected by the first receiving unit and the optical pulse output from the delay interferometer.
Need to check novelty before this filing date? Find Prior Art

Description

Secure key extraction method and apparatus for quantum key distribution using time bins

[0001] The present disclosure relates to secure key extraction techniques and apparatus for performing quantum key distribution.

[0002] Research and development of quantum cryptography or quantum key distribution (QKD) is underway as a system for securely supplying keys for symmetric key cryptographic communication between two distant parties. In QKD, a quantum state in which key information is encoded is transmitted and received, and a key is generated by performing post-processing such as key distillation, error correction, or privacy amplification on the transmission and reception results. The security of the generated key is guaranteed by the quantum mechanical property that quantum states undergo state changes when observed or manipulated. Due to this property, if eavesdropping occurs, the reception state will differ from normal, and eavesdropping can be detected. In other words, if transmission and reception are normal, it is guaranteed that eavesdropping has not occurred and that the communication is secure.

[0003] To achieve highly confidential and secure communications, several QKD protocols have been proposed in which both the transmitter and receiver share a key that is difficult for others to eavesdrop on. The first proposed QKD protocol was the BB84 protocol (Non-Patent Document 1), and demonstration experiments have been conducted implementing BB84 using two optical time bins as quantum states (Non-Patent Documents 2, 3, and 4). In addition, BB84 generates a quantum state based on information selected by the transmitter and transmits it to the receiver. However, protocols such as BBM92 (Non-Patent Document 5) and QCKA (Non-Patent Document 6) transmit quantum entangled states from the transmitter to multiple receivers.

[0004] As shown in Figure 1, in QKD using time bins, the phase difference between two time bins is measured using an interferometer 3. However, from a practical perspective, it is desirable to use a passive delay interferometer for the interferometer 3, which does not require active control. However, when using this passive delay interferometer, two time bins are divided into three (1a, 1b, 1c), and only the second of the three, time bin 1b, for which the timing is measured, is used for security evaluation as a result of interference. On the other hand, there are specific eavesdropping methods that utilize these, such as the first time bin 1a and the third time bin 1c, called satellite time bins, where an eavesdropper can control the detection of satellite time bins by inserting light outside the two time bins before interference. However, if the processing method is incorrect, key sharing may become insecure.

[0005] C. H. Bennett et al. “Quantum cryptography: Public key distribution and coin tossing”. In Proceedings of IEEE International Conference on Computers, Systems and Signal Processing, volume 175, page 8 (1984)Davide Scalcon et al. “Cross-Encoded Quantum Key Distribution Exploiting Time-Bin and Polarization States with Qubit-Based Synchronization” Advanced Quantum Technologies, 5, 12 (2022)Hua-Lei Yin et al. “Experimental composable security decoy-state quantum key distribution using time-phase encoding”, Optics Express Vol. 28, Issue 20, pp. 29479 (2020)Yan-Lin Tang et al. “Time-bin phase-encoding quantum key distribution using Sagnac-based optics and compatible electronics”, Optics Express Vol. 31, Issue 16, pp. 26335 (2023)C. H. Bennett, et al. “Quantum cryptography without Bell's theorem” Physical Review Letters. 68, 5, 557-559 (1992)Glaucia Murta et al. “Quantum Conference Key Agreement: A Review” Advanced Quantum Technologies, Vol.3, Issue11 (2020)

[0006] The present disclosure has been made in consideration of the above-mentioned problems, and its purpose is to provide a processing method and apparatus for detecting satellite time bins, thereby enabling secure key generation.

[0007] According to an embodiment for achieving this object, there is provided a quantum key distribution device that uses time and a phase difference as quantum information and transmits the quantum information from a transmitter to a first receiver, wherein the transmitter comprises a light source configured to transmit the quantum information as optical pulses of time bins to the first receiver, and the first receiver comprises an optical element configured to branch the optical pulses of the time bins from the transmitter, a delay interferometer configured to cause the optical pulses of the time bins branched by the optical element to interfere with each other, and a recorder configured to record the detection time of an optical pulse outside a predetermined time, and the quantum information is decoded using the detection time of the optical pulses of the time bins detected by the first receiver and the optical pulses output from the delay interferometer.

