Quantum key distribution system
Patent Information
- Application Number
- PCT/JP2025/005809
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2026-08-27
Smart Images

Figure JP2025005809_27082026_PF_FP_ABST
Abstract
Description
Quantum key distribution system
[0001] This disclosure relates to a quantum key distribution system.
[0002] Research and development are underway on quantum key distribution (QKD), a method for securely supplying secret keys for symmetric-key cryptographic communication to two distant parties based on the principles of quantum mechanics. While there are several QKD schemes, the "Sending-or-Not-Sending Twin-Field QKD (SNS-TF-QKD)" scheme, which is mainly used in long-distance QKD transmission experiments, is well known (see, for example, Non-Patent Document 1).
[0003] Figure 1 shows a schematic configuration of a conventional SNS-TF-QKD system. In this specification, following conventional practice, the two parties who share the key are referred to as Alice and Bob, and the third party who acts as an intermediary in key sharing between them is referred to as Charlie. As shown in Figure 1, the SNS-TF-QKD system 100 has key sharing nodes 110a and 110b used by the two parties (Alice and Bob) who share the secret key, and an intermediary node 130 used by the intermediary (Charlie).
[0004] The key sharing node 110a (110b) includes a coherent pulse light source 111a (111a) that generates coherent pulse light, an optical phase modulator (PM) 112a (112b) that randomly assigns phase to the coherent pulse light, an optical intensity modulator (IM) 113a (113b) that modulates the intensity of the phase-assigned coherent pulse light, and an attenuator 114a (114b) that attenuates the phase-assigned and intensity-modulated coherent pulse light. The phase-assigned, intensity-modulated and attenuated coherent pulse light is transmitted from the key sharing node 110a (110b) as weak coherent pulse light.
[0005] The intermediary node 130 has a two-input, two-output beamsplitter (BS) 131 and photon detectors 132 and 133 provided at each of the two outputs of the BS 131.
[0006] In the SNS-TF-QKD system 100 shown in FIG. 1, signal lights (weak coherent pulse lights) are respectively sent from Alice and Bob to Charlie, and Charlie combines the sent signal lights by a 2-input 2-output beam splitter and performs photon detection. Using such a system configuration, Alice and Bob share a secure secret key. In system 100, since the physical distance between Alice and Bob is twice the transmission distance of the signal light, it is a QKD method suitable for increasing the key distribution distance (distance between Alice and Bob). Here, the "secure secret key" means a secret key that is secure not only against external eavesdroppers but also against Charlie, that is, a secret key that is concealed even from Charlie who acts as an intermediary.
[0007] Using the configuration shown in FIG. 1, Alice and Bob share a secret key by the following procedure. (1) Alice and Bob send weak coherent pulse lights with random phases and light intensities ( = average photon numbers) of 0 (zero) or μ x or μ y or μ z (where 0 < μ x , μ y , μ z < 1) to Charlie. The state where the transmission light intensity is zero means that the weak coherent pulse light is not transmitted from the key sharing node.
[0008] (2) Charlie combines the received weak coherent pulse light using a 2-input 2-output beam splitter 131, and detects photons using photon detectors 132 and 133 provided at the two output ends. At the beam splitter 131, the weak coherent pulse lights from Alice and Bob interfere with each other, and photons are detected by the two photon detectors 132 and 133 according to the phase difference between them. Here, if the phase difference of the weak coherent pulse light at the time of transmission by Alice and Bob is 0, photons are detected by the detector 132, and if it is π, photons are detected by the detector 133. Adjust the transmission phases from Alice and Charlie and from Bob to Charlie so that photons are detected respectively. Under this condition, when the phase difference of the weak coherent pulse light at the time of transmission by Alice and Bob is other than {0, π}, photons are probabilistically detected by the photon detector 132 or the photon detector 133 according to the probability determined by the phase difference. Note that since the average photon number of the weak coherent pulse light is less than 1 by the attenuators 113a and 113b, it is rare for photons to be detected.
[0009] (3) Charlie notifies Alice and Bob of the photon detection result (whether photons are detected or not and by which photon detector photons are detected).
