Method and system for simulating quantum communication processes
The method and system simulate quantum communication processes using a quantum processor with spatially controllable quantum particles to address the limitations of current simulations, enhancing the security and scalability of quantum communication protocols.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- BUNDESDRUCKEREI GMBH
- Filing Date
- 2026-01-12
- Publication Date
- 2026-07-23
Smart Images

Figure DE2026100023_23072026_PF_FP_ABST
Abstract
Description
[0001] Bundesdruckerei GmbH et al.
[0002] B89592WO
[0003] Method and system for simulating quantum communication processes
[0004] The invention relates to a method and a system for simulating a quantum communication process.
[0005] background
[0006] Most encryption systems used today rely on the computational hardness of mathematical problems such as factorization into prime numbers and discrete logarithms, which would become compromised as soon as a sufficiently powerful quantum computer is available. To prepare currently transmitted data under the assumption that such quantum computers are not yet available but will be in the future—the so-called SNDL (store-now-decrypt-later) scenario—post-quantum cryptography techniques have been developed. These methods are based on mathematical problems that are believed to be difficult to solve even for future, more powerful quantum computers.
[0007] Another solution to the problem is quantum-secure communication, where security is based from the outset on principles of quantum physics. Quantum communication within quantum networks ("quantum internet") is of great importance, especially when using quantum key distribution (QKD). A well-known QKD protocol (or simply protocol) is BB84 (C. Bennett, et al., Quantum cryptography: Public key distribution and coin tossing, Proc. Int. Conf. Comput. Syst. Sig. Proc. Vol. 1, pp. 175-179). An overview of quantum threats, post-quantum cryptography and QKD in general is provided by the publication “Quantum-safe cryptography” (2022) of the Federal Office for Information Security (www.bsi.bund.de / SharedDocs / Down-loads / EN / BSI / Publications / Brochure / quantum-safe-cryptography.html).
[0008] With the commercial availability of QKD hardware, the need arises to investigate security statements not only asymptotically, but also with regard to finite key sizes, real noise levels, and an attacker who potentially has access to a quantum computer. It must be investigated whether, under these conditions, an eavesdropper has a finite probability of reconstructing the established key undetected. Quantum communication is relatively difficult to test and expensive to deploy. New data transfer and QKD protocols can therefore often only be developed experimentally to a limited extent, and existing protocols often cannot be fully verified. At the same time, there is a great need for theoretical quantum communication (Boehmert & Boehmert).
[0009] - 2 -
[0010] It is necessary to test paradigms in real-world systems, as current simulations do not offer sufficient scope for a representative investigation of quantum effects. For example, current possibilities for investigating QKD security proofs and QKD side-channel attacks are often limited. In particular, there is a need to provide secure and scalable solutions for quantum communication.
[0011] Beyond quantum communication, computational operations using ion traps are known in the context of quantum computing. For example, V. Kaushal et al., Shuttling-based trap-ped-ion quantum information processing, AVS Quantum Sci. 2, 014101 (2020), describe relevant parameters and performance specifications for microstructured ion traps, waveform generators and additional circuits, shuttling operations, and suitable measurement methods for verifying system performance. Qiskit is an example of a known transpiler for generating control instructions for quantum processors from quantum circuits (A. Javadi-Abhari et al., Quantum computing with Qiskit, ar-xiv.org / abs / 2405.08810 - www.ibm.com / quantum / qiskit).
[0012] In F.A. Khaleel et al., Implementation of a modified noise-free and noisy multistage quantum cryptography protocol using QISKIT, quantum studies: mathematics and foundations, Vol. 11, 2024, a simulation and implementation of a modified multistage QKD protocol using Qiskit is described. The proposed multistage QKD protocol applies different random commutative sets of Euler angles to the transmitted qubits.
[0013] In K. Badrike et al., QisDAX: An Open Source Bridge from Qiskit to Trapped-Ion Quantum Devices, 2023 IEEE international conference on quantum computing and engineering, interfaces for Python programs written with Qiskit are presented. Users can generically access ARTIQ control systems that operate trapped-ion quantum devices.
[0014] In V. Sharma, "Effect of Noise on Practical Quantum Communication Systems," Defence science journal, Vol. 66, 2016, No. 2, a single classical bit is used to transmit information under the influence of a noisy quantum channel. The entanglement content of quantum states is calculated under noisy channels such as amplitude attenuation, phase attenuation, Pauli channels, and various collective noise models in conjunction with QKD protocols. (BOEHMERT & BOEHMERT)
[0015] - 3 -
[0016] In A. Ponosova et al., Protecting fiber-optic quantum key distribution sources against lightinjection attacks, arXiv:2201.06114v2 (2022), countermeasures against light injection attacks are proposed, consisting of an additional sacrificial component attached to the output of a source. This component should either withstand high-power incident light while simultaneously attenuating it to a safe level that cannot alter the rest of the source, or be destroyed into a permanent state of high attenuation, thus interrupting the transmission.
[0017] Summary
[0018] The object of the invention is to provide a method and a system with which quantum communication processes can be analyzed and improved effectively and cost-efficiently.
[0019] To solve this problem, a method and a system for simulating a quantum communication process are provided according to independent claims 1 and 10. Further embodiments are the subject of dependent subclaims.
[0020] According to one aspect of the invention, a method for simulating (at least) one quantum communication process comprises the following steps:
[0021] - Providing, in a data processing unit, quantum communication information for at least one quantum communication process to be simulated between at least a first quantum communication device, a second quantum communication device, and an eavesdropping device via at least one quantum channel; - Determining, in the data processing unit and from the quantum communication information, control data for a quantum processor in which quantum operations are applied to quantum particles that are ions or neutral atoms and that are spatially controllable within several operational domains; and
[0022] - Simulating the quantum communication process in the quantum processor using the control data, wherein: each quantum bit of the quantum communication process is assigned to one of the quantum particles, communication operations of the quantum communication process each correspond to at least one of the quantum operations, wherein the quantum operations include at least one first quantum operation for the first quantum communication device, at least one second quantum operation for the second quantum communication device, and at least one third quantum operation for the listening device, and a noise process during the quantum BOEHMERT & BOEHMERT
[0023] - 4 -
[0024] The communication process corresponds to at least one other quantum operation.
[0025] According to another aspect, a system for simulating a quantum communication process has a data processing unit and a quantum processor and is set up to execute the aforementioned procedure.
[0026] Using the proposed method, quantum-based communication protocols, in particular quantum key exchange protocols, can be mapped in a specifically adapted quantum system with corresponding quantum physical effects, so that, for example, fast prototyping of quantum communication network architectures can be enabled, taking into account possible interactions with complex environmental factors such as noise sources or side-channel attacks.
[0027] The ions or neutral atoms can be spatially controlled by means of a (particle) trap. The quantum processor can have at least one ion trap (for spatial control of ions) or at least one magneto-optical trap (for spatial control of neutral atoms). The ions can be, for example, magnesium ions, while the neutral atoms can be, for example, Rydberg atoms. The ion trap can be configured as a Paul trap. The trap can be divided into several operational regions. The ion trap or the magneto-optical trap can, for example, have a plurality of memory segments, for example, between 8 and 64, preferably between 8 and 32. One or more of the memory segments can each be grouped into an operational region. The quantum processor can be configured as a NISQ (noisy intermediate-scale quantum) device.