[0008] Furthermore, according to an embodiment of a method for distributing a private key, there is provided a quantum key distribution method using time and a phase difference as quantum information and decoding the quantum information using a detection time and a delay state, the quantum key distribution method including the steps of: generating optical pulses of time bins carrying quantum information from a transmitting unit and transmitting the optical pulses to a first receiving unit; determining whether detection has occurred in the first receiving unit at a predetermined timing; if detection has occurred at the predetermined timing, determining whether only interference between optical pulses of the time bins has occurred; if interference has occurred, generating a key based on the position of the detected photon detector; determining whether detection has occurred only in paths that do not use an interferometer; and if detection has occurred only in paths that do not use an interferometer, generating a key based on the detection time of the optical pulses of the time bins that have been detected.

[0009] According to the present disclosure, secure private key extraction becomes possible in quantum key distribution using time bins and a delay interferometer.

[0010] FIG. 1 is a diagram showing definitions according to the prior art and embodiments of the present disclosure. FIG. 2 is a block diagram according to the first embodiment. FIG. 3 is a flow diagram according to the first embodiment. FIG. 4 is a diagram showing definitions according to the second embodiment. FIG. 5 is a flow diagram according to the second embodiment. FIG. 6 is a block diagram according to the third embodiment. FIG. 7 is a block diagram according to the fourth embodiment. FIG. 8 is a block diagram according to the fifth embodiment. FIG. 9 is a block diagram according to the sixth embodiment.

[0011] 1 and 2, a configuration of a quantum key distribution device 200 according to a first embodiment of the present disclosure will be described. Then, a method for generating a key using the quantum key distribution device 200 according to the first embodiment will be described.

[0012] The quantum key distribution device 200 of the first embodiment includes a transmitter 10 (conventionally called "Alice"), a receiver 20a (conventionally called "Bob"), and a quantum communication unit 30. The transmitter 10 and the receiver 20a can exchange signals via the quantum communication unit 30 (transmission line), and can exchange quantum information such as quantum states.

[0013] 2, the transmitting unit 10 and the receiving unit 20a can further exchange classical signals via a classical communication unit 40 provided between the classical communication unit 6 of the transmitting unit and the classical communication unit 7 of the receiving unit. Classical signals may also be exchanged via a quantum communication unit 30. Furthermore, the quantum communication unit 30 and the classical communication unit 40 may be physically separated from each other.

[0014] The transmitter 10 includes a light source 1 configured to select the Z basis or the X basis, select a bit 0 or 1, and generate a weak optical pulse in response to the selection.

[0015] The transmitting unit 10 generates only the forward time bin 1E (hereinafter referred to as the "forward optical pulse") when the base is Z and 0, and generates only the backward time bin 1L (hereinafter referred to as the "backward optical pulse") when the base is Z and 1. When the base is X and 0, optical pulses are generated in both the forward 1E and the backward 1L, and the phase difference between the optical pulses is modulated to 0. When the base is X and 1, optical pulses are generated in both the forward 1E and the backward 1L, and the phase difference between the optical pulses is modulated to π. Using the above method, the transmitting unit 10 can transmit optical pulses having basis (Z base and X base) and bit (0 and 1) information as time bins to the receiving unit 20a.

[0016] The weak optical pulse from the transmitter 10 is transmitted via a quantum communication unit 30 provided between the transmitter 10 and the receiver 20a. The quantum communication unit 30 may be, for example, an optical fiber or free space including outer space.

[0017] The receiving unit 20a includes a first optical element 2a (e.g., a beam splitter or a coupler) configured to split an optical pulse sent from the transmitting unit 10, a first photon detector 4a configured to measure one of the optical pulses split by the first optical element 2a, a first photon time measuring device 5a connected to the first photon detector 4a and measuring the detection timing of the photon, a delay interferometer 3 configured to receive the other optical pulse of the optical pulses split by the first optical element 2a and interfere with the forward optical pulse 1E and the backward optical pulse 1L, a second photon detector 4b and a third photon detector 4c configured to detect photons from the two outputs of the delay interferometer 3, and a second photon time measuring device 5b and a third photon time measuring device 5c configured to measure the timing at which the photon is detected by each photon detector.