[0010] (4) When only one of the photon detectors, photon detector 132 or photon detector 133, detects a photon, Alice and Bob generate bits from the transmission status of their own weak coherent pulsed light as follows: Alice generates {bit 0 if not transmitting, bit 1 if transmitting}. Bob generates {bit 1 if not transmitting, bit 0 if transmitting}. Here, there are four patterns in which only one of the photon detectors detects a photon: (i) {Alice transmits, Bob does not transmit}, (ii) {Alice does not transmit, Bob transmits}, (iii) both Alice and Bob transmit, but a photon is detected by only one of the two photon detectors due to interference or a small number of received average photons, and (iv) both Alice and Bob do not transmit, but a photon detection is output due to a malfunction of the photon detector (dark count). The bits generated by Alice and Bob will match in patterns (i) and (ii), but will not match in patterns (iii) and (iv). Furthermore, the generated bit value is determined by the transmission status (transmission or non-transmission) of Alice and Bob's weak coherent pulsed light, and this information is not known to the outside world, so it is kept secret from everyone, including Charlie.
[0011] (5) After repeating steps (1) to (4) above to generate a bit sequence, the generated bit sequence is subjected to error correction. The error-corrected bit sequence is used as the corrected secret key. Note that this error correction is performed by exchanging the necessary information between Alice and Bob via a normal communication channel (also called a classical channel). Therefore, there is a possibility that the amount of information used for error correction may be leaked.
[0012] Next, Alice and Bob verify the possibility that the generated correction key has been intercepted as follows: (6) Alice and Bob inform each other of the average number of photons in the weak coherent pulse light that did not result in photon detection in step (3), and the average number of photons in the weak coherent pulse light that resulted in a bit error in step (5).
[0013] (7) For time slots in step (6) during the information exchange where either Alice or Bob did not transmit, verify whether the number of photon detections is consistent with the statistics obtained when receiving a weak coherent pulse of light with an average number of photons (= T × μ (where T is the transmission path transmittance and μ is the light intensity at the time of transmission)). This verification method is called the decoy method and is a widely used eavesdropping detection method in QKD using coherent light pulses, as a means of detecting eavesdropping methods that detect the number of photons of weak coherent pulses of light by quantum nondestructive measurement and extract a specific number of photons from it.
[0014] (8) Of the bits generated in step (4), the bits generated from patterns (iii) and (iv) are error bits, and in step (6), the average number of photons involved in the received event is disclosed. Alice and Bob extract the transmitted pulse information for this received event in which the average number of transmitted photons was the same, and further notify each other of the pulse light phase at that time. Then, for photon detection events in which the phases of their weak coherent pulse light match, Charlie verifies whether a predetermined interference occurred in his beam splitter. This detects an eavesdropping method in which the malicious Charlie individually measures Alice and Bob's non-weak coherent pulse light and notifies them of falsified photon detection information based on the measurement results.
[0015] (9) Based on the verification results of steps (7) and (8), the likelihood of eavesdropping is quantitatively estimated, and the amount of leakage and the amount of information that may have been leaked during the error correction process in step (5) are excluded from the correction key generated in step (5) by a data compression method called confidentiality enhancement. This obtains a secure private key. The above describes the configuration and private key generation procedure of SNS-TF-QKD.
[0016] Xiang-Bin Wang, Zong-Wen Yu and Xiao-Long Hu, “Twin-field quantum key distribution with large misalignment error,” Phys. Rev. A 98, 062323 (2018)A. Chefles and S. Barnett, “Optimum unambiguous discrimination between linearly independent symmetric states,” Physics Letter A, vol. 250, pp. 223-229 (1998)
[0017] In the conventional SNS-TF-QKD system described above, information exchange and data processing from step (6) onward are performed to verify the amount of information leakage of the corrected secret key once it has been generated. To this end, Alice and Bob randomly modulate the phase of the coherent light pulse using the light intensity modulator 112 and four-level modulated the light intensity of the coherent light pulse using the light intensity modulator 113 before transmitting it. Subsequently, they extract received events in which the phase and light intensity of the transmitted coherent light pulse match. These means for modulating the coherent light pulse and data processing are provided to prevent eavesdropping by Charlie, and therefore the configuration of the key sharing node and the secret key generation procedure are complicated. In addition, it is necessary to send and receive weak coherent light pulses many times in order to obtain received events in which the phase and light intensity match, and it takes a long time to finally obtain the secret key.
[0018] This disclosure is made in view of the above issues and aims to provide a quantum key distribution device that enables longer key distribution distances by having Alice and Bob transmit signal light to Charlie, who is located midway between them, and generates a secret key that is hidden from malicious Charlie, using a simpler device configuration and procedure than the prior art.