[0028] A quantum particle can possess a quantum state (or simply state), which can be formed, in particular, as a quantum bit (or qubit). Quantum operations (qubit operations) in a quantum processor can be performed, for example, by laser excitation within one of the operational areas (addressing zones, quantum registers). Each quantum operation can correspond to one or more quantum gates.
[0029] The control data can specify the quantum operations. In particular, the control data can specify the (at least one) first quantum operation, the (at least one) second quantum operation, and the (at least one) third quantum operation. The control data can also specify the noise process. A communication operation can correspond to a quantum gate (within a quantum circuit). BOEHMERT & BOEHMERT
[0030] - 5 -
[0031] The quantum communication information can specify the quantum communication process. In particular, the quantum communication information can include a quantum circuit. The quantum communication information can include parameters (especially machine parameters) of quantum communication devices (especially for quantum key exchange).
[0032] The first, second, and third quantum operations on the quantum particles can be performed in a (single) active operation region. Preferably, at least one further (inactive) quantum particle, for which no action from any of the quantum operations is intended at any given time, can be located spatially outside the active operation region.
[0033] In particular, all of the quantum operations, especially all first quantum operations, second quantum operations and third quantum operations, can be performed in the active operation domain.
[0034] The other (inactive) quantum particle can be placed in one or more inactive operational areas, especially as long as no action from one of the quantum operations is planned.
[0035] The transfer to the active or inactive operating region can be accomplished by means of (at least) one shuttling operation. The shuttling operation can be performed, for example, by changing the voltage at a trap electrode (the ion trap or the magneto-optical trap), which can preferably be assigned to the relevant operating region. The shuttling operation can, in particular, comprise at least one of the following: linear transport of a quantum particle, separation of quantum particles, merging of quantum particles, and exchange of quantum particles.
[0036] The first quantum operation can be performed in a first operational domain, and / or the second quantum operation can be performed in a second operational domain, and / or the third quantum operation can be performed in a third operational domain. Preferably, the first operational domain, the second operational domain, and / or the third operational domain can be formed separately from one another.
[0037] The first operating area and / or the second operating area and / or the third BOEHMERT & BOEHMERT
[0038] - 6 -
[0039] Operating areas can therefore be formed in a non-overlapping manner. In particular, the first operating area and / or the second operating area and / or the third operating area can each be spaced apart from one another. For example, the first operating area and / or the second operating area and / or the third operating area can each be separated from one another by at least one further operating area. It can also be provided that at least two of the first, second, and third operating areas are spatially adjacent to each other.
[0040] By executing the first, second, and third quantum operations in separate operational domains, more complex protocols can be authentically simulated. Furthermore, crosstalk noise can be reduced, thus lowering the probability of errors in the simulation.
[0041] The operational domains of the quantum processor, in particular the first operational domain, the second operational domain and the third operational domain or the active operational domain and the inactive operational domain(s), can be arranged along a (one-dimensional) chain.
[0042] Alternatively, the operational domains of the quantum processor, in particular the first operational domain, the second operational domain and the third operational domain, or the active operational domain and the inactive operational domain(s), can be arranged in a two-dimensional lattice.
[0043] The quantum communication process can include at least one quantum key exchange protocol, preferably a photonic quantum key exchange protocol. The quantum key exchange protocol can be, for example, one of BB84, E91, and BBM92. The quantum communication process can also include multiple quantum key exchange protocols.
[0044] The quantum communication process can include another quantum communication device. In other words, the quantum communication process can take place between at least the first quantum communication device, the second quantum communication device, the further quantum communication device, and the eavesdropping device via at least one quantum channel. The quantum operations can include at least a fourth quantum operation for the further quantum communication device. In particular, the quantum communication process can include a plurality of further quantum communication devices.
[0045] - 7 -
[0046] The communication devices include quantum communication devices, and the quantum operations can include a plurality of fourth quantum operations for the plurality of further quantum communication devices. For example, the quantum communication process can take place within a quantum communication device network.
[0047] In particular, multiple quantum communication processes can be simulated simultaneously. For this purpose, quantum communication information can be provided for multiple quantum communication processes to be simulated.
[0048] When simulating the quantum communication process, at least one (in particular, at least two) of the following attacks can be simulated in the quantum processor: denial-of-service attack, photon splitting attack, light injection attack, fake source attack, qubit interception attack, error correction attack, fake state attack, commitment attack, and attack with a phase-covariant quantum cloning machine (PCCM attack). For this purpose, corresponding quantum communication information can be determined, for example, quantum gates within a quantum circuit, and in particular, corresponding quantum operations of the quantum processor.
[0049] The noise process can indicate at least one of the following: qubit errors due to quantum gates, depolarization errors due to unwanted collisions, qubit loss, vacuum loss, and a disturbed random number generator for base selection. Corresponding quantum communication information can be determined for this purpose, for example, quantum gates within a quantum circuit, and in particular, corresponding quantum operations of the quantum processor.
[0050] The noise process can be controlled using a noise model, for example, by means of a fitted distribution. The noise process can be determined as a function of the ratio of ion-trap noise to noise in photonic quantum key exchange.
[0051] When simulating the quantum communication process, a plurality of noise processes during the quantum communication process can also be simulated, which preferably each correspond to at least one further quantum operation.
[0052] When simulating the quantum communication process, a post-processing process can be simulated, in particular at least one of basis reconciliation (BOEHMERT & BOEHMERT).
[0053] - 8 -
[0054] (Quantum) error detection, (quantum) error correction, and privacy amplification.
[0055] In the quantum communication process, quantum states can be encoded using a quantum error correction code, and preferably, when simulating the quantum communication process, encoding quantum operations corresponding to encoding quantum gates are performed. The quantum error correction code can, for example, be a stabilizer code, specifically a Calderbank-Shor-Steane code (CSS code), in particular a [[7,1,3]]-CSS code.
[0056] The method may further include: adjusting the quantum communication information based on a simulation result of simulating and / or repeating the determination of the control data, simulating the quantum communication process, and adjusting the quantum communication information until a predetermined measure of quality (for the quantum communication process) is achieved.
[0057] Adjusting the quantum communication information can involve, for example, adjusting quantum key exchange protocol parameters, particularly quantum gate parameters. The quality measure can specify, for instance, a similarity (especially fidelity) between a state of the first quantum communication device and a state of the second quantum communication device, and / or a similarity (especially fidelity) between a state of the first quantum communication device and a state of the listening device. The method can also include: (Physically) executing the quantum communication process based on the adjusted quantum communication information.
[0058] In conjunction with the system for simulating a quantum communication process, the configurations described above in connection with the method can be provided accordingly. Information relating to "Alice," "Bob," or "Eve" can be provided accordingly for the first quantum communication device, the second quantum communication device, or the eavesdropping device, respectively.
[0059] In the context of the present disclosure, interval references (“between”, “from… to”) are to be understood as encompassing the interval ends. BOEHMERT & BOEHMERT
[0060] - 9 -
[0061]
[0062] from
[0063] Further examples of implementation are explained in more detail below with reference to figures in a drawing. These show:
[0064] Fig. 1 shows a schematic representation of a system for simulating quantum communication processes.
[0065] Fig. 2 shows a schematic representation of a trap of a quantum processor,
[0066] Fig. 3 shows a schematic representation of an arrangement for a quantum communication process,
[0067] Fig. 4 shows a schematic representation of a quantum circuit for a phase-covariant quantum cloning machine.