[0018] The first optical element 2a branches the optical pulse sent from the transmitter 10 into two paths: a first path (i) and a second path (ii). In the first path (i), the timing at which the optical pulse enters is measured using a photon detector 4a and a photon time counter 5a, and a 0 / 1 in the Z basis is extracted depending on whether the optical pulse is measured at the timing of forward 1E or backward 1L. Furthermore, if photons are detected at both the timings of forward 1E and backward 1L, a 0 / 1 is randomly assigned and used as the key for the Z basis. Note that the photon detector 4a does not need to be able to resolve the number of photons; it is sufficient for it to be a device that detects whether or not a photon has entered.

[0019] The second path (ii) is provided with a delay interferometer 3 configured to have a time difference corresponding to the time interval between the forward 1E and backward 1L optical pulses, and receives the other optical pulse of the optical pulses branched by the first optical element 2a. The delay interferometer 3 may be a passive interferometer that does not require control for each event, such as a Mach-Zehnder interferometer or an interferometer using a Faraday mirror. The delay interferometer 3 outputs two optical pulses, which can be detected by a second photon detector 4b and a third photon detector 4c.

[0020] 1, in one event, the forward 1E and backward 1L optical pulses input to the receiver 20a can be stochastically branched into three optical pulses (1a, 1b, 1c) by the delay interferometer 3. For example, if the forward 1E optical pulse is output via a relatively short path 3S, the first time bin 1a can be output, and if it is output via a relatively long path 3L, the second time bin 1b can be output. Similarly, if the backward 1L optical pulse is output via a relatively short path 3S, the second time bin 1b can be output, and if it is output via a relatively long path 3L, the third time bin 1c can be output.

[0021] When the case of X basis and 0 (i.e., when there are optical pulses both forward 1E and backward 1L and the phase difference is 0) is output at the second timing, the photon is detected by the third photon detector 4c. Also, when the case of X basis and 1 (i.e., when there are optical pulses both forward 1E and backward 1L and the phase difference is π) is output at the second timing, the photon can be detected by the second photon detector 4b.

[0022] If only a satellite time bin is detected, the event is discarded and not used for key generation. Also, if a satellite time bin is detected and the second time bin 1b is also detected, the event is discarded and not used for key generation. If no satellite time bin is detected but a detection occurs at the second timing, 0 / 1 in the X basis is extracted depending on which photon detector detected the detection. Furthermore, if a photon is detected by both photon detectors, 0 / 1 is randomly assigned and used as the key for the X basis.

[0023] A method for generating and distributing keys using the quantum key distribution device 200 will be described in detail below with reference to the flow chart of FIG.

[0024] When the process of distributing a private key begins (step 301), authentication is first performed between the transmitter 10 and the receiver 20a (step 303). The transmitter 10 generates optical pulses carrying basis (Z-basis and X-basis) and bit (0 and 1) information based on a predetermined rule and transmits them to the receiver 20a (step 305). The receiver 20a uses multiple photon detectors 4a, 4b, and 4c and multiple photon time counters 5a, 5b, and 5c provided in the receiver 20a to determine whether detection has occurred at the receiver 20a at the expected timing (i.e., the timing at which the optical pulse transmitted by the transmitter 10 and the optical pulse detected by the receiver 20a are synchronized) (step 307). Here, the expected timing is set to a time that takes into account the fixed time it takes for the optical pulse to propagate from the transmitter 10 to the receiver 20a. If the optical pulse is not received at the expected timing, the process returns to step 305 and the optical pulse carrying the information is transmitted again to the receiving section 20a.

[0025] If it is determined that the optical pulse was received at the expected timing, the quantum key distribution device 200 generates a key from the detection results of the multiple photon detectors. The quantum key distribution device 200 determines whether a photon was detected in the second pass (ii) and the first pass (i) (steps 309 and 313). Unless detection occurred only at timing 1b in the second pass (ii) or only in the first pass (i), the process returns to step 305, and the optical pulse carrying the information is retransmitted to the receiver 20a.

[0026] In step 309, when detection occurs only at the second timing 1b of the second pass (ii), whether the detection occurred at the second photon detector 4b or the third photon detector 4c is set as 0 / 1 and used as the key for X. When detection occurs at both photon detectors, 0 / 1 is randomly assigned and used as the key for X (step 311).

