Skip to content

BB84

BB84 is a prepare-and-measure quantum key distribution protocol introduced by Charles Bennett and Gilles Brassard in 1984. Alice encodes random candidate key bits in one of two conjugate qubit bases. Bob measures each received signal in a randomly chosen basis. After transmission, they use an authenticated public channel to keep compatible events, estimate disturbances, reconcile their strings, verify agreement, and compress away an adversary’s possible information.

BB84 does not directly encrypt a message, and its raw measurement outcomes are not yet a secret key. The protocol’s output contract is: either abort, or produce matching strings that are close to uniform and independent of an adversary under a stated device and attack model. Authentication, parameter estimation, error correction, and privacy amplification are indispensable parts of that statement.

This page is the canonical home for the ideal four-state protocol, basis sifting, intercept–resend calculation, source-replacement picture, bit-versus-phase error reasoning, and the standard asymptotic one-way key fraction. Quantum Key Distribution owns the general composable security definition and finite-key pipeline. Cryptography Case Studies owns realistic optical loss, weak-coherent-pulse and decoy-state rate models, and experimental comparisons.

Let x∈{0,1}x\in\{0,1\} be Alice’s bit and let θ∈{0,1}\theta\in\{0,1\} be her basis choice. Write

∣ψxθ⟩=Hθ∣x⟩,|\psi_{x\theta}\rangle = H^\theta|x\rangle,

where HH is the Hadamard gate. The four states are:

Basisθ\thetaBit xxSignal state
computational, ZZ0000$
computational, ZZ0011$
Hadamard, XX1100$
Hadamard, XX1111$

Within either basis, the two states are orthogonal. Across bases, every squared overlap is one half:

∣⟨x∣H∣x′⟩∣2=12.\left| \langle x|H|x'\rangle \right|^2 = \frac12.

Bob chooses a basis ϕ∈{0,1}\phi\in\{0,1\} and measures with projectors

My(ϕ)=Hϕ∣y⟩⟨y∣Hϕ,y∈{0,1}.M_y^{(\phi)} = H^\phi|y\rangle\langle y|H^\phi, \qquad y\in\{0,1\}.

The Born probabilities are

Pr⁡(y∣x,θ,ϕ)={δxy,θ=ϕ,12,θ≠ϕ.\Pr(y|x,\theta,\phi) = \begin{cases} \delta_{xy}, & \theta=\phi,\\ \tfrac12, & \theta\neq\phi. \end{cases}

Thus a matched ideal measurement reproduces Alice’s bit, whereas a mismatched measurement is uniformly random.

What the signal reveals before basis announcement

Section titled “What the signal reveals before basis announcement”

If Alice’s bit is uniform, the average state in either basis is maximally mixed:

ρZ=12(∣0⟩⟨0∣+∣1⟩⟨1∣)=I2,ρX=12(∣+⟩⟨+∣+∣−⟩⟨−∣)=I2.\begin{aligned} \rho_Z &= \frac12\left( |0\rangle\langle0| +|1\rangle\langle1| \right) = \frac{I}{2}, \\ \rho_X &= \frac12\left( |+\rangle\langle+| +|-\rangle\langle-| \right) = \frac{I}{2}. \end{aligned}

No measurement on the ideal signal can reveal which basis was chosen before the later announcement, because the two basis ensembles define the same density operator. This does not mean Eve learns nothing from every possible interaction. It means that security must be analyzed as a tradeoff among her quantum side information, the public transcript, and the disturbance seen in the test data.

The four states occupy the +z+z, −z-z, +x+x, and −x-x directions on the Bloch sphere. Because four nonorthogonal states live in a two-dimensional Hilbert space, no measurement can identify all four without error or an inconclusive outcome.

For rounds i=1,…,Ni=1,\ldots,N, the ideal protocol proceeds as follows.

  1. Choose: Alice samples independent random bits (xi,θi)(x_i,\theta_i).
  2. Prepare: She transmits Hθi∣xi⟩H^{\theta_i}|x_i\rangle through an insecure quantum channel.
  3. Measure: Bob independently samples ϕi\phi_i and measures in that basis, recording outcome yiy_i or a no-detection event.
  4. Acknowledge detections: Bob authenticates which rounds produced a valid record before Alice reveals her basis choices.
  5. Reveal bases: Alice and Bob disclose θi\theta_i and ϕi\phi_i over the authenticated public channel, but not the unrevealed key bits.
  6. Sift: They retain detected rounds satisfying θi=ϕi\theta_i=\phi_i.
  7. Estimate: They reveal a designated random sample or test-basis data, estimate relevant error parameters, and abort when the acceptance test fails.
  8. Reconcile and verify: They correct differences between their remaining strings and verify that the results agree, accounting for every disclosed syndrome and tag.
  9. Amplify privacy: They apply an agreed universal hash to produce shorter final keys KAK_A and KBK_B.
  10. Refresh authentication: They reserve key material for later transcript authentication when the system is intended to expand a continuing secret.

