BB84
BB84 is a prepare-and-measure quantum key distribution protocol introduced by Charles Bennett and Gilles Brassard in 1984. Alice encodes random candidate key bits in one of two conjugate qubit bases. Bob measures each received signal in a randomly chosen basis. After transmission, they use an authenticated public channel to keep compatible events, estimate disturbances, reconcile their strings, verify agreement, and compress away an adversary’s possible information.
BB84 does not directly encrypt a message, and its raw measurement outcomes are not yet a secret key. The protocol’s output contract is: either abort, or produce matching strings that are close to uniform and independent of an adversary under a stated device and attack model. Authentication, parameter estimation, error correction, and privacy amplification are indispensable parts of that statement.
This page is the canonical home for the ideal four-state protocol, basis sifting, intercept–resend calculation, source-replacement picture, bit-versus-phase error reasoning, and the standard asymptotic one-way key fraction. Quantum Key Distribution owns the general composable security definition and finite-key pipeline. Cryptography Case Studies owns realistic optical loss, weak-coherent-pulse and decoy-state rate models, and experimental comparisons.
The Four Signal States
Section titled “The Four Signal States”Let be Alice’s bit and let be her basis choice. Write
where is the Hadamard gate. The four states are:
| Basis | Bit | Signal state | |
|---|---|---|---|
| computational, | $ | ||
| computational, | $ | ||
| Hadamard, | $ | ||
| Hadamard, | $ |
Within either basis, the two states are orthogonal. Across bases, every squared overlap is one half:
Bob chooses a basis and measures with projectors
The Born probabilities are
Thus a matched ideal measurement reproduces Alice’s bit, whereas a mismatched measurement is uniformly random.
What the signal reveals before basis announcement
Section titled “What the signal reveals before basis announcement”If Alice’s bit is uniform, the average state in either basis is maximally mixed:
No measurement on the ideal signal can reveal which basis was chosen before the later announcement, because the two basis ensembles define the same density operator. This does not mean Eve learns nothing from every possible interaction. It means that security must be analyzed as a tradeoff among her quantum side information, the public transcript, and the disturbance seen in the test data.
The four states occupy the , , , and directions on the Bloch sphere. Because four nonorthogonal states live in a two-dimensional Hilbert space, no measurement can identify all four without error or an inconclusive outcome.
Protocol Transcript
Section titled “Protocol Transcript”For rounds , the ideal protocol proceeds as follows.
- Choose: Alice samples independent random bits .
- Prepare: She transmits through an insecure quantum channel.
- Measure: Bob independently samples and measures in that basis, recording outcome or a no-detection event.
- Acknowledge detections: Bob authenticates which rounds produced a valid record before Alice reveals her basis choices.
- Reveal bases: Alice and Bob disclose and over the authenticated public channel, but not the unrevealed key bits.
- Sift: They retain detected rounds satisfying .
- Estimate: They reveal a designated random sample or test-basis data, estimate relevant error parameters, and abort when the acceptance test fails.
- Reconcile and verify: They correct differences between their remaining strings and verify that the results agree, accounting for every disclosed syndrome and tag.
- Amplify privacy: They apply an agreed universal hash to produce shorter final keys and .
- Refresh authentication: They reserve key material for later transcript authentication when the system is intended to expand a continuing secret.
The quantum transmission creates correlated raw data; the authenticated public postprocessing turns accepted data into a key or an abort decision. Dashed arrows denote public classical communication, which Eve may read but must not be able to modify undetected.
The ordering matters. For example, if an unmodeled detector can choose which rounds survive after learning Alice’s basis, loss can become a basis-dependent postselection channel. A security proof defines which announcements occur when, which systems may remain quantum, and what Eve knows at every step.
Sifting and Quantum Bit Error Rate
Section titled “Sifting and Quantum Bit Error Rate”Let be the set of detected rounds and let
be the sifted set. With independent uniform basis choices,
This factor is conditional on a usable detection; it is not the optical transmission probability. If Alice and Bob choose with probabilities and , then the basis-match probability is
Biased-basis BB84 can reduce sifting loss by using one basis predominantly for key generation and the other for testing. The bias cannot eliminate the need for enough complementary-basis data to bound phase errors.
For a revealed test set , the observed quantum bit error rate (QBER) is
No-detection events are not automatically bit errors. They are losses whose security treatment depends on the source and detector model. The test QBER is also not automatically the error rate of the unrevealed key block. A finite-key proof supplies a random-sampling bound and a failure probability for that inference.