[0019] To achieve this objective, one embodiment of the present disclosure is a quantum key distribution system that supplies a secret key for symmetric-key cryptographic communication to two key-sharing nodes. The quantum key distribution system comprises two key-sharing nodes and an intermediary node positioned between the two key-sharing nodes. The two key-sharing nodes are configured to transmit a continuous coherent pulse train at constant time intervals to the intermediary node, each pulse of the continuous coherent pulse train having a phase randomly selected from 0 or π / 2 or π or 3π / 2 applied to it, with an average number of photons per pulse being less than 1. The intermediary node comprises a delayed Mach-Zehnder interferometer (MZI) having two inputs and two outputs, wherein the delay time is equal to the time interval of the continuous coherent pulse train, and the light resulting from the interference of the continuous coherent pulse trains from the two key-sharing nodes input from the two inputs is output from the two outputs, and two photon detectors positioned at the two outputs of the delayed MZI. The intermediary node is further configured to notify the two key-sharing nodes of the time when a photon was detected by the photon detector and the photon detector that detected the photon. The two key-sharing nodes are further configured to notify each other of the phase applied to the first pulse of the two consecutive pulses resulting from the photon detection notified by the intermediary node, from the continuous coherent pulse train transmitted to the intermediary node, and to generate key bits based on (a) the photon detector that detected the photon notified by the intermediary node, (b) the phase applied to the first pulse, and (c) the phase applied to the second pulse of the two consecutive pulses resulting from the photon detection notified by the intermediary node.
[0020] As described above, according to one embodiment of the present disclosure, a simple quantum key distribution system can be provided that enables long-distance key distribution. The secret key generated by the quantum key distribution system of one embodiment of the present disclosure is kept confidential even from intermediaries.
[0021] This figure shows the schematic configuration of a conventional SNS-TF-QKD system. This figure shows the schematic configuration of a quantum key distribution system according to one embodiment of this disclosure. This figure shows the schematic configuration of a key sharing node in a quantum key distribution system according to one embodiment of this disclosure. This figure shows the schematic configuration of an intermediary node in a quantum key distribution system according to one embodiment of this disclosure. This figure shows the schematic configuration of an eavesdropping node for a quantum key distribution system according to one embodiment of this disclosure. This figure shows the USD success probability for a coherent state with a phase of 0 or π / 2 or π or 3π / 2. This figure shows the schematic configuration of an eavesdropping node for a quantum key distribution system according to one embodiment of this disclosure. This figure shows the schematic configuration of the control devices for the key sharing node and intermediary node of a quantum key distribution system according to one embodiment of this disclosure. This figure shows the flow of the secret key generation method in a quantum key distribution system according to one embodiment of this disclosure.
[0022] Embodiments of this disclosure will be described in detail below with reference to the drawings. Identical or similar reference numerals indicate identical or similar elements, and repeated descriptions may be omitted. The numerical values shown below are illustrative, and it goes without saying that embodiments of this disclosure can be implemented with other numerical values without departing from the spirit of the work.
[0023] Figure 2A is a schematic diagram of a quantum key distribution system according to one embodiment of the present disclosure. The quantum key distribution system 200 has key sharing nodes 210a and 210b used by Alice and Bob, who share a secret key for symmetric-key cryptographic communication, and an intermediary node 130 used by an intermediary (Charlie). Similar to the prior art described with reference to Figure 1, the quantum key distribution system 200 is configured such that Alice and Bob each transmit signal light (coherent pulse light) to Charlie, who is located at an intermediate point, and Charlie receives the signal light from both of them combined. The transmission distance and propagation phase from Alice to Charlie and from Bob to Charlie are adjusted to be the same.
[0024] Figure 2B shows the configuration of the key sharing node used by Alice and Bob. The key sharing node 210 shown in Figure 2B includes a coherent pulse light source 211 that generates coherent pulses, an optical phase modulator (PM) 212 that randomly assigns phase to the coherent pulse light, an attenuator 214 that attenuates the phase-assigned coherent pulse light, and a control device 215. Unlike the key sharing nodes 110a and 110b described with reference to Figure 1, the key sharing node 210 (210a and 210b) does not have an optical intensity modulator (IM) that modulates the intensity of the phase-assigned coherent pulse.
[0025] The coherent pulse light source 211 is configured to generate a continuous pulse train at regular time intervals. Each pulse in the continuous pulse train is coherent pulse light.
[0026] The optical phase modulator (PM) 212 is configured to impart a randomly selected phase of 0, π / 2, π, or 3 / 2π to each coherent pulse of light, according to instructions from the control device 215. In this specification, this may also be referred to as the phase modulation phase imparted to each coherent pulse of light by the optical phase modulator 212.