BB84 flow from random basis-state preparation through an insecure quantum channel to authenticated sifting, testing, reconciliation, verification, and privacy amplification

The quantum transmission creates correlated raw data; the authenticated public postprocessing turns accepted data into a key or an abort decision. Dashed arrows denote public classical communication, which Eve may read but must not be able to modify undetected.

The ordering matters. For example, if an unmodeled detector can choose which rounds survive after learning Alice’s basis, loss can become a basis-dependent postselection channel. A security proof defines which announcements occur when, which systems may remain quantum, and what Eve knows at every step.

Let DD be the set of detected rounds and let

S={i∈D:θi=ϕi}S = \{i\in D:\theta_i=\phi_i\}

be the sifted set. With independent uniform basis choices,

Pr⁡(θi=ϕi)=12.\Pr(\theta_i=\phi_i) = \frac12.

This factor is conditional on a usable detection; it is not the optical transmission probability. If Alice and Bob choose ZZ with probabilities pZAp_Z^A and pZBp_Z^B, then the basis-match probability is

pmatch=pZApZB+(1−pZA)(1−pZB).p_{\rm match} = p_Z^A p_Z^B + (1-p_Z^A)(1-p_Z^B).

Biased-basis BB84 can reduce sifting loss by using one basis predominantly for key generation and the other for testing. The bias cannot eliminate the need for enough complementary-basis data to bound phase errors.

For a revealed test set T⊂ST\subset S, the observed quantum bit error rate (QBER) is

QT=1∣T∣∑i∈T1[xi≠yi].Q_T = \frac{1}{|T|} \sum_{i\in T} \mathbf 1[x_i\neq y_i].

No-detection events are not automatically bit errors. They are losses whose security treatment depends on the source and detector model. The test QBER is also not automatically the error rate of the unrevealed key block. A finite-key proof supplies a random-sampling bound and a failure probability for that inference.

The simplest attack illustrates information–disturbance without proving full security. Eve intercepts every signal, measures it in a uniformly random ZZ or XX basis, prepares the state indicated by her outcome, and sends that replacement to Bob.

Condition on a sifted round, so Bob happened to use Alice’s basis.

  • With probability 1/21/2, Eve also chose Alice’s basis. She learns the bit and resends the correct state, causing no ideal error.
  • With probability 1/21/2, Eve chose the conjugate basis. Her outcome is random, and Bob’s measurement of the resent state is wrong with probability 1/21/2.

Therefore

QIR=Pr⁡(Eve wrong basis)Pr⁡(Bob error∣wrong)=12⋅12=14.\begin{aligned} Q_{\rm IR} &= \Pr(\text{Eve wrong basis}) \Pr(\text{Bob error}|\text{wrong}) \\ &= \frac12\cdot\frac12 = \frac14. \end{aligned}

If Eve attacks only a fraction ff of otherwise ideal rounds, this model gives

QIR=f4.Q_{\rm IR}=\frac{f}{4}.

After basis disclosure, Eve knows the sifted bit perfectly on the half of her intercepted rounds where she chose correctly. For this particular hard-decision attack, her mutual information is f/2f/2 bit per sifted bit before error correction and privacy amplification.

The number 25%25\% is not the BB84 security threshold. General individual, collective, and coherent attacks need not behave like intercept–resend. Device noise can create errors without Eve, and flawed devices can leak information without producing this disturbance. The security theorem bounds Eve over its entire allowed attack class from the complete observed statistics and device assumptions.

The no-cloning theorem rules out a perfect copier for arbitrary unknown pure states. It does not rule out approximate cloning, partial measurements, coherent interactions with an ancilla, selective forwarding, exploitation of multiphoton pulses, or attacks on implementation side channels. Eve need not identify each state perfectly to obtain useful correlated information.

BB84 security instead rests on complementarity and privacy amplification: gaining predictive information about one basis constrains predictions in the conjugate basis, and the observed sample bounds the adversary’s remaining uncertainty. A rigorous proof then compresses the reconciled string below that uncertainty bound.