[0068] Fig. 5 shows a flowchart of a method for simulating quantum communication processes,
[0069] Fig. 6 a schematic representation of the BB84 protocol as a quantum circuit, Fig. 7 a schematic representation of steps during the simulation of the BB84 protocol,
[0070] Fig. 8 shows a diagram with control instructions during the simulation of the BB84 protocol, Fig. 9 shows another quantum circuit for the BB84 protocol using an asymmetric cloning operation,
[0071] Fig. 10 shows a plot of the accuracy of the simulation of the BB84 protocol,
[0072] Fig. 11 shows a schematic representation of the BB84 protocol based on the trap when using multiple active operating areas,
[0073] Fig. 12 shows a schematic representation of the E91 protocol as a quantum circuit, Fig. 13 shows a schematic representation of steps during the simulation of the E91 protocol and
[0074] Fig. 14 shows a schematic representation of the E91 protocol when using multiple active operating areas.
[0075] System for simulating quantum communication processes
[0076] Figure 1 shows a schematic representation of a system for simulating quantum communication processes. The system comprises a (classical) data processing unit 10 with a (classical) processor 11 and (classical) memory 12, as well as a quantum processor 14, which is communicatively connected to the data processing unit 10. In particular, classical signals (for example, control data for the quantum processor 14 or measurement results from the quantum BOEHMERT & BOEHMERT) can be transmitted via an interface 13.
[0077] - 10 -
[0078] Data is exchanged between the data processing unit 10 and the quantum processor 14. The quantum processor 14 comprises a preparation unit 15 for preparing and manipulating quantum particles and a measurement unit 16 for (quantum) measurement. The data unit 10 can be a data processing device, for example, a computer, or a part thereof, for example, a computer module. The data processing unit 10 can also be distributed across a plurality of data processing devices.
[0079] In the quantum processor 14, quantum particles (ions or neutral atoms) within several operational areas 21 (addressing zones) are spatially controlled by a (quadrupole) ion trap / Paul trap 20 or a magneto-optic trap 20, and quantum operations (e.g., quantum gates) are performed. This can be done, for example, by laser excitation of the quantum particles.
[0080] The quantum particles can be moved between different operational areas 21 by means of shuttling operations. Fig. 2 shows a schematic representation of a Paul trap 20 segmented into several operational areas 21 within the quantum processor 14. Quantum particles can be moved linearly by means of a movable potential 22 and separated by means of a double sink potential 23. Furthermore, quantum particles can be combined 24 and exchanged 25.
[0081] Quantum processors with trapped neutral atoms or atomic ions show great promise in terms of a quantum advantage for relevant computational tasks. Ion-trap quantum processors have achieved several milestones in quantum information processing, such as the first controlled NOT gate, a maximum number of entangled qubits, and record fidelity for 2-qubit gates. Complex quantum algorithms, such as chemical simulations and small instances of factorization, have already been run on ion-trap platforms. The following chapter discusses how ion-trap quantum computers can be used to simulate attacks on QKD protocols.
[0082] Current quantum processors 14 with ions, for example, feature a segmented Paul trap 20 with 32 memory segments and a laser interaction zone. The Paul trap 20 can contain multiple ion crystals, each containing one or two ions. Effective full connectivity is achieved through reconfiguration operations such as ion transport between inactive (memory) and active (memory) regions, separation and recombination of ion crystals, and positional reconfiguration.
[0083] - 11 -
[0084] Exchange within an ion crystal is achieved. Operational accuracy determined through randomized benchmarking is 99.99% for 1-qubit gates and up to 99.80% for 2-qubit gates. Furthermore, measurement and preparation error rates of less than 0.1% are achieved, entanglement of up to six qubits has been successfully demonstrated, and one of the first implementations of a reconfiguration-based fault-tolerant parity measurement with four data and two auxiliary qubits has been performed. A combination of subregister addressing in conjunction with reconfiguration operations is feasible.
[0085] The quantum processor 14 can be controlled by control software. This control software can be located at least partially in the data processing unit 10 and / or at least partially in the quantum processor 14 itself. The control software is divided into a high-level stack and a low-level stack, as well as additional logging and calibration frameworks. A quantum algorithm, which may, for example, contain quantum communication information, can be translated into a hardware-agnostic framework such as Qiskit and / or exported into a quantum assembly language such as OpenQASM. Taking into account quantum processor-specific quantum gates and / or quantum operations, a quantum processor-specific quantum circuit can then be determined. Subsequently, control data for the quantum processor 14 is determined (compiled) from this quantum processor-specific quantum circuit.Alternatively, the control data can also be determined directly from the quantum communication information. The control data can be determined using a shuttling compiler and / or a low-level stack compiler.
[0086] Quantum key exchange
[0087] The quantum communication processes to be simulated can include, in particular, quantum key exchange protocols, which are summarized below.
[0088] The term quantum key exchange (QKD) refers to a set of protocols that (at least) two parties, “Alice” with a first quantum communication device 30 and “Bob” with a second quantum communication device 31, can use to determine a shared private key via an (insecure and / or noisy) quantum channel 32 (see Fig. 3). An eavesdropping party, “Eve”, with an eavesdropping device 33 (a (illegitimate) third quantum communication device), may also be involved. In general, no quantum computers are required to use this technology.
[0089] - 12 -
[0090] to perform QKD. Rather, the first quantum communication device 30, the second quantum communication device 31, and, if applicable, the listening device 33 each have a measuring device 34 for measuring quantum states, a preparation device 35 for preparing and / or manipulating quantum states, and a classical communication unit 36 for exchanging classical signals (for example, via a classical communication channel, which may be unencrypted). The quantum channel 32 is set up for transmitting quantum states, in particular qubits. For example, Alice sends qubits to Bob via quantum channel 32, and Eve can intercept qubits on this quantum channel 32 and forward qubits she has prepared to Bob.
[0091] The following explains how individual QKD protocols work.
[0092] BB84 protocol
[0093] The QKD protocol BB84 is based on the fact that measurements of a qubit state in two mutually unaffected bases can never both simultaneously yield deterministic results. Initially disregarding noise, communication operations are performed by sender Alice and receiver Bob according to the following table.
[0094] Alice Bob Choose random bit 0 1 1 0 1 0
[0095] string
[0096] Choose random X z X zzz preparation bases
[0097] Prepare qubit- l + > ll> I - > |0> ll> |0>
[0098] Conditions
[0099] Sending qubits from Alice to Bob
[0100] z XX z X z Select random measurement bases 0 / 1 + / - — 0 + / - 0 Measurement results Public X zz Public announcement Announcement Checking bits, 1 0 0 Checking
[0101]
[0102] BOEHMERT & BOEHMERT
[0103] - 13 -
[0104] Determination of the bit, determination of the key
[0105] Key
[0106]
[0107] In a first step, Alice selects a random bit string of length 2n. Then, a random basis, either X or Y, is chosen for each bit. A prepares all qubits in +1 eigenstates of the respective bases, according to the bit values. All qubits are then transferred from Alice to Bob. The receiver, Bob, now measures each qubit in a randomly chosen measurement basis. Subsequently, both parties publicly disclose their chosen bases. After the measurements (post-processing), Alice and Bob compare the bases and retain the subsets of their bit strings for which the preparation and measurement bases match.