Intercept–Resend Attack
Section titled “Intercept–Resend Attack”The simplest attack illustrates information–disturbance without proving full security. Eve intercepts every signal, measures it in a uniformly random or basis, prepares the state indicated by her outcome, and sends that replacement to Bob.
Condition on a sifted round, so Bob happened to use Alice’s basis.
- With probability , Eve also chose Alice’s basis. She learns the bit and resends the correct state, causing no ideal error.
- With probability , Eve chose the conjugate basis. Her outcome is random, and Bob’s measurement of the resent state is wrong with probability .
Therefore
If Eve attacks only a fraction of otherwise ideal rounds, this model gives
After basis disclosure, Eve knows the sifted bit perfectly on the half of her intercepted rounds where she chose correctly. For this particular hard-decision attack, her mutual information is bit per sifted bit before error correction and privacy amplification.
The number is not the BB84 security threshold. General individual, collective, and coherent attacks need not behave like intercept–resend. Device noise can create errors without Eve, and flawed devices can leak information without producing this disturbance. The security theorem bounds Eve over its entire allowed attack class from the complete observed statistics and device assumptions.
Why No-Cloning Is Not the Proof
Section titled “Why No-Cloning Is Not the Proof”The no-cloning theorem rules out a perfect copier for arbitrary unknown pure states. It does not rule out approximate cloning, partial measurements, coherent interactions with an ancilla, selective forwarding, exploitation of multiphoton pulses, or attacks on implementation side channels. Eve need not identify each state perfectly to obtain useful correlated information.
BB84 security instead rests on complementarity and privacy amplification: gaining predictive information about one basis constrains predictions in the conjugate basis, and the observed sample bounds the adversary’s remaining uncertainty. A rigorous proof then compresses the reconciled string below that uncertainty bound.
Source-Replacement Picture
Section titled “Source-Replacement Picture”The prepare-and-measure protocol has an equivalent virtual description. Alice may be imagined to prepare
keep system , and send through the channel. Measuring in basis with outcome prepares Bob’s system in because the BB84 basis vectors are real in the computational basis. Eve cannot distinguish this delayed-choice construction from direct state preparation when the emitted density operators agree.
This source-replacement step makes two error classes visible:
- a bit error means Alice and Bob disagree when both measure in the key basis;
- a phase error is the hypothetical disagreement that would occur in the conjugate basis and controls Eve’s information about the key.
In a CSS-code entanglement-purification argument, one syndrome corrects bit errors and another corrects phase errors. If Alice and Bob could distill nearly perfect Bell pairs, measuring those pairs in the key basis would produce a nearly ideal secret key. Shor and Preskill showed that the required CSS operations can be rearranged and removed until the remaining observable procedure is prepare-and-measure BB84 with classical error correction and privacy amplification.
Entanglement Distillation develops the distributed syndrome viewpoint. Stabilizer Formalism owns the code and syndrome machinery.
Standard Asymptotic Key Fraction
Section titled “Standard Asymptotic Key Fraction”Let and be valid asymptotic upper bounds on bit- and phase-error rates for the sifted key block. Define the binary entropy
In the ideal single-photon BB84 model with one-way postprocessing, an achievable secret fraction per sifted key bit is
The first entropy term is the ideal error-correction cost; the second is the privacy cost associated with phase uncertainty. For symmetric BB84 statistics under the standard reduction,
so
This lower bound becomes positive when
The familiar value is therefore an ideal asymptotic threshold for this proof and one-way processing, not a universal abort setting. Two-way postprocessing, different proof techniques, finite statistics, source flaws, detector models, and protocol variants change the achievable boundary.
Real reconciliation reveals more than the Shannon limit. If its inefficiency is represented by , a common asymptotic engineering estimate is
before verification, authentication, finite-size, and implementation penalties. This expression is a ledger, not a composable finite-key theorem.
The rate per transmitted optical mode must also include detection, basis selection, parameter-estimation sacrifice, dead time, and every other accepted mode criterion. Multiplying only by a clock frequency is not enough.
Authentication and Man-in-the-Middle Attacks
Section titled “Authentication and Man-in-the-Middle Attacks”The public channel need not be secret, but it must be authenticated. Without authentication, Eve can block the quantum and classical traffic and run one independent BB84 session with Alice while impersonating Bob, and another with Bob while impersonating Alice. Both local sessions can have low QBER. Alice and Bob nevertheless share no key with each other.
Information-theoretic authentication can start from a short preshared secret and consume part of each newly generated key. BB84 is then a key-expansion mechanism when the fresh key exceeds authentication and operational costs. Using computational signatures for bootstrap can be sensible, but the final security claim must include that computational assumption and its lifetime.