[0027] The attenuator 214 is configured to attenuate the phase-modulated coherent pulsed light in the phase-modulated continuous pulse train to an average of less than 1 photon / pulse before transmission. The key sharing node 210a used by Alice and the key sharing node 210b used by Bob are configured to transmit a constant and equal average number of photons. The continuous pulse trains transmitted by Alice and Bob are transmitted to and received by Charlie.
[0028] Figure 2C shows the configuration of the intermediary node used by Charlie. The intermediary node 230 shown in Figure 2C includes a delayed Mach-Zehnder interferometer (MZI) 231, photon detectors D1 236 and D2 237, and a control device 238.
[0029] The delay MZI231 has two splitters 232 and 233, and two mirrors 234 and 235. The two mirrors 234 and 235 are positioned in one of the two optical paths formed between splitter 232 and splitter 233. Nothing is positioned in the other of the two optical paths between splitter 234 and splitter 235. The optical path in which the two mirrors 234 and 235 are positioned is called the long path, and the optical path in which nothing is positioned is called the short path. The difference in optical path length between the long path and the short path is equivalent to a certain time interval between adjacent pulses in the continuous pulse train transmitted from the key sharing node 210. That is, the delay time caused by the difference in optical path length is equal to the time interval between adjacent pulses in the continuous pulse train, and the propagation phase difference is an integer multiple of 2π.
[0030] The two inputs of the splitter 234 are each input to a continuous pulse train from key sharing nodes 210a and 210b, respectively. A mirror 234, which is located on a long path, is placed on one of the two outputs of the splitter 234, and a splitter 233 is placed on the other output.
[0031] Light propagating along the long and short paths is input to the two inputs of the splitter 233. Photon detectors D1 236 and D2 237 are connected to the two outputs of the splitter 233, respectively.
[0032] The control device 238 is configured to receive the outputs of photon detectors D1 236 and D2 237 via signal line 239. The control device 238 is also configured to transmit information to key sharing nodes 210a and 210b via signal line 251.
[0033] Charlie inputs the continuous pulse trains from Alice and Bob to the two inputs of the delay MZI231 at the same time. In this configuration, the splitter 234 of the delay MZI231 overlaps and interferes with four pulses, namely Alice's two adjacent pulses and Bob's two adjacent pulses. Photon detectors D1 236 and D2 237 detect photons according to the relative phase of the four overlapping pulses.
[0034] Here, the state of interference of the overlapping four pulses is explained using equations. The overlapping pulses are the adjacent pulses of Alice and Bob that are input to the delay MZI 231 at the same timing. If these are defined as the first and second pulses of Alice and Bob, the first pulse that has passed through the long path of the delay MZI 231 and the second pulse that has passed through the short path overlap at the splitter 233. If the complex amplitudes of the first and second pulses of Alice at the time of input to the delay MZI 231 are respectively Aexp(iθ a1 ), Aexp(iθ a2 ), and the complex amplitudes of the first and second pulses of Bob are respectively Aexp(iθ b1 ), Aexp(iθ b2 ), then the output light E1 to the photon detector D1 236 and the output light E2 to the photon detector D2 237 are respectively expressed by the following equations (1) and (2).
[0035]
[0036] However, since the propagation lengths from Alice to Charlie and from Bob to Charlie are the same (therefore the propagation losses are the same), the real amplitudes of each pulse are equal and denoted as A. The optical intensity of each pulse is given by A 2 and this corresponds to the average photon number of each pulse.
[0037] Equations (1) and (2) use the phase differences Δθ ab = θ a1 - θ b1 between the first pulse of Alice and the first pulse of Bob, Δθ a = θ a2 - θ a1 between the first pulse of Alice and the second pulse of Alice, and Δθ b = θ b2 - θ b1 between the first pulse of Bob and the second pulse of Bob, and are rewritten as the following equations (3) and (4) respectively.
[0038]
[0039] From this, the light intensities I1 and I2 of the light pulses output to photon detector D1 236 and photon detector D2 237 are expressed as shown in the following equations (5) and (6).
[0040]
[0041] The above equations show that the light intensities I1 and I2 output to photon detectors D1 236 and D2 237 depend on the phase difference of each pulse. Here, since the propagation phases from Alice and Bob to Charlie are adjusted to be equal, the phase of each pulse is the value at the time of transmission, i.e., 0 or π / 2 or π or 3π / 2. Therefore, the phase difference {Δθ} in equations (5) and (6) is ab , Δθ a , Δθ b} is 0 or π / 2 or π or 3π / 2. For example, Δθ ab When = 0, the output light intensities I1 and I2 for each phase difference are as shown in Table 1. In Table 1, μ ≡ A 2 This corresponds to the average number of photons per pulse.