[0108] It should be noted that in this procedure the bit strings themselves are not made public – only the bases are disclosed. Initially, 2n qubits should be used, as on average half of the qubits are rejected due to mismatched bases. Public disclosure should take place after the measurements have been performed. Since Alice's and Bob's bases for the accepted bits are identical, the key bits between Alice and Bob will also match in the absence of noise.
[0109] Noise, in turn, can be caused by hardware malfunctions or by a third party—Eve with a listening device 33. If a qubit is intercepted during transmission and measured by Eve to obtain information about the transmitted message, it would be advantageous for Eve (without a quantum computer) to measure the qubit with a random base, then, based on the measurement result, to re-prepare the qubit with the same base and send it on to Bob. Since the bases are mutually unaffected, this leads to an error rate of 50% between Alice and Bob if the bases of Alice and Bob match and do not match Eve's, or to an overall error rate of 25% between Alice and Bob if all bases match.If Eve had access to a quantum computer, the best course of action would be to create an imperfect copy of the received qubit, forward one of the qubits to Bob, and store the other. Once the bases are exposed, Eve can measure in the same basis that Alice used for preparation. Since the no-cloning theorem prohibits perfect copying, imperfect cloning will inevitably lead to errors in the form of discrepancies between Alice's and Bob's results.
[0110] One solution to this eavesdropping problem is for Alice and Bob to agree on their BOEHMERT & BOEHMERT
[0111] - 14 -
[0112] The matching bits are not immediately accepted as keys, but rather a verification layer is introduced as part of post-processing, in which the measurement results for a subset of the matching bits are compared (verification bits). An estimate of the error rate is calculated from the public comparison of the verification bits. If the error rate is significantly higher than the value expected due to hardware limitations, it can be assumed that a listening device 33 is present.
[0113] Therefore, (4 + <5)n qubits are regularly used, with Alice and Bob agreeing beforehand which randomly selected half of the matching bits will be the check bits and the other half the bits of the shared key. The <5 parameter allows Alice and Bob to control the probability that the resulting key bit string actually has length n within a single pass of the protocol. It should be noted that, through classical post-processing as explained in more detail in Section 2.7, A and B can generate a valid and secure key with a high probability, even in the presence of noise—regardless of whether it was caused by an eavesdropper or not.
[0114] E91 protocol
[0115] The E91 protocol is based on a pre-shared entangled state, such as a two-qubit Bell state. Furthermore, an entangled Bell pair of the form |O can be used. +) = (100) ± 111) ) / V2 can be used. The E91 protocol is said to offer a practical advantage over BB84 in that the key is only generated at the moment the qubits are measured. Unlike BB84, no transmission of qubits is required after key generation. The state |O + ) could have been created by Alice, who then sends a qubit to Bob, or Alice and Bob receive their qubit from a trusted source that |O + ) prepared. Their joint measurement probabilities for the measurement on the X and Z bases are
[0116] Poo = Pu = P++ = P— = 1 / 2, Poi = Pio = P+- = P-+ = 0,
[0117] In a noise-free scenario, the measurement results are perfectly correlated, regardless of the measurement basis. The built-in safety component of the E91 consists of the calculation of the CHSH size (BOEHMERT & BOEHMERT).
[0118] - 15 -
[0119]
[0120] = |(A(B + B') + A'(B - B'))\.
[0121] Here, A, A', B, B' are abbreviations for single-shot measurement results from Alice and Bob, and the apostrophized and non-apostrophized results refer to different measurement bases. The angle brackets denote averaging over any number of runs. For classical correlations between two pairs of measurements from one party, 5 < 2. This inequality is violated by entangled states (S < 2 / 2), where equality occurs in maximally correlated Bell states such as |O + ) consists.
[0122] For each trial, Alice and Bob randomly select a measurement basis from the following sets - Alice: A
[0123]
[0124] 1 = Z, A2 = X, A3 = (X + Z) / √2; Bob: B1 = Z, B2 = (Z − X) / √2, B3 = (X + Z) / √2. After a certain number of independent repetitions, the post-processing resembles the BB84 protocol: First, Alice and Bob transmit the selected bases on a public channel. The results are sorted into three groups: A first group for the measurement base A B2, A B3, A2B2, or A2B3, with the results being sent and used to calculate S(A1, A2, B2, B3). The protocol terminates if 5 < 2, as it must then be assumed that the pre-shared entangled state was measured by a listening device 33 and collapsed into a mixed state. A second group contains the correlated results for identical bases A1, B1 and A3, B3, which are used to generate the key. The results for all other combinations of bases are discarded.A random sequence of base pairs for is shown in the following table for illustration.
[0125] Ai A3A A2A3A3A A3
[0126] B2B3BI B2B, B2B, B3
[0127] The bit values corresponding to the bases in columns 2, 3, 7, and 8 are used for key generation, and the bit values in columns 1 and 4 are used to determine the CHSH size. If a CHSH violation is detected, the data from measurements using the same bases are post-processed in the same way as with BB84 to generate the key.
[0128] According to the alternative BBM92 protocol, unlike E91, only two states are used. BOEHMERT & BOEHMERT
[0129] - 16 -
[0130] Further aspects of QKD protocols
[0131] Both the BB84 and E91 protocols require classical post-processing to obtain secure and valid keys with a high probability. In a realistic scenario, all communication operations of a QKD protocol can be susceptible to noise. The initial states are prepared with finite accuracy, transmission over quantum channels and unused storage can adversely affect the qubits, and the measurement will result in finite errors. Therefore, the bit sequences obtained by Alice and Bob cannot match, even in the absence of a listening device 33. In the presence of a listening device 33, the rate at which the bits do not match increases due to noise, such as that caused by imperfect cloning.First, Alice and Bob perform an information exchange using classical error correction over a public channel to obtain identical keys with a high probability. A common method is the iterative cascade protocol, which permutes the key bits at each iteration and then forms blocks from which parities are calculated. By querying Alice's respective parities, Bob can eventually flip bits to correct errors and compare his key with Alice's. While this method results in identical keys with a high probability, the information will leak to Eve.
[0132] In the next step, privacy amplification is used to reduce mutual information / transinformation with Eve. One possible method for this is hashing: Alice and Bob can additionally hash their key bits obtained from the procedure described above to suppress correlations with the data collected by Eve. This function results in a bit string of length m. The collision entropy of the hashed key, if Eve is known, is greater than or equal to m − 2. m−d, where d is a lower bound for the collision entropy of the unhashed key chain given Eve's knowledge. This means that by choosing a small value for m, the value can be brought arbitrarily close to m. Eve might potentially intercept the transmitted syndrome information needed for the error correction / information matching step, thus expanding its knowledge of the key. This additional information changes the lower bound for Eve's collision entropy, but it is still 1 − 2 −s bounded from below. The parameter s can be chosen such that the collision entropy of Eve is determined with a probability of at least 1 − 2. −s is limited. This results in Eve's information being limited after the information-BOEHMERT & BOEHMERT procedure.
[0133] - 17 -
[0134] The value of the privacy amplification is less than 2m−d+2(k+s) bits, meaning it can still approach zero exponentially. For practical purposes, it is usually sufficient to assume that Alice and Bob can reduce Eve's mutual information to (almost) zero using privacy amplification if the initial value is finite and less than one.