Authentication covers the full transcript: detection acknowledgments, basis lists, test positions, error-correction messages, verification tags, abort signals, and privacy-amplification seed. Freshness and session binding are needed to prevent replay and cross-session substitution.
Ideal Model and Physical Devices
Section titled “Ideal Model and Physical Devices”The four-state derivation is exact only after its abstraction boundary is declared.
| Ideal proof object | Physical complication | Required response |
|---|---|---|
| one qubit in one of four states | weak coherent pulse may contain zero, one, or several photons | phase randomization, decoy-state estimation, tagged-signal or other source proof |
| basis-independent source | intensity, spectrum, timing, phase, or spatial mode reveals the setting | characterize and bound basis dependence; filter or redesign the source |
| trusted projective measurement | efficiency mismatch, afterpulsing, dead time, blinding, or wavelength response | detector model, countermeasure validation, or measurement-device-independent design |
| erasure-like loss | Eve can correlate forwarding with hidden modes or detector response | prove the accepted-event sampling model; do not treat missing clicks as evidence of secrecy |
| private random choices | biased, predictable, reused, or correlated random numbers | characterize entropy and independence at the protocol interface |
| isolated laboratories | Trojan-horse probes and electromagnetic or optical leakage | isolation, monitoring, leakage bounds, and authenticated control |
| stationary independent rounds | drift, memory, afterpulsing, and coherent attacks | proof covering correlations plus time-resolved diagnostics |
Weak coherent pulses
Section titled “Weak coherent pulses”A phase-randomized coherent pulse of mean photon number has Poisson photon-number probabilities
Multiphoton pulses invalidate the literal single-qubit story because Eve may, under an insufficient proof model, retain one photon and forward another. Decoy-State QKD varies intensity to estimate single-photon contributions without assuming Eve treats signal and decoy labels honestly. That page owns the yield equations, vacuum-plus-weak bounds, and source assumptions. Cryptography Case Studies applies the estimator inside a concrete optical link ledger.
Loss and accepted events
Section titled “Loss and accepted events”In an ideal model, channel loss can be treated as erasure and Eve may control which signals arrive. Security comes from the statistics of accepted events, not from the absence of detections. If acceptance depends on basis, bit, wavelength, arrival time, detector control, or a leaked source mode, the surviving sample may not represent the intended qubit ensemble.
Finite statistics
Section titled “Finite statistics”The asymptotic identity between test and key error rates is replaced by a confidence statement. A finite-key analysis must account for sampling without replacement, smoothing or entropy-estimation terms, error-correction leakage, verification failure, privacy-amplification failure, authentication failure, and all abort branches. Quantum Key Distribution owns that composable ledger.
Variants and Naming
Section titled “Variants and Naming”- Efficient BB84 biases the basis choices so most matched detections can contribute to the key while enough conjugate-basis rounds remain for tests.
- Three-state BB84 omits one of the four signal states but requires its own parameter-estimation and security analysis.
- BBM92 is an entanglement-based protocol using the same two measurement bases; it is operationally related to source replacement but has a different physical source boundary. E91 and Entanglement-Based QKD owns the Bell-tested three-setting protocol and explains why entanglement-based does not automatically mean device-independent.
- Decoy-state BB84 adds intensity settings to bound photon-number-resolved yields for weak coherent pulses; decoys are not extra key-encoding bases.
- Measurement-device-independent QKD moves the detector trust boundary to an untrusted relay and is not merely BB84 with a different detector brand.
Changing basis probabilities, state alphabet, detector trust, source model, or classical postprocessing changes the protocol theorem. The label “BB84” does not by itself specify a secure implementation.
Common Mistakes
Section titled “Common Mistakes”- Calling sifted bits a secret key before parameter estimation, reconciliation, verification, and privacy amplification.
- Saying an eavesdropper necessarily causes QBER; that number belongs to full intercept–resend under the ideal model.
- Treating as a universal experimental threshold.
- Using no-cloning as a complete security proof.
- Forgetting that the classical channel must be authenticated.
- Revealing basis choices before Bob has committed to accepted detections.
- Equating the measured bit-error rate with the phase-error rate without the proof step that relates them.
- Counting lost pulses as evidence that Eve learned nothing.
- Modeling a weak coherent pulse as a guaranteed single photon.
- Quoting secret bits per sifted bit as secret bits per pulse or per second.
- Subtracting dark counts or detector errors from security data without a proof that permits the subtraction.
- Assuming a countermeasure closes every source and detector side channel.