The prepare-and-measure protocol has an equivalent virtual description. Alice may be imagined to prepare

∣Φ+⟩AB=∣00⟩+∣11⟩2,|\Phi^+\rangle_{AB} = \frac{|00\rangle+|11\rangle}{\sqrt2},

keep system AA, and send BB through the channel. Measuring AA in basis θ\theta with outcome xx prepares Bob’s system in Hθ∣x⟩H^\theta|x\rangle because the BB84 basis vectors are real in the computational basis. Eve cannot distinguish this delayed-choice construction from direct state preparation when the emitted density operators agree.

This source-replacement step makes two error classes visible:

  • a bit error means Alice and Bob disagree when both measure in the key basis;
  • a phase error is the hypothetical disagreement that would occur in the conjugate basis and controls Eve’s information about the key.

In a CSS-code entanglement-purification argument, one syndrome corrects bit errors and another corrects phase errors. If Alice and Bob could distill nearly perfect Bell pairs, measuring those pairs in the key basis would produce a nearly ideal secret key. Shor and Preskill showed that the required CSS operations can be rearranged and removed until the remaining observable procedure is prepare-and-measure BB84 with classical error correction and privacy amplification.

Entanglement Distillation develops the distributed syndrome viewpoint. Stabilizer Formalism owns the code and syndrome machinery.

Let ebe_b and epe_p be valid asymptotic upper bounds on bit- and phase-error rates for the sifted key block. Define the binary entropy

h2(q)=−qlog⁡2q−(1−q)log⁡2(1−q).h_2(q) = -q\log_2q -(1-q)\log_2(1-q).

In the ideal single-photon BB84 model with one-way postprocessing, an achievable secret fraction per sifted key bit is

r≥1−h2(eb)−h2(ep).r \geq 1-h_2(e_b)-h_2(e_p).

The first entropy term is the ideal error-correction cost; the second is the privacy cost associated with phase uncertainty. For symmetric BB84 statistics under the standard reduction,

eb=ep=Q,e_b=e_p=Q,

so

r≥1−2h2(Q).r \geq 1-2h_2(Q).

This lower bound becomes positive when

Q<0.110027….Q<0.110027\ldots.

The familiar 11.0%11.0\% value is therefore an ideal asymptotic threshold for this proof and one-way processing, not a universal abort setting. Two-way postprocessing, different proof techniques, finite statistics, source flaws, detector models, and protocol variants change the achievable boundary.

Real reconciliation reveals more than the Shannon limit. If its inefficiency is represented by fEC≥1f_{\rm EC}\geq1, a common asymptotic engineering estimate is

rest≈1−fECh2(eb)−h2(ep),r_{\rm est} \approx 1-f_{\rm EC}h_2(e_b)-h_2(e_p),

before verification, authentication, finite-size, and implementation penalties. This expression is a ledger, not a composable finite-key theorem.

The rate per transmitted optical mode must also include detection, basis selection, parameter-estimation sacrifice, dead time, and every other accepted mode criterion. Multiplying rr only by a clock frequency is not enough.

Authentication and Man-in-the-Middle Attacks

Section titled “Authentication and Man-in-the-Middle Attacks”

The public channel need not be secret, but it must be authenticated. Without authentication, Eve can block the quantum and classical traffic and run one independent BB84 session with Alice while impersonating Bob, and another with Bob while impersonating Alice. Both local sessions can have low QBER. Alice and Bob nevertheless share no key with each other.

Information-theoretic authentication can start from a short preshared secret and consume part of each newly generated key. BB84 is then a key-expansion mechanism when the fresh key exceeds authentication and operational costs. Using computational signatures for bootstrap can be sensible, but the final security claim must include that computational assumption and its lifetime.

Authentication covers the full transcript: detection acknowledgments, basis lists, test positions, error-correction messages, verification tags, abort signals, and privacy-amplification seed. Freshness and session binding are needed to prevent replay and cross-session substitution.

The four-state derivation is exact only after its abstraction boundary is declared.