[0135] The eavesdropping tool Eve is limited in its attack capabilities if only one qubit can be intercepted at a given time. However, if Eve can store qubit states and perform collective attacks, a wider range of possibilities must be considered. Therefore, the following security parameters ö, s, and l are regularly used:
[0136] - The qubit overhead <5 controls the probability that at least half of the qubits will be accepted when measured by Alice and Bob in potentially different bases.
[0137] - The QKD scheme is with a probability of 1 — O(2 -s ) successful: For a protocol that distributes n Bell pairs, the quality (fidelity) of the resulting state is p AB even
[0138]
[0139] ® n ( \p AB | )® n > 1 − 2 −s . This statement is based on the following argument of classical random sampling: The probability of observing more than t = sn bit / phase errors on the key qubits and simultaneously less than (e — e')n errors on the check bits is asymptotically bounded from above by exp[−¼ε′²n / (ε − ε²)].
[0140] - The mutual information (transinformation) between Eve and the key is less than 2 −l This means for the quality of p AB , that ( Aß ) < (2n + s + l / ln2)2 -s + O(2 −2s The Holevo theorem states that the mutual information I(AB-. E) < S^PE) = S(p Aß ) is limited by the degree of entanglement of system AB with its environment E. S( Aß ) is exponentially close to zero, since p AB is exponentially close to a pure state. This is a manifestation of the "monogamy of entanglement," i.e., if A and B are maximally entangled, there can be no entanglement between A and E.
[0141] If n copies of a partially entangled two-qubit state (J) exist, entanglement distillation can be used to obtain from them a smaller number m < n of maximally entangled Bell states. This corresponds to a situation where the qubits are not sent sequentially, but rather Alice and Bob each have an n-qubit state of Alice and Bob, respectively. (BOEHMERT & BOEHMERT)
[0142] - 18 -
[0143] QKD protocols can be operated using quantum error correction codes (QEC codes) via encoded logical qubit states. For example, if a distance-d QEC code is used, which can handle errors up to t = n physical qubits, then...
[0144]
[0145] Corrected, it is possible to faithfully restore the transmitted logical qubit state, assuming that no more than t errors occur during the noisy transmission or through Eve. In an environment where single errors occur with probability p, the error rate of the procedure is guaranteed to be 풪(p). t+1 ), if a fully fault-tolerant implementation of the QKD circuits is used.
[0146] An extension of BB84 using physical qubits encoded logic qubits can be achieved as follows. Alice uses highly entangled n-qubit logic states for the protocol |0) L , |1) L , | + ) L and | — ) L The additional degrees of freedom, namely the eigenvalues of stabilizer generators, are used to increase security and for error correction. Alice can choose a random combination of +1 eigenvalues for each stabilizer generator and sends this classical information to Bob. Upon receiving the qubits, Bob can also measure the stabilizer generators, compute a relative syndrome using his own syndrome bits and Alice's syndrome bits, and perform a recovery operation. Using a QEC code capable of correcting up to t errors, this procedure will always succeed if no more than t errors occur as a result of noise or eavesdropping. QEC codes, especially CSS (Calderbank-Shor-Steane) codes, can be used to ensure the security of QKD protocols even when no quantum hardware is available.In this case, classic bit strings representing labels of QEC code states are decoded classically. As a first step, Alice sends a random valid base state of a code state |0>. L , |1> L ,|+> L or |-) L with a specific syndrome on Bob. When using a [[7,1,3]]-Steane code (a [[n,1,d]]-CSS code with n=7 and d=3), such a state could be, for example, |0001111), since it is one of eight underlying basis states of |0) L In this case, the transmitted X-syndrome would be the trivial syndrome {+1 +1 +1}. After receiving the acknowledgment, Bob measures the qubits in the respective Z / X basis (as prescribed by BB84) and uses Alice's and his own syndrome to perform classical error correction on the measured bit sequence (information reconciliation). Subsequently, by decoding the classically error-corrected bit sequence, Bob has obtained a specific logical state. With a code of 2 k Alice and Bob calculate the codewords to determine which corresponds to their shared bit sequence, thereby enabling PrivacyBOEHMERT & BOEHMERT
[0147] - 19 -
[0148] To perform amplification. An error rate of 11% is regularly acceptable in practice.
[0149] Attacks on quantum key exchange protocols
[0150] Various threat scenarios can generally be divided into two categories. The first category encompasses attacks that exploit obvious shortcomings in the protocol design itself. The second category includes attack vectors that exploit loopholes inherent in practical protocol implementations. Fundamentally, no quantum key exchange protocol can be effective if Eve has the ability to impersonate Alice while communicating with Bob, and vice versa.
[0151] Basically, a distinction can be made between:
[0152] - individual attacks with a unitary mapping U BE = U® n as a communication operation as well as independent measurements of auxiliary systems immediately after Eve knows a single-qubit measurement result,
[0153] - collective attacks with a unitary mapping U BE = U® n as a communication operation and collective measurement at the end of the protocol, including classic post-processing, and
[0154] - coherent attacks with a general unitary mapping as a communication operation and collective measurement at the end of the protocol.
[0155] The following specific attacks are fundamentally feasible:
[0156] - Denial-of-Service (DoS) attack: Eve's physical access to Alice and Bob's quantum channel can be used for a DoS attack. While the simplest form of DoS attack might be the physical destruction of the quantum channel, Eve could also generate enough noise to render the quantum channel practically unusable.
[0157] - Photon number splitting (PNS) attack: In QKD using weak light pulses, a finite number of photons are emitted from real photon sources. Eve can split off individual photons and perform a measurement after Alice has revealed her base. Eve will not be detected if Bob has no information about the initial photon number distribution. This problem can be circumvented by using decoy states.
[0158] - Light injection attack: In certain photonic setups, Eve may be able to inject light pulses into the quantum communication devices used by Alice and Bob. BOEHMERT & BOEHMERT
[0159] - 20 -
[0160] to inject 30, 31. Through the possible reflections of these light pulses, which Eve directs onto Alice's state preparation device or Bob's measuring device, they have some limited means of verifying the manner of manipulation of quantum states. Alice and Bob can, for example, use a monitoring device to detect incoming / unwanted light.
[0161] - Fake-source attack: Eve can access Alice's qubits before they are sent to Bob. This is not yet harmful if Eve does not know which bits are randomly selected for verification, nor does Eve know on what basis Alice and Bob will prepare or measure states. For an entanglement traceability protocol, it does not matter if Eve can replace Alice's source with his own source containing manipulated states, as long as Alice's measurement of a single qubit of the two-qubit state yields random results to which Eve subsequently has no access. With a deterministic source, the QKD protocol will fundamentally be insecure. If Alice always prepares |0) and |+) as a result of a manipulated source, Bob will always receive the same key bits as Alice, but the protocol fails because it must be assumed that Eve has extracted a macroscopic part of the key.
[0162] - Qubit interception attack: In the BB84 protocol, Eve can intercept Alice's qubit when it is sent to Bob. Eve then measures the qubit using a random base and forwards a qubit state corresponding to the measurement result to Bob. This simple type of attack results in a large amount of excess noise.
[0163] - Error Detection / Correction Attack: Eve can perform ideal stabilizer measurements on an intercepted logical qubit state undetected, as this process does not alter the logical qubit state by design. Eve can also decode and recode the logical state (provided Eve is capable of performing approximately ideal quantum gate operations). However, Eve cannot measure the decoded state in the physical X / Z basis or alternatively with logical operators without affecting Bob's measurement probability distributions.