[0042]
[0043] Table 1 shows that there is a combination of phase differences in which the average number of photons output to one photon detector is 2μ and the average number of photons output to the other photodetector is zero. Specifically, {Δθ a = 0, Δθ b = π}{Δθ} a = π / 2, Δθ b = π / 2}{Δθ a = π, Δθ b = 0}{Δθ a = 3π / 2, Δθ b There are four cases where Δθ = 3π / 2. ab Performing similar calculations for Δθ, and extracting and listing the combinations of phase differences where the average output photon count is 2μ and zero for the other, we get Table 2. ab There are four possibilities for Δθ = 0. abThere are four cases for π, for a total of eight cases, where the average number of photons in one output is 2μ and the other is zero. In these combinations of phase differences, photons can be detected by only one of the detectors.
[0044]
[0045] Using the above device configuration and photon detection characteristics, Alice and Bob generate bits according to the following procedure. Specifically, they control and communicate so that the control devices 215 and 238, described later, generate bits according to the following procedure.
[0046] (I) After sending and receiving a continuous pulse train, Charlie notifies Alice and Bob of the time slot in which the photon was detected and the information indicating the photon detector.
[0047] (II) Alice and Bob inform each other of the modulation phase of the first pulse of the two consecutive pulses that caused the photon detection. This determines Δθ ab This becomes clear.
[0048] (III) Alice and Bob identified Δθ in step (II). ab Based on the information from the photon detector notified by Charlie in step (I), and the phase difference of its own two consecutive pulses, the bits are generated as follows:
[0049] (III-a) Δθ ab If = 0 and the photon detector D1 detects a photon, then Alice is Δθ a If = π / 2, then bit 0, Δθ a = 3π / 2 generates bit 1. Bob is Δθ b If = π / 2, then bit 0, Δθ b = 0 generates bit 1. (III-b) Δθ ab If = 0 and detector D2 detects a photon, then Alice is Δθ a If = 0, then bit 0, Δθ a = 3π / 2 generates bit 1. Bob is Δθ b If = π, then bit 0, Δθ b= If 3π / 2, then bit 1 is generated. (III-c) Δθ ab = π and when detector D1 detects a photon, Alice is Δθ a If = π, then bit 0, Δθ a = 3π / 2 generates bit 1. Bob is Δθ b If = 0, then bit 0, Δθ b = If 3π / 2, then bit 1 is generated. (III-d) Δθ ab = π and when detector D2 detects a photon, Alice is Δθ a If = 0, then bit 0, Δθ a = π / 2 generates bit 1. Bob is Δθ b If = π, then bit 0, Δθ b If the result is π / 2, a bit 1 is generated. Otherwise, no bit is generated.
[0050] (IV) Alice and Bob notify each other of how to generate bits according to step (III) in any two consecutive pulses. Then, the bits generated by both Alice and Bob are kept, and the bits generated by only one of Alice or Bob are discarded.
[0051] Based on the photon detection characteristics shown in Table 2, the bit values generated by repeating steps (I) to (IV) above will be the same for Alice and Bob. These will be the secret key bits.
[0052] Next, we will discuss the confidentiality of the generated secret key. In the prior art or embodiments of this disclosure, the most powerful eavesdropper against a system that generates a secret key via Charlie is Charlie, who is capable of photon detection and can manipulate the photon detection results notified to Alice and Bob. The most effective method of eavesdropping on Charlie is considered to be directly measuring the coherent pulsed light transmitted by Alice and Bob at a position close to them, as shown in Figure 3. More specifically, the phase of each coherent pulsed light is directly measured, and the photon detection results that would be obtained if passed through a predetermined interferometer are notified to Alice and Bob. By obtaining accurate measurement results and ensuring that the frequency of notification to Alice and Bob matches the original photon detection probability, the generated bits of Alice and Bob can be obtained without their knowledge.
[0053] To perform such eavesdropping, it is necessary to accurately identify the phases of four coherent pulses of light with a probability consistent with the actual photon detection probability. A quantum-theoretically known measurement method for this purpose is called "Unambiguous State Discrimination (USD)." USD measurement is a quantum mechanical measurement method in which the probability of obtaining a measurement result is less than 1, but the obtained result is infallible. The upper limit of the USD measurement probability for the four states (coherent states with phases of 0, π / 2, π, or 3π / 2) used in this embodiment has been derived quantum-theoretically (see, for example, Non-Patent Document 2).