[0027] Next, in step 313, if detection occurs only in the first pass (i), whether the forward 1E or backward 1L optical pulse is detected is set as 0 / 1 and used as the Z-based key, and if both the forward 1E and backward 1L optical pulses are detected, 0 / 1 is randomly assigned and used as the Z-based key (step 315).

[0028] Thereafter, the quantum key distribution device 200 determines whether the length of the key generated in the above steps is the expected length (step 317). If it determines in step 317 that the key length is not sufficient, the process returns to step 305, and steps 305 to 315 are repeated until a key of the expected length is generated.

[0029] Next, the transmitting unit 10 and the receiving unit 20a disclose the base information between them, and any mismatched keys are discarded (step 319). Generally, the disclosure of the base information is performed via the classical communication unit 7. Furthermore, the transmitting unit 10 and the receiving unit 20a disclose a portion of the key between them, calculate the error rate (step 321), and determine whether the error rate is below a predetermined threshold (step 323). If the error rate is below the threshold, the process proceeds to the next step (step 325) in which error correction is performed between the two parties. However, if the error rate exceeds the threshold, the process returns to step 303, where authentication is performed between the transmitting unit 10 and the receiving unit 20a, and the key generation process is repeated.

[0030] Finally, privacy amplification is performed between the transmitter 10 and the receiver 20a to obtain a private key (step 327), after which the process ends (step 329). The process from step 317 to step 327 is the same as the method generally used in conventional private key generation.

[0031] By using the quantum key distribution device 200 and method described above, secure key generation is possible in quantum key distribution using time bins.

[0032] Second Embodiment A configuration of a quantum key distribution device 400 according to a second embodiment of the present disclosure will be described with reference to the block diagram of Fig. 4. Fig. 4 shows only the receiver 20a of the quantum key distribution device 400 according to the second embodiment.

[0033] In the second embodiment, the process of detecting satellite time bins (1a and 1c in FIG. 4) in the receiver 20a in the first embodiment is changed. Specifically, in the first embodiment, when a satellite time bin occurs, the event is discarded and not used for key generation, but in the second embodiment, the generated satellite time bin is used as a key. In FIG. 4, only the receiver 20a, which is different from the quantum key distribution device 200 according to the first embodiment, is shown.

[0034] The first optical element 2a provided in the receiving unit 20a branches the forward 1E and backward 1L optical pulses sent from the transmitting unit 10 into two paths: a first path (i) and a second path (ii). If detection occurs only at the second timing in the second path (ii), 0 / 1 is used as the key for the X basis, depending on which detector the detection occurs in. Furthermore, if a satellite time bin is detected in the first path (i) or the second path (ii), and a forward 1E optical pulse is detected (e.g., 1a in FIG. 4), 0 is used as the key for the Z basis, and if a backward 1E optical pulse is detected (e.g., 1c in FIG. 4), 1 is used as the key for the Z basis. Furthermore, if both 0 and 1 are detected in both the Z basis and the X basis, 0 / 1 is randomly selected as the key.

[0035] In this embodiment, satellite time bins are used, and therefore it is necessary to prevent information leakage from the satellite time bins. For example, if an eavesdropper (conventionally referred to as "Eve") attacks a signal transmitted through the quantum communication unit 30 (transmission line), an optical pulse 1d (hereinafter referred to as a bad timing optical pulse) may be detected outside of the expected timing (e.g., 1a, 1b, 1c). Therefore, in the quantum key distribution device 400 of this embodiment, for secure key generation, the occurrence of a bad timing optical pulse 1d is monitored and recorded. The occurrence of the bad timing optical pulse 1d is recorded in a recording unit 9 connected to multiple photon time counters 5a, 5b, and 5c. While the recording unit 9 is illustrated in the receiving unit 20a in FIG. 4, it may also be included in the photon time counters 5a, 5b, and 5c.

[0036] A method for generating and distributing keys using the quantum key distribution device 400 will be described in detail below with reference to the flow chart of FIG.