[0164] - Fake State Attack: Eve gains access to the mechanism Bob uses to generate random measurement bases. Eve causes Bob to use predetermined bases, allowing her to extract the key undetected.
[0165] - Commitment attack: The binding to the sent message is undermined by Alice changing her qubit state after she has already sent it to Bob. Since Bob only has access to his share and the protocol is supposed to be secure against Eve, the hiding property Ti^G 'oX 'ol) =
[0166]
[0167] , where bit values b G {0,1} correspond to the transmitted quantum states I 'o) respectively. Then there is a communication-Boehmert & Boehmert
[0168] - 21 -
[0169] soperation according to a unitary mapping such that (U A ® IB) O) = I 'i). which Alice can use to change her state after sending it to Bob. - PCCM attack: Although perfect cloning of unknown quantum states is physically impossible, a limited set of possible quantum states can be imperfectly cloned with finite fidelity. In practice, Eve can use a phase-covariant quantum cloning machine (PCCM), which allows him to create imperfect copies of, say, BB84 states. If the noise generated by the copying is effectively indistinguishable from the noisy quantum communication channel, eavesdropping on Alice and Bob can succeed undetected.
[0170] Figure 4 shows a schematic representation of a quantum circuit for an exemplary PCCM attack on a BB84 protocol. The upper line 40 corresponds to a qubit of Bob and the lower line 41 to a qubit of Eve. First, the quantum gate R x Neglected and a = n assumed. Eve's qubit is flipped when Bob's qubit is in state |1). Previously in state 10), Eve's state will now trigger a conditional feedback on Bob's qubit via the second two-qubit gate, flipping Bob's qubit again. The two quantum gates cause Bob's qubit to be flipped from |1) to |0) or remain in |0). The angle a determines the strength of the flip. The quantum circuit creates an imperfect copy of Bob's state for both Bob and Eve, as long as Bob's state lies on the equator of the Bloch sphere. The additional one-qubit gates R x Rotate this set of states by 90° so that the BB84 states |0>, 1>, |+) and ) can be copied instead. Optimal copying can be achieved with a = n / 2, resulting in separable states for all four inputs and local fidelity of F. B = F E "85% achieved. When er = 0, no cloning takes place, and when a = n, the states of Bob and Eve are perfectly swapped."
[0171] Three approaches are possible by which the preceding process can be reversed and the original states restored, allowing Eve to erase its traces. It should be noted that the relative phase of a quantum state on the equator of the Bloch sphere remains unchanged due to amplitude damping. This phase could be estimated by a suitable quantum algorithm, and Eve could then re-emit a suitable one-qubit basis state after the measurement. There is no single operation that accomplishes this task; however, BOEHMERT & BOEHMERT
[0172] - 22 -
[0173] No no-go theorems are known that would prevent this when dissipative circuit elements are used. Another possibility would be to reverse the amplitude attenuation through an (optical) pumping process. Finally, E could use a "1 N + 1" PCCM, which generates N copies of Bob's state with lower optimal fidelity than in the "1 2" case. However, Eve can encode the copies into an N-qubit repeat code to further reduce the error rate, since the repeat code threshold is equal to p. th = 1 / 2. Using simulation, it is conceivable to determine an optimal value of the angle / clone parameter a for a specific noisy real device, for example in a hybrid quantum-classical optimization method.
[0174] Since the noise expected in a currently available NISQ (noisy intermediate-scale quantum) device is sufficiently low, a classical error correction code can be used for information matching.
[0175] One advantage of simulating QKD protocols is that actual key bits for all three parties, Alice, Bob, and Eve, can be obtained. Thus, there is no limitation to abstract mathematical statements about QKD security, such as reconstructed mutual information, but rather extracted key bits can be directly compared. In particular, the proposed additivity of / eavesdropped can be demonstrated. ur| d / reconciliation ' n This can be tested in practice. With fidelity levels of 85% to 87%, it can be assumed that approximately 10 extracted data points correspond to one error bar. 4 Shots are required that can be safely performed with current hardware.
[0176] The noise of particle-trap quantum processors 14 differs from the noise encountered in real-world QKD scenarios where photonic qubits are transmitted over optical fibers and detected using single-photon detectors. Given the long coherence times and high gate and detection fidelity of ion-trap qubits, additional errors regularly need to be introduced to achieve a realistic simulation of photon QKD setups. Since circuits used to implement simple QKD protocols typically require only a few qubits and a shallow gate depth, native decoherence rates and gate errors will have little impact. While typical gate, shuttle, and readout timescales range from 10 ps to 100 ps, decoherence timescales on the order of seconds or longer can be achieved with ion qubits.Furthermore, state-of-the-art ion quantum processors achieve gate and read error rates on the order of 10. -3 per operation. In contrast, QKD-BOEHMERT & BOEHMERT suffer
[0177] - 23 -
[0178] Setups are primarily subject to photon loss during transmission and the limited quantum efficiency of single-photon detectors. The best single-photon detectors currently achieve a detection efficiency of approximately 98% at telecommunications wavelengths. To realistically simulate a QKD protocol, such errors must be injected regularly. A simple way to do this would be a probabilistic post-processing stage where readout statistics are modified to model qubit loss. At the physical level, such errors can be injected into metastable states by controlled pumping of the population from the subspace encoding the qubit, either after the protocol stages related to qubit transmission or before readout.
[0179] Since the circuit depth achievable on NISQ devices is generally limited by physical operational fidelities, quantum error correction must be employed to suppress the noise to a level required for approximately the Shor algorithm, which runs on IO. -10 up to 10 -14 is estimated. Quantum error correction codes (or codes for short) make it possible to encode k < n logical qubits using a number n of physical qubits, which are protected from errors by a spacing d of the code. By taking the
[0180]
[0181] By increasing the distance of the code, a quantum computation can, in principle, be sustained indefinitely. A characteristic value of quantum error correction codes is their threshold, which specifies an error rate p below which the use of the code actually improves the performance of the qubits at the extremes of large distances. For codes such as surface codes, color codes, or qLDPC codes (geometrically local stabilizer code), the thresholds are typically around p. th « 10 -4 — 10 -3 To ensure that the overhead of quantum error correction codes actually improves the performance of logic qubits compared to physical qubits, careful design of all quantum circuits is required. A fault-tolerant circuit design ensures that t errors occurring to a logic qubit during storage or computation can never lead to a logic failure, and thus provides a set of tools for systematically reducing noise, despite the typically larger number of noisy operations in such quantum circuits. Fault-tolerant quantum computing (FTQC), for example, operating at a fault tolerance level of t = 3, should be able to handle a physical error rate of p = 10⁻¹⁰. -4 to a logical error rate p L = 풪(p t+1 ) = Ö(p 4 ) = c ■ 10 -16 to suppress, where the proportionality constant c can be very large, depending on the qubit and quantum gate overhead of the error tolerance. BOEHMERT & BOEHMERT
[0182] - 24 -
[0183] If Alice and Bob have NISQ devices available as part of their quantum communication devices 30, 31, this means that the overall failure rate of their quantum circuits depends linearly on the error rates of the physical operations, p L ~ p for p 0. In a scenario where Eve is able to operate a fault-tolerant quantum communication device 33 at fault tolerance level t, its communication operations will have an error rate p L ~ p t+1 This was performed at low physical error rates. In this situation, Eve should be able to systematically reduce the influence of her actions on the transmitted state so that they are indistinguishable from noise to Alice and Bob.