Ideal proof objectPhysical complicationRequired response
one qubit in one of four statesweak coherent pulse may contain zero, one, or several photonsphase randomization, decoy-state estimation, tagged-signal or other source proof
basis-independent sourceintensity, spectrum, timing, phase, or spatial mode reveals the settingcharacterize and bound basis dependence; filter or redesign the source
trusted projective measurementefficiency mismatch, afterpulsing, dead time, blinding, or wavelength responsedetector model, countermeasure validation, or measurement-device-independent design
erasure-like lossEve can correlate forwarding with hidden modes or detector responseprove the accepted-event sampling model; do not treat missing clicks as evidence of secrecy
private random choicesbiased, predictable, reused, or correlated random numberscharacterize entropy and independence at the protocol interface
isolated laboratoriesTrojan-horse probes and electromagnetic or optical leakageisolation, monitoring, leakage bounds, and authenticated control
stationary independent roundsdrift, memory, afterpulsing, and coherent attacksproof covering correlations plus time-resolved diagnostics

A phase-randomized coherent pulse of mean photon number μ\mu has Poisson photon-number probabilities

Pμ(n)=e−μμnn!.P_\mu(n) = e^{-\mu} \frac{\mu^n}{n!}.

Multiphoton pulses invalidate the literal single-qubit story because Eve may, under an insufficient proof model, retain one photon and forward another. Decoy-State QKD varies intensity to estimate single-photon contributions without assuming Eve treats signal and decoy labels honestly. That page owns the yield equations, vacuum-plus-weak bounds, and source assumptions. Cryptography Case Studies applies the estimator inside a concrete optical link ledger.

In an ideal model, channel loss can be treated as erasure and Eve may control which signals arrive. Security comes from the statistics of accepted events, not from the absence of detections. If acceptance depends on basis, bit, wavelength, arrival time, detector control, or a leaked source mode, the surviving sample may not represent the intended qubit ensemble.

The asymptotic identity between test and key error rates is replaced by a confidence statement. A finite-key analysis must account for sampling without replacement, smoothing or entropy-estimation terms, error-correction leakage, verification failure, privacy-amplification failure, authentication failure, and all abort branches. Quantum Key Distribution owns that composable ledger.

  • Efficient BB84 biases the basis choices so most matched detections can contribute to the key while enough conjugate-basis rounds remain for tests.
  • Three-state BB84 omits one of the four signal states but requires its own parameter-estimation and security analysis.
  • BBM92 is an entanglement-based protocol using the same two measurement bases; it is operationally related to source replacement but has a different physical source boundary. E91 and Entanglement-Based QKD owns the Bell-tested three-setting protocol and explains why entanglement-based does not automatically mean device-independent.
  • Decoy-state BB84 adds intensity settings to bound photon-number-resolved yields for weak coherent pulses; decoys are not extra key-encoding bases.
  • Measurement-device-independent QKD moves the detector trust boundary to an untrusted relay and is not merely BB84 with a different detector brand.

Changing basis probabilities, state alphabet, detector trust, source model, or classical postprocessing changes the protocol theorem. The label “BB84” does not by itself specify a secure implementation.

  • Calling sifted bits a secret key before parameter estimation, reconciliation, verification, and privacy amplification.
  • Saying an eavesdropper necessarily causes 25%25\% QBER; that number belongs to full intercept–resend under the ideal model.
  • Treating 11%11\% as a universal experimental threshold.
  • Using no-cloning as a complete security proof.
  • Forgetting that the classical channel must be authenticated.
  • Revealing basis choices before Bob has committed to accepted detections.
  • Equating the measured bit-error rate with the phase-error rate without the proof step that relates them.
  • Counting lost pulses as evidence that Eve learned nothing.
  • Modeling a weak coherent pulse as a guaranteed single photon.
  • Quoting secret bits per sifted bit as secret bits per pulse or per second.
  • Subtracting dark counts or detector errors from security data without a proof that permits the subtraction.
  • Assuming a countermeasure closes every source and detector side channel.

Compute all four cross-basis probabilities ∣⟨zx∣xy⟩∣2|\langle z_x|x_y\rangle|^2.

Solution

Using

∣+⟩=∣0⟩+∣1⟩2,∣−⟩=∣0⟩−∣1⟩2,|+\rangle = \frac{|0\rangle+|1\rangle}{\sqrt2}, \qquad |-\rangle = \frac{|0\rangle-|1\rangle}{\sqrt2},

one obtains

∣⟨0∣+⟩∣2=∣⟨0∣−⟩∣2=12,∣⟨1∣+⟩∣2=∣⟨1∣−⟩∣2=12.\begin{aligned} |\langle0|+\rangle|^2 &= |\langle0|-\rangle|^2 = \frac12, \\ |\langle1|+\rangle|^2 &= |\langle1|-\rangle|^2 = \frac12. \end{aligned}

Thus either state in one basis gives a uniform outcome when measured in the other basis.