[0037] When the process of distributing the private key begins (step 501), authentication is performed between the transmitter 10 and the receiver 20a (step 503). The transmitter 10 generates optical pulses carrying basis (Z basis and X basis) and bit (0 and 1) information based on a predetermined rule and transmits them to the receiver 20a (step 505). The receiver 20a records any detections that occur at bad timing using multiple photon detectors 4a, 4b, and 4c and multiple photon time counters 5a, 5b, and 5c provided in the receiver 20a (step 506). The receiver 20a determines whether detection occurs at the expected timing (i.e., the timing at which the optical pulse transmitted by the transmitter 10 and the optical pulse detected by the receiver 20a are synchronized) (step 507). Here, the expected timing is set to a time that takes into account the fixed time it takes for the optical pulse to propagate from the transmitter 10 to the receiver 20a. If the optical pulse is not received at the expected timing, the process returns to step 505 and the optical pulse carrying the information is transmitted again to the receiving section 20a.

[0038] If it is determined that the optical pulse was received at the expected timing, the quantum key distribution device 400 generates a key from the detection results of the multiple photon detectors. It is determined whether a photon was detected in the second pass (ii) and the first pass (i) (steps 509 and 513). Unless the detection occurred only at the timing of the second pass (ii) 1b or only in the satellite time bin of the first pass (i) or the second pass (ii), the process returns to step 505, and the information-carrying optical pulse is retransmitted to the receiver 20a.

[0039] In step 509, when detection occurs only at the second timing 1b of the second pass (ii), whether the detection occurred at the second photon detector 4b or the third photon detector 4c is set as 0 / 1 and used as the key for X. When detection occurs at both photon detectors, 0 / 1 is randomly assigned and used as the key for X (step 511).

[0040] Next, in step 513, if detection occurs only in the satellite time bin of the first pass (i) or the second pass (ii), the Z-based key is set to 0 / 1 depending on whether the optical pulse detected is the forward 1E or the backward 1L optical pulse, and if both the forward 1E and the backward 1L optical pulses are detected, 0 / 1 is randomly assigned and used as the Z-based key (step 515).

[0041] Thereafter, the quantum key distribution device 400 determines whether the length of the key generated in the above steps is the expected length (step 517). If it determines in step 517 that the key length is not sufficient, the process returns to step 505, and steps 505 to 515 are repeated until a key of the expected length is generated.

[0042] Next, the transmitting unit 10 and the receiving unit 20a disclose the base information between them, and any mismatched keys are discarded (step 519). Generally, the disclosure of the base information is performed via the classical communication unit 7. Furthermore, the transmitting unit 10 and the receiving unit 20a also disclose a portion of the key between them, calculate the error rate (step 521), and determine whether the error rate is below a predetermined threshold (step 523). If the error rate is below the threshold, the process proceeds to the next step (step 525) in which error correction is performed between the two parties. However, if the error rate exceeds the threshold, the process returns to step 503, where authentication is performed between the transmitting unit 10 and the receiving unit 20a, and the key generation process is repeated.

[0043] Finally, privacy amplification is performed between the transmitter 10 and the receiver 20a to obtain a private key (step 527). In privacy amplification, the key is shortened depending on the rate of detection at bad timing, etc. Then, the process ends (step 529). The process from step 517 to step 527 is the same as the method generally used in conventional private key generation.

[0044] By using the quantum key distribution device 400 and method described above, secure key generation is possible in quantum key distribution using time bins.

[0045] (Embodiment 3) In embodiment 3, we propose a quantum key distribution device including an optical gate 8 configured to control the input of an optical pulse at the receiver 20a in order to prevent detection at the wrong timing when an optical pulse 1d is generated at the wrong timing. Figure 6 shows the configuration of a quantum key distribution device 600 in embodiment 3. The difference from embodiment 2 is that the optical gate 8 is located before the first optical element 2a installed in the receiver 20a, and the input intensity outside the two expected forward and backward optical pulses 1E and 1L is set to zero. As an example, the optical gate 8 is an intensity modulator.

[0046] The optical gate 8 may be any device that realizes an optical shutter, such as an optical switch that switches the direction of light by changing the refractive index in response to an electrical signal, or an optical switch that uses a nonlinear optical effect caused by an optical signal. The optical gate 8 is configured to be able to communicate with the light source 1 via the classical communication unit 40, and the opening and closing timing of the optical gate 8 can be determined in accordance with the timing of transmission of an optical pulse from the light source 1.

[0047] The series of processes for generating a private key is the same as the process of embodiment 2 described with reference to FIG. 5, but since the optical pulse 1d at bad timing is removed before the photon detector by the optical gate 8, step 506 of "recording if detection occurs at bad timing" is not required.