[0184] If all communication operations are performed fault-tolerantly on logical qubits and at a rate of p L The attack can fail if Eve intercepts a qubit, decodes it, and performs a PCCM attack. The error rate of the physical qubit is p. The PCCM attack reduces the fidelity to F. B = -(1 + cos er) lowered and a copy with a fidelity of F E = -(1 + sin er) generates. Eve can generate the infidelity 1 — F B Eve can further reduce the error rate by performing fault-tolerant coding to lower the original error rate p. L to be accessed again unnoticed. For example, when using a Steane code, a logical qubit can be accessed with p. L « 10 -4 for a physical error rate p2« 2 x 10 -3 for entanglement gates, which can be better than error rates pt = 3 x 10 -3 during the initialization of physical qubit states. However, for such low error rates, F E Only about 55% is expected. With a physical error rate of 10%, Eve has a fidelity of F. E = 80%. In practice, Eve would be best advised to wait until the bases are revealed. She could use a fault-tolerant quantum memory to store the qubit until she can measure it. However, if Eve has a NISQ device, such an attack is difficult, as the encoding does not improve the error rate.
[0185] Methods for simulating quantum communication processes
[0186] The general sequence of the proposed procedure is described below. Fig. 5 shows a corresponding schematic flowchart. In a first step 51, the quantum communication information for the quantum communication process to be simulated between at least one first quantum communication device 30, a second quantum communication device 31, and an eavesdropping device 33 is provided in the data processing unit 10 via at least one quantum channel 32. BOEHMERT & BOEHMERT
[0187] - 25 -
[0188] The quantum communication information can, for example, include a quantum circuit specifying the first quantum communication device 30, the second quantum communication device 31, and the listening device 33. For example, the quantum circuit can include first (quantum) communication operations of the first quantum communication device 30, second communication operations of the second quantum communication device 31, and third communication operations of the listening device 33. The first, second, and third communication operations can each correspond to quantum gates. The quantum circuit can also include at least one quantum channel and / or specify on which the first, second, and / or third communication operations (or their quantum gates) are applied.
[0189] In a second step 52, control data for the quantum processor 14 are determined in the data processing unit from the quantum communication information. This processor applies quantum operations to quantum particles (ions or neutral atoms) that are spatially controllable within several operational domains 21. The control data can be determined, for example, by means of one or more successive compilation processes.
[0190] In a third step 53, the quantum communication process is simulated in the quantum processor 14 using the control data. Here, each quantum bit of the quantum communication process is assigned to one of the quantum particles. Furthermore, communication operations of the quantum communication process each correspond to at least one of the quantum operations, wherein the quantum operations include at least one first quantum operation for the first quantum communication device 30, at least one second quantum operation for the second quantum communication device 31, and at least one third quantum operation for the listening device 33. Additionally, a noise event during the quantum communication process corresponds to at least one further quantum operation, which is controlled using a noise model.
[0191] In a fourth step (54), the quantum communication process can be adjusted based on the simulation. Specifically, the quantum communication information (e.g., parameters of the quantum communication information) can be adjusted based on a simulation result. The preceding steps (51 to 54) can be repeated until, for example, a predetermined goodness-of-fit measure for the BOEHMERT & BOEHMERT
[0192] - 26 -
[0193] Quantum communication has been achieved through simulation.
[0194] The following section describes in detail the simulation of specific quantum key exchange protocols.
[0195] Figure 6 shows a schematic representation of the BB84 protocol as a quantum circuit underlying the simulation (a). In the first quantum communication device 30, a first qubit 60 – which corresponds to a first quantum particle 60a in the quantum processor 14 – is adapted by means of initial communication operations: First, depending on the bit value v A of a classic information bit string an X gate 61 and then depending on the bit value b A A Hadamard gate 62 is applied to a classical basic bit string. Subsequently, the listening device 33 applies third communication operations, in particular a cloning gate 64, to the first qubit 60 together with a second qubit 63 – which corresponds to a second quantum particle 63a in the quantum processor 14. In this way, an imperfect copy of the first qubit 60 is created from the second qubit 63. A detailed view of an embodiment of the cloning gate 64 is shown in partial view (b) of Fig. 6. One of the qubits 60, 61 is forwarded to the second quantum communication device 31, which takes control of the processing zone. Before each of the 31 measurement operations, the second quantum communication device 31 and the listening device 33 each apply Hadamard gates 65, 66.In the subsequent post-processing, the data that would be sent in a real-world implementation is considered available to all parties. Potential transmission errors along a noisy quantum channel, as well as preparation and readout errors exceeding native error rates, can be appropriately simulated.
[0196] Fig. 7 shows a schematic representation of steps 71 to 74 during the simulation of the BB84 protocol in the quantum processor 14. In a first step 71, at the time of the execution of the first communication operations (X gate 61, Hadamard gate 62), the first quantum particle 60a, which corresponds to the first qubit 60, is located in an active operating region 75. At the same time, the second quantum particle 63a, which corresponds to the second qubit 63, is located outside the active operating region 75 in an inactive operating region 76. Quantum operations in the active operating region 75 take place by means of laser excitation 77.
[0197] In a second step 72, at the time of the execution of the cloning gate 64, which represents a 2-qubit gate, the first quantum particle 60a and BOEHMERT & BOEHMERT are located
[0198] - 27 -
[0199] The second quantum particle 63a is in the active operating region 75. In a third step 73, the Hadamard gate 66 is applied to the first qubit 60 by the listening device 33 - accordingly, the first quantum particle 60a is in the active operating region 75 and the second quantum particle 63a is outside.
[0200] In a fourth step 74, the Hadamard gate 65 of the second quantum communication device 31 is applied to the second qubit 63. Consequently, the second quantum particle 63a is located in the active operating region 75 and the first quantum particle 60a is outside of it.
[0201] Figure 8 shows a diagram of control instructions during the simulation of the BB84 protocol. The spatial positions (sequential memory segment number) of the involved quantum particles 60a and 63a are plotted as a function of time. Line 80 corresponds to the first quantum particle 60a (qubit q_0), and line 81 to the second quantum particle 63a (qubit q_1). Memory segment 19 is located within the active operating region 75, while memory segment 25 is located outside of the active operating region 75.
[0202] Individual quantum operations in trap 20 are marked by vertical stripes and labeled on the x-axis. Quantum operations in a first area 82 correspond to first quantum operations (by Alice); quantum operations in second areas 83 correspond to second quantum operations (by Bob); quantum operations in a third area 84 correspond to third quantum operations (by Eve). The OpticalPump quantum operation in area 85 is another quantum operation, corresponding to a noise process. Various noise sources (error sources) can be simulated: qubit errors due to quantum gates, depolarization errors due to unwanted collisions, qubit loss, vacuum loss, or side-channel attack (e.g., a malfunctioning random number generator for choosing the basis in the first quantum communication device 30).
[0203] The quantum operations marked with R are rotation operations. For example, RY(q_0, I. OOTT) corresponds to a Y-rotation of the first qubit 60 by the angle n.
