| BB84 protocol | |
|---|---|
| Name | BB84 protocol |
| Caption | Schematic of BB84 quantum key distribution |
| Designer | Charles Bennett and Gilles Brassard |
| Introduced | 1984 |
| Related | Quantum key distribution, Quantum cryptography |
| Field | Quantum physics; Cryptography |
BB84 protocol
The BB84 protocol is a pioneering quantum key distribution (QKD) scheme introduced in 1984 by Charles Bennett and Gilles Brassard. It employs the quantum properties of individual photons and incompatible measurement bases to enable two parties to establish a shared secret key with security based on quantum mechanics rather than computational hardness. BB84 laid the conceptual foundation for practical quantum communication systems and motivated later theoretical and experimental work in quantum information science.
BB84 is one of the earliest and most studied protocols in quantum cryptography. The protocol enables two parties, conventionally named Alice and Bob, to generate a symmetric key by transmitting qubits encoded in non-orthogonal states. Security stems from the no-cloning theorem and the disturbance induced by measurement in incompatible quantum measurement bases. BB84 has driven development in optical fiber and free-space quantum links, and influenced standards and prototypes produced by research institutions such as IBM, ID Quantique, and laboratories including Los Alamos National Laboratory and NIST.
BB84 uses two sets of basis states, typically the rectilinear (|0〉, |1〉) and diagonal (|+〉, |−〉) polarization bases for single photons. Alice chooses a random bit string and a random basis string; she encodes each bit as a photon polarized according to the chosen basis and sends the sequence to Bob over a quantum channel. Bob measures each incoming photon in a randomly chosen basis. After transmission, Alice and Bob communicate over an authenticated classical channel (for example using MACs) to reveal their basis choices and discard events where their bases differ, yielding a raw key. They perform error rate estimation by comparing a subset of bits, execute error correction (information reconciliation), and apply privacy amplification to reduce any information an eavesdropper might have, resulting in a final secret key.
Key operational elements include single-photon sources or weak coherent pulses, single-photon detectors (such as avalanche photodiodes or SNSPDs), and an authenticated classical channel often implemented over conventional Internet protocol networks.
Security of BB84 is rooted in fundamental quantum mechanics: measurement of non-orthogonal states perturbs the system, enabling detection of an eavesdropper (Eve). The no-cloning theorem prevents perfect copying of unknown quantum states. Early security arguments were intuitive; rigorous proofs followed using tools from information theory and quantum error correction.
Provable security analyses include individual, collective, and coherent attack models. The Shor–Preskill proof connected BB84 security to quantum error-correcting codes and CSS codes, demonstrating unconditional security against general attacks when observed quantum bit error rate (QBER) is below a threshold. Entanglement-based formulations relate BB84 to the Ekert protocol and use entanglement purification arguments. Security proofs often assume an authenticated classical channel and model imperfections in sources and detectors; composable security frameworks have been developed to ensure keys are safe for cryptographic use.
Practical BB84 systems use a variety of photonic implementations: polarization encoding in free-space links, phase encoding in interferometer-based fiber systems, and time-bin encoding for long-distance fiber transmission. Source technologies range from attenuated laser pulses (weak coherent states) to true single-photon emitters such as quantum dots and nitrogen-vacancy centers. Decoy-state methods mitigate attacks against weak coherent sources by varying pulse intensities.
Detectors include silicon SPADs for visible wavelengths and SNSPDs for telecom wavelengths, offering low dark counts and high detection efficiency. Integrated photonics and chip-based modulators from companies and research groups provide scalable modulation, routing, and stabilization. Classical post-processing uses established algorithms for error correction (e.g., LDPC codes, Cascade) and hash-based privacy amplification.
Real-world deployments face channel loss, detector inefficiencies, and device imperfections. These open vulnerabilities exploited by practical attacks: the photon number splitting attack targets weak coherent pulses; time-shift attack and detector blinding attack exploit detector response nonidealities; side-channel attacks leak basis or bit information via classical or analog signatures. Countermeasures include decoy-state protocols, device characterization, measurement-device-independent QKD (MDI-QKD) to remove detector trust, and device-independent approaches that rely on violation of Bell's theorem.
Environmental factors (e.g., atmospheric turbulence in free-space links) and classical authentication management also complicate deployment. Standards work and field trials (e.g., metropolitan QKD networks) address integration with existing telecommunications infrastructure.
BB84 inspired numerous variants and extensions. Practical variants add decoy states (decoy-state BB84) to protect weak coherent sources. Entanglement-based equivalents connect BB84 to the E91 protocol. Measurement-device-independent QKD removes all detector-side channels. Continuous-variable QKD uses coherent states and homodyne detection as an alternative encoding paradigm. Higher-dimensional generalizations employ qudits (e.g., orbital angular momentum) to increase key rates. Protocols combining BB84 elements with quantum repeaters and entanglement swapping aim to extend range toward a global quantum internet.
Category:Quantum cryptography Category:Quantum information theory