[0054] Figure 4 shows the upper limit of the success probability of state identification (USD) of coherent pulsed light with an average photon count of μ and a phase of 0, π / 2, π, or 3π / 2, calculated using the formula presented in Non-Patent Literature 2.
[0055] According to the calculation results shown in Figure 4, for example, the USD probability of coherent pulsed light with an average photon count of 0.2 is 10 -3 This is the degree. This is the USD probability for one pulse, so the USD success rate for four pulses is (10 -3 ) 4 = 10 -12This is the result. On the other hand, the average number of photons in an interferometer input pulse in a normal system is (average number of photons transmitted) × (transmission path transmittance). For example, if the average number of photons transmitted = 0.2, the transmission path loss = 0.2 dB / km, and the transmission distance = 500 km, then 0.2 × 10⁻¹⁰ -10 This is the result. According to Table 2, the average number of photons in the interferometer output light at this time is 0.2 × 10⁻⁶. -10 ×2 = 4 × 10 -11 Therefore, the probability of detecting a photon from this is 4 × 10⁻¹⁵, assuming a detection efficiency of 0.25 for the photon detector. -11 ×0.25 = 10 -11 This means that the transmission distance from Alice to Charlie and from Bob to Charlie is 500km, which means the distance between Alice and Bob is 1000km. This key distribution distance is equivalent to the longest record in QKD experiments using the protocol described in the section on conventional technology.
[0056] The expected photon detection rate in this standard system is 10 -11 and 4 pulses USD probability 10 -12 Comparing the two, (USD probability) < (normal photon detection probability). Therefore, Charlie cannot notify Alice and Bob of the photon detection results expected from the USD measurement at a frequency consistent with the photon detection rate in the normal system. In other words, Charlie cannot perform eavesdropping by direct measurement as shown in Figure 3.
[0057] The point that the above eavesdropping method is ineffective is that it generates key bits from the interference of four coherent pulses of light by using a delay interferometer. Therefore, in order to know the key bits, the USD measurement must be performed on four coherent pulses of light. On the other hand, in the case of conventional techniques that generate key bits from the interference of two coherent pulses of light, the above eavesdropping method only requires the USD measurement of two coherent pulses of light. In that case, the USD probability is (10 under the same conditions as in the example above). -3 ) 2 = 10 -6 This is because the photon detection rate is 10 -10 It is sufficiently large, and therefore complete eavesdropping is possible using the above eavesdropping method.
[0058] As described above, the eavesdropping method of notifying Alice and Bob of falsified photon detection information by altering the normal device configuration of the intermediary node 230, as explained with reference to Figure 2C, is not feasible. Therefore, as an alternative eavesdropping method, a method of using the normal device configuration of the intermediary node 230 can be considered. Figure 5 is a diagram of such an eavesdropping method. Charlie, the eavesdropper, is positioned close to Alice and Bob and splits a portion of the coherent pulse light transmitted by each of them using beam splitters 532a and 532b, storing it in memories 532a and 532b, and transmitting the remainder through a lossless transmission path to input to the delay MZI 231. Here, the light intensity of the coherent pulse light split by beam splitters 532a and 532b is set to be the same as the amount lost due to propagation loss in the original transmission path, and the light intensity of the coherent pulse light input to the delay MZI 231 is set to be the same as when there is no eavesdropping. In other words, the light intensity that would be lost in the original transmission path is split by beam splitters 532a and 532b.
[0059] Charlie detects a photon using the light output from the normally delayed MZI231 and notifies Alice and Bob of the result (step (I)). Upon receiving this notification, Alice and Bob communicate to each other (step (II)) the phase of the first pulse of the two consecutive pulses that caused the photon detection. This information exchange takes place over a normal communication channel, so Charlie is also aware of it.
[0060] Charlie then extracts the second pulse of the two consecutive pulses from the signal pulse train stored in memories 532a and 532b, and measures in USD whether its relative phase with the first pulse is 0 or ±π / 2. Once the measurement result is obtained, the bit values of Alice and Bob can be determined.
[0061] However, what Alice and Bob transmit is a continuous pulse train consisting of coherent pulses of light with an average number of photons per pulse of less than 1 and a phase of 0, π / 2, π, or 3π / 2. The USD probability of each pulse in such a continuous pulse train is less than 1, for example, 0.18 for a pulse with an average number of photons of 0.2. Therefore, what is obtained by the beam-split eavesdropping method described above is a portion of the secret key. Some of the eavesdropped amount can be excluded by a data compression operation called confidentiality enhancement, thereby allowing Alice and Bob to obtain a completely confidential secret key.
