| BB84 | |
|---|---|
| Name | BB84 |
| Caption | Quantum key distribution protocol |
| Author | Charles H. Bennett and Gilles Brassard |
| Introduced | 1984 |
| Related | Quantum key distribution |
BB84
BB84 is a quantum key distribution (QKD) protocol devised in 1984 by Charles H. Bennett and Gilles Brassard. It uses properties of quantum mechanics — notably quantum superposition and the no-cloning theorem — to enable two parties to establish a shared secret key with the ability to detect eavesdropping. BB84 is foundational in the field of quantum cryptography and has influenced modern efforts in secure communications, standards, and national cryptographic policy.
BB84 was introduced in the 1984 paper "Quantum Cryptography: Public Key Distribution and Coin Tossing" by Charles H. Bennett and Gilles Brassard while both were affiliated with IBM Research. The protocol arrived amid Cold War technological competition and growing concern over secure communications. It combined theoretical insights from quantum mechanics with emerging ideas in cryptography and computer science. Early experimental demonstrations were performed by groups at institutions such as Bennett laboratory collaborators and later by teams at Los Alamos National Laboratory and University of Geneva, helping to seed the modern quantum information science community and national programs in the United States and European Union.
BB84 involves two communicating parties commonly called Alice and Bob, and a potential eavesdropper called Eve. Alice prepares a sequence of quantum states (usually single photons) encoded in one of two non-orthogonal bases: the rectilinear (|0⟩,|1⟩) or the diagonal (|+⟩,|−⟩) basis. Bob measures each received photon in a randomly chosen basis. After transmission, Alice and Bob publicly compare basis choices over an authenticated classical channel; they keep only those measurement outcomes where bases matched to form the raw key. They then perform error estimation, error correction (information reconciliation), and privacy amplification to generate a shorter, secret key. The protocol relies on quantum measurement disturbance to reveal eavesdropping and on classical cryptographic techniques for authentication, often employing hash functions or message authentication codes.
Security of BB84 rests on fundamental quantum principles: measurement disturbance and the no-cloning theorem. Initial proofs were heuristic; rigorous unconditional security proofs followed, including complementarity-based proofs by Artur Ekert and others, and mathematical reductions to entanglement-based protocols such as the E91 protocol. Important formal results include Shor and Preskill's proof linking BB84 security to quantum error correction and entanglement purification, and device-independent and semi-device-independent analyses that relax assumptions about equipment. Security proofs address collective and coherent attacks by adversaries with access to quantum memory, and rely on composable security frameworks used in modern cryptographic protocol design.
Experimental implementations of BB84 have used attenuated laser pulses, true single-photon sources (e.g., nitrogen-vacancy centers, quantum dots), and entangled-photon systems. Photonic degrees of freedom include polarization, phase encoding in Mach–Zehnder interferometers, and time-bin encoding for fiber networks. Deployments have been carried out over optical fiber links, free-space optical links (including satellite-to-ground experiments by agencies like CNSA and ESA), and metropolitan networks integrated with classical optical infrastructure. Key enabling technologies include single-photon detectors such as avalanche photodiodes and superconducting nanowire single-photon detectors, random-number generators, and classical post-processing hardware for error correction and privacy amplification.
While BB84 is provably secure in idealized models, practical systems face implementation vulnerabilities. Notable attacks include photon-number-splitting (PNS) attacks against weak coherent pulses, detector blinding and time-shift attacks exploiting detector nonidealities, and side-channel leaks from source imperfections. Countermeasures developed include decoy-state protocols to defeat PNS attacks, measurement-device-independent QKD (MDI-QKD) to remove detector trust assumptions, device-independent QKD to counter broader device flaws, and enhanced device characterization and certification by standards bodies such as ETSI and national cryptographic agencies. Continuous monitoring, hardware redundancy, and conservative engineering practices remain important in operational deployments.
BB84 and its variants underpin practical QKD services for key renewal, secure government and military links, financial sector communications, and critical infrastructure protection. Trials and pilot networks have been fielded in cities and across national backbones, informing standards and public procurement. BB84 complements post-quantum cryptography research by offering information-theoretic key material that can be combined with classical encryption schemes such as AES for hybrid security. International cooperation on QKD touches on export controls, national security policy, and norms for critical infrastructure resilience.
BB84 exemplifies operational consequences of core quantum phenomena: the impossibility of measuring an unknown quantum state without disturbance, the Heisenberg uncertainty principle in information terms, and constraints implied by entanglement and nonlocality. The protocol influenced conceptual debates in quantum foundations about information, measurement, and reality, motivating work by researchers across physics and mathematics on how information-theoretic principles can serve as axioms for quantum theory. BB84 remains a pedagogical example in courses on quantum information theory and a bridge between theoretical physics, engineering, and national-scale technology programs.
Category:Quantum cryptography Category:Quantum information theory Category:Cryptographic protocols