Exercises
Section titled “Exercises”1. Verify mutual unbiasedness
Section titled “1. Verify mutual unbiasedness”Compute all four cross-basis probabilities .
Solution
Using
one obtains
Thus either state in one basis gives a uniform outcome when measured in the other basis.
2. Count sifted rounds
Section titled “2. Count sifted rounds”Suppose signals produce valid detections. How many sifted rounds are expected with uniform independent bases? What is the basis-match probability if both parties choose with probability ?
Solution
Uniform choices match with probability , so the expected sifted count is
With ,
This would yield matched detections on average, but the -matched subset has expected fraction and may be too small for the desired finite statistical bound.
3. Partial intercept–resend
Section titled “3. Partial intercept–resend”In an otherwise noiseless ideal system, the measured QBER is . If every error is attributed to the partial intercept–resend model, what attacked fraction would explain it, and how much sifted-bit information would Eve have in that model?
Solution
Since ,
Eve knows the bit on half of the intercepted sifted rounds, so her mutual information in this simplified model is
bit per sifted bit. This inference is not valid for a general attack or a noisy implementation; it is specific to the stated model.
4. Hide the basis
Section titled “4. Hide the basis”Show that the density operator of a uniformly random bit is in both BB84 bases. Does this prove that Eve has zero information after interacting with a signal and later hearing the basis announcement?
Solution
For the basis,
For the basis,
The equality proves that the ideal emitted ensemble does not reveal the basis before announcement. It does not prove zero later information. Eve may couple an ancilla coherently to the signal, retain it, and condition her final measurement on the public transcript. Security bounds that side information using the disturbance and a full attack model.
5. Find the ideal one-way threshold
Section titled “5. Find the ideal one-way threshold”Solve numerically. Evaluate the asymptotic fraction at .
Solution
The root satisfies and is
At ,
so
secret bit per sifted key bit under the ideal asymptotic assumptions.
6. Separate bit and phase errors
Section titled “6. Separate bit and phase errors”Why can Alice and Bob not simply substitute the observed key-basis QBER for in every BB84 implementation?
Solution
The key-basis QBER directly samples bit disagreement in one basis. The phase error is a counterfactual complementary-basis quantity. Equality or a bound between them follows only from protocol symmetry, random basis sampling, and the source and detector assumptions used in the proof. Basis-dependent flaws or biased accepted events can break a naive equality, so a valid proof derives from test data and characterized imperfections with a failure probability.
7. Explain the authentication requirement
Section titled “7. Explain the authentication requirement”Construct a man-in-the-middle attack on unauthenticated BB84 in which both Alice and Bob observe low QBER.
Solution
Eve blocks all communication. She impersonates Bob in a complete BB84 session with Alice and independently impersonates Alice in a complete session with Bob. Eve honestly performs each local protocol, so both sessions can have low QBER and pass privacy amplification. Alice shares one key with Eve and Bob shares another key with Eve; Alice and Bob share no common key. Eve can then decrypt, modify, and re-encrypt later traffic. Authentication prevents this substitution of identities and transcripts.
8. Build an asymptotic leakage ledger
Section titled “8. Build an asymptotic leakage ledger”After testing, Alice has sifted key bits. Suppose a justified asymptotic model gives , reconciliation uses , and all finite-size, verification, and authentication terms are temporarily omitted. Estimate the remaining secret bits.
Solution
The engineering estimate is
Since ,
This is not a finite-key output length because the exercise explicitly omitted statistical, smoothing, verification, and authentication penalties. A real protocol must subtract them before choosing the hash length.
Further Connections
Section titled “Further Connections”- Quantum Key Distribution supplies correctness, secrecy, composability, finite-key accounting, and the common postprocessing pipeline.
- E91 and Entanglement-Based QKD contrasts BB84’s prepare-and-measure transcript with distributed singlets, Bell-test rounds, and source trust.
- Decoy-State QKD extends weak-coherent-pulse BB84 with photon-number yield estimation while keeping the four-state encoding unchanged.
- Measurement-Device-Independent QKD uses trusted BB84 state preparation at both endpoints and places the Bell analyzer and detectors in an untrusted relay.
- No-Cloning and No-Signaling states the no-go theorems accurately and explains why neither alone proves QKD security.
- Bloch Sphere for Quantum Information places the four BB84 states on the and axes and tracks noisy affine maps.
- Projective Measurement derives the Born probabilities and conditional state update used by Bob and by intercept–resend.
- Density Operators for Quantum Information explains why different ensembles with density operator are indistinguishable before side information arrives.