[0048] (Embodiment 4) Embodiment 4, in which a quantum entanglement light source is used in the light source 1, will be described using the block diagram of Fig. 7. A quantum key distribution device 700 in this embodiment includes a transmitter 10 and two receivers 20a and 20b (hereinafter referred to as the first receiver 20a and the second receiver 20b). The transmitter 10 includes a quantum entanglement light source 1, and transmits optical pulse pairs via quantum communication units 30a and 30b provided between the transmitter 10 and each of the receivers 20a and 20b. The quantum communication units 30a and 30b may be, for example, optical fibers or free space including outer space.

[0049] The first receiving unit 20a includes a first optical element 2a (e.g., a beam splitter or a coupler) configured to split an optical pulse sent from the transmitting unit 10, a first photon detector 4a configured to measure one of the optical pulses split by the first optical element 2a, a first photon time measuring device 5a connected to the first photon detector 4a and measuring the detection timing of the photon, a first delay interferometer 3a configured to receive the other optical pulse of the optical pulses split by the first optical element 2a and cause interference between the forward optical pulse 1E and the backward optical pulse 1L, a second photon detector 4b and a third photon detector 4c configured to detect photons from the two outputs of the first delay interferometer 3a, and a second photon time measuring device 5b and a third photon time measuring device 5c configured to measure the timing at which the photon is detected by each photon detector.

[0050] The second receiving unit 20b has the same configuration as the first receiving unit 20a, and includes a second optical element 2b (e.g., a beam splitter, a coupler, etc.) configured to split the optical pulse sent from the transmitting unit 10, a fourth photon detector 4d configured to measure one of the optical pulses split by the second optical element 2b, a fourth photon time measuring device 5d connected to the fourth photon detector 4d and measuring the detection timing of the photon, a second delay interferometer 3b configured to receive the other optical pulse of the optical pulses split by the second optical element 2b and cause interference between the forward optical pulse 1E and the backward optical pulse 1L, a fifth photon detector 4e and a sixth photon detector 4f configured to detect photons from the two outputs of the second delay interferometer 3b, and a fifth photon time measuring device 5e and a sixth photon time measuring device 5f configured to measure the timing at which the photon is detected by each photon detector.

[0051] The transmitter 10 and the first and second receivers 20a and 20b can further exchange classical signals via classical communication units 40a, 40b, and 40c provided between the transmitter's classical communication unit 6 and the classical communication units 7a and 7b arranged in the respective receivers 20a and 20b. Classical signals may also be exchanged via the quantum communication unit 30. Furthermore, the quantum communication unit 30 and the classical communication unit 40 may be physically separated.

[0052] The difference between the first to third embodiments and this embodiment is that a secret key is shared between the first receiving unit 20 a and the second receiving unit 20 b, rather than between the transmitting unit 10 and the first receiving unit 20 a and / or the second receiving unit 20 b. The quantum entanglement light source 1 transmits quantum information (e.g., whether a photon exists in the forward optical pulse 1E or the backward optical pulse 1L, or the phase difference between the forward optical pulse 1E and the backward optical pulse 1L) in a determined state, but in a superposed and bidirectionally correlated state.

[0053] The basis and bits of the optical pulses from the transmitter 10 are determined only when they are measured by the first receiver 20a and the second receiver 20b. If the basis is the same, then in principle, the measurement result measured by the first receiver 20a will match the measurement result measured by the second receiver 20b. A secret key is then shared between the first receiver 20a and the second receiver 20b. When there are two receivers, a protocol called BBM92 (Non-Patent Document 5) can be used to generate the secret key, and when there are three or more receivers, a protocol called QCKA (Non-Patent Document 6) can be used to generate the secret key.

[0054] In the process of generating a private key, the light source 1 in the transmitter 10 generates quantum entangled optical pulses and transmits them to the receivers 20a and 20b, and the subsequent process is the same as in the above-described embodiments 1 to 3. However, if there are three or more receivers, a master receiver and the other slave receivers are determined, and error correction and privacy amplification are performed according to the key of the master receiver.

[0055] In this embodiment, in order to eliminate the optical pulse 1d with the wrong timing, a light opening / closing unit 8 may be attached in front of each of the optical elements 2a and 2b, as in the third embodiment.