[0062] Thus, the quantum key distribution system 200 of this embodiment can be said to be secure even against eavesdropping that directly utilizes the configuration of legitimate intermediary nodes.
[0063] Finally, with reference to Figures 6 and 7, the configuration and operation of the control device 215 of the transmitting node 210 and the control device 238 of the intermediary node 230 for carrying out the procedure for generating secret key bits in the quantum key distribution system 200 described above will be explained.
[0064] As shown in Figure 6, the control device 215 and the control device 236 each include a communication device 601, a storage device 602, and a computing device 603 configured to operate together with the communication device 601 and the storage device 602.
[0065] The communication device 601 is a device that communicates with other notebooks via a normal communication channel.
[0066] The storage device 602 can be a hard disk, ROM, or a semiconductor memory such as RAM. The storage device 602 provides an area for storing programs executed by the arithmetic unit 603 and information useful for processing by the arithmetic unit, and an area for recording various data.
[0067] The arithmetic unit 603 can be a general-purpose device that performs various tasks, such as a microprocessor or CPU, or a dedicated device, such as an FPGA or ASIC.
[0068] The arithmetic units 603 of the key sharing nodes 210a and 210b are configured to supply control signals to the phase modulator 212. The control unit 603 is also configured to generate the bits of the secret key.
[0069] Meanwhile, the arithmetic unit 603 of the intermediary node 230 records the time slot in which the photon was detected and the photon detector that detected the photon in the storage device 602 of the intermediary node 230, in response to signals indicating that photons have been detected from the photon detectors D1 234 and D2 235.
[0070] Referring to Figure 7, the procedure for generating the secret key bits in the quantum key distribution system 200 will be described in detail.
[0071] In step 701, the key sharing node 210a used by Alice and the key sharing node 210b used by Bob transmit a continuous pulse train at regular time intervals to the mediating node 230 used by Charlie. The arithmetic units 603 of the key sharing nodes 210a and 210b randomly select a phase (0 or π / 2 or π or 3π / 2) to be applied to the coherent pulse light in each time slot, generate a control signal, and instruct the phase modulator 212 to perform phase modulation. At the same time, the arithmetic units 603 of the key sharing nodes 210a and 210b record the phase applied to the coherent pulse light in each time slot.
[0072] In step 702, the intermediary node 230 used by Charlie interferes adjacent pulses in the continuous pulse train transmitted from key sharing nodes 210a and 210b using a delayed Mach-Zehnder interferometer 231 to detect a photon in the overlap of four pulses using either photon detector D1 236 or photon detector D2 237. The arithmetic unit 603 of the intermediary node 230 records the time slot in which the photon was detected and the photon detector that detected the photon in the storage device 602 of the intermediary node 230 in response to signals from photon detectors D1 234 and D2 235 indicating that a photon has been detected.
[0073] In step 703, the intermediary node 230 transmits information indicating the time slot in which the photon was detected and the photon detector in which the photon was detected to the key sharing nodes 210a and 210b.
[0074] In step 704, the shared node 210a and the key-sharing node 210b notify each other of the modulation phase of the first pulse among adjacent pulses caused by the photon detection, based on the information received from the intermediary node 230 indicating the time slot in which the photon was detected and the photon detector in which the photon was detected. The shared node 210a and the key-sharing node 210b then determine the phase difference (Δθ) between the two first pulses. ab ) is determined. At key sharing nodes 210a and 210b, the arithmetic unit 603 of the control device 215 can obtain information on the modulation phase of the first pulse by referring to the phase assigned to the coherent pulse light in each time slot recorded in the arithmetic unit 603 in step 701.
[0075] In step 705, the shared node 210a and the key sharing node 210b have a phase difference (Δθ) determined in step 704. ab ), the time slot in which the photons transmitted and received in step 703 were detected, and the phase difference (Δθ) between the transmitted consecutive pulses (adjacent pulses). a or Δθ b Bits are generated based on the above. The arithmetic unit 603 of the control device 215 can obtain the phase difference between consecutive pulses (i.e., the difference between the modulation phase of the first pulse caused by photon detection and the modulation phase of the second pulse adjacent to the first pulse) by referring to the phase assigned to the coherent pulse light in each time slot recorded in the arithmetic unit 603 in step 701. The arithmetic unit 603 of the control device 215 can generate bits according to step (III) described above. The arithmetic unit 603 of the control device 215 records the generated bits and information on which of the two consecutive pulses generated the bits in the storage device 602.