- Entanglement Distillation develops the Bell-pair and syndrome picture behind the Shor–Preskill reduction.
- Why Quantum Error Correction Is Possible separates syndrome information from the protected logical information.
- Cryptography Case Studies follows BB84 through weak coherent pulses, decoy estimation, realistic loss, and evidence claims.
- Trace Distance gives the operational distance used to express composable secrecy.
References
Section titled “References”- C. H. Bennett and G. Brassard, “Quantum Cryptography: Public Key Distribution and Coin Tossing,” in Proceedings of the IEEE International Conference on Computers, Systems and Signal Processing, Bangalore, 175–179 (1984); reprinted in Theoretical Computer Science 560, 7–11 (2014), doi:10.1016/j.tcs.2014.05.025.
- C. H. Bennett, F. Bessette, G. Brassard, L. Salvail, and J. Smolin, “Experimental Quantum Cryptography,” Journal of Cryptology 5, 3–28 (1992), doi:10.1007/BF00191318.
- C. A. Fuchs, N. Gisin, R. B. Griffiths, C.-S. Niu, and A. Peres, “Optimal Eavesdropping in Quantum Cryptography. I. Information Bound and Optimal Strategy,” Physical Review A 56, 1163–1172 (1997), doi:10.1103/PhysRevA.56.1163.
- D. Mayers, “Unconditional Security in Quantum Cryptography,” Journal of the ACM 48, 351–406 (2001), doi:10.1145/382780.382781.
- H.-K. Lo and H. F. Chau, “Unconditional Security of Quantum Key Distribution over Arbitrarily Long Distances,” Science 283, 2050–2056 (1999), doi:10.1126/science.283.5410.2050.
- P. W. Shor and J. Preskill, “Simple Proof of Security of the BB84 Quantum Key Distribution Protocol,” Physical Review Letters 85, 441–444 (2000), doi:10.1103/PhysRevLett.85.441.
- D. Gottesman, H.-K. Lo, N. Lütkenhaus, and J. Preskill, “Security of Quantum Key Distribution with Imperfect Devices,” Quantum Information and Computation 4, 325–360 (2004), doi:10.26421/QIC4.5-1.
- M. Koashi, “Simple Security Proof of Quantum Key Distribution Based on Complementarity,” New Journal of Physics 11, 045018 (2009), doi:10.1088/1367-2630/11/4/045018.
- R. Renner, Security of Quantum Key Distribution, Ph.D. thesis, ETH Zürich (2005), doi:10.3929/ethz-a-005115027.
- M. Tomamichel, C. C. W. Lim, N. Gisin, and R. Renner, “Tight Finite-Key Analysis for Quantum Cryptography,” Nature Communications 3, 634 (2012), doi:10.1038/ncomms1631.
- V. Scarani, H. Bechmann-Pasquinucci, N. J. Cerf, et al., “The Security of Practical Quantum Key Distribution,” Reviews of Modern Physics 81, 1301–1350 (2009), doi:10.1103/RevModPhys.81.1301.
- F. Xu, X. Ma, Q. Zhang, H.-K. Lo, and J.-W. Pan, “Secure Quantum Key Distribution with Realistic Devices,” Reviews of Modern Physics 92, 025002 (2020), doi:10.1103/RevModPhys.92.025002.
- C. Portmann and R. Renner, “Security in Quantum Cryptography,” Reviews of Modern Physics 94, 025008 (2022), doi:10.1103/RevModPhys.94.025008.
- M. N. Wegman and J. L. Carter, “New Hash Functions and Their Use in Authentication and Set Equality,” Journal of Computer and System Sciences 22, 265–279 (1981), doi:10.1016/0022-0000(81)90033-7.
- M. A. Nielsen and I. L. Chuang, Quantum Computation and Quantum Information, 10th anniversary ed., Cambridge University Press (2010), doi:10.1017/CBO9780511976667.
Summary
Section titled “Summary”BB84 encodes random bits in two conjugate qubit bases. Matched-basis measurements create correlated sifted data; mismatched bases produce uniform outcomes. Intercept–resend causes QBER when applied to every ideal signal, but that pedagogical attack is neither a complete adversary model nor a security threshold.
The source-replacement picture turns BB84 into a virtual entanglement protocol with bit and phase errors. In the ideal asymptotic one-way model this gives and, under the symmetric reduction, . A trustworthy implementation additionally specifies source, detector, loss, randomness, finite-statistical, leakage, authentication, and postprocessing assumptions. Only after those steps do Alice and Bob have a key rather than correlated raw measurements.