[0056] (Embodiment 5) A quantum key distribution device 800 for a special case of embodiments 2 and 3 in which satellite time bins are used for the private key will be described using the block diagram of Fig. 8. In embodiments 2 and 3, the X basis is determined using the second time bin 1b when an optical pulse of forward 1E and an optical pulse of backward 1L interfere with each other, and the Z basis is determined using the satellite time bins (e.g., the first time bin 1a and / or the third time bin 1c) or the measurement results of the first pass (i). However, in certain cases where the probability of measurement is 50 / 50 (i.e., 50 / 50 between the X-basis key and the Z-basis key), the first pass (i) is unnecessary, and the X basis and the Z basis can be determined only from the measurement results of the second pass (ii).

[0057] Therefore, compared to the second and third embodiments, it is possible to reduce the number of the first optical element 2a that splits the optical pulse from the transmitter 10 into the first path (i) and the second path, and the number of the photon detector 4a and the photon time counter 5a used in the first path (i), which is a great advantage in practical application of the quantum key distribution device.

[0058] The quantum key distribution device 800 also selectively includes either a recording unit 9 that monitors and records whether or not a bad timing optical pulse 1d is generated, as described in embodiment 2, or an optical gate 8 that is configured to control the input of an optical pulse at the receiving unit 20a to prevent detection at bad timing, as described in embodiment 3. Furthermore, the private key generation process is the same as in embodiments 2 and 3, except for the part where the forward 1E and backward 1L optical pulses are detected using the first path (i).

[0059] (Embodiment 6) Another embodiment in which a quantum entanglement light source is used in a special case of the above-mentioned embodiment 5 will be described using the block diagram of Fig. 9. Embodiment 6 is a special case in which key distribution using quantum entanglement is performed and half of the keys are in the X-basis and half are in the Z-basis.

[0060] The quantum key distribution device 900 of this embodiment uses a quantum entanglement light source as in the fourth embodiment, and therefore includes a first receiving unit 20a and a second receiving unit 20b. A private key is shared between the first receiving unit 20a and the second receiving unit 20b.

[0061] The quantum key distribution device 900 is a special case where half of the keys are based on the X-base and half on the Z-base, and therefore the first pass (i) can be eliminated. For example, when quantum entanglement is generated in the transmitter 10 and distributed to n parties through the quantum communication channel 30, the number of photon detectors and photon time counters can be reduced from 3n to 2n compared to the fourth embodiment. Therefore, this embodiment has a great advantage in practical application of quantum key distribution devices.

[0062] Furthermore, when applied to embodiment 2 in which bad timing is recorded, a recording unit 9 is provided, and when applied to embodiment 3 in which bad timing is removed, an optical gate unit 8 is provided before the first delay interferometer 3 a and the second delay interferometer 3 b. Furthermore, the process of generating a private key is the same as in embodiments 2 and 3 after the transmitter 10 generates quantum entanglement and distributes it to n recipients. However, when there are three or more recipients, a master and the other slaves are determined, and error correction and privacy amplification are performed according to the master's key.

[0063] Therefore, according to the embodiments of the present disclosure, secure key extraction can be performed in quantum key distribution using time bins and a delay interferometer.

[0064] Additional Considerations The foregoing description of embodiments of the present invention has been presented for purposes of illustration and is not intended to be exhaustive or to be limited to the precise form disclosed. Those skilled in the art will recognize that many modifications and variations are possible in light of the above disclosure.

[0065] Finally, the language used herein has been selected primarily for readability and instructional purposes, and may not have been selected to delineate or limit the subject matter of the invention. Accordingly, it is intended that the scope of the invention be limited not by this detailed description, but rather by the appended claims. Accordingly, the disclosure of embodiments of the invention is intended to be illustrative, but not limiting, of the scope of the invention, which is set forth in the claims.