[0076] In step 706, the shared node 210a and the key-sharing node 210b notify each other of which of the two consecutive pulses generated the bit. The shared node 210a and the key-sharing node 210b discard the bit generated by only one of the shared nodes. The arithmetic unit 603 of the control device 215 of one of the key-sharing nodes can identify and discard the bit generated by only one of the two key-sharing nodes based on the information of the two consecutive pulses that generated the bit, which was notified by the other key-sharing node.
[0077] In step 707, the shared node 210a and the key-sharing node 210b use the remaining bits from step 706 as the secret key.
[0078] As explained above, the quantum key distribution system of this disclosure is a quantum key distribution method that aims to extend the key distribution distance by having two parties who wish to share a secret key (Alice and Bob) each transmit signal light to a third party (Charlie) located midway between them. The secret key is generated by a procedure that includes (i) sending and receiving signal light (a continuous pulse train consisting of coherent pulsed light), (ii) Charlie notifying Alice and Bob of the received information (photon detection information), and (iii) Alice and Bob exchanging phase information (modulation phase information). On the other hand, in the prior art, information exchange and data processing to verify the security of the key are also performed in addition to the above. The disclosure is a system that can generate a secret key with a simpler procedure than the prior art and shortens the time required to obtain the final secret key. Furthermore, since the quantum key distribution system of this disclosure transmits a quaternary phase-modulated pulse train with constant intensity, intensity modulation means and random phase modulation means, as in the prior art, are unnecessary, resulting in a system with a simple transmitter configuration.
[0079] 100 SNS-TF-QKD system 110a, 110b Key sharing node 111a, 111b Coherent pulse light source 112a, 112b Optical phase modulator (PM) 113a, 113b Optical intensity modulator (IM) 114a, 114b Attenuator 130 Intermediate node 131 Beam splitter (BS) 132, 133 Photon detector 200 Quantum key distribution system 210, 210a, 210b Key sharing node 211, 211a, 211b Coherent pulse light source 213, 213a, 213b Optical intensity modulator (IM) 214, 214a, 214b Attenuator 215, 215a, 215b Control unit 230 Intermediate node 231 Delayed Mach-Zehnder interferometer (delayed MZI) 232, 233 Beam splitter (BS) 234, 235 Mirror 236 Photon detector D1 237 Photon detector D2 238 Control unit 239 Signal lines 241, 241a, 241b Optical pulse transmission channel 252 Classical communication channel 530 Eavesdropping node 531a, 531b Beam splitter 532a, 532b Memory 601 Communication device 602 Storage device 603 Arithmetic unit
Claims
1. A quantum key distribution system comprising: two key sharing nodes; and an intermediary node positioned midway between the two key sharing nodes, wherein the system supplies a secret key for symmetric-key cryptographic communication to the two key sharing nodes, the two key sharing nodes being configured to transmit a continuous coherent pulse train at regular time intervals to the intermediary node, each pulse of the continuous coherent pulse train having a phase randomly selected from 0 or π / 2 or π or 3π / 2 applied to it, and the average number of photons per pulse being less than 1; the intermediary node comprising: a delayed Mach-Zehnder interferometer (MZI) having two inputs and two outputs, wherein the delay time is equal to the time interval of the continuous coherent pulse train, and the light resulting from the interference of the continuous coherent pulse train from the two key sharing nodes input from the two inputs is output from the two outputs; and two photon detectors positioned at the two outputs of the delayed MZI. A quantum key distribution system further configured such that the intermediary node notifies the two key-sharing nodes of the time at which a photon is detected by the photon detector and the photon detector that detected the photon, and the two key-sharing nodes notify each other of the phase applied to the first pulse of two consecutive pulses resulting from the photon detection, which are among the continuous coherent pulse train transmitted to the intermediary node and notified by the intermediary node, and generates key bits based on (a) the photon detector that detected the photon notified by the intermediary node, (b) the phase applied to the first pulse, and (c) the phase applied to the second pulse of the two consecutive pulses resulting from the photon detection, which are notified by the intermediary node.
2. The quantum key distribution system according to claim 1, wherein the two key sharing nodes are configured to verify the phase difference of the first pulse of the two consecutive pulses notified to each other, and generate bits based on (a') the time and the photon detector notified by the intermediary node, (b') the phase difference of the first pulse, and (c') the phase difference between the first pulse and the second pulse of the two consecutive pulses caused by the photon detection notified by the intermediary node.
3. The quantum key distribution system according to claim 2, further configured such that the two key sharing nodes notify each other of two consecutive pulses that generated the bit, and discard the bit generated by only one of the two key sharing nodes.