| BB84 | |
|---|---|
| Name | BB84 |
| Caption | Schematic of polarization states used in BB84 |
| Designer | Charles H. Bennett; Gilles Brassard |
| Publish date | 1984 |
| Field | Quantum cryptography |
| Related | Quantum key distribution |
BB84
BB84 is a quantum key distribution (QKD) protocol introduced in 1984 by Charles H. Bennett and Gilles Brassard. It was the first practical scheme to use fundamental principles of quantum mechanics—notably the Heisenberg uncertainty principle and quantum no-cloning theorem—to allow two parties to establish a shared secret key with provable detection of eavesdropping. BB84 is foundational in the development of quantum cryptography and has influenced theoretical and experimental research in quantum information science.
BB84 enables two parties usually named Alice and Bob to create a shared secret key over an insecure channel using the transmission of quantum states. The protocol encodes classical bits into non-orthogonal quantum states so that any measurement by an eavesdropper (Eve) perturbs the states and introduces detectable errors. The scheme contrasts with classical cryptographic key distribution, relying on information-theoretic security rather than computational hardness assumptions like those underlying RSA or Diffie–Hellman.
In BB84, Alice prepares qubits in one of two conjugate bases: typically the rectilinear (|0⟩, |1⟩) and diagonal (|+⟩, |−⟩) polarization bases. Each transmitted qubit encodes a bit value chosen uniformly at random and a basis chosen uniformly at random. Bob measures each qubit in a randomly chosen basis. After transmission, Alice and Bob communicate over a classical authenticated channel to reveal their chosen bases (but not the bit values) and discard events where bases disagree. The remaining bits form the raw key. They then perform error estimation by disclosing a subset of bits and apply quantum error correction and privacy amplification to obtain a shorter, secure key. BB84 assumes an authenticated classical channel, which can be bootstrapped via message authentication codes or initial symmetric keys.
BB84's security is based on quantum principles: the no-cloning theorem prevents perfect copying of unknown quantum states, and measurement in one basis disturbs complementary observables. Security proofs have progressed from the original heuristic arguments to rigorous proofs against general attacks, including collective and coherent attacks. Key theoretical advances involved techniques by Dominic Mayers, Peter W. Shor, John Preskill, and Renato Renner, culminating in information-theoretic bounds on the secret key rate as a function of observed error rate. Security analyses consider models such as the individual attack, collective attack, and the most general coherent attack; practical proofs account for imperfections via the composable security framework and finite-key analyses.
Real-world BB84 implementations translate ideal qubits into physical carriers such as single photons or weak coherent pulses produced by laser diodes. Polarization-encoded BB84 often uses optical fiber or free-space links; phase-encoded variants use interferometers (e.g., Mach–Zehnder interferometer). Practical systems must address sources of imperfection: multi-photon emission, detector inefficiencies, dark counts, and side channels. Countermeasures include the decoy state protocol to foil photon-number-splitting attacks and the development of single-photon detector technologies such as SNSPDs and APDs. Industry efforts by companies like ID Quantique and research groups at National Institute of Standards and Technology and Toshiba Research Europe have produced commercial and prototype QKD systems based on BB84.
BB84 has been demonstrated in laboratory and field trials, including fiber links over hundreds of kilometers and satellite-to-ground experiments. Notable experiments include metropolitan networks like the SECOQC project and long-distance records set using low-loss fibers and quantum repeaters research. Satellite demonstrations by programs such as Micius (Chinese Academy of Sciences) enabled entanglement-based and BB84-like QKD over thousands of kilometers. Testbeds by institutions like Los Alamos National Laboratory and NIST validated performance metrics—secret key rate, quantum bit error rate (QBER), and robustness to environmental conditions—guiding standards from bodies such as the European Telecommunications Standards Institute (ETSI).
BB84 inspired numerous variants and hybrid protocols. The B92 protocol simplifies state sets to two nonorthogonal states. The decoy state protocol augments BB84 for weak coherent sources, while measurement-device-independent QKD (MDI-QKD) eliminates detector side-channel vulnerabilities by shifting trust to an untrusted relay. Continuous-variable QKD uses quadrature measurements as an alternative encoding. Protocols combine BB84 principles with quantum-resistant classical cryptography in practical network architectures and integrate with trusted node topologies, quantum repeaters research, and proposals for device-independent QKD that leverage Bell's theorem for stronger security assumptions.
BB84 remains the canonical protocol for securing point-to-point quantum links and underpins quantum-secure network prototypes and encrypted key delivery for classical symmetric cryptosystems. Its concepts shaped standards, influenced regulatory interest in post-quantum readiness, and provided a testbed for advancing quantum-resistant infrastructure. Research continues on improving key rates, extending transmission distance, and integrating BB84-based QKD into existing telecommunications networks using wavelength-division multiplexing and quantum-safe key management compatible with protocols such as IPsec and TLS.
Category:Quantum cryptography Category:Quantum key distribution Category:Cryptographic protocols