| quantum key distribution | |
|---|---|
| Name | Quantum key distribution |
| Type | Cryptographic protocol |
| Invented | 1984 |
| Inventor | Charles H. Bennett and Gilles Brassard; contributions by Artur Ekert |
| Developer | IBM, ID Quantique, Toshiba Corporation, QinetiQ, NIST |
| Application | Secure key exchange |
| Based on | Quantum mechanics |
quantum key distribution
Quantum key distribution (QKD) is a set of cryptographic protocols that use principles of quantum mechanics to enable two parties to generate a shared, secret random key. QKD matters in Quantum physics and information security because it provides information-theoretic detection of eavesdropping based on quantum phenomena such as the Heisenberg uncertainty principle and quantum entanglement, potentially complementing or replacing classical key distribution schemes vulnerable to advances in cryptanalysis or quantum computing.
QKD relies on encoding information in quantum states—commonly single photons or weak coherent pulses—so that any measurement by an eavesdropper inevitably disturbs those states and can be detected. Key principles include the no-cloning theorem which forbids perfect copying of unknown quantum states, and the unpredictability of measurement outcomes for non-orthogonal states. Typical workflows use a quantum channel for state transmission and a classical authenticated channel for sifting, error correction, and privacy amplification. Central parties in descriptions are conventionally named Alice and Bob, while an adversary is called Eve.
Foundational work began with the 1984 BB84 protocol by Charles H. Bennett and Gilles Brassard, followed by the entanglement-based E91 protocol proposed by Artur Ekert in 1991. Experimental milestones include early free-space demonstrations by Anton Zeilinger's group, fiber-based transmissions by teams at BT Group and Los Alamos National Laboratory, and deployment of commercial systems by ID Quantique in the early 2000s. National testbeds and networks such as the SECOQC project, the Tokyo QKD Network, and the Micius satellite mission showcase progress toward metropolitan and global QKD. Standardization has been pursued by institutions including ETSI and research agencies like NIST and the European Commission.
Prominent protocols include: - BB84 (prepare-and-measure), using two non-orthogonal bases. - E91 (entanglement-based), leveraging Bell correlations. - B92 and variants that simplify state sets. - Continuous-variable QKD (CV-QKD) protocols using quadrature measurements and coherent states, developed in groups like Toshiba Research Europe and CNRS labs. Implementations vary by photonic source (single-photon sources, attenuated lasers), detectors (single-photon avalanche diodes, superconducting nanowire single-photon detectors developed at NIST and research labs), and encoding (polarization, phase, time-bin). Integrated photonics platforms and systems from companies such as Toshiba Corporation and QinetiQ have produced field-deployable units.
Security proofs for QKD link the observed error rate (quantum bit error rate, QBER) to bounds on an eavesdropper's information. Proof techniques include entropic uncertainty relations, decoy-state analysis to counter photon-number-splitting attacks, and composable security frameworks formalized by researchers such as Renato Renner and institutions including ETH Zurich. Device-independent QKD (DI-QKD), inspired by Bell inequality violations demonstrated by groups like Alain Aspect and John Clauser, aims to remove trust in device internals by using loophole-free Bell tests (e.g., experiments by Hensen et al.) to certify keys, though DI-QKD remains experimentally demanding.
Experimental platforms span fiber-optic metropolitan links, free-space line-of-sight systems, and satellite-based QKD such as the Micius mission by the Chinese Academy of Sciences. Key enabling technologies include single-photon sources, decoy-state lasers, superconducting detectors developed in labs such as NIST and MIT Lincoln Laboratory, and integrated photonic chips from academic groups and industry. Testbeds like the UK Quantum Network and the EU Quantum Flagship initiatives integrate QKD with classical networks and explore interoperability with IPsec and TLS gateways.
Real-world QKD faces practical limitations: transmission loss in optical fibers limits range, detector dark counts increase QBER, and finite-key effects require careful statistical treatment. Practical attacks exploit device imperfections—examples include detector blinding attacks demonstrated in academic labs and Trojan-horse attacks—leading to mitigations such as measurement-device-independent QKD (MDI-QKD) which removes detector-side channels, decoy-state methods to thwart photon-number-splitting attacks, and hardware countermeasures certified through standards bodies. Side-channel analysis, supply-chain security, and robust authentication of the classical channel remain critical.
QKD is applied to secure key distribution for high-value links in finance, government, and critical infrastructure. Deployments integrate with classical cryptographic systems: QKD can provide symmetric keys for use with AES or hybrid constructions combining QKD-derived keys with post-quantum cryptography (PQC) algorithms being standardized by NIST. QKD networks aim to interoperate with existing telecommunications infrastructure, often using trusted-node architectures for long distances or satellite relays for global links. Research continues on key management, network architectures, and cost-effective scaling to broader commercial use.
Category:Quantum cryptography Category:Quantum optics Category:Cryptographic protocols