Suppose 80,00080{,}000 signals produce valid detections. How many sifted rounds are expected with uniform independent bases? What is the basis-match probability if both parties choose ZZ with probability 0.90.9?

Solution

Uniform choices match with probability 1/21/2, so the expected sifted count is

80,000×12=40,000.80{,}000\times\frac12 = 40{,}000.

With pZA=pZB=0.9p_Z^A=p_Z^B=0.9,

pmatch=(0.9)2+(0.1)2=0.82.p_{\rm match} = (0.9)^2+(0.1)^2 = 0.82.

This would yield 65,60065{,}600 matched detections on average, but the XX-matched subset has expected fraction 0.010.01 and may be too small for the desired finite statistical bound.

In an otherwise noiseless ideal system, the measured QBER is 3%3\%. If every error is attributed to the partial intercept–resend model, what attacked fraction ff would explain it, and how much sifted-bit information would Eve have in that model?

Solution

Since Q=f/4Q=f/4,

f=4Q=0.12.f=4Q=0.12.

Eve knows the bit on half of the intercepted sifted rounds, so her mutual information in this simplified model is

f2=0.06\frac{f}{2}=0.06

bit per sifted bit. This inference is not valid for a general attack or a noisy implementation; it is specific to the stated model.

Show that the density operator of a uniformly random bit is I/2I/2 in both BB84 bases. Does this prove that Eve has zero information after interacting with a signal and later hearing the basis announcement?

Solution

For the ZZ basis,

12(∣0⟩⟨0∣+∣1⟩⟨1∣)=I2.\frac12 \left( |0\rangle\langle0|+|1\rangle\langle1| \right) = \frac{I}{2}.

For the XX basis,

12(∣+⟩⟨+∣+∣−⟩⟨−∣)=I2.\frac12 \left( |+\rangle\langle+|+|-\rangle\langle-| \right) = \frac{I}{2}.

The equality proves that the ideal emitted ensemble does not reveal the basis before announcement. It does not prove zero later information. Eve may couple an ancilla coherently to the signal, retain it, and condition her final measurement on the public transcript. Security bounds that side information using the disturbance and a full attack model.

Solve 1−2h2(Q)=01-2h_2(Q)=0 numerically. Evaluate the asymptotic fraction at Q=5%Q=5\%.

Solution

The root satisfies h2(Q)=1/2h_2(Q)=1/2 and is

Q∗=0.110027864….Q_*=0.110027864\ldots.

At Q=0.05Q=0.05,

h2(0.05)=0.286397…,h_2(0.05)=0.286397\ldots,

so

r≥1−2h2(0.05)=0.427206…r \geq 1-2h_2(0.05) = 0.427206\ldots

secret bit per sifted key bit under the ideal asymptotic assumptions.

Why can Alice and Bob not simply substitute the observed key-basis QBER for epe_p in every BB84 implementation?

Solution

The key-basis QBER directly samples bit disagreement in one basis. The phase error is a counterfactual complementary-basis quantity. Equality or a bound between them follows only from protocol symmetry, random basis sampling, and the source and detector assumptions used in the proof. Basis-dependent flaws or biased accepted events can break a naive equality, so a valid proof derives epe_p from test data and characterized imperfections with a failure probability.

Construct a man-in-the-middle attack on unauthenticated BB84 in which both Alice and Bob observe low QBER.

Solution

Eve blocks all communication. She impersonates Bob in a complete BB84 session with Alice and independently impersonates Alice in a complete session with Bob. Eve honestly performs each local protocol, so both sessions can have low QBER and pass privacy amplification. Alice shares one key with Eve and Bob shares another key with Eve; Alice and Bob share no common key. Eve can then decrypt, modify, and re-encrypt later traffic. Authentication prevents this substitution of identities and transcripts.

After testing, Alice has n=80,000n=80{,}000 sifted key bits. Suppose a justified asymptotic model gives eb=ep=0.04e_b=e_p=0.04, reconciliation uses fEC=1.15f_{\rm EC}=1.15, and all finite-size, verification, and authentication terms are temporarily omitted. Estimate the remaining secret bits.

Solution

The engineering estimate is

ℓ≈n[1−fECh2(eb)−h2(ep)]=80,000[1−2.15h2(0.04)].\begin{aligned} \ell &\approx n\left[ 1-f_{\rm EC}h_2(e_b)-h_2(e_p) \right] \\ &= 80{,}000 \left[ 1-2.15h_2(0.04) \right]. \end{aligned}

Since h2(0.04)=0.242292…h_2(0.04)=0.242292\ldots,

ℓ≈38,326.\ell\approx38{,}326.