[0204] According to step 71 in Fig. 7, in region 82 the first quantum particle 60a is located in memory segment 19 within the active operating region 75, and the second quantum particle 63a is located in memory segment 25 outside the active operating region 75. Within the second region 84 are the quantum particle 60a and the second BOEHMERT & BOEHMERT
[0205] - 28 -
[0206] Quantum particle 63a for certain quantum operations simultaneously in memory segment 19 (see step 72 in Fig. 7).
[0207] Another quantum circuit for the BB84 protocol, using an asymmetric cloning operation for cloning gate 64, is shown in Fig. 9. A 25% X-error is applied to the line between Alice and Bob before the asymmetric cloning operation is performed.
[0208] Figure 10 shows a plot illustrating the goodness of fit of the simulation of the BB84 protocol using an ion-trap quantum processor 14. The y-axis represents the success probability for Eve: the similarity C AE Eve's key and Alice's key. The similarity C is found on the x-axis. AB between Alice's key and Bob's key. The goal here is maximum similarity between Alice / Bob and maximum similarity between Alice / Eve. Similarity with Alice is sufficient to know the overall key, as it must be the same for both Alice and Bob. At the same time, Alice's key can often be considered a reference, while Bob's key may contain errors, requiring Bob to perform error correction. Thus, Alice can be viewed as the server and Bob as the client, who can query the server regarding the key's characteristics. The different value groups 101, 102, and 103 correspond to the attack strength with respect to a specific choice of Alice / Bob's base (Z - 101 or X - 103). The (radial) middle value group 102 corresponds to the average of value groups 101 and 103 and thus represents the overall attack strength.The asymmetric cloner can attack states in the X basis more effectively than states in the Z basis, which in this case is due to the additional X error. The results of the ion trap simulation are as expected.
[0209] In an alternative configuration, attacks on QKD protocols can also be carried out using multiple active operational domains. In particular, the various quantum communication devices 30, 31, 33 involved in the protocol can also be represented spatially separated within trap 20.
[0210] Fig. 11 shows a corresponding schematic representation of the BB84 protocol based on the trap 20 when using several active operational areas, namely a first operational area 115, which is assigned to the first quantum communication device 30 and thus to the first quantum operations, a second operational area 116, which is assigned to the second quantum communication device 31 and thus to the second quantum operations, and a third operational area 117, the listening device 33 and thus to the BOEHMERT & BOEHMERT
[0211] - 29 -
[0212] The third quantum operation is assigned. Steps 111, 112, 113 and 114 correspond to steps 71, 72, 73 and 74 from Fig. 7. The execution of a quantum operation is indicated by double arrows 118.
[0213] By using multiple active operating areas, which are spatially separated, more complex protocols can be simulated. Furthermore, crosstalk noise is reduced, resulting in a lower probability of errors during simulation.
[0214] As an alternative to the BB84 protocol, attacks on protocols such as the E91 protocol can also be simulated. Figure 12 shows a schematic representation of the E91 protocol as a quantum circuit. In the first quantum communication device 30, a first qubit 121 and a second qubit 122 are connected by quantum gate 123 in a first communication operation. + ) entangled. The qubit intended to be sent to the second quantum communication device 31 is intercepted by the listening device 33, which performs a cloning gate 124 using a third qubit 125. One of the cloned qubits is forwarded to the second quantum communication device 31, which is in basis b B measures, while the first quantum communication device 30 in the basis b A measures. Then b A and b B in the listening device 33 and used for corresponding measurements. In the simulation, the first, second and third qubits 121, 122 and 125 correspond to a first, second and third quantum particle 121a, 122a and 125, respectively.
[0215] 125a.
[0216] The corresponding simulation of the E91 protocol in a trap 20 is schematically illustrated in Fig. 13 with reference to steps 131, 132, 133, 134, and 135. Quantum operations take place only in a single active operation region 75. Unaffected quantum particles remain outside in an inactive operation region 76. An alternative setup with first quantum operations in a first operation region 115, second quantum operations in a second operation region 116, and third quantum operations in a third operation region 117 in steps 141, 142, 143, and 144 is shown in Fig. 14.
[0217] The features disclosed in the foregoing description, the claims and the drawing can be important for the realization of the various embodiments, both individually and in any combination.
Claims
Bundesdruckerei GmbH et al. B89592WO Claims 1. Method for simulating a quantum communication process, comprising the following steps: - Providing, in a data processing unit (10), quantum communication information for at least one quantum communication process to be simulated between at least a first quantum communication device (30), a second quantum communication device (31) and an eavesdropping device (33) via at least one quantum channel (32); - Determine, in the data processing unit (10) and from the quantum communication information, control data for a quantum processor (14) in which quantum operations are applied to quantum particles that are ions or neutral atoms and that are spatially controllable within several operational domains (21); and - Simulating the quantum communication process in the quantum processor (14) using the control data, wherein: - each quantum bit of the quantum communication process is assigned to one of the quantum particles, - Communication operations of the quantum communication process each correspond to at least one of the quantum operations, wherein the quantum operations include at least one first quantum operation for the first quantum communication device (30), at least one second quantum operation for the second quantum communication device (31) and at least one third quantum operation for the listening device (33), and - a noise process during the quantum communication process corresponds to at least one other of the quantum operations.
2. The method of claim 1, wherein: - the first quantum operation, the second quantum operation and the third quantum operation are performed on the quantum particles in a single active operation area (75) and - another quantum particle, for which no action of any of the quantum operations is planned at a given time, is spatially located outside the active operational area (75).
3. Method according to claim 1, wherein: - the first quantum operation in a first operational domain (115), the second BOEHMERT & BOEHMERT - 2 - The quantum operation is performed in a second operational domain (116) and the third quantum operation in a third operational domain (117) and - the first operating area (115), the second operating area (116) and the third operating area (117) are formed separately from each other.
4. Method according to at least one of the preceding claims, wherein the quantum communication process comprises a quantum key exchange protocol, preferably one of BB84, E91 and BBM92.
5. Method according to at least one of the preceding claims, wherein the quantum communication process comprises a further quantum communication device and the quantum operations comprise at least a fourth quantum operation for the further quantum communication device.
6. Method according to at least one of the preceding claims, wherein, when simulating the quantum communication process, at least one of the following attacks is simulated in the quantum processor: Denial-of-service attack, photon splitting attack, light injection attack, fake source attack, qubit interception attack, error correction attack, fake state attack, commitment attack and attack with phase-covariant quantum cloning machine.
7. Method according to at least one of the preceding claims, wherein the noise process comprises at least one of the following: qubit error due to quantum gates, depolarization error due to unwanted collisions, qubit loss, vacuum loss and disturbed random number generator for base selection.
8. Method according to at least one of the preceding claims, wherein in the quantum communication process quantum states are encoded by means of a quantum error correction code and in the simulation of the quantum communication process encoding quantum operations are performed which correspond to encoding quantum gates.
9. Method according to at least one of the preceding claims, further comprising: - Adapting quantum communication information based on a simulation result from the simulation and - Repeating the determination of the control data, the simulation of the quantum BOEHMERT & BOEHMERT - 3 - communication process and the adjustment of the quantum communication information until a predetermined measure of quality for the quantum communication process is achieved.
10. System for simulating a quantum communication process, comprising a data processing unit and a quantum processor and configured to execute the method according to at least one of the preceding claims.