[0066] 1E Forward time bin 1L Backward time bin 1a First time bin 1b Second time bin 1c Third time bin 1d Bad timing optical pulse 2a, 2b Optical element 3, 3a, 3b Delay interferometer 3S Short path in delay interferometer 3L Long path in delay interferometer 4a to 4f Photon detector 5a to 5f Photon time measuring device 6 Classical communication unit in transmitter 7, 7a, 7b Classical communication unit in receiver 8 Optical gate unit 9 Recording unit 10 Transmitter 20a, 20b Receiver 30 Quantum communication unit 40 Classical communication unit 200, 400, 600, 700, 800, 900 Quantum key distribution device 300, 500 Process of distributing private key

Claims

1. A quantum key distribution device that uses time and phase differences as quantum information and sends the quantum information from a transmitter to a first receiver, wherein the transmitter comprises a light source configured to transmit the quantum information as optical pulses of time bins to the first receiver, and the first receiver comprises: an optical element configured to branch the optical pulses of the time bins from the transmitter; a delay interferometer configured to cause the optical pulses of the time bins branched by the optical element to interfere with each other; and a recorder configured to record the detection time of an optical pulse outside a predetermined time, and the quantum information is decoded using the detection time of the optical pulse of the time bin detected by the first receiver and the optical pulse output from the delay interferometer.

2. A quantum key distribution device that uses time and phase differences as quantum information and sends the quantum information from a transmitter to a first receiver, wherein the transmitter comprises a light source configured to transmit the quantum information as optical pulses of time bins to the first receiver, and the first receiver comprises: an optical element configured to branch the optical pulses of the time bins from the transmitter; a delay interferometer configured to cause interference between the optical pulses of the time bins branched by the optical element; and an optical gate unit configured to remove optical pulses outside of a predetermined time, and the quantum information is decoded using the detection time of the optical pulses of the time bins detected by the first receiver and the optical pulses output from the delay interferometer.

3. The quantum key distribution device according to claim 1 or 2, further comprising a second receiving unit having the same configuration as that of the first receiving unit, wherein the light source is a quantum entanglement light source configured to transmit optical pulses of the same time bin to the first receiving unit and the second receiving unit, and wherein a secret key is shared between the first receiving unit and the second receiving unit.

4. A quantum key distribution device that uses time and phase differences as quantum information and sends the quantum information from a transmitter to a first receiver, wherein the transmitter comprises a light source configured to transmit the quantum information as optical pulses of time bins to the first receiver, and the first receiver comprises a delay interferometer configured to output a different basis with a 50% probability depending on whether or not there is interference between the optical pulses of the time bins, and either a recording unit configured to record the detection time of an optical pulse outside a predetermined time or an optical gate unit configured to remove the optical pulses outside the predetermined time, and the quantum information is decoded using the optical pulses output from the delay interferometer.

5. The quantum key distribution device of claim 4, further comprising a second receiving unit having the same configuration as that of the first receiving unit, wherein the light source is a quantum entanglement light source configured to transmit optical pulses in the same time bin to the first receiving unit and the second receiving unit, and wherein the quantum key distribution device is configured to share a secret key between the first receiving unit and the second receiving unit.

6. A quantum key distribution method using time and phase difference as quantum information and decoding the quantum information using detection time and interference of delayed states, comprising: a step of generating an optical pulse of a time bin carrying the quantum information from a transmitting unit and transmitting the optical pulse to a first receiving unit; a step of determining whether detection has occurred in the first receiving unit at a predetermined timing; a step of determining whether only interference between optical pulses of the time bin has occurred if detection has occurred at the predetermined timing; a step of generating a key based on the position of the detected photon detector if interference has occurred; a step of determining whether detection has occurred only in paths that do not use an interferometer; and a step of generating a key based on the detection time of the optical pulse of the time bin if detection has occurred only in paths that do not use an interferometer.

7. The quantum key distribution method of claim 6, further comprising the step of monitoring whether or not an optical pulse outside of a predetermined time has been detected between the step of generating an optical pulse for a time bin carrying the quantum information from the transmitting unit and transmitting it to the first receiving unit and the step of determining whether detection has occurred in the first receiving unit at a predetermined timing, and recording the detection when an optical pulse outside of the predetermined time has been detected, and after the step of determining whether or not only interference has occurred between optical pulses in the time bin, generating a key based on the detection time if any occurrence occurs other than only interference between optical pulses in the time bin.

Citation Information

Patent Citations

  • Quantum encryption communication equipment

    JP2006074249A

  • Quantum key distribution system, and transmission device and receiving device thereof

    JP2008270873A

  • Quantum encryption key distribution system

    JP2011077995A

  • Quantum key delivery system and redundancy method

    JP2016163079A

  • Method and apparatus for timing adjustment of photon detector

    JP2019016900A