This is not a finite-key output length because the exercise explicitly omitted statistical, smoothing, verification, and authentication penalties. A real protocol must subtract them before choosing the hash length.

  1. C. H. Bennett and G. Brassard, “Quantum Cryptography: Public Key Distribution and Coin Tossing,” in Proceedings of the IEEE International Conference on Computers, Systems and Signal Processing, Bangalore, 175–179 (1984); reprinted in Theoretical Computer Science 560, 7–11 (2014), doi:10.1016/j.tcs.2014.05.025.
  2. C. H. Bennett, F. Bessette, G. Brassard, L. Salvail, and J. Smolin, “Experimental Quantum Cryptography,” Journal of Cryptology 5, 3–28 (1992), doi:10.1007/BF00191318.
  3. C. A. Fuchs, N. Gisin, R. B. Griffiths, C.-S. Niu, and A. Peres, “Optimal Eavesdropping in Quantum Cryptography. I. Information Bound and Optimal Strategy,” Physical Review A 56, 1163–1172 (1997), doi:10.1103/PhysRevA.56.1163.
  4. D. Mayers, “Unconditional Security in Quantum Cryptography,” Journal of the ACM 48, 351–406 (2001), doi:10.1145/382780.382781.
  5. H.-K. Lo and H. F. Chau, “Unconditional Security of Quantum Key Distribution over Arbitrarily Long Distances,” Science 283, 2050–2056 (1999), doi:10.1126/science.283.5410.2050.
  6. P. W. Shor and J. Preskill, “Simple Proof of Security of the BB84 Quantum Key Distribution Protocol,” Physical Review Letters 85, 441–444 (2000), doi:10.1103/PhysRevLett.85.441.
  7. D. Gottesman, H.-K. Lo, N. Lütkenhaus, and J. Preskill, “Security of Quantum Key Distribution with Imperfect Devices,” Quantum Information and Computation 4, 325–360 (2004), doi:10.26421/QIC4.5-1.
  8. M. Koashi, “Simple Security Proof of Quantum Key Distribution Based on Complementarity,” New Journal of Physics 11, 045018 (2009), doi:10.1088/1367-2630/11/4/045018.
  9. R. Renner, Security of Quantum Key Distribution, Ph.D. thesis, ETH Zürich (2005), doi:10.3929/ethz-a-005115027.
  10. M. Tomamichel, C. C. W. Lim, N. Gisin, and R. Renner, “Tight Finite-Key Analysis for Quantum Cryptography,” Nature Communications 3, 634 (2012), doi:10.1038/ncomms1631.
  11. V. Scarani, H. Bechmann-Pasquinucci, N. J. Cerf, et al., “The Security of Practical Quantum Key Distribution,” Reviews of Modern Physics 81, 1301–1350 (2009), doi:10.1103/RevModPhys.81.1301.
  12. F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, “Secure Quantum Key Distribution with Realistic Devices,” Reviews of Modern Physics 92, 025002 (2020), doi:10.1103/RevModPhys.92.025002.
  13. C. Portmann and R. Renner, “Security in Quantum Cryptography,” Reviews of Modern Physics 94, 025008 (2022), doi:10.1103/RevModPhys.94.025008.
  14. M. N. Wegman and J. L. Carter, “New Hash Functions and Their Use in Authentication and Set Equality,” Journal of Computer and System Sciences 22, 265–279 (1981), doi:10.1016/0022-0000(81)90033-7.
  15. M. A. Nielsen and I. L. Chuang, Quantum Computation and Quantum Information, 10th anniversary ed., Cambridge University Press (2010), doi:10.1017/CBO9780511976667.

BB84 encodes random bits in two conjugate qubit bases. Matched-basis measurements create correlated sifted data; mismatched bases produce uniform outcomes. Intercept–resend causes 25%25\% QBER when applied to every ideal signal, but that pedagogical attack is neither a complete adversary model nor a security threshold.

The source-replacement picture turns BB84 into a virtual entanglement protocol with bit and phase errors. In the ideal asymptotic one-way model this gives r≥1−h2(eb)−h2(ep)r\geq1-h_2(e_b)-h_2(e_p) and, under the symmetric reduction, r≥1−2h2(Q)r\geq1-2h_2(Q). A trustworthy implementation additionally specifies source, detector, loss, randomness, finite-statistical, leakage, authentication, and postprocessing assumptions. Only after those steps do Alice and Bob have a key rather than correlated